A Technical Analysis of the 'Green Dam-Youth Escort' Software
协作组编写 A collaborative work
2009年6月 June, 2009
关于 About
绿坝-花季护航是金惠堵截黄色图像和不良信息专家系统的市场产品名。Green Dam is the informal name given tothe expert system from Jinhui Technologies which blocks pornographicimages and other harmful information.
1)国家公安部信息安全专用产品销售许可证(XKC30492)National Ministry of Public Safety Information Security Product Sales License No. XKC30492
2)国家发展和改革委员会批准(发改高技[2004]2040号)列入“重大软件产业化专项”,是全国同类过滤产品唯一批准项目 NationalDevelopment and Reform Commission Approval (NDRC Circular[2004]#2040)as "Major Software Industrialization Project", the only approvedfiltering software project of its kind nationwide
3)国家科技部(国科发技字[2004]449号)批准为“技术创新基金项目” Ministry of Science andTechnology (MOST Circular[2004]#449) Approval for "technologicalinnovation project funding"
4)国家信息产业部(信部运[2005]9号)批准为“电子信息产业发展基金项目” Ministry of Industry andInformation Technology (MIIT Circular[2005]#9) Approval for "electronicinformation industry development project funding"
国家互联网违法和不良信息举报中心(net.china.cn)唯一正式推荐 Only the China Internet IllegalInformation Reporting Center (ciirc.china.cn) has officiallyrecommended Green Dam.
第九届中国国际软件博览会荣获金奖 Awarded first prize at the Ninth Chinese International Software Expo
2005中国郑州先进适用技术交易会金奖 First prize at the 2005 Zhengzhou Advanced Adaptive Technology Trade Fair
郑州市科技进步一等奖 First prize in technological advancement from Zhengzhou City
金惠公司营销服务中心电话:0371-63697160,63697161 Jinhui Marketing Service Center: 0371-63697160
传真:0371-63697171 Fax: 0371-63697171
目的和功能 Objectives and functions
以工信部,教育部,财政部和国务院新闻办为合作伙伴,绿坝目前有家庭版,厂商版,渠道版,网吧版以及校园版(家庭版与校园版经校验后发现完全一致,没有发现有官员版)。With the Ministry of Industry and Information Technology,Ministry of Education, Ministry of Finance and State CouncilInformation Department as its partners, Greed Dam currently offersFamily, Commercial, Organization, Internet Bar and Campus Editions.
公开宣称的功能: 针对10-16岁青少年,过滤色情图片、色情内容、暴力内容
潜在功能:过滤政治内容? 过滤反审查软件(例如无界)?
Stated features: To protect minors from age 10-16 through the filtering of pornographic and violent images and content.
Latent features: To filter political content? To filter circumvention software (such as Wujie)?
还有一个绿坝网络版,在 [<a target=_blank href="http://www.zzjinhui.com/down/newServerCard.rar" target="_blank">http://www.zzjinhui.com/down/newServerCard.rar[</a> 可以下载。
There also exists a Network Edition of Green Dam, which can be downloaded here (.rar).
适用性 Applicability
虽然产品声明的目标是针对10-16岁青少年,但是产品的约定安装机器并没有选择性,产品缺省假设每台被安装的机器都是青少年使用。目前该产品只提供Windows 版本,对IE、Google Chrome(因为采用了系统的网络设置)有效,对Firefox无效。软件屏蔽的不良信息包括时政类的不良信息,软件并非采用一般软件的安装方式,对Firefox无效,关闭浏览器及将网址加入黑名单无确认。在IE下,对明显属于时政类“不良信息”的信息判断不稳定。对色情类“不良信息”的网页判断较准。换成Firefox后,软件没反应。
Current versions only support Windows; effective only when used inconjunction with Internet Explorer or Google Chrome, it has no effectwhen used with Firefox. The harmful information screened by thesoftware includes politically-related harmful information, and thesoftware relies on non-conventional methods to install, alsoineffective within Firefox, closing the browser and adding the websiteaddress onto a banned list without confirmation. In Internet Explorer,the software's ability to classify clearly political content as"harmful information" is unreliable; for pornographic content, GreenDam is able to make relatively accurate assessments. When used withFirefox, however, the software shows no response.
