Showing posts with label CYBER SECURITY IN INDIA.. Show all posts
Showing posts with label CYBER SECURITY IN INDIA.. Show all posts

Sunday, May 16, 2010

Authority For Telecom Security In India

By
Praveen Dalal

In this guest column, Mr. Praveen Dalal is sharing his views regarding the recent controversy of banning Chinese telecom products and establishment of a telecom security regulatory authority of India.

Telecom infrastructure forms the backbone of information and communication technology (ICT) base of any nation. Telecom is also an essential part of critical infrastructure of a nation that requires security norms of the highest level. This has necessitated formation of effective telecommunication laws in India on the one hand and establishment of effective telecom security on the other.

India presently does not have a telecom security regulatory authority that can perform these cyber security and telecom security tasks nor does it have any specific law that ensures telecom security in India.

In this background it came as a pleasant surprise when the Indian government declared to set up a regulator to provide security certification at different stages for equipment brought to India by both the public and private sectors.

There cannot be a doubt about the proposition that both hardware and software based backdoors and malware can be preinstalled. However, what is frustrating is targeting China exclusively for this purpose. Let me ask the government of India a simple question: Has you found any malware, vulnerability or backdoor in the Chinese telecom or other equipments? If the answer is in positive then Indian government must give Chinese manufactures an opportunity to explain the same and if found guilty can proceed to blacklist them partially or permanently.

Similarly, Indian government must clear its head regarding crucial issues like encryption standards, network sniffing, e-mails sniffing, mobile phones interceptions, cell phone data usages, etc. It is high time for India to enact a comprehensive legislation in this regard.

Saturday, April 17, 2010

Cyber Security In India Needs To Improve

It has been reported that India, needs immediate techno-legal online safety. Perry4Law is supervising the special techno-legal online security investigation, training and educational centre in India.

Cyber security in India has always got an unfamiliar treatment. Online protection is not only vital for securing the cyberspace of a Nation, it is also essential for securing its territorial boundaries.

Planned and critical data can be collected from manipulating Information and Communication Technology (ICT) used by strategic units of a Nation. For safeguarding businesses, governments and general public at large, cyber security is very important.

The situation is said to be most terrible when it comes to wireless safety in India. Wireless security has become a headache due to its misuse by terrorists in India.

Another crucial aspect related to a secure and strong cyber security in India pertains to critical ICT infrastructure protection in India. If ICT system is not secured risk of critical ICT infrastructure also increases.

It has been reported that, recently, Chinese intelligence groups might have planted computer malware and broken into the headquarters of 33 Corps, the army formation taking care of most of the north-eastern border with China.

It is believed that the break-in integrated the planting of Trojan viruses, which might have provided Chinese operators distant access to the computer network at the 33 Corps headquarters in Sukhna, near Siliguri, West Bengal.

AUTHOR: PANKAJ LAKHOTIA

SOURCE: STOCK WATCH

Tuesday, April 6, 2010

India Is A Sitting Duck Says NTRO

The government of India (GOI) is least bothered about cyber security in India and critical infrastructure protection in India. According to Praveen Dalal, the leading techno-legal expert of India, we must pay more attention towards securing India’s cyberspace not only from internal but also external threats. Now even NTRO has admitted that India needs to have a dedicate cyber security organisation.

There is nothing to stop China, unless India develops its own tools for cyber warfare, National Technical Research Organisation (NTRO), the agency principally involved with investigating the depth of the damage caused by Chinese hackers, has warned. The Chinese hacking force uses malware, spyware, key loggers, trojans, bots and malicious code generators to break into Indian computers, copy documents, ex-filtrate sensitive material and bug classified correspondence. Without a dedicated Indian cyber-security organisation, this country will remain a sitting duck.

Sunday, January 24, 2010

The Growing Risks Of Electronic Communications Sniffing In India

Recent news has revealed that some unknown Pakistani hackers had intercepted an official email communication between J&K Police’s intelligence chief and the J&K Chief Minister. However, it is claimed that the intercepted email did not carry “sensitive information”. As per a senior police officer this is normal as both sides do it.

