Showing posts with label Cyber Espionage Against India. Show all posts
Showing posts with label Cyber Espionage Against India. Show all posts

Thursday, February 9, 2012

National Critical Information Infrastructure Protection Centre (NCIPC) Of India

In the recent times, there is an increasing stress upon cyber security at the international level. This is so because cyber attacks are happening at the international level and all the countries are facing this threat.

Countries are trying to coordinate cyber security initiatives at national and international levels. However, cyber security in India is still not up to the mark. India is increasingly facing cyber attacks and cyber threats from foreign nationals.

The cyber laws and cyber security trends of India 2011 by Perry4Law and Perry4Law Techno Legal Base (PTLB) has clearly showed the cyber security vulnerabilities of India. The cyber law trends of India 2012 have also projected an increased rate of cyber crimes in India and cyber attacks against India in the year 2012.

For instance, cyber terrorism against India, cyber warfare against India, cyber espionage against India and cyber attacks against India have increased a lot. Presently, we do not have a strong cyber law to deter cyber attacks and cyber crimes. Further, we have no cyber security laws in India as well.

Cyber security is also crucial to protect critical infrastructure protection of India. Critical infrastructure protection in India requires a well formulated policy. Presently we have no critical infrastructure protection policy of India. Even critical ICT infrastructure protection in India is required.

A national critical information infrastructure protection centre (NCIPC) of India has been proposed. It intends to ensure critical infrastructure protection and critical ICT infrastructure protection in India.

There are few prerequisites that can make the NCIPC of India successful. Firstly, there must be a centralised ICT command centre of India that can coordinate various cyber security issues. Secondly, specialised agencies and authorities must be constituted for critical infrastructure areas like power, telecom, defense, etc. These agencies and authorities must coordinate with the centralised command centre for cyber security related issues.

Ministry of communication and information technology (MCIT) has already taken certain initiatives in this regard. For instance, a central monitoring system (CMS) project of India has been launched by MCIT to monitor and intercept electronic communications, messages and information. Further, a national telecom network security coordination board (NTNSCB) of India has also been proposed to strengthen the national telecom security of India.

Similarly, the home ministry of India has also launched national intelligence grid (Natgrid) project of India, crime and criminal tracking networks and systems (CCTNS) project of India, national counter terrorism centre (NCTC) of India, etc. These projects intend to strengthen the intelligence gathering and counter terrorism capabilities of India.

However, there is a big problem in the successful implementation of all the abovementioned projects and initiatives as well as the NCIPC of India. Indian government has been avoiding parliamentary oversight of these projects. This is a bad precedent that needs to be urgently taken care of. We need urgent parliamentary oversight for e-surveillance in India, Internet censorship in India, intelligence gathering in India, intelligence authorities of India, central bureau of Investigation, law enforcement agencies of India, Aadhar project of India, etc.

Even privacy laws in India, data security laws in India, data protection laws in India, etc are urgently required to be formulated. The cyber law of India must be suitably amended, perhaps repealed, to make a more robust and stringent cyber law of India. We need dedicated cyber security legal framework in India and cyber forensics laws in India.

For too long Indian parliament has been ignoring its crucial legislative business and it is high time for Indian parliament to do the needful in this regard. Contemporary techno legal issues cannot be left at the mercy and indifference of Indian parliament and Indian government as that may have serious adverse effects upon Indian economy and national security of India.

Monday, October 3, 2011

India's National Cyber Security Policy

Cyber security is an area that cannot be ignored by India. Cyber security in India has still not been paid enough attention. As a result important departments and computers of Indian governments are frequently breached and compromised.

India is poor at cyber security for numerous reasons. First and foremost being that cyber security policy of India is still missing. Till cyber security is considered at the policy level not much can be achieved.

However, politicians in India have no time for cyber security. Lack of political will towards a crucial topic like cyber security is evident when we have no national cyber security policy of India.

Indian national cyber security policy is also suffering on the count of legal enablement. Till now we have no legal enablement of ICT systems in India. We have no legal framework for cyber security in India. Even the cyber law of India is grossly deficient and is ineffective in tackling the growing cyber crimes and cyber attacks.

Naturally, the fronts like cyber warfare against India, cyber espionage against India, cyber terrorism against India, etc are still wide open for anybody and everybody to exploit.

Another factor that has resulted in poor cyber security in India is the growing incidences of industrial lobbying in India. Industrial lobbying is not allowing a strong cyber law and cyber security framework in India. Companies that may be required to follow stringent cyber law and cyber security practices are lobbying to make them redundant and powerless and Indian government is obliging the same.

India has waited for too long for an effective, robust and implementable cyber security policy. A national cyber security policy of India must be implemented as soon as possible for the larger interest of India and ignoring the same any further would only be counter productive.

Monday, August 22, 2011

Indian Strategic Departments Are Targeted By Cyber Espionage

The cases of cyber attacks and cyber espionage are not new to India. In the past computers located at crucial departments/ministries of India have been successfully targeted and compromised.

