How access to pages distributing prohibited content is blocked (now the RKN also checks search engines)

How access to pages distributing prohibited content is blocked (now the RKN also checks search engines)

Before we proceed to describe the system responsible for access filtering by telecommunications operators, it should be noted that Roskomnadzor will now also oversee the operations of search engines.

At the beginning of the year, a procedure for control and a list of activities was approved to ensure that search engine operators comply with the requirements to cease the issuance of information about internet resources, access to which is restricted on the territory of the Russian Federation.

The corresponding order from Roskomnadzor dated November 7, 2017, No. 229 has been registered with the Ministry of Justice of Russia.

The order was adopted within the framework of the implementation of the provisions of Article 15.8 of Federal Law No. 149-FZ 'On Information, Information Technologies, and Information Protection' dated July 27, 2006, which defines the obligations for VPN service providers, 'anonymizers,' and search engine operators to restrict access to information, the distribution of which is prohibited in Russia.

Control activities are conducted at the location of the control authority without interaction with search engine operators.

How access to pages distributing prohibited content is blocked (now the RKN also checks search engines)
An information system is understood to be the Federal State Information System of information resources of information and telecommunications networks, access to which is restricted.

Following the event, a report is compiled, which includes, in particular, information about the software used to establish these facts, as well as data confirming that a specific page (or pages) of the website was in the information system for more than a day at the time of control.

The report is sent to the search engine operator via the information system. In case of disagreement with the report, the operator has the right to submit their objections to Roskomnadzor within three working days, which will also consider the objections within three working days. Based on the results of reviewing the operator's objections, the head of the control authority or his deputy will make a decision on initiating a case of administrative offense.

How the access filtering system for telecommunications operators is currently structured

Several laws in Russia require telecommunications operators to filter access to pages that disseminate prohibited content:

  • Federal Law No. 126 'On Communication,' amendment to Article 46 — on the obligation of the operator to restrict access to information (FSEM).
  • "Unified Register" — a resolution of the Government of the Russian Federation dated October 26, 2012, No. 1101 "On the unified automated information system 'Unified Register of Domain Names, Website Page Addresses in the Information and Telecommunications Network 'Internet', and Network Addresses that Allow Identifying Websites in the Information and Telecommunications Network 'Internet' Containing Information Whose Distribution is Prohibited in the Russian Federation"
  • Federal Law No. 436 "On the Protection of Children...", the categorization of accessible information.
  • Federal Law No. 3 "On Police", Article 13, Paragraph 12 — on eliminating the causes and conditions that contribute to threats to citizen safety and public security.
  • Federal Law No. 187 "On Amendments to Certain Legislative Acts of the Russian Federation Regarding the Protection of Intellectual Rights in Information and Telecommunications Networks" (the "anti-piracy law").
  • Implementation of court decisions and instructions from prosecution authorities.
  • Federal Law dated July 28, 2012, No. 139-FZ "On Amendments to the Federal Law 'On the Protection of Children from Information Harmful to Their Health and Development' and Certain Legislative Acts of the Russian Federation".
  • Federal Law dated July 27, 2006, No. 149-FZ "On Information, Information Technologies, and Information Protection".

Requests from Roskomnadzor for blocking contain an updated list of requirements for the provider; each entry in such a request includes:

  • the type of register under which the restriction is imposed;
  • the time from which the need for access restriction arises;
  • the type of urgency for response (normal urgency – within a day, high urgency – immediate response);
  • the type of blocking of the registry entry (by URL or by domain name);
  • the hash code of the registry entry (changes with any modification of the entry's content);
  • the details of the decision on the necessity of access restriction;
  • one or more page addresses of websites that access should be restricted (not mandatory);
  • one or more domain names (not mandatory);
  • one or more network addresses (not mandatory);
  • one or more IP subnets (not mandatory).

To effectively relay information to operators, the 'Information System for Interaction of Roskomnadzor with Communication Operators' was created. It is located along with regulatory acts, instructions, and memos for operators on a specialized portal:

vigruzki.rkn.gov.ru

In response, to check communication operators, Roskomnadzor has started issuing client AS 'Revisor'. Below is some information about the agent's functionality.

The algorithm for checking the availability of each URL by the Agent. When checking, the Agent must:

  • determine the IP addresses to which the network name of the checked site (domain) resolves or use the IP addresses provided in the export;
  • for each IP address obtained from the DNS servers, perform an HTTP request to the checked URL. If the checked site returns an HTTP redirect, the Agent must verify the URL to which the redirect occurs. No fewer than 5 consecutive HTTP redirects are supported;
  • if the HTTP request cannot be made (the TCP connection cannot be established), the Agent should conclude that the IP address is blocked completely;
  • if the HTTP request is successful, the Agent must check the response received from the checked site by the HTTP response code, by HTTP headers, and by HTTP content (the first received data, up to 10 KB). If the received response matches the templates of blocking pages created at the Central Office, a conclusion should be drawn about the presence of a blockage on the checked URL.;
  • During the URL check, the Agent must verify the establishment of an encrypted connection and mark the resource;
  • if there is no match between the data received by the Agent and the templates of blocking pages or trusted redirect pages indicating a resource blockage, the Agent should conclude that there is no blockage of the URL by the operator's SPD. In this case, the information about the data (HTTP response) obtained by the Agent is recorded in the report (check log file). The system administrator has the ability to create a template for a new blocking page from this record to prevent subsequent false conclusions about absence of blockage.

