This blog contains notes from different learning sites. This notes falls in Information Security, Cyber Security, Network Security and other Security Domain class. Any suggestion to make this site helpful is truly welcome :)
Showing posts with label Cyber Attack. Show all posts
Showing posts with label Cyber Attack. Show all posts
Thursday, March 7, 2019
Friday, January 25, 2019
Thursday, January 17, 2019
Wednesday, January 16, 2019
Thursday, May 19, 2016
Cyber Conflicts: Law of Neutrality and Humanitarian Law
http://plato.stanford.edu/entries/war/
The law asserts that neutral countries should not allow their resources to be used by one country to attack another country.
The fundamental problem with this is the weakness of sovereign infrastructure of countries. Computers can be infiltrated without cognizance of the neutral country to launch attack. Can we hold these countries responsible for the attacks launched by other countries, or elements that they don't control?
Especially if the country does not have technical ability or resources to secure the network to protect from such activities.
Can they be responsible, or can they be held responsible? Take the case of attack on Sony, multiple countries were attributed to the attacks by different people. But the attribution was never clear. So whom can we blame for the attack?
And so neutrality can be maintained only when there is equality. Only when there is enough technical ability among the countries to be able to manage the attacks.
And enough technical ability to be able to monitor their own networks. Given that you don't have total control of cyberspace in all the countries, this whole idea of neutrality and the law of neutrality is very difficult to apply.
Third, look at the humanitarian law.
There has been a particular emphasis on application of this international humanitarian law to cyber conflict.
This law defines a set of rules that limit the effects of armed conflict while protecting individuals who are not, or are no longer participating in the hostilities and restricts the means and methods of warfare.
While one may agree that the arguments being made, once you recognize the unique difference between the sovereign and physical domain. In several instances citizens of a country are themselves involved in launching attacks. For instance, if you look at the US-Russia conflict, the citizens of Russia were launching attacks on the computers that were installed in Estonia and Georgia in two different attacks. Now, can the citizens of a country be held responsible, especially if they were instigated by non-governmental bodies? Who is responsible? Or, if the entire population of a country were responsible for an attack. So again, this is a very difficult thing to gauge.
It is also important to note that laws are subject interpretation, based on one's own point of view.
They can be applied erroneously, misused for parochial reasons, or flouted by reasons of reciprocity on flimsy grounds. The laws need to be made such that are unambiguous and enforceable.
The attackers can use the cloak of anonymity that the Internet provides to camouflage their true identities. And therein lies the difficulty in enforcing the rules. There are several explicit factors that make enforceability very hard, and one of them is ambiguity. Which is very hard to overcome.
International Humanitarian law does not strictly prohibit countries from entering a war but declares certain actions in a war to be legal or not.
The law asserts that neutral countries should not allow their resources to be used by one country to attack another country.
The fundamental problem with this is the weakness of sovereign infrastructure of countries. Computers can be infiltrated without cognizance of the neutral country to launch attack. Can we hold these countries responsible for the attacks launched by other countries, or elements that they don't control?
Especially if the country does not have technical ability or resources to secure the network to protect from such activities.
Can they be responsible, or can they be held responsible? Take the case of attack on Sony, multiple countries were attributed to the attacks by different people. But the attribution was never clear. So whom can we blame for the attack?
And so neutrality can be maintained only when there is equality. Only when there is enough technical ability among the countries to be able to manage the attacks.
And enough technical ability to be able to monitor their own networks. Given that you don't have total control of cyberspace in all the countries, this whole idea of neutrality and the law of neutrality is very difficult to apply.
Third, look at the humanitarian law.
There has been a particular emphasis on application of this international humanitarian law to cyber conflict.
This law defines a set of rules that limit the effects of armed conflict while protecting individuals who are not, or are no longer participating in the hostilities and restricts the means and methods of warfare.
While one may agree that the arguments being made, once you recognize the unique difference between the sovereign and physical domain. In several instances citizens of a country are themselves involved in launching attacks. For instance, if you look at the US-Russia conflict, the citizens of Russia were launching attacks on the computers that were installed in Estonia and Georgia in two different attacks. Now, can the citizens of a country be held responsible, especially if they were instigated by non-governmental bodies? Who is responsible? Or, if the entire population of a country were responsible for an attack. So again, this is a very difficult thing to gauge.
It is also important to note that laws are subject interpretation, based on one's own point of view.
They can be applied erroneously, misused for parochial reasons, or flouted by reasons of reciprocity on flimsy grounds. The laws need to be made such that are unambiguous and enforceable.
The attackers can use the cloak of anonymity that the Internet provides to camouflage their true identities. And therein lies the difficulty in enforcing the rules. There are several explicit factors that make enforceability very hard, and one of them is ambiguity. Which is very hard to overcome.
International Humanitarian law does not strictly prohibit countries from entering a war but declares certain actions in a war to be legal or not.
Cyber Conflicts: Quiz 3 - Cyberwarfare and International Conflicts
This week quiz is also very simple and easy to comprehend and answer. However, if you require any suggestion or help about how to answer do mention in the comment and I will help with that.
1. Since 1999 cyber attacks have caused large-scale injury, loss of life and destruction of property.


4. What's the current level of threat of cyber attack of terrorist activity, aka cyber terrorism?


8. ___________ of infrastructure means a failure in one element could cause cascading failures on multiple _____________ infrastructure components.
Choose the BEST set of terms to complete the phrase above:
1. Since 1999 cyber attacks have caused large-scale injury, loss of life and destruction of property.
- True
- False
- Information gathering and espionage
- Disruption of services
- Physical system attacks
- Social media and propaganda
- None of the above
- Russia and China
- China and U.S.
- U.S. and Russia
- All of the above

4. What's the current level of threat of cyber attack of terrorist activity, aka cyber terrorism?
- Cyber terrorism threat has been largely unfounded
- Cyber terrorism threat is somewhat likely
- Cyber terrorism threat is extremely likely and dangerous
- Cyber terrorism often happened in the past but no longer a big issue
- Citizens in Russia working to attack computers in Estonia
- Bank personel in China using computers to attack Australia
- Groups of thugs in Egypt using cyber attacks on Tunisia
- None of the above
- False
- True
- Taiwan
- China
- U.S.
- Russia
- Iran

8. ___________ of infrastructure means a failure in one element could cause cascading failures on multiple _____________ infrastructure components.
