Showing posts with label information warfare. Show all posts
Showing posts with label information warfare. Show all posts

Tuesday, April 29, 2014

Cyber Warfare in the Indian Context

Lt Gen (Retd) Gautam Banerjee, 
Executive Council, VIF

The Cyber Space

The contemporary era is characterised by what has been described as the ‘information revolution’. This is a phenomenon in which automated processes are activated to marshal and manipulate huge volumes of digitised information as relevant to every field of human endeavours before disseminating that information across a virtually unlimited realm. As human societies across the entire globe as well as the systems governing these become entirely captive to usage of information assets, effective harness of information infrastructure in military engagements too becomes an undeniable obligation.

Information infrastructure is a chain of high-technology systems made up of sensors, transmission media, data processors, information centres and competent personnel to man these, all of which are coupled to form a most effective regulating medium for all global activities. However, the soul of this infrastructure rests in the all pervasive electronic time-space continuum. Described as ‘cyber-space’, this is the arena in which all exactions of societal progress, peace, stability - and war, of course – must be played out. Cyber-space, therefore, is central to the information infrastructure.

Just as it is in case of all other arenas of competitive engagement – land, sea, air, space and perception - the native instinct of usurpation of other’s resources has made it obligatory to protect one’s usage of cyber-space against corruption, subversion and neutralisation by adversarial powers, or even friendly competitors. When this obligation is sought to be fulfilled in the realm of military operations, the concept of Cyber Warfare crystallises. In principle, the term ‘Cyber Warfare’ should be usable only in military context and differentiated from the term ‘Cyber Security’, the latter term being better reserved for civilian information security functions. This distinction is necessary to avoid intrusion of conceptual ambiguities into the nation’s civilian and military security strategies.

The subject matter being vast, in this paper it is proposed to focus the discussion to the basic framework which dictates the terms of engagement in Cyber Warfare.

Information Warfare

Military security of a nation is cultivated by preparing for, or activating if necessary, such extreme inflictions that make the adversary desist from his unbearable animosity. In the nation’s military security functions, the profound role performed by information infrastructure makes it a key military objective, to be nurtured or neutralised as the case may be. Thus, the activities undertaken to gain ‘Information Superiority’ over the adversary through recourse to various kinds of military operations are termed as ‘Information Warfare’. Notably, while the ‘hard’ objects of information infrastructure may be attacked or protected by physical - active and passive - means, the ‘virtual reality’ of cyber-space needs sophisticated science and high-technology to tackle. Thus, within the overall ambit of Information Warfare, when military operations are carried out in the domain of cyber-space, the term used is ‘Cyber Warfare’. It is, however, important to note that while the adversary may be disabled by Cyber Warfare, he may not yet be induced to submit; whereas Information Warfare, when prosecuted, could achieve that purpose.

Measures applied to engage in Information Warfare are classified under two categories, namely, ‘Information Operations – Offensive’ and ‘Information Operations – Defensive’. These conventions help in delineating the military aspects of the information era.

Information Operations

Information Operations in either mode – Offensive and Defensive – are by convention classified under the following descriptions:-
  • Command and Control Warfare (C2W): Attacking adversary’s ability to generate and communicate commands to its forces is termed as C2W. It is directed at the adversary’s Defence Information Infrastructure.
  • Intelligence Based Warfare (IBW): It is the integration of sensors, processors and data-links to achieve profound and near-real time surveillance, reconnaissance, decision support, target selection and engagement, and finally, damage assessment.
  • Electronic Warfare (EW): Combat in the electromagnetic medium to achieve enhancement, degradation, interruption or corruption of radiating wave emissions is classified as EW. In other words, it implies domination of the electro-magnetic spectrum.
  • Psy Warfare: This is aimed at targeting the adversary's mental orientation and perception, and thereby influence his intention. In a larger context, it may be aimed at demoralising the hostile population.
  • Hacker Warfare: This is defined as destruction, degradation or exploitation of adversary’s computer data-base. Intrusion into adversary’s systems by ‘virus’, ‘worm’, ‘trojan horse’, logic bomb’ etc. is the mode adopted in this case.
  • Infrastructural or Economic Warfare. This involves ‘information blockade’ and ‘information hegemony’ to garner undue economic advantage. Under warlike conditions, its extreme manifestation may lead to attacks on the adversary’s core infrastructure – railways, power, oil sectors, for example.
It is needless to emphasise that the last three kinds of warfare are liable to transcend into the civilian domain.

