Cybersecurity guide for developing countries II.1.2.3 Proliferation of hacks and vulnerabilities The widespread availability of “hacks”, which exploit system vulnerabilities, and libraries of attacks and software that build on criminal know-how, make the task of carrying out a computer attack easier. This, combined with the possibility of virtual action, encourages computer experts with criminal tendencies and criminals with computer skills to turn their expertise to a malicious use. In some cases, cyberspace eases the transition to a criminal act almost unawares. II.1.2.4 Faults and vulnerabilities Criminals exploit organizational and technical faults and vulnerabilities of the internet, the absence of a harmonized legal framework between countries, and the lack of effective coordination between national law-enforcement agencies. This may involve traditional forms of criminality (traditional crimes committed with new technologies: money-laundering, blackmail, extortion, etc.) or new types of crime based on digital technologies: system intrusion, theft of processor time, theft of source codes, databases, etc. The environment, in all of those cases, is exceptionally conducive: minimum risks, wide coverage, lucrative profits. Figure II.2 summarizes the sources of the vulnerabilities of the internet infrastructure. Figure II.2 – Principal characteristics of the internet exploited for criminal purposes Internet technology aspects System aspects – public, open technology – version history – security mechanisms not built-in – best-effort technology design – availability of tools for network administration, traffic analysis, audit and encryption – availability of attack tools – configuration laxness – attractive systems (targets) – management deficiencies – piecemeal approach to security Characteristics of the legal system – multiple jurisdiction – digital safe havens Internet Characteristics of the cyberworld – intangible – virtual – trend to cyber-everything Network aspects – extended connectivity – component growth and distribution – no overall control – inadequate performance User aspects – different categories – large and growing number – varying levels of training and expertise – unpredictable – unsuitable behaviour – uncertain ethical integrity – inadequate use of security tools – poor security management Cybercrime 29

Select target paragraph3