Rethinking Cyber warfare: Strategic Implications for United States and China



“Every age had its own kind of war, its own limiting conditions, and its own peculiar preconceptions.”Carl von Clausewitz

Internet has transformed the front lines of war. Modern conflicts are now waged online in cyberspace. World Wide Web (WWW) has eradicated all physical borders and defences, without which weak and powerful states are all prone to attacks. Concurring to this pretext, a number of countries have formally recognized cyber as the new domain of warfare in their strategy papers and documents. United States and China are the master players in this realm having military units active, with sophisticated state of art capabilities dedicated to cyber strikes. The consequences are dire, for the sole superpower, and for the rising economic giant which is projected to take over the former by 2025.

The dynamic nature of cyber warfare has caused frustration in the inner circles of Washington and Beijing. Both the public and the private sector have been targeted. The former to get hands on state secrets and latter for intellectual property rights. According to an estimate by US Cyber Command (USCYBERCOM), it has cost the American economy $338 billion, an amount closer to the entire Gross Domestic Product (GDP) of Pakistan. China on the other hand leads the Asia-Pacific region in cyber losses which incurs the country an annual estimated loss of $60 billion.

Next Generation Warfare

There is a surge seen in cyber attacks against the US. The Central Intelligence Agency (CIA), Federal Bureau of Investigation (FBI) and National Security Agency (NSA) at multiple times have came under attack. This is followed by Silicon Valley tech giants, such as Netflix, Twitter and Spotify who on numerous occasions have been taken down by cyber attackers. It is very difficult to trace the identity and origin of the attack, as various techniques like changing Internet Protocol (IP) cannot only hide identity of attacker but misattribute it to other nations. Cyber security analysts working in their private capacity have collected evidence that seems indicate China as the alleged perpetrator of recent waves of cyber-attacks.

However, cyber pundits have openly stated that they cannot guarantee with a hundred percent accuracy that the evidence collected in wake of cyber-attacks is authentic and not planted by perpetrators to seem to look genuine. In cyberspace. An attack could be from anywhere around the globe. It could be from friends and foes alike, anyone can attack and make it look like an attack came from China or other adversary. In the past, cyberattackers from France bypassed into secured servers stealing classified information relating to American products and designs. Added to that, it is an expensive and difficult task to analyze these attacks. To know that you have been attacked or infiltrated is itself a big achievement. Considering that, it take days or even months to find that your security has been compromised. It took seven months for security analyst to find the Stuxnet virus that was hiding itself into a legitimate Siemens software responsible for controlling centrifuges at nuclear power plants around the world. According to an estimate starting rates for analyzing and identifying cyber attacks start from $650 dollars per hour, which often end up towards an uncertain conclusions.

Philippe Goldstein author of Babel Zero argues that attacking against a wrong adversary would be catastrophic. A troublesome scenario, where attacks in cyberspace can be met with conventional and even nuclear culminating a “Cyber Armageddon”. It is this reason that states have taken cyber warfare seriously and synonymous to national security. China has incorporated cyber command structure within its armed forces, under the“Three Warfare strategy.”

Cybersecurity analysts have called minuet “cyber bullets” as ‘Cyber weapons of Mass Destruction.’ All one needs is ‘bad timings, bad decision making and some bad luck!’ and you can end up having a World War III which was 24/7 nightmare of Cold War veterans. The world is not immune from such attacks. Anyone having an access to any computing device, from iPods to digital smart watches, having right technical skills can cause a national security crisis. This is well depicted in John Badham’s film, WarGames where a young hacker unknowingly sets a US military supercomputer to launch nuclear weapons on the former Soviet Union. Few years back, an attack on FBI’s website resulted in leaking of classified data caused alarm bells in Washington. Later it was found out the perpetrator was a 15 year old school boy from Glasgow, Scotland.

The way forward for states remains cumbersome in the absence of legal framework from the United Nations (UN). Further complications arise when the attack is orchestrated by a non-state actor or private individual from a particular state. Recent debates among the North Atlantic Treaty Organization (NATO) members have arisen in the wake of alleged Russian sponsored cyber activities against Europe and America whether the collective defence measures under Article 5 would apply to a cyber-attack.

Cyber security is a relatively new introduction in war studies. The US Department of Defence (DOD) recognized cyber warfare, as the fifth domain of warfare following land, sea, air and outer space. There are around 30 countries that have dedicated cyber military units, whereas more than 140 countries have or are in developing stages to acquire cyber weapons. Cyber is the means by which countries irrespective of their financial standing can acquire to further states objectives. US and China are considered advanced states in cyber realm, having cyber military technology and capabilities that are rarely matched by other contenders. Therefore, studying their way of cyber dealings, strategies and policy making would allow other countries such as Pakistan to better able to understand the dynamics and nature of this new type of warfare. India has tasked the Defence Cyber Agency (DCA), presently headed by a two-star Admiral which reports directly to Chairman of the Chiefs of Staff Committee (CCSC). DCA is presently undertaking to prepare a Cyber warfare doctrine for India. The repercussions of the developments are critical for Pakistan, which require a comprehensive safety and information guideline to be prepared for the masses. 

