SlideShare una empresa de Scribd logo
1 de 20
Descargar para leer sin conexión
OONI-probe
                  Detecting internet filtering for a Free and Transparent
                                         Internet




Tuesday, November 8, 2011
Surveillance

                   • Internet filtering is a
                          subset of Surveillance
                   • If they are filtering
                          something, it means
                          that they are surveilling
                          everything



Wednesday, November 9, 2011
Censorship
     It’s a distortion of what is in reality
     the internet.

     Follows the subjectiveness of the
     authorities

     This does not help humanity




                                                 • Internet filtering is a form
                                                   of non democratic
                                                   oppression on people
                                                 • It allows those in power
                                                   to subvert reality
                                                 • FilterNet

Wednesday, November 9, 2011
FilterNet

                   • It’s a distortion of what is in reality the
                            internet.
                   • Follows the subjectiveness of the
                            authorities
                   • This does not help humanity

Tuesday, November 8, 2011
What we are doing?

                   • Help people circumvent censorship (Tor)
                   • Help people speak freely and anonymously
                            (Tor Hidden Services)
                   • Measure Internet filtering in the world
                            (OONI-Probe)



Tuesday, November 8, 2011
Tor

                   • Tor software downloads are currently
                            blocked from China, Iran, Lebanon, Qatar,
                            etc.
                   • Tor delivers via email, write to
                            gettor@torproject.org and we will send
                            you a client to bootstrap a Tor client



Tuesday, November 8, 2011
Hidden Services

                   • They allow a server to give access to
                            content anonymously
                   • This means people can publish content
                            even if filtering is in place
                   • No fear of retaliation

Tuesday, November 8, 2011
Tor Hidden Services

                   • am4wuhz3zifexz5u.onion
                   • Anonymity for the Server
                   • DoS protection
                   • End-To-End encryption

Tuesday, November 8, 2011
How HS work

                   Client
                                           Hidden Server
                                 IP

                                 IP
                                      IP
                        RP



Tuesday, November 8, 2011
Existing filter detection
                           tools
                                                                            OpenNet Initiative
                                                                            (rTurtle)

                                                                            Herdict

                                                                            Academic research

                   •        Various captive portal software
                            •   Windows/iOS/Android/Google Chrome

                   •        ONI has a tool called “rTurtle”
                            •   ...

                   •        Herdict “The verdict of the herd”
                            •   ...

                   •        Some academic research
                            •   GATech and UC Berkeley have the best work

                   •        Methodology, tools and data are (usually) closed


Tuesday, November 8, 2011
OONI-probe:
                              Measuring filtering

                   • Open Observatory of Network
                            Interference
                   • Provide a methodology and framework
                   • Make our data and code publicly available


Tuesday, November 8, 2011
How filtering is
                               performed

                   • Varies by country and agency
                    • Lebanon uses Free Software (squid)
                    • Syria uses commercial software
                            (BlueCoat)




Tuesday, November 8, 2011
Filtering Techniques
        Cost
                                                                Keyword Filtering




                                                DNS Filtering



                                IP Filtering


                                                                                  Accuracy
 Source: A Taxonomy of Internet Censorship and AntiCensorship - Princeton University
Tuesday, November 8, 2011
OONI-Probe Risk
                                Levels
                   • The tests that are run by OONI-probe are
                            divided into three categories:
                            • Active/High (High Risk)
                            • Active/Medium (Medium Risk)
                            • Active/Low (Low Risk)
                            • Passive (No Risk)
Tuesday, November 8, 2011
TTL walking
                                                       Active/High
                                                       Active/Low



                   • UDP, TCP, ICMP
                   • Common ports 0, 53, 80, 123, 443
                   • Compare the result of UDP, TCP with
                            common ports and ICMP traceroute




Tuesday, November 8, 2011
Keyword injection
                                                     Active/High




                   • Actively probe for blocking of particular
                            keywords
                   • Connect to unblocked IP address with fake
                            Host Header




Tuesday, November 8, 2011
DNS probing
                                                  Active/High
                                                  Active/Medium




                   • Compare a good DNS server with a test
                            one
                   • This is used in Italy


Tuesday, November 8, 2011
HTTP requests
                                                    Active/Low
                                                    Passive


                   • Manipulated HTTP requests
                    • HTTP GeT foo.html
                   • Check for altered response/request
                            headers
                   • This is used to detect squid

