discovered a criminal selling a complete installation of Zeus for US$250. Illicit consulting
services can also assist in setting up “botnets”, which infect computers and allow criminals to
hijack and use them for other purposes, for charges that range from US$350-400. The truly
idle offender can pay to have services distributed through an existing botnet at US$30 for
20,000 spam emails, or US$525 for 5 hours of DDoS attacks per day for a week13.
1.24 The transnational nature of the technologies, and of the crimes they facilitate, make it
easy for offenders to seek out and exploit any weak links or vulnerable locations. This
creates practical challenges in that legislation, law enforcement, prevention and security
measures become interdependent, and also that seeking out and closing any vulnerabilities
becomes a constant and ongoing task. Any location where law enforcement or security
measures are relatively weak can be used by offenders as a base of operations from which
to target other, better-protected locations, and this creates a powerful shared incentive for
technical assistance and capacity building to eliminate weaknesses that render everyone
vulnerable.
1.25 In this context, what matters is not necessarily the perspective of governments, but
that of offenders. From their perspective a ‘relatively weak’ or vulnerable ‘location’ may
range from a single address, file-server or local computer system to an entire country, and
‘weakness’ simply means choosing whatever digital location offers the easiest illicit access
and/or the lowest risk of detection and prosecution. Weaknesses and vulnerabilities may be
technological or jurisdictional, and they are ‘relative’ to one another in the sense that, as
each specific vulnerability is addressed, another one becomes the ‘weakest link’ in the
network and will become a new focus for offenders. No country, company, or individual can
be complacent, because security depends on keeping one’s own security measures at the
same level as others as well as one step ahead of offenders.
1.26 Technical vulnerabilities are mostly a concern for the private sector, which develops
the technologies and operates the networks. For companies individually, the security of
products and systems is a key element of competition and commercial success, and
collectively there is a shared interest in making the Internet itself safer. In general the fear of
crime is bad for business, and cybercrime is no exception.
Cybercrime happens quickly
1.27 Fast communications mean that offences can be committed very quickly, and that
digital evidence of them can be erased equally quickly. This presents serious challenges for
conventional investigative techniques. In response, the laws of many countries and the
Budapest Convention provide ‘fast freeze - slow thaw’ schemes in which investigators may
seize, or order the preservation of, digital evidence quickly and then complete the necessary
judicial proceedings before it may be accessed and actually examined and read. Even with
the best possible legal measures, the speed of offending is still a major challenge for
investigators, and the practical implications of this include the need for a high degree of skill
and extensive training, and that investigators have equipment which is as fast and powerful
as that used by the offenders.
Technology evolves rapidly, and Cybercrime evolves with it
1.28 Information technology evolves very rapidly, and new ways to commit cybercrimes
are constantly being developed. For example, as mobile phone usage increases and the
technology becomes more sophisticated, criminals seek to target mobile operating systems.
13
Fortnet Security, Anatomy of a Botnet.
16