網絡空間治理的力量博弈、理念演變與中國戰略 // Power Game of Network Space Governance, Evolution of Ideas & China’s Strategy


Power Game of Network Space Governance, Evolution of Ideas & China’s Strategy

The global cyberspace governance process involves not only the complex game of information developed countries and information developing countries in the fields of Internet key resources, network power and network security, but also the mutual game between government, private sector and civil society. “Prism door incident” in the intensification of cyberspace governance game at the same time, but also to promote the policy position of the parties continue to adjust to increase the possibility of governance cooperation. At the same time, the cyberspace game also reflects the Internet governance and cyberspace governance and other related governance concepts of mutual conflict and integration trend. At present, China’s participation in global cyberspace governance still faces many challenges. China needs to be based on the development trend of network space game and the evolution of governance concept. Combining with the strategy of network power in the “13th Five-Year Plan”, this paper constructs long-term, complete and comprehensive aspects of international mechanism shaping, talent cultivation and technology development as the core Participation strategy.
In June 2013, former US National Security Agency (NSA) former employee Edward Snowden disclosed the council’s “prism” monitoring program. The event [1] made cyberspace governance in the international agenda in the priority of the re-ascension, but also exacerbated the differences in the position of the parties, leading to cyberspace governance in trouble, for the network space management system to create a great challenge The In addition, the international community on the complexity of cyberspace and its governance lack of clear, unified awareness, resulting in one-sided position and a single policy to further exacerbate the governance dilemma. In the face of the complex situation, Joseph Nye tries to explain the practice of cyberspace governance by referring to the theory of mechanism complex in the field of environmental governance, and analyzes the cyberspace management through the loosely coupled complex composed of many different governance mechanisms The [2] This provides a useful perspective for the analysis of cyberspace governance, that is, cyberspace governance is composed of multiple rather than a single governance mechanism, the interaction between the various mechanisms have an impact on governance. This paper intends to examine the development of cyberspace governance from a more macro perspective, and try to explore the evolution of the concept behind cyberspace game, and analyze the complex relationship between government, private sector and civil society in international and domestic levels The On this basis, to explore China’s response measures and participate in cyberspace governance strategy.

First, the power of cyberspace governance Game

network space management process with the government between the game process. According to the situation of network technology, network capacity and network utilization, governments can be divided into three categories: information developed countries, information developing countries and information undeveloped countries. [③] There are also international organizations to use the network readiness (Readiness) as an indicator to measure the degree of information technology. This ranking basically overlaps with the traditional developed, developing and underdeveloped countries, and of course there is also the level of informationization in individual developing countries rising to the ranks of developed countries, or the level of information in some developing countries The level of the developed countries. Therefore, in accordance with the information developed countries, developing countries and underdeveloped countries to divide the three points in the academic more accurate. There are three aspects of the power game of cyberspace governance: one is the game between the developed countries and the information developing countries in the network ownership, the network resource allocation; the second is the non-governmental actors and the government on the Internet key resource control, network security And freedom and other issues of the game; Third, as the dominant space in cyberspace, the US government in its own private sector, civil society and other countries in the Internet between the key resources and other issues on the game (Figure 1).

First of all, information between developed countries and information-developing countries around the network space between the key infrastructure and network technology between the game. According to the behavior, the topic and the characteristic of the power game in cyberspace management, it can be divided into three stages.
The first stage is the early period of Internet governance, which is roughly from the beginning of the formation of the Internet to the United Nations World Summit on Information Society (World Summit on Information Society, WSIS), which is divided into two phases: the Geneva Conference in 2003 and the Tunis Agenda in 2005. The World Summit on the Information Society appears to be a struggle between governments and the private sector and civil society, in essence, the game between the United States and other countries on Internet control.
This period is the stage of rapid development of the Internet, a large number of new technical and technical standards have been created, the US government took the opportunity to vigorously promote the development of information technology, and developed a series of international technical standards, industry and industry norms. And information developing countries are still in the study, learn from the stage, which makes the United States and other developed countries in the field in an absolute strong position. [4] This stage of Internet governance mainly around the Internet domain name registration and analysis and its corresponding 13 root server control, Internet Protocol (IP) address allocation and other key resources to compete. The United States has almost controlled all international organizations and core businesses that have developed and managed Internet standards and refused to internationalize the relevant management functions or to the United Nations specialized agencies. [⑤] Therefore, at the World Summit on the Information Society, despite the pressure from the United Nations, the developing countries and even the European countries, the United States still refused to hand over the Internet management rights. Into the 21st century, the information represented by China’s developing countries to enhance the network technology, they have the domain name, users and other Internet resources have exceeded the information developed countries, but the representation in the Internet governance is far from enough, So the existing Internet governance reflects the legitimacy of the questioned.
The second stage is the stage of political competition and sovereignty competition of cyberspace governance, which is called the “return” stage of the government in cyberspace. This stage from the Information Society World Summit to 2011. In 2011, China, Russia and other countries to the 66th session of the General Assembly to submit the “International Code of Conduct for Information Security”, advocated the United Nations in cyberspace governance play a leading role. In the same year, the United States and Britain and other governments dominated the global network space management conference (Global Cyberspace Conference), also known as the London process (London Process) was held. <A The network space has become the “fifth strategic space” of human society. With the continuous breakthrough of network technology and its disruptive transformation of real society, cyberspace has become the fifth strategic space of human society. The distribution of order, power and wealth in cyberspace, the developed countries and information developing countries have serious differences on the following issues: whether the cyberspace attribute is “global public domain” or “sovereignty”; governance is government-led “Multilateral governance”, or a multi-stakeholder model dominated by non-governmental actors; governance culture is a “multicultural” or “multicultural” that is dominated by the West. [⑥] The focus of this period is also reflected in the free flow of information content in the field, when Hillary Clinton took the US Secretary of State, the Internet for the freedom of many speeches, advocating the US Internet freedom strategy. The role of the US government and social media sites in the wake of the turbulence in North Africa, which began at the end of 2010, has aroused widespread concern in the developing countries and strengthened the management of the Internet. [⑦] The third stage from the “Prism Gate incident” until now, this stage of the competition more focused on cyberspace security governance. “Prism door incident” to the United States in the field of cyberspace governance moral high ground questioned, leadership decline, forcing it to promote cyberspace governance in the low posture. At the same time, cyberspace security situation is further deteriorating, and the security threats facing countries are further increased. After experiencing the fierce confrontation of the “prism gate incident”, the developed countries and the information developing countries are aware that the maintenance of cyberspace requires the participation of all countries, and no country can lead the cyberspace governance process alone. Information developed countries and information development countries in the cognitive level of the gap gradually narrowed, the reduction of confrontational initiatives, cooperation began to grow space. Second, the “prism gate incident” caused the government and the private sector, civil society between the network security, privacy and other issues on the fierce game. Former US National Security Agency former employee Edward Snow led to expose a including “prism”, “X key points” (X-Keyscore), “Fair” (Fairview), “core” (Main Core) and other monitoring systems, including 10 monitoring systems, the monitoring system by the National Security Agency, the Central Intelligence Agency, the Federal Bureau of Investigation and other intelligence agencies to participate in almost cover the cyberspace of social networks, e-mail, instant messaging, Web pages, videos, photos, and so on. [8] National Security Agency requires Microsoft, Google, Facebook and other nine major global Internet companies to open the database to monitor the project to carry out data monitoring. In the “Prism Gate incident” exposure, Microsoft, Google, Facebook and other companies to the court to prosecute the federal government. [⑨] civil society have also acted against large-scale data monitoring. The American Civil Society Alliance launched a “Stop Watch Us” action on the Internet, putting pressure on the US government to get tens of thousands of Internet users’ signatures, messages and responses from hundreds of civic groups by organizing parades Demonstrations, petition to Congress, launch network initiatives, etc. to cooperate with the action. [⑩] In the “prism door incident” triggered the other countries with the US government to carry out monitoring projects ICT enterprises dissatisfaction, countries have taken new measures to protect cyberspace security. For example, the Chinese government has accelerated the process of legalization of cyberspace and began to discuss the guiding ideology of cybersecurity equipment, and formulated the network security review method. After the introduction of the “national security law”, “anti-terrorism law” “Network Security Law (Draft)” and “Criminal Law Amendment (9)” have significantly increased the terms involved in network security. These initiatives have aroused serious concern about US ICT companies and lobbyed the US government to put pressure on China to require the Chinese government to cancel the relevant provisions, such as Article 18 of the Anti-Terrorism Act provides that “telecom operators, Internet services Providers should be for the public security organs, the state security organs in accordance with the law to prevent and investigate terrorist activities to provide technical interface and decryption technical support and assistance. [11] Although from the government point of view, these initiatives help to maintain network security and national security, but in the private sector, the above-mentioned initiatives will not only increase the technical input, but also a substantial increase in costs. As long as cyberspace governance does not achieve a breakthrough, the government and the private sector, civil society between the game will continue to exist, and to a certain extent, will evolve into a national game. <A Finally, the US government and its private sector, civil society alliance with other countries in the Internet key resources on the issue of the game. Internet key resources include: IP address allocation, protocol parameter registration, gTLD system management, ccTLD system management and root server system management and time zone database management. Some scholars use the “cyberspace” in cyberspace to describe the status of Internet Corporation for Assigned Names and Numbers (ICANN) in cyberspace governance. [12] For historical reasons, these resources have been by the National

