Showing posts with label Cyber Warfare. Show all posts
Showing posts with label Cyber Warfare. Show all posts

India, US sign cyber shield deal






 India and the US today inked a pact on cybersecurity to intensify information exchange on threats to computers and networks and initiate joint work on technologies against cyber-attacks.
A joint statement on the India-US strategic dialogue has announced the cybersecurity agreement among new initiative by the two countries. These initiatives also include a plan to develop a software platform to make available non-sensitive government data to the public and to award $3 million each year to entrepreneurial projects that commercialise technologies to improve health.
A memorandum of understanding between the Indian and the American Computer Emergency Response Teams (CERT) is expected to lead to routine exchange of information on vulnerabilities and co-operation on cybersecurity technologies, Indian CERT officials said.
“This comes at a time when cybersecurity-related incidents are increasing in number and becoming more and more sophisticated,” said Gulshan Rai, director-general of the Indian CERT, a division of the ministry of communications and information technology.
Rai said the MoU is expected to lead to greater exchange of information between Indian and US CERTs about known and emerging threats, specific vulnerabilities of computers and networks and open opportunities for joint technology development.
The CERTs track and catalogue threats, advocate protective mechanisms, and respond to attacks on computer systems in the two countries.
The latest monthly security bulletin from India’s CERT says 151 computer security-related incidents were reported during May 2011 alone, among which more than half involved “phishing” — an attack or an intrusion that involves some form of identity theft.
Last year, unidentified hackers, believed to be based in China, had penetrated computers in sensitive Indian government offices, including the National Security Council secretariat, and stolen documents on missiles, and personal and financial data of Indian officials.
India already has cybersecurity pacts, primarily for the exchange of information, with Japan and Korea and is planning to develop one with Finland, Rai told The Telegraph.
The cybersecurity pact followed consultations led by the Indian and the US National Security Councils on prospects for bilateral co-operation on cybersecurity issues, held on Monday, a joint statement on the India-US strategic dialogue said.
The joint statement also said the Nasa has “reiterated its willingness to discuss potential co-operation with the Indian Space Research Organisation on human spaceflight”.
While the Nasa offer comes on the eve of the retirement of the US Space Shuttle, space experts believe Nasa has accumulated enormous expertise on human spaceflight — for instance, in the area of onboard life support systems — that could help India in its own long-term plans to develop a space capsule large enough to carry two astronauts into a low-earth orbit for a short mission.
The open source software platform that India and the US plan to create is intended to help make available to the public all non-sensitive government information through a user-friendly website.
It is expected to be patterned on the lines of America’s own government data website www.data.gov which began with 47 government data sets in May 2009, but has more than 392,000 data sets today.
“We have all kinds of data there — data sets on infant car seats, airline statistics, hospitals,” said Aneesh Chopra, the chief technology officer in the US, who is also assistant to US President Barack Obama.
An Indian government official said India is preparing a policy initiative to get myriad government departments into making non-sensitive data — from education to health to public infrastructure — public through a so-called National Data Sharing Access Policy (NDSAP). The official who spoke on condition of anonymity said this NDSAP is yet to be approved by the Union cabinet.
Among other initiatives, the India-US science and technology endowment board established in 2009 has decided to award $3 million annually to projects proposed by entrepreneurs for commercialisation of technologies to improve health and empower citizens.
The first call for proposals has already attracted more than 380 joint India-US proposals and the first set of awards will be announced in September this year.

New War Ground between India and Pakistan : Cyber Warfare

After sea, land and air warfare, traditional arch rivals India and Pakistan are now facing each other in another arena. With the help of Israelis, Indians have launched another war on a new axis against Pakistan – Cyber Warfare.

In certain aspects, Cyber warfare is complex, more penetrating and detrimental to the national security than conventional warfare. It is fought on the cyberspace using weapons like Cyber espionage, web vandalism, gathering data, Distributed Denial-of-Service Attacks (DDOS), equipment disruption, attacking critical infrastructure, compromised counterfeit hardware, virus and worm release. Potential targets include;


1) Emergency services
2) Financial markets and bank systems
3) Power grids Water and fuel pipelines
4) Strategic Weapons systems Communication networks (Military / Civil)
5) Industrial and Engineering Complexes
6) E-Government services (internet based utility services, web servers)

The Internet security company McAfee stated in their 2007 annual report that approximately 120 countries have been developing ways to use the Internet as a weapon and target financial markets, government computer systems and utilities.

Global Cyber Wars

China and US are spearheading cyber war at global level with dozens of cyber attacks on each other’s critical IT infrastructure. Both countries are spending millions every year in order to fight against cyber attacks.