产品当前支持的兼容性列表
Compatibility list of currently supported projects
序号 项目 内容 备注 Sequence / Item / Content/ Notes
操作系统 Operation Systems
1 Win98 兼容 不支持屏幕文字监控 1. Windows 98, compatible, text screening not supported
2 Win2000 兼容 2. Windows 2000, compatible
3 Winxp 兼容 3. Windows XP, compatible
4 Win vista 兼容 安装升级和卸载需管理员身份 4. Windows Vista, compatible, updates anduninstall can only be performed through User Account Control.
浏览器 Browsers
1 IE6.0/7.0 兼容 1. Internet Explorer 6.0/70, compatible
2 Opera 9.5 兼容 2. Opera 9.5, compatible
3 Firefox 2.0 兼容 3. Firefox 2.0, compatible
4 Netscape 9.0 兼容 4. Netscape 9.0, compatible
5 腾讯TT 3.0 兼容 5. Tencent Traveler 3.0, compatible
6 Maxthon 2.0 兼容 6. Maxthon 2.0, compatible
办公软件 Office Software
1 MS Office2003 兼容 1. Microsoft Office 2003, compatible
2 金山WPS 2007 兼容 2. Kingsoft WPS 2007, compatible
3 永中Office2007 兼容 Evermore Office 2007, compatible
杀毒软件 Anti-virus Software
1 卡巴斯基6/7 兼容 1. Kaspersky 6/7, compatible
2 瑞星19 兼容 2. Rising 19, compatible
3 江民2008 兼容 3. Jiangmin 2008, compatible
4 诺顿2008 兼容 4. Norton 2008, compatible
5 McAfee2008 兼容 5. McAfee 2008, compatible
技术架构分析 Technical Framework Analysis
绿坝-花季护航”所有的文件都安装在系统目录(windows/system32)下,程序菜单没有提供卸载入口,后发现卸载功能在主程序的一个菜单里。在启用“绿坝-花季护航”的图片过滤功能时,软件自动清除的浏览器缓存。All files within "Green Dam-YouthEscort" are installed to the system directory (windows/system32), andwhile no means to uninstall are provided in the Applications menu, theoption to uninstall can be found in a menu within the main program.When launching Green Dam's image filtering function, the softwareautomatically clears the browser cache.
在windows目录下的xstring.s2g存放着该软件所有文件的安装路径。Within xstring.s2g, located inthe Windows directory, there can be found all the installation pathsfor all the program's files.
运行时加载的模块:
驱动: C:Windows\system32\Drivers\mgtaki.sys
服务: C:Windows\MPSvcC.exe
启动项: C:Windows\system32\xnet2.exe
During operation, Green Dam installs the following modules:
Drivers: C:Windows\system32\Drivers\mgtaki.sys
Service: C:Windows\MPSvcC.exe
Launch: C:Windows\system32\xnet2.exe
绿坝将密码用MD5算法转换后,以文本方式保存在C:\WINDOWS\system32目录下的kwpwf.dll文件中。以记事本打开该文件,以“D0970714757783E6CF17B26FB8E2298F”替换其内容后保存,即可将密码恢复为初始密码“112233”。
After Green Dam converts the password using the MD5 algorithm, it savesit in text format within the kwpwf.dll file located in theC:\WINDOWS\system32 directory. When opened using Notepad, if thecontent is then replaced with "D0970714757783E6CF17B26FB8E2298F" andsaved, the password can then be restored to the original "112233".
绿坝的一个设置文件 xnet2_lang.ini中有一行:AOption0_1117=发现不良网站自动向金惠公司报告。在system32中有个filtport.dat的文件,默认内容是FreeGate/8567/tcp Urf/9666/tcp,绿坝的过滤文件。
Within Green Dam installation file xnet2_lang.ini, one line reads:"AOption0_1117=Upon discovery of harmful information, reportautomatically to Jinhui Corporation." Located in system32 in the filefiltport.dat, the default content is "FreeGate/8567/tcp Urf/9666/tcp",suggesting that this is Green Dam's filtering file.
