💥Join UPSC 2027,2028 Mentorship (July Batch) + XFactor Notes & Microthemes PDF

GS Paper: Cyber Security

  • 5G: Security Features and Concerns

    5G

    Central Idea

    • With the arrival of 5G technology, all electronic devices will potentially be connected to the internet. Cyber damage scenarios, imagined only in dystopian fiction, could become a reality. A collaborative approach between the government, academia, and businesses is necessary to address these cyber security concerns and ensure that 5G technology is safe and secure for consumers.

    What exactly is 5G?

    • Latest advancement: 5G, or fifth-generation wireless technology, is the latest advancement in mobile communication and internet technology.
    • Higher frequency spectrum: 5G operates on a higher frequency spectrum than 4G, typically between 24 GHz to 90 GHz. This higher frequency range allows for faster data transfer rates and lower latency.
    • MIMO technology: 5G uses a technology called MIMO (Multiple Input Multiple Output) to transmit and receive multiple data streams simultaneously. This allows for greater capacity and faster speeds.
    • Network slicing: It also utilizes network slicing, which enables the creation of multiple virtual networks on a single physical network. This allows for more efficient use of network resources and can improve overall network performance.
    • Applications: 5G technology is expected to enable the development and implementation of emerging technologies such as self-driving cars, virtual and augmented reality, and smart cities.

    Security Features of 5G Technology

    • Security-by-Design Approach: 5G technology is designed with a security-by-design approach that embeds security features from the beginning. This approach ensures that security is an integral part of the technology, rather than an afterthought.
    • Strong Encryption Standards: 5G technology incorporates strong encryption standards that make it extremely difficult for attackers to access and use any information they might obtain. Even if an attacker manages to obtain some information, it will be in an unusable format.
    • Interconnected Device Protection: 5G technology also includes protocols that protect the confidentiality of interconnected devices. These protocols prevent unauthorized access and ensure that data transmitted between devices remains secure and private.

    5G

    What are the Concerns?

    • Inheriting past vulnerabilities: The initial wave of 5G will be built on existing 4G infrastructure, therefore, it will inherit vulnerabilities of the past.
    • Multiplying privacy concerns: More devices connected to the internet increase the scope of cyber-attacks. In a connected network, such attacks can spread like wildfire if not contained in time. Privacy concerns are bound to multiply as the number of devices increases.
    • Concerns about pre-ban imported equipment: A bulk of 5G network components have been imported and manufactured in factories based in China. Imports of such equipment have been banned. However, concern remains about the use of the equipment that was imported before the ban came into effect.
    • For instance, concerns over user privacy: Many countries including the USA and Canada have expressed concerns over protocols used by Huawei and ZTE that compromise the privacy of users.

    What can be done to Ensure 5G Security

    • Collaborative efforts between government, academia, and businesses: Governments should work with industry experts and academia to develop comprehensive security measures and policies that align with the rapidly evolving technological landscape.
    • Ongoing security testing: Telecom companies should perform regular security testing of their 5G infrastructure to identify vulnerabilities and address them before they can be exploited by attackers. Telecom companies and ethical hackers can be invited to test infrastructure.
    • For instance: C-DOT’s 5G alliance focuses on security aspects, it needs to be scaled up as a Center of Excellence involving IITs and CERT-In.
    • Reward mechanisms: Offering incentives to 5G service providers who adhere to high security standards can promote better security practices across the industry.
    • Consumer education: Government agencies like CERT-In can publish easy-to-understand advisories to educate end-users on best practices to protect themselves and their devices from potential security breaches.
    • Greater responsibility: All stakeholders must assume greater responsibility to protect the 5G ecosystem from cyber threats.
    • International cooperation: International cooperation between governments and organizations can help establish global standards and guidelines for 5G security, promoting greater consistency and transparency in security practices.

    Conclusion

    • Consumers are at the heart of the 5G ecosystem and need to be aware of the security challenges. Exciting times await us in 2023. All stakeholders need to prepare for the security challenges of the 5G package.

    Mains Question

    Q. Technology upgrade comes with advantages and challenges. In this light discuss security features concerns related to the implementation of 5G technology?


    Are you an IAS Worthy Aspirant? Get a reality check with the All India Smash UPSC Scholarship Test

    Get upto 100% Scholarship | 900 Registration till now | Only 100 Slots Left


     

  • Cyberattacks: India’s Opportunity To Conceptualize Global Cyber Security Framework

    Cyberattacks

    Central Idea

    • The past few weeks have highlighted the soft underbelly of our fast-expanding digital networks. Ransomwares have emerged as the most predominant of malicious cyberattacks. Here, the perpetrators demand hefty payments for the release of withheld data. Data show that over 75% of Indian organisations have faced such attacks, with each breach costing an average of ₹35 crore of damage.

    Get your Rs 10,000 worth of UPSC Strategic Package for FREE | PDFs, Zoom session, Tests, & Mentorship

    Two recent ransomware attacks

    1. Ransomware attack on AIIMS: The first was the ransomware attack on the servers of India’s premium institute, the All-India Institute of Medical Sciences. Nearly 40 million health records were compromised and it took over two weeks for the systems to be brought online.
    2. BlackCat breached Solar Industries Ltd.: Soon afterwards, a ransomware gang, BlackCat, breached the parent company of Solar Industries Limited, one of the Ministry of Defence’s ammunition and explosives manufacturers, and extracted over 2 Terabyte of data.

    Cyberattacks

    What is mean by Cyber-attack?

    • Cyberattacks are unwelcome attempts to steal, expose, alter, disable or destroy information through unauthorized access to computer systems.
    • These attacks can target various entities such as governments, businesses, organizations, or individuals, and can have serious consequences such as theft of sensitive information, financial loss, reputational damage, or disruption of critical services.

    Who is behind cyberattacks?

