Skip to main content
QUICK REVIEW

[论文解读] Characterizing and Avoiding Routing Detours Through Surveillance States

Anne Edmundson, Roya Ensafi|arXiv (Cornell University)|May 24, 2016
Internet Traffic Analysis and Secure E-voting参考文献 15被引用 17
一句话总结

本文研究了跨国路由绕行问题,揭示了即使源点和目的地均位于非监控国家,用户流量仍可能暴露于监控国家。通过测量通往热门域名的路径,研究发现覆盖层中继和开放DNS解析器可显著减少对高监控司法管辖区的穿越——将巴西流量经由美国的传输比例从84%降至37%——尽管主要监控国家仍难以完全避开。

ABSTRACT

An increasing number of countries are passing laws that facilitate the mass surveillance of Internet traffic. In response, governments and citizens are increasingly paying attention to the countries that their Internet traffic traverses. In some cases, countries are taking extreme steps, such as building new Internet Exchange Points (IXPs), which allow networks to interconnect directly, and encouraging local interconnection to keep local traffic local. We find that although many of these efforts are extensive, they are often futile, due to the inherent lack of hosting and route diversity for many popular sites. By measuring the country-level paths to popular domains, we characterize transnational routing detours. We find that traffic is traversing known surveillance states, even when the traffic originates and ends in a country that does not conduct mass surveillance. Then, we investigate how clients can use overlay network relays and the open DNS resolver infrastructure to prevent their traffic from traversing certain jurisdictions. We find that 84\% of paths originating in Brazil traverse the United States, but when relays are used for country avoidance, only 37\% of Brazilian paths traverse the United States. Using the open DNS resolver infrastructure allows Kenyan clients to avoid the United States on 17\% more paths. Unfortunately, we find that some of the more prominent surveillance states (e.g., the U.S.) are also some of the least avoidable countries.

研究动机与目标

  • 理解为何非监控国家的流量仍会穿越已知的监控国家,即使已尝试保持流量本地化。
  • 评估覆盖网络中继和开放DNS解析器在规避经由监控司法管辖区的路由绕行方面的有效性。
  • 识别因在全球路由基础设施中扮演关键角色而最难避开的国家。
  • 为希望借助路由选择最小化大规模监控暴露的用户和网络提供可操作的见解。

提出的方法

  • 从多个观测点测量通往热门域名的国家层级路径,以识别跨国绕行。
  • 分析在客户端部署覆盖层中继对路径多样性及司法管辖区暴露的影响。
  • 评估使用开放DNS解析器基础设施以重定向查询并避开特定国家的效果。
  • 使用traceroute和DNS查询分析映射路由路径,并检测是否经过监控国家。
  • 基于公开可查的关于大规模监控计划的证据,将国家分类为监控国家。
  • 比较基线路由行为与使用中继或替代DNS解析器时的路由行为。

实验结果

研究问题

  • RQ1非监控国家的流量路径在多大程度上会穿越已知的监控国家?
  • RQ2覆盖网络中继在减少经由美国等高监控司法管辖区的传输方面效果如何?
  • RQ3开放DNS解析器基础设施能否帮助客户端避免经由特定国家(如美国)的路由?
  • RQ4哪些监控国家因在全球路由中的核心地位而最难避开?
  • RQ5网络拓扑结构和路由多样性对司法管辖区规避可行性有何影响?

主要发现

  • 84%的巴西发起的流量路径会穿越美国,尽管巴西并未开展大规模监控。
  • 当客户端使用覆盖层中继时,巴西路径中穿越美国的比例降至37%,表明暴露程度显著降低。
  • 使用开放DNS解析器基础设施使肯尼亚客户端在17%更多的路径上避开了美国,相比默认配置。
  • 尽管美国是主要监控国家,但因其在全球路由中的核心地位,仍是最难避开的国家之一。
  • 许多国家试图保持本地流量本地化的努力,因热门网站的托管和路由多样性不足而受挫。
  • 即使采用缓解技术,由于某些高监控国家在全球骨干网络中的主导地位,仍无法完全避开。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。