đŸ’„Join UPSC 2027,2028 Mentorship (July Batch) + XFactor Notes & Microthemes PDF

Subject: Internal Security

  • [pib] INS Karanj – A Kalvari Class Submarine

    Indian Navy’s third stealth Scorpene-class Submarine INS Karanj has been commissioned into the Indian Navy. It also completed the trials of the Indigenous Air Independent Propulsion (AIP) System jointly developed by Naval Materials Research Laboratory (NMRL) and DRDO.

    In a rare case, we would see a question based on various classes of Indian Submarines in the CSP. However, we can expect a question based on the AIP system in the CSP and CAPF exam.

    INS Karanj

    • INS Karanj is the third submarine of the first batch of six Kalvari-class submarines for the Indian Navy.
    • It is a diesel-electric attack submarine based on the Scorpene-class, designed by French naval defence and energy group DCNS and manufactured by Mazagon Dock Limited, an Indian shipyard in Mumbai.

    What is AIP?

    For this, we have to understand how a submarine works. Traditionally we hear about two types of submarines- Nuclear and Diesel Electric.

    Diesel Electric Submarines

    • While Nuclear Submarines can stay submerged for a prolonged period and remain undetected, Diesel Electric submarines cannot do so, and they must surface after a stipulated time interval.
    • Their Diesel Propulsion would need air to run the engine like any other Vehicle or Aircraft engines and for this, they would need oxygen which is not available underwater.
    • Hence they have to move closer to the surface so that their engines can breathe air through their snorkels.

    So, these diesel turbines charge the batteries available in the submarine and once the batteries are fully charged, the submarine goes underwater where the propeller shaft, as well as other systems, runs on the power stored in the batteries.

    • This makes the Submarine very much vulnerable to threats from Air, Sea or even underwater.
    • Not only has this, but the storage of excessive fuel also reduced the overall performance and weapon holding of the submarine too.

    Why don’t we can induct only the Nuclear Submarines in the Navy?

    • Though nuclear submarines can stay underwater for months, they cannot do so with total stealth.
    • While a diesel-electric submarine (while underwater) is making no noise, Nuclear submarines have a lot of vibrations that are generated from the coolant pumping system of their reactors which must run nonstop.
    • This makes even nuclear submarines vulnerable to depth sonars.
    • Moreover, the manufacturing cost of these submarines is several times higher than those of diesel-electric ones.
    • So, the most effective and commercially viable solution is a diesel-electric submarine with AIP.

    What is AIP, then?

    • Over the years the biggest challenge before the mariners was to ensure that the submarines can sustain underwater for a prolonged time.
    • AIP is any marine propulsion technology that allows a non-nuclear submarine to operate without access to atmospheric oxygen (by surfacing or using a snorkel).
    • While there are different types of AIP systems being pursued internationally, the DRDO has applied fuel cell-based AIP using hydrogen onboard.
    • Fuel cell-based AIP has merits in performance compared to other technologies
    • While the first two submarines (INS Kalvari & INS Khanderi) are equipped with French-made AIPs, the rest of the submarines will be equipped with an Indian system.

    Note: The Project 75I-class submarine is a follow-on of the Project 75 Kalvari-class submarine for the Indian Navy.

    Significance for India

    • With this induction, India has joined the club of six other elites who have the capacity to design and install such complex systems.
    • These countries are France, China, Spain, Sweden, Germany and Russia.
    • Indian AIP system is unique. It is one of the most advanced AIP systems of the world where Fuel Cell technology is used to generate onboard power.
    • With indigenous AIP, submarines can stay underwater for more than 3 weeks in low consumption mode, more than 2 weeks in endurance mode and 2-4 days in max power mode.

    Back2Basics: Various classes of Submarines in India

    In maritime terms, a class of ships is a group of vessels that have the same make, purpose and displacement.

