💥Join UPSC 2027,2028 Mentorship (July Batch) + XFactor Notes & Microthemes PDF

GS Paper: Cyber Security

  • Status of India’s National Cyber Security Strategy

    Recently, Chinese state-sponsored hackers targeted Indian electricity distribution centres near Ladakh.

    Amid a surge in cyberattacks on India’s networks, the Centre is yet to implement the National Cyber Security Strategy which has been in the works since 2020.

    Recent trends of Cyber-attacks in India

    • As per American cybersecurity firm Palo Alto Networks’ 2021 report, Maharashtra was the most targeted State in India — facing 42% of all ransomware attacks.
    • India is among the more economically profitable regions for hacker groups and hence these hackers ask Indian firms to pay a ransom, usually using cryptocurrencies, in order to regain access to the data.
    • One in four Indian organisations suffered a ransomware attack in 2021.
    • Indian organisations witnessed a 218% increase in ransomware — higher than the global average of 21%.
    • Software and services (26%), capital goods (14%) and the public sector (9%) were among the most targeted sectors.

    Increase in such attacks has brought to light the urgent need for strengthening India’s cybersecurity.

    What is the National Cyber Security Strategy?

    Conceptualised by the Data Security Council of India (DSCI), the report focuses on 21 areas to ensure a safe, secure, trusted, resilient, and vibrant cyberspace for India.

    The main sectors of focus of the report are:

    • Large scale digitisation of public services: There needs to be a focus on security in the early stages of design in all digitisation initiatives and for developing institutional capability for assessment, evaluation, certification, and rating of core devices.
    • Supply chain security: There should be robust monitoring and mapping of the supply chain of the Integrated circuits (ICT) and electronics products. Product testing and certification needs to be scaled up, and the country’s semiconductor design capabilities must be leveraged globally.
    • Critical information infrastructure protection: The supervisory control and data acquisition (SCADA) security should be integrated with enterprise security. A repository of vulnerabilities should also be maintained.
    • Digital payments: There should be mapping and modelling of devices and platform deployed, transacting entities, payment flows, interfaces and data exchange as well as threat research and sharing of threat intelligence.
    • State-level cyber security: State-level cybersecurity policies and guidelines for security architecture, operations, and governance need to be developed.

    What steps does the report suggest?

    To implement cybersecurity in the above-listed focus areas, the report lists the following recommendations:

    • Budgetary provisions: A minimum allocation of 0.25% of the annual budget, which can be raised up to 1% has been recommended to be set aside for cyber security.
    • Ministry-wise allocation: In terms of separate ministries and agencies, 15-20% of the IT/technology expenditure should be earmarked for cybersecurity.
    • Setting up a Fund of Funds: The report also suggests setting up a Fund of Funds for cybersecurity and to provide central funding to States to build capabilities in the same field.
    • R&D, skill-building and technology development: The report suggests investing in modernisation and digitisation of ICTs, setting up a short and long term agenda for cyber security via outcome-based programs and providing investments in deep-tech cyber security innovation.
    • National framework for certifications: Furthermore, a national framework should be devised in collaboration with institutions like the National Skill Development Corporation (NSDC) and ISEA (Information Security Education and Awareness) to provide global professional certifications in security.
    • Creating a ‘cyber security services’: The DSCI further recommends creating a ‘cyber security services’ with cadre chosen from the Indian Engineering Services.
    • Crisis management: For adequate preparation to handle crisis, the DSCI recommends holding cybersecurity drills which include real-life scenarios with their ramifications. In critical sectors, simulation exercises for cross-border scenarios must be held on an inter-country basis.
    • Cyber insurance: Cyber insurance being a yet to be researched field, must have an actuarial science to address cybersecurity risks in business and technology scenarios as well as calculate threat exposures.
    • Cyber diplomacy: Cyber diplomacy plays a huge role in shaping India’s global relations. To further better diplomacy, the government should promote brand India as a responsible player in cyber security and also create ‘cyber envoys’ for the key countries/regions.
    • Cybercrime investigation: It also suggests charting a five-year roadmap factoring possible technology transformation, setting up exclusive courts to deal with cybercrimes and remove backlog of cybercrimes by increasing centres providing opinion related to digital evidence under section 79A of the IT act.
    • Advanced forensic training: Moreover, the DSCI suggests advanced forensic training for agencies to keep up in the age of AI/ML, blockchain, IoT, cloud, automation.
    • Cooperation among agencies: Law enforcement and other agencies should partner with their counterparts abroad to seek information of service providers overseas.

