💥Join UPSC 2027,2028 Mentorship (July Batch) + XFactor Notes & Microthemes PDF

GS Paper: Cyber Security

  • New online platform maps Pegasus spread

    An online database about the use of the spyware Pegasus was recently launched by the Forensic Architecture, Amnesty International and the Citizen Lab to document attacks against human rights defenders.

    What is Pegasus?

    • Last year, one of the biggest stories that broke into cyberspace was WhatsApp’s reports that 1,400 of its users were hacked by Pegasus, a spyware tool from Israeli firm NSO Group.
    • All spyware do what the name suggests — they spy on people through their phones.
    • Pegasus works by sending an exploit link, and if the target user clicks on the link, the malware or the code that allows the surveillance is installed on the user’s phone.
    • A presumably newer version of the malware does not even require a target user to click a link.
    • Once Pegasus is installed, the attacker has complete access to the target user’s phone.

    Why is Pegasus dangerous?

    • What makes Pegasus really dangerous is that it spares no aspect of a person’s identity. It makes older techniques of spying seem relatively harmless.
    • It can intercept every call and SMS, read every email and monitor each messaging app.
    • Pegasus can also control the phone’s camera and microphone and has access to the device’s location data.
    • The app advertises that it can carry out “file retrieval”, which means it could access any document that a target might have stored on their phone.
  • Global Cybersecurity Index 2020

    India has made it to the top 10 in Global Cybersecurity Index (GCI) 2020 by ITU, moving up 37 places to rank as the tenth best country in the world on key cybersafety parameters.

    Global Cybersecurity Index

    • GCI assessment is done on the basis of performance on five parameters of cybersecurity including legal measures, technical measures, organizational measures, capacity development, and cooperation.
    • The performance is then aggregated into an overall score.
    • For each of the five aspects, all the countries’ performance and commitment are assessed through a question-based online survey, which further allowed for the collection of the supporting evidence.

    India’s progress

    • As per the ranking, India has moved up by 37 places to rank as the tenth best country in the world.
    • The US topped the chart, followed by the UK and Saudi Arabia tied on the second position, while Estonia was ranked third in the index.
    • India has also secured the fourth position in the Asia Pacific region, underlining its commitment to cybersecurity.

    Its significance

    • The affirmation by the UN body of India’s efforts on cybersecurity comes just ahead of the sixth anniversary of Digital India on July 1.
    • India is emerging as a global IT superpower, asserting its digital sovereignty with firm measures to safeguard data privacy and online rights of citizens.

    Back2Basics: International Telecommunication Union

    • ITU is the United Nations specialized agency for information and communication technologies – ICTs.
    • Founded in 1865 to facilitate international connectivity in communications networks. It is Headquartered in Geneva, Switzerland.
    • It allocates global radio spectrum and satellite orbits, develops the technical standards that ensure networks and technologies seamlessly interconnect, and strives to improve access to ICTs to underserved communities worldwide.
    • Recently, India got elected as a member of ITU Council for another 4-year term – from 2019 to 2022. India has remained a regular member since 1952.
  • Cyberattacks reveal vulnerabilities in critical infrastructures

    The article highlights the threat posed by cyberattacks to our critical infrastructure and suggest the ways to deal with the the ever evolving threat.

    Civilian targets of cyberattacks

    • Several high-profile cyberattacks were reported from the United States during the past several months.
    • These attacks were all primarily on civilian targets, though each one was of critical importance.
    • Obviously cyber, which is often referred to as the fifth domain/dimension of warfare, is now largely being employed against civilian targets.
    • Most nations have been concentrating till date mainly on erecting cyber defences to protect military and strategic targets, but this will now need to change.

    Challenges

    • Defending civilian targets, and more so critical infrastructure, against cyberattacks such as ransomware and phishing is almost certain to stretch the capability and resources of governments across the globe.
    • The distinction between military and civilian targets is increasingly getting erased and the consequences of this could be indeterminate.
    •  In the civilian domain, two key manifestations of the ‘cat and mouse game’ of cyber warfare today, are ransomware and phishing, including spear phishing.
    • Banking and financial services were most prone to ransomware attacks till date, but oil, electricity grids, and lately, health care, have begun to figure prominently.
    • Ransomware attacks have skyrocketed, with demands and payments going into multi-millions of dollars.
    • India figures prominently in this list, being one of the most affected.
    • Compromised ‘health information’ is proving to be a vital commodity for use by cybercriminals.
    • All indications are that cybercriminals are increasingly targeting a nation’s health-care system and trying to gain access to patients’ data.
    • The available data aggravates the risk not only to the individual but also to entire communities.
    • Cybercriminals are becoming more sophisticated, and are now engaged in stealing sensitive data in targeted computers before launching a ransomware attack.
    • Also, today’s cybercriminals, specially those specialising in ransomware and similar attacks, are different from the ordinary  criminals.
    • Many are known to practise ‘reverse engineering’ and employ ‘penetration testers’ to probe high secure networks.

