Showing posts with label Cyber Security. Show all posts
Showing posts with label Cyber Security. Show all posts

Thursday, November 23, 2017

"China's Internal Dynamics, Cyber Security and Relations with India"

The Vivekananda International Foundation (VIF) organized a seminar titled "China's Internal Dynamics, Relations with India & Cyber Security", along with the Prospect Foundation from Taiwan on 01 November 2017. Dr. Arvind Gupta, Director VIF, and Dr. Tan-Sun Chen, Chairman, Prospect Foundation, delivered the opening remarks. Dr. I-Chung Lai, Dr. Yi-Bin Lu, and Mr. Fan Peng participated from the Prospect Foundations whereas Mr. Jayadeva Ranade, Amb. TCA Rangachari, Dr. Sujit Dutta and Lt Gen Davinder Kumar represented the Indian side. The Taiwanese Representative in India, Chung- Kwang Tien, Mr. Jason Huang, Mr. Chihlung Sheng, and Mr. Oliver Harn also participated. Many senior members of the strategic community, scholars from think tanks and universities attended the seminar.
The discussion was divided into three sessions: One, ‘Evaluation of 19th Party Congress; two, ‘China’s Rising Cyber Power’; and three, ‘A Case for India-Taiwan Strategic Cooperation’. Opinions expressed by the Taiwanese delegation in each Session are enumerated in the succeeding paragraphs.
Session 1 : The Chinese Communist Party (CCP) General Secretary Xi Jinping, who holds fourteen formal positions (more than any other CCP leader so far) has emerged stronger from the 19th Party Congress. The biggest takeaway from the 19th Party Congress was that there are no apparent successors, leading to strong speculation that Xi could seek a third term after concentrating his power. The Party Congress emphasised that the People’s Liberation Army should focus on realising ‘Chinese Dream’ for which it should develop “a new military strategy under the new situation”. China will complete the modernisation of its armed forces by 2035 and achieve a world-class military by 2050 that can fight and win wars across all theatres.
Session 2: China has leveraged cyber-enable theft of intellectual property to create its critical mass. Its ‘Internet Plus’ strategy will further help in building its cyber space capacity. However, China is unlikely to be a dominant cyber power as it has inward looking focus. Democratic countries are more deliberate and hence they can build better cyber power in the long run.
Session 3: India and Taiwan have democratic governments and can identify cyber security as a strategic enabler of their unofficial relations. Both have the potential to pool together critical mass capability for strategic cooperation in cyber security.
Event Date: 
November 1, 2017

Tuesday, April 29, 2014

Cyber Warfare in the Indian Context

Lt Gen (Retd) Gautam Banerjee, 
Executive Council, VIF

The Cyber Space

The contemporary era is characterised by what has been described as the ‘information revolution’. This is a phenomenon in which automated processes are activated to marshal and manipulate huge volumes of digitised information as relevant to every field of human endeavours before disseminating that information across a virtually unlimited realm. As human societies across the entire globe as well as the systems governing these become entirely captive to usage of information assets, effective harness of information infrastructure in military engagements too becomes an undeniable obligation.

Information infrastructure is a chain of high-technology systems made up of sensors, transmission media, data processors, information centres and competent personnel to man these, all of which are coupled to form a most effective regulating medium for all global activities. However, the soul of this infrastructure rests in the all pervasive electronic time-space continuum. Described as ‘cyber-space’, this is the arena in which all exactions of societal progress, peace, stability - and war, of course – must be played out. Cyber-space, therefore, is central to the information infrastructure.

Just as it is in case of all other arenas of competitive engagement – land, sea, air, space and perception - the native instinct of usurpation of other’s resources has made it obligatory to protect one’s usage of cyber-space against corruption, subversion and neutralisation by adversarial powers, or even friendly competitors. When this obligation is sought to be fulfilled in the realm of military operations, the concept of Cyber Warfare crystallises. In principle, the term ‘Cyber Warfare’ should be usable only in military context and differentiated from the term ‘Cyber Security’, the latter term being better reserved for civilian information security functions. This distinction is necessary to avoid intrusion of conceptual ambiguities into the nation’s civilian and military security strategies.

