A/66/152
vulnerabilities. Such tools are not visible in the conventional sense, are quite
stealthy and may have latent “signatures” that can be easily mimicked. Because of
the nature of the Internet, malicious code can be routed through many national
territories before delivery to target, making identification of their origin onerous,
time-consuming and often requiring substantial transnational cooperation. Even if
their origin is discovered, the identity of the perpetrator or the sponsors can remain
elusive. Consequently, malicious actors can and do operate in secrecy, with
substantial impunity, from virtually anywhere on the planet.
This obscurity of identity is compounded by an obscurity of the motive
underlying an intrusion in cyberspace. Organized criminals and other individuals or
groups may act to advance their own interests but also can be enlisted to serve as
proxies by both State and non-State actors alike. The lack of timely, high-confidence
attribution and the possibility of “spoofing” can create uncertainty and confusion for
Governments, thus increasing the potential for crisis instability, misdirected
responses and loss of escalation control during major cyberincidents.
The primary actors that together constitute threats to the reliable functioning of
cyberspace include:
(a) Criminals. Many of the malicious tools originate in the entrepreneurial
efforts of organized criminals and hackers. The growing sophistication and scope of
criminal activity highlight the potential for malicious activity in cyberspace to affect
national competitiveness, to cause a general erosion of trust in the use of the
Internet for commerce and trade, even to cripple civil infrastructure. The volume
and scope of such activities are increasing;
(b) States. There is increased anecdotal public reporting that States are
developing and using capabilities that extend traditional forms of state conflict into,
using, or through cyberspace. However, conclusive evidence regarding the source or
intentions behind events commonly assumed to be State-sponsored remains elusive.
As is often the case, the identity and motivation of the perpetrator(s) can only be
inferred from the target, effects and other circumstantial evidence surrounding an
incident;
(c) Terrorists. Terrorist capability to compromise information networks or
to execute operations with physical effects through the use of information and
communications technologies is currently lacking, although the possibility that such
capabilities may emerge in the future cannot be ruled out. Most experts agree that,
currently, terrorists rely on information and communications technologies to recruit,
to organize and to solicit funding. Specific threats arising from terrorist use of the
Internet may include use of the Internet for organizing and carrying out a specific
kinetic terrorist attack;
(d) Proxies. Of increasing concern are individuals or groups who engage in
malicious online activities on behalf of others, whether State or non-State actors, for
financial gain or for nationalist or other political motivation. So-called “botmasters” are reported to offer various malicious services to the highest bidder. The
unique attributes of information technology offer a high degree of anonymity to
such actors and effectively obscure any relationship to a sponsor, offering the
sponsor plausible deniability.
The challenges States face in addressing such threats are formidable. The
attributes of information and communications technologies mean that the actions of
16
11-41691