gfw the great firewall of china

22
GFW The Great Firewall of China Ruiwei Bu CSC 540

Upload: cooper

Post on 13-Jan-2016

145 views

Category:

Documents


1 download

DESCRIPTION

GFW The Great Firewall of China. Ruiwei Bu CSC 540. What?. Part of China’s “Golden Shield” Project A huge firewall that covers mainland China Focusing on Internet Security, Control and CENSORSHIP Name from The Great Firewall of China by Charles R. Smith, May 2012 Started in 1998 - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: GFW The Great Firewall of China

GFWThe Great Firewall of China

Ruiwei BuCSC 540

Page 2: GFW The Great Firewall of China

What?•Part of China’s “Golden Shield” Project

•A huge firewall that covers mainland China

•Focusing on Internet Security, Control and CENSORSHIP

•Name from The Great Firewall of China by Charles R. Smith, May 2012

•Started in 1998

•Famous for the block of Twitter, Facebook, Google and so on

Page 3: GFW The Great Firewall of China

Who?

•The Chinese Government

•Binxing Fang - Father of the GFW• Xiong Gang, Meng Jiao, Cao Zi-gang, Wang Yong, Guo Li, Fang

Binxing, Research Progress and Prospects of Network Traffic Classification. Journal of Integration Technology, Vol 1, May, 2012.

•Hardware: CISCO and others

•Software: Companies and Top University research labs

Page 4: GFW The Great Firewall of China

Where?•Major Devices: ISP backbone and

International Gateway

•Physical Location: Unclear, deployed allover China

•Mongol.py

Page 5: GFW The Great Firewall of China

Target• UGC (User Generated Content), such as

Twitter, Facebook, ...

• Information related to Chinese Government and Politics, such as Tibetan issue

• Opinions that go against the government

• Cults, such as Falun Gong

• Nation Security

• “Random” Websites, such as Github, SourceForge, Python’s Official Website

Page 6: GFW The Great Firewall of China

An Interesting Fact•Top UGC websites maybe blocked,

such as Twitter, Facebook and Youtube

•There are clones in China for all blocked UGC sites.

•Twitter - Sina Weibo, Fanfou, ...

•Facebook - Renren, ...

•Youtube - Tudou, Youku, ...

•Seems no-one cares about not-so-famous ones, such as Path

Page 7: GFW The Great Firewall of China

Typical Route

Page 8: GFW The Great Firewall of China

Abilities•IP Blocking

•DNS Injection and Pollution

•URL Filtering

•Content Filtering and Censorship

•Network Traffic Analysis

•Interfere Secure Connections

•Record user activities

•Network Security

Page 9: GFW The Great Firewall of China

IP and URL Blocking

•Most Simple Method

Page 10: GFW The Great Firewall of China

DNS Injection and Pollution

•/etc/hosts

•Change DNS server, such as 8.8.8.8 or OpenDNS

Page 11: GFW The Great Firewall of China

But...•Still can be polluted even use DNS

outside of the GFW

•DNS attacks returns RST packet before the DNS server returns the address

•And the result is “Connection Reset”

•Can harm the entire Internet

• Anonymous: The collateral damage of internet censorship by DNS injection. CCR July 2012.

Page 12: GFW The Great Firewall of China

URL/Content Filtering

•Can be triggered by any potential keyword in a unknown blacklist. Especially when searching with Google.

•Usually blocks you 10-30 minutes

Page 13: GFW The Great Firewall of China

URL/Content Filtering

•The name of the formal Chinese president is Hu Jintao (胡锦涛 ), but when you search carrot (胡萝卜 ) in Google in mainland China....

Page 14: GFW The Great Firewall of China

Others

•SSL Certificate Filtering and Faking

•Github’s certificate was replaced by a self-signed certificate in Spring 2013

•Fake Tor Nodes and obfs bridge probe and block

• https://blog.torproject.org/blog/tor-partially-blocked-china

•...

Page 15: GFW The Great Firewall of China

Solutions?

•Host Modification

•Proxy

•VPN

Page 16: GFW The Great Firewall of China

Host Modification

•/etc/hosts

•%SystemRoot%/System32/drivers/etc/hosts

•Most simple but not always work

•Can block IP directly

Page 17: GFW The Great Firewall of China

Proxy

•Tunnel Proxy

•Forward Proxy

•Reverse Proxy

•Open Proxy

Page 18: GFW The Great Firewall of China

Online Proxies

•Websites, so easy to use

•Not safe and secure at all

•Can be detected

Page 19: GFW The Great Firewall of China

Proxy Softwares•Freegate, Wujie

•Who’s the funder?

•Tor project

•Onion Network

•.onion pseudo top-level domain

•crimes - Silk Road and so on

•GoAgent (Google App Engine as Proxy)

•Maybe unsafe and unsecure

Page 20: GFW The Great Firewall of China

Tunnel Proxies•Usually deployed on private servers,

such as VPS and GAE

•Private and Safe, under full control by yourself

•Requires advanced networking skills

•SSH (Secure Shell) Tunnel and Port Forwarding, 80, 443!

•VPS servers or IP segments maybe blocked

•Network Traffic Analysis

Page 21: GFW The Great Firewall of China

VPN

•PPTP (Point-to-Point Protocol)

•L2TP (Layer Two Tunneling Protocol)

•More secure

•OpenVPN

•Maybe the best on desktop?

Page 22: GFW The Great Firewall of China

A Simple Proxy Server

Demo Time!