Cyber-Crime



Cyber Crime
As Internet usage is growing daily the world is coming closer. The World Wide Web sounds like a vast phenomenon but surprisingly one of its qualities is bringing the world closer making it a smaller place to live in for its users. However, it has also managed to create another problem for people who spend long hours browsing the Cyber World – which is cyber crimes. While law enforcement agencies are trying to tackle this problem, it is growing steadily and many people have become victims of hacking, theft, identity theft and malicious software. One of the best ways to avoid being a victim of cyber crimes and protecting your sensitive information is by making use of impenetrable security that uses a unified system of software and hardware to authenticate any information that is sent or accessed over the Internet. However, before you can understand more about this system, let us find out more about cyber crimes.

Types of Cyber Crimes

When any crime is committed over the Internet it is referred to as a cyber crime. There are many types of cyber crimes and the most common ones are explained below:

Hacking: This is a type of crime wherein a person’s computer is broken into so that his personal or sensitive information can be accessed. In the United States, hacking is classified as a felony and punishable as such. This is different from ethical hacking, which many organizations use to check their Internet security protection. In hacking, the criminal uses a variety of software to enter a person’s computer and the person may not be aware that his computer is being accessed from a remote location.

Theft: This crime occurs when a person violates copyrights and downloads music, movies, games and software. There are even peer sharing websites which encourage software piracy and many of these websites are now being targeted by the FBI. Today, the justice system is addressing this cyber crime and there are laws that prevent people from illegal downloading.

Cyber Stalking: This is a kind of online harassment wherein the victim is subjected to a barrage of online messages and emails. Typically, these stalkers know their victims and instead of resorting to offline stalking, they use the Internet to stalk. However, if they notice that cyber stalking is not having the desired effect, they begin offline stalking along with cyber stalking to make the victims’ lives more miserable.

Identity Theft: This has become a major problem with people using the Internet for cash transactions and banking services. In this cyber crime, a criminal accesses data about a person’s bank account, credit cards, Social Security, debit card and other sensitive information to siphon money or to buy things online in the victim’s name. It can result in major financial losses for the victim and even spoil the victim’s credit history.

Malicious Software: These are Internet-based software or programs that are used to disrupt a network. The software is used to gain access to a system to steal sensitive information or data or causing damage to software present in the system.

Child soliciting and Abuse: This is also a type of cyber crime wherein criminals solicit minors via chat rooms for the purpose of child pornography. The FBI has been spending a lot of time monitoring chat rooms frequented by children with the hopes of reducing and preventing child abuse and soliciting.

Causes of Cyber Crime

Wherever the rate of return on investment is high and the risk is low, you are bound to find people willing to take advantage of the situation. This is exactly what happens in cyber crime. Accessing sensitive information and data and using it means a rich harvest of returns and catching such criminals is difficult. Hence, this has led to a rise in cyber crime across the world.

History of Cyber Crime

When computers and networks came into being in the 1990s, hacking was done basically to get more information about the systems. Hackers even competed against one another to win the tag of the best hacker. As a result, many networks were affected; right from the military to commercial organizations. Initially, these hacking attempts were brushed off as mere nuisance as they did not pose a long-term threat. However, with malicious software becoming ubiquitous during the same period, hacking started making networks and systems slow. As hackers became more skillful, they started using their knowledge and expertise to gain benefit by exploiting and victimizing others.

Cyber Crime in Modern Society

Today, criminals that indulge in cyber crimes are not driven by ego or expertise. Instead, they want to use their knowledge to gain benefits quickly. They are using their expertise to steal, deceive and exploit people as they find it easy to earn money without having to do an honest day’s work.

Cyber crimes have become a real threat today and are quite different from old-school crimes, such as robbing, mugging or stealing. Unlike these crimes, cyber crimes can be committed single handedly and does not require the physical presence of the criminals. The crimes can be committed from a remote location and the criminals need not worry about the law enforcement agencies in the country where they are committing crimes. The same systems that have made it easier for people to conduct e-commerce and online transactions are now being exploited by cyber criminals.