    • Criminal organizations, state actors and private persons can launch cyberattacks against enterprises. One way to classify cyberattack risks is by outsider versus insider threats.
    1. Outsider threats: External cyber threats include; Organized criminals or criminal groups Professional hackers, like state-sponsored actors, Amateur hackers, like hacktivists
    2. Insider threats: Insider threats are users who have authorized and legitimate access to a company’s assets and abuse them either deliberately or accidentally. They include, Employees careless of security policies and procedures, Disgruntled current or former employees, Business partners, clients, contractors or suppliers with system access

    Growing vulnerability

    • There are malwares that could infect all kinds of computer systems: With the lines between the physical and digital realms blurring rapidly, every critical infrastructure, from transportation, power and banking systems, would become extremely vulnerable to the assaults from hostile state and non-state actors.
    • For instance; Cyber capabilities are also playing a pivotal role: As seen in the ongoing conflict in Ukraine, where electronic systems in warheads, radars and communication devices have reportedly been rendered ineffective using hacking and GPS jamming.
    • Cyber security breaches would only increase: With the introduction of 5G and the arrival of quantum computing, the potency of malicious software, and avenues for digital security breaches would only increase.
    • For instance: This year, cybercrimes are expected to cause damage worth an estimated $8 trillion worldwide.

    India’s cybersecurity architecture

    • CERT-In: In 2022, the Indian Computer Emergency Response Team (CERT-In), which is India’s cybersecurity agency, introduced a set of guidelines for organisations to comply with when connected to the digital realm. This included the mandatory obligation to report cyberattack incidents within hours of identifying them, and designating a pointsperson with domain knowledge to interact with CERT-In.
    • Draft Digital Personal Protection Bill, 2022: India’s draft Digital Personal Protection Bill 2022 proposes a penalty of up to ₹500 crore for data breaches.
    • Defence Cyber Agency (DCyA): Recently, India’s armed forces created a Defence Cyber Agency, capable of offensive and defensive manoeuvres. All Indian States have their own cyber command and control centres.
    • Cybercrime Co-ordination centre: The Indian Cybercrime Co-ordination Centre (I4C) established by the Ministry of Home Affairs, acts as a nodal point in the response against cybercrime by coordinating with state police forces across the country. It also co-ordinates the implementation of mutual legal assistance treaties (MLAT) with other countries.

    Have you heard about “Bluebugging”?

    • It is a form of hacking that lets attackers access a device through its discoverable Bluetooth connection.
    • Once a device or phone is blue-bugged, a hacker can listen to the calls, read and send messages and steal and modify contacts.
    • It started out as a threat for laptops with Bluetooth capability. Later hackers used the technique to target mobile phones and other devices.

    Limitations In India’s cybersecurity infrastructure

    • Lack of tools to identify: Most organisations lack the tools to identify cyberattacks, let alone prevent them.
    • Scarcity of cybersecurity professional: India also faces an acute scarcity of cybersecurity professionals. India is projected to have a total workforce of around 3,00,000 people in this sector in contrast to the 1.2 million people in the United States.
    • Private sector participation is limited: Most of our organizations are in the private sector, and their participation remains limited in India’s cybersecurity structures.

    Global understanding is essential

    • International cooperation is critical: With most cyberattacks originating from beyond our borders, international cooperation would be critical to keep our digital space secure. It would also be a cause which would find resonance abroad.
    • Cybersecurity treaties: India has already signed cybersecurity treaties, where the countries include the United States, Russia, the United Kingdom, South Korea and the European Union.
    • Multinational frameworks are there but there is no truly global framework: Even in multinational frameworks such as the Quad and the I2U2 (which India is a member of) there are efforts to enhance cooperation in cyber incident responses, technology collaboration, capacity building, and in the improvement of cyber resilience. Yet, there is no truly global framework, with many operating in silos.
    • UNGA established two processes on ICT: The United Nations General Assembly establish two processes on the issues of security in the information and communication technologies (ICT) environment.
    • The Open-ended Working Group (OEWG), comprising the entire UN membership, established through a resolution by Russia.
    • The other is the resolution by the U.S., on the continuation of the Group of Governmental Experts (GGE), comprising 25 countries from all the major regions.
    • Differ vastly on many aspects of Internet: The two antagonistic permanent members of the UN Security Council, counted among India’s most important strategic partners, differ vastly on many aspects of the Internet, including openness, restrictions on data flow, and digital sovereignty. Amidst the turbulent current world events, these UN groups would struggle to have effective dialogues.

    Conclusion

    • The G-20 summit this year in India, which will see participation by all the stakeholders driving the global levers of power, is a rare opportunity to bring together domestic and international engagement groups across the spectrum, and steer the direction of these consultations. India could make an effort to conceptualize a global framework of common minimum acceptance for cybersecurity. This would be one of the most significant contributions made by any nation towards collective security in modern times.

    Attempt UPSC 2024 Smash Scholarship Test | FLAT* 100% OFF on UPSC Foundation & Mentorship programs

  • Budget and the Digital Governance

    Budget

    Context

    • 2023 promises to be a landmark year for technology and digitisation in India. The Union Budget indicates growing prioritisation of these areas. For instance, the Digital India programme has been allotted Rs 4,795.24 crore, the allocation to the Ministry of Electronics and IT has nearly doubled, and there is a 1,000 per cent increase in the funding for the Artificial Intelligence and Digital Intelligence Unit. But something crucial is amiss.

    Crack Prelims 2023! Talk to our Rankers

    What is the issue?

    • Budget has deep discord between pace of the digitisation and legal policy: Many of the initiatives announced with the budget reinforce the deep discord between the pace of digitisation efforts, and the implementation of effective legal frameworks to strengthen privacy and cybersecurity.

    Budget

    What is Anonymised data?

    • Anonymised data includes data that does not contain Personally Identifiable Information (PII) like name, age, phone number, address, etc., or data from which PII has been removed.