    Progress in its implementation

    • The Centre has formulated a draft National Cyber Security Strategy 2021 which holistically looks at addressing the issues of security of national cyberspace.
    • Without mentioning a deadline for its implementation, the Centre added that it had no plans as of yet to coordinate with other countries to develop a global legal framework on cyber terrorism.

    Way forward

    • India has to contend with the importance and necessity of cyber offence as much as cyber defence.
    • As of today, India’s primary or possibly only response measures appear to be defensive.
    • India has to also invest in more offensive cyber means as a response.

     

    UPSC 2022 countdown has begun! Get your personal guidance plan now! (Click here)

  • Reporting cyber attacks

    Context

    The Ministry of Electronics and Information Technology is likely to come out with new cyber security regulations which will put the onus on organisations to report any cybercrime that may have happened against them, including data leaks.

    Damages inflicted by the cyber crimes

    • Apart from private firms, government services, especially critical utilities, are prone to cyber attacks and breach incidents.
    • The ransomware attack against the nationwide gas pipeline in 2021 in the U.S. virtually brought down the transportation of about 45% of all petrol and diesel consumed on the east coast.
    • If it were measured as a country, then cyber crime — which is predicted to inflict damages totalling $6 trillion globally in 2021 — would be the world’s third-largest economy after the U.S. and China.

    Provision for reporting the cybercrime

    • Clause 25 in the Data Protection Bill 2021 says that data fiduciaries should report any personal and non-personal data breach incident within 72 hours of becoming aware of a breach.
    • Clause in EU GDPR: Even the golden standard for data protection, namely the European Union General Data Protection Regulation (EU GDPR), has a clause for reporting data breach incidents within a stringent timeline.
    •  This, in principle, is likely to improve cyber security and reduce attacks and breaches.

    Why reporting cybercrime is important

    • Alerting other organisations: If incidences are reported, the Indian Computer Emergency Response Team and others can alert organisations about the associated security vulnerabilities.
    • Precautionary measures: Firms not yet affected can also take precautionary measures such as deploying security patches and improving their cyber security infrastructure.
    • Why firms are reluctant to notify the crime? Any security or privacy breach has a negative impact on the reputation of the associated firms.
    • An empirical study by Comparitech indicates that the share prices for firms generally fall around 3.5% on average over three months following the breach.
    • So, firms weigh the penalties they face for not disclosing the incidents versus the potential reputational harm due to disclosure, and decide accordingly.

    Possible solutions

    • Periodic cyber security audits:  How will the regulator come to know when a firm does not disclose a security breach?
    • It can be done only through periodic cyber security audits.
    •  Unfortunately, the regulators in most countries including India do not have such capacity to conduct security audits frequently and completely.
    • Empanel third-party auditors: The government can empanel third party cyber security auditors for the conduct of periodical cyber security impact assessments, primarily amongst all the government departments, both at the national and State level, so that security threats and incidents can be detected proactively and incidents averted.
    • Evaluation and Certification of cyber security: The Ministry, as part of cyber security assurance initiatives of the Government of India, to evaluate and certify IT security products and protection profiles, has set up Common Criteria Testing Laboratories and certification bodies across the country.
    • These schemes can be extended towards cyber security audits and assessments as well.
    • Security command centre:  Much like IBM, which set up a large cyber security command centre in Bengaluru, other large firms can also be encouraged to set up such centres for protection of their firms’ assets.

    Consider the question “Reporting cyber security breaches is important. Yet, firms are reluctant to report the breaches. Examine the reasons for reluctance on part of the firms and suggest the way forward.”

    Conclusion

    Such measures will also pass the muster of the EU GDPR, thereby moving India closer to the set of countries that have the same level of cyber security and data protection as that of EU, for seamless cross-border data flow.

