Why cybercrime?
Vaibhav Garg, L. Jean Camp · ACM SIGCAS Computers and Society · 2015
How do cybercrime markets emerge, evolve, and persist? How can cybercrime be prevented, decreased and mitigated? Extant anti-cybercrime efforts have concentrated on deterrence through criminal prosecution and technical mitigation. Deterrence-only strategies, however, may be more expensive for the network than for attackers, particularly considering the asymmetric nature of computer security. The implicit assumption of deterrence, i.e. criminals are strictly self-optimizing rational agents cognizant only of a cost-benefit function, is contentious. Criminal actions are constrained/enabled by the institutional structures of their immediate neighborhood. Exposure to crime (or probability of victimization is similarly influenced. Thus, this paper examines the respective economic, structural, and cultural theories in criminology and explores their relevance online. We discuss the implications for technical solutions, security design, as well as public policy. An intuitive position is to lower the entry cost of legal enterprise, and thereby increase the opportunity cost of cybercrime engagement. We also discuss solutions that allow simultaneous investments (to reduce crime online) by both public and private entities, while mitigating for potential moral hazard. Our concluding argument, then, is for complementing deterrence with policy solutions that preemptively engage potential criminals as legitimate market stakeholders. In addition to the explicit examination of deterrence theories of cybercrime, this work offers a broader consideration of cybercrime that is grounded in theories of crime offline.