    Analysis: Privacy deficit in India

    • New National Data Governance Policy: A new National Data Governance Policy is going to be introduced to enable access to anonymised data. However, several studies have demonstrated the ease with which anonymised data can be reverse-engineered to identify individuals. Current anonymisation techniques are inadequate and do not guarantee privacy protection.
    • For instance: A study in 2019 was able to accurately reidentify 99.98 per cent of Americans in an anonymised dataset, including information held by the US government on more than 11 million people.
    • Shortfall in Draft Digital Data Protection Bill, 2022: The current Draft Digital Data Protection Bill, 2022, falls short and fails to incorporate safeguards from previous rounds of consultations and even earlier iterations of the Bill.
    • For instance: The 2021 draft imposed a penalty for the intentional reidentification of an individual’s anonymized personal information. This provision has been done away with, amplifying concerns around insufficient limitations and safeguards for privacy.
    • No effective legislative safeguards to prevent access to personal information: The budget also proposes privacy-invasive changes to the Income Tax search and seizure provisions in view of the increased use of technology and digitization. IT officials could seek the assistance of experts to access digital devices and encrypted data. Such broad authorizations are bound to increase the scope for arbitrariness and misuse.

    Budget

    What issues need to be addressed for expanding the scope of DigiLocker?

    • The budget proposes expanding the scope of DigiLocker. For this measure to truly serve the objective of “Trust Based Governance”, two issues need to be addressed:
    • Strengthening of the cybersecurity infrastructure: Strengthening of the cybersecurity infrastructure, including implementation of the long-awaited National Cyber Security Strategy, to inspire people’s trust, and potentially avert situations like the one in 2020 where 3.8 crore DigiLocker accounts were compromised.
    • Preventing scope creep of Aadhaar: Prevent the continuing scope creep of Aadhaar, which is increasingly being made mandatory not only to avail services and benefits but also to exercise fundamental rights such as voting. The negative human rights impact of the forced, widespread use of Aadhaar has been well-documented.

    Did you know?

    • DigiLocker, a government-run cloud-based platform for storing, sharing, and verifying documents and certificates, to make it a one-stop solution of reconciliation and updating of identity and addresses with Aadhaar as foundational identity.

    Budget

    Conclusion

    • The World Economic Forum’s Global Cybersecurity Outlook 2023 finds that data privacy and cybersecurity regulations are effective for reducing cyber risks. Many new laws have been assured this year on data protection, telecom, internet governance and cybersecurity. As the country kickstarts its G20 presidency and prepares to be a leader in this space, we would do well to prioritise the development of exemplary, rights-respecting privacy and cybersecurity regimes.

    Mains question

    Q. For the potential of anonymised data to be unleashed without jeopardising people’s privacy, India first needs a robust data protection law. Discuss.

    (Click) FREE 1-to-1 on-call Mentorship by IAS-IPS officers | Discuss doubts, strategy, sources, and more

  • The world of Cyberspace and Cyber sovereignty

    Cyber sovereignty

    Context

    • A state’s desire to control ‘cyberspace’ within its borders is achieved by exercising what is called ‘cyber sovereignty’. While some countries such as the United States (US) support the free flow of information, others like China, by default, restrict the flow for its citizens, leading to the fragmentation of the internet.

    Click and get your FREE Copy of CURRENT AFFAIRS Micro Notes

    What is mean by Cyber threat?

    • A cyber threat or cyber security threat is defined as a malicious act intended to steal or damage data or disrupt the digital wellbeing and stability of an enterprise.
    • Cyber threats include a wide range of attacks ranging from data breaches, computer viruses, denial of service, and numerous other attack vectors.

    What is cyberspace?

    • Defined by Cyber security expert Daniel Kuehl: cyberspace is a global domain within the information system whose distinctive and unique character is framed by the use of electronics and the electromagnetic spectrum to create, store, modify, exchange, and exploit information via independent and interconnected networks using information-communication technologies.
    • Traditionally three layers of cyberspace: Traditionally, cyberspace was understood only in three layers: the physical/hardware, neural/software, and data.
    • Forth layer of social interaction and sovereignty: Alexander Klimburg, in his book The Darkening Web, introduced a fourth layer that deals with the social interaction among the three layers: “If cyberspace can be said to have a soul or mind, this is where it is. Establishing control over all the layers is necessary to build sovereignty in cyberspace.

    Cyber sovereignty

    What is Cyber sovereignty?

    • Term coined by Bruce Schneir: One of the leading voices in internet governance, Bruce Schneier, has coined the term as the attempt of governments to take control over sections of the internet within their borders.
    • It is about Internet governance: The term cyber sovereignty stems from internet governance and usually means the ability to create and implement rules in cyberspace through state governance.
    • Cyber sovereignty does not necessarily mean governance by state: Cyber sovereignty does not necessarily have to mean governance by a state. It first and foremost refers to the ability to create and implement rules in cyberspace. Alternatively, one could say it refers to the authority to speak the law, i.e., having juris-diction, in cyberspace.
    • Technology that drives policy decisions: In contrast to other technologies whose development is driven by policy, here it is technology which drives policy decisions. These characteristics make cyberspace governance complex and lead to confrontations among states and other stakeholders.

    Whether states should be held accountable for cyber-attacks emanating from their territory?

    • Sovereignty as defined by ICJ: The International Court of Justice (ICJ) defines sovereignty as that which confers rights upon states and imposes obligations on them. This implies that states must control their cyber infrastructure and prevent it from being knowingly or unknowingly used to harm other states and non-state actors.
    • Who comes under the cyber sovereignty ambit: The state, or the citizens of the state, if involved in attacking other states or non-state actors’ cyber facilities, also come under the ambit of cyber sovereignty.

    Cyber sovereignty

    Implications of Cyber sovereignty

    • Cyber sovereignty restricts the free flow of information: The internet was created to promote the free flow of information, but cyber sovereignty works the other way around. Restricting the flow of information can also put global businesses at risk due to the lack of interoperability it leads to.
    • It may lead to data imperialism: Control over the data could lead to new forms of colonialism and imperialism, commonly referred to as ‘data colonisation’ and ‘data imperialism’ in the digital era. States and private players can overreach their powers and violate human rights through cyberspace surveillance, controlling information flow, and enforcing internet shutdowns.
    • Implications from the fragmentation of the internet to violation of human rights: The implications are broad, impinging on citizens’ rights such as privacy, freedom of expression, access to information, press freedom, freedom of belief, non-discrimination and equality, freedom of assembly, freedom of association, due process and personal security.
    • For instance: Access to geolocation data can give insights into people who participated in a protest. Further, based on a user’s online behaviour, it is possible to determine a person’s sexual orientation, political affiliation and religious beliefs.

