Article Reviews

Article Review 1: “Stolen Identity Valuation and Market Evolution on the Dark Web” by Chad M.S. Steel

Chad M.S. Steel’s “Stolen Identity Valuation and Market Evolution on the Dark Web” investigates the trade of stolen identities and the market forces that drive dark web exchanges. The piece explores what fuels the value of these identities and how the market adapts to shifts in technology, society, and rules. This review distills the research through the lens of social science ideas, with some thoughts on its broader implications.

Principles of Social Science

Steel’s piece brushes against some of the most important ideas in social science, like cultural relativity, structural functionalism, and rational choice theory. Cultural relativity, for instance, demonstrates how hacker subcultures develop norms specific to their context, such as trust processes around transactions. Steel documents how norms of behavior vary from region to region and group to group and adapt accordingly within different societal contexts (Steel, 2021). Then you have structural functionalism, which describes how dark web markets respond to law enforcement pressures by moving to encrypted platforms and decentralized systems, allowing them to remain stable (Steel, 2021). Finally, rational choice theory looks at the logic behind the actions of cyber offenders, as they weigh the risks and rewards of their activities.

Questions and Hypotheses

Steel makes some interesting points about the viability of dark web markets. He wonders, for example, how different enforcement strategies would change the way these markets function.

Research Methods

Steel offers a qualitative analysis of forum discussions along with quantitative market trend analysis. He employs ethnographic techniques to explore hacker communities’ norms, while pricing data provides him with strong empirical insights.

Data and Analysis

Pricing trends of stolen identities and transaction volumes on various dark web marketplaces are among the data. According to Steel, pricing is influenced by data quality and intended use.

Class Concepts

Four concepts from class that inform Steel’s work:

  • Motives behind Cyber Offending: As Steel explains, the reasons behind why people choose to become engaged in cybercrime can vary but are largely due to financial gain, ideologies, or wanting to be regarded in hacktivist circles. This multifaceted viewpoint reveals that these motives affect how perpetrators behave and the ways they use (Steel, 2021).
  • Sociological Theories: Structural functionalism and conflict theory allow us to analyze how dark web markets adapt in the face of external threats, like law enforcement intervention. They reflect how these black markets are embedded in broader social systems (Steel, 2021).
  • Hacker Communities: Steel examines how hacker subcultures maintain social structures and trust hierarchies for their long-term survival. Such cultural aspects ensure that transactions are trustworthy and underground markets can thrive (Steel, 2021).
  • Social Engineering: How techniques like phishing and the different forms of pretexting leverage human weaknesses in systematic ways. Steel’s focus on social engineering further proves its importance in the obtaining of identities (Steel, 2021).

Societal Contributions

One contribution to society is the research aiding in understanding the economic and social sides of the dark web and may provide valuable information for authorities to address markets. Second, it reminds us of the harm identity theft and cybercrime can cause, as well as the increased targeting of marginalized groups due to lower cybersecurity awareness.

Conclusion

Steel tends to have a more active focus on dark web markets, highlighting the need for tailored action to reduce the broader impact on society. By examining the economics and sociology of these markets, Steel shows just how much these underground online ecosystems can outlast the threat of shutdown and why it’s crucial to take an integrated approach to addressing cybercrime. This research, however, serves as a tool for policymakers and law enforcement in the war on identity theft and its larger consequences (Steel, 2021).

Reference

Steel, C. M. S. (2019). Stolen identity valuation and market evolution on the dark web. Retrieved from https://cybercrimejournal.com/pdf/Steelvol13issue1IJCC2019.pdf

Article Two: “An empirical study of ransomware attacks on organizations: an assessment of severity and salient factors affecting vulnerability”

How the Article Connects to Social Sciences

The article explores some crucial social science ideas, especially in sociology and economics, through the lens of cybersecurity in cities. From a sociological angle, it shows how things like IoT devices change how we interact with one another and our environment.

This article also mentions the economic side. It discusses how cyber-attacks can affect a city’s financial standing and states that if adequately protected, there will be substantial financial benefits.

Research Questions or Hypotheses

The article provides three different hypotheses. All three reference how different variables affect the severity of a ransomware attack, such as:

-An organization’s size influences the impact severity of a ransomware attack.

-An organization’s sector influences the impact severity of a ransomware attack.

-An organization’s security posture influences the impact severity of a ransomware attack.

These questions aim to discover what factors cause extremely harmful ransomware attacks.

Research Methods

In phase 1, the researchers used a qualitative research style by evaluating historical cyber-attacks and existing research. They also held interviews to investigate these events further. Instead of conducting a new experiment, the researchers utilized these techniques to reach conclusions regarding cybersecurity risks. In phase 2. they used a quantitative research style to test their hypotheses.

Data and Analysis

In phase 1, the researcher created a collection of ways a company can be impacted by ransomware and assigned a degree of severity to the extent of that impact.

In phase 2, they used 50 organizations of varying sizes, sectors, and industries to assess the effects of the ransomware attack. Utilizing the collection from Phase 1, the researchers compared the various outcomes and applied them to the degree of severity.

PowerPoint Concepts

One central concept from our PowerPoint that applies to this article is motive. Ransomware is created with financial gain in mind, which directly displays money as a motive, which we learned about in module 5.

This article also touches on risk assessment from module 11. This concept is relevant because all companies need cybersecurity. Part of the decision on how to choose the extent of the security measures needed involves conducting risk assessments.

Challenges for Marginalized Groups

The article highlights that marginalized communities often face the highest risks, given their limited access to secure technologies and a greater likelihood of being targeted in cyberattacks. It emphasizes the urgent need for inclusive cybersecurity policies to protect these vulnerable groups.

Contributions to Society

This study draws attention to the consequences of cyber threats and offers policy suggestions for creating more secure and equitable cyberspaces for companies. It also shows that, due to the ever-evolving field of cybersecurity, further research is always needed.

Reference:

Binns, R. (2020). Cybersecurity and the state: A critical analysis of public policy and governance in cyberspace. Cybersecurity, 6(1), tyaa023. https://doi.org/10.1093/cybersecurity/tyaa023