Showing posts with label cyber warfare. Show all posts
Showing posts with label cyber warfare. Show all posts

Tuesday, April 29, 2014

Cyber Warfare in the Indian Context

Lt Gen (Retd) Gautam Banerjee, 
Executive Council, VIF

The Cyber Space

The contemporary era is characterised by what has been described as the ‘information revolution’. This is a phenomenon in which automated processes are activated to marshal and manipulate huge volumes of digitised information as relevant to every field of human endeavours before disseminating that information across a virtually unlimited realm. As human societies across the entire globe as well as the systems governing these become entirely captive to usage of information assets, effective harness of information infrastructure in military engagements too becomes an undeniable obligation.

Information infrastructure is a chain of high-technology systems made up of sensors, transmission media, data processors, information centres and competent personnel to man these, all of which are coupled to form a most effective regulating medium for all global activities. However, the soul of this infrastructure rests in the all pervasive electronic time-space continuum. Described as ‘cyber-space’, this is the arena in which all exactions of societal progress, peace, stability - and war, of course – must be played out. Cyber-space, therefore, is central to the information infrastructure.

Just as it is in case of all other arenas of competitive engagement – land, sea, air, space and perception - the native instinct of usurpation of other’s resources has made it obligatory to protect one’s usage of cyber-space against corruption, subversion and neutralisation by adversarial powers, or even friendly competitors. When this obligation is sought to be fulfilled in the realm of military operations, the concept of Cyber Warfare crystallises. In principle, the term ‘Cyber Warfare’ should be usable only in military context and differentiated from the term ‘Cyber Security’, the latter term being better reserved for civilian information security functions. This distinction is necessary to avoid intrusion of conceptual ambiguities into the nation’s civilian and military security strategies.

The subject matter being vast, in this paper it is proposed to focus the discussion to the basic framework which dictates the terms of engagement in Cyber Warfare.

Information Warfare

Military security of a nation is cultivated by preparing for, or activating if necessary, such extreme inflictions that make the adversary desist from his unbearable animosity. In the nation’s military security functions, the profound role performed by information infrastructure makes it a key military objective, to be nurtured or neutralised as the case may be. Thus, the activities undertaken to gain ‘Information Superiority’ over the adversary through recourse to various kinds of military operations are termed as ‘Information Warfare’. Notably, while the ‘hard’ objects of information infrastructure may be attacked or protected by physical - active and passive - means, the ‘virtual reality’ of cyber-space needs sophisticated science and high-technology to tackle. Thus, within the overall ambit of Information Warfare, when military operations are carried out in the domain of cyber-space, the term used is ‘Cyber Warfare’. It is, however, important to note that while the adversary may be disabled by Cyber Warfare, he may not yet be induced to submit; whereas Information Warfare, when prosecuted, could achieve that purpose.

Measures applied to engage in Information Warfare are classified under two categories, namely, ‘Information Operations – Offensive’ and ‘Information Operations – Defensive’. These conventions help in delineating the military aspects of the information era.

Information Operations

Information Operations in either mode – Offensive and Defensive – are by convention classified under the following descriptions:-
  • Command and Control Warfare (C2W): Attacking adversary’s ability to generate and communicate commands to its forces is termed as C2W. It is directed at the adversary’s Defence Information Infrastructure.
  • Intelligence Based Warfare (IBW): It is the integration of sensors, processors and data-links to achieve profound and near-real time surveillance, reconnaissance, decision support, target selection and engagement, and finally, damage assessment.
  • Electronic Warfare (EW): Combat in the electromagnetic medium to achieve enhancement, degradation, interruption or corruption of radiating wave emissions is classified as EW. In other words, it implies domination of the electro-magnetic spectrum.
  • Psy Warfare: This is aimed at targeting the adversary's mental orientation and perception, and thereby influence his intention. In a larger context, it may be aimed at demoralising the hostile population.
  • Hacker Warfare: This is defined as destruction, degradation or exploitation of adversary’s computer data-base. Intrusion into adversary’s systems by ‘virus’, ‘worm’, ‘trojan horse’, logic bomb’ etc. is the mode adopted in this case.
  • Infrastructural or Economic Warfare. This involves ‘information blockade’ and ‘information hegemony’ to garner undue economic advantage. Under warlike conditions, its extreme manifestation may lead to attacks on the adversary’s core infrastructure – railways, power, oil sectors, for example.
It is needless to emphasise that the last three kinds of warfare are liable to transcend into the civilian domain.

Cyber Warfare

To reiterate, Information Warfare is resorted to gain Information Superiority by the means of Information Operations which are executed in Offensive as well as Defensive modes. There are many operating fields of Information Operations, such as human intervention, passive and active protection, weaponised attack, sabotage etc. which are executed in the physical domain. Similarly, the electro-magnetic spectrum becomes the battle field for Electronic Warfare. Lastly, when Information Operations are executed in the cyber domain, the term applicable is Cyber Warfare.

Cyber Warfare involves targeting the adversary’s military networks to induce collapse or corruption of his information-based Command, Control, Communication, Co-ordination, Intelligence and Inter-operable Systems (C4I2). Point to note is that the scope of hostilities are liable to transcend into the civil sector too, when the focus would be on the adversary’s societal perception and his national administrative and economic infrastructure.

Cyber Warfare is therefore one of the ‘military operations of war’. In the Indian context, it may be used as a purely military term and prosecuted in the manner of a military operation in the same spirit of extreme measures just as it is in the case of conventional, sub-conventional, manoeuvre or positional, mine and nuclear warfare.

Objectives of Cyber Warfare

The purpose of Cyber Warfare is to undertake defensive and offensive Information Operations in the cyber-space to degrade the adversary’s sensory, early warning, data analysis, intelligence exchange, decision support, and command, control and communication network – the entire system of military net-centricity in short - while at the same time protecting own information assets from hostile intrusion. In offensive operations, that goal is achieved by intrusion into the adversary’s vast volumes of digitised information that circulate in the cyber-space. Notably however, in defensive mode, besides adoption of general security measures, the effort cannot be so much in locking up own volumes of information simply because in the cyber domain that is impractical to achieve. The effort therefore is to identify the algorithms and processes of the adversary’s offensive Information Operations and neutralise these through corresponding counter-offensive measures - preferably proactive.

Objective of Cyber Warfare therefore is to gain information superiority in the aspects of surveillance and reconnaissance, data analysis, intelligence exchange, command and control of battle elements and flow of communication, and thereby protect own net-centric systems while disrupting that of the adversary.

Science of Cyber Warfare

Automated exploitation of information in the cyber-space covers the entire gamut of communication, computation and transmission net-works. In Cyber Warfare, the process of extracting information from vast array of data, converting these into intelligence and then deriving tactical inferences to support decision making is a highly complex matter. Even if humans naturally do so remarkably well, there are limitation of volume and speed that they can handle. Here science comes to the rescue, to define and quantify information, analyse input-data and facilitate decision making.

The matter of the science of Cyber Warfare is vast. It would therefore suffice here to just mention the core aspects of mathematical analyses which help in identification, selection and targeting in the cyber-space. This process is carried out through algorithms based on mathematical logic and digitised models, and involves the following defensive-offensive steps in continuum:-

  • Sensor based detection of presence, identification and tracking of cyber-entities (e.g. personnel and equipment, radiation pattern, etc.) by the process of search and intrusion of the cyber-space. This involves mathematical derivation of ‘inductive’ and ‘deductive’ logic to select relevant signatures or data-input.
  • Determination of inter-relationships and activities (e.g. data-mining, computation, data-transfer etc.) of the targeted cyber-entities. Comparison and templating with help of ‘data ware-house’ and ‘data-fusion’ is resorted to chart the adversary’s possible options thus. Application of information theories to sift through the data, identification of the target cyber-space and inference of intelligence are carried out through processes known as ‘abduction’ and ‘deduction’ of information.
  • Inference of plausible objectives of the adversary (e.g. dissemination of intelligence, command or engagement instructions etc.) through activation of the cyber-entities. This is accomplished by means of ‘indicator-data analysis’
    of the detected cyber-hierarchy and the deployment pattern of the cyber-entities. ‘Decision theories’ are applied to analyse and evaluate the alternatives.
  • Determination of the likely courses of Cyber Warfare, reactive or proactive, available to the adversary. This is a technical appreciation, assisted by automated military logic.
  • Assessment of own possible Cyber Warfare options and objectives. This too is a process of technical appreciation, duly narrowed down by pre-loaded military logic. The assessment is contingent upon right evaluation of the utility of intelligence and its exploitation in effective conduct of Cyber Warfare.
  • Decision support, passage of orders and monitoring of Cyber Warfare, and feedback. This may include automated target fixation, selection of the mode and method of Cyber Warfare, media selection, generation of engagement and manoeuvre instructions and fixation of the parameters of time and space (e.g. activation of sensors and other cyber-entities, followed by passage of orders).
The point to note is that Information Technology is the creator of cyber-space and also the core resource in the conduct of Cyber Warfare. Obviously therefore, it is also the most lucrative target of Information Warfare, cyber-attack included.

Features of Cyber Warfare

Having seen that it is impractical to establish any clear distinction between the conduct of offensive and defensive Cyber Warfare, it would suffice here to touch upon the mutually shared qualifying features. Accordingly, an overview of the likely ‘approaches’, ‘targets’ and ‘points’ of Cyber Attack may be in order.

Approaches of Cyber Attack: The approaches that could be adopted to carryout Cyber Attacks could be as follows:-
  • Direct or Penetration Attack: This involves penetration into adversary’s communication links, computer net work or data-base to steal or compromise internal information in favour of the attacker.
  • Indirect or Sensor or Media Attack: Insertion of false inputs into the adversary’s observation sensors or sources to achieve counter-information will be the objective of attack in this case.
  • Hybrid Attack: This will be a combination of the above mentioned two types of attacks – a most likely approach.
  • Cryptographic Attack: This involves one-time intrusion to locate vulnerabilities in the adversary’s system of cryptography, for manipulation when time comes. This aim is achieved by breaking the ‘key programme’ which is the heart of the system’s security.
  • Net Exploitation: This is an extension of ‘NETINT’ (Network Intelligence) aimed at compromising or corrupting the adversary’s information network. Introduction of malicious software executing agents, data scanners, ‘Radio Frequency Interception’ through wire tapping or remote 'sniffing', and software tools to carryout synchronised attack upon multiple cyber-entities are the means to do so.
Targets of Cyber Attack: Unlike other forms of attack, in Cyber Warfare, there is no scope of achieving any residual consolation from ‘near-hits’. Therefore, whatever be the approach adopted, a Cyber Attack has to be focused on a specific target. These targets could be:-
  • Content Attack: In this case, content of the information is targeted for disruption or denial with the purpose of misleading the adversary’s decision making process.
  • Dislocating Attack: In this form of attack, the location of data or its route for access is targeted to cause confusion, delay or corruption of information.
  • Temporal Attack: Here, either the retrieval of information is delayed till it is too late or a pre-conceived notion is reinforced well ahead of the actual event. This way the timeliness of information is subjected to disruption, thus diverting the adversary’s process of decision making.
Cyber Attack Points: Data or network level Cyber Attacks may be directed at any of the following vulnerable points:-
  • The adversary’s input sources or reporting links, by means of electronic warfare, irrational visuals and deception. The other option is to alter the orientation and focus of input sensors by steering away the control mechanism.
  • The process of object identification or tracking may be truncated by placement of hostile radiators.
  • The adversary’s sensor behaviour may be put through analysis to infer his focus of information query, and so gain insight of his objective.
  • Degradation or deception of the adversary’s deductive process may be achieved through network interference devices.
  • The adversary’s system design may be stolen, so as to acquire the capability of accessing his data base. This facilitates launching of Cyber Attack as and when necessary.
Imperatives of Cyber Defence

It is seen that when it comes to planning and execution of Cyber Warfare, there is little to distinguish between attack and defence. The fact is that foolproof Cyber Defence is difficult to achieve even after committing enormous resources unless it incorporates the ingredients of Cyber Attack. Even then, in the prosecution of Cyber Warfare, there are certain defensive obligations to be adopted. These, in brief, are:-
  • Warning mechanism for impending Cyber Attack, to trigger security drills including the automated response for safety or shut down.
  • Retrieval of corrupted, diverted, destroyed or captured assets - such as primary, secondary and tertiary data, the operating protocols, automated processes, etc.
  • Restoration of the compromised cyber driven systems - fiscal, transportation, power, industrial, technological and societal programmes, for example.
It will be noticed that only the first of the three responses has any room for retaliatory action, the rest being in-house measures. This limitation reinforces the fact that in the Cyber Warfare, defence comes a cropper unless its execution is facilitated by pre-planned intrusions into the adversary’s Cyber War establishment.

Conclusion

Being a relatively new form, it is important to develop indigenous postulations, concepts and practices of Cyber Warfare in the Indian context. This paper suggests that the term ‘Cyber Warfare’ be usable in the context of military operations, as distinct from the overarching scheme of ‘Cyber Security’ at the national level. It also posits that when prosecuted under the overall ambit of Information Operations, Cyber Warfare is predominant in offensive content and may be conducted from space, earth and cyber-space. Further, it implies that: firstly, continuous engagement in Information Operation during peace keeps the system fully updated and promotes experimentation and the spirit of innovations; and secondly, readiness for instant engagement is an imperative of Cyber Warfare.

It is also reiterated that most of the principles and activities associated with Cyber Warfare are applicable, with certain reorientations, to the civil information infrastructure too. Indeed, since the state of war engulfs the entire nation, targeting the adversary’s quasi-military and civil infrastructure to disrupt his national functioning may be an ultimate objective of Cyber Warfare. It is therefore absolutely necessary to adopt similar mechanisms for the sanctity of the nation’s civil infrastructure, and so foster a regime of ‘Cyber Security’ at the national level.

“The wise man does at once what the fool does finally” – Niccolo Machiavelli.

References
  1. “Information Warfare: Concept and Development”, 21st Century Army: Strategies for Future, Lt Gen (Retd) Gautam Banerjee, Manas Publications, New Delhi, 2012.
  2. Waltz, Edward, “Information Warfare Principles and Operations” : ARTECH House, London, 1998.
  3. Fialka, JJ, “War by Other Means”, New York: WW Norton, 1997.
  4. David and Katherine Hollis, “The Cyberspace Policies We Need”, Armed Forces Journal, USA, 2010.
  5. “Stray Voltage: War in Information Age”, WM Hall, Naval Institute Press, USA, 2003.
  6. http://www.vifindia.org/article/2014/february/07/dimensions-of-cyber-sec....

Published Date: 28th April 2014, Image source: http://economictimes.indiatimes.com

Monday, February 10, 2014

Dimensions of Cyber Security in India

Lt Gen (Retd) Gautam Banerjee, 
Executive Council, VIF

Preamble

This is the information age and therefore like all lucrative assets of the past ages, information assets must be an object of competition and conflict – and in extreme cases, warfare. This conflict is being played out in a new domain: the cyber-space. With increasing dependency on the cyber domain for every aspect of human endeavours, it is obvious that like all national assets, India’s cyber-space has to be secured against all forms of espionage, subversion, sabotage and attack.

In this article, it is proposed to discuss the theology of cyber security and the fundamental considerations that might lead to its effective implementation in the Indian context.

Civil and Military Functions of Cyber Security

There are five domains in which the civil as well as military functions of national security have to be performed, viz, land, sea, air, space and cyber- space. In reference to the last named, it is a common supposition that there is singular convergence of civil and military functions. The misconception is reflected in the use of undefined terminologies and loose semantics which lead to confusing juxtaposition of concepts that govern the issue of cyber security. Factually though, the said convergence is no more prominent than it is in the context of civil-military interplay in all of the other domains of inter-state competition and conflict. In order to make the best use of our resources in achieving a fair degree of cyber security therefore, it is important to promote clarity and consistency in ruling definitions and concepts in the Indian context.

We understand that every nation nurtures its own set of specific aspirations in consonance with a given set of geo-political, social and natural assets. These aspirations go to define the path for national prosperity which are then sought to be protected by the triumvirate of national power, viz, socio-political, economic and military security. The first two of these aspects of security are civil functions whereas the third takes recourse to warfare to perform its role. The distinction to note here is that the civil functions of socio-political and economic security of a nation is bound by inter-state ideological differences, geo-political adversities, competition for resources and business rivalries - all aimed at extracting more and more self-advantages. This is a continuous process. Military security, on the other hand, is an extreme step that is performed as a last resort to force the adversary to desist from his unbearable animosity either by threatening to, or by actually inflicting physical punishment on him. For the intervening periods of no-war, the purpose of the military institution is to prepare for that extreme eventuality called ‘war’. This distinction between the civil and military functions of national security influences the domain of the cyber-space just as it does in others domains of competition and conflict; it has universal applicability.

Appreciation of the afore-stated distinction is more relevant in the Indian context. This is so because in the Indian dispensation, military power is not seen as a fulcrum of nationhood as it is in the case of America or China and a host of other countries. Recognition of the distinction would obviate emergence of discrepancies between the civil and military functions that is caused by use of undefined phraseology like ‘cyber security’, ‘cyber-attack’, ‘cyber warfare’ etc.; our cyber policies must clearly convey as to what is intended to be accomplished.

Cyber Security and Cyber Warfare

In general, civil functions of national security involve fierce inter-state machinations that are marred by economic usurpation, industrial espionage, technology denial, geo-political ganging etc. – all carried out under a façade of civility. These machinations, vicious as these may be, are yet not described as ‘warfare’ simply because there is no element of force-imposition here. In the civil domain therefore, cyber-intrusions, disablers, corrupters, theft, sabotage etc., and the counter-measures against these, may not be termed as cyber warfare. Conversely, ‘cyber warfare’ is a military function and its prosecution is but a military operation, to be conducted in the spirit of extreme measures - just as it is in the case of conventional, sub-conventional or nuclear warfare. Notably however, when it comes to cyber security skills and resources, there is near-total commonality between the civil and military domains. In view of these subtle-yet-salient distinctions, formal apportionment between the civil functions of ‘cyber security’ from its military counterpart, ‘cyber warfare’, is obligatory to obviate emergence of policy irrationalities.

Civil Functions of Cyber Security

Civil functions over the cyber-space have four denominators :-
  • Public Services (health, education, civil-supplies, social security schemes, essential services),
  • Financial Services (banking, subsidy funding),
  • Industry (manufacturing, service sector, R&D, trade),
  • Governance (policy, procedure, statistics, survey, records, administration).
The burden of cyber security is driven by inter-state political and ideological differences, competition for resources including ‘knowledge’ itself, business rivalries and even terrorism. Accordingly, civil functions of cyber security aim at securing the cyber-space in a manner as to prevent inimical acts of the following kinds :-
  • Sabotage of ‘National Information Infrastructure’ (NII) through intrusion into electro-magnetic spectrum,
  • Inducing collapse, corruption or diversion of the nation’s Information Technology (IT) driven public service, administrative, economic, technical and industrial infrastructure.
  • Psychological subversion of the society to manipulate public opinion.
Cyber-threat in civil domain may emanate from foreign or domestic sources, both adversarial or friendly. These sources could be state intelligence agencies, economic and technological competitors, foreign military establishments as part of their war preparedness, and lastly, rogue non-state elements perpetrating acts of cyber-terrorism. The threats are characterised as follows:-
  • Paralysis of cyber intensive systems at the national level to freeze the adversary’s ability to function unencumbered.
  • The saboteur may not be easily identifiable. Even if identified, the perpetrator’s system architecture may be difficult to decipher, thus hampering effective counter-action.
  • Once triggered, even the perpetrator will not be able to control the intended degree of paralysing effects upon the adversary, neither is it possible to contain the damage from affecting unintended parties. To that extent cyber-sabotage is like terrorism.
  • It would be banal to expect a nation to submit to launch, or the threat of launch, of cyber-sabotage. Therefore, it is not a civil deterrence like economic sanction, technology denial etc.
  • Dependence on global cyber-assets like the Internet, GPS, digital information, satellite images etc. has some advantages too. Due to its world-wide connectivity, cyber-sabotage on one party would also cause collateral damages to the cyber-assets of unintended public and private sectors at the global arena – and that imposes caution upon the saboteurs.
Notably, in the matter of cyber security, only a thin line separates the passive and defensive measures with the active and offensive ones. Therefore, there must be a strong pro-active as well as reactive element of offensive built into the civil functions of cyber security. However, in instituting these measures, the problems of role-overlap and mix-up of organisations would arise. It would therefore be necessary to formally define the civil functions of cyber security activities to distinguish these from their more intense and destructive military counterpart, and so obviate defocus and redundancy. This end could be met through promulgation of a comprehensive ‘National Cyber Security Protocol’ (NCSP), a part of which may remain confidential.

Cyber Security Mechanisms

Considering India’s policy orientations, protection of the cyber-space from manipulations and intrusions from inimical parties would mostly be sought to be achieved through passive measures; execution of pro-active disabling actions seems to be rather farfetched in our context. Accordingly, the civil functions of cyber security in our context would involve the following mechanisms:-
  • Warning and response to cyber-attacks,
  • Retrieval of cyber-assets – primary, secondary and tertiary data, protocols and processes, and,
  • Restoration of the compromised cyber driven systems – economic, industrial, technological, societal systems.
It will be noticed that first of the three mechanisms involves adoption of pre-emptive and retaliatory counter-measures. The problem, however, is that in the cyber domain, defensive actions come the cropper unless coupled with pre-planned, debilitating cyber-intrusions. Therefore, notwithstanding any reluctance over policy endorsement, the mechanism must have an element of pro-active offensive to be able to warn and respond to an impending cyber-attack. The other two mechanisms are skill, process and resource intensive in nature. Obviously, all three mechanisms have to be operative at full gear at all times.
For judicious and overarching control over these complex and widespread mechanisms, India will have to go beyond just promulgating rhetorical cyber security policies. Indeed, formal enunciation of an elaborate NCSP would meet that end. Further, to implement and control the NCSP, it would be sensible to construct an organisation, duly empowered in terms of authority over policy direction, coordination, legal scrutiny and enforcement across the public as well as private sectors.

Cyber Warfare in the Military Domain

In the military domain, operations that are undertaken to gain information superiority fall under the ambit of ‘Information Warfare’ (IW). Within that ambit, offensive and defensive ‘Information Operations’ (IO) are waged by means of weaponised intervention, electronic warfare etc., ‘cyber warfare’ being one such mean that is prosecuted in the cyber-space. Cyber warfare therefore is truly a ‘military operations of war’, to be conducted as an element of offensive and defensive IO, and waged in the same spirit of ultimate measures. It is distinguished by predominance of offensive content and is to be prosecuted through military-dedicated IT-based satellites, data warehouses, maps, communication net-works, GPS, UAV, AWACs, PGM etc. However, while civil functions are to be operational at all times, the military function during peace-time is to prepare and test continuously, letting go at war-time to disable the opponent’s military, quasi-military and civil infrastructure. Herein lies the distinction between the civil and military functions of cyber security. Conversely, there are many commonalities between the two functions with respect to the above discussed civil cyber security mechanisms as well as the software skills, hardware and processes.

Objectives of Cyber Warfare

The purpose of cyber warfare is to degrade the adversary’s surveillance, reconnaissance, command, control, communication and intelligence systems through cyber-attacks on his operational nerve centres. These are ‘disabling’ attacks which must be complemented with ‘disorienting’ attacks which are aimed at registration of false information to the enemy and make him 'see' non-existent battle groups, missiles, bridges, etc, thus inducing him into irrelevant committal of his forces. The combined result is expected to lead to disruption and dislocation of the enemy’s orchestration for war.
As an element of IO in defensive as well as offensive modes, cyber warfare would focus upon the following aspects: -
  • Command and Control Warfare (C2W): The objective is to attack the adversary’s ability to generate and communicate commands to its forces and disable or corrupt his Defence Information Infrastructure (DII).
  • Intelligence Based Warfare (IBW): It is the integration of sensors, processors and data-links to achieve efficient reconnaissance, surveillance, target acquisition, target engagement and finally, damage assessment.
  • Electronic Warfare (EW): Communication as well as non-communication combat to achieve degradation, disorientation, interruption and corruption of the adversary’s electro-magnetic emissions is classified as EW. In other words, it implies domination of electro-magnetic spectrum.
  • Psychological Warfare: This is aimed at targeting the adversary's mental orientation and perception, and thereby influence his intent.
  • Hacker Warfare: This is defined as destruction, degradation or corruption of adversary’s computer data-base and automated decision support and executive processes.
  • Infrastructural Warfare: Under the civil functions, this involves ‘information blockade’ and ‘information imperialism’ to derive political and economic advantage. Under warlike conditions, its extreme manifestation leads to attacks on the adversary’s primary infrastructure – railways, power plants, oil sector etc. for example.
The Regime of Cyber Security

Most advanced countries have instituted robust mechanisms to protect their cyber domain. In this respect, USA enjoys overwhelming superiority even if she takes care to keep her elaborate activities under wraps. Besides passive measures, she secures her cyber-space by technology driven barrage of highly complex cyber-intrusions and backs it up with deliberate enticement of cyber-attacks from adversaries and friends alike to break into their algorithm. To do so, civil and military functions of cyber security are seamlessly enmeshed to produce the best results, cyber- attacks like ‘Gauss’, ‘Stuxnet’, ‘Duqu’, ‘Flame’ etc. being a few known ones. China, on the other hand, depends upon her innovative mass of cyber operatives, reportedly two million strong, to support her cyber security regime, much of which is committed on internal surveillance and the rest being devoted to intrusive hacking. The score for the European nations stands even despite many reported hacking attacks from China and Russia, not to speak of their all-weather ally, the US. In any case, not being at the centre-stage of global circus, the European stakes are mainly limited to economic cyber-assets.

India is a novice in comparison, even if there have been some tentative attempts made to venture into the realm of cyber security. These attempts are however, more or less confined just to work-station access-denials, blocks against hacking and back-up storage. Whereas the private sector has taken few baby-steps to maintain a facade of security of its IT-based assets, the state, nonplussed as it seems to be in the matter, is not motivated enough to proceed beyond promulgating a policy-outline that cries out for more serious substance. Of course, certain laudable efforts have been made in the Government’s intelligence set up and the ‘Department of Electronics and Information Technology’, but these are individual rather than institutional initiatives, and therefore confined just to specific bands of the threat-spectrum.

A Structure for Cyber Security

Having discussed the functions of civil cyber security and military cyber warfare and the differences as well as commonalities between the two, it becomes apparent that: One, there would have to be a substantial degree of congruence of resources and efforts in protecting the Indian cyber-space; and Two, when it comes to prosecution of cyber warfare, it would have to be a purely military venture. Thus appears the necessity for an apex body to coordinate these primary and secondary functions at the national level. Accordingly, we may conclude the discussion with a brief look at some of the measures that might afford the desired level of protection to the indigenous cyber-space. These measures could be:-
  • Establishment of a ‘National Cyber Regulatory, Control and Security Authority’ (NCRCSA), to coordinate between the civil NCSP and the military ‘Cyber Warfare’. Incorporation of a ‘Cyber Research Department’ would also be necessary.
  • Regulation, coordination and strengthening of the civilian cyber activities of the ‘National Information Centre’, ‘National Crisis Management Centre’, ‘National Cyber Response Centre’, ‘National Information Infrastructure Protection Centre’, ‘Computer Emergency Response Teams’, NDMA, NTRO, Department of IT, DOT, MHA, MoD and the private sector under the aegis of the proposed NCRCSA. The responsibility and wherewithal for cyber security is too diffused at present to be able to prevent cyber-attack, and respond to it quickly and effectively.
  • ‘Cyber Command’ may be formed to plan and prepare prosecution of Cyber Warfare across the service barriers, and in coordination with the national level authority. A ‘Cyber Warfare Research Establishment’ must form part of this Command. NCSP and Cyber Warfare must be permanent and continuously performing commitments, with permanent set ups and flexible recruitment and training rules, and as stated, function under the overarching management of the proposed NCRCSA.
Conclusion


The stage when creation of cyber-assets becomes contingent upon its robust protection has arrived in India. It is time therefore to accord high priority to cyber security even if it means some compromise with proliferation of the nation’s cyber domain. The foremost consideration in seeking that end is that if our cyber security has to remain inviolable, the security measures have to be tailored to Indian conditions and devised by native genius. This consideration further reinforces the cause of formal apportionment of roles and responsibilities between the civil and military functions of cyber security.

Tuesday, November 20, 2012

Special Laws to Counter Terrorism in India: A Reality Check


Dr N Manoharan 
(Senior Fellow, VIF)

A National Convention held recently in New Delhi on ‘Politics of Terror’ has brought to focus the need to re-look into provisions of special laws that are currently in use to counter terrorism.

When confronted with armed militancy, democracies face what is known as “democratic dilemma”. On the one hand, they have to protect the territorial integrity, sovereignty and security of their people from the arbitrary violence by militants; if they fail, their authority and credibility are undermined. On the other hand, in the process of combating militancy, if they slip into repression and authoritarianism, they end-up alienating the population and lose legitimacy. To maintain the equilibrium, use of legal framework, otherwise called as ‘criminal justice model’, is therefore suggested.
The use of special/security laws is justified on the grounds that the existing criminal laws are not adequate to deal with the militancy that is “well-armed, far more dangerous and modernised”. Since what is at stake is not just law and order but the very existence of state and society, there is a need to have special laws with far higher deterrence value. Introduction of special laws are also justified citing prevailing international environment and obligations as in the case of POTA after 9/11 attack and UN Resolution 1373.
India has long tradition of special/security laws dating back to its pre-independence years. These laws have been enacted, repealed and re-enacted periodically since independence. Such special laws fall under four categories:

  1. Exclusive laws against terrorism like POTA.
  2. Security forces empowerment laws that give immunity and additional special powers to the security forces like the Armed Forces Special Powers Act.
  3. Laws of proscription that criminalises terrorist groups and a range of undesirable activities like the Unlawful Activities Prevention Act (UAPA).
  4. Other exclusive laws on control of finances, money laundering, drug-trafficking, cyber warfare and so on.
However, how far these extra-ordinary laws have been successful in preventing, deterring and correcting militants and, in turn, enhance security? The answer is mixed. Some of the main reasons for the ineffectiveness of special laws are as follows:
  • Over-reaction to the threat posed and far more drastic measures than necessary. .
  • Hasty enactment without giving much room for public debate or judicial scrutiny. .
  • Overly broad and ambiguous definitions of terrorism and penal provisions that fail to satisfy the principle of legality.
  • Pretrial investigation and detention procedures that infringe upon due process and personal liberty. And the number of cases that finally end in convictions is low. .
  • Lack of sufficient oversight mechanisms. .
  • Space to settle political scores. .
  • Weak witness protection provisions. .
  • The provision of the use of special courts attracting undue political interference in the judicial process and maximises potential bias.
Yet, this does not mean that special laws are totally redundant. They serve the purpose if all the above identified issues are addressed. What is required is not “a new law for every new crime” but fewer and effective laws. The guiding principle should be, as William Ewart Gladstone observed, “Good laws make it easier to do right and harder to do wrong.” An ideal legal framework should comprise three elements – prevention, deterrence, and rehabilitation – in right proportion. Presently, Indian special laws are biased towards ‘deterrence’. The proportion depends on the character of the militancy and the environment in which it is taking place. One size does not fit all. The frame work should not fail to take into account human rights concerns. There have to be proper safeguards against any misuse/abuse. To put in simple terms, as Lydia Maria Child observed, “Law is not law, if it violates the principles of eternal justice.” There has to be clear cut definitions of crimes and penal provisions to avoid excessive discretionary powers. Enactment of special laws should not be in haste; for greater awareness and acceptance, the process has to be transparent and should be subject to public debate and judicial scrutiny.

What is also required is political consensus on the issue at two levels: at the national level among all parties and between the Center and its federal units. Special laws should possess review mechanisms and ‘sun-set’ clauses for periodic assessments. “The law must be stable, but it must not stand still.” Reforms in criminal justice system – investigation, prosecution and adjudication – are the need of the hour. Role of civil society is vital in moderating the role of special laws in counter-terrorism. Media, especially, has to understand the aspect of legal framework rightly, avoid sensationalism, educate people, and at the same time support the government of the day in its fight against terrorism.

Thursday, July 26, 2012

Preparing for Cyberwar - A National Perspective


Commander Mukesh Saini (Retd.)

On November 12th, 2011 Maj. Gen. Moghaddam, the "architect" of Iran's missile program, was showing a new type of warhead for nuclear weapon capable missile Sejil 2, to a group of experts for their comments, at a site about 50 Kms from Tehran. Warhead was connected to computer for simulation which was being watched on a big screen. And instead of simulation the actual warhead went off pulverising the site. Explosion was so powerful that it could be heard in Tehran. Initially Iranian government refused to accept that there was any such explosion however later conceded that in the explosion 17 officers of Revolutionary Guards have lost lives (though 36 funerals took place). Explosion was so powerful that no one was alive to narrate the incident and nothing was left at the site to provide evidence. Revolutionary Guards (IRGC) investigation pointed at two probabilities; (a) infiltration by a Mossad operative or (b) computer controlling the missile was infected with Stuxnet (like) worm. The second probability was considered much more likely after two well-known cyber infiltrations using Stuxnet and Duqu to stall Iran’s nuclear ambition. Probably this incident is historic as for the first time cyber weapon was used to cause real world explosion or kinetic attack. (Israel Insider, 2011)

Introduction

Cyberspace has changed many old concepts. In this globalised world everyone is neighbour of other. There is no established concept of boundaries. Identification of targets and what is under threat or need to be attacked in case of Cyberwar is important to segregate the facet of Cyberwar from wars using other form of attacks on ground, air and as Sea. What needs to be secured is what needs protection. Therefore definition of Cyber security will give fair idea about the scope of Cyberwar and its targets. The Information Technology Act 2000 (India) defines Cyber Security which means protecting information, equipment, devices computer, computer resource, communication device and information stored therein from unauthorized access, use, disclosure, disruption, modification or destruction. Richard A. Clark in his book Cyber War defines "cyberwarfare" as "actions by a nation-state to penetrate another nation's computers or networks for the purposes of causing damage or disruption. However things are not as simplistic and materialist but a game of mind and perception also.

To understand the real meaning of Cyberwar, it is necessary to understand the meaning of War and its import on governance and diplomacy. The British Parliamentary Committee in its report after Iraq war noted that “War” is a term that has both popular and legal connotations. Colloquially, “war” embraces conflicts between the armed forces of states and, occasionally, major internal conflicts such as the British or American Civil wars. “War” as a legal institution is a feature of both international and national law. In international law, the distinguishing characteristic of “war” is the legal equality of the belligerents and the special status of those states not taking part in the conflict (“neutral” states). The condition of “war” could be brought about by a declaration of war but one was not necessary (nor, where there was a declaration of war, were hostilities inevitable). Additionally, states could choose to regard a conflict between them as “war” and apply the legal rules accordingly, or neutrals could insist on respect for their rights. “War” as an institution of domestic law did require a declaration, made in the Monarch’s name but by the Prime Minister, acting under the prerogative. This action triggered domestic consequences—nationals of the opponent state became “enemy aliens”, liable to measures of restraint including detention. Property of enemy aliens was liable to seizure. Statute provided for emergency measures—for the call up of troops, the sequestration of property and so on. (Constitution, 27 July 2006)

To fit this definition of War the only Operation Orchard fits the bill were Air Defence System of Syria was made ineffective by Israel during their attack on alleged nuclear plant of Syria. In all other cases be it cyber-attack on Estonia, Georgia or Operations Titan Rain, Night Dragon Shady Rats etc may not be termed as the acts of war. The case of explosion at Iran’s missile site lacks affirmation and evidence.

War has International Ramifications

Various international laws and treaties especially of Paris and also Charter of United Nations prohibit use of threat or use of force in international relations. Prior to these developments post 1945, declaration of war was a standard practice, but today no one officially declares war to the international community. This is nothing but just masking because internally a nation state has to declare war, whether limited in scope or a full-fledged war. This is necessary to activate appropriate structures; authorisation to force commanders to use Rules of Engagement (R.o.E) for ‘conflict’; activate provisions of War-Book; freezing of assets of enemy aliens; mobilisation of resources; suspension of local laws against the enlisted personnel engaged in war; and even enforcing ‘Emergency’ in the country. Thus a war whether declared or otherwise is a ‘structured-response’ to a conflict which is expected to result in subjugating the enemy to the will of a nation.

National Information Security Policy & Doctrine of Cyberwar

It is necessary to define what would constitute an “attack” serious enough to precipitate into military counter offensive. It is necessary to define this line in an open stated policy, so that in case of any military retaliation, the international community can be with India. However defining this Lakshman Rekha is not easy. If the threshold is kept too law then breaches will be norm and finding exception where counter offensive becomes necessary in a transparent manner would be difficult. If the threshold is kept too high then nation can be bled by thousand wounds rather than massive attack and no formal retaliatory force can be used.

Another challenge is attribution. Cyber-attack may appear to be originated from one or multiple countries but actual culprit may be a third country. Recently in April 2012, National Informatics Centre has told the press that some unknown third country has used its servers to attack other countries including China. (Joseph, 2011) This statement had two immediate adverse effects on our cyber war preparedness, firstly it has exposed our vulnerabilities that we do not have sufficient capacity to identify originating country despite servers and logs are under our control and secondly it has provided a perfect alibi to our enemies to attack us and deny ownership of such attacks. Can we now blame China for attacks on Indian cyberspace?

Thus attribution is critical for appropriate response. In fact noting this fact, Annual Report 2011-2012 by Intelligence and Senator Committee of UK has termed cyber attack as a ‘Tier One threat to UK and has direct to government to inter-alia develop capabilities of cyber-attack without detection ( or at least without attribution). The UK government has been allocation of funds equivalent to Rs. 5720 Crores over next 3 years for National Cyber Security Program to prepare for cyber-attack. The committee has also advised the intelligence agencies to not to use such technologies against own citizens except with specific approval. (Intelligence and Security Committee, UK, 2012)
In 2005, after 2 years of extensive deliberations between 21 ministry/departments of the government and industry confederations, National Information Board under NSA Sh. JN Dixit had approved the draft National Information Security Policy (NISP), it is yet to be approved by the government. In the mean while Department of Electronics & IT drafted another NISP (apparently without wider consultation) and sought public opinion in 2011. Nothing has been heard of new NISP since then. Due to this intervening period on this front we moved from leader to laggard. Without such policy defining Information Warfare Doctrine for nation (not a doctrine by Armed forces) will be distant dream. Therefore to fight as well defend against future cyber-attacks, it is paramount that a good quality and well consulted over-arching NISP is finalized and formally declared. And based on this IW Doctrine for India (inclusive of Intelligence Services as well as private sector) be developed.

Amendment to National War book

Once as a policy India declares the existence of cyber war and its contours, and also develop cyber war doctrine, the war book required to be amended accordingly. The role and responsibility required to analyze and articulated to prevent confusion and fratricide at the time of war. It is also essential for efficient and effective conduct of war including cyber-war. The war book therefore needs to specify as how to maintain no-contact cyber war and when the government decide to go for full-contact or partial-contact war then how cyber war will be integrated to meet overall war objectives. The war is the only place which mandates the change in command and control structure and transfer of certain powers to military. It is the war-book which will clarify the intra-government relationship and any failure to do so can lead to turf war and chaos at the time of crisis.

Rule of Engagement

The offensive Cyber operations by the enemy will be swift and paralyzing. Therefore central control of conduct of cyber war may not be the good idea. It is necessary to define as unambiguously as possible Rule of Engagement for cyber warriors (whether uniformed or militia). Uncontrolled offensive can not only hurt in retaliatory fire against unplanned defensive measures but also can isolate us in community of nations. The role of diplomatic cadre can therefore never to be underestimated in events leading up to full scale cyber war. The National Internet Exchange (NIXI) is up and running to defend our intra-India Internet in case of worst situation, isolation but poor defensive mechanism, lack of capacity can paralyze us and can cause loss of our will to fight back. Therefore it is necessary to coordinate not only with in the government and armed forces but also with private sector as well as patriotic hackers outside the government and RoE for everyone should be articulated. While preparing RoE the issues highlighted in following paragraphs must be addressed.

According to RoE of most of the Armed Forces of the world, Line of Communication and nodes which directly or indirectly supports military operations of belligerent nations are valid military targets. By this Rule of Engagement all telecommunication and internet service providers are legitimate targets during any Cyber war. However when the Hague rule (1923) of Air warfare article 24(2) was prepared the dependency of life of masses on communication structures was not as heavy as it is today. Not even at the time when in 1956 New Delhi Draft rules were prepared, which clearly established that “The objectives belonging to the following categories are those considered to be of generally recognized military importance: ... (7) The installations of broadcasting and television stations; telephone and telegraph exchanges of fundamental military importance.” there was no Internet. Now technically it is possible to mount unbearable misery on masses through attacking on Critical Information Infrastructure. The question is that if such an attack is undertaken, will it amount to war-crime?

While dealing with IHL /LOAC, the British Parliamentary Committee felt, “The situation is different, however, in the case of breaches of IHL. The Minister of State for the armed forces told us that “once a conflict actually begins, whatever the legal basis for this participation, it is conduct by all participants as required by the body of law in rules known as the International Humanitarian Law. The four Geneva Conventions of 1949 are a part of that IHL. The United Kingdom is also bound by a number of other conventions and protocols, such as the first additional protocol to the Geneva Conventions ... Those are not our laws. We apply them. Those have been defined elsewhere and we simply live within them, so to speak”. Mr. Ingram added that “all of our personnel are so trained in understanding the basis upon which they are having to conduct themselves in a conflict situation and it is very much part of the whole training process”. Individuals (and in some cases their commanders) suspected of violations of IHL such as killing prisoners of war, the ill-treatment of detainees in occupied territory or the use of prohibited weapons must be considered for prosecution in national courts. The Government has said, in the context of the ICC, that all allegations of this kind would be stringently investigated and, where appropriate, criminal proceedings instigated. This duty, which mainly derives from the Geneva Conventions, has gained in importance following the United Kingdom’s acceptance of the Statute of the ICC. The prosecution of those alleged to be responsible for serious violations of IHL is within the jurisdiction of the ICC, but only where the proceedings in national law have been unsatisfactory or non-existent. The Government’s position has been that there will never be prosecutions against British servicemen before the ICC because there always will be adequate national investigations, followed, where required, by prosecutions. (Constitution, 27 July 2006)

Need for Coordination and Control

The cyber-attack on Iran in form of Stuxnet, Duqu and Flamer are just peek into the future. US President has repeatedly stated that cyber-attacks are most serious economic and national security challenge that America faces. To meet this challenge US has introduced Cyber security Act 2012 in Senate on 20th July 2012. (BBC, 2012). US conducts exercise ‘Cyber Strom’ every alternate year. NATO, Australia and many European countries undertake extensive cyber security exercises to improve command, control and coordination. A formal Cyber command and control structures have been established in most of the first world countries and China.