    Cyber sovereignty

    Example to understand the Implication of cyber sovereignty

    • In 2009, seeking justice for their co-workers whom the Han Chinese killed in a doll factory, Uighurs, a Muslim minority community in China, organised a protest using Facebook and Uighur-language blogs.
    • Following this incident, Facebook and Twitter were blocked across the country, and the internet was shut down for ten months in the region.
    • Following the incident, the Chinese government, with the help of the private sector, developed AI-enabled applications like the Integrated Joint Operations Platform (Ijop) to monitor the daily activities of Uighur Muslims. This app obtains information like skin colour, facial features, properties owned, payments, and personal relationships, and reports if there are any suspicious activities. An investigation is initiated if the systems flag any person. Data is gathered 24/7 to carry out mass surveillance.

    Value addition notes: Consider these for Essays

    • Unlike other spaces such as land, sea, air, and outer space, cyberspace was created by humans; therefore, complete control can be established over it.
    • Countries have tried to frame policies and rules to regulate cyberspace by building the necessary infrastructure.
    • This can be seen as either a defensive mechanism that states use to protect their own critical infrastructure or a framework adopted to exploit other states’ resources.
    • It has led to a security dilemma and added fuel to the fire of great-power politics.
    • Realising its importance, states have started to see cyberspace as equivalent to physical territory, and are building virtual walls to protect their ‘cyber territory’ with the help of various technologies.

    Conclusion

    • It is often said that information is wealth, competition has developed between states, and between state and non-state actors, to control and access this wealth. The dichotomy of states trying to protect the data generated in their territory by introducing data protection laws but, simultaneously, wanting to exploit other states’ data is adding to the complexity.

    Mains question

    Q. Technological advancements have made cyberspace an integral part of human lives. In this context, what do you understand by Cyber sovereignty. Discuss the implications of cyber sovereignty.

    (Click) FREE 1-to-1 on-call Mentorship by IAS-IPS officers | Discuss doubts, strategy, sources, and more

  • Draft cybersecurity strategy has been formulated: Centre

    The National Security Council Secretariat (NSCS) has formulated a draft National Cyber Security Strategy, which holistically looks at addressing the issue of security of national cyberspace, the government informed the Lok Sabha.

    What is the National Cyber Security Strategy?

    Conceptualised by the Data Security Council of India (DSCI), the report focuses on 21 areas to ensure a safe, secure, trusted, resilient, and vibrant cyberspace for India.

    The main sectors of focus of the report are:

    • Large scale digitisation of public services: There needs to be a focus on security in the early stages of design in all digitisation initiatives and for developing institutional capability for assessment, evaluation, certification, and rating of core devices.
    • Supply chain security: There should be robust monitoring and mapping of the supply chain of the Integrated circuits (ICT) and electronics products. Product testing and certification needs to be scaled up, and the country’s semiconductor design capabilities must be leveraged globally.
    • Critical information infrastructure protection: The supervisory control and data acquisition (SCADA) security should be integrated with enterprise security. A repository of vulnerabilities should also be maintained.
    • Digital payments: There should be mapping and modelling of devices and platform deployed, transacting entities, payment flows, interfaces and data exchange as well as threat research and sharing of threat intelligence.
    • State-level cyber security: State-level cybersecurity policies and guidelines for security architecture, operations, and governance need to be developed.

    What steps does the report suggest?

    To implement cybersecurity in the above-listed focus areas, the report lists the following recommendations:

    • Budgetary provisions: A minimum allocation of 0.25% of the annual budget, which can be raised up to 1% has been recommended to be set aside for cyber security.
    • Ministry-wise allocation: In terms of separate ministries and agencies, 15-20% of the IT/technology expenditure should be earmarked for cybersecurity.
    • Setting up a Fund of Funds: The report also suggests setting up a Fund of Funds for cybersecurity and to provide central funding to States to build capabilities in the same field.
    • R&D, skill-building and technology development: The report suggests investing in modernisation and digitisation of ICTs, setting up a short and long term agenda for cyber security via outcome-based programs and providing investments in deep-tech cyber security innovation.
    • National framework for certifications: Furthermore, a national framework should be devised in collaboration with institutions like the National Skill Development Corporation (NSDC) and ISEA (Information Security Education and Awareness) to provide global professional certifications in security.
    • Creating a ‘cyber security services’: The DSCI further recommends creating a ‘cyber security services’ with cadre chosen from the Indian Engineering Services.
    • Crisis management: For adequate preparation to handle crisis, the DSCI recommends holding cybersecurity drills which include real-life scenarios with their ramifications. In critical sectors, simulation exercises for cross-border scenarios must be held on an inter-country basis.
    • Cyber insurance: Cyber insurance being a yet to be researched field, must have an actuarial science to address cybersecurity risks in business and technology scenarios as well as calculate threat exposures.
    • Cyber diplomacy: Cyber diplomacy plays a huge role in shaping India’s global relations. To further better diplomacy, the government should promote brand India as a responsible player in cyber security and also create ‘cyber envoys’ for the key countries/regions.
    • Cybercrime investigation: It also suggests charting a five-year roadmap factoring possible technology transformation, setting up exclusive courts to deal with cybercrimes and remove backlog of cybercrimes by increasing centres providing opinion related to digital evidence under section 79A of the IT act.
    • Advanced forensic training: Moreover, the DSCI suggests advanced forensic training for agencies to keep up in the age of AI/ML, blockchain, IoT, cloud, automation.
    • Cooperation among agencies: Law enforcement and other agencies should partner with their counterparts abroad to seek information of service providers overseas.

    What next?

    • India has to contend with the importance and necessity of cyber offences as much as cyber defence.
    • As of today, India’s primary or possibly only response measures appear to be defensive.
    • India has to also invest in more offensive cyber means as a response.