绿坝的通过网络自动更新,更新的网址为:[<a target=_blank href="http://www.zzjinhui.com/softpatch/" target="_blank">http://www.zzjinhui.com/softpatch/[</a> ,里面还包含一张美女图:
不知是何用意。在经过网络用户的分析后,发现 [<a target=_blank href="http://www.zzjinhui.com/softpatch/kwupdate.dat" target="_blank">http://www.zzjinhui.com/softpatch/kwupdate.dat[</a> 此文件和屏蔽关键词和URL有关。有2个相关IP:211.161.1.134和 203.171.236.231,其中第二个IP指向 河南省郑州市景安计算机网络技术有限公司。(zzidc.com.cn)
Green Dam updates automatically online, and the update address is: [<a target=_blank href="http://www.zzjinhui.com/softpatch/" target="_blank">http://www.zzjinhui.com/softpatch/[</a>;found therein is a pretty woman picture although its purpose isunknown. Following analysis by Internet users, it was discovered thatthe file [<a target=_blank href="http://www.zzjinhui.com/softpatch/kwupdate.dat" target="_blank">http://www.zzjinhui.com/softpatch/kwupdate.dat[</a>is related to the filtering of keywords and URLs. Connected to that aretwo IP addresses: 211.161.1.134 and 203.171.236.231; the second of theIP addresses belongs to Zhengzhou Giant Computer Network Technology Co.Ltd. in Henan province. (zzidc.com.cn)
使用测试和算法分析 Performance test and algorithm analysis
通过实际测试和用户反馈,发现绿坝的宣称功能的实现能力并不强,却没有避免在各个层面添加很多没有宣称的功能。部分用户的使用体验和讨论:
Through testing and user feedback, it has been noted that Green Dam'sability to achieve its stated function is in fact not that strong, andhas not avoided including many additional undisclosed functionssituated at various levels. Here is a sample of some users' userexperiences and discussion:
图像过滤 Image filtering
图像检测进程从待检图像队列中获取图像数据,先归一化图像尺寸,然后分离肤色区域和非肤色区域,在对肤色区域关系进行分析后去除干扰,提取区域的特征送入已训练SVM分类器。当图像被检为色情图像后送入人脸检测器,若人脸不是主要部分便确定为色情图像。这套算法的主要问题是,色情图像的识别严重依赖于肤色和肤色形状;而最后使用人脸检测加权判定也只是手工打补丁避免出现大幅人脸识别为色情图像问题的办法,且经验权值可靠性缺乏验证。Theprocess of image detection begins by obtaining
我在我的老红帽linux上面运行这个程序,红帽说:你当我傻帽啊?我又把这个文件发到我的手机上,结果手机给退回来了,还发了个短信给我:Plsdo not send files larger than the physical memory of thisdevice。最后,我终于找到一台windows的机器,可以运行了。嗯,以后上网,就用windows了。
安装:
Reports: China to require all PCs to have site blocking software
HONG KONG, China (CNN) -- The Chinese government will require allPCs sold in China after July 1 to include software that blocks"harmful" content, news reports said on Monday.
Farmers in China learn how to use the Internet in April 2008 in Guangdong province.
Farmers in China learn how to use the Internet in April 2008 in Guangdong province.
The rule, released on May 19, will require all computers to have "GreenDam," a software program that is designed to block pornography sites,the Wall Street Journal reported.
The software must either be preloaded on hardware or enclosed on compact disc with the computer, the report said.
Industry observers fear the software could be used to bring China's "Great Fire Wall" down to the desktop level.
"Why wouldn't we be suspicious about a government saying all computersmust be sold with this particular software from this particularcompany?" said Charles Mok, chairman of the Internet Society of HongKong.
Green Dam is produced by Jinhui Computer System Engineering Co., whichhas ties to China's military and security ministry, the report said.
Company founder Bryan Zhang told the Journal the software is similar toparental control software in other countries and will transmit bannedWeb sites to computers similar to antivirus updates. Learn more abouthow China monitors the Internet »
A spokesperson for Hewlett-Packard Co. in Singapore confirmed toBloomberg News that China has told them to include web site blockingsoftware.
Don't Miss
* China targets Web sites
* Report: Iran blocks Facebook
advertisement
Mok of the Internet Society fears the software could be used to stopuse of software such as onion routing systems that protect anonymityand circumvent router-based site blockage.