Choose the BEST set of terms to complete the phrase above:
- interdependence; critical
- association; cyber
- criticality; complex
- internet; cyber
- comparability; internet
- IT blocking
- URL and packet filtering
- Web feed blocking
- DNS filtering
- Modems, IPs
- Bot nets; bots
- Trojans; viruses
- Computers; spams
Cyber Conflicts: Internet Censorship
Another looming battle that we see is of internet censorship.
When the governments try to control the public internet, a struggle over information content has caused international discord. Some governments are apprehensive about exposing their citizens to offensive material that might be morally, culturally, or politically deleterious. While other government and citizens' groups vociferously advocate free speech. Effective censorship requires multi layered access control, including laws and regulations, technical filtering, physical restrictions, surveillance, and monitoring, warnings as the last, arrests. Laws and regulations include penal codes, anti-terrorism laws, visual media laws, and legislation allowing government access to ISP and telecommunication company information. For instance, the Chinese government deploys firewalls and gateways to prevent access to certain IP addresses. It also performs DNS poisoning of specific websites and imposes harsh penalties on ISPs and organizations that carry content not permitted by Chinese law.
Many other countries also engage in online censorship including Bahrain, Burma, Cuba, Iran, Jordan, Kuwait, Saudi Arabia, the list goes on.
And even Germany and Switzerland censors specific web sites for content. Techniques for censoring information include IP blocking, DNS filtering, routing, url and packet filtering, as well as blocking the web feed. Internet content is also monitored through automated tools and manual inspection to block objectionable pages and ISP cooperation.
Censorship can, however, be circumventing through use of proxy servers, allowing anonymous access to censored material. These servers can be blocked and their use discouraged by government threats to shut down websites.
So there's a fight on the censorship fronts. The large companies sometimes fight back. For example, in 2010 Google threatened to remove its Google dot China search engine and website unless China allowed its search engine to access uncensored information.
Remove its offices from China, cancel media events and delay release of phones with Android operating system. These declarations were in response to a chain of hacker attacks on Google's servers.
And brought out the long growing battle of internet censorship into the open.
Concerning the economic consequences of such actions companies cooperating with governments receive preferential access to rights and contracts, while non cooperating companies can lead to potential harassment and litigation. Google was among the first in around 2006 to willfully abide by the Chinese internet censorship regulation. Despite public disapproval in the US, Google's decision, 2010, to suspend censorship rules in China in response to the attacks and is not only financial based but as retaliation for the espionage. The threat of Google alone may not warrant concern, but combined with other large companies such as Microsoft and Yahoo could pose a greater threat to China's situation than any government action.

The leverage of companies against governments and the influence of individual governments have helped in
in multinationals is generally defined by local circumstances.
The complexity of the issue of government control of information is evident from both the public battle, and it is part communication company in motion and it would to mid 2011. When it had to engage with several countries, including China, India, Russia, Saudi Arabia, and UAE so that they could monitor Blackberry communication, ostensibly for fighting terrorism.
Being a cross border network makes it difficult for RIM, or Research In Motion, the company that makes Blackberry, to comply with conflicting laws in different countries. For example, dealing with a call between US and somebody outside, let's say in China, can become very tricky, where US citizens are protected by US laws. China emphasizes the rights of the government to be able to intercept and monitor communication.
So there are a lot of such contentious issues that we are facing. And we need to face all of these issues as we go forward in the cyber warfare arena. There are several actors which have all independent motivation. There are several attacks that can be launched. But one thing is clear, the strategies of national governments are very strong in developing these cyber arsenals. And there's a cyber going on, and we need to discuss it and debate it and make sure this does not derail the free internet and all that we have come to expect of it. Thank you very much.
When the governments try to control the public internet, a struggle over information content has caused international discord. Some governments are apprehensive about exposing their citizens to offensive material that might be morally, culturally, or politically deleterious. While other government and citizens' groups vociferously advocate free speech. Effective censorship requires multi layered access control, including laws and regulations, technical filtering, physical restrictions, surveillance, and monitoring, warnings as the last, arrests. Laws and regulations include penal codes, anti-terrorism laws, visual media laws, and legislation allowing government access to ISP and telecommunication company information. For instance, the Chinese government deploys firewalls and gateways to prevent access to certain IP addresses. It also performs DNS poisoning of specific websites and imposes harsh penalties on ISPs and organizations that carry content not permitted by Chinese law.
Many other countries also engage in online censorship including Bahrain, Burma, Cuba, Iran, Jordan, Kuwait, Saudi Arabia, the list goes on.
And even Germany and Switzerland censors specific web sites for content. Techniques for censoring information include IP blocking, DNS filtering, routing, url and packet filtering, as well as blocking the web feed. Internet content is also monitored through automated tools and manual inspection to block objectionable pages and ISP cooperation.
Censorship can, however, be circumventing through use of proxy servers, allowing anonymous access to censored material. These servers can be blocked and their use discouraged by government threats to shut down websites.
So there's a fight on the censorship fronts. The large companies sometimes fight back. For example, in 2010 Google threatened to remove its Google dot China search engine and website unless China allowed its search engine to access uncensored information.
Remove its offices from China, cancel media events and delay release of phones with Android operating system. These declarations were in response to a chain of hacker attacks on Google's servers.
Concerning the economic consequences of such actions companies cooperating with governments receive preferential access to rights and contracts, while non cooperating companies can lead to potential harassment and litigation. Google was among the first in around 2006 to willfully abide by the Chinese internet censorship regulation. Despite public disapproval in the US, Google's decision, 2010, to suspend censorship rules in China in response to the attacks and is not only financial based but as retaliation for the espionage. The threat of Google alone may not warrant concern, but combined with other large companies such as Microsoft and Yahoo could pose a greater threat to China's situation than any government action.
The leverage of companies against governments and the influence of individual governments have helped in
in multinationals is generally defined by local circumstances.
The complexity of the issue of government control of information is evident from both the public battle, and it is part communication company in motion and it would to mid 2011. When it had to engage with several countries, including China, India, Russia, Saudi Arabia, and UAE so that they could monitor Blackberry communication, ostensibly for fighting terrorism.
Being a cross border network makes it difficult for RIM, or Research In Motion, the company that makes Blackberry, to comply with conflicting laws in different countries. For example, dealing with a call between US and somebody outside, let's say in China, can become very tricky, where US citizens are protected by US laws. China emphasizes the rights of the government to be able to intercept and monitor communication.
