Thwarting Hacks by Thinking Like the Humans Behind Them

If we understood the humans behind hacking incidents – and their intent – could we stop them?
Michigan State University
5-Feb-2020 10:35 AM EST, by Michigan State University

Newswise — EAST LANSING, Mich. – If we understood the humans behind hacking incidents – and their intent – could we stop them? Research from Michigan State University reveals the importance of factoring in a hacker’s motive for predicting, identifying and preventing cyberattacks.

Most people tend to focus on how to minimize the risk of a hack, from antivirus software to regularly updating computer software. While these defenses against attacks are helpful, study author and MSU criminal justice professor Thomas Holt believes it’s just as important to have a strong offense.

“The more we start thinking like an attacker, the more we can better secure systems and move away from this perspective that everything can be solved through a piece of software,” Holt said. “Any good attacker, no matter what their motivation is, can get around a security tool.”

Holt found that the targeting practices of a specific kind of hack called a web defacement – where the attacker changes the original content of a webpage to images or content of their choosing – vary based on the self-identified motivation of the attacker. 

“Their decision-making process can be modeled, and it can help us to understand how to better secure systems and think like a hacker,” Holt said. 

While considered a simple form of hacking, web defacements are a timely concern, Holt said.

“Earlier in January, hackers claiming ties to Iran defaced a U.S. government website. The page for the Federal Depository Library Program was replaced with pro-Iran messaging and an image of a bloodied President Donald Trump,” Holt said. “The defacement demonstrates hackers are motivated by more than money, and that they may engage in future cyberattacks.”

Holt collaborated with Rutger Leukfeldt and Steve Van De Weijer from the Netherlands Institute for the Study of Crime and Law Enforcement to analyze more than 100,000 web defacements against websites from January 2011 to April 2017. The researchers wanted to see if the targets of defacements were associated with attacker motivation, and how they actually performed the hack as well. 

The findings revealed that web defacements – one of the more public forms of hacking – can be inspired by a variety of motives. The ways a defacement can be performed also vary, though defacers often attempt to compromise as many sites as possible as quickly as possible. Targeting thousands of web pages simultaneously demonstrates more skill as a hacker than if only one is targeted, unless it is a high level, recognizable site.

“If you can demonstrate to others your capacity, or expertise, that has value,” Holt said. “So people will begin to realize and connect the handle or online nickname you use with some type of skill. It can net you clout within the hacker subculture. When you use more sophisticated methods or do things in a novel way, that lends an air of credibility to your identity.” 

Due to the overall threat they pose, hackers engaging in data breaches or using ransomware garner more attention than those acting out of subcultural or ideological motivations. Still, examining all types of hacks – and the hackers behind them – will help researchers predict and defend against cyberattacks.

“We can’t just say we’re only concerned about the economic stuff,” Holt said. “We have to be concerned about political, ideological and subcultural at the same time.”

(Note for media: Please include a link to the original paper in online coverage: https://journals.sagepub.com/eprint/JJJPYJUAWRGTWBKQ7NBC/full)

 

###

 

Michigan State University has been working to advance the common good in uncommon ways for 160 years. One of the top research universities in the world, MSU focuses its vast resources on creating solutions to some of the world’s most pressing challenges, while providing life-changing opportunities to a diverse and inclusive academic community through more than 200 programs of study in 17 degree-granting colleges.

 

For MSU news on the Web, go to MSUToday. Follow MSU News on Twitter at twitter.com/MSUnews.

SEE ORIGINAL STUDY

Filters close

Showing results

110 of 5699
Newswise: 250647_web.jpg
Released: 4-Dec-2020 4:05 PM EST
For nationalistic regimes, similar COVID-19 policies are the sincerest form of flattery
University of Texas at Arlington

Analysis from a University of Texas at Arlington assistant professor of public policy suggests that nationalistic governments around the globe are more likely to copy other nationalistic governments in responding to the current pandemic.

Released: 4-Dec-2020 10:30 AM EST
BIDMC researchers define immune system’s requirements for protection against COVID-19
Beth Israel Lahey Health

In a new paper in the journal Nature, BIDMC researchers shed light on the role of antibodies and immune cells in protection against SARS-CoV-2, the virus that causes COVID-19, in rhesus macaques.

Released: 4-Dec-2020 9:00 AM EST
Conference on Corporations and Democracy
Stanford Graduate School of Business

Corporations do not vote in elections, but their impact on democratic societies is immense.

Newswise: Pediatric ER Saw Steep Drop in Asthma Visits During Spring COVID-19 Lockdown
1-Dec-2020 8:00 AM EST
Pediatric ER Saw Steep Drop in Asthma Visits During Spring COVID-19 Lockdown
American Thoracic Society (ATS)

A new study published online in the Annals of the American Thoracic Society discusses a steep drop off from prior years in asthma-related emergency department (ED) visits at Boston Children’s Hospital during the spring 2020 COVID-19 surge and lockdown.

Newswise: 250384_web.jpg
Released: 3-Dec-2020 3:05 PM EST
Study finds COVID-19 hindering US academic productivity of faculty with young children
University of Tennessee Health Science Center

The academic productivity of higher education faculty In the United States in the science, technology, engineering, mathematics, and medicine (STEMM) fields with very young children suffered as a result of the stay-at-home orders during the early months of the coronavirus pandemic, according to a new study by researchers at the University of Tennessee Health Science Center, the University of Florida College of Medicine, and the University of Michigan School of Medicine.

Released: 3-Dec-2020 2:50 PM EST
Kidney disease leading risk factor for COVID-related hospitalization
Geisinger Health System

An analysis of Geisinger's electronic health records has revealed chronic kidney disease to be the leading risk factor for hospitalization from COVID-19.

Newswise: 250494_web.jpg
Released: 3-Dec-2020 2:05 PM EST
Why does it matter if most Republican voters still think Biden lost?
University of Rochester

As President-elect Joe Biden and his administrative team officially begin the transition process, only about 20 percent of Republican voters consider him the true winner of the election.

Released: 3-Dec-2020 2:00 PM EST
Testosterone May Contribute to More Severe COVID-19 Disease
American Physiological Society (APS)

New research suggests that levels of the sex hormones estrogen and testosterone could contribute to infection risk and severity of COVID-19.

Newswise: Chicago neighborhoods with barriers to social distancing had higher COVID-19 death rates
Released: 3-Dec-2020 11:55 AM EST
Chicago neighborhoods with barriers to social distancing had higher COVID-19 death rates
University of Illinois at Chicago

New research has found that Chicago neighborhoods with barriers to social distancing, including limited access to broadband internet and low rates of health insurance, had more COVID-19 deaths in spring 2020. The study, led by researchers at the University of Illinois Chicago, is published in the Annals of Epidemiology.


Showing results

110 of 5699

close
1.92593