    UPSC 2022 countdown has begun! Get your personal guidance plan now! (Click here)

  • Cyber warfare

    Alongside the missiles and bombs slamming down in Ukraine, the country has also been hit by a wave of cyber-attacks targeting critical infrastructure companies.

    What is Cyberwarfare?

    • Cyberwarfare has emerged as a new form of retaliation or passive aggression deployed by nations that do not want to go to actual war but want to send a tough message to their opponents.
    • In June 2020, security experts from Cyfirma uncovered a conspiracy by Gothic Panda and Stone Panda, two China-based hacker groups, to target media and critical infra companies in India.
    • They led large-scale attacks amid the border stand-off between India and China in Ladakh.
    • For many countries, cyberwarfare is a never-ending battle as it allows them to constantly harass and weaken geopolitical rivals.

    What has happened in Ukraine so far?

    • Ukraine  has  been  one  of  the  primary targets of Russia since 2020.
    • The recent spate of attacks started in mid-January and knocked out websites of the ministry of foreign affairs and the ministry of education.
    • Government websites and a number of banks have been hit by another mass distributed denial of service (DDoS) attacks.
    • DDoS attacks disrupt online services by overwhelming websites with more traffic than their server can handle.

    Which countries are behind state-backed cyberattacks?

    • Russia is one of the top perpetrators of state-backed cyberattacks.
    • According to an October 2021 report by Microsoft Corp., Russia accounted for 58% of state-backed attacks worldwide, followed by North Korea (23%), Iran (11%), and China (8%).
    • North Korea is said to have built a cyber-army of 7,000 hackers.

    Which companies are targeted and why?

    • State-backed cyberattacks are usually carried out to steal state secrets, trade deals and weapons blueprint, or target large multinationals to steal their intellectual property (IP) and use it to build local industry.
    • Cryptos are also on the radar now. North Korean hackers reportedly stole cryptos worth $400 million in 2021.
    • However, when states launch cyberattacks on other states as a result of worsening of geopolitical relations, the target is usually critical infrastructure firms to disrupt economic activity.

    How often is India targeted?

    • Such cyberattacks rose 100% between 2017 and 2021, according to a global study by Hewlett-Packard and the University of Surrey.
    • In 2019, the administrative network of the Kudankulam Nuclear Power Plant was hit by a malware attack by North Korea-backed Lazarus Group.
    • China-backed hackers were believed to be behind a power outage in Mumbai in 2020.
    • According to Black Lotus Labs, Pakistan-based hackers targeted power firms and one government organization in India in early 2021 using Remote Access Trojans.

     

     

    UPSC 2022 countdown has begun! Get your personal guidance plan now! (Click here)

  • MHA recommends ban on 54 Chinese Apps

    The Ministry of Home Affairs has recommended a ban on 54 Chinese mobile applications that pose a threat to the country’s security.

    Legal basis of app ban

    • The ban has been enforced under Section 69A of the Information Technology Act, 2000.
    • This act empowers to issue directions for blocking for public access of any information through any computer resource.
    • This is done in the interest of –
      1. sovereignty and integrity of India
      2. defense of India, security of the State
      3. friendly relations with foreign states
      4. public order (or)
      5. for preventing incitement to the commission of any cognizable offense relating to above

    Why MHA has put such a ban?

    • Most of these apps were operating as clones or shadow apps of the apps that had earlier been banned by the government.
    • There was stealing and secretly transmitting users’ data in an unauthorized manner to servers that have locations outside India.
    • These apps largely impact the psychosocial abilities of the users.
    • The immediate decision has been taken in a specific strategic and national security

    Implications of the ban

    • India’s offensive: The move comes as an exercise of coercive diplomacy with China amid the heated exchange of words during the diplomatic boycott on the winter Olympics.
    • Hurting china’s ambitions: The ban may affect one of China’s most ambitious goals, namely to become the digital superpower of the 21st century.
    • Data nationalization: The ban is also based on the recognition that data streams and digital technology are a new currency of global power.

    Issues with the ban

    • Not only China: Data privacy and data security concerns are not limited only to Chinese apps.
    • Harm already caused: The apps that were banned were very popular in India and the move to block them comes after these apps had already amassed hundreds of millions of users in India.
    • Further dependency on China: The ban on Chinese mobile apps is a relatively soft target, as India remains reliant on Chinese products in several critical and strategically sensitive sectors.

