Understanding Cybercrime and Cybersecurity Law: A Student's Guide
In our increasingly digital world, information and communication technologies (ICT) are indispensable, but their widespread use also brings a significant challenge: cybercrime. This comprehensive guide will break down the essential aspects of cybercrime and cybersecurity law, providing a clear overview for students. We'll explore definitions, classifications, common cyberattacks, and the legal frameworks designed to combat these digital threats, offering valuable insights for anyone studying the field.
What is Cybercrime? Definitions and Core Concepts
The term cybercrime refers to criminal activities where computers or information and communication technologies (ICT) are either the target of an attack or the means by which a crime is committed. While previously known as "computer crime" in the 1990s, focusing solely on personal computers is now too simplistic. Many modern devices with microprocessors, though not called PCs, can also be targets or tools for crime.
There isn't one universal, generally accepted definition of cybercrime due to the dynamic growth of ICT. However, several definitions help us understand its scope:
- Council of Europe (2000): "An offence against the integrity, availability or secrecy of computer systems or an offence in the traditional sense using modern information and communication technologies."
- EU Council Framework Decision 2002/584/JHA: Refers to "computer-related crime" as conduct directed against a computer or where the computer is a means of committing a crime.
- Cybersecurity Glossary: "Criminal activity in which a computer appears in some way as an aggregate of hardware and software (including data), or only some of its components may appear, or sometimes a larger number of computers either standalone or interconnected into a computer network appear, and this either as the object of interest of this criminal activity (with the exception of such criminal activity whose objects are the described devices considered as immovable property) or as the environment (object) or as the instrument of criminal activity."
It's crucial to understand that not every undesirable action involving ICT is a cybercrime. For example, using a computer as a blunt weapon in a physical assault, or stealing a truck full of computer components, is not cybercrime in the true sense. Cybercrime specifically involves the use or misuse of ICT within an information, system, program, or communication environment – essentially, in cyberspace.
Classifying Cybercrime: Types and Categories
Cybercrime can be classified in various ways, helping us understand its diverse nature. Here are some prominent classifications:
1. According to the Convention on Cybercrime and Additional Protocol:
- Offences against the confidentiality, integrity, and availability of computer data and systems.
- Computer-related offences.
- Content-related offences (e.g., child pornography).
- Offences related to infringements of copyright and related rights.
- Additional Protocol includes: dissemination of racist and xenophobic material, racist and xenophobic motivated threat/insult, and denial/justification of genocide or crimes against humanity.
2. According to the Council of Europe's Committee of Experts (2000):
- Position of the computer: Target of the attack or means (tool) of the attack.
- Type of act: Traditional infringements (e.g., counterfeiting) or new infringements (e.g., phishing, DDoS).
3. According to eEurope+:
- Crimes that violate privacy (e.g., illegal data collection).
- Crimes related to computer content (e.g., child pornography, racism).
- Economic crimes (e.g., unauthorized access, hacking, fraud).
- Crimes related to intellectual property.
4. According to Criminology (Porada and Konrád):
- Unauthorized tampering with input data.
- Unauthorized changes to stored data.
- Unauthorized instructions for computer operations.
- Unauthorized intrusion into computers, systems, and databases.
- Attack of another's computer, software, and files/data.
5. According to Europol's European Cyber Crime Centre (EC3):
Europol focuses on three main areas:
- FP TERMINAL: Payment fraud (online fraud).
- FP Cyborg: High-Tech Crimes (attacks on critical infrastructure and information systems like malware, ransomware, hacking, phishing, identity theft).
- FP Twins: Child Sexual Exploitation (investigation support).
6. Classification by "Relationship" to the Digital Environment:
- Narrow concept ("pure" cybercrime): Cyberattacks taking place entirely in cyberspace, where the goal and tool are computer systems or data (e.g., hacking, DoS/DDoS attacks, attacks on critical infrastructure).
- Broad concept: The transfer of "old" or "ordinary" criminal conduct into the new digital environment (e.g., fraud conducted online).
