Showing posts with label Cyber Law. Show all posts
Showing posts with label Cyber Law. Show all posts

Thursday, May 19, 2016

Cyber Conflicts: Trust between Nations and Prisonner's Dilemma

Welcome back to this section on international issues in information security.

In this lecture, we will address the growing problem of mistrust between states regarding the use of cyberspace. The tensions and anxieties that exists between nations related to the nature and origin of cyber-attacks and espionage have the potential to escalate quickly into major cyber conflict and cyber warfare. The key to stopping the escalation of conflict to warfare is mutual trust.

My previous lecture identified key elements of interpersonal trust. In this lecture, we will shift our focus to trust between nations and ask the questions, how can nations trust each other and cooperate in order to prevent cyber attacks? We will examine the aspects of interpersonal trusts that are relevant to this discussion and what needs to be added to our analysis to ensure international cooperation in the cyber arena. If you remember from last lecture, we saw that humans are remarkably able to limit their self-interests, even in interactions with strangers, particularly because of the strength of reciprocity and fairness norms. We also saw that norms are particularly effective when there are repeated interactions between individuals that have long-term implications and when sanctions for non-cooperative behavior exist. We also saw the attributions of self-interest and low-expectations for reciprocity underminded trust.

These same principles are relevant when examining trust between nations.

In addition, we identified two important cognitive processes in trust relevant situations. First, feelings of vulnerability. And second, expectations of how the other party is likely to behave across time.

People will lack trust with others when they feel vulnerable and they do not feel confident in how the other individuals will behave.

These same cognitions apply, whether we are discussing trust between two people, or between nation states. In the case of two people entering a marriage or long-term relationships, partners feel vulnerable. They are committing their lives to the other person and they expect the other person to do the same. Over time, they can observe each other's behavior for signs of commitment and fidelity. They can't observe all that other person's behavior, obviously, but they can form expectations on what they do observe.

Now think of the same cognitive processes occurring between nation-states in the realm of cyberspace.

First, nations certainly feel very vulnerable when it comes to cyberspace. We live in a highly connected society, and any disruption of services can cause economic and financial damage. There is even significant psychological damage on nations from attacks, such as the 2004 hacks into Sony's studios. Think of the effect that that had on the psyche of Americans.

There are also new forms of espionage emerging constantly and increased sophistication of cyber attacks and probes. Third, nations have grave concerns about attacks on their country's infrastructure. An attack on a nation's power grid, for example, would have devastating consequences.

In addition, most nations perceive, quite accurately, that their defensive capabilities are not as strong as their offensive capabilities in cyberspace. Right now, offense has tremendous advantage over defense in cyber conflicts. Now, let's face it, the internet was built for convenience rather than security. And so, nations are always scrambling when it comes to defending their information.

Finally, the anonymity of attacks elevates feelings of vulnerability. Not knowing where attacks come from makes you suspicious of everyone.

So for these many reasons, nations feel very vulnerable to attacks from their adversaries.

Let's move to the second important cognition in trust relevant situations. Expectations for the behaviors of others.

The unique aspects of cyberspace make it difficult for nations to form clear and confident expectations about how their partners will behave.

The anonymity of the internet makes it difficult to determine who is responsible for malicious actions. An attack on a nation's institutions could be from the state actors, such as intelligence or defense agencies, or from non-state actors, criminal or a terrorist. It is difficult to tell, and thus nations often have plausible deniability, even if they were behind an attack.

It's also difficult to judge the intent of suspicious actions or attacks. For example, is an attack on a nation's financial institutions an attempt to steal money, or is it an act of espionage?

Another key point is that the barriers of entry are low when it comes to cyber-conflict. Small states and non-state actors can enter into the fray for relatively minimal costs. So the number of actors is much larger than in traditional conflicts. As is the number of possible strategic alliances.

Thus, the state of affairs in cyberspace seems slanted towards mistrust. Nations feel highly vulnerable and do not have confident expectations about the behavior of other nations, particularly their adversaries.

However, it is absolutely critical to establish trust between nations. Societies and economies depend on network communications provided by the internet. We are so interconnected that, if these networks are disrupted, the consequences would be disastrous. With low barriers to entry and ability to attack anyone from any place in the world, tracking down criminals and terrorists will take a coordinated effort between nations, which is only possible if mutual trust exists. So the problem, then, is how do we increase trust between nations when it comes to the use of cyberspace?

To start, let's return to our previous discussions of interpersonal trust. We saw that trust is likely to be higher in a relationship when each member's self-interested outcomes match those of their partner. In other words, what is best for me is also best for you.

And when both partners expect that the actions of the others

will be in terms of what is best for both people, for the relationship, rather than for personal self-interest. This is the ideal state we should strive for. Nations recognize the same end-goals, and expect that each other will act to obtain what is best for both parties, rather than what may be immediate best for one party.

Well, how is this done? Well, with individuals we saw that this is done through the process of positive reciprocity. Partners are exposed, themselves, to small amounts of risks, and observe how the other person responds. If the other person gives up something in order to reciprocate the partners initial trust, then there is mutual gain and heightened trust occurs. The importance of initial experiences and incremental steps cannot be overstated. Repeated experiences of mutually beneficial outcomes leads partners to perceive situations as positive sum, as opposed to zero sum situations.

These repeated outcomes may encourage the partner to engage in further relationship building and relationship sustaining acts.

Let's return briefly to the Prisoner's Dilemma game. What you saw is part of a exercise for the previous module.

The Prisoner's Dilemma sets up a situation where partners decide whether to cooperate or compete with each other. It establishes a positive-sum scenario. But to achieve that, outcome partners have to trust each other and overcome the tendency to see situations as competitive or zero-sum scenarios.

A zero-sum scenario is one in which one party's gains are balanced by another party's losses. It's a win-lose situation. One person wins, the other person loses. A positive-sum situation is one where all parties may gain or lose together. It potentially is a win-win situation.

The Prisoners Dilemma's payoff grid shows that both parties gain from a cooperative response.

However, if one party chooses a non-cooperative or competitive response, a defect response in this diagram, they stand the chance to gain more points and the partner comes away with nothing. That's the competitive win-lose response. So, parties may feel the urge to maximize their self-interests, at any single trial of the Prisoners Dilemma game. But if interactions occur over time, which is the case with nation-states, then an initial competitive response by one actor is going to elicit a competitive response in the other. And as a result, mutual gains are eroded. If one actor takes a risk and offers cooperation, and the partner responds by competing, the defect response here, then the chances of future cooperation are diminished. However, if an initial cooperative act is responded to in-kind, then mutually beneficial outcomes are experienced and trust builds. So the goal is to build positive-sum situations related to cyber security and conflict.

There have been several attempts to do this, primarily in the area of what are called confidence building measures.

