An Analysis of China's "Great Cannon"
Bill Marczak, Nicholas C. Weaver, Jakub Dalek, Roya Ensafi, David A. Fifield, Sarah Lindley McKune, Arn Rey, John Scott-Railton, Ronald J. Deibert, Vern Paxson · 2015
On March 16th, 2015, the Chinese censorship apparatus em-ployed a new tool, the “Great Cannon”, to engineer a denial-of-service attack on GreatFire.org, an organization dedicated to resisting China’s censorship. We present a technical analy-sis of the attack and what it reveals about the Great Cannon’s working, underscoring that in essence it consitutes a selective nation-state Man-in-the-Middle attack tool. Although sharing some code similarities and network locations with the Great Firewall, the Great Cannon is a distinct tool, designed to com-promise foreign visitors to Chinese sites. We identify the Great Cannon’s operational behavior, localize it in the network topol-ogy, verify its distinctive side-channel, and attribute the system as likely operated by the Chinese government. We also discuss the substantial policy implications raised by its use, including the potential imposition on any user whose browser might visit (even inadvertently) a Chinese web site. 1