Madeline Bennett
Madeline Bennett

Could prison cure viruses?

Will the sentences imposed by courts really serve as a deterrent against virus writers?

Written by Madeline Bennett

German law enforcement agencies had a success this month with the arrest of the teenager thought responsible for the Sasser worm. The investigation - involving German police, the FBI and Microsoft - and subsequent arrest were hailed as an example of how joint efforts by industry and government agencies can get results.

The outcome was also touted as a success story for Microsoft's scheme launched late last year to offer cash rewards for information about the identity of virus writers.

Advertisement

But catching a suspect is only one step. It's no use getting the culprit to court if they are let off with a slap on the wrist or a nominal community service order.

One sure-fire way to ensure harsher penalties would be for firms to start being a bit more open about the damage inflicted to their systems. If judges were presented with hard data about financial losses inflicted by worms or hack attacks, collected from a range of companies, they would be more likely to impose suitable sentences.

However, I don't think many companies are happy publishing this type of data without safeguards in place to protect their reputations - and rightly so. It's still the case that admitting to being hit by a virus or denial-of-service attack doesn't go down well with customers and investors.

Initiatives such as the National Hi-Tech Crime Unit (NHTCU)'s Confidentiality Charter have been designed to allow firms to report attacks with the knowledge that the information will remain confidential. Such schemes are welcome, but more needs to be done to inform firms of their existence and to build up trust with potential contributors.

All-party lobby group Eurim has proposed another way of tackling the problem of internet crime. It recently released a paper arguing that a lack of IT forensic experts in the police and industry is hampering investigations and reducing the chances of obtaining successful prosecutions. It is therefore calling for the government to develop guidelines for computer crime investigations, and it wants certification schemes to be introduced for mid-level forensic computing skills.

And we also have an update of the Computer Misuse Act on the cards, to ensure the law adequately covers all types of computer-related offences, and to close loopholes.

However, even with adequate laws and skilled investigators, there is still a risk that convicted offenders will get off lightly.

Going back to the Sasser case, teenager Sven Jaschan could face up to five years in prison for the damage he's accused of having caused. But I doubt very much that such a stringent sentence will be handed out. A suspended sentence, community service, or a slap on the wrist and "no more computers for you, sir" are all much more likely outcomes if he's found guilty.

Indeed one group of well-wishers even set up a support fund for Jaschan, collecting donations to help with legal fees in return for the service he's done by highlighting the weakness of IT security. (For those readers keen to donate, I'm sorry to say the Sasser Support Team ended its fundraising drive after unsuccessful attempts to contact the man himself).

Until we stop making excuses for these people and see them for what they are - law-breakers as opposed to mischievous pests - any drives to combat computer crime will be severely hampered.

Tags:

Related articles

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

10 Oct 2008

7.33 MBPodcast Special: Views from the Valley More...

Podcast image

09 Oct 2008

12.99 MBComputing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security More...

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

MoD building

Latest data breach leads MPs to demand culture change

MoD admits to losing a hard drive containing up to...  More...

Online shopping

E-retailers urged to prepare for Christmas

Credit crunch sending shoppers online for cheaper presents   More...

Mobile phone

Emerging markets drive mobile growth

Mobile penetration rates expected to reach 95 per cent by...  More...

Digital information

Poor data classification costing companies dear

Millions wasted on searching through clutter, says analyst   More...

Primary Navigation