    Way Forward

    • There is a strong case to revise the key legislations and sync them to change the digital environment.
    • Data privacy and security remain to be major challenges emanating from the ongoing digital revolution.
    • Thus, a data protection law is long overdue.
    • India must speed up indigenization, research, and development, and frame up a regulatory architecture to claim data sovereignty.

     

    UPSC 2022 countdown has begun! Get your personal guidance plan now! (Click here)

  • Taking a byte out of cyber threats

    Context

    Cyber-attacks may be a relatively new phenomenon, but in a short timeframe have come to be assessed as dangerous as terrorism.

    A cyber attack is a type of attack that targets computer systems, infrastructures, networks, or personal computer devices using various methods at hand. India is ranked 10th (among 194 countries) in the Global Cybersecurity Index (GCI) 2020 ahead of China and
    Pakistan.

    The increasing threat of cyber attacks

    • Stuxnet Worm in 2010: Resulted in large-scale damage to Iran’s centrifuge capabilities.
    • Natanz nuclear facility (Iran) in 2021: Targeted the industrial control systems and destroyed the power supply to centrifuges used to create enriched uranium
    • Chinese cyberattack on the power system in Mumbai brought the entire city to a halt.
    • Ransomware as a Service (RaaS) — a business model for ransomware developers — is no mere idle threat.
    • Advanced Persistent Threats (APT) attacks are set to increase, with criminal networks working overtime and the Dark web allowing criminals to access even sensitive corporate networks.

    Tools of Cyberattacks

    • Malware: Malicious software to disrupt computers. It can include Viruses, Spyware, Trojans, etc.
    • Phishing: It is the method of trying to gather personal information using deceptive e-mails and websites.
    • Denial of Service attacks: A Denial-of-Service (DoS) attack is an attack meant to shut down a machine or network, making it inaccessible to its intended users.
    • Hacktivism:  Misusing a computer system or network for a socially or politically motivated reason. For example, hacktivists can block access to Government’s website, deface the government’s website or unblock the sites which have been blocked by the Government.
    • Social Engineering: Entice users to provide confidential information. For example, these days u must have come across some of the fake Facebook accounts which are opened in the name of your close friends. First, the cyber attackers send you the friend request in the name of your close friend. Once u accept it, they will ask to request you to transfer some money.

    Consequences of Cyberattacks

    • Impact on data: Confidentiality, Integrity and Availability of information.
    • Impact on Critical Information Infrastructure: Presently, most of the sectors are critically dependent on the use of ICT to carry on their operations. These sectors are Banking and Finance, Power systems, Transport sector, Telecommunication, etc. Cyber attacks on these critical information infrastructures can bring the entire country to a grinding halt. For example, the recent Chinese cyber attack on the power system in Mumbai brought the entire city to a halt.
    • Creates Distrust: A cyber-attack on a specific component exposes vulnerabilities in the entire system which may negatively impact relations with allies and adversaries and questions our nuclear reliability.
    • Financial loss: Estimates of the cost to the world in 2021 from cyberattacks are still being computed, but if the cost of cybercrimes in 2020 (believed to be more than $1 trillion) is any guide, it is likely to range between $3trillion-$4 trillion.
    • Threat to National Security and peace and stability in a country.

