Showing posts with label Cyber Warfare. Show all posts
Showing posts with label Cyber Warfare. Show all posts

Saturday

US ‘CYBERCOM’ May Trigger A New Cyber Warfare: Chinese analysts

The US’ announcement to set up a Cyber Command (CYBERCOM), which is aimed at gaining military supremacy in cyber space, might trigger a new Cyber Warfare Race, Chinese strategic analysts have warned.

“It has already had the lead in conventional military and nuclear forces. Now it is expanding this advantage to be the leading force in new fields, such as electromagnetic space and outer space,” state-run China Daily quoted Peng Guangqian, a Beijing-based strategist, as saying.

US Secretary of Defence Robert Gates, recently, announced the establishment of the world’s first comprehensive, multi-service military cyber operation, called CYBERCOM, which could provide US forces a lead in new emerging strategic fields like space and outer space.

The announcement came only a few days after President Barack Obama laid out his National Security Strategy, stressing for the first time in such a document the importance of cyber security as one of the core national security interests, he said.

Meng Xiangqing, a professor with the National Defence University said there is a very thin line between a defencive and an offencive act when it comes to cyber space.

“CYBERCOM ranks high in the US military, reporting directly to the US Strategic Command, and the US is the most advanced state in cyber technology. This absolute advantage may trigger a new type of arms race,” Meng said.

Despite the US insisting CYBERCOM is mainly defencive, Meng said it “has raised a new challenge for China, and that is how to guard our national cyber security.”

States other than the US have already been planning mechanisms to guard national cyber security, including the UK, France, Russia, South Korea and Israel, which already has a military cyber force.

Song Xiaojun, a Beijing-based military strategist, said even if other countries join in the cyber arms race, they are not capable of competing with the US since it possesses the core technologies of the Internet and of all 13 Internet root servers in the world, 10 are in the US, including the only one main root server.

The newspaper also reported the comments of US Deputy Defence Secretary William J Lynn III that the potential enemy that CYBERCOM will fight has not yet been clearly identified.

“I think we need to be prepared for the unexpected. In fact, over the past several years we have experienced damaging penetrations,” Lynn had said apparently referring alleged attempts by Chinese hackers to break into sensitive defence sites. 


http://www.china-defense-mashup.com/

NATO And India Would Work Together For Busting Chinese Hackers

Faced with a common cyber security threat from Chinese hackers, NATO is eyeing India as an ally in securing its computers that hold sensitive information and data against malware and Trojan viruses.

With US already signing a cyber security collaboration pact with India this July, the 28-nation American-led political and military alliance is of the view that it can collaborate with the South Asian information technology superpower in protecting the cyber world, one of the global commons.
"You have one of the most advanced cyber industries in the world... and information technology industries. The issue of cyber security is one that affects the United States, NATO and India no matter whether we are aligned or non-aligned," a senior NATO official told IANS at the alliance's headquarters here.

"The cyber world doesn't recognise alignments. It only recognises switches and servers. As a result, we are in this cyber world together, whether we like it or not.

"We better figure out a way to cooperate, particularly since it does matter that you have a neighbour (country) next door, which is pretty much involved in cyber issues, even far away. Because in the cyber world, we are equally close," the official, who did not want to be identified because of the organisation's rules, said.

Although he did not name any of India's neighbours, it was clear he was referring to China, which is suspected of being behind spy software attacks on American, NATO, Indian and Tibetan computers in the last half-a-decade, stealing highly classified military and security data.

In 2009, an investigation by Information Warfare Monitor (IWM) comprising researchers from Ottawa-based think-tank, SecDev Group, and the Munk Centre for International Studies at the University of Toronto, had blamed a spy network of Chinese hackers, called GhostNet, to have breached the firewalls of computers of NATO and other countries, including that of Tibetan leader Dalai Lama.
Their 2010 report claimed that major Indian defence establishments, including the Institute of Defence Studies and Analyses, National Security Council Secretariat, National Maritime Foundation, and armed forces units were targeted and secret presentations on weapons systems stolen by Chinese hackers.

A cyber security report earlier this year had suggested that the worldwide web-based attacks in 2010 were up 93 per cent from 2009.

As recently as July this year, 'Anonymous' hackers had targeted NATO in a cyber attack.
Just a month ahead of the latest attack, NATO had decided to create a special task force to detect and respond to such attacks by beefing up its cyber defence capabilities.

Its 2010 summit in Lisbon too recognised the growing sophistication of cyber attacks and set policies for the alliance to cooperation with partner countries.