Telecommunications and Information Administration (National Telecommunication and Information Administration, NTIA) under the Internet Digital Distribution Agency (Internet Assigned Numbers Authority, IANA) is responsible for managing, and NTIA authorizes its management of IANA functions through regular engagement with ICANN. Therefore, it can be argued that the US government controls the key resources of the Internet. The United Nations-appointed Working Group on Internet Governance (WGIG) noted in its report that the US government unilaterally controls the Internet’s key resources, such as root zone documents. [13] The international community has been dissatisfied with this situation, and the WGIG report has proposed four options to replace the existing structure, hoping to take over the Internet’s critical resources through intergovernmental organizations or global institutions. [14] For ICANN, although it has been seeking independence from the US government and has repeatedly contested it, it is more concerned with how to avoid other intergovernmental organizations or institutions to take over or replace their status. Milton Muller described the phenomenon as “some network liberals even eventually turned into secret supporters of nationalism, because as long as the challenged countries were their motherland, they turned to defend the United States, allowing Its control, leading the Internet. “[15] Thus, in some cases, ICANN chooses to” align “with the US government to prevent other countries or intergovernmental organizations from influencing their governance structures. In ICANN’s organizational structure and decision-making system, the Government Advisory Committee (Government Advisory Committee, GAC) is eligible to nominate a liaison who does not have the right to vote. Information developing countries believe that as an international mechanism for Internet governance, the lack of representation in ICANN from information developing countries should reflect government responsibilities and powers in their future management structures and increase the authority of the Governmental Advisory Committee The But ICANN has repeatedly said it will not accept this change. In this case, the US government representatives are highly consistent with ICANN’s official position, both in the government advisory committee and at ICANN’s plenary meetings. Until the “Prism Gate Event” broke out, the US government was forced to restart the process of internationalization of ICANN’s efforts to guide the cyberspace governance game to a new stage. Second, the future development of cyberspace management trend With the advancement of the network space management process, the parties to the understanding of the spatial properties of the network gradually reached a consensus, and thus in the governance approach, the path of the differences narrow. Especially at the cognitive level, the cognition of cyberspace from various countries is based on different political, economic and cultural backgrounds, emphasizing their uniqueness to objective properties and laws based on cyberspace, emphasizing the integration between different views. [16] Internet space interconnection, sharing attributes determine the zero-sum game does not apply to cyberspace, cyberspace security, development, freedom is the government, the private sector and civil society to pursue the common goal. At the same time, the mutual restraint of the three issues of security, development and freedom makes it impossible for either party to ignore the interests of other actors and pursue their own absolute interests. As President Xi Jinping on December 16, 2015 at the Second World Internet Conference (World Internet Conference, WIC) said: “There is no double standard in the field of information, countries have the right to maintain their own information security, not a national security while other countries are not safe, part of the national security and another part of the country is not safe, but not Sacrifice the security of other countries to seek their own so-called absolute security. ” [17] This position reflects the above special properties of cyberspace governance. As a result, the international community has gradually realized that no one can dominate the process of cyberspace governance. First, the US cyberspace strategy adjustment and ICANN internationalization will drive a major transformation of the cyberspace governance architecture. Facing the pressure, the United States by part of the Internet to give up the key resources of direct control, for its network space to adjust the international strategy to prepare. [18] On March 14, 2014, NTIA, a subsidiary of the US Department of Commerce, announced that it would give up control of ICANN and pointed out in its transfer statement that ICANN’s management would organize global multi-stakeholder discussions on receiving issues, but explicitly United Nations or other intergovernmental organizations. [19] ICANN has been seeking its own independent position since its inception, and ICANN’s internationalization goal is not only to get rid of the constraints of the US government, but also to ensure that the US government will not be taken over by other countries and intergovernmental organizations. Therefore, ICANN needs to reach an agreement with the US government to ensure their independence, but also with other governments to start a game, to avoid its internationalization was strongly opposed. Second, the role of the United Nations in cyberspace governance continues to improve, will effectively promote the network space management structure and norms of the pace of construction. Through the efforts of the United Nations Group of Governmental Experts on Information Security (GGE), the international community has also made important breakthroughs in cyberspace codes of conduct and confidence-building measures. In June 2013, the United Nations published a report of the Group of Experts, composed of representatives of 15 countries. The report clarifies for the first time that “national sovereignty and sovereign international norms and principles apply to national communications technology activities and the jurisdiction of the State in its territory for communications technology infrastructure.” At the same time, the report further recognizes the Charter of the United Nations In the applicability of cyberspace “. [20] “While efforts to address the security of communications technology, States must respect the human rights and fundamental freedoms contained in the Universal Declaration of Human Rights and other international instruments.” [21] Compared with the 2010 expert group report, the above contents were presented as sections 20 and 21 of the 2013 report, which is a significant improvement in the compatibility of information developed countries and information developing countries in cyberspace governance Sex continues to improve.
In July 2015, the United Nations Group of Governmental Experts on the Development of Information and Telecommunications from the Perspective of International Security published a third report on the Code of Conduct for Cyberspace. This report has reached a consensus on the protection of cyberspace-critical infrastructure, confidence-building measures, and international cooperation. The network sovereignty of the developing countries is further clarified, and the application of international law, especially the law of armed conflict, which is advocated by the developed countries, is also included in the application of cyberspace. [22] Finally, the competition and cooperation model between government and non-state actors in cyberspace governance will undergo a major change, and multi-level game will become the “new normal” of cyberspace governance. In terms of governance and path, countries’ policy positions in cyberspace governance also place greater emphasis on reality, especially in dealing with the relationship between government and other actors. All parties are aware that the responsibilities of the government and other actors should be divided according to the problems in cyberspace governance. For the multi-stakeholder governance model, the information developed countries and information development countries gradually unified awareness, the government and the private sector, civil society according to their respective functions to participate in cyberspace governance. The narrowing of cognition means that one party is more aware of the concerns of the other party. The game between the developed countries and the developing countries in cyberspace governance will be more targeted, and competition and cooperation will be carried out synchronously to promote cooperation through competition. Of course, this has increased the investment in cyberspace, and the increase in the right to speak on cyberspace governance. Brazil, China has established a network space multi-stakeholder meeting (NetMundial) and the World Internet Conference mechanism to explore the network and national security, network sovereignty and other core issues, the voice of developing countries will be more and more, more and more Big. Third, the evolution of the concept of cyberspace governance <a In the information developed countries and information development countries, governments, the private sector and civil society around the network space governance game from conflict to integration behind, reflecting the continuous evolution of the concept of cyberspace governance. Although the game around cyberspace governance is mainly to compete for the power and wealth of cyberspace, the different cognition of actors, objects and methods of governance has had an important influence on the conflict and fusion of governance. Craig Mundie, Microsoft’s chief research and strategy officer, pointed out at the 7th China-US Internet forum that “the misunderstanding of cyberspace in both China and the United States is largely due to ‘Internet governance’ and ‘ ‘Cyberspace governance’ caused by the confusion of the two concepts. [23] Similarly, cyberspace governance game and conflict also reflect the conflict between the two governance concepts. Internet governance is considered to be a multi-stakeholder governance model that is dominated by non-governmental actors, but cyberspace governance also requires the participation and coordination of government and intergovernmental organizations. Internet Governance Project (Internet Governance Project, IGP) defines Internet governance as a network-related decision that is linked by an Internet protocol, including the establishment of a dispute resolution mechanism for policies, rules, and technical standards that are common to the owner, operator, developer, and user. Distribution and global Internet standards of human behavior. “[24] The above definition includes three aspects, namely the acceptance and recognition of technical standards and agreements, the allocation of Internet resources such as domain names and IP addresses, spam generated by human Internet behavior, Cybercrime, copyright and trademark disputes, consumer protection issues, public sector and private security issues, rules and policies. Laura DeNardis (Laura DeNardis) proposed to be in accordance with the Internet transmission TCP / IP protocol level, and according to different levels of different functions to build Internet mode, based on the function, tasks and actors were discussed Internet resource control, standard settings , Network access, network security management, information flow, intellectual property protection and other six levels of Internet governance content. [25] Cyberspace governance has shifted from the professional and technical fields that have been emphasized by the original Internet governance to a wider range of political, security and economic sectors, and the importance of government and intergovernmental organizations in cyberspace governance has become increasingly prominent. Cyberspace is a broader field that includes not only the Internet, but also the data that is transmitted in the network, the users of the network, and the interaction between real society and virtual society. The corresponding cyberspace governance is a broader concept, which is “a category of cyberspace infrastructure, standards, law, social culture, economy, development and so on.” [26] It contains more diverse governance issues and challenges that are increasing. Such as the “Prism Gate Incident”, the government’s high-level threat (APT) due to network action in cyberspace, the Digital Divide and Data Poverty ), Cyber ​​terrorism, online business theft and more and more governance issues have gone beyond the scope of the traditional concept of Internet governance. <A The conflict between “global public domain” and “network sovereignty”, “network autonomy” and “state dominance” in cyberspace governance game reflects that people can not understand “Internet governance” and “network Space governance “between the different governance subjects, objects and methods, trying to use a single governance approach to solve the multiple issues. The bottom-up, open and transparent governance model, which is advocated by the Internet governance subject represented by ICANN, is concerned with the high risk of cyber warfare, large-scale data monitoring and theft, and cyber terrorism. Lack of effectiveness and relevance. At the same time, the state-centered, top-down cyberspace governance philosophy can not effectively deal with the real problems of the current Internet governance and can not replace the dominance of Internet international organizations in the field. With the advance of the network space management process, the two governance ideas and methods in the collision also began to integrate. Joseph Chennai believes that cyberspace is composed of multiple governance mechanisms, in which Internet governance focuses on the technical level and is a subset of cyberspace governance. Should be based on different governance issues, to build a different governance mechanism, so that different actors to play a leading role. [27] The integration of governance concepts is also reflected in the increasing consensus among the parties on the multi-stakeholder governance model. ICANN uses a bottom-up, consensus-based decision-making process that advocates a governance model that limits the role of government. [28] Many developing countries initially opposed the multi-stakeholder governance model, stressing that government-led multilateral governance models should be adopted. With the deepening of the governance process, the information-developing countries have gradually accepted the multi-stakeholder governance model, which is gaining more and more consensus in the private sector and civil society as long as the role of the government is well reflected. The government, the private sector and the civil society participate in the decision-making process according to their respective functions and responsibilities, do not deliberately exclude other actors, nor deliberately pursue the leadership of individual actors, reflecting a more objective and balanced approach to cyberspace governance. Fourth, China’s strategic response <a The Chinese government has put forward the two goals of global governance of cyberspace, namely, to build a peaceful, safe, open and cooperative cyberspace and to establish a multilateral, democratic and transparent international Internet governance system. Important strategic objectives into the “thirteen five” plan recommendations. The former advocates foreign participation in the international network space management process, in order to establish a favorable international governance system; the latter advocates the development of network technology, nurture the network industry, enhance the national network strength. The mutual support and mutual promotion between the two requires an international strategy that can co-ordinate internal and external situations in response to complex cyberspace. Although the Chinese government has not published a specific international cyberspace strategy document, but by analyzing the existing relevant policies, can still be found in China’s international strategy of cyberspace is still in the exploratory stage. Therefore, it is necessary to analyze and discuss the international strategy of cyberspace in China according to the characteristics of cyberspace power game and the strategy of network power. (A) China’s cyberspace international policy practice Since 1994 access to the Internet, China has developed a variety of forms of international network policy into the international network space system. This aspect is to expand the needs of opening up, hope that through international cooperation in learning, the introduction of foreign advanced technical standards; the other is the driving force of information technology, integration into the globalization must be all-round participation in the international system. [29] In addition, with China’s growing influence in international affairs and increased dependence on the network, active participation in cyberspace governance is also an important way to maintain national interests and ways. China’s network policy is largely influenced by the situation of international cyberspace governance and developed and promoted in the interaction with the international cyberspace management system, showing the characteristics of multi-domain, multi-level and multi-subject. <A First, the international policy of the Chinese government network covers international cooperation in international technical standards, information and communication technology industry cooperation, global Internet governance, combating cybercrime, network economy, digital divide and other fields, and the development trend of global network governance Generally consistent. First of all, from the early technology, industry and Internet standards to gradually expand the cooperation to a wider range of network-related policy cooperation, many policy areas in fact beyond the scope of the Internet itself, and international economic, political and security. Secondly, after the “prism door incident”, with the cyberspace security governance become the main issue in governance, the focus of China’s network policy is also focused on the network security governance, and based on the establishment of national security, political security, Safety and social security. China not only vigorously oppose large-scale network monitoring in the international arena, advocate the maintenance of national network sovereignty, but also pay more attention to the legislative work related to cybersecurity in domestic policy and maintain national security and sovereignty in practice. Second, China’s cyberspace international policy covers bilateral, regional, multilateral and international levels. From the bilateral level, China has established intergovernmental dialogue and cooperation mechanisms with countries such as South Korea, Britain and Australia. These cooperation not only covers the contents of network security, digital economy and development, but also become an important content and support for bilateral diplomatic relations. In addition, China and the United States, between China and Russia in the field of network security to carry out a different degree of confidence-building measures (Confidence Building Measures, CBMs). [30] At the regional level, China and ASEAN, the SCO, the European Union, the Arab League and other regional organizations and countries to establish a variety of forms of network dialogue and cooperation mechanism. In 2009, the Chinese government signed the Cooperation Framework of the China-ASEAN Telecommunications Regulatory Commission on Network Security and the Intergovernmental Agreement on Safeguarding International Information Security of Member States of the Association of Southeast Asian Nations (ASEAN) and ASEAN Member States. [31] China also actively participated in the work of the ASEAN Regional Network Security Working Group, and in September 2013 held in Beijing, the ASEAN Regional Forum “to strengthen the network security measures seminar – legal and cultural perspective.” Conference development The development of the Internet requires the guidance of legal rules and the need to promote and respect cultural diversity. All parties should strengthen exchanges in the field of cybersecurity, promote mutual trust, promote cooperation and jointly build peace, security, openness and cooperation. [32] Finally, China is also actively involved in the multilateral and international level of cyberspace governance mechanisms, both within the United Nations Framework for Information Security, the International Telecommunication Union, the World Summit on the Information Society, the Internet Governance Forum, or the United Nations Framework London process, cyberspace multi-stakeholder meetings and other mechanisms, China is the main participant; in addition, China also through the World Internet Conference to carry out cyber space home diplomacy. China has also submitted two versions of the International Code of Conduct for Information Security to the United Nations General Assembly, together with representatives of OECD countries such as Russia and Uzbekistan. [33] China is also a major participant in the Global Internet Governance Consortium, where the head of the National Internet Information Office (NYSE), Lu Wei and Alibaba Group Chairman Ma, was elected as a member of the Alliance. <A Third, with the cyberspace governance covered by more and more widely, China’s cyberspace international policy to participate in the main body from the traditional Ministry of Foreign Affairs, Ministry of Industry and further expanded to the Ministry of Public Security, Ministry of Commerce, Ministry of Finance and the new The establishment of the network letter Office, the Ministry of Foreign Affairs set up a “network affairs office” to deal with cyberspace of foreign affairs. Among them, the Ministry of Foreign Affairs is mainly responsible for bilateral, regional, multilateral and international level of network diplomacy, it is China’s docking under the framework of the United Nations network governance mechanism of the main forces, especially from the Ministry of Foreign Affairs arms control officials throughout the four United Nations information security Working Group of Experts. Net letter office as the central network security and information leading group of permanent institutions, China is to co-ordinate the network security and information management of the newly established important institutions. Since the role of network management as a co-ordination and coordination of China’s network affairs is becoming more and more important in the international policy of the network, it has not only carried out multi-level international network security and digital economic cooperation, but also established the governance mechanism of the World Internet Conference.
In addition, the Ministry of Public Security in the fight against cyber security crime, network anti-terrorism, the Ministry of Commerce in the information and communication technology market access, the Ministry of Finance in the network infrastructure external assistance and other areas of work will be China’s future implementation of cyberspace international strategy a solid foundation. It can be seen that China has formed a more comprehensive and in-depth international strategic framework of cyberspace, including pluralistic participant, wide-ranging problem coverage and multi-level participation path, which laid a good foundation for the international strategic construction of cyberspace governance basis. With the development of China from the network power to the network power, China will establish a comprehensive and perfect international strategy of cyberspace. (2) Challenges in the international strategy of cyberspace The evolution of cyberspace governance has brought many challenges to China’s cyberspace international strategy: First, the information developed countries will continue to dominate the network space governance game, which is the network of China The international strategy of space poses a challenge; the second is due to the lack of advanced Internet governance talent, leading to China’s Internet international organization in the serious shortage of the third is the network space governance game to emphasize capacity building (Capacity Building), best practice (Best Practice) And so on, will bring competitive pressure to China. These issues and challenges will have a greater impact on China’s cyberspace international strategy, if handled properly, will have a negative impact on the implementation of the network strategy. <A I = 35> First, the information developed countries continue to dominate the network space governance game direction on China’s international strategic challenges. The global governance of cyberspace is played through various forms of governance, and the construction of the mechanism depends on the negotiation between the actors. The bargaining of the negotiations depends not only on the size of the powers of the actors, but also on the global governance of cyberspace In the agenda set the ability to be closely related. [34] According to Joseph Nye’s definition, the former can be called “hard power”, the latter is “soft power”. [35] The advantages of the developed countries in these two areas are obvious, especially in the mechanism of selective or prioritizing the discussion of cyberspace governance. For example, in cybersecurity governance, the United States relies on its agenda setting capacity to prevent the international community from making large-scale data monitoring a governance agenda, while setting its network economy to focus on priority agendas. In addition, the information developed countries in the establishment of the network of human rights agenda, will focus on the field of freedom, and democracy (one country one vote), equality (the size of the country has the same discourse) and other equally important issues are excluded from the agenda. Not only that, for countries in the “prism door incident” after the request to strengthen the exercise of network sovereignty trend, the United States put forward the “data localization” (Data Localization) this agenda to circumvent the global governance mechanism to discuss network sovereignty. Compared with the information developed countries, information development countries in the agenda setting capacity there is still a big gap, the lack of initiative to set the agenda. In recent years, with China, Brazil, India and other countries have established a variety of cyberspace governance mechanism, emerging powers in the global management of cyberspace in the agenda set the ability to continue to increase. But in general, the gap between China and the information developed countries in governance capacity still exists, and will affect China through international mechanisms to safeguard their own national interests, as well as express their concerns. <
Secondly, due to the lack of advanced cyberspace governance talent, leading to China in the Internet international organizations in the representation of a serious shortage. The trend of cyberspace governance game shows that the control of Internet key resources by international organizations such as ICANN, IETF and other international organizations will not be challenged by government and intergovernmental organizations. As the US government abandons its control over ICANN, the latter will have greater independence. Network space is built on the basis of the Internet, the basis of cyberspace governance is also Internet governance. Therefore, China’s cyberspace international strategy must be in the field of Internet governance to achieve a breakthrough, while enhancing the international organizations in the Internet in the influence and representation. For the majority of developing countries, including China, it is necessary to increase the representation in international organizations such as ICANN, so that more voices from China and other developing countries appear in ICANN. Third, the network space governance game to emphasize the ability to build, best practice and other direction, which will bring China’s severe competitive pressure. The convergence of the cyberspace governance game concept has led to the international community’s focus on cyberspace governance to operational and enforceable areas such as capacity building, best practices, including the provision of network infrastructure to information developing countries and underdeveloped countries; Training in technology, law, and policy related to cyberspace governance; and providing best practices for solving specific problems in cyberspace governance. This is China’s participation in cyberspace governance of the international strategy put forward higher requirements, information developed countries in the field of resources, talent advantage is difficult to shake in the short term, which not only requires the Chinese government to invest more resources, but also China’s Internet companies , Industry associations, legal experts of the common and active participation. (C) China’s strategic thinking of cyberspace governance The basic path of China’s cyberspace international strategy is consistent with the overall macro strategy of China’s integration into the international system and the reform of the international system. [36] In response to the complex cyberspace governance game, China on the one hand to strengthen capacity-building, and focus on the ability to participate in the global control of cyberspace influence; the other hand, between the network security and openness to seek a balance, International cyberspace to establish their own legitimate rights and interests, to avoid the negative impact of excessive security; and strengthen the network strategy and cyberspace international strategy between the strategic interaction, the formation of mutually supportive cyberspace strategy system. <A I = 40> First, combined with the new and future development of cyberspace governance, to strengthen the shaping of international mechanisms. In the cyber space global governance level, the struggle around the governance platform is becoming increasingly fierce. Including the Internet forum, the International Telecommunication Union, the London process, the Brazilian cyberspace multi-stakeholder meeting and China’s World Internet Congress, all platforms have their dominant forces, actors involved in the subject matter and the impact of the play Are not the same. China should explore ways to enhance its own capacity-building programs to the international community in the areas of cybersecurity, cybercrime, capacity building, network economy, cyber culture and the digital divide, in conjunction with the World Internet Forum and other cyberspace governance mechanisms involved. Good practice and solutions such as the ability of public goods. Second, focus on training to participate in cyberspace governance of international talent.
Internet governance organizations are mostly non-governmental organizations, and their multi-stakeholder governance model usually requires the selection of senior management personnel from the Internet community, and the corresponding high-level management, based on the contribution of the selection object to Internet technology and governance Management positions, rather than a traditional intergovernmental organization of a country or vote in accordance with the population, economic ratio to allocate places. In the case of ICANN, its existing management structure is comprised of the Board of Directors and three support organizations, three advisory committees and two technical advisory bodies. The Board consists of 16 voting members and 5 non-voting liaison officers, with the exception of the ICANN President, the remaining 15 places from the Supporting Organizations, the General Members Advisory Committee, the Regional General Membership Organization and the Nominating Committee. To be elected as a member of the voting, must pass the bottom-up nomination and election. Therefore, China should rationalize the system and mechanism, and actively to ICANN and other international non-governmental organizations to transport talent to encourage Internet companies, industry organizations and academic institutions to actively participate in ICANN, IETF, Internet Architecture Board (Internet Architecture Board, IAB) and other institutions to select the talent in order to enhance the international organizations in the Internet in the representation and voice, and to improve China’s influence on Internet governance. Third, to strengthen the network strategy and cyberspace international strategy between the strategic interaction. China has put forward the strategy of strengthening the network power in the “13th Five-Year Plan”, and proceeded from five aspects: technological innovation, network culture, network infrastructure, network security and information construction and international cooperation. [37] Network power strategy has repeatedly referred to the opening up, and actively participate in the Internet governance, and even international cooperation as a separate chapter. This shows that the international strategy of cyberspace and network power strategy between the integration of mutual support. The effective interaction between the two is related to China’s openness to cyberspace, the relationship between security and development. From the perspective of the two-tier game, any country’s strategy is faced with the external situation and the internal interests of the double constraints, excessive emphasis on openness or security are not conducive to the overall national security and interests. Strengthening the interaction between the network strategy and the international strategy of cyberspace helps to improve the awareness of the decision-makers on the security and opening of cyberspace, the security of cyberspace, the development and the Original Mandarin Chinese:

全球網絡空間治理進程不僅涉及信息發達國家與信息發展中國家在互聯網關鍵資源、網絡權力和網絡安全等領域的複雜博弈,還包括政府、私營部門和市民社會等行為體之間的相互博弈。 “棱鏡門事件”在加劇網絡空間治理博弈的同時,也推動各方政策立場持續調整,增加了治理合作的可能性。與此同時,網絡空間領域的博弈也反映出互聯網治理與網絡空間治理等相關治理理念的相互衝突與相互融合趨勢。目前,中國在全球網絡空間治理上的參與仍面臨諸多挑戰。中國需要以網絡空間博弈的發展趨勢和治理理念的演進為基礎,結合“十三五”規劃提出的網絡強國戰略,以國際機制塑造、人才培養及技術發展等為核心建構長遠、完備和全面的參與戰略。
2013年6月,美國國家安全局(NSA)前僱員愛德華·斯諾登披露了該局的“棱鏡”監聽項目。該事件[①] 使網絡空間治理在國際議程中的優先次序再度提升,但也加劇了各方立場的分化,導致網絡空間治理陷入困境,為網絡空間治理的建章立制帶來極大挑戰。另外,國際社會對網絡空間及其治理的複雜性缺乏清晰、統一的認知,由此而造成的片面立場和單一政策進一步加劇了治理困境。面對上述複雜情勢,約瑟夫·奈(Joseph Nye)試圖通過借鑒環境治理領域的機制複合體理論來解釋網絡空間治理的實踐,通過多個不同的治理機制組成的鬆散耦合複合體來分析網絡空間治理。 [②] 這為分析網絡空間治理形勢提供了一個有益的視角,即網絡空間治理是由多個而非單一的治理機制組成,各種機制之間的相互作用對治理產生影響。本文擬從更加宏觀的視角來審視網絡空間治理髮展的進程,並試圖探索網絡空間博弈背後的理念演變,同時分析政府、私營部門、公民社會等治理行為體在國際、國內兩個層面的複雜關係。在此基礎之上,探討中國的應對措施和參與網絡空間治理的戰略。


網絡空間治理的進程伴隨著各國政府之間的博弈過程。根據各國政府在網絡技術、網絡能力和網絡使用度等方面的情況,可以將其劃分為信息發達國家、信息發展中國家和信息不發達國家三類。 [③] 也有國際組織以網絡就緒度(Readiness)為指標衡量各國的信息化程度。這種排名基本上與傳統的發達、發展中以及不發達國家的三分法相重疊,當然也存在個別發展中國家的信息化水平上升到發達國家行列,或部分發展中國家的信息化水平跌落到不發達國家的水平。因此,按照信息發達國家、發展中國家和不發達國家的三分法來劃分在學術上更加精確。網絡空間治理的力量博弈主要有三個方面:一是信息發達國家與信息發展中國家在網絡權歸屬、網絡資源分配方面的博弈;二是非政府行為體與政府之間就互聯網關鍵資源控制、網絡安全與自由等問題的博弈;三是作為網絡空間中的主導國家,美國政府聯合其境內的私營部門、市民社會與其他國家之間在互聯網關鍵資源歸屬等問題上的博弈(圖1)。

