{"id":5977,"date":"2024-10-28T16:31:48","date_gmt":"2024-10-28T21:31:48","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/china-cyber-corps-hone-skills-virtual-battlefields"},"modified":"2024-10-28T16:31:48","modified_gmt":"2024-10-28T21:31:48","slug":"chinas-elite-cyber-corps-hone-skills-on-virtual-battlefields","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/10\/28\/chinas-elite-cyber-corps-hone-skills-on-virtual-battlefields\/","title":{"rendered":"China&#8217;s Elite Cyber Corps Hone Skills on Virtual Battlefields"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blte0a1b976b9920590\/672003f665a90d8b1211d67e\/kb_photodesign-china-cyber-flag-shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/chinas-elite-cyber-corps-hone-skills-on-virtual-battlefields.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Over the last decade, the Chinese government has established an efficient pipeline of capture-the-flag (CTF) tournaments both as a way to attract cyber-savvy citizens to cybersecurity, and as part of its cybersecurity curriculum and training regimen.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The efforts have paid off.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Today, the nation has more than 50 annual competitions used as part of the training of tens of thousands \u2014 and possibly, hundreds of thousands \u2014 of cybersecurity specialists, while creating stronger connections to government and industry, according to a research report published by the Atlantic Council on October 18. Moreover, sector-specific contests \u2014 targeting mobile, autonomous vehicles, and smart cities, for example \u2014 help deepen the technical expertise of participants and address the specific needs of each industry.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Overall, the Chinese government has successfully marshaled the nation toward solving its cybersecurity shortages and the goal of becoming a cyber superpower, says Eugenio Benincasa, senior cyber defense researcher at the Center of Security Studies at ETH Zurich and a co-author of the report.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;China, like the West, has a scarcity of talents, and addressing that scarcity through a system that can help you to evaluate talent is definitely a better way of addressing the problem,&#8221; he says. &#8220;If you look at the entire ecosystem, there are many ways in which hacking contests can bring better allocation of resources, both in the short and also in the long term.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In 2014, Chinese President Xi Jinping called for the country to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.brookings.edu\/articles\/china-as-a-cyber-great-power-beijings-two-voices-in-telecommunications\/\" rel=\"noopener\">become a &#8220;cyber great power,&#8221;<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> aiming to strengthen its technology industry, while at the same time, embarking on a domestic effort to restrict its reliance on foreign technology. Cybersecurity has become a key element of that effort: The Chinese government has successfully created a pipeline for training future cybersecurity specialists, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/bug-bounty-programs-hacking-contests-power-chinas-cyber-offense\" rel=\"noopener\">restricted the dissemination of vulnerability information<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and established its own cybersecurity providers. These include <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/-isoon-contractor-helps-the-prc-hack-foreign-governments-companies\" rel=\"noopener\">hacking firms and cyber-range operators<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 such as Beijing Integrity Tech and Cyber Peace \u2014&nbsp;which act both as hosts for legitimate infrastructure and for some nation-state actors, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/china-unleashes-flax-typhoon-apt-live-off-land-microsoft-warns\" rel=\"noopener\">such as Flax Typhoon<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Critical Curriculum for Cybersecurity Studies\">Critical Curriculum for Cybersecurity Studies<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Hacking contests are a key component of the nation&#8217;s efforts. At least 129 unique cybersecurity events, including 54 annual contests, were identified by the report&#8217;s authors, Benincasa and Dakota Cary, a strategic advisory consultant at Sentinel One.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">China&#8217;s Ministry of Education accounts for the most competitions \u2014 a total of 22 \u2014 identified by the researchers, compared to 14 associated with the Cyberspace Administration of China, and 13 sponsored by the Ministry of Public Security, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.atlanticcouncil.org\/in-depth-research-reports\/report\/capture-the-red-flag-an-inside-look-into-chinas-hacking-contest-ecosystem\/\" rel=\"noopener\">according to the report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. About two-thirds of universities considered hacking contests to be an important part of the curriculum for cybersecurity specialists, with more than three-quarters of students (77%) participating in at least one event by the end of their sophomore year.<\/span><\/p>\n<div readability=\"10\"><img data-recalc-dims=\"1\" decoding=\"async\" data-testid=\"content-image\" data-component=\"image\" class=\"ContentImage-Image ContentImage-Image_align_left\" data-src=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/chinas-elite-cyber-corps-hone-skills-on-virtual-battlefields-1.jpg\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/chinas-elite-cyber-corps-hone-skills-on-virtual-battlefields-1.jpg?w=640&#038;ssl=1\" loading=\"lazy\" alt=\"Chart showing growth in number of competitions\" title=\"Chart showing growth in number of competitions\"><\/p>\n<p class=\"ContentImage-Link\">Since the early 2010s, China&#8217;s CTF competitions have taken off. Source: &#8220;Capture the (red) flag&#8221; report, Atlantic Council<\/p>\n<\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Among other benefits, the competitions allow the Chinese government to gain important information on new strategies and techniques, as well as collecting exploit techniques used by participants, which the government mandated since 2018. Hacking contests can also attract younger participants, such as high schoolers, into the field of cybersecurity, and help professionals keep up their skills.