Lethality of cyber warfare become palpable by the fact that till April 2009, Pentagon had spent more than 100 million dollars in just 6 months to fight against cyber attacks on its different systems. Money spent on propaganda operations are apart from this. In October 2010, US army created its first ever US army Cyber Command headed by a 3 star General.



From Pakistan’s perspective, unlike any other conventional threat, cyber warfare is rather a new battle field. Pakistan is not geared nor prepared to respond to this latest threat. India has all the reasons and resources to use this as a weapon against Pakistan. Recently Israel has joined hands with India raising this threat level significantly to be ignored any longer.

Cyber espionage, web vandalism and information gathering are the known cyber weapons and tools to be used against a security establishment and government. Apart from these cyber threats, the cyber world has been also used ruthlessly for the propaganda warfare. As per various media reports one can be sure that Indians and Israelis are taking these known cyber threats to its next level by using money, talent and technology to defame Pakistan and its nuclear program.

How eagerly the Indians want to gain an edge in cyber warfare technology is evident from what the Indian Naval Chief Admiral Sureesh Mehta told to Start Post;

“The Indian Armed Forces are increasingly investing in networked operations, both singly and in a joint fashion. We cannot afford to be vulnerable to cyber attacks. Information Technology is our country’s known strength and it would be in our interest to leverage this strength in developing a formidable ‘offensive’ and ‘defensive’ cyber warfare capability. Harnessing the gene pool available in academia, private industry and the younger generation of talented individuals is imperative,”

Statement of the Indian Naval Chief is an endorsement to the media reports that India has offensive cyber warfare plans. Pakistan is the natural target though Indian military establishment and political leadership used Chinese threat as an excuse for introducing this new war theatre in the region.

Indian Endeavour:

In August 2010 the Indian government decided to recruit and form cyber army of software professionals to spy on the classified data of hostile nations (read Pakistan and China) by hacking into their computer systems.

A strategy was drafted for this purpose earlier in a high level security meeting on July 29, 2010, chaired by Indian National Security Advisor Shiv Shankar Menon and attended by the director of Indian Intelligence Bureau (IB) as well as the senior officials of the telecom department, IT ministry and RAW.

According to the strategy drafted in the meeting, India will recruit IT professionals and hackers who will be assigned to be on the offensive or to launch pre-emptive strikes by breaching the security walls of enemy’s computer systems. The most important factor to note is the involvement of the Indian National Technical Research Organization (NTRO) along with the Defence Intelligence Agency (DIA) who will be responsible for creating these cyber-offensive capabilities. It is to be noted that NTRO is a key government agency of India that gathers technical intelligence while DIA is tasked with collating inputs from the Navy, Army and the Air Force.

The Indian Army conducted a war game called the Divine Matrix in March 2009. The most interesting aspect of this exercise was that Indian Military simulated a scenario in which China launches a nuclear attack on India somewhere in 2017. The purpose of the exercise was to describe how China will launch a cyber attack on India before the launch of the actual nuclear strike.

Chinese were not amused by this Indian war gaming and simulation. Their Foreign Ministry’s spokesman Qin Gang expressed his views on the Indian cyber warfare exercise. “We are surprised by the report. Leaders of China and India had already reached at consensus that the two countries will not pose a threat to each other but rather treat each other as partners.”

However, recently the Indian Army chief and the ex-chief have clearly threatened that there can be a nuclear war in the region (a veiled threat to both Pakistan and China).

Indo-Israeli Cyber nexus against Pakistan:

Though no large scale cyber attack has been reported as yet in Pakistan, yet a number of limited cyber skirmishes have already taken place between the Indian and Pakistani hackers in the recent years. In 2008 a group of Indian hackers defaced a Pakistani website of the Ministry of Oil and Gas. In a quick and effective retaliation Pakistani hackers attacked and defaced many Indian websites. This year too, many websites were defaced by the hackers on both sides.

This is where the interests of both India and Israel converged. According to reports, Israel has recently established a Cyber Task Force for Cyber Warfare against Islam and Pakistan, besides harming the Palestinian cause. A 15 million dollar budget has been allocated to this force to carry out various digital espionage and information gathering operations against Islam and Pakistan.