NATO has already spelt out its intention of having India as a political and military partner country, considering its growing stature as a regional power.


http://ibnlive.in.com/

Monday

Cyber Security Command on cards in India

The National Security Advisory Board (NSAB) has recommended formation of a central cyber security command on the lines of the US Cyber Command (USCYBERCOM) set up last May to fight back the new generation attacks on the government’s computer systems and networks.

A policy paper of the board stresses need for such a command not only to prevent any leaks of the sensitive information but also to ensure the valued government data is not hacked or destroyed by anybody from outside or from within the system. The document gives an insight to a lot of work done by China for inflicting damage to the computer networks in other countries.

The latest such attack was made on the website of Central Bureau of Investigation (CBI), purportedly from Pakistan, destroying all the data on its website (cbi.nic.in) which is still not up even after 11 days of struggle by the National Informatic Centre engineers who maintain the government websites. Luckily, the intruders could not get into the CBI’s computer that stores the sensitive data, inaccessible easily from the Internet.


India does not have the risk of wiki type leaks as access to the classified and sensitive material is limited to a very limited number of top officials unlike even a corporal having access to the diplomatic cables of the US missions, the government sources say.

Moreover, they say the government organisations doing the sensitive works have been already ordered to prepare cyber crisis management plans.
Defence and nuclear installations had upgraded their measures and laid down standard operating procedures even before wiki-leaks started trickling early last July, when Iranian nuclear facilities in Natanz were reportedly hit by a computer worm Stunxnet. 

This work is touted as the first discovered worm that spies on and reprogrammes industrial systems. Russians described it as a working and fearsome prototype of a cyber-weapon that will lead to the creation of a new arms race in the world.


Only the other day Defence Minister A K Antony admitted in Parliament that India is already exposed to the possible cyber attacks and explained how the top army brass was working in unison to make cyber systems secure and non-porous to protect systems.


“The paradigms of security in the age of information technology are seldom constant. The evolving security matrix is complex and calls for co-operation and coordination of the highest level,” Antony said.
Earlier last month, he also told the army commanders that cyber attacks were “fast becoming the next generation of threats” and as such, no single service could work in isolation. “We need to make our cyber systems as secure and as non-porous as possible,” he said.

The assertion comes amid frequent attacks and the subsequent alerts sounded by the army authorities over China and Pakistan-based cyber spies peeking into India’s sensitive business, diplomatic and strategic records. 

The policy paper distributed by NSAB among the country’s strategic community stresses on simultaneous creation of a security centre that should monitor cyber operations and undertake active monitoring of cyber space. 

It also stresses need for funding to develop innovative technologies to protect the Indian networks and promote growth of critical skills in the arena.

The research paper, titled “Informationising Warfare” warns that “as China grows militarily and economically, its resultant strategies are all likely to expand, especially in the cyber warfare arena.” Perhaps the most crucial among the beyond rules criteria is manifested in the form of “asymmetric warfare” — for instance, cyber attacks directed against data networks.

“The primary idea is to strike in unexpected ways against vulnerable targets,” the paper says, stressing that India has to prepare for these strategies that do not fall in the terrain of the present defence structure of Indian Army, Indian Air Force and Indian Navy, the researcher underlined.

The research paper quotes two Chinese strategists explaining a “combination scenario” being tried by China in which it secretly musters large amounts of capital and launches a sneak attack on an adversary’s financial markets. 


Subsequently, it inflicts a computer virus and hacker attachment in the opponent’s computer systems and attacks his networks to disrupt and paralyse the networks of civilian electricity, traffic dispatch, financial transactions, telephone communications, and mass media, thereby causing social panic, street riots, and political crises for the adversary, the paper said.

The cyber warfare consists of two types: Cyber attacks and cyber protection. Cyber attacks include virus attacks and hacker attacks. Computer virus attacks refer to operational actions that use computer viruses to destroy or tamper information stored in computer systems in a manner that they do not work properly.


“In the military field, the core equipment of military information systems and cyberised weapons are all likely targets of computer virus attacks. Computer hacker attacks refer to those actions taken by hackers to intrude upon and destroy an opponent’s cyber systems,” the paper stressed.

It points out that Beijing is also pursuing a diverse and comprehensive portfolio of space warfare investments since the late 1980s. The status of these programmes runs from advanced concept development and testing, through product engineering evaluation, line-level manufacturing and acquisition from foreign sources, to integration as war-fighting capabilities into the Chinese armed forces.

