2026/05/31 by Ali Sadeghi Jahromi, Jason Jaskolka
Computer Science · #cs.NI
12 pages, 3 figures
arxiv created 2026/07/30 · arxiv updated 2026/07/31
Iran conducted two nationwide Internet shutdowns in 2026, on January 8-25 and March 1-May 26, the latter lasting 86 days. We characterize both using three complementary measurement planes: six months of daily Censys scan data, BGP analysis of RIPE RIS snapshots spanning 2019-2026, and continuous per-prefix TCP probing from five vantage points. Each plane captures a different aspect of Iranian connectivity, and interpreting any one in isolation can be misleading. Unlike the partial BGP withdrawal of 2019, the 2022 and 2026 shutdowns were enforced by forwarding-plane discard while 80-88% of Iranian prefixes remained announced, leaving control-plane monitors blind. Restoration is similarly invisible to BGP, appearing in our forwarding-plane measurements as a centrally coordinated step. Censys host counts overshoot to approximately 3.6 times their pre-shutdown baseline after both restorations, rather than returning to baseline. Active probing reveals this inflation to be an artifact: most of the 3M apparent hosts are injected UDP/5353 responses synthesized by an on-path element at Iran's international gateway. Finally, AS-path classification shows that some apparent shutdown survivors were routed through foreign upstreams and never traversed the enforcement point. Together, these results show that measuring shutdowns requires reading multiple planes against one another, as no single signal reliably distinguishes genuine connectivity from its absence.