Propaganda Warfare and Cyber Space

In a new development, Israel has also setup a huge workforce of writers on the internet and is still increasing its strength. Primary task of this force would also be to wage propaganda war against Pakistan and its nuclear weapons and armed forces. Israelis are waging a net based disinformation and psychological war against Pakistan for quite some time now. Hebrew websites and magazines have been targeting Pakistan by orchestrating near to impossible scenarios about vulnerability of Pakistani nukes and the “possibility” of their falling into Al-Qaeda hands. Israelnationalnews.com, IsraelNN.com, and Arutz-7’s Hebrew newsmagazine are a few to name among these media outfits where Israelis are spiting and spewing venom against Pakistan.

Israeli government first tested these cyber propaganda tools during operation Cast Lead (brutal military operation in Gaza in 2008) when bloggers, surfers and writers were asked by the ministry of foreign affairs of Israel, through GIYUS (Give Israel You United Support), to promote words like “holocaust”, “promised land” and “murder of Jews” on social networking and blogging websites like Face Book, Twitter, MySpace, BlogSpot, wordpress etc. Israeli government went to the extent of giving written messages to be posted on the aforementioned websites as if they were the personal responses or views of the citizens of other countries.

Israeli lobbies have been heavily exploiting their clouts in US and UK to wage propaganda war against Pakistan’s nuclear program through satellite news channels (like BBC, FOX, SkyNews) and news papers (New York Time, Washington Post, etc.). Disinformation campaign was also launched from US and Western media when operation Rah-e-Rast was initiated in Swat and Malakand regions. Taliban threat was so exaggerated that a perception was created as if Islamabad was about to fall to the Taliban! Indian government also took active part in this campaign. Indian Prime Minister took this disinformation war to new heights by saying that some of the Pakistani nuclear installations were already under Taliban control!

Israeli cyber operations were resolutely and admirably countered by the young Palestinian bloggers by posting thousands of pictures and footages of Israeli brutalities in GAZA over the internet.

Final Thoughts:

In Pakistan, as compared to the adequate measures being taken for the upkeep of the conventional forces and the safety and security of the strategic assets, it is alarming to see the absence of any serious threat perception in the theatre of cyber warfare. The government as well as the armed forces seem to have neglected this threat for too long now and are not prepared to readily respond to this new challenge. Pakistan cannot afford any more complacency in this regard and better take immediate steps to respond to this lurking threat on literal war footings.

It would need absolute coordination, planning or understanding within various civil and military organizations and intelligence agencies responsible for the Cyber Warfare and perception management through propaganda wars in the cyber space. The whole existing system and organizations are to be revamped and some restructured to deliver effectively in these times of great crisis and threats in this arena. Reliance on the old fashioned methods of collecting and collating information and processing have to be updated. This should be clearly understood that in the modern world only those nations would have the advantage on the battle field, in both conventional and unconventional wars, which have fought and won the war in the cyber world first. The entire military equation in a war can be changed dramatically without even firing a shot, by controlling the critical infrastructure and perception of the target population through propaganda war in the cyber world.

Weapons like E-bombs have emerged as a new threat to cripple the military communication infrastructure by producing massive electromagnetic pulse. Pakistan must start work on Transient Electro Magnetic Pulse Emanations Standards, known as TEMPEST in military parlance to counter electromagnetic-pulse bombs that can interrupt wireless signals.

Pakistan has already faced interception of its vital secrete data on military operations in FATA by India through its assets in the area. It is, therefore, a must that we should work on TEMPEST and harden it to a degree of zero chances of interception of data transferred by defence agencies.

Pakistan needs urgently to create a centralized, aggressive and pro-active Command for Cyber and Information warfare under the Chairman Joint Chiefs of Staff Committee. The unguarded flank of Pakistan defence must be secured at the soonest.
Read More  AT:
http://paktribune.com/news/index.shtml?242277

China's Newspaper Threatens Google For Hacking Claims




The tough warning appeared in the overseas edition of the People's Daily, the leading newspaper of China's ruling Communist Party, indicating that political tensions between the United States and China over Internet security could linger.

Last week, Google said it had broken up an effort to steal the passwords of hundreds of Google email account holders, including U.S. government officials, Chinese human rights advocates and journalists. It said the attacks appeared to come from China.

The Chinese Foreign Ministry rejected those accusations, and the party newspaper warned Google against playing a risky political game.

By saying that Chinese human rights activists were among the targets of the hacking, Google was "deliberately pandering to negative Western perceptions of China, and strongly hinting that the hacking attacks were the work of the Chinese government," the People's Daily overseas edition, a small offshoot of the main domestic paper, said in a front-page commentary.

"Google's accusations aimed at China are spurious, have ulterior motives, and bear malign intentions," said the commentary, written by an editor at the paper.

"Google should not become overly embroiled in international political struggle, playing the role of a tool for political contention," the paper added.