So there are a lot of such contentious issues that we are facing. And we need to face all of these issues as we go forward in the cyber warfare arena. There are several actors which have all independent motivation. There are several attacks that can be launched. But one thing is clear, the strategies of national governments are very strong in developing these cyber arsenals. And there's a cyber going on, and we need to discuss it and debate it and make sure this does not derail the free internet and all that we have come to expect of it. Thank you very much.
Cyber Conflicts: Cyber Warfare - Types of the Attacks
There are several reported cases of cyber warfare over the past five years that have involved reconnaissance and espionage between countries. And the cyberspace has increasingly become important in US military strategy and tactics, as it is in Russia and China.
And so, we will look at what some of these motivations are for these countries.
And there are several reports attributed to Chinese military officials, specifically discusses the need for China to devise cyber-warfare techniques to target enemy financial network, civilian electricity grids, and telecommunication networks. While installing malware on systems, ahead of launching cyber attacks, in a 2009 investigation by researchers at the University of Cambridge and the University of Toronto, a massive espionage network was discovered originating from China, that it infiltrated at least 1,200 computers in 103 countries, including many embassies, foreign ministries, and government offices, as well as the Dalai Lama's Tibetan exile centers in India, Brussels, London, and New York. In 2009, Chinese hackers reportedly launched an attack that penetrated computers of more than 30 companies, including Google and Yahoo. These attacks were camouflaged by multiple levels of encryption, allowing hackers to operate undetected for long periods of time. Attack vectors including a generic explorer remote code execution exploit were downloaded by email or instant message links. The militia then infected websites, hackers stole intellectual property, gained access to the email messages of human rights activists, and monitored their behavior.
The attacks purportedly came from Taiwan, but were traced back to Mainland China. So assigning attribution is often a very serious challenge.
For instance, let us consider the recent attack where purported attacks from North Korean hackers was done on the Sony studio. The attribution of that was never clear, but it was being attributed by different people to different organizations, including North Korea, including some hacker groups, including Russia, but it's never clear. And there's another example that the Taiwanese hacker could've attacked and purported attacks through electronic media.
But someone in Mainland China was actually responsible for that. So this misattribution is becoming a huge challenge.
In traditional warfare this is different. Where there's warfare between countries, where the enemy's identity is more or less readily discernible, not all attacks aim to disable computing and network infrastructure. And equal devastation is caused by use of social media for propaganda, manipulation of public opinion, and incitement of violence, hatred, and national, nation-state public disharmony. And so, we look at what this propaganda and social warfare can do.
The internet has amplified terrorist effectiveness many fold by enabling distribution of shared ideologies to a much wider population. For example, social networks are employed to foster member kinship, fuel member zeal and to act by propagating ideas about martyrdom and revenge. Public internet allows loosely connected terrorist groups to aggregate, forming larger networks. They're distributed, layered, and more redundant, and consequently more resistant to leadership changes and disruption, and even detection.
The ability to recruit members from population centers for terrorist acts are to be committed, rather than transporting operatives globally, give the terrorists a strategic advantage. That's another consequence of cyber warfare and the internet.
There is evidence that terrorists' reach is widening. And this can be seen from attacks across the globe, in Egypt, India, Indonesia, Pakistan, Russia, Spain, UK and the US. An important element in terrorist fight strategy is mobilizing public opinion. To sustain themselves, terrorist organization need sympathizers to willingly provide resources and logistic support, as well as to perpetrate their crimes.
Terrorist groups are able to launch effective propaganda using the internet, gaining influence over international affairs, including the flow of information, public opinion, and politics. And efforts intended to locate and share terrorist websites have been largely unsuccessful over the last ten years. The websites are able to crop up elsewhere. Counter-narratives are being used extensively to negate terrorist messages but with limited success.
Another source of threats come from sociopolitical groups operating independently or under direct patronage from national governments, which are very large threats. They have large social following and they're used for both propaganda and attacks. For instance, during Israel's great Gaza offensive in the Winter of 2009, a Moroccan based Islamic group hacked into a Israeli registration server and poisoned the routing table of popular domains to reel out users to a page featuring hacker-created anti-Israel messages, rather than launch a typical dos attack. Likewise, following the November 2008 attacks in Mumbai, hackers in India and Pakistan defaced government-sponsored web sites in Pakistan and Indian web sites respectively, throughout one another's national networks. Most such attacks can be categorized in news sensors drawing minimal attention to their respective causes. And affecting only specific government websites that are often quickly resolved.
However, deliberate attacks to disable a critical portion of national government web presence can affect communication between government and the citizens, demoralizing the citizens and destabilizing governments. These attacks reflect an even more disturbing trend with long-term ramification, especially as they links to political conflicts in nations. Within hours of the start of the Russia-Georgia war in 2008, Russian based cyber attackers disabled and defaced Georgian government web sites. The attacks were encouraged and facilitated by a Russian patriotic hacker group called Nashi and launched by seemingly ordinary citizens who could not be probably employed by the Russian government or military. While there is evidence that Russia was the source of the attack, no conclusive proof confirms Russian government involvement.
What was clear is that ordinary Russian citizens participated in the attacks. The hacker groups provided the resources and information to perform the attacks. And a large number of Russian citizens and expats launched them.
A similar attack in May 2007 was launched by Russian hackers against Estonian government websites was response to uprooting of a World War II memorial bronze statue, which was commemorating Russian military losses in the campaign to drive the Germans from the region in World War II. Numbers of attack participants can play an important role in such attacks.
Now, this raises an important question. As the disparity in internet availability is breached between developed and developing countries, countries with larger populations can expect to have a future strategic advantage. China and India, with populations of more than a billion each, will be powerful forces in citizen-led attacks. Ironically, botnets, which are blamed for many recent attacks, will be critical in shifting the strategic cyber warfare balance, as nations attempt to create botnets using resources from other countries to bridge this disparity. As a disparity in internet availability is bridged between developed and developing countries, countries with larger populations can expect to have a future strategic advantage.
The key question that we face, however, is how do we classify these attacks by ordinary citizens participating in these political conflicts? Are they criminals? Are they warriors? Are they patriots? The answer is neither obvious nor easy, but I see this implication in terms of law enforcement and international justice.
And that's something we need to ponder over. And these are the attacks that we have seen, but there's future battle that we need to worry about.
So let's look at some of these.
