Skip to content
Net Surveil

Methodology

How we collect signals and turn them into connectivity and censorship scores.

Net Surveil is an observatory, not a courtroom. Two independent scores summarize different questions. Prefer reading labels as signals consistent with disruption or filtering, then open the country pulse before treating a claim as decisive.

Dual scores

  • Connectivity (0–100%)

    Can people actually reach the internet? Higher is healthier. User-plane signals are primary. This score alone sets disruption level and can open connectivity incidents when evidence is strong enough.

  • Censorship (0–100%)

    How blocked or filtered is the network? 0% = none, 100% = full. Levels rise with the score: low, elevated, high, severe. Score-only — chronic blocking does not flood the incident ledger.

What we measure

  • Connectivity — traffic and quality

    Cloudflare netflow, IQI, and speed; M-Lab NDT; ArvanCloud (IR); probe loss, latency, jitter, foreign speed, DNS reachability.

  • Connectivity — reachability

    IODA ping and darknet telescope falling below diurnal-adjusted baselines.

  • Connectivity — routing (secondary)

    RIPE BGP v4, IODA BGP, RIS Live withdrawals, nationwide outage flags. Routing-only anomalies cannot open major/blackout incidents alone.

  • Censorship — blocking and filtering

    OONI IM and circumvention blockage; Censored Planet unexpected rates; probe DNS poisoning and SNI blocking; Tor censorship events; government-directed outage flags.

  • Advisory

    RIPE BGP v6 is collected for inspection but not scored (uneven IPv6 deployment).

How collection works

A separate Tracker service polls providers on a fixed interval (default about 15 minutes), stores time series, and scores countries. Volunteer probes register once and submit encrypted pulses. This website reads Tracker website_* views via DATABASE_URL (website_readonly). Partners use the Tracker HTTP API — this site does not scrape providers or handle probe crypto.

Ranking

Comparative ranks come from monthly website_country_ranks rows. Browse the ranking board.

  • Trailing 12 months (default)

    Average each country’s monthly connectivity and censorship means over the last 12 calendar months, then RANK. MoM/YoY compare shifted 12-month windows (not a single calendar month).

  • Latest month

    Tracker-authored calendar-month cohort with stored MoM/YoY deltas (previous month / same month a year earlier).

  • Polarity

    Rank 1 = worst connectivity (lowest mean) or highest censorship (highest mean). Rank delta positive = improved. Connectivity mean up = healthier; censorship mean up = more censorship.

  • Disruption days

    On usable connectivity observation days only: disrupted days are scores < 65; blackout days are scores < 30. Trailing boards sum these across the window.

Anomaly detection

Continuous healthier-is-higher series use MAD modified Z-scores against rolling baselines (soft Z > 2.5 with ≥5% drop; hard Z > 3.5 with ≥15% drop), plus absolute floors where configured. High-frequency sources use ~24h history; slower feeds look back farther. Cloudflare netflow, IODA, and RIPE visibility subtract hour-of-week medians before MAD so routine night/weekend dips look less like outages.

Blockage-style metrics (OONI, Censored Planet, probe poisoning/SNI) use absolute soft/hard thresholds instead of MAD.

Corroboration and bands

Penalties dampen single-source noise and scale with multi-source confidence. Connectivity keeps a routing secondary cap so BGP cannot dominate. Coverage and confidence appear on country views so thin telemetry is visible next to the scores.

Connectivity disruption bands (map and incidents):

When a monitored country has no usable signals in the lookback window, Tracker reports insufficient data instead of normal. That band is not a healthy reading and does not auto-clear open incidents. GeoJSON territories without a Tracker row stay unmonitored on the map (distinct from normal).

What becomes an incident

Only connectivity collapses open incidents. Major disruption and blackout require at least one primary user-plane hard signal; routing-only anomalies stay at degraded and do not open the ledger. Soft single-source degraded states stay on the country view. Likely cause labels are interpretive and never set either score. Browse the incidents ledger.

Sources

  • Traffic volume (netflow), Internet Quality Index, download speed, and outage feeds that can add countries mid-event.

  • Ping probing, darknet telescope, and BGP routing signals. Outage alerts help discover countries in disruption.

  • BGP routing visibility for IPv4 and IPv6 plus neighbour counts from RIS peers.

  • Live BGP announcement and withdrawal sampling for short-window routing stress.

  • Application measurement outcomes for instant-messaging and circumvention tool blockage.

  • Remote scanner unexpected-response rates consistent with interference or filtering.

  • Crowdsourced NDT download throughput and minimum RTT.

  • Relay, bridge, and snowflake user counts plus Tor Project censorship events.

  • Iranian ISP disruption signals when Iran is in scope.

  • Encrypted in-country pulses: packet loss, latency, jitter, DNS poisoning, SNI blocking, foreign-path download speed.

Probe privacy

Volunteer probes use Ed25519 identities and encrypted envelopes. The Tracker stores network-local HMAC pseudonyms; this site shows aggregates only. Full retention, rights, and data-handling details are in the Privacy Policy. To run a node, see Probes.