The subject matter being vast, in this paper it is proposed to focus the discussion to the basic framework which dictates the terms of engagement in Cyber Warfare.

Information Warfare

Military security of a nation is cultivated by preparing for, or activating if necessary, such extreme inflictions that make the adversary desist from his unbearable animosity. In the nation’s military security functions, the profound role performed by information infrastructure makes it a key military objective, to be nurtured or neutralised as the case may be. Thus, the activities undertaken to gain ‘Information Superiority’ over the adversary through recourse to various kinds of military operations are termed as ‘Information Warfare’. Notably, while the ‘hard’ objects of information infrastructure may be attacked or protected by physical - active and passive - means, the ‘virtual reality’ of cyber-space needs sophisticated science and high-technology to tackle. Thus, within the overall ambit of Information Warfare, when military operations are carried out in the domain of cyber-space, the term used is ‘Cyber Warfare’. It is, however, important to note that while the adversary may be disabled by Cyber Warfare, he may not yet be induced to submit; whereas Information Warfare, when prosecuted, could achieve that purpose.

Measures applied to engage in Information Warfare are classified under two categories, namely, ‘Information Operations – Offensive’ and ‘Information Operations – Defensive’. These conventions help in delineating the military aspects of the information era.

Information Operations

Information Operations in either mode – Offensive and Defensive – are by convention classified under the following descriptions:-
  • Command and Control Warfare (C2W): Attacking adversary’s ability to generate and communicate commands to its forces is termed as C2W. It is directed at the adversary’s Defence Information Infrastructure.
  • Intelligence Based Warfare (IBW): It is the integration of sensors, processors and data-links to achieve profound and near-real time surveillance, reconnaissance, decision support, target selection and engagement, and finally, damage assessment.
  • Electronic Warfare (EW): Combat in the electromagnetic medium to achieve enhancement, degradation, interruption or corruption of radiating wave emissions is classified as EW. In other words, it implies domination of the electro-magnetic spectrum.
  • Psy Warfare: This is aimed at targeting the adversary's mental orientation and perception, and thereby influence his intention. In a larger context, it may be aimed at demoralising the hostile population.
  • Hacker Warfare: This is defined as destruction, degradation or exploitation of adversary’s computer data-base. Intrusion into adversary’s systems by ‘virus’, ‘worm’, ‘trojan horse’, logic bomb’ etc. is the mode adopted in this case.
  • Infrastructural or Economic Warfare. This involves ‘information blockade’ and ‘information hegemony’ to garner undue economic advantage. Under warlike conditions, its extreme manifestation may lead to attacks on the adversary’s core infrastructure – railways, power, oil sectors, for example.
It is needless to emphasise that the last three kinds of warfare are liable to transcend into the civilian domain.

Cyber Warfare

To reiterate, Information Warfare is resorted to gain Information Superiority by the means of Information Operations which are executed in Offensive as well as Defensive modes. There are many operating fields of Information Operations, such as human intervention, passive and active protection, weaponised attack, sabotage etc. which are executed in the physical domain. Similarly, the electro-magnetic spectrum becomes the battle field for Electronic Warfare. Lastly, when Information Operations are executed in the cyber domain, the term applicable is Cyber Warfare.

Cyber Warfare involves targeting the adversary’s military networks to induce collapse or corruption of his information-based Command, Control, Communication, Co-ordination, Intelligence and Inter-operable Systems (C4I2). Point to note is that the scope of hostilities are liable to transcend into the civil sector too, when the focus would be on the adversary’s societal perception and his national administrative and economic infrastructure.

Cyber Warfare is therefore one of the ‘military operations of war’. In the Indian context, it may be used as a purely military term and prosecuted in the manner of a military operation in the same spirit of extreme measures just as it is in the case of conventional, sub-conventional, manoeuvre or positional, mine and nuclear warfare.

