financially-motivated cybercrime: the turn to intermediaries · pdf filefinancially-motivated...

15
Financially-Motivated Cybercrime: The Turn to Intermediaries Chris Jay Hoofnagle, Adjunct Professor, I School & Law Aniket Kesari, JD/PhD Yale/Berkeley Student Amanda Maya, JD Candidate Damon McCoy, Assistant Professor, NYU CS & Engineering Platform Law: Public and Private Regulation of Online Platforms April 20–21, 2017

Upload: phungduong

Post on 03-Feb-2018

231 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: Financially-Motivated Cybercrime: The Turn to Intermediaries · PDF fileFinancially-Motivated Cybercrime: The Turn to Intermediaries Chris Jay Hoofnagle, Adjunct Professor, I School

Financially-MotivatedCybercrime:TheTurnto

IntermediariesChrisJayHoofnagle,AdjunctProfessor,ISchool&Law

AniketKesari,JD/PhDYale/BerkeleyStudentAmandaMaya,JDCandidate

DamonMcCoy,AssistantProfessor,NYUCS&EngineeringPlatformLaw:

PublicandPrivateRegulationofOnlinePlatformsApril20–21,2017

Page 2: Financially-Motivated Cybercrime: The Turn to Intermediaries · PDF fileFinancially-Motivated Cybercrime: The Turn to Intermediaries Chris Jay Hoofnagle, Adjunct Professor, I School

PopularPerception:Cybercrimeisanonymous,placeless

Source:FBI.gov

Noface

Numbersareneeded

Nokeyboard

Page 3: Financially-Motivated Cybercrime: The Turn to Intermediaries · PDF fileFinancially-Motivated Cybercrime: The Turn to Intermediaries Chris Jay Hoofnagle, Adjunct Professor, I School

CSCybercrimeLit:CybercriminalsDependentonPlatforms—Payments,Hosting,etc

• “…foraparticularspamnetwork,justthree acquiringbanksmanagedthemerchantaccountsfor95%ofthenearly1billionspammessagesanalyzed…”

• Cybercriminalsmaybedifficulttoreach,buttheirplatformsarenot

• Goldman&McCoy,DeterringFinanciallyMotivatedCybercrime,8J.Nat'lSec.L.&Pol'y 595(2015-2016)

• Levchenkoetal.,ClickTrajectories:End-to-EndAnalysisoftheSpamValueChain,Proceedingsofthe2011IEEESymposiumonSecurityandPrivacy (2011)

Page 4: Financially-Motivated Cybercrime: The Turn to Intermediaries · PDF fileFinancially-Motivated Cybercrime: The Turn to Intermediaries Chris Jay Hoofnagle, Adjunct Professor, I School

OnlinePharmacies:Turn totheIntermediaries

Page 5: Financially-Motivated Cybercrime: The Turn to Intermediaries · PDF fileFinancially-Motivated Cybercrime: The Turn to Intermediaries Chris Jay Hoofnagle, Adjunct Professor, I School

Googleagreestoanti-pharmaadprocedures

“Canada’s”

Page 6: Financially-Motivated Cybercrime: The Turn to Intermediaries · PDF fileFinancially-Motivated Cybercrime: The Turn to Intermediaries Chris Jay Hoofnagle, Adjunct Professor, I School

Thuspharmas havetocompeteinorganicsearch

Sponsored:noillegalpharma

Okaytohaveinorganicresults

Page 7: Financially-Motivated Cybercrime: The Turn to Intermediaries · PDF fileFinancially-Motivated Cybercrime: The Turn to Intermediaries Chris Jay Hoofnagle, Adjunct Professor, I School

Howtogettothetop?

