KEY FINDINGS Key Findings Mass export of China’s ‘Great Firewall’ model This report makes it clear how Geedge Networks is selling Great Firewall (GFW) capabilities to the governments of Kazakhstan, Ethiopia, Pakistan, and Myanmar — as well as to another unidentified country. Geedge Networks may present itself as a conventional cybersecurity firm providing standard network management hardware and software solutions comparable to other commercially available systems. In reality, Geedge Networks’ offerings enable comprehensive surveillance and censorship capabilities. These systems empower client governments to conduct both broad-scale population monitoring and internet shutdowns, while simultaneously enabling granular surveillance of internet users and targeted blocking and censorship. These products are explicitly marketed to authoritarian governments with a disregard for the privacy and security of citizens’ personal data. Regionalizing the Great Firewall within China In addition to working with international government clients, this research also provides evidence of the emergence of a provincial firewall model in China that is supplementing the National Great Firewall. Geedge Networks is working with several regional governments in China to build provincial firewalls, with censorship rules that may differ from region to region. InterSecLab has identified regional Chinese provincial firewall projects in Xinjiang, Fujian, and Jiangsu. Commoditization of Surveillance Capabilities The suite of products offered by Geedge Networks allow a client government unprecedented access to internet user data and enables governments to use this data to police national and regional networks. These capabilities include deep packet inspection for advanced classification, interception, and manipulation of application and user traffic; monitoring the geographic location of mobile subscribers in real time; analyzing aggregated network traffic in specific areas, such as during a protest or event; flagging unusual traffic patterns as suspicious; creating tailored blocking rules to obstruct access to a website or application (such as a VPN (Virtual Private Network) or circumvention tool); throttling traffic to specific services; identifying individual internet users for accessing websites or using circumvention tools or VPNs; assigning individual internet users reputation scores based on their online activities; and infecting users with malware through in-path injection. Identifying VPNs and Circumvention Tools Through the Geedge Networks suite, government clients are able to detect the use of many different VPNs and other circumvention tools such as Tor and Psiphon. The documents reviewed by InterSecLab show that Geedge Networks’ government clients are able to look back at an internet user’s past activities to see if they have visited a website that is later ...

Select target paragraph3