- Our appetite and addiction to the internet and its pleasures increase while ignoring the lurking dangers
- Cybercrime is no different; in fact, it is more obscure and faster growing than any physical vector of crime today
The old phrase “don’t put the carriage before the horse” is quite often used in the past when things are not in proper order. However, since the dawn of the Internet this phrase is silenced by our increasing appetite and addiction for the internet of its convenience and pleasure ignoring the dangers it brings along. Rather than weighing its Pros against the Cons, the tendency is to embrace the digital world considering only the sweeter side.
Averaging over 500+ deaths a year by bullets, the Ally’s in Chicago is said to be the most dangerous due to gang violence. The outskirts in Johannesburg and Mexico City records the greatest number of armed robberies, kidnapping for ransom and rapes each day. Cybercrime is no different; in fact, it is more obscure and faster growing than any physical vector of crime today. Unlike any physical stream, the online stream invites learned and crafty criminals to engage more and more as the digital landscape loopholes provide an opportunity to erase their tracks and the use of advanced technology that can be misused to perform such frauds or acts of sabotage efficiently.
Two and a half decades have passed since the boom of the internet and now it seems like we have to “build the plane while flying it” basically to find avenues to defend ourselves from cyber criminals while transacting through the internet. Despite the adoption of advanced technology such as Firewalls and Antivirus software’s for security, most businesses are compelled to lower their defences for the sake of cost and the hurry to trade online. In the past businesses just wanted to get their business listed online through Google and so they did till they faced a DOS (denial of Service) attack and whilst overcoming that with some technological improvement only to endure a more advanced DDOS attack. Inquiring into the matter a new word was added to our vocabulary called BOTs and BOTNets and the list goes on.
Old websites of Government institutes face Cross Site Scripting (XSS) regularly, while some old and un-updated software backed websites were handicapped by Buffer Overflow Attacks. Most of these attacks are financially motivated with criminal intent, whilst a minute has been driven by extreme activists (AKA Hacktivist). However, some newcomers to the hacking business who are called Script Kiddies can get lucky in breaking through, reminding of an old Sinhala idiom “Ali Madi Wa-Ta Koti” basically “Swatting flies while fighting a lion”
However, Ransomware is being considered as one of the deadliest, where the hacker apprehends the victim’s PC and its memory, keeping its data locked under encryption making the victim pay a ransom for the encryption keys. The famous Colonial Pipeline incident of 2021 in the USA, where a cybercriminal group Dark-Side alleged with Eastern European origin managed to extort USD 4.4 million to release the system back to the company.
Likewise, subtle but equally damaging are phishing schemes, quite often tied up with social engineering schemes to trick people to divulge credentials i.e. user IDs and passwords, at times social security and unique identity numbers. The elderly and the immature fall victims to these schemes only to lose money from their online accounts and at times from their digital wallets. However, successfully infiltrated into large corporations, the opportunities are endless for the attacker, since his spyware and other data exfiltrating software’s are implanted in the victim’s computers and systems. The classic example is the Sony Pictures Phishing Attack of 2014, where film producers planned to launch a film ridiculing the North Korean leader. In response an advance Phishing Attack through the FB page managed to infiltrate the computers of the Sony Company big boys and a lot of personal data was held as BLACK MAIL till the producers decided not to launch the movie. What humiliating success for the attacker?
This drama gets better and better, phrases like Man in the Middle Attack (MITM) sounds like a strategy in the mission impossible TV series, but it is a bigger reality in the digital world. Intercepting internet communication and abusing Protocols and hoodwinking people to use unsecured HTTP rather than HTTPS is one of many ways a MITM can be performed. When we hear these things, it’s suspicious whether our communication is actually private or not. The conventional diary and notebook appear to be more secure than our PCs or Smart Phones.
The authorities and police are less equipped to deal with complexity and obscurity of the nature of these cybercrimes. Realistically small nations like Sri Lanka definitely lack the technical know and the sophistication in terms of the technology to deal with these evolving cyber threats. Also, due to the inadequate digital literacy and awareness of cyber criminals and their schemes of exploit have exacerbated the issue further.
Some attacks are successful when they’re collaborated, just like Jelly & Custard, works like a prayer. Referring to Social Engineering followed by a Phishing attack; Social Engineering aspect mines personal information whilst promoting engagement using Apps, Easy Quizzes and Games that offers a small reward. The Phishing part provides the bait that lures the victim to the trap. Based on the target segments these attacks has many nicknames like SPEAR fishing when its aimed at a single person, WHALING when its aimed at high net worth individual, SPRAYING when its commonly distributed, SMISHING if it’s through SMS and VISHING if it’s a Voice message.
Once these criminals obtain these Credentials by crafty means, it’s like handing over the chickens to the wolves. A Phishing attacker is literally a Wolf in Sheep clothes; the success is how innocent and authentic the attacker’s emails or SMS look like. Either way these simple methods can be very lethal once the victim is tricked to hand over their Credentials.
The proverb “Prevention is Better than Cure” seems to be the way forward. Late as it appears to be, nevertheless educating and making people aware of these cybercriminals devious schemes can protect from reoccurrence. Also, software and technological specialists have natural and moral responsibility to counter these attacks by either staying ahead of these criminals or by luring them through decoys and helping authorities such as FCID or SL CERT to track these criminals. Further, the Government's officials should build international ties with nations who possess the expertise and know-how in addressing these issues and seek international assistance to track and mitigate these attacks.
The writer is an Assistant Manager - Data Protection currently reading for a Postgraduate Diploma in Cyber Security Policy at the Bandaranaike Academy for Leadership and Public Policy (BALPP)
----------------
The views and opinions expressed in this column are those of the author, and do not necessarily reflect those of this publication