2.4.3.1
Active and Passive Attacks
An "active" attack aims to alter system resources or affect their operation. Conversely, a
"passive" attack seeks to use information from a system but does not affect system
resources of that system (IETF 2007). Instead, passive attacks aim to obtain data for an
off-line attack. For example, hackers typically use packet inspection and analysis to
facilitate offline review of security protocols and thus fine-tune exploits.
2.4.3.2
Inside and Outside Attacks
We may also characterise attacks according to their initiation point. The Internet Security
Glossary describes an “Inside Attack” as one that is initiated by an entity inside the
security perimeter (an "insider"). Insider attacks are difficult to defend against because
the culprits misuse the access privileges obtained for legitimate business functions. In
contrast, unauthorised or illegitimate users initiate "outside” attacks outside the security
perimeter. Outsider attackers include hackers, organised criminal groups and States.
The attack types are not mutually exclusive as outsiders often rely on insiders.
3
UN CYBERSECURITY
ACTIVITIES
3.1
RESOLUTIONS ON CYBERSECURITY
Cybersecurity has been high on the agenda of the United Nations (UN) for a number of
years. The UN took up the subject out of recognition that building trust and confidence in
the use of ICTs is crucial to the socio-economic well-being of humanity. As a result, the
UN General Assembly (UNGA) has expressed itself on cybersecurity matters in five
major Resolutions. Next, we explore the relevant Resolutions to assess the views of the
international community on cybersecurity.
3.1.1
A/RES/55/63: COMBATING CRIMINAL USE OF ICTs
th
The Resolution issued on 4 December 2000 focused on combating the criminal misuse
15
of information technologies. It draws on the United Nations Millennium Declaration and
asks States to ensure that the benefits of the new technologies are available to all. The
Resolution is relevant to this Guide as follows. It recognises that free flow of information
can promote economic and social development, education and democratic governance.
Indeed, the Resolution warns that unless addressed, the increasing criminal misuse of
information technologies may have grave impacts on all States.
15
Obtain a copy of the UN Millennium Declaration here: http://www.un.org/millennium/declaration/ares552e.htm
17