UNIT 1: FUNDAMENTALS OF CYBER CRIME & LEGAL FRAMEWORK (CY-402)
1.0 Introduction to Cyber Crime
1.1 Definition and Evolution of Cyber Crime
-
Definition: Cyber Crime refers to any illegal activity that involves a computer, network, or the internet as a tool, target, or place of criminal conduct. It encompasses crimes where technology is integral to the offense.
-
Evolution:
-
1970s-80s: Early incidents like phone phreaking, simple virus creation, and unauthorized access to mainframe systems (e.g., "The Creeper" worm).
-
1990s: Rise of the commercial internet, web defacement, email-based attacks, and the first major financial frauds.
-
2000s-Present: Sophistication increased with organized crime, state-sponsored attacks, ransomware, cryptojacking, large-scale data breaches, and attacks on critical infrastructure (IoT, Cloud).
-
1.2 Impact of Internet and Mobile Proliferation
-
Increased Attack Surface: Billions of connected devices (smartphones, IoT) create vast entry points.
-
Anonymity & Scale: Perpetrators can operate remotely across borders, targeting millions simultaneously.
-
Monetization: Digital payment systems and cryptocurrencies enable profitable criminal enterprises.
-
Data as Target: Personal, financial, and corporate data became a valuable commodity ("data is the new oil").
1.3 Key Challenges
| Challenge | Description |
|---|---|
| Jurisdiction | Crimes cross national borders instantly. Which country's laws apply? Enforcement requires international treaties (e.g., Budapest Convention). |
| Attribution | Hiding identity using proxies, VPNs, Tor, and botnets makes identifying the true perpetrator technically and legally difficult. |
| Technical Complexity | Attacks leverage advanced cryptography, zero-day exploits, and polymorphic malware, requiring high forensic expertise. |
| Legal Lag | Technology evolves faster than legislation. Laws often become obsolete upon enactment. |
| Evidence Volatility | Digital evidence can be altered or destroyed in seconds. |
1.4 Nature and Elements of Cyber Criminality
-
Actus Reus (Guilty Act): The technical act (e.g., writing malware, sending a phishing email, accessing a system without authorization).
-
Mens Rea (Guilty Mind): The intention or knowledge to cause harm, gain unauthorized access, or commit fraud. Motive is not always a legal element but is relevant for profiling.
-
Causation: The illegal act must directly cause harm (e.g., data theft, financial loss, service disruption).
-
Legality: The act must be defined as a crime under existing law (e.g., IT Act, 2000 in India).
1.5 Classification/Taxonomy of Cyber Crimes
| Category | Against Persons | Against Property | Against Organizations