     

     

    Click and get your FREE Copy of CURRENT AFFAIRS Micro Notes

    (Click) FREE 1-to-1 on-call Mentorship by IAS-IPS officers | Discuss doubts, strategy, sources, and more

  • QUAD and the Telecom network security

    QUAD

    Context

    • The advent of 5G provides the Quad or the Quadrilateral Security Dialogue of the United States (US), Japan, Australia and India, a unique opportunity to demonstrate how democracies can engage in effective technology collaboration.

    Click and get your FREE Copy of CURRENT AFFAIRS Micro Notes

    Background: The Huawei and QUAD response

    • Huawei’s connection with Chinese Communist Party: Recognising the risks that companies like Huawei, which is connected to the Chinese Communist Party, pose to telecommunications networks, each member country of the Quad has taken steps to ensure secure and resilient access to 5G.
    • Australia’s measure: Australia, for one, banned Huawei from its 5G rollout in 2018 and did the same with ZTE, citing national security concerns.
    • US concerns: For its part, the US has been raising concerns about Huawei since 2012, and doubled-down on its efforts in 2019 by adding Huawei to the Entity List.
    • Japan creating Open RAN: Japan, meanwhile, a long-time leader in the telecommunications space has accelerated its efforts to create ‘Open Radio Access Networks (Open RAN)’, which promote vendor diversification and competition for better solutions.
    • India 5G and conflict with China on border: India took what it called a “step towards the new era” by deploying its first 5G services in select cities in October 2022; it is aiming to extend the network across the country over the next few years. India is unlikely to include Huawei in its networks, given the clash with Chinese forces in Galwan Valley in June 2020 and concerns about vendor trustworthiness.

    QUAD

    QUAD alignment on securing 5G telecom networks

    • Agreement in first meeting: During the first in-person leaders’ meeting in September 2021, Quad countries agreed to “build trust, integrity, and resilience” into technology ecosystems by having suppliers, vendors, and distributors ensure strong safety and security-by-design processes, and committed to a “fair and open marketplace”.
    • Memorandum of cooperation on 5g suppliers: Later, at the fourth meeting in May 2022, partners signed a New Memorandum of Cooperation on 5G Supplier Diversification and Open RAN, and reaffirmed their desire to “collaborate on the deployment of open and secure telecommunications technologies in the region.”

    Why QUAD must cooperate on Network Security?

    • Fast emerging telecom technologies: For one, virtualised (software-based) networks will be the norm in the next 10 years, by which time 6G networks will begin to rollout. Early attention to security issues for emerging telecommunications technologies will help ensure that there is sufficient focus on security in the runup to 5G rollouts.
    • Interoperable software’s need to check: The Quad’s advocacy of Open RAN networks or network architectures that consist of interoperable software run on vendor-neutral hardware is another reason why there is a need to focus on software supply chain and software-based infrastructure security.
    • To ensure the comprehensive network strategy: Critics of Open RAN solutions often point to security concerns to argue against deploying these technologies. A comprehensive 5G security strategy is necessary to ensure trust in these networks.5G networks are critical infrastructure and it is imperative for states to ensure their security.
    • For instance: In 2018, Australian officials were the first to warn the public of the risks posed by untrustworthy vendors on 5G networks. Officials from the other Quad countries have followed suit and, along with key partners such as the European Union and United Kingdom, there is a clear consensus on the fundamental importance of secure and resilient communications networks.

    How QUAD will be a key player in Talent Development?

    • Bridging the gap of talent pool: Nations across the globe are suffering from a talent shortage in the technology domain. With heightened demand for high-skilled workers, like-minded nations must cultivate and share their expertise with one another to bridge critical gaps.
    • Quad Fellowship: this, the Quad created the Quad Fellowship, which will support 100 students per year to pursue STEM-related graduate degrees in the United States. This could be an effective way to grow the talent pipeline in a way that fills current and emerging needs.
    • Restructuring programs that can fulfil the current and future demand: Many nations have started to consider changes to immigration policies for high-skilled talent. Australia, for example, has raised its permanent immigration cap by 35,000 for the current fiscal year, and Japan is planning to expand its programs soon.
    • Creative ways of QUAD countries to recruit talent: Shortage of talent pool that all Quad countries are experiencing as they seek creative ways to grow their technology talent pool. Indian companies, for example, are beginning to recruit in rural areas to address significant tech worker shortages that may stymie a growing start-up ecosystem.

    QUAD

    What QUAD need to do?

    • Ensure close coordination: While these commitments are significant, maintaining momentum requires close coordination of resources and policies. No one country can build resilient, open, and secure telecommunications networks on its own, particularly as countries deploy 5G and think ahead to 6G.
    • Adhering to the goals and principles: To ensure that operationalisation moves forward in line with the Quad’s stated principles and goals, the member countries must work together in four key areas: standard-setting; security; talent development; and vendor diversity.
    • Develop a recruitment framework for telecommunications: Quad countries have an opportunity to set a precedent for other democracies by rethinking what it means to be “qualified” for a position. Companies can look beyond degrees during the hiring process and focus on relevant skills by jointly developing assessment criteria for worker readiness and performance.
    • Incentivise 5G deployment in underserved areas: To ensure that talent is not left out of the candidates’ pool for tech jobs, Quad members can agree to prioritise secure 5G deployment in rural regions. Lack of access to reliable information and communications can be a significant barrier to entering the workforce, and expanding 5G deployment is a critical aspect of broadening the talent pool.
    • Enhance public-private partnerships: As Quad countries build their infrastructure and talent pools at home, they must also think about other countries that only consider cost when choosing Huawei and other untrusted telecom providers. As such, the Quad could leverage public-private partnerships to bolster the presence of trusted companies in new locations. By using coordinated, strategic financial incentives, they will also have an opportunity to train and educate third country governments on the threats posed by untrusted 5G vendors. Consequently, they will contribute to broader network security and resiliency as 5G is more widely deployed.
    • Provide R&D incentives: The governments of the Quad countries should offer incentives to promote ongoing work in hardware, software, and security improvements, specific technologies such as high-band technology and end-to-end network slicing, and research areas including telehealth, energy research, and agriculture. A broad base of enabling technologies and applications would encourage new entrants into the market.

