{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T16:10:05Z","timestamp":1781107805104,"version":"3.54.1"},"reference-count":25,"publisher":"IGI Global Scientific Publishing","issue":"4","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017,10,1]]},"abstract":"<p>Data breaches are becoming more common and numerous every day, where huge amount of data (corporate and personal) are leaked more frequently than ever. Corporate responses to data breaches are insufficient, when commonly remediation is minimal. This research proposes that a similar approach to physical pollution (environmental pollution) can be used to map and identify data leaks as Cyber pollution. Thus, IT institutions should be made aware of their contribution to Cyber pollution in a more measurable method. This article defines the concept of cyber pollution as: security vulnerable (such as unmaintained or obsolete) devices that are visible through the Internet and corporate networks. This paper analyses the recent state of data breach disclosures Worldwide by providing statistics on significant scale data breach disclosures from 2014\/01 to 2016\/12. Ivan Burke and Renier van Heerden model security threat levels similar to that of pollution breaches within the physical environment. Insignificant security openings or vulnerabilities can lead to massive exploitation of entire systems. By modelling these breaches as pollution, the aim is to introduce the concept of cyber pollution. Cyber pollution is a more tangible concept for IT managers to relay to staff and senior management. Using anonymised corporate network traffic with Open Source penetration testing software, the model is validated.<\/p>","DOI":"10.4018\/ijcwt.2017100104","type":"journal-article","created":{"date-parts":[[2017,10,11]],"date-time":"2017-10-11T11:54:49Z","timestamp":1507722889000},"page":"35-51","source":"Crossref","is-referenced-by-count":0,"title":["The World is Polluted With Leaked Cyber Data"],"prefix":"10.4018","volume":"7","author":[{"given":"Ivan D.","family":"Burke","sequence":"first","affiliation":[{"name":"Council for Scientific and Industrial Research, University of Pretoria, Pretoria, South Africa and Rhodes University, Grahamstown, South Africa"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Renier P.","family":"van Heerden","sequence":"additional","affiliation":[{"name":"Council for Scientific and Industrial Research, University of Pretoria, Pretoria, South Africa and Nelson Mandela University, South Africa"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"IJCWT.2017100104-0","unstructured":"Botha, J., Eloff, M., & Swart, I. (2016). Pro-active data breach detection: examining accuracy and applicability on personal information detected. In Proceedings of the 11th International Conference on Cyber Warfare and Security ICCWS, Boston, MA."},{"key":"IJCWT.2017100104-1","unstructured":"Breach Level Index. (2017, January 20). Data Breach Statistics by Year, Industry and More - Breach Level Index. Retrieved February 2017, 2017, from http:\/\/www.breachlevelindex.com\/"},{"key":"IJCWT.2017100104-2","unstructured":"Daily News. Istanbul. (2013, December 16). Russian hackers stole 54 million Turkish citizens\u2019 ID data: Claim. Retrieved January 16, 2017, from http:\/\/www.hurriyetdailynews.com\/russian-hackers-stole-54-million-turkish-citizens-id-data-claim.aspx?pageID=238&nID=59644&NewsCatID=338weak-state-servers-breach-causes-mass-identity-theft-in-turkey-haberi"},{"key":"IJCWT.2017100104-3","author":"C.Doctorow","year":"2011","journal-title":"Context"},{"key":"IJCWT.2017100104-4","unstructured":"Dutch Data Protection Authority. (2015, December 8). The data breach notification obligation as laid down in the Dutch Data Protection Act. Retrieved from https:\/\/autoriteitpersoonsgegevens.nl\/sites\/default\/files\/atoms\/files\/policy_rules_data_breach_notification_obligation.pdf"},{"key":"IJCWT.2017100104-5","unstructured":"ENISA. (2010, October 25). Data breach notifications in the EU. Retrieved from https:\/\/www.enisa.europa.eu\/publications\/dbn\/at_download\/fullReport"},{"key":"IJCWT.2017100104-6","unstructured":"European Commission. (2016, November 24). Protection of personal data. Retrieved from http:\/\/ec.europa.eu\/justice\/data-protection\/"},{"key":"IJCWT.2017100104-7","unstructured":"European Parliament. (2002, July 31). Directive 2002\/58\/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector. Retrieved from http:\/\/eur-lex.europa.eu\/LexUriServ\/LexUriServ.do?uri=CELEX:32002L0058:EN:HTML"},{"key":"IJCWT.2017100104-8","unstructured":"FIRST. (2015, June 10). Common Vulnerability Scoring System, V3 Development Update. Retrieved from https:\/\/www.first.org\/cvss"},{"key":"IJCWT.2017100104-9","unstructured":"Government Gazette. (2013, November 26). Protection of Personal Information Act. Retrieved from http:\/\/www.gov.za\/sites\/www.gov.za\/files\/37067_26-11_Act4of2013ProtectionOfPersonalInfor_correct.pdf"},{"key":"IJCWT.2017100104-10","unstructured":"Greenberg, A. (2016, April 5). Hack Brief: Turkey Breach Spills Info on More Than Half Its Citizens. Retrieved January 16, 2017, from https:\/\/www.wired.com\/2016\/04\/hack-brief-turkey-breach-spills-info-half-citizens\/"},{"key":"IJCWT.2017100104-11","unstructured":"Grubb, B. (2014, April 15). Heartbleed disclosure timeline: who knew what and when. Retrieved from http:\/\/www.smh.com.au\/it-pro\/security-it\/heartbleed-disclosure-timeline-who-knew-what-and-when-20140414-zqurk.html"},{"key":"IJCWT.2017100104-12","unstructured":"IEEE Standards Association. (n. d.). Registration Authority. Retrieved January 5, 2017, from http:\/\/standards.ieee.org\/develop\/regauth\/oui\/"},{"key":"IJCWT.2017100104-13","unstructured":"KPMG. (2017, August 1). Overview of China\u2019s Cyber Crime Law. Retrieved from https:\/\/assets.kpmg.com\/content\/dam\/kpmg\/cn\/pdf\/en\/2017\/02\/overview-of-cybersecurity-law.pdf"},{"key":"IJCWT.2017100104-14","unstructured":"Manners, D., & Vanderbrink, R. (2011, October 20). The user agent field: Analyzing and detecting the abnormal or malicious in your organization. Retrieved from https:\/\/www.sans.org\/reading-room\/whitepapers\/hackers\/user-agent-field-analyzing-detecting-abnormal-malicious-organization-33874"},{"key":"IJCWT.2017100104-15","unstructured":"McAfee. (2015, July 31). How to combat the W32\/Conficker worm. Retrieved from https:\/\/kc.mcafee.com\/corporate\/index?page=content&id=KB60909"},{"key":"IJCWT.2017100104-16","unstructured":"Murdock, J. (2016, May 19). Anonymous hacker claims to leak hospital data of millions of Turkish citizens. Retrieved January 16, 2017, from http:\/\/www.ibtimes.co.uk\/anonymous-hacker-claims-leak-hospital-data-more-10-million-turkish-citizens-1560985"},{"key":"IJCWT.2017100104-17","unstructured":"Ponemon Institute LLC. (2016). 2016 Cost of Data Breach Study."},{"key":"IJCWT.2017100104-18","author":"B.Schneier","year":"2015","journal-title":"Data and Goliath: The hidden battles to collect your data and control your world"},{"key":"IJCWT.2017100104-19","unstructured":"Shodan. (2016, March 26). Devices Vulnerable to Heartbleed. Retrieved from https:\/\/www.shodan.io\/report\/89bnfUyJ"},{"key":"IJCWT.2017100104-20","unstructured":"Shodan. (2017, February 10). Countries vulnerable to Heartbleed. Retrieved from https:\/\/www.shodan.io\/report\/9F6Zj0R4"},{"key":"IJCWT.2017100104-21","unstructured":"Shodan. (2017, February 12). IIS 2.0. Retrieved from https:\/\/www.shodan.io\/report\/1jePq5mb"},{"key":"IJCWT.2017100104-22","unstructured":"Symantec. (2014, September 25). ShellShock: All you need to know about the Bash Bug vulnerability. Retrieved from http:\/\/www.symantec.com\/connect\/blogs\/shellshock-all-you-need-know-about-bash-bug-vulnerability"},{"key":"IJCWT.2017100104-23","unstructured":"Turner, A. (2012, September 5). TCPRewrite. Retrieved January 5, 2017, from TCPReplay: http:\/\/tcpreplay.synfin.net\/wiki\/tcprewrite"},{"key":"IJCWT.2017100104-24","unstructured":"US-CERT. (2014, October 17). SSL 3.0 Protocol Vulnerability and POODLE Attack. Retrieved from https:\/\/www.us-cert.gov\/ncas\/alerts\/TA14-290A"}],"container-title":["International Journal of Cyber Warfare and Terrorism"],"original-title":[],"language":"ng","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=190590","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,6]],"date-time":"2022-05-06T20:08:47Z","timestamp":1651867727000},"score":1,"resource":{"primary":{"URL":"https:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/IJCWT.2017100104"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2017,10,1]]},"references-count":25,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2017,10]]}},"URL":"https:\/\/doi.org\/10.4018\/ijcwt.2017100104","relation":{},"ISSN":["1947-3435","1947-3443"],"issn-type":[{"value":"1947-3435","type":"print"},{"value":"1947-3443","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,10,1]]}}}