Cyber Conflicts: Principles of Just War

In this unit we are going to discuss the laws of foreign conflict, or the laws of war. The reason we need to understand is we need to see how they translate when we start talking about cyber warfare. Or how cyber warfare relates to these laws, so that we can start to understand how we can resolve the conflicts which are happening on the internet. There are two distinct domains in which the rights and laws of armed conflict apply in the actions of going to war. In the actions in a war, the principles that govern the right to go to war are also know as jus ad bellum, and the principles that govern the action of war are also known as jus in bello. Laws regarding war conduct are laid out in international law, mostly through what is known as international humanitarian law. International humanitarian law is reference to jus in bello, or acts within a war. International humanitarian law limit the effects of armed conflict and is made up of different laws which makes up a treaty that many of countries have signed. And the most important of which are probably the Geneva Convention Center additional protocols.

International Humanitarian Law is just a set of international agreements, many of which the US is a signatory to. In the US, according to Article 6 of the Constitution, international treaties and laws are part of US laws and therefore should be followed as such. The principle of jus ad bellum, on the other hand, fall under what is known as just war theory and are not necessarily explicitly laid out in international laws. Some jus ad bellum principles present in the Charter of the United Nations. For example, Article 2 states all members shall refrain in their international relations from the threat or the use of force against the territorial integrity or political independence of any state, or in any other manner inconsistent with the purposes of the United Nations. And article 51 states, nothing in the present Charter shall impair the inherent right of individual or collective self defense if an armed attack occurs against a Member of the United Nations.

There are generally five recognized principals of jus ad bellum, we will cover them here and raise questions about how we may think about these principals in the context of cyber warfare. One reference to the notion that war should be waged by a proper and legitimate authority, following proper processes.

Now in the context of cyber warfare you may ask what is the legitimate authorities of cyber warfare? Cyber warfare is a covert warfare typically conducted by proxies of countries. Are the proxies of nation states legitimate? Would nation states ever agree that the entities committing their tax are the proxies? What if the proxies are operating outside of the country? These are some of the questions which make it challenging to apply that.

The second indicates that war must be waged with right intentions, motivated by just cause. What is a just cause in cyber space? Can a preemptive strike for national interest be justified? Again, an unanswered question. The probability of success must be determined. Efforts that cannot address the situation must be avoided.

Given the complexity of the technologies through which cyber-attack occurs, it is often difficult to make accurate assessment of the probability of success. It will be unclear if a counterattack is effective in deterring a current attack. Therefore, again, hard to apply the principle. Another principle refers to the notion that benefits of war must be proportional or worth the costs encountered, principally casualties. The concept of proportionality is based on assessment of damage, which often takes a long time to do in cyber warfare. Due to the need of immediate reaction, it is difficult to assure proportionality. Also cyber attacks at least up until now, are not usually encountered direct casualties, so I don't know how well it applies. War should, again, be waged as a last resort, only when diplomatic options have been exhausted. With ambiguity and attribution, diplomatic wrangling can often be tedious and long drawn, while need for response has urgency to repose the attack and minimize collateral damage.

So again, it's very hard to manage this. So these are a lot of unanswered questions that we have on how we can apply the international humanitarian law to cyber warfare. And as we go through this course further, we are going to discuss it and try to understand what the nuances of this are and we will debate in different cases as we study along with this. How we can start to understand this problem, how international law can start to apply with the problem of cyber warfare. Thank you.

Cyber Conflicts: Quiz 3 - Cyberwarfare and International Conflicts

This week quiz is also very simple and easy to comprehend and answer. However, if you require any suggestion or help about how to answer do mention in the comment and I will help with that.


1. Since 1999 cyber attacks have caused large-scale injury, loss of life and destruction of property.
  • True
  • False
2. Identify the item which has NOT been recognized as a mode of cyberwarfare attack and activity.
  • Information gathering and espionage
  • Disruption of services
  • Physical system attacks
  • Social media and propaganda
  • None of the above
3. The countries who conduct powerful cyber attacks are:
  • Russia and China
  • China and U.S.
  • U.S. and Russia
  • All of the above


4. What's the current level of threat of cyber attack of terrorist activity, aka cyber terrorism?
  • Cyber terrorism threat has been largely unfounded
  • Cyber terrorism threat is somewhat likely
  • Cyber terrorism threat is extremely likely and dangerous
  • Cyber terrorism often happened in the past but no longer a big issue
5. What's an example of a real event for an activity of non-state actors?
  • Citizens in Russia working to attack computers in Estonia
  • Bank personel in China using computers to attack Australia
  • Groups of thugs in Egypt using cyber attacks on Tunisia
  • None of the above
6. There are a defined set of cyber attack characteristics that can clearly identify the different types of actor motivations.
  • False
  • True
7. A 2009 attack on more than 30 companies including Google and Yahoo stealing intellectual property was attributed to Taiwan. Where were the hackers traced back to?
  • Taiwan
  • China
  • U.S.
  • Russia
  • Iran


8. ___________ of infrastructure means a failure in one element could cause cascading failures on multiple _____________ infrastructure components.

Choose the BEST set of terms to complete the phrase above:
  • interdependence; critical
  • association; cyber
  • criticality; complex
  • internet; cyber
  • comparability; internet
9. Techniques for censoring information include the following, except:
  • IT blocking
  • URL and packet filtering
  • Web feed blocking
  • DNS filtering
10. __________ are machines connected to the Internet who have been infected by a virus or spyware and may be used by others to cause damage to any computer or networks, including by "denial of service attacks" where multiple __________ can suck up the resources of certain critical computers connected to the Internet.
  • Modems, IPs
  • Bot nets; bots
  • Trojans; viruses
  • Computers; spams

Cyber Conflicts: Internet Censorship

Another looming battle that we see is of internet censorship.

When the governments try to control the public internet, a struggle over information content has caused international discord. Some governments are apprehensive about exposing their citizens to offensive material that might be morally, culturally, or politically deleterious. While other government and citizens' groups vociferously advocate free speech. Effective censorship requires multi layered access control, including laws and regulations, technical filtering, physical restrictions, surveillance, and monitoring, warnings as the last, arrests. Laws and regulations include penal codes, anti-terrorism laws, visual media laws, and legislation allowing government access to ISP and telecommunication company information. For instance, the Chinese government deploys firewalls and gateways to prevent access to certain IP addresses. It also performs DNS poisoning of specific websites and imposes harsh penalties on ISPs and organizations that carry content not permitted by Chinese law.

Many other countries also engage in online censorship including Bahrain, Burma, Cuba, Iran, Jordan, Kuwait, Saudi Arabia, the list goes on.

And even Germany and Switzerland censors specific web sites for content. Techniques for censoring information include IP blocking, DNS filtering, routing, url and packet filtering, as well as blocking the web feed. Internet content is also monitored through automated tools and manual inspection to block objectionable pages and ISP cooperation.

Censorship can, however, be circumventing through use of proxy servers, allowing anonymous access to censored material. These servers can be blocked and their use discouraged by government threats to shut down websites.