    Conclusion

    • Quad countries are well-positioned to accomplish plenty together. Of the many areas where they can progress, securing 5G is particularly promising due to the clearly stated objectives that Quad countries share. The Quad countries have the potential to provide a secure, flexible and open 5G network model to the Indo-Pacific and nations seeking democratic alternatives for their telecommunications infrastructure.

    Mains question

    Q. It is said that QUAD countries are well-positioned to secure the telecommunication network in the world. Discuss.

    (Click) FREE1-to-1 on-call Mentorship by IAS-IPS officers | Discuss doubts, strategy, sources, and more

  • What is Bluebugging?

    Bluebugging

    Cybersecurity experts note that apps that let users connect smartphones or laptops to wireless earplugs can record conversations, and are vulnerable to hacks through a process called Bluebugging.

    What is Bluebugging?

    • It is a form of hacking that lets attackers access a device through its discoverable Bluetooth connection.
    • Once a device or phone is blue-bugged, a hacker can listen to the calls, read and send messages and steal and modify contacts.
    • It started out as a threat for laptops with Bluetooth capability. Later hackers used the technique to target mobile phones and other devices.
    • Independent security researcher Martin Herfurt blogged about the threat of bluebugging as early as 2004.
    • He noted that the bug exploited a loophole in Bluetooth protocol, enabling it to download phone books and call lists from the attacked user’s phone.

    How does bluebugging hack devices?

    • Bluebugging attacks work by exploiting Bluetooth-enabled devices.
    • The device’s Bluetooth must be in discoverable mode, which is the default setting on most devices.
    • The hacker then tries to pair with the device via Bluetooth. Once a connection is established, hackers can use brute force attacks to bypass authentication.
    • They can install malware in the compromised device to gain unauthorised access to it.
    • Bluebugging can happen whenever a Bluetooth enabled device is within a 10-metre radius of the hacker.
    • However, according to a blog by VPN service provider NordVPN, hackers can use booster antennas to widen the attack range.

    Why is it a big threat?

    • Even the most secure smartphones like iPhones are vulnerable to such attacks.
    • Any app with access to Bluetooth can record users’ conversations with Siri and audio from the iOS keyboard dictation feature when using AirPods or Beats headsets, some app developers say.
    • Through Bluebugging, a hacker can gain unauthorised access to these apps and devices and control them as per their wish.

    How can one prevent bluebugging?

    Here are some of the ways to prevent bluebugging-

    1. Turning off Bluetooth and disconnecting paired Bluetooth devices when not in use,
    2. Updating the device’s system software to the latest version,
    3. Limiting the use of public Wi-Fi, and
    4. Using VPN as an additional security measure

     

    Click and get your FREE Copy of CURRENT AFFAIRS Micro Notes

    (Click) FREE1-to-1 on-call Mentorship by IAS-IPS officers | Discuss doubts, strategy, sources, and more

  • Online Women safety

    Women

    Context

    • India has one of the youngest youth demographics in the world and among the most active online. As online interactions increase, more content is created and shared among people, helping them form new and wonderful connections. Sometimes, however, these interactions also make them vulnerable to harm.

    What constitute as online harassment of women?

    • Sharing embarrassing and cruel content about a person to impersonation
    • Stalking and electronic surveillance
    • Non-consensual use of photography
    • Violent threats and hate speech
    • Defamation
    • Flaming- use of vitriolic and hostile messages including threats, insults
    • Trolling
    • The online harassment of women, sometimes called Cyber-sexism or cyber-misogyny, is specifically gendered abuse targeted at women and girls online.
    • It incorporates sexism, racism and religious prejudice.

    Women

    How women disproportionately get affected?

    • Often women are blamed: Often, crimes that disproportionately impact women devolve into mass panic and lead to an all too predictable top-down discourse around the need to protect our sisters and daughters.
    • Curbing the freedom of Women: The reaction, however well intentioned, will end up denying women their freedom and agency by their so-called protectors, many of whom are simply telling women to go offline, to be ashamed of expressing themselves, to stay in their lane.

    What is role of intermediaries in preventing such abuses?

    • Making intermediary liable: As of now, the intermediaries are not liable for any third-party data or communication link hosted or stored by them.
    • Mandatory Data retention by intermediaries: They are required to retain the requisite data for duration as prescribed by the Government and supply the same to the authorities concerned, as and when sought.
    • Punishment for Non-compliance is: Highlighting any contravention attracts punishment as prescribed under the IT Act.

    Women

    What are the Steps taken by the Government?

    • IT rules 2021: The Ministry of Electronics and Information Technology notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
    • Defined Categories of abuse: They include contents that are defamatory, obscene, pornographic, paedophilic, invasive of another’s privacy, insulting or harassing on the basis of gender, libellous, racially or ethnically objectionable, etc.
    • Prohibition on derogatory publications: The intermediaries, on the direction of the court or appropriate government agency, are prohibited from hosting, storing or publishing any information declared unlawful.
    • Removal of content within 24 hours: Within 24 hours from the receipt of a complaint from, or on behalf of, an individual about any offensive content, they are required to take all reasonable and practicable measures to remove or disable access to it.
    • Meetings of parliamentary committees: Various parliament committees in India have held meetings to discuss the issue of online safety of women over the years, and part of the government’s motivation in notifying the new IT rules had been rooted in the growing concern regarding the safety and security of users, particularly women and children. These are very good tangible steps.
    • Amendment in IT act should include the concerns of women: With the IT Act coming up for a rehaul, there is an opportunity to discuss in detail the nature of technology-facilitated abuse, capturing what this means, understanding how cases impact individuals as well as communities, the language needed to capture such offences and the punishment penalties, jail or even rehabilitation programmes for perpetrators. This could be the start of an era of evidence-based discussion.

    Women

    Conclusion

    • Despite these efforts, it is clear that women in India won’t feel safe online anytime soon unless society lets them. What could be helpful here is to elevate the public discourse around technology-facilitated abuse.

    Mains Question

    Q. How women are vulnerable against online abuse? What is the role of Intermediaries in online abuse case? What are governments efforts to make women friendly cyberspace?