第一階段是早期的互聯網治理時期,這大致從國際互聯網的形成初期到聯合國召開信息社會世界峰會(World Summit on Information Society, WSIS)為止;該峰會分為2003年日內瓦會議和2005年突尼斯議程兩個階段。信息社會世界峰會表面上表現為各國政府與私營部門和市民社會之間的鬥爭,實質上則是美國與其他國家就互聯網控制權而展開的博弈。
這一時期是互聯網快速發展的階段,大量新的技術及技術標準被創造出來,美國政府藉機大力推動信息技術發展,並製定了一系列國際技術標準、行業和產業規範。而信息發展中國家還處於學習、借鑒階段,這使美國等發達國家在該領域處於絕對強勢地位。 [④] 這一階段的互聯網治理主要圍繞互聯網域名註冊與解析及其相應的13台根服務器控制權、互聯網協議(IP)地址分配等關鍵資源展開爭奪。美國幾乎控制了互聯網標準制定和管理的所有國際組織和核心企業,並拒絕將相關管理職能國際化或交由聯合國專門機構管理。 [⑤] 因此,在信息社會世界峰會上,儘管面臨來自聯合國、信息發展中國家甚至歐洲國家的壓力,美國依然拒絕交出國際互聯網管理權。進入21世紀後,以中國為代表的信息發展中國家的網絡科技力量不斷提升,它們所擁有的域名、用戶等互聯網資源已經超過了信息發達國家,但在互聯網治理中的代表性遠遠不足,因此對現有互聯網治理體現的合法性提出了質疑。
第二階段是網絡空間治理的政治競爭和主權競爭階段,有人稱之為政府在網絡空間的“回歸”階段。這一階段從信息社會世界峰會到2011年。 2011年,中國、俄羅斯等國向第66屆聯大提交了“信息安全國際行為準則”,主張聯合國在網絡空間治理中發揮主導作用。同年,美英等國政府主導的全球網絡空間治理大會(Global Cyber​​space Conference),又稱倫敦進程(London Process)正式召開。
這一階段網絡空間治理博弈的特點是,隨著網絡技術的不斷突破及其對現實社會的顛覆性變革,網絡空間已經成為人類社會的“第五戰略空間”。圍繞網絡空間中秩序、權力與財富的分配,信息發達國家與信息發展中國家在下列問題上產生了嚴重分歧:網絡空間屬性是“全球公域”還是“主權領域”;治理手段是政府主導的“多邊治理”,還是非政府行為體主導的多利益攸關方(Multi-stakeholder)模式;治理文化是西方主導的“一元文化”,還是平等協商的“多元文化”。 [⑥] 這一時期的矛盾焦點還集中體現在信息內容的自由流通領域,希拉里·克林頓就任美國國務卿時,針對互聯網自由發表了多次講話,鼓吹美國的互聯網自由戰略。在始於2010年年底的西亞北非動蕩之中,美國政府與社交媒體網站在背後所扮演的角色引起了信息發展中國家的廣泛關注,並加強了對互聯網的管理。 [⑦]
第三階段從“棱鏡門事件”之後一直到現在,這一階段的競爭更加聚焦網絡空間的安全治理。 “棱鏡門事件”使美國在網絡空間治理領域的道德製高點遭受質疑、領導力下降,迫使其在推動網絡空間治理中放低姿態。與此同時,網絡空間安全形勢進一步惡化,各國面臨的安全威脅進一步加大。在經歷了“棱鏡門事件”初期的激烈對抗之後,信息發達國家與信息發展中國家均意識到維護網絡空間的安全需要各國的共同參與,沒有任何國家可以單獨主導網絡空間治理進程。信息發達國家與信息發展中國家在認知層面的差距逐漸縮小,對抗性舉措減少,合作的空間開始增長。
其次,“棱鏡門事件”引起了政府與私營部門、市民社會之間在網絡安全、公民隱私等問題上的激烈博弈。美國國家安全局前僱員愛德華·斯諾登揭露了一個包括“棱鏡”、“X關鍵分”(X-Keyscore)、“美景”(Fairview)、“核心”(Main core)等近10個監控項目在內的監控體系,該監控體係由國家安全局、中央情報局、聯邦調查局等多個情報機構參與,幾乎覆蓋了網絡空間的社交網絡、郵件、即時通訊、網頁、影片、照片等所有信息。 [⑧] 國家安全局要求微軟、谷歌、臉譜等9家主要全球互聯網企業向監控項目開放數據庫以便開展數據監控。在“棱鏡門事件”曝光後,微軟、谷歌、臉譜等企業向法院公開起訴聯邦政府。 [⑨] 市民社會也紛紛行動起來,反對大規模數據監控。美國市民社會聯盟在網上發起“停止監視我們”(Stop Watch Us)的行動,向美國政府施加壓力,得到數万網民在網站上的簽名、留言及數百個公民團體的響應,他們通過組織遊行示威、向國會請願、發起網絡倡議等方式配合該行動。 [⑩]
在“棱鏡門事件”引發了其他國家對與美國政府合作開展監控項目ICT企業的不滿,各國紛紛採取新的措施保障網絡空間安全。例如,中國政府加快了網絡空間的法制化進程,並開始討論網絡安全設備自主可控的指導思想、制定了網絡安全審查辦法,在先後出台的《國家安全法》、《反恐怖主義法》、 《網絡安全法(草案)》和《刑法修正案(九)》中都大幅增加了涉及網絡安全的條款。這些舉措引起了美國信息通信技術企業的嚴重關切,並遊說美國政府對中國施壓,要求中國政府取消相關規定,如《反恐怖主義法》第十八條中規定“電信業務經營者、互聯網服務提供者應當為公安機關、國家安全機關依法進行防範、調查恐怖活動提供技術接口和解密技術支持和協助”。 [11] 儘管從政府角度看,這些舉措有助於維護網絡安全和國家安全,但在私營部門看來,上述規定的舉措不僅將增加技術上的投入,也會大幅度增加成本。只要網絡空間治理未實現突破,政府與私營部門、市民社會之間的博弈會繼續存在,並在一定程度上將演變為國家間博弈。
最後,美國政府與其境內的私營部門、市民社會之間結盟與其他國家在互聯網關鍵資源歸屬問題上的博弈。互聯網關鍵資源包括:IP地址分配、協議參數註冊、通用頂級域名(gTLD)系統管理,國家和地區頂級域名(ccTLD)系統的管理及根服務器系統的管理和時區數據庫管理等。有學者形像地用掌握網絡空間中的“封疆權”來形容互聯網名稱與數字地址分配機構(Internet Corporation for Assigned Names and Numbers, ICANN)在網絡空間治理中的地位。 [12]

由於歷史的原因,這些資源一直由美國國家通信與信息管理局(National Telecommunication and Information Administration, NTIA)下屬的互聯網數字分配機構(Internet Assigned Numbers Authority, IANA)負責管理,NTIA通過定期與ICANN簽訂合同,授權其管理IANA的職能。因此,可以認為美國政府控制著互聯網的關鍵資源。聯合國任命的互聯網治理工作組(WGIG)在報告中指出,美國政府單方面控制著如根區文件在內的互聯網關鍵資源。 [13] 國際社會對這種情況一直不滿,WGIG報告中提出了四種方案以取代既有架構,希望通過政府間組織或全球性機構來接管互聯網關鍵資源。 [14] 對於ICANN來說,雖然一直尋求獨立於美國政府之外並與之開展了多次爭奪,但它更關注的是如何避免其他政府間組織或機構接管或取代其地位。彌爾頓·穆勒將這種現象描述為“一些網絡自由主義者甚而最終轉變成了國家主義的秘密支持者,因為只要被挑戰的國家是他們的祖國,他們就轉而為美國辯護,允許其控制、主導互聯網。”[15]
因此,在一些情況下,ICANN選擇與美國政府“結盟”共同阻止其他國家或政府間組織影響其治理結構。在ICANN的組織架構和決策體制中,各國政府代表所在的政府諮詢委員會(Government Advisory Committee, GAC)只有資格提名一名不具有表決權的聯絡員。信息發展中國家認為,作為一種互聯網治理的國際機制,在ICANN中來自信息發展中國家的代表性不足,在其未來的管理架構中,應當體現政府的職責和權力,增加政府諮詢委員會的權限。但ICANN多次表示不會接受這種改變。對於這種情況,無論是在政府諮詢委員會中,還是在ICANN的全體會議上,美國政府代表與ICANN的官方立場高度一致。直到“棱鏡門事件”爆發,美國政府才迫於多方面壓力宣布重啟ICANN的國際化進程,這將網絡空間治理博弈導向了新的階段。


隨著網絡空間治理進程的推進,各方對網絡空間屬性的認知逐漸達成共識,並由此使其在治理方法、路徑上的分歧縮小​​。特別是在認知層面,各國對網絡空間的認知由基於不同的政治、經濟、文化背景,強調各自的獨特性轉向基於網絡空間的客觀屬性和規律,強調不同觀點之間的融合。 [16] 網絡空間的互聯、共享屬性決定了零和博弈不適用於網絡空間,網絡空間的安全、發展、自由是政府、私營部門和市民社會所追求的共同目標。同時,安全、發展、自由這三個議題的相互制約關係,使得任何一方都不能忽視其他行為體的利益,而追求自身的絕對利益。正如習近平主席2015年12月16日在第二屆世界互聯網大會(World Internet Conference, WIC)開幕式的主題演講中指出:“在信息領域沒有雙重標準,各國都有權維護自己的信息安全,不能一個國家安全而其他國家不安全,一部分國家安全而另一部分國家不安全,更不能犧牲別國安全謀求自身所謂絕對安全”。 [17] 這一立場反映了網絡空間治理的上述特殊屬性。由此,國際社會也逐步意識到,沒有任何一方可以主導網絡空間治理進程。
首先,美國的網絡空間戰略調整與ICANN國際化進程將推動網絡空間治理架構的重大轉型。面臨重重壓力,美國通過部分放棄互聯網關鍵資源的直接控制權,為其網絡空間國際戰略的調整做準備。 [18] 2014年3月14日,美國商務部下屬的NTIA宣布將放棄對ICANN的控制,並在移交聲明中指出,將由ICANN管理層組織全球多利益攸關方討論接收問題,但明確拒絕由聯合國或其他政府間組織接管。 [19] ICANN自成立以來一直在尋求自己的獨立地位,ICANN國際化的目標不僅是要擺脫美國政府的製約,同時還要確保在美國政府放權後,不會被其他國家和政府間組織接管。因此,ICANN既需要與美國政府達成協議以保證自己的獨立性,也要與其他國家政府展開博弈,避免其國際化遭到強烈反對。
其次,聯合國在網絡空間治理中的作用持續提升,將有力地推動網絡空間治理架構和規範的建設步伐。通過聯合國信息安全政府專家組(GGE)的努力,國際社會在網絡空間的行為規範和建立信任措施等方面也取得了重要突破。 2013年6月,聯合國發表了一份由15個國家的代表組成的專家組的報告。報告首次明確了“國家主權和源自主權的國際規範及原則適用於國家進行的通信技術活動,以及國家在其領土內對通信技術基礎設施的管轄權。”同時,報告進一步認可了“聯合國憲章在網絡空間中的適用性”。 [20] “各國在努力處理通信技術安全問題的同時,必須尊重《世界人權宣言》和其他國際文書所載的人權和基本自由。”[21] 與2010年的專家組報告相比,上述內容分別作為2013年報告的第20和21條款出現,這是一個巨大的進步,表明信息發達國家和信息發展中國家在網絡空間治理認知理念的兼容性不斷提高。 2015年7月,聯合國關於從國際安全的角度看信息和電信領域的發展政府專家組公佈了第三份關於網絡空間國家行為準則的報告。這份報告在保護網絡空間關鍵基礎設施、建立信任措施、國際合作等領域達成了原則性共識。信息發展中國家關心的網絡主權進一步得到明確,信息發達國家主張的國際法特別是武裝衝突法在網絡空間中的適用也寫入其中。 [22]


在信息發達國家與信息發展中國家,政府、私營部門和市民社會等圍繞網絡空間治理的博弈從衝突轉向融合的背後,反映了網絡空間治理理念的持續演變。儘管圍繞網絡空間治理的博弈主要是為了爭奪網絡空間的權力與財富,但行為體對治理的主體、客體和方法的不同認知對治理的衝突與融合產生了重要影響。微軟首席研究及戰略官克瑞格·蒙迪(Craig Mundie)在第七屆中美互聯網論壇上就曾指出,“中美雙方在網絡空間的誤解很大程度上是由於對’互聯網治理’和’網絡空間治理’兩個概念的混淆所導致”。 [23] 同樣,網絡空間治理博弈和衝突也反映了上述兩種治理概念之間的衝突。
互聯網治理被認為屬於一種由非政府行為體主導的多利益攸關方治理模式,但網絡空間治理也需要政府和政府間組織的參與和協調。互聯網治理項目(Internet Governance Project, IGP)將互聯網治理定義為“所有者、運營商、開發者和用戶共同參與的一個由互聯網協議所聯接起來的與網絡相關的決策,包括確立政策、規則和技術標準的爭端解決機制,制定資源分配和全球互聯網中人類行為的標準。”[24] 上述定義包括三個方面,即技術標準和協議的接受和認可,域名和IP地址等互聯網資源的分配,人類的互聯網行為產生的垃圾郵件、網絡犯罪、版權和商標爭議、消費者保護問題、公共部門和私人的安全問題等相關的規定、規則和政策等。勞拉·迪娜尼斯(Laura DeNardis)提出要按照互聯網傳輸的TCP/IP協議的層級,並根據不同層級的不同功能構建互聯網模式,依據功能、任務和行為體分別討論互聯網資源控制、標准設定、網絡接入、網絡安全治理、信息流動、知識產權保護等六個層面的互聯網治理內容。 [25]
網絡空間治理從原先互聯網治理所強調的專業性、技術性領域轉向更廣泛的政治、安全和經濟範疇,政府和政府間組織在網絡空間治理中的重要性也日益凸顯。網絡空間是一個更廣泛的領域,它不僅包括互聯網,還包括網絡中傳輸的數據,網絡的用戶以及現實社會與虛擬社會的交互等。相對應的網絡空間治理則是一個更加寬泛的概念,它是“包括網絡空間基礎設施、標準、法律、社會文化、經濟、發展等多方面內容的一個範疇”。 [26] 它所包含的治理議題更加多元,面臨的挑戰也在不斷增加。如“棱鏡門事件”引發的對大規模數據監控的關注、政府在網絡空間開展的網絡行動導致的高持續性威脅(APT)、全球範圍內的數字鴻溝(Digital Divide)與數據貧困(Data Poverty )、網絡恐怖主義、網絡商業竊密等越來越多的治理議題已經超越了傳統的互聯網治理理念的範疇。
隨著網絡空間治理進程的推進,上述兩種治理理念和方法在碰撞中也開始不斷融合。約瑟夫·奈認為,網絡空間是由多個治理機制組成,其中互聯網治理聚焦於技術層面,是網絡空間治理的一個子集。應當根據不同的治理議題,構建不同的治理機制,讓不同的行為體來發揮主導作用。 [27] 治理觀念的融合還表現在各方對多利益攸關方治理模式共識的增加。 ICANN採用的是一種自下而上、基於共識基礎的決策過程,並主張限制政府作用的治理模式。 [28] 很多信息發展中國家最初對多利益攸關方治理模式持反對態度,強調應當採用政府主導的多邊治理模式。隨著治理進程的深入,信息發展中國家逐步接受多利益攸關方治理模式,只要政府的作用得到合理體現,這種觀點也在私營部門和市民社會代表中獲得越來越多的共識。政府、私營部門和市民社會根據各自的功能與責任來參與決策過程,不刻意將其他行為體排除在外,也不刻意追求個別行為體的領導權,體現出更加客觀和平衡的網絡空間治理理念。


自1994年接入國際互聯網起,中國就制定了各種形式的網絡國際政策融入國際網絡空間體系。這一方面是擴大開放的需要,希望通過國際合作學習、引進國外先進的技術標準;另一方面是信息技術的驅動,融入全球化必須要全方位參與國際體系。 [29] 此外,隨著中國在國際事務中的影響力越來越大以及對網絡的依存度上升,主動參與網絡空間治理也是維護國家利益的重要路徑和方式。中國的網絡政策在很大程度上受到國際網絡空間治理形勢的影響,並在與國際網絡空間治理制度的互動中得到發展和提升,呈現出多領域、多層次和多主體的特點。
第二,中國的網絡空間國際政策覆蓋了雙邊、地區、多邊和國際等多個層級。從雙邊層面來看,中國與韓國、英國、澳大利亞等國家建立了政府間對話合作機制,這些合作不僅覆蓋網絡安全、數字經濟和發展等內容,還成為雙邊外交關係的重要內容和支撐。此外,中美、中俄之間在網絡安全領域開展了不同程度的建立信任措施(Confidence Building Measures, CBMs)。 [30] 在地區層面,中國與東盟、上合組織、歐盟、阿盟等地區組織和國家之間建立了多種形式的網絡對話合作機制。 2009年中國政府分別與東盟和上合組織成員國簽訂了《中國—東盟電信監管理事會關於網絡安全問題的合作框架》和《上合組織成員國保障國際信息安全政府間合作協定》。 [31] 中國還積極參與東盟地區論壇網絡安全工作組的工作,並於2013年9月在北京召開了東盟地區論壇“加強網絡安全措施研討會——法律和文化視角”。會議倡議互聯網的發展需要法律規則的引領,也需要促進和尊重文化多樣性,各方應在網絡安全領域加強交流、增進互信、推進合作,共同構建和平、安全、開放、合作的網絡空間。 [32] 最後,中國還積極參與多邊和國際層面的網絡空間治理機制,無論是聯合國框架下的信息安全政府專家組、國際電信聯盟、信息社會世界峰會、互聯網治理論壇,還是聯合國框架之外的倫敦進程、網絡空間多利益攸關方會議等機制,中國都是主要參與者;此外,中國還通過召開世界互聯網大會來開展網絡空間的主場外交。中國還與俄羅斯、烏茲別克斯坦等上合組織成員國共同向聯合國大會提交了兩個版本的“信息安全國際行為準則”。 [33] 中國也是全球互聯網治理聯盟的主要參與方,國家互聯網信息辦公室(網信辦)主任魯煒和阿里巴巴集團董事局主席馬雲當選為該聯盟的委員。
網絡空間治理的力量博弈變化給中國的網絡空間國際戰略帶來了多重挑戰:一是信息發達國家將繼續主導網絡空間治理博弈的方向,這對中國的網絡空間國際戰略構成挑戰;二是由於缺乏高級互聯網治理人才,導致中國在互聯網國際組織中的代表性嚴重不足;三是網絡空間治理博弈轉向強調能力建設(Capacity Building)、最佳實踐(Best Practice)等方向,將給中國帶來競爭壓力。這些問題和挑戰對中國網絡空間國際戰略將產生較大衝擊,若處理不當,會對網絡強國戰略的實施造成負面影響。
第一,信息發達國家繼續主導網絡空間治理博弈方向對中國國際戰略構成的挑戰。網絡空間全球治理是通過各種形式的治理機制發揮作用,機制的構建取決於各行為體之間的談判,談判的籌碼不僅取決於各行為體的權力大小,還與各方在網絡空間全球治理中的議程設置能力息息相關。 [34] 按照約瑟夫·奈的定義,前者可稱之為“硬權力”,後者是“軟權力”。 [35] 信息發達國家在這兩個領域的優勢明顯,特別是在通過選擇性或者優先設置議程左右網絡空間治理的機制構建。比如在網絡安全治理中,美國依靠其議程設置能力阻止國際社會將大規模數據監控列為治理議程,同時將其重點關切的網絡經濟竊密設置為優先議程。此外,信息發達國家在設置網絡人權議程時,將重點置於自由領域,而民主(一國一票)、平等(大小國家擁有同等話語權)等同樣重要的議題則被排除在議程之外。不僅如此,對於各國在“棱鏡門事件”後要求加強行使網絡主權的趨勢,美國則提出“數據本地化”(Data Localization)這一議程以規避在全球治理機制中討論網絡主權。與信息發達國家相比,信息發展中國家在議程設置能力上還存在較大差距,缺乏主動設置議程的能力。近年來,隨著中國、巴西、印度等國先後建立了各種網絡空間治理機制,新興大國在網絡空間全球治理中的議程設置能力不斷增強。但總體而言,中國與信息發達國家在治理能力方面的差距依舊存在,並將影響中國通過國際機制維護自身國家利益,以及表達自身關切。