Page 8: Financially-Motivated Cybercrime: The Turn to Intermediaries · PDF fileFinancially-Motivated Cybercrime: The Turn to Intermediaries Chris Jay Hoofnagle, Adjunct Professor, I School

Collecttop-rankedresults

Linkanalysisofads,html

links,customerservice,

paymentinPalantirGotham

Page 9: Financially-Motivated Cybercrime: The Turn to Intermediaries · PDF fileFinancially-Motivated Cybercrime: The Turn to Intermediaries Chris Jay Hoofnagle, Adjunct Professor, I School

Hoofnagle et al., Online Pharmacies and Technology Crime, inTHE HANDBOOK OFTECHNOLOGY, CRIME ANDJUSTICE (Michael McGuire and Thomas J. Holt, eds.) (Routledge Press 2017)

Page 10: Financially-Motivated Cybercrime: The Turn to Intermediaries · PDF fileFinancially-Motivated Cybercrime: The Turn to Intermediaries Chris Jay Hoofnagle, Adjunct Professor, I School

• Botnets,hackingforhire• Transnationalcriminalorganizations• Counterfeitgoods• Anti-prostitution

ForPlatformLaw:HowDoEnforcersUsetheLawtoPoliceIntermediaries?

Page 11: Financially-Motivated Cybercrime: The Turn to Intermediaries · PDF fileFinancially-Motivated Cybercrime: The Turn to Intermediaries Chris Jay Hoofnagle, Adjunct Professor, I School

Interventions:Rule65TROs&FRCRMP41

• StandardRule65TRO,PIsusedfor• Anti-botnetactivities• Counterfeiting

• Reliefisgrantedquickly—sometimeswithindays• Reliefincludesseizuresofscoresofdomainnames• Exparte• InnewKelihos botnet,gov’treliedonFRCRMP41

• Butprocedurelooksthesame—• Gov’tidentifies,seizescommand&controlservers• “Sinkholes”communicationsorpatchesvulnerablebots

Page 12: Financially-Motivated Cybercrime: The Turn to Intermediaries · PDF fileFinancially-Motivated Cybercrime: The Turn to Intermediaries Chris Jay Hoofnagle, Adjunct Professor, I School

• DepartmentofTreasury’sSpeciallyDesignatedNationalsListisbeingusedtoblocktransactionswithcyberactors.

• Theseareassetblocks,bansonUScompaniesdoingbusinesswithdesignatedindividuals

• 3programsbeingused:• Cyber:Nooneyetdesignated.

• EO13694(Obama2015)• Cyber2:Russianoperationrelatedto2016electionhacking.

• EO13757(Obama2016)• TCO:PacNet groupmoneylaundering.

• TransnationalCriminalOrganizationsSanctionsRegulations, ExecutiveOrder13581

Interventions:TreasurySanctions

Page 13: Financially-Motivated Cybercrime: The Turn to Intermediaries · PDF fileFinancially-Motivated Cybercrime: The Turn to Intermediaries Chris Jay Hoofnagle, Adjunct Professor, I School

• Thesearebothprivateandpublicinterventions• OperationChokepoint• Self-regulatoryefforts

• Amex(closedloopsystem)attemptingtocutoffBackpage.com (”escort”services)

• CAAG’smoneylaunderingcaseagainstBackpage standsatopeffortstocircumventAmex’sban

Interventions:PaymentSystems

Page 14: Financially-Motivated Cybercrime: The Turn to Intermediaries · PDF fileFinancially-Motivated Cybercrime: The Turn to Intermediaries Chris Jay Hoofnagle, Adjunct Professor, I School

• CDA&DMCAisafocusofthelegalliteratureofintermediaries• Butourworkfocusesonotherinterventions• We’lldiscussclaimantabuse,dueprocess,overbreadth• Wesuspectintermediaryattackswillcontinuetobeeffectiveagainstfinancially-motivatedcybercriminals,especiallywhenpaymentplatformsaretargeted

• ToomanyalternativesintheDNSspace;whack-a-mole• Googlewillcontinuetobeakeyintermediary• Decentralizationofserviceproviders(e.g.BitCoin)isanunlikelyalternative

Concluding

Page 15: Financially-Motivated Cybercrime: The Turn to Intermediaries · PDF fileFinancially-Motivated Cybercrime: The Turn to Intermediaries Chris Jay Hoofnagle, Adjunct Professor, I School

Thanksto…

• CenterforLong-TermCybersecurity• PalantirTechnologies• Laurin Weissinger,Nuffield