Cybersecurity guide for developing countries
II.1.2.3
Proliferation of hacks and vulnerabilities
The widespread availability of “hacks”, which exploit system vulnerabilities, and libraries of attacks
and software that build on criminal know-how, make the task of carrying out a computer attack easier.
This, combined with the possibility of virtual action, encourages computer experts with criminal
tendencies and criminals with computer skills to turn their expertise to a malicious use. In some cases,
cyberspace eases the transition to a criminal act almost unawares.
II.1.2.4
Faults and vulnerabilities
Criminals exploit organizational and technical faults and vulnerabilities of the internet, the absence of
a harmonized legal framework between countries, and the lack of effective coordination between
national law-enforcement agencies. This may involve traditional forms of criminality (traditional
crimes committed with new technologies: money-laundering, blackmail, extortion, etc.) or new types
of crime based on digital technologies: system intrusion, theft of processor time, theft of source codes,
databases, etc. The environment, in all of those cases, is exceptionally conducive: minimum risks,
wide coverage, lucrative profits.
Figure II.2 summarizes the sources of the vulnerabilities of the internet infrastructure.
Figure II.2 – Principal characteristics of the internet exploited for criminal purposes
Internet technology aspects
System aspects
– public, open technology
– version history
– security mechanisms not built-in
– best-effort technology design
– availability of tools for network administration,
traffic analysis, audit and encryption
– availability of attack tools
– configuration laxness
– attractive systems (targets)
– management deficiencies
– piecemeal approach to security
Characteristics of the legal system
– multiple jurisdiction
– digital safe havens
Internet
Characteristics of the cyberworld
– intangible
– virtual
– trend to cyber-everything
Network aspects
– extended connectivity
– component growth and distribution
– no overall control
– inadequate performance
User aspects
– different categories
– large and growing number
– varying levels of training and expertise
– unpredictable
– unsuitable behaviour
– uncertain ethical integrity
– inadequate use of security tools
– poor security management
Cybercrime
29