AI is transforming cyber attacks as well as defences: What this means for India, Pg9

AI's rapid adoption amplifies sophisticated cyber threats, challenging India's defenses and critical infrastructure, necessitating robust policy and indigenous AI capabilities.

Practice MCQs

767 Students attempted
Attempt Now

Key Highlights:

  • Artificial Intelligence (AI) has rapidly advanced, significantly amplifying cyber threats in terms of speed, scale, and sophistication.
  • AI enables new attack vectors such as autonomous cyber agents, LLM-generated polymorphic malware, and the discovery of zero-day vulnerabilities.
  • India is identified as one of the most cyber-attacked nations globally, with threats from state-sponsored groups like APT36.
  • India's indigenous AI ecosystem lags behind leading countries, creating a dependency on foreign technology for advanced cyber defense.
  • The Indian Computer Emergency Response Team (CERT-In) has adopted AI-driven threat detection, and the Ministry of Electronics and Information Technology (MeitY) is developing new AI governance frameworks.
Cyberthreat.jpg

Cyberthreat.jpg

Detailed Insights:

  • AI has automated reconnaissance and enabled the creation of AI-generated deepfakes and sophisticated phishing emails.
  • Anthropic reported that a Chinese state-sponsored group, G7G-1002, allegedly used Claude Code as an autonomous cyber agent in a cyber-espionage campaign.
  • Frontier AI models, such as Claude Mythos Preview, have demonstrated the ability to autonomously identify thousands of zero-day vulnerabilities in critical operating systems.
  • These vulnerabilities pose significant risks to Operational Technology (OT) and Industrial Control Systems (ICS) that manage critical infrastructure like energy grids and nuclear facilities.
  • Traditional antivirus and static security patches are becoming ineffective against constantly evolving AI-generated polymorphic malware.
  • The ransomware group World Leaks reportedly stole data related to India's Kudankulam nuclear plant.
  • Operation Sindoor involved Pakistan-backed threat actors targeting India's defense sectors, including the Ministry of Defence and Bharat Operating System Solutions (BOSS) Linux.
  • India's AI ecosystem requires significant development across foundational models, GPUs, chip design, and large-scale data-center infrastructure.
  • CERT-In advises organizations to remove unnecessary internet-facing services and treat newly discovered vulnerabilities as immediate threats.
  • MeitY is exploring a consent-based framework for synthetically generated content and clearer liability frameworks for AI models.

Key Concepts Involved:

  • Artificial Intelligence (AI): The simulation of human intelligence processes by machines, especially computer systems.
  • Cyber Kill Chain: A framework outlining the stages of a cyberattack, from initial reconnaissance to the final objective.
  • Zero-day Vulnerability: A software flaw unknown to the vendor, for which no patch exists, making it highly exploitable.
  • Polymorphic Malware: Malicious code that constantly changes its identifiable features to evade detection by antivirus software.
  • Deepfake: Synthetic media in which a person in an existing image or video is replaced with someone else's likeness.
  • Operational Technology (OT): Hardware and software that monitors and controls physical processes, devices, and infrastructure.
  • Industrial Control Systems (ICS): Systems used to control industrial processes, including SCADA and Distributed Control Systems (DCS).
  • CERT-In: The national agency responsible for responding to computer security incidents in India.
  • Ministry of Electronics and Information Technology (MeitY): The Indian government ministry responsible for IT policy, strategy, and development.
SuperKalam
SuperKalam is your personal mentor for UPSC preparation, guiding you at every step of the exam journey.

Download the App

Get it on Google PlayDownload on the App Store
Follow us

ⓒ Snapstack Technologies Private Limited