Showing posts with label Cybercrime. Show all posts
Showing posts with label Cybercrime. Show all posts

Saturday, May 20, 2023

CRS Reports – Week of 5-20-23 – Cybercrime

This week, the Congressional Research Service (CRS) published a report on “Cybercrime and the Law: Primer on the Computer Fraud and Abuse Act and Related Statutes”. This longer than normal (53 pages) report provides a detailed look at the CFAA, its definitions and seven categories of actions prohibited under the statue. It concludes with a discussion of potential issues of concern for Congress.

The latter discussion should be of interest to anyone working in or on the fringes of the cybersecurity community. Topics include:

Botnet trafficking,

“Hacking back”,

Critical infrastructure,

Doxing and swatting, and

The insider threat.

 

Friday, December 3, 2021

S 2629 Reported in Senate - Cybercrime Reporting

Earlier this week the Senate Judiciary Committee reported S 2629, the Better Cybercrime Metrics Act favorably without a written report. The Committee met on November 18th, 2021, to consider the bill and ordered it reported at that time without amendment. The bill is now cleared for possible consideration by the full Senate.

The bill would require DOJ to establish a taxonomy for classifying cybercrime in the National Incident-Based Reporting System (NIBRS) and would require the reporting of cybercrimes according to that taxonomy. The bill provides for $1 million to support the development of the taxonomy, including a study on the topic by the National Academy of Sciences. It would have no effect on cybercrime reporting by victims.

Reporting a bill without a written report is usually an indication that an effort is going to be made to bring the bill to the floor for consideration. With the strong bipartisan support seen for this bill in Committee, it is possible that the bill could be offered under the Senate’s unanimous consent process.

Thursday, February 14, 2019

Bills Introduced – 02-13-19


Yesterday with both the House and Senate in session there were 98 bills introduced. Three of those bills may receive additional coverage in this blog:

HR 1158 To authorize cyber incident response teams at the Department of Homeland Security, and for other purposes. Rep. McCaul, Michael T. [R-TX-10] 

HJ Res 45 Making further continuing appropriations for fiscal year 2019, and for other purposes. Rep. Biggs, Andy [R-AZ-5]

S 482 A bill to strengthen the North Atlantic Treaty Organization, to combat international cybercrime, and to impose additional sanctions with respect to the Russian Federation, and for other purposes.  Sen. Graham, Lindsey [R-SC] 

I will be watching S 482 for language that would include attacks on industrial control systems in the definition of ‘cybercrime’, but I am not holding my breath.

There was one other oddly named bill that I will personally be watching (but will probably not be writing about here), S 483. Introduced by Sen. Roberts (R,KS) it is titled: “A bill to enact into law a bill by reference.” Odd.

Monday, August 13, 2018

S 3288 Introduced – Cybercrime


Last month Sen. Graham (R,SC) introduced S 3288, the International Cybercrime Prevention Act. The bill would make a number of amendments to 18 USC that are intended to make it easier to prosecute a variety of cybercrimes and to effectively increase the punishments available for such crimes by allowing for seizures and forfeitures in conjunction with the prosecution of those crimes.

Racketeering


Section 2 of the bill would add language to 18 USC 1956 (Laundering of monetary instruments) that would include §2512 (Manufacture, distribution, possession, and advertising of wire, oral, or electronic communication intercepting devices prohibited) as a predicate act for §1956. It would additionally add language to §1961 (Definitions section of the RICO chapter) that would include violations of §1030 (Fraud and related activity in connection with computers) in the crimes which could be included in the definition of ‘racketeering activity’.

Forfeiture


Section 3 of the bill completely rewrites §2513 (Confiscation of wire, oral, or electronic
communication intercepting devices). First it expands the confiscation authority to include ‘other property’ to include “any property, real or personal, constituting or derived from any gross proceeds, or any property traceable to such property, that such person obtained or retained directly or indirectly” {new §2513(a)(1)(A)} as a result of a violation of §2511 (Interception and disclosure of wire, oral, or electronic communications prohibited) or §2512.

Section 3 provides for criminal forfeiture proceedings using the procedures established for controlled substance under 21 USC 853 and for civil forfeiture proceedings using the procedures established under 18 USC Chapter 46.

Botnets


Section 4 of the bill amends 18 USC 1345 (Injunctions against fraud). First it expands the heading of the section to read “Injunctions against fraud and abuse” {§4(a)(1)}. Then it adds a new subparagraph (a)(1)(D) which adds a violation of  §1030(a)(5) to the list of offenses under which §1345 allows the Attorney General to “commence a civil action in any Federal court to enjoin such violation” {existing §1345(a)(1)}. The §1030 offense may only included if it adversely affects 100 or more protected computers in a one-year period.