Objectives of Cyber Warfare

The purpose of Cyber Warfare is to undertake defensive and offensive Information Operations in the cyber-space to degrade the adversary’s sensory, early warning, data analysis, intelligence exchange, decision support, and command, control and communication network – the entire system of military net-centricity in short - while at the same time protecting own information assets from hostile intrusion. In offensive operations, that goal is achieved by intrusion into the adversary’s vast volumes of digitised information that circulate in the cyber-space. Notably however, in defensive mode, besides adoption of general security measures, the effort cannot be so much in locking up own volumes of information simply because in the cyber domain that is impractical to achieve. The effort therefore is to identify the algorithms and processes of the adversary’s offensive Information Operations and neutralise these through corresponding counter-offensive measures - preferably proactive.

Objective of Cyber Warfare therefore is to gain information superiority in the aspects of surveillance and reconnaissance, data analysis, intelligence exchange, command and control of battle elements and flow of communication, and thereby protect own net-centric systems while disrupting that of the adversary.

Science of Cyber Warfare

Automated exploitation of information in the cyber-space covers the entire gamut of communication, computation and transmission net-works. In Cyber Warfare, the process of extracting information from vast array of data, converting these into intelligence and then deriving tactical inferences to support decision making is a highly complex matter. Even if humans naturally do so remarkably well, there are limitation of volume and speed that they can handle. Here science comes to the rescue, to define and quantify information, analyse input-data and facilitate decision making.

The matter of the science of Cyber Warfare is vast. It would therefore suffice here to just mention the core aspects of mathematical analyses which help in identification, selection and targeting in the cyber-space. This process is carried out through algorithms based on mathematical logic and digitised models, and involves the following defensive-offensive steps in continuum:-

  • Sensor based detection of presence, identification and tracking of cyber-entities (e.g. personnel and equipment, radiation pattern, etc.) by the process of search and intrusion of the cyber-space. This involves mathematical derivation of ‘inductive’ and ‘deductive’ logic to select relevant signatures or data-input.
  • Determination of inter-relationships and activities (e.g. data-mining, computation, data-transfer etc.) of the targeted cyber-entities. Comparison and templating with help of ‘data ware-house’ and ‘data-fusion’ is resorted to chart the adversary’s possible options thus. Application of information theories to sift through the data, identification of the target cyber-space and inference of intelligence are carried out through processes known as ‘abduction’ and ‘deduction’ of information.
  • Inference of plausible objectives of the adversary (e.g. dissemination of intelligence, command or engagement instructions etc.) through activation of the cyber-entities. This is accomplished by means of ‘indicator-data analysis’
    of the detected cyber-hierarchy and the deployment pattern of the cyber-entities. ‘Decision theories’ are applied to analyse and evaluate the alternatives.
  • Determination of the likely courses of Cyber Warfare, reactive or proactive, available to the adversary. This is a technical appreciation, assisted by automated military logic.
  • Assessment of own possible Cyber Warfare options and objectives. This too is a process of technical appreciation, duly narrowed down by pre-loaded military logic. The assessment is contingent upon right evaluation of the utility of intelligence and its exploitation in effective conduct of Cyber Warfare.
  • Decision support, passage of orders and monitoring of Cyber Warfare, and feedback. This may include automated target fixation, selection of the mode and method of Cyber Warfare, media selection, generation of engagement and manoeuvre instructions and fixation of the parameters of time and space (e.g. activation of sensors and other cyber-entities, followed by passage of orders).
The point to note is that Information Technology is the creator of cyber-space and also the core resource in the conduct of Cyber Warfare. Obviously therefore, it is also the most lucrative target of Information Warfare, cyber-attack included.

Features of Cyber Warfare

Having seen that it is impractical to establish any clear distinction between the conduct of offensive and defensive Cyber Warfare, it would suffice here to touch upon the mutually shared qualifying features. Accordingly, an overview of the likely ‘approaches’, ‘targets’ and ‘points’ of Cyber Attack may be in order.