And there are several reports attributed to Chinese military officials, specifically discusses the need for China to devise cyber-warfare techniques to target enemy financial network, civilian electricity grids, and telecommunication networks. While installing malware on systems, ahead of launching cyber attacks, in a 2009 investigation by researchers at the University of Cambridge and the University of Toronto, a massive espionage network was discovered originating from China, that it infiltrated at least 1,200 computers in 103 countries, including many embassies, foreign ministries, and government offices, as well as the Dalai Lama's Tibetan exile centers in India, Brussels, London, and New York. In 2009, Chinese hackers reportedly launched an attack that penetrated computers of more than 30 companies, including Google and Yahoo. These attacks were camouflaged by multiple levels of encryption, allowing hackers to operate undetected for long periods of time. Attack vectors including a generic explorer remote code execution exploit were downloaded by email or instant message links. The militia then infected websites, hackers stole intellectual property, gained access to the email messages of human rights activists, and monitored their behavior.
The attacks purportedly came from Taiwan, but were traced back to Mainland China. So assigning attribution is often a very serious challenge.
For instance, let us consider the recent attack where purported attacks from North Korean hackers was done on the Sony studio. The attribution of that was never clear, but it was being attributed by different people to different organizations, including North Korea, including some hacker groups, including Russia, but it's never clear. And there's another example that the Taiwanese hacker could've attacked and purported attacks through electronic media.
But someone in Mainland China was actually responsible for that. So this misattribution is becoming a huge challenge.
In traditional warfare this is different. Where there's warfare between countries, where the enemy's identity is more or less readily discernible, not all attacks aim to disable computing and network infrastructure. And equal devastation is caused by use of social media for propaganda, manipulation of public opinion, and incitement of violence, hatred, and national, nation-state public disharmony. And so, we look at what this propaganda and social warfare can do.
The internet has amplified terrorist effectiveness many fold by enabling distribution of shared ideologies to a much wider population. For example, social networks are employed to foster member kinship, fuel member zeal and to act by propagating ideas about martyrdom and revenge. Public internet allows loosely connected terrorist groups to aggregate, forming larger networks. They're distributed, layered, and more redundant, and consequently more resistant to leadership changes and disruption, and even detection.
The ability to recruit members from population centers for terrorist acts are to be committed, rather than transporting operatives globally, give the terrorists a strategic advantage. That's another consequence of cyber warfare and the internet.
There is evidence that terrorists' reach is widening. And this can be seen from attacks across the globe, in Egypt, India, Indonesia, Pakistan, Russia, Spain, UK and the US. An important element in terrorist fight strategy is mobilizing public opinion. To sustain themselves, terrorist organization need sympathizers to willingly provide resources and logistic support, as well as to perpetrate their crimes.
Terrorist groups are able to launch effective propaganda using the internet, gaining influence over international affairs, including the flow of information, public opinion, and politics. And efforts intended to locate and share terrorist websites have been largely unsuccessful over the last ten years. The websites are able to crop up elsewhere. Counter-narratives are being used extensively to negate terrorist messages but with limited success.
Another source of threats come from sociopolitical groups operating independently or under direct patronage from national governments, which are very large threats. They have large social following and they're used for both propaganda and attacks. For instance, during Israel's great Gaza offensive in the Winter of 2009, a Moroccan based Islamic group hacked into a Israeli registration server and poisoned the routing table of popular domains to reel out users to a page featuring hacker-created anti-Israel messages, rather than launch a typical dos attack. Likewise, following the November 2008 attacks in Mumbai, hackers in India and Pakistan defaced government-sponsored web sites in Pakistan and Indian web sites respectively, throughout one another's national networks. Most such attacks can be categorized in news sensors drawing minimal attention to their respective causes. And affecting only specific government websites that are often quickly resolved.
However, deliberate attacks to disable a critical portion of national government web presence can affect communication between government and the citizens, demoralizing the citizens and destabilizing governments. These attacks reflect an even more disturbing trend with long-term ramification, especially as they links to political conflicts in nations. Within hours of the start of the Russia-Georgia war in 2008, Russian based cyber attackers disabled and defaced Georgian government web sites. The attacks were encouraged and facilitated by a Russian patriotic hacker group called Nashi and launched by seemingly ordinary citizens who could not be probably employed by the Russian government or military. While there is evidence that Russia was the source of the attack, no conclusive proof confirms Russian government involvement.
What was clear is that ordinary Russian citizens participated in the attacks. The hacker groups provided the resources and information to perform the attacks. And a large number of Russian citizens and expats launched them.
A similar attack in May 2007 was launched by Russian hackers against Estonian government websites was response to uprooting of a World War II memorial bronze statue, which was commemorating Russian military losses in the campaign to drive the Germans from the region in World War II. Numbers of attack participants can play an important role in such attacks.
Now, this raises an important question. As the disparity in internet availability is breached between developed and developing countries, countries with larger populations can expect to have a future strategic advantage. China and India, with populations of more than a billion each, will be powerful forces in citizen-led attacks. Ironically, botnets, which are blamed for many recent attacks, will be critical in shifting the strategic cyber warfare balance, as nations attempt to create botnets using resources from other countries to bridge this disparity. As a disparity in internet availability is bridged between developed and developing countries, countries with larger populations can expect to have a future strategic advantage.
The key question that we face, however, is how do we classify these attacks by ordinary citizens participating in these political conflicts? Are they criminals? Are they warriors? Are they patriots? The answer is neither obvious nor easy, but I see this implication in terms of law enforcement and international justice.
And that's something we need to ponder over. And these are the attacks that we have seen, but there's future battle that we need to worry about.
So let's look at some of these.
Cyber Conflicts: Cyber Warfare - Types of the Attacks
There are several reported cases of cyber warfare over the past five years that have involved reconnaissance and espionage between countries. And the cyberspace has increasingly become important in US military strategy and tactics, as it is in Russia and China.
And so, we will look at what some of these motivations are for these countries.
And there are several reports attributed to Chinese military officials, specifically discusses the need for China to devise cyber-warfare techniques to target enemy financial network, civilian electricity grids, and telecommunication networks. While installing malware on systems, ahead of launching cyber attacks, in a 2009 investigation by researchers at the University of Cambridge and the University of Toronto, a massive espionage network was discovered originating from China, that it infiltrated at least 1,200 computers in 103 countries, including many embassies, foreign ministries, and government offices, as well as the Dalai Lama's Tibetan exile centers in India, Brussels, London, and New York. In 2009, Chinese hackers reportedly launched an attack that penetrated computers of more than 30 companies, including Google and Yahoo. These attacks were camouflaged by multiple levels of encryption, allowing hackers to operate undetected for long periods of time. Attack vectors including a generic explorer remote code execution exploit were downloaded by email or instant message links. The militia then infected websites, hackers stole intellectual property, gained access to the email messages of human rights activists, and monitored their behavior.
