Publicité

Outlaws and disorder in cyber space

29 mars 2005, 00:00

Par

Partager cet article

Facebook X WhatsApp

lexpress.mu | Toute l'actualité de l'île Maurice en temps réel.

Most of us have received unsolicited e-mails in our inbox at one time or another. Worse still, it is becoming an almost daily phenomenon. Offers are flogged on Internet users as if virtual generosity was unparalleled. But almost all of them are fraudulent. They are part of the Internet?s thriving criminal activities.

Last week, Mauritius got a first taste of what to expect if it is to develop into a cyber island. Whatever the reason for the breakdown at the cyber city, we can reasonably expect that attacks on the system will be a future trend. As we develop more experts in the technology, so grows the threat of creating high-tech criminals. Despite the 2003 legislation, perpetrators of cyber crimes are difficult to track down.

This quasi-anonymity of criminals has allowed spam or junk e-mail to become the most important traffic on the Internet, clogging mailboxes worldwide. Anti-spam organisations, like the Spanhaus Project, estimate that up to 60% of all Western e-mail traffic is spam. The majority is illegal, a famous one being the Nigerian letter scam, which promises oil shares in the country for a minimum investment. Victims are then lured into disclosing their financial details, eventually leading them to be defrauded of thousands of dollars.

<B>Chasing invisible criminals</B>

Spamming is very attractive for criminals. They only need a few replies to the millions of junk e-mails they send at any one time to realise a profit. The problem is that people actually respond to spam. In 2002, the Direct Marketing Association found that 36% of users purchased a product after receiving a commercial e-mail alert. Subscribing to websites, shopping on the Internet and replying to unsolicited e-mail are just like leaving your business card everywhere you go, making your contact details public. But, once spammers get access to your mailbox, they can gain access to everyone else in your address book.

If spam sometimes leads to people being defrauded, viruses and worms are even worse. Known as malware (malicious software), they are becoming increasingly powerful. Again, the identity of the perpetrator is almost always unknown. A study by the CERT (Computer Emergency Response Team) Coordination Centre, an Internet security expertise centre, revealed that from 1991 to 2001, as the attacks grew in sophistication, knowledge of the culprits declined. Malware can either wipe out the hard drive of the infected computer, post confidential documents on the Internet via e-mail or install a ?Trojan horse? which allows hackers access to the computer.

Penetrating remote hard drives is one of the intruders? favourite lines of attack. This further conceals their identity and allows them to disrupt other networks. When broadband joined more computers, hackers witnessed an expansion in their abilities to strike. The CERT Coordination Centre calculated that the number of successful intruders has risen exponentially since the 90s as more people became connected to the virtual world. This could plague Mauritius in the future as Internet users increase and broadband becomes more accessible. Worms, unlike viruses, do not need any e-mail attachments to reach their target and can thus cause havoc on the 24-hour broadband connection.

Another type of cyber crime which is on the rise is the ?phishing? phenomenon. The term comes from the idea of fishing for passwords and financial data from the sea of Internet users. Hackers usually hijack trusted brands of well-known banks, online retailers and credit card companies. They then send spoof e-mails, convincing the recipients to divulge their private data. According to the Anti-Phishing Working Group, in January of this year alone, 64 brands were hijacked and the number of active ?phishing? sites amounted to 2,560. The average monthly growth in these counterfeit websites from July last year to January was 28%. This represents a new threat as they keep shifting location and their existence at a particular address is around 6 days on average. ?Phishing? sites are located everywhere around the world. The US hosts nearly a third of them, followed by China at 13% and Korea at 10%.

<B>High costs to businesses</B>

But the seedy underworld of the Internet does not represent a challenge to individual users only. Businesses have suffered from repeated attacks, forcing them to invest in Internet security. In a survey of 201 UK companies, a national hi-tech crime unit found that 167 of theme xperinced hi-tech crime in 2003 costing a combined total of £ 195 million.

However, it seems that, whatever the authorities do, the hackers are always a step ahead. The Internet has become like a chessboard, pitching the hackers against security experts (themselves sometimes ex-hackers) in a war of attrition. There are also concerns that cyber terrorists could try to bring a country?s systems down. But a paper in 2002 by the Washington-based Centre for Strategic and International Studies dismissed these reports as ludicrous.

As it is, cyber crime strikes a small number of people. But for countries like Mauritius, with hi-tech ambitions, it is more serious. Legislation is only the first line of defence and it must be backed up with highly trained personnel, responsive to perpetual mutations of cyber criminality. As in the real world, a more imaginative approach is needed to tackle virtual criminals.

<B>Diren VALAYDEN</B> <I>Outlook Correspondent in Dublin

Publicité