NEW - IDC WebcastFree E-NewslettersRSS Feeds | Site Map
Security Resource CentreBusiness Value of TechnologyMunicipal Centre
SearchSearch
Tips
Policy
Slice by Program

From cybermischief to cybercrime

By: Richard Bray(12/07/05)

In the good old days - like June 2002 - IT security professionals were worried about vandalism. OCIPEP, the federal government's Office of Critical Infrastructure Protection and Emergency Preparedness, was advising departments to secure their web servers, due to an increase in web site defacements with anti-G8 messages.

But it was not long before online cybermischief was taking second place to escalating cybercrime, and the RCMP was issuing a warning about phishing or "brand spoofing," described as "the act of sending an e-mail to a user falsely claiming to be a legitimate enterprise in an attempt to scam the user into disclosing private information.

"Government, financial institutions and online auctions/pay services are common targets of brand spoofing," the RCMP noted.

Both kinds of activity are undoubtedly criminal, and can undermine public confidence in online institutions, including governments. But the latest trend in attacks is aimed at governments themselves. Around the world, the Internet has become an inexpensive and accessible vehicle for every kind of overt propaganda and covert communication in support of combat operations. The Internet, in short, has become a weapon.

The spectrum ranges from civil unrest to all-out war. Youthful rioters in France have used web sites and blogs to incite a mood of rebellion against the government and text messaging to coordinate attacks against particular targets. As the French government moved to block specific information about the violence in an effort to cool things down, the Internet became an unofficial but universal channel for information to keep the fires burning.

In 2002, when terrorists videotaped the murder of Daniel Pearl in Pakistan, many mainstream media outlets refused to broadcast the footage. It slowly became available on the Internet, but limited broadband connectivity and inefficient distribution blunted its impact. By contrast, the May 2004 murder in Iraq of Nicholas Berg was flashed around the world in a variety of formats from a network of web sites.

Today on the Internet, there are Web sites with detailed instructions on how to build bombs or set up a roadside ambush. Some analysts even suspect that some combat actions against U.S. and government forces in Iraq are staged simply because they can be videotaped and posted on the Internet for their propaganda value.

Attackers do not need to hunt for potential targets on the Internet. Governments themselves are constantly broadcasting their vulnerabilities. Here in Canada, the Auditor-General's 2005 IT Security Report was full of clues for hackers: ". . . we found that most departments are not complying fully with the [Government Security] Policy, and major inconsistencies in compliance exist." Elsewhere, the report stated, "we found that many departments and agencies did not have secure controls in place. In many cases, the devices were not configured to consistently prevent unauthorized access to the systems on their networks." For more detailed guidance, "vulnerability assessments b& revealed significant weaknesses that could be exploited b&. There were also vulnerabilities that had existed for some time in the older versions of products. In such cases, the vulnerabilities cannot be rectified, and the products must be upgraded to ensure adequate protection."

In other words, the Auditor General was advising lazy hackers to just keep checking MERX and press releases about IT contract awards for the latest news about particularly vulnerable systems.

In the United States, the Government Accountability Office recently said that country's air navigation system was vulnerable to cyberattack, particularly from people with knowledge of the system.

In September, Time magazine wrote about Titan Rain, a series of attacks against U.S. government computer systems. Quoting anonymous officials and unnamed documents, the report described a pattern of highly professional, well-coordinated and often successful attempts over several years to penetrate both open and secure systems. According to one researcher working on his own, the source of the attacks appeared to be about 10 operators working through one network in China.

The skill level of the attackers was described as extremely high. In less than half an hour, they could enter a system, take everything they wanted and move on without leaving a trace of evidence that they had ever been there. These probes may be just a highly advanced form of industrial espionage, but it is a short step from there to overt hostilities.

Even the suspicion of official involvement in attacks against computer systems should be enough to sound an alarm within national governments. In 10 years, crime on the Internet has gone from prank to profit to a weapon for guerrilla warfare. Perhaps it's time to think about placing the ultimate responsibility for Internet security with the Department of National Defence.

Richard Bray (writer@canada.com) is a freelance journalist in Ottawa specializing in high technology and security issues.

Bookmark on:del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article?
Add a new commentLetter to the Editor
Find an inappropriate comment? You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields
Blog Spotlight: Sandford Borins
Sandford Borins

As Professor of Strategic Management at the University of Toronto, Sandford Borins brings InterGovWorld.com readers exclusive insights into how and why the public sector is changing. You'll find new perspectives and questions, observations and objectives, lessons and answers. Cover to Cover, the blog by Prof. Sandford Borins, appears every Thursday.

Inside Cover to Cover

Unified Communications
Data Defence

Unity is a word often heard in the public sector, with myriad agencies and departments looking to foster collective thinking around some of today's most pressing issues. The word, however, doesn't usually get mentioned in the same breath as technology. That's a situation, though, that might soon be changing, thanks to a new software platform known as unified communications.

Inside the latest issue of CGR

More Resources
Driving innovation through effective service management
This white paper discusses how a service-oriented governance framework can help ensure that IT decisions are consistent with business vision, values and strategies-and that IT delivers maximum value to the business. Complimentary with registration.
IT Service Management Solutions and the service desk
This white paper presents the capabilities of IBM Tivoli CCMDB, and describes how Tivoli CCMDB extends the value of the service desk and integrates other essential ITIL processes in support of IBM Service Management. Complimentary with registration.
Info-Tech Research Note: WAN Optimization Tools worth the investment
Multi-site enterprises experiencing WAN bandwidth demand growth and struggling to maintain acceptable application performance should evaluate WAN optimization technology immediately. WAN optimization appliances can dramatically improve inter-site WAN performance, reduce bandwidth requirements, and allow for server centralization. For many enterprises a positive ROI can be achieved in less than a year. Download this research note now. Complimentary with registration.
Advertisement
2007 Salary Calculator
Knowledge Centres at a Glance
White Papers
read more white papers
New blog entries
Thoughts of the day
This week's top stories
Most popular stories of the week
Readers write back
Comments from Intergovworld readers
Government to government
Inside the public sector machine
Government to business
P3: Public-private partnerships
Government to citizen
e-Government service transformation
Blogs
Browse Blogs By:
WiFi Hot Spot Finder
Upload Centre
Upload Your Documents
Contribute and share with your peers by uploading:
- Initiative updates
- White Papers
- Job Links
- Events
- Other
Download Centre
Most popular downloads:
Download More Documents
Download:
- Initiative updates
- White Papers
- Job Links
Subscription Services
Manage your InterGovWorld.com account!
Change your account information, password, e-mail address, and existing e-newsletter subscriptions.
Site Feedback Survey
Tell us what you think of InterGovWorld.com!
FUN SurveyFUN Survey
Take the one-minute Family Unit Networking survey!
IT Salary Survey IT Salary Survey
Take the IT Salary Survey '06 Today
Career Resources
InterGovWorld provides links to resources for government job seekers and current employees, including: current job postings, job search strategies, career options and training, and employee rights, provided by all levels of government from everywhere across Canada.

Public Service Commission of Canada
Service Canada
Jobs in Canada
Service Canada
Public Service Human Resources Management Agency of Canada