    (Click) FREE1-to-1 on-call Mentorship by IAS-IPS officers | Discuss doubts, strategy, sources, and more

     

  • Cyber ​​threats as a challenge to Internal Security

    Cyber

    Context

    • As the 21st century advances, a new danger the cyber threat is becoming a daily monster. It is hardly confined to any one domain though the military is the one most often touted. Rather, it is the civilian sphere where the cyber threat is becoming more all-pervading today and, in turn, a serious menace.

    What is mean by Cyber threat?

    • A cyber threat or cyber security threat is defined as a malicious act intended to steal or damage data or disrupt the digital wellbeing and stability of an enterprise.
    • Cyber threats include a wide range of attacks ranging from data breaches, computer viruses, denial of service, and numerous other attack vectors.

    Cyber

    How Cyber threat is ever increasing?

    • Increasing Grey Zone Operations: Grey zone Operations which fall outside traditional concepts of conflicts have become the new battleground, especially in regard to cyber warfare. ‘Grey Zone Operations’ are already beginning to be employed to undermine the vital of a state’s functioning, a trend likely to grow. The convergence of emerging technologies alongside new hybrid usages, pose several challenges to nations and institutions.
    • Attack on examination: The recent arrest in India, of a Russian for hacking into computers involved in the conduct of examinations for entry into the Indian Institutes of Technology (IITs), is a reflection of how cybercriminals are significantly amplifying their Grey Zone Warfare’ tactics
    • Pervasive nature of cyber threat: What is most unfortunate is that not enough attention is being bestowed on the all-encompassing nature of the cyber threat. In the wake of the Russia-Ukraine conflict, the world seems awash with papers on artificial intelligence (AI)-driven military innovations and potential crisis hot zones, along with stray references to new forms of hybrid warfare.
    • Weaponization of everything: There is very little about the threat posed by cyber-attacks. Ignored also is the new reality of the weaponization of everything’ which has entered the vocabulary of threats. The latter clearly demands a ‘proto-revolutionary’ outlook on the part of policymakers, which is evidently lacking.
    • Becoming a Multi-dimensional threat: Lost in translation is also the nature of today’s weapon of choice, viz., cyber. This lack of awareness is unfortunate at a time when states clearly lack the necessary resilience to face a variety of multi-vector threats.
    • Cyber weapon as symbol of national Power: Cyber space has been described by Lt. Gen. Rajesh Pant (retired), India’s current national cyber security coordinator, as a “superset of interconnected information and communication technology, hardware, software processes, services, data and systems”. Viewed from this perspective, it constitutes a critical aspect of our national power.
    • Simultaneous attacks in multiple dimensions: Cyber threats are not confined to merely one set of conflicts such as Ukraine, where no doubt cyber tools are being extensively employed extending well beyond this and other conflicts of a varied nature. The cyber threat is in this sense all-pervading, embracing many regions and operating on different planes.

    Cyber

    Challenges to India’s cyber security infrastructure

    • Structural:

    1. Absence of any geographical constraints.

    2.Lack of uniformity in devices used for internet access.

    • Administrative:
    1. Lack of national-level architecture for cybersecurity
    2. Security audit does not occur periodically, nor does it adhere to the international standards.
    3. The appointment of the National Cyber Security Coordinator in 2014 has not been supplemented by creating liaison officers in states.
    • Procedural
    1. Lack of awareness in local police of various provisions of IT Act, 2000, and also of IPSC related to cybercrime.
    2. Lack of data protection regime.
    • Human Resource Related
    1. Inadequate awareness among people about the security of devices and online transactions.

    Cyber

    What are the Steps taken by India to strengthen cyber security?

    • Section 66F of ITA: Specific provision dealing with the issue of cyber terrorism that covers denial of access, unauthorized access, introduction of computer contaminant leading to harm to persons, property, critical infrastructure, disruption of supplies, ‘sensitive data’ thefts. Provides for punishment which may extend to life imprisonment.
    • National Cyber Security Policy 2013: Policy document drafted by the Department of Electronics and Information Technology. Established National Critical Information Infrastructure Protection Centre (NCIIPC) to improve the protection and resilience of the country’s critical infrastructure information; Create a workforce of 5 lakh professionals skilled in cybersecurity in the next 5 years.
    • National Critical Information Infrastructure Protection Centre (NCIIPC): It has been setup to enhance the protection and resilience of Nation’s Critical information infrastructure. It functions under the National Technical Research Organization (NTRO).
    • Computer Security through CERT-IN: Organization under the Ministry of Electronics and Information Technology with an objective of securing Indian cyberspace. The purpose of CERT-In is to respond to computer security incidents, report on vulnerabilities and promote effective IT security practices throughout the country. According to the provisions of the Information Technology Amendment Act 2008, CERT-In is responsible for overseeing the administration of the Act.
    • Cyber Surakshit Bharat Initiative: It was launched in 2018 with an aim to spread awareness about cybercrime and build capacity for safety measures for Chief Information Security Officers (CISOs) and frontline IT staff across all government departments.
    • Cyber Crisis Management Plan (CCMP): It aims at countering cyber threats and cyber-terrorism.
    • National Cyber Coordination Centre (NCCC): It seeks to generate necessary situational awareness of existing and potential cyber security threats and enable timely information sharing for proactive, preventive and protective actions by individual entities. National Cyber Security Coordinator (NCSC) under National Security Council Secretariat (NSCS) coordinates with different agencies at the national level for cyber security matters.
    • Cyber Swachhta Kendra: This platform was introduced for internet users to clean their computers and devices by wiping out viruses and malware.
    • Information Security Education and Awareness Project (ISEA): Training of personnel to raise awareness and to provide research, education, and training in the field of Information Security.

    Conclusion

    • With several non-state actors engaging in hybrid warfare and distorting day-to-day practices, including examinations, these pose legal, ethical and real dilemmas. Left unchecked, the world may have to confront a new kind of Wild West, before states find a common denominator for regulating cyber space and lay down proper rules and practices to prevent anarchy and chaos.

    Mains Question

    Q. Cyber threat is intruding the daily life of citizens and making the internal security more challenging task. Comment what are the policy loopholes in India’s fight against the cyber threat?

