Contd. Assigning User Reputation Scores The system possesses the capability to maintain a reputation score for each subscriber, which is determined by their online activities and the extent of personal information the system has collected about them. Should a subscriber’s reputation score decline significantly, their internet service may be cut-off and they might be required to undergo photo ID and facial recognition verification to authenticate their identity and improve their score. Furthermore, the system can identify individual subscribers as known VPN users and then later track their Internet usage and categorize any future unknown highbandwidth traffic flows as suspicious. This individualized classification can lead to the identification and blocking of previously unidentified services when an internet user switches to a new VPN provider, potentially exposing this new VPN and implicating not only the identified internet user but also all other users of this service. Identifying and Blocking Individual Internet Users TSG can also identify individual internet users that are sharing the same public IP address. TSG includes its own implementation of Network Address Translation, referred to as WANNAT, which can function in either Source NAT (SNAT) mode to implement Carrier-Grade Network Address Translation (CGNAT) or in Destination NAT (DNAT) mode to redirect traffic destined for the internet. For example, it can reroute traffic intended for public DNS resolvers to a carrier or government-controlled DNS resolver. TSG also has the ability to detect and block subscribers who utilize the tethering function to share their mobile phone's network connection with other devices. 12 These features are notable offerings, as they are functions that are appealing to Internet Service Providers, rather than client governments, and reflect network management and cost saving needs. This may help ensure the buy-in from ISPs for installing Geedge onto their network by providing attractive services in addition to the wider surveillance and censorship features. Infecting Users with Malware TSG is equipped with an in-path injection capability that allows for the insertion of malicious code into files transmitted through the network. Geedge Networks is very explicit that this feature is intended for inserting malware into internet traffic as it passes through the TSG system. This functionality is comparable to other in-path injection systems, such as the FinFly ISP system formerly sold by FinFisher and the Sandvine PacketLogic system utilized in Egypt for redirecting users to harmful traffic. TSG is capable of injecting malicious JavaScript and CSS into web pages accessed by users, as well as modifying and embedding malicious code into executable files downloaded in real-time.

Select target paragraph3