“The evidence suggests that these programmes are protean: They lend themselves to steady evolution across the spectrum, from space denial to space dominance, if Beijing’s political goals change over time, though at present and for the foreseeable future, they are optimised for the space-denial mission,” the paper said.

Its stress is that the defence planning and implementation in future has to incorporate the virtual word to limit physical damage to the real one as China is increasingly integrating computer technology into modern military organisations to play the twin roles of being both a target and a weapon.

Cyber forces are most likely to be integrated by China into an overall battle strategy as part of a combined arms campaign. The aim is to increase the ‘fog of war’ for the enemy and to reduce it for one’s own forces—to  be achieved through direct military strikes designed to degrade the enemy’s information-processing and communications systems or by attacking the systems internally to achieve, not denial of service, but a denial of capability.

Thursday

India, US sign cyber shield deal


 India and the US today inked a pact on cybersecurity to intensify information exchange on threats to computers and networks and initiate joint work on technologies against cyber-attacks.
A joint statement on the India-US strategic dialogue has announced the cybersecurity agreement among new initiative by the two countries. These initiatives also include a plan to develop a software platform to make available non-sensitive government data to the public and to award $3 million each year to entrepreneurial projects that commercialise technologies to improve health.
A memorandum of understanding between the Indian and the American Computer Emergency Response Teams (CERT) is expected to lead to routine exchange of information on vulnerabilities and co-operation on cybersecurity technologies, Indian CERT officials said.
“This comes at a time when cybersecurity-related incidents are increasing in number and becoming more and more sophisticated,” said Gulshan Rai, director-general of the Indian CERT, a division of the ministry of communications and information technology.
Rai said the MoU is expected to lead to greater exchange of information between Indian and US CERTs about known and emerging threats, specific vulnerabilities of computers and networks and open opportunities for joint technology development.
The CERTs track and catalogue threats, advocate protective mechanisms, and respond to attacks on computer systems in the two countries.
The latest monthly security bulletin from India’s CERT says 151 computer security-related incidents were reported during May 2011 alone, among which more than half involved “phishing” — an attack or an intrusion that involves some form of identity theft.
Last year, unidentified hackers, believed to be based in China, had penetrated computers in sensitive Indian government offices, including the National Security Council secretariat, and stolen documents on missiles, and personal and financial data of Indian officials.
India already has cybersecurity pacts, primarily for the exchange of information, with Japan and Korea and is planning to develop one with Finland, Rai told The Telegraph.
The cybersecurity pact followed consultations led by the Indian and the US National Security Councils on prospects for bilateral co-operation on cybersecurity issues, held on Monday, a joint statement on the India-US strategic dialogue said.
The joint statement also said the Nasa has “reiterated its willingness to discuss potential co-operation with the Indian Space Research Organisation on human spaceflight”.
While the Nasa offer comes on the eve of the retirement of the US Space Shuttle, space experts believe Nasa has accumulated enormous expertise on human spaceflight — for instance, in the area of onboard life support systems — that could help India in its own long-term plans to develop a space capsule large enough to carry two astronauts into a low-earth orbit for a short mission.
The open source software platform that India and the US plan to create is intended to help make available to the public all non-sensitive government information through a user-friendly website.
It is expected to be patterned on the lines of America’s own government data website www.data.gov which began with 47 government data sets in May 2009, but has more than 392,000 data sets today.
“We have all kinds of data there — data sets on infant car seats, airline statistics, hospitals,” said Aneesh Chopra, the chief technology officer in the US, who is also assistant to US President Barack Obama.
An Indian government official said India is preparing a policy initiative to get myriad government departments into making non-sensitive data — from education to health to public infrastructure — public through a so-called National Data Sharing Access Policy (NDSAP). The official who spoke on condition of anonymity said this NDSAP is yet to be approved by the Union cabinet.
Among other initiatives, the India-US science and technology endowment board established in 2009 has decided to award $3 million annually to projects proposed by entrepreneurs for commercialisation of technologies to improve health and empower citizens.
The first call for proposals has already attracted more than 380 joint India-US proposals and the first set of awards will be announced in September this year.

New War Ground between India and Pakistan : Cyber Warfare

After sea, land and air warfare, traditional arch rivals India and Pakistan are now facing each other in another arena. With the help of Israelis, Indians have launched another war on a new axis against Pakistan – Cyber Warfare.

