Showing posts with label Cybercrime. Show all posts
Showing posts with label Cybercrime. Show all posts

7/31/2013

US Loses Big Time



Attacks on businesses and consumers are a blight on the economy, with criminals foreign and domestic using the Internet to steal identities, intellectual property, trade secrets and just about anything else they can get their hands on. 

A new economic model (above) developed at a prominent D.C. think tank puts the cost to the U.S. economy as high as $100 billion annually, with a corresponding loss of as many as half a million jobs. 

The report, released by the Center for Strategic and International Studies (CSIS) and written by James Lewis and Stewart Baker, two old hands in the Washington cybersecurity policy discussion, offers a quantitative approach based on data from the Commerce Department and analogous losses from activities such as car crashes, piracy and other losses and crimes. 

The authors explain: "One way to think about the costs of malicious cyber activity is that people bear the cost of car crashes as a tradeoff for the convenience of automobiles; similarly they may bear the cost of cybercrime and espionage as a tradeoff for the benefits to business of information technology." 

The report, sponsored by security software vendor McAfee, eschews survey data, which the authors say is flawed because respondents "self-select," and businesses often either conceal or do not realize the full extent of the losses from a cyber attack. 

"We believe the CSIS report is the first to use actual economic modeling to build out the figures for the losses attributable to malicious cyber activity," Mike Fey, executive vice president and CTO at McAfee, said in a statement. 

"As policymakers, business leaders and others struggle to get their arms around why cybersecurity matters, they need solid information on which to base their actions." 

Cybersecurity is the subject of a long-running policy debate in Congress, with lawmakers divided over what role the government should play in setting and enforcing security standards for critical infrastructure operators in the private sector.   Read more:

5/02/2013

The Top Gun of Hackers



In case there’s any doubt about which country is the world’s top industrial cyberspy, a new report adds to the mounting pile of evidence — it’s China.

Verizon’s new Data Breach Investigations Report issued Monday estimates that 96 percent of recorded, state-affiliated attacks targeting businesses’ trade secrets and other intellectual property in 2012 could be traced to Chinese hackers.
“This may mean that other threat groups perform their activities with greater stealth and subterfuge,” Verizon notes in its report. “But it could also mean that China is, in fact, the most active source of national and industrial espionage in the world today.”

Verizon’s annual DBIR, a fixture in the cybersecurity community, should add fuel to the political firefight on Capitol Hill over improving the nation’s digital defenses. The report also describes criminal organizations and hackers elsewhere taking aim at banks, retailers, utilities and manufacturing companies.

The new findings come a week after the House passed the bill known as CISPA — a proposal meant to help companies and the government share cyberthreat data. But the measure faces a skeptical Senate, not to mention the renewed threat of a presidential veto.

In the meantime, lawmakers and the Obama administration are pushing China on the cyberattacks amid a steady stream of reports naming the country as a hacker haven. Gen. Martin Dempsey, chairman of the Joint Chiefs of Staff, is headed there this week, the second such high-profile trip with cybersecurity on the agenda after Secretary of State John Kerry visited Beijing earlier this month.

In the end, it’s practically impossible to determine the full extent of Chinese hacking: attributing attacks to their true source is difficult, companies are reluctant to disclose when they’ve been victimized and much information about China’s cyber activities remains classified.

Even the incomplete picture painted by Verizon’s new report, though, reveals the serious, novel challenges posed by digital hackers, many of whom appear to be located in China.

In total, Verizon confirmed 621 total breaches among more than 47,000 reported cyber incidents. Three-fourths of those 621 breaches were “financially motivated” cyber crimes, according to Verizon, while state-affiliated espionage — including from China — represented just about 1 in 5 incidents.

Even though China is responsible for much of the cyber espionage reported to Verizon last year, it’s still among a larger group of countries affiliated with foul play in cyberspace. Romania, for example, was home base to hackers with financial motivations in mind. Rounding out the top three: the United States, which is responsible for a small fraction of the state-affiliated attacks recorded by Verizon in 2012.