    Way forward

    • The need to be aware of the nature of the cyber threat to their businesses and take adequate precautionary measures, has become extremely vital.
    • Cybersecurity essentially hinges on data protection. 
    • As data becomes the world’s most precious commodity, attacks on data and data systems are bound to intensify.
    • With mobile and cloud computing expanding rapidly cybersecurity professionals are now engaged in building a ‘Zero Trust Based Environment’, viz., zero trust on end point devices, zero trust on identity, and zero trust on the network to protect all sensitive data. 
    • Building deep technology in cyber is essential.
    • New technologies such as artificial intelligence, Machine learning and quantum computing, also present new opportunities.
    • Pressure also needs to be put on officials in the public domain, as also company boards, to carry out regular vulnerability assessments and create necessary awareness of the growing cyber threat.

    Consider the question “Several high-profile cyberattacks across the world have exposed vulnerabilities in the critical infrastructure of even advanced nations. In light of this, examine the challenges posed by cyberattacks and suggest measures to deal with these challenges.” 

    Conclusion

    The threat posed by the cyberattacks highlights the need for improved defences against actual, and potential, cyberattacks by all countries across continents.

  • What is Fastly Internet Outage?

    Several big websites around the world went down for about half an hour because of a major issue with the content delivery network (CDN) of American cloud computing services provider Fastly.

    Global internet outage: Which websites were affected?

    • com, Reddit, Twitch, Spotify, Pinterest, Stack Overflow, GitHub, gov.uk, Hulu, HBO Max, Quora, PayPal, Vimeo and Shopify are some of the big names.
    • Prominent news websites impacted were the Financial Times, the Guardian, the New York Times, CNN, and Verge, to name some.
    • Most users would have seen a 503 error when trying to access these websites, indicating that the browser was not able to access the server.

    What is Fastly?

    • Fastly is a cloud computing services provider, which offers CDN, edge computing, cloud storage services.
    • All of its geographies, including the three stations it has in India — Chennai, Mumbai and New Delhi — were suffering from “Degraded Performance”.

    Answer this PYQ from CSP 2018:

    Q.The terms ‘WannaCry, Petya, Eternal Blue’ sometimes mentioned news recently are related to

    (a) Exoplanets

    (b) Crypto currency

    (c) Cyber attacks

    (d) Mini satellites

    What is a CDN?

    • A CDN refers to a geographically distributed group of servers that work together to provide fast delivery of Internet content.
    • They house content close to the telecom service providers’ networks.
    • Majority of web traffic across the world today is routed through CDNs.
    • Platforms such as Netflix, Facebook, Amazon — ones with large quantities of data held in global libraries — host their geographically relevant content closer to where that content is to be consumed.
    • This ensures the end customer is able to access the content faster.
    • Another reason companies rely on these CDNs is to help protect their sites against traffic spikes, distributed denial of service (DDOS) attacks, etc.
  • Cybersecurity norms for payment services

    What prompted RBI to take such step

    • Following a series of data breaches faced by operators including Mobikwik and payment aggregator JusPay, the Reserve Bank of India (RBI) will soon issue cybersecurity norms for payment service providers (PSPs).
    • On cyber frauds, Reserve Bank of India has issued very recently basic guidelines on cyber hygiene and cybersecurity for banks and certain NBFCs,
    • The standards for fintech-driven payment services providers will be similar to these cyber hygiene norms issued recently.
    • the critical challenge for regulators would be to speed up the absorption of fintech without undermining the financial system’s integrity or stability.