The attacks purportedly came from Taiwan, but were traced back to Mainland China. So assigning attribution is often a very serious challenge.
For instance, let us consider the recent attack where purported attacks from North Korean hackers was done on the Sony studio. The attribution of that was never clear, but it was being attributed by different people to different organizations, including North Korea, including some hacker groups, including Russia, but it's never clear. And there's another example that the Taiwanese hacker could've attacked and purported attacks through electronic media.
But someone in Mainland China was actually responsible for that. So this misattribution is becoming a huge challenge.
In traditional warfare this is different. Where there's warfare between countries, where the enemy's identity is more or less readily discernible, not all attacks aim to disable computing and network infrastructure. And equal devastation is caused by use of social media for propaganda, manipulation of public opinion, and incitement of violence, hatred, and national, nation-state public disharmony. And so, we look at what this propaganda and social warfare can do.
The internet has amplified terrorist effectiveness many fold by enabling distribution of shared ideologies to a much wider population. For example, social networks are employed to foster member kinship, fuel member zeal and to act by propagating ideas about martyrdom and revenge. Public internet allows loosely connected terrorist groups to aggregate, forming larger networks. They're distributed, layered, and more redundant, and consequently more resistant to leadership changes and disruption, and even detection.
The ability to recruit members from population centers for terrorist acts are to be committed, rather than transporting operatives globally, give the terrorists a strategic advantage. That's another consequence of cyber warfare and the internet.
There is evidence that terrorists' reach is widening. And this can be seen from attacks across the globe, in Egypt, India, Indonesia, Pakistan, Russia, Spain, UK and the US. An important element in terrorist fight strategy is mobilizing public opinion. To sustain themselves, terrorist organization need sympathizers to willingly provide resources and logistic support, as well as to perpetrate their crimes.
Terrorist groups are able to launch effective propaganda using the internet, gaining influence over international affairs, including the flow of information, public opinion, and politics. And efforts intended to locate and share terrorist websites have been largely unsuccessful over the last ten years. The websites are able to crop up elsewhere. Counter-narratives are being used extensively to negate terrorist messages but with limited success.
Another source of threats come from sociopolitical groups operating independently or under direct patronage from national governments, which are very large threats. They have large social following and they're used for both propaganda and attacks. For instance, during Israel's great Gaza offensive in the Winter of 2009, a Moroccan based Islamic group hacked into a Israeli registration server and poisoned the routing table of popular domains to reel out users to a page featuring hacker-created anti-Israel messages, rather than launch a typical dos attack. Likewise, following the November 2008 attacks in Mumbai, hackers in India and Pakistan defaced government-sponsored web sites in Pakistan and Indian web sites respectively, throughout one another's national networks. Most such attacks can be categorized in news sensors drawing minimal attention to their respective causes. And affecting only specific government websites that are often quickly resolved.
However, deliberate attacks to disable a critical portion of national government web presence can affect communication between government and the citizens, demoralizing the citizens and destabilizing governments. These attacks reflect an even more disturbing trend with long-term ramification, especially as they links to political conflicts in nations. Within hours of the start of the Russia-Georgia war in 2008, Russian based cyber attackers disabled and defaced Georgian government web sites. The attacks were encouraged and facilitated by a Russian patriotic hacker group called Nashi and launched by seemingly ordinary citizens who could not be probably employed by the Russian government or military. While there is evidence that Russia was the source of the attack, no conclusive proof confirms Russian government involvement.
What was clear is that ordinary Russian citizens participated in the attacks. The hacker groups provided the resources and information to perform the attacks. And a large number of Russian citizens and expats launched them.
A similar attack in May 2007 was launched by Russian hackers against Estonian government websites was response to uprooting of a World War II memorial bronze statue, which was commemorating Russian military losses in the campaign to drive the Germans from the region in World War II. Numbers of attack participants can play an important role in such attacks.
Now, this raises an important question. As the disparity in internet availability is breached between developed and developing countries, countries with larger populations can expect to have a future strategic advantage. China and India, with populations of more than a billion each, will be powerful forces in citizen-led attacks. Ironically, botnets, which are blamed for many recent attacks, will be critical in shifting the strategic cyber warfare balance, as nations attempt to create botnets using resources from other countries to bridge this disparity. As a disparity in internet availability is bridged between developed and developing countries, countries with larger populations can expect to have a future strategic advantage.
The key question that we face, however, is how do we classify these attacks by ordinary citizens participating in these political conflicts? Are they criminals? Are they warriors? Are they patriots? The answer is neither obvious nor easy, but I see this implication in terms of law enforcement and international justice.
And that's something we need to ponder over. And these are the attacks that we have seen, but there's future battle that we need to worry about.
So let's look at some of these.
And so, we will look at what some of these motivations are for these countries.
And there are several reports attributed to Chinese military officials, specifically discusses the need for China to devise cyber-warfare techniques to target enemy financial network, civilian electricity grids, and telecommunication networks. While installing malware on systems, ahead of launching cyber attacks, in a 2009 investigation by researchers at the University of Cambridge and the University of Toronto, a massive espionage network was discovered originating from China, that it infiltrated at least 1,200 computers in 103 countries, including many embassies, foreign ministries, and government offices, as well as the Dalai Lama's Tibetan exile centers in India, Brussels, London, and New York. In 2009, Chinese hackers reportedly launched an attack that penetrated computers of more than 30 companies, including Google and Yahoo. These attacks were camouflaged by multiple levels of encryption, allowing hackers to operate undetected for long periods of time. Attack vectors including a generic explorer remote code execution exploit were downloaded by email or instant message links. The militia then infected websites, hackers stole intellectual property, gained access to the email messages of human rights activists, and monitored their behavior.
The attacks purportedly came from Taiwan, but were traced back to Mainland China. So assigning attribution is often a very serious challenge.
For instance, let us consider the recent attack where purported attacks from North Korean hackers was done on the Sony studio. The attribution of that was never clear, but it was being attributed by different people to different organizations, including North Korea, including some hacker groups, including Russia, but it's never clear. And there's another example that the Taiwanese hacker could've attacked and purported attacks through electronic media.
But someone in Mainland China was actually responsible for that. So this misattribution is becoming a huge challenge.
In traditional warfare this is different. Where there's warfare between countries, where the enemy's identity is more or less readily discernible, not all attacks aim to disable computing and network infrastructure. And equal devastation is caused by use of social media for propaganda, manipulation of public opinion, and incitement of violence, hatred, and national, nation-state public disharmony. And so, we look at what this propaganda and social warfare can do.