Cyber Warfare

To reiterate, Information Warfare is resorted to gain Information Superiority by the means of Information Operations which are executed in Offensive as well as Defensive modes. There are many operating fields of Information Operations, such as human intervention, passive and active protection, weaponised attack, sabotage etc. which are executed in the physical domain. Similarly, the electro-magnetic spectrum becomes the battle field for Electronic Warfare. Lastly, when Information Operations are executed in the cyber domain, the term applicable is Cyber Warfare.

Cyber Warfare involves targeting the adversary’s military networks to induce collapse or corruption of his information-based Command, Control, Communication, Co-ordination, Intelligence and Inter-operable Systems (C4I2). Point to note is that the scope of hostilities are liable to transcend into the civil sector too, when the focus would be on the adversary’s societal perception and his national administrative and economic infrastructure.

Cyber Warfare is therefore one of the ‘military operations of war’. In the Indian context, it may be used as a purely military term and prosecuted in the manner of a military operation in the same spirit of extreme measures just as it is in the case of conventional, sub-conventional, manoeuvre or positional, mine and nuclear warfare.

Objectives of Cyber Warfare

The purpose of Cyber Warfare is to undertake defensive and offensive Information Operations in the cyber-space to degrade the adversary’s sensory, early warning, data analysis, intelligence exchange, decision support, and command, control and communication network – the entire system of military net-centricity in short - while at the same time protecting own information assets from hostile intrusion. In offensive operations, that goal is achieved by intrusion into the adversary’s vast volumes of digitised information that circulate in the cyber-space. Notably however, in defensive mode, besides adoption of general security measures, the effort cannot be so much in locking up own volumes of information simply because in the cyber domain that is impractical to achieve. The effort therefore is to identify the algorithms and processes of the adversary’s offensive Information Operations and neutralise these through corresponding counter-offensive measures - preferably proactive.

Objective of Cyber Warfare therefore is to gain information superiority in the aspects of surveillance and reconnaissance, data analysis, intelligence exchange, command and control of battle elements and flow of communication, and thereby protect own net-centric systems while disrupting that of the adversary.

Science of Cyber Warfare

Automated exploitation of information in the cyber-space covers the entire gamut of communication, computation and transmission net-works. In Cyber Warfare, the process of extracting information from vast array of data, converting these into intelligence and then deriving tactical inferences to support decision making is a highly complex matter. Even if humans naturally do so remarkably well, there are limitation of volume and speed that they can handle. Here science comes to the rescue, to define and quantify information, analyse input-data and facilitate decision making.

The matter of the science of Cyber Warfare is vast. It would therefore suffice here to just mention the core aspects of mathematical analyses which help in identification, selection and targeting in the cyber-space. This process is carried out through algorithms based on mathematical logic and digitised models, and involves the following defensive-offensive steps in continuum:-

