Chapter 3
Computer and Internet Crime
At a Glance
Instructors Manual Table of Contents
Overview
Objectives
Teaching Tips
Quick Quizzes
Discussion Questions
Additional Projects
Additional Resources
Key Terms
Lecture Notes
Overview
Chapter 3 provides an overview of security, starting with reasons why attacks on computer
systems are on the rise. The chapter presents different types of perpetrators of attacks, and the
methods used by attackers. It ends with a discussion of how to prevent attacks and an overview
of the components of an effective security policy.
Objectives
As studentsyou read this chapter, they should consider the following questions:
What key trade-offs and ethical issues are associated with the safeguarding of data and
information systems?
Why has there been a dramatic increase in the number of computerrelated security
incidents in recent years?
What are the most common types of computer security attacks?
Who are the primary perpetrators of computer crime, and what are their objectives?
What are the key elements of a multilayer process for managing security vulnerabilities
based on the concept of reasonable assurance?
What actions must be taken in response to a security incident?
What is computer forensics, and what role does it play in responding to a computer
incident?
Teaching Tips
Vignette—The Reveton Ransomware Attacks
The Iranian Cyber Army
1. Introduce the term Ransomware—malware that disables a computer or smartphone until
the victim pays a fee, or ransom.
I. IT Security Incidents: A Major Concern
1. Begin this section by discussing the ethical decisions regarding IT security faced by
business managers, IT professionals, and IT users.
2. Note that the number of IT-related security incidents is increasing. According to a
A. Why Computer Incidents Are So Prevalent
Increasing Complexity Increases Vulnerability
1. Introduce the terms cloud computing and virtualization software.
Teaching
Tip
Give an overview of the different entry points into a system and discuss how
each one might provide a way to compromise security.
Higher Computer User Expectations
1. Today, time means money, and the faster computer users can solve a problem, the
sooner they can be productive. As a result, computer help desks are under intense
pressure to respond very quickly to users’ questions.
Expanding and Changing Systems Introduce New Risks
1. An important point to make is that it is increasingly difficult to keep up with the pace
of technological change, successfully perform an ongoing assessment of new security
risks, and implement approaches for dealing with them.
Bring Your Own Device
Increased Reliance on Commercial Software with Known Vulnerabilities
1. Introduce the term exploit.
3. Introduce the term zero-day attack.
B. Types of Exploits
1. Use this section to discuss some of the more common attacks, including the virus,
worm, Trojan horse, spam, distributed denial-of-service, rootkit, phishing,
spear-phishing, smishing, and vishing.
Viruses
1. Technically, a virus is a piece of programming code, usually disguised as something
else, that causes a computer to behave in an unexpected and usually undesirable
manner.
2. Point out that a true virus does not spread itself from one computer to another. A virus
is spread to other machines when a computer user opens an infected email attachment,
downloads an infected program, or visits infected Web sites. In other words, viruses
Worms
1. Discuss the differences between worms and viruses.
2. Note that the negative impact of a worm attack on an organization’s computers can be
considerablelost data and programs, lost productivity due to workers being unable to
use their computers, additional lost productivity as workers attempt to recover data and
programs, and lots of effort for IT workers to clean up the mess and restore everything
to as close to normal as possible.
Trojan Horses
1. Point out that a Trojan horse can be delivered as an email attachment, downloaded
from a Web site, or contracted via a removable media device such as a CD/DVD or
USB memory stick. Once an unsuspecting user executes the program that hosts the
Trojan horse, the malicious payload is automatically launched as wellwith no telltale
signs. Common host programs include screen savers, greeting card systems, and
games.
2. Introduce the term logic bomb.
Spam
detracts from the ability of recipients to communicate effectively due to full mailboxes
and relevant emails being hidden among many unsolicited messages, and costs
Internet users and service providers millions of dollars annually.
4. Introduce the Controlling the Assault of Non-Solicited Pornography and
Marketing (CAN-SPAM) Act which went into effect in January 2004.
5. Introduce CAPTCHA (Completely Automated Public Turing Test to Tell
Computers and Humans Apart) software, which generates and grades tests that
humans can pass but all but the most sophisticated computer programs cannot. Use
Figure 3-12 to aid the discussion.
Distributed Denial-of-Service (DDoS) Attacks
1. Point out that a distributed denial-of-service (DDoS) attack does not involve
infiltration of the targeted system. Instead, it keeps the target so busy responding to a
stream of automated requests that legitimate users cannot get inthe Internet
equivalent of dialing a telephone number repeatedly so that all other callers hear a
Rootkits
1. Introduce the class to rootkits, noting that once installed, the attacker can gain full
control of the system and even obscure the presence of the rootkit from legitimate
system administrators.
Phishing
2. Introduce the term spear-phishing.
Smishing and Vishing
1. Discuss the difference between smishing and vishing. Use examples to aid the
discussion.
Quick Quiz 1
1. _____ emulates computer hardware by enabling multiple operating systems to run on one
computer host.
2. In computing, a(n) _____ is an attack on an information system that takes advantage of a
particular system vulnerability.
3. A(n) _____ is a piece of programming code, usually disguised as something else, that causes
a computer to behave in an unexpected and usually undesirable manner.
4. A(n) _____ is a harmful program that resides in the active memory of the computer and
duplicates itself.
C. Types of Perpetrators
1. Students should be aware that the people who launch these kinds of computer attacks
include thrill seekers wanting a challenge, common criminals looking for financial gain,
industrial spies trying to gain a competitive advantage, and terrorists seeking to cause
destruction to further their cause. Use Table 3-54 to aid the discussion.
Hackers and Crackers
1. Point out that hackers test the limitations of information systems out of intellectual
curiosityto see whether they can gain access and how far they can go.
Teaching
Tip
Emphasize that although a hacker might be motivated by curiosity, their actions
are not harmless and even unskilled hackers can damage a system.
2. Introduce the terms lamers or/ script kiddies and data breach.
Malicious Insiders
1. Introduce the term malicious insider—an ever-present and extremely dangerous
adversary.
2. Point out that the fraud that occurs within an organization is usually due to weaknesses
in its internal control procedures. As a result, many frauds are discovered by chance
Teaching
Tip
Emphasize that although malicious insiders may be difficult to detect, unlike
hackers, once they are detected they can be held accountable, whereas with
outside hackers it can be difficult to trace the attack back to the hacker.
Industrial Spies
1. Industrial spies use illegal means to obtain trade secrets from competitors. Note that
Teaching
Tip Use examples to discuss legal and illegal means of gathering intelligence.
Cybercriminals
1. Explain that cybercriminals are motivated by the potential for monetary gain and hack
into computers to steal, often by transferring money from one account to another to
Hacktivists and Cyberterrorists
1. Explain that the term hacktivism, a combination of the words hacking and activism, is
used to describe hacking that achieves a political or social goal.
2. Introduce the term cyberterroist.
Teaching
Tip
Emphasize that although cyberterrorism is disruptive, it is much less likely to
occur than cybercrime, and thus the costs associated with cybercrime are
greater at this time.
D. Federal Laws for Prosecuting Computer Attacks
1. Over the years, several laws have been enacted to help prosecute those responsible for
computer related crime. Use Table 3-65 to aid the discussion.
Quick Quiz 2
1. A(n) _____ is the unintended release of sensitive data or the access of sensitive data by
unauthorized individuals.)
2. _____ use illegal means to obtain trade secrets from competitors.
3. _____ is legally obtained information gathered using sources available to the public.
4. _____ are motivated by the potential for monetary gain and hack into computers to steal.
II. Implementing Trustworthy Computing
1. Trustworthy computing is a method of computing that delivers secure, private, and
reliable computing experiences based on sound business practiceswhich is what
organizations worldwide are demanding today. Use Figure 3-4 and Table 376 to aid the
discussion.
2. Note that the security of any system or network is a combination of technology, policy, and
Teaching
Tip
Explain why longer passwords that use numbers and special characters are more
secure, noting that if a password is 2 characters long, and the number of
possible characters is 26, then there are 262 possible different combinations a
hacker would have to try, but if the password is 12 characters long, then the
hacker would have to test 2612 different possibilities. If a password uses
numbers as well as letters, then the hacker has to try 3612 different combinations.
A. Risk Assessment
1. Risk assessment is the process of assessing security-related risks to an organization’s
computers and networks from both internal and external threats. Such threats can
B. Establishing a Security Policy
1. A security policy defines an organization’s security requirements, as well as the controls
and sanctions needed to meet those requirements. Explain that a good security policy
delineates responsibilities and the behavior expected of members of the organization.
2. Point out that the SANS (SysAdmin, Audit, Network, Security) Institute’s Web site offers
a number of security-related policy templates that can help an organization to quickly
develop effective security policies.
C. Educating Employees and Contract Workers
1. An ongoing security problem for companies is creating and enhancing user awareness of
security policies. Explain that employees and contract workers must be educated about
the importance of security so that they will be motivated to understand and follow the
security policies.
D. Prevention
1. No organization can ever be completely secure from attack. Point out that the key is to
implement a layered security solution to make computer break-ins so difficult that an
attacker eventually gives up.
Installing a Corporate Firewall
1. Explain that a firewall stands guard between an organization’s internal network and the
Internet, and limits network access based on the organization’s access policy. Use