    UPSC 2023 countdown has begun! Get your personal guidance plan now! (Click here)

     

  • Making India’s Quantum Cyberspace resilient

    Quantum

    Context

    • The Army has collaborated with industry and academia to build secure communications and cryptography applications. This step builds on last year’s initiative to establish a quantum computing laboratory at the military engineering institute in Mhow, Madhya Pradesh.

     What is mean by quantum computing?

    • Quantum computing is an area of study focused on the development of computer based technologies centered around the principles of quantum theory.
    • Quantum computing studies computation systems that make direct use of quantum-mechanical phenomena to perform operations on data.
    • Classical computers encode information in bits. Each bit can take the value of 1 or 0. These 1s and 0s act as on/off switches that ultimately drive computer functions.

    What is quantum Theory?

    • Quantum theory explains the nature and behavior of energy and matter on the quantum (atomic and subatomic) level. Quantum theory is the theoretical basis of modern physics.
    • The nature and behavior of matter and energy at that level is sometimes referred to as quantum physics and quantum mechanics.

    Quantum

    What is quantum computing laboratory that the Army has set up?

    • Two research centres: The Army has set up a quantum computing laboratory and a centre for artificial intelligence (AI) at a military engineering institute in Madhya Pradesh. The Army will get support from National Security Council Secretariat (NSCS).
    • Purpose of the quantum lab: To spearhead research and training in this key developing field. It said the Indian Army is making steady and significant strides in the field of emerging technologies
    • To Train personnel on the cyber warfare: Training on cyber warfare is being imparted through a state of the art cyber range and cyber security labs.
    • The Focus areas: Key thrust areas are quantum key distribution, quantum communication and quantum computing, among others.

    What is the rationale behind this development?

    • To provide facility centre for extensive and dedicated research: The two centres will carry out extensive research in developing transformative technologies for use by the armed forces.
    • To transform the current system of cryptography: Research undertaken by the Army in the field of quantum technology will help it leapfrog into the next generation of communication and transform the current system of cryptography to post-quantum cryptography.
    • Developing quantum resistant systems: With traditional encryption models at risk and increasing military applications of quantum technology, the deployment of quantum-resistant systems has become the need of the hour.
    • Vulnerable existing digital infrastructure: There is a need of upgrading current encryption standards that can be broken by quantum cryptography. Current protocols like the RSA will quickly become outdated. This means that quantum cyber attacks can potentially breach any hardened target, opening a significant vulnerability for existing digital infrastructure. Hack proofing these systems will require considerable investments.
    • To be in a League of nations in this sector: For example US: National Quantum Initiative Act has already allocated $1.2 billion for research in defence related quantum technology. China now hosts two of the world’s fastest quantum computers.

    Quantum

    India’s developments in this sector so far?

    • National Mission on Quantum Technologies and Applications: In 2019, the Centre declared quantum technology a “mission of national importance”. The Union Budget 2020-21 had proposed to spend Rs 8,000 crore on the newly launched National Mission on Quantum Technologies and Applications.
    • Successfully demonstrated a Quantum key Distribution (QKD) link: In February 2022, a joint team of the Defence Research and Development Organization and IIT Delhi successfully demonstrated a QKD link between two cities in UP  Prayagraj and Vindhyachal  located 100 kilometres apart.

    What are the challenges facing India?

    • Current capabilities are not sufficient: Currently, India has very few capabilities in developing advanced systems capable of withstanding quantum cyber attacks.
    • The china challenge: China’s quantum advances expand the spectre of quantum cyber attacks against India’s digital infrastructure, which already faces a barrage of attacks from Chinese state-sponsored hackers.
    • Dependence on Foreign hardware: India is heavily dependent on foreign hardware, particularly Chinese hardware, is an additional vulnerability.

    Quantum

    How India can make its cyberspace resilient?

    • Procuring quantum resistant mechanism from US: India must consider procuring the United States National Security Agency’s (NSA) Suite B Cryptography Quantum-Resistant Suite as its official encryption mechanism. The NSA is developing new algorithms for their cypher suite that are resistant to quantum cyber attacks. This can then facilitate India’s official transition to quantum-resistant algorithms.
    • Enhancing cryptographic standards: The Indian Defence establishment can consider emulating the cryptographic standards set by the US’s National Institute of Standards and Technology (NIST) which has developed a series of encryption tools to handle quantum computer attacks. It has developed a series of four algorithms to frame a post-quantum cryptographic standard.
    • Diplomatic partnerships in this sector: Diplomatic partnerships with other techno-democracies countries with top technology sectors, advanced economies, and a commitment to liberal democracy can help India pool resources and mitigate emerging quantum cyber threats.
    • Active participation in global avenues: Active participation in the Open Quantum Safe project a global initiative started in 2016 for prototyping and integrating quantum-resistant cryptographic algorithms.
    • Providing funds and encouragement: India must start its national initiatives to develop quantum-resistant systems. For this, the government can fund and encourage existing open-source projects related to post-quantum cryptography.
    • Start implementing the capabilities: The country should start implementing and developing capabilities in quantum-resistant communications, specifically for critical strategic sectors. QKDs over long distances, especially connecting military outposts for sensitive communications, can be prioritised to ensure secure communications whilst protecting key intelligence from potential quantum cyber attacks.
    • Establishing nationwide network: Establish a nationwide communication network integrated with quantum cryptographic systems, thereby protecting cyberspace from any cross-border quantum cyber offensive.

    Conclusion

    • The world is moving towards an era in which the applications of quantum physics in strategic domains will soon become a reality, increasing cyber security risks. India is getting there slowly but steadily. India needs a holistic approach to tackle these challenges. At the heart of this approach should be the focus on post-quantum cyber security.

    Mains Question

    Q.The world is moving towards an era in which applications of quantum physics in strategic domains will soon become a reality, increasing cyber security threats. In this context, what steps can India take to make its cyberspace resilient and quantum-resistant? Discuss.

    UPSC 2023 countdown has begun! Get your personal guidance plan now! (Click here)