Cyber Menace: Integrated Defensive Policy Needed

Ravi Prasad <[email protected]> 24 May 2003 17:03:56 -0000
Newsgroups gmane.comp.security.papers
Message-ID <[email protected]>

Cyber Menace: Integrated Defensive Policy Needed=0D
By Ravi Visvesvaraya Prasad  =0D
=0D
Published in the =93Times of India=94, edit page, on Tuesday, 20 May 2003=
=0D
=0D
http://timesofindia.indiatimes.com/cms.dll/xml/uncomp/articleshow?=0D
msid=3D46885502=0D
=0D
Copyright: Ravi Visvesvaraya Prasad, 2003=0D
=0D
International Publishing Rights in all media with Times of India, 2003=0D
=0D
By Ravi Visvesvaraya Prasad  =0D
=0D
In his article =93A Virtual Non-Starter =96 Cyber Terrorism May Not Be fo=
r =0D
Real=94 (Times of India, Tuesday, 08 April 2003, edit page), Mr Vikas Sin=
gh, =0D
Associate Editor of the Times of India, described the consequences of =0D
cyber terrorism, especially on control systems and networks of computer-=0D
controlled devices. =0D
=0D
Mr Singh referred to an incident in Australia where a million litres of =0D
sewage were released into the water supply. What set off alarm bells amon=
g =0D
cybersecurity professionals worldwide was that 44 previous attempts by =0D
Vitek Boden had remained undetected; Boden being thwarted only by non-=0D
computerized backup safety measures. =0D
=0D
India=92s SCADA-controlled (Supervisory Control & Data Acquisition System=
s) =0D
electricity grids, power distribution systems, dam controls, water =0D
supplies, barrage controls, and sewage networks are highly vulnerable to =
=0D
attacks by cyberterrorists since almost none of them have up-to-date =0D
intrusion detection mechanisms installed. Worse, at least 30 percent of =0D
such Indian SCADA networks are accessible by modems which could be =0D
connected to the Public Switched Telephone Network. Moreover, public =0D
sector employees in India=92s infrastructure sectors are lax about non-=0D
computerized backup security procedures which are nowadays routinely =0D
implemented in SCADA systems abroad.=0D
=0D
India=92s banking sector, stock exchanges, and telecom and internet netwo=
rks =0D
are also highly vulnerable since they have implemented piecemeal security=
 =0D
solutions rather than an integrated defensive policy.=0D
=0D
A second threat that India faces is loss of highly sensitive data from =0D
government offices. For over six years Pakistani cracker groups such as G=
-=0D
Force Pakistan, Pakistan Hackerz Club, Anti-India Crew, World=92s =0D
Fantabulous Defacers and Silver Lords have been regularly breaking into =0D
the computer systems of Bhabha Atomic Research Centre, Indira Gandhi =0D
Centre for Atomic Research, Nuclear Science Centre, Ministry of Defence, =
=0D
Prime Minister=92s Office, Cabinet Secretariat, Home Ministry, Ministry o=
f =0D
External Affairs, and those of the three services, and accessing =0D
information. The damage that they caused was limited only by their =0D
adolescent mindsets rather than by any Indian cybersecurity measures. The=
y =0D
could have caused far greater damage to India=92s reputation if, instead =
of =0D
plastering puerile anti-Indian obscenities on the websites of various =0D
Indian ministries, they had altered the officially published texts of the=
 =0D
speeches of Vajpayee, Advani or Fernandes on these government websites to=
 =0D
make it appear that they were, say, calling for the genocide of Muslims i=
n =0D
India or for a nuclear strike on Pakistan. Such semantic attacks have bee=
n =0D
carried out on the websites of several news agencies abroad where cracker=
s =0D
altered news reports about various corporations in order to manipulate =0D
share prices.=0D
=0D
Now that India=92s National Informatics Centre is hosting the websites of=
 =0D
the new Afghan government, it would also be open to attacks by Middle =0D
Eastern organizations such as Ikhwan al Muslimoon, Jamaat Islami, Hizb-ut=
-=0D
Tahrir, Khilafah, Izz al-Din Al-Kassam, and Nida'ul Islam which have well=
-=0D
developed offensive information warfare capabilities. =0D
=0D
Far more serious than Pakistan is the long-term threat posed by China. =0D
While Pakistani cracker groups are mainly adolescents who receive =0D
encouragement and infrastructural support from Inter Services =0D
Intelligence, China=92s People=92s Liberation Army has successfully integ=
rated =0D
the latest C4ISRT (Command, Control, Communications and Computers =0D
Intelligence, Surveillance, Reconnaissance and Targeting) and information=
 =0D
warfare techniques into its People=92s War doctrine. PLA=92s offensive an=
d =0D
defensive infowar capabilities are now next only to NATO=92s.=0D
=0D
While China=92s offensive infowar capabilities are mainly targeted agains=
t =0D
Taiwan, USA, Japan and South Korea, they could be turned against India at=
 =0D
any time, especially as China and India will inevitably jostle for =0D
geopolitical supremacy in Asia in the coming decades.=0D
=0D
In mid-1999, China established a task force on information warfare =0D
composed of senior politicians, military officers and academics, headed b=
y =0D
Xie Guang, Vice-Minister of the Commission of Science, Technology and =0D