Approaches of Cyber Attack: The approaches that could be adopted to carryout Cyber Attacks could be as follows:-
  • Direct or Penetration Attack: This involves penetration into adversary’s communication links, computer net work or data-base to steal or compromise internal information in favour of the attacker.
  • Indirect or Sensor or Media Attack: Insertion of false inputs into the adversary’s observation sensors or sources to achieve counter-information will be the objective of attack in this case.
  • Hybrid Attack: This will be a combination of the above mentioned two types of attacks – a most likely approach.
  • Cryptographic Attack: This involves one-time intrusion to locate vulnerabilities in the adversary’s system of cryptography, for manipulation when time comes. This aim is achieved by breaking the ‘key programme’ which is the heart of the system’s security.
  • Net Exploitation: This is an extension of ‘NETINT’ (Network Intelligence) aimed at compromising or corrupting the adversary’s information network. Introduction of malicious software executing agents, data scanners, ‘Radio Frequency Interception’ through wire tapping or remote 'sniffing', and software tools to carryout synchronised attack upon multiple cyber-entities are the means to do so.
Targets of Cyber Attack: Unlike other forms of attack, in Cyber Warfare, there is no scope of achieving any residual consolation from ‘near-hits’. Therefore, whatever be the approach adopted, a Cyber Attack has to be focused on a specific target. These targets could be:-
  • Content Attack: In this case, content of the information is targeted for disruption or denial with the purpose of misleading the adversary’s decision making process.
  • Dislocating Attack: In this form of attack, the location of data or its route for access is targeted to cause confusion, delay or corruption of information.
  • Temporal Attack: Here, either the retrieval of information is delayed till it is too late or a pre-conceived notion is reinforced well ahead of the actual event. This way the timeliness of information is subjected to disruption, thus diverting the adversary’s process of decision making.
Cyber Attack Points: Data or network level Cyber Attacks may be directed at any of the following vulnerable points:-
  • The adversary’s input sources or reporting links, by means of electronic warfare, irrational visuals and deception. The other option is to alter the orientation and focus of input sensors by steering away the control mechanism.
  • The process of object identification or tracking may be truncated by placement of hostile radiators.
  • The adversary’s sensor behaviour may be put through analysis to infer his focus of information query, and so gain insight of his objective.
  • Degradation or deception of the adversary’s deductive process may be achieved through network interference devices.
  • The adversary’s system design may be stolen, so as to acquire the capability of accessing his data base. This facilitates launching of Cyber Attack as and when necessary.
Imperatives of Cyber Defence

It is seen that when it comes to planning and execution of Cyber Warfare, there is little to distinguish between attack and defence. The fact is that foolproof Cyber Defence is difficult to achieve even after committing enormous resources unless it incorporates the ingredients of Cyber Attack. Even then, in the prosecution of Cyber Warfare, there are certain defensive obligations to be adopted. These, in brief, are:-
  • Warning mechanism for impending Cyber Attack, to trigger security drills including the automated response for safety or shut down.
  • Retrieval of corrupted, diverted, destroyed or captured assets - such as primary, secondary and tertiary data, the operating protocols, automated processes, etc.
  • Restoration of the compromised cyber driven systems - fiscal, transportation, power, industrial, technological and societal programmes, for example.
It will be noticed that only the first of the three responses has any room for retaliatory action, the rest being in-house measures. This limitation reinforces the fact that in the Cyber Warfare, defence comes a cropper unless its execution is facilitated by pre-planned intrusions into the adversary’s Cyber War establishment.

Conclusion

Being a relatively new form, it is important to develop indigenous postulations, concepts and practices of Cyber Warfare in the Indian context. This paper suggests that the term ‘Cyber Warfare’ be usable in the context of military operations, as distinct from the overarching scheme of ‘Cyber Security’ at the national level. It also posits that when prosecuted under the overall ambit of Information Operations, Cyber Warfare is predominant in offensive content and may be conducted from space, earth and cyber-space. Further, it implies that: firstly, continuous engagement in Information Operation during peace keeps the system fully updated and promotes experimentation and the spirit of innovations; and secondly, readiness for instant engagement is an imperative of Cyber Warfare.

It is also reiterated that most of the principles and activities associated with Cyber Warfare are applicable, with certain reorientations, to the civil information infrastructure too. Indeed, since the state of war engulfs the entire nation, targeting the adversary’s quasi-military and civil infrastructure to disrupt his national functioning may be an ultimate objective of Cyber Warfare. It is therefore absolutely necessary to adopt similar mechanisms for the sanctity of the nation’s civil infrastructure, and so foster a regime of ‘Cyber Security’ at the national level.