确立中国网络空间国际战略的基本路径与中国整体对外战略强调的融入国际体系,并推动改革国际体系的宏观目标相一致。[36] 为应对复杂的网络空间治理博弈,中国一方面要加强能力建设,并注重将能力转化为参与网络空间全球治理的影响力;另一方面在网络安全与开放之间寻求平衡,通过参与国际网络空间建章立制来维护自己的合法权益,避免过度安全化带来的负面影响;并加强网络强国战略与网络空间国际战略之间的战略互动,形成相互支持的网络空间战略体系。
第二,着重培养参与网络空间治理的国际化人才。国际互联网治理组织多为非政府组织,其采用的多利益攸关方治理模式通常要求从互联网社群中选拔高级管理人才,根据选拔对象对互联网技术、治理所作出的贡献来来担任相应的高级管理职务,而非传统政府间组织的一国一票或按照人口、经济比例来分配名额。以ICANN为例,其现有的管理架构是由董事会和3个支持组织、3个咨询委员会及2个技术咨询机构组成。董事会由16名具有表决权的成员和5名不具有表决权的联络员组成,除ICANN总裁之外,其余15个名额分别来自支持组织、一般会员咨询委员会、区域一般会员组织和提名委员会。要想当选为有投票权的委员,必须要通过自下而上的提名和选举。因此,中国应当理顺体制和机制,积极向ICANN等国际非政府组织输送人才,鼓励互联网企业、行业组织和学术机构积极参与ICANN、IETF、互联网架构委员会(Internet Architecture Board, IAB)等机构的人才选拔,以此来提升在互联网国际组织中的代表性和发言权,并提高中国对互联网治理的影响力。
第三,加强网络强国战略与网络空间国际战略之间的战略互动。中国在“十三五”规划建议中正式提出网络强国战略,并从技术创新、网络文化、网络基础设施、网络安全和信息化建设、国际合作五个方面着手,推进网络强国建设。[37] 网络强国战略中多次提到了对外开放、积极参与国际互联网治理,甚至将国际合作作为单独一章。由此可见,网络空间国际战略与网络强国战略之间相互融合、相互支撑。两者的有效互动,关系到中国对网络空间的开放、安全与发展关系的处理。从双层博弈的角度来看,任何一个国家的战略都面临外部形势和内部利益集团的双重约束,过度强调开放或者安全都不利于整体国家安全和利益。强化网络强国战略与网络空间国际战略之间的互动,有助于提高决策者对于网络空间的安全与开放,网络空间的安全、发展、与开放之间关系的认知,打破双重约束,制定更加符合客观规律的政策。

Original URL:


中央網信辦發布《國家網絡安全事件應急預案》Communist Chinese Party issues National Network Security Incident Contingency Plans


Communist Chinese Party issues National Network Security Incident Contingency Plans

2017年06月27日 17:16中国网信网

Notice of the Central Network Office on Printing and Distributing the Emergency Plan for National Network Security Incidents

China Network Office issued a document [2017] No. 4

Provinces, autonomous regions and municipalities, Xinjiang Production and Construction Corps Party Committee Network Security and Information Leading Group, the central and state organs of the ministries, the people’s organizations:

“National network security incident contingency plans” has been the central network security and information leading group agreed, is now issued to you, please carefully organize the implementation.

Central Network Security and Information Leading Group Office

January 10, 2017

National network security incident contingency plans

table of Contents

1 General

1.1 Purpose of preparation

1.2 Preparation basis

1.3 Scope of application

1.4 Event rating

1.5 working principle

Organizational Structure and Responsibilities

2.1 Leadership and Responsibilities

2.2 offices and responsibilities

2.3 Responsibilities of various departments

2.4 duties of provinces (autonomous regions and municipalities)

3 monitoring and early warning

3.1 Early warning classification

3.2 Early warning monitoring

3.3 Early warning judgment and release

3.4 Early warning response

3.5 warning release

4 emergency treatment

4.1 Event report

4.2 Emergency response

4.3 Emergency end

5 Investigation and evaluation

6 to prevent work

6.1 Daily management

6.2 Walkthrough

6.3 Advocacy

6.4 Training

Precautions during important events

7 safeguards

7.1 Institutions and personnel

7.2 technical support team

7.3 expert team

7.4 Social resources

7.5 base platform

7.6 Technology research and development and industry promotion

7.7 International cooperation

7.8 material security

7.9 Funds protection

7.10 Responsibility and rewards and punishments

8 Annex

8.1 Project Management

8.2 Explanation of the plan

8.3 Implementation time of the plan

1 General

1.1 Purpose of preparation

Establish and improve the national network security incident emergency mechanism to improve the ability to deal with network security events, prevent and reduce network security incidents caused by the loss and harm, protect the public interest, safeguard national security, public safety and social order.

1.2 Preparation basis

“People’s Republic of China Incident Response Law”, “People’s Republic of China Network Security Law”, “National General Public Emergency Plan”, “Emergency Emergency Plan Management Measures” and “Information Security Technology Information Security Event Classification Classification Guide “(GB / Z 20986-2007) and other relevant provisions.

1.3 Scope of application

The cybersecurity incident referred to in this plan refers to events that cause adverse effects to the society due to human causes, hardware and software defects or failures, natural disasters, etc., which cause harm to the network and the information system or the data in it, Network attack events, information corruption events, information content security incidents, device facility failures, catastrophic events, and other events.

This plan applies to the work of network security events. Among them, the information content security incident response, to develop a special plan.

1.4 Event rating

Network security events are divided into four levels: particularly significant network security events, major network security incidents, larger network security events, and general network security events.

(1) meets one of the following scenarios for a particularly significant cyber security incident:

① Significant network and information systems suffer from particularly serious system losses, resulting in large paralysis of the system and loss of business processing capacity.

② State secret information, important sensitive information and key data loss or theft, tampering, counterfeiting, constitute a particularly serious threat to national security and social stability.

③ other network security incidents that pose a particularly serious threat to national security, social order, economic construction and public interest, causing particularly serious impact.

(2) meets one of the following scenarios and does not meet significant network security incidents for significant network security incidents:

① important network and information systems suffered serious system losses, resulting in a long time the system interrupted or partial paralysis, business processing capacity has been greatly affected.

② State secret information, important sensitive information and key data loss or theft, tampering, counterfeiting, posing a serious threat to national security and social stability.

③ other serious threats to national security, social order, economic construction and public interest, causing serious impact on network security incidents.

(3) meet one of the following conditions and does not meet significant network security incidents for larger network security events:

① important network and information systems suffer from greater system loss, resulting in system interruption, significantly affect the system efficiency, business processing capacity is affected.

② State secret information, important sensitive information and key data loss or theft, tampering, counterfeiting, posing a serious threat to national security and social stability.

③ other on the national security, social order, economic construction and public interests constitute a more serious threat, resulting in more serious impact of network security incidents.

(4) In addition to the above, the national security, social order, economic construction and public interests constitute a certain threat, resulting in a certain impact on the network security incidents for the general network security incidents.

1.5 working principle

Adhere to the unified leadership, grading responsibility; adhere to the unified command, close coordination, rapid response, scientific treatment; adhere to the prevention of prevention, prevention and emergency combination; adhere to who is responsible for who, who is responsible for running, give full play to all forces together Prevention and disposal of network security incidents.

Organizational Structure and Responsibilities

2.1 Leadership and Responsibilities

Under the leadership of the Central Network Security and Information Leading Group (hereinafter referred to as the “Leading Group”), the Office of the Central Network Security and Information Leading Group (hereinafter referred to as the “Central Network Office”) coordinates the organization of national network security incident response, Establish and improve the cross-sectoral linkage mechanism, the Ministry of Industry and Information Technology, the Ministry of Public Security, the State Secrecy Bureau and other relevant departments in accordance with the division of responsibilities responsible for the relevant network security incident response. If necessary, the establishment of national network security incident emergency headquarters (hereinafter referred to as “the headquarters”), responsible for the special major network security incident handling organization and coordination and coordination.

2.2 offices and responsibilities

National Network Security Emergency Office (hereinafter referred to as “emergency office”) is located in the central network letter office, the specific work by the central network letter to do Network Security Coordination Bureau. Emergency Office is responsible for the network security emergency cross-sectoral, cross-regional coordination of the work and the headquarters of the transactional work, organization and guidance of national network security emergency technical support team to do emergency technical support work. The relevant departments are responsible for the relevant work of the Secretary-level comrades as liaison officers, contact emergency office work.

2.3 Responsibilities of various departments

The central and state departments and departments in accordance with their duties and authority, responsible for the sector, the industry network and information systems network security incident prevention, monitoring, reporting and emergency response.

2.4 duties of provinces (autonomous regions and municipalities)

The administrative departments of the provinces (autonomous regions and municipalities) shall coordinate and organize the prevention, monitoring, reporting and emergency handling of network security incidents in the regional network and information systems under the unified leadership of the Party Committee’s Network Safety and Information Leading Group.

3 monitoring and early warning

3.1 Early warning classification

The network security event warning level is divided into four levels: from high to low, followed by red, orange, yellow and blue, respectively, corresponding to occur or may occur particularly significant, significant, large and general network security events.

3.2 Early warning monitoring

The units in accordance with the “who is responsible for who is responsible for who who is responsible for” the requirements of the organization of the unit construction and operation of the network and information systems to carry out network security monitoring. Focus on industry executives or regulatory organizations to guide the organization to do the work of network security monitoring. The provinces (autonomous regions and municipalities) network letter department with the actual situation in the region, the organization of the region to carry out the network and information systems security monitoring. Provinces (autonomous regions and municipalities), the departments will be important monitoring information reported to be urgent, emergency office to carry out inter-provincial (district, city), cross-sectoral network security information sharing.

3.3 Early warning judgment and release

Provinces, autonomous regions and municipalities, departments of the monitoring of information on the judge, that the need for immediate preventive measures, should promptly notify the relevant departments and units, may occur on major and above network security incidents in a timely manner to the emergency response report. Provinces (autonomous regions and municipalities), the departments can be based on monitoring and judging the situation, the release of the region, the industry’s orange and the following warning.

Emergency organization to determine, determine and publish red warning and involving multi-province (district, city), multi-sectoral, multi-industry early warning.

Early warning information includes the category of the event, the level of the alert, the starting time, the possible scope, the warning, the measures and time limits that should be taken, the issuing authority, and so on.

3.4 Early warning response

3.4.1 Red warning response

(1) the emergency response organization organization early warning response work, contact experts and relevant agencies, organizations to track the development of the situation to study and formulate preventive measures and emergency work program, coordination of resource scheduling and departmental linkage of the preparatory work.

(2) the relevant provinces (autonomous regions and municipalities), the Department of network security incident emergency command agencies to implement 24 hours on duty, the relevant personnel to maintain communication links. Strengthen the network security incident monitoring and development of information collection work, organize and guide the emergency support team, the relevant operating units to carry out emergency treatment or preparation, risk assessment and control work, the important situation retribution urgent.

(3) the national network security emergency technical support team into the standby state, for the early warning information research to develop a response program, check emergency vehicles, equipment, software tools, to ensure a good condition.

3.4.2 Orange warning response

(1) the relevant provinces (autonomous regions and municipalities), departmental network security incident emergency command agencies to start the corresponding contingency plans, organize early warning response, do risk assessment, emergency preparedness and risk control.

(2) the relevant provinces (autonomous regions and municipalities), departments in a timely manner to the situation of the situation reported to the emergency response. The Emergency Office is closely following the development of the matter and timely notification of the relevant provinces (autonomous regions and municipalities) and departments.

(3) the national network security emergency technical support team to keep in touch, check emergency vehicles, equipment, software tools, to ensure that in good condition.

3.4.3 yellow, blue warning response

The relevant regional and departmental network security incident emergency command agencies to start the corresponding contingency plans to guide the organization to carry out early warning response.

3.5 warning release

Early warning release departments or regions according to the actual situation, to determine whether to lift the warning, timely release warning release information.

4 emergency treatment

4.1 Event report

After the network security incident occurs, the incident unit should immediately start the emergency plan, the implementation of disposal and timely submission of information. The relevant regions and departments immediately organize the early disposal, control the situation, eliminate hidden dangers, at the same time organization and judgment, pay attention to save the evidence, do a good job of information communication. For the primary judgment is particularly significant, major network security incidents, and immediately report to the emergency office.

4.2 Emergency response

The network security incident emergency response is divided into four levels, corresponding to particularly significant, significant, large and general network security events. Level I is the highest response level.

4.2.1 Class I response

Is a particularly important network security incidents, timely start I-level response, the establishment of the headquarters, the implementation of emergency response to the unified leadership, command and coordination responsibilities. Emergency Office 24 hours on duty.

The relevant departments (district, city), the department emergency response agencies into the emergency state, in the command of the unified leadership, command and coordination, responsible for the province (district, city), the department emergency work or support security work, 24 hours on duty, And sent to participate in emergency office work.

The relevant provinces (autonomous regions and municipalities), departments to track the development of the situation, check the scope of the impact of the situation in time to change the situation, the progress of the report retribution. The headquarters of the response to the work of the decision-making arrangements, the relevant provinces (autonomous regions and municipalities) and departments responsible for the organization and implementation.

4.2.2 Class II response

The level response of the network security incident is determined by the relevant province (district, city) and the department according to the nature and circumstances of the incident.

(1) the incident occurred in the province (district, city) or department of the emergency command agencies into the emergency state, in accordance with the relevant emergency plans to do emergency work.

(2) the incident occurred in the province (district, city) or departments in a timely manner to change the situation developments. The emergency office will keep the relevant matters and the relevant departments and departments in a timely manner.

(3) the disposal of the need for other relevant provinces (autonomous regions and municipalities), departments and national network security emergency technical support team with the support and business emergency response to be coordinated. Relevant provinces (autonomous regions and municipalities), departments and national network security emergency technical support team should be based on their respective responsibilities, and actively cooperate to provide support.

(4) The relevant provinces (autonomous regions and municipalities) and departments shall, in accordance with the notification of the emergency office, strengthen the prevention and prevent the greater impact and losses on the basis of their actual and targeted efforts.

4.2.3 Class Ⅲ, Ⅳ level response

Event areas and departments in accordance with the relevant plans for emergency response.

4.3 Emergency end

4.3.1 End of class I response

Emergency Office to make recommendations, reported to the headquarters after approval, timely notification of the relevant provinces (autonomous regions and municipalities) and departments.

4.3.2 Level II response ends

(Autonomous regions and municipalities) or departments, the emergency response, emergency response to the relevant provinces (autonomous regions and municipalities) and departments.

5 Investigation and evaluation

Special major network security incidents by the emergency branch of the relevant departments and provinces (autonomous regions and municipalities) to investigate and summarize the assessment, according to the procedures reported. Significant and the following network security incidents are organized by the event area or department to organize their own investigation and summary assessment, including the major network security incident related to the summary report of the report retribution. Summary of the investigation report should be the cause of the event, nature, impact, responsibility analysis and evaluation, put forward the views and improvement measures.

The investigation and summary of the incident is carried out in principle within 30 days after the end of the emergency response.

6 to prevent work

6.1 Daily management

All localities and departments should do a good job in the day-to-day prevention of network security incidents, formulate and improve relevant emergency plans, do a good job of network security inspection, risk investigation, risk assessment and disaster recovery, improve the network security information notification mechanism, take timely and effective measures, Reduce and avoid the occurrence and harm of network security incidents, improve the ability to deal with network security incidents.

6.2 Walkthrough

Central Network letter to coordinate the relevant departments to organize regular exercises, test and improve the plan to improve the actual combat capability.

The provinces (autonomous regions and municipalities), departments at least once a year to organize a plan exercise, and the exercise situation reported to the central network letter to do.

6.3 Advocacy

All localities and departments should make full use of various media and other effective propaganda forms to strengthen the publicity and disposal of relevant laws, regulations and policies for the prevention and disposal of sudden network security incidents and carry out propaganda activities on basic knowledge and skills of network security.

6.4 Training

All localities and departments should regard the emergency knowledge of cyber security incidents as the training content of leading cadres and relevant personnel, strengthen the training of network security, especially network security contingency plans, and improve awareness and skills.

Precautions during important events

In the national important activities, during the meeting, the provinces (autonomous regions and municipalities), various departments to strengthen the network security incidents to prevent and emergency response to ensure network security. Emergency Office to coordinate the work of network security, according to the requirements of the relevant provinces (autonomous regions and municipalities), departments to start the red warning response. The relevant provinces (autonomous regions and municipalities), departments to strengthen network security monitoring and analysis of judgments, timely warning may cause significant impact on the risks and risks, key departments, key positions to maintain 24 hours on duty, timely detection and disposal of network security incidents.

7 safeguards

7.1 Institutions and personnel

All localities and departments, units to implement the network security emergency work responsibility system, the responsibility to implement specific departments, specific positions and individuals, and establish a sound emergency working mechanism.

7.2 technical support team

Strengthen the network security emergency technical support team building, do a good job of network security incident monitoring and early warning, prevention and protection, emergency response, emergency technical support work. Support network security enterprises to improve emergency response capabilities, to provide emergency technical support. The central network to do assessment of the development of accreditation standards, organizational assessment and identification of national network security emergency technical support team. All provinces (autonomous regions and municipalities), departments should be equipped with the necessary network security professional and technical personnel, and strengthen the national network security related technical units of communication, coordination, the establishment of the necessary network security information sharing mechanism.

7.3 expert team

The establishment of national network security emergency expert group, for the network security incident prevention and disposal of technical advice and decision-making recommendations. All regions and departments to strengthen their own team of experts, give full play to the role of experts in the emergency response.

