Exhaustive Study Guide on Computer and Internet Crime, Security Threats, and Countermeasures

Overview of Information Technology Security Concerns

  • Fundamental Importance of IT Security:
    • Information technology security is a critical priority for modern organizations to safeguard confidential business data and protect private customer and employee information.
    • Security measures must defend systems against malicious acts of theft, unauthorized access, and operational disruption.
    • Security controls must be continuously balanced against broader business objectives, operational requirements, and usability constraints.
    • Worldwide IT-related security incidents continue to increase rapidly in both frequency and sophistication.

Factors Driving the Increase in Computer Security Incidents

  • Expanding System Complexity and Entry Points:

    • Computing environments are extraordinarily complex and growing more intricate through the adoption of modern architectures.
    • Emerging paradigms such as cloud computing and virtualization software significantly expand the total attack surface and number of system entry points.
  • Rising User Expectations and Support Help Desk Pressures:

    • Computer support help desks face intense operational pressure to resolve technical issues rapidly.
    • Under strict efficiency demands, help desk personnel may fail to verify user identity or check proper authorization levels before granting access or resetting passwords.
    • Pervasive credential sharing among computer users (sharing login IDs and passwords) compromises access control integrity.
  • Network Ubiquity and System Architecture Changes:

    • Personal computers connect directly to global networks housing millions of other systems, enabling seamless information sharing as well as widespread vulnerability propagation.
    • Information technology has become ubiquitous and essential for organizational goal achievement, making it difficult for security practices to match the rapid pace of technological evolution.
  • Reliance on Commercial Software with Known Vulnerabilities:

    • Exploits: An exploit is an attack on an information system that takes advantage of a specific system vulnerability arising from poor system design or implementation.
    • Patches: A patch is a software modification produced by developers to eliminate a known vulnerability. Software users bear full responsibility for obtaining and installing patches in a timely manner. Delays in patching expose systems to security breaches.
    • Zero-Day Attacks: A zero-day attack occurs on the exact day a software vulnerability is discovered or exploited by malicious actors before software vendors can issue a fix or patch.

Categories and Mechanisms of Computer Exploits

  • Target Diversity:

    • Both desktop computer systems and mobile smartphones serve as primary targets for software exploits.
  • Viruses:

    • A virus is a piece of programming code, usually disguised as a harmless component, that causes unexpected and undesirable system behavior.
    • Viruses attach themselves to existing files or programs and deliver a malicious payload.
    • Propagation requires direct human intervention, such as opening infected email file attachments, downloading compromised software, or visiting infected websites.
  • Worms:

    • A worm is a standalone harmful program that resides in the active memory of a computer system.
    • Worms replicate and propagate themselves across computer networks without requiring human intervention or user action.
    • The negative impacts of worm attacks include lost data, corrupted programs, severely reduced network productivity, and significant labor overhead for IT personnel.
  • Trojan Horses:

    • A Trojan horse is malicious code hidden inside a program that appears entirely benign or useful to the end user.
    • Users are tricked into installing Trojan horses via infected email attachments, downloads from compromised websites, or infected removable media devices.
    • Logic Bombs: A logic bomb is a specialized type of Trojan horse or malicious routine that remains dormant until triggered by a specific event or condition (such as a specific date, time, or system command).
  • Distributed Denial-of-Service (DDoS) Attacks:

    • In a DDoS attack, a malicious actor takes control of internet-connected computers and instructs them to flood a target server or website with continuous demands for data and small task requests.
    • Zombies: Individual computers hijacked and controlled by an attacker without the owner's knowledge.
    • Botnets: A very large group of zombie computers controlled collectively by an attacker.
    • DDoS attacks do not require breaking into the target machine directly; instead, the target machine becomes completely consumed responding to automated traffic, blocking access for legitimate users.

