Forecast of computer crime
THE IMPACT OF COMPUTER CRIME: THE FUTURE IS NOW
Throughout this text, the authors have noted the significant problem of cybercrime and terror, the motives and actors involved, and diverse agencies tasked with investigation and prosecution of these offenses. Taking this body of knowledge as a whole, it is important to consider how the landscape of cybercrime will look in the future. This vision is highly dependent on the ways that computer technology shifts and changes with time. Specifically, the hyperevolution of technology and networking that fuels e-commerce and communications are quickly co-opted or corrupted by cybercriminals. For example, the growth of wireless local area networks (WLANs) has not only increased mobile computing but also made networks easier to penetrate by outsiders. As noted in Chapter 4 , hackers engage in war driving, where persons drive through a community with a wireless network card in a laptop computer activated in order to detect the presence of a wireless network. The “war drivers” then attempt to access the network—often successfully—and use this as a portal to the Internet. Less scrupulous users will also attempt to penetrate the network’s computers—essentially a “drive-by hacking.” Interestingly, wireless networks are fairly easy to penetrate because they are frequently “open” with no security, apparently to make it easier for the network’s users; of course, this makes it easier for the intruder also.
Another technological trend is the increased availability of wireless microintegrated and multifunction devices that have increased storage and networking capacity. The most common illustrations of this are the integrated wireless telephone (i.e., smart-phone) and tablets with full Internet connectivity capability. Given the types of information often kept in smartphones and tablets—ranging from credit card numbers to passwords to Social Security Numbers and various types of account and financial information—the ability to access this information using a combination of hacking and phreaking skills within the device’s operating system by intruders is a threat to be reckoned with. These devices also provide mobile attack platforms, as they can download applications and utilities that can be used to engage in hacking. For example, the Apple iPad has Internet connectivity and supports a variety of hacker tools, making it an excellent device to engage in covert mobile hacking from a coffee shop or private network. The presence of these devices, integrated with WLANs and combined with the growth of e-commerce and e-government, makes the probability of technological criminality even more pervasive.
Finally, there is a significant growth in the number of home computers using broadband access to the Internet. Generally speaking, whenever these computers are booted, they are connected to the Web, whether being used or not by the owner. Moreover, home computers are less likely to have security (such as a firewall), or if they have security, it is usually a form that is easier to penetrate. Hackers, using port scanners, can identify computers connected to the Web and can conceivably access personal and financial information. If, for example, a person manages his or her banking account and pays bills using a program such as QuickBooks, then the intruder could easily access those files and obtain a significant amount of information that could be used in frauds or other forms of identity theft. Essentially, the growth in capacity, speed, and ease of computerization and networking will also contribute to the speed of exploitation by offenders. The brief history of computer crime has shown that offenders are faster and more adaptable than law enforcement in using the technology.
With this in mind, this chapter will consider and explore the trends, needs, and issues related to cybercrime and terror in the future through the use of forecasts. The forecasts provided here were developed using inductive logic based on existing knowledge and trends within computer crime, criminal justice, and national security. Two important limitations to the forecasts are the lack of empirical data and the inability to be precise in anticipating incidents of computer crime. Forecasts of behavior—like weather forecasts—often lack pinpoint precision, but they can help prepare a response and minimize damage from a phenomenon. Using the small, but growing, knowledge of the incidence, methods, dispersion, character, and trends of computer crime, we can begin to make some assertions as to the future of computer crime and terror. The discussion provided here is not, however, based on scientifically categorized data, methodological controls, or rigorous analysis to explore the validity of typological constructs. In essence, the literature contains logical speculation and assumptions, but virtually no data or information collected and analyzed under controlled methods. It should be noted that these limitations are recognized by the authors, as is the problem of poor data sources and the lack of a uniform reporting system for computer-related crimes.
Other important factors limit the ability to analyze or collect valid and reliable quantitative data. One significant factor is the difficulty—and sometimes impossibility—of determining when a computer crime has occurred, for example, the undetected incursion of a system by a cracker or the undetected theft of intellectual property by an employee who copies files to removable media. Another factor is the tendency of businesses to not report computer-related crimes that have been detected. There are several reasons for this: In some cases, businesses view this simply as a “loss” or even an expense, but not a crime. In other cases, businesses hold the perspective that offenders will not be caught due to the difficulty of investigation, thus reporting the crime would be “wasted effort.” Perhaps, however, one of the more fundamental reasons is the fear that publicity of computer crime victimization would undermine the confidence of the company’s clients. 2
THE FUTURE OF DIGITAL CRIME AND DIGITAL TERRORISM: FORECASTS
Based on the analysis of information collected, eight primary forecasts related to computer crime have been developed for this chapter.
Forecast 1: Computer Crime will Significantly Impact the Police and Courts
FORECAST:
The number of offenses reported to the police involving computers and electronic storage media will continue to increase substantially, requiring changing priorities for resource allocation, new training for line officers and investigators, new police specialties, and new knowledge for prosecuting attorneys and judges.
Perhaps a keyword in this forecast is “require.” The number of police agencies with a high-tech or computer crime unit has increased significantly over the last few years, but most of these agencies serve large urban populations. 3 In addition, prosecutors and judges are becoming increasingly well versed in computer crime and the unique law and vagaries inherent in these cases. That being said, it is still unknown how well state and local law enforcement agencies are equipped to handle these offenses.
For example, a study of forensic examiners found that they are regularly overworked and experience stress related to their work. 4 In fact, more than half of the individuals contacted felt that they did not have the workforce to complete their tasks at work. 5 The examiners felt that their work would be challenged by others and that there are other ways to accomplish their jobs. Additionally, examiners recognize that they need greater training to keep up with the rapid changes in computer technology. 6 Resources are always in demand within police agencies, but computer crime units appear to suffer disproportionately at this point in time due to the various resources needed to appropriately image and analyze digital evidence (see Box 15.1 ).
A reasoned, analytic assessment documenting criminal incidents in a jurisdiction would give meaningful insight on which to make basic decisions. Ideally, a routinized data collection system—perhaps similar to the National Crime Victimization Survey managed by the U.S. Department of Justice, Bureau of Justice Statistics (BJS)—including computer crimes would be a useful planning tool. Such a survey was developed and implemented in the business community in 2005. The Bureau of Justice Statistics conducted the first National Computer Security Survey, drawing 7,818 responses from businesses around the country. 7