Cybersecurity guide for developing countries
I.2.3
The security deficit
The security deficit in information and communication technologies is a reflection of the nature of IT
and of cyberspace. The fact that users move in a virtual world, acting remotely and relatively
anonymously, compounds the difficulties of designing, implementing, managing and controlling this
technology; when one adds failures, malfunctions, errors, mistakes, inconsistencies and even natural
disasters into the equation, the result, not surprisingly, is an aura of insecurity that taints the IT infrastructure (see Figure I.4).
Figure I.4 – The internet infrastructure and the many origins of problems
Attackers
Internet infrastructure
q Network
infrastructure
q Operating
infrastructure
Accidents, natural disasters
q Physical
infrastructure
q Identity theft, spoofing,
etc.
q Environment
infrastructure
q Tampering, theft,
destruction, degradation,
infection, etc.
q Active listening (monitoring)
q Passive listening (sniffing)
ACCIDENT
q Routing attacks
q Bombardment, denialof-service, etc.
Human and other errors, etc.
q Software, application,
service infrastructure
q Human error, other errors,
accidents, attacks
In this context, there are many ways in which a malicious attacker may exploit vulnerabilities3.
The proliferation of such attacks – including identity theft, system spoofing, intrusion, resource
hijacking, infection, deterioration, destruction, tampering, breach of confidentiality, denial of service,
theft, extortion, etc. – illustrates the limitations of current security strategies, but also, paradoxically,
shows that the infrastructures have a certain robustness.
Whatever the motivations of individual computer criminals may be, the results always include a far
from trivial economic impact. Cybercrime is fast turning into an international hydra-headed monster.
Security solutions do exist, but they are never absolute, and generally represent no more than a
response to a particular problem in a specific context. The result is that the security problem is
displaced, and the responsibility for security shifts; furthermore, the solutions in their turn need to be
secured, and managed in a protected manner.
3 Cybercrime, cyberattacks and cyberoffences are discussed in depth in Part II.
Cybersecurity
9