  • Sensor based detection of presence, identification and tracking of cyber-entities (e.g. personnel and equipment, radiation pattern, etc.) by the process of search and intrusion of the cyber-space. This involves mathematical derivation of ‘inductive’ and ‘deductive’ logic to select relevant signatures or data-input.
  • Determination of inter-relationships and activities (e.g. data-mining, computation, data-transfer etc.) of the targeted cyber-entities. Comparison and templating with help of ‘data ware-house’ and ‘data-fusion’ is resorted to chart the adversary’s possible options thus. Application of information theories to sift through the data, identification of the target cyber-space and inference of intelligence are carried out through processes known as ‘abduction’ and ‘deduction’ of information.
  • Inference of plausible objectives of the adversary (e.g. dissemination of intelligence, command or engagement instructions etc.) through activation of the cyber-entities. This is accomplished by means of ‘indicator-data analysis’
    of the detected cyber-hierarchy and the deployment pattern of the cyber-entities. ‘Decision theories’ are applied to analyse and evaluate the alternatives.
  • Determination of the likely courses of Cyber Warfare, reactive or proactive, available to the adversary. This is a technical appreciation, assisted by automated military logic.
  • Assessment of own possible Cyber Warfare options and objectives. This too is a process of technical appreciation, duly narrowed down by pre-loaded military logic. The assessment is contingent upon right evaluation of the utility of intelligence and its exploitation in effective conduct of Cyber Warfare.
  • Decision support, passage of orders and monitoring of Cyber Warfare, and feedback. This may include automated target fixation, selection of the mode and method of Cyber Warfare, media selection, generation of engagement and manoeuvre instructions and fixation of the parameters of time and space (e.g. activation of sensors and other cyber-entities, followed by passage of orders).
The point to note is that Information Technology is the creator of cyber-space and also the core resource in the conduct of Cyber Warfare. Obviously therefore, it is also the most lucrative target of Information Warfare, cyber-attack included.

Features of Cyber Warfare

Having seen that it is impractical to establish any clear distinction between the conduct of offensive and defensive Cyber Warfare, it would suffice here to touch upon the mutually shared qualifying features. Accordingly, an overview of the likely ‘approaches’, ‘targets’ and ‘points’ of Cyber Attack may be in order.

Approaches of Cyber Attack: The approaches that could be adopted to carryout Cyber Attacks could be as follows:-
  • Direct or Penetration Attack: This involves penetration into adversary’s communication links, computer net work or data-base to steal or compromise internal information in favour of the attacker.
  • Indirect or Sensor or Media Attack: Insertion of false inputs into the adversary’s observation sensors or sources to achieve counter-information will be the objective of attack in this case.
  • Hybrid Attack: This will be a combination of the above mentioned two types of attacks – a most likely approach.
  • Cryptographic Attack: This involves one-time intrusion to locate vulnerabilities in the adversary’s system of cryptography, for manipulation when time comes. This aim is achieved by breaking the ‘key programme’ which is the heart of the system’s security.
  • Net Exploitation: This is an extension of ‘NETINT’ (Network Intelligence) aimed at compromising or corrupting the adversary’s information network. Introduction of malicious software executing agents, data scanners, ‘Radio Frequency Interception’ through wire tapping or remote 'sniffing', and software tools to carryout synchronised attack upon multiple cyber-entities are the means to do so.
Targets of Cyber Attack: Unlike other forms of attack, in Cyber Warfare, there is no scope of achieving any residual consolation from ‘near-hits’. Therefore, whatever be the approach adopted, a Cyber Attack has to be focused on a specific target. These targets could be:-
  • Content Attack: In this case, content of the information is targeted for disruption or denial with the purpose of misleading the adversary’s decision making process.
  • Dislocating Attack: In this form of attack, the location of data or its route for access is targeted to cause confusion, delay or corruption of information.
  • Temporal Attack: Here, either the retrieval of information is delayed till it is too late or a pre-conceived notion is reinforced well ahead of the actual event. This way the timeliness of information is subjected to disruption, thus diverting the adversary’s process of decision making.
Cyber Attack Points: Data or network level Cyber Attacks may be directed at any of the following vulnerable points:-
  • The adversary’s input sources or reporting links, by means of electronic warfare, irrational visuals and deception. The other option is to alter the orientation and focus of input sensors by steering away the control mechanism.
  • The process of object identification or tracking may be truncated by placement of hostile radiators.
  • The adversary’s sensor behaviour may be put through analysis to infer his focus of information query, and so gain insight of his objective.
  • Degradation or deception of the adversary’s deductive process may be achieved through network interference devices.
  • The adversary’s system design may be stolen, so as to acquire the capability of accessing his data base. This facilitates launching of Cyber Attack as and when necessary.
Imperatives of Cyber Defence