    Steps taken by India to improve Cyber Security

    • Section 66F of ITA: Specific provision dealing with the issue of cyber terrorism that covers denial of access, unauthorized access, introduction of computer contaminant leading to harm to persons, property, critical infrastructure, disruption of supplies, ‘sensitive data’ thefts. Provides for punishment which may extend to life imprisonment.
    • National Cyber Security Policy 2013: Policy document drafted by the Department of Electronics and Information Technology. Established National Critical Information Infrastructure Protection Centre (NCIIPC) to improve the protection and resilience of the country’s critical infrastructure information; Create a workforce of 5 lakh professionals skilled in cybersecurity in the next 5 years.
    • National Critical Information Infrastructure Protection Centre (NCIIPC): It has been setup to enhance the protection and resilience of Nation’s Critical information infrastructure. It functions under the National Technical Research Organization (NTRO).
    • CERT-IN: Organization under the Ministry of Electronics and Information Technology with an objective of securing Indian cyberspace. The purpose of CERT-In is to respond to computer security incidents, report on vulnerabilities, and promote effective IT security practices throughout the country. According to the provisions of the Information Technology Amendment Act 2008, CERT-In is responsible for overseeing the administration of the Act.
    • Cyber Surakshit Bharat Initiative: It was launched in 2018 with an aim to spread awareness about cybercrime and build capacity for safety measures for Chief Information Security Officers (CISOs) and frontline IT staff across all government departments.
    • Cyber Crisis Management Plan (CCMP): It aims at countering cyber threats and cyber-terrorism.
    • National Cyber Coordination Centre (NCCC): It seeks to generate necessary situational awareness of existing and potential cyber security threats and enable timely information sharing for proactive, preventive and protective actions by individual entities.
    • National Cyber Security Coordinator (NCSC) under National Security Council Secretariat (NSCS) coordinates with different agencies at the national level for cyber security matters.
    • Cyber Swachhta Kendra: This platform was introduced for internet users to clean their computers and devices by wiping out viruses and malware.
    • Information Security Education and Awareness Project (ISEA): Training of personnel to raise awareness and to provide research, education, and training in the field of Information Security.

    Challenges

    • Structural:
      a)Absence of any geographical constraints.
      b)Lack of uniformity in devices used for internet access.
    • Administrative:
      a) Lack of national-level architecture for cybersecurity
      b) Security audit does not occur periodically, nor does it adhere to the international standards.
      c) The appointment of the National Cyber Security Coordinator in 2014 has not been supplemented by creating liaison officers in states.
    • Procedural
      a) Lack of awareness in local police of various provisions of IT Act, 2000, and also of IPSC related to cybercrime.
      b) Lack of data protection regime.
    • Human Resource Related
      a) Inadequate awareness among people about the security of devices and online transactions.

    Way forward

    • International Convention: Presently, Budapest Convention is the first international treaty that promotes greater cooperation between countries in fighting cybercrimes. India should accede to Budapest Convention at the earliest. It would reduce India’s capacity to combat cybercrimes at a global level.
    • PPP Framework for Cyber Security: Presently, most of the cyber security operations are carried out by the Government agencies such as CERT-In. Given the fast-changing nature and intensity of cyber threats, there is a need to leverage private sector expertise in combating cyber crimes through the PPP framework.
    • Capacity building and skill development- Recently, according to a report published by NASSCOM, India needs around 10 lakh, cyber security experts. However, presently there are only around 64,000 professionals. One of the main reasons for the lower number of cyber security professionals is due to lack of an adequate number of specialized courses in cyber security, poor training Infrastructure, lack of availability of trainers, etc. Hence, accordingly, the Government has to recognize the lacunae and increase the number of Skilled professionals.
    • Promoting Startups in the field of Cybersecurity.
    • Investment in R&D to improve Cyber Security- Big data, AI
    • Learning from best practices such as the Tallinn manual of the US.

    Conclusion

    Failure to build resilience — at both the ‘technical and human level — will mean that the cycle of cyber attacks and the distrust they give rise to will continue to threaten the foundations of a democratic society. Preventing erosion of trust is critical in this day and age.

    UPSC 2022 countdown has begun! Get your personal guidance plan now! (Click here)

  • What is Pegasus Spyware Controversy?

    A New York Times report has claimed that the Indian government had bought the Pegasus Spyware in 2017.

    What is Pegasus?

    • Pegasus is a spyware developed by NSO Group, an Israeli surveillance firm that helps spies hack into phones.
    • In 2019, when WhatsApp sued the firm in a U.S. court, the matter came to light.
    • In July 2021, Amnesty International, along with 13 media outlets across the globe released a report on how the spyware was used to snoop hundreds of individuals, including Indians.
    • While the NSO claims its spyware is sold only to governments, none of the nations have come forward to accept the claims.

    Why is Pegasus so lethal?

