Don’t open strange mails or attachments, officials told

By Devirupa Mitra, IANS
Wednesday, April 7, 2010

NEW DELHI - With alarming reports of a Chinese cyber spy ring targeting India’s strategic establishment, Indian officials and diplomats are being taught not to treat an e-mail as just a digital message but a potential spying instrument.

A “sensitisation” proecess begun right from the lowest rung to the seniormost officials of the Ministry of External Affairs (MEA) through a series of internal workshops that began last month.

It was in late 2008 that the attacks against the MEA’s computer network were first detected. Most of them were tracked to Chengdu in China, which led to an overhaul of the hardware and the establishment of a unified threat management system, with multiple layers of firewalls.

A recent report by American and Canadian researchers found that China-based hackers had penetrated and retrieved information from computers of India’s ministry of defence and other defence-related installations. It also said that several Indian embassies abroad had also been targeted.

While the South Block headquarters of MEA did not figure in the report, officials said that the ministry was still waging a daily cyber war.

“Since we are monitoring the system all the time, we notice that there are almost daily efforts to try and find holes in the system. So far, we think they have been unsuccessful,” said an official, who deals with network security in the government. The official spoke to IANS strictly on condition of anoymity as he was not authorised to speak to the media.

It has since been realized that the weakest link in combating cyber attacks was not the hardware, but the bureaucrats sitting in front of the 600-odd computers in the Lutyen-designed colonial building.

So, from last month, the MEA’s e-governance and information technology division began a “sensitization” process. The first batch consisted of lower division and upper division clerks, followed by personal secretaries. The last batch consisted under secretaries, with more senior officials to be called for these classes in the coming days.

To drive home the message, live demonstrations of potentially hazardous practices were shown - for example, a “suspicious” mail was sent to an inbox, which contained a link to another site which asked for the user’s password.

“We were told not to click on any strange mails with attachments or outside links,” said an official, who attended the workshop.

“There were reminders to take basic steps like changing password for the official mail on a monthly basis,” added another official.

The officials were also told how to read the “header” of such suspicious mails, so that by checking their Internet Protocol (IP) addresses, the geographical location of the sender can be tracked.

“Of course, if the sender was from certain countries, then the mail had to be carefully handled,” the official told IANS.

The cyber experts strictly told the ministry officials not to send attachments, especially of Microsoft word documents and Adobe PDF files, with their e-mails. “As far as possible, all the contents should be part of the main body of the mail,” he said.

Most ministry employees are provided with two computers - one which is internet-enabled, and the other which is a stand-alone device, with no network links.

“The problem arises, when we want to send an encrypted mail. Since the encryption software is in the stand-alone computer, we have to transfer data using pen drives which makes the other computer vulnerable to infection,” he said.

The ministry is considering installing another operating system, like Linux in the stand-alone computers. “We know that trojans or viruses may be targeting windows, but these become totally inoperative when introduced in another operating system based on Linux,” said the official.

(Devirupa Mitra can be contacted at devirupa.m@ians.in)

YOUR VIEW POINT
NAME : (REQUIRED)
MAIL : (REQUIRED)
will not be displayed
WEBSITE : (OPTIONAL)
YOUR
COMMENT :