Showing posts with label Critical Infrastructure Protection In India. Show all posts
Showing posts with label Critical Infrastructure Protection In India. Show all posts

Wednesday, November 23, 2011

Cyber Security Of Automated Power Grids Of India

Power sector reforms in India are in the pipeline. Among many suggested measures, some of them pertain to use of automated systems through IT intervention for sustained collection of accurate baseline data and automation of some electricity functions. The idea is good but is not free from problems like lack of expertise and inadequate cyber security in India.

Malware like Stuxnet and Duqu have already proved that critical infrastructures like power grids, nuclear facilities, satellites, defense networks, governmental informatics infrastructures, etc are vulnerable to sophisticated cyber attacks.

In the Indian context, the critical infrastructure protection of India is not in good shape. There is neither an implementable cyber security policy of India nor there is any critical ICT infrastructure protection policy of India.

In these circumstances, use of automated power grids in India should be undertaken only after making cyber security of India robust, reliable and effective. For instance, the supervisory control and data acquisition (SCADA) systems are used world over for managing automated water utilities and power grids. However, successful cyber attacks against these SCADA systems have result in great loss and productivity of these utilities.

SCADA may be the new cyber attack priority for cyber criminals and rouge nations. We must ensure sufficient cyber protection of SCADA systems in India in general and critical infrastructure in particular.

Consider a real life situation in India. The Restructured Accelerated Power Development and Reform Programme (R-APDRP) of UT electricity department will soon be implemented as the Joint Electricity Regulatory Commission ( JERC) has accorded its approval to the department for availing the funds from the central government through the Power Finance Corporation (PFC). These funds will be used towards the implementation of Part-A of R-APDRP scheme for creation of reliable and automated systems with IT intervention for sustained collection of accurate baseline data.

R-APDRP will have projects which would be undertaken in two parts - part A and part B. Part-A includes the projects for establishment of baseline data and IT applications for energy accounting/auditing and setting up IT based consumer service centres. Part-B shall include regular distribution strengthening projects. Part-A also covers SCADA implementation which facilitates centralised control of power supply position in Chandigarh. PFC has been appointed as a nodal agency for this Central Government funded scheme.

If cyber security aspects of automated electricity grids in India are taken care of, this e-governance drive would prove very useful and productive for power sector of India. We hope Indian government would consider all these aspects for the larger interest of power industry of India.

Saturday, October 29, 2011

India Is Investigating Duqu Malware

Of late sophisticated Malware have entered into the cyber crime market place. Whether it is state sponsored or private profiting, Malware is becoming a good choice for all. The evolution of Malware is also happening in an innovative, constant and quick manner.

From Stuxnet to the latest Malware Duqu the trend in this regard is absolutely clear. If nations are not well prepared on the front of cyber security, critical infrastructures would be vulnerable. While this is not a situation that requires a paranoid reaction yet this is at the least a wake up call for ensuring strong and robust cyber security.

In order to analyse the Duqu Malware, Indian officials from department of information technology (DIT) have recently seized computer equipment from a data center in Mumbai. They took several hard drives and other components from a server that was communicating with computers infected with Duqu.

While detailed investigation is still going on yet preliminary examination suggests that Duqu was developed by sophisticated cyber criminals to help lay the groundwork for attacks on critical infrastructure such as power plants, oil refineries and pipelines, etc. It is suspected to be another incidence of state sponsored cyber attack tactics to test future cyber capabilities.

Duqu, so named because it creates files with "DQ" in the prefix, was designed to steal secrets from the computers it infects. The target includes design documents from makers of highly sophisticated valves, motors, pipes and switches.

Monday, October 3, 2011

Cyber Warfare Against India

Cyber warfare is a concept that is still haunting the international community. The situation is so serious that north atlantic treaty organisation (NATO) has sought stronger cooperation with India to counter growing cyber threats.

Cyber warfare is still a murky area as different countries deal with cyber attacks and cyber warfare attacks differently. While countries like US are considering it as an act of aggression on the footing of war yet other countries are taking divergent views. However, all countries are willing to use every possible cyber capabilities as preventive and curative cyber methods.

Till United Nations (UN) steps in and enacts “universally acceptable” international cyber law treaty and international cyber security treaty, this problem would remain murky and difficult to resolve. Further, nothing can benefit more than an international cyber security cooperation that is urgently required.

The incidences of cyber attacks, cyber terrorism, cyber espionage, cyber warfare, etc are increasing against India. However, in the absence of India’s national cyber security policy, cyber security in India is a neglected field. We must urgently develop cyber warfare capabilities in India to thwart growing cyber attacks against India. Further, we must also formulate a cyber warfare policy in India that is presently missing.

Cyber warfare is also the reason why we need to ensure critical infrastructure protection in India and critical ICT infrastructure protection in India. In fact the growing cyber attacks are affecting Indian critical infrastructure. Thus, cyber security capabilities through techno legal cyber security trainings in India must be strengthened. We must stress upon cyber security skills development in India.

The situation is equivalent to a wake up call and Indian government must take urgent steps to strengthen Indian cyber security. The sooner it is adopted the better it would be for a safe and secure cyberspace of India.

Friday, June 3, 2011

Critical ICT Infrastructure Protection Policy Of India

Critical ICT Infrastructure Protection in India is in news thanks to the India US Homeland Security Dialogue. India has to go a long way before it can effectively protect its Critical ICT Infrastructures from Cyber Attacks. India is also all alone in its initiatives irrespective of Bilateral Agreements as there is no “International Norms” in this regard.

Further, absence of Cyber Security in India and Cyber Security Policy and Strategy of India has further complicated the matter. Naturally Indian Cyberspace is Vulnerable to Cyber Attacks, Cyber Terrorism, Cyber Warfare and Cyber Espionage. Absence of Cyber Warfare Policy of India has further complicated this situation.

The least Indian Government can do in this regard is to formulate a Critical ICT Infrastructure Protection Policy for India. These days a majority of crucial functions of Private Companies and Government are essentially connected with the Computers and Computers Systems. If these Computers or Computer Systems are compromised, much damage can be done to the Country where such breach has occurred.

At Perry4Law and Perry4Law Techno Legal Base (PTLB) we are working in the direction of formulating a world class Critical ICT Infrastructure protection Policy of India. We are analysing the “International Best Practices” in this regard so that a “Composite Policy” can be formulated in this regard.

We have also opened a Techno Legal Cyber Security Research and Training Centre (CSRTCI) that is analysing Techno Legal aspects of Cyber Law, Cyber Security, Cyber Forensics, Cyber Warfare, Cyber Espionage, Critical ICT Infrastructure Protection (CIIP), etc.

Perry4Law and PTLB can enter into a Public Private Partnership (PPP) Agreements with National and International Organisations like United Nations (UN), North Atlantic Treaty Organisation (NATO), Indian Government, Foreign Governments, etc on a mutually beneficial basis.

We are also working in the direction of “Harmonisation” of International Standards and Norms in the field of Cyber Law, Cyber Crimes, Cyber Security, etc. Interested Individuals or Organisations may Contact Us in this regard.

Now it is for the Indian Government to take the call and start working upon crucial Policies issues pertaining to Cyber Crimes, Cyber Security and Critical ICT Infrastructure Protection.