Protecting the Investigators

An article in the Harvard Journal of Law & Technology from the summer of 1997 issue (http://jol t.law.harvard.edu/articles/10hjolt465.html) warns that police may face attacks against their information systems in the 21st century. As criminals become more sophisticated about information technology, the concern loses any hint of science fiction. Attacking the investigators may become a viable […]

Published: Oct 16, 2000
Updated: Apr 15, 2021
3 minute read
Protecting the Investigators
Enterprise Networking Planet のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る


An article in the Harvard Journal of Law & Technology from the summer of 1997 issue (http://jol t.law.harvard.edu/articles/10hjolt465.html) warns that police may face attacks against their information systems in the 21st century. As criminals become more sophisticated about information technology, the concern loses any hint of science fiction. Attacking the investigators may become a viable option, especially when one doesn’t even have to visit the police station.

In fact not only police face vulnerability. Private sector investigators working in the IT industry could also encounter technology-based attacks. Areas of mutual exposure include:

  1. Database systems containing criminal history and intelligence files.
  2. Communication systems including e-mail and cellular telephone transmissions.
  3. 911 systems in the public sector; corporate emergency alert systems for the private sector.
  4. Radio transmissions.
  5. The personal infosphere (credit files, home telephone devices, public record databases, and so on) of investigators and police officers.
  6. Security systems such as CCTV, alarms, access control devices, and auditing programs.
"Information is a two-edged sword. The mere collection of facts for a
good purpose doesn’t insure against someone converting the data for a
bad purpose."



In addition, every corporate espionage trick such as wiretapping, dumpster diving, and eavesdropping on computer traffic will serve criminals in gathering intelligence. Information is a two-edged sword. The mere collection of facts for a good purpose doesn’t insure against someone converting the data for a bad purpose. Investigators need to protect their information resources and the data streams that feed those resources.

Mare D. Goodman’s article, "Why the Police Don’t Care About Computer Crime" suggests that law enforcement, with the exception of some high-tech crime units, does not understand the threat of computer crime. He feels that police largely focus on traditional law enforcement operations. What is becoming clear, though, is even conventional police operations could face serious disruptions from computer savvy criminals. The same goes for corporate security departments.

While considerable literature exists on investigative techniques regarding crime in general, including computer crime, discussion on protecting the investigative effort itself is at the early stages. We can’t always focus just on the benefits of information technology. Understanding the pitfalls may be key to survival.

Advertisement

What would happen to criminal justice if the AFIS (Automated Fingerprint Identification System) network was attacked and seriously degraded? What would be the consequences for your company if your business intelligence database were compromised?

"Sound strategic thinking is necessary to protect investigative and
security resources. A mere fortress mentality, however, may fail."



Sound strategic thinking is necessary to protect investigative and security resources. A mere fortress mentality, however, may fail. In an environment filled with highly motivated and resourceful computer criminals, overconfidence may lead to disaster. So good protective strategy would include:

  1. Adopting risk management techniques. These techniques include risk assessment, resource planning, and contingency planning. Web sites with information on risk management are:
    1. Hall Associates http://www.techriskmgt.com/
    2. Risks, Ltd. http://www.risksltd.com/
    3. Risk Decisions http://www.risk-decisions.com/
    4. ABS Group Inc. http://www.jbfa.com/
    5. AMA Associates http://www.ama-assoc.co.uk/


  2. Develop and use formal analytical tools to identify vulnerabilities and to measure risk. Two common methods are decision trees and root cause analysis. Traditional security surveys usually are just checklists. Formal analysis traces the pathways of critical information flows to uncover vulnerabilities not considered in routine checklists. Two good introductory web sites on these methods are:
    1. Vanguard Software Corporation (http://www.vanguardsw.com/)
    2. "Root Cause Leader" ABS Group Inc. (http://www.jbfa.com/)
  3. Bruce Schneier’s method known as Attack Trees also deserves consideration at http://www.counterpane.com.
  4. Maintain good intelligence on emerging threats. In an article on http://www.fcw.com "Report Slams DOE counterintelligence" (dated 6/28/2000), the real need for current, actionable intelligence arises from today’s headlines. (See also my article on Intelligence Gathering from Security Portal January 25, 2000.)
  5. And, investigators need to strive to keep their own personal information profile low. Avoid releasing in-depth personal information in the press or on Web sites.

SecurityPortal is the world

’

s foremost on-line resource and services provider for companies and individuals concerned about protecting their information systems and networks.

http://www.SecurityPortal.com

The Focal Point for Security on the Net

™


Enterprise Networking Planet Logo

Enterprise Networking Planet aims to educate and assist IT administrators in building strong network infrastructures for their enterprise companies. Enterprise Networking Planet contributors write about relevant and useful topics on the cutting edge of enterprise networking based on years of personal experience in the field.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。