Skip to main content
QUICK REVIEW

[论文解读] How Great is the Great Firewall? Measuring China's DNS Censorship

Nguyen Phong Hoang, Arian Akhavan Niaki|arXiv (Cornell University)|Jun 3, 2021
Internet Traffic Analysis and Secure E-voting参考文献 32被引用 11
一句话总结

本文介绍了GFWatch,这是一个大规模、长期的测量平台,每日测试数亿个域名,以监控中国防火墙(GFW)的DNS审查。在九个月的监测期内,GFWatch检测到311,000个被屏蔽的域名,并识别出3,580个伪造的IPv4和IPv6 IP地址,其中包括来自美国公司的全球可路由IP地址,同时揭示了公共DNS解析器(如Google和Cloudflare)广泛存在的DNS污染问题。

ABSTRACT

The DNS filtering apparatus of China's Great Firewall (GFW) has evolved considerably over the past two decades. However, most prior studies of China's DNS filtering were performed over short time periods, leading to unnoticed changes in the GFW's behavior. In this study, we introduce GFWatch, a large-scale, longitudinal measurement platform capable of testing hundreds of millions of domains daily, enabling continuous monitoring of the GFW's DNS filtering behavior. We present the results of running GFWatch over a nine-month period, during which we tested an average of 411M domains per day and detected a total of 311K domains censored by GFW's DNS filter. To the best of our knowledge, this is the largest number of domains tested and censored domains discovered in the literature. We further reverse engineer regular expressions used by the GFW and find 41K innocuous domains that match these filters, resulting in overblocking of their content. We also observe bogus IPv6 and globally routable IPv4 addresses injected by the GFW, including addresses owned by US companies, such as Facebook, Dropbox, and Twitter. Using data from GFWatch, we studied the impact of GFW blocking on the global DNS system. We found 77K censored domains with DNS resource records polluted in popular public DNS resolvers, such as Google and Cloudflare. Finally, we propose strategies to detect poisoned responses that can (1) sanitize poisoned DNS records from the cache of public DNS resolvers, and (2) assist in the development of circumvention tools to bypass the GFW's DNS censorship.

研究动机与目标

  • 提供长期、大规模的持续监测,以观察中国DNS过滤行为。
  • 揭示GFW DNS审查的真实范围,包括被屏蔽域名和伪造IP地址。
  • 分析GFW DNS过滤对全球DNS解析器(尤其是Google和Cloudflare等公共解析器)的影响。
  • 逆向分析GFW的过滤规则,并检测对无害域名的过度屏蔽行为。
  • 开发针对污染DNS响应的检测与缓解策略,以支持绕过审查和解析器净化。

提出的方法

  • 部署GFWatch,一个使用GFW两侧专用机器的大规模DNS测试平台,以实现对DNS解析的全面测量。
  • 在九个月期间,每日对平均4.11亿个不同域名进行测试。
  • 通过分析已知被屏蔽域名的DNS响应,使用探测技术逆向推导GFW的黑名单。
  • 通过比较预期响应与实际响应,识别DNS响应中伪造的IP地址,重点关注全球可路由IP。
  • 通过关联被屏蔽域名与权威名称服务器的位置及地理路由,检测地理封锁效应。
  • 基于伪造响应中的观察模式和解析器污染,提出针对污染DNS记录的检测策略。

实验结果

研究问题

  • RQ1在中国GFW DNS过滤长期运行期间,有多少个域名被屏蔽?
  • RQ2GFW在DNS响应中注入的伪造IP地址具有哪些特征及其分布情况?
  • RQ3GFW的DNS屏蔽在多大程度上污染了Google和Cloudflare等公共DNS解析器?
  • RQ4地理限制和权威名称服务器在中国的存在如何导致外部解析器中的DNS污染?
  • RQ5哪些检测机制能够有效识别并缓解来自GFW的污染DNS响应?

主要发现

  • GFWatch在九个月内测试了5.34亿个不同域名,检测到311,000个被GFW DNS过滤器屏蔽的域名。
  • GFW在伪造的DNS响应中注入了1,781个唯一的IPv4地址和1,799个唯一的IPv6地址,其中包括来自美国公司(如Facebook、Dropbox和Twitter)的全球可路由IP。
  • 在被屏蔽的311,000个域名中,有41,000个为无害域名,且符合GFW的正则表达式过滤规则,表明存在过度屏蔽。
  • 由于GFW的过滤,77,000个被屏蔽域名在Google和Cloudflare等公共解析器中存在污染的DNS记录。
  • 地理限制以及权威名称服务器位于中国,是导致外部解析器中DNS污染的重要因素。
  • 本研究在OONI中识别出593个常见的伪造IP,在Censored Planet中识别出1,600个,凸显了因解析器策略和测量范围差异导致的平台间差异。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。