Distributed denial-of-service attack diagram

  • Rootkits:

    • A rootkit is a set of administrative software tools that allows an attacker to gain full, administrator-level access to a computer without the end user's knowledge or consent.
    • Once installed, the attacker gains complete control of the system and can conceal the rootkit's presence from security scans.
    • Identifying a rootkit is fundamentally difficult because the actively running operating system cannot be trusted to report valid system diagnostic test results.
  • Spam:

    • Spam refers to the abuse of email systems to transmit unsolicited bulk messages to massive numbers of recipients.
    • It is commonly used for low-cost commercial advertising of questionable products and services, though some legitimate businesses also utilize bulk mailing techniques.
    • CAPTCHA: Completely Automated Public Turing Test to Tell Computers and Humans Apart is a software defense mechanism generating tests that human users can pass but automated software programs (bots) cannot.
  • Phishing and Variants:

    • Phishing: The fraudulent practice of sending emails that appear legitimate to trick recipients into revealing sensitive personal or financial information on fake websites.
    • Spear-Phishing: Highly targeted phishing emails sent specifically to individuals or employees within a chosen target organization.
    • Smishing: Phishing attempts executed via Short Message Service (SMS) text messages.
    • Vishing: Phishing attempts conducted via voice mail or phone conversations.

Example of a phishing email pretending to be from eBay

Classification and Motives of Computer Crime Perpetrators

  • Perpetrator Profiles and Objectives:
    • Perpetrators vary widely in technical capability, available resources, risk tolerance, and underlying motivations.
Type of PerpetratorTypical Motives
HackerTest limits of system and/or gain publicity
CrackerCause problems, steal data, and corrupt systems
Malicious InsiderGain financially and/or disrupt company's information systems and business operations
Industrial SpyCapture trade secrets and gain competitive advantage
CybercriminalGain financially
HacktivistPromote political ideology
CyberterroristDestroy infrastructure components of financial institutions, utilities, and emergency response units
  • Hackers and Crackers:

    • Hackers: Individuals who explore system boundaries out of intellectual curiosity or technical interest. Skill levels range from highly talented developers to inexperienced individuals referred to as "lamers" or "script kiddies".
    • Crackers: Individuals who break into security systems explicitly to cause harm, steal sensitive data, or corrupt operations; cracking is inherently criminal.
  • Malicious Insiders:

    • Represent one of the most serious security concerns for corporate organizations.
    • Internal fraud is frequently attributable to deficiencies in internal control procedures.
    • Collusion: Joint malicious activity between an internal employee and an external actor.
    • Insiders include full-time employees as well as external consultants, contractors, and temporary vendors.
    • Detecting malicious insider threats is extremely difficult because these individuals possess legitimate, authorized access to the systems they misuse.
    • Negligent insiders (unintentional policy violators) also possess the potential to cause massive organizational damage.
  • Industrial Spies:

    • Utilize illegal mechanisms to gather proprietary trade secrets from commercial competitors.
    • Trade Secret Protection: Trade secrets are protected under federal law via the Economic Espionage Act of 1996.
    • Competitive Intelligence: Legal information-gathering techniques focused on publicly available resources.
    • Industrial Espionage: Illegal information-gathering methods used to obtain confidential, non-public proprietary data.
  • Cybercriminals:

    • Infiltrate corporate networks to execute financial theft and fraudulent transactions.
    • Fraudulent online card transactions lead to chargebacks (disputed customer payment reversals).
    • The erosion of customer trust results in long-term damage far exceeding direct financial fraud losses.
    • Key anti-fraud countermeasures for online transactions include:
    • Data encryption technologies during transmission.
    • Billing address verification matching against issuing bank records.
    • Requiring Card Verification Value (CVV) numbers.
    • Real-time transaction-risk scoring software.
    • Smart Cards: Payment cards containing embedded memory microchips that update with encrypted data during each transaction (widely adopted throughout Europe, but less prevalent in the United States).
  • Hacktivists and Cyberterrorists:

    • Hacktivism: Executing computer hacks specifically to advance political, social, or environmental causes.
    • Cyberterrorists: Threaten or disrupt critical computer networks and infrastructure to coerce governments or societies into meeting specific political or social objectives. Their primary aim is direct service destruction rather than intelligence gathering.

Multi-Layered Security Prevention and Mitigation Strategies

  • Layered Defense Infrastructure:
    • Implementing a defense-in-depth model increases the difficulty of unauthorized network break-ins.
    • Corporate Firewalls: Hardware and software barriers positioned at network perimeters to filter and restrict incoming and outgoing traffic.
    • Intrusion Prevention Systems (IPS): Dedicated inline security devices that actively inspect, detect, and block malicious traffic, malformed network packets, and software threats.
    • Antivirus Software: Scanning solutions that search files and memory for specific binary sequences known as virus signatures.
    • US-CERT: The United States Computer Emergency Readiness Team operates as a national clearinghouse for vulnerability reporting and threat intelligence.