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Compared to China&#8217;s comprehensive approach, Western nations continue to fall short, Benincasa says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;There are contests that are organized by the private companies or universities, but they do not go into the detail or scale that we see in China, nor they are part of university degrees,&#8221; he says. &#8220;They do not count as part of the evaluation to your grades, and so that practical-skill, direct-confrontation component is absent compared to the Chinese ecosystem.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"China's Reversal of Cyber Fortunes\">China&#8217;s Reversal of Cyber Fortunes<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The effort is a reversal of the situation before 2015, when Chinese CTF teams struggled in international contests and met with social condemnation domestically for profiting from vulnerability awards. China&#8217;s CTF ecosystems \u2014 especially the inter-collegiate competitions, which bring together hundreds of teams \u2014 are now the best in the world, according to the researchers. Major contests include the Information Security Ironman Triathlon, Qiang Wang Cup, Wangding Cup, and National University Cyber Security League.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The events all have government support, with the Ministry of Public Security, the People&#8217;s Liberation Army, the Ministry of State Security, and the Ministry of Education all sponsoring at least one of the university-based events each.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Western governments could learn from the approach, says Benincasa. Currently, the US and Europe face <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/cyber-staffing-shortages-remain-cisos-biggest-challenge\" rel=\"noopener\">a scarcity of cyber talent <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">because of a lack of a pipeline for funneling technically minded students into cybersecurity roles.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We are behind when it comes to, specifically, the hacking-contest ecosystem,&#8221; he says. &#8220;We need to integrate CTF contests into academic curricula, so we can have a better, more direct correlation between hacking classes and the graduation of talent.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">China was able to turnaround its cybersecurity picture, and the lesson is, focusing on practical experience through hacking contests and CTF tournaments \u2014&nbsp;as well as creating deeper pipelines between universities, the government, and industry \u2014 could go a long way to solving the problems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This was very much a bottom-up, organically driven process that at some point the state recognized and encouraged,&#8221; he says. &#8220;They started seeing these successes abroad and recognizing \u2014 because of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/us-israel-dutch-spy-stuxnet-malware-against-iran\" rel=\"noopener\">geopolitical events like Stuxnet <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/how-did-snowden-do-it-\" rel=\"noopener\">[Edward] Snowden<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 recognizing how important [cybersecurity] is and that contributed to the breaking of taboos and &#8230; a big change in the culture.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/china-cyber-corps-hone-skills-virtual-battlefields\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Over the last decade, the Chinese government has established an<\/p>\n","protected":false},"author":12,"featured_media":5978,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5977","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/chinas-elite-cyber-corps-hone-skills-on-virtual-battlefields.jpg?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/chinas-elite-cyber-corps-hone-skills-on-virtual-battlefields.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/chinas-elite-cyber-corps-hone-skills-on-virtual-battlefields.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/chinas-elite-cyber-corps-hone-skills-on-virtual-battlefields.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/chinas-elite-cyber-corps-hone-skills-on-virtual-battlefields.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/chinas-elite-cyber-corps-hone-skills-on-virtual-battlefields.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/chinas-elite-cyber-corps-hone-skills-on-virtual-battlefields.jpg?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/chinas-elite-cyber-corps-hone-skills-on-virtual-battlefields.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/chinas-elite-cyber-corps-hone-skills-on-virtual-battlefields.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/chinas-elite-cyber-corps-hone-skills-on-virtual-battlefields.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/chinas-elite-cyber-corps-hone-skills-on-virtual-battlefields.jpg?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5977","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5977"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5977\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5978"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5977"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5977"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5977"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}