Even the computers at prime minister’s office (PMO) have been compromised for months without any knowledge of the same. Similarly, computers at ministry of external affairs (MEA), home ministry, defense computers, etc have been targeted and compromised in the past. Even the website of central bureau of investigation (CBI) was defaced and compromised in the past.

Now it has been reported that some of the top officials in the PMO, including principal secretary to the PM TKA Nair and national security advisor Shiv Shankar Menon, received warning calls from India’s technical intelligence agency, the National Technical Research Organisation (NTRO).

NTRO required all computer systems to be shut down and all computers were to be unplugged until its officials arrive at the PMO. Similarly, other key ministries were also asked to shut down the computer systems.

This was one of the most strategically targeted cyber attacks on India’s key ministries, as officials from the ministries of home affairs, defence, external affairs and the armed forces began to receive similar calls asking them to shut down their computer systems.

On July 12, 2011 NTRO officials noticed bulk emails from one address with an attached Word document titled “cms,ntro:dailyelec.mediareport (2011)” being sent to inboxes of key officials of India’s vast security architecture.

Other officials who received the email were joint secretaries and directors in the PMO, the special secretary (internal security) UK Bansal in the ministry of home affairs, seven key joint secretaries in the ministry of external affairs dealing with the US and Pakistan, and a host of other officials in BSF and CISF.

For several hours, the computer systems remained infected and compromised as NTRO officials struggled to make them Malware free. Luckily for them, a lot of good work had already been done to prepare for such an eventuality. In April and May this year, the agency observed a mass attack on India’s key security-related ministries. The NTRO contacted several key officials whose systems had been compromised for months.

Two of them were joint secretaries in the PMO and the national council secretariat that collates all the intelligence generated by agencies like RAW, IB and NTRO. The third target to be detected was the rear admiral who was posted in the “Perspective Plans” directorate of the Integrated Defence Headquarters, a joint armed forces setup.

NTRO officials were horrified that these official systems were targeted and infected with Malware. These were well-planned attacks meant to launch selective commands on the system that would be saved on a virtual drive created secretly by the Malware.

As the officials began to decode the systems, they approached the service provider MTNL to get access to their key communication nodes. Here, NTRO’s sensors picked up an additional 500 email addresses that had already been compromised by a similarly coded Malware. The report concluded that this was “a deliberate attempt to gain access to email addresses of key officials” through which major systems could be breached and compromised.

By July 20, Dr Nirmaljeet Singh Kalsi, a joint secretary in the ministry of home affairs sent out a detailed note spelling out the nature of the attack so as to prevent a future breach. It noted that “reports of cyber espionage attack” on various government installations had been received, and advised key ministries to lay down strict security protocol. The attack was being initiated by trusted email addressees that had actually been compromised as early as 2007.

Racing against time, NTRO officials analysed and reversed the Malware in a bid to detect the origin and nature of the attack. By July 8, a detailed three-page report was issued to all the key ministries to remain alert to a much more targeted attack. This effort minimised the damage of the July 12 attack and the breach was sealed in a matter of hours.

Tuesday, July 5, 2011

Indian Cyber Security And International Cooperation

It has been long felt that we need to strengthen the cyber security of India. As more and more cyber crimes are committed against India and severe cyber attacks launched against India this requirement has become even more demanding.

India needs to intensify its focus on cyber security issues at both national and international level and must promote more international cooperation regarding cyber security.

India must also develop and adopt existing best practices in cyber security area. Similarly, India must develop a more efficient cyber incident response mechanism to tackle cyber attacks.

Public private partnerships (PPP) on cyber security must be given more importance in India. Presently, PPP in India in the field of cyber security is in infancy stage. Similarly, there are very few international cooperations between India and foreign players regarding cyber security.

Perry4Law and Perry4Law Techno Legal Base (PTLB) suggest that to start with, we must urgently formulate a techno legal cyber security policy of India. The cyber security policy of India must cover issues like legal framework for cyber security, PPP model for cyber security, international cooperation for cyber security, cyber crisis management plan of India, human rights protection in cyberspace, etc.

Once the cyber security policy of India is at place, we must work in the direction of implementing the same in true letter and spirit. The growing incidences of cyber crimes, cyber attacks against India, cyber espionage against India, websites defacement and cracking, etc show that India has still not taken cyber security seriously.

While absolute cyber security is next to impossible to achieve yet a basic level cyber security audit of Indian government’s websites, computers and computer systems would show that they are vulnerable to cyber attacks.

Perry4Law and PTLB believe that we must at least start securing our websites, servers and government computers. Further, computers located at sensitive government departments and ministries must have a well defined cyber security policy and usage. We hope these suggestions of Perry4Law and PTLB would be useful for Indian government.

Tuesday, June 7, 2011

Cyber Security Policy Of India

Cyber Security is an issue that tries to protect and preserve the Information Technology Infrastructure (ITI) of a Nation. Since Cyberspace is boundary less it is possible to attack the ITI of any Nation from any place.

We are still dealing with the Cyber Security issues in India. Although India has formulated the Cyber Security Strategy but it is more on the side of prescribed guidelines alone. The practical and actual implementation of the same is still missing.