It is seen that when it comes to planning and execution of Cyber Warfare, there is little to distinguish between attack and defence. The fact is that foolproof Cyber Defence is difficult to achieve even after committing enormous resources unless it incorporates the ingredients of Cyber Attack. Even then, in the prosecution of Cyber Warfare, there are certain defensive obligations to be adopted. These, in brief, are:-
  • Warning mechanism for impending Cyber Attack, to trigger security drills including the automated response for safety or shut down.
  • Retrieval of corrupted, diverted, destroyed or captured assets - such as primary, secondary and tertiary data, the operating protocols, automated processes, etc.
  • Restoration of the compromised cyber driven systems - fiscal, transportation, power, industrial, technological and societal programmes, for example.
It will be noticed that only the first of the three responses has any room for retaliatory action, the rest being in-house measures. This limitation reinforces the fact that in the Cyber Warfare, defence comes a cropper unless its execution is facilitated by pre-planned intrusions into the adversary’s Cyber War establishment.

Conclusion

Being a relatively new form, it is important to develop indigenous postulations, concepts and practices of Cyber Warfare in the Indian context. This paper suggests that the term ‘Cyber Warfare’ be usable in the context of military operations, as distinct from the overarching scheme of ‘Cyber Security’ at the national level. It also posits that when prosecuted under the overall ambit of Information Operations, Cyber Warfare is predominant in offensive content and may be conducted from space, earth and cyber-space. Further, it implies that: firstly, continuous engagement in Information Operation during peace keeps the system fully updated and promotes experimentation and the spirit of innovations; and secondly, readiness for instant engagement is an imperative of Cyber Warfare.

It is also reiterated that most of the principles and activities associated with Cyber Warfare are applicable, with certain reorientations, to the civil information infrastructure too. Indeed, since the state of war engulfs the entire nation, targeting the adversary’s quasi-military and civil infrastructure to disrupt his national functioning may be an ultimate objective of Cyber Warfare. It is therefore absolutely necessary to adopt similar mechanisms for the sanctity of the nation’s civil infrastructure, and so foster a regime of ‘Cyber Security’ at the national level.

“The wise man does at once what the fool does finally” – Niccolo Machiavelli.

References
  1. “Information Warfare: Concept and Development”, 21st Century Army: Strategies for Future, Lt Gen (Retd) Gautam Banerjee, Manas Publications, New Delhi, 2012.
  2. Waltz, Edward, “Information Warfare Principles and Operations” : ARTECH House, London, 1998.
  3. Fialka, JJ, “War by Other Means”, New York: WW Norton, 1997.
  4. David and Katherine Hollis, “The Cyberspace Policies We Need”, Armed Forces Journal, USA, 2010.
  5. “Stray Voltage: War in Information Age”, WM Hall, Naval Institute Press, USA, 2003.
  6. http://www.vifindia.org/article/2014/february/07/dimensions-of-cyber-sec....

Published Date: 28th April 2014, Image source: http://economictimes.indiatimes.com

Tuesday, April 22, 2014

PLA’s Information Warfare Capabilities on an Upward Trajectory Printer-friendly version

Brig (Retd) Vinod Anand, 
Senior Fellow, VIF

In end February this year, Chinese President Xi Jinping formed a new working group at the apex level on cyber security and information security. While this was seen as the political leadership’s renewed efforts in underlining the threats and challenges to the national security in this arena, the military leadership has been paying particular attention to information warfare (IW) challenges since early 1990s. According to People’s Liberation Army (PLA) concepts, the term information warfare encompasses cyber warfare, electronic warfare, deception warfare, psychological warfare, computer warfare, and transcends beyond the military realm.

