FINDING · EVALUATION

Over 2.5 months (Nov 2024–Jan 15, 2025), IRBlock scanned all 11M Iranian IPv4 addresses daily, finding 6.8M IPs subject to DNS poisoning and HTTP blockpage injection, and 5.4M IPs subject to UDP-based traffic disruption. Testing over 700M FQDNs (500M apex domains) revealed 6M banned FQDNs from 3.3M censored apex domains. Of 537 active ASes in Iran, 485 (90.3%) exhibited blocking for at least 25% of assigned IPs. DNS and HTTP censorship overlapped at >99% of censored IPs; UDP blocking was a strict subset of DNS-censored IPs, affecting ~5M addresses.

From 2025-tai-irblockIRBlock: A Large-Scale Measurement Study of the Great Firewall of Iran · §5.1, §1 · 2025 · USENIX Security Symposium

Implications

Tags

censors
ir
techniques
dns-poisoningpacket-injectionhttp3-quic-block

Extracted by claude-sonnet-4-6 — review before relying.