Cybersecurity guide for developing countries II.1.2.5 Unmasking cybercriminals Computer-related crime is sophisticated, and is usually committed across national borders, frequently with a time delay. The traces it leaves in the systems are intangible and difficult to gather and save. They take the form of digital information stored on all sorts of media: working memory, storage peripherals, hard discs, external discs and USB sticks, electronic components, etc. The problem is how to capture the wide variety of evidence turned up in a digital search. The following questions illustrate the extent to which the concept of digital evidence remains elusive: – How to identify the relevant data? – How to trace them? – How to store them? – What are the judicial rules of evidence? – How to recover files that have been deleted? – How to prove the origin of a message? – How to establish the identity of a person on the basis of only a digital trace, in view of the difficulties of reliably linking digital information with its physical author (virtualization) and the proliferation of identity theft? – How to establish the conclusiveness of digital evidence in establishing the truth before a court (concept of digital evidence), knowing that the storage media from which the evidence has been recovered are not infallible (date-time information being treated differently from one computer system to another, and subject to tampering)? – etc. Digital evidence is even more difficult to obtain when it is scattered across systems located in different countries. In such cases, success depends entirely on the effectiveness of international cooperation between legal authorities and the speed with which action is taken. Effective use of such evidence to identify individuals depends on the speed with which requests are treated: if treatment is slow, identification is next to impossible. Figure II.3 shows the different types of problems caused by malicious acts such as physical destruction or theft of equipment, preventing access to systems and data, infection of resources, compromised decision-making or communication processes through denial-of-service attacks (or as the result of espionage or intrusion into the systems), information theft and tampering (manipulation of opinion, info-war). It also outlines the main characteristics of cybercrime that make it difficulty to identify the criminals. Furthermore, in most countries there is a significant mismatch between the skills of the criminals who commit high-technology crimes and the resources available to the law-enforcement and justice authorities to prosecute them. The use of computer technologies by those authorities, whether at the national or international level, remains weak and varies greatly from one country to another. In most cases, the police and judicial authorities rely on conventional investigation methods used for ordinary crime to prosecute cybercriminals so as to identify and arrest them. 30 Cybercrime

Select target paragraph3