Showing posts with label Critical ICT Infrastructure Protection In India. Show all posts
Showing posts with label Critical ICT Infrastructure Protection In India. Show all posts

Thursday, February 9, 2012

National Critical Information Infrastructure Protection Centre (NCIPC) Of India

In the recent times, there is an increasing stress upon cyber security at the international level. This is so because cyber attacks are happening at the international level and all the countries are facing this threat.

Countries are trying to coordinate cyber security initiatives at national and international levels. However, cyber security in India is still not up to the mark. India is increasingly facing cyber attacks and cyber threats from foreign nationals.

The cyber laws and cyber security trends of India 2011 by Perry4Law and Perry4Law Techno Legal Base (PTLB) has clearly showed the cyber security vulnerabilities of India. The cyber law trends of India 2012 have also projected an increased rate of cyber crimes in India and cyber attacks against India in the year 2012.

For instance, cyber terrorism against India, cyber warfare against India, cyber espionage against India and cyber attacks against India have increased a lot. Presently, we do not have a strong cyber law to deter cyber attacks and cyber crimes. Further, we have no cyber security laws in India as well.

Cyber security is also crucial to protect critical infrastructure protection of India. Critical infrastructure protection in India requires a well formulated policy. Presently we have no critical infrastructure protection policy of India. Even critical ICT infrastructure protection in India is required.

A national critical information infrastructure protection centre (NCIPC) of India has been proposed. It intends to ensure critical infrastructure protection and critical ICT infrastructure protection in India.

There are few prerequisites that can make the NCIPC of India successful. Firstly, there must be a centralised ICT command centre of India that can coordinate various cyber security issues. Secondly, specialised agencies and authorities must be constituted for critical infrastructure areas like power, telecom, defense, etc. These agencies and authorities must coordinate with the centralised command centre for cyber security related issues.

Ministry of communication and information technology (MCIT) has already taken certain initiatives in this regard. For instance, a central monitoring system (CMS) project of India has been launched by MCIT to monitor and intercept electronic communications, messages and information. Further, a national telecom network security coordination board (NTNSCB) of India has also been proposed to strengthen the national telecom security of India.

Similarly, the home ministry of India has also launched national intelligence grid (Natgrid) project of India, crime and criminal tracking networks and systems (CCTNS) project of India, national counter terrorism centre (NCTC) of India, etc. These projects intend to strengthen the intelligence gathering and counter terrorism capabilities of India.

However, there is a big problem in the successful implementation of all the abovementioned projects and initiatives as well as the NCIPC of India. Indian government has been avoiding parliamentary oversight of these projects. This is a bad precedent that needs to be urgently taken care of. We need urgent parliamentary oversight for e-surveillance in India, Internet censorship in India, intelligence gathering in India, intelligence authorities of India, central bureau of Investigation, law enforcement agencies of India, Aadhar project of India, etc.

Even privacy laws in India, data security laws in India, data protection laws in India, etc are urgently required to be formulated. The cyber law of India must be suitably amended, perhaps repealed, to make a more robust and stringent cyber law of India. We need dedicated cyber security legal framework in India and cyber forensics laws in India.

For too long Indian parliament has been ignoring its crucial legislative business and it is high time for Indian parliament to do the needful in this regard. Contemporary techno legal issues cannot be left at the mercy and indifference of Indian parliament and Indian government as that may have serious adverse effects upon Indian economy and national security of India.

Thursday, November 17, 2011

India’s National Informatics Centre Servers Compromised

Attacking and compromising the servers located in various countries has become a common practice for cyber criminals. By compromising the servers of various nations, these cyber criminals can launch general and sophisticated cyber attacks, without much chances of their identity being known to the victim individuals, organisations and nations.

Cyberspace is boundary less and it is very difficult to prevent cyber attacks from different jurisdictions. Essentially cyber security is an international aspect that must be dealt with at the international level. An international cyber security cooperation and treaty is required that can take care of various issues like cyber attacks, cyber warfare, cyber terrorism, cyber espionage, etc.

