The goal of this paper is to advance efforts to improve cybercrime metrics, measures of the scale and impact of cybercrime that are widely considered to be an essential part of any comprehensive enforcement strategy against cybercriminals. Enforcing laws to protect citizens and their property against harms caused by criminal behavior is a basic function of modern society. Measuring the scale and impact of criminal activity has long been an essential part of that function. “[A]ccurate and valid data and research information on both crime and victimization are critical for an understanding of crime. . . and for any assessment of the quality of the activities and programs of the criminal justice system.” When it comes to tackling criminal activity involving or targeting computers, the importance of metrics to crime deterrence are critical and obvious. As reflected in this observation from 15 years ago: “[u]ntil there are accepted measures and benchmarks for the incidence and damage caused by computer-related crime, it will remain a guess whether we are spending enough resources to investigate or protect against such crimes. . . In short, metrics matter.” Given that many countries have well-established procedures for producing official government reports on the incidence of traditional or meatspace crime; there would appear to be a “cybercrime metrics gap,” a global shortage of official data on crimes committed in cyberspace. However, this apparent “cybercrime metrics gap” is an illusion. Even the most affluent of nations have not yet managed to consistently generate acceptable statistics about any crimes, cyber or noncyber, where acceptable means the level of accuracy, detail, completeness, and timeliness required to satisfy the needs of those who shape, make, and enforce the law. While a deficiency in crime metrics clearly hampers enforcement efforts
This paper addresses a number of increasingly urgent questions about the defence of information systems against criminal hackers, the fi rst of which is this: can the world produce enough appropriately skilled human defenders of digital systems to defeat the humans who seek to compromise such systems for nefarious purposes? Multiple studies suggest that a signifi cant ‘cybersecurity skills gap’ currently exists and is hampering efforts to defend information systems against criminal hackers. Based on this assumption, many countries are scrambling to increase the supply of cyber-skilled humans capable of making a worthwhile contribution to the defence of the digital infrastructure on which so many economies now depend. Massive education and recruitment efforts are being funded in numerous countries to attract more people to the profession. The success of these efforts is predicated on the assumption there will be an adequate supply of willing entrants who possess the necessary traits and abilities to become effective cybersecurity professionals. In other words, it is assumed that a wide range of people can be trained to become effective cybersecurity professionals, and that enough of them will want to do so. In questioning that assumption, this paper provides a critical review of existing efforts to assess cyber-aptitude and ability, and considers the results of a number of experimental fast-track cybersecurity training programmes. The challenge of recruiting and retaining participants in a profession that can be both highly demanding and lacking in some traditional forms of job satisfaction is also discussed. To address the problems raised, the paper presents several positive scenarios for consideration in the areas of technology, economics and governance.
The allure of malware, with its tremendous potential to infiltrate and disrupt digital systems, is understandable. Criminally motivated malware is now directed at all levels and corners of the cyber domain, from servers to endpoints, laptops, smartphones, tablets, and industrial control systems. A thriving underground industry today produces ever-increasing quantities of malware for a wide variety of platforms, which bad actors seem able to deploy with relative impunity. The urge to fight back with "good" malware is understandable. In this paper we review and assess the arguments for and against the use of malicious code for either active defense or direct offense. Our practical experiences analyzing and defending against malicious code suggest that the effect of deployment is hard to predict with accuracy. There is tremendous scope for unintended consequences and loss of control over the code itself. Criminals do not feel restrained by these factors and appear undeterred by moral dilemmas like collateral damage, but we argue that persons or entities considering the use of malware for "justifiable offense" or active defense need to fully understand the issues around scope, targeting, control, blowback, and arming the adversary. Using existing open source literature and commentary on this topic we review the arguments for and against the use of "malicious" code for "righteous" purposes, introducing the term "righteous malware". We will cite select instances of prior malicious code deployment to reveal lessons learned for future missions. In the process, we will refer to a range of techniques employed by criminally-motivated malware authors to evade detection, amplify infection, leverage investment, and execute objectives that range from denial of service to information stealing, fraudulent, revenue generation, blackmail and surveillance. Examples of failure to retain control of criminally motivated malicious code development will also be examined for what they may tell us about code persistence and life cycles. In closing, we will present our considered opinions on the risks of weaponizing code.
Chapter 15 Penetrating Computer Systems and Networks Chey Cobb, Chey CobbSearch for more papers by this authorStephen Cobb, Stephen CobbSearch for more papers by this authorM. E. Kabay, M. E. KabaySearch for more papers by this authorTim Crothers, Tim CrothersSearch for more papers by this author Chey Cobb, Chey CobbSearch for more papers by this authorStephen Cobb, Stephen CobbSearch for more papers by this authorM. E. Kabay, M. E. KabaySearch for more papers by this authorTim Crothers, Tim CrothersSearch for more papers by this author Book Editor(s):Seymour Bosworth, Seymour BosworthSearch for more papers by this authorMichel E. Kabay, Michel E. KabaySearch for more papers by this authorEric Whyne, Eric WhyneSearch for more papers by this author First published: 02 January 2012 https://doi.org/10.1002/9781118851678.ch15 AboutPDFPDF ToolsRequest permissionExport citationAdd to favoritesTrack citation ShareShareShare a linkShare onFacebookTwitterLinked InRedditWechat Summary This chapter discusses different aspects of penetration of computer systems and networks. Both technical and nontechnical aspects come into play when people attempt to penetrate security systems. Penetration of information systems is possible by means of a wide range of methods, some of which are very hard to defend against. People responsible for securing systems have to defend against this wide range of penetration methods. The cheapest and most effective attacks are often nontechnical, exploiting human frailty rather than weaknesses in the technology. Experienced criminal hackers tend to favor the nontechnical attack over the technical; and the best defense, employee awareness, is also nontechnical. Systems can be attacked at the client, at the server, or at the connection between the two. This chapter looks at methods of tricking people into allowing unauthorized access to systems. It also examines technical measures for overcoming security barriers and specific techniques for penetration, and describes legal and political aspects of system penetration. Computer Security Handbook, Sixth Edition RelatedInformation
Chapter 4 Hardware Elements of Security Sy Bosworth, Sy BosworthSearch for more papers by this authorStephen Cobb, Stephen CobbSearch for more papers by this author Sy Bosworth, Sy BosworthSearch for more papers by this authorStephen Cobb, Stephen CobbSearch for more papers by this author Book Editor(s):Seymour Bosworth, Seymour BosworthSearch for more papers by this authorMichel E. Kabay, Michel E. KabaySearch for more papers by this authorEric Whyne, Eric WhyneSearch for more papers by this author First published: 02 January 2012 https://doi.org/10.1002/9781118851678.ch4 AboutPDFPDF ToolsRequest permissionExport citationAdd to favoritesTrack citation ShareShareShare a linkShare onFacebookTwitterLinked InRedditWechat Summary This chapter presents an overview of the hardware elements of computer security. Computer hardware has always played a major role in computer security. Over the years, that role has increased dramatically, due to both the increases in processing power, storage capacity, and communications capabilities as well as the decreases in cost and size of components. The ubiquity of cheap, powerful, highly connected computing devices poses significant challenges to computer security. At the same time, the challenges posed by large, centralized computing systems have not diminished. An understanding of the hardware elements of computing is thus essential to a well-rounded understanding of computer security. This chapter deals with the means by which hardware elements of a data processing system affect the security and integrity of its operations. Concepts related to binary design, parity, hardware operations, interrupts, memory and data storage are discussed. An overview of data communications and cryptography is also presented. Computer Security Handbook, Sixth Edition RelatedInformation
From the Publisher:With the strategies contained in this practical guide, you'll rest easier knowing that your vital personal computer equipment and data are protected against loss. Covering stand-alone and networked environments, this accessible book/disk package describes a variety of low-cost solutions you can use to shield your data from viruses, hackers, vandals, competitors, industrial spies, disgruntled or careless employees, power failures, floods, and other calamities. Get started right away with the collection of helpful security utilities included on the accompanying disk. Sponsored by the National Computer Security Association, this handbook helps you assess your exposure to data loss and provides workable solutions you can implement quickly and inexpensively. You'll learn how to create a secure environment through careful planning, commonsense precautions, and user training - reducing the need to invest in costly specialized products. You'll find up-to-the-minute coverage of security issues relating to the Internet, bulletin boards, and online services, as well as a comprehensive examination of networks. Special World Wide Web links give you access to the latest developments in security resources. Disk contains valuable security utilities and a hypertext security product buyer's guide.