Friday | 9 January, 2009
CIO
China Makes Viruses for Cyberwar First-Strike
Even though the report's short section on information warfare is necessarily vague, it's a good window into what the US government is seeing from China
Gregg Keizer (Computerworld (US)) 30 May, 2007 11:23:04

China's military has developed cyberwarfare first-strike capabilities that include units charged with developing viruses to attack enemy computer networks, a US Department of Defence (DoD) report has warned.

"The PLA [People's Liberation Army] has established information warfare units to develop viruses to attack enemy computer systems and networks, and tactics and measures to protect friendly computer systems and networks," the Pentagon's annual report to Congress on China's military power said. "In 2005, the PLA began to incorporate offensive CNO [computer network operations] into its exercises, primarily in first strikes against enemy networks."

The Chinese were a lot more concerned about our viruses because they were using off-the-shelf [Western] software . . . Now there's no mention of that, and much more of the discussion is about first-strike capabilities
Andrew Macpherson — University of New Hampshire

This newest report shows how the Chinese military's thinking on information warfare has changed in recent years, said Andrew Macpherson, director of the technical analysis group at the US University of New Hampshire's Justiceworks and a research assistant professor of Justice Studies. Macpherson, a cybercrime and cyberwar researcher whose group debuted a Cyber Threat Calculator in January at a US DoD cybercrime conference, noted that as recently as two years ago, other editions of the report stressed China's investments in defensive measures.

"The Chinese were a lot more concerned about our viruses because they were using off-the-shelf [Western] software," Macpherson said. "Now there's no mention of that, and much more of the discussion is about first-strike capabilities."

Even though the report's short section on information warfare is necessarily vague, "it's a good window into what our government is seeing from China", Macpherson said. "It's the highest level of unclassified American thought on China's capabilities and how they would use them. These annual reports are helpful [because] they show how China continues to develop its information warfare strategy."

And that development, Macpherson said, includes thinking about using viruses and other cyberwarfare tactics in a first strike. "A lot of [the PLA's] weapons systems are first-strike capable, to give them an advantage in any conflict. They're actively thinking about it. They know they will never catch up [to US military technology], so they need these leapfrog technologies," such as an integrated information warfare capability, he added.

Using cyberwarfare in a first strike, however, is another matter, and as in other military-political decisions, rests on whether China's leaders believed that they had an answer to some sort of political question. Most analysts have pointed to Taiwan, the island nation that the People's Republic of China (PRC) views as a rogue province, as the location of any possible first strike by the PLA, cyberwarfare or otherwise. "Taiwan is their primary national security issue," Macpherson noted.

The DoD report put it into perspective. "A limited military campaign could include computer network attacks against Taiwan's political, military, and economic infrastructure to undermine the Taiwan population's confidence in its leadership."

China's work with viruses dates back at least to the late 1990s, when a PLA exercise featured both network attacks and virus-killing software, said Timothy Thomas, of the Foreign Military Studies Office at Fort Leavenworth, in a paper written in 2000. In that paper, Thomas also spelled out how the information revolution had given new life to Mao Zedong's 70-year-old theories of a people's war.

"China clearly has the people to conduct 'take home battle', a reference to battle conducted with laptops at home that allow thousands of citizens to hack foreign computer systems when needed," Thomas said. He pointed to a 1999 "network battle" fought between Chinese and American hackers after the US bombed the Chinese embassy in Belgrade as an example. After the back-and-forth of site defacings and distributed denial-of-service (DDoS) attacks, the PLA's official newspaper, the Liberation Army Daily, called for training a large number of "network fighters" and using civilian computer hackers to take part in any future information war.

If the circumstances were right, Macpherson said, China might strike, viruses and all. "Maybe they would be willing to unplug from the Internet if they saw the advantage to their side was great" by attacking the Web as a whole, he said.

But although Macpherson noted that China's strategy relies on "how the inferior can challenge the superior", the Communist country needn't strike first to have an impact. "Long-term attacks can work too," he said. "They can get access to intellectual property, and publish it. Or taint data so that [one] couldn't be sure that backups were reliable."

The PRC's Foreign Ministry blasted the DoD report, but the spokeswoman did not mention cyberwarfare specifically. The US said Jiang Yu in a statement posted to the Ministry of Foreign Affairs' Web site, "continues to spread myth of the 'China Threat' by exaggerating China's military strength and expenses out of ulterior motives.

"As a peace-loving country, China steadfastly follows a road of peaceful development, adopting a national defence policy that is defensive in nature," she added.

Jiang also reiterated China's policy on Taiwan. "We will never tolerate the 'Taiwan Independence' or any attempt by anyone to separate Taiwan from China by whatever means," Jiang said and called on the US to stop arms sales to Taiwan and end military ties with the island.

Featured Whitepaper Sponsors
Market Place
 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
  • +

    CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00

    Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00

    Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05

    Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    TJX Maxx hacker banged up for 30 years 09 January, 2009 11:26:00

    Key figure in the infamous TJX Maxx Wi-Fi hack of 2005 has been sentenced to 30-years in prison by a Turkish court.
    Maksym Yastremskiy, the Ukrainian accused of being a key figure in the infamous TJX Maxx Wi-Fi hack of 2005, has been sentenced to 30-years in prison by a Turkish court.
  • +

    Data breaches rose sharply in 2008, says study 08 January, 2009 08:27:00

    More than 35 million data records were breached in 2008, according to the Identity Theft Resource Center.
    More than 35 million data records were breached in 2008 in the U.S., a figure that underscores continuing difficulties in securing information, according to the Identity Theft Resource Center (ITRC).
  • +

    Rogue SSL certificate exploit puts VeriSign on the spot 07 January, 2009 11:04:00

    Wishes "white hat" researchers had notified VeriSign before public demo.
    Following the success of researchers last week in creating a false SSL certificate based on VeriSign's RapidSSL brand, the company is scrambling to explain how it happened, how it's preventing it from reoccurring, and whether its other SSL certificate-generation services are at risk.
  • +

    With Gaza conflict, cyberattacks come too 05 January, 2009 08:03:00

    Pro-Palestinian hackers have defaced thousands of sites following attacks in Gaza.
    The conflict raging in Gaza between Israel and Palestine has spilled over to the Internet.
  • +

    5 ways to secure your Blackberry 18 December, 2008 12:58:00

    What do Tom Cruise and the McCain campaign have in common? They have both been bitten by the loss of a Blackberry. Mobile expert Dan Hoffman gives advice on how to keep your cherished mobile device safe, even if it's out of your hands
    What do Tom Cruise and the McCain campaign have in common? They have both been bitten by the loss of a Blackberry. Mobile expert Dan Hoffman gives advice on how to keep your cherished mobile device safe, even if it's out of your hands.
CIO Webcast Innovation #8 - What are the biggest roadblocks to IT's involvement in innovation at your company?
Watch the latest latest edition of CIO Innovation which is now available for download.
Watch the webcast
Sign up to the CIO Innovation update email


CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper

Best Practice in Building an Integrated Information Management Strategy

Discover the business value that creating an integrated information platform can bring. Learn how to provide consistent, accurate information to all stakeholders within your business network. Integrate vital data from disparate sources and deliver a trusted information foundation. Read on to uncover the stepping-stones to your new information management strategy.