The PLA has been adapting Western concepts to suit local conditions and considers it as a ‘driving force in PLA’s military combat readinesses. PLA has used the construct of People’s War and devised its own precepts of ‘Peoples War in IW domain’ where millions of Chinese, both civilians and soldiers armed with computers, could achieve the objectives of IW. That is what has been precisely happening since over the last one decade wherein a number of cyber/information attacks are known to have originated from China with India being one among many other countries being at the receiving end. In last few years, Indian government’s computers including those of National Security Council and some other important offices have been hacked with all evidence pointing towards China. PLA’s information warriors and hacker groups have been actively involved in virus warfare and hacking activities in countries of their interest.

PLA has intensified its efforts in IW field since it officially pronounced its military doctrine of ‘Local War under the conditions of informationalisation’ in its 2004 White Paper on Defence. The objective laid down was to build an informationalised force and to win an information war and push forward the revolution in military affairs with Chinese characteristics with ‘informationalisation’ at its core. Since the articulation of its current military doctrine, PLA has laid solid foundations for fighting information and cyber wars. According to PLA’s precepts, before any physical operations take place it would be the information and cyber domains that would be used to cripple the adversary’s capabilities.

PLA’s expanding capabilities in the use of space for military purposes provides it with the means to enhance its command and control, intelligence, surveillance, reconnaissance, information and cyber warfare capabilities. Space is considered as a commanding height for enabling the battlefield information operations. PLA’s strategists have also stressed on the imperatives and necessity of ‘destroying, damaging and interfering’ with an enemy’s reconnaissance and communications satellite systems. No country other than China has plans of launching almost 100 satellites till 2015. Compared to China, India’s plans for launching satellites are very modest; in fact in the last 37 years, India has launched 100 missions. Such endeavours when fully realized would add to China’s counter-space and IW capabilities.

PLA has also vastly expanded its optical fiber and other terrestrial networks giving it a tremendous IW capability. At the national level, China has a C3I system based on fiber optic cables, satellite communications, micro-wave links and automated command and control systems. The PLA has both secured and non-secured telecommunications and has an army wide data communication network and integrated field operations communication system which has been strengthened in the last decade. Many joint exercises carried out by PLA show that its WAN capabilities within Chinese borders have improved. PLA has been carrying out military exercises in Lanzhou and Chengdu Military Regions (which include the entire Sino-Indian border) where the PLA has practiced joint and integrated operations that include ‘information operations’.

According to Pentagon’s Annual Report to Congress on China’s Military and Security Developments of 2013, PLA’s Information Operations (IO) have matured and the top priority in peacetime is given to Computer Network Defence. As mentioned above, not only the IO/IW should be used even before the start of the campaign it would continue in all phases of war. Pre-emption also rhymes well with PLA’s doctrine of active defence where counter attack can be used to gain advantage even before the commencement of hostilities. Chinese military theorists also believe that if an information campaign is won then the need for military operations may not be necessary. Such a contingency may arise possibly with nations (like the U.S.) which are information dependent.

But that is no solace for India as both military and civil arena in our country is increasingly becoming dependent on information and information networks and systems. Our critical infrastructure dependent on a wide variety of information systems remains vulnerable to information attacks. Stuxnet attack on Iranian nuclear facility did make India reflect on its vulnerabilities in the field of critical infrastructure. It has also been reported that even though the target of Stuxnet was Iran, Kaspersky Lab experts’ data indicates that in fact it was India that was the epicenter of Stuxnet activity thus raising questions about its implications and motives of the originator. Some analysts aver that the largest power outage in Indian history (of July 2012) which affected more than half of India was caused by the malicious ware of Stuxnet.

One also needs to take note of the theories and concepts articulated by two senior colonels of PLA in their book ‘Unrestricted Warfare’ where they opine that there would be no boundaries between military and non-military areas of warfare in future.

