FINDING · EVALUATION

Unsolicited background radiation traffic to the UCSD network telescope—particularly Conficker worm scanning (TCP SYN, port 445, 48-byte packets)—dropped nearly simultaneously with Egyptian BGP route withdrawals on January 27, corroborating control-plane analysis with data-plane evidence. Crucially, some worm-infected hosts continued to generate outbound scanning traffic even after their prefixes were BGP-withdrawn, because packet filtering was absent; this asymmetry between inbound unreachability and outbound connectivity can distinguish pure BGP-based blocking from combined BGP-plus-filtering approaches.

From 2011-dainotti-analysisAnalysis of Country-wide Internet Outages Caused by Censorship · §4.3, §5.1 · 2011 · Internet Measurement Conference

Implications

Tags

censors
generic
techniques
bgp-hijackasn-blackholingmeasurement-platform

Extracted by claude-sonnet-4-6 — review before relying.