Showing posts with label Intelligence. Show all posts
Showing posts with label Intelligence. Show all posts

Tuesday, December 11, 2012

Need to Expedie The Creation Of An Indian Cyber Command


Radha Krishna Rao 
(Research Fellow, VIF)

Along with the outer space, cyber space is rapidly emerging as a new and sophisticated theatre of warfare with serious consequences for the security of the countries that lack the expertise and infrastructure to ensure the safety of their information and communications networks and mount counter offensive. Indeed, the overall lethality and destructive potential of the cyber war, where the adversary remains invisible and difficult to detect, has been increasing at a phenomenal pace. Because stealth and anonymity are the distinct advantages of cyber war, it is possible to inflict unprecedented damages on the civilian and military assets of a targeted country at a short notice and that too without any elaborate preparations normally associated with a conventional war.

Moreover, cyber attacks could also easily be mounted on corporate and industrial entities to cripple their operations and put them out of the business by a breed of smart cyber hackers. “In the past, we could count the number of bombers and tanks your enemy had. In cyber war, we really can’t tell whether the enemy has the weapons until he uses them,” says Richard Clarke, a former Chairman of White House Critical infrastructure Protection Board.

Because cyber communications continues to be a dynamic and rapidly evolving area that is subject to the process of sustained innovations and refinements, there is no fool proof firewall capable of insulating the information networks and computer systems from the malicious manoeuvres of a well trained and highly motivated cyber warriors. The recent defacing of the websites of some of the key government of India organisations including the ones belonging to an advisor to the Prime Minister and DRDO (Defence Research and Development Organisation) cannot but be a wakeup call for India. Of course, this cyber attack that reportedly took place on Oct 31 this year resulted in the temporary shutdown of a few Government of India (GOI) websites. However, GOI sources in New Delhi made it clear that these websites maintained by NIC (National Informatics Centre) did not contain any classified information. There were also intelligence reports in November, 2011 about the probable compromise of computers of the Eastern Naval Command located in Vishakhapatnam.

It was the shocking Mumbai terror attack mounted by the Pakistan trained terrorists that spurred US Government to announce measures to strengthen its cyber security system. Indeed, US President Barack Obama, citing the use of GPS and net phones in the Mumbai terror attack, described the cyber attack as the “future face of the war.” Obama was clear in his observation, “the terrorists that sowed so much death and destruction in Mumbai relied not only on guns and grenades but also on GPS and phones using voice over the Internet.”

Indeed, both the US political establishment and defence set up are fully well aware of the ground reality that the US$100-billion plus global cyber crime market has emerged as a major headache for the defence forces and security agencies in various parts of the world. For there have been instances of the theft of critical data stored in ostensibly high security systems of the defence establishments of various countries. Even the seemingly all powerful Pentagon has not escaped the bouts of cyber attacks. US intelligence and security sources say that classified data on aircraft, avionics, surveillance technology, satellite communications systems and network security protocols stored in Pentagon information systems have been siphoned off.

In fact, the super intelligent breed of cyber criminals are finding it easy to disrupt the data flow and communications links of the defence forces scattered across a widely dispersed geographical stretch. Moreover, since all the wings of the services are making extensive use of the cyberspace for their coordinated warfare strategy, cyber criminals and terrorist groups are devising novel techniques to break open the security walls put around the data storage systems and communications links of the defence forces. Banks, financial services and public utilities including power supply systems and transportation networks could easily be paralysed by well executed plans of cyber criminals. According to the Boston based Core Security Technologies, cyber criminals could gain access to a “country’s water treatment plants, natural gas pipelines and other critical utilities,” through imaginatively conceived and well executed plans.

Meanwhile, in keeping with the growing threat perception, the US Cyber Command charged with the task of ensuring the security of the networks being operated by US Department of Defense (DOD)and also launching offensive operations in cyber space in pursuit of the national interest, is all poised to be upgraded with an independent status. This elevation would put it on par with its parent organisation, US Strategic Command, which is responsible for US space and nuclear operations. In fact, this development follows the revelations by US intelligence agencies that Chinese cyber hackers are hyper active in so far as penetrating the high security networks of Pentagon containing classified strategic information is concerned. But then the Chinese Government sources in Beijing have consistently been denying the involvement of Beijing in many of the cyber attacks that are said to have their origin in China. “China is totally opposed to various kinds of hacking activities on the internet and we are committed to relevant counter hacking initiatives,” says a spokesman of Chinese External Affairs Ministry.

But it would be wrong to come to the conclusion that China alone is responsible for all the vicious cyber attacks reported from various parts of the world; far from it. For, it is widely perceived that the US in association with Israel had carried out an attack on Iran’s disputed nuclear centrifuge facility though highly malicious Stuxnet malware in 2010. And a section of US officialdom believes that the malware Shamoon that temporarily paralysed the Saudi based Aramco in August this year had its origin in Iran. The attack on Saudi oil firm Armaco has left USA deeply worried. In October this year, the US Defence Secretary, Leon Penetta described the attack on Armaco as the most sophisticated yet launched on a private company. Even as Iran is suspected to be behind this attack, sources in Tehran have denied any involvement in Armaco attack.

Meanwhile, there is a growing body of evidence pointing out to the Chinese hackers focussing on mounting economic espionage and paralysing high security networks of the countries considered inimical to the interest of the mainland China. Against this backdrop, the three day all India executive committee meeting of the 87 years old Rashtriya Swayamsevak Sangh(RSS)held in Chennai in early November 2012 had cautioned against growing threat to India’s security from China based “cyber criminals”. Pointing out that China posed a serious threat to India’s cyber and communications network, the RSS resolution said China is capable of crippling the technological capabilities of even advanced nations such as USA. Against this backdrop, RSS has called for the formulation of a comprehensive national security policy with a particular focus on strengthening cyber safety.

A fact-filled report prepared by McAfee in association with SDA(Security and Defence Agenda), a Brussels based defence and security think tank, ranks India as the fifth most cyber crime affected country. “Much of the vulnerability is explained by the widespread computer illiteracy and easily pirated machines,” points out this report. Making reference to Indian cyber security scenario Cherian Samuel of the New Delhi based think tank Institute for Defence Studies and Analysis ( IDSA) says, “In India, we went straight from no telephones to the latest in mobile technology. It is the same with internet connected computers. They came in all of a sudden and no one was taught even the basic facts about cyber security”. Cyber security experts feel that the main challenge for India now is to train and equip the law enforcement agencies and judiciary particularly outside the big cities like New Delhi, Mumbai and Bangalore.

Low conviction rate of cyber criminals in India is an area of concern in so far as strengthening the cyber security mechanism is concerned. Awareness programmes and educational campaigns need to be stepped up to bring home the importance of cyber security in all its manifestations, say experts. India, which lags behind Western countries in terms of putting in place latest genre tools to ensure cyber safety, is highly vulnerable to the attacks from cyber space for the simple reason that it boasts of more than 120-million active internet users. Further, with the electronic payments making rapid inroads in the country, threat of “economic damages” being inflicted from across the borderless cyber space has assumed serious dimensions. According to Karl Rauscher, Chief Technology Officer of the New York based East West Institute, the explosion of internet connectivity in India could very well become a double edged sword. “Since India is one of the top generators of spam in the world, it is particularly important for the network operators, service providers and government agencies to apply the best practices as applicable,” points out Rauscher. The dark spot of the Indian cyber security scenario is that India’s advances in the area of information technology and software services have not been harnessed to make the information networks in the country impervious to the cyber hacking.

Not surprisingly then there is a growing realization of the magnitude of the threat that India faces from cyber space and the need to ensure the safety of information networks, both civilian and defence. But then to face the cyber threat India would need to come out with a comprehensive and holistic cyber security policy that will be properly coordinated through a nodal authority. It is in the fitness of things that the National Security Council had taken a decision to create a permanent joint working group with the private sector to overcome cyber security challenges. In particular, the abuse and misuse of social media platforms to foment sectarian discontent has been amply illustrated by the panic migration of the North Easterners settled in various parts of the country in the wake of disturbances in Assam. All said and done, international cooperation and coordination is of paramount importance in warding off the threat from cyber space. For India’s cyber security continues to be a matter of grave concern for multinational enterprises and western governments alike.

