Deep Packet Inspection Technology and Censorship Deep Packet Inspection Technology and Censorship Rob Frieden, Pioneers Chair and Professor of Telecommunications.

Slides:



Advertisements
Similar presentations
Ethernet Switch Features Important to EtherNet/IP
Advertisements

Delivery and Forwarding of
Computer Networks20-1 Chapter 20. Network Layer: Internet Protocol 20.1 Internetworking 20.2 IPv IPv6.
20.1 Chapter 20 Network Layer: Internet Protocol Copyright © The McGraw-Hill Companies, Inc. Permission required for reproduction or display.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Addressing the Network – IPv4 Network Fundamentals – Chapter 6.
1 Chapter 3 TCP and IP. Chapter 3 TCP and IP 2 Introduction Transmission Control Protocol (TCP) Transmission Control Protocol (TCP) User Datagram Protocol.
Transport Layer – TCP (Part1) Dr. Sanjay P. Ahuja, Ph.D. Fidelity National Financial Distinguished Professor of CIS School of Computing, UNF.
Chapter 20 Network Layer: Internet Protocol Stephen Kim 20.1.
Building Your Own Firewall Chapter 10. Learning Objectives List and define the two categories of firewalls Explain why desktop firewalls are used Explain.
UDP - User Datagram Protocol UDP – User Datagram Protocol Author : Nir Shafrir Reference The TCP/IP Guide - ( Version Version.
OSI Model.
FIREWALLS & NETWORK SECURITY with Intrusion Detection and VPNs, 2 nd ed. 6 Packet Filtering By Whitman, Mattord, & Austin© 2008 Course Technology.
A Guide to major network components
Internet 3.0: Assessing the Scope of a Non-Neutral and Tiered Web Internet 3.0: Assessing the Scope of a Non-Neutral and Tiered Web Rob Frieden, Pioneers.
FIREWALL TECHNOLOGIES Tahani al jehani. Firewall benefits  A firewall functions as a choke point – all traffic in and out must pass through this single.
Packet Filtering. 2 Objectives Describe packets and packet filtering Explain the approaches to packet filtering Recommend specific filtering rules.
1. What is the DMCA? Digital Millennium Copyright Act. Signed into law in Provides the legal framework for copyright holders to claim copyright.
Chapter 2 The Infrastructure. Copyright © 2003, Addison Wesley Understand the structure & elements As a business student, it is important that you understand.
Lecture 2 TCP/IP Protocol Suite Reference: TCP/IP Protocol Suite, 4 th Edition (chapter 2) 1.
Chapter 6: Packet Filtering
Internet Packet Switching and Its Impact on the Network Neutrality Debate and the Balance of Power Between IP Creators and Consumers Rob Frieden, Pioneers.
OV Copyright © 2013 Logical Operations, Inc. All rights reserved. Network Security  Network Perimeter Security  Intrusion Detection and Prevention.
OV Copyright © 2011 Element K Content LLC. All rights reserved. Network Security  Network Perimeter Security  Intrusion Detection and Prevention.
15-1 Networking Computer network A collection of computing devices that are connected in various ways in order to communicate and share resources.
Packet Filtering Chapter 4. Learning Objectives Understand packets and packet filtering Understand approaches to packet filtering Set specific filtering.
1 The Internet and Networked Multimedia. 2 Layering  Internet protocols are designed to work in layers, with each layer building on the facilities provided.
Wireless Carterfone: A Long Overdue Policy Promoting Consumer Choice and Competition A Presentation at Free My Phone-- Is Regulation Needed to Ensure Consumer.
Dr. John P. Abraham Professor UTPA
Internetworking Internet: A network among networks, or a network of networks Allows accommodation of multiple network technologies Universal Service Routers.
