‏إظهار الرسائل ذات التسميات Cyber. إظهار كافة الرسائل
‏إظهار الرسائل ذات التسميات Cyber. إظهار كافة الرسائل

السبت، 28 أبريل 2012

E-Commerce And Cyber Crime - Part 4

How To Deal With The Consequences

Just losing assets is one of the consequences of cyber misbehavior in e-commerce. Whether the attacker is inside or outside the organization, most of the time victims suffer from negative publicity. This can harm the organization's fame and reputation very badly, erode business relationships with the customers and other stakeholders and reduce the amount of potential revenue. According to the reports of a survey that was conducted by Gallup organization for a marketing firm At Plan in March 2000 it was seen that consumers have been hurt badly by attack on different prominent sites. Almost one-third of the overall consumers stated that they might not be that much interested in purchasing products via the World Wide Web because of the recent news of cyber crimes. Almost seven out of every 10 online shoppers who were contacted via telephone said that they were concerned about the cyber attacks that has blocked access to prominent websites like Yahoo, Amazon etc.

Because of this ever present array of cyber threats, it is very important for the organizations to develop a cyber defense program that will interlace preventive measures into the e-business operations stuff.

But only prevention is not enough. Along with prevention, a defense program should also be developed for detection. Because, if you cannot detect the attacker, how will you prevent the attack? The detection process should be like a sound forensic incident response process. Because by the establishment of such procedure, policies as well as procedures for the departmental and individual behaviors are established. Along with that, ongoing communication process for the employees, other stakeholders, analysts, press is encompassed. This incident response process is very much important because it cannot be geared just for the emergency situations. An interesting thing is that the organizations repel lot of attacks everyday. In the world of interconnected business, these attacks are a part of everyday life of the organizations. But that does not mean that everyone should be treated or suspected as attacker. Then it will be impossible to conduct business. For that the organization leaders need to be judicious enough to detect different types of attacks. They should remember that attempted hacks are equally illegal to successful ones. The attempted perpetrators also need to be detected and punished. In emergency situations, the most important thing is to preserve the forensic evidence for the identification, apprehension and prosecution of the perpetrator.

E-business security is an ongoing and comprehensive process of adding, managing and removing layers of actions that are based on holistic strategies of risk management. As the organizations are providing system access to the inside and outside people, they should integrate a cyber defense system that encompasses all the possible points of interconnection, from the inside out. This is very much important because failing to do so can leave the organization vulnerable to different kinds of cyber attacks, both inside and outside the organization. That will not be good for the organization's business. So it is important to design a very good cyber defense system.

http://www.criminalattorneyin.net/ is the resource for your ultimate criminal law solution.


View the original article here

الخميس، 19 أبريل 2012

E-Commerce And Cyber Crime - Part 1

Business Reliance On Technology And Perceived Risks

In today's world, there will be hardly any organization that does not rely upon communications and different forms of latest technologies for running its activities. It is undoubtedly acceptable fact that technology is an integral part of business. But all is not well with any of the particular thing in the world. Same is the matter with technologies too. Along with the blessings of technologies, there are also curses. There are many perceived risks which many of the business organizations cannot yet even think of. Because of the advanced use of technologies and resulting inter connectivity among organizations, the offenders are getting a very good chance of committing fraudulent things over the internet. With the growth of e-business, the perpetrators have got a very good chance of exploiting the vulnerabilities. They can also use the new technological weaknesses in both software and hardware architectures that is the backbone of many business organizations. It is possible to commit a crime from any part of the world in a networked environment. In this article, we are going to discuss on how different organizations can be prepared for preventing the effects of new risks. Because if the organizations are not aware about these risks, than their business could be diminished very soon.

Recognizing Your Attacker

There is a misconception among many that the individuals who attack on different networks are teenagers or these attacks are due to social misfits. But according to many experienced persons, these persons are the representatives of a very small number of the various groups of criminals perpetrating e-crimes both outside and inside the organizations. These criminals may commit the-crimes for fulfilling their own objectives or hired by others for providing service.

The persons who can be external intruders are as follows:

1. Crackers who are "sophisticated." These persons develop as well as use technological tools that provide illegal access to the network of an individual or an organization. These persons either work in groups, personally or on hire for someone or any deceptive organization. These are very dangerous ones because after achieving their landmark, they anonymously distribute their tools visa the internet. They distribute the tools for masking their organization either by using the tools or by exploiting the victim.
2. "Cookbook" crackers. These are persons who have lacking in knowledge, ability and skill on how to create and use intrusion tools that are "sophisticated." But these persons seek the tools and then launch attack.

http://www.criminalattorneyin.net/ is the resource for your ultimate criminal law solution.


View the original article here

الثلاثاء، 17 أبريل 2012

E-Commerce And Cyber Crime - Part 2

Recognize The Attacker: It's Important

Recognizing the attacker is very important in case of cyber crimes. Because the attackers share motivations between themselves. No matter whoever the perpetrator is, a deliberate cyber attack can do the following damages:

1. Destroy an asset completely. That is the asset has no value in future.

2. Corrupt an asset. In this case, the worth and value of the asset is reduced.

3. Deny all kinds of access to an asset. That is the asset still exists, but is not attainable.

4. Leads to stealing of an asset. That is the inherent value of the asset is retained but its possession is changed.

Revenge, malevolence, greed or misguided intellectual challenge of creating chaos in the large networks can be a motivating factor for both outsiders and insiders. External attacks include offenders from outside. These offenders break into a victim's network for taking something of worth or for serving the purpose of "trojanising" the network. What is this "trojainising?" It is named for the virus Trojan horse. In this crime, the security measures of networks are compromised and the security tracking mechanisms/legitimate programs are modified for gaining unmonitored access in future. In such cases, the perpetrator's objective is to gain full control over the victim's network system so that unauthorized functions that are unknown to the owner can be executed. Here are some examples:

1. A highly rated e-commerce shopping cart developer is accused of building a backdoor software into the program that might provide him or the hackers full control of the server on which the program is installed. Such a shopping cart is the Dansie shopping cart. This shopping cart is used in more than 200 e-commerce sites. It is also recommended by some of the renowned web hosting firms. However the cart contains such programming codes that enable the author to potentially run any kind of command on the web server.

2. In the year 2000, a person was proved guilty in the federal court of Delaware. The person set off a computerized time bomb halting manufacturing of a high tech company. It led to a loss of about 10 million dollars.

In case of internal attacks, the attacks are perpetrated either by the employees of the organization or trusted associates who misuse their power and have unauthorized access to the organization's systems as well as facilities. Here are some examples of internal attacks:

1. Very recently, in New York, "Internet Trading Technologies Corporation's network was hacked and it was hacked by no outsider but by one of their employee. As a result, the business dealings were halted and it lasted for three days. It also had the potential to affect the large portion of the NASDAQ trades that were conducted by the company. But the attack was not sophisticated and the employee was traced. He was charged five years of jail stay.

2. The organizations need to be careful about the disgruntled employees. These employees can also create havoc in the networks of the organization. Recently, three electronic music stations, namely E101, Trance Invasion and Pro G had gone off the air after they were actually misplaced from the computer server where they were hosted. The whole procedure was performed by a former disgruntled employee.

http://www.criminalattorneyin.net/ is the resource for your ultimate criminal law solution.


View the original article here