7.4 Social resources

From the educational research institutions, enterprises and institutions, associations in the selection of network security personnel, pooling technology and data resources, the establishment of network security incident emergency service system to improve the response to particularly significant, major network security incidents.

7.5 base platform

All regions and departments to strengthen the network security platform and management platform for emergency management, so early detection, early warning, early response, improve emergency response capability.

7.6 Technology research and development and industry promotion

Relevant departments to strengthen network security technology research, and constantly improve the technical equipment, emergency response to provide technical support. Strengthen the policy guidance, focus on supporting network security monitoring and early warning, prevention and protection, disposal of rescue, emergency services and other directions to enhance the overall level of network security industry and core competitiveness, and enhance the prevention and disposal of network security event industry support capabilities.

7.7 International cooperation

Relevant departments to establish international cooperation channels, signed a cooperation agreement, if necessary, through international cooperation to deal with sudden network security incidents.

7.8 material security

Strengthen the network security emergency equipment, tools, reserves, timely adjustment, upgrade software hardware tools, and constantly enhance the emergency technical support capabilities.

7.9 Funds protection

The financial department provides the necessary financial guarantee for the emergency disposal of the network security incident. Relevant departments to use the existing policies and funding channels to support the network security emergency technical support team building, expert team building, basic platform construction, technology research and development, planning exercises, material security and other work carried out. All regions and departments for the network security emergency work to provide the necessary financial protection.

7.10 Responsibility and rewards and punishments

Implementation of Responsibility System for Emergency Work of Network Security Incident.

The central network letter office and the relevant regional and departmental network security incident emergency management work to make outstanding contributions to the advanced collective and individuals to commend and reward.

The central network and the relevant departments and departments do not follow the provisions of the formulation of plans and organizations to carry out exercises, late, false, concealed and owe the network security incidents important or emergency management work in other misconduct, dereliction of duty, in accordance with the relevant Provides for the responsible person to be punished; constitute a crime, shall be held criminally responsible.

8 Annex

8.1 Project Management

The plan is evaluated in principle once a year and revised in a timely manner according to the actual situation. The revision work is handled by the central network.

All provinces (autonomous regions and municipalities), departments and units shall, according to the plan, formulate or revise the contingency plans for the network security incidents in the region, the department, the industry and the unit.

8.2 Explanation of the plan

The plan is interpreted by the central network letter office.

8.3 Implementation time of the plan

The plan has been implemented since the date of issuance.


1. Network security event classification

2. Terminology

3. Network and information system loss degree description


Network Security Event Classification

Network security events are classified as unwanted program events, network attack events, information corruption events, information content security incidents, device facility failures, catastrophic events, and other network security incidents.

(1) Harmful program events are classified into computer virus events, worm events, Trojan events, botnet events, mixed program attack events, web embedded malicious code events, and other unwanted program events.

(2) network attacks are divided into denial of service attacks, backdoor attacks, vulnerability attacks, network scanning eavesdropping events, phishing events, interference events and other network attacks.

(3) information destruction events are classified as information tampering events, information fake events, information disclosure incidents, information theft events, information loss events and other information destruction events.

(4) Information content security incidents refer to the dissemination of laws and regulations through the Internet to prohibit information, organize illegal series, incite rallies or hype sensitive issues and endanger national security, social stability and public interest events.

(5) equipment and equipment failure is divided into hardware and software failure, peripheral protection facilities failure, man-made damage and other equipment and equipment failure.

(6) Disastrous events refer to network security incidents caused by other emergencies such as natural disasters.

(7) Other events refer to network security events that can not be classified as above.

Annex 2


First, the important network and information systems

The network and information systems that are closely related to national security, social order, economic construction and public interest.

(Reference: “Information Security Technology Information Security Event Classification and Classification Guide” (GB / Z 20986-2007))

Second, the important sensitive information

Information that is not related to national secrets but is closely related to national security, economic development, social stability and corporate and public interest, which, once unauthorized, is disclosed, lost, misused, tampered with or destroyed, may have the following consequences:

A) damage to national defense, international relations;

B) damage to State property, public interest and personal property or personal safety;

C) affect the state to prevent and combat economic and military spies, political infiltration, organized crime;

D) affect the administrative organs to investigate and deal with illegal, dereliction of duty, or suspected of illegal, dereliction of duty;

E) interfere with government departments to carry out administrative activities such as supervision, management, inspection and auditing impartially, hinder government departments from performing their duties;

F) endanger the national key infrastructure, government information system security;

G) affect the market order, resulting in unfair competition, undermining the laws of the market;

H) can be inferred from the state secret matter;

I) infringement of personal privacy, corporate trade secrets and intellectual property rights;

J) damage to the country, business, personal other interests and reputation.

(Reference: “Information Security Technology Cloud Computing Service Security Guide” (GB / T31167-2014))

Annex 3

Network and Information System Losses

Network and information system loss refers to the network security incidents due to network hardware and software, functions and data damage, resulting in system business interruption, so as to the loss caused by the organization, the size of the main consideration to restore the normal operation of the system and eliminate security incidents Negative effects are deducted as particularly serious system losses, severe system losses, greater system losses, and minor system losses, as follows:

A) Particularly serious systemic damage: a large area of ​​paralysis of the system, loss of business processing capacity, or confidentiality, integrity, availability of critical data, serious damage to the system, normal operation of the system and elimination of the negative impact of security incidents The price paid is very great, for the incident is unbearable;

B) Serious system loss: causing the system to be interrupted for a long time or partially paralyzed, greatly compromising its business processing capacity, or the confidentiality, integrity, availability of the critical data, the recovery of the system and the elimination of security incidents Negative effects are huge, but are affordable for the organization;

C) Larger system losses: causing system outages, significantly affecting system efficiency, affecting the operational capacity of important information systems or general information systems, or the confidentiality, integrity, availability of system critical data, and the restoration of the system The cost of running and eliminating the negative effects of security incidents is greater, but it is entirely affordable for the organization;

D) Smaller system losses: causing system interruption, affecting system efficiency, affecting system operational capacity, or confidentiality, integrity, availability of system critical data, restoring system uptime and eliminating security incidents The cost of the impact is less.

Original Mandarin Chinese:








目 錄

1 總則

1.1 編制目的

1.2 編制依據

1.3 適用範圍

1.4 事件分級

1.5 工作原則

2 組織機構與職責

2.1 領導機構與職責

2.2 辦事機構與職責

2.3 各部門職責

2.4 各省(區、市)職責

3 監測與預警

3.1 預警分級

3.2 預警監測

3.3 預警研判和發布

3.4 預警響應

3.5 預警解除

4 應急處置

4.1 事件報告

4.2 應急響應

4.3 應急結束

5 調查與評估

6 預防工作

6.1 日常管理

6.2 演練

6.3 宣傳

6.4 培訓

6.5 重要活動期間的預防措施

7 保障措施

7.1 機構和人員

7.2 技術支撐隊伍

7.3 專家隊伍

7.4 社會資源

7.5 基礎平台

7.6 技術研發和產業促進

7.7 國際合作

7.8 物資保障

7.9 經費保障

7.10 責任與獎懲

8 附則

8.1 預案管理

8.2 預案解釋

8.3 預案實施時間

1 總則

1.1 編制目的


1.2 編制依據

《中華人民共和國突發事件應對法》、《中華人民共和國網絡安全法》、《國家突發公共事件總體應急預案》、《突發事件應急預案管理辦法》和《信息安全技術信息安全事件分類分級指南》(GB/Z 20986-2007)等相關規定。

1.3 適用範圍



1.4 事件分級















1.5 工作原則


2 組織機構與職責

2.1 領導機構與職責


2.2 辦事機構與職責


2.3 各部門職責


2.4 各省(區、市)職責


3 監測與預警

3.1 預警分級


3.2 預警監測


3.3 預警研判和發布




3.4 預警響應

3.4.1 紅色預警響應




3.4.2 橙色預警響應




3.4.3 黃色、藍色預警響應


3.5 預警解除


4 應急處置

4.1 事件報告


4.2 應急響應

網絡安全事件應急響應分為四級,分別對應特別重大、重大、較大和一般網絡安全事件。 I級為最高響應級別。

4.2.1 Ⅰ級響應




4.2.2 Ⅱ級響應






4.2.3 Ⅲ級、Ⅳ級響應


4.3 應急結束

4.3.1 Ⅰ級響應結束


4.3.2 Ⅱ級響應結束


5 調查與評估



6 預防工作

6.1 日常管理


6.2 演練




6.3 宣傳


6.4 培訓


6.5 重要活動期間的預防措施


7 保障措施

7.1 機構和人員


7.2 技術支撐隊伍


7.3 專家隊伍


7.4 社會資源


7.5 基礎平台


7.6 技術研發和產業促進


7.7 國際合作


7.8 物資保障


7.9 經費保障


7.10 責任與獎懲




8 附則

8.1 預案管理



8.2 預案解釋


8.3 預案實施時間



1. 網絡安全事件分類

2. 名詞術語

3. 網絡和信息系統損失程度劃分說明















(參考依據:《信息安全技術信息安全事件分類分級指南》(GB/Z 20986-2007))



a) 損害國防、國際關係;

b) 損害國家財產、公共利益以及個人財產或人身安全;

c) 影響國家預防和打擊經濟與軍事間諜、政治滲透、有組織犯罪等;

d) 影響行政機關依法調查處理違法、瀆職行為,或涉嫌違法、瀆職行為;

e) 干擾政府部門依法公正地開展監督、管理、檢查、審計等行政活動,妨礙政府部門履行職責;

f) 危害國家關鍵基礎設施、政府信息系統安全;

g) 影響市場秩序,造成不公平競爭,破壞市場規律;

h) 可推論出國家秘密事項;

i) 侵犯個人隱私、企業商業秘密和知識產權;

j) 損害國家、企業、個人的其他利益和聲譽。





a) 特別嚴重的系統損失:造成系統大面積癱瘓,使其喪失業務處理能力,或系統關鍵數據的保密性、完整性、可用性遭到嚴重破壞,恢復系統正常運行和消除安全事件負面影響所需付出的代價十分巨大,對於事發組織是不可承受的;

b) 嚴重的系統損失:造成系統長時間中斷或局部癱瘓,使其業務處理能力受到極大影響,或系統關鍵數據的保密性、完整性、可用性遭到破壞,恢復系統正常運行和消除安全事件負面影響所需付出的代價巨大,但對於事發組織是可承受的;

c) 較大的系統損失:造成系統中斷,明顯影響系統效率,使重要信息系統或一般信息系統業務處理能力受到影響,或系統重要數據的保密性、完整性、可用性遭到破壞,恢復系統正常運行和消除安全事件負面影響所需付出的代價較大,但對於事發組織是完全可以承受的;

d) 較小的系統損失:造成系統短暫中斷,影響系統效率,使系統業務處理能力受到影響,或系統重要數據的保密性、完整性、可用性遭到影響,恢復系統正常運行和消除安全事件負面影響所需付出的代價較小。

美軍方憂慮中國信息戰 稱之為毛式網絡人民戰 // US Military Anxious & Worried About China’s Information Warfare – Mao-Style Network War is the People’s Warfare

US Military Anxious & Worried About China’s Information Warfare – Mao-Style Network War is the People’s Warfare

This article was originally published in the US Army “Military Intelligence” magazine July 7-9 months. The author Timothy Thomas is the US Army Lieutenant Colonel, now an analyst at the US Foreign Military Research Office (FMSO). The author graduated from the famous West Point military academy, served as the US military 82th Airborne Division unit commander, the information warfare, psychological warfare, low-intensity conflict in-depth study. This paper reflects the American military’s worries and alertness in the theory and construction of China’s information warfare. This article is specially translated for reference only.

In the past few years, the Chinese military and civil experts set off a wave of information warfare. After reading their works, it is not difficult to find that China’s theory of information warfare has several obvious characteristics: First, China is eager to develop its own theory of information warfare, which is related to its own security threats; secondly, China’s information War theory is influenced by its traditional military command art. Whether it is the ancient “Art of War” and “thirty-six”, or Mao Zedong’s people’s war thinking in the theory of information war laid a deep imprint; Third, China’s information warfare awareness and classification, obviously different In the beginning of the information warfare originator – the United States, although similar to the Russian information war theory, but only the shape and God is not.

Wai Wei save Zhao

The advent of the information age prompted people to rethink the way in which war was conducted. China is aware of its conventional armed forces and the superpower compared to the strength of disparity, in the near future, whether conventional or nuclear weapons, China can not constitute a strong deterrent to the United States. However, the ambitious Oriental dragon that: with the advent of the information age, the war form, the military structure, combat methods and command means will have a new change, the information will replace people full of future battlefield. As long as the focus of strategic research into the information warfare war form, grasp the trend of development of the times, it is not difficult to shorten the distance, and further lead.

Ancient China has a military order called “thirty-six dollars”, one of which “Wai Wei save Zhao” pointed out that if the enemy is too strong front power, should avoid the virtual, hit its weakness. For example, if you can not launch a direct attack (nuclear strike), then the information warfare, the weak financial, power, etc., to the West, and so on.

Network system to start. Although the conventional armed forces can not compete with the United States, however, China’s information warfare forces in theory is a real threat to the US political and economic security, the Americans can not afford the New York Stock Exchange and the Nasdaq Stock Exchange in an instant collapse. The global accessibility of information warfare, the speed of light transmission is not a feature of nuclear war, the Chinese people want is the speed of information warfare, accuracy and continuity to beat the opponent.

Information warfare can make up for the lack of conventional armed forces. The establishment of various battlefield information networks can not only improve the management level of traditional warfare, enhance the overall combat effectiveness of the troops, but also to a certain extent make up for the lack of conventional forces. In the eyes of the Chinese people, information warfare is even more powerful, is the power of conventional armed forces multiplier.

Information warfare

In 1996, China’s earliest information warfare expert Shen Weiguang to the information war under the definition is: “warring parties through the control of information and intelligence resources to compete for battlefield initiative of the war.” With the United States “to protect friendly information system, attack enemy information System “compared to the definition of Shen Weiguang more emphasis on” control “the enemy.

In 1998, the Chinese military information warfare Wei Wang Wang save major general classification of information warfare: according to time is divided into normal, crisis, wartime; by nature is divided into attack, defense; by level into the country, strategy, theater, tactics ; Divided by the scale of the battlefield, theater, local war. The characteristics of information warfare include directive and control warfare, intelligence warfare, electronic warfare, psychological warfare, space control war, hacker warfare, virtual warfare, economic warfare and so on. Information warfare in principle to take cut, blinded, transparent, fast and improve the viability and other measures. General Wang’s understanding of the information war is closer to the West, with emphasis on the confrontation of advanced technology.

In 1999, Chinese experts discussed the information warfare. Shen Weiguang at this time to expand the scope of information warfare, he believes that “information war, broadly refers to the confrontation of the military (including political, economic, science and technology and all areas of society) to seize the information space and information resources for the war, narrowly refers to the war Which is one of the essential characteristics of modern warfare.The essence of information war lies in the fact that by acquiring the right to information to achieve ‘no war and subdue the soldiers’. ”

The military another information warfare expert general general Wang Pufeng information warfare have a very deep understanding, in 2000, he information warfare and information warfare distinction. According to his explanation, the information war refers to a form of war, which contains information warfare, and information warfare refers to a combat activity. He believes that “information warfare includes all combat activities, including a series of intrusion and computer virus attacks on the theft, tampering, deception, deception, disruption, obstruction, interference, paralysis of information and information systems, and finally the enemy computer Network does not work. “He advocated China’s information warfare theory in drawing on foreign advanced combat ideas at the same time, should have China’s own characteristics.

“Mao-style network people’s war”

China’s knowledge of information warfare is very traditional. Many military theorists believe that the information age has given Mao Zedong a new connotation of the people’s war thinking, therefore, advocates rely on and mobilize the broad masses of people to carry out online war. It is conceivable that no matter which same family, with 1.3 billion people playing network warfare is daunting.

Mao Zedong’s network The most important feature of the people’s war theory is that it breaks the boundaries between the army and the people. Blurred the traditional boundaries of military installations and civilian facilities, military technology and civilian technology. The sharing of information technology in military and civilian use has created the conditions for the widespread use of civil technology for military purposes. For example, the use of civil electronic information equipment for information interception and transmission can use the civilian communication network for war mobilization; can use the private computer network attack and defense. Second, the difference between military personnel and non-military personnel is gradually disappearing. With the development of network technology and the expansion of application areas, a large number of network technology talent come to the fore. These have the special ability of the network elite will become the future network of people in the war of Gladiator. At the same time, communication, transportation, financial systems and other information networks and international networking, for China to carry out the people’s war provides the necessary conditions.

Nowadays, the idea of ​​people’s war has been established as the fundamental guiding principle of China’s network information warfare. A Chinese military writer wrote: “The flexible tactical and tactical principle is still the soul of the network information warfare.The broad masses of people actively participate in the war, especially technical support and online warfare, is to win the network information war victory of the masses and strength Source. ”

The power of the people’s war is so terrible, perhaps, we can understand why the Chinese are willing to cut the size of their armed forces – imagine that once the war broke out, China could launch a large number of people involved in war, information engineers and civilians will be organized through the home Computer attack on the US network information system, then why should we maintain a large combat force?

Information warfare

Over the past few years, China has held several major information warfare military exercises to test the theory of information warfare. The first “special war” (information warfare) exercise took place in October 1997. A military army of a military army was designed to paralyze its system of virus attacks, the group of military anti-virus software for defense. The exercise is called “invasion and anti-intrusion exercise”. The exercise also used ground logistics, medical and air forces.

In October 1998, China held a high-tech comprehensive exercise jointly conducted by the three military regions. The first use of the “military information superhighway” was used in the joint defense operations. The information network system in the command automation system is composed of digital, dialing, command network and secret channel. The other parts of the command automation system are subsystems such as command warfare, audio and graphics processing, control and data encryption.

In October 1999, the People’s Liberation Army for the first time between the two groups of war-level computer online confrontation exercises. Conducted reconnaissance and anti-reconnaissance, interference and anti-interference, blockade and anti-blockade, air strikes and anti-air raid and other subjects. In the software environment, resource sharing, combat command, situation display, auxiliary evaluation, signal transmission and intelligence warfare and other six types of operations. The computer evaluation system conducts data and quality analysis of the performance of both parties.