Omar Abdullah, Chief Minister J&K, has been encouraging use of Information and Communication Technology (ICT) for government functions. He has been seeking police reports and daily confidential police bulletins through e-mails instead of traditional mailing system.

According to Mr. Praveen Dalal, Managing Partner of Perry4Law and the leading Techno-Legal Expert of India, “Electronic communications sniffing is a very effective mechanism to steal e-mail passwords and confidential information. The same happens if the sniffer is at the same network in case of wired networks or through airwaves if he is targeting the wireless networks”.

To avoid the interception of the email communication by the security agencies, terrorists are not communicating between two email addresses but use a single address with several people knowing the password. The militant then save the document in the draft folder which could be subsequently read by his companions.

Similarly, security agencies are also adopting various methods to keep their e-communications safe and secure. This tussle between the terrorists and security agencies would further increase in the distant future and India should be well prepared to deal with the same.



Friday, January 22, 2010

Backtrack 4 Final Version Is A Good Tool Says Perry4law And PTLB

BackTrack 4 final version is now released for security professionals. The development team has mentioned that lots of downloads have already taken place from the official site. BackTrack 4 is providing penetration testing, cyber security and most importantly cyber forensics functionalities for the concerned people. It is a fantastic tool as suggested by Perry4Law and PTLB.

BackTrack is one of the highest rated and acclaimed Linux security distribution to date. BackTrack is a Linux-based penetration testing arsenal that aids security professionals in the ability to perform assessments in a purely native environment dedicated to hacking. Regardless if you’re making BackTrack your primary operating system, booting from a LiveDVD, or using your favorite thumbdrive, BackTrack has been customized down to every package, kernel configuration, script and patch solely for the purpose of the penetration tester.

BackTrack is intended for all audiences from the most savvy security professionals to early newcomers to the information security field. BackTrack promotes a quick and easy way to find and update the largest database of security tool collection to-date.

If you need any help feel free to contact its “Forum” or check its “how to” segment or its “FAQ” segment. If you need good training in these crucial areas, feel free to consult its “Training” segment.

If you need any “Techno-Legal” assistance in India you must contact Perry4Law for the same. Perry4Law is India’s first and exclusive techno-legal law firm of India and one of the few in the world.

Perry4Law is also managing Perry4Law Techno-Legal Base (PTLBTM/SM). PTLB is India’s first dedicated techno-legal platform that is providing consultancy, litigation and training services in the fields of cyber law, cyber security, cyber forensics, etc. Presently, India lacks cyber forensics capabilities and PTLB is meeting this much needed requirement. PTLB is operating as a “Resource Centre for Cyber Forensics in India”.

If any person is interested in getting consultancy, litigation or training services in the field of cyber forensics in India, you may check the “Contact Point” of Perry4Law.

SOURCE: MYNEWS

Monday, December 14, 2009

US and Russia Wish To Curb Cyber War

Cyber War and Cyber Terrorism are matters of grave concern to all countries. Equally important are the issue pertaining to cyber security of defense forces in India. These issues are important as they strike at the very root of the critical ICT infrastructure protection in India. While countries like US and Russia are negotiating to limit the impact of cyber wars, India is not doing the needful in this regard.

The military version of cyber war has the potential to be as serious as a nuclear war in terms of creating chaos. It could crash power and water supplies, as well as trashing the global financial systems and information systems. Russia is in favour of an internet disarmament treaty, but the practical aspects are tougher than nukes ever were.

Malware are posing significant threat to India yet there is no attention towards cyber security in India. For instance, we need express provisions and specified procedures to deal with issues like denial of service (DOS), distributed denial of services (DDOS), bot, botnets, trojans, backdoors, viruses and worms, sniffers, SQL injections, buffer overflows etc. Till now India has done nothing in this crucial direction.

India is also suffering from the menaces of cyber war and cyber terrorism. Nobody cares about any these threats in India. Media reports claim that China’s intensified cyber warfare against India is becoming a serious threat to national security. In October 2007, Chinese hackers defaced over 143 Indian websites.