For instance, even if a cyber attack can be located to a particular jurisdiction, “attributing” the same to a single individual or organisation/nation is really difficult. This means we cannot pinpoint with absolute certainty that a particular nation is behind a particular cyber attack. This raises a very complicated jurisdictional and attribution problem.

The starting point to gather sufficient information pertaining to cyber attacks existing simultaneously at various jurisdictions is to have an internationally acceptable cyber security cooperation. An internationally acceptable cyber crimes/law treaty is also required in this regard.

Cyber attacks against India as well as from India are increasing. For instance, the servers of the Indian National Informatics Centre (NIC) have been attacked and compromised successfully in recent months and were used to launch attacks on countries including China.

Indian critical infrastructure protection is already in bad shape. Further, we also do not have any critical ICT infrastructure protection policy in India. Indian nuclear facilities are vulnerable to cyber attacks from Malware like Stuxnet. It is also believed that Stuxnet was also responsible for the destruction of an Indian broadcasting satellite.

India is already investigation the Duqu Malware that used the command and control servers located in India. Fortunately Stuxnet virus removal tools and Duqu virus removal tools are already available free of cost that can be used to test various systems for these Malware. Perhaps time has come for a cyber command and control authority of India that can take care of these cyber threats.

Friday, November 11, 2011

Free Stuxnet Malware Removal Toolkits And Software

Stuxnet and Duqu Malware have shown the vulnerabilities of our critical infrastructures. Critical infrastructure protection in India is also required to be analysed from the point of view of these sophisticated Malware. In fact, we must urgently formulate a critical ICT infrastructure protection policy of India.

While the destruction of an Indian broadcasting satellite by Stuxnet Malware is still a mystery yet India is investigating Duqu Malware that had a command and control server in India. Meanwhile, open source Duqu Malware removal toolkits and software have also been released by the open source community.

Undoubtedly, Stuxnet is the most sophisticated Malware that has come to notice so far. There are few good tools and software that can be used to deal with Stuxnet Malware. They can be used for a specific purpose or for checking the entire computer system.

These tools and software are providing curative protection against Stuxnet Malware in the following forms:

(1) Computer: The Stuxnet Removal Tool can be used to scan an entire computer for Stuxnet Malware.

(2) USB: The Stuxnet Remover for USB can be used for analysing a USB for Stuxnet infection.

(3) LNK Shortcut: Stuxnet also utilises the shortcut vulnerabilities of various versions of Windows operating systems. Microsoft has released Microsoft Fix it tools to fix this vulnerability. For Microsoft Fix it to disable .LNK and .PIF file functionality you can use this tool. If you want to disable workaround offered by Fix it than use this tool. You need to restart your computer after using this workaround to take affect on your computer. Another good tool is the Sophos Windows Shortcut Exploit Protection tool to block Stuxnet rootkit from exploiting LNK Shortcut vulnerability in all versions of Windows.

It is worth while to give these tools and software a try.

Saturday, November 5, 2011

Are Indian Nuclear Facilities Cyber Secure?

Nuclear facilities are part of the critical infrastructure of India that need robust protection. The critical infrastructure protection policy of India must protect them on priority basis. Similarly, critical ICT infrastructure protection in India is required to be taken seriously.

Malware writers have been increasingly targeting critical infrastructures world over. Their latest targets seem to be nuclear installations and facilities. Stuxnet is a classic example of this Malware attack upon nuclear facilities.

The addition of Duqu Malware into the league is a hint where cyber crimes and cyber attacks game is going. India is presently investigating the Duqu Malware. While the task has not been accomplished yet news about possible cyber attack against India’s lone uranium enrichment facility at Rattehalli, near Mysore, has surfaced.