    • Chakra Class: Under a 10-year lease from Russia since 2012
    • Arihant Class: Nuclear-powered ballistic missile submarines
    • Shishumar Class: Diesel-electric attack submarines Indian variant of the Type 209 submarines developed by the German Navy
    • Kalvari Class: Diesel-electric attack submarines designed by French company DCNS
    • Sindhughosh Class: Kilo-class diesel-electric submarines built with the help of Russia
  • Critical information infrastructure

    The article underscores the threat of cyberattacks on the critical infrastructure and also suggests the steps to be taken to secure these infrastructures.

    Cyberattack on the power grid

    • On October 12 last year, Mumbai plunged into darkness as the electric grid supply to the city failed.
    • Recently, a study by Massachusetts-based Recorded Future,  said that the Mumbai power outage could have been a cyberattack aimed at critical infrastructure.
    • It was carried out by the state-sponsored group Red Echo.
    • As recently as in February, the Centre’s nodal agency National Critical Information Infrastructure Protection Centre (NCIIPC) had reported concerted attempts by Red Echo to hack the critical grid network.
    • CERT-In, is reported to have detected the ShadowPad malware in one of the largest supply chain attacks a month after the Mumbai outage.
    • Many of the suspected IP addresses identified by NCIIPC and CERT-In were the same and most have been blocked in time.
    • The Chinese focus in the past was stealing information and not projecting power, but the situation with India might be different.

    Why critical infrastructures are so vulnerable

    • As many of these critical infrastructures were never designed keeping security in mind and always focused on productivity and reliability, their vulnerability is more evident today.
    • With devices getting more interconnected and dependent on the internet facilitating remote access during a pandemic, the security of cyber-physical systems has, indeed, become a major challenge for utility companies.

    Critical information infrastructure protection

    • For more than a decade, there have been concerns about critical information infrastructure protection (CIIP).
    • In January 2014, the NCIIPC was notified to be the national nodal agency for CIIP and over these years has been working closely with the various agencies.
    • In January 2019, the government also announced a National Mission on Interdisciplinary Cyber-Physical Systems (NM-ICPS), with a budget of Rs 3,660 crore for the next five years, to strengthen the sector.

    Way forward

    • Most ministries and departments need better budget allocations for cybersecurity as well as a more robust infrastructure, processes and audit system.
    • The Industrial Cybersecurity Standards (IEC62443) launched by the Bureau of Indian Standards (BIS), has to be adopted soon.
    • For the power sector, a strong regulation on the lines of the North American Electric Reliability Critical Infrastructure Protection (NERC) policy could serve as a guide.

    Consider the question “Discuss the importance of critical information infrastructure protection (CIIP)? Also mention the steps taken by the government in this regard.” 

    Conclusion

    Clearly, the incident is a wake-up call for better preparedness in terms of a more robust cyber security ecosystem in place. The new cyber security policy awaiting imminent announcement will hopefully cater to that.

  • [pib] Exercise Dustlik-II

    The Second Edition of Joint Exercise Dustlik is scheduled from tomorrow.

    Must read:

    [Prelims Spotlight] Various Defence Exercises in News

    Exercise Dustlik-II

    • It is a bilateral defence exercise held between the Indian Army And Uzbekistan Army.
    • It is named after Dustlik, a town in the Jizzakh region of Uzbekistan.
    • The first edition of the exercise, Dustlik-I was held in Uzbekistan, near Tashkent, from November 3-13, 2019.
    • Defence Minister Rajnath Singh had flagged off the exercise along with his Uzbek counterpart, Major General Bakhodir Kurbanov in 2019 for the first time.
    • The joint exercise focused on counter-insurgency and counter-terrorism operations in urban settings.
  • China’s cyber eye and India

    Amid souring relations between India and China last year, evidence has emerged that a Chinese government-linked company’s attempt led to a power outage in Mumbai yesterday and now in Telangana today.

    Q.The use of cyber offensive tools and espionage is a fairly active element of the People’s Republic of China. Discuss in light of recent incidences of cyber attack in India.

