Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

06:45 PM
Connect Directly

NSF-Funded Research Aims to Help Disrupt Cybercrime Supply Chains

The National Science Foundation awarded a grant to Georgia State University (GSU) to come up with innovative ways to thwart the supply chains for counterfeiting, loan- and unemployment fraud.

The National Science Foundation has awarded a $250,000 grant to Georgia State University (GSU) to study how best to disrupt - and ultimately take down - the supply chains that allow cybercriminals to thrive.

David Maimon, associate professor and director of the Evidence-Based Cybersecurity Research Group at GSU, says his team will focus on the supply chains that support counterfeiting cash money and PII such as credit card data, social security numbers, and names and addresses, as well as fraud around Small Business Administration loans and unemployment claims.

Maimon says by using an evidence-based approach, the team at GSU will use rigorous social science research, observations, and surveys to find out which law enforcement techniques actually work in the field. 

"The goal is to take down these supply chains," Maimon says. "Cyber researchers and law enforcement agencies chasing cybercriminals tend to focus on taking down servers to disrupt cybercrime. While these activities are effective, they often have short-term impact, as the cybercriminals can reconfigure servers very quickly and stay in operation."

Ed Cabrera, chief cybersecurity officer at Trend Micro, says there's a definite need for research that looks at the nature of the supply chain versus the technical cyber-side of the equation. 

"We tend to look at the symptoms and not the disease, which is the ecosystems that enable these criminal activities," Cabrera says. "As security researchers in the industry, we'll look at the malware bought and sold, the macro picture. But there's a need for more innovative ways to go after these groups."

Anatomy of the Supply Chain

Maimon says the GSU team will study how the four junctions of the supply chain interact with one another and look for creative ways to disrupt them. This includes enablers, offenders, victims, and guardians.

According to GSU, enablers are individuals and organizations that deliver services to those who wish to carry out cyberattacks. Enablers include the coders or programmers of malicious software; distributors and vendors who trade and sell hacking tools and stolen data; teachers who exchange information regarding cybercrime techniques and tools; and moderators and administrators of online marketplaces who maintain the criminal infrastructure, vouch for the goods, and enforce social norms in these criminal marketplaces.

Online offenders and enablers of cybercrime tend to meet in both offline or online environments.

The victims of cybercrimes are private individuals or companies that experience attacks on their computers, networks, and IoT devices. For a variety of reasons, they are often reticent to report that they've been the victim of a cybercrime to law enforcement.

Finally, the list of relevant cybercrime guardians that monitor these activities includes law enforcement agencies such as the FBI and state and local police agencies, governmental intelligence agencies such as the National Security Agency, and systems administrators at Internet service providers, corporations, and industries.

Maimon says GSU's research group especially seeks to find more creative ways to interact with the offenders and enablers so they can protect victims and come up with new tools and techniques for law enforcement. For example, instead of just monitoring traffic on servers, they may look to spread gossip on the Dark Web to see if they can disrupt the market and get the offenders or enablers to make a mistake.

The GSU has two years to report its findings and issue recommendations to law enforcement, government security agencies, and the private sector.


Steve Zurier has more than 30 years of journalism and publishing experience and has covered networking, security, and IT as a writer and editor since 1992. Steve is based in Columbia, Md. View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Why Vulnerable Code Is Shipped Knowingly
Chris Eng, Chief Research Officer, Veracode,  11/30/2020
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-12-03
There is a local denial of service vulnerability in the Antiy Zhijia Terminal Defense System and an attacker can cause a computer crash (BSOD).
PUBLISHED: 2020-12-03
There is a local privilege escalation vulnerability in Alfredo Milani Comparetti SpeedFan 4.52. Attackers can use constructed programs to increase user privileges
PUBLISHED: 2020-12-03
An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD files. A specially crafted malformed file can trigger an out-of-bounds memory access and modification which results in memory corruption. To trigger this vulnerability, the victim n...
PUBLISHED: 2020-12-03
The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL injection in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
PUBLISHED: 2020-12-03
There is a local denial of service vulnerability in Wise Care 365 5.5.4, attackers can cause computer crash (BSOD).