For old-fashioned detectives, the problem was always acquiring information. For the modern cybersleuth, hunting evidence in the data tangle of the Internet, the problem is different.
“The holy grail is how can you distinguish between information which is garbage and information which is valuable?” said Rafal Rohozinski, a social scientist trained at the University of Cambridge and involved in computer security issues.
Beginning eight years ago he co-founded two groups, Information Warfare Monitor and Citizen Lab, which have headquarters at the University of Toronto, with Ronald Diebert, a University of Toronto political scientist. In pursuit of that grail, these groups strive to put investigative tools normally reserved for law enforcement agencies and computer security investigators at the service of groups that do not have such resources.
“We thought that civil society groups lacked an intelligence capacity,” Mr. Diebert said.
They have had some important successes. Last year Nart Villeneuve, an international relations researcher who works for the two groups, found that a Chinese version of Skype software was being used for eavesdropping by one of the major Chinese wireless carriers, probably on behalf of Chinese law enforcement agencies.
This year, Mr. Villeneuve helped uncover a spy system — he and his fellow researchers dubbed it Ghostnet — which looked like a Chinese government-run operation looking at mostly South Asian government-owned computers around the world.
Both discoveries were the result of a new genre of detective work, and they illustrate the strengths and the limits of detective work in cyberspace.
The researchers were not able to determine with certainty who controlled the system. It could have been created by so-called patriotic hackers, independent computer activists in China whose actions are closely aligned with, but independent from, the Chinese government. Or it could have been created and run by Internet spies in a third country.
Indeed, the discovery raised as…