💥Join UPSC 2027,2028 Mentorship (July Batch) + XFactor Notes & Microthemes PDF

GS Paper: Cyber Security

  • What is the SolarWinds Hack?

    The ‘SolarWinds hack’, a cyberattack recently discovered in the US, has emerged as one of the biggest ever targeted against the US government, its agencies and several other private companies.

    Do you know about the ‘Five Eyes’ group of nations?

    Solar-Winds Hack

    • It was first discovered by US cybersecurity company FireEye, and since then more developments continue to come to light each day.
    • The US termed it as a highly sophisticated threat actor calling it a state-sponsored attack, although it did not name Russia.
    • It said the attack was carried out by a nation with top-tier offensive capabilities and the attacker primarily sought information related to certain government customers.

    How dangerous is the attack?

    • This is being called a ‘Supply Chain’ attack.
    • Instead of directly attacking the federal government or a private organization’s network, the hackers target a third-party vendor, which supplies software to them.
    • Once installed, the malware gave a backdoor entry to the hackers to the systems and networks of SolarWinds’ customers.
    • More importantly, the malware was also able to thwart tools such as anti-virus that could detect it.

    The deadliest cyber-attack ever in the US

    • The US Energy department which is responsible for managing America’s nuclear weapons is the latest agency to confirm that it has been breached in the SolarWinds cyber attack.
  • RBI’s Positive Pay system

    The new ‘Positive Pay’ mechanism was recently introduced by the Reserve Bank of India (RBI).

    Try this PYQ:

    With reference to digital payments, consider the following statements:

    1. BHIM app allows the user to transfer money to anyone with a UPI-enabled bank account.
    2. While a chip-pin debit card has four factors authentication, BHIM app has only two factors of authentication.

    Which of the statements given above is/are correct? (CSP 2018)

    a) 1 only
    b) 2 only
    c) Both 1 and 2
    d) Neither 1 nor 2

    What is the move?

    • Issuers will be able to send all details to their bank, thereby ensuring faster clearance of cheques above Rs 50,000.
    • All cheques will be processed as per the information sent by the account holder at the time of issuance of cheques.
    • This will cover approximately 20 per cent of transactions by volume and 80 per cent by value.
    • It will make cheque payments safer and reduces instances of frauds.

    What is Positive Pay Mechanism?

    • Positive Pay is a fraud detection tool adopted by banks to protect customers against forged, altered or counterfeit cheques.
    • It crosses verifies all details of the cheque issued before funds are encashed by the beneficiary.
    • In case of a mismatch, the cheque is sent back to the issuer for examination.
    • By following such a system, a bank knows of a cheque being drawn by the customer even before it is deposited by the beneficiary into his/her account.

    How does the mechanism work?

    • Under Positive Pay feature, the issuer will first share the details of the issued cheque like cheque number, date, name of the payee, account number, amount and the likes through his/her net banking account.
    • Along with this, an image of the front and reverse side of the cheque is also required to be shared, before handing it over to the beneficiary.
    • When the beneficiary submits the cheque for encashment, the details are compared with those provided to the bank through Positive Pay.
    • If the details match, the cheque is honoured. However, in the case of mismatch, the cheque is referred to the issuer.
    • In this way, any cheque where any sort of fraud has happened cannot be cleared at all and hence, a depositor’s money can be protected.
  • What are Deep Fakes?

    Cybercrime officials in India have been tracking certain apps and websites that produce vulgar photographs of innocent persons using Artificial Intelligence (AI) algorithms. These images are then used to blackmail victims, seek revenge or commit fraud on social networking and dating sites.

    The most notorious misuse of AI is knocking the door. The Deepfake is an application of Deep Learning (an axiom of AI and Machine Learning). UPSC may ask a mains question about the challenges posed by AI-based technology.

    What is Deep Fake?

    • Cybercriminals use AI software — now easily available on apps and websites — to superimpose a digital composite (assembling multiple media files to make a final one) on to an existing video, photo or audio.
    • They are computer-generated images and videos.
    • Using AI algorithms a person’s words, head movements and expressions are transferred onto another person in a seamless fashion.
    • That makes it difficult to tell that it is a deepfake unless one closely observes the media file.

    Threats posed

    • Because of how realistic deepfake images, audio and videos can be, the technology is vulnerable for use by cybercriminals who could spread misinformation to intimidate or blackmail people.
    • With real-time face tracking it is becoming easier to fabricate believable videos of people doing and saying things they never did.
    • There are rising cases of “revenge porn” i.e. creation of sexually explicit videos or images that are posted on the Internet without the consent of the subject as a way to harass them.

    What are the catfish accounts?

    • Catfishing refers to the practice of setting up fictitious online profiles most often for the purpose of luring another into a fraudulent romantic relationship.
    • A “catfish” account is set up a fake social media profile with the goal of duping that person into falling for the false persona.

    What can we do to protect yourself?

    • A basic check of their social media profiles, comments on the images and whether similar profiles exist could help determine if the person is genuine.
    • While it is not easy to keep track of who downloads or misuses the user images, the best way to protect is to ensure that we are using privacy settings on social media profiles.
    • If one feels his/her image has been used without prior permission, they could use freely available reverse image search tools to find images that are similar to yours.
    • One can also be mindful of who he/she is conversing with on the web.
  • [op-ed snap] We should offer to safeguard the world’s telecom networks

     Context

    India should grab cybersecurity opportunities instead of focusing on smaller issues like import tariffs during Trump’s visit.