Zaeem Hassan Mehmood, is an alumnus of National Defence University, Islamabad. He is serving as Research Associate at National Centre for Maritime Policy Research (NCMPR)

Application of Cyber Security: A Comparative Analysis of Pakistan and India



In today’s world, communication is controlled by the internet. The Internet is what links the communication protocol of a state to its cyber domain. Cyber security encompasses techniques, technologies, methods and blueprints made to secure networking systems from potential cyber-attacks. Efficient systems of cyber security therefore mitigate and reduce the danger of network systems being attacked or accessed by unauthorized systems.

Despite the existence of such robust networks and security protocols, the exploit of such systems is always a click away, due to the integration of the internet as a worldwide network, and in times of global outbreaks and crisis, internet activity also inevitably increases. This was particularly observable with the spread of the Covid-19 as a global pandemic, which also saw an increase in over-the-web activity, and gave a new breathing space for cyber-criminals. According to estimates, Covid-19, as a pandemic, can already be classified as the largest ever existing threat to cyber-security across the globe, since the induction of the world wide web as a global chain of networks. Thus, it would be fair to say that the effects of the covid-19 were not selectively felt by developing states only, but also encapsulated great powers of the contemporary era.

While contextualizing Pakistan and India in the cyber-security debate following the events of the covid-19 scenario, the trend in increased virtual cyber-attacks and espionage was no different to the rest of the world. The real question mark lies in the ability of both countries to effectively deal with the overwhelming cyber-activity in the post-pandemic era. The government of Pakistan established the National Center for Cyber Security (NCCS) in June 2018, and continues to strengthen its cyber-security domain, with a dynamic change in policy making, centric to cybersecurity and threats to cybersecurity from its immediate adversary, India. The current Prime Minister of Pakistan, Mr. Imran Khan, also launched ‘Digital Pakistan Vision’, with the primary   objectives of  increasing connectivity, rectifying digital infrastructure, and investing in the awareness of digital skills and promotion of entrepreneurship. Pakistan also approved the first ‘Digital Pakistan Policy’, aiming to focus on investment opportunities by IT companies and building the framework necessary for a digital ecosystem. Although a sustained effort has been made to strengthen the cyber-domain of Pakistan, there are many technicalities and loopholes that must be addressed with high priority. One, the lack of an effective communication method, that is free from external intrusion, and allows for the restriction of unwanted network traffic on its master server. In more recent times, an intrusion occurred during the webinar of Institute of   Strategic Studies (ISSI) due to non-encrypted internet connection, which allowed unspecified individuals access to the digital webinar. Two, the lack of stable internet connectivity, which prevents effective implementation of security protocols and acts as a hindrance to critical data packets, that must be sent between cyber-security officials in an event of a cyber-attack or espionage of any degree. Three, the existence of exploitable source code in key governmental websites and pages that are always prone to cyber-attacks, and must be revisited in the near future.

On the other hand, India saw a 37% in cyber-activity in the wake of the covid-19 pandemic; an eye-opener for state officials, who have prioritized cybersecurity as the next immediate threat to Indian National Security. In recent developments, India has also launched several directives to its cyber-security strategy in the post-pandemic era, including the initiative launched by The Ministry of Electronics and Information Technology (MEITY), namely ‘Cyber Surakshit Bharat’ with the coordination and support of the  National E-Governance Division. According to MIETY, 44 training and mock drills are being given to 265 organizations from different states of the world, a landmark achievement in Indian cyber-security history. However, just like its South Asian neighbor Pakistan, India is also equally overwhelmed by the threat and emergence of hostile cyber-activity. With a 45% ratio of internal cyber attacks, and a 38% ratio of external intrusions from proposed adversaries, China and North Korea, India has strengthened its ties with Israel to revamp its cyber-security strategy,  in order to mitigate the immediate threat to its cyber-domain, both internally and externally.

Conclusion and Recommendations

There is an immediate need to extend and further research the cyber capabilities of both Pakistan and India, which would primarily define the different types of technologies and how they are being actively made a part of the National security policy of both Pakistan and India. These efforts must be the immediate need of the hour, with the uncertainty of the Covid-19 and its irregular patterns becoming an inevitable fate of regional and global politics, in the times to come. While India seems to have its primary bases covered, there is no denying that the Covid-19 pandemic did not have a sparing effect on its cyber-domain, either, leaving the door open for Pakistan to make significant improvements to its cyber domain and cyber-security strategy, in order to effectively deter the threat faced from its adversary. Moreover, Pakistan can also seek inspiration from a potential integrated tri-service defense cyber strategy, that is being highly considered by Indian cyber-security and state officials, which would aid in keeping any form of cyber-hostility at bay in upcoming times.

