Internet censorship doesn't run on magic — it runs on boxes: deep-packet-inspection (DPI) appliances that sit on the wire, read traffic, and drop what the operator forbids. Those boxes have makers, and the makers have a fingerprint. Voidly maintains a library of 14 DPI signatures — drawn from a decade of Citizen Lab and academic research — and matches them against its measurement corpus. 16.8% of evidence rows (about 30,000) carry a recognizable DPI signature. The picture that emerges has two halves.

Half the censorship is home-grown

The most-matched signatures are state-built DPI — systems governments designed and deployed themselves:

These regimes don't buy their censorship off a shelf; they build and tune it (Iran and China rotate their keyword and SNI lists daily). The fingerprints trace to peer-reviewed measurement work — Xue et al. (IMC 2022) on TSPU, Ensafi/Wang on the GFW, Aryan et al. (FOCI 2013) on Iran.

The other half ships from the West

The library also catalogs seven commercial DPI appliances — gear sold by Western and allied vendors and documented by Citizen Lab in authoritarian markets: Fortinet (FortiGate), Cisco (Ironport Web Security), Palo Alto Networks, McAfee (Smartfilter), Blue Coat / Symantec ProxySG, Netsweeper, and Sangfor. Citizen Lab has placed these boxes across the Gulf (UAE, Saudi Arabia, Bahrain, Qatar, Kuwait), South and Southeast Asia (Pakistan, India, Myanmar, Indonesia, Vietnam), and beyond — Blue Coat famously turned up in Syria, Netsweeper across the Gulf, FortiGate in a dozen countries.

In Voidly's own measurements, two of those commercial signatures surface at scale: FortiGate (519 matches) — the most-detected commercial appliance, consistent with its wide deployment — and Blue Coat (30). The others are catalogued from public research but rarely match Voidly's current evidence, which is the honest state of the art: the commercial supply chain is well-documented historically, but day-to-day blocking data is dominated by the state systems.

The honest caveats (read these)

Fingerprinting censorship hardware is inference, not a serial number. This is heuristic matching, not ML, so false positives are possible. Public fingerprints lag vendor updates — FortiGate redesigned its blockpage HTML in 2023, so older evidence may still match an old template. State configs rotate. And most importantly: a measurement matching a vendor's signature does not prove that vendor performed the block — only that the observed behavior resembles that gear. Treat these as leads for investigation, not courtroom attribution.

Why it matters

Censorship has a supply chain, and a chunk of it runs through publicly-traded companies subject to export controls and shareholder pressure. Naming the gear — carefully, with caveats — is how accountability starts: you can't pressure a vendor you can't see. Voidly pairs this with its federal surveillance-spending dataset (which US contracts flow to surveillance vendors) so the buyer and the builder can be examined together. Live: GET /v1/atlas/dpi-fingerprints.