Firewall configuration separating internal network perimeter from public servers and the Internet

  • Popular Personal Computer Firewalls:
SoftwareVendor
Zone Alarm ProCheckPoint Software Technologies Ltd.
F-Secure Internet SecurityF-Secure Corporation
Panda Global ProtectionPanda Security
NeT FirewallNT Kernel Resources
ESET Smart Security 4ESET
  • Internal Threat Prevention Protocols:

    • Promptly revoke network access, delete user accounts, and disable login credentials for departing employees, contractors, and third-party vendors.
    • Carefully define job functions to enforce the principle of separation of duties.
    • Establish role-based access control (RBAC) to restrict individual user authority strictly to the minimum required for job execution.
  • Critical Infrastructure Protection:

    • The Department of Homeland Security (DHS) and its National Cyber Security Division (NCSD) coordinate national protection efforts.
    • Operates a national cyber incident response framework.
    • Manages comprehensive cyber-risk management initiatives for critical national infrastructure, including banking and finance, public water systems, core government functions, and emergency services.
  • Periodic IT Security Audits:

    • Regularly review formal security policies and evaluate organizational compliance.
    • Verify active user permission levels and administrative access rights.
    • Test technical security safeguards through penetration testing and vulnerability assessments.
    • Utilize standardized evaluation tools such as the Information Protection Assessment kit provided by the Computer Security Institute (CSI).

Intrusion Detection and Incident Response

  • Intrusion Detection Systems (IDS):

    • Security software designed to inspect system activity and catch unauthorized access in real time.
    • Monitors network assets and internal host operations, issuing immediate alerts to administrators upon detecting potential external intrusions or internal system misuse.
    • Knowledge-Based Detection: Identifies intrusions by matching system activity against established signatures of known attacks.
    • Behavior-Based Detection: Compares current system and user behaviors against established baseline profiles to flag abnormal or suspicious anomalies.
  • Incident Response Planning:

    • Formal response procedures must be established well before a security breach occurs and receive explicit approval from senior management and the legal department.
    • The primary objective of an incident response plan is to regain operational control and minimize damage, rather than monitoring or attempting to catch the intruder.
    • Currently, only 56%56\% of organizations possess a formal, documented incident response plan.
  • Incident Notification and Documentation:

    • Predefine explicit protocols regarding which internal and external entities must be notified and which must not be notified.
    • Security experts strongly advise against disclosing specific technical details regarding system compromises in public forums.
    • Systematically document every detail of the incident, including system event logs, specific technical actions taken, and all communications with external parties.
  • Containment, Eradication, and Recovery:

    • Act immediately to contain the breach and isolate affected systems.
    • Log and preserve all digital evidence according to strict forensic standards.
    • Verify that system backups are uncorrupted, complete, and current before creating fresh baseline system backups.
    • Conduct follow-up analyses to determine how the breach occurred and reconfigure security controls to prevent recurrence.
  • Post-Incident Review and Legal Exposure:

    • Perform a thorough review to evaluate the attack timeline and assess organizational response performance.
    • Balance the resource costs required to apprehend a perpetrator against potential risks of public disclosure and adverse publicity.
    • Establish legal precedents hold commercial organizations accountable if breaches occur due to negligent IT security safeguards.

Computer Forensics and Legal Implications

  • Scope and Objective of Computer Forensics:

    • Combines principles of computer science and law to identify, collect, examine, and preserve digital evidence while ensuring its evidentiary integrity for court proceedings.
    • Forensic investigation requires specialized training, formal certification, and detailed knowledge of statutory evidence laws governing criminal and civil investigations.
  • Core Summary Principles:

    • Ethical decision-making is necessary to prioritize which systems and data assets require the highest protection levels.
    • Managing vulnerabilities requires a multi-layered security model encompassing risk assessment, threat mitigation, user education, robust security policies, and specialized technical hardware/software defenses.
    • Computer forensics serves as the essential technical foundation for prosecuting cybercrimes and defending organizational liability within legal frameworks.