20.1 Chapter 20 Network Layer: Internet Protocol Copyright © The McGraw-Hill Companies, Inc. Permission required for reproduction or display.
Chapter 19 Network Layer Protocols Copyright © The McGraw-Hill Companies, Inc. Permission required for reproduction or display.
Internetworking Internet: A network among networks, or a network of networks Allows accommodation of multiple network technologies Universal Service Routers.
Chapter 20 Network Layer: Internet Protocol
Network Neutrality and Its Potential Impact on Carrier Pricing Network Neutrality and Its Potential Impact on Carrier Pricing Rob Frieden, Pioneers Chair.
Lecture 4 Overview. Ethernet Data Link Layer protocol Ethernet (IEEE 802.3) is widely used Supported by a variety of physical layer implementations Multi-access.
STORE AND FORWARD & CUT THROUGH FORWARD Switches can use different forwarding techniques— two of these are store-and-forward switching and cut-through.
1 12-Jan-16 OSI network layer CCNA Exploration Semester 1 Chapter 5.
1 Computer Communication & Networks Lecture 19 Network Layer: IP and Address Mapping Waleed Ejaz.
IT 210: Web-based IT Fall 2012 Lecture: Network Basics, OSI, & Internet Architecture.
1 Figure 3-5: IP Packet Total Length (16 bits) Identification (16 bits) Header Checksum (16 bits) Time to Live (8 bits) Flags Protocol (8 bits) 1=ICMP,
Address Resolution Protocol (ARP). Internet and Data Link Layer Addresses Each host and router on a subnet needs a data link layer address to specify.
A Primer on Local Number Portability A Primer on Local Number Portability An Unsponsored Presentation at the Ministerial Workshop on a Regional Approach.
Data Communications and Networks Chapter 6 – IP, UDP and TCP ICT-BVF8.1- Data Communications and Network Trainer: Dr. Abbes Sebihi.
Lect1..ppt - 01/06/05 CDA 6505 Network Architecture and Client/Server Computing Lecture 3 TCP and IP by Zornitza Genova Prodanoff.
Chapter 3 TCP and IP 1 Chapter 3 TCP and IP. Chapter 3 TCP and IP 2 Introduction Transmission Control Protocol (TCP) User Datagram Protocol (UDP) Internet.
TCP/IP1 Address Resolution Protocol Internet uses IP address to recognize a computer. But IP address needs to be translated to physical address (NIC).
Vocabulary Prototype: A preliminary sketch of an idea or model for something new. It’s the original drawing from which something real might be built or.
Chapter 3 TCP and IP Chapter 3 TCP and IP.
Behrouz A. Forouzan TCP/IP Protocol Suite, 3rd Ed.
Packets & Routing Lower OSI layers (1-3) concerned with packets and the network Packets carry data independently through the network, and into other networks…
Vocabulary Prototype: A preliminary sketch of an idea or model for something new. It’s the original drawing from which something real might be built or.
The OSI Model and the TCP/IP Protocol Suite
Vocabulary Prototype: A preliminary sketch of an idea or model for something new. It’s the original drawing from which something real might be built or.
Chapter 6: Network Layer
Internet Protocol Version4
The OSI Model and the TCP/IP Protocol Suite
Packet Sniffing.
Guide to TCP/IP Fourth Edition
Dr. John P. Abraham Professor UTPA
Chapter 20 Network Layer: Internet Protocol
Dr. John P. Abraham Professor UTRGV, EDINBURG, TX
File Transfer Issues with TCP Acceleration with FileCatalyst
Delivery and Forwarding of
Dr. John P. Abraham Professor UTPA
Net 323 D: Networks Protocols
COMPUTER NETWORKS CS610 Lecture-29 Hammad Khalid Khan.
The OSI Model and the TCP/IP Protocol Suite
NET 323D: Networks Protocols
Transport Layer 9/22/2019.
Presentation transcript:

Deep Packet Inspection Technology and Censorship Deep Packet Inspection Technology and Censorship Rob Frieden, Pioneers Chair and Professor of Telecommunications and Law Penn State University web site: blog site: A Presentation at A Digital Rights Roundtable The Ryerson Law Research Centre Toronto, Ontario Canada June 18, 2010

2 Main Points Improvements in traffic management technology, including Deep Packet Inspection (“DPI”), make it efficient and economical for Internet Service Providers (“ISPs”) to operate non-neutral networks offering “better than best efforts” traffic routing, variable quality of service, Digital Rights Management, and all kinds of “traffic shaping.” Improvements in traffic management technology, including Deep Packet Inspection (“DPI”), make it efficient and economical for Internet Service Providers (“ISPs”) to operate non-neutral networks offering “better than best efforts” traffic routing, variable quality of service, Digital Rights Management, and all kinds of “traffic shaping.” DPI offers censorship on a chip or via software. DPI offers censorship on a chip or via software. DPI censors, blocks and drops packets before any administrative or judicial review. This changes the balance of power between carrier and subscriber, because heretofore in most instances users get access to content and only after the fact may have to justify such use. DPI censors, blocks and drops packets before any administrative or judicial review. This changes the balance of power between carrier and subscriber, because heretofore in most instances users get access to content and only after the fact may have to justify such use. DPI can restrict or eliminate lawful access to content depending on programmed parameters; overzealous Penn State programmers blocked my s to some Penn State network users based on a signature containing the word Blogspot. DPI can restrict or eliminate lawful access to content depending on programmed parameters; overzealous Penn State programmers blocked my s to some Penn State network users based on a signature containing the word Blogspot.

3 Main Points (cont.) In the U.S. ISPs enjoy “safe harbor” exemption from liability for copyright infringement, acting as a good samaritan to protect children and serving as a conduit for transmission of other harmful content. In the U.S. ISPs enjoy “safe harbor” exemption from liability for copyright infringement, acting as a good samaritan to protect children and serving as a conduit for transmission of other harmful content. ISPs oppose any limitation on their options for tiering and diversifying services that can accrue financial, operational and consumer benefits, but also achieve anticompetitive goals. ISPs oppose any limitation on their options for tiering and diversifying services that can accrue financial, operational and consumer benefits, but also achieve anticompetitive goals. When ISPs elect to operate non-neutral networks through cheap and effective traffic management technology, they challenge the presumption that ISPs can only operate as neutral conduits. When ISPs elect to operate non-neutral networks through cheap and effective traffic management technology, they challenge the presumption that ISPs can only operate as neutral conduits.

4 Packet Sniffing Explained ISPs use packet switching to subdivide traffic for routing over any available network. ISPs use packet switching to subdivide traffic for routing over any available network. Each packet contains a header that provides routers with needed information about the source and destination of traffic using addressing and management protocols such as TCP/IP. Payloads in packets contain content. Each packet contains a header that provides routers with needed information about the source and destination of traffic using addressing and management protocols such as TCP/IP. Payloads in packets contain content. Improvements in router technology make it possible for ISPs to secure more information from headers for purposes of tiering and prioritizing traffic based on the nature of the content, e.g., streaming content needing instantaneous (“real time”) delivery and high quality of service versus store and forward content such as not requiring immediate processing particularly during network congestion. Improvements in router technology make it possible for ISPs to secure more information from headers for purposes of tiering and prioritizing traffic based on the nature of the content, e.g., streaming content needing instantaneous (“real time”) delivery and high quality of service versus store and forward content such as not requiring immediate processing particularly during network congestion. Routers also can interrogate (“sniff”) headers for instructions on Digital Rights Management, possibly including a go/no go determination whether the intended recipient has the requisite “rights” to receive a specific stream of packets. Routers also can interrogate (“sniff”) headers for instructions on Digital Rights Management, possibly including a go/no go determination whether the intended recipient has the requisite “rights” to receive a specific stream of packets.

TCP Packet Header 4500XXXX XXXX XXXX 4b Ver4b H dL n ToSToS Length in Bytes IP ID 0D FM F M F 13- bit Fra g. Off set TTLTTL ProtocolHeader Checksum Source IP Address XXXX XX Destination IP Address So urc e Por t Destination PortSequence NumberAck Number XXXX XX source: Michael McDonnell and Winterstorm Solutions, Inc. available at:

6 An Easier Analogy

7 How Might ISPs Lose the §512 Safe Harbor Exemption? §512 of the DMCA balances ISPs’ obligations not to induce or contribute to copyright infringement with the national interest in promoting Internet commerce. §512 of the DMCA balances ISPs’ obligations not to induce or contribute to copyright infringement with the national interest in promoting Internet commerce. The DMCA establishes 4 safe harbor exemptions when “online service providers” operate as a neutral, transitory conduit for content, temporarily cache content, store content at the direction of a user and provide search tools for linking to content created by others. The DMCA establishes 4 safe harbor exemptions when “online service providers” operate as a neutral, transitory conduit for content, temporarily cache content, store content at the direction of a user and provide search tools for linking to content created by others. ISPs lose an exemption by not responding to requests to take down infringing content and arguably when they know about infringement and have the right and ability to control such conduct. ISPs lose an exemption by not responding to requests to take down infringing content and arguably when they know about infringement and have the right and ability to control such conduct.

8 Recalculating the Cost of Deep Packet Inspection ISPs characterize network neutrality as creating disincentives to invest in next generation infrastructure and the (re)imposition of “confiscatory” common carrier regulation. ISPs characterize network neutrality as creating disincentives to invest in next generation infrastructure and the (re)imposition of “confiscatory” common carrier regulation. Ironically ISPs have financially benefited from the presumption that they operate as neutral conduits. Ironically ISPs have financially benefited from the presumption that they operate as neutral conduits. When an ISP decides to use packet sniffing to differentiate service it cannot readily ignore the DRM instructions also contained in the header. When an ISP decides to use packet sniffing to differentiate service it cannot readily ignore the DRM instructions also contained in the header. Arguably ISPs can act on DRM flags using ISP routers as opposed to sending the traffic onward to its final destination where end user equipment might process the flag if lawfully required to do so (see ALA v. FCC, 406 F.3d 689 (D.C. Cir. 2005). Arguably ISPs can act on DRM flags using ISP routers as opposed to sending the traffic onward to its final destination where end user equipment might process the flag if lawfully required to do so (see ALA v. FCC, 406 F.3d 689 (D.C. Cir. 2005). The potential loss of the DMCA Sec. 512 safe harbor may change the cost/benefit analysis in non-neutral network operation. The potential loss of the DMCA Sec. 512 safe harbor may change the cost/benefit analysis in non-neutral network operation.

9 Conclusions ISPs do not have an affirmative duty to monitor their traffic streams to detect IP infringement. ISPs do not have an affirmative duty to monitor their traffic streams to detect IP infringement. However technological innovations in routers and packet inspection create opportunities for ISPs to generate more revenue by operating non-neutral networks. However technological innovations in routers and packet inspection create opportunities for ISPs to generate more revenue by operating non-neutral networks. When making the affirmative decision to use packet sniffing for service tiering, ISPs no longer remain passive conduits. When making the affirmative decision to use packet sniffing for service tiering, ISPs no longer remain passive conduits.

10 Conclusions (cont.) Having decided not to operate as non-neutral conduits, ISPs cannot readily ignore DRM formatting standards that could insert header information about whether ISPs should continue to route traffic in light of possible piracy. Having decided not to operate as non-neutral conduits, ISPs cannot readily ignore DRM formatting standards that could insert header information about whether ISPs should continue to route traffic in light of possible piracy. DPI may provide some degree of contemporaneous DRM that ISPs may not ignore if they want to retain safe harbor exemption from secondary liability. DPI may provide some degree of contemporaneous DRM that ISPs may not ignore if they want to retain safe harbor exemption from secondary liability. If ISPs comply with DRM instructions creating a go/no go decision regarding traffic routing, software and hardware will have preempted end users from accessing content on fair use grounds. If ISPs comply with DRM instructions creating a go/no go decision regarding traffic routing, software and hardware will have preempted end users from accessing content on fair use grounds.