    Opportunity for India in the US-China trade war

    • Technology will be an important front in the emerging trade war between the US and China.
      • It will create significant opportunities for India as global supply chains re-adjust to geopolitical pushes and pull.
      • In manufacturing: The immediate opportunity is in across-the-board manufacturing, especially if the Government puts in place a special task force to unclog the regulatory issues.
      • In cybersecurity: Beyond manufacturing, the unfolding US-China technology war is creating opportunities for India in the cybersecurity space on a scale that could match Y2K.

    Balance national security and industry economics

    • The UK’s approach: It is a carefully constructed middle path.
    • Not allowing high-risk vendors: The UK decided that “high-risk vendors” will not be permitted in its core networks.
      • High regulatory and security oversight: High-risk vendors will also be subject to higher levels of regulatory and security oversight.
      • Ability to switch: Operators are expected to have the ability to switch away from such vendors should the government so require.
    • 35% restriction: The UK restricted to less than 35% of the equipment base of each telecom operator.
    • The EU approach:  The European Union is likely to adopt some variant of the British approach.
      • This means Chinese-made equipment will be deployed across EU countries but under tighter surveillance, audit and assurance regime.

    How is it going to create opportunities?

    • 5G and more need for more security professionals
      • More base stations: 5G networks will employ many more base stations than existing networks.
      • The internet of things (IoT) is set to bring billions of connected sensors and devices online.
      • The requirement of security professionals: Tightening security norms will require both telecom firms and their customers to employ a lot of cybersecurity professionals in a wide range of roles, of varying levels of sophistication and sensitivity.
    • Shortage of cybersecurity professionals
      • The problem is: the world is already short of cybersecurity professionals.
      • Even before 5G networks are rolled out, estimates suggest that there are 2 to 3 million unfilled cybersecurity vacancies around the world.
      • Scrutiny of the Chinese vendors and employment opportunities: The more stringent the security regimes around Chinese vendors, the greater the demand for cybersecurity professionals security regimes around Chinese vendors, the greater the demand for cybersecurity professionals.
    • Where is the opportunity for India? The industry is responding to this shortage by employing more automation.
      • But demand for human will increase: The demand for trustworthy, reliable and competent human beings to keep an eye on cyber threats will only increase.
      • Where can hundreds of thousands of technology professionals who might be able to fill this gap come from? India and China.
      • Advantage India: Chinese firms and individuals are unlikely to be chosen to keep an eye on Chinese equipment makers and state-linked cyber attackers, it is advantage India.

    Can India grab this opportunity?

    • Inadequate professionals in India: India doesn’t have adequate numbers of cybersecurity professionals either.
      • Skill initiative by the government: The government has launched a skills initiative to plug the shortage, but we’re far away from addressing our own cybersecurity needs.
      • India has all the necessary conditions to become as big a player in the global cybersecurity market.
      • India has the numbers, the companies and the market-driven economic models that can produce the skills that the industry wants.
    • Private sector’s role: During the 1990s’ information technology boom, India produced hundreds of thousands of software engineers not because of any government skills development programme, but because private firms popped up and supplied the skills that people and their employers wanted.

    Way forward

    • Government to government arrangements: Unlike the Y2K days, the global demand for cybersecurity professionals has entry barriers that firms and individuals cannot easily cross on their own. Government-to-government arrangements can help Indian firms and individuals get clearances for cybersecurity roles.
    • Developing cybersecurity partnership: India will have to work on developing cybersecurity partnerships with the US, UK and the EU, focused on opening up their markets to Indian firms.
    • Win the trust: The latter, for their part, must work on gaining the trust of the West’s national security establishments.

     

     

  • [pib] Indian Cyber Crime Coordination Centre (I4C)

    Union Minister for Home Affairs has inaugurated the Indian Cyber Crime Coordination Centre (I4C) and also dedicated National Cyber Crime Reporting Portal to the Nation.

    I4C

    • The scheme to setup I4C was approved in October 2018 to deal with all types of cybercrimes in a comprehensive and coordinated manner.
    • At the initiative of Union Ministry for Home Affairs (MHA), 15 States and UTs have given their consent to set up Regional Cyber Crime Coordination Centres at respective States/UTs.
    • It has seven components:
    1. National Cyber Crime Threat Analytics Unit
    2. National Cyber Crime Reporting Portal
    3. National Cyber Crime Training Centre
    4. National Cyber Crime Research and Innovation Centre
    5. National Cyber Crime Forensic Laboratory Ecosystem
    6. Platform for Joint Cyber Crime Investigation Team
    7. Cyber Crime Ecosystem Management Unit

    About National Cyber Crime Reporting Portal

    • National Cyber Crime Reporting Portal (www.cybercrime.gov.in) is a citizen-centric initiative that will enable citizens to report cyber crimes online through the portal.
    • All the cyber crime related complaints will be accessed by the concerned law enforcement agencies in the States and Union Territories for taking action as per law.
    • This portal was launched on pilot basis on 30th August, 2019 and it enables filing of all cyber crimes with specific focus on crimes against women, children, particularly child pornography, child sex abuse material, online content pertaining to rapes/gang rapes, etc.
    • This portal also focuses on specific crimes like financial crime and social media related crimes like stalking, cyber bullying, etc.
    • This portal will improve coordination amongst the law enforcement agencies of different States, districts and police stations for dealing with cyber crimes in a coordinated and effective manner.