A multi-perspective view of Internet censorship in Myanmar FOCI’21, August 27, 2021, Virtual Event, USA Myanmar. The company has over 300 customers—large telecoms, CDNs and other Internet-focused enterprises—using its solutions for NetFlow analysis and half agree for their data to be used in aggregate analysis. NetFlow is a protocol used to record metadata about IP traffic flows—including per-flow source and destination IP addresses, packet count, bytes transferred etc.— traversing a NetFlow-enabled network device (such as a router, switch, or host). Since Kentik’s customers include major tier-1 ISPs and global content providers, Kentik’s (sampled) NetFlow dataset includes samples collected from Internet routers, enabling the analysis of censorship events (among other uses). This data represents a large cross-section of traffic flowing through the Internet and is useful for large-scale understanding of Internet behavior. To protect users in Myanmar, Kentik aggregated NetFlow traffic statistics by source and destination ASes (for ASes in Myanmar) and extracted the overall traffic observed at the AS-level. We analyzed this aggregated data (collected between Jan. 30 to May 05 2021) and present normalized results. • Internet global routing data We analyze BGP data collected by the RouteViews [72] and RIPE RIS[70] projects to understand the impact of an accidental announcement of Twitter address space by a Myanmar ISP on the global Internet routing system. 3 were completely disconnected from the Internet. The complementary perspectives offered by IODA and Kentik allow us to detect a wider range of events. User-driven traffic originating in Myanmar has diurnal patterns, making it more challenging to observe outages in the night using Kentik’s traffic. Conversely, IODA has limited visibility into the connectivity of cellular networks (e.g., because they often use Carrier Grade NAT) whereas Kentik’s traffic datasets present visibility into cellular network connectivity as well. For easy visual comparison of time series values from the four data sources (3 from IODA and 1 from Kentik), we present normalized values that fall between 0 and 1. Figure 2: IODA and Kentik data show Internet connectivity outages on Feb. 1 and Feb. 6., in the first week after the coup. ANALYSIS In this section, we present our analyses. Section 3.1 offers a timeline of the events that we detected. In Section 3.2, we use data from IODA and Kentik to investigate Internet connectivity shutdowns and in Section 3.3, we use data from OONI to analyze website and socialmedia blocks. Section 3.4 investigates a BGP hijack event targeting Twitter’s address space and the collateral damage to users outside Myanmar. We published an initial (non-peer-reviewed) report about these events in Mar. 2021 soon after they had begun [84]; this paper considerably extends our analysis. 3.1 Coup-day outage. We observed a significant Internet outage affecting Myanmar from 21:00 UTC (03:30 AM on Feb. 1 in local time) on Jan. 31st—the day the coup began (Figure 2). While the outage is visible in the BGP and Active Probing data sources—with the number of /24 address blocks in Myanmar reachable on BGP dropping from 695 to 376, a decrease of 46%—it is less evident in the Darknet and Kentik Traffic data sources. However, examining the Traffic data sources at the AS level shows drops in traffic for several prominent ASes at the same time as drops in IODA data sources. Further, media reports indicate that an Internet outage did indeed occur on this day [19, 38, 53, 78]. Notably, there were several differences in the extent to which ISPs were affected by this outage and in timing patterns (see Figure 6 in Appendix A.2). Some providers (Ooredoo (AS132167) and Telenor (AS133385)) experienced outages that began at 21:00 UTC whereas others (MPT (AS9988) and Mytel (AS136255)) underwent outages just after midnight UTC. Some ISPs (Frontiir (AS58952) and YTP (AS18399)) did not face a significant outage whereas others (MPT (AS9988) and Mytel (AS136255)) experienced near-complete loss of Internet connectivity. These differences in timing patterns and extent of the outages are consistent with weak coordination from the government and/or ISPs. They also suggest the lack of an Internet kill switch that could cut connectivity for the entire country with one fell swoop; instead, each provider appears to have received (or at least acted) upon orders at different times and with different levels of execution. Overview: a timeline of events The first week after the coup saw several major censorship events. The first was an Internet connectivity outage on the day of the coup itself, on Feb. 1 2021, heralding the tightening of information controls that would follow. On Feb. 4, Facebook was blocked, and a day later, so was Twitter. On the same day that Twitter was blocked, Campana Mythic (AS136168) hijacked address space belonging to Twitter—likely accidentally—leading to collateral damage for Twitter users beyond Myanmar’s borders. A massive Internet outage that lasted longer than 24 hours occurred on the first weekend after the coup, as protests against the coup intensified. Internet controls tightened in the time since, and have only recently (as of mid-May 2021) begun to show signs of relaxing. Beginning on Feb. 14, country-wide Internet outages affected Myanmar every night for 72 nights straight, until Apr. 28. Cellular data has been severely restricted from Mar. 15th [31] and restrictions remain, as of mid-May 2021. Similarly, social media and website blocks also continue to remain in place. 3.2 Weekend-after-coup outage. On Saturday, Feb. 6, a 28-hour long Internet outage affected most ISPs in Myanmar (Figure 2). This outage is visible clearly in IODA’s data sources, although the BGP and active probing data sources appear to suggest that some networks remain connected. The outage is also visible in traffic data Internet connectivity outages We analyzed measurements collected by the IODA system and traffic data from Kentik to investigate episodes where users in Myanmar 29

Select target paragraph3