    Red Echo & ShadowPad

    • On February 28, a Massachusetts-based firm published a report saying it had observed a steep rise in the use of resources like malware by a Chinese group called Red Echo.
    • It aimed to target “a large swathe” of India’s power sector.
    • It said 10 distinct Indian power sector organisations were targeted, including four Regional Load Despatch Centres (RLDCs) that are responsible for the smooth operation of the country’s power grid by balancing the supply and demand of electricity.
    • Red Echo used malware called ShadowPad, which involves the use of a backdoor to access servers.

    India confirms cyber attack

    • The Ministry of Power has confirmed these attempts, stating it had been informed in November 2020 about the ShadowPad malware at some control centres.
    • The Ministry said it was informed of Red Echo’s attempts to target the country’s load despatch centres in February.
    • It had said “no data breach/data loss” had been detected due to the incidents.

    What does it imply?

    • This is clearly something that is linked to China’s geopolitical interests.
    • It is established very clearly that the use of cyber offensive tools and espionage is a fairly active element of what the People’s Republic of China seems to be adopting and encouraging.
    • Even when they are not directly in charge of an offensive operation, they seem to be consistently encouraging actors to develop this capability.

    PRC’s long term strategy

    • These cyber-attacks are seen as an attempt to test and lay the grounds for further operations in the future.
    • We need to remember that sometimes these offensive operations are carried out to distract people from other places that they might be targeting or other activities that might be occurring.
    • There was an increase in cyber offensive operations and incidents around the world in the second half of 2020 especially targeting the healthcare and vaccine space.
    • When vaccine companies are targeted, the motive could be competition.
    • The motivation behind Stone Panda’s attack against SII and Bharat Biotech’s IT systems was to extract the companies’ intellectual property and gain a competitive advantage.

    Other such attacks: Stone Panda & vaccines

    • A Chinese hacker group known as Stone Panda had identified gaps and vulnerabilities in the IT infrastructure and supply chain software of Bharat Biotech and the Serum Institute of India.
    • These companies have developed Covaxin and Covishield, which are currently being used in the national vaccination campaign.
    • They are also in the process of testing additional Covid-19 vaccines that could add value to efforts around the world.
  • Pakistan to remain on FATF ‘Greylist’

    The Financial Action Task Force (FATF) has decided to retain Pakistan on the “greylist” till the next review of its performance.

    Practice question for mains:

    Q.What is FATF? Discuss its role in combating global financial crimes and terror financing.

    What is the FATF?

    • FATF is an intergovernmental organization founded in 1989 on the initiative of the G7 to develop policies to combat money laundering.
    • The FATF Secretariat is housed at the OECD headquarters in Paris.
    • It holds three Plenary meetings in the course of each of its 12-month rotating presidencies.
    • As of 2019, FATF consisted of 37 member jurisdictions.
    • India became an Observer at FATF in 2006. Since then, it had been working towards full-fledged membership. On June 25, 2010, India was taken in as the 34th country member of FATF.

    What is the role of FATF?

    • The rise of the global economy and international trade has given rise to financial crimes such as money laundering.
    • The FATF makes recommendations for combating financial crime, reviews members’ policies and procedures, and seeks to increase acceptance of anti-money laundering regulations across the globe.
    • Because money launderers and others alter their techniques to avoid apprehension, the FATF updates its recommendations every few years.

    What is the Black List and the Grey List?

    • Black List: The blacklist, now called the “Call for action” was the common shorthand description for the FATF list of “Non-Cooperative Countries or Territories” (NCCTs).
    • Grey List: Countries that are considered safe haven for supporting terror funding and money laundering are put in the FATF grey list. This inclusion serves as a warning to the country that it may enter the blacklist.