    • What makes Pegasus really dangerous is that it spares no aspect of a person’s identity.
    • It makes older techniques of spying seem relatively harmless.
    • It can intercept every call and SMS, read every email and monitor each messaging app.
    • Pegasus can also control the phone’s camera and microphone and has access to the device’s location data.
    • The app advertises that it can carry out “file retrieval”, which means it could access any document that a target might have stored on their phone.

    Dysfunctions created by Pegasus

    • Privacy breach: The very existence of a surveillance system, whether under a provision of law or without it, impacts the right to privacy under Article 21 and the exercise of free speech under Article 19.
    • Curbing Dissent: It reflects a disturbing trend with regard to the use of hacking software against dissidents and adversaries. In 2019 also, Pegasus software was used to hack into HR & Dalit activists.
    • Individual safety: In the absence of privacy, the safety of journalists, especially those whose work criticizes the government, and the personal safety of their sources is jeopardised.
    • Self-Censorship: Consistent fear over espionage may grapple individuals. This may impact their ability to express, receive and discuss such ideas.
    • State-sponsored mass surveillance: The spyware coupled with AI can manipulate digital content in users’ smartphones. This in turn can polarize their opinion by the distant controllers.
    • National security: The potential misuse or proliferation has the same, if not more, ramifications as advanced nuclear technology falling into the wrong hands.

    Snooping in India:  A Legality check

    For Pegasus-like spyware to be used lawfully, the government would have to invoke both the IT Act and the Telegraph Act. Communication surveillance in India takes place primarily under two laws:

    1. Telegraph Act, 1885: It deals with interception of calls.
    2. Information Technology Act, 2000: It was enacted to deal with surveillance of all electronic communication, following the Supreme Court’s intervention in 1996.

    Cyber security safeguards in India

    • National Cyber Security Policy: The policy was developed in 2013 to build secure and resilient cyberspace for India’s citizens and businesses.
    • Indian Computer Emergency Response Team (CERT-In): The CERT-In is responsible for incident responses including analysis, forecasts, and alerts on cybersecurity issues and breaches.
    • Indian Cyber Crime Coordination Centre (I4C): The Central Government has rolled out a scheme for the establishment of the I4C to handle issues related to cybercrime in the country in a comprehensive and coordinated manner.
    • Budapest Convention: There also exists Budapest Convention on Cybercrime. However, India is not a signatory to this convention.

    Issues over government involvement

    • It is worth asking why the government would need to hack phones and install spyware when existing laws already offer impunity for surveillance.
    • In the absence of parliamentary or judicial oversight, electronic surveillance gives the executive the power to influence both the subject of surveillance and all classes of individuals, resulting in a chilling effect on free speech.

    Way forward

    • The security of a device becomes one of the fundamental bedrock of maintaining user trust as society becomes more and more digitized.
    • Constituting an independent high-level inquiry with credible members and experts that can restore confidence and conduct its proceedings transparently.
    • The need for judicial oversight over surveillance systems in general, and judicial investigation into the Pegasus hacking, in particular, is very essential.

    Conclusion

    • We must recognize that national security starts with securing the smartphones of every single Indian by embracing technologies such as encryption rather than deploying spyware.
    • This is a core part of our fundamental right to privacy.
    • This intrusion by spyware is not merely an infringement of the rights of the citizens of the country but also a worrying development for India’s national security apparatus.

     

    UPSC 2022 countdown has begun! Get your personal guidance plan now! (Click here)

  • [pib] CERT-In authorized as CVE Numbering Authority (CNA)

    CERT-In has partnered with the Common Vulnerabilities and Exposures (CVE) Program and has been authorized as a CVE Numbering Authority (CNA) for vulnerabilities impacting all products designed, developed and manufactured in India.

    What is CVE Program?

    • CVE is an international, community-based effort and relies on the community to discover vulnerabilities.
    • The vulnerabilities are discovered then assigned and published to the CVE List.
    • Information technology and cybersecurity professionals use CVE Records to ensure they are discussing the same issue, and to coordinate their efforts to prioritize and address the vulnerabilities.
    • Partners publish CVE Records to communicate consistent descriptions of vulnerabilities.

    Mission of the Program

    • The mission of the CVE Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities.
    • The vulnerabilities are discovered then assigned and published by organizations from around the world that have partnered with the CVE Program.

    Who are the CNAs?