Industry for National Defense. Other key members were Fu Quanyou, Chief o=
f =0D
China=92s General Staff, Yuan Banggen, Head of General Staff Directorate,=
 =0D
Major General Wang Pufeng, Senior Colonel Wang Baocun, Shen Weiguang, Wan=
g =0D
Xiaodong, Qi Jianguo, Liang Zhenxing, Yang Minqing, Dai Qingmin, Leng =0D
Bingling, Wang Yulin, and Zhao Wenxiang. =0D
=0D
This task force had prepared detailed plans to cripple the civilian =0D
information infrastructures of Taiwan, USA, India, Japan and South Korea.=
 =0D
Qi Jianguo and Dai Qingmin have formulated a comprehensive scheme: First,=
 =0D
China would not attack military or political targets in these countries =0D
but would target their financial, banking, electrical supply, water, =0D
sewage, and telecommunications networks. Second, Chinese companies would =
=0D
establish business links with private companies in these countries. After=
 =0D
carrying on legitimate business for some time, they would insert maliciou=
s =0D
computer codes and viruses over commercial e-mail services. Third, the =0D
viruses and malicious codes would be sent through computers in =0D
universities in third countries so that they could not be traced back to =
=0D
China but would be thought to be the handiwork of adolescent pranksters. =
=0D
Fourth, the attacks would be launched when the political leadership of th=
e =0D
target countries was preoccupied, such as with election campaigns. Leng =0D
Bingling, Wang Yulin, and Zhao Wenxiang are in charge of mobilizing =0D
students and businessmen to support their military=92s cyberattacks again=
st =0D
civilian targets in these countries. =0D
=0D
PLA has conducted several field exercises. An =93Informaticized People=92=
s =0D
Warfare Network Simulation Exercise=94 was conducted in Echeng District o=
f =0D
Hubei Province. Five hundred soldiers simulated cyberattacks on the =0D
telecommunications, electricity, finance, and television sectors of =0D
Taiwan, India, Japan and South Korea. Ten functions were rehearsed in =0D
another exercise in Xian in Jinan Military Region: planting information =0D
mines; conducting information reconnaissance; changing network data; =0D
releasing information bombs; dumping information garbage; disseminating =0D
propaganda; applying information deception; releasing clone information; =
=0D
organizing information defense; and establishing network spy stations. In=
 =0D
Datong, forty PLA specialists are preparing methods of seizing control of=
 =0D
networks of commercial internet service providers in Taiwan, India, Japan=
 =0D
and South Korea. They held demonstrations for Beijing Region Military =0D
Command, Central Military Commission, and General Staff Directorate. =0D
=0D
Chief of General Staff Fu Quanyou presided over an exercise in Lanzhou an=
d =0D
Shenyang Military Regions which simulated electronic confrontation with =0D
countries south and west of Gobi Desert. This focused on electronic =0D
reconnaissance, counter-reconnaissance, electronic interference and =0D
counter-interference. It tested the battle readiness of PLA=92s command =0D
automation systems, command operations, situation maps, audio and graphic=
s =0D
processes and controls, and data encryption systems. Smaller exercises =0D
were carried out in Chengdu Military Region and Guangzhou Military Region=
. =0D
=0D
While it is gratifying that the Indian government has decided to establis=
h =0D
a national center on information systems security, it should tap the =0D
expertise of universities and private software and internet companies, =0D
rather than merely rely on the outdated knowledge of unmotivated =0D
government employees. In addition to the government and defence sectors, =
=0D
this Centre should cater to India=92s banking networks, stock exchanges, =
=0D
telecom and internet networks, power and water supplies, and =0D
transportation sectors. =0D
=0D
By Ravi Visvesvaraya Prasad =0D
=0D
The author heads a group which analyzes fourth-generation warfare and =0D
C4ISRT (Command, Control, Communications and Computers Intelligence, =0D
Surveillance, Reconnaissance and Targeting) in South Asia. He is also =0D
Advisor, Information Warfare & Revolution in Military Affairs, Centre for=
 =0D
Monitoring Chinese Military Activities.=0D
=0D
Cyber Menace: Integrated Defensive Policy Needed=0D
By Ravi Visvesvaraya Prasad  =0D
=0D
Published in the =93Times of India=94, edit page, on Tuesday, 20 May 2003=
=0D
=0D
http://timesofindia.indiatimes.com/cms.dll/xml/uncomp/articleshow?=0D
msid=3D46885502=0D
=0D
=0D
Ravi Visvesvaraya Prasad=0D
GSM: {91} 98 117 56789=0D
Pager: {91} [11] 96 22 17 36 60=0D
[email protected], [email protected]=0D
Fax: {91} [11] 25 26 68 68=0D
=0D
Cyber Menace: Integrated Defensive Policy Needed=0D
By Ravi Visvesvaraya Prasad  =0D
=0D
Published in the =93Times of India=94, edit page, on Tuesday, 20 May 2003=
=0D
=0D
http://timesofindia.indiatimes.com/cms.dll/xml/uncomp/articleshow?=0D
msid=3D46885502=0D
=0D
=0D
Copyright: Ravi Visvesvaraya Prasad, 2003=0D
=0D
International Publishing Rights in all media with Times of India, 2003=0D