Policies and Strategies issues are best implemented practically and effectively if they are made part of the National Policies. Till now we have not formulated a National Cyber Security Policy of India that is implantable at National level.

The Cyber Security Policy of India must cover areas like Cyber Laws, Cyber Crimes, Transnational Technological Crimes, Cyber Attacks, Cyber Warfare, Cyber Terrorism, Cyber Espionage, Human Rights Protection in Cyberspace, Critical Infrastructure Protection Plan, Critical ICT Infrastructure Protection, Crisis Management Plan, etc.

Till now there is no National Cyber Security Policy of India that covers these issues and is implementing the same. Our websites are frequently defaced, strategic computers are often compromised, sensitive defence documents are occasionally stolen and cyber espionage against India is frequently committed.

I also understand that it is not possible to have an absolute Cyber Security. The notion of having an absolute Cyber Security is a “Myth” as we cannot ensure absolute Cyber security anywhere. There are exploits and vulnerabilities, both hardware and software based, that cannot be anticipated and tackled in advance. In fact, “Zero Days Exploits” are the most difficult one to anticipate and handle. In these types of exploits all Cyber Security Measures proves ineffective and futile.

Further, human beings are usually the weakest link in the Cyber Security infrastructure and Social Engineering is the easiest way to break into a Computer System. Besides being easy, Social Engineering can be incredibly cheap. Social Engineering is the hardest form of attack to defend against because an individual or organisation cannot protect itself with hardware or software alone.

Both Government Departments and Private Companies must have good employee’s awareness activities and information dealing policies in place and the employees must strictly follow these policies. The employees must be willing to ask relevant questions while dealing with a request to provide sensitive information.

Indian Government must also focus upon Techno Legal Cyber Security Skill Development for its employees and departments. Suitable Techno Legal Cyber Security Courses must be made available to Government departments and employees. All these issues must be made part of the Cyber Security Policy of India that should be formulated and implemented as soon as possible.

Wednesday, June 1, 2011

Cyber Security In India

Cyber security in India is not upto the mark and is an ignored world. Further, India has no cyber security policy and strategy that can be implemented under any legal framework. Merely mentioning that India has formulated a cyber security strategy or policy is not enough till it has a force of law.

One area that India has not touched at all pertains to enactment of cyber security laws. Till now we have no cyber security laws in India. Of course, one or two vague provisions have been incorporated in the information technology act, 2000 (IT Act 2000) of India that happens to be the sole cyber law of India.

Even the cyber law of India is weak and ineffective in tackling the fast growing cyber crimes in India. Many of the provisions contained in the IT Act 2000 have crossed the limits of constitutionality. This has made a dominant part of Indian cyber law unconstitutional. In fact, so bad is the position that a need to repeal the cyber law of India has been felt these days.

So we have neither a policy/strategy for cyber security nor legal framework for its implementation. All we have are uncodified and non implementable words that have no significance and legal value.

India has faced many cyber attacks in the past. Many of them were not detected for a very long period of time. Indian websites are regularly defaced by cyber miscreants. Cases of cyber espionage are rampant in India. Sensitive and strategic defence forces and ministries computer systems are frequently breached and sensitive data is occasionally stolen.

Perry4Law and Perry4Law Techno Legal Base (PTLB) firmly believe that it is high time for India to formulate effective cyber security policies/strategies and cyber security laws in India. Further the cyber law of India must also be repealed and a strong and robust law must be enacted that is also constitutionally and legally sound.

Wednesday, May 18, 2011

India-US Homeland Security Dialogue

India and United States (US) have in the past worked in the direction of homeland security. In fact a cyber security forum was started between India and US that faced some troubles and it became obsolete. Now talks are in progress to revive Indo US homeland security dialogue once more.

A special emphasis has been laid upon counter-terrorism co-operation, intelligence sharing, technology transfers and capacity building. Homeland security in India is at the infancy stage. Issues like cyber law, cyber security, cyber espionage, cyber terrorism, cyber warfare, etc are still not considered while formulation national policies of India.

At Perry4Law Techno Legal Base (PTLB) we are managing the exclusive techno legal cyber security research and training centre of India (CSRTCI). The centre is covering areas like cyber law, cyber security, cyber forensics, critical ICT infrastructure protection, cyber warfare, cyber terrorism, cyber espionage, national counter terrorism centre (NCTC), national intelligence grid (Natgrid) of India, crime and criminal tracking networks and systems (CCTNS), etc.

CSRTCI is supported by Cyberspace Human Rights Protection Centre of India that is working in the direction of reconciling the conflicting interests of national security and civil liberties protection.

The proposed Indo US homeland security dialogue must address many crucial issues ranging from cyber law to cyber security. Issues like encryption, technology transfer, international cooperation to fight cyber crimes and terrorism, etc must also be a part of national policies of both US and India.

PTLB believes that besides addressing these issues the proposed India US dialogue must also concentrate upon mutual trainings and skills development issues in the abovementioned fields. India particularly needs skill development trainings for intelligence gathering and their analysis. In all probability, this would be a fruitful and productive dialogue between India and US.