So there's a fight on the censorship fronts. The large companies sometimes fight back. For example, in 2010 Google threatened to remove its Google dot China search engine and website unless China allowed its search engine to access uncensored information.

Remove its offices from China, cancel media events and delay release of phones with Android operating system. These declarations were in response to a chain of hacker attacks on Google's servers.

Top Courses in IT & Software 728x90 And brought out the long growing battle of internet censorship into the open.

Concerning the economic consequences of such actions companies cooperating with governments receive preferential access to rights and contracts, while non cooperating companies can lead to potential harassment and litigation. Google was among the first in around 2006 to willfully abide by the Chinese internet censorship regulation. Despite public disapproval in the US, Google's decision, 2010, to suspend censorship rules in China in response to the attacks and is not only financial based but as retaliation for the espionage. The threat of Google alone may not warrant concern, but combined with other large companies such as Microsoft and Yahoo could pose a greater threat to China's situation than any government action.
Top Courses in Network & Security 728x90
Scholastic Teacher Store Spring Special ends 5/31/16
The leverage of companies against governments and the influence of individual governments have helped in

in multinationals is generally defined by local circumstances.

The complexity of the issue of government control of information is evident from both the public battle, and it is part communication company in motion and it would to mid 2011. When it had to engage with several countries, including China, India, Russia, Saudi Arabia, and UAE so that they could monitor Blackberry communication, ostensibly for fighting terrorism.
April2516-25off-sitewide468x60
Being a cross border network makes it difficult for RIM, or Research In Motion, the company that makes Blackberry, to comply with conflicting laws in different countries. For example, dealing with a call between US and somebody outside, let's say in China, can become very tricky, where US citizens are protected by US laws. China emphasizes the rights of the government to be able to intercept and monitor communication.

So there are a lot of such contentious issues that we are facing. And we need to face all of these issues as we go forward in the cyber warfare arena. There are several actors which have all independent motivation. There are several attacks that can be launched. But one thing is clear, the strategies of national governments are very strong in developing these cyber arsenals. And there's a cyber going on, and we need to discuss it and debate it and make sure this does not derail the free internet and all that we have come to expect of it. Thank you very much.

Cyber Conflicts: Future Battles - Threats to Critical Infrastructure

The cyber warfare incidents to date have not generated mass panic, and are driven more by citizen groups, rather than the overt government sponsored national campaigns. These past attacks were meant to send a political message. However, future attacks could have serious consequences, pitting nation against nation and requiring political as well as military intervention. One concern shared by all governments is that threat to critical infrastructure through electronic control systems.
Testive
The critical infrastructure is an easy target for enemy countries and rogue transnational since groups it is widely distributed geographically and left largely unprotected. The systems and manage water supply, power, oil and transport are all a part of the national critical infrastructure. Each represents different threat levels. The significant interdependencies can lead to unintended consequences during an attack.

The critical infrastructure is also increasingly under the control of SCADA systems. A supervisory control and data acquisition system. Probably through ease of remote monitoring and management. However, increased accessibility correlates with increased vulnerability to breach security. And as SCADA has become more and more homogeneous. The potential of breaches is further exacerbated since a single exploit could be used to attack multiple systems. They draw graphic distribution of critical infrastructure, the government recognizes as inability to protect everything. A key concern is that interdependence of infrastructure elements could mean a failure in a single element could cause devastating widespread damage in multiple critical infrastructure elements. The power grid is one of the most vulnerable including transmission lines, transformers, power stations and suppliers.
April2516-25off-sitewide468x60
In 2009 actually authorities found that many segments of the U.S. power Ggid had experienced and suspected hacker infiltration. Software tools are to be used to disable infrastructure while identified on the machines. Interdependencies in the power grid alone were evident from the blackouts throughout the Northeast US and Canada in August 2003. A failure of a single Ohio power plant led to complete blackout of the Northeast US, along with nearby connected portions of Canadian National Power System.

Given some fragility in the system, we need to be very careful in protecting our critical infrastructure from cyber attacks. In 2008, the US power grid in multiple regions was disrupted purportedly for the purpose of extorting money.

The water supply is another critical infrastructure.

Encompassing both fresh water supply and wastewater collection. The US has more than a 170,000 public water systems, including weather wise dams, wells, aquifers, treatment facilities, pumping stations, aqueducts, and transmission pipelines. Waste collection includes 19,500 sanitary systems and 800,000 miles of sewer lines. In October 2006, an unknown hacker gained control of water filtering plant in Harrisburg, installing software that affect the plant operations. Though the US water supply is well distributed for the country, presenting multiple soft targets.

Interdependencies are weak and the effect of any single attack would be localized affecting at most a few hundred people.

A fail bomb is easily repaired or restarted leading to quick recovery without any serious long term devastating consequences but again the potential is here.

The financial of, the failure of financial institution infrastructure is however, more serious. It could undermine public confidence in financial institutions, as well as the government.

Less clear is how to compare these financial losses to the loss of life or to injury. Not all infrastructure attacks are perceived as equally devastating.

The risk and interdependency analysis are needed to accurately determine the risks. There's a lot of work that needs to be done.

Cyber Conflicts: Cyber Warfare - Actors of Cyberwarfare

Cyberwar acts are continually morphing as a variety of actors are strengthening their skills and devise new ways to bolster their cyber arsenals that are growing both in sophistication and scale.

In order to be able to predict and envision how cyber warfare may evolve over time, we turn to examining the current actors and their motivations. So let's look at who these actors are.

The cyber warfare involves several actors including nation states, terrorists, sociopolitical groups. And they all differ in their primary intent and targets.

April2516-25off-sitewide468x60
Nation states aim to weaken the enemy nation to give the attacker wartime advantage. The terrorists generally inflict damage as a revenge, or as a show of strength leveraging it to solicit sponsors and recruits.

And sociopolitical groups create and relevance in political negotiations and policy formulation.

In some cases the distinction between terrorists and social political groups has blurred with groups defined by overlapping motivations.

Social political groups may have the tacit support of government organizations when their objectives align. In addition, secondary players work symbiotically or parasitically with major actors towards their own goals, with political or financial. Engaging in espionage or reconnaissance attacks on the internet infrastructure and the raw cyber vandalism.

The primary actors in the cyber warfare arena are states, non-state actors and international organizations. Arguably, anybody who uses the internet can become an actor in this arena.

Groups of state citizens targeting either their own government or other states, in this case, patriotic hacking, have influenced the course of domestic and international politics, which is a game changer.

In the past, states mostly watched on the sidelines as noisy hackers demonstrated their hacking skills by hacking each other's websites, often for bravado with little real impact.

Over the last few years, however, states have become the most active players in the cyber arena. Governments, military, and intelligence agencies have recognized the potential harm that cyber attacks could inflict on their countries information and communication infrastructure.

It's physical infrastructure, economy, as well as potential benefits of a cyber arsenal for counter attack and first strike capabilities.