    Consequences of being in the FATF grey list:

    • Economic sanctions from IMF, World Bank, ADB
    • Problem in getting loans from IMF, World Bank, ADB and other countries
    • Reduction in international trade
    • International boycott

    Pakistan and FATF

    • Pakistan, which continues to remain on the “grey list” of FATF, had earlier been given the deadline till the June to ensure compliance with the 27-point action plan against terror funding networks.
    • It has been under the FATF’s scanner since June 2018, when it was put on the Grey List for terror financing and money laundering risks.
    • FATF and its partners such as the Asia Pacific Group (APG) are reviewing Pakistan’s processes, systems, and weaknesses on the basis of a standard matrix for anti-money laundering (AML) and combating the financing of terrorism (CFT) regime.
  • Australia vs Facebook Row

    The social media giant Facebook is locked in a battle with Australia over legislation that would require FB, Google to pay for news outlets.

    Row over the news on social media

    • Australia had proposed a law called the News Media and Digital Platforms Mandatory Bargaining Code Bill 2020.
    • It seeks to mandate a bargaining code that aims to force Google and Facebook to compensate media companies for using their content.

    Imagine if the case arises in India where tons of news channels and impulsive journalists are dying off hard to gather TRPs!

    Response from the ‘giants’

    • Google had threatened to make its search engine unavailable in Australia in response to the legislation, which would create a panel to make pricing decisions on the news.
    • Facebook responded by blocking users from accessing and sharing Australian news.

    Why countries are bringing such legislation?

    • Australia has launched a global diplomatic offensive to support its proposed law to force Internet giants Facebook and Google to pay media companies.
    • Google accounts for 53% of Australian online advertising revenue and Facebook for 23%.
    • The legislation sets a precedent in regulating social media across geographies and is being closely watched the world over.

    What is happening in other countries?

    • Australia’s proposed law would be the first of its kind, but other governments also are pressuring Google, Facebook and other internet companies to pay news outlets and other publishers for the material.
    • In Europe, Google had to negotiate with French publishers after a court last year upheld an order saying such agreements were required by a 2019 EU copyright directive.
    • France is the first government to enforce the rules, but the decision suggests Google, Facebook and other companies will face similar requirements in other parts of the 27-nation trade bloc.

    The ‘doubted’ reluctance

    • Last year, Facebook announced it would pay US news organizations including The Wall Street Journal, The Washington Post and USA Today for headlines.
    • In Spain, Google shut down its news website after a 2014 law required it to pay publishers.

    Why does this matter?

    • Developments in Australia and Europe suggest the financial balance between multibillion-dollar internet companies and news organizations might be shifting.
    • Australia is responding to complaints by news reports, magazine articles and other content that appears on their websites or is shared by users.
    • The government acted after its competition regulator tried and failed to negotiate a voluntary payment plan with Google.
    • The proposed law would create a panel to make binding decisions on the price of news reports to help give individual publishers more negotiating leverage with global internet companies.

    Not losing out revenue gain

    • Google’s agreement means a new revenue stream for news outfits, but whether that translates into more coverage for readers, viewers and listeners is unclear.
    • The union for Australian journalists is calling on media companies to make sure online revenue goes into newsgathering.
  • What is Extinction Rebellion?

    Delhi Police have named some environmental activists who are volunteers of a global environment movement seeking to call attention to the climate change emergency, in the Greta Thunberg ‘toolkit’ case.

    Q.Climate activism is increasingly turning into a propaganda movement. Discuss.

    What is Extinction Rebellion?

    • The global movement Extinction Rebellion also referred to as ‘XR’, describes itself as a decentralized, international and politically non-partisan movement using non-violent direct action and civil disobedience.
    • It aims to persuade governments to act justly on the Climate and Ecological Emergency.
    • XR was launched in the UK on October 31, 2018, as a response to a report by the United Nations Intergovernmental Panel on Climate Change (IPCC).
    • It had then declared that we only have 12 years to stop catastrophic climate change and our understanding that we have entered the 6th mass extinction event.
    • The movement now has a presence in 75 countries, including India.

    What does XR want?

    • The group has “three core demands” of governments around the world.
    • It wants governments to “Tell the Truth”, to “Act Now”, and to “Go Beyond Politics” in order to confront the climate and ecological emergency that the world is faced with.
    • It wants them to communicate the urgency to bring change, and reduce greenhouse gas emissions to net-zero by 2025.
    • XR seeks to “rebel”, and asks groups to “self-organise”, without the need for anyone’s permission, to come up with collective action plans as long as they adhere to the group’s core principles and values.