In certain aspects, Cyber warfare is complex, more penetrating and detrimental to the national security than conventional warfare. It is fought on the cyberspace using weapons like Cyber espionage, web vandalism, gathering data, Distributed Denial-of-Service Attacks (DDOS), equipment disruption, attacking critical infrastructure, compromised counterfeit hardware, virus and worm release. Potential targets include;


1) Emergency services
2) Financial markets and bank systems
3) Power grids Water and fuel pipelines
4) Strategic Weapons systems Communication networks (Military / Civil)
5) Industrial and Engineering Complexes
6) E-Government services (internet based utility services, web servers)

The Internet security company McAfee stated in their 2007 annual report that approximately 120 countries have been developing ways to use the Internet as a weapon and target financial markets, government computer systems and utilities.

Global Cyber Wars

China and US are spearheading cyber war at global level with dozens of cyber attacks on each other’s critical IT infrastructure. Both countries are spending millions every year in order to fight against cyber attacks.

Lethality of cyber warfare become palpable by the fact that till April 2009, Pentagon had spent more than 100 million dollars in just 6 months to fight against cyber attacks on its different systems. Money spent on propaganda operations are apart from this. In October 2010, US army created its first ever US army Cyber Command headed by a 3 star General.



From Pakistan’s perspective, unlike any other conventional threat, cyber warfare is rather a new battle field. Pakistan is not geared nor prepared to respond to this latest threat. India has all the reasons and resources to use this as a weapon against Pakistan. Recently Israel has joined hands with India raising this threat level significantly to be ignored any longer.

Cyber espionage, web vandalism and information gathering are the known cyber weapons and tools to be used against a security establishment and government. Apart from these cyber threats, the cyber world has been also used ruthlessly for the propaganda warfare. As per various media reports one can be sure that Indians and Israelis are taking these known cyber threats to its next level by using money, talent and technology to defame Pakistan and its nuclear program.

How eagerly the Indians want to gain an edge in cyber warfare technology is evident from what the Indian Naval Chief Admiral Sureesh Mehta told to Start Post;

“The Indian Armed Forces are increasingly investing in networked operations, both singly and in a joint fashion. We cannot afford to be vulnerable to cyber attacks. Information Technology is our country’s known strength and it would be in our interest to leverage this strength in developing a formidable ‘offensive’ and ‘defensive’ cyber warfare capability. Harnessing the gene pool available in academia, private industry and the younger generation of talented individuals is imperative,”

Statement of the Indian Naval Chief is an endorsement to the media reports that India has offensive cyber warfare plans. Pakistan is the natural target though Indian military establishment and political leadership used Chinese threat as an excuse for introducing this new war theatre in the region.

Indian Endeavour:

In August 2010 the Indian government decided to recruit and form cyber army of software professionals to spy on the classified data of hostile nations (read Pakistan and China) by hacking into their computer systems.

A strategy was drafted for this purpose earlier in a high level security meeting on July 29, 2010, chaired by Indian National Security Advisor Shiv Shankar Menon and attended by the director of Indian Intelligence Bureau (IB) as well as the senior officials of the telecom department, IT ministry and RAW.

According to the strategy drafted in the meeting, India will recruit IT professionals and hackers who will be assigned to be on the offensive or to launch pre-emptive strikes by breaching the security walls of enemy’s computer systems. The most important factor to note is the involvement of the Indian National Technical Research Organization (NTRO) along with the Defence Intelligence Agency (DIA) who will be responsible for creating these cyber-offensive capabilities. It is to be noted that NTRO is a key government agency of India that gathers technical intelligence while DIA is tasked with collating inputs from the Navy, Army and the Air Force.

The Indian Army conducted a war game called the Divine Matrix in March 2009. The most interesting aspect of this exercise was that Indian Military simulated a scenario in which China launches a nuclear attack on India somewhere in 2017. The purpose of the exercise was to describe how China will launch a cyber attack on India before the launch of the actual nuclear strike.

Chinese were not amused by this Indian war gaming and simulation. Their Foreign Ministry’s spokesman Qin Gang expressed his views on the Indian cyber warfare exercise. “We are surprised by the report. Leaders of China and India had already reached at consensus that the two countries will not pose a threat to each other but rather treat each other as partners.”

However, recently the Indian Army chief and the ex-chief have clearly threatened that there can be a nuclear war in the region (a veiled threat to both Pakistan and China).

