Reporting the crime The investingation

12
ØKOKRIM Reporting the crime The investingation Politiinspektør Berit Børset Solstad Politiets datakrimsenter 20.10.04

description

Reporting the crime The investingation . Politiinspektør Berit Børset Solstad Politiets datakrimsenter 20.10.04. The police data crime center. Opened15. mai 2003 Address: Bryn by Kripos lawyers, police and technologists 21 employees. Scenarioet. Agenda. 60 % of all organisations - PowerPoint PPT Presentation

Transcript of Reporting the crime The investingation

Page 1: Reporting the crime  The investingation

ØKOKRIM

Reporting the crime The investingation

Politiinspektør Berit Børset SolstadPolitiets datakrimsenter

20.10.04

Page 2: Reporting the crime  The investingation

ØKOKRIM

QuickTime™ og en TIFF (ukomprimert)-dekomprimerer kreves for å se dette bildet.

The police data crime center

• Opened15. mai 2003

• Address: Bryn by Kripos

• lawyers, police and technologists

• 21 employees

Page 3: Reporting the crime  The investingation

ØKOKRIM

• Scenarioet

Agenda

Page 4: Reporting the crime  The investingation

ØKOKRIM

How many are hit by hackers?

• 60 % of all organisations • 5200 attacks (datainnbrudd)• 2,7 mill attempts• 150 000 virus infections

Page 5: Reporting the crime  The investingation

ØKOKRIM

Consequences

• 70 % of companies had extra work• 38 % analysed security after the attack• 5 % - loss of business

Page 6: Reporting the crime  The investingation

ØKOKRIM

Difficult to estimate financial loss

• 25 % can estimate direct loss• 6 % indirect loss• 12 % have routines to estimate loss

• 5 billion kroner in loss

Page 7: Reporting the crime  The investingation

ØKOKRIM

Sikkerhetstiltak og –rutiner

Page 8: Reporting the crime  The investingation

ØKOKRIM

Number of cases reported 2001 - 2003

0 20 40 60 80 100 120

Misbruk av IT-ressurser

Tyveri av datainformasjon

Datainnbrudd

Dataskadeverk og -bedrageri

2001

2003

Page 9: Reporting the crime  The investingation

ØKOKRIM

This case• Financial motive• The employees background/skills• The results of investigation

– In the company – The employee’s home computer

Page 10: Reporting the crime  The investingation

ØKOKRIM

Investigation abroad

• Directly between countries• Interpol• Europol• G8-nettverk

Page 11: Reporting the crime  The investingation

ØKOKRIM

G8-network

• Bakgrunn for deltakelse– Convention on Cybercrime– Rask respons– Uavhengig av tidssoner/arbeidstid

• 24/7-nettverk• Stor antall land med ulike regelverk

Page 12: Reporting the crime  The investingation

ØKOKRIM

• The ISPs obligation to save traffic information – Few countries demand that ISPs collect traffic

information • The ISP’s obligation to freeze information

after police intervention – varies from a few days to several months