Critical Infrastructure Computer


Section 5 of the bill would add a new §1030A (Aggravated damage to a critical infrastructure computer) to 18 USC. This new section would make it separately illegal during the violation of §1030 “to knowingly cause or attempt to cause damage to a critical infrastructure computer” {new §1030A(a)} if the damage results in substantial impairment of:

• The operation of the critical infrastructure computer; or
The critical infrastructure associated with such computer

The section uses the definition of ‘computer’ and ‘damage’ from §1030. The definition of ‘critical infrastructure’ is spelled out in §1030A(d)(2). In general it is a pretty generic definition except that it specifically adds “including voter registration databases, voting machines, and other communications systems that manage the election process or report and display results on behalf of State and local governments”.

18 USC 1030 Amended


Section 6 of the bill amends 18 USC 1030. First it adds a new subparagraph (8) to §1030(a) that essentially expands the list of potential offenses covered under this computer fraud statute. That new offense would be the trafficking “in the means of access to a protected computer” {new §1030(a)(8)}. While similar to §1030(a)(6), it does not include the ‘intent to defraud’ language of that section. It also includes a requirement that trafficker knows that the recipient of the means of access intends to use that access to “damage a protected computer in a manner prohibited by this section” or “violate section 1037 [Fraud and related activity in connection with electronic mail; link added] or 1343 [Fraud by wire, radio, or television; link added]”

Section 6 then goes on to add the same injunction provisions to §1030 added to §2513 by section 3 of the bill (described above).

Moving Forward


Graham is a member of the Senate Judiciary Committee and the Chair of the Subcommittee on Crime and Terrorism. It is very likely that he has sufficient influence to see this bill considered in Committee. His two Democratic cosponsors {Sen. Blumenthal (D,CT) and Sen. Whitehous (D,RI)} are also influential members of the Judiciary Committee, so it would appear that there will be at least some bipartisan support for the legislation.

I will be very surprised if this bill makes it through the Committee process this late in the session. It almost certainly will not make it to the floor of the Senate, because this is a complex bill that would require floor debate and an amendment process that would interfere with the work the Senate needs to complete before the end of the year.

Friday, July 27, 2018

Bills Introduced – 07-26-18


Yesterday with both the House and Senate in session (and the House preparing to leave on its extended summer break) there were 131 bills introduced (109 in the House). Of these, five may be of specific interest to readers of this blog:

HR 6555 To amend the Homeland Security Act of 2002 to establish a DHS Cybersecurity On-the-Job Training and Employment Apprentice Program, and for other purposes. Rep. Jackson Lee, Sheila [D-TX-18]

HR 6609 To amend title 46, United States Code, to reauthorize the port security grant program, and for other purposes. Rep. Meng, Grace [D-NY-6]

HR 6617 To provide for a legal framework for the operation of public unmanned aircraft systems, and for other purposes. Rep. Poe, Ted [R-TX-2]

HR 6620 To require the Department of Homeland Security to prepare a threat assessment relating to unmanned aircraft systems, and for other purposes. Rep. Richmond, Cedric L. [D-LA-2]

S 3288 A bill to amend title 18, United States Code, to provide the Department of Justice needed legal authorities to combat cybercrime, including state sponsored cybercrime, and for other purposes. Sen. Graham, Lindsey [R-SC]

I suspect HR 6555 will be a program for federal employees, but it would still be worthwhile to watch how such a program was established. It could actually be an interesting model for similar programs in the private sector.

It will be interesting to see what sorts of restrictions are placed on public unmanned aircraft systems in HR 6617.

S 3288 will bear close scrutiny of definitions as they will likely have unintended bearing on activities of cybersecurity researchers.

Tuesday, May 17, 2016

Bills Introduced – 05-16-16

With both the House and Senate in session yesterday there were 25 bills introduced. There was only one that may be of specific interest to readers of this blog:

S 2931 A bill to amend title 18, United States Code, to protect Americans from cybercrime. Sen. Graham, Lindsey [R-SC]


If the language of this bill includes provisions for industrial control system ‘crimes’, you can expect to see further analysis and coverage here. I’m not holding my breath.

Friday, April 22, 2016

Bills Introduced – 04-22-16

With the House and Senate preparing to leave Washington for the weekend there were 53 bills introduced yesterday. Of those three may be of specific interest to readers of this blog:

HR 5026 To direct the President to develop and submit to Congress a comprehensive strategy to combat cybercrime, and for other purposes. Rep. Ross, Dennis A. [R-FL-15]

S 2837 An original bill making appropriations for the Departments of Commerce and Justice, Science, and Related Agencies for the fiscal year ending September 30, 2017, and for other purposes. Sen. Shelby, Richard C. [R-AL]

S 2844 An original bill making appropriations for the Departments of Transportation, and Housing and Urban Development, and related agencies for the fiscal year ending September 30, 2017, and for other purposes. Sen. Collins, Susan M. [R-ME]

HR 5026 could be interesting depending on its definition of ‘cybercrime’. I will only provide coverage if it looks like it would include attacks on control systems.


As always, I watch spending bills for cybersecurity provisions. Of course the transportation bill will also be followed for its effects on hazardous chemical transportation issues.
 
/* Use this with templates/template-twocol.html */