{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,5]],"date-time":"2026-08-05T11:23:16Z","timestamp":1785928996132,"version":"3.56.0"},"reference-count":14,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2012,6,26]],"date-time":"2012-06-26T00:00:00Z","timestamp":1340668800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGCOMM Comput. Commun. Rev."],"published-print":{"date-parts":[[2012,6,26]]},"abstract":"<jats:p>Some ISPs and governments (most notably the Great Firewall of China) use DNS injection to block access to \"unwanted\" websites. The censorship tools inspect DNS queries near the ISP's boundary routers for sensitive domain keywords and inject forged DNS responses, blocking the users from accessing censored sites, such as twitter and facebook. Unfortunately this causes collateral damage, affecting communication beyond the censored networks when outside DNS traffic traverses censored links. In this paper, we analyze the causes of the collateral damages and measure the Internet to identify the injecting activities and their effect. We find 39 ASes in China injecting forged DNS replies. Furthermore, 26 of 43,000 measured open resolvers outside China, distributed in 109 countries, may suffer some collateral damage from these forged replies. Different from previous work that considers the collateral damage being limited to queries to root servers (F, I, J) located in China, we find that most collateral damage arises when the paths between resolvers and some TLD name servers transit through ISPs in China.<\/jats:p>","DOI":"10.1145\/2317307.2317311","type":"journal-article","created":{"date-parts":[[2012,7,3]],"date-time":"2012-07-03T11:53:04Z","timestamp":1341316384000},"page":"21-27","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":66,"title":["The collateral damage of internet censorship by DNS injection"],"prefix":"10.1145","volume":"42","author":[{"family":"Anonymous","sequence":"first","affiliation":[{"name":"Anonymous, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2012,6,26]]},"reference":[{"key":"e_1_2_2_1_1","unstructured":"LookinGlass. http:\/\/lookinglass.org.  LookinGlass. http:\/\/lookinglass.org."},{"key":"e_1_2_2_2_1","unstructured":"Technical requirements for authoritative name servers. http:\/\/http:\/\/www.iana.org\/procedures\/nameserver-requirements.html.  Technical requirements for authoritative name servers. http:\/\/http:\/\/www.iana.org\/procedures\/nameserver-requirements.html."},{"key":"e_1_2_2_3_1","volume-title":"Nov.","author":"Brown M. A.","year":"2010","unstructured":"M. A. Brown , D. Madory , A. Popescu , and E. Zmijewski . DNS Tampering and Root Servers , Nov. 2010 . http:\/\/www.renesys.com\/tech\/presentations\/pdf\/DNS-Tampering-and-Root-Servers.pdf. M. A. Brown, D. Madory, A. Popescu, and E. Zmijewski. DNS Tampering and Root Servers, Nov. 2010. http:\/\/www.renesys.com\/tech\/presentations\/pdf\/DNS-Tampering-and-Root-Servers.pdf."},{"key":"e_1_2_2_4_1","volume-title":"Selection and Operation of Secondary DNS Servers. RFC2182","author":"Bush R.","year":"1997","unstructured":"R. Bush , M. Patton , R. Elz , and S. Bradner . Selection and Operation of Secondary DNS Servers. RFC2182 , 1997 . R. Bush, M. Patton, R. Elz, and S. Bradner. Selection and Operation of Secondary DNS Servers. RFC2182, 1997."