74 Annex 2 GLOSSARY ANNEX 2: GLOSSARY Action Fraud – the UK’s national fraud and internet crime reporting centre, providing a central point of contact for the public and businesses. Computer Network Exploitation (CNE) – cyber espionage; the use of a computer network to infiltrate a target computer network and gather intelligence. Active Cyber Defence (ACD) – the principle of implementing security measures to strengthen the security of a network or system to make it more robust against attack. Cyber Crime marketplace – the totality of products and services that support the cyber crime ecosystem. Anonymisation – the use of cryptographic anonymity tools to hide or mask one’s identity on the Internet. Authentication – the process of verifying the identity, or other attributes of a user, process or device. Cryptography – the science or study of analysing and deciphering codes and ciphers; cryptanalysis. Cyber attack – deliberate exploitation of computer systems, digitally-dependent enterprises and networks to cause harm. Autonomous System – a collection of IP networks for which the routing is under the control of a specific entity or domain. Cyber crime – cyber-dependent crime (crimes that can only be committed through the use of ICT devices, where the devices are both the tool for committing the crime and the target of the crime); or cyber–enabled crime (crimes that may be committed without ICT devices, like financial fraud, but are changed significantly by use of ICT in terms of scale and reach). Big data – data sets which are too big to process and manage with commodity software tools in a timely way, and require bespoke processing capabilities to manage their volumes, speed of delivery and multiplicity of sources. Cyber ecosystem – the totality of interconnected infrastructure, persons, processes, data, information and communications technologies, along with the environment and conditions that influence those interactions. Bitcoin – a digital currency and payment system. Cyber incident – an occurrence that actually or potentially poses a threat to a computer, internet-connected device, or network – or data processed, stored, or transmitted on those systems – which may require a response action to mitigate the consequences. Automated system verification – measures to ensure that software and hardware are working as expected, and without errors. Commodity malware – malware that is widely available for purchase, or free download, which is not customised and is used by a wide range of different threat actors. National Cyber Security Strategy 2016

Select target paragraph3