    UPI dominated by limited players

    •  There are not too many payment systems in India and the number of players is limited.
    • Two apps provide about 70% of third-party services in the UPI system.
    • The concentration of two or three third-party providers in this retail payments space could give rise to competitive weaknesses. 
    • Therefore, the National Payments Corporation of India (NPCI) had laid down a framework for a more even distribution of share of third-party app providers in the UPI system.
  • Why the Personal Data Protection Bill matters

    The existing data protection framework based on IT Act 2000 falls short on several counts. The Personal Data Protection Bill seeks to deal with the shortcoming in it. The article explains how the two differs.

    Need for new data protection regime

    • The need for a more robust data protection legislation came to the fore in 2017 post the Supreme Court’s landmark judgment in Justice K.S. Puttaswamy (Retd) v. Union of India.
    • In the judgment, the Court called for a data protection law that can effectively protect users’ privacy over their personal data.
    • Consequently, the Committee of Experts was formed under the Chairmanship of Justice (Retd) B.N. Srikrishna to suggest a draft data protection law.
    • The Personal Data Protection Bill, 2019, in its current form, is a revised version of the draft legislative document proposed by the Committee.

    Issues with the existing data protection framework

    • The Information Technology Act, 2000 governs how different entities collect and process users’ personal data in India.
    • However, entities could override the protections in the regime by taking users’ consent to processing personal data under broad terms and conditions.
    • This is problematic given that users might not understand the terms and conditions or the implications of giving consent.
    •  Further, the frameworks emphasise data security but do not place enough emphasis on data privacy.
    • As a result, entities could use the data for purposes different to those that the user consented to.
    •  The data protection provisions under the IT Act also do not apply to government agencies.
    • Finally, the regime seems to have become antiquated and inadequate in addressing risks emerging from new developments in data processing technology.

    How the new regime under Data Protection Bill 2019 is different

    • First, the Bill seeks to apply the data protection regime to both government and private entities across all sectors.
    • Second, the Bill seeks to emphasise data security and data privacy.
    • While entities will have to maintain security safeguards to protect personal data, they will also have to fulfill a set of data protection obligations and transparency and accountability measures.
    • Third, the Bill seeks to give users a set of rights over their personal data and means to exercise those rights.
    • Fourth, the Bill seeks to create an independent and powerful regulator known as the Data Protection Authority (DPA).
    • The DPA will monitor and regulate data processing activities to ensure their compliance with the regime.

    Concerns

    • Under clause 35, the Central government can exempt any government agency from complying with the Bill.
    • Similarly, users could find it difficult to enforce various user protection safeguards (such as rights and remedies) in the Bill.
    • For instance, the Bill threatens legal consequences for users who withdraw their consent for a data processing activity.
    • Additional concerns also emerge for the DPA as an independent effective regulator that can uphold users’ interests.

    Consider the question “What are the issues with the present framework in India for data and privacy protection? How the Personal Data Protection Bill seeks to address these issues?”

    Conclusion

    The Joint Parliamentary Committee that is scrutinising the Bill is expected to submit its final report in the Monsoon Session of Parliament in 2021 Taking this time to make some changes in the Bill targeted towards addressing various concerns in it could make a stronger and more effective data protection regime.

  • Critical information infrastructure

    The article underscores the threat of cyberattacks on the critical infrastructure and also suggests the steps to be taken to secure these infrastructures.

    Cyberattack on the power grid

    • On October 12 last year, Mumbai plunged into darkness as the electric grid supply to the city failed.
    • Recently, a study by Massachusetts-based Recorded Future,  said that the Mumbai power outage could have been a cyberattack aimed at critical infrastructure.
    • It was carried out by the state-sponsored group Red Echo.
    • As recently as in February, the Centre’s nodal agency National Critical Information Infrastructure Protection Centre (NCIIPC) had reported concerted attempts by Red Echo to hack the critical grid network.
    • CERT-In, is reported to have detected the ShadowPad malware in one of the largest supply chain attacks a month after the Mumbai outage.
    • Many of the suspected IP addresses identified by NCIIPC and CERT-In were the same and most have been blocked in time.
    • The Chinese focus in the past was stealing information and not projecting power, but the situation with India might be different.

    Why critical infrastructures are so vulnerable

    • As many of these critical infrastructures were never designed keeping security in mind and always focused on productivity and reliability, their vulnerability is more evident today.
    • With devices getting more interconnected and dependent on the internet facilitating remote access during a pandemic, the security of cyber-physical systems has, indeed, become a major challenge for utility companies.

