perception of respondents as to what constitutes a ‘data breach’, ‘intrusion’, ‘unavailability of ICT
services’, or ‘malicious software.’ One survey covering private sector organizations in five countries,
for example, reports extremely high enterprise ‘victimization’ rates – such as between 1.1 and 1.8
‘successful cyber-attacks per surveyed organization per week.’31 Such findings are likely heavily influenced not
only by the perception of what constitutes a ‘cyber-attack’ on an enterprise,32 but also by the size of
the enterprise computer infrastructure available to attack. This particular survey, for instance,
focused on organizations with more than 1,000 ‘enterprise seats’ – defined as direct connections to
the network and enterprise systems.33
Indeed, a greater cybercrime risk for larger enterprises is also borne out by data for the
European private sector. The proportion of enterprises in Europe experiencing data corruption due
to malicious software or unauthorized access is greater for large enterprises (more than 250 persons)
(two to 27 per cent), than for medium enterprises (50-249 persons) (two to 21 per cent), which is, in
turn, greater than for small enterprises (10-49 persons) (one to 15 per cent).
In addition to the ‘available attack surface’, such differences may also relate to a perception
amongst perpetrators that larger enterprises represent higher value targets. It may also be the case,
however, that small and medium enterprises possess a lower capacity to identify attacks in the first
place. Some 65 per cent of large enterprises, for example, reported having a formally defined ICT
policy, compared with 43 per cent of medium enterprises, and only 22 per cent of small
enterprises.34
Criminal tools – the botnet
A defining feature of today’s cybercrime landscape is the extensive use of computer misuse
tools across a range of cyber-offences. ‘Botnets’ (a term derived from the words ‘robot’ and
‘network’) consist of a network of interconnected, remote-controlled computers generally infected
with malicious software that turns the infected systems into so-called ‘bots’, ‘robots’, or ‘zombies.’35
The legitimate owners of such systems may often be unaware of the fact of infection. Zombies
within the botnet connect to computers controlled by perpetrators (known as ‘command and
control servers’ or C&Cs), or to other zombies, in order to receive instructions, download additional
software, and transmit back information harvested from the infected system.
Because botnets can be used for a number of actions – including DDoS attacks, sending
spam, stealing personal information, hosting malicious sites, and delivering ‘payloads’ of other
malicious software36 – they represent a key cybercrime tool of choice. A number of responding
countries highlighted the increasing use of botnets in cybercrime during the past five years.37 From a
criminal law perspective, the installation of malware on a personal or enterprise computer system
can represent illegal access to a computer system, and/or illegal data interference or system
interference.38 In countries where computer misuse tools are criminalized, producing, selling,
possessing, or distributing botnet software itself may also be a criminal offence. In addition, use of
the botnet for further criminal gain may constitute a range of offences, such as illegal access to,
31
32
33
34
35
36
37
38
HP/Ponemon, 2012. Cost of Cybercrime Study AU, DE, JN, GB and US.
Survey results are thus more reliable where experience of a particular, defined event, is asked about. See UNODC/UNECE, 2010.
Manual on Victimization Surveys.
Ibid.
Eurostat, 2011. Statistics in Focus 7/2011. ICT security in enterprises, 2010.
OECD, 2008. Malicious Software (Malware). A Security Threat to the Internet Economy. DSTI/ICCP/REG(2007)5/FINAL. 28 April 2008.
Hogben, G. (ed.) 2011. Botnets: Detection, Measurement, Disinfection and Defence. European Network and Information Security Agency
(ENISA).
Study cybercrime questionnaire. Q84.
See Annex One (Act descriptions). See also NATO Cooperative Cyber Defence Centre of Excellence and ENISA, 2012. Legal
Implications of Countering Botnets.
32