AIRLINK 196.20 Increased By ▲ 4.36 (2.27%)
BOP 10.16 Increased By ▲ 0.29 (2.94%)
CNERGY 7.92 Increased By ▲ 0.25 (3.26%)
FCCL 38.30 Increased By ▲ 0.44 (1.16%)
FFL 15.90 Increased By ▲ 0.14 (0.89%)
FLYNG 25.44 Increased By ▲ 0.13 (0.51%)
HUBC 130.65 Increased By ▲ 0.48 (0.37%)
HUMNL 13.79 Increased By ▲ 0.20 (1.47%)
KEL 4.66 Decreased By ▼ -0.01 (-0.21%)
KOSM 6.38 Increased By ▲ 0.17 (2.74%)
MLCF 44.95 Increased By ▲ 0.66 (1.49%)
OGDC 209.79 Increased By ▲ 2.92 (1.41%)
PACE 6.68 Increased By ▲ 0.12 (1.83%)
PAEL 41.05 Increased By ▲ 0.50 (1.23%)
PIAHCLA 17.75 Increased By ▲ 0.16 (0.91%)
PIBTL 8.13 Increased By ▲ 0.06 (0.74%)
POWER 9.38 Increased By ▲ 0.14 (1.52%)
PPL 180.99 Increased By ▲ 2.43 (1.36%)
PRL 40.00 Increased By ▲ 0.92 (2.35%)
PTC 24.41 Increased By ▲ 0.27 (1.12%)
SEARL 111.75 Increased By ▲ 3.90 (3.62%)
SILK 0.99 Increased By ▲ 0.02 (2.06%)
SSGC 38.17 Decreased By ▼ -0.94 (-2.4%)
SYM 19.22 Increased By ▲ 0.10 (0.52%)
TELE 8.75 Increased By ▲ 0.15 (1.74%)
TPLP 12.10 Decreased By ▼ -0.27 (-2.18%)
TRG 66.00 Decreased By ▼ -0.01 (-0.02%)
WAVESAPP 12.29 Decreased By ▼ -0.49 (-3.83%)
WTL 1.69 Decreased By ▼ -0.01 (-0.59%)
YOUW 3.99 Increased By ▲ 0.04 (1.01%)
BR100 12,090 Increased By 159.6 (1.34%)
BR30 35,982 Increased By 322.6 (0.9%)
KSE100 114,866 Increased By 1659.2 (1.47%)
KSE30 36,099 Increased By 534 (1.5%)

Cyber Crimes are on an increase with corresponding expansion of Internet, the fastest growing phenomena in the world. Being a global village, today absence of strong legislation and punitive action encourages the cyber criminals globally, resulting in bad reputation on international level.
Security is like making efforts to plugging a dam. Once one hole is fixed, it is often difficult to know where the next leak will appear.
With the exponential growth in computer related crime, effective information security measures are of the prime importance to every enterprise.
Computer crime encompasses a range of activities that may be split into three categories: crimes against machines, such as hacking, traditional crimes such as fraud, and conventional crimes in which a computer is used incidentally, as in the production of counterfeits.
The trend now is towards crimes via computer in online shopping fraud, identity fraud and other ways of gaining financial advantage.
Fraudulent e-commerce transactions tend to be centred on certain countries. A recent survey showed that 09 percent of fraudulent transactions were from Pakistan. Three percent of purchases from Yugoslavia and 10 percent from Romania were fraudulent compared with 1.7 percent from the USA.
Ammar Jaffri, Project Director National Response Centre for Cyber Crime (NR3c), Federal Investigation Agency (FIA) has defined the current trends of Cyber Crimes in the country, which include, DOS and DDOS attacks, phishing a real threat, threatening e-mails, defacement of web-sites, hacking attempts on commercial databases and carding business etc.
Banking industry is still a favourite target, as success has high rewards but chances of being caught are limited due to absence of exact electronic crime laws. Financial institutions being the prime targets of Cyber criminals, worstly affecting the technological progress in the area of e -commerce which in turn slow down the economic progress of a country.
The (NR3c) was established in April 2002 within FIA under Ministry of Interior to establish working co-ordination between different government organisations including law enforcement agencies.
NR3C was setup with the objectives to serve as 'Reporting Centre' for all types of cyber crimes in the country, maintain type wise log, liaison with all national and international organisations to handle the issue of cross border jurisdiction for efficiently handling the cases against the Cyber Criminals, provide necessary technical support, carry out regular R&D activities and providing timely information to critical infrastructure owners and government departments about threats, actual attacks and recovery techniques.
NR3C - (www.nr3c.gov.pk) also provides law enforcement and other Federal and Local government employees training in issues pertaining to Cyber Crimes. Presently, it is offering courses in Cyber Security Foundation, Cyber Security Working, Cyber Security Advance and Cyber Security for Executives/Legislative issues in Cyber Security.
NR3C has its special focus on banking industry, but still the e-banking and e-commerce frauds go on because of the non-existence of legislation for e-banking, EFT, customer and database protection.
There are no provisions in PPC and CrPC pertaining to cyber crimes, nor there has been any conviction by the court of law to any cyber criminal.
The objectives of the Cyber Crime Laws should be to deter actions directed against confidentiality, integrity, availability of computer systems networks, computer data misuse of such systems, networks and data.
These criminal offences may be combated by facilitating detection, investigation, search and seizure and prosecution of such criminal offences.
The most common financial crimes include credit card, debit card, ATM card frauds and switch account balancing. Today most of the banks authenticate their customers by User ID and password over a secured connection (SSL) between customer workstation and Bank's server. But! How secure is this transaction?
Chairman Financial Working Group AFACT, Arif Siddiqui in a presentation recently pointed out the reasons, why threats and risks against e-banking could not be controlled in the country. According to him:
-- Criminal justice system in Pakistan is not prepared to handle high-tech crime.
-- Shortage of trained investigators and analysts.
-- Too much data.
-- No case has been registered under ED ordinance 2002.
-- Other countries may have their own cyber laws.
- Issues relating to time (in case of DOS, if a site is not equipped at that time, nothing may be noticed at all).
-- The use of encryption is becoming common.
-- Most of the crimes were committed by students.
-- And the most important, it easy to commit and its fun.
Credit card generators had been widely used in past and are still being used. These are programs that generate false credit cards numbers that still pass through most checks. Credit card generators are especially good to use when ordering stuff online. These are easily available on various websites and can be downloaded even for free. A couple of largely used and effective generators are 'Credit Card Wizard v1.1' and 'Fraud3r', which even generates a phony address too.
Since prevention is better than cure, the organisations, especially banks, financial institutions and concerns offering online trade, as suggested by head of AFACT, should establish high-profile awareness program and be well aware of the risks. Risk starts once the connection to the Internet is established and the security planning must be initiated the very moment, corporate firewalls are largely recommended in this regard.
The organisations should educate their staff as well as customers, observe strict control before live implementations of the security programs, thoroughly review third party software and use multi-vendor security products.
In order to effectively deal with the threat, lowers forum should be established to help banks MITT and customers. Banks should introduce customers' awareness plan as part of product launch and establish key risk assessment process before launch of any product.
Standard guideline should be prepared for Internet banking, ATM switch and debit card switch while banks should conduct risk assessment on the basis of the guide line.
Standard security guideline should be prepared and implemented with proper control.

Copyright Business Recorder, 2005

Comments

Comments are closed.