Introduction Establishment Workforce power Constituency Contact Incident handling

54 CNCERTCC National Computer network Emergency Response technical Team Coordination Center of China - People’s Republic of China 1. About CNCERTCC

1.1. Introduction

The National Computer Network Emergency Response Technical TeamCoordination Center of China known as CNCERT or CNCERTCC is a non-governmental non-profit cybersecurity technical center and the key coordination team for China’s cybersecurity emergency response community.

1.2. Establishment

CNCERT was founded in 2002, and became a member of FIRST in Aug 2002. It also took an active part in the establishment of APCERT as a founding member.

1.3. Workforce power

CNCERT, which is based in Beijing, the capital of China, has spread branch offices in 31 provinces, autonomous regions and municipalities in mainland China.

1.4. Constituency

As a national CERT, CNCERT strives to improve nation’s cybersecurity posture, and protect critical infrastructure cybersecurity. CNCERT leads efforts to prevent, detect, warn and coordinate the cybersecurity threats and incidents, according to the guideline of “proactive prevention, timely detection, prompt response and maximized recovery”.

1.5. Contact

E-mail: cncertcert.org.cn Hotline: +8610 82990999(Chinese), 82991000(English) Fax: +8610 82990375 PGP Key: http:www.cert.org.cncncert.asc 55 2. Activities Operations

2.1. Incident handling

In 2014, CNCERT received a total of about 56.2 thousand incident complaints, a 77.3 increase from the previous year. And among these incident complaints, 878 were reported by overseas organizations, making a 9.6 drop from the year of 2013. As shown in Figure 2-1, most of the victims were plagued by vulnerability 36.4, phishing 32.1and website defacement16.3. Vulnerability still overtook phishing to be the most frequent incident complained about. And website defacement ranked the third place with an increase of 1.9 from 2013. Figure 2-1Categories of the Incident Reported to CNCERT in 2014 In 2014, CNCERT handled almost 56.1 thousand incidents, a significant rise of 79.8 compare with that in 2013. As illustrated in Figure 2-2, vulnerability 36.1 dominated the categories of the incidents handled by CNCERT in 2014, followed by phishing 32.0 and website defacement 16.0. 56 Figure 2-2 Categories of the Incidents Handled by CNCERT in 2014 2.2. Internet Awareness 2.2.1. Malware Activities