Contd. TSG’s Capabilities
including HTTP, DNS, Email, TLS, QUIC, and SIP. TSG is designed to monitor both internet
traffic
and
telephone
censor
specific
(VPNs)
and
sessions
in
communications.
applications
other
and
methods
realtime
of
through
Additionally,
websites,
it
as
well
as
circumvention.
TSG
is
techniques
such
as
has
to
the
capacity
block
Virtual
to
identify
Private
and
Networks
also
capable
of
modifying
spoofing
redirect
responses,
HTTP
altering
headers, injecting scripts, replacing text, and overriding response bodies.
TSG has the ability to block, monitor, intercept, or manipulate network traffic by matching a
range of metadata, such as IP addresses, host names, built-in and user-defined categories,
URLs, and TLS fingerprints. When the connection is not encrypted using TLS, it can even
intercept
HTTP
header
content.
Furthermore,
signatures,
TSG
can
passwords,
extract
the
email
addresses,
metadata
for
attachments,
telephone
and
email
communications,
including both origin and destination phone numbers.
TSG
is
capable
methods.
The
of
analyzing
first
method
Transport
involves
Layer
full
Security
decryption
(TLS)
using
traffic
the
through
two
primary
Man-in-the-Middle
(MITM)
technique, which requires the installation of a self-signed root Certificate Authority (CA)
certificate by the subscriber. The second method employs deep packet inspection (DPI)
and
machine
learning
techniques
to
extract
metadata
from
encrypted
traffic.
The
latter
approach is more commonly used, as it’s invisible to the internet user, thereby eliminating
the need for the internet user to install a CA certificate or configure any proxy settings.
Additionally, a hybrid operation is possible, where full decryption is restricted to a specific
subset of domains. Decrypted traffic can also be mirrored to another device for further
inspection. The component responsible for implementing the TLS MITM attacks is referred
to as the Tiangou Frontend Engine (TFE).
The company's use of these two distinct TLS analysis methods may stem from decisions
made
when
deploying
in
one
of
Geedge’s
first
client
countries,
Kazakhstan.
When
Kazakhstan first attempted to implement nationwide censorship, long before Geedge was
founded, Kazakhstan explored requiring all internet users to install a government-controlled
TLS certificate authority. This approach would have enabled them to intercept all encrypted
traffic
by
running
their
own
CA
and
operating
outside
the
global
internet
trust
system.
However, the method proved impractical—requiring manual installation on every device—
and ultimately failed when international browser manufacturers blocked the root certificate.
This example is described in more detail in the country deployment section.
Blocking VPNs & Circumvention Tools
TSG also employs deep packet inspection to comprehensively identify protocols associated
with
Virtual
Private
Networks
(VPNs)
and
circumvention
tools,
such
as
OpenVPN
WireGuard. It then allows clients to work with Geedge Networks to develop rulesets to...
and