Tuesday, November 8, 2011
URL lists
                                                   Active/High




                   • Use URL lists of known blocked sites



Tuesday, November 8, 2011
TPO in lebannon
                               Network latency
                                                     Active/Low




                   • Check if the latency is congruent with the
                            destination
                   • A case is Lebanon


Tuesday, November 8, 2011

Más contenido relacionado

Último

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Victor Rentea
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Último (20)

ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 

Destacado

How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
ThinkNow
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 

Destacado (20)

How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 
ChatGPT webinar slides
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slides
 

ooni-probe and Tor (Long Version)

  • 1. OONI-probe Detecting internet filtering for a Free and Transparent Internet Tuesday, November 8, 2011
  • 2. Surveillance • Internet filtering is a subset of Surveillance • If they are filtering something, it means that they are surveilling everything Wednesday, November 9, 2011
  • 3. Censorship It’s a distortion of what is in reality the internet. Follows the subjectiveness of the authorities This does not help humanity • Internet filtering is a form of non democratic oppression on people • It allows those in power to subvert reality • FilterNet Wednesday, November 9, 2011
  • 4. FilterNet • It’s a distortion of what is in reality the internet. • Follows the subjectiveness of the authorities • This does not help humanity Tuesday, November 8, 2011
  • 5. What we are doing? • Help people circumvent censorship (Tor) • Help people speak freely and anonymously (Tor Hidden Services) • Measure Internet filtering in the world (OONI-Probe) Tuesday, November 8, 2011
  • 6. Tor • Tor software downloads are currently blocked from China, Iran, Lebanon, Qatar, etc. • Tor delivers via email, write to gettor@torproject.org and we will send you a client to bootstrap a Tor client Tuesday, November 8, 2011
  • 7. Hidden Services • They allow a server to give access to content anonymously • This means people can publish content even if filtering is in place • No fear of retaliation Tuesday, November 8, 2011
  • 8. Tor Hidden Services • am4wuhz3zifexz5u.onion • Anonymity for the Server • DoS protection • End-To-End encryption Tuesday, November 8, 2011
  • 9. How HS work Client Hidden Server IP IP IP RP Tuesday, November 8, 2011
  • 10. Existing filter detection tools OpenNet Initiative (rTurtle) Herdict Academic research • Various captive portal software • Windows/iOS/Android/Google Chrome • ONI has a tool called “rTurtle” • ... • Herdict “The verdict of the herd” • ... • Some academic research • GATech and UC Berkeley have the best work • Methodology, tools and data are (usually) closed Tuesday, November 8, 2011
  • 11. OONI-probe: Measuring filtering • Open Observatory of Network Interference • Provide a methodology and framework • Make our data and code publicly available Tuesday, November 8, 2011
  • 12. How filtering is performed • Varies by country and agency • Lebanon uses Free Software (squid) • Syria uses commercial software (BlueCoat) Tuesday, November 8, 2011
  • 13. Filtering Techniques Cost Keyword Filtering DNS Filtering IP Filtering Accuracy Source: A Taxonomy of Internet Censorship and AntiCensorship - Princeton University Tuesday, November 8, 2011
  • 14. OONI-Probe Risk Levels • The tests that are run by OONI-probe are divided into three categories: • Active/High (High Risk) • Active/Medium (Medium Risk) • Active/Low (Low Risk) • Passive (No Risk) Tuesday, November 8, 2011
  • 15. TTL walking Active/High Active/Low • UDP, TCP, ICMP • Common ports 0, 53, 80, 123, 443 • Compare the result of UDP, TCP with common ports and ICMP traceroute Tuesday, November 8, 2011
  • 16. Keyword injection Active/High • Actively probe for blocking of particular keywords • Connect to unblocked IP address with fake Host Header Tuesday, November 8, 2011
  • 17. DNS probing Active/High Active/Medium • Compare a good DNS server with a test one • This is used in Italy Tuesday, November 8, 2011
  • 18. HTTP requests Active/Low Passive • Manipulated HTTP requests • HTTP GeT foo.html • Check for altered response/request headers • This is used to detect squid Tuesday, November 8, 2011
  • 19. URL lists Active/High • Use URL lists of known blocked sites Tuesday, November 8, 2011
  • 20. TPO in lebannon Network latency Active/Low • Check if the latency is congruent with the destination • A case is Lebanon Tuesday, November 8, 2011