Sunday, March 18, 2012
Blog Post 2 - Cybercrime
I found chapter 7 in Tavani regarding Cybercrime an interesting read and can relate this somewhat to a personal experience I've had in the IT field.
From my tenure as a supervisor at a telecommunications outfit, I dealt with some levels of fraud. However, most of them were not related to cybercrime and were mostly financial cases. One thing I do remember was watching our System Administrator perform some Active Defense Hacking (Tavani, 204).
The system administrator, or "SysAdmin" as we called him, was a self-proclaimed "code poet" and I couldn't deny him that title. This man knew what he was doing with Linux software, networks, and overall server management. At the time, our company had just been purchased by a larger conglomerate which had internal security issues. At the time they were a long-standing local telephone company that had dial-up and DSL Internet services, but struggled with their network infrastructure and occasional DDoS (Distributed Denial of Service) attacks. I remember watching the administrator as he used a "port-sniffing" software tool to find commonly-exploited ports that were open on each network node (this would include basic terminals, workstations, servers, and mainframes). The port-sniffing software could be defined within Tavani's classification of hacking tools used by a typical cybercriminal, but was used with the intention of strengthening the security and integrity of the network (Tavani, 203).
The administrator then took action at the server level to adjust permissions and TCP/UDP protocols. On a few occasions of inbound DDoS attacks, he would counter-attack the originating IP addresses with what I assumed were similar tactics. Although I did not know what actions were actually performed.
Ethically speaking, it is unknown if the counter-attacks were soundly justified. First off, our administrator was not a Certified Ethical Hacker (CEH) or at least he wasn't to my knowledge. Second, as Tavani's example states "if hacking is illegal, then it would seem that hacking back would be no less illegal" (Tavani, 205).
I believe if the administrator acted only on securing the ports with the possibly-risque port-sniffing software, he could have maintained his ethical integrity. The counter-hacking was definitely counter-intuitive from my standpoint.
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment