海角大神

Exposing China's cyber espionage campaign hasn't lessened scope, US says

'China has not reduced its cyber intrusions against the United States despite recent public exposure of Chinese cyber espionage in technical detail,' a commission set up by Congress to monitor US-China ties reported.

|
Carlos Barria/Reuters
The National Information Security Engineering Center, a building commissioned by the People's Liberation Army's Cyber Unit, is seen at the Zhangjiang High Technology Park, on the outskirts of Shanghai March 16, 2013. Faculty members at a top Chinese university have collaborated for years on technical research papers with a People's Liberation Army (PLA) unit accused of being at the heart of China's alleged cyber-war against Western commercial targets. Picture taken March 16, 2013.

China is 鈥渄irecting and executing a large-scale cyber espionage campaign against the United States鈥 and has succeeded in targeting networks belonging to the US government, Defense Department, and private companies, according to a new government report.

These activities are designed to reap economic and strategic benefits, including providing Chinese firms with an advantage over competitors around the world, advancing research and development goals, and obtaining information for future military operations, according to the US-China Economic and Security Review Commission鈥檚 2013 report, which was released late Wednesday.

鈥淐hina has not reduced its cyber intrusions against the United States despite recent public exposure of Chinese cyber espionage in technical detail,鈥 concluded the Security Review Commission, which was set up by Congress to report annually on the relationship between the two countries. 鈥淭his suggests Beijing has decided to continue its cyber campaign against the United States.鈥

Such findings are not a huge surprise to cyber experts or anyone else watching the drumbeat of cyber security company reports over the past two years implicating Chinese hackers with the wholesale theft of intellectual property from US corporations 鈥 their 鈥渃rown jewels.鈥

One of the most damning of those reports cited by the commission was a study released in February by Mandiant, a US-based cyber security company. It laid bare a wholesale multi-year cyber economic espionage campaign that it carefully linked back to an address in Beijing 鈥 a 12-story building occupied by an intelligence unit of the the People鈥檚 Liberation Army (PLA). Since 2006, the PLA鈥檚 Unit 61398 had penetrated networks of 141 organizations, including US companies, foreign governments, and others, Mandiant reported.

Eighty percent of the organizations infiltrated were located in the US or had their headquarters in the US. While cyber espionage declined for about a month from the Beijing-based groups that Mandiant was watching, it soon rebounded using different cyber techniques and malicious software.

In April, Verizon鈥檚 cyber security team reported that in 621 cases of 鈥樷榗onfirmed data disclosure鈥 in 2012, at least 19 percent of the intrusions were espionage carried out by 鈥樷榮tate-affiliated actors.鈥欌 Among that latter group, 96 percent were linked back to China, it found.

鈥淭he public exposure of Chinese cyber espionage in 2013 has apparently not changed China鈥檚 attitude about the use of cyber espionage to steal intellectual property and proprietary information,鈥 said Dennis Shea, vice chairman of the commission in his prepared remarks unveiling the report. 鈥淢itigating the problem will require a long-term and multifaceted approach.鈥

Recommendations by the commission to deal with the problem and moderate China鈥檚 economic cyber espionage include:

鈥 New legislation to clarify what actions US companies are allowed to take to track intellectual property stolen through cyber intrusions

鈥 Amending the Economic Espionage Act to permit 鈥渁 private right of action鈥 when trade secrets are stolen 鈥 including getting the information back, or even possibly taking action to damage a cyber spy鈥檚 computer systems

鈥 Urging the White House to expedite measures that would enable the Department of Defense to more effectively limit risks associated with certain Chinese-made equipment that enter the Defense supply chain.

Other steps that could have an impact in changing China鈥檚 spying could include linking Chinese economic cyber espionage to trade restrictions; preventing Chinese firms that use stolen US intellectual property from accessing the US banking system; and creating a list of banned entities whose members would not be allowed to travel to the US.

鈥淚f I were the Chinese I wouldn鈥檛 worry about Congress doing anything about this report, which is unfortunate because congressional action is one of the best levers we have,鈥 says James Lewis, a cyber security expert with the Center for Strategic and International Studies in Washington. 鈥淓ven small symbolic actions can be influential with the Chinese. Putting names on a treasury or travel list really can have an effect. If you put Unit 61398 on a no-travel or other list, that would get global attention and make the Chinese unhappy.鈥

So far, however, US steps to get the Chinese to back off have been undermined by recent revelations of National Security Agency spying. In April 2013, US Secretary of State John Kerry announced that the US and Chinese governments would establish a working group to discuss cyber security. But progress in the talks has been stalled by the leaks of NSA documents by Edward Snowden, the former NSA contractor, experts say.

Since June the leaks have overshadowed those talks and China鈥檚 interest in cyber accommodation has appeared to cool, experts say.

Lewis says the chilly cyber relations are a significant bad sign. Some reports have put US economic losses of intellectual property as high as $300 billion so far.

鈥淲hat leapt out of this report is that the cyber dialog has been put on hold by the Snowden revelations,鈥 he said. 鈥淭his is really a major issue for the US. Let鈥檚 not forget this is a big problem. We had the secretary of the Treasury travelling to China last week 鈥 and he didn鈥檛 raise cyber at all. That sends a signal.鈥

You've read  of  free articles. Subscribe to continue.
Real news can be honest, hopeful, credible, constructive.
海角大神 was founded in 1908 to lift the standard of journalism and uplift humanity. We aim to 鈥渟peak the truth in love.鈥 Our goal is not to tell you what to think, but to give you the essential knowledge and understanding to come to your own intelligent conclusions. Join us in this mission by subscribing.
QR Code to Exposing China's cyber espionage campaign hasn't lessened scope, US says
Read this article in
/World/Security-Watch/2013/1121/Exposing-China-s-cyber-espionage-campaign-hasn-t-lessened-scope-US-says
QR Code to Subscription page
Start your subscription today
/subscribe