So far, states have primarily focused on identifying vulnerabilities in enemy infrastructure, espionage, and intelligence gathering, but their stats are increasing acquiring hacker assets to be able to stay ahead of their adversaries in developing strategic cyber warfare capabilities. Several countries, including the United States, Russia, China, and Israel have gathered formidable arsenals of cyber weapons. However, they remain weak in defending against sophisticated cyber attacks. The point to note here is that, as we are collecting all of these cyber arsenals, the basic premise that the cyber ward is a stabilizer and equalizer against discrepancies. And the current expanse of countries is changing.

More money, more resources are giving more leverage to countries with more resources to have a better cyber arsenal. For the strategic advantage which some of the foreign countries have in being able to launch cheap and dirty attacks is changing. And the attacks are getting much more sophisticated. And there's a huge asymmetry in defense and offence, there are multiple targets to defend, when only a few vulnerabilities could be exploited for a successful attack. Therefore, most countries are fairly weak at defending against cyber attacks.

A major fear has been cyber attacks launched by Islamic terrorists, some of whom had demonstrated some initial hacking promise.

However, the fear of attacks by terrorists on critical infrastructure have not been realized.

And the threat of extreme harm posed by non-state actors has thus far proved unfounded.

Most of the attacks from such non-state actors are focused on propaganda and publicity to mobilize people to join their cause and join their fights.

But such cyber attacks have not directly caused much substantive damage. Sophisticated cyber attacks are no longer a matter of a viskit program, or executing a spectacular attack, but rather rigorous processes that require large investments in manpower, training, computing, equipment, and intelligence.

Most non set actors are unable to compete with the resources of large states. They, however, continue to effectively use social media and other web resources for fundraising, propaganda, and member recruitment.

The arena of cyber warfare has expanded steadily as internet connectivity and the number of individuals willing to use internet for political objectives grows. For instance, some attacks launched during the Russian conflict with Georgia, Estonia and involved Russian citizens, who prompted by nationalistic zeal work in mass to launch attacks against government and business websites in Estonia and Georgia. This has raised a spectrum of different form of war field, a cyber war that is conducted by civilians of one country against government institutions and civilians in another country but may or may not be state sanctioned or even controlled by the military of the state. Citizens are also involved actively in fomenting unrest against national governments in response to propaganda, information warfare of other countries. The Arab Spring triggered fear among many authoritative leaders of similar social, social media field revolutions. Which are in turn prompted them to constantly scour the network for activity that may catalyze into an uprising similar to the Arab Spring.
Testive
Ironically, even those days may store public outrage and basically support several attacks against adversaries. The same important citizens can strike back at the state to bring political change in their own countries. In addition to states, non-state actors and civilians, international organizations such as the United Nations, the Organization for Security and Cooperation in Europe, NATO and the Shanghai Cooperation Organization have become key players in fostering International cooperation aimed at reducing the threats to international peace, peace, and security posed by a possibility of full scale cyber warfare. The activities of each of these international organizations have, however, often reflect the narrow strategic interests of key state members. And despite strong rhetoric about cyber cooperation, and limiting the potential of conflicts, negotiations toward agreements and treaties often exhibit crucial differences among these key states and of the international organizations compose of these states.

An absence of this consensus is also influenced by insufficient credibility of international organizations to provide guarantee of compliance. With any cyber arms control or cyber peace treaties signed by member states.

Fundamental problems in actor definition lie in actors serving as proxys for others and in differing perception of actors. First, the distinction between state and non-state actors is often blurred because these non-state actors often have tacit and financial support as at the patronage of government organizations, such as Hezbollah being a proxy for Iran, the Russian Business Network being a proxy for Russian government and the Hidden Lynx hacking group being a proxy for the Chinese government. All of this are basically attributions to different organizations without concrete proof.

It is very difficult to prove the nexus conclusively, hence this ambiguity.

Second, the definition of terrorism differs based on perception. A social activist for some could be a terrorist for others. They have been making the distinction even fuzzier. For example, the cyber terrorism has been used to describe Al Qaeda's use of we to influence Young Muslim United States and Europe to join jihadis aimed at achieving Islamist objectives. Of course, some of the same protesters that have been initially categorized as cyber activists by using social media in protests against the Kadafi regime in Libya and the Assad regime in Syria, are now categorized as cyber terrorists because they also support implementation of sharia and establishment of Islamic states. And politically, in the case of Syria, use the internet to call upon Muslims in Europe and the United States to come join in the jihad against Assad's regime.

So this is a complex scenario.

Tuesday, May 17, 2016

Cyber Attacks in a Global Context


Microsoft Press

All right, so let's sort of wrap things up here and try to think in terms of trying to explain the different types of hackers that exist and why. The motivation question, why they hack. Searching this model here by Nir Kshetri, a researcher at the University of North Carolina, Greensboro.

He developed this model of cyber attacks using theories of human motivations that I've just described. But also putting it into a more global context and focusing on cultural aspects,

cultural factors may influence the motivation of the attacker. And also looking at the profile of the organization that is being attacked.


This is useful because the theories that I was explaining before really focus on just individual perceptions in individual motivation. But, you can't really take individuals out of their cultural context, okay. So that hacking should be seen as partly culturally determined as well as individually determined. What Kshetri has done is looked at some of the characteristics of source nations. So you know where the source being where the hacking is originating, where is it coming from.

In certain countries probably would be more conducive to hacking. All countries have people good at computer skills. Why do some countries produce more hackers than others? Well, could be due to something about the nation itself, or the country. When economic conditions are poor, jobs aren't plentiful. Those with good computer skills who normally could be highly employed in many countries, they have a difficult time getting legitimate employment. They may then use those skills for criminal purposes. Also countries vary in terms of the regulations and social norms. In some cases hacking is not seen as as much a criminal activity as it is, say, in some western countries. So there's characteristics of the source nation that will influence the motivation for attackers. There's also characteristics of the attacker. But in the middle here, ad we're looking at it under motivation for the attack, what Kshetri has outlined are sort of three primary sources of motivation that relate to the continuum I had on an earlier slide. There's extrinsic motivation. April2516-25off-sitewide300X250
And then there's pure intrinsic motivation, enjoyment base. We do it because it is fun, gives us autonomy, provides a challenge.

Then there's a sort of middle one, the sort of obligation we're doing it because we feel obligated whether to a country, to an organization or to a group that we belong.

But the motivation for the attack may actually determine what type of attack ends up occurring.

Earlier we talked in an earlier lecture, we talked about targeted attacks, carefully planned out and opportunistic attacks. Those that sort of just present themselves.

Well when in a state of flow or when operating out of intrinsic motivation, people may be more likely to pursue opportunistic attacks. What's available now? Whereas extrinsic motivation, looking for a financial gain for example, or obligation to social groups you belong to, they'd be more targeted. More carefully planned out.