},{"key":"e_1_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315290"},{"key":"e_1_2_2_6_1","first-page":"27","volume-title":"Proceedings of the 7th USENIX conference on Networked systems design and implementation, NSDI'10","author":"Dischinger M.","year":"2010","unstructured":"M. Dischinger , M. Marcon , S. Guha , K. P. Gummadi , R. Mahajan , and S. Saroiu . Glasnost: Enabling End Users to Detect Traffic Differentiation . In Proceedings of the 7th USENIX conference on Networked systems design and implementation, NSDI'10 , pages 27 -- 27 , Berkeley, CA, USA , 2010 . USENIX Association. M. Dischinger, M. Marcon, S. Guha, K. P. Gummadi, R. Mahajan, and S. Saroiu. Glasnost: Enabling End Users to Detect Traffic Differentiation. In Proceedings of the 7th USENIX conference on Networked systems design and implementation, NSDI'10, pages 27--27, Berkeley, CA, USA, 2010. USENIX Association."},{"key":"e_1_2_2_7_1","volume-title":"Clarifications to the DNS Specification. RFC2181","author":"Elz R.","year":"1997","unstructured":"R. Elz and R. Bush . Clarifications to the DNS Specification. RFC2181 , 1997 . R. Elz and R. Bush. Clarifications to the DNS Specification. RFC2181, 1997."},{"key":"e_1_2_2_8_1","volume-title":"Odd Behaviour on One Node in I root-server","author":"Ereche M. V.","year":"2010","unstructured":"M. V. Ereche . Odd Behaviour on One Node in I root-server , 2010 . https:\/\/lists.dns-oarc.net\/pipermail\/dnsoperations\/2010-March\/005260.html. M. V. Ereche. Odd Behaviour on One Node in I root-server, 2010. https:\/\/lists.dns-oarc.net\/pipermail\/dnsoperations\/2010-March\/005260.html."},{"key":"e_1_2_2_9_1","unstructured":"G. Lowe P. Winters and M. L. Marcus. The Great DNS Wall of China. http:\/\/cs.nyu.edu\/~pcw216\/work\/nds\/final.pdf 2007.  G. Lowe P. Winters and M. L. Marcus. The Great DNS Wall of China. http:\/\/cs.nyu.edu\/~pcw216\/work\/nds\/final.pdf 2007."},{"key":"e_1_2_2_10_1","unstructured":"W. Lucas. Internet Topology Collection. http:\/\/irl.cs.ucla.edu\/topology\/.  W. Lucas. Internet Topology Collection. http:\/\/irl.cs.ucla.edu\/topology\/."},{"key":"e_1_2_2_11_1","volume-title":"Domain Names - Concepts and Facilities. RFC1034","author":"Mockapetris P.","year":"1987","unstructured":"P. Mockapetris . Domain Names - Concepts and Facilities. RFC1034 , 1987 . P. Mockapetris. Domain Names - Concepts and Facilities. RFC1034, 1987."},{"key":"e_1_2_2_12_1","volume-title":"Domain Names - Implementation and Specification. RFC1035","author":"Mockapetris P.","year":"1987","unstructured":"P. Mockapetris . Domain Names - Implementation and Specification. RFC1035 , 1987 . P. Mockapetris. Domain Names - Implementation and Specification. RFC1035, 1987."},{"key":"e_1_2_2_13_1","volume-title":"Host Anycasting Service. RFC1546","author":"Partridge C.","year":"1993","unstructured":"C. Partridge , T. Mendez , and W. Milliken . Host Anycasting Service. RFC1546 , 1993 . C. Partridge, T. Mendez, and W. Milliken. Host Anycasting Service. RFC1546, 1993."},{"key":"e_1_2_2_14_1","unstructured":"L. Spitzner. Honeytokens: The Other Honeypot. http:\/\/www.symantec.com\/connect\/articles\/honeytokens-other-honeypot 2003.  L. Spitzner. Honeytokens: The Other Honeypot. http:\/\/www.symantec.com\/connect\/articles\/honeytokens-other-honeypot 2003."}],"container-title":["ACM SIGCOMM Computer Communication Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2317307.2317311","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2317307.2317311","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:20:53Z","timestamp":1750238453000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2317307.2317311"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,6,26]]},"references-count":14,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2012,6,26]]}},"alternative-id":["10.1145\/2317307.2317311"],"URL":"https:\/\/doi.org\/10.1145\/2317307.2317311","relation":{},"ISSN":["0146-4833"],"issn-type":[{"value":"0146-4833","type":"print"}],"subject":[],"published":{"date-parts":[[2012,6,26]]},"assertion":[{"value":"2012-06-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}