FOCI’21, August 27, 2021, Virtual Event, USA
Padmanabhan et al.
from Kentik; this data source shows that negligible traffic was sent
during this time. Since IODA’s data indicating (some) connectivity
may be due to responses to active probes from infrastructure (like
routers), the traffic dataset provides us with the additional detail
that most end-users in Myanmar likely had no Internet connectivity
during this outage.
IODA’s measurements show that the start time of these outages
had some differences across ISPs, but the outages’ end-times were
similar across most ISPs. This synchronization is suggestive of
improved planning, coordination, and execution of this shutdown.
to fixed-line networks, these outages are often not visible even in
state-of-the-art monitoring systems such as IODA. However, by
examining aggregated traffic statistics from a major company, we
were able to shed light and increase awareness upon these outages
as well.
3.3
Website and social media blocking
We analyzed OONI measurements collected from Myanmar from
Feb. 1, 2021 to Apr. 30, 2021 [58]. Specifically, we analyzed OONI
Web Connectivity [59, 60] measurements, which are designed to
measure the DNS, TCP/IP, and HTTP blocking of websites.
Figure 4 shows results for some of the websites found highly
blocked based on our analysis, aggregating the measurement values per day across tested ASes in Myanmar. In the ‘TCP/IP’, ‘DNS’
and ‘HTTP’ blocking cases, the local OONI Probe user observed a
different response compared to the response from OONI’s control
vantage point (Section A.3 in the Appendix contains additional
methodology details). We limited the findings in Figure 4 to include popular social media sites, circumvention tool sites, as well as
wikipedia.org, coronavirus.app, and several websites that presented
anomalies (possibly) due to collateral damage. As shown by the size
of the bubbles in Figure 4, more OONI Probe users ran measurements in Feb. immediately following the coup compared to later
months; the surge in Feb. was partially driven by the "Anonymous"
group encouraging Myanmar users to run OONI Probe tests [26].
Nightly curfews. From the night of Feb. 14, nightly outages affected most ISPs for 72 nights, until Apr. 28th. These outages began
at the same time (18:30 UTC/01:00 local) and lasted 8 hours on
most nights (Figure 7, Appendix A.2). The outages are visible in
all data sources, although the traffic data source again reveals that
whatever connectivity IODA reports during these times is unlikely
to be from end-users, since there is negligible end-user traffic.
In contrast to the coup-day outage, the nightly outages occurred
in a highly synchronized manner, with outages beginning and
ending at identical times for most ISPs. This synchronization is
consistent with enhanced censorship mechanisms and tools that
diverse ISPs likely now possess and also with increased control
over these ISPs by the government.
DNS blocking. In Figure 4, we have annotated measurements
as ‘Confirmed DNS blocked’ when we observed DNS-based interference returning IP addresses that (previously) hosted block
pages (59.153.90.11, 167.172.4.60) or an address in private IP
space (such as 127.0.0.1 or 172.29.8.1). Many ISPs in Myanmar
showed evidence of confirmed DNS blocking, usually resolving to
an IP address that hosted a blockpage. Some ISPs responded with
NXDOMAIN responses for domains like www.facebook.com. DNS
interference was not consistent inside an ISP; some DNS resolvers
implemented DNS blocking while others in the same ISP did not.
IP address blocking. We primarily observe IP-based blocking
of websites, as most measurements (across ASes) show that TCP
connections to the resolved IP addresses failed (when resolution
succeeded in providing the right IP address for the website). Our
empirical observation of IP-based blocking partially corroborates
anecdotal evidence of purportedly blocked IP addresses that circulated on social media (a VPN block list circulated on Facebook,
listing specific VPN IP addresses that ISPs in Myanmar may have
been required to block access to [27]). This censorship technique
is primarily seen in OONI data after the coup, as OONI’s analysis in Myanmar in 2020 showed that DNS based interference was
previously more prevalent [45].
Figure 3: Traffic data from Kentik show that cellular traffic
has reduced considerably from Mar. 15th.
Cellular outages. From Mar. 15th, cellular connectivity has been
heavily restricted [31]. Although these outages are not visible in
IODA’s datasets, the drop in Kentik traffic is clearly visible in Figure 7 (Appendix A.2). In Figure 3, we break down the traffic dataset
from Kentik by four large cellular providers (MPT (AS9988), Mytel
(AS136255), Telenor (AS133385), and Ooredoo (AS132167)), and also
include a major non-cellular provider for contrast. We see a substantial reduction in traffic from the cellular providers even during
the day, whereas the non-cellular provider only observes drops
in traffic during the nightly curfews. The cellular restrictions are
ongoing, as of mid-May 2021.
Observing these cellular outages was only possible due to the
added perspective of the traffic dataset from Kentik, and demonstrates the value of using multiple measurement techniques. Since
cellular networks have some idiosyncratic differences compared
Collateral damage. IP based blocking can potentially lead to collateral damage, affecting the accessibility of other domains hosted
on a blocked IP address. We found 2 such cases:
(i) Domains hosted on the IP 172.217.194.121. This IP address
belongs to the Google hosting network and includes domains such
as www.snapchat.com, www.getoutline.org, www.paganpride.org,
and www.privaterra.org, all of which presented TCP/IP anomalies
between Feb. 24 - 27, 2021 (as illustrated in Figure 4). The fact that
30