Showing posts with label macafee vcr 2008. Show all posts
Showing posts with label macafee vcr 2008. Show all posts

Monday, December 15, 2008

Cyber(in)security roundup

Producing the Macafee VCR makes you more than normally aware that every vendor and their (robo)dog , plus apparently most NGOs, produces a report on some aspect of online spam, crime, fraud etc in that vital run up period to Christmas when apparently our minds are focused on fun, festivity and, er, fraud:

My esteeemed co-author Blogzilla helpfully summarises a few from the US and international organisations:

"Securing Cyberspace for the 44th Presidency — the Center for Strategic and International Studies argues that President Obama should create a comprehensive national security strategy for cyberspace, echoing many of [the Macafee] recommendations.

Financial Aspects of Network Security: Malware and Spam — the International Telecommunications Union develops a framework for assessing the financial impact of malware.

The OECD calls for a global partnership against malware, and a move from reactive responses to proactive threat reduction and mitigation."

But there's also been some more local offerings:

The Garlik UK Cybercrime Report 2008 - which, like our report, top-lines the credit crunch and its effect on cyberfraud. Despite the name the figures appear to relate to 2007. For the UK, it is claimed,we have seen
  • Overall cybercrime has risen by 9% from 2006
  • Online financial fraud is up by 24%
  • Online card fraud is up 45%
  • 84,700 cases of online identity fraud
  • 40% of all identity frauds are facilitated online
  • "More than two million victims suffered abusive or threatening emails, false or offensive accusations posted on websites and blackmail perpetrated over the internet, up from 1,944,000 in 2006." Much of this apparently tookplace on social network sites. Pangloss is curious where they got this figure - must go print out the whole report.
ENISA, the EU's security agency, also produced in early December a rather underlooked report ENISA - Photo Sharing, Wikis, Social Networks –Web 2.0 and Malware 2.0.
This has an interesting analysis of risks primarily to *systems* from the hard technical viewpoint, as opposed to the emphasis most the other reports place on risks to *users* (though of course the two are connected.) The risks of cross - scripting exploits in multi-origin environments like SNSs are highlighted, along with typically weak control of authentication and access privileges. The policy recommendation to governments are interesting:

"Policy incentives for secure development practices such as certification-lite, reporting exemptionsand the funding of pilot actions. These incentives are needed to address the large number of, eg,cross-site scripting vulnerabilities caused largely by poor development practice.
• Address/investigate Web 2.0 provider concerns about conflicts between demands for content
intervention and pressure to maintain ‘mere conduit’ or ‘common carrier’ (US) status. This is
considered a very important problem by Web 2.0 providers because of the strong user-generated
content component.
• Encourage public and intergovernmental discussion on policy towards behavioural
marketing (eg, by the Article 29 Working Party)."


Perhaps unsurprisingly in light of all this, the EU has just announced (9/12/08) its plans to continue funding its Safer Internet Programme to the tune of 55 million Euros:

"The EU will have a new Safer Internet Programme as of 1 January 2009 (to 2013) . ..While 75% of children (aged between 6 and 17 years) are already online and 50% of 10-year-olds have a mobile phone, a new Eurobarometer survey published today shows that 60% of European parents are worried that their child might become a victim of online grooming (when an adult befriends a child with the intention of committing sexual abuse) and 54% that their children could be bullied online.. The new Safer Internet Programme will fight grooming and bullying by making online software and mobile technologies more sophisticated and secure."

The money is to go to:

  • Ensure awareness of children, parents and teachers, and support contact points that are providing them with advice on how to stay safe online.
  • Provide the public with national contact points for reporting illegal and harmful content and conduct, in particular on child sexual abuse material and grooming.
  • Foster self-regulatory initiatives in this field and stimulate the involvement of children in creating a safer online environment.
  • Establish a knowledge base on the use of new technologies and related risks by bringing together researchers engaged in online child safety at European level.
So more media literacy, more research, more IWF style hotlines, but no apparent endorsement of the ISP or mobile coms sectors being required to impose mandatory "upstream" filtering: either of the IWF-lead UK Cleanfeed inititiative or the disputed new Ozzy variety. Interesting..

Friday, December 12, 2008

Macafee Virtual Criminology Report 2008, and Predictions for 2009 in the IT Law World

Pangloss is back in town (well, Edinburgh) after her jaunts to Israel and London, which culminated in a brief and rather bronchitic appearance on the Today programme talking about cybercrime - the germ (contracted in Israel) was clearly genetically engineered by Mossad to take out the EC's top legal brains. Er, well, or something like that:)

The 2008 Macafee Virtual Criminology Report, which I was plugging on the aforesaid Today prog, is now available free online in a variety of languages, edited by myself and Dr Ian Brown of the OII, with this year an even wider selection of contributing international experts we interviewed - read and comment here should you wish!

Our top level findings this year included:

- the credit crunch will inspire greater investment in cybercrime by criminal gangs etc, especially in the financial phishing area where the confusion of mergers and bankruptcies in the financial sector has left the consumer confused and vulnerable
- difficult financial prioritising may also leave both the conmercial and public sectors vulnerable to further security and personal data breaches, and compliance action must take this into account
- local individuals may be pulled into international phishing as "money mules"; new e-payments and virtual world payments systems are also likely to be utlised to launder the profits of cybercrime
- cyber terrorism continues to be an issue, with more attacks from alleged sources in China and Russia, especially against the likes of Georgia in 2008
- however some excperts also suspect misdirection and obfuscation as to where the true sources of both cybercrime and cyberterrorists attacks are; it is easy to direct Internet traffic via "scapegoat" countries and some cybercrime overlords may be much more local than we think.
- creating "cybercops" is a tough job for nation states, especially in the non Western countries and we may need to look at the creation of a NATO-style transnational "standing cyber-police".


Meanwhile Pangloss was also one of a number of practitioners and academics asked to contribute ideas to the SCL's round up of predictions for what the IT law field may see happening in 2009. The results make interesting if relatively consistent reading (credit crunch will reduce IT and law spending, more out sourcing, more clampdowns on personal data breaches , more powers for ICO, more copyright maximalism by rightsholders, more attempted IP infringement by the bored/unemployed) which probably means something entirely different wil happen instead..

Israel was a remarkable experience, which I hope to write more about at some point. It is quite something for a privacy scholar, even of the non-fundamentalist variety, to see in action a society which so clearly thinks in the majority, that in its unique case, security simply demands substantial inroads into what we would see here as basic personal autonomy and privacy standards. As my niece, studying in Tel Aviv, put it; "It makes me feel safe".

There is a norm of having bags searched on entry to most public places; cars and travellers can be stopped for no reason; security alerts closing public transport and roads down are commonplace. On the other hand Tel Aviv is extremely Western and secular (it reminded me of a cross between LA and Barcelona) and the privacy and technology lawyers at Tel Aviv University who hosted me are as involved as any at Berkeley and Harvard in promoting human rights standards, anti racism, and running pro bono clinics etc. As I visited they had just been involved in condemning e-voting in Tel Aviv local elections which did not meet democratic standards, and they are helping Israel to apply for privacy "adequacy" certification under the EC Data Protection Directive. It was a fascinating time and I hope to go back and discover more in the not too distant future. Thanks to Michael Birnhack and Assaf Jacob especially for inviting me!