Also, the profile of the targeted organization is gonna influence the type of attack, especially if you're looking at it sort of for political purposes, or for financial gain.
 Rakuten Affiliate Network Welcome Program
You're gonna look at the symbolic and financial significance of the organization. And also any sort of weaknesses that they may have in their organization. And this sort of then explains the different types of hacking that we see.

Your positive deviance, if you will, the whitehat hackers are probably gonna be operating perhaps more out of enjoyment-based interests and motivation.

Your hacktivists may be operating more out of community. They're obligation based intrinsic motivation.

Those who are motivated most by financial outcomes or gain, extremes of motivation, would be targeting organizations. And finding those that will maximize their outcomes. In all cases though, you can bring it back to expectancy value theory. Okay, they're attacking and they're performing a behavior striving for some goal based on the outcomes whether its enjoyment or financial gain.
 $30 off Norton Security Premium 1 Year. Use code NSBUCA30OFF. MSRP $89.99

And when they think that its likely there's a chance that they will attain value to outcomes whether they're intrinsic or extrinsic the motivation to hack will be quite high.

Cyber Attacks in a Global Context


banner
All right, so let's sort of wrap things up here and try to think in terms of trying to explain the different types of hackers that exist and why. The motivation question, why they hack. Searching this model here by Nir Kshetri, a researcher at the University of North Carolina, Greensboro.

He developed this model of cyber attacks using theories of human motivations that I've just described. But also putting it into a more global context and focusing on cultural aspects,

cultural factors may influence the motivation of the attacker. And also looking at the profile of the organization that is being attacked.

This is useful because the theories that I was explaining before really focus on just individual perceptions in individual motivation. Testive Symantec Corp. Symantec CA But, you can't really take individuals out of their cultural context, okay. So that hacking should be seen as partly culturally determined as well as individually determined. What Kshetri has done is looked at some of the characteristics of source nations. So you know where the source being where the hacking is originating, where is it coming from.

In certain countries probably would be more conducive to hacking. All countries have people good at computer skills. Why do some countries produce more hackers than others? Well, could be due to something about the nation itself, or the country. When economic conditions are poor, jobs aren't plentiful. Those with good computer skills who normally could be highly employed in many countries, they have a difficult time getting legitimate employment. They may then use those skills for criminal purposes. Also countries vary in terms of the regulations and social norms. In some cases hacking is not seen as as much a criminal activity as it is, say, in some western countries. So there's characteristics of the source nation that will influence the motivation for attackers. Find Enroll Learnbanner
There's also characteristics of the attacker. But in the middle here, ad we're looking at it under motivation for the attack, what Kshetri has outlined are sort of three primary sources of motivation that relate to the continuum I had on an earlier slide. There's extrinsic motivation. And then there's pure intrinsic motivation, enjoyment base. We do it because it is fun, gives us autonomy, provides a challenge.

Then there's a sort of middle one, the sort of obligation we're doing it because we feel obligated whether to a country, to an organization or to a group that we belong.

But the motivation for the attack may actually determine what type of attack ends up occurring.

Earlier we talked in an earlier lecture, we talked about targeted attacks, carefully planned out and opportunistic attacks. Those that sort of just present themselves.

Well when in a state of flow or when operating out of intrinsic motivation, people may be more likely to pursue opportunistic attacks. What's available now? Whereas extrinsic motivation, looking for a financial gain for example, or obligation to social groups you belong to, they'd be more targeted. More carefully planned out.

Also, the profile of the targeted organization is gonna influence the type of attack, especially if you're looking at it sort of for political purposes, or for financial gain. You're gonna look at the symbolic and financial significance of the organization. And also any sort of weaknesses that they may have in their organization. And this sort of then explains the different types of hacking that we see. banner

Your positive deviance, if you will, the whitehat hackers are probably gonna be operating perhaps more out of enjoyment-based interests and motivation.

Your hacktivists may be operating more out of community. They're obligation based intrinsic motivation.

Those who are motivated most by financial outcomes or gain, extremes of motivation, would be targeting organizations. And finding those that will maximize their outcomes. In all cases though, you can bring it back to expectancy value theory. Okay, they're attacking and they're performing a behavior striving for some goal based on the outcomes whether its enjoyment or financial gain.

And when they think that its likely there's a chance that they will attain value to outcomes whether they're intrinsic or extrinsic the motivation to hack will be quite high.

Quiz 1: Introduction to Cybercrime

1.

From the options below, select the two fundamental issues that make solving international cyber conflicts difficult?

Problems with attack attribution due to anonymous nature of Internet
Jurisdictional issues due to Internet transcending national boundaries
Technical difficulties in operating the Internet
All of the above

Pearson Education (InformIT)

2.

Identify a recognized type of cyber crime from the following options.
Hacking
Extortion
Identity theft
Cyber bullying

Child soliciting and abuse
All of the above


3.

Which of the following could be an example of "positive deviance"? Select all that apply.
Testing security vulnerabilities of a security system
Stealing and selling intellectual property
Gaining unauthorized access to a computer
Threatening national security

Python Specialization from University of Michigan

4.

What types of hackers promote their political goals or ideas using non-violent hacking?
Hacktivists
Crackers
Black hat hackers
Cyber-punks



5.

What are the fundamental parameters of motivated behavior?
Intensity
Persistence
Direction
Initiation


Learn SEO with UC Davis and Coursera. Prepay and receive a 10% discount.

6.

It is true to say that motivated behavior is __________.
More like a trait, varying based on personal characteristic
More like a state variable, varying from situation to situation



7.

Which of the hacking motives below is related to the psychological drive of mastery?
Ideology
Recognition
Financial gain
Challenge
Curiosity

None of the above

Testive

8.

Which of the outcomes below are driven by both internal/intrinsic and external/extrinsic motivations? Select all that apply.
Pride
Fun
Mastery
Monetary gain
Fame
Status

Self satisfaction

Learn Corporate Finance with BNY Mellon and Coursera

9.

What are some of the motives for hacking? Select all that apply.
Ideology
Greed
Challenge
Status
Curiosity

None of the above

Become a Web Developer in 2016 with Coursera

10.

What does IP stand for?
Interest Protocol
Internal Packets
Internet Protocol
Internet Packets

Cyber Conflicts: Motives for Hacking

https://www.coursera.org/learn/cyber-conflicts/lecture/LwoZ6/motives-for-hacking

banner


So let's look at some of the motives that have been out there in the literature for hacking and for cyber crimes. Different things that come up, okay, like greed, money, financial gain is one big reason why individuals hack into systems. Monetary outcomes are attractive. It clearly relates to the drive to get ahead, the drive to acquire things, okay? There's also a challenge involved, the old school hackers, the white hat hackers are referred to. They be motivated by the challenge of breaking into a computer network or system. This relates to the drive to learn, the mastery need that I imagined. It also could relate to the drive to acquire cuz you're acquiring new skills which may improve your overall functioning as well. Another set of motives for hacking are status and recognition, okay? This is also an important motive for those who may fall on the positive deviant side of things and even the cyberpunks that I referred to. The idea is that you gain status or recognition through your accomplishments.

