Cybersecurity guide for developing countries It is entirely legitimate to ask whether the breakdown of the internet, or a portion of it, as a result of malicious acts, might not sow terror within the community of web users, some groups of economic players, and the general public. Or, in the main, we may be dealing with instances of economic terrorism, aimed at damaging organizations that use the internet for their activities. The term cyberterrorism, which has come into vogue since the September 11 attacks, should be used with discretion. It should not be forgotten that the very first widely publicized distributed denial-ofservice (DDOS) attacks, on 10 May 2000, were the work of a fifteen year-old who went by the nick-name of “Mafia Boy”. The youth was identified and apprehended several months later. Although the reasons for his actions remain unknown, it is highly unlikely that they were political in nature. Had the same attack been carried out after the events of September 11, it might have been immediately classified as cyberterrorism. In the absence of specific information, such as a note from the attackers or their identity, it is difficult to attribute an attack to cyberterrorism. The term cyberterrorism covers a fairly vague catalogue of new threats, and it is difficult to speculate what the motivation or aims of an unknown attacker or group of attackers might be. When the only thing known is the target of the attack, it is very dubious to extrapolate to the thinking that may have motivated a hacker, terrorist, mercenary, activist, ordinary criminal or prankster. The type of computer-related attack cannot be used to state the motivation or aims of the attackers with any certainty. This is one of the difficulties in the fight against computer-related crime, as additional information is needed to determine what the criminal intention was. Whether it is through a process of economic destabilization, by threatening critical infrastructures, spreading ideology or manipulating information, cyberterrorism constitutes a new threat that must be taken very seriously. Apart from its threat to the information systems and the cyberworld, symbolized by the internet, it can endanger human life by creating an indirect menace to life and limb. II.1.7 Hackers Understanding a hacker’s motivation and level of technical skill can help to assess how serious an attack is, and assist in devising a counter-strategy. In order to secure an information system, one needs to know against whom it needs to be protected. At the present time there are two principal groups of hackers: the professionals who make money from their work, and the amateurs, who tend to be persons with a pronounced need for recognition (Figure II.4). Professional hackers generally fall into one or more of these categories: – direct competitors of the organization targeted; – civil servants; – mercenaries (hackers in the pay of an organization in the private or the public sector); – other criminal elements. Amateur hackers may include: 34 – technicians, the descendants of the original “hackers”, computer buffs who were motivated primarily by the desire to display their mastery of the technologies involved; – snoops; – pranksters, also called “script-kiddies” or “kidiots”, who frequently enjoy a great amount of publicity when they are caught, although the fact that they tend to be the ones most frequently unmasked should not lead us to imagine that they are the only representatives of the category of hackers; Cybercrime

Select target paragraph3