    Critical information infrastructure protection

    • For more than a decade, there have been concerns about critical information infrastructure protection (CIIP).
    • In January 2014, the NCIIPC was notified to be the national nodal agency for CIIP and over these years has been working closely with the various agencies.
    • In January 2019, the government also announced a National Mission on Interdisciplinary Cyber-Physical Systems (NM-ICPS), with a budget of Rs 3,660 crore for the next five years, to strengthen the sector.

    Way forward

    • Most ministries and departments need better budget allocations for cybersecurity as well as a more robust infrastructure, processes and audit system.
    • The Industrial Cybersecurity Standards (IEC62443) launched by the Bureau of Indian Standards (BIS), has to be adopted soon.
    • For the power sector, a strong regulation on the lines of the North American Electric Reliability Critical Infrastructure Protection (NERC) policy could serve as a guide.

    Consider the question “Discuss the importance of critical information infrastructure protection (CIIP)? Also mention the steps taken by the government in this regard.” 

    Conclusion

    Clearly, the incident is a wake-up call for better preparedness in terms of a more robust cyber security ecosystem in place. The new cyber security policy awaiting imminent announcement will hopefully cater to that.

  • China’s cyber eye and India

    Amid souring relations between India and China last year, evidence has emerged that a Chinese government-linked company’s attempt led to a power outage in Mumbai yesterday and now in Telangana today.

    Q.The use of cyber offensive tools and espionage is a fairly active element of the People’s Republic of China. Discuss in light of recent incidences of cyber attack in India.

    Red Echo & ShadowPad

    • On February 28, a Massachusetts-based firm published a report saying it had observed a steep rise in the use of resources like malware by a Chinese group called Red Echo.
    • It aimed to target “a large swathe” of India’s power sector.
    • It said 10 distinct Indian power sector organisations were targeted, including four Regional Load Despatch Centres (RLDCs) that are responsible for the smooth operation of the country’s power grid by balancing the supply and demand of electricity.
    • Red Echo used malware called ShadowPad, which involves the use of a backdoor to access servers.

    India confirms cyber attack

    • The Ministry of Power has confirmed these attempts, stating it had been informed in November 2020 about the ShadowPad malware at some control centres.
    • The Ministry said it was informed of Red Echo’s attempts to target the country’s load despatch centres in February.
    • It had said “no data breach/data loss” had been detected due to the incidents.

    What does it imply?

    • This is clearly something that is linked to China’s geopolitical interests.
    • It is established very clearly that the use of cyber offensive tools and espionage is a fairly active element of what the People’s Republic of China seems to be adopting and encouraging.
    • Even when they are not directly in charge of an offensive operation, they seem to be consistently encouraging actors to develop this capability.

    PRC’s long term strategy

    • These cyber-attacks are seen as an attempt to test and lay the grounds for further operations in the future.
    • We need to remember that sometimes these offensive operations are carried out to distract people from other places that they might be targeting or other activities that might be occurring.
    • There was an increase in cyber offensive operations and incidents around the world in the second half of 2020 especially targeting the healthcare and vaccine space.
    • When vaccine companies are targeted, the motive could be competition.
    • The motivation behind Stone Panda’s attack against SII and Bharat Biotech’s IT systems was to extract the companies’ intellectual property and gain a competitive advantage.

    Other such attacks: Stone Panda & vaccines

    • A Chinese hacker group known as Stone Panda had identified gaps and vulnerabilities in the IT infrastructure and supply chain software of Bharat Biotech and the Serum Institute of India.
    • These companies have developed Covaxin and Covishield, which are currently being used in the national vaccination campaign.
    • They are also in the process of testing additional Covid-19 vaccines that could add value to efforts around the world.
  • Sandes: the government’s new Instant Messaging Platform

    The National Informatics Centre (NIC) has launched an instant messaging platform called Sandes on the lines of WhatsApp.  Open initially only to government officers, it has now been released for the common public as well.

    Features of Sandes Platform

    • The instant messaging app, called Sandes, has an interface similar to many other apps currently available in the market.
    • Like WhatsApp, the new NIC platform can be used for all kinds of communications by anyone with a mobile number or email id.
    • Although there is no option to transfer the chat history between two platforms, the chats on government instant messaging systems or GIMS can be backed up to a users’ email.
    • It also offers features such as group making, broadcast message, message forwarding and emojis.
    • Further, as an additional safety feature, it allows a user to mark a message as confidential, which will allow the recipient to be made aware the message should not be shared with others.