In July 2000, a military area also conducted an online confrontation exercise. The three training tasks related to the exercise are: organizing and planning the campaign, seizing air power and making information, implementing breakthroughs and breaking down. There are more than 100 terminal networking involved in the exercise.

Militia unit

China’s people’s war has a complete system, its overall development direction is “elite standing army and powerful reserve forces combined”, this defense system is conducive to play the overall effectiveness of the people’s war and “network tactics” advantage.

China 1.5 million reserve forces are very keen to play the network of people’s war. In some areas, the PLA has prepared the reserve forces into small information warfare forces. For example, in Yichang City, Hubei Province, the military division organized 20 municipal departments (electricity, finance, television, medical, etc.) technical staff set up a reserve information warfare. The Department has a network of war camps, electronic war camps, intelligence war camps and 35 technical units. The department has also established the first training base in China to accommodate 500 people.

Yichang is not the only area where the organization’s reserve and militia are engaged in information warfare training. December 1999 in Xiamen, Fujian held a reserve and militia meeting. During the subsequent exercise, the militia units with high-tech equipment carried out electronic countermeasures, cyber attacks and protection, radar reconnaissance performances. The goal of the fake attack is an encircled island, so it is easy for outsiders to think about being against Taiwan. Xiamen is a special economic zone, bringing together a large number of high-tech talent, so there are advantages of the implementation of information warfare.

In an exercise conducted by the Jinan Military Region, the Xi’an People’s Armed Forces Information Warfare team played the blue side of the attack, and they developed 10 kinds of information warfare measures, including information mine, information reconnaissance, change of network information, release of information bombs, dumping Network spam, distribute web leaflets, information spoofing, spread false information, organize information defense, and establish web spy stations. From these network information warfare can be seen that their research on the network information war has been quite specific and in-depth.

China’s military experts also suggested that all levels of militia organizations should set up network technology professional units, in order to facilitate the coordination of command, militia network technology professional units should be provincial or regional units for the implementation of the group, vertical management. Reserve forces to participate in the future war in the “network attack and defense” and “network technology security”, its actions should be organized by the military organization and unified coordination.

Training base

The Chinese People’s Liberation Army has developed its own set of information warfare education methods, the steps are: first to teach the basic knowledge of network information warfare; secondly through the military’s advanced military thinking to improve the level of information warfare knowledge; and then improve the use of information technology skills, Electronic technology, psychological warfare technology and information attack and defense technology; Finally, through the exercise of knowledge into practical ability. In China, mainly by the People’s Liberation Army institutions to foster information warfare high-tech talent responsibility:

People ‘s Liberation Army Communications Command College, located in Wuhan. In 1998, the hospital published two books, namely, “information combat command and control” and “information combat technology”, these two books is China’s information warfare education the most important teaching materials. The college has a high reputation for its excellent information warfare tutorials, which analyze the information, operational requirements of strategic, operational, and tactical levels.

People’s Liberation Army Information Engineering University, located in Zhengzhou, by the original PLA Information Engineering Institute, Institute of Electronic Technology and Surveying Institute merged. The main research areas of the school are information security, modern communication technology and space technology, and in some cutting-edge disciplines to explore, such as remote sensing information technology, satellite navigation and positioning technology, geographic information database technology.

People’s Liberation Army Polytechnic University, located in Nanjing, by the former People’s Liberation Army Communications Engineering College, Engineering Engineering College, Air Force Meteorological Institute and the General Association of 63 Institute merged. The school is responsible for training information warfare, commanding automation and other new disciplines of military talent. There are nearly 400 experts and professors in the university engaged in information war theory and technology research.

People’s Liberation Army National Defense Science and Technology University, located in Changsha, the school directly under the Central Military Commission. Has developed the famous “Galaxy” series of supercomputers. During the Kosovo war in April-June 1999, nearly 60 senior officers gathered in this study of high-tech wars.

People’s Liberation Army Naval Engineering University, located in Wuhan, is the only naval study of information warfare institutions. The purpose of the school’s information warfare is to apply information technology to naval equipment so that the Chinese navy can adapt to the information war.

in conclusion

What conclusions can we get from the study of information warfare in China? What can the American army get from it?

First of all, China’s military theorists have found a cheap and effective information warfare method, which makes China in the strategic military and international status to obtain the same position with the West, so that China in Asia to play a more important strategic role.

Secondly, China’s attention to the new information warfare forces is extraordinary. It may be possible to develop various forms of information warfare forces, such as: network forces (independent arms), “cyber warriors” raid units, information protection forces, information corps, electronic police and joint networks of people’s war institutions. It is interesting to note that Western countries, not China, have the ability to put these ideas into practice at this stage.

Thirdly, China’s information warfare theory reflects the combination of Western and Chinese ideas, and the influence of the former is getting weaker. Due to some common origins of military command art (Marxist dialectical thinking), China’s information warfare thought is more similar to that of Russia. However, in terms of its essence, China’s information war theory and Russia and the West are different. China’s information war theory emphasizes control, computerized warfare, cyber warfare, intellectual warfare and system of information rights.

Fourth, in the field of information warfare, China has spanned a number of technological developments and has used the Quartet’s technology to save time and save money. However, China does not fully follow the foreign, but the use of creative information war strategy. But no matter what, China is worthy of attention is different from other countries, the power of information.

For the US military, the study of China’s information war theory is not just to give the military a few opinions. “Art of War” called “know that know, victorious”. From the perspective of foreign information warfare theory to analyze the ability of the US information warfare in order to find the fatal flaws of the US information warfare system.

As the Chinese say, the losers of the information warfare are not necessarily behind the technology, and those who lack the art of command and strategic ability are the most likely to be losers. The United States to the reflection of their own information war thinking, and to study the information war strategy and tactical time. (Fan Shengqiu compilation) (“International Outlook”)

China and the latitude and longitude network February 11, 2004


Original Mandarin Chinese:



宜昌並不是組織預備役和民兵進行信息戰訓練的唯一地區。 1999年12月在福建廈門召開了預備役和民兵會議。在隨後進行的演習中,擁有高技術裝備的民兵分隊進行了電子對抗、網絡攻擊和防護、雷達偵察表演。山於假想攻擊的目標是一座被包圍的島嶼,因此很容易讓外人聯想到是針對台灣。廈門是經濟特區,匯集了大量高科技人才,因此有實施信息戰的優越條件。
解放軍通信指揮學院,位於武漢。 1998年,該院出版了兩部書籍,分別是《信息作戰指揮控制學》和《信息作戰技術學》,這兩部書籍是中國信息戰教育最重要的教材。該學院以其優良的信息戰教程設置而享有很高的聲譽,這些教程分析了戰略、戰役、戰術層次的信息作戰要求。
解放軍國防科技大學,位於長沙,該校直接隸屬於中央軍委。曾開發了著名的“銀河”系列超級計算機。 1999年4月到6月科索沃戰爭期間,近60名高級軍官匯集在此研究高科技戰爭。
對美軍而言,研究中國的信息戰理論絕非僅僅為了給軍方提供幾條意見。 《孫子兵法》稱“知彼知已,百戰百勝”。從外國信息戰理論的角度來分析美國的信息戰能力,才能發現美國信息戰系統的致命缺陷。
正如中國人所言,信息戰的失敗者不一定是技術落後方,那些缺乏指揮藝術和戰略能力的人才最可能是失敗者。美國到了該反省自己的信息戰思想,並研究信息戰戰略和戰術的時候了。 (範胜球編譯)(《國際展望》)
華夏經緯網 2004年02月11日


China’s Blurred War: Trends of Future Battlefields // 中國模糊戰爭:未來戰場的發展趨勢

With the continuous development of information technology, changing the form, nature and scale of war, so that the combat style, combat methods, combat environment, combat conditions and other elements have been a lot of changes in the past, the future battlefield becomes more blurred, Can be summarized as the following:

War scale and level ambiguity

War in size and level, can be divided into strategies, campaigns and tactics, in the past, the difference between the three very obvious. From the three interrelationships, the strategy decides the battle, the battle determines the tactics, and the tactics reacts to the battle, the battle reacts to the strategy, which is the inherent law of the existence of the war itself. With the development of information technology, the development of high-tech war as information war, although not fundamentally change the strategic, campaign, tactical and counter-role of this dialectical relationship, but it makes the strategy, battle, tactical action scale increasingly blurred. This is because, under the conditions of information under the conditions of local war, the size and use of troops, weapons, limited duration of war, political prominence, war and strategy, battle, tactics combined very closely, tend to one. Information weapons and weapons to combat high precision, powerful, long range, with all-weather, all-weather combination of peaceful reconnaissance and combat integration capabilities for the rapid realization of the purpose of war to provide an effective means, sometimes do not use large forces can Reach the strategy, the battle target. Any combat unit, and even the individual combat operations, can get a strong information and fire support. Under their influence, tactical combat can directly achieve strategic objectives, strategic command can be involved in the tactical level is no longer a dream at any time. Thus, in the past through the local small victory gradually integrated into a strategic victory of the operational theory of the impact of the strategy, campaign, tactical three combat levels between the increasingly blurred.

With the extensive use of precision strike weapons, stealth weapons, unmanned aerial vehicles, and thus through the first and second fire assault can be reached a battle or strategic objectives. In the Gulf War, the multinational force first through a large-scale strategic air raids, and then through the ground operations of the various forces reached a war purpose; US invasion of Panama, through the use of the Army to implement the five-way center of the campaign to achieve the desired purpose; In the war in Afghanistan, the US military, through the air strike and the special forces to achieve the purpose of the war; the Iraq war, the US military in the air against the cover, the US Army division through tactical action reached a war purpose. The scale of operation and the ambiguity of the level are the reflection of the essential characteristics of information warfare. In the information war, the hostile parties for the rapid completion of the established strategic objectives, will be extraordinary use of combat power, to maximize the advanced technical weapons and elite troops, and strive to destroy each other in a short time the command and control system to win the battlefield The advantage of making information right. This feature of the information warfare, so that the battle of combat and strategic purposes there is no obvious distinction between the scale of operations there is no clear battle battle difference. A battle may determine the outcome of the war, a battle may also achieve the purpose of war, thus greatly improving the strategic role of the battle battle. Especially the various precision guidance weapons, ballistic missile defense system, reconnaissance surveillance system, stealth weapon, C4ISR system and other information weapons and the extensive use of rapid reaction forces, special forces, strategic reserve and other frequently into the battlefield, making the definition of combat scale fuzzy More prominent.

Therefore, in the future information operations, the two sides will fight with the uncertainty of the scale of operations, to take over-the-line precision strike, non-programmatic “acupuncture” and structural damage and other tactics, against each other’s battlefield awareness system and information systems Quickly achieve the purpose of fighting. In this way, the special operations forces on the battlefield may be able to show their talents, that is, before the war secretly penetrate the enemy, direct attack and paralyze the enemy command and control system, so that the enemy lost control of its combat forces, and thus into the chaos of command, The Although the scale of the operation of the smaller, but for the outcome of the war can play a very important role.

Weapon equipment and functional blur

Technical decision tactics, also determines the army’s system and the composition of military and arms. For example, the emergence of weapons and equipment such as artillery, chemical weapons and radio telegraphy, laid the material foundation for the emergence of new arms such as artillery, chemical warfare, and communications. In terms of military services, due to the emergence of the aircraft, and then produced the Air Force; ship advent, gave birth to the Navy. Industrial era, the requirements of the division of labor, so refined and produced more and more professional, reflected in the composition of the army, is the division of arms and branches more and more fine; information age, requires the overall combat, the professional Close cooperation, and take the road of integrated and integrated operations. Reflected in the composition of the military trend, is the integration of combat systems. For example, many of the future weapons and equipment system will form an independent combat unit, both to complete the army requirements of the combat mission, but also to achieve the Air Force’s operational requirements, but also to achieve the purpose of naval combat. In other words, when the future combat aircraft’s infinite capacity to extend, and beyond the atmosphere combat; Army bid farewell to the “ground crawling” to achieve global arrival, global operations; the Navy to the sea to land, to the air combat capability transformation, Battle will inevitably lead to integrated forces. Integrated combat troops, generally composed of armored forces, artillery, mechanized infantry, missiles, attack and transport helicopters, naval vessels and other components, can independently combat, will realize the professional army to the professional army transition.

Future integration forces will be the main performance, will break the traditional land, sea, air, days and other military system, in accordance with the requirements of system integration, the establishment of “super-integrated” integrated combat forces. The future of information warfare is a highly integrated joint operations, the use of traditional forces of the implementation of joint operations, it is difficult to adapt to this highly integrated joint operations needs. To this end, the future composition of the military organization, will break the traditional land, sea, air, days and other military system, in accordance with the reconnaissance surveillance, command and control, precision strike and support to protect the four operational functions, built four subsystems, namely: Subsystems, command and control subsystems, precision strike and combat subsystems, and support assurance subsystems. The functions of these four subsystems are closely linked and organically linked to form an interdependent large integrated joint combat system. The army constructed in accordance with this idea will fundamentally abandon the pattern of military construction in the industrial age, eliminate the disadvantages of playing the military expertise and pursuing the interests of a single service, so that the combat forces form a “systematic system” or “system integration” Give full play to the overall power, the implementation of the true sense of “super-joint” integrated joint operations.


Military combat operations and the preparation of fuzzy war

Military combat forces have different targets and perform different combat missions. World War II, combat forces mainly infantry-based, basically infantry and infantry confrontation; the Second World War, due to the development of weapons and equipment, aircraft, tanks, cannons for war, arms and arms between the combat The task has a distinct distinction, usually performing a different combat mission. However, under the conditions of information in the local war, due to the development of weapons and equipment to the direction of multi-functional integration, the establishment of the army, not only the arms, as well as various services. Combat forces can perform both ground combat missions, but also the implementation of the fight against air and sea objectives and tasks, so that the boundaries between the military operations will be difficult to distinguish. For example: destroy the enemy tank weapons, may have been the Army’s tanks or anti-tank weapons, it may be the Air Force aircraft or naval submarines launched “smart” missiles. The US military plans to form four integrated forces: an integrated ground force composed of armored forces, artillery, flying warriors, attack and transport helicopters: air-to-air mechanized units with “flying tanks”; air force mixed knits composed of multiple models and A “joint task force” consisting of various military units. The Russian army intends to form a “multi-purpose mobile force”, an “aerospace force” composed of ground, air and space forces, and a “non-nuclear strategic deterrent force” composed of non-strategic nuclear forces.

In the future of localized information warfare, weapons and equipment to the multi-functional, integrated direction, the development of the trend of the trend of mixing, miniaturization. Combat, the arms and arms around the established operational objectives, each other, integrated into the organic whole. On the battlefield, the arms and services will be in the land, sea, air, days, electricity and other multi-dimensional areas, around the purpose of a unified combat, both in the activities of space is relatively independent, but also in the combat operations on a high degree of integration, making different arms and arms The task line becomes more vague.

War motives and ambiguity

The motive of the traditional war is generally the political struggle to cover up the economic interests of the dispute. In the information age, the economic interests of the dispute will continue to lead to the root causes of the war, but in addition, due to the international and domestic political forces between the various contacts increased, closely linked, which will inevitably lead to various countries, And the conflicts between the societies caused by political, diplomatic and spiritual factors have increased, so that the contradictions between religions and nationalities have increased, so that violence can be smuggled and drug trafficking and terrorist activities are internationalized. These contradictions and conflicts are not only the direct cause of the “sub-war operations”, but also one of the causes of the war. The direct cause of the Gulf War in 1991 was the convening of the United Nations Security Council immediately after Iraq’s invasion of Kuwait on 2 August 1990, the adoption of resolution 660, condemning Iraq’s invasion of Kuwait, and demanding that Iraq be unconditionally withdrawn from its forces. The United States for the protection of Western oil sources and in order to establish a new order in line with the interests of the world’s new order, take the lead in the implementation of economic sanctions against Iraq, followed by the United States led the multinational force to implement the UN Security Council resolution in the name of the troops to the Gulf. Through 42 days of war, the US military reached the purpose of the war. The war in Iraq, the United States to Iraq has a weapons of mass destruction on the grounds, without the authorization of the United Nations launched an injustice war. Throughout the war, the focus of US military operations against Saddam Hussein and a handful of Iraqi high-level leaders, and to find weapons of mass destruction and launched the attack. Although the war has overthrew the Saddam regime, the United States still has not found strong evidence that Iraq has such banned weapons. In this war military purpose, the United States is also to test the new operational theory.

In recent years, the US military vigorously advocated military reform. The theory of the war in Iraq is the theory of “cyber-centric warfare” and uses the new theory of “shock and deterrence” put forward in 1996: emphasizing the use of violent firepower, shocking against opponents, regardless of frontier and depth, The enemy to combat, the use of advanced precision guidance technology, against each other’s goals when one side of the pursuit of both sides less casualties; air and ground operations at the same time, the purpose is to destroy each other’s will, so that its regime collapse, so as to achieve war and subdue The purpose of the soldiers. In the Iraq war, the US military did not carry out large-scale strategic bombing, but the use of high-tech and special forces tactics to combat, which is one of the main achievements of US military reform.

War attack and defense blur

The process of attack and defense in the past is very clear, the attacking party usually in accordance with the offensive preparation, breakthrough, shock, deep combat and other step by step attack procedures, defense side in accordance with the defense preparation, fire against the preparation, anti-impact, deep combat and other sub-combat operations Attack and defense both sides of the various stages of combat orderly. The development of high-tech weapons and equipment and information technology, the new military revolution will change the future combat procedures, combat operations will break through the fixed battlefield and position constraints in the entire operational space at all levels, all directions, all aspects of the same time. In this way, the front and rear lines in the past are blurred, the relatively stable front and fixed battlefields no longer exist, the line of offensive action and defensive action because the battlefield’s high mobility and uncertainty also become blurred and influence World military force balance. Offensive and defensive both offensive and defensive combat, especially offensive and defensive information war will become the focus of future combat art, so that every war has attack in the defense, anti-attack.

Attack and defense operations will be in the land, sea, air, days, electricity and outer space and front and depth, front and wing side, front and rear at the same time, the battlefield frequent mobility, line combat style has not adapted to the conditions of local war development Need to, instead of non-line operations, the formation of a “island-based combat base”, front and rear of the line, the enemy and the two sides of the front becomes blurred, the battlefield of the flow of non-linear or non-state state of the multi-dimensional battlefield.