Indo-Israeli Cyber nexus against Pakistan:

Though no large scale cyber attack has been reported as yet in Pakistan, yet a number of limited cyber skirmishes have already taken place between the Indian and Pakistani hackers in the recent years. In 2008 a group of Indian hackers defaced a Pakistani website of the Ministry of Oil and Gas. In a quick and effective retaliation Pakistani hackers attacked and defaced many Indian websites. This year too, many websites were defaced by the hackers on both sides.

This is where the interests of both India and Israel converged. According to reports, Israel has recently established a Cyber Task Force for Cyber Warfare against Islam and Pakistan, besides harming the Palestinian cause. A 15 million dollar budget has been allocated to this force to carry out various digital espionage and information gathering operations against Islam and Pakistan.

Propaganda Warfare and Cyber Space

In a new development, Israel has also setup a huge workforce of writers on the internet and is still increasing its strength. Primary task of this force would also be to wage propaganda war against Pakistan and its nuclear weapons and armed forces. Israelis are waging a net based disinformation and psychological war against Pakistan for quite some time now. Hebrew websites and magazines have been targeting Pakistan by orchestrating near to impossible scenarios about vulnerability of Pakistani nukes and the “possibility” of their falling into Al-Qaeda hands. Israelnationalnews.com, IsraelNN.com, and Arutz-7’s Hebrew newsmagazine are a few to name among these media outfits where Israelis are spiting and spewing venom against Pakistan.

Israeli government first tested these cyber propaganda tools during operation Cast Lead (brutal military operation in Gaza in 2008) when bloggers, surfers and writers were asked by the ministry of foreign affairs of Israel, through GIYUS (Give Israel You United Support), to promote words like “holocaust”, “promised land” and “murder of Jews” on social networking and blogging websites like Face Book, Twitter, MySpace, BlogSpot, wordpress etc. Israeli government went to the extent of giving written messages to be posted on the aforementioned websites as if they were the personal responses or views of the citizens of other countries.

Israeli lobbies have been heavily exploiting their clouts in US and UK to wage propaganda war against Pakistan’s nuclear program through satellite news channels (like BBC, FOX, SkyNews) and news papers (New York Time, Washington Post, etc.). Disinformation campaign was also launched from US and Western media when operation Rah-e-Rast was initiated in Swat and Malakand regions. Taliban threat was so exaggerated that a perception was created as if Islamabad was about to fall to the Taliban! Indian government also took active part in this campaign. Indian Prime Minister took this disinformation war to new heights by saying that some of the Pakistani nuclear installations were already under Taliban control!

Israeli cyber operations were resolutely and admirably countered by the young Palestinian bloggers by posting thousands of pictures and footages of Israeli brutalities in GAZA over the internet.

Final Thoughts:

In Pakistan, as compared to the adequate measures being taken for the upkeep of the conventional forces and the safety and security of the strategic assets, it is alarming to see the absence of any serious threat perception in the theatre of cyber warfare. The government as well as the armed forces seem to have neglected this threat for too long now and are not prepared to readily respond to this new challenge. Pakistan cannot afford any more complacency in this regard and better take immediate steps to respond to this lurking threat on literal war footings.

It would need absolute coordination, planning or understanding within various civil and military organizations and intelligence agencies responsible for the Cyber Warfare and perception management through propaganda wars in the cyber space. The whole existing system and organizations are to be revamped and some restructured to deliver effectively in these times of great crisis and threats in this arena. Reliance on the old fashioned methods of collecting and collating information and processing have to be updated. This should be clearly understood that in the modern world only those nations would have the advantage on the battle field, in both conventional and unconventional wars, which have fought and won the war in the cyber world first. The entire military equation in a war can be changed dramatically without even firing a shot, by controlling the critical infrastructure and perception of the target population through propaganda war in the cyber world.

Weapons like E-bombs have emerged as a new threat to cripple the military communication infrastructure by producing massive electromagnetic pulse. Pakistan must start work on Transient Electro Magnetic Pulse Emanations Standards, known as TEMPEST in military parlance to counter electromagnetic-pulse bombs that can interrupt wireless signals.

Pakistan has already faced interception of its vital secrete data on military operations in FATA by India through its assets in the area. It is, therefore, a must that we should work on TEMPEST and harden it to a degree of zero chances of interception of data transferred by defence agencies.

Pakistan needs urgently to create a centralized, aggressive and pro-active Command for Cyber and Information warfare under the Chairman Joint Chiefs of Staff Committee. The unguarded flank of Pakistan defence must be secured at the soonest.
Read More  AT:
http://paktribune.com/news/index.shtml?242277
Related Posts Plugin for WordPress, Blogger...
Web Analytics