WAYS TO FIGHT BACK
AGAINST
CYBER CRIMINALS

Listcrime is a one-stop-shop for reliable, up-to-date information about cyber crime, we at Listcrime.com want to give home users and small businesses the advice they need to use the Internet safely. For the most part, references within this web page appear as links to the actual site that the information came from. I revert to customary referencing when citing non-WWW based sources. A bibliography of any sources not linked will appears at the end of this web page.

FIGHT BACK AGAINST CYBER CRIME

According to some in Law Enforcement and most security consultants, Law enforcement is only able to take on the top three per cent or four per cent of the most serious crimes unfortunately that that alone tell you how unaffectedly cybercrime is being dealt with.  Most law enforcement experts state that when it comes to combating cybercrime jurisdiction is limited by national borders and the ability to pursue overseas criminals often depends on personal contacts and priorities of foreign law enforcement agencies.

Cyber attacks on information networks can have serious consequences such as disrupting critical operations, causing loss of revenue and intellectual property, or even loss of life. Organized cyber criminals and underground markets have become a serious problem and represent a substantial security threat to internet use. Most approaches for disrupting underground markets have focused on standard law enforcement activities such as locating and disabling hosting infrastructure or identifying and arresting market participants.

These techniques face numerous social and technological hurdles which limit their success and result in substantial associated costs. For example, disabling the hosting infrastructure for a black market web site may require multi-national cooperation, which can be time and resource consuming. Furthermore, nations may refuse to cooperate with foreign law enforcement agencies or may lack appropriate laws for prosecution. Even in the cases where law enforcement techniques have succeeded in disrupting an underground markets, those markets often re-emerge under a new administration with a new “bulletproof” hosting infrastructure. Identifying and arresting key players also includes a host of associated complexities and costs, such as tracing individuals through chains of compromised hosts and the cost of the subsequent legal proceedings sometimes outweigh the threat.

With the limited resources and lack of action by Law Enforcement agencies, we asked some cybercrime fighting experts to give us some advice on low-cost approaches to countering the threat posed by underground markets.

As a citizen and victim of Identity theft or cyber crime you can help to get these BAD GUYS. Lets look at the Sybil/Slander technique suggested by some.  To utilize this technique you go on to some of those IRC channels and semi-covert Web sites that advertise illicit activity and beat them at their own game.   This involves joining illicit chat rooms and forums and causing as much CHAOS as possible.  To participate in the chat, you need a type of program or plug-in called an IRC client. Once logged in to these BAD GUYS IRC Channels or Web Sites try to give them a taste of there own medicine.

 

Try the below techniques.

1) Sybil & Slander attack (Citizens)

A Sybil attack, named after the pseudonym of a woman known for her multiple personalities, involves creating multiple online identities as a merchant of stolen data. These identities could be used to undermine confidence in the market by repeatedly failing to deliver data paid for by those seeking to commit credit card fraud by purchasing your stolen data.

A Slander attack aims to destroy the reputation of established dealers in stolen data to depress prices and drive customers to less-reputable dealers, who may defraud them aiming to commit fraud and further destabilize the black market. This tactic takes advantage of the primitive processes most illegitimate IRC channels use for handling complaints of false transactions, allowing slanderers to wrongly defame someone. A reputation system's vulnerability to a Slander attack depends on how cheaply identities can be generated, so if these BAD GUYs allow you to access there IRC CHAT rooms or web sites to make false comments about the system to others. Do and Say anything to disrupt there system.

To use these types of attacks you simply go to a known IRC chat that openly exploits Personal Identifiable Information (PII) & stolen data and exploit the open nature of the underground market to establish Sybil identities which in turn disrupt the market by undercutting its participant verification system.

For example:

1. Go on to the BAD GUYS IRC chat or Web site and establishes multiple Sybil identities by connecting to the market’s IRC servers and registering nicknames.

2. Builds the status of each of your Sybil identities. This can be accomplished through positive feedback from other Sybils or out-of-band activities. The success of a Sybil attack depends on the cost associated with generating a Sybil identity and the cost of achieving verified status.

By using the Sybil attack method you may present yourself with multiple identities in a peer-to-peer network to appear and function as distinct nodes. By becoming part of the peer-to-peer network, you may join the site and act maliciously. By masquerading and presenting multiple identities, you can create CHAOS on that site. This results in a decrease in the number of successful transactions which is the desired outcome.

3. To build positive feedback just enter several separate IRC channels and replay credit card data seen in one channel to a different channel. This allows verified-status Sybils to be produced at a minimal cost. Deceptive Sales.

4. Utilizes your verified-status (Slander/Sybil) to advertise goods and services for sale. Instead of a an honest transaction, you openly request payment for goods and services you claimed you purchased from so-called (BAD GUY) reputable dealer.  The (BAD  GUY) reputable dealer loses his reputation which adds to CHAOS on the site. This is termed “ripping” and it is the goal of the administrator of the site to minimize such behavior.

Most of these channel moderators (Basically they have authority over who can participate in an IRC channel and are able to kick and ban a specific person from the chat session) are crooks and most crooks can't manage anything.

5. If your (Slander/Sybil) Attacks are indistinguishable from any other verified sellers, a buyer will be unable to identify honest verified sellers/buyers from dishonest verified-status Sybils.

Also, always use a unique screen name that is not associated with your e-mail address if you chat online. Screen names are accessible, so don't make it too easy for them to guess your e-mail address.

                             NEXT>>

CONTACT US       ABOUT US     DISCLAIMER

COPYRIGHT ©LISTCRIME 2008 ALL RIGHTS ®RESERVED