Across the board, financial organizations, including banks, were most under siege last year, followed by retailers and restaurants. In addition, 1 in 5 intrusions involved manufacturing, transportation or utility companies, according to Verizon.
The threat of hacktivism, which sharply increased in Verizon’s previous report, remained steady in 2012 — but it didn’t result in much stolen data, as groups “shifted” to disrupting services and systems. Meanwhile, Verizon noted a sharp uptick in attacks with “social tactics” as cyber criminals — many of whom are believed to be state-sponsored — took to email and other forms of communication as a way to establish “a foothold in their intended victims’ systems,” according to the report.     Read more:


10/16/2012

NO PLACE TO HIDE

Click to enlarge...
The Cybercrime Prevention Act of 2012, officially recorded as Republic Act No. 10175, is a law in the Philippines approved on 12 September 2012. It aims to address legal issues concerning online interactions and the Internet in the Philippines. Among the cybercrime offenses included in the bill are cybersquatting, cybersex, child pornography, identity theft, illegal access to data and libel.

While hailed for penalizing illegal acts done via the internet that were not covered by old laws, the act has been criticized for its provision on criminalizing libel, which is perceived to be a curtailment in freedom of expression.

Unlike most computer terms, "cyberspace" does not have a standard, objective definition. Instead, it is used to describe the virtual world of computers. For example, an object in cyberspace refers to a block of data floating around a computer system or network. With the advent of the Internet, cyberspace now extends to the global network of computers. So, after sending an e-mail to your friend, you could say you sent the message to her through cyberspace.

The word "cyberspace" is credited to William Gibson, who used it in his book, Neuromancer, written in 1984. Gibson defines cyberspace as "a consensual hallucination experienced daily by billions of legitimate operators, in every nation, by children being taught mathematical concepts... A graphical representation of data abstracted from the banks of every computer in the human system. Unthinkable complexity. Lines of light ranged in the non-space of the mind, clusters and constellations of data" (New York: Berkley Publishing Group, 1989), pp. 128.

According to the third annual study of U.S. companies, the occurrence of cyber attacks has more than doubled over a three-year period, while the financial impact has increased by nearly 40 percent.

Conducted by the Ponemon Institute and sponsored by HP, the 2012 Cost of Cyber Crime Study found that the average annualized cost of cybercrime incurred by a benchmark sample of U.S. organizations was $8.9 million. This represents a 6 percent increase over the average cost reported in 2011, and a 38 percent increase over 2010.

The 2012 study also revealed a 42 percent increase in the number of cyberattacks, with organizations experiencing an average of 102 successful attacks per week, compared to 72 attacks per week in 2011 and 50 attacks per week in 2010.       Read more…  

Secretary of Defense Leon Panetta
"cyber attack perpetrated by nation states are violent extremists groups could be as destructive as the terrorist attack on 9/11. Such a destructive cyber-terrorist attack could virtually paralyze the nation”, said Secretary of Defense Leon Panetta.  Credits:  nation.time.com

Secretary of Defense Leon Panetta, speaking on board a U.S. aircraft carrier, spoke to a group of business leaders on October 11, 2012 about the issue of cyber defense. There he warned of the possibility of a devastating attack being directed against the United States by cyber terrorists that could “virtually paralyze the nation.”

“Cyberspace has fundamentally transformed the global economy. It has transformed our way of life, providing two billion people across the world with instant access to information to communication, to economic opportunities. Cyberspace is the new frontier, full of possibilities to advance security and prosperity in the 21st century. And yet, with these possibilities, also come new perils and new dangers”, he said. 

Mountain View, CA – Sept. 5, 2012 – Norton by Symantec (NASDAQ:SYMC) today released the findings of its annual Norton Cybercrime Report, one of the world’s largest consumer cybercrime studies. The study is aimed at understanding how cybercrime affects consumers, and how the adoption and evolution of new technologies impacts people’s security. With findings based on self-reported experiences of more than 13,000 adults across 24 countries, the 2012 edition of the Norton Cybercrime Report calculates the direct costs associated with global consumer cybercrime at US $110 billion over the past twelve months.

This year’s survey shows an increase in “new” forms of cybercrime compared to last year, such as those found on social networks or mobile devices - a sign that cybercriminals are starting to focus their efforts on these increasingly popular platforms. One in five online adults (21 percent) has been a victim of either social or mobile cybercrime, and 39 percent of social network users have been victims of social cybercrime.