Categories of Cyber Crime

Cyber crimes are broadly categorized into three categories, namely crime against

Individual
Property
Government
Each category can use a variety of methods and the methods used vary from one criminal to another.

Individual: This type of cyber crime can be in the form of cyber stalking, distributing pornography, trafficking and “grooming”. Today, law enforcement agencies are taking this category of cyber crime very seriously and are joining forces internationally to reach and arrest the perpetrators.

Property: Just like in the real world where a criminal can steal and rob, even in the cyber world criminals resort to stealing and robbing. In this case, they can steal a person’s bank details and siphon off money; misuse the credit card to make numerous purchases online; run a scam to get naïve people to part with their hard earned money; use malicious software to gain access to an organization’s website or disrupt the systems of the organization. The malicious software can also damage software and hardware, just like vandals damage property in the offline world.

Government: Although not as common as the other two categories, crimes against a government are referred to as cyber terrorism. If successful, this category can wreak havoc and cause panic amongst the civilian population. In this category, criminals hack government websites, military websites or circulate propaganda. The perpetrators can be terrorist outfits or unfriendly governments of other nations.

How to Tackle Cyber Crime

It has been seen that most cyber criminals have a loose network wherein they collaborate and cooperate with one another. Unlike the real world, these criminals do not fight one another for supremacy or control. Instead they work together to improve their skills and even help out each other with new opportunities. Hence, the usual methods of fighting crime cannot be used against cyber criminals. While law enforcement agencies are trying to keep pace with cyber criminals, it is proving to be a Herculean task. This is primarily because the methods used by cyber criminals and technology keeps changing too quickly for law enforcement agencies to be effective. That is why commercial institutions and government organizations need to look at other methods of safeguarding themselves.

The best way to go about is using the solutions provided by Cross-Domain Solutions. When organizations use cross domain cyber security solutions, they can ensure that exchange of information adheres to security protocols. The solution allows organizations to use a unified system comprising of software and hardware that authenticates both manual and automatic transfer and access of information when it takes places between different security classification levels. This allows seamless sharing and access of information within a specific security classification, but cannot be intercepted by or advertently revealed to user who is not part of the security classification. This helps to keep the network and the systems using the network safe.

Cross Domain Solution offers a way to keep all information confidential by using safe and secure domains that cannot be tracked or accessed. This security solution can be used by commercial and governmental organization to ensure an impenetrable network while still making sure that users can get access to the required information easily.

Proudly powered by WordPress
Cross Domain Solutions
Ensuring Complete Data Security
Menu Skip to content
Elements of Cyber Security
The vulnerability of human interactions with the information systems can be easily exploited to launch a scathing cyber attack. A better understanding of the elements of cyber security will cause the information managers to get over their misguided sense of invincibility and plug the loopholes bringing about a malicious attack.

Application Security

Application security embraces steps taken through an information application’s lifecycle to thwart any attempts to transgress the authorization limits set by the security policies of the underlying system. The security protocols set right the exceptions in the systems that are inherently flawed owing to design, development, and deployment, up-gradation or maintenance of the application.

Applications are only concerned with controlling the utilization of resources given to them. The specific use of resources is determined through the application users via application security.

The methodology to tackle threats to application security involves knowing about the potential threats, adequately enhancing the security of the application, network or host, and embedding security within the software development process.

In the context of application security, an asset refers to a resource of value like information within a database or in the file system or system resource. The challenge is to identify the vulnerabilities within the parent system which when becomes exposed to the cyber attacker can be exploited to provide valuable insights into the functioning of the application. The risk can be mitigated by weaving security within the application.

Common application threats and attack types are enumerated below.

Input validation related like cross site coding, buffer overflow, canonicalization, SQL injection and buffer overflow.
Authentication related like brute force assault, network eavesdropping, replaying cookies, dictionary assaults, stealing credentials etc.
Authorization related like intentional revelation of sensitive information, tampering with critical data, privilege elevation, inviting attacks etc.
Configuration management related like illegitimate access to administration controls, illegitimate entry to configuration stores, and absence of user accountability, higher-privilege service and procedural accounts, retrieving clear text configuration information.
Sensitive information related like attempting to enter storage area for accessing critical data, eavesdropping network lines and tapering with data.
Session management related like hijacking session, replaying session, man in the middle etc.
Cryptography related like poor public/private key generation/ key management, weak encryption.
Parameter manipulation related like query manipulating query string, form field, cookie or HTTP header.
Exception management related like denial of service, information disclosure.
Auditing and logging related like denial by user to perform an operation, exploitation of an application by attacker and covering up the trail.
Information Security

Information security involves safeguarding sensitive information from illegitimate access, usage, revelation, disruption, alteration, reading, inspection, damage or recording. This is an assurance that critical data is not lost when any issue like natural disasters, malfunction of system, theft or other potentially damaging situation arises.

The attributes defining security are confidentiality, integrity and availability. The information systems are a conglomerate of hardware, software and communications. The motive is identifying and applying information security pertaining to protection and prevention mechanisms at the three levels. The procedures developed serve as guidelines for administrators, users and operators to adhere to safe usage practices for heightened security.

Data confidentiality relates to thwarting the willful or inadvertent information disclosure to illegitimate systems or individuals. Confidentiality is enforced through encryption of critical information during transmission over fragile communication channel vulnerable to eavesdropping. The places where information will be visible are limited like databases, log files, backups, printed receipts etc. and by imposing restrictions on the information storage area. It prevents security breach which can lead to disclosure of private information from a safe system.

Data integrity refers to maintenance and assurance of the reliability, consistency and accuracy of classified data throughout its life. This implies preventing undetected or unauthorized modification of data either in storage or while in transit.

Data availability means information is available for use when required by authorized services and users. This calls for proper functioning of systems employed for storing and processing information, security controls used for protecting information, and the network channels used for accessing it. The system should be available round the clock by not allowing service disruptions owing to power failures, hardware glitches and system upgrades. This also applies in deterring denial of service attacks.

Authenticity implies genuineness of the information, transactions, communications or documents. It involves checking the credentials of the users going to transact with the system. Non-repudiation means that the parties involved in a transaction cannot deny their role with data transmission or reception.

Risks that hold the potential of damaging the information system are assessed and necessary mitigation steps are taken.

Network Security

Network security refers to comprehensive security policies and provisions adopted in an adaptive and proactive manner by the network administrator for thwarting and monitoring unauthorized access, deliberate misuse, alteration, denial of service for a computer host and other network accessible and interaction related resources. It involves checking the privilege rights of users to validate the legitimacy of users and grant them access to network’s data or allow for exchange of information. Users are allotted ID and password or other form of authentication checks to demarcate their authority and consequent usage of authorized domain.

Network security extends coverage over diverse computer networks, encompassing private and public that is used for transacting and communicating among organizations.

Security procedure starts with user authentication; one, two, or three factors based. One factor implies password validation, while two means password coupled with security dongle, token, card or mobile phone; and three implies retinal scan or fingerprint coupled with aforesaid two.

Once the authentication has been completed, a network firewall imposes access policies like what services can be accessed by network users. Antivirus application and intrusion prevention system assists in detecting and inhibiting the potentially malicious content passed along over the network like Trojans and worms. An anomaly-based intrusion detection system may be employed for monitoring the network traffic for suspicious or unexpected content or behavior. This will help in averting situations like denial of service attacks or a disgruntled employ tampering with the files, thus protecting the resources. Individual events happening within the network can be logged for auditing or high level scrutiny later on.

The communication occurring among network hosts can be encrypted to avoid eavesdropping. Deployment of decoy network accessible resources will serve as surveillance and early warning measures. Techniques employed by attackers for compromising the decoy resources can be studied post attack to understand their logic behind development of new exploitation means.

The common types of attacks confronted by networks include passive ones like idle scan, port scanner, wiretapping; or active like DDOS attack, spoofing, ARP poisoning, smurf attack, buffer or heap overflow, format string attack and SQL injection.

Disaster Recovery/ Business Continuity Planning

Business continuity is the process of summoning into action planned and managed procedures which enable an organization to carry out the operation of its critical business units, while a planned or unintentional disruption hampering regular business operations is in effect. Once a cyber attack has brought the business to a standstill by crippling the information systems, this disaster recovery planning plays a vital role in keeping critical parts ticking to make the business survive. The planning assists in bringing down the recovery cost and operational overheads.

The key aspects defined below should be intensely focused upon for creating effective business continuity plans that will allow businesses to sail through difficult times effortlessly.

In the event of a disaster striking the information system, what are the primary areas where attention should be committed? Should the authorized users be called upon to ensure their safety or the bank or e-payment gateways are approached to ascertain that the business capital is safe? The emergency response fleet should be adequately prepared to tackle the disaster and the Crisis Management team should start doing its bit.
Which areas of the business should be focused on first for recovery? Should this be the segment which serves as the cash cow or should it be the one where the bulk of capital has been directed to? Which part of the information system is vital for sustained future growth? The identified segment should be the business unit that is the most critical.
What should be the logical time frame within which the recovery of critical information units should be started? The answer to this question will require calculating the quantum of cost involved in recovering from a disruption.
What resources and infrastructures would be required to bring about an effective IT recovery? One should critically consider the relative importance of each contributing aspect. This will help in gaining clarity on the cost involved. The onus of driving business continuity rests on the shoulders of business leaders.
What would be the most strategic point to conduct business recovery? Will the business center have adequate space or would it be overwhelmed with other disaster stricken people?
Once the disaster recovery plan has been pressed into service and the production has been started in reduced capacity, assessment has to be conducted to determine the life of such operations in the non-availability of major operational sites. Careful assessment should be done to understand the resilience of business.
The disaster recovery plan should be tested at least once every year to ascertain that the plan yields the desirable results, should a business recovery is mandated. The plan can be reviewed for sufficiency and necessary rewrites/ updates can be implemented.
A business continuity plan takes a comprehensive approach to deal with enterprise wide disaster effects. A disaster recovery plan inherently is a subset of business continuity and directs its focus on taking relevant steps to get the normal business operations resumed at the earliest. The execution of disaster recovery plan takes place hot on the heels of disaster. It carries in detail the list of steps that are to be executed for effective recovery of sensitive information technology infrastructure. Disaster recovery planning leads to the formation of a planning group to carry out risk assessment, prioritize jobs, develop recovery tactics, prepare inventories and get the plan documented. The implementation of the plan is preceded by development of verification criteria and auditing procedure.

End User Education

The human element in cyber security is the weakest link that has to be adequately trained to make less vulnerable. Comprehensive security policies, procedures and protocols have to be understood in depth by users who regularly interact with the highly secure system and accessing classified information. Periodic end user education and reviews are imperative to highlight the organizational weaknesses, system vulnerabilities and security loopholes to the user. Sound security behavior of users should take precedence over other aspects.

It has been observed that training imparted randomly or at high-level prove to be less productive than frequent, granular training and exercises that have been custom made to tackle specific behavioral patterns and practices of users. Senior leaders should compulsorily participate in training events for demonstrating the importance of responsible security behavior to better gear up to tackle the challenge of cyber-attacks.

Strong cyber security programs believe in leveraging a combination of technological and human elements. Organizations should exhibit keen interest in investing in areas of human based security apart from technological infrastructure. Substantial benefits can be drawn by providing greater transparency and exhibiting willingness to embrace newer techniques by users.

The training should be based on research conducted for identification of the behaviors and motivations of users at different levels of information security. Better human element protocols in the security chain can be established by gaining insights into the viewpoints of users regarding technology and response to security threats. Training sessions will lead to further research in the region of human machine interactions.

Cyber crimes are increasingly becoming social engineering, wherein perpetrators of the crime invest resources to gain knowledge about organizational stakeholders. Training will allow senior management to familiarize themselves with system users that will help to better nurture awareness regarding user specific access privileges and internal sources capable of providing access to confidential information. User training will help eliminate resistance to change and lead to closer user scruting.

Comments

Popular posts from this blog

by vineet