286
China
originate from the group Human Rights in China were sent to numerous other organizations that, if opened and executed, would install malware connected to a
command-and-control server located in China.
137 In a similar incident, staff at the
Committee to Protect Journalists received falsifi ed e-mail invitations to the Nobel
Peace Prize awards ceremony of Chinese dissident Liu Xiabo containing malware
designed to contact servers in Bengbu, China.
138 These reports followed 2009 ’ s Tracking
GhostNet report by the Information Warfare Monitor, which identifi ed an extensive
cyber espionage network that compromised thousands of computers, including some
at the private offi ce of the Dalai Lama and several Tibetan nongovernmental organizations (NGOs), which contacted command-and-control servers located in China.
139
Other organizations that do work in China have also reported malware infection.
Journalists and other staff of media organizations have been targeted with malware
attacks that made contact with servers in China. The Foreign Correspondents ’ Club
of China warned fellow journalists to be cautious following an e-mail-based malware
attack targeting media organizations.
140 Further investigation found a sophisticated
malware campaign that compromised users ’ computers and attempted to make contact
with servers at a university in Taiwan.
141 The increase in malware attacks targeting
foreign journalists occurred before the 60th anniversary of the founding of the People ’ s
Republic of China, a sensitive political event that saw an increase in security
precautions.
142
Cyber attacks attributed to sources in China have been identifi ed by a variety of
different states. Reports from Australia,
143 Japan,
144 Pakistan,
145 South Korea,
146 the
United Kingdom,
147 and the United States
148 all point to the rise of cyber attacks originating from China. However, attribution of these incidents remains an ongoing challenge. While many of the targets of these attacks may refl ect strategic interests for
China ’ s government, the country also represents the largest single population of
Internet users and thus the greatest potential source of cyber-attack instigators.
ONI Testing Results
In 2010, the OpenNet Initiative conducted testing on a single Chinese ISP, CNLink
Networks. The testing results confi rm that China maintains an advanced Internet
fi ltering system at the backbone level that is capable of blocking content through a
variety of methods, such as IP blocking, DNS tampering, and keyword fi ltering (TCP
resets).
Filtering in China is implemented at the backbone level through a method known
as keyword-based fi ltering, or TCP resets. This blocking method is unique to China and
works in part by inspecting the content of IP packets to determine if specifi c, sensitive
keywords are present. These keywords relate to historical events, banned groups, and
other topics considered sensitive or controversial by the Chinese government. A
Précédent

- 303/431

Suivant