“The wise man does at once what the fool does finally” – Niccolo Machiavelli.

References
  1. “Information Warfare: Concept and Development”, 21st Century Army: Strategies for Future, Lt Gen (Retd) Gautam Banerjee, Manas Publications, New Delhi, 2012.
  2. Waltz, Edward, “Information Warfare Principles and Operations” : ARTECH House, London, 1998.
  3. Fialka, JJ, “War by Other Means”, New York: WW Norton, 1997.
  4. David and Katherine Hollis, “The Cyberspace Policies We Need”, Armed Forces Journal, USA, 2010.
  5. “Stray Voltage: War in Information Age”, WM Hall, Naval Institute Press, USA, 2003.
  6. http://www.vifindia.org/article/2014/february/07/dimensions-of-cyber-sec....

Published Date: 28th April 2014, Image source: http://economictimes.indiatimes.com

Tuesday, April 23, 2013

Let’s not Get too Relaxed on China


Kanwal Sibal, Dean, 
Centre for International Relations and Diplomacy, VIF

Reports of Chinese soldiers intruding 10 kilometres into Ladakh challenge once again our assumptions about the stability of the situation on the unsettled India-China border. Our expanding relationship with China has encouraged thinking that the border issue is no longer central to the future of the relationship and can await resolution as and when possible. We have adjusted ourselves to China’s India strategy. We downplay such incursions.

Hopeless

The low priority attached by the Chinese leadership to the resolution of the border dispute is ignored by us. President Xi Jinping has lost no time in telling us that the border issue is not easy to resolve, reiterating former Chinese premier Wen Jiabao’s remarks in Delhi in 2010. He has scotched any hope of changed thinking in Beijing on an issue that generates distrust and apprehensions about China’s longer term intentions. In effect, President Xi has closed the doors to a settlement for the next ten years when he will be in power. We have not reacted.

President Xi’s five point proposal for conducting relations with India is self-serving, as it is calculated to play to China’s strenghts and side step India’s concerns.

After ruling out a border settlement, the Chinese President proposes that the two countries cooperate to maintain peace and tranquillity. This is singularly unimaginative as the two are maintaining peace and tranquillity for the last two decades, following the relevant agreements of 1993 and 1996.

When President Xi proposes that border differences shoud not affect the overall relationship, he is only nodding at existing realities. The bilateral relationship has progressed tremendously despite Chinese periodic provocations, such as those laying claim to Arunachal Pradesh and describing it as “South Tibet”, protesting the visits of our political leaders there, shortening the length of the Sino-Indian border in a bid to question India’s territorial sovereignty in the eastern and western sectors, giving Kashmir-linked stapled visas etc.

These provocations have been one-sided. Notwithstanding them, our Prime Minister has met China’s leaders oftener than others; we have a strategic dialogue with China at political, economic and defence levels; our armed forces now conduct joint exercises, albeit limited. The two countries engage with each other in the Russia-India-China format, that of BRICS and G-20, apart from collaborating in WTO and climate change negotiations. Now China has proposed a dialogue with us on Afghanistan, which we have welcomed.

In proposing that differences over the border should not affect the overall relationship, President Xi wants to preserve the freedom to continue provoking us and undermining our interests in our neighbourhood, as the latest strategic decision to take over Gwadar demonstrates. His proposal that India should maintain close strategic communication in order to keep bilateral relations on the right track excludes any explanation from China about its strategic ties with Pakistan, its continuing assistance in building Pakistan’s nuclear capability, its opposition to our joining the Nuclear Suppliers Group and our permanent membership of the Security Council, etc.

Telecom

President Xi calls for harnessing each other’s comparative strengths and expand mutually beneficial cooperation in infrastructure, investment etc. India has comparative strength in Information Technology and pharmaceuticals for instance, but it faces hurdles in accessing the Chinese domestic market. China, on the other hand, has become India’s largest trading partner in goods despite our unsustainable trade deficit with it. Chinese telecommunication and power companies have bagged huge contracts in India despite serious cybersecurity concerns. China would like to have a share of the $1 trillion we intend investing in upgrading our infrastructure in the next 5 years, especially when it has huge unutilized capacities in this sector and opportunities abroad are declining because of a global slow down. It can use its financial strength to advantage in countries like India if the politics can be managed. Unsurprisingly with the border issue “effectively controlled”, the People’s Daily advocates more focus on trade and multilateral issues with India.

President Xi’s emphasis on strenghtening cultural ties is unobjectionable. Enhancing cooperation in multilateral forums to safeguard the legitimate rights and interests of developing countries in tackling global challenges- another point that President Xi makes- is desirable although China has hardly championed the rights of developing countries in the past, though today its hunger for natural resources and markets accounts for a different stance.

Concerns

When the Chinese President says that the two countries should accommodate each other’s core concerns, the hard kernel of his message becomes evident. India has never identified its core concerns to the international community or to China bilaterally. Consequently, President Xi is not talking about China accommodating India’s stated core concerns. In any case, whether in the case of transferring nuclear and missile technologies to Pakistan, undermining our position in our neighbourhood, whether in Nepal, Sri Lanka, Maldives or Bangladesh, China disregards our obvious core concerns.

The Chinese leader is expecting India, in a one-sided proposition, to accommodate China’s core concerns, evidently in South China Sea and Tibet, as Taiwan and Sinkiang are not contentious issues with us. China wants its sovereignty over these areas to be respected, while using Tibet to claim Indian territory and expanding its presence in territory under Pakistan’s illegal occupation in J&K.

We have chosen to interpret President Xi’s remarks positively. We possibly believe that we are in control of our relations with China, that China is reaching out to us and we must therefore seize this opportunity to explore the potential of the bilateral relationship. We are disregarding hard realities and confusing China’s tactical moves with its strategic intent. President Xi has signalled that China will not compromise on territorial issues, whether today in the east with others and tomorrow in the west with us.

Friday, May 25, 2012

Next Challenge for Governance - the Cloud Computing

 
Commander Mukesh Saini (Retd.)

The internet has transformed the planet Earth into a global village; where in cyberspace boundaries have little meaning. However perimeterization of an organizational data was always possible even in the Internet environment and it was possible to create De-Militarized Zone (DMZ) between the Internet and organization’s data. However with the adoption of Cloud computing, even this hazy boundary is being eroded. Thus the challenge ahead for a sovereign state is how to adapt to new technological paradigm.

Cloud computing (‘Cloud’) is changing the concepts of information handling in the same revolutionary manner as the World Wide Web did to it about a decade ago. So what is this Cloud Computing? It describes the use of collection of services, applications, information, processing power and storage resources. These components can be rapidly provisioned, implemented and decommissioned and scale up or down, providing for an on demand utility-like model of allocation and consumption of Computer based resources. It is hiring of various hardware, operating system and application software remotely from a very large pool from a Cloud Service Provider (CSP). The word cloud emerged from the initial diagrammatical representation of the Internet as cloud. It changes the capital cost into a variable cost.

Cloud computing is an evolving term that describes the development of many existing technologies and approaches to computing into something different. Some of the existing technologies orchestrated together to form a cloud include web 2.0, ubiquitous connectivity, virtualization, broadband networking, clustering, utility computing, multi tenancy, service oriented architecture and out sourcing. Cloud separates application and information resources from the underlying infrastructure, and the mechanisms used to deliver them.
National Institute of Standards and Technology (US) has published the working definition of the Cloud, which is “ A model for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g. networks, servers, storage, applications, and services) that can rapidly provisioned and released with minimal management effort or service provider interaction”.

According to NIST, Cloud services exhibit five essential characteristics that demonstrate their relation to, and differences from, traditional computing approaches: On-demand self-service, broad network access, resource pooling, rapid elasticity and measured service.

Though there are many flavors of services provided by CSPs but primarily there are three service models. Where only hardware such as Servers, memory, storage space etc. are provided on demand and user need to deploy its own Operating System (OS) and applications (apps), such services are called Infrastructure as a Service (IaaS). Incase CSP provides IaaS + Operating System than such a service model is called Platform as a Service (PaaS). The Software as a Service (SaaS) is the service model where CSP provides complete package including apps.