The internet has amplified terrorist effectiveness many fold by enabling distribution of shared ideologies to a much wider population. For example, social networks are employed to foster member kinship, fuel member zeal and to act by propagating ideas about martyrdom and revenge. Public internet allows loosely connected terrorist groups to aggregate, forming larger networks. They're distributed, layered, and more redundant, and consequently more resistant to leadership changes and disruption, and even detection.
The ability to recruit members from population centers for terrorist acts are to be committed, rather than transporting operatives globally, give the terrorists a strategic advantage. That's another consequence of cyber warfare and the internet.
There is evidence that terrorists' reach is widening. And this can be seen from attacks across the globe, in Egypt, India, Indonesia, Pakistan, Russia, Spain, UK and the US. An important element in terrorist fight strategy is mobilizing public opinion. To sustain themselves, terrorist organization need sympathizers to willingly provide resources and logistic support, as well as to perpetrate their crimes.
Terrorist groups are able to launch effective propaganda using the internet, gaining influence over international affairs, including the flow of information, public opinion, and politics. And efforts intended to locate and share terrorist websites have been largely unsuccessful over the last ten years. The websites are able to crop up elsewhere. Counter-narratives are being used extensively to negate terrorist messages but with limited success.
Another source of threats come from sociopolitical groups operating independently or under direct patronage from national governments, which are very large threats. They have large social following and they're used for both propaganda and attacks. For instance, during Israel's great Gaza offensive in the Winter of 2009, a Moroccan based Islamic group hacked into a Israeli registration server and poisoned the routing table of popular domains to reel out users to a page featuring hacker-created anti-Israel messages, rather than launch a typical dos attack. Likewise, following the November 2008 attacks in Mumbai, hackers in India and Pakistan defaced government-sponsored web sites in Pakistan and Indian web sites respectively, throughout one another's national networks. Most such attacks can be categorized in news sensors drawing minimal attention to their respective causes. And affecting only specific government websites that are often quickly resolved.
However, deliberate attacks to disable a critical portion of national government web presence can affect communication between government and the citizens, demoralizing the citizens and destabilizing governments. These attacks reflect an even more disturbing trend with long-term ramification, especially as they links to political conflicts in nations. Within hours of the start of the Russia-Georgia war in 2008, Russian based cyber attackers disabled and defaced Georgian government web sites. The attacks were encouraged and facilitated by a Russian patriotic hacker group called Nashi and launched by seemingly ordinary citizens who could not be probably employed by the Russian government or military. While there is evidence that Russia was the source of the attack, no conclusive proof confirms Russian government involvement.
What was clear is that ordinary Russian citizens participated in the attacks. The hacker groups provided the resources and information to perform the attacks. And a large number of Russian citizens and expats launched them.
A similar attack in May 2007 was launched by Russian hackers against Estonian government websites was response to uprooting of a World War II memorial bronze statue, which was commemorating Russian military losses in the campaign to drive the Germans from the region in World War II. Numbers of attack participants can play an important role in such attacks.
Now, this raises an important question. As the disparity in internet availability is breached between developed and developing countries, countries with larger populations can expect to have a future strategic advantage. China and India, with populations of more than a billion each, will be powerful forces in citizen-led attacks. Ironically, botnets, which are blamed for many recent attacks, will be critical in shifting the strategic cyber warfare balance, as nations attempt to create botnets using resources from other countries to bridge this disparity. As a disparity in internet availability is bridged between developed and developing countries, countries with larger populations can expect to have a future strategic advantage.
The key question that we face, however, is how do we classify these attacks by ordinary citizens participating in these political conflicts? Are they criminals? Are they warriors? Are they patriots? The answer is neither obvious nor easy, but I see this implication in terms of law enforcement and international justice.
And that's something we need to ponder over. And these are the attacks that we have seen, but there's future battle that we need to worry about.
So let's look at some of these.
Cyber Conflicts: Cyber Warfare - Actors of Cyberwarfare
Cyberwar acts are continually morphing as a variety of actors are strengthening their skills and devise new ways to bolster their cyber arsenals that are growing both in sophistication and scale.
In order to be able to predict and envision how cyber warfare may evolve over time, we turn to examining the current actors and their motivations. So let's look at who these actors are.
The cyber warfare involves several actors including nation states, terrorists, sociopolitical groups. And they all differ in their primary intent and targets.

Nation states aim to weaken the enemy nation to give the attacker wartime advantage. The terrorists generally inflict damage as a revenge, or as a show of strength leveraging it to solicit sponsors and recruits.
And sociopolitical groups create and relevance in political negotiations and policy formulation.
In some cases the distinction between terrorists and social political groups has blurred with groups defined by overlapping motivations.
Social political groups may have the tacit support of government organizations when their objectives align. In addition, secondary players work symbiotically or parasitically with major actors towards their own goals, with political or financial. Engaging in espionage or reconnaissance attacks on the internet infrastructure and the raw cyber vandalism.
The primary actors in the cyber warfare arena are states, non-state actors and international organizations. Arguably, anybody who uses the internet can become an actor in this arena.
Groups of state citizens targeting either their own government or other states, in this case, patriotic hacking, have influenced the course of domestic and international politics, which is a game changer.

In the past, states mostly watched on the sidelines as noisy hackers demonstrated their hacking skills by hacking each other's websites, often for bravado with little real impact.

Over the last few years, however, states have become the most active players in the cyber arena. Governments, military, and intelligence agencies have recognized the potential harm that cyber attacks could inflict on their countries information and communication infrastructure.
It's physical infrastructure, economy, as well as potential benefits of a cyber arsenal for counter attack and first strike capabilities.
So far, states have primarily focused on identifying vulnerabilities in enemy infrastructure, espionage, and intelligence gathering, but their stats are increasing acquiring hacker assets to be able to stay ahead of their adversaries in developing strategic cyber warfare capabilities. Several countries, including the United States, Russia, China, and Israel have gathered formidable arsenals of cyber weapons. However, they remain weak in defending against sophisticated cyber attacks. The point to note here is that, as we are collecting all of these cyber arsenals, the basic premise that the cyber ward is a stabilizer and equalizer against discrepancies. And the current expanse of countries is changing.
