Cybersecurity guide for developing countries
Many malicious programs are disguised as helpful add-ons for navigation, connection, customization
of services etc., when in fact they are designed to carry out surveillance (information theft, password
theft, traffic surveillance), use computer resources or perpetrate attacks. They are also used to
disseminate and control tools used for distributed denial-of-service attacks. Thousands of these
programs are in circulation, the objective being financial gain.
Denial-of-service (DOS) and distributed denial-of-service (DDOS) attacks are aimed at crippling
system resources. Typically they operate by overloading a server with requests for the ordinary
services it is designed to provide routinely, thus preventing it from delivering the service to regular
users (whence the term denial-of-service). Because these requests resemble ordinary requests, such an
attack is very difficult to counter (it is the sheer volume of requests that overwhelms the system). For
added effectiveness, they can be launched simultaneously from many different points or systems; this
is what constitutes a distributed DOS attack.
The means by which malware of various sorts is propagated include free or demonstration software
and pornographic websites or games, e-mail, but also spam and discussion groups.
Whatever the means used to infiltrate malware – it may even include, for example in the case of
adware (but never spyware), a step of explicit or tacit approval by the user – once installed, they are
turned to illicit use. Most commonly, they are executed without the consent of the user. Clandestinely,
they collect and transmit data (for example, on surfing habits, of interest for targeted advertising).
They can act as drones for illegal activities like spam and phishing attacks, effectively working for the
controller’s financial gain. Detecting and uninstalling such software is not always straightforward.
Frequently, users lack the skills and tools necessary to control these risks.
The term phishing – a metaphor for angling, where the fisherman reels in his catch after attracting it
with bait and hooking it – refers to an attack using mail programs to trick or coax web users into
revealing sensitive information that can be then exploited for criminal purposes (e.g. fraud or
embezzlement). The Journal du net15 of 26 January 2005 recorded over five thousand phishing sites
that were active on the web in just one month (September 2005), targeting 110 different brands.
In general, phishing attacks are conducted using e-mail messages that are forged to appear as though
they come from a genuine institution with which the user may have dealings (e.g. the post office, a
bank, a dealer, online auction site), but attackers may also use a telephone call, instant messaging (IM)
or cellphone text messages, or even approach the victim in person.
15 www.journaldu net.com
38
Cybercrime