Cybersecurity guide for developing countries
Notable events that contributed to the growing awareness of the threat of cybercrime – in addition to
the Y2K bug, which drew attention to the vulnerability of software and society’s dependence on
computers – include denial-of-service attacks such as those launched against Yahoo (on
10 February 2000) and the attack by the notorious “I love you” virus (4 May 2000). Since then, media
coverage of the virus attacks (such as the “Code red” virus in July 2001 or “Nimda” in September
2001) and denial-of-service attacks (such as that launched against the DNS network on 21 October
2002), among many other examples, has increased the general public’s awareness of the reality of
threats that operate through the internet. The news media continue to devote considerable space to
covering problems related to computers.
II.1.2
Factors that make the internet attractive for criminal elements
II.1.2.1
Virtualization and the virtual world
The uncoupling of transactions from physical media (virtualization), communication tools involving
encryption, steganography and anonymity: these are factors which criminals in different countries
exploit in order to collaborate while dispensing with physical meetings, operating in a flexible, secure
manner and with complete impunity. They can form teams, plan crimes and carry them out, whether in
the traditional manner or using new technologies. The global reach of the internet allows criminals to
act globally, on a large scale and very rapidly.
These powerful possibilities created by the digital world and telecommunication come on top of the
inherent problems associated with the design, implementation, management and control of information
technology, with its crashes, malfunctions, errors and human mistakes, and even natural disasters, as
well as the interdependence of infrastructures, all of which imply by definition a certain level of
insecurity in digital infrastructures.
The potential for malicious exploitation of vulnerabilities is thus very broad, translating in practice
into:
identity theft, spoofs, unauthorized access, fraudulent use of resources, infection, sabotage,
destruction, tampering, breach of confidentiality, data theft, blackmail, extortion, protection
rackets, denial of service, etc.
This clearly shows the inadequate control of computer-related risks of criminal origin to which
organizations are exposed, and the limits of current security strategies.
Cyberspace, which allows users to operate remotely via a network, hidden behind a screen, creates
ideal conditions for criminal activity. Indeed, some individuals may in fact stray across the boundary
into criminal activity without ever being fully conscious of the criminal nature of their acts.
II.1.2.2
Networking of resources
The wide-scale networking of computer and information resources makes them attractive targets for
economic crime using new technologies. The various forms of computer attack that exist have in
common the relatively low level of risk for the criminal, set against a potential for harm and damage
that greatly exceeds the resources necessary to launch an attack. Electronic identity theft, easy
anonymity and the possibilities for taking control of computers make it easy to carry out illegal acts
without exposing oneself to any great risk.
28
Cybercrime