Cybersecurity guide for developing countries
II.1.2.5
Unmasking cybercriminals
Computer-related crime is sophisticated, and is usually committed across national borders, frequently
with a time delay. The traces it leaves in the systems are intangible and difficult to gather and save.
They take the form of digital information stored on all sorts of media: working memory, storage
peripherals, hard discs, external discs and USB sticks, electronic components, etc. The problem is how
to capture the wide variety of evidence turned up in a digital search. The following questions illustrate
the extent to which the concept of digital evidence remains elusive:
–
How to identify the relevant data?
–
How to trace them?
–
How to store them?
–
What are the judicial rules of evidence?
–
How to recover files that have been deleted?
–
How to prove the origin of a message?
–
How to establish the identity of a person on the basis of only a digital trace, in view of the
difficulties of reliably linking digital information with its physical author (virtualization) and
the proliferation of identity theft?
–
How to establish the conclusiveness of digital evidence in establishing the truth before a court
(concept of digital evidence), knowing that the storage media from which the evidence has
been recovered are not infallible (date-time information being treated differently from one
computer system to another, and subject to tampering)?
–
etc.
Digital evidence is even more difficult to obtain when it is scattered across systems located in different
countries. In such cases, success depends entirely on the effectiveness of international cooperation
between legal authorities and the speed with which action is taken. Effective use of such evidence to
identify individuals depends on the speed with which requests are treated: if treatment is slow,
identification is next to impossible.
Figure II.3 shows the different types of problems caused by malicious acts such as physical destruction
or theft of equipment, preventing access to systems and data, infection of resources, compromised
decision-making or communication processes through denial-of-service attacks (or as the result of
espionage or intrusion into the systems), information theft and tampering (manipulation of opinion,
info-war). It also outlines the main characteristics of cybercrime that make it difficulty to identify the
criminals.
Furthermore, in most countries there is a significant mismatch between the skills of the criminals who
commit high-technology crimes and the resources available to the law-enforcement and justice
authorities to prosecute them. The use of computer technologies by those authorities, whether at the
national or international level, remains weak and varies greatly from one country to another.
In most cases, the police and judicial authorities rely on conventional investigation methods used for
ordinary crime to prosecute cybercriminals so as to identify and arrest them.
30
Cybercrime