A list of what the Agent must provide

  • Contact the Data Center to obtain a complete list of URLs and blocking modes that need to be tested;
  • Contact the Data Center for information on the verification modes. Supported modes: full one-time check, full periodic check at a specified interval, one-time selective check with a user-defined list of URLs, periodic check at a specified interval for a list of URLs (of a defined type of records);
  • Continue with the specified verification procedures using the existing list of URLs, in case of being unable to obtain the list of URLs from the Data Center, and storing the obtained verification results for subsequent transmission to the Data Center;
  • Complete execution of the specified verification procedures using the available lists of URLs, in case of being unable to obtain information about the verification modes from the Data Center, and storing the obtained verification results for subsequent transmission to the Data Center;
  • Conduct checks on the blocking results in accordance with the established mode;
  • Send the Data Center a report on the conducted check (verification log file);
  • Ability to check the operability of the operator's communication system, i.e., check the availability of a list of already accessible websites;
  • Ability to perform checks on blocking results using a proxy server;
  • Ability for remote software updates;
  • Ability to conduct diagnostic procedures on the communication system (response time, packet flow path, download speed from an external resource, determine IP addresses for domain names, speed of information retrieval in the reverse communication channel in wired access networks, packet loss rate, average transmission delay time of packets);
  • Verification performance of at least 10 URLs per second provided there is sufficient bandwidth;
  • Ability for multiple agent requests to the resource (up to 20 times), with variable frequency from once per second to once per minute;
  • Ability to create a random order of records in the list provided for testing and assign priority to a specific page on the Internet site.

In general terms, the structure looks like this:

How access to pages distributing prohibited content is blocked (now the RKN also checks search engines)
Software and hardware solutions for internet traffic filtering (DPI solutions) allow operators to block traffic from users to sites on the Roskomnadzor blacklist. Whether they are blocked or not is verified by the Revizor client. It automatically checks the availability of the site against the Roskomnadzor list.

An example of a monitoring protocol is available. at the link.

Last year, Roskomnadzor began testing solutions for blocking that operators can implement under this scheme. Here is a quote from the results of such testing:

“Positive conclusions were received by specialized software solutions 'UBIC', 'EcoFilter', 'SKAT DPI', 'Tiksin-Blocking', 'SkyDNS Zapret ISP', and 'Carbon Reductor DPI'.

A conclusion from Roskomnadzor was also obtained, confirming the possibility for communication operators to use the software 'ZapretService' as a means to restrict access to forbidden resources on the internet. Testing results showed that when installed according to the manufacturer’s recommended connection scheme 'in-line' and with proper configuration of the communication operator's network, the number of identified violations according to the Unified Register of Forbidden Information does not exceed 0.02%.

Thus, communication operators are provided with the opportunity to choose the most suitable solution for them to limit access to forbidden resources, including from the list of software products that received a positive conclusion from Roskomnadzor.

At the same time, during the testing of the IdecoSelecta ISP software product, due to the lengthy deployment and configuration process, some operators could not commence tests within the established timelines. For more than half of the communication operators participating in the testing, the testing period for Ideco Selecta ISP did not exceed one week. Considering the small amount of statistical data obtained and the limited number of test participants, Roskomnadzor stated in the official conclusion that it is impossible to draw definitive conclusions about the effectiveness of the 'Ideco Selecta ISP' product as a means of restricting access to forbidden resources on the internet.

I should add that up to 27 telecom operators with various subscriber numbers from different federal districts of the Russian Federation participated in the testing of each software product.

You can familiarize yourself with the official conclusions on the test results. hereIn these conclusions, there is virtually zero technical information. You can read about the product "Ideco Selecta ISP" to understand how not to do things.

This year testing will continue, and at the moment, according to news from Roskomnadzor, one product has already been taken for testing and two more are planned shortly.

What if the blocking occurred by mistake?

In conclusion, I would like to remind you that Roskomnadzor does "not make mistakes," as confirmed by the Constitutional Court.

The ruling, which effectively absolves Roskomnadzor of responsibility for erroneous site blocks, was made in the context of a complaint to the Constitutional Court from the director of the internet publishers' association, Vladimir Kharitonov. It stated that in December 2012, Roskomnadzor mistakenly blocked his internet library digital-books.ru. As Mr. Kharitonov explained, his resource was located on the same IP address as the portal rastamantales(.)ru (now rastamantales(.)com), which was the original object of the blocking. Vladimir Kharitonov tried to challenge Roskomnadzor's decision in court, but in June 2013, the Tagansky District Court recognized the blocking as lawful, and in September 2013, this decision was upheld by the Moscow City Court.

From there:

At Roskomnadzor, "Ъ" was informed that they are satisfied with the Constitutional Court's decision. "The Constitutional Court confirmed that Roskomnadzor is acting in accordance with the law. If the operator does not have the technical ability to restrict access to a specific page of the site, rather than its network address, then that is the operator's responsibility," said the agency's press secretary to "Ъ."

This issue is also relevant for cloud providers and hosting companies, as similar incidents have occurred with them. In June 2016, the cloud service Amazon S3 was blocked in Russia, even though only the page of the poker room 888poker hosted on its platform was added to the register at the request of the Federal Tax Service. The blocking of the entire resource was actually due to the fact that Amazon S3 uses the secure https protocol, which does not allow individual pages to be blocked. Only after Amazon itself removed the page that faced complaints from Russian authorities was the resource excluded from the register.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster