Total Pageviews

December 15, 2010

X - Cyber crimes – issues, problems and perspectives

Defining and Publicizing the Problem
  • Articulate the seriousness of various forms of cyber crime, both in the public mind and in the criminal law, so that the harmful impact of computer and Internet abuse is clear.
  • Partner in society-wide efforts to develop a body of ethics around computer and Internet use to be incorporated into education and workplace management.
  • Share information with system owners on ways to prevent cyber crime, including protection against invaders.
Increasing Resources to Fight Cyber Crime 
  • Assign top government priority to the prevention and prosecution of cyber crime and increase budgets devoted to the issue.
  • Increase the number of graduates with expertise in computer and Internet security by developing security curriculums in universities and providing adequate budgets to fund teaching faculty.
  • Upgrade skills of criminal-justice professionals by providing them with training in the detection, investigation and prosecution of cyber crime.
  • Develop the knowledge base with regards to cyber crime through additional financial and human resources devoted to research in network security.
  • Set up computer crime investigation squads staffed with professionals trained in investigating and tracking cyber criminals, and provide them with the advanced technology necessary to pursue their activities.
  • Set up mechanisms to ensure efficient coordination, cooperation and information sharing among governments, law-enforcement agencies, and the private sector regarding attacks, threats, vulnerabilities and the development and application of solutions  
 Retooling the Criminal Law
  • Update national and regional criminal-law regimes to include cyber crime.
  • Ensure penalties available are appropriate to the crime.
  • Recognize electronic information as an asset that is uniquely vulnerable.
  • International Cooperation
  • Develop international initiatives to trace the origins of viruses and other cyber crimes.
  • Develop frameworks for allowing expeditious cross-border access to electronic data-storage banks in order to discover and secure evidence.
  • Develop treaties and protocols for extradition and co-operative prosecution of perpetrators of cyber crime.
  • Develop internationally accepted definitions of cyber crime and harmonize international laws.
As a conclusion it can be said that Information technology is an asset to the man kind and it is unfortunate that so many crimes are being committed with the help of this technology. It can be safely said that if all concerned that is the users, the companies and the government act in unison this sort of crime can be avoided. Cyber crime respects no borders and it is time that the world community and its leaders present a unified face and determination in solving this menace which if unchecked might endanger our planet.

December 14, 2010

IX - Cyber crimes – issues, problems and perspectives

At the same time, it is important to recognize that even with the development and adoption of inoculating tools, systems may still be vulnerable to attack.  As a result, law-enforcement agencies must be provided with the financial and human resources they need to effectively investigate, track and prosecute cyber offenders. Furthermore, governments must ensure that legal systems, including the courts, also appreciate the impact of cyber crime and are empowered to effectively deal with Internet-related offenses.  It is important that the sanctions imposed reflect the impact and importance of the offense, while at the same time are flexible and reflect the proper social context.  For minor offenses, jail terms and fines need not be the only form of retribution considered.  
A Shared Commitment:  A shared commitment is fundamental to controlling cyber crime.  All of society must work together to find solutions and identify ways of dealing with the threat of cyber crime. While the private sector can certainly maximize its efforts to improve network security and the justice and law enforcement systems can be empowered with effective means to investigate and prosecute attackers, neither can meet the challenge of cyber crime alone.
As indicated above, both the private and public sectors need to commit significant resources to develop the existing knowledge base on network security, through increased research funding and the training of new specialists in the field.  They also need to take part in open discussions on security failings and work together to devise responses to incidents and address the weak links in network defence.  A regular dialogue including government officials, law enforcement agencies along with creators and users of computer and Internet technologies would allow each to keep abreast of the latest information on threats, vulnerabilities and attacks and the measures developed to fight them. 
All ICT players should recognizes that there is a price to pay for security on the Internet.  Because secure networks also translate into more anonymity for criminals, less traceability of messages, difficulties in monitoring communications.  But, as we police and protect cyberspace, privacy is a value not to be lost.  We must work to ensure society can confront cyber crime without jeopardizing the very values that are fundamental to the continued development and growth of the Internet. 
IX. A possible strategy for action:
Concerted efforts are needed to meet the challenge of cyber crime.  Cooperation between the private and public sectors, both nationally and internationally, is essential to creating and protecting a secure international information community. All members should be prepared to take action in the following areas, in partnership with national governments and intergovernmental bodies

December 13, 2010

VIII - Cyber crimes – issues, problems and perspectives

Government action and international treaties aiming to harmonize laws and coordinate legal procedures are key in the fight against cyber crime, but warns that these should not be relied upon as the only instruments able to meet the challenge of combatting online offenders should be recognized. Cyber crime is a technology-created problem and it requires a healthy reliance on technology-based solutions.

VII. The Role of Industry

 The ICT (Information Computing and Technology) industry must be at the forefront of efforts to combat cyber crime.  It is at the leading edge of innovation, providing technology and solutions to fight cyber attacks, and has a unique role to play as a leader, advocate and partner
All industry members should also be committed to participate in the development of codes of behaviour and ethics around computer and Internet use, and in campaigns for the need for ethical and responsible online behaviour.  Given the international reach of Internet crime, computer and Internet users around the world must be made aware of the need for high standards of conduct in cyberspace. 
Computer operators have an important role to play in protecting their systems against cyber attacks.  They have a duty to act responsibly, to assign top priority and adequate resources to systems defence, and to adopt available technologies and solutions to protect their systems against invasions.  As more and more attacks are perpetrated through the use of unwitting third-party systems, operators must make their own systems secure to ensure that they are not used as instruments in attacks on others.
The ICT industry can also play a key role in preventing cyber crime by making every effort to address weaknesses in network defences, to ensure that their products and services are secure, and by helping to raise awareness with regards to the importance of systems protection.  Just as automobile manufacturers provide maintenance instructions to ensure the safety of vehicles, ICT companies should provide their clients with the information they require to continually protect their systems and data. 
In addition, ICT companies should, when security vulnerabilities are reported with regards to particular technologies or online services, alert their customers and provide them with the patches required to remedy the problem.  It is believed that in the future, the ability to provide secure systems and transactions will represent a significant competitive advantage.  Success and growth in the new economy will accrue to those companies that are able to provide this assurance. 

VIII. The Role of Government

Various initiatives have been proposed by governments to protect data networks from intruders.  Among the options put forward has been the establishment of systems that monitor Internet traffic.  While these would certainly be effective at preventing some attacks and would undoubtedly increase the likelihood of identifying the source of intrusions, it is virtually impossible to police all of cyber space, and the risk to personal privacy is in any case too high. Maximum emphasis should instead be put on establishing effective protective measures.

December 12, 2010

VII - Cyber crimes – issues, problems and perspectives

Fighting cyber criminals is extremely costly and time consuming.  New technologies, new software and new hacking programs are continuously being developed, so keeping up with the ongoing innovations of the hacker underground requires significant resources.  Not only is research funding in the area of network security insufficient to allow for the knowledge-base to grow as much as it needs to, but there is also an insufficient number of individuals with the skills to develop new security tools and solutions.  Few colleges and universities provide in-depth training in computer security and those that provide the curriculum are forced to compete with the private sector for the services of qualified graduates.
Perhaps the most serious challenge faced by investigators is the difficulty of tracing the origin of attacks.  It is easy to maintain anonymity on the Internet and computer invaders are experts at camouflaging and falsifying their identity. And, as attacks are often perpetrated using several computers located in a number of different jurisdictions, tracking and pursuing offenders is a daunting task.  Because cyber crime often crosses geographic borders, governments are faced with the additional challenge of investigating attacks and pursuing perpetrators in jurisdictions where laws may not punish the attack with the same severity. 
Indeed, laws on cyber crime can vary widely from one jurisdiction to another.  Even in countries where the legal system recognizes cyber crime as an offence, penalties imposed can be uneven and may not serve as an effective deterrent.  As a result, some countries may well become “safe-havens” for offenses and export them around the world via the Internet. 

VI. Fighting cyber crime -  International Cooperation

Cyber crime respects no national boundaries. Infected programs originating in one country can target and paralyze systems all over the world.  Not surprisingly, initiatives for combating cyber crime rely largely on international treaties and conventions. 
All concerned should acknowledges the importance of international cooperation in the prevention, investigation and prosecution of cyber crime and it recognizes the need for harmonization of laws so that no country can become a safe haven for cyber criminals.  However, in a world where cyber viruses can be propagated worldwide in a matter of hours, the months and years required to draft, debate, adopt and implement international principles and action plans represent a significant impediment to effective action.  Cyberspace crime calls for a response mechanism which is just as swift and efficient at reaching its target as perpetrators are at reaching their own
An additional concern is that countries, in their push to design solutions to the cyber crime issue, may well implement decisions and laws that could encroach on individuals’ rights to anonymity and privacy on the Internet.  More importantly, they may also criminalize the exchange of information, along with the research, testing and reverse engineering activities that are vital to the continued development of tools that detect security weaknesses and that inoculate against viruses and other cyber-attack programs.

December 11, 2010

VI - Cyber crimes – issues, problems and perspectives

Professional hackers (corporate espionage): The corporate world is heavily dependent upon computers for storing sensitive information. Rival organizations employ hackers to steal industrial secrets and other information that could be beneficial to them.
The temptation to use professional hackers for industrial espionage also stems from the fact that physical presence required to gain access to important documents is rendered needless if hacking can retrieve those.

IV. Continuing Problems

Even when the source(s) of the attack/s are traced there are many problems, which the victim may be faced with. He will need to inform all the involved organizations in control of the attacking computers and ask them to either clean the systems or shut them down. Across international boundaries this may prove to be a titanic task. The staff of the organization may not understand the language. They may not be present if the attack were to be launched during the night or during weekends. 
The computers that may have to be shut down may be vital for their processes and the staff may not have the authority to shut them down. The staff may not understand the attack, system administration, network topology, or any number of things that may delay or halt shutting down the attacking computer(s). Or, more simply, the organization may not have the desire to help.
If there are hundreds or even thousands of computers on the attack, with problems like the ones mentioned above, the victim may not be able to stop the attack for days by which time the damage would have been done. His servers would be completely incapacitated to administer to so many demands and consequently would crash.
These tools also provide another service by which the attacking computer can change its source address randomly thereby making it seem as if the attack is originating from many thousands of computers while in reality there may be only a few.

V. Need for a law to control cyber crime

  • Cyber crime is transnational, and requires a transnational response.
  • Cyber criminals exploit weaknesses in the laws and enforcement practices of States, exposing all other States to dangers that are beyond their capacity unilaterally or bilaterally to respond.
  • The speed and technical complexity of cyber activities requires prearranged, agreed procedures for cooperation in investigating and responding to threats and attacks.
What needs to be done
  • adopt laws making dangerous cyber activities criminal;
  • enforce those laws or extradite criminals for prosecution by other States;
  • cooperate in investigating criminal activities and in providing usable evidence for prosecutions; and
  • participate in formulating and agree to adopt and implement standards and practices that enhance safety and security.