Cybersecurity guide for developing countries
It is entirely legitimate to ask whether the breakdown of the internet, or a portion of it, as a result of
malicious acts, might not sow terror within the community of web users, some groups of economic
players, and the general public.
Or, in the main, we may be dealing with instances of economic terrorism, aimed at damaging
organizations that use the internet for their activities.
The term cyberterrorism, which has come into vogue since the September 11 attacks, should be used
with discretion. It should not be forgotten that the very first widely publicized distributed denial-ofservice (DDOS) attacks, on 10 May 2000, were the work of a fifteen year-old who went by the
nick-name of “Mafia Boy”. The youth was identified and apprehended several months later. Although
the reasons for his actions remain unknown, it is highly unlikely that they were political in nature.
Had the same attack been carried out after the events of September 11, it might have been immediately
classified as cyberterrorism.
In the absence of specific information, such as a note from the attackers or their identity, it is difficult
to attribute an attack to cyberterrorism.
The term cyberterrorism covers a fairly vague catalogue of new threats, and it is difficult to speculate
what the motivation or aims of an unknown attacker or group of attackers might be. When the only
thing known is the target of the attack, it is very dubious to extrapolate to the thinking that may have
motivated a hacker, terrorist, mercenary, activist, ordinary criminal or prankster.
The type of computer-related attack cannot be used to state the motivation or aims of the attackers
with any certainty. This is one of the difficulties in the fight against computer-related crime, as
additional information is needed to determine what the criminal intention was.
Whether it is through a process of economic destabilization, by threatening critical infrastructures,
spreading ideology or manipulating information, cyberterrorism constitutes a new threat that must be
taken very seriously. Apart from its threat to the information systems and the cyberworld, symbolized
by the internet, it can endanger human life by creating an indirect menace to life and limb.
II.1.7
Hackers
Understanding a hacker’s motivation and level of technical skill can help to assess how serious an
attack is, and assist in devising a counter-strategy. In order to secure an information system, one needs
to know against whom it needs to be protected. At the present time there are two principal groups of
hackers: the professionals who make money from their work, and the amateurs, who tend to be
persons with a pronounced need for recognition (Figure II.4).
Professional hackers generally fall into one or more of these categories:
–
direct competitors of the organization targeted;
–
civil servants;
–
mercenaries (hackers in the pay of an organization in the private or the public sector);
–
other criminal elements.
Amateur hackers may include:
34
–
technicians, the descendants of the original “hackers”, computer buffs who were motivated
primarily by the desire to display their mastery of the technologies involved;
–
snoops;
–
pranksters, also called “script-kiddies” or “kidiots”, who frequently enjoy a great amount of
publicity when they are caught, although the fact that they tend to be the ones most frequently
unmasked should not lead us to imagine that they are the only representatives of the category
of hackers;
Cybercrime