Govt 11: Cybercrime and Cyber warfare (v1.0)

Key reference is Prof Paul Rosenzweig of George Washington University.  

A New Era Begins

The world entered a new era in July 2010. Until then, the prevailing belief was that cyber‑attacks would remain confined to the digital domain. Symantec had already discovered more than 400 million pieces of malware by 2011 and neutralized them. But in 2010, a new malware—STUXNET—changed everything.

STUXNET was extraordinarily sophisticated. It penetrated multiple layers of defense and rendered at least 1,000 centrifuges inoperable at Iran’s Natanz uranium enrichment facility. The attack required deep insider knowledge of the systems involved and is estimated to have set Iran’s nuclear program back by at least two years. More importantly, it demonstrated that malware could inflict physical damage on real‑world infrastructure.

This opened the world’s eyes: any computer‑controlled system—power plants, drones, missiles, aircraft, dams, water systems, the electric grid, financial institutions—could be vulnerable.


Why the Internet Is So Vulnerable

The internet became globally successful because it was simple, open, transparent, interoperable, flexible, and easy to use. No one controls it. Anyone can extend it by purchasing a domain name. Security and identity were not core design priorities.

Today:

  • Over 2.5 billion people use the internet

  • Over 630 million domain names exist (22% in the U.S.)

  • Every minute, 1,800 terabytes of new data are created

  • Every two days, humanity creates as much information as from the dawn of civilization to 2003

Anything connected to the internet is potentially hackable.

Five features make the internet especially vulnerable:

  • Borderless: Information flows freely across national boundaries.

  • Anonymous: Identifying attackers is difficult.

  • Instantaneous: Attacks can occur from anywhere, at any time.

  • Asymmetric: Small actors can inflict disproportionate damage at low cost.

  • Uniform: Everything is just 1s and 0s—no inherent distinction between types of data.

Governments and private organizations now invest heavily in defending critical systems. At the same time, nations, criminals, and hacking groups invest heavily in offensive capabilities. Individual users must also take steps to protect themselves.


Types of Malware and Attacks

Malware exploits security flaws in operating systems, networks, or applications. Once a flaw becomes known, it can be patched—but a newly discovered flaw is extremely valuable to attackers. When exploited before a patch exists, it is called a zero‑day attack.

Common attack types:

  • DDoS (Distributed Denial of Service): Overwhelms a website with fake requests using botnets.

  • Botnets: Networks of infected machines controlled remotely; can send spam or launch attacks.

  • Trojans: Malicious code hidden inside legitimate downloads.

  • Phishing: Masquerading as a trusted source to steal sensitive information.

  • Spear‑phishing: Highly targeted phishing using personal details.

  • Spyware: Long‑term monitoring of keystrokes, webcam, or microphone.

  • Logic bombs: Malicious code triggered by specific conditions.

  • Adware: Unwanted advertising software.

Rule for users: Do not click unknown links, open suspicious attachments, or download unverified programs.


How Prevalent Are Cyber‑Attacks?

We don’t know the full scale. Governments no longer track everything. A Canadian study estimated:

  • 80,000 zero‑day exploits per day

  • 1.5 million compromised computers active at any time

  • 21 million botnet connection attempts per day

  • Military systems probed thousands of times and scanned millions of times daily

Global cybercrime losses were estimated at $6 trillion per year in 2021, rising to $10.5 trillion by 2025. Intellectual property theft is a major component.


Cybercrime, Fraud, and Espionage

A large portion of cybercrime involves theft of money, identity, or high‑value information. Many cybercrimes resemble traditional crimes and are covered by existing laws. Others are harder to prosecute.

Examples:

  • Nigerian scams: Mass‑sent fraud schemes promising large payouts in exchange for small upfront fees.

  • Economic espionage: Often involving intellectual property theft, sometimes originating in China.

  • Organized cybercrime syndicates: Frequently based in Russia.


Computer Crimes and the CFAA

Some offenses involve misuse of computers rather than theft:

  • Using a fake identity on a platform that prohibits it

  • Emailing confidential documents

  • Posting prohibited hate content

These fall under the Computer Fraud and Abuse Act (CFAA). CFAA also likely makes hack‑back—retaliatory hacking by companies—illegal.


Hacktivism and Cyber Insurgency

Hacktivism involves coordinated attacks by activists or protesters. Examples:

  • Estonia: A massive DDoS attack from Russian hackers crippled government systems.

  • Wikileaks and Anonymous: More sophisticated operations, bordering on cyber insurgency.

  • Counter‑groups: “Happy Ninjas” and others who fight malicious actors.

Much of the internet’s infrastructure is privately owned. Corporations unhappy with government policy could theoretically disrupt the systems they control.


Cyberwarfare as a New Domain

Nations increasingly view cyberspace as a distinct domain of conflict. There is no consensus on its boundaries or rules. Some form of cyberwar is likely inevitable.

The Pentagon’s policy: If a cyber‑attack qualifies as an act of war, the U.S. may respond with any means necessary, proportionally. The challenge is determining what constitutes an act of war in cyberspace.


What About Defenses?

That will be addressed in a later essay:
https://jaykasi.blogspot.com/2023/06/how-to-defend-against-cyber-attacks.html

Want to Read on?

NEXT: The surveillance state and society


Comments