geedge.lantern.io

Techniques

ASN / prefix blackholing

detection high

The same T1/NTC node config (ntcconf/t1conf/main.conf, K18/Astana/Kazakhtelecom) exposes concrete DPI enforcement toggles: a SYNACK_OR_RST switch and SEND_INJECT_PKT flag governing active TCP-response/packet-injection behavior; ASN- and IP-based blocklists (ASN_MAAT, IPD_DYN_MAAT, IPD_STATIC_MAAT) refreshed from MAAT/Redis on a 1-second effect interval; a dynamic blacklist with a 180s timeout; explicit protocol-blocking switches for BitTorrent (DHT/uTP) and eMule (Kad); and TLS metadata harvesting including certificate SAN fields (NTC_SSL_COLLECT, collect_san_sw=1) streamed to a Kafka topic.

rst-injectionpacket-injectionasn-blackholingip-blockingtls-fingerprint
detection high

Commit history for the K18 (Kazakhstan) argus-ntc console reveals its concrete feature set: a scheduled "网页关键字定时器" (webpage-keyword timer/scheduler) for keyword filtering, ASN/IP block-list configuration pages, a "BGP泛收" (BGP wide-collection) page, an SSL-interception config toggle, a file-scanning results page with MALWARE TYPE/MALWARE NAME columns, app-identification entries including a WhatsApp rename, and a VoIP business-config approval workflow, with blocking actions relabeled from "阻断" (block) to "封堵(丢弃)" (interdict/drop).

kz keyword-filteringip-blockingasn-blackholingbgp-hijack
detection medium

Two exported IP/CIDR filter-list objects (762 and 5,631 rows respectively, each spanning all ports 0-65535) consist almost entirely of recognizable DigitalOcean (138.68.x, 143.198.x, 159.89.x, 164.90.x, 188.226.128.0/17, etc.) and OVH SAS (51.15.x, 51.83.x, 54.36.x) cloud-hosting CIDR ranges respectively, indicating the platform blocks entire commercial VPS/cloud-hosting provider address space wholesale rather than only individually-identified circumvention-server IPs.

cn ip-blockingasn-blackholing
detection high

The PanGu/mesa_plug bundle (2019) shows the plugin framework's config layout with an explicit http_url_filter.conf plugin config and a dedicated ntc_bgp_plug submodule alongside asn_tableinfo.conf and IP-deny table config, confirming both URL-based content filtering and BGP-feed-driven ASN/prefix blocking are first-class, separately-configured plugins within the DPI stack (not just SNI/IP list matching).

keyword-filteringasn-blackholingbgp-hijack