Measure the outcome of the war with the standard fuzzy

In the past, the criteria for measuring the outcome of a war usually refer to how many troops are wiped out, how many weapons are seized, how many cities and territories are occupied, but in the case of local warfare, the criteria for measuring the outcome of a war are not just that. Under the conditions of information, local warfare, political purpose and war are closely integrated, war attempts often not through the invasion of each other’s territory, wiped out the enemy or the enemy completely surrendered, so as not to lead the world public opinion and the people’s strong opposition, resulting in political Passive.

One of the hallmarks of information warfare is that it minimizes casualties, in particular, collateral damage, and often uses precision-guided weapons to strike precisely, to avoid heavy assault, face-to-face fights, and fight against Libya “Surgical” operations, the implementation of air long-range maneuvers, to achieve the purpose of war; also the implementation of missiles, thousands of miles away siege warfare, but also to achieve the purpose of local war; also like the Gulf War, do not occupy its territory, Do not kill their soldiers a soldier, not seized its weapons, ammunition, the implementation of large-scale air strikes, weakened its military facilities, destroyed its regime.

The war army is blurred with the people

In previous wars, the links between the army and the society were relatively “loose” due to restrictions on information infrastructure and technology; pure war weapons and equipment also led to military organizations that were completely independent of the people. Information age, information has become a link between the military and the people, this combination, with the social and military information degree of development, integration will also continue to improve. This makes society and ordinary people no longer a spectator of war, and even not only in support and subordinate status, but with the army, from the back of the war to the front desk.

As people see, on the one hand, the purpose of modern warfare is no longer simply pursuing siege and the greatest annihilation of enemy forces, the target is no longer confined to the enemy’s heavy military and military facilities, but includes Corresponding to the survival and operation of the infrastructure, such as: financial networks, power grids, transport networks, administrative networks, communications networks. On the other hand, the war has a tendency to “civilians”. For example, information makes the “non-state” has the ability to confront national power. Any “non-state subject”, as long as there is a certain technical and information equipment, you can attack the vital goal of a country, its harm is sometimes no less than a traditional sense of the war. Such as Al Qaeda attacks on the United States launched the 9.11 attack, that is the case. Although the composition of the information warfare forces, although still have traces of the war in the past war, but in the form of form and combat quality, due to more information to join the content, in particular, more to join the information of the whole society Warfare ability, so no doubt to determine the specific role of information warfare when the thinking tends to blur, but for combat decision-making and command to bring greater difficulties. With the in-depth development of information technology, the degree of social information will be greatly improved. In this case the information war, it is more prominent military and civilian compatibility characteristics. Especially in the information warfare, many high-tech work, alone, the strength of the army is difficult to complete independently, but also the need for the whole social forces of collaboration, which makes the information warfare combat power, more into the national factors.

Combat both forces with contrast and blur

In the past, the strength of the war between the two sides, usually the number of military personnel, the number of weapons to measure the number of weapons to determine the strength of the advantages of planning and combat operations. But in the information under the conditions of local war, concentrated forces of content and methods have changed. The strength of the comparison is not only the number of considerations, but also mainly consider the quality, in particular, to consider the concentration of firepower and information, a variety of long-range strike weapons do not need to focus on deployment, you can focus on the implementation of the target surprise. To make the concentration of fire after the effective role, but also must focus on a lot of information, otherwise they can not capture, track and destroy the target. The most important weapon in military forces will no longer be a high-performance fighter, bomber, tank, warships, but a huge flood of data from the information system. Invisible information and knowledge, like armored masters, play a huge role in combat and are increasingly becoming the most important combat and power multiplier. Computing power, communication ability, reconnaissance ability, processing ability, decision-making ability, computer simulation ability, network warfare and other information and knowledge factors will become a key factor in measuring military power.

The contrast of military forces is increasingly dependent on the invisible and difficult potential of the intelligence and structural forces of the information weapons system. Therefore, in the past according to the number of combatants and tanks, aircraft, artillery, warships and other weapons and equipment performance, quantity and other static indicators to assess the strength of military strength is clearly challenged. Because of the intelligence of the information weapon system, the structural force has great potential for dynamic. The strength of the Gulf War contrast and the outcome of the war can explain this problem. Before the war, Iraq and the multinational force compared to 1.6: 1, but the result of the war is the Iraqi army casualties for the multinational force 100 times. Obviously, if not a large number of multinational force weapons system to play a multiplier combat potential, there will be no such a war situation. It can be seen that the principle of force assessment of the number of static quantities will be replaced by a new force theory.

Battlefield information is true and false

Because of the development of information technology, and widely used in future war, so that a large amount of modern war information, processing information has been very difficult. Such as: the US Strategic Air Force Command, an average of more than 815,000 per month to deal with military information, almost 26,500 copies per day. In the Gulf War, the multinational force in the 42 days of combat, dealing with up to millions of military information. Only the US Army logistics will handle 10,700 copies of military information every day. After the military, weapons and equipment and the battlefield are digitized, the military information highway will cover the entire combat space, the information is true and false, there are new and old, heavy and light, there is real, there are thick and so on, information Like the tide to the red and blue both sides of the command came. In such a fast-paced, fighter fleeting, information massive battlefield environment, to the red and blue commander of a brief decision-making time, forcing both commanders in the complex battlefield information forging discrimination, analysis and judgment, quick decision-making , Through the phenomenon to seize the essence, improve the command ability.

Battlefield space and scope is blurred

Battlefield is the enemy of the two sides of the interaction between combat forces and combat forces and firepower to kill the maximum distance. In the past war, due to the level of weapons and equipment constraints, cold weapons era battlefield space, basically confined to the war between the two sides of the visual distance; hot weapons and mechanized war era, battlefield space by the firearms and the two sides of the maneuverability And the battlefield space is expanding, and from a single land battlefield, to the development of the marine battlefield and air battlefield; combat distance from the visual distance to the development of remote and ultra-long-range , The depth and dimension of the battlefield continue to expand. After entering the information warfare, with the development of military weapons and equipment and structure changes, modern warfare space from the traditional land, sea and air to space, computer space, especially information, psychology, electromagnetic, cognitive and other virtual space expansion , In addition to the range of modern weapons and equipment and a substantial increase in mobility, the future battlefield in front and rear become increasingly blurred, in addition to the solid space in the solid before and after the exception, in the dynamic action space has no difference. Fighting may start from the front, it may start from the depth. Especially the establishment of digital forces, so that the army choose the way of combat operations, with greater freedom and flexibility. At the same time, but also to accurately determine the other side of the operational space and the exact location of the space, increasing the complexity. First, information weapons greatly improve the military’s ability to war, so that the military battlefield combat more flexible way. Second, information weapons greatly enhance the military’s full-time, all-round rapid mobility, so that information warfare warfare areas to expand.

Military aerospace capacity and long-range air transport capacity, the extensive use of armed helicopters, to achieve long-range rapid maneuver provides a good material basis. Future information warfare, or in three-dimensional space or in four-dimensional space, generally difficult to accurately grasp. And only when the other side of the combat operations to a certain size, it is possible to make a relatively accurate judgments, which to some extent increased the difficulty of command and control. The ambiguity of combat space is also manifested in the fuzzy scope of combat operations. As the future of information operations will break through the frontier to the depth of the gradual advance of the pattern, in a multi-dimensional space within the full range, full depth of the war, so that the scope of combat operations increased, combat space has become elusive. The uncertainty of the scale of combat operations in the information warfare determines the diversity of combat space. This also makes it possible to judge the space of the other combat operations, become blurred, and show the characteristics of difficult to predict and control.

Combat methods and methods are blurred

Advanced information technology, not only to achieve the real-time reconnaissance intelligence and digital battlefield, greatly improving the combat effectiveness of the army, more importantly, there have been many new means of warfare: such as information warfare momentum and power to make enemies Information deterrence; to disperse, conceal and open the information channel of the information shielding; on the enemy battlefield awareness system and information system implementation of information attacks; through the information system hidden false information fraud and information cut, computer virus attacks , Special operations, psychological warfare, non-contact operations, non-fatal attacks, structural damage warfare, these combat methods used in information warfare, completely changed the past offensive and defensive procedures clear and coherent characteristics, so that the use of combat means Order, combat form of non-model and other characteristics of more and more prominent, and then led to the information warfare, the use of the enemy means of warfare, timing and methods, become more difficult to guess. In the process of the combination of fuzzy, that is, in the course of the war, due to the enemy due to the appropriate choice of means of attack, and flexible combination, so that the enemy can not determine what the other side will take the means of combat, can not effectively take the appropriate protective measures. In the use of the timing of the fuzzy, that is, according to the intention of war and combat purposes, for different stages of combat and different areas of combat, to take different means of attack, reduce the enemy resistance will make it in trouble. In the fight against the ambiguity of the target, that is, the use of information warfare means of diversification, for the needs of information operations, both sound East West, but also the East and East, the flexibility to combat the enemy command center, communication center or radar station, air defense system , Logistical support systems and other key nodes, so that the enemy is difficult to use the means of my war to make accurate predictions.

Original Mandarin Chinese:




























由於信息技術的發展,並廣泛運用於未來戰爭,使現代戰爭信息量很大,處理信息已經十分困難。如:美國戰略空軍司令部,平均每月要處理軍事信息815000多份,差不多每天處理26500份。在海灣戰爭中,多國部隊在42 天作戰中,處理軍事信息多達數百萬份。僅美國陸軍後勤每天就要處理軍事信息10700份。在軍隊、武器裝備和戰場都實現數字化以後,軍事信息高速公路將覆蓋整個作戰空間,這些信息有真有假、有新有舊、有重有輕、有虛有實、有粗有細等,信息像潮水般地向紅藍雙方指揮所湧來。在這樣快節奏、戰機稍縱即逝、信息海量戰場環境中,給紅藍雙方指揮員短暫決策處理時間,逼著雙方指揮員在錯綜複雜的戰場信息中鍛鍊辨別力、分析判斷力、快速決策力,透過現象抓住本質,提高指揮能力。






Original Source:


中國優先發展網絡戰略信息化戰 // China to give priority to the development of network strategy & information warfare

中國優先發展網絡戰略信息化戰 //

China to give priority to the development of network strategy & information warfare

Cyberspace has become the national comprehensive security of the door. Network warfare reality, the network battlefield globalization, network confrontation normalization, the network attack heart white hot, the network to build the army of the general trend, no one can block. Give priority to the development of network strategy, and actively seize the commanding heights of network strategy, for my army building is of great significance.

  The main features of network strategy

Network strategic strength refers to the ability to achieve the desired results through cyberspace. From the current development and possible future trends, mainly with the following characteristics.

Composed of multiple. In recent years, the major network events in the world have shown that the strategic power of the military network is the main force of cyberspace competition. The strategic power of the government departments and the private sector is an important part of the cyberspace competition. The “cyber warrior” An important addition.

Strong professionalism. Network strategy strength has a strong latent and difficult to predict, and the speed of light, instantaneous effect, monitoring and early warning is difficult; once the action is effective, damage effect superimposed magnification or non-linear step, with a typical “butterfly effect.” In 2010, the “shock net” virus attacked the centrifuges of the Iranian Bushehr nuclear power plant and the Natanz uranium enrichment plant, resulting in nearly a thousand centrifuge scrapped, forcing Iran’s nuclear capacity building to delay 2 to 3 years, opened the network attack soft means Destroy the national hard facilities.

Destructive. The strategic power of the network is no less than the weapons of mass destruction. Russia and Georgia in 2008, “the five-day war”, the Russian military to Georgia’s television media, government websites and transportation systems as the goal, to carry out a comprehensive “bee group” type of network paralysis attacks, leading to grid government agencies operating chaos, Logistics and communication system collapse, much-needed war materials can not be delivered in a timely manner, the potential of the war has been seriously weakened, a direct impact on the grid of social order, operational command and troop scheduling. The Russian military doctrine has identified cybercrime as a weapon of mass destruction and has retained the right to use weapons of mass destruction or nuclear weapons to counterattack.

Advanced technology and phase. Network strategy strength development speed, replacement fast, technical materialization for the equipment cycle is short. At present, the speed of the microprocessor doubles every 18 months, the backbone bandwidth doubled every six months, a variety of new electronic information equipment after another, all kinds of application software dizzying. Cyber ​​space confrontation is the field of information in the field of offensive and defensive struggle, the use of network strategy forces in the confrontation of the phase with grams, constantly renovated. The development of the firewall and the information monitoring technology makes the software of the anti-wall software upgrade continuously. The development of the firewall and the information monitoring technology has led to the development of the firewall. , Can be described as “a foot high, magic high ten feet.”

  The Developing Trend of Network Strategic

From the subordinate force to the development of key forces. In the past, the network strategic power is mainly for other forces to provide information security, in a subordinate position; with the development of network information technology, network system control of other rights, network strategic forces from subordinate status to the dominant position to accelerate into, to maintain the country The key to safety. There is no network security there is no sovereign security, “no net” to become a new law of war, the world’s major countries around the network space development rights, dominance and control of a new round of competition, especially the United States and Russia adhere to the practice In the use and continue to develop.

From the maintenance of force to the development of specialized forces. In the past, the network strategy is mainly to maintain the network information system and all kinds of network transmission system, network attack and defense attributes are not clear. At present, all areas of the network space in depth, the world’s major countries are hard to build cyberspace offensive and defensive capabilities, the main military power of the network strategy has become a network of reconnaissance, network attacks, network defense and other clear division of labor, professional regular military forces. The United States has so far built the world’s most complete and powerful network of the army, and held a series of “network storm” series of exercises. The new “cyberspace strategy” in the United States, the first public to cyberspace combat as one of the tactical options for future military conflict, clearly proposed to improve the US military in the cyberspace of deterrence and offensive capability. In order to adapt to the new strategy, the US Department of Defense proposed 2018 to build a offensive and defensive, flexible form, with full combat capability of the network forces construction goals.

From the military to the integration of military and civilian development. The development of the strategic power of the military network started relatively late compared with the civil field, and because of the confidentiality of military confrontation and the specificity of the operational objectives, it is often developed independently. With the development of network technology, the military’s own network strategic strength is difficult to meet the needs of diversified tasks, we must learn from local folk technical means, integrate local network resources, realize the integration of military and civilian development. Network space capacity building on the talent, intelligence, experience and other software environment is extremely high, coupled with the local convergence of a wealth of network resources, military and civilian forces to promote the development of cyberspace capabilities become the strong tone of the times.

From a single model to the “network integration” development. At present, the network includes both the computer IP system network and the non-computer IP system network including a large number of complex early warning detection network, satellite communication network and tactical data link. The traditional single network confrontation model is difficult to meet the challenge of cyberspace. With the development of information technology, especially the Internet of Things technology, the relationship between the network and the power of the battlefield network more and more closely, which for the “network integration” in the technical means to provide the possibility. The use of electronic warfare and network warfare means, for different systems around the open bow, broken chain broken network, to achieve complementary advantages, system damage, as the latest guidance on the construction of network space. Data show that the US military typical network of integrated attack equipment “Shu special” system has been from the “Shu-1” to the current development of “Shu-5”. According to reports, “Shute” system through the enemy radar antenna, microwave relay station, network processing nodes to invade the enemy air defense network system, real-time monitoring of enemy radar detection results, even as a system administrator to take over the enemy network, Control of the sensor.

From non-state actors to state actors. At present, the network attack has developed from a single hacker behavior for the national, political, military confrontation, the attack object has been developed from the personal website to the country, the army’s important information system, attack “unit” has grown from stand-alone to tens of thousands Hundreds of thousands of terminals, and can instantly release the amazing attack energy. Although many of the intentions of malicious acts of non-State actors are non-state, the consequences are national, whether they are espionage, political opinions, or personal discontent, or terrorist activities , Have a direct impact on social stability, disrupt the economic order, endanger the stability of state power. Once the relevant reaction is made, the subject of the act must be the state and the army, and not the non-state actors themselves.

  The Construction of Network Strategic Strength

Strengthen strategic planning. Cyberspace competition is the first strategic battle of the contest. From the national level, the network strategy of the power of the main function is to reduce the risk of cyberspace, maintaining the normal operation of the country. We must understand the extreme importance and realistic urgency of cyberspace security from the perspective of national security, raise the focus of cyberspace capacity building to the strategic level, and try to reduce the national cyberspace security while trying to solve the problem of how to make good use of cyberspace Risk, so that cyberspace security has become an important support for national prosperity and security. From the military level, the network strategy is mainly to seize the system of network power. We must expand the military vision, the cyberspace as an important area of ​​action, to seize the system as the core, change the military ideas and ideas, adjust the structure and composition of armed forces, the development of weapons and equipment and take a new tactics.

Speed ​​up the construction of the power system. Maintain cyberspace security in the final analysis depends on the strength. We must base ourselves on the characteristics and laws of cyberspace capacity building, focus on the core elements of network capability system and the overall layout of network strategy, and systematically design the system structure which conforms to the law and characteristics of cyberspace confrontation in our country, and perfect the system of leadership and command Functional tasks, straighten out the relationship between command and management. We should take the network strategic power as an important new combat force, from the organization construction, personnel training, equipment development, elements of training and other aspects, to take extraordinary measures to give priority construction, focus on protection. To normalize the national network of offensive and defensive exercises, test theory, tactics, equipment and technology effectiveness, and comprehensively enhance the comprehensive prevention of cyberspace capabilities.

Promote technological innovation. The essence of cyberspace confrontation is the competition of core technology, and it is necessary to accelerate the independent innovation of network information technology. To improve the ability of independent innovation as a strategic basis to the national innovation system as the basic support, focus on breaking the forefront of network development technology and international competitiveness of the key core technology, advanced deployment and focus on the development of information technology and information industry. To speed up the process of localization of key core technologies, strengthen the construction of safety testing and active early warning means, and gradually improve the equipment system of cyberspace in China, and comprehensively improve our network space capability. To follow the basic laws of cyberspace confrontation, in accordance with the “asymmetric checks and balances” strategy, increase the quantum technology, Internet of things and cloud computing and other new technology research and development efforts to create unique combat capability, master the initiative of cyberspace security development The

Promote the integration of military and civilian development. The integration of the military space ability of military and civilian development is not only the overall situation of national security and development strategy, the overall planning of national defense and economic and social development, but also the objective fact that cyberspace security can not be avoided. We must actively promote the deep integration of military and civilian development, to promote China’s network space capacity supporting the construction. It is necessary to formulate top-level planning in the form of policies and regulations, clarify the objectives, methods, organizational division and basic requirements of the deepening development of cyberspace in the form of policies and regulations, and make the integration of military and civilian development into law enforcement and organizational behavior; To establish a sound military coordination, demand docking, resource sharing mechanism, through a unified leadership management organization and coordination of military needs and major work, to achieve risk sharing, sharing of resources and common development of the new situation. We should pay attention to the distinction between the boundaries of military and civilian integration, clear the concept of development-oriented people and the main battle concept of the army, and actively explore the military and the people, the advantages of complementary channels.

