A multi-perspective view of Internet censorship in Myanmar
FOCI’21, August 27, 2021, Virtual Event, USA
Myanmar. The company has over 300 customers—large telecoms,
CDNs and other Internet-focused enterprises—using its solutions for NetFlow analysis and half agree for their data to be
used in aggregate analysis. NetFlow is a protocol used to record
metadata about IP traffic flows—including per-flow source and
destination IP addresses, packet count, bytes transferred etc.—
traversing a NetFlow-enabled network device (such as a router,
switch, or host). Since Kentik’s customers include major tier-1
ISPs and global content providers, Kentik’s (sampled) NetFlow
dataset includes samples collected from Internet routers, enabling
the analysis of censorship events (among other uses). This data
represents a large cross-section of traffic flowing through the
Internet and is useful for large-scale understanding of Internet
behavior. To protect users in Myanmar, Kentik aggregated NetFlow traffic statistics by source and destination ASes (for ASes
in Myanmar) and extracted the overall traffic observed at the
AS-level. We analyzed this aggregated data (collected between
Jan. 30 to May 05 2021) and present normalized results.
• Internet global routing data We analyze BGP data collected
by the RouteViews [72] and RIPE RIS[70] projects to understand
the impact of an accidental announcement of Twitter address
space by a Myanmar ISP on the global Internet routing system.
3
were completely disconnected from the Internet. The complementary perspectives offered by IODA and Kentik allow us to detect a
wider range of events. User-driven traffic originating in Myanmar
has diurnal patterns, making it more challenging to observe outages
in the night using Kentik’s traffic. Conversely, IODA has limited
visibility into the connectivity of cellular networks (e.g., because
they often use Carrier Grade NAT) whereas Kentik’s traffic datasets
present visibility into cellular network connectivity as well.
For easy visual comparison of time series values from the four
data sources (3 from IODA and 1 from Kentik), we present normalized values that fall between 0 and 1.
Figure 2: IODA and Kentik data show Internet connectivity
outages on Feb. 1 and Feb. 6., in the first week after the coup.
ANALYSIS
In this section, we present our analyses. Section 3.1 offers a timeline
of the events that we detected. In Section 3.2, we use data from IODA
and Kentik to investigate Internet connectivity shutdowns and in
Section 3.3, we use data from OONI to analyze website and socialmedia blocks. Section 3.4 investigates a BGP hijack event targeting
Twitter’s address space and the collateral damage to users outside
Myanmar. We published an initial (non-peer-reviewed) report about
these events in Mar. 2021 soon after they had begun [84]; this paper
considerably extends our analysis.
3.1
Coup-day outage. We observed a significant Internet outage affecting Myanmar from 21:00 UTC (03:30 AM on Feb. 1 in local
time) on Jan. 31st—the day the coup began (Figure 2). While the
outage is visible in the BGP and Active Probing data sources—with
the number of /24 address blocks in Myanmar reachable on BGP
dropping from 695 to 376, a decrease of 46%—it is less evident in
the Darknet and Kentik Traffic data sources. However, examining
the Traffic data sources at the AS level shows drops in traffic for
several prominent ASes at the same time as drops in IODA data
sources. Further, media reports indicate that an Internet outage did
indeed occur on this day [19, 38, 53, 78].
Notably, there were several differences in the extent to which
ISPs were affected by this outage and in timing patterns (see Figure 6
in Appendix A.2). Some providers (Ooredoo (AS132167) and Telenor
(AS133385)) experienced outages that began at 21:00 UTC whereas
others (MPT (AS9988) and Mytel (AS136255)) underwent outages
just after midnight UTC. Some ISPs (Frontiir (AS58952) and YTP
(AS18399)) did not face a significant outage whereas others (MPT
(AS9988) and Mytel (AS136255)) experienced near-complete loss of
Internet connectivity.
These differences in timing patterns and extent of the outages
are consistent with weak coordination from the government and/or
ISPs. They also suggest the lack of an Internet kill switch that could
cut connectivity for the entire country with one fell swoop; instead,
each provider appears to have received (or at least acted) upon
orders at different times and with different levels of execution.
Overview: a timeline of events
The first week after the coup saw several major censorship events.
The first was an Internet connectivity outage on the day of the
coup itself, on Feb. 1 2021, heralding the tightening of information
controls that would follow. On Feb. 4, Facebook was blocked, and a
day later, so was Twitter. On the same day that Twitter was blocked,
Campana Mythic (AS136168) hijacked address space belonging to
Twitter—likely accidentally—leading to collateral damage for Twitter users beyond Myanmar’s borders. A massive Internet outage
that lasted longer than 24 hours occurred on the first weekend after
the coup, as protests against the coup intensified.
Internet controls tightened in the time since, and have only recently (as of mid-May 2021) begun to show signs of relaxing. Beginning on Feb. 14, country-wide Internet outages affected Myanmar
every night for 72 nights straight, until Apr. 28. Cellular data has
been severely restricted from Mar. 15th [31] and restrictions remain,
as of mid-May 2021. Similarly, social media and website blocks also
continue to remain in place.
3.2
Weekend-after-coup outage. On Saturday, Feb. 6, a 28-hour long
Internet outage affected most ISPs in Myanmar (Figure 2). This
outage is visible clearly in IODA’s data sources, although the BGP
and active probing data sources appear to suggest that some networks remain connected. The outage is also visible in traffic data
Internet connectivity outages
We analyzed measurements collected by the IODA system and traffic data from Kentik to investigate episodes where users in Myanmar
29