• Securing nation’s political & socio-economic interests from cyber threats
  • 1st Gen: fire arms, line arrangements
  • 2nd Gen: artillery, cavalry, infantry, steam engine, total warfare
  • 3rd Gen: storm tactics, Blitzkreig, nuclear capabilities
  • 4th Gen: unconventional, irregular, hybrid

Types of Warfare

  • Unconventional Warfare
    • use of indirect or covert approach
    • to conduct activities
      • resistance movements
      • insurgency
    • to coerce, disrupt or overthrow a govt
    • eg. use of proxy forces, underground armies, use of surrogates, psyops
    • eg. ISIS supports Khalistani Mvmt
  • Irregular Warfare
    • oldest form of warfare
    • significant proportion of those fighting are not part of conventional security forces
    • generally protracted, main aim not territorial but acquiring influence over ppl
  • Hybrid Warfare
    • combination
    • exploits all vulnerabilities of opposition which include diplomatic, intelligence, military, economic, financial, legal, informational, political vulnerabilities
      • DIEFLIP

Motivation behind Cyberwarfare

  • Challenges w/ kinetic warfare
    • deterrence distance
    • asymmetry in cost, impact
    • retaliation
    • preference to offence

advantage of cyber warfare are mainly from disadvantages of conventional warfare

  • conventional warfare will beget heavy sanctions
  • deterrence distance created by introduction of nuclear technology makes it expensive (life, property) to engage in conventional war

Advantage of cyberwarfare

  • Asymmetricity
    • cost, impact, response
    • conducted at state level, non state level
    • long term or short term
    • eg. targeted attack on country’s smart grid network is short term
    • cyber espionage is long term
    • dozen hackers cheaply equipped can bring down economy’s entire digital infra
  • Plausible deniability
    • cyber conflicts low intensity, non lethal, => don’t attack retaliation using conventional state instruments
    • actors can be non state, attack be made to appear from diff jurisdiction => difficult to trace origin
  • Combined warfare
    • combine cyber capabilities w/ conventional military capabilities
    • cyber warfare can be carried out even during peacetime
  • Preference to offense
    • internet collaborative, hence zero day vulnerabilities always remains
    • what matters is speed, not deterrence

Cybersecurity

  • acc to IT Act, cybersec is defined as securing computer devices, networks and information stored on them from unauthorized access, disclosure, disruption, modification or destruction

Cyberthreats faced by India

  • Cybercrime
    • defined as crimes carried out in cyberspace
    • eg. phishing, hacking, DoS, cyberstalking, child pornography
    • para social relationships
      • intelligible awareness of other
      • awareness exerts influence
  • Cyber terrorism
    • use of cyberspace by terror outfits to carry out unlawful attacks/threats of attacks against computer network, devices, information to intimidate or coerce a govt or its ppl towards the furtherance of socio political objectives
  • Cyber warfare
    • use of offensive action by nation state against others
    • eg. Stuxnet - from Israel-USA against Iran’s nuclear program
    • Op. Cuckoo Bees - by chinese state actor APD 41, stolen intellectual property worth trillions of dollars from 30MNC in USA
    • eg. Viper Malware 2017 -
    • russia military intelligence released Notpetya worm to attack ukraine militari establishments (Op. Acid Rain)

India vulnerability to cyber threats

India among top 5 targets in Asia pacific. Reasons are

  • inc internet penetration
    • 4% in 2007
    • 45% in 2021
  • massive digitization across various spheres
    • e governance
  • biggest citizen identity platform: Aadhar
  • electronic money transfer increasing
    • UPI, NEFT
  • sizeable population at risk of cybercrime, esp. w/ digital divide

Implication of attacks

  • siphoning off of 1.25L Cr in 2019
  • personal details of 81Cr Indians leaked and put on dark web as result of ICMR db leak
  • alleged chinese cyberattack on 5 AIIMS servers, compromising data of 3-4cr patients
  • 2017, Petya ransomware disrupted shipping facilities an JLN Port Trust
  • 2020, Mumbai hit by massive power outage, alleged few TO responsible
  • 68% orgs in india have had atleast one ransomware attack
    • acc to NCRB, 25% inc in registered cybercrime in India from 2021-22

Stages of Cyber Attack

  1. Planning: attacker selects target and particular weapon
  2. Reconnaissance: weapon introduced in cyber env where looks for vulnerability
  3. Replicate: post vulnerability identification, the weapon starts to replicated itself in stealth
  4. Assault: weapon starts attack
  5. Obfuscate: weapon my stay hidden or self destruct
  6. Withdraw: if both parties agree, weapon may be withdrawn

India’s Cyber Sec Architecture

  • Information Act 2000 to formalize electronic contracts, regulate online txn
    • initially aim to not prohibit cyber terrorism, cyber offence etc
    • amendments made in 2008 to concern w/ cyber sec
    • eg. sec 43A puts resp of protecting personal info of users on pvt compny
    • now repealed 66A prohibited act of publishing annoying/menacing info
    • similarly, 66C against identity theft
    • 67B against child pornography
    • 66F defines cyber terrorism
  • National Cyber Security Policy 2013
    • mentioned 5yr target for training & inducting 5L cyber sec professionals
    • setting up nodal agency for protecting critical info infra
    • fin incentive to pvt companies to strengthen cyber sec practices
    • establish 24x7 cybersec tech to deduct & respond to cyber threats
    • mandates development of IT infra acc to guidelines under ISO27001
    • mandates public & pvt companies to hire chief information officer
    • promotes collaboration b/w industry & research facilities

Institutional Front

  • National Critical Information Infrastructure Protection Center (NCIIPC)
    • nodal agency to create safe and secure critical info infra env
  • CERT-in
    • nodal agency for providing emergency response in case of cybersec incidents
    • analyses and disseminates info to relevant stakeholders
  • I4C - Indian Cybercrimes coordination center
    • task to coordinate response to cyber attack
  • CSK - Cyber Swachhta Kendra
    • botnet, malware analysis centre
    • detects malicious programs
    • provides free tools to citizens to remove them
  • NCRP - National Cybercrime Reporting Portal
  • National Information Board
    • main policy agency in context of cybersec
    • headed by National Security Advisor (NSA)
    • responsible for inter ministerial coordination
  • National Cybersec Strategy 2020

Challenges

  • Legal
    • no dedicated procedural law concerning IT offences
    • agencies rely on Indian Evidence Act, not effective for cyber
    • BIS laid down comprehensive guidelines concerning collection & analysis of evidence but no legal backing
    • Last IT Act amendment in 2008, not updated
  • Institutional
    • lack of coherence b/w various institutions
    • lack of effectiveness
    • procedural delays
  • Infra
    • india imports 70% telecom equipment
    • vulnerable to bugs at manufacturing itself
    • state forensic labs lack tech to carry out investigations of cyber crime
    • over dependence on external servers for data storage
    • minuscule spending of GDP on R&D
  • Policy related
    • National cybersec policy outdated
    • india lacks comprehensive cybersec doctrine
  • human resources
    • lack of trained staff for investigation
    • policy aim of 5L cybersec professionals unfulfilled
    • delayed enactment of PDP legislation