This could be seen as the drive to bond, to get along with others. You gain status, they admit you to their group. You maintain membership in the group and you have an elevated status in the group. It's also, perhaps, related to acquiring things and getting ahead, because with status comes greater material gain, as well. Another motive is curiosity that relates directly to the mastery motives of the drive to learn that I mentioned before. And then finally, you have the other motive of ideology, whether it's political or religious. This probably relates most strongly to the drive to bond, again, cuz it's associated with social groups.

So this is the content. All right, so we understand a little bit more about why we do things. What gives us energy and directs that energy in terms of motivation. But that's not a comprehensive model or explanation of motivated behavior. We need to add some cognitive components. So one theory I think is useful for this discussion, as well as for discussions that we'll have the remainder of this course, is expectancy value theory. A sort of omnibus theory of human motivation that can explain why people choose to do the things they do. Expectancy value theory has a pretty basic set of premises. First it's gonna argue that behavior is instigated and directed to the extent that people one, believe that behavior or effort will lead to goal attainment.

If I try, I will attain this. I will reach this goal if I put forth effort. All right, so for example, the student in the class will say, if I study 10 hours this week, I will get an A in the class. That's sort of a believe that effort translates to performance. There's also, however, behavior will be instigated and directed to the extent that people believe that outcomes, or rewards, are attached to goal attainment.
Norton by Symantec
If I get an A on that test, something good will happen, I'll get rewarded. I'll get an A in a class, I'll get into graduate school.

Okay, so outcomes being attached to goal attainment. Finally, you have to value those rewards or those outcomes.

It's like, yes I want to get into grad school or I want to get an A in a class, I value that, if you don't value that, then you may not be motivated. The key to expectancy value if you look at the form E times V, it's a multiplicative function, which means both elements are necessary. You need the expectancy that effort will lead to goal attainment. And you need the value. You need to value the rewards that will follow from it. So, going back to the hacker example, if a hacker believes that they can break into the system, and something good will follow from breaking into that system, they will be motivated to break into the systems.

In expectancy value theory, there's this concept of force, motivational force, okay? And force is, simply the multiplicative function of expectancy times value, okay? So, your psychological force to perform an act is a function of the expectancy that the act will lead to different outcomes, and the value attached to those different outcomes. We call that the valence of performance. So, the goal that you're striving for, the performance that you're shooting for will be attached to many different outcomes. Each of those outcomes may have a different value attached to them. If we sum the multiplicative function of each of those

terms, then we have an overall force. Which is how motivated we are. It's the intensity parameter of motivation that I referred to before.

Obviously, form is not critical to memorize, it's just putting this up there to show you that psychological force and motivation is really a joint function of expectancy and value. I could value something very much but if my expectancy of getting it is zero, the probability of me obtaining that goal is zero, then I'm not gonna be motivated. I'd love to play in the NBA. The National Basketball Association. But at my height and my age, there's just not way it's gonna happen. Expectancy is literally zero. So how much I would value that, I would not be motivated to try. Likewise, you can think there are things that we see that are sure things in life, we can attain them, okay? But we don't value the outcomes so again, we wouldn't be motivated. Here is a little example of expectancy theory at work. Imagine you were choosing between two difficult tasks, okay? You can choose projects at work, or you can put it back to the cyber crime situation. Think of a hacker trying to hack into two systems. One very easy, okay? Maybe their grandmother's. Something very low security, okay? So an easy system to hack into or a difficult system to hack into. Or at work, we can choose between an easy task or a difficult task.

Accomplishing those tasks, success on those, we attach a probability of success to it. That's expectancy. How likely is it that I can break into this system? How likely is it that I can accomplish this task, this easy task? How likely is it that I can have success in the difficult task? So there's a probability of success attached to each task.

Attached to the goal attainment in each situation are outcomes. And I just put two up here for illustrative purposes, let's just say that the same outcome, financial gain and status and recognition. There's gonna be some monetary outcome that you will receive and there's also status and recognition. Now, people different values those outcomes differently. In this case, let's say it's me, I value status and recognition highly and financial gain less so. Okay, so I look at how likely are these outcomes that I value attached to success. In the easy task situation, okay, notice that I have highlighted the link between success and status and recognition at 0. Doing something easy is not gonna give you much status or recognition, everybody can do it, you get no recognition for it. And that's something I value highly, so you can already sort of start seeing that I'm probably not going to be motivated doing the easy task because there's nothing of value attached to it. For succeeding on a difficult task or breaking into a complex system however, it's likely to bring status and recognition which I value highly. That got a probability of 1 attached to that.
Pearson Education (myPEARSONstore)
So if you do the math, you can do it yourself or you can just look at what I have on the slide. The motivational force for the first task is actually 3.5. The motivational force for the second easy task is 1, okay, so the difficult task has a higher motivational force, 3.5 versus the motivational force of 1 for the easy task. The individual should choose the difficult task in this case. Basically because there's a chance, not a certain chance, but there's a chance of obtaining a valued outcome. From the easy task, there's nothing of value to be gained. So that's an illustration of expectancy theory at work. So let's try to use that in explaining some of the cyber attacks.

One more piece here though is that if we go back through the outcomes that are attached to success. We can think of those outcomes as varying in terms of whether they provide intrinsic motivation or extrinsic motivation. The incentives for action are the outcomes on the far right hand side of that diagram I had up there. These incentives for actions may stem from internal feelings

which could be quite powerful, often discounted, but they're quite powerful. Things like pride, self-satisfaction are important, and may drive our behavior. So those are internal incentives. There's also external factors, external contingencies, the monetary gain we may get from doing a good job, for example. So now think of the outcomes as varying from extrinsic outcomes to intrinsic outcomes. Intrinsic being fun, mastery, autonomy. Extrinsic being money. But there's also some that are sort of in the middle. They're sort of intrinsic because they're feelings, but they are sort of driven by extrinsic factors. And those are things like obligation. The shoulds in our life. I know I should do that. That's an internal feeling that makes us do something. But it's really sort of driven by
Microsoft Press
attachment to the external world, obligations. Status and fame I think we outta put there also. It feels good to have status. But primarily, even though it's an internal feeling, it's because we want to elevate our status in an external group. So there are different kinds of incentives and you can see them being folded into the different types of hackers. I wanna focus one for a second on the intrinsic motivation side of that equation. Because if you look at trying to explain why do individuals start hacking and while they continue and progress perhaps from a simple hacking into very complex and ultimately sort of destructive. I would argue because that that's because computer hacking is ideally suited for an extreme form of intrinsic motivation, which we call psychological flow.

Psychological flow is sort of an intense high performance state, okay? You may have experienced it. When you're in flow, everything comes easy. If you're an athlete, it's when you have the hot hand in basketball. Whatever you do, it's going to work, okay? Everything's working and you're not really focusing on things. That's the state of psychological flow. It's the state of optimal experience.