    What activities have XR done so far?

    • The group had announced a “Declaration of Rebellion” at launch, involving a public act of civil disobedience in London, demanding that the government reduce carbon emission to zero by 2025.
    • The eventual plan was to coordinate actions in other countries and to engage in an “International Rebellion” in March 2019.
    • The XR global website, however, states that the movement is “strictly non-violent”, and that they are “reluctant law-breakers”.
    • In April 2019, Greta Thunberg, the teenage Swedish climate activist, lent her support to the group by speaking to its members in London.

    XR and India

    • The movement claims to have been inspired by 15 major civil disobedience movements around the world, including, apart from Women’s Suffrage and the Arab Spring, India’s struggle for Independence.
    • It refers to Mahatma Gandhi’s Salt March in 1930.
    • XR’s website says there are 19 groups in the country, including in the cities of Mumbai, Pune, Delhi, Hyderabad, Bengaluru, Kolkata, and Chennai.

    Recent events

    • One of the group’s early public events was a “die-in” protest organised at Bandra Reclamation in Mumbai in October 2019.
    • Participants at “die-in” protests lie on the ground, pretending to be dead.
    • Since the city was already seeing protests against the felling of trees at Aarey Colony for the Metro crashed, police did not grant permission for the “die-in” protest.
  • Arjun: Main Battle Tank MK-1A

    PM has recently handed over the indigenously developed Arjun Main Battle Tank (MK-1A) to the Indian Army.

    Q.Discuss India’s preparedness for high-altitude warfare.

    Arjun Main Battle Tank

    • The Arjun Main Battle Tank project was initiated by DRDO in 1972 with the Combat Vehicles Research and Development Establishment (CVRDE) as its lead laboratory.
    • The objective was to create a “state-of-the-art tank with superior firepower, high mobility, and excellent protection”.
    • During the development, the CVRDE achieved breakthroughs in the engine, transmission, hydro-pneumatic suspension, hull and turret as well as the gun control system.
    • Mass production began in 1996 at the Indian Ordnance Factory’s production facility in Avadi, Tamil Nadu.

    Features of the Arjun tank

    • The Arjun tanks stand out for their ‘Fin Stabilised Armour Piercing Discarding Sabot (FSAPDS)’ ammunition and 120-mm calibre rifled gun.
    • It also has a computer-controlled integrated fire control system with a stabilised sighting that works in all lighting conditions.
    • The secondary weapons include a co-axial 7.62-mm machine gun for anti-personnel and a 12.7-mm machine gun for anti-aircraft and ground targets.

    How is Mk-1A different?

    • The Mk-1A version has 14 major upgrades on the earlier version.
    • It is also supposed to have missile firing capability as per the design, but this feature will be added later as final testing of the capability is still on.
    • However, the biggest achievement with the latest version is 54.3 per cent indigenous content against the 41 per cent in the earlier model.
  • What is NetWire Malware?

    This newscard is an excerpt from the original article published in The Hindu.

    Try this question from CSP 2018:

    Q.The terms ‘WannaCry, Petya, Eternal Blue’ sometimes mentioned news recently are related to

    (a) Exoplanets

    (b) Crypto currency

    (c) Cyber attacks

    (d) Mini satellites

    What is NetWire?

    • NetWire, which first surfaced in 2012, is a well-known malware.
    • It is also one of the most active ones around.
    • It is a remote access Trojan, or RAT, which gives control of the infected system to an attacker. Such malware can log keystrokes and compromise passwords.

    Threats posed

    • This malware essentially does two things:
    1. One is data exfiltration, which means stealing data. Most anti-virus software is equipped to prevent this.
    2. The other involves infiltrating a system, and this has proven to be far more challenging for anti-virus software.
    • NetWire is described as an off-the-shelf malware, while something like Pegasus, which used a bug in WhatsApp to infiltrate users’ phones in 2019, is custom-made and sold to nations.

