KEY FINDINGS
Key Findings
Mass export of China’s ‘Great Firewall’ model
This report makes it clear how Geedge Networks is selling Great Firewall (GFW) capabilities
to the governments of Kazakhstan, Ethiopia, Pakistan, and Myanmar — as well as to
another unidentified country. Geedge Networks may present itself as a conventional
cybersecurity firm providing standard network management hardware and software
solutions comparable to other commercially available systems. In reality, Geedge Networks’
offerings enable comprehensive surveillance and censorship capabilities. These systems
empower client governments to conduct both broad-scale population monitoring and
internet shutdowns, while simultaneously enabling granular surveillance of internet users
and targeted blocking and censorship. These products are explicitly marketed to
authoritarian governments with a disregard for the privacy and security of citizens’ personal
data.
Regionalizing the Great Firewall within China
In addition to working with international government clients, this research also provides
evidence of the emergence of a provincial firewall model in China that is supplementing the
National Great Firewall. Geedge Networks is working with several regional governments in
China to build provincial firewalls, with censorship rules that may differ from region to
region. InterSecLab has identified regional Chinese provincial firewall projects in Xinjiang,
Fujian, and Jiangsu.
Commoditization of Surveillance Capabilities
The suite of products offered by Geedge Networks allow a client government
unprecedented access to internet user data and enables governments to use this data to
police national and regional networks. These capabilities include deep packet inspection for
advanced classification, interception, and manipulation of application and user traffic;
monitoring the geographic location of mobile subscribers in real time; analyzing aggregated
network traffic in specific areas, such as during a protest or event; flagging unusual traffic
patterns as suspicious; creating tailored blocking rules to obstruct access to a website or
application (such as a VPN (Virtual Private Network) or circumvention tool); throttling traffic
to specific services; identifying individual internet users for accessing websites or using
circumvention tools or VPNs; assigning individual internet users reputation scores based on
their online activities; and infecting users with malware through in-path injection.
Identifying VPNs and Circumvention Tools
Through the Geedge Networks suite, government clients are able to detect the use of many
different VPNs and other circumvention tools such as Tor and Psiphon. The documents
reviewed by InterSecLab show that Geedge Networks’ government clients are able to look
back at an internet user’s past activities to see if they have visited a website that is later ...