Against this broad canvas, the Indian defence set up has felt the need for creating a full-fledged and well equipped cyber security command. Recent reports suggest that the three wings of the Indian service are seriously mulling the creation of a cyber command that would draw assets, resources and expertise from all the defence establishment of the country. But as of now, the structural nuances and operational philosophy of an Indian cyber command is far from clear. Whether it would be an independent entity or a part of the larger strategic command, the Indian defence set up should be clear in its vision before it gets green signal for the setting up of the cyber command. Further, the functional aspects of such a command should be articulated in a well defined manner to provide it with the “punch and power” it deserves. One important question that needs to be addressed is whether the Indian cyber command would draw on the expertise available in Indian IT companies and research organisations possessing expertise in the area of information network security.

While the immediate term focus of this proposed cyber command would be on protecting the high security information networks of the Indian defence forces, in the long run it should try to expand its scope to the civilian networks with a view to insulate the country as a whole against the multifarious threats emanating from cyber space. Of course, the Indian cyber command should in unison with the civilian agencies endeavour to protect the information networks and computer systems cutting across the structural jurisdictions. Similarly, the Indian cyber command should have expertise and resources to launch offensive operations. In this context, it could take a leaf out of the experience of the US cyber command.

By all means, the creation of an Indian cyber command should be taken up on a war footing by shunning lethargy and delay typical of the decision making process at the higher echelons of the military bureaucratic structure of the country. Of course, the setting up of the cyber command is just a small step towards the long journey of ensuring the cyber security in India in all its manifestations.

From the security perspective, India cannot remain a silent spectator to the lead China has taken in creating a hackers brigade. For in recent years, China based cyber warriors have become the most persistent source of a variety of cyber attacks experienced by a number of countries including India. Not long back, Chinese hackers are known to have used social networking sites to break into the computer networks of the Indian defence establishment. Among the institutions targeted by the Chinese hackers were the National Security Council Secretariat, 21 Mountain Artillery Brigade based in north eastern sector and Air Forces Station in New Delhi.

What is more, the computer systems being operated by the Indian military colleges were taken over by the elusive Chinese cyber spies. Some of the documents accessed by Chinese cyber warriors are known to have included secret assessments of security situation in north eastern India as well as Maoist uprising in parts of India. Following this, the Indian army directed its officials to keep away from social networking sites including Twitter, Facebook and Orkut. In particular, they have been asked not to post any sensitive and classified information including their posting location.

According to Norton Cyber Crime Report 2012, over 42 million net users in India became victims of cyber crime during 2011-12, suffering approximately US$8-billion in direct financial loss. As per this report, 66% of adults in India have been victims of cyber crime in their lifetime. “Cyber criminals are changing their tactics to target fast growing mobile platforms and social networks where consumers are less aware of security risks,” says Effendy Ibrahim, Internet Safety Advocate and Director, Norton(Asia).  

Monday, July 16, 2012

Naresh Chandra Task Force’s Report on National Security: An Appraisal


Nitin Gokhale
Visiting Fellow, VIF

The high-powered Naresh Chandra Task Force, appointed by the government last year, submitted its detailed report to the Prime Minister a couple of months ago but so far there is no indication that the report will be made public soon. We do not even know if within the government deliberations have begun on the recommendations given by the Task Force.

All that is available in public domain so far is a glimpse of some key recommendations made by the task force that too through media reports obviously based on conversations with some members of the task force. For instance, the task force has apparently recommended:

  1. Appointment of a Permanent Chairman, Chiefs of Staff Committee (CoSC)
  2. Integration of Service HQ and Ministry of Defence by allowing more cross-postings
  3. Shifting focus of India's national security strategy from Pakistan to China
  4. Better Intelligence Coordination between all agencies
  5. Creation of dedicated financial Institution for access to energy, rare earths and raw materials from across the world


From some of the occasional interaction that this author has had with a few members of the Task Force, before and after the submission of the report, one aspect is very clear: There was no consensus on the creation of the post of the Chief of Defence Staff (CDS), leading to, what one believes, a half-hearted recommendation to appoint another four-star officer as permanent chairman of the Chiefs of Staff Committee (CoSC).

