Inside China

You are here: silicon.com > Research > Special Reports > Inside China

Inside China

Cracked: The Great Firewall of China

Cambridge computer experts decode censorship system...

By Tom Espiner

Published: 4 July 2006 08:55 GMT

Computer experts from the University of Cambridge claim not only to have breached the Great Firewall of China but to have found a way to use the firewall to launch denial of service attacks against specific IP addresses in the country.

The firewall, which uses routers supplied by Cisco, works in part by inspecting web traffic for certain keywords the Chinese government wish to censor, including political ideologies and groups it finds unacceptable.

The Cambridge research group tested the firewall by firing data packets containing the word "Falun" at it, a reference to the banned Falun Gong religious group. The researchers found it was possible to circumvent the Chinese intrusion detection systems (IDS) by ignoring the forged TCP resets injected by the Chinese routers, which would normally force the endpoints to abandon the connection.

Richard Clayton of the University of Cambridge computer laboratory explained: "The machines in China allow data packets in and out but send a burst of resets to shut connections if they spot particular keywords. If you drop all the reset packets at both ends of the connection, which is relatively trivial to do, the web page is transferred just fine."

Clayton added this means the Chinese firewall can be used to launch denial of service attacks against specific IP addresses within China, including those of the Chinese government itself.

The IDS uses a stateless server, which examines each data packet both going in and out of the firewall individually, unrelated to any previous request. By forging the source address of a packet containing a "sensitive" keyword, people could trigger the firewall to block access between source and destination addresses for up to an hour at a time.

If an attacker had identified the machines used by regional government offices, they could block access to Windows Update, or prevent Chinese embassies abroad from accessing specific Chinese web content.

Clayton said: "Due to the design of the firewall, a single packet addressed from a high party official could block their web access."

Even though this technique would only block communication between two particular points on the internet, the researchers calculated that a lone attacker using a single dial-up connection could still generate a "reasonably effective" denial of service attack. If an attacker generated 100 triggering packets per second, and each packet caused 20 minutes of disruption, 120,000 pairs of endpoints could be prevented from communicating at any one time.

Clayton, speaking at the Sixth Workshop on Privacy Enhancing Technologies in Cambridge last week, said the researchers had reported their findings to the Chinese Computer Emergency Response Team.

Tom Espiner writes for ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure
Inside China News

Huawei's $1bn R&D pot 'matches Western rivals'
News analysis: It's Huawei or the highway...

One billion PCs worldwide by end of 2008
Fuelled by China and other emerging markets, says Forrester

India gets offshore cyber crime watchdog
Eye on data breaches...

IBM bags world's top outsourcing spot
But the Indian companies are catching up fast...

Sony BMG does mobile downloads deal in China
Chasing 300 million+ subscribers...

Inside China Extra

Stories from around the web...

Yahoo-eBay war rages in China Red Herring

Godfather of information industry China Daily

China can produce 400 million mobile phones a year Xinhua via People's Daily Online

US: China failing to fight piracy BusinessWeek Online

RELATED RESEARCH

silicon.com and the Bathwick Group have created an opportunity for business and IT executives to share their experience with each other and thus enhance their knowledge of the IT marketplace.

Join our research panel, and you'll be asked to participate in short surveys - and then will be privy to the answers of all your colleagues, as we send you tailored versions of the results.

Extras include complementary passes to silicon.com events and survey prizes such as iPods. Plus, there are the obvious networking opportunities with your fellow panellists.

For more about the Research Panel and how to join, click here



Quick Sitemap Links: