I need an Computer Grimes Gure to help me ..Explain the four (4) major categories of computer crimes, and provide at least one (1) example for each.
Classification of Computer Crime
Defining computer crime sufficiently is a daunting and difficult task. Nevertheless there are, generally, four categories of computer crime, including (1) the computer as a target, (2) the computer as an instrument of the crime, (3) the computer as incidental to crime, and (4) crimes associated with the prevalence of computers. Definitions can become rapidly outdated, as new technology has consistently bred new offenses and victimizations.
1 The Computer as a Target
Crimes where the computer itself is the target include the denial of expected service or the alteration of data. In other words, the attack seeks to deny the legitimate user or owner of the system access to his or her data or computer. Network intruders target the server and may cause harm to the network owners or the operation of their business.
Data alteration and denial directly target the computer by attacking the useful information stored or processed by the computer. Altered data may affect business decisions made by the company or may directly impact individuals by altering their records. Furthermore, this activity, in some circumstances, results in the expenditure of great resources to recover the data. Although malicious network intruders may alter critical data, the most common source of such damage is an employee of the affected company. The primary difference between data alteration and network intrusion is the intent of the intruder. By reading or “browsing” through confidential files, the intruder actually creates a copy of the file. Thus, mere browsing may be theft, but it does not deprive the owner of the data or the user of the data. This makes the distinction between data alteration and intrusion more meaningful.
The story of Kevin Mitnick (perhaps the poster boy of hackers) perfectly exemplifies this distinction, as he wreaked havoc on countless systems during his hacking career. The prosecution of Mitnick relied on estimates of the value of software he downloaded but did not alter. Several major corporations placed a total value of hundreds of millions of dollars on the software Mitnick obtained. This amount was determined by a method suggested by the FBI: They directed the companies to estimate the total development costs of the software. This amount was questioned at various stages in Mitnick’s trial.Since Mitnick did not deprive the companies of the product of their research and development, it seems that the actual economic harm caused would be less than the total cost. This contention was supported by the failure of any of the corporation on the list of Mitnick’s victims to report such a loss to the Securities and Exchange Commission, as required for losses suffered by a company that sells stock.
When intrusion is discovered, it often requires the owner or administrator of the affected system to question the integrity, accuracy, and authenticity of data on the network. Although the legitimate user of the system and data is not denied access to either, there is no reasonable certainty of the data’s security in the system. Security measures often require the removal of Web-based resources and restoration of data from, hopefully, unaffected backup copies.
More direct than the subtleties of a network intruder, the denial of service leaves little room for argument of a negative effect. Although any resource may be denied to the rightful user, the most prominent example of this crime targeting the computer is the network denial-of-service attack. For example, on February 7, 2000, the Web site of Yahoo! was subjected to an unprecedented attack that effectively removed the site from the Internet for three hours. The initial reaction of law enforcement, security, and even hackers was shock that a site as large as Yahoo could be overwhelmed. 44 Subsequent investigation showed that the attacks had been aimed at choke points that funneled the majority of the site’s traffic through a few routers. While not as bad as first suspected, the attack showed that even the largest sites on the Internet were not safe.
The significance of denial-of-service attacks was also demonstrated in the recent conflict between Russia and Estonia, which was caused by the removal of a Russian war monument from a memorial garden in Estonia. 45 Russian citizens in Estonia and elsewhere were enraged by this action, leading to protests and violence in the streets of both Estonia and Russia. Computer-based attacks quickly ensued against government and private resources in both nations by computer hackers and citizens alike. In particular, Russian hackers so severely limited access to Estonian government and financial systems that the government had to temporarily host files on servers in the United States to continue business without interruption. 46 The damage the denial-of-service attacks caused to the Estonian economy was so severe that the country was crippled as a result.
Computer vandalism also falls under the category of crimes where the computer is a target. When an intruder removes valuable information from a computer system, the intruder denies the legitimate user or owner access to that information. This could represent a substantial loss of expected revenue. If the data are for direct sale, like a computer program or music, it may be possible to estimate the value of the lost data. However, it is more likely that data disrupted will be provided to the public for goodwill, to generate advertising income, or for no commercial purpose.
Even though a dollar value cannot be attached to the data, the owner still has a right to present the intended message and be free from disruption. Many organizations, like the University of Cambridge, maintain a Web presence for no apparent commercial purpose. In this case, the University of Cambridge has the distinction of owning the last defaced Web page to be archived at Attrition.org . On May 13, 2001, the Web camera at the University of Cambridge was replaced with the calling card of a computer vandal. The vandal wished to express nothing more important than “Ne0tz owned u!” 47 In another example of computer vandalism, a group named “Hacking for Girlies”defaced the New York Times Web site. The defacement caused the New York Timesembarrassment and the loss of advertising revenue for its free Web-based service. Some defacements, however, allow individuals to express their perspectives about a political or religious agenda. For example, when a U.S. spy plane crashed in China in 2001, a small war erupted between hackers in these countries over the rights to the plane and the reasons the jet was flying in the first place. The defacements contained political messages such as “Fuck the U.S.A.” and “China is Wrong!” and affected Web sites owned by the government, academia, and the private sector. 48 The consequences of computer vandalism are similar to data alteration or denial of service; many instances of computer vandalism also include network intrusion. All of these offenses target the computer.
2 The Computer as an Instrument of a Crime
Unlike crimes targeting the computer, using the computer as the instrument of the crime means that the computer is used to gain some other criminal objective. In other words, a burglar uses crowbars and lock picks as the instruments of crime in a fashion similar to the cybercriminal using computers and networks for crimes, such as theft, theft of service, fraud, exploitation, and threats or harassment.
Theft is defined as the taking of property with the intent of permanently depriving the owners of their property or service. In an environment where data are more easily copied than deleted, depriving the owner of the property permanently is relatively rare. However, theft can also mean taking property with the intent to deprive the owner of the value of the property or stealing securities. Parker, creator of the first computer crime typology, notes that market-sensitive proprietary information, financial information, trade secrets, process technology information, human resources information, customer information, information products, transitory information, and security information can all have value to the owner. 49 To some degree, each of these forms of information requires that the owner either maintain confidence in the integrity of the information or control the distribution of the information to maintain its value.
Other, more blatant, examples of computerized theft do actually deprive the legitimate owner of a tangible asset. The salami slice technique is a money crime; it is an automated means of stealing assets from a large number of transactions. In the round-down salami technique, the computer is used to round calculated dollar amounts down to the nearest cent. By always rounding down and diverting that amount to a special account, the criminal deprives both merchant and consumer of assets; however, the amounts are often trivial, similar to a slice taken from a salami, too thin to produce a noticeable effect, unless millions of transactions are involved.
Some thefts specifically involve theft of service. Although many services available on the Internet are free, some data and services are considered proprietary. This means the users must pay to use the data or service. The use of these proprietary services without payment is theft. For example, many service providers invest in the ability to meet demand for their service. In the mid-1990s, Internet service provider America Online (AOL) failed to anticipate demand for Internet access. As a result, many customers were not able to connect to AOL servers. To remedy this situation, AOL invested significant amounts of money in increasing its capacity. The amount of the increase was carefully planned to avoid spending too much. The damage from theft of service occurs when the criminal use of service forces the owner to invest in greater capacity to meet the projected needs of legitimate users.
Computers can also be used as instruments to commit fraud. Fraud committed by using a computer exploits the trust, which is guaranteed by law, in a business transaction. The buyer, seller, or peer in a transaction can perpetrate fraud. Shopping cart fraud is an example of consumer fraud against a business. Once purchases are selected, the computer criminal saves a copy of the purchase page and alters the prices. Once the altered prices are in place, the criminal submits the page as normal. Some merchants do not discover the fraud until they match inventory to purchases—possibly a month or more after the merchandise is shipped. Although basic security procedures or well-designed shopping cart programs would prevent this, many online merchants do not use either.