Original Mandarin Chinese:



















Source URL:

Full Text of China’s National Cyberspace Security Strategy // 國家網絡空間安全戰略全文

Full Text of China’s National Cyberspace Security Strategy


Beijing,People’s Republic of China

27 DEC 2017

December 27, approved by the Central Network Security and Information Technology Leading Group, the National Internet Information Office released the “national cyberspace security strategy”, the full text is as follows.

The extensive application of information technology and the rise and development of cyberspace have greatly promoted the economic and social prosperity and progress, but also brought new security risks and challenges. Cyberspace security (hereinafter referred to as cybersecurity) concerns the common interests of mankind, related to world peace and development, and national security. Safeguarding China’s network security is an important measure to coordinate and promote the comprehensive construction of a well-off society, comprehensively deepen reform, comprehensively administer the country according to law, and strictly pursue the strategic layout of the party, and realize the goal of “two hundred years” and realize the great rejuvenation of the Chinese nation An important guarantee. In order to implement the “four principles” of promoting the transformation of the global Internet governance system and the “five-point proposition” to build the cyberspace destiny community, we have clarified China’s important position on cyberspace development and security, guided China’s network security work, The state in the cyberspace of sovereignty, security, development interests, the development of this strategy.

First, opportunities and challenges

(A) a major opportunity

With the rapid development of information revolution, Internet, communication network, computer system, automation control system, digital equipment and its application, service and data, such as the network space, is a comprehensive change in people’s production and lifestyle, profound impact on human society Development process.

New channels for information dissemination. The development of network technology, breaking the time and space constraints, expanding the scope of communication, innovative means of communication, triggering a fundamental change in the pattern of communication. The network has become a new channel for people to access information and learn to communicate, and become a new carrier of human knowledge transmission.

Production and life of the new space. In today’s world, the depth of the network into people’s learning, life, work and other aspects of online education, entrepreneurship, health care, shopping, finance and other increasingly popular, more and more people through the network exchange ideas, achievements and dreams.

The new engine of economic development. The Internet is becoming the leading force of innovation-driven development. Information technology is widely used in all sectors of the national economy. It has promoted the upgrading of traditional industries, promoted new technologies, new forms, new industries and new models, promoted the adjustment of economic structure and economic development , For economic and social development has injected new impetus.

Cultural prosperity of the new carrier. The network promotes the cultural exchange and the popularization of knowledge, the release of cultural development vitality, the promotion of cultural innovation creation, the enrichment of people’s spiritual and cultural life, has become a new way to spread culture, provide a new means of public cultural services. Network culture has become an important part of cultural construction.

A new platform for social governance. The role of the network in advancing the national governance system and the modernization of the governance capability has become increasingly prominent. The application of e-government has been deepened, and the government information has been shared and publicized. The government has made scientific decision-making, democratization and rule of law, and has smoothed the channels of citizens’ participation in social governance. An important way to protect citizens’ right to know, to participate, to express and to supervise.

Exchange and cooperation of the new link. The development of information and globalization has promoted the global flow of information, capital, technology, talent and other elements, and promoted the integration of different civilizations. Network to the world into a global village, the international community more and more you have me, I have your fate in the community.

National sovereignty of the new territory. Cyber ​​space has become an important part of human activity with land, sea, sky and space. National sovereignty extension extends to cyberspace, and cyberspace sovereignty becomes an important part of national sovereignty. Respect for cyberspace sovereignty, safeguard network security, seek co-governance, achieve win-win situation, is becoming the international community consensus.

(B) severe challenges

The security situation of the network is becoming more and more serious, the national politics, economy, culture, society, national defense security and the legitimate rights and interests of citizens in cyberspace are facing severe risks and challenges.

Network penetration threatens political security. Political stability is the basic prerequisite for national development and people’s happiness. The use of the network to interfere in the internal affairs of other countries, to attack other countries political system, incite social unrest, subversion of other countries, as well as large-scale network monitoring, network theft and other activities seriously endanger the national political security and user information security.

Network attacks threaten economic security. Network and information systems have become the key infrastructure and the entire economic and social center of the nerve, suffered damage, a major security incident, will lead to energy, transportation, communications, financial and other infrastructure paralysis, resulting in catastrophic consequences, seriously endangering national economic security And public interest.

Network Harmful Information Erosion Cultural Security. Various ideological and cultural networks on the network agitation, confrontation, excellent traditional culture and mainstream values ​​facing the impact. Network rumors, decadent culture and obscenity, violence, superstition and other harmful information contrary to the socialist core values ​​erode the physical and mental health of young people, corrupt the social atmosphere, misleading the value orientation, endangering cultural security. Online moral anomie, the phenomenon of lack of integrity frequent, the degree of network civilization need to be improved.

Network terror and criminals undermine social security. Terrorism, separatism, extremism and other forces to use the network to incite, plan, organize and implement violent terrorist activities, a direct threat to people’s lives and property security, social order. Computer viruses, Trojans and other cyberspace spread spread, cyber-fraud, hacking, infringement of intellectual property rights, abuse of personal information and other illegal acts exist, some organizations want to steal user information, transaction data, location information and business secrets, serious damage to the country , Business and personal interests, affecting social harmony and stability.

The international competition in cyberspace is in the ascendant. International competition and control of cyberspace strategic resources, to seize the right to formulate rules and strategic high ground, to seek strategic competition in the increasingly fierce. Individual countries to strengthen the network deterrence strategy, intensify the cyberspace arms race, world peace by new challenges.

Cyberspace opportunities and challenges coexist, opportunities are greater than challenges. We must insist on active use, scientific development, management according to law, ensure safety, resolutely safeguard network security, make maximum use of cyberspace development potential, and benefit more than 1.3 billion Chinese people for the benefit of all mankind and firm maintenance of world peace.

Second, the goal

With the overall national security concept as the guide, implement the innovation, coordination, green, open and shared development concept, enhance the sense of risk and crisis awareness, the overall situation of domestic and international, overall development of security two major events, active defense, effective response, Promote network space peace, security, openness, cooperation and orderly, safeguard national sovereignty, security, development interests, and realize the strategic goal of building a network power.

Peace: the abuse of information technology has been effectively curbed, cyberspace arms race and other activities threatening international peace have been effectively controlled, cyberspace conflict has been effectively prevented.

Security: network security risks are effectively controlled, the national network security system is sound and perfect, the core technology and equipment are safe and controllable, and the network and information system are stable and reliable. Network security personnel to meet the needs of the whole society of network security awareness, basic protection skills and the use of network confidence greatly improved.

Open: Information technology standards, policies and markets open, transparent, product circulation and information dissemination more smoothly, the digital divide is increasingly bridging. Regardless of size, strength, rich and poor, countries around the world, especially developing countries can share development opportunities, share the fruits of development, fair participation in cyberspace governance.

Cooperation: the world in the technical exchanges, the fight against cyber terrorist and cyber crime and other areas of cooperation more closely, multilateral, democratic and transparent Internet governance system sound and perfect, win-win cooperation as the core of the network space fate community gradually formed.

Order: public interest in the cyberspace, participation, expression, supervision and other legitimate rights and interests are fully protected, cyberspace personal privacy is effectively protected, human rights are fully respected. The network environment of the domestic and international legal system, the standard norms gradually established, the network space to achieve effective management according to law, network environment integrity, civilization, health, freedom of information flow and safeguard national security, public interests to achieve organic unity.

Third, the principle

A safe, stable and prosperous cyberspace is of great significance to all countries and the world. China is willing to work with all countries to strengthen communication, expand consensus, deepen cooperation, and actively promote the global Internet governance system changes, and jointly safeguard the peace and security of cyberspace.

(A) respect for the maintenance of cyberspace sovereignty

Cyberspace sovereignty is inviolable, respect for the independent choice of development path, network management model, Internet public policy and equal participation in international network space management rights. The network affairs within the sovereign scope of each country are made by the people of each country, and each country has the right to take the necessary measures to manage the network activities of its own information system and its own territory according to its own national conditions and draw lessons from international experience, formulate laws and regulations on cyberspace, National information systems and information resources from intrusion, interference, attack and destruction, to protect the legitimate rights and interests of citizens in cyberspace; to prevent, prevent and punish harmful information harmful to national security and interests in the national network to disseminate and maintain cyberspace order. Any country does not engage in network hegemony, do not engage in double standards, do not use the network to interfere in the internal affairs of other countries, do not engage in, condone or support national activities against national security.

(B) the peaceful use of cyberspace

Peaceful use of cyberspace is in the common interest of mankind. States should abide by the principles of the Charter of the United Nations concerning the non-use or threat of use of force and prevent the use of information technology in the context of the maintenance of international security and stability, to boycott cyberspace arms races and prevent cyberspace conflicts. Adhere to mutual respect, equal treatment, seeking common ground while reserving differences, tolerance and mutual trust, respect for each other in cyberspace security interests and major concerns, to promote the construction of a harmonious network world. Against the use of national security as an excuse to use technological advantages to control other countries network and information systems, to collect and steal other countries data, but can not sacrifice the security of other countries to seek their own so-called absolute security.

(C) to manage cyberspace according to law

Comprehensively promote the legalization of cyberspace, adhere to the rule of law network, according to the law network, according to the Internet, so that the Internet in the rule of law on the healthy operation of the track. According to the law to build a good network order, the protection of cyber space information according to the law of free flow, protection of personal privacy, protection of intellectual property rights. Any organization and individual in the cyberspace to enjoy freedom, exercise the rights at the same time, to comply with the law, respect for the rights of others, their own words and deeds on the network.

(4) co-ordinate network security and development

There is no national security without national security, there is no information without modernization. Network security and information is one of the two wings, driven by the two wheels. Correctly handle the development and security of the relationship, adhere to the security development, to promote the development of security. Security is the prerequisite for development, and any development at the expense of security is difficult to sustain. Development is the foundation of security, and development is not the greatest insecurity. No information development, network security is not guaranteed, the existing security and even lost.

Fourth, strategic tasks

China’s Internet users and network size of the world’s first, to maintain China’s network security, not only their own needs, for the maintenance of global network security and world peace are of great significance. China is committed to safeguarding the national cyberspace sovereignty, security, development interests, promote the Internet for the benefit of mankind, and promote the peaceful use of cyberspace and co-governance.

(A) firmly defended cyberspace sovereignty

According to the Constitution and laws and regulations to manage China’s sovereignty within the network activities to protect China’s information facilities and information resources security, including economic, administrative, scientific and technological, legal, diplomatic, military and other measures, unswervingly maintain China’s cyberspace sovereignty. Resolutely oppose all the acts of subverting China’s state power through the Internet and undermining our national sovereignty.

(B) firmly uphold national security

To prevent, stop and punish any act of using the Internet for treason, secession, incitement to rebellion, subversion or incitement to subdue the people’s democratic dictatorship; to prevent, stop and punish the use of the Internet to steal, to disclose state secrets and other acts endangering national security; Prevent, stop and punish foreign forces to use the network to penetrate, destroy, subvert, split the activities.

(Iii) Protection of critical information infrastructures

The key information infrastructure of the country refers to the information facilities that are related to national security, national economy and people’s livelihood, which have been damaged, destroyed or lost, which may seriously endanger the national security and public interests, including but not limited to the provision of public communication, radio and television transmission Information network, energy, finance, transportation, education, scientific research, water conservancy, industrial manufacturing, health care, social security, public utilities and other areas of important information systems, important Internet applications. Take all necessary measures to protect critical information infrastructures and their important data from attack damage. Adhere to the combination of technology and management, protection and deterrence simultaneously, focus on identification, protection, detection, early warning, response, disposal and other aspects, the establishment of the implementation of key information infrastructure protection system, from management, technology, personnel, Comprehensive measures to effectively strengthen the key information infrastructure security protection.

Key information infrastructure protection is the common responsibility of the government, enterprises and society as a whole. The supervisors, the operating units and organizations shall take the necessary measures to ensure the safety of the key information infrastructure in accordance with the requirements of laws, regulations and system standards. Strengthen critical information infrastructure risk assessment. Strengthen the party and government organs and key areas of the site security protection, grassroots party and government organs to build an intensive mode of operation and management. The establishment of government, industry and business network security information orderly sharing mechanism, give full play to enterprises in the protection of key information infrastructure in the important role.

Adhere to open to the outside world, based on open environment to maintain network security. Establish and implement the network security review system, strengthen the supply chain security management, the party and government organs, key industries procurement and use of important information technology products and services to carry out security review, improve product and service security and control, to prevent product service providers And other organizations use information technology to implement unfair competition or harm the interests of users.

(D) to strengthen the construction of network culture

Strengthen the construction of online ideological and cultural positions, vigorously cultivate and practice the socialist core values, the implementation of network content construction projects, the development of a positive network culture, the dissemination of positive energy, gather a strong spiritual strength, and create a good network atmosphere. Encourage the development of new business, create new products, to create the spirit of the times reflect the network culture brand, and constantly improve the network culture industry scale. The implementation of the outstanding culture of Chinese online communication project, and actively promote the excellent traditional culture and contemporary culture of digital, network production and dissemination. Play the advantages of Internet communication platform, promote the excellent cultural exchange between China and foreign countries, so that people understand the Chinese culture, so that the Chinese people understand the excellent culture of all countries, and jointly promote the prosperity and development of network culture, enrich people’s spiritual world and promote the progress of human civilization.

Strengthen the network ethics, network civilization construction, play moral education guide role, with human civilization excellent results nourish network space, repair network ecology. The construction of civilized integrity of the network environment, advocate civilization network, civilized Internet, the formation of safe, civilized and orderly information dissemination order. Resolutely crack down on rumors, obscenity, violence, superstition, cults and other harmful information spread in cyberspace spread. Improve the youth network literacy literacy, strengthen the protection of minors online, through the government, social organizations, communities, schools, families and other aspects of the joint efforts for the healthy growth of young people to create a good network environment.

(5) to combat cyber terror and crime

Strengthen the network anti-terrorism, anti-spy, anti-stealing capacity building, crack down on cyber terror and cyber espionage.

Adhere to comprehensive management, source control, according to the law to prevent, crack down on cyber fraud, Internet theft, trafficking in drug trafficking, infringement of personal information, dissemination of pornography, hacking, infringement of intellectual property rights and other criminal acts.

(6) improve the network management system

Adhere to the law, open, transparent network management network, and effectively do law, according to law, law enforcement must be strict, illegal research. Improve the network security laws and regulations system, enacted network security law, minor network protection regulations and other laws and regulations, a clear social responsibility and obligations, a clear network security management requirements. To speed up the revision and interpretation of existing laws, so that it applies to cyberspace. Improve the network security related system, establish a network trust system, improve the network security management of the scientific standardization level.

Speed ​​up the construction of legal norms, administrative supervision, industry self-discipline, technical support, public supervision, social education, a combination of network governance system to promote the network of social organization and management innovation, improve the basic management, content management, industry management and network crime prevention and combat Work linkage mechanism. Strengthen the cyberspace communication secrets, freedom of speech, trade secrets, as well as the right to reputation, property rights and other legitimate rights and interests of protection.

Encourage social organizations to participate in network governance, the development of network public welfare undertakings, strengthen the new network of social organization. Encourage Internet users to report network violations and bad information.

(7) reinforce the network security foundation

Adhere to innovation-driven development, and actively create a policy environment conducive to technological innovation, co-ordinate resources and strength to enterprises as the main body, combining production and research, collaborative research to point to the surface, the overall advance, as soon as possible in the core technology breakthrough. Attention to software security, accelerate the application of secure and credible products. The development of network infrastructure, rich network space information content. The implementation of “Internet +” action, vigorously develop the network economy. The implementation of national large data strategy, the establishment of large data security management system to support large data, cloud computing and other new generation of information technology innovation and application. Optimize the market environment, encourage network security enterprises bigger and stronger, to protect the national network security and consolidate the industrial base.

Establish and improve the national network security technology support system. Strengthening the basic theory and major problems of network security. Strengthen the network security standardization and certification work, more use of standard norms cyberspace behavior. Do a good job of level protection, risk assessment, vulnerability discovery and other basic work, improve the network security monitoring and early warning and network security emergency response mechanism.

The implementation of network security personnel projects, strengthen the network security professional construction, build first-class network security college and innovation park, the formation of personnel training and innovation and entrepreneurship of the ecological environment. Run the network security publicity week activities, vigorously carry out the national network security publicity and education. Promote the network security education into the teaching materials, into the school, into the classroom, improve the network media literacy, enhance the whole society network security awareness and protection skills, improve the network of Internet users harmful information, network fraud and other illegal and criminal activities identification and resistance.

(8) to enhance the ability of network space protection

Cyberspace is the new territory of national sovereignty. Construction and international status commensurate with the network power to adapt to the network space protection, and vigorously develop the network security and defense means to detect and resist the network invasion, casting and maintenance of national network security strong backing.

(9) to strengthen international cooperation in cyberspace

On the basis of mutual respect and mutual trust, strengthen cooperation in international cyberspace dialogue and promote the transformation of the global governance system of the Internet. Deepen cooperation with the bilateral and multilateral network security dialogue and information communication, effective control of differences, and actively participate in global and regional organizations, network security cooperation, to promote the Internet address, root domain name servers and other basic resource management internationalization.

Support the United Nations to play a leading role in promoting the development of international agreements on cyberspace, international cyberspace international anti-terrorism conventions, and sound legal mechanisms to combat cybercrime, deepening policy and legal, technical innovation, standards, emergency response, critical information infrastructure Protection and other fields of international cooperation.

Strengthen support for assistance in the development of Internet technologies and infrastructure in developing and backward regions, and strive to bridge the digital divide. To promote “along the way” building, improve the level of international communication interoperability, smooth information Silk Road. To build the World Internet Conference and other global Internet sharing system, and jointly promote the healthy development of the Internet. We will build a multilateral, democratic and transparent international Internet governance system through active and effective international cooperation to build a peaceful, safe, open, cooperative and orderly cyberspace.

Original Mandarin Chinese:
















































































Original Source: