Cybersecurity guide for developing countries I.2.3 The security deficit The security deficit in information and communication technologies is a reflection of the nature of IT and of cyberspace. The fact that users move in a virtual world, acting remotely and relatively anonymously, compounds the difficulties of designing, implementing, managing and controlling this technology; when one adds failures, malfunctions, errors, mistakes, inconsistencies and even natural disasters into the equation, the result, not surprisingly, is an aura of insecurity that taints the IT infrastructure (see Figure I.4). Figure I.4 – The internet infrastructure and the many origins of problems Attackers Internet infrastructure q Network infrastructure q Operating infrastructure Accidents, natural disasters q Physical infrastructure q Identity theft, spoofing, etc. q Environment infrastructure q Tampering, theft, destruction, degradation, infection, etc. q Active listening (monitoring) q Passive listening (sniffing) ACCIDENT q Routing attacks q Bombardment, denialof-service, etc. Human and other errors, etc. q Software, application, service infrastructure q Human error, other errors, accidents, attacks In this context, there are many ways in which a malicious attacker may exploit vulnerabilities3. The proliferation of such attacks – including identity theft, system spoofing, intrusion, resource hijacking, infection, deterioration, destruction, tampering, breach of confidentiality, denial of service, theft, extortion, etc. – illustrates the limitations of current security strategies, but also, paradoxically, shows that the infrastructures have a certain robustness. Whatever the motivations of individual computer criminals may be, the results always include a far from trivial economic impact. Cybercrime is fast turning into an international hydra-headed monster. Security solutions do exist, but they are never absolute, and generally represent no more than a response to a particular problem in a specific context. The result is that the security problem is displaced, and the responsibility for security shifts; furthermore, the solutions in their turn need to be secured, and managed in a protected manner. 3 Cybercrime, cyberattacks and cyberoffences are discussed in depth in Part II. Cybersecurity 9

Select target paragraph3