"For when the international winds shift direction, it may become sacrificed to politics and will be spurned by the marketplace," it said, without specifying how Google's business could be hurt.

A Google spokeswoman said the U.S. firm had no comment on the remarks.

The latest friction with Google could bring Internet policy back to the foreground of U.S.-China relations, reprising tensions last year when the Obama administration took up Google's complaints about hacking and censorship from China.

Google partly pulled out of China after that dispute. Since then, it has lost more share to rival Baidu Inc in China's Internet market, the world's largest by user numbers with more than 450 million users.

Google said last week that the hacking attacks appeared to come from Jinan, the capital of China's eastern Shandong province and home to an intelligence unit of the People's Liberation Army.

U.S. Defense Secretary Robert Gates over the weekend warned that Washington was prepared to use force against cyber-attacks it considered acts of war.

In February, overseas Chinese websites, inspired by anti-authoritarian uprisings across the Arab world, called for protests across China, raising Beijing's alarm about dissent and prompting tightened censorship of the Internet.

China already blocks major foreign social websites such as Facebook and Twitter.
(source Reuter)

U.S. Arms Makers Bleeding Secrets To Cyber Foes




Top Pentagon contractors have been bleeding secrets for years as a result of penetrations of their computer networks, current and former national security officials say.

The Defense Department, which runs its own worldwide eavesdropping, spying and code-cracking systems, says more than 100 foreign intelligence organizations have been trying to break into U.S. networks.

Some of the perpetrators "already have the capacity to disrupt" U.S. information infrastructure, Deputy Defense Secretary William Lynn, who is leading remedial efforts, wrote last fall in the journal Foreign Affairs.

Joel Brenner, the National Counterintelligence executive from 2006 to 2009, said most if not all of the big defense contractors' networks had been pierced.

"This has been happening since the late '90s," he told Reuters Tuesday. He identified the main threats as coming from Russia, China and Iran.

"They're after our weapons systems and R&D," or research and development, said Brenner, now with the law firm of Cooley LLP in Washington.

Lockheed Martin Corp, the Pentagon's No. 1 supplier by sales, said on Saturday that it had thwarted "a significant and tenacious" attack on its information systems network that it detected May 21. Ten days later, the company says its still working to restore full employee access to the network while maintaining the highest level of security.

Lockheed, which is also the government's top information technology provider, said it had become "a frequent target of adversaries from around the world." A spokeswoman said it said it used the term "adversaries" only in a general sense.

Lockheed builds F-16, F-22 and F-35 fighter jets as well as Aegis naval combat system, THAAD missile defense and other big-ticket weapons systems sold to U.S. allies. It has not disclosed which of its business units was targeted.

Cyber intruders were reported in 2009 to have broken into computers holding data on Lockheed's projected $380 billion-plus F-35 fighter program, the Pentagon's costliest arms purchase.

Other big Pentagon contractors include Boeing Co, Northrop Grumman Corp, General Dynamics Corp, BAE Systems Plc and Raytheon Co. Each of these declined to comment on whether it believed its networks had been penetrated.

James Miller, the principal deputy undersecretary of defense for policy, said last May that the United States was losing terabytes of data in cyber attacks, enough to fill "multiple Libraries of Congress." The world's largest library, its archive totaled about 235 terabytes of data as of April, the Library of Congress says on its web site.

"The scale of compromise, including the loss of sensitive and unclassified data, is staggering," Miller told a Washington forum.

U.S. Senator Sheldon Whitehouse, who led a Senate Intelligence Committee cyber task force last year, said in March that cybercrime has put the United States "on the losing end of what could be the largest illicit transfer of wealth in world history."

Retired Air Force General Michael Hayden, a former director of central intelligence and ex-head of the Pentagon's National Security Agency, said no network was safe if it had Internet access.

"You can isolate a network, a classified network," he told Reuters in an interview last year. "Maybe you can get a certain level of confidence that you are not penetrated. But if you are out there connected to the world wide web you are vulnerable all the time."

Anup Ghosh, a former senior scientist at the Pentagon's Defense Advanced Research Projects Agency, or DARPA, said there had been a string of intrusions into networks of U.S. defense contractors, security companies and U.S. government labs, including the U.S. Energy Department's Oak Ridge National Laboratory, since the start of this year.

The advantage is with the intruders, said Ghosh, who worked on securing military networks for DARPA from 2002 to 2006 and now heads Invincea, a software security company.

"We've failed to innovate in the area of information security," he said in an email Tuesday. "We're fighting today's battles with the equivalent of cold-war era defenses."