How the system used by the FSB to monitor Russians online works. Belarusian security forces might use similar tools
What can the FSB find out when someone accesses Telegram, turns on a VPN, or opens a specific website? Internal documents from the developers of the Russian system for technical means of operational-investigative activities reveal its capabilities. Belarusian security forces likely use similar tools.

The publication "Vazhnye Istorii" (Important Stories) has studied technical documentation, fragments of source code, service logs, records of intercepted traffic, screenshots, and videos of the Russian system of technical means for ensuring the functions of operational-investigative activities, more commonly known as SORM.
The materials are dated 2021-2024.
The documents do not describe absolutely all variants of SORM equipment but allow us to understand how the internet traffic analysis system works.
SORM receives a copy of all traffic
SORM equipment is located within the operator's network and receives a full copy of its users' traffic. The system attempts to link it to a specific subscriber: in a mobile network — via phone number and subscriber ID, in a wired network — via the provider's login.
Therefore, SORM associates actions via home Wi-Fi with the person who signed the internet contract.
Next, the system analyzes the traffic and determines what the user did: visited a website, sent a file, used email, a messenger, or another service.
The system recognizes different types of traffic by characteristic features, server names, and statistical connection peculiarities.
If information was not selected for immediate transmission to the FSB console, it does not mean it disappears. Connection statistics and message content that the system managed to obtain are stored in a data repository called "Yanvar" (January).

Depending on the type of information, it can be stored there for six months to three years. During this time, security forces can technically access the accumulated traffic. How often and to what extent they do this is not known from the studied documents.
What the FSB can see
The system's capabilities have a significant limitation: most modern internet traffic is encrypted. According to the studied documentation, SORM developers did not aim to decrypt this encryption.
Therefore, the text of messages, the content of conversations, and transferred files in modern encrypted services remain inaccessible to the system.
But encryption does not hide all data. SORM can collect metadata — information about the fact and characteristics of the connection itself. For example, the system can determine when a person went online, which sites they visited, how much data they transferred, when a messenger call started and ended, and how long it lasted.
Such data already allows a lot to be learned about a person's behavior. And by comparing the start and end times of calls from different users, it is theoretically possible to find out who spoke with whom. However, it is unknown from the documents whether the FSB conducts such analysis in practice.
The FSB can filter the necessary traffic from the general stream by IP address, phone number, email, or domain.

Screenshot from a training video on using control panels. The dropdown list shows the criteria by which data can be filtered. Photo: istories.media
Technically, SORM allows searching even by specific words. But, according to a source from "Vazhnye Istorii," this was rarely used in practice: such a search requires many resources, and there is little unencrypted traffic now.
To obtain more information from intercepted traffic, SORM developers use decoders — separate software modules for specific services and applications. They do not decrypt traffic but allow the service to be recognized and more detailed metadata to be collected.
Such decoders exist for many messengers, traffic anonymization tools, and some cryptocurrencies.
If there is no decoder for a particular service, information is still collected. But some data may be lost, and the traffic itself is marked as unrecognized.
Here's how SORM recognizes some popular services
Telegram, WhatsApp, IMO, Zoom, Viber, WeChat, and Discord. SORM has decoders for these, and the system can determine that a person is using these services and collect call metadata. But SORM does not see who the person is talking to or what they are talking about.
Signal. There is no separate decoder for it in the studied documentation. Moreover, SORM probably cannot always reliably determine even the fact of Signal usage: its traffic looks like a regular encrypted connection.
Google. The system sees that the user accessed google.com but does not see the search query itself or Google's response. There are no separate decoders for Google Meet and Google Drive in the documentation either. Therefore, SORM cannot hear a conversation in Google Meet or read a file uploaded to Google Drive, although it can distinguish a video call from a file transfer by the nature of the traffic.
ICQ, "Mail.ru Agent," and Jabber. These older unencrypted services are much more transparent for SORM: the system can even obtain the content of messages.
OpenVPN and PPTP. SORM can recognize these VPN protocols.
WireGuard and VLESS. They are not mentioned in the studied documentation. VLESS masquerades as ordinary HTTPS traffic, so for SORM, it probably looks like a regular encrypted web connection. Whether the system can recognize WireGuard is unclear from the documents.

Thus, SORM is not a system that automatically "reads everything." The encryption of modern services significantly limits its capabilities. But even without access to the content of correspondence, it allows linking internet activity to a specific subscriber, seeing website visits and the use of a number of services, collecting metadata, and filtering traffic according to criteria set by the FSB.
At the same time, this only refers to SORM's capabilities. The lack of access to encrypted correspondence through this system does not mean that Russian security forces cannot obtain it by other means.
Comments