    • CNAs are organizations responsible for the regular assignment of CVE IDs to vulnerabilities, and for creating and publishing information about the Vulnerability in the associated CVE Record.
    • The CVE List is built by CVE Numbering Authorities (CNAs).
    • Every CVE Record added to the list is assigned by a CNA.
    • The CVE Records published in the catalog enable program stakeholders to rapidly discover and correlate vulnerability information used to protect systems against attacks.
    • Each CNA has a specific Scope of responsibility for vulnerability identification and publishing.

    Back2Basics: Indian Computer Emergency Response Team (CERT-IN)

    • CERT-IN is an office within the Ministry of Electronics and Information Technology.
    • It is the nodal agency to deal with cyber security threats like hacking and phishing. It strengthens the security-related defense of the Indian Internet domain.
    • It was formed in 2004 by the Government of India under the Information Technology Act, 2000 Section (70B) under the Ministry of Communications and Information Technology.

     

    UPSC 2022 countdown has begun! Get your personal guidance plan now! (Click here)

  • National Cyber Coordination Centre (NCSC)

    There are cybersecurity organisations in the country but no central body responsible for safety in the online space said the National Cyber Security Coordinator (NCSC).

    National Cyber Coordination Centre

    Headed by National Cyber Security Coordinator:  Lt. Gen. Rajesh Pant (Retd.)

    Objective: To help the country deal with malicious cyber-activities by acting as an Internet traffic monitoring entity that can fend off domestic or international attacks

    • The National Cyber Coordination Centre (NCCC) is an operational cybersecurity and e-surveillance agency in India.
    • It is jurisdictionally under the Ministry of Home Affairs.
    • It coordinates with multiple security and surveillance agencies as well as with CERT-In of the Ministry of Electronics and Information Technology.
    • Components of the NCCC include a cybercrime prevention strategy, cybercrime investigation training and review of outdated laws.

    Functions

    • It will be India’s first layer for cyber threat monitoring and all communication with government and private service providers would be through this body only.
    • The NCCC will be in virtual contact with the control room of all ISPs to scan traffic within the country, flowing at the point of entry and exit, including the international gateway.

    Cyber-security bottlenecks in India

    • India has no dedicated Cyber-security regulation and is also not well prepared to deal with cyberwarfare.
    • India has formulated the National Cyber Security Policy 2013 which is not yet implemented.
    • NCCC has been classified to be a project of the Indian government without a legal framework, which may be counterproductive as it may violate civil liberties and human rights.
    • Some have expressed concern that the NCCC could encroach on Indian citizens’ privacy and civil liberties, given the lack of explicit privacy laws in the country.

    Back2Basics: Indian Computer Emergency Response Team (CERT-IN)

    • CERT-IN is an office within the Ministry of Electronics and Information Technology.
    • It is the nodal agency to deal with cyber security threats like hacking and phishing. It strengthens the security-related defence of the Indian Internet domain.
    • It was formed in 2004 by the Government of India under the Information Technology Act, 2000 Section (70B) under the Ministry of Communications and Information Technology.

     

    UPSC 2022 countdown has begun! Get your personal guidance plan now! (Click here)

  • The epoch of cyberweapons

    Context

    The controversy over the use of Pegasus spyware for snooping highlights the threats posed by cyber-weapons.

    The emergence of the cyber weapons epoch

    • Cyberattacks on institutions such as banks and on critical infrastructure have proliferated to an alarming extent, signaling the emergence of the cyber weapon epoch.
    • Privacy has been eroded and the Internet has become a powerful weapon in the hands of those seeking to exploit its various facets.
    • Fifth dimension of warfare: Cyber is often touted as the fifth dimension of warfare — in addition to land, sea, air and space.

    The domain of everyday life

    • Cyber, as the domain of military and national security, also co-exists with cyber as a domain of everyday life.
    • The war is no longer out there.
    • It is now directly inside one’s drawing-room, with cyberweapons becoming the weapon of choice.
    • Israelis today dominate the cyber domain along with the Chinese, Russians, Koreans and, of course, the Americans.
    • The linkage between sabotage and intrusive surveillance is but a short step.

    Cyberattacks during the past decades

    •  Beginning with the 2007 devastating cyberattack on Estonia’s critical infrastructure, this was followed by the Stuxnet worm attack a few years later on Iran’s nuclear facility.
    • The Shamoon virus attack on Saudi Aramco occurred in 2012.
    • In 2016, a cyberattack occurred on Ukraine’s State power grid; in 2017 there was a Ransomware attack (NotPetya) which affected machines in as many as 64 countries.
    • United Kingdom’s National Health Service fell prey to the Wannacry attack the same year.
    • The series of attacks happened this year on Ireland’s Health Care System and in the United States such as ‘SolarWinds’, the cyber attack on Colonial Pipeline and JBS, etc.

    What are the threats posed by cyberattacks?

    • Cyberweapons carry untold capacity to distort systems and structures — civilian or military.
    • Cyberweapons also interfere with democratic processes, aggravate domestic divisions and, above all, unleash forces over which established institutions or even governments have little control.
    • As more and more devices are connected to networks, the cyber threat is only bound to intensify, both in the short and the medium term.
    • What is especially terrifying is that instruments of everyday use can be infected or infiltrated without any direct involvement of the target.
    • The possibilities for misuse are immense and involve far graver consequences to an individual, an establishment, or the nation.
    • It is not difficult to envisage that from wholesale espionage, this would become something far more sinister such as sabotage.

    Way forward

    • Deeper understanding:  Dealing with ‘zero day’ vulnerabilities require far more thought and introspection than merely creating special firewalls or special phones that are ‘detached’ from the Internet.
    • Recognising the mindset: What is needed is a deeper understanding of not only cyber technologies, but also recognising the mindsets of those who employ spyware of the Pegasus variety, and those at the helm of companies such as the NSO.
    • Short-term remedies are unlikely to achieve desired results.
    • No use of AI: Artificial Intelligence (AI) is often seen as a kind of panacea for many of the current problems and ills, but all advances in technology tend to be a double-edged sword.
    • If truth be told, AI could in turn make all information warfare — including cyber related — almost impossible to detect, deflect or prevent, at least at the current stage of development of AI tools.

    Conclusion

    All this suggests that security in the era of ever-expanding cyberweapons could become an ever-receding horizon.


    Back2Basics: Zero-day vulnerability

    • The term “zero-day” refers to a newly discovered software vulnerability.
    • Because the developer has just learned of the flaw, it also means an official patch or update to fix the issue hasn’t been released.
    • So, “zero-day” refers to the fact that the developers have “zero days” to fix the problem that has just been exposed — and perhaps already exploited by hackers.
  • Back in news: Pegasus Spyware

    Telephone numbers of some noted Indian journalists were successfully snooped upon by an unidentified agency using Pegasus software.

    Pegasus Spyware

    • All spyware do what the name suggests — they spy on people through their phones.
    • Pegasus works by sending an exploit link, and if the target user clicks on the link, the malware or the code that allows the surveillance is installed on the user’s phone.
    • A presumably newer version of the malware does not even require a target user to click a link.
    • Once Pegasus is installed, the attacker has complete access to the target user’s phone.
    • The first reports on Pegasus’s spyware operations emerged in 2016, when Ahmed Mansoor, a human rights activist in the UAE, was targeted with an SMS link on his iPhone 6.

    What is the new threat?

    • Pegasus has evolved from its earlier spear-phishing methods using text links or messages to ‘zero-click’ attacks which do not require any action from the phone’s user.
    • This had made what was without a doubt the most powerful spyware out there, more potent and almost impossible to detect or stop.

    How do zero-click attacks work?

    • A zero-click attack helps spyware like Pegasus gain control over a device without human interaction or human error.
    • Zero-click attacks are hard to detect given their nature and hence even harder to prevent.
    • Detection becomes even harder in encrypted environments where there is no visibility on the data packets being sent or received.
    • Most of these attacks exploit software that receive data even before it can determine whether what is coming in is trustworthy or not, like an email client.

    Answer this PYQ from CSP 2018:

    Q.The terms ‘WannaCry, Petya, Eternal Blue’ sometimes mentioned news recently are related to

    (a) Exoplanets

    (b) Crypto currency

    (c) Cyber attacks

    (d) Mini satellites