Oh wait, they can't, as all manufacturing was outsourced to China and that would be the first thing China cuts off...
Sarcasm aside: how can the West possibly react on the events of the last years?! There's not many options available any more.
Oh wait, they can't, as all manufacturing was outsourced to China and that would be the first thing China cuts off...
Sarcasm aside: how can the West possibly react on the events of the last years?! There's not many options available any more.
GDPR recently drove us to build our own application level firewall from scratch, which turned up behavior that is never reported by CloudFront or Google Analytics - those services are only hiding the severity of the problem.
You may have heard of "Fancy Bear". That's one APT out of Russia.
For more information, see https://en.wikipedia.org/wiki/Advanced_persistent_threat
https://attack.mitre.org/groups/ https://en.wikipedia.org/wiki/Advanced_persistent_threat
When I see patterns in traffic coming from 45,000 one-off hosts for a month straight it is clear that there is a distributed botnet behind the requests.
When I see a vulnerability scan from an Azure cloud instance seconds after I ban a block of Russian addresses, I can be sure there is coordination.
And don't get me started on the Moldavian Registration Bots. Those are a combination of automated and human-assisted CAPTCHA solvers, and it took me almost a full week of careful observation to weed them out.
These are some of the things my application firewall can detect automatically. Every now and then I see a new pattern, that is all I was trying to say.
We just weren't getting enough information from Bing or Google Analytics or CloudFlare, and when I developed a realtime activity dashboard, patterns started emerging: distributed web scrapers, registration bots, vulnerability scans, and some of these in tandem (i.e., scans commencing immediately after blocking a block of addresses). And many of these are coming from cloud hosts, Azure being the worst, with Google a close second. This is the type of traffic they don't want you to see, so those respective analytics services just supress it because it would be a negative advertisement if we could actually see what is happening realtime. I compared the numbers - Google was consistently underreporting our traffic by at least 40%, and a lot (not the majority, but enough to be noticible) of that traffic was coming their own hosted servers (not the indexing bots, but the user cloud instances).
CloudFlare implements temporary bans but I needed something permanent for those threats that were recognizable based on their request patterns.
The ARIN squatting is the latest thing I'm seeing - a lot of requests coming from netblocks that are former DoD and RedHat addresses. The publicly available ARIN databases aren't entirely up-to-date and the bad guys know it, some of the checks we depend on have to be taken with a grain of salt.
So far, I've been able to develop business rules to separate out the human activity from the carefully constructed scraper/probe attempts, but I fear that if they get just a bit more sophisticated I may lose that ability.
Also, China has massive sums of dollars and euros, they can simply play the "long game", i.e. weather out the storm until Europe/US caves.
Many companies are moving out of China at the moment, either due to the threat of a Trump-caused trade war or because other countries are even cheaper than China, and it takes them years.
China can weather one year of export blockade to EU/US. No problem. But EU/US can not, not in any way.
All of them have a pretty harsh stand against Russia.
Crimea ( Ukraine) almost made Russia's entire naval fleet useless.
Russia is still getting punished for it economically and Putin has never seen these low approval rates. There are also a lot of protests there.
China thinks they can possess the world, but they are even having severe problems in their own country. We just need to wait, China's plan was smart, but they forgot the will for freedom in every execution/plan they had and are doomed to fail. Sooner or later.
Depends on how you look at things :)