In April 2008, Indian intelligence agencies detected Chinese hackers breaking into the computer network of the Ministry of External Affairs forcing the government to think about devising a new strategy to fortify the system.

As a countermeasure, the Indian armed forces are trying to enhance their C4ISR capabilities, so that the country can launch its own cyber offensive if the need arises. Similarly, Pakistan is taking steps to intensify its cyber war propaganda against India with the help of its intelligence outfit, the ISI by carrying reports of alleged communal fissures taking place on the Indian side of Kashmir. Issues like these have to be resolved as well.

India must immediately start working upon the issues like cyber warm, cyber terrorism, critical infrastructure protection, etc in the larger national interest and national security.

SOURCE: GROUND REPORT

Saturday, May 16, 2009

Legal Enablement Of ICT Systems In India Is Urgently Required

Legal enablement of ICT systems in India requires a futuristic approach that can be achieved by acquiring techno-legal insight by the law makers. The most important requirement for achieving the same is an awareness and acceptance of the benefits of ICT by the policy and law makers in India. The “political will” is required to ensure a timely and appropriate legal enablement of ICT systems in India. There is also a requirement to reduce the wide existing corruption, lack of transparency and accountability, bureaucratic hurdles, etc in India. These vices are eliminating the chances of India becoming an ICT super power.

India needs good e-governance models, sound cyber law, effective cyber security, cyber forensics capabilities, etc to achieve the task of legal enablement of ICT systems. The industrial lobbying and vested interests have really brought a situation where India has started to fall back upon the ICT developmental path. Various International reports and surveys have shown that India’s e-governance, e-readiness, transparency, privacy rights, data protection, etc have deteriorated further.


SOURCE: ITVOIR

Saturday, May 2, 2009

Political Agendas, Lies And Gullible Indians

Indian elections drama is once again unfolding. Political parties are covering all the aspects of economic development as well as launch pads of political mileage. What is surprising is that the issues covered by these agendas and manifestos are so broad and important that no political party of India can give effect to them at all. All of us are aware that not even 10% of these promises would see the light of the day. Still Indian population is gullible in nature and we would give our future in the hands of those who least care for us for another 5 years. The fact remains that neither BJP nor Congress can move away from their traditional political promises as they have been used time and again to fool Indians. I would not go into the details of all the promises, agendas and manifestos but would confine myself to those issues that cover Information and Communication Technology (ICT).

While BJP has come up with an IT Agenda, Congress seems to be indifferent towards ICT once again. The truth of these agendas and manifestos cannot be ascertained till we are made fool once again by a collation government. However, there are some very absurd events taking place in India in the meanwhile.

Firstly, the Parliament of India passed the Information Technology Amendment Bill, 2008 (Bill 2008) without any debate or discussion. All laws, including the Bill, 2008, are prima facie unconstitutional but neither our Judiciary nor the President of India found any problems with that. The Bill 2008 got President’s approval on 5th February, 2009 without the President even thinking once about its ill effects. Except Mr. Praveen Dalal none seems to have protested about this situation. Fortunately, as a result of this the proposed Bill 2008 seems to have been “withdrawn”.

Secondly, ICT must be used as a tool of development rather than as a means of harassment. Excessive and illegal e-surveillance eliminates the chances of effective use of ICT on the one hand and operates as an opponent of e-governance on the other. E-governance presupposes a free, fair and transparent public dealing in the cyberspace. Of late India has been treading on the wrong path of becoming an excessive surveillance State rather being a technology knowledge driven society. The recent example of mandating the e-mail companies to maintain their e-mail servers in India is a very novice decision. It only shows the ignorance about cyber security and ICT management issues in India. It is not clear whether Congress led government has come up with this idea or it is a work of government departments like Department of Information Technology (DIT) or Department of Telecommunications (DOT). Whoever has suggested this idea has no knowledge how Internet works and cyber security is ensured.

India needs good legal framework for technology, sound cyber security and effective cyber forensics expertise. The fill in gaps actions would only ridicule India in front of the entire world. It would be better if India come up with good ICT strategies and policies that are not only sensible but also possible to be implemented.

AUTHOR: V.K.SINGH

SOURCE:
MYNEWS