Common Cyberattacks and Cybersecurity Concepts
Understanding common cyberattacks is vital for cybersecurity. Here are some examples from the study materials:
- Social Engineering: Manipulating people to divulge confidential information.
- Botnet: A network of compromised computers controlled remotely.
- Malware: Malicious software (e.g., viruses, worms, Trojans).
- Ransomware: Software that encrypts data and demands a ransom for its release.
- Spam: Unsolicited bulk electronic messages.
- Scam (e.g., 419 Scam): Fraudulent schemes designed to trick victims into sending money.
- Hoax: A deception, often spread online, designed to trick people.
- Fraudulent Offers: Deceptive proposals for goods, services, or investments.
- Phishing: Attempting to obtain sensitive information (e.g., usernames, passwords) by masquerading as a trustworthy entity in electronic communication.
- Pharming: Redirecting users from legitimate websites to fraudulent ones without their knowledge.
- Spear Phishing: Targeted phishing attacks.
- Vishing: Phishing conducted over the phone (voice phishing).
- Smishing: Phishing conducted via SMS messages.
- Business Email Compromise (BEC): Email fraud targeting businesses to trick employees into transferring funds or sensitive data.
- Fraudulent Websites/Companies: Websites designed to deceive users.
- Hacking: Unauthorized access to computer systems.
- Cracking: Breaking into computer systems, often with malicious intent.
- Internet (Computer) Piracy: Copyright infringement involving intellectual property in cyberspace.
- Sniffing: Intercepting data packets over a network.
- DoS/DDoS Attacks: Denial-of-Service (Distributed Denial-of-Service) attacks that overload systems to make them unavailable.
- Dissemination of Defective Content: Spreading harmful or illegal content.
- Cyberbullying: Harassment or intimidation using electronic communication.
- Cybergrooming: Building a relationship with a child online for exploitative purposes.
- Sexting: Sending sexually explicit messages or images, especially between minors.
- Cyberstalking: Using electronic means to harass or stalk an individual.
- Identity Theft: Illegally obtaining and using another person's personal identifying information.
Key Cybersecurity Elements: The success of a cyberattack often lies in breaching people, processes, and technologies. Effective cybersecurity requires applying these elements throughout their lifecycle, including prevention, detection, and response.
- A cybersecurity event is an occurrence that may cause a breach in information security. It's a threat, but without immediate negative consequences.
- A cybersecurity incident is a real breach in security caused by a cybersecurity event, having a negative impact.
- Computer data is any expression of facts, information, or concepts suitable for computer processing.
- Information is data processed into a useful form for a recipient.
Legal Frameworks and Cybersecurity Law
Cyberspace, though virtual, has real-world implications, necessitating legal regulation. The challenge lies in its borderless nature. While some existing laws can be adapted, new legislation is often required to address novel cybercrimes.
International and EU/EC Documents:
Key international efforts to harmonize cybersecurity law and combat cybercrime include:
- Council of Europe Convention No. 185 on Cybercrime (Budapest Convention, 2001): The most important legal document, obliging signatory parties to criminalize defined cybercrimes and establish frameworks for international cooperation. It defines four basic groups of offenses against data and systems, computer-related offenses, content-related offenses, and copyright infringement.
- Council of Europe Additional Protocol No. 189 to the Convention on Cybercrime (2003): Extends the Convention to cover offenses related to racist and xenophobic material disseminated through computer systems.
- EU Directives and Decisions: A range of EU documents aim to harmonize legislation among Member States, covering areas like data protection (e.g., GDPR), electronic communications, combating child pornography, attacks on information systems, and establishing agencies like ENISA and Europol.
Czech Republic Legal Norms:
The Czech Republic's legal framework includes various acts addressing cybercrime and cybersecurity, such as:
- Act No. 40/2009 Sb., Criminal Code
- Act No. 181/2014 Sb., on Cybersecurity
- Act No. 121/2000 Sb., Copyright Act
- Act No. 110/2019 Sb., on the Processing of Personal Data (implementing GDPR)
Substantive Aspects of Cybercrime in Czech Criminal Law:
The Criminal Code (Act No. 40/2009 Sb.) includes specific objective elements for cybercrimes. These can be categorized as:
a) Crimes where ICT means are the subject of protection (the target of a cyberattack):
- Breach of Secrecy of Correspondence (Section 182)
- Unauthorised Access to Computer Systems and Information Media (Section 230)
- Damage to Computer Systems and Information Media Records (Section 232)
- Infringement of Copyright, Rights Related to Copyright and Rights to Databases (Section 270)
- Terrorist Attack (Section 311) using ICT as a target.
b) Crimes where ICT means are used as a tool to commit a criminal offence:
- Illicit Handling of Personal Data (Section 180)
- Defamation (Section 184) via digital means.
- Production and Handling of Child Pornography (Section 192) using ICT.
- Fraud (Section 209) committed online.
- Dangerous Threatening (Section 353) or Dangerous Pursuing (Section 354) via cyber means.
- Incitement of Hatred towards a Group of People (Section 356) online.
Some offenses can fall into both categories, as they protect ICT and involve their misuse. The evolution of laws attempts to keep pace with the dynamic nature of cyber threats, ensuring that cyberspace does not become a lawless environment for perpetrators.
Cyberspace: Layers and Concepts
Cyberspace is often defined metaphorically as a virtual reality, effectively boundless, yet completely dependent on real-world material foundations (hardware, cables, networks). It's a digital environment enabling information creation, processing, and exchange.
According to the Cyberspace Operations: Concept Capability Plan 2016–2028, cyberspace consists of three layers:
- Physical Layer: Includes the geographic location of network elements and physical network components (cables, routers, devices).
- Logical Layer: Consists of logical connections between network nodes, implemented via communication protocols.
- Social Layer: Comprises "cyber personality" (digital identification like email, IP address) and actual human users connected to the network. An individual can have multiple cyber personalities, and a single cyber personality might be shared by multiple real people.
Cyberspace can also be divided by data availability and traceability for the average user:
- Surface Web: Services and data available via standard internet search engines.
- Deep Web: Services and data available only within specific networks and devices, not indexed by standard search engines.
- Dark Web: Intentionally hidden services and data accessible only using special tools (often referred to as D4rkN3ts – Darknets).
These concepts highlight the complexity of the digital realm and the challenges in regulating it. As users, our information literacy and awareness of potential threats are critical to cybersecurity. Education about these risks should be an integral part of learning in our digital society.
FAQ: Your Questions on Cybercrime and Cybersecurity Law Answered
What is the primary difference between "cybercrime" and a "cyberattack"?
While related, a cyberattack is any illegal conduct by an attacker in cyberspace directed against the interests of another person, potentially causing disruption. It can be completed, in preparation, or at a trial stage, and doesn't always constitute a crime. Cybercrime, however, specifically refers to criminal acts that fulfill the objective elements of a crime under criminal law, where ICT is either the tool or the target, and the activity occurs in cyberspace. So, all cybercrimes are cyberattacks, but not all cyberattacks are crimes (some might be administrative or civil torts, or merely immoral behavior).
Why is there no single, universally accepted definition of cybercrime?
The lack of a universal definition stems from the extremely rapid and dynamic growth of information and communication technologies (ICT). As new technologies emerge and evolve, so do the possibilities for their misuse, leading to constantly changing forms of criminal activity. This makes it difficult to create a static definition that fully encompasses the scope and depth of cybercrime, as legislators and experts are continually adapting to new threats.
How does the concept of "cyberspace" influence cybersecurity law?
Cyberspace significantly influences cybersecurity law due to its unique characteristics: decentralization, globality, openness, and the delocalization of legal entities. Traditional laws often rely on physical borders and jurisdictions, which don't directly apply to the virtual realm. This creates challenges in enforcing laws, identifying perpetrators (who often feel anonymous), and harmonizing legislation across different countries. Cybersecurity law must adapt to these challenges by focusing on international cooperation and flexible legal instruments that can address acts committed virtually across borders.
Flashcards
Tap to flip · Swipe to navigate