More money, more resources are giving more leverage to countries with more resources to have a better cyber arsenal. For the strategic advantage which some of the foreign countries have in being able to launch cheap and dirty attacks is changing. And the attacks are getting much more sophisticated. And there's a huge asymmetry in defense and offence, there are multiple targets to defend, when only a few vulnerabilities could be exploited for a successful attack. Therefore, most countries are fairly weak at defending against cyber attacks.
A major fear has been cyber attacks launched by Islamic terrorists, some of whom had demonstrated some initial hacking promise.
However, the fear of attacks by terrorists on critical infrastructure have not been realized.
And the threat of extreme harm posed by non-state actors has thus far proved unfounded.
Most of the attacks from such non-state actors are focused on propaganda and publicity to mobilize people to join their cause and join their fights.
But such cyber attacks have not directly caused much substantive damage. Sophisticated cyber attacks are no longer a matter of a viskit program, or executing a spectacular attack, but rather rigorous processes that require large investments in manpower, training, computing, equipment, and intelligence.
Most non set actors are unable to compete with the resources of large states. They, however, continue to effectively use social media and other web resources for fundraising, propaganda, and member recruitment.
The arena of cyber warfare has expanded steadily as internet connectivity and the number of individuals willing to use internet for political objectives grows. For instance, some attacks launched during the Russian conflict with Georgia, Estonia and involved Russian citizens, who prompted by nationalistic zeal work in mass to launch attacks against government and business websites in Estonia and Georgia. This has raised a spectrum of different form of war field, a cyber war that is conducted by civilians of one country against government institutions and civilians in another country but may or may not be state sanctioned or even controlled by the military of the state. Citizens are also involved actively in fomenting unrest against national governments in response to propaganda, information warfare of other countries. The Arab Spring triggered fear among many authoritative leaders of similar social, social media field revolutions. Which are in turn prompted them to constantly scour the network for activity that may catalyze into an uprising similar to the Arab Spring.
Ironically, even those days may store public outrage and basically support several attacks against adversaries. The same important citizens can strike back at the state to bring political change in their own countries. In addition to states, non-state actors and civilians, international organizations such as the United Nations, the Organization for Security and Cooperation in Europe, NATO and the Shanghai Cooperation Organization have become key players in fostering International cooperation aimed at reducing the threats to international peace, peace, and security posed by a possibility of full scale cyber warfare. The activities of each of these international organizations have, however, often reflect the narrow strategic interests of key state members. And despite strong rhetoric about cyber cooperation, and limiting the potential of conflicts, negotiations toward agreements and treaties often exhibit crucial differences among these key states and of the international organizations compose of these states.
An absence of this consensus is also influenced by insufficient credibility of international organizations to provide guarantee of compliance. With any cyber arms control or cyber peace treaties signed by member states.
Fundamental problems in actor definition lie in actors serving as proxys for others and in differing perception of actors. First, the distinction between state and non-state actors is often blurred because these non-state actors often have tacit and financial support as at the patronage of government organizations, such as Hezbollah being a proxy for Iran, the Russian Business Network being a proxy for Russian government and the Hidden Lynx hacking group being a proxy for the Chinese government. All of this are basically attributions to different organizations without concrete proof.

It is very difficult to prove the nexus conclusively, hence this ambiguity.
Second, the definition of terrorism differs based on perception. A social activist for some could be a terrorist for others. They have been making the distinction even fuzzier. For example, the cyber terrorism has been used to describe Al Qaeda's use of we to influence Young Muslim United States and Europe to join jihadis aimed at achieving Islamist objectives. Of course, some of the same protesters that have been initially categorized as cyber activists by using social media in protests against the Kadafi regime in Libya and the Assad regime in Syria, are now categorized as cyber terrorists because they also support implementation of sharia and establishment of Islamic states. And politically, in the case of Syria, use the internet to call upon Muslims in Europe and the United States to come join in the jihad against Assad's regime.
So this is a complex scenario.
In order to be able to predict and envision how cyber warfare may evolve over time, we turn to examining the current actors and their motivations. So let's look at who these actors are.
The cyber warfare involves several actors including nation states, terrorists, sociopolitical groups. And they all differ in their primary intent and targets.
Nation states aim to weaken the enemy nation to give the attacker wartime advantage. The terrorists generally inflict damage as a revenge, or as a show of strength leveraging it to solicit sponsors and recruits.
And sociopolitical groups create and relevance in political negotiations and policy formulation.
In some cases the distinction between terrorists and social political groups has blurred with groups defined by overlapping motivations.
Social political groups may have the tacit support of government organizations when their objectives align. In addition, secondary players work symbiotically or parasitically with major actors towards their own goals, with political or financial. Engaging in espionage or reconnaissance attacks on the internet infrastructure and the raw cyber vandalism.
The primary actors in the cyber warfare arena are states, non-state actors and international organizations. Arguably, anybody who uses the internet can become an actor in this arena.
Groups of state citizens targeting either their own government or other states, in this case, patriotic hacking, have influenced the course of domestic and international politics, which is a game changer.

In the past, states mostly watched on the sidelines as noisy hackers demonstrated their hacking skills by hacking each other's websites, often for bravado with little real impact.

Over the last few years, however, states have become the most active players in the cyber arena. Governments, military, and intelligence agencies have recognized the potential harm that cyber attacks could inflict on their countries information and communication infrastructure.
It's physical infrastructure, economy, as well as potential benefits of a cyber arsenal for counter attack and first strike capabilities.
So far, states have primarily focused on identifying vulnerabilities in enemy infrastructure, espionage, and intelligence gathering, but their stats are increasing acquiring hacker assets to be able to stay ahead of their adversaries in developing strategic cyber warfare capabilities. Several countries, including the United States, Russia, China, and Israel have gathered formidable arsenals of cyber weapons. However, they remain weak in defending against sophisticated cyber attacks. The point to note here is that, as we are collecting all of these cyber arsenals, the basic premise that the cyber ward is a stabilizer and equalizer against discrepancies. And the current expanse of countries is changing.
More money, more resources are giving more leverage to countries with more resources to have a better cyber arsenal. For the strategic advantage which some of the foreign countries have in being able to launch cheap and dirty attacks is changing. And the attacks are getting much more sophisticated. And there's a huge asymmetry in defense and offence, there are multiple targets to defend, when only a few vulnerabilities could be exploited for a successful attack. Therefore, most countries are fairly weak at defending against cyber attacks.
A major fear has been cyber attacks launched by Islamic terrorists, some of whom had demonstrated some initial hacking promise.
However, the fear of attacks by terrorists on critical infrastructure have not been realized.