The cloud can be deployed as a ‘Private cloud’ by a group of companies under same banner or a government for internal purpose; or as ‘Community cloud’ for a specific community, say banking community; or as ‘Public cloud’ where anyone can buy any services and use; and in ‘Hybrid cloud’ environment private and public clouds are jointly used in an efficient and secure mode.

In ideal situation, cloud provides a kind of security which can never be matched by any medium size organization and at cost which can be as low as 10% of existing security cost. But the sense of loss of data outside the perimeter of the organization creates new challenges to cyber security. Challenges are created because the data of the organization is under CPS’s control, which may be fragmented and stored /processed at various locations across the globe unless service level agreement specifically bars it.
For a nation-state, the Cloud has created a new area of legal risks which lacks any precedence or established legal history. There will be difficulties in establishing legal jurisdiction for gathering evidence and enforcing any court order. Some of the challenges for law enforcement in the Cloud will be:-
(a) How the evidence will be gathered from the Cloud, in reliable and authentic manner, which can be verified during the trial - may be few years later?

(b) Who will be considered as custodian of data – the user who kept the data in the cloud or the CSP who owns the data storage space?

(c) Indian Police, which is still cannot cope with collecting digital evidence from desktops in accordance with the IT Act, let alone servers & clusters, how will they collect the evidence from the Cloud?
(d) Unlike first world countries where e-discovery and cyber evidence related to privacy of an individual can be gathered only on a court order, in India such orders are issued under sections 68 and 69 of IT Act by the executive. How such dramatic differences will be resolved? Rule under section 69 have been issued but no one is following them. Such attitude cannot help in cases with international ramifications.
(e) What happens when the original CSP goes bankrupt or taken over by a company from a country having not so friendly relations with India?

(f) What if criminals/ cyber terrorists use cloud for perpetuating a crime in real world and then release all resources back to the cloud? How such evidence will be retrieved? (It is one of the cloud management requirements that if a storage space is vacated by one legitimate tenant of the cloud, same to be forensically cleaned up immediately otherwise there exist a possibility of data leakage.)

Cloud Computing is a new paradigm which cannot be wished away, nor an executive order that no one to use cloud, will be of help because not allowing own companies / organization to use the Cloud will make them far less efficient and will have adverse affect on economy. It has been estimated that cloud provides 80 to 90 percent efficiency on IT spend and allow an organization to focus on its core competence. Simile could be, buying an aircraft to go from Delhi to New York, (traditional computing) versus buying a ticket from an airline for the journey (Cloud computing).

According to Gartner survey report, cloud computing service revenue in 2010 was estimated to be around £41 billion. The US Government as well as US industry is very aggressive on this technological shift. China has already rolled out “Sea of Cloud Plan” which will create 200 billion Yuan industrial cloud server by 2015.
Some of the suggested recommendations at nation-state level are:

(a) Government cannot afford to move at its lethargic pace, not only security but the very growth rate of India may be adversely impacted if this issue is not handled properly and timely manner.

(b) Government must aggressively launch Cyber Security Awareness campaign.


(c) Frame all rules as envisaged under the IT Act.

(d) Form a task force to advice and guide the policy and law makers. The Task Force must contain those who understand cloud security technological issues as well as national policy matters.

(e) Government must sign Convention of Cybercrime without further delay.

(f) Train Police, Cyber Forensic experts, Public prosecutors, lawyers and judiciary, to understand the complexity of investigation in the Cloud.

(g) Involve industry and private players in capacity building.

(h) Be a proactive partner in international fora on Cyber Security.

(i) And appoint an Ombudsman for resolving complaints of Cloud users and CSPs.

The world is at the chasm of next disrupting technological breakthrough which will make the national borders further meaningless. We can ignore the CLOUD at our own peril. There will be no choice expect adopting this new tool, therefore it will be better to understand it and make new laws to protect our interest, without attempting to contain its adoption. Aligning with international community will be a necessity, while getting into cocoon could be dangerous.