Other varieties of fraud found online are simply high-tech variants of older methods. Old scams have found entirely new audiences of victims on the Internet. Pyramid schemes have found a new source of legitimacy with professional-appearing Web sites and official-sounding Web addresses. In fact, virtually every tired bunko scheme has found new life through the Internet. Perhaps the most common one recently is the Nigerian bank scheme, where unsuspecting victims send their bank account numbers overseas with the dreams of getting millions in return. New forms of whole cloth fraud have also developed online, such as phishing. This offense involves victims being tricked into providing their financial information to a criminal through the use of convincing and extremely accurate fraudulent Web sites. 50
Computers are now often used as instruments to make threats or harass individuals. The U.S. Department of Justice maintains a Web site that details a range of threatening behaviors conducted on the Internet. In an early case of cyberstalking, a Maryland man, Warren Gray, pled guilty to sending five e-mail messages that graphically threatened the life of his victim and the victim’s family. At the same time, Gray slashed the victim’s car tires and left a hatchet in the victim’s office. In this case, cyberstalking coincided with real-world stalking, but the conviction under federal law came from the use of “interstate wires” to transmit the threat.
Even schoolyard bullying has moved to the Internet through the use of social networking Web sites and instant messaging services. Children can easily post messages that attempt to poke fun or humiliate another individual. In fact, a recent case of bullying through the social networking Web site Myspace led a young woman named Megan Meier to commit suicide after receiving cruel and harassing messages from a young man named Josh Evans. In reality, Evans was a fictitious identity created by Lori Drew, the mother of one of Megan’s friends. 51 Drew created this identity as a means to humiliate Megan as retribution for slighting her daughter. Unfortunately, this event highlights the severity of cyberbullying.
3 The Computer as Incidental to a Crime
Carter characterizes the computer as incidental to other crimes when “a pattern or incident of criminality uses a computer simply for ease in maintaining the efficacy of criminal transactions.” 52 In this category, the computer is not the primary instrument of the crime; it simply facilitates it. These crimes include money laundering, criminal enterprise, child pornography, and luring victims into compromising situations.
Money laundering is needed to provide criminals with the ability to spend their money. Funds can be divided into groups that are too small to be noticed and “smurfed” 53 out of the country to be assembled later in an offshore bank. Coordinating such a complex scheme is greatly facilitated by using computers. 54 Banks or casinos are closely regulated and heavily penalized for money laundering; however, the enormous volume of financial transactions in the United States makes it difficult for regulators to identify even relatively large questionable transactions. These types of transactions have increased with the growth of electronic payment systems, such as e-gold, which allow individuals to make and accept payments in foreign countries without any regulation. 55
Criminal enterprises also use computers as incident to the crimes that they commit. Computers appeal to criminal enterprises or businesses for many of the same reasons they appeal to others: They are quick, reliable, very accurate, and perform many business-related tasks far faster than if done manually. Thus, they are used to support many different types of criminal enterprises, including loan-sharking and drug rings. A number of prostitution rings have been found using computers to keep track of customers and payroll. The customers of prostitutes have also developed Web sites that enable discussion and reviews of the services provided by a sex worker. 56 This sort of Internet-based information sharing helps to facilitate the sex trade in the real world.
The production and distribution of child pornography have also benefited from the computer revolution. The Internet has been the key communication medium for the sale and exchange of child pornography on both international and domestic bases. In September 1998, the largest single child pornography sting operation in history occurred, resulting in the arrest of over 200 people in 21 countries. 57 Code named “Operation Cathedral,” British police coordinated raids in Europe, Australia, and the United States, confiscating more than 100,000 indecent images of children. Most of the images were being traded between child pornographers over the Internet. While most of those arrested were men, some were women who also belonged to exclusive child pornography clubs throughout the world. One U.S.-based club, called “Wonderland,” had images for sale depicting children as young as two years of age. The sheer size of the pornography network shocked the police as well as the general public. The United Nations called for a worldwide offensive to curb the exchange of pedophilia on the Internet—a very difficult task considering the vast number of jurisdictions and judicial systems present in the international community. 58
Some crimes of violence are facilitated through the use of a computer. For example, the Internet has been used to lure victims to pedophiles. Adult users of chat rooms may use the supposed anonymity of the Internet to pose as teenagers to establish a rapport with their intended victim. Numerous “sting” operations have placed law enforcement officers in these same chat rooms posing as children. In fact, a recent study found that these sorts of proactive investigations comprised 25 percent of all arrests for Internet sex crimes against minors and produced a high rate of guilty pleas and generally successful prosecutions. 59
4 Crimes Associated with the Prevalence of Computers
Targets of these types of crimes are mainly the industry itself, but also include its customers and even people who have avoided information technology. These crimes include intellectual property violations, component theft, counterfeiting, identity theft, and a variety of corporate offenses. Intellectual property violations are often described as piracy. The music trading service Napster has recently caused music piracy to replace software piracy in the public mind as the leading example of this crime. Large-scale software piracy began in Asia. The Business Software Alliance reports that just one person selling unauthorized copies of some 40 different popular programs in Singapore may have made several million dollars, even though he charged as little as $15 for copies of programs that retailed for as much as $600. 60 Violation of American copyright laws in China—particularly piracy of software, videotaped entertainment, and music—led the United States in early 1995 to announce that it would place a 100 percent tariff on all products entering this country from China unless the Chinese government took action to eliminate such violations.
Extensive software piracy now exists worldwide and is facilitated by the Internet. Dutch bulletin boards 61 provided the nexus of “cracked” games and software during the 1980s. Today, piracy groups continue the tradition by racing to provide the first cracked edition of new software, music, and movies for download through Web sites and resources around the world, often before it is released officially. In fact, a movie reviewer for Fox News online was fired for reviewing a pirated copy of the movie X-Men Origins: Wolverine, which he obtained through a piracy group a few months before its official release in the theater. 62 This sort of rapid and large-scale piracy is engendered by the growth of file-sharing programs such as Bit Torrent and Rapidshare, which enable individuals to quickly capture data hosted on multiple computers around the world.
The theft of desktop and laptop computers, monitors, printers, scanners, modems, and other computer components has also become a problem due to the increased portability of computer systems and the potential for sensitive information to be contained on the system files. In 2007, the theft of laptops and mobile devices accounted for 50 percent of the incidents reported by business and industry security professionals. 63 Although the value of laptops has decreased due to dropping prices of computer technology, the information contained on their hard drives, such as documents and passwords, has significant monetary value. Theft of proprietary information accounts for over $3 million in losses within the private sector. 64
The full extent of computer theft is unknown because many thefts go unreported and because many police departments consider theft of computer hardware as just another stolen-property crime. Some computer owners do not even know what they own and therefore cannot provide the police with an accurate description, let alone the serial numbers. This is a problem compounded by the inability of some police officers to accurately differentiate among computer equipment and peripherals. Furthermore, the massive growth in small portable devices like iPads, Blackberry devices, and other personal computers and their perceived value make them attractive targets for thieves due to their value and popularity.
Identity theft has become a major concern for both the public and members of the law enforcement community. Although identity theft can occur without the aid of a computer, the anonymity of the Internet and access to vast numbers of personal information have fundamentally changed the nature of this crime. In a fairly common case, almost 40 people employed by a San Diego pharmaceutical company had their identities stolen by a laboratory aide who had discovered unprotected personnel records at the firm. Before being caught, the thief obtained 75 credit cards, $100,000 in merchandise, 20 cellular phones, and rented 3 apartments.
Identity theft is also significantly enabled by hackers who can gain access to sensitive databases of information. Once inside of a large repository of credit cards, personal information, and other files, hackers can parse out this information and sell it in open markets for a profit. In fact, an individual named Kenneth Flurry obtained stolen debitcard numbers with personal information from hackers in Russia and Asia and used the information to create fraudulent ATM cards. He obtained over $380,000 from ATMs over a three-week period using these cards and was arrested and subsequently prosecuted in the U.S. federal court system.
The expanded use of the Social Security number is the primary reason for the ease of identity theft. Three major credit reporting bureaus control the information on all persons applying for credit in the United States: Equifax, Trans Union, and Experian. These companies allow anyone with a name and Social Security number to access credit histories. Credit card companies make the process of credit application little more complicated than supplying this information.
Various corporate crimes also appear to be on the rise as computer use has expanded. The rapid growth of the computer industry has caused many questionable business practices to be developed. Examples of these questionable practices include rebate fraud, grossly one-sided end user license agreements (EULAs), misleading advertising, component swapping, reselling refurbished components in “new” systems, simple fraud, and many others. The Federal Trade Commission (FTC) has become involved in actions against several companies that promised mail-in rebates, but could not deliver. Although rebates are a common practice in the industry, the first case to draw widespread attention was the Iomega Zip Drive.TM With the unprecedented demand for the Zip Drive, the rebate fulfillment center contracted to handle the processing of rebates was overwhelmed. A large number of rebates were simply lost, and delays of a year or more were common. Interestingly, with the advancement of rewritable computer disks (CDs) and CD/DVD burners, and their subsequent affordability to the general public, the demand for “zip drives” has decreased significantly over the past two years.
EULAs are contracts that specify the rights of the consumer when purchasing a license 65 to use software. Originally intended to prevent people from reselling copies of their software, EULAs have become so one-sided as to violate common tenets of contract law and consumer protection legislation. Common elements of the EULAs include a stipulation that the software licensed need not function for any particular purpose, even if that function is advertised. Although it is legal to require an EULA, the terms of that contract do not automatically supercede false advertising legislation. There is also an assumption that an item sold is fit for use.
An excellent example of a problem resulting from EULAs is the Sony Music Trojan, which was revealed in 2005. The Sony Corporation placed a program called XCP, or Extended Copy Protection, onto its music CDs to limit the ability of the consumer to make copies of the disk. The functionality of the program and its presence were not fully elaborated in the EULA. 66 Although the program did nothing malicious, many consumers and artists were embarrassed and outraged that the company felt it appropriate to micromanage customer computer activity.
Summary
Attempts to categorize and label specific types of computer crime have followed traditional methodologies, looking at the computer as a target or instrumentality of the crime as applied to other types of existing legislation. Unfortunately, these types of categorizations and labeling exercises often fall short in grasping the overall milieu in which computer crime is observed. Additionally, they often fail to take into account the behavioral and criminological aspects of digital crime. This may be particularly true when the crime touches some aspect of the Internet or involves a new type of white-collar scam or sophisticated corporate fraud. Categorizations do help us sort out and define more commonly observed criminal incidents where computers are used. We would like to fit all sorts of different and varied criminal methodologies that involve computers into discrete boxes. Certainly, society has accomplished this task for traditional crime by defining the elements necessary to commit a specific crime. There is a new challenge posed by computer crime: Specific incidents may well fit into a criminal violation and hence meet the basic elements of a crime, while other, more sophisticated criminalities may not. The difficulty in specifically and accurately defining each type and incident of computer crime will continue to plague successful prosecution of those misusing computers.
However, and much more important, the nature of digital crime is so expansive as to include ominous and catastrophic events that cripple our critical infrastructure and threaten national security and cause international conflict. In the post-9/11 era, terrorism has become a real threat to our society and to our way of life. We have attempted to secure ourselves through the use of physical searches for weapons, the employment of new technological sensing devices in critical areas, more visible signs of police and security presence, and a stepped-up military offensive against those in foreign countries who may pose threats. Trying to engage the police in the “war on terrorism” may be futile, as the criminal justice system (and particularly the police) is designed to address crime. The people who pose significant terrorist dangers are often motivated by ideologies that are really not criminal in the traditional sense of the word. They seek destruction and devastation as part of war. The police and the criminal justice system are ill-equipped to handle such threats. Sometimes, these terrorists pose significant threats to computer and information systems by targeting our critical infrastructure. Designing a system that will be secure, yet provide easy accessibility to needed data and information, will be a trick. Indeed, securing our information infrastructure may well be one of the most challenging tasks of the future.
Taylor, R. W., Fritsch, E. J., Liederbach, J. C. (02/2014). Digital Crime and Digital Terrorism, Future Problems, 3rd Edition. [VitalSource Bookshelf Online]. Retrieved from https://strayer.vitalsource.com/#/books/9781323101704/