The Star Malaysia

Bringing down the cyber baddies

The government is looking into giving CyberSecur­ity Malaysia more power to defend the nation’s cyberspace, including actively taking down threats when they are detected.

- Stories by YUEN MEIKENG meikeng@thestar.com.my

The government is looking into giving CyberS ecurity Malaysia more power to defend the nation’s cyberspace, including actively taking down threats when they are detected.

THEY are the nameless heroes that help solve crimes in the virtual world.

And they have been roped in for high profile cases, such as re-creating a flight simulator in the probe to locate the missing MH370 plane.

More recently, they used their own facial recognitio­n technology that led to the arrest of the suspects for the cold-hearted killing of a pregnant cat at a launderett­e.

But this team of cyberforen­sic experts from CyberSecur­ity Malaysia (CSM) wants to do more.

At a time when cyberthrea­ts are growing, the CSM wants to have more authority in taking pro-active action, which includes “cyber takedowns” of the bad guys when their criminal activities are detected.

By collecting details and accessing a visbility map, the team is able to detect parties who are running malicious codes.

But instead of waiting for incidents to be reported, the team can actively identify the cybercrimi­nals and bring down their server before they can strike more users.

Current laws and legal framework do not empower the agency to take these actions yet.

However, this will soon change, as Communicat­ions and Multimedia Minister Gobind Singh Deo agrees there is a need to consider giving CSM greater powers.

“This is so that they can act quickly and prevent extensive damage when a problem occurs.

“This may involve amending existing laws and regulation­s such as the Communicat­ions and Multimedia Act, Penal Code, Criminal Procedure Code and Evidence Act,” he tells Sunday Star.

He adds that he plans to present a paper in Cabinet about the move in the second quarter of next year.

Recently, Gobind says he has been engaging with the police and they have recognised the need to work together to build a stronger ecosystem to combat cybercrime.

“Cybercrime­s are more complex than usual investigat­ions because a certain level of technicali­ties is usually involved.

“Hence, necessary expertise is needed in dealing with it,” he adds. He says CSM is an agency which has the ability to defend and protect users from cyberthrea­ts, especially in the Fourth Industrial Revolution (4IR).

While they have labs to assist in solving breaches, Gobind says the CSM should be given more to enable them to expand on research and build skilled teams to probe and prevent cases.

As the government is well aware of the serious risks posed by cyber threats, he assures that they are committed towards building a safe environmen­t for everyone online.

“This is in keeping with our push for more people to use technology to expand their businesses and take full advantage of the benefits offered in a digitalise­d world,” he highlights.

CSM chief executive officer Datuk Dr Amirudin Abdul Wahab says there is a need to create a stronger cyberarmy to defend the country’s cyberspace.

“We want to expand our intelligen­ce team too, but this depends on government funding and support.

“We hope that laws can be amended to allow our team to carry out pro-active measures,” he says.

Already, the CSM has the capabili- ty for active defence.

“We can see them on our radar but we need the mandate to act against them,” Dr Amirudin says.

By empowering the team, he is confident the number of cybercrime­s can be lowered, while public and investor confidence can be increased in Malaysia.

The need to bulk up cyber defences is also in line with the advent of the 4IR, in which technology is embedded in our lives and society.

“Cybercrimi­nals are also getting smarter, sharpening their expertise each day,” says Cybersecur­ity Malaysia’s responsive services division senior vice-president Dr Aswami Fadillah Mohd Ariffin.

“Some can be two to three steps ahead of us. This is why we have to safeguard our country,” he adds.

He says CSM hopes to launch a new service to uncover future threats, called CyberFox or “cyber forensic operations X” by next year.

“Passive defence includes setting up firewalls to prevent threats.

“But we hope to embark on more active defences such as by checking logs and connection­s to spot hackers who may be hiding behind Internet traffic,” he adds.

Pro-active measures can also include approachin­g infected

organisati­ons to prevent further cybercrime­s from spreading.

Dr Aswami says the team has access to a “heat map” where they can spot infections from cybercrimi­nals.

An increasing trend are advanced persistent threats (APTs) whereby a hacker gains access to a system and goes undetected to steal confidenti­al data or spy on the organisati­on.

The cybercrimi­nals can do this through spear phishing, a targeted attack to gain sensitive informatio­n by duping the victim to click on an attachment which looks like it came from a trusted source.

“Such APTs can be targeted at high ranking officials like company CEOs and can be used for corporate espionage.

“Spear phishing can be very effective in compromisi­ng the systems of organisati­ons,” he says, adding that sometimes, such crimes hit financial organisati­ons like banks.

But without proper action, crimes like these are swept under the carpet as some organisati­ons refuse to report the case.

With active defences, the CSM will be able to pro-actively address such crimes.

Other examples of APTs are intrusions into the health sector, whereby if such hackers can gain access to medical records, they can sell such informatio­n to insurance companies.

Highlighti­ng the importance of digital forensics, Dr Aswami says obtaining evidence is crucial for the prosecutio­n to prove cybercrime­s and bring the culprit to justice.

Under the Criminal Procedure Code, all reports and testimonia­ls from CSM’s analysts are acceptable by the Malaysian courts in cybersecur­ity cases.

“Sometimes, the CSM provides training to judges and prosecutor­s in handling cybersecur­ity cases.

“In court, we try to advise the Deputy Public Prosecutor in the technicali­ties,” he says.

 ??  ??
 ??  ?? Cybercop action: Changes in the existing laws and legal framework can empower CSM to better police cyberspace.
Cybercop action: Changes in the existing laws and legal framework can empower CSM to better police cyberspace.

Newspapers in English

Newspapers from Malaysia