The Experts below are selected from a list of 36 Experts worldwide ranked by ideXlab platform

Michael Polgar - One of the best experts on this subject based on the ideXlab platform.

  • social network analysis of a Criminal Hacker community
    Journal of Computer Information Systems, 2015
    Co-Authors: Yong Lu, Michael Polgar
    Abstract:

    Computer crime Hackers have been identified as a primary threat to computer systems, users, and organizations. Much extant research on Hackers is conducted from a technical perspective and at an individual level of analysis. This research empirically examines the social organization of a Hacker community by analyzing one network called Shadowcrew. The social network structure of this infamous Hacker group is established using social networking methods for text mining and network analysis. Analysis of relationships among Hackers shows a decentralized network structure. Leaders are identified using four actor centrality measures (degree, betweenness, closeness, and eigenvector) and found to be more involved in thirteen smaller sub-groups. Based on our social network analysis, Shadowcrew exhibits the characteristics of deviant team organization structure.

Yong Lu - One of the best experts on this subject based on the ideXlab platform.

  • social network analysis of a Criminal Hacker community
    Journal of Computer Information Systems, 2015
    Co-Authors: Yong Lu, Michael Polgar
    Abstract:

    Computer crime Hackers have been identified as a primary threat to computer systems, users, and organizations. Much extant research on Hackers is conducted from a technical perspective and at an individual level of analysis. This research empirically examines the social organization of a Hacker community by analyzing one network called Shadowcrew. The social network structure of this infamous Hacker group is established using social networking methods for text mining and network analysis. Analysis of relationships among Hackers shows a decentralized network structure. Leaders are identified using four actor centrality measures (degree, betweenness, closeness, and eigenvector) and found to be more involved in thirteen smaller sub-groups. Based on our social network analysis, Shadowcrew exhibits the characteristics of deviant team organization structure.

  • the social organization of a Criminal Hacker network a case study
    International Journal of Information Security and Privacy, 2009
    Co-Authors: Yong Lu
    Abstract:

    Financial fraud and identity theft conducted by Criminal Hackers have become the top source of the greatest financial losses for organizations. Even though Hacker groups are complex socio-technical systems, much extant research on Hackers is conducted at the individual level of analysis. This research proposes a research model composed of five dimensions and their relations in order to study Hacker’s social organization in the whole socio-technical context. Based on this model, the researcher applies network analysis methods to disclose the structure and patterns of a significant and complex Hacker group, Shadow crew. Network analysis tools, such as Automap and ORA, are applied for data processing and data analysis. Three network measures: degree centrality, cognitive demand, and eigenvector centrality, are utilized to determine the critical leaders. Out-degree centrality is employed to analyze the relations among the five dimensions in the research model.

Ed Skoudis - One of the best experts on this subject based on the ideXlab platform.

  • Hiring Ex-Criminal Hackers
    2020
    Co-Authors: Ed Skoudis
    Abstract:

    Suppose someone applies for a system administrator job, or, better yet, an open slot on your computer security team. The applicant is eminently qualified for the position, having wizard-like skills on the exact operating systems deployed throughout your organization. You need his skills, big time. However, the candidate poses a bit of a problem. This otherwise-stellar applicant has a bit of a spotty record with the Criminal justice system. By spotty, I mean that your potential hire was found guilty of hacking a Fortune 500 company and stealing some sensitive data. He did the crime, but he has also done the time. Should you still consider such a person for a position on your security team? Or, should you let bygones be bygones and just move forward? Some companies shy away from such individuals immediately. Others take a “Don’t ask... Don’t tell” stance. Still others actively embrace such people for their great skills. If your organization hires an ex-Criminal Hacker, would you be legally responsible if he damages a customer or supplier’s computer systems? You could be found guilty of negligent hiring, whereby an employer is liable for taking a hiring risk and exposing customers, suppliers, and other employees to it. This chapter analyzes the issues associated with hiring ex-Criminal Hackers so you can think through your own organization’s approach to this issue. The chapter looks at both sides of the problem, and then the author states his opinion on the matter, for what it is worth. While the author attempts to evenhandedly argue both sides of this topic, keep in mind that the author does not necessarily agree with all of these arguments. Instead, the concepts raised are those most often advanced by proponents on either side of this divide. The discussion in this chapter does not refer to non-Criminal Hackers. Remember, as used in the computer underground, the term “Hacker” does not by itself imply that the person has done wrong. People who have hacking skills may have acquired them completely lawfully, by studying computer security or conducting legitimate penetration testing against consenting targets, such as their employers or customers. There are many of these “white-hat” Hackers in the information technology business. The author himself falls into this whitehat category, as do many others, and would like to think we are very hirable without concerns. This chapter analyzes the question of whether to hire Hackers who have an actual prior Criminal conviction, or are known to have been involved in Criminal activity but may have not been prosecuted (yet). We refer to them as ex-Criminal Hackers because they were either busted and did some time in jail or are known to have committed crimes. In other words, we are talking about actual former black hats or deeply gray hats. AU1997_Frame_Ch075 Page 907 Monday, November 17, 2003 10:10 AM

Ed Stroz - One of the best experts on this subject based on the ideXlab platform.

  • Cyber Adversary Characterization: Auditing the Hacker Mind
    2004
    Co-Authors: Tom Parker, Marcus Sachs, Eric D. Shaw, Ed Stroz
    Abstract:

    The wonders and advantages of modern age electronics and the World Wide Web have also, unfortunately, ushered in a new age of terrorism. The growing connectivity among secure and insecure networks has created new opportunities for unauthorized intrusions into sensitive or proprietary computer systems. Some of these vulnerabilities are waiting to be exploited, while numerous others already have. Everyday that a vulnerability or threat goes unchecked greatly increases an attack and the damage it can cause. Who knows what the prospects for a cascade of failures across US infrastructures could lead to. What type of group or individual would exploit this vulnerability, and why would they do it? "Inside the Mind of a Criminal Hacker" sets the stage and cast of characters for examples and scenarios such as this, providing the security specialist a window into the enemy's mind - necessary in order to develop a well configured defense. Written by leading security and counter-terrorism experts, whose experience include first-hand exposure in working with government branches and agencies (such as the FBI, US Army, Department of Homeland Security), this book sets a standard for the fight against the cyber-terrorist. Proving, that at the heart of the very best defense is knowing and understanding your enemy. This book will demonstrate the motives and motivations of Criminal Hackers through profiling attackers at post attack and forensic levels. This book is essential to those who need to truly 'know thy enemy' in order to prepare the best defense. The breadth of material in "Inside the Criminal Mind" will surprise every security specialist and cyber-terrorist buff of how much they do and (more importantly) don't know about the types of adversaries they stand to face.

S. S. Grishunov - One of the best experts on this subject based on the ideXlab platform.

  • Analysis of cyber attacks on banking systems
    Issues of radio electronics, 2019
    Co-Authors: V. V. Dragan, Yu. S. Belov, S. S. Grishunov
    Abstract:

    The article discusses the main methods by which cyberCriminals carry out attacks on financial organizations using ATM vulnerabilities (network attacks, blackbox attacks, exiting the user’s restriction of computer use by only one application (kiosk mode) and connecting to the hard drive). The main vulnerabilities of banking systems are analyzed, the results of Positive Technologies research on the percentage of ATMs exposed to the above vulnerabilities are described, and recommendations are made to increase the level of security of information systems of financial organizations. Various, including phishing attacks on the SWIFT (Society for Worldwide Interbank Financial Telecommunications) and AWP CBD (automated workplace of a Bank of Russia client) systems of the most dangerous Criminal Hacker groups: Cobalt, MoneyTaker and Silence, are considered.