Paper

profileGvs
EMERGINGTHREATSCOUNTERMEASURESLITERTUREREVIEW-GROUP1.docx

Running head: EMERGING THREATS AND COUNTERMEASURES 1

LITERATURE REVIEW

Emerging threats and countermeasures in the U.S. critical infrastructure

Table of content

Background information 3

Research questions 3

Methodological approach 3

Data analysis and findings 3

Challenges in confronting threats 6

Conclusion and discussion 8

References…………………………………………………………………………………………9

Background information

In recent times, the province of security architecture has profoundly transposed by the escalation of threats targeting critical national infrastructure. The rise in such threats is directly related to the rapid integration of the infrastructures with emergent information technologies (IT). That said, it is easy to conclude that the destructive threats to the infrastructures are from cybercrime. Cybercrime manifests in several dimensions from worms, viruses to malware. It would be easy if such threats confronted quickly. However, the state of affairs is that it is not an easy endeavor at all, and hence protecting national infrastructure is even more challenging than it has ever been.

Research questions

This essay answers the questions of the literature related to the emergent threats in the protection of critical national infrastructure. More also, it answers the question of the challenges involved in securing the infrastructures.

Methodological approach

The study of data collection is conducted using a qualitative approach. Qualitative research is the scientific study of observations that seeks to describe, explore, explain, and diagnose phenomena by gathering non-numerical data.

Data analysis and findings

It has not been easy protecting national infrastructure in the last two decades thanks to an increase in cybercrime. Public information systems are lucrative targets for hackers and other ill-motivated criminals. The state affairs have led to a conclusion that in a time in the current generation, the world is increasingly veering toward cyber warfare. The cost of cybersecurity threats is estimated to be over billions of dollars and still learning. Even with new measures, it appears the rate at which cybercriminals are expanding their technological dominion in the deep web is exceedingly strange.

Cybersecurity attacks take different dimensions. Perhaps one of the most devastating has been related to user inefficiency when handling systems. Most cybercriminal activities have shown an impeccable ability to surpass both the human and system shields that protect systems. In the dawn of the early 2000s, for example, the world was in a panic following an attack unleashed by two Philippine students. The attack, known as love bug exposed the value system behind the human-based security system. It is one of the weakness and which is solely flexible to easy manipulation. Following the love bug attack, the national intelligence system had to be switched off for several hours. The cutting-edge world has seen a multiplication in the development of web associations and data innovation gadgets which applied in business set-up, both private and open division enterprises, for proficiency in tasks the board. The creators note that these fresher inventive advances have prompted a massive ascent in instances of digital assault occurrences which, to a more prominent degree, have unsatisfactory results to the business and money industry. Spread of malware into data and correspondence innovation frameworks and systems for malevolent goals has been a scandalous standard. The national security facts from remote-based strikes and its PC organize the U.S. Government protects systems. The National Cybersecurity and Protection framework program named Einstein initially dependent on the examination innovation sent more than ten years earlier, and the system's guaranteeing $218 million overhauls should make it ready to do dynamically ambush expectation.

There have been several attacks lately targeting information systems across the world. These attacks included denial of service attacks, which takes over a system. The second type of cybersecurity attack is a man in the middle attack. The third attack is phishing. Phishing exploits the human bridge between systems and security. It makes no difference how secure a system is. It is always non-immune to attack. The fourth cyber-based challenge is the eavesdropping attack. Finally, critical national infrastructure systems are also vulnerable to smurf attacks. The standard form of attacks involves the hacker saturating a system with traffic to the extent that such systems fail to perform essential functions. The attack medium ranges from viruses to worms and malware. Worms are a potential source of concern as they can easily permeate through a network system. The leading type of malware is computer viruses, spyware, adware, rootkit, Trojan horse, ransomware, worm, key logger, and botnet (Hansen et al., 2016). Computer viruses are infectious software that quickly self-replicates intending to destroy confidential and valuable data or cause irreparable damage (Holt et al., 2015). The scholar utilized a qualitative method in analyzing the risks. Cyber-attacks are growing at a rapid rate nowadays. Most of the threats focus on Government Systems, businesses, and commerce. One of the recent attacks on Barclays bank was made using a remote-controlled Keyboard, Video, and Mouse (KVM).

Threats are physical as well. Currently, the world faces a political and violent conflict situation in their endeavor to protect critical infrastructure. There is an escalation in terrorist activity, mainly emanating from the developing nations in the Middle East and parts of Africa such as Somalia, Northern Nigeria, and some areas in North Africa such as Libya. Terrorism activities are as much related to religious radicalization as they exhibit an element of resources and resource conflict. They have a resources element because they motivated by the unabated flow of dark money, which is used to control and pacify an already disappointed bulging youth population in the countries (Olmstead, & Smith, 2017). Furthermore, the conflicts are related to resource conflict because most of the time, it is the authoritative allocation of resources that is to blame for radicalization. Terrorism activities are diversified, and in recent times the world is increasingly conscious of biothreats among others.

Challenges in confronting threats

Confronting cybersecurity threats have proven to be one of the most challenging dispensations in recent times (Sood, Rohit, & Richard, 2012). First, there has been a revolution in hacking technologies. Hidden in the dark and deep web, and operated by malicious experts in advanced data centers, hacking technologies have progressed even quicker than the preventive capacities. Sood, Rohit, & Richard (2012) also argues that it is also straightforward to acquire the technologies on the dark web. They are all sorts of sites in such places which deal with startup packages for anybody wishing to live their lives as a hacker. Individuals are seeking crime display a remarkable ability to adapt to changing technologies, environments, and lifestyles. The ability of hackers to infiltrate new protection systems and hack has shown impeccable revolution lately. Singh, & Singh (2016) argue that the main reason behind the revolution in cyber-attacks because cybercrime has become more lucrative with the introduction of digital currencies. These currencies are the mainstream medium of exchange between hackers and victims of breaches. The currency can also not be tracked down by law enforcement agencies, and they leave very little forensic evidence behind (Singh, & Singh, 2016).

The advancement in the technologies is directly related to increased monetization of cybercrime. The last decade has seen the growth of digital currencies. The currencies are indeed a catalyst for concealing cybercrime as financial payments easily flow from victims to criminals without a trace. Digital currency lacks identification details which complicate the ability of law enforcement agencies to track and respond to crime. They were designed to mirror traditional currencies, in hard notes, where it would never be easy to monitor where a dollar note goes after it leaves the federal bank.

Forensic experts have also been a little bit incapacitated in the fight against cybercrime. One of the main reasons is the complication of cybercrime (O'Dowd, 2017). The agencies are incapable of confronting cybercrime as quickly as possible and arresting the culprits. The fundamental deterrence to any form of crime is the probability of arrest. Even with arrest, the agency has an inadequate forensic capacity to gather and handle evidence. The challenge in protecting against crimes with a global magnitude is multifaceted. Cybercrime, for example, faces a challenge as a result of overlapping jurisdiction. For terrorism activities, challenges are originating from resources and resource conflict.

More also, cybercrime is not the province of local politics and control but supersedes boundaries, to the reach of often rogue states that also sponsor such activities (Thornton-Trump 2012). The scholar also argues that where, however, there exists the will to prosecute criminals in different states, the problem of jurisdiction and sovereignty works hand in hand to frustrate the quest of law enforcement agencies. The problem is that not all nations in the globe have an elaborate legal system that defines hacking as a crime (White, 2016). The weakness of such a state of affair is evident in the love bug case where the two Philippines would not prosecute because the Philippines lacked in statutes that addressed cybercrime directly. The ultimate hurdle facing law enforcement agencies is its inability to keep up with the innovation speed. It emanates from the fact that there lack specially dedicated labs in several states for dealing, detecting, and ultimately handling threat modeling. Threat modeling deals with speculations aspects and relies on the premise of preventing and identifying threats before it occurs.

One of the greatest hindrances to overcoming cybercrime threats is the human elements. User-based links to threats is undoubtedly a point of concern because, as it is evident, most threats are related to phishing attempts. Threat agents permeate through a weakness in systems, and on most occasions, the weakness caused by human beings who operate the systems. (Von & Upton, 2016). User-based threats result from inadequate education. Users who operate and run critical infrastructure systems need thorough training on system security. The training is currently insufficient or probably inadequate, though it is not surprising because phishing attempts and attacks focus on human emotional weaknesses.

Conclusion and discussion

Critical national infrastructure currently faces a myriad of threats, whether physical or cyber-based. The most devastating of the crime is cyber, which manifests in several dimensions. The world surely is increasingly and inflexibly veering toward cyber warfare. USA has recognized cyberspace as a fifth domain in the security agenda after land, sea, air, and space (Harrop.W & Matteson.A, 2015). Critical infrastructure has also been a victim of domestic and international sabotage and terrorism. Cybersecurity plays a vital role in the growth of the digital economy (Chooi S, Ahmad M, 2017). This paper can conclude that cyber warfare is coming and the impact can be prevented or minimized by following the security measures.

References

Hansen, S. S., Larsen, T. M. T., Stevanovic, M., & Pedersen, J. M. (2016, February). An approach for detection and family classification of malware based on behavioral analysis. In 2016 International Conference on Computing, Networking, and Communications (ICNC) (pp. 1-5). IEEE.

J. Holt, Thomas & Bossler, Adam & Seigfried-Spellar, Kathryn. (2015). Cybercrime and DigitalForensics: An Introduction.

O'Dowd, A. (2017). Major global cyber-attack hits NHS and delays treatment. BMJ: British Medical Journal (Online), 357.

Olmstead, K., & Smith, A. (2017). Americans and cybersecurity. Pew Research Center, 26.

Singh, S., & Singh, N. (2016, December). Blockchain: Future of financial and cybersecurity. In 2016 2nd International Conference on Contemporary Computing and Informatics (IC3I) (pp. 463-467). IEEE.DOI:10.1109/ic3i.2016.7918009.

Sood, Aditya K., Rohit Bansal, and Richard J. Enbody. (2012). "Cybercrime: Dissecting the state of the underground enterprise." IEEE internet computing 17.1 (2012): 60-68.

Thornton-Trump, Ian. (2018). "Malicious attacks and actors: an examination of the modern cybercriminal." EDPACS 57.1 17-23.

Von Solms, B., & Upton, D. (2016). Cybersecurity capacity governance. The Business & Management Review, 7(4), 34.

White, J. (2016). Cyber Threats and Cyber Security: National Security Issues, Policy, and Strategies. Global Security Studies, 7(4).

Nandakumar, N., & Lakshmi, I. (2017). Emerging and Upcoming Threats in Cyber Security in 21 Century. International Journal of Computer Science and Mobile Computing, 6 (2), 107–118.

Hewes, C. A. (2016). Threat and challenges of cyber-crime and the response. Quarterly journal. S.A.M.Advanced Management Journal, 81(2), 4-10,2.

Harrop W, Matteson A. (2015) Cyber resilience: a review of critical national infrastructure and cybersecurity protection measures applied in the UK and USA. DOI 10.1057/9781137455550

Chooi, T., & Ahmad M. (2017) National cybersecurity strategies for digital economy. DOI 10.1109/ICRIIS.2017.8002519