According to the news, the facility may become the target of the gravest act of cyber war against India to date, attacking no less than its strategic nuclear programme. The sources said computers at the Rattehalli facility, euphemistically called Rare Materials Plant (RMP), were possibly infected by the deadly Stuxnet, or a Stuxnet-derived Malware, as a precursor to an attack to destroy thousands of centrifuges installed there.

This situation has once again reiterated the need for India to develop cyber warfare capabilities. In the past, similar attacks on Iran’s Natanz enrichment plant destroyed over 1,000 centrifuges and set its alleged nuclear bomb programme back at least 12-18 months.

An official response from Indian authorities in this regard is still awaited. But one thing is for sure that India is still not yet ready for the new Malware game that is producing serious cyber threats in the form of Stuxnet, Duqu, etc.

Monday, October 3, 2011

Cyber Warfare Against India

Cyber warfare is a concept that is still haunting the international community. The situation is so serious that north atlantic treaty organisation (NATO) has sought stronger cooperation with India to counter growing cyber threats.

Cyber warfare is still a murky area as different countries deal with cyber attacks and cyber warfare attacks differently. While countries like US are considering it as an act of aggression on the footing of war yet other countries are taking divergent views. However, all countries are willing to use every possible cyber capabilities as preventive and curative cyber methods.

Till United Nations (UN) steps in and enacts “universally acceptable” international cyber law treaty and international cyber security treaty, this problem would remain murky and difficult to resolve. Further, nothing can benefit more than an international cyber security cooperation that is urgently required.

The incidences of cyber attacks, cyber terrorism, cyber espionage, cyber warfare, etc are increasing against India. However, in the absence of India’s national cyber security policy, cyber security in India is a neglected field. We must urgently develop cyber warfare capabilities in India to thwart growing cyber attacks against India. Further, we must also formulate a cyber warfare policy in India that is presently missing.

Cyber warfare is also the reason why we need to ensure critical infrastructure protection in India and critical ICT infrastructure protection in India. In fact the growing cyber attacks are affecting Indian critical infrastructure. Thus, cyber security capabilities through techno legal cyber security trainings in India must be strengthened. We must stress upon cyber security skills development in India.

The situation is equivalent to a wake up call and Indian government must take urgent steps to strengthen Indian cyber security. The sooner it is adopted the better it would be for a safe and secure cyberspace of India.

Sunday, September 25, 2011

National Cyber Security Policy Of India

The recent cyber attacks upon India have proved once again that we need to pay more attention to cyber security in India. Cyber security in India is required not only to protect sensitive information stored in the computers of strategic Indian departments and ministries but also to safeguard the present and future critical infrastructure of India.

Not only critical infrastructure protection in India is needed but also critical ICT infrastructure protection in India (CIIP in India) is need of the hour. CIIP in India is an area that requires urgent attention of our policy makers. We must formulate a critical ICT infrastructure protection policy of India as soon as possible.

Similarly, cyberspace crisis management plan of India is also required to be formulated. We must formulate a national ICT crisis management plan of India. Further, Indian crisis management plan against cyber attacks and cyber terrorism must also be formulated.

All these, and many more, aspects must be made a part of the cyber security policy of India. A national cyber security policy of India must be formulated in this regard that is made implementable after a reasonable period. Issues like cyber warfare, cyber terrorism, cyber espionage, international cyber security cooperation, etc must be part of the same.

We need a clear and implementable cyber security strategy of India. The cyber security policy and strategy of India must be techno legal in nature that can take care of both technical and legal aspects of cyber security.

There is no second opinion that national security policy of India is required and cyber security is an essential and indispensable part of the same. The sooner we formulate and adopt the same the better it would be for the larger interests of India.

Friday, June 10, 2011

Legal Enablement Of ICT Systems In India

Information and communication technology (ICT) is both a boon and bane. It is a boon as it facilitates e-governance, e-commerce and e-delivery of public services. It is a bane as it has a darker side as well. ICT is very frequently used for committing various cyber contraventions and cyber crimes.

This is the reason why we must have a strong and stringent legal framework to regulate ICT dealings. Legal enablement of ICT systems ensures formulation of legal framework for various cyberspace dealings.

