Presentation is loading. Please wait.

Presentation is loading. Please wait.

© British Telecommunications plc Network Filtering.

Similar presentations


Presentation on theme: "© British Telecommunications plc Network Filtering."— Presentation transcript:

1 © British Telecommunications plc Network Filtering

2 © British Telecommunications plc Network Filtering Overview Controls deployment outside of the home in the ISP Effectiveness depends on desired goal –Protection of users wanting to avoid access –Prevention of users wanting to gain access Number of network techniques –DNS filtering –IP blocking –Network deployed web filtering software –Deep Packet Inspection –Hybrid options Not just about technology…

3 © British Telecommunications plc Web browsing overview www.bbc.co.ukwww.bbc.co.uk = 212.58.244.67 http://www.bbc.co.uk/news DNS 212 58 244 67

4 © British Telecommunications plc DNS (Domain Name Service) filtering What –DNS translates an easily typed address (domain) into the IP address of the end site –DNS Filtering involves changing the IP address the domain resolves to, or removing the entry all together. http://www.bbc.co.ukhttp://www.bbc.co.uk = 212.58.244.67

5 © British Telecommunications plc DNS Filtering overview www.bbc.co.ukwww.bbc.co.uk = Non existent http://www.bbc.co.uk/news DNS 212 58 244 67 ?

6 © British Telecommunications plc www.bbc.co.uk http://www.bbc.co.uk/news

7 © British Telecommunications plc DNS (Domain Name Service) filtering Issues –Blocks a whole site (eg, www.bbc.co.uk) and not specific elementswww.bbc.co.uk –Users can easily change the DNS service to a different server from that provided by the ISP –Many facilities to manually translate the domain to IP address on the web. (eg: http://www.network-tools.com)http://www.network-tools.com User then enters IP address rather than domain name (eg: http://212.58.244.67/news) http://212.58.244.67/news http://www.bbc.co.ukhttp://www.bbc.co.uk = 212.58.244.67

8 © British Telecommunications plc IP Blocking What –Requires an ISP to block user traffic to the IP address of the site in their network

9 © British Telecommunications plc IP Blocking overview www.bbc.co.ukwww.bbc.co.uk = 212.58.244.67 http://www.bbc.co.uk/news DNS 212 58 244 67 Router 

10 © British Telecommunications plc IP Blocking Issues –Like DNS, blocks a whole site (eg, 212.58.244.67) and not specific elements –Users can still gain access via “proxy” sites on different networks to bypass the filtering –Easy for sites to move between IP addresses by altering DNS entries

11 © British Telecommunications plc

12 Proxy overview freeproxyserver.net = 67.159.44.96 http://freeproxyserver.net/ DNS 212 58 244 67 Router  67 159 44 96 DNS

13 © British Telecommunications plc http://www.bbc.co.uk/news

14 Proxy overview http://freeproxyserver.net/ DNS 212 58 244 67 Router  67 159 44 96 DNS www.bbc.co.uk = 212.58.244.67

15 © British Telecommunications plc

16 Network deployed web filtering software What –Requires deployment of equipment that understands the user communication (eg, web proxies) –Able to block very specifically

17 © British Telecommunications plc Filtering software overview www.bbc.co.ukwww.bbc.co.uk = 212.58.244.67 http://www.bbc.co.uk/news DNS 212 58 244 67 http://www.bbc.co.uk/news http://news.bbcimg.co.uk/images/header.jpg http://news.bbcimg.co.uk/images/image1.jpg  http://news.bbcimg.co.uk/images/image2.jpg  http://news.bbcimg.co.uk/images/image3.jpg http://news.bbcimg.co.uk/icons/sm_icon.ico

18 © British Telecommunications plc

19 Network deployed web filtering software Issues –Must sit in the route of the users traffic –Cost of deploying new dedicated hardware –Users can still gain access via “proxy” sites on different networks to bypass the block

20 © British Telecommunications plc Deep Packet Inspection What –Can cover more protocols than application specific technology –Able to block very specifically –Can look deeper into packets to stop proxying Issues –Must sit in the route of the users traffic –Generally more costly than application specific technology as requires greater processing power. –Encryption disables the ability to inspect traffic https web proxy sites Tunnelling networks (eg TOR) –Greater user privacy concerns

21 © British Telecommunications plc Packet inspection http:// Text is readablehttps:// Text is secure

22 © British Telecommunications plc Hybrid Options What –Combination of network routing and deployment of hardware to minimise costs Stage 1 – manipulate routing to direct traffic between user and site to dedicated filtering hardware Stage 2 – filter using application layer or DPI technology

23 © British Telecommunications plc Request to good URL on filtered server (2,5) Request to filtered URL on filtered server (3,4) Request to good URL on OK server (1,6) Ealing Ilford T/house Kingston Bletch. Birm Manc EdinGlasSheff Redbus St.Alb UK/EU Linx Peers WWW Filtered Server OK Server Filtered Server OK Server 1 2 3 4 5 6 Network Traffic Overview BT Global Network BT UK Network

24 © British Telecommunications plc Ealing Ilford T/house Kingston Bletch. Birm Manc EdinGlasSheff Redbus St.Alb UK/EU Linx Peers BT Global Network WWW Filtered Server OK Server Filtered Server OK Server BT UK Network 1 2 3 4 5 6 Revised Traffic Overview Filtering equipment Request to good URL on filtered server (2,5) Request to filtered URL on filtered server (3,4) Request to good URL on OK server (1,6)

25 © British Telecommunications plc Hybrid Options Issues –Users can still gain access via “proxy” sites on different networks to bypass the filtering as these sites won’t be directed to dedicated technology –Encryption disables the ability to inspect traffic https web proxy sites Tunnelling networks (eg TOR)

26 © British Telecommunications plc Not just about technology… Who decides what to filter? Operational cost of managing filtering

27 © British Telecommunications plc Summary Shown BT’s current offerings Highlighted options available to customer’s in the home Shown network controls and associated issues Effectiveness depends on desired goal –Protection of users wanting to avoid access –Prevention of users wanting to gain access

28 Questions & Answers


Download ppt "© British Telecommunications plc Network Filtering."

Similar presentations


Ads by Google