The levels of integration between the civilian and military efforts of PRC in all the fields of information and cyber warfare have been on the rise. The top political and military leadership of China is thoroughly seized with the significance of acquiring information and cyber warfare capabilities. The concept of Computer Network Operations (CNO) and Integrated Network Electronic Warfare is germane to their doctrine of IW. PLA’s Third and Fourth Departments of General Staff have been made responsible for executing CNO. While the Third Department has been tasked to collect intelligence and carry out defensive operations, the Fourth Department has the responsibility for network attacks and other offensive IW operations.

China’s defence budget (as also the internal security budget) has witnessed a double digit growth (in percentage terms) every year for over a decade. According to one study, the Chinese government actively funds IW related research in commercial IT companies and civil and military universities. The number of universities conducting such research is put around 50 which indicates the importance and priority given to security related aspects of information technologies. Further, China’s commercial IT companies involved in R & D actively seek collaboration with foreign firms to obtain cutting edge technologies which have dual use and therefore, in the end, benefit the PLA also. In certain cases, the civil use is only nominal and routing the research and development through the civil entities is undertaken as a matter of expediency. Such a subterfuge also helps in lowering the costs for the PLA. As is well known, China’s official defence budget is said to be much less than the actual one.

In fact, in January this year, Chinese telecom equipment companies Huwaei was accused of hacking into Bharat Sanchar Nigam Limited (BSNL)’s network and sabotaging its expansion plans in Rajahmundry in coastal Andhra Pradesh. A five-member team comprising senior officials from the National Security Council Secretariat, Intelligence Bureau, Ministry of Home Affairs and BSNL was formed to investigate the issue. Even a US Congressional report highlights the security threat posed by the Chinese companies like Huwaei and ZTE.

In conclusion, security threats and challenges to India in information warfare domain that includes cyberspace cannot be overemphasized. The Indian armed forces have promulgated a joint Information warfare doctrine and a tri-service Cyber Command is in the process of being established. Some efforts by the government have also been made in the shape of establishing a Computer Emergency Response Team and formulation of a National Cyber Security Policy-2013. However, what is needed of integrating the efforts of a number of ministries and stakeholders in this field. Allotment of additional funds for R & D and supporting such activities in educational institutions and universities is an imperative. Creating of space assets that support the information and cyber warfare efforts is also an imperative.


Information deterrence is equally important as a conventional military deterrence or even nuclear deterrence (which in turn is dependent upon a robust information capability). If critical infrastructure of a nation like banking, power industry, and railway or air communication networks are crippled, then there may be no need for a war. The nation would stand defeated as depicted by the Chinese military writers

Monday, July 2, 2012

China’s Cyberwar Doctrine: Implications for India

Gurmeet Kanwal
Visiting Fellow, VIF

In alarming front page news reports published by several Indian newspapers in 2009 and 2010, Chinese cyber spies were reported to have hacked into computers and stolen documents from hundreds of government and private offices around the world, including those of the National Security Adviser and the Indian embassy in the US. Earlier it had been reported that the Chinese army uses more than 10,000 cyber warriors with degrees in information technology to maintain an e-vigil over China’s borders. “Chinese soldiers now swipe cards and work on laptops as they monitor the border with great efficiency… electronic sentinels functioning 24 hours a day.” This number will soon go up to one million laptop warriors.

While information about the People’s Liberation Army’s (PLA) cyber warriors has begun to appear in the public domain only recently, PLA watchers across the world have known for long about China’s well conceived doctrine on information operations and cyberwar. China’s cyberwar doctrine is designed to level the playing field in a future war with better equipped Western armed forces that rely on Revolution in Military Affairs (RMA) technologies and enjoy immense superiority in terms of weapons platforms and intelligence, surveillance and reconnaissance (ISR) and command and control networks.
Early in the first decade of the new century, China’s Central Military Commission (CMC) had called for a detailed study of the concept of “people’s war under conditions of informationisation”, implying increasing attention to the application of information technology to the conduct of conventional conflict. Since then the scope of the cyber war doctrine has been expanded to develop the capabilities necessary to take control of all the major networks that drive the world’s economic engines such as banking, stock exchanges and telecommunications if it becomes necessary.

