Ecuadorian Cybersecurity: Bridging the Gap Between Infrastructure and Strategy

An Approach of Cyberattacks with the Use of Social Networks and Communication Media for Public Organizations of the Ecuador

2019-12-18
Segundo Moisés Toapanta Toapanta, Dhilan Torres Tapia, Luis Enrique Mafla Gallegos
Summary
Problem
Method
Results
Takeaways
Abstract

The paper proposes a prototype Cybersecurity Management Model tailored for public organizations in Ecuador to combat the rising tide of cyberattacks leveraging social networks and communication media. It introduces a structured framework integrating risk assessment via a 3x3 matrix and strategic mitigation protocols aligned with international standards.

TL;DR

As cyberattacks against Ecuadorian public institutions escalate—reaching staggering figures of 40 million incidents in short periods—technical defenses are proven insufficient. This paper introduces a Cybersecurity Management Model that shifts the focus from purely technical fixes to a risk-driven management framework, utilizing a 3x3 matrix to quantify threats from social networks and decentralized media.

Background & Positioning

In the global landscape of cybersecurity, Ecuador stands at a crossroads. While the country has invested in technical infrastructure, the absence of a unified strategic plan has left critical sectors like the Civil Registry and CNE (National Electoral Council) exposed. This work serves as a tactical blueprint, positioning itself as a "bridge" between local policy (Mintal) and international excellence (ISO/IEC standards).

The Core Problem: The Social Media Vector

Traditional security models often fail to account for the human factor inherent in social media. Attackers increasingly use platforms like Twitter (X) and LinkedIn to deploy:

  • Hammertoss Malware: Utilizing social media as a command-and-control channel.
  • Application Layer DDoS: Exposing server-side vulnerabilities through high-frequency requests.
  • Credential Sniffing: Exploiting the public disclosure of personal info to launch targeted spoofing.

The authors argue that the problem is not a lack of tools, but a lack of a deductive management method to prioritize these threats.

Methodology: The 4-Pillar Management Model

The heartbeat of the paper is a management architecture designed to be adopted by any public entity.

1. The Risk Matrix (The Quantitative Core)

The paper introduces a rigorous formula for determining risk priority: (Risk Value = Impact Level × Occurrence Probability)

Cybersecurity Management Model

2. Strategic Pillars

  • Incident Response: Direct actions triggered by the Risk Value (Acceptable vs. Critical).
  • Quality Management: Adhering to the ISO/IEC 27000 series, ensuring that the Information Security Management System (ISMS) is not just present, but audited and standardized.
  • Legal Regulations: Integrating Ecuadorian data protection projects into the technical workflow.

Experiments & Observations: A Reality Check

The study highlights the vulnerability of the EXIM email environment and the high incidence of HTTP-based DDoS attacks. Unlike volume-based attacks, these application-layer strikes deplete server resources effectively, requiring the "Trust Management Helmet" mechanism to differentiate legitimate users from bots.

Risk Matrix and Values Table: The 3x3 Matrix classifying risk zones from "Acceptable" (1-2) to "Critical" (>6).

Critical Insight: Why This Matters

The most striking takeaway is the authors' insistence on Cybersecurity Awareness at the user level. They argue that technical mitigations for "Information Theft" are useless if users do not establish privacy settings or limit public data disclosure.

Limitations: The model is highly administrative. While it provides a "guide," the actual technical implementation of the "six-layer model based on cryptographic algorithms" mentioned in the discussion deserves more granular detail regarding computational overhead.

Conclusion

This paper shifts the narrative from "buying more firewalls" to "building better management." For Ecuador’s public sector, the viable path forward lies in adopting this 3x3 risk-standardized approach to turn chaotic reactive measures into a proactive, audited security culture.

Find Similar Papers

Try Our Examples

  • Examine recent case studies of national cybersecurity policy implementations in Latin American public sectors post-2020.
  • What are the latest advancements in "Hammertoss" style malware that utilizes social media platforms for command and control?
  • Analyze the comparative effectiveness of the ISO/IEC 27000 series versus NIST frameworks in managing social engineering risks for government agencies.
Contents
Ecuadorian Cybersecurity: Bridging the Gap Between Infrastructure and Strategy
1. TL;DR
2. Background & Positioning
3. The Core Problem: The Social Media Vector
4. Methodology: The 4-Pillar Management Model
4.1. 1. The Risk Matrix (The Quantitative Core)
4.2. 2. Strategic Pillars
5. Experiments & Observations: A Reality Check
6. Critical Insight: Why This Matters
7. Conclusion