China has reportedly upgraded its website blocking system, called the Great Firewall by experts, to be able to launch attacks on foreign businesses and organizations on the internet through any browser.
Researchers from the University of Toronto, the International Computer Science Institute, the University of California, Berkeley, and Princeton University have confirmed suspicions of many security researchers: China is holding web traffic hostage across the country and thwarting websites that criticize the authoritarian regime.
Typically, connections to Chinese web servers pass through the state's border routers, which can and do inject malicious JavaScript code into the web pages being loaded. This malicious code causes victims' browsers to silently send multiple requests (DDoS) to selected targets.
So websites that interest the world end up not working, as they receive a classic Denial of Service attack. In this way, the Chinese government ensures that no one in the world can access them.
One such attack began last month on the California-based GitHub.com service, which hosts two projects that bypass the censorship mechanisms of China's Great Firewall.
This aggressive firewall has been dubbed Great Cannon by researchers, and it typically works by hijacking requests from China's Baidu ad network. Anyone visiting a website that serves Baidu ads could end up unwittingly bombarding a foreign site that Chinese authorities don't like.
“In the attack on GitHub and GreatFire.org, Great Cannon intercepted traffic sent to Baidu infrastructure servers commonly used for analytics, social, or advertising scripts,” the university researchers said in a blog post.
Researchers point out that the Great Cannon and the Great Firewall are structured in a very similar way, theRegister reports. They are similar in how they receive traffic from the internet, how requests come in and out of the country, and how they are analyzed before any republishing or redirecting of the traffic.

Diagram explaining how the Great Cannon works. Credit: CitizenLab.org
(Click to enlarge)
Unlike the Great Firewall, however, the Great Cannon operates with a much narrower focus, monitoring traffic only to a few specific locations (webpages) before injecting malicious JavaScript code to carry out the distributed denial of service attack.
Researchers believe that the Chinese government is behind Great Cannon . They note that both Great Cannon and the Great Firewall are located in facilities operated by state-owned ISPs.
“The development of the Great Cannon is a significant change in tactics, and it has very visible consequences,” they wrote.
The researchers point out that Great Cannon actually bears a striking resemblance to another web-injection platform – the NSA and GCHQ QUANTUM tool that has been used in the past to attack Telco and other websites.