Analysts of the People’s Liberation Army (PLA) have called the ongoing Revolution in Military Affairs (RMA) an informationised military revolution with Chinese characteristics. Informationisation relates to the PLA’s ability to adopt information technologies to command, intelligence, training and weapon systems. The PLA is seeking to contest the information battle space with its space-based, airborne, naval and ground-based surveillance and intelligence gathering systems and its new anti-satellite, anti-radar, electronic warfare and information warfare systems. According to China’s White Paper on National Defence issued in 2004, “In its modernisation drive, the PLA takes informationalisation as its orientation and strategic focus.”

The denial of information, strategic deception and the achievement of psychological surprise have for long been an integral part of Chinese military doctrine. The Chinese find information warfare (IW) extremely attractive as they view it as an asymmetric tool that will enable them to overcome their relative backwardness in military hardware. The Chinese are devoting considerable time and energy to perfecting the techniques of IW to target the rapidly modernizing Western armed forces that are becoming increasingly more dependent on the software that runs computer networks and modern communications. In Chinese thinking, IW presents a level playing field for projecting power and prevailing upon the adversary in future wars.

Information warfare includes intelligence operations; command and control operations to disrupt enemy information flow; electronic warfare by seizing the electromagnetic initiative through electronic attack, electronic protection and electronic warfare support; targeting enemy computer systems and networks to damage and destroy critical machines and networks and the data stored on them; and, the physical destruction of enemy information infrastructure through the application of kinetic firepower. The Chinese call their pursuit of information warfare and other hi-tech means to counter the overwhelmingly superior conventional military capabilities of the Western Alliance “acupuncture warfare”. Acupuncture warfare (also called “paralysis warfare”) is described as “Paralysing the enemy by attacking the weak link of his command, control, communications and information as if hitting his acupuncture point in kung fu combat.”
In another five to 10 years China will develop much greater depth and sophistication in its understanding and handling of information warfare techniques and information operations. With Indian society becoming increasingly dependent on automated data processing and vast computer networks, India will also become extremely vulnerable to such information warfare techniques. The fact that it can be practiced from virtually any place on the earth even during peacetime makes acupuncture or paralysis warfare even more diabolical. India can ill-afford to ignore this new challenge to its security.

India should adopt a comprehensive inter-ministerial, inter-departmental, inter-Services, multi-agency approach to dealing with emerging cyber warfare threats and must develop appropriate responses. No single agency in India is charged with ensuring cyber and IT security. A nodal agency must be created to spearhead India’s cyberwar efforts under a national cyber security advisor who should report directly to the NSA. The armed forces must be part of the overall national effort from the very beginning so that emerging tactics, techniques and procedures can be incorporated into doctrine and training.

On June 23, 2009, Robert Gates, then US Secretary of Defence, authorised the creation of a new military command that will develop offensive cyber-weapons and defend command and control networks against computer attacks. India too needs a Cyber Command to lead efforts within the military to safeguard computer networks from hackers and cyber attacks.

India’s strategy must be defensive to guard the country’s vulnerable assets, such as military command and control networks and civilian infrastructure dependent on the use of cyber space, as well as offensive to disrupt the adversary’s C4I2SR systems and develop leverages that can be exploited at the appropriate time. With some of the finest software brains in the world available to India, it should not prove to be an insurmountable challenge.

This is too important a field to allow the traditional Indian approach – digging heads into the sand while waiting for the threat to go away – to hold sway and react only when the enemy has reached Panipat and is knocking on the gates of Delhi. In this case, the nothingness of cyberspace connects China’s one million laptop warriors directly with Delhi, Mumbai, Kolkata, Chennai, Bangalore and Hyderabad and other Indian cities, as also India’s strategic establishments.