Unlike military war, the non-state actors such as terrorist organization, large corporate houses, hacktivist, cyber privateer and cyber insurgents have capacity and will to take on nation states. Wikileaks, Anon, Luzesec were some of the non-state players who have challenged the might on nations including the United States of America. Large organizations such as Intel, Microsoft, Huawei, etc can also play role to support their respective government. In case of ‘Flamer’ virus original Microsoft Digital Signature was misused. (Adhikari, 2012; Adhikari, 2012).

It is myth that hackers will win or lose the cyber war. Hackers (with due respect) are just foot soldiers, and wars are fought by General who are visionary, know their forces, understand enemy forces as well as mind of their commander, can coordinate with other wings of the government and first of all finest leader who draws respect from his soldiers (Hackers).

In India we are yet to formally recognize the dangers, not because it is not so recognized in the power circle but just because it is so recognized as one of the most powerful tool that everyone wants to play the lead role and turf war has broken out. Institute of Defence Studies and Analyses has attempted to give some course correction to this rudderless situation through its recently released book ‘India’s Cyber Security Challenges’. (IDSA, 2012; IDSA Task Force, March 2012) However overall paralysis is continuing and well planned structure such as CERT-IN, NTRO and NSCS are being consistently undermined. It is therefore necessary the National Information Board (a board of score of secretary ranked officer) be resuscitated and board meeting be held at least every quarter till things stabilise and we as nation become competent to defend our cyberspace.

Role of Defence Forces

Role of defence forces in case of Cyber war is limited. They are required to protect only its own domain and at the most government domain such as .gov.in, .mil.gov.in, army.in etc. But if this control is not practiced in peace time same cannot be undertaken in war time. In fact probably intelligence agencies and CERTs are better positioned to take on such tasks. However IHL and LOAC neither cover nor envisaged to cover the activities of Intelligence agencies. Similarly for offensive operations, intelligence agencies that had undertaken surveillance of enemy networks and probably placed backdoors and spybots in the target network may be more suitable for offensive action. For example if National Security Agency of US have deployed the launch pads of cyber weapons then NSA alone will be in better position to arm and launch cyber weapons from these pads. In case of Duqu probably some intelligence agency was controlling the Command & Control centres of Duqu. Non applicability of IHL / LOAC on such agencies is a glaring flaw in scheme of things for containing any Cyberwar. And also launching Cyberwar on other nation without adequately protecting own cyberspace will be similar to MAD (Mutually Assured Destruction / Disruption) of nuclear war.

Cyberwar also challenges some of the basic tenet of armed conflict. What is use of fighting personnel to wear uniform when the opposing forces are not going to be physically present in front of each other? How would belligerent forces know that attacking party is enlisted or a civilian? Suppose all major data of one of the belligerent nations are encrypted and made unusable, will the data which may be very vital for the survival of the population amount to prisoner-of-war? If collision of train takes place due to intentional malfunctioning of signalling system leading to death of masses, will it amount to War Crime?

Conclusion

War is serious matter which involves lives of all citizens. Even if external declaration of war has become redundant, this is required internally to divert resources for fighting the war. When war get (internally) declared there are changes in organisational structure of governance; War Book comes into force; Rules of Engagement changes; financial allocation made; civilian criminal laws stand suspended for actions taken in pursuance of war; and National Emergency may be declared. These are too profound changes which cannot be taken lightly. Therefore every cyber-attack does not amount to cyber war. Involvement of defence forces along with enlisting of hackers and allocation of cyber-targets for proper coordination is required. The international treaties and conventions such as IHL and LOAC come into force. Wars are not limited to action on ground but diplomatic struggle also begins. Non-state actors have the ability to stand winnable chance against a nation state. Therefore it recommended that Cyberwar be looked at with all seriousness and following steps should be take-up in double quick time to prepare our nation for Cyberwar:

a. Declare National Information Security Policy after wide consultation with all stake holders. Such policy should be as much as possible technology neutral, overarching and long lasting;

b. Evolve Cyber warfare doctrine and develop capacity to implement such doctrine;

c. Modify National War-Book to include this new form of war and its peculiar characteristics such as no-contact war and role of non-actors;

d. Define Rule-of-engagement for Cyberwar to prevent unintended escalation of war and unintended Human Rights violations;

e. Establish command and control structures for efficient and effective conduct of Cyberwar and prevent turf war within during the period of crisis.

f. And to do all this and much more, National Information Board should meet at frequent interval; else Cabinet Committee on Security should find an alternative.

Bibliography

Adhikari, R., 2012. Flame Singes Microsoft Security Certificates. [Online]
Available at: http://www.technewsworld.com/story/75289.html [Accessed 20 June 2012].

BBC, 2012. News Technology. [Online]
Available at: http://www.bbc.co.uk/news/technology-18928854 [Accessed 21 July 2012].

Constitution, S. C. o. t., 27 July 2006. Waging war: Parliament's role and responsibility Volume I: Report,London: HOUSE OF LORDS.
Hague Convention V, 18 October 1907. Hague Convention V. [Online]
Available athttp://avalon.law.yale.edu/20th century/hague05.asp [Accessed 05 May 2012].

IDSA Task Force, March 2012. India's Cyber Security Challenges, New Delhi: Institute of Defence Studies and Aanlysis. IDSA, 2012. India's Cyber Security Challenge. First ed. New Delhi: IDSA.

Intel Technology Brief , 2011. Protect Laptops and Data with Intel® Anti-Theft Technology. [Online] Available at: http://www.intel.com/technology/anti-theft/anti-theft-tech-brief.pdf [Accessed 24 May 2012].

Intelligence and Security Commitee, UK, 2012. Annual Report 2011-2012, London: Controller of Her Majesty's Stationery Office.
Israel Insider, 2011. Suspicion in Iran that Stuxnet caused Revolutionary Guards base explosions. [Online]

Joseph, J., 2011. Govt servers used for cyber attacks on China, other countries' networks. [Online] Available at: http://timesofindia.indiatimes.com/tech/news/internet/Govt-servers-used-for-cyber- attacks-on-China-other-countries-networks/articleshow/10760699.cms [Accessed 24 July 2012].

Quintin, K. J. a. A., 18 November 2011. The Internet in Bello: Cyber War Law, Ethics & Policy. Berkeley, UC Berkeley School of Law.