Legal enablement covers areas like cyber law, cyber security, cyber forensics, critical ICT infrastructure protection, anti cyber warfare steps, anti cyber espionage steps, anti cyber terrorism steps, etc.

Legal enablement also includes policy issues like cyber law policy, cyber security policy, cyber forensics policy, etc. At the same time legal enablement also ensures a legal framework for all these components. A cyber crisis management plan is also an essential part of the legal enablement initiative of any nation.

In the national context we have no legal enablement of ICT systems in India. We have information technology act 2000 as the cyber law of India that is trying to give some legitimacy to cyberspace dealings in India. However, in the desire to get everything at a single place, the cyber law of India has failed to achieve even a single aspect of legal enablement.

There is no deterrent for cyber criminals in India as almost all the cyber crimes are bailable. Mandatory e-governance services in India are missing and the cyber law of India has imposed a blanket ban upon asking such services by Indiana citizens. The e-commerce environment of India is also not safe and sound. Lack of cyber security and encryption usage makes e-commerce of India highly vulnerable to cyber attacks.

India must repeal the cyber law of India and come up with separate laws on these aspects of legal enablement. As far as cyber security law and cyber forensics law are concerned, India has none.

It would be safe to presume that we have no legal enablement of ICT systems in India. India is not a part of international cyber law treaty and there is also no international cyber security treaty in existence. Thus, India is lax regarding legal frameworks, policy issues and cyber security requirements and the same need to be changed as soon as possible for the larger interest of India.

Tuesday, June 7, 2011

Cyber Security Policy Of India

Cyber Security is an issue that tries to protect and preserve the Information Technology Infrastructure (ITI) of a Nation. Since Cyberspace is boundary less it is possible to attack the ITI of any Nation from any place.

We are still dealing with the Cyber Security issues in India. Although India has formulated the Cyber Security Strategy but it is more on the side of prescribed guidelines alone. The practical and actual implementation of the same is still missing.

Policies and Strategies issues are best implemented practically and effectively if they are made part of the National Policies. Till now we have not formulated a National Cyber Security Policy of India that is implantable at National level.

The Cyber Security Policy of India must cover areas like Cyber Laws, Cyber Crimes, Transnational Technological Crimes, Cyber Attacks, Cyber Warfare, Cyber Terrorism, Cyber Espionage, Human Rights Protection in Cyberspace, Critical Infrastructure Protection Plan, Critical ICT Infrastructure Protection, Crisis Management Plan, etc.

Till now there is no National Cyber Security Policy of India that covers these issues and is implementing the same. Our websites are frequently defaced, strategic computers are often compromised, sensitive defence documents are occasionally stolen and cyber espionage against India is frequently committed.

I also understand that it is not possible to have an absolute Cyber Security. The notion of having an absolute Cyber Security is a “Myth” as we cannot ensure absolute Cyber security anywhere. There are exploits and vulnerabilities, both hardware and software based, that cannot be anticipated and tackled in advance. In fact, “Zero Days Exploits” are the most difficult one to anticipate and handle. In these types of exploits all Cyber Security Measures proves ineffective and futile.

Further, human beings are usually the weakest link in the Cyber Security infrastructure and Social Engineering is the easiest way to break into a Computer System. Besides being easy, Social Engineering can be incredibly cheap. Social Engineering is the hardest form of attack to defend against because an individual or organisation cannot protect itself with hardware or software alone.

Both Government Departments and Private Companies must have good employee’s awareness activities and information dealing policies in place and the employees must strictly follow these policies. The employees must be willing to ask relevant questions while dealing with a request to provide sensitive information.

Indian Government must also focus upon Techno Legal Cyber Security Skill Development for its employees and departments. Suitable Techno Legal Cyber Security Courses must be made available to Government departments and employees. All these issues must be made part of the Cyber Security Policy of India that should be formulated and implemented as soon as possible.