Publications
Please cite this USENIX Security 2025 paper if you use this data in your research. Questions, feedback, or collaboration ideas are very welcome: drop us a line at NPHoang@UBCNet.ca.
Jonas Tai, Karthik Nishanth Sengottuvelavan, Peter Whiting, and Nguyen Phong Hoang. 2025. IRBlock: A Large-Scale Measurement Study of the Great Firewall of Iran. Proceedings of the 34th USENIX Security Symposium (USENIX Security '25).
@inproceedings{tai2025:irblock,
author = {Tai, Jonas and Sengottuvelavan, Karthik Nishanth and Whiting, Peter and Hoang, Nguyen Phong},
title = {{IRBlock}: A Large-Scale Measurement Study of the Great Firewall of Iran},
booktitle = {Proceedings of the 34th USENIX Security Symposium},
series = {{USENIX Security '25}},
year = {2025},
}
Data
The aggregated metrics shown on this dashboard are free to use for academic research.
Behind them sits a considerably larger longitudinal archive: per-scan censored-address counts by network reaching back to October 2024, per-cycle blocked-domain lists, and several million inferred blocking rules per mechanism with the dates each was observed.
We provide two curated bulk datasets on request rather than as open downloads:
- Aggregated censored IP addresses, by network and mechanism, over the period you need.
- Tested and censored FQDNs, with the mechanism that caught each one and the inferred blocking rule.
Access is by request for two reasons. These files describe live censorship infrastructure in detail, and posting them openly hands the operator a convenient map of exactly what we can see, which is the fastest way to lose the measurement. It also lets us record what a dataset is being used for, which our ethics commitments require. Requests from researchers, circumvention developers and journalists are all welcome: write to NPHoang@UBCNet.ca with a sentence on what you are working on, and we will set up access.
Raw packet captures are not distributed. If your work needs something beyond what is published here, describe what you are trying to measure and we will see what we can prepare, or run the analysis on your behalf. Methodology questions, replication requests, and collaboration ideas are equally welcome.
Method and its limits
IRBlock exploits the GFI's bidirectional blocking as a side channel: much of its filtering acts on traffic regardless of direction, so packets sent inward from our probes provoke the same middleboxes a user inside would meet, and the injected responses are the measurement. No volunteers or devices inside Iran are involved, and coverage extends to essentially the whole address space rather than a handful of vantage points.
What this measures is therefore the bidirectionally-triggerable portion of the apparatus. That qualifier is load-bearing: our earlier work on China's Great Firewall established that bidirectional blocking is not symmetric, and that certain filtering responds only when probed from inside the country. Such filtering is invisible to this method by construction. Every figure published here is a lower bound, and an absence in the data is not evidence that nothing is being blocked.
The design accepts that limit deliberately. Sustained large-scale measurement from inside Iran would require volunteers to run probes against a strict surveillance apparatus; in-country vantage points are impractical to obtain under sanctions and Iranian regulation, and would in any case be too few to represent a country-sized network; and probing in-country public servers at this volume raises its own ethical concerns. Measuring from outside trades the inside-only-triggerable blind spots for continuous, near-complete coverage sustained over years at no risk to anyone in Iran.
The sharpest instance is Iran's mobile carriers. We detect censorship on under 2% of their address space, against 89 to 100% for fixed-line networks, yet in-country measurements published by OONI confirm blocking in those same networks at rates equal to or higher than elsewhere. Roughly a third of Iran's IPv4 space sits in networks where our figures are effectively a floor rather than a measurement. We have not established why: cellular networks generally deploy carrier-grade NAT that discards unsolicited inbound traffic, and we separately observe carrier-side captive-portal responses from these networks, either of which could stop a probe reaching the filtering path. The two approaches are complementary rather than competing, and neither describes Iran alone.
Probing is rate-limited, carries an opt-out reference on the source hosts, and honours every opt-out request received. The address space we probe in Iran is derived from a five-source consensus rather than a single geolocation provider, to avoid probing addresses that are not in fact in Iran.
Research support
Supported by The Open Technology Fund.
