• Tidak ada hasil yang ditemukan

CyberSecurity Malaysia | An Agency Under MOSTI

N/A
N/A
Protected

Academic year: 2017

Membagikan "CyberSecurity Malaysia | An Agency Under MOSTI"

Copied!
11
0
0

Teks penuh

(1)

BRIDGING BARRIERS:

LEGAL

AND

TECHNICAL

OF

CYBERCRIME CASES

Bridging Legislation &

Technical – A Bridge Too Far?

Harme
Mohamed
 Malaysian
Communications
and
 Multimedia
Commission


(2)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

Penetration Rates

42.6% 

Fixed 

(per 100  households) 

Television 

Sabah & Sarawak : 88.4% 

60.1% 

Sabah & Sarawak : 88.1%  Peninsular: 94.9% 

121.0% 

Celullar 

(3)

Penal Code

Criminal Procedure Code • Sedition Act 1948

Evidence Act 1950

Dangerous Drugs Act 1952 • Copyright Act 1987

Banking and Financial Institutions Act 1989 • Extradition Act 1992

Computer Crimes Act 1997

Communications and Multimedia Act 1998

Mutual Assistance in Criminal Matters Act 2002

(4)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

(5)

Crimes performed in and with computers, computer networks and increasing mobile communications (smart phones)

Computers, and data stored in them are:

Targets (hacking, DDoS-attacks, defacements, etc.)

Tools (host and create undesirable content, fraud,

forgery, originate attacks, etc.)

Device that contains evidence of crimes (drug trades,

terrorism)

International, not bound by territorial borders

(6)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

Investigation and analysis of hardcore

cybercrimes, such as botnets, hacking and malwares

Investigation and analysis of the role and use of

computers in the combat against crime in general, such as frauds and undesirable contents

No single crime scene to process and combination

of attacks to be analyzed

Changing requirements of an Investigating Officer

Requires new methods of surveillance and

investigations

(7)

Sometimes still need tried and tested methods

The discipline is very much the same, statement

taking etc. but need to know what to ask etc. (criminal conduct and exploited technology)

Importance of analysis & forensics capabilities

Usage of appropriate tools which are available

(8)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

(9)

Balance between the privacy of citizens and effectiveness of law enforcement

Preventive measure – put in technological

infrastructure to combat cybercrime

Classification of techniques (social engineering,

malware, network breaches) – are the current laws able to identify and deal with these techniques?

International cooperation

Anti-forensic tools and anonymization technologies

(10)

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

Endorsed by: Organizer:

People First, Performance Now

Ministry od Science, Technology and Innovation

(11)

Existing laws need to be reviewed to keep abreast of new technologies but not to stifle innovation of new technologies and services

Need clear process and procedures and

empowerment to law enforcement agencies

Need to encourage home-grown technologies to

assist investigations and evidence gathering

Referensi

Dokumen terkait

The Creative Industry (including the Music Industry) form complex business networks in content-driven sectors and contribute significantly to the economic, social

Once installed, the Trojan can collect usernames and passwords of email accounts, collect system information, upload documents and data to a remote computer, downloading of

Developments in Information and Communications Technology (ICT) and growing dependencies on information systems have made it more difficult to protect and defend confidential

With our growing dependence on information networks and the rapid changes in network technology and threats, it is critical for organisations to adopt the best security practices

The program will pass the user inputs (obtained from the URL or HTML form) and states (from cookies, hidden fields and environment variables) to the application to be processed and

• Monitor and control physical access – Monitor and control physical access to the storage ecosystem – data center facilities, active and passive network. infrastructure, and

The DoS and DDoS attacks in combination with malicious codes implantations, are easily launched but difficult to completely stop. With the nature of TCP/IP and programming

In developing sound strategic legal risk management policies at the enterprise level, a good starting point is to develop an overall framework and to start thinking of the methods