    Why need such instant messaging platform?

    • Following the nationwide lockdown, the government felt the need to build a platform to ensure secure communication between its employees as they worked from home.
    • The idea for a secure communication network dedicated exclusively to government employees has been in the works for the past four years.
    • In August 2020, the NIC released the first version of the app, which said that the app could be used by both central and state government officials for intra and inter-organisation communication.
    • The app was initially launched for Android users and then the service was extended to iOS users.

    Limitations of the app

    • The limitation, however, is that the app does not allow the user to change their email id or registered phone number.
    • The user will have to re-register as a new user in case they wish to change their registered email id or phone number on the app.

    Do you remember?

    [Burning Issue] WhatsApp Snooping

  • What is NetWire Malware?

    This newscard is an excerpt from the original article published in The Hindu.

    Try this question from CSP 2018:

    Q.The terms ‘WannaCry, Petya, Eternal Blue’ sometimes mentioned news recently are related to

    (a) Exoplanets

    (b) Crypto currency

    (c) Cyber attacks

    (d) Mini satellites

    What is NetWire?

    • NetWire, which first surfaced in 2012, is a well-known malware.
    • It is also one of the most active ones around.
    • It is a remote access Trojan, or RAT, which gives control of the infected system to an attacker. Such malware can log keystrokes and compromise passwords.

    Threats posed

    • This malware essentially does two things:
    1. One is data exfiltration, which means stealing data. Most anti-virus software is equipped to prevent this.
    2. The other involves infiltrating a system, and this has proven to be far more challenging for anti-virus software.
    • NetWire is described as an off-the-shelf malware, while something like Pegasus, which used a bug in WhatsApp to infiltrate users’ phones in 2019, is custom-made and sold to nations.

    Back2Basics: Classification of malicious softwares

    Viruses

    • A computer virus is a type of malware that propagates by inserting a copy of itself into and becoming part of another program.
    • It spreads from one computer to another, leaving infections as it travels.
    • Viruses can range in severity from causing mildly annoying effects to damaging data or software and causing denial-of-service (DoS) conditions.
    • Almost all viruses are attached to an executable file, which means the virus may exist on a system but will not be active or able to spread until a user runs or opens the malicious host file or program.
    • When the host code (alternative word for a computer program) is executed, the viral code is executed as well.

    Ransomware

    • Ransomware is a type of malicious software that threatens to publish the victim’s data or perpetually block access to it unless a ransom is paid.
    • While some simple ransomware may lock the system in a way that is not difficult for a knowledgeable person to reverse, more advanced malware uses a technique called cryptoviral extortion.
    • This encrypts the victim’s files, making them inaccessible, and demands a ransom payment to decrypt them.

    Worms

    • Computer worms are similar to viruses in that they replicate functional copies of themselves and can cause the same type of damage.
    • In contrast to viruses, which require the spreading of an infected host file, worms are standalone software and do not require a host program or human help to propagate.
    • To spread, worms either exploit the vulnerability on the target system or use some kind of social engineering to trick users into executing them.
    • A worm enters a computer through a vulnerability in the system and takes advantage of file-transport or information-transport features on the system, allowing it to travel unaided.
    • More advanced worms leverage encryption, wipers, and ransomware technologies to harm their targets.

    Trojans

    • A Trojan is a harmful piece of software that looks legitimate.
    • After it is activated, it can achieve any number of attacks on the host, from irritating the user (popping up windows or changing desktops) to damaging the host (deleting files, stealing data, or activating and spreading other malware, such as viruses).
    • Trojans are also known to create backdoors to give malicious users access to the system.
    • Unlike viruses and worms, Trojans do not reproduce by infecting other files nor do they self-replicate.
    • Trojans must spread through user interaction such as opening an email attachment or downloading and running a file from the Internet.

    Bots

    • “Bot” is derived from the word “robot” and is an automated process that interacts with other network services.
    • Bots often automate tasks and provide information or services that would otherwise be conducted by a human being.
    • A typical use of bots is to gather information, such as web crawlers, or interact automatically with Instant Messaging (IM), Internet Relay Chat (IRC), or other web interfaces.
    • They may also be used to interact dynamically with websites.