And the threat of extreme harm posed by non-state actors has thus far proved unfounded.
Most of the attacks from such non-state actors are focused on propaganda and publicity to mobilize people to join their cause and join their fights.
But such cyber attacks have not directly caused much substantive damage. Sophisticated cyber attacks are no longer a matter of a viskit program, or executing a spectacular attack, but rather rigorous processes that require large investments in manpower, training, computing, equipment, and intelligence.
Most non set actors are unable to compete with the resources of large states. They, however, continue to effectively use social media and other web resources for fundraising, propaganda, and member recruitment.
The arena of cyber warfare has expanded steadily as internet connectivity and the number of individuals willing to use internet for political objectives grows. For instance, some attacks launched during the Russian conflict with Georgia, Estonia and involved Russian citizens, who prompted by nationalistic zeal work in mass to launch attacks against government and business websites in Estonia and Georgia. This has raised a spectrum of different form of war field, a cyber war that is conducted by civilians of one country against government institutions and civilians in another country but may or may not be state sanctioned or even controlled by the military of the state. Citizens are also involved actively in fomenting unrest against national governments in response to propaganda, information warfare of other countries. The Arab Spring triggered fear among many authoritative leaders of similar social, social media field revolutions. Which are in turn prompted them to constantly scour the network for activity that may catalyze into an uprising similar to the Arab Spring.
Ironically, even those days may store public outrage and basically support several attacks against adversaries. The same important citizens can strike back at the state to bring political change in their own countries. In addition to states, non-state actors and civilians, international organizations such as the United Nations, the Organization for Security and Cooperation in Europe, NATO and the Shanghai Cooperation Organization have become key players in fostering International cooperation aimed at reducing the threats to international peace, peace, and security posed by a possibility of full scale cyber warfare. The activities of each of these international organizations have, however, often reflect the narrow strategic interests of key state members. And despite strong rhetoric about cyber cooperation, and limiting the potential of conflicts, negotiations toward agreements and treaties often exhibit crucial differences among these key states and of the international organizations compose of these states.
An absence of this consensus is also influenced by insufficient credibility of international organizations to provide guarantee of compliance. With any cyber arms control or cyber peace treaties signed by member states.
Fundamental problems in actor definition lie in actors serving as proxys for others and in differing perception of actors. First, the distinction between state and non-state actors is often blurred because these non-state actors often have tacit and financial support as at the patronage of government organizations, such as Hezbollah being a proxy for Iran, the Russian Business Network being a proxy for Russian government and the Hidden Lynx hacking group being a proxy for the Chinese government. All of this are basically attributions to different organizations without concrete proof.

It is very difficult to prove the nexus conclusively, hence this ambiguity.
Second, the definition of terrorism differs based on perception. A social activist for some could be a terrorist for others. They have been making the distinction even fuzzier. For example, the cyber terrorism has been used to describe Al Qaeda's use of we to influence Young Muslim United States and Europe to join jihadis aimed at achieving Islamist objectives. Of course, some of the same protesters that have been initially categorized as cyber activists by using social media in protests against the Kadafi regime in Libya and the Assad regime in Syria, are now categorized as cyber terrorists because they also support implementation of sharia and establishment of Islamic states. And politically, in the case of Syria, use the internet to call upon Muslims in Europe and the United States to come join in the jihad against Assad's regime.
So this is a complex scenario.
Tuesday, May 17, 2016
Cyber Attacks in a Global Context
He developed this model of cyber attacks using theories of human motivations that I've just described. But also putting it into a more global context and focusing on cultural aspects,
cultural factors may influence the motivation of the attacker. And also looking at the profile of the organization that is being attacked.

This is useful because the theories that I was explaining before really focus on just individual perceptions in individual motivation. But, you can't really take individuals out of their cultural context, okay. So that hacking should be seen as partly culturally determined as well as individually determined. What Kshetri has done is looked at some of the characteristics of source nations. So you know where the source being where the hacking is originating, where is it coming from.
In certain countries probably would be more conducive to hacking. All countries have people good at computer skills. Why do some countries produce more hackers than others? Well, could be due to something about the nation itself, or the country. When economic conditions are poor, jobs aren't plentiful. Those with good computer skills who normally could be highly employed in many countries, they have a difficult time getting legitimate employment. They may then use those skills for criminal purposes. Also countries vary in terms of the regulations and social norms. In some cases hacking is not seen as as much a criminal activity as it is, say, in some western countries. So there's characteristics of the source nation that will influence the motivation for attackers. There's also characteristics of the attacker. But in the middle here, ad we're looking at it under motivation for the attack, what Kshetri has outlined are sort of three primary sources of motivation that relate to the continuum I had on an earlier slide. There's extrinsic motivation.
And then there's pure intrinsic motivation, enjoyment base. We do it because it is fun, gives us autonomy, provides a challenge.
Then there's a sort of middle one, the sort of obligation we're doing it because we feel obligated whether to a country, to an organization or to a group that we belong.
But the motivation for the attack may actually determine what type of attack ends up occurring.
Earlier we talked in an earlier lecture, we talked about targeted attacks, carefully planned out and opportunistic attacks. Those that sort of just present themselves.
Well when in a state of flow or when operating out of intrinsic motivation, people may be more likely to pursue opportunistic attacks. What's available now? Whereas extrinsic motivation, looking for a financial gain for example, or obligation to social groups you belong to, they'd be more targeted. More carefully planned out.
Also, the profile of the targeted organization is gonna influence the type of attack, especially if you're looking at it sort of for political purposes, or for financial gain.
You're gonna look at the symbolic and financial significance of the organization. And also any sort of weaknesses that they may have in their organization. And this sort of then explains the different types of hacking that we see.
Your positive deviance, if you will, the whitehat hackers are probably gonna be operating perhaps more out of enjoyment-based interests and motivation.
Your hacktivists may be operating more out of community. They're obligation based intrinsic motivation.
Those who are motivated most by financial outcomes or gain, extremes of motivation, would be targeting organizations. And finding those that will maximize their outcomes. In all cases though, you can bring it back to expectancy value theory. Okay, they're attacking and they're performing a behavior striving for some goal based on the outcomes whether its enjoyment or financial gain.
$30 off Norton Security Premium 1 Year. Use code NSBUCA30OFF. MSRP $89.99
And when they think that its likely there's a chance that they will attain value to outcomes whether they're intrinsic or extrinsic the motivation to hack will be quite high.
Subscribe to:
Posts (Atom)