According to the Task Force, this officer will be in charge of the two existing tri-services commands-the Strategic Command Force (SFC) and the Andaman Nicobar Command (ANC)-- while the three service Chiefs will continue command and lead their respective services, the Task Force said.

The Permanent Chairman CoSC, according to the recommendation of the Naresh Chandra Task Force, will have a fixed tenure of two years and will be rotated among the three services. This officer will be assisted by the existing Integrated Defence Staff (IDS), headed by a three star officer from any of the three services.

Over the past decade, the IDS has evolved in a barely workable tri-services structure with over 300 officers drawn from the three services trying to function as a cohesive unit tasked with evolving "jointness." On ground however, jointness or inter-operability has remained at best patchy.

The new recommendation seeks to overcome these differences. The Naresh Chandra Task Force has also recommended the creation of a separate Special Operations Command on the lines of the US structure since asymmetric threats are seen as the main challenge to India's national security in coming decades.

The new post, the Task Force is hoping, will also bring in synergy in major acquisitions for all the three forces. Often, the three services have worked independently in procuring same set of equipment, duplicating work and creating separate infrastructure when synergy would have saved hundreds of crores of rupees.

However, critics of the new system say the recommendation to appoint Chairman CoSC is nothing but old wine in new bottle. It is a 'no go' because the Chairman will remain ever dependent on each of the services Army, Navy & IAF for its personnel requirements. Personnel of each service will be 'lobbyists' of respective Chiefs. Yet another opportunity, they say, to reform has been lost. National Security System does not have to depend on seeking Least Common Multiple (LCM)-solutions. It does not have to seek to appease lobbies and turfs.

The solution, some in service officers say, lies in divesting the three Chiefs of operational command of forces. Let them be Chiefs of respective Staff - 'resource providers to joint operational/ strategic commands' - content with recruiting, training of personnel; holding and maintaining equipment; and executing related administrative functions.

Appointment of CDS is however the prerogative of the apex political authority, namely the Cabinet Committee on Security (CCS). It can choose from panel of names forwarded by the three Services. There should be no rotation to appease services. Choice of apex political authority has to be final.

In absence of a common meeting ground on deciding to appoint a CDS, the Naresh Chandra Task Force recommendation can however be utilised in the interim in creating more cohesion among the services. For instance, the Chairman Chiefs of Staff Committee, who will have a fixed two year tenure can be made in charge of making net assessment about the strengths and weaknesses of India’s adversaries—China and Pakistan—in a holistic manner, taking into consideration inputs from all the three services and cross-referencing those inputs with other agencies like the Defence Intelligence Agency (DIA) and RAW. Currently, the three services send their individual assessments just to complete formalities to the IDS where it remains buried in files that never see the light of the day.

Moreover, if the Chairman Chiefs of Staff Committee is going to lead the proposed Special Operations Command why not create two more tri-services commands and give him some more work?

Given the frequency of cyber-attacks on India's IT infrastructure, creation of a cyber-command is only a matter of time. An aerospace command is inevitable sooner than later. Along with the creation of the proposed Special Operations Command, why not create these two additional tri-service commands? And let the Army, Air Force and Navy be the lead service for a particular command? And let the Army, Air Force and Navy be the lead service for a particular command?

The proposed Chairman Chiefs of Staff Committee can remain the head of these three commands with each of them being led by an Army Commander level officer. Given the experience and expertise available with the Army, it can take charge of the Special Operations Command, the IAF, with its domain knowledge, can take over the aerospace command and the Navy can lead the cyber command. The heads of these commands can have their second rung manned by two-star officers from each of the services so that they continue to have the benefit of expert advice from across the services but the overall responsibility must remain with the designated service.

Given that the existing tri-services commands go through painful changes each time their Commanders-in-Chief get rotated, making each of the service responsible for the proposed new commands will make their the working smoother and more efficient.

Over a decade after a CDS was recommended by the Group of Ministers (GoM) in the wake of the Kargil conflict, there is no unanimity on that issue yet. Given the strong differences within the services as well as in the political class, could this be the best arrangement for now? Or is it too impractical?

To find the right answers the government perhaps owes it to the people of India to make the Naresh Chandra Task Force report public and let a healthy debate ensue.