Skip to Content
[CAIDA - Center for Applied Internet Data Analysis logo]
Center for Applied Internet Data Analysis > publications : papers : 2011 : outages_censorship
Analysis of Country-wide Internet Outages Caused by Censorship
A. Dainotti, C. Squarcella, E. Aben, K. Claffy, M. Chiesa, M. Russo, and A. Pescapè, "Analysis of Country-wide Internet Outages Caused by Censorship", in ACM Internet Measurement Conference (IMC), Nov 2011, pp. 1--18.

A version of this paper was later published in 2014 to IEEE/ACM Transactions on Networking (ToN).

|   View full paper:    PDF    DOI    Related Presentation    |  Citation:    BibTeX    Resource Catalog   |

Analysis of Country-wide Internet Outages Caused by Censorship

Alberto Dainotti4
Claudio Squarcella3
Emile Aben2
Kimberly Claffy1
Marco Chiesa3
Michele Russo4
Antonio Pescapè4

CAIDA, San Diego Supercomputer Center, University of California San Diego


RIPE NCC, Amsterdam, The Netherlands


Roma Tre University


University of Napoli Federico II,
Napoli, Italy

In the first months of 2011, Internet communications were disrupted in several North African countries in response to civilian protests and threats of civil war. In this paper we analyze episodes of these disruptions in two countries: Egypt and Libya. Our analysis relies on multiple sources of large-scale data already available to academic researchers: BGP interdomain routing control plane data; unsolicited data plane traffic to unassigned address space; active macroscopic traceroute measurements; RIR delegation files; and MaxMind's geolocation database. We used the latter two data sets to determine which IP address ranges were allocated to entities within each country, and then mapped these IP addresses of interest to BGP-announced address ranges (prefixes) and origin ASes using publicly available BGP data repositories in the U.S. and Europe. We then analyzed observable activity related to these sets of prefixes and ASes throughout the censorship episodes. Using both control plane and data plane data sets in combination allowed us to narrow down which forms of Internet access disruption were implemented in a given region over time. Among other insights, we detected what we believe were Libya's attempts to test firewall-based blocking before they executed more aggressive BGP-based disconnection. Our methodology could be used, and automated, to detect outages or similar macroscopically disruptive events in other geographic or topological regions.

Keywords: active data analysis, data, internet outages, measurement methodology, network geometry, network telescope, passive data analysis, routing, security, topology
  Last Modified: Tue Nov-17-2020 04:47:12 UTC
  Page URL: