UNIT 2: CYBER CRIME, LEGAL FRAMEWORKS, AND COUNTERMEASURES
I. FOUNDATIONS OF CYBER CRIME
A. Definition and Evolution of Cyber Crime
-
Core Definition: Cyber crime refers to any illegal activity that involves a computer, network, or the internet as a tool, target, or place of criminal conduct.
-
Evolution Drivers:
-
Internet & Mobile Proliferation: Expanded attack surface, increased data generation, and ubiquitous connectivity have made cyber crime more accessible, scalable, and profitable.
-
Anonymity & Jurisdiction: The cross-border, pseudonymous nature of the internet challenges traditional law enforcement.
-
-
Key Challenges:
-
Jurisdictional Issues: Crime originates in one country, affects another; conflicting laws.
-
Anonymity: Use of encryption, proxies, and dark web hinders attribution.
-
Technical Complexity: Rapidly evolving tools and techniques outpace legislation and investigation.
-
Evidence Volatility: Digital evidence can be easily altered or destroyed.
-
-
Elements/Characteristics:
-
Actus Reus: A voluntary act/omission involving a computer/network (e.g., unauthorized access, data alteration).
-
Mens Rea: Intent or knowledge to cause harm/gain (e.g., intent to defraud, cause damage).
-
Causation: The act must cause or be capable of causing harm (financial loss, data breach, service disruption).
-
-
Nature of Criminality in Cyberspace:
-
De-physicalization: Crime can be committed remotely without physical presence.
-
Low Risk, High Reward: Perpetrators often perceive low probability of getting caught vs. potential gain.
-
Global Impact: A single attack can have worldwide consequences.
-
[!TIP] Exam Focus: Be prepared to define cyber crime and list at least 4-5 challenges with examples (e.g., a server in India hacked from Pakistan = jurisdiction issue).
B. Cyber Criminal Profiling and Typology
-
Characteristics of Cyber Criminals: Often young, tech-savvy, motivated by financial gain, thrill, ideology, or notoriety. May operate from locations with weak cyber laws.
-
Teenage Web Vandals:
-
Motivations: Thrill-seeking, peer recognition, curiosity, rebellion, boredom.
-
Psychological/Social Factors: Low perception of risk, sense of anonymity, "online disinhibition effect," lack of ethical guidance.
-
Impact: Website defacements, service disruptions, data leaks, erosion of trust in online platforms.
-
-
Hackers vs. Crackers:
-
Hacker: Deep technical interest in exploring/comprehending systems; may break into systems for learning/curiosity (ethical intent implied).
-
Cracker: Uses skills for malicious purposes—stealing data, causing damage, financial fraud.
-
-
Hacktivists vs. Extremist Groups/Insurgents:
-
Hacktivists: Use cyber attacks for political/social causes (e.g., website defacements, DDoS to protest).
-
Extremist Groups/Insurgents: Use cyber tools for terrorism—disrupting critical infrastructure, spreading propaganda, fundraising, planning attacks.
-
-
Categories of Hackers (By Intent):
-
White Hat: Ethical security experts who find vulnerabilities with permission to fix them.
-
Grey Hat: Break into systems without malicious intent but without permission; may disclose flaws publicly.
-
Black Hat: Malicious hackers seeking personal/financial gain or causing harm.
-
Script Kiddies: Low-skilled individuals using pre-written tools/scripts to attack, lacking deep understanding.
-
[!TIP] Common Pitfall: Do not use "hacker" synonymously with "criminal." In exams, explicitly define the distinction between Hacker and Cracker.
II. CLASSIFICATION AND MECHANISMS OF CYBER CRIMES
A. Unauthorized Access & Intrusion
-
Hacking: Gaining unauthorized access to a computer system/network. Objectives: Data theft, espionage, service disruption, proving skill.
-
Common Techniques: Password cracking, exploiting software vulnerabilities (zero-days), session hijacking, social engineering.
-
Web Server Hacking (Steps):
-
Reconnaissance: Footprinting, scanning (Nmap) for open ports/services.
-
Vulnerability Assessment: Identifying weaknesses (e.g., outdated software, