FINDING · DEPLOYMENT

TTL-based path analysis showed that all censorship actions (DNS poisoning, HTTP injection, TLS resets) in the June 2025 shutdown occurred at the same network hop across all tested ISPs, indicating a single centralized national border gateway—likely TCI AS gateways—rather than per-ISP enforcement. Global BGP announcements were kept intact throughout, making the shutdown invisible to routing monitors while domestic connectivity collapsed.

From 2025-aryapour-stealth-blackoutIran's Stealth Internet Blackout: A New Model of Censorship · §4.5 · 2025 · arXiv preprint (cs.NI)

Implications

Tags

censors
ir
techniques
dpidns-poisoningrst-injection

Extracted by claude-sonnet-4-6 — review before relying.