Cybersecurity guide for developing countries
Figure II.3 – Difficulties in identifying an attacker
No access
Compromised data
Information theft
Manipulation of opinion
Information war
Sniffing
Physical
Infections, Hacking
Destruction Viruses
Cracking
Theft
Etc.
DoS
Decisionmaking and
communication
processes
Sophisticated crime, committed across
borders
Delayed effect
Non-physical evidence: difficult to collect
Anonymity
Identity theft
Virtualization
Relays
Multiple intermediaries
Etc.
II.1.2.6
Surveillance
and
espionage
Psych-ops
and
propaganda
International cooperation?
Identification of attackers?
?
Aterritoriality, digital safe havens
Criminals take advantage of the aterritorial nature of the internet and the lack, in some countries, of
legislation outlawing computer-related crime, as well as the multitude of jurisdictions covering the
internet.
In a similar manner to tax havens, digital safe havens allow criminals to host servers, distribute illegal
content or perform illegal actions without fear of retribution. Installing such servers on the territory of
weak countries creates a haven for cross-border operations.
The lack of international regulation and control and the ineffective nature of international cooperation
in legal investigations and prosecutions allows the internet to act as a protective buffer for criminals.
Currently, no effective approach, legal or technical, has been adopted for dealing with all the different
types of crime observed on the internet, such as:
–
the highly organized parallel industry of large-scale software, film and music piracy, which
has taken on unprecedented dimensions in cyberspace;
–
copyright violations, betrayal of professional trust, violation of digital privacy and intellectual
property;
–
property offences, theft, damage to or destruction of property, and interference in someone
else’s property (concept of electronic trespassing);
–
distribution of legal content;
–
attacks against competitors, industrial espionage, trademark infringements, disinformation,
and denial-of-service attacks against competitors.
Cybercrime
31