- Securing nation’s political & socio-economic interests from cyber threats
- 1st Gen: fire arms, line arrangements
- 2nd Gen: artillery, cavalry, infantry, steam engine, total warfare
- 3rd Gen: storm tactics, Blitzkreig, nuclear capabilities
- 4th Gen: unconventional, irregular, hybrid
Types of Warfare
- Unconventional Warfare
- use of indirect or covert approach
- to conduct activities
- resistance movements
- insurgency
- to coerce, disrupt or overthrow a govt
- eg. use of proxy forces, underground armies, use of surrogates, psyops
- eg. ISIS supports Khalistani Mvmt
- Irregular Warfare
- oldest form of warfare
- significant proportion of those fighting are not part of conventional security forces
- generally protracted, main aim not territorial but acquiring influence over ppl
- Hybrid Warfare
- combination
- exploits all vulnerabilities of opposition which include diplomatic, intelligence, military, economic, financial, legal, informational, political vulnerabilities
- DIEFLIP
Motivation behind Cyberwarfare
- Challenges w/ kinetic warfare
- deterrence distance
- asymmetry in cost, impact
- retaliation
- preference to offence
advantage of cyber warfare are mainly from disadvantages of conventional warfare
- conventional warfare will beget heavy sanctions
- deterrence distance created by introduction of nuclear technology makes it expensive (life, property) to engage in conventional war
Advantage of cyberwarfare
- Asymmetricity
- cost, impact, response
- conducted at state level, non state level
- long term or short term
- eg. targeted attack on country’s smart grid network is short term
- cyber espionage is long term
- dozen hackers cheaply equipped can bring down economy’s entire digital infra
- Plausible deniability
- cyber conflicts low intensity, non lethal, => don’t attack retaliation using conventional state instruments
- actors can be non state, attack be made to appear from diff jurisdiction => difficult to trace origin
- Combined warfare
- combine cyber capabilities w/ conventional military capabilities
- cyber warfare can be carried out even during peacetime
- Preference to offense
- internet collaborative, hence zero day vulnerabilities always remains
- what matters is speed, not deterrence
Cybersecurity
- acc to IT Act, cybersec is defined as securing computer devices, networks and information stored on them from unauthorized access, disclosure, disruption, modification or destruction
Cyberthreats faced by India
- Cybercrime
- defined as crimes carried out in cyberspace
- eg. phishing, hacking, DoS, cyberstalking, child pornography
- para social relationships
- intelligible awareness of other
- awareness exerts influence
- Cyber terrorism
- use of cyberspace by terror outfits to carry out unlawful attacks/threats of attacks against computer network, devices, information to intimidate or coerce a govt or its ppl towards the furtherance of socio political objectives
- Cyber warfare
- use of offensive action by nation state against others
- eg. Stuxnet - from Israel-USA against Iran’s nuclear program
- Op. Cuckoo Bees - by chinese state actor APD 41, stolen intellectual property worth trillions of dollars from 30MNC in USA
- eg. Viper Malware 2017 -
- russia military intelligence released Notpetya worm to attack ukraine militari establishments (Op. Acid Rain)
India vulnerability to cyber threats
India among top 5 targets in Asia pacific. Reasons are
- inc internet penetration
- 4% in 2007
- 45% in 2021
- massive digitization across various spheres
- e governance
- biggest citizen identity platform: Aadhar
- electronic money transfer increasing
- UPI, NEFT
- sizeable population at risk of cybercrime, esp. w/ digital divide
Implication of attacks
- siphoning off of 1.25L Cr in 2019
- personal details of 81Cr Indians leaked and put on dark web as result of ICMR db leak
- alleged chinese cyberattack on 5 AIIMS servers, compromising data of 3-4cr patients
- 2017, Petya ransomware disrupted shipping facilities an JLN Port Trust
- 2020, Mumbai hit by massive power outage, alleged few TO responsible
- 68% orgs in india have had atleast one ransomware attack
- acc to NCRB, 25% inc in registered cybercrime in India from 2021-22
Stages of Cyber Attack
- Planning: attacker selects target and particular weapon
- Reconnaissance: weapon introduced in cyber env where looks for vulnerability
- Replicate: post vulnerability identification, the weapon starts to replicated itself in stealth
- Assault: weapon starts attack
- Obfuscate: weapon my stay hidden or self destruct
- Withdraw: if both parties agree, weapon may be withdrawn
India’s Cyber Sec Architecture
Legal Front
- Information Act 2000 to formalize electronic contracts, regulate online txn
- initially aim to not prohibit cyber terrorism, cyber offence etc
- amendments made in 2008 to concern w/ cyber sec
- eg. sec 43A puts resp of protecting personal info of users on pvt compny
- now repealed 66A prohibited act of publishing annoying/menacing info
- similarly, 66C against identity theft
- 67B against child pornography
- 66F defines cyber terrorism
- National Cyber Security Policy 2013
- mentioned 5yr target for training & inducting 5L cyber sec professionals
- setting up nodal agency for protecting critical info infra
- fin incentive to pvt companies to strengthen cyber sec practices
- establish 24x7 cybersec tech to deduct & respond to cyber threats
- mandates development of IT infra acc to guidelines under ISO27001
- mandates public & pvt companies to hire chief information officer
- promotes collaboration b/w industry & research facilities
Institutional Front
- National Critical Information Infrastructure Protection Center (NCIIPC)
- nodal agency to create safe and secure critical info infra env
- CERT-in
- nodal agency for providing emergency response in case of cybersec incidents
- analyses and disseminates info to relevant stakeholders
- I4C - Indian Cybercrimes coordination center
- task to coordinate response to cyber attack
- CSK - Cyber Swachhta Kendra
- botnet, malware analysis centre
- detects malicious programs
- provides free tools to citizens to remove them
- NCRP - National Cybercrime Reporting Portal
- National Information Board
- main policy agency in context of cybersec
- headed by National Security Advisor (NSA)
- responsible for inter ministerial coordination
- National Cybersec Strategy 2020
Challenges
- Legal
- no dedicated procedural law concerning IT offences
- agencies rely on Indian Evidence Act, not effective for cyber
- BIS laid down comprehensive guidelines concerning collection & analysis of evidence but no legal backing
- Last IT Act amendment in 2008, not updated
- Institutional
- lack of coherence b/w various institutions
- lack of effectiveness
- procedural delays
- Infra
- india imports 70% telecom equipment
- vulnerable to bugs at manufacturing itself
- state forensic labs lack tech to carry out investigations of cyber crime
- over dependence on external servers for data storage
- minuscule spending of GDP on R&D
- Policy related
- National cybersec policy outdated
- india lacks comprehensive cybersec doctrine
- human resources
- lack of trained staff for investigation
- policy aim of 5L cybersec professionals unfulfilled
- delayed enactment of PDP legislation