Showing posts with label cyber crime. Show all posts
Showing posts with label cyber crime. Show all posts

Thursday, September 15, 2016

Securing the Internet of Things from terrorism

Terrorists use the internet on a 4 R frame - to relate to, recruit, retain, and refer their clandestine network. They use the net to build bonds and networks, and to maintain dangerous relationships. Given a common mission (to disrupt if not destroy the State), they meet and tie together in virtual space platform.  

How do the terrorists use the internet?
  • Selling a radical ideology - the web as a medium to propagate.
  • Eavesdrop to  enable recruiting followers with an extreme bend of mind.
  • Virtually communicate in forms which are accessible to password restricted followers but inaccessible to authorities.
  • Deepening relationships through instilling fear within and without and creating the obsession of goal achievement.
  • Building protected cyber-forums.
  • Instilling hatred for the system.
  • Provoking the mind of the potential recruit (may be through a photo, a story, a harping on a series of stories.  call to action).
  • Exaltation of terrorism to obsessive levels in the psyche of the potential terrorist.
  • ‘Fundamentalizing’ thought from a level of acceptance of the neighbour to a level of abhorrence. 
  • Arranging stealth finance. Payment systems are used: funds are moved through electronic wire transfers, credit card or alternate payment facilities.
  • Using avenues like crowd funding, e-commerce to solicit funds for the illegal activities.  

  
Criminal activity in finance would include
  • identity theft,
  • access to account database,
  • credit card theft,
  • wire fraud,
  • stock fraud,
  • intellectual property crimes,
  • auction fraud, 
  • e-gold online payment accounts  
  • using commodity markets


Case 1: Younis Tsouli  (2005) built websites and ran web forums for terrorists. He was a distributor of video material for terrorists. He hijacked web sites; ran password-protected forums with large number of members which were used for military instructions. Laundered money was used to fund the registration of nearly 180 websites as also to equip terrorists across several countries. Approximately 1,400 credit cards generated approximately £1.6 million of crime driven money.

Case 2: Tariq Al-Daour (2006)  had 37,000 credit card details on his computer drives. These were obtained through phishing attacks or purchased in on-line forums where stolen information circulates. Gullible people were led to believe that they were verifying their accounts were unwittingly helping the group fund their terrorist activities.

As terrorists connect through cyberspace, IoT raises security issues as never before. Given that the devices are all inter-connected, theft at any one point could have a contagion effect with the criminal having recourse to a huge set of data. Ranging from electronic key to mobiles to identity theft, there are multiple avenues but also immense potential for harm. IoT would enable availability of movements and preferences of consumers,Criminal hackers could track these through a host of inter-connected devices. The security threat implicit in multiple connected devices has to be instilled in the consumer mind-set. In the absence of any IoT regulator, self regulatory standards by independent vendor are essential.

References:-
http://techonomy.com/2016/08/27253/

(Excerpts from a forthcoming book by the author) 

Operational Risks of IoT - Cyber-attacks

A cyber-attack is a deliberate, planned criminal use of computer networks to launch an attack against the intended victim, entity, organization or country.  The machine led virtual attacks aim to disrupt or at least weaken the optimal functioning of target entities. This disruption would result in a slowing of or 'freeze state' in regard to  the computer infrastructure. 

The modus operandi could be hacking, social media interventions, computer viruses, malware, ransomware, phlooding (“Phlooding” refers to the aiming at freezing the central organizational servers through intended, deliberate overloading of the servers, which consequentially slows systems or stalls the systems) etc. Inevitably, there is a  service delay or denial to customers.   

Cyberattacks will instil fear of a different variety. The withdrawal of balances through ATM in remote places (as recently happened in India) is sufficient to cause panic in general public. Imagine then,  a series of crippling attacks as was seen in Israel in January 2012, involving the targeting of multiple representational Israeli websites.

Case 1 : In January 2012, hackers stuck at financial muscle of Tel Aviv - the Stock Exchange, and the First International Bank. There was a DOS attack. – denial of service. The disclosure of the credit card and account details of thousands of Israeli nationals - Banking Supervision Department of Bank of Israel said 15000 accounts were broken  into - unnerved public at large. The e-attacker, OxOmar and sometime earlier, the Gaza Hackers Team which had usurped Israeli fire services website,  had indicated the operational risks in using internet.

Case 2 - One of the big US  banks went public in 2014 that it systems had been susceptible. Data of seventy six million household customers and seven million businesses, had been reportedly run over. Their names, email addresses and telephone numbers were in the hands of intruders.

The cyber-attackers are obsessed with religious, political or social objectives. They will continue to orchestrate run on the systems without any fear of the future. Any country can be attacked any time,  anywhere.   

As IoT evolves and seeks to put in place an elaborate pattern of connected systems, contagion risk is very high. We need to erect moats to safeguard the fort of Internet of Things.

References:
http://edition.cnn.com/2012/11/19/tech/web/cyber-attack-israel-anonymous/
http://www.bbc.com/news/world-16577184 
http://www.timesofisrael.com/israelis-in--hack-case-to-be-extradited-to-us/

(Excerpts from a forthcoming book by the author) 

Friday, March 20, 2015

Next banks will come from Silicon Valley...

Banks have to adapt,  says Executive Board Member  Anreas Dombret of German Bundesbank in his 11 March interview with a German Newspaper, Suddeutsche Zeitung. He included low interest rates and digitalization of banks as challenges to European banks.  Digitalization , he opined is inevitable and the need for efficiency is a driver. 

He also cautioned that hackers are getting together to re-organize on the strength of financial and technical resources. 

He suggested that non profitable banks should exit respecting the fair play of market forces. 

Our Comments
The forthcoming great 'fintech' revolution is going to change banking as we know. Tomorrow's competitors for banks are not banks or finance companies but technologically sophisticated companies with massive on time investments in techniques, talent and money. Apple to Microsoft to Samsung to Google may be the fintech players in an era of Internet of Things. Click and Mouse will pave way for renewed vigor in real time settlement , transparency,  and customerization on a  real time basis. The new players will take us away from 'fixing' by majors to a real time banking perfect market (modifying a la foreign exchange market) . 

Those who cannot foresee this great change or do not who have the resources to change will be condemned to the dustbins of banking history. 


Technology has always been a catalyst in banking and finance. It will accelerate transformation in times of the Internet of Things.



Copyright of this article and its contents vests with the author of this blog: Jayaram Nayar. He can be contacted at email: jaynayar@gmail.com