    Back2Basics: Classification of malicious softwares

    Viruses

    • A computer virus is a type of malware that propagates by inserting a copy of itself into and becoming part of another program.
    • It spreads from one computer to another, leaving infections as it travels.
    • Viruses can range in severity from causing mildly annoying effects to damaging data or software and causing denial-of-service (DoS) conditions.
    • Almost all viruses are attached to an executable file, which means the virus may exist on a system but will not be active or able to spread until a user runs or opens the malicious host file or program.
    • When the host code (alternative word for a computer program) is executed, the viral code is executed as well.

    Ransomware

    • Ransomware is a type of malicious software that threatens to publish the victim’s data or perpetually block access to it unless a ransom is paid.
    • While some simple ransomware may lock the system in a way that is not difficult for a knowledgeable person to reverse, more advanced malware uses a technique called cryptoviral extortion.
    • This encrypts the victim’s files, making them inaccessible, and demands a ransom payment to decrypt them.

    Worms

    • Computer worms are similar to viruses in that they replicate functional copies of themselves and can cause the same type of damage.
    • In contrast to viruses, which require the spreading of an infected host file, worms are standalone software and do not require a host program or human help to propagate.
    • To spread, worms either exploit the vulnerability on the target system or use some kind of social engineering to trick users into executing them.
    • A worm enters a computer through a vulnerability in the system and takes advantage of file-transport or information-transport features on the system, allowing it to travel unaided.
    • More advanced worms leverage encryption, wipers, and ransomware technologies to harm their targets.

    Trojans

    • A Trojan is a harmful piece of software that looks legitimate.
    • After it is activated, it can achieve any number of attacks on the host, from irritating the user (popping up windows or changing desktops) to damaging the host (deleting files, stealing data, or activating and spreading other malware, such as viruses).
    • Trojans are also known to create backdoors to give malicious users access to the system.
    • Unlike viruses and worms, Trojans do not reproduce by infecting other files nor do they self-replicate.
    • Trojans must spread through user interaction such as opening an email attachment or downloading and running a file from the Internet.

    Bots

    • “Bot” is derived from the word “robot” and is an automated process that interacts with other network services.
    • Bots often automate tasks and provide information or services that would otherwise be conducted by a human being.
    • A typical use of bots is to gather information, such as web crawlers, or interact automatically with Instant Messaging (IM), Internet Relay Chat (IRC), or other web interfaces.
    • They may also be used to interact dynamically with websites.
  • [pib] Malabar Naval Exercises

    The 24th edition of Malabar maritime exercise, hosted by Indian Navy in 2020, witnessed the participation by Indian Navy, United States Navy, Japan Maritime Self Defence Force and Royal Australian Navy.

    Such news is nothing but the repetitive chunk that occurs every year with few or no new developments. Still, they are significant for the sake of information as Australia has joined it after several apprehensions.

     Question can be expected in CAPF, CDS or AFCAT exams.

    About Ex. Malabar

    • Exercise Malabar is a trilateral naval exercise involving the US, Japan and India as permanent partners.
    • This year Australia has joined as a permanent partner.
    • Originally begun in 1992 as a bilateral exercise between India and the United States, Japan became a permanent partner in 2015.
    • Past non-permanent participants are Australia and Singapore.
    • The annual Malabar series began in 1992 and includes diverse activities, ranging from fighter combat operations from aircraft carriers through Maritime Interdiction Operations Exercises.

    Significance of Australia’s inclusion

    • Earlier, India had concerns that it would give the appearance of a “quadrilateral military alliance” aimed at China.
    • Now both look forward to the cooperation in the ‘Indo-Pacific’ and the strengthening of defence ties.
    • This has led to a convergence of mutual interest in many areas for a better understanding of regional and global issues.
    • Both are expected to conclude the long-pending Mutual Logistics Support Agreement (MLSA) as part of measures to elevate the strategic partnership.