Well research has been done

trying to determine when individuals get in the state of flow.

And it seems to be when an individual's skill levels match the challenge of the task.

So skills matched with challenge increases the chances of flow. And as you go up the continuum on both skill and challenge and you match, the probability of flow expands. So when you have high skills and a very high challenging situation, your chance of experiencing flow are even greater.

So this is sort of the challenge that many computer hackers, those with good computing skills, may sit down and start trying to hack into computer systems, okay? And they get into a state of physiological flow because there's a balance between skill and challenge. And they're basically doing it because it's fun.

They're experiencing this optimal challenge and they get good at it. Then, however, they may use it in different situations. But seeing it from this perspective, computer hacking is sort of a breeding ground for flow for those with high computer skills.

Cyber Conflicts: Understanding Motivated Behavior

https://www.coursera.org/learn/cyber-conflicts/lecture/UHZb7/understanding-motivated-behavior


Motivation is one of those terms that most of us believe that we understand fully. However there's many misconceptions about motivation, okay, misconceptions about them. The most common is that motivation is a trait, people tend to think of motivation as individual difference.

Something that people vary in. You're motivated or not. You're highly motivated, weakly motivated. In actuality, it's more appropriate to think of motivation as a state variable. It's something that varies from situation to situation and from time to time.

Now, we may be highly motivated to do our job task in some situations, to do them diligently with the proper care and high effort. And other times in other situations, or other projects, we may be more weakly motivated and do not care that much about being diligent and putting forth high effort. So within ourselves, across time and space, we tend to vary in motivation. So motivation is best seen as a state-variable and not a trait.

In defining motivation, it's probably best to think about the parameters of motivation. What it involves. And if we look at motivated behavior, cyber attacks included, we can see it varying in terms of four different parameters. First, it varies in terms of initiation. What is it that energizes behavior?

It also varies in terms of direction.

What are you attempting to do? Where are you going with this energy?

Finally, it varies in terms of intensity. How energized are you in carrying out those behaviors? And finally, persistence. How long will you try?

So those are the four parameters, initiation, direction, intensity, and persistence. What energizes you, what direction is that energy going, how long will you persist, and at what level of intensity?

To simplify things, I think you can boil these four parameters down to two fundamental questions. And that is what causes behavior? And why does behavior vary in its intensity? In terms of the first question, what causes behavior, this is what psychologists refer to as the content of motivation, okay? And the content of motivation you see in this slide, we think about behavior and look at the causes or the precursors of behavior. We see that the most immediate precursor of behaviors are goals.

We typically have, especially for purposeful behavior, we have an intention or goal, what we want to do, all right? Going back to the cyber attackers, it may be to create havoc. It may be to advance your political cause. Or it may be to steal things. That's your goal.

Where do those goals come from however? They come from needs and drives. Needs are deficiencies. Psychological or physiological. Physiological drive is hunger, for example. When I have gone while without eating, the body sends signals saying, hey, you know what? Go find food. That's the hunger drive. But we also have psychological drives. The drive to master, to achieve, to bond with others. These needs set up drives which are sort of the tendencies. Energic tendencies to act towards our goals. So these are the content of motivation. And there's a lot of different needs and drives that have been hypothesized over the years. It'd be nice to sort of boil that down into sort of some basic fundamental universal human tendencies or drives. And some psychologists make a distinction between two basic drives, motives if you will. One being getting along with others, the other being getting ahead of others.

So many of the different drives and motives that we have can be boiled down and put into one of these two categories. We are social beings. Our species has evolved because of our ability to bond with others, to cooperate, to reciprocate with each other. And that's one of the bases of our communities, which has allowed us to advance as a species.

So much of our behavior is motivated to join groups, to remain in groups, to bond with others.

At the same time, we also, in terms of individual fitness, have survived by getting ahead of others. Competition is sort of ingrained in humans as well. So this notion that we have to acquire things for our own fitness. So we're motivated to compete, or motivated to acquire things that we think will increase our fitness. And if you look at your behavior, much of it can be boiled down into getting along and getting ahead. However, I would add a third category which is particularly relevant, I think, for explaining cyber attacks and cyber crime and hacking and that is mastery. Okay, there's sort of a drive to master our environments. It's sort of the curiosity that most of us have. The desire to learn things, to master our environment.

The old expression curiosity killed the cat, if you have kittens and cats, you know how curious they are. Well we may not be as curious as cats, but we are curious. Place us in new environments, we try to figure them out.

Mastering our environments has helped us to advance as a species as well. So I think if you think of these three basic motives. Getting along, getting ahead, and mastering our environments can explain much about behavior and they can explain behavior in cyber attacks and cyber crime as well

Monday, May 16, 2016

Actors of Cybercrime

https://www.coursera.org/learn/cyber-conflicts/lecture/Qlu34/actors-of-cybercrime


In this module, we're gonna be looking at theories of human motivation, and how they may be used to explain cyber crime. Cyber crime is sort of a unique business, okay? The perpetrators or attackers, often operate in anonymity, and have low probability of being caught or detected.

Like many crimes,

those who perpetuate cyber crime do it for many different reasons, as we'll see. So it's not easy to lump all cyber criminals into one box and explain their behavior neatly. So we'll be looking at theories of human motivation that can explain the different types of cyber crime.

Let's start, first though, by looking at the behavior that we're trying to explain, all right? Cyber attacks occur in many different situations, many different contexts. Let's just use for now a look at hacking, because most cyber crime at some point deals with an individual attacking a computer network and on having unauthorized access to it. Cyber attack can be seen as deviance, but according to different perspectives, the term carries both positive and negative connotations.

When research first started on cyber criminals, there was a distinction made between black hat and white hat hackers. It's probably an old, outdated term, but it's useful to explain this difference between negative deviance and positive deviance. Negative deviance you can think of as your typical computer criminal. They can be national security threats, they're after intellectual property. They're gonna steal secrets and they're gonna sell information, things that we see as bad. Positive deviance refers to hackers who break into systems, unauthorized access to computer systems, but the intent is seen in more positive light. White hat hackers, initially portrayed themselves as pioneers of public access. They were the people who were arguing and keeping open source out there, keeping the Internet free for everybody. They would also be claiming to just test out the security of systems for organizations. So they would sort of break in. It's like the thief that comes into your house and leaves a note on your refrigerator and says, hey, your house is insecure. I didn't take anything, but I just wanna let you know that your house is insecure. Similar here in positive deviance. Breaking in, unauthorized access, but just testing out the security of systems. They see themselves as performing an important service. Many of us, or many people still this as deviance, but obviously it's not as negative as stealing secrets and selling them.  This distinction between positive and negative deviance carries over into the typologies of cyber attackers that have developed over the years. I have a list of them here. I'll run through them quickly. We have the old school hacker, these are the computer programmers primarily interested in lines of code, programming, and analyzing systems. For the most part, these are what are referred to as the white hat hackers. There's no malicious intent or criminal activity. However, you can also say that they aren't concerned about privacy or proprietary information. They also, as I mentioned before, are likely to believe that the Internet is an open system that should be used by all.

These actually were the first known hackers in the early 60s. These were computer programmers at MIT and Stanford.

Shortly after, as the Internet evolved I should say, you saw a different type of hacker occurring, and these are the cyber-punks, or what have been labeled cyber-punks. These are predominantly young males. They like to break things. Okay, they hack into systems to vandalize or disrupt.

They also like to brag about their accomplishments, which often gets them caught by authorities.

Another set of hackers, in fact these have been growing at a fast rate, are professional criminals. The term has been used crackers to refer to this set of attackers.

They break into systems to steal information and then sell it. They may be hired by governments, or they may be hired to do corporate spying. The idea is to get intellectual property or to get information and then to sell it.

There are also coders and virus writers. These are individuals with a strong programming background, they write code that others will use to create havoc or to break into systems. They tend to see themselves as the elite. They actually don't do the hacking but they write the code, and write the programs that allow others to do it. Finally, more recently in the last decade or so, you see an increase in activists and patriots.

The term hactivists that has been used for social activists who use the computer and use their hacking skills to promote their goals of their organization. They tend to be political and they see themselves as non-violent activism.

They see themselves as perhaps a tool against oppression. The group Anonymous, many of you are aware of them. That is perhaps the best example of this. Others however see them as cyber terrorists.

And then final group is patriots, these are the individuals that take action on the basis of nationalism or patriotism, sort of like defending their country. In a way, they could be the old codebreakers of World War II as an analogy. The point here is that there's a diverse set of actors out there, perpetuating these cyber crimes, or hacking.

And this diverse set of actors has different underlying motivation. So to fully understand the sets of actors and why they're doing what they're doing, we need a better understanding of motivated behavior.

Evolution and Types of Cybercrime


https://www.coursera.org/learn/cyber-conflicts/lecture/MeWFG/evolution-and-types-of-cybercrime


We've had a history of crime in this world. And all kinds of crime from murder to other capital crimes, to basically forgery and fraud. And basically, bullying, all of these are different kinds of crimes at different levels.

So, why is the internet important today? Why is cyber crime so important? What the cybercrime has done is, it has taken a lot of the crimes that we had in the street. And they have or given them another vector in which they can be coveted.

Cybercrime today is defined as a crime that utilizes computers and networks.

However, there are three distinct acts of crimes where the computer is a target, weapon, or just a facilitator.

In the first case, computer is a target. It involves activities such as theft, destruction, disruption of data services and software. In the second case, the computer is a weapon which involves using a computer to launch attacks such as cyberbullying, pornography, child pornography, spam, ect.

And in the third case, computer is a facilitator which involves supporting traditional crime such as robbery, murder, and terrorism, ect. Support of that crime, either through recruitment or through trying to find out what they can, learn about the victims, and using this for solicitation.

Cybercrime is generally considered as a regular crime with a new

in the internet, but it differs quite a bit. Well, the difference is the scale and the reach of the crime using automatic scanning tools and bots attacks can be launched across millions of peoples within minutes. And within hours, the entire globe could be covered with the same virus, worm, or anything else.

How did it evolve? Cybercrime really started as a hobby of bored computer scientists and young students, whose primary goal was to demonstrate their prowess and show their hacking abilities to the community of their peers. And if there were hacking groups, underground clubs, that provided support to these activities. And they were basically trying to outdo each other. Even though some of the attacks caused serious financial damage, the perpetrators seldom gained any financial remuneration from the attacks. And in most cases, the victims are random without any specific targets. However, since the 2000s, there had been a gradual shift towards more organized crime and criminal networks, rather than individual hackers.

Cybercrime has become big business. And as you can see from a spate of cybercrimes and the breaches that have happened recently. They are getting targeted toward companies which have deep financial pockets from which they can make money.

What are people using the cybercrime for? For stealing passwords. For stealing credit card numbers. For stealing financial information. So that they can actually benefit from this. There's a huge market out there where you can buy stolen credit card numbers. And to the extent that in case of credit card does not work or have been closed, you can actually get a refund back. So, it is a real business today.

There are several way in which cybercrime can occur. You know, one of the most attacks of information in which computer and networks have reached in order to collect information such as credit card, trade secrets, information about dissidence, and information involve large corporations where hackers break in by breaching security or from individual where hackers have it inside the organizations.

And they use all kinds of information like social engineering, phishing messages, just to con employees of organizations into revealing information that will allow them to break in. The second type of priming involves extortion, where criminal gangs breach the security and threaten to destroy the data and infrastructure. Or reveal private information in case hush or protection money is paid.

And the third involves fraud on the Internet, and this can take many forms. It usually involves providing false information to a specific individual or to the entire community. For instance, stock prices can be manipulated by fabricating positive or negative information, and then disseminating widely among market participants. And it has happened before. It has led to markets going up and going down, and specific stocks crashing.

Another part of crime is called Identity theft, in which, hackers can assume the entity of the victim and assume their persona on the internet to make online transactions. People have bought cars on other people's identities, they have run debts to hundred of thousands of dollars. And the problem becomes for the victim then to go and clear their name out, to get their credit history restored, and it's a horrendous problem. One key issue which is not really a part of traditional crime, a cybercrime that is considered today is media virus and distribution. This has always been a controversial topic with a societal divide on the culpability of the perpetrators and the morality of such practices. On one hand, people are offended by the greed and the ability to make money for the large corporations which are selling music. And on the other hand, we have the people who are objecting to this as a theft of information, theft of intellectual property.

And so given that this is such a prevalent means of getting music and other media, this is becoming a very societal and a social issue. In the long run, laws are created by the societal norms. And in this case, the societal norms seem to have changed. So, this is another thing that we'll discuss in depth and figure out where public opinion on this lies.

The cybercrime can also be classified based on sophistication of technique that are used, and can vary from highly technical to highly social. Technical crimes involve intruding into computers, the networks, and including phishing, identity theft, denial of service, spoofing attacks, manipulation of data services, or committing fraud. And the characteristics of these crimes include, generally, a singular or discrete event from the prospective of the victim.

And it's usually facilitated by malicious software such as keystroke loggers, bots, spyware viruses, backdoor, or trojan horses. These are all the means in which crime can be done.

But it can be facilitated by exploiting different vulnerabilities.

And the characteristics of the social crime include, generally, using legitimate tools such as forum social media, messaging applications and dating websites, and they are generally repeated contacts or events from prospect of the user. And the activities such as stalking, harassment, child predation, extortion, blackmail, complex corporate espionage, and cyberterrorism. All of these are a part of the social crime or the social way they literally can do crime.

And having talked about this, in the next segment, we will talk about the active motivations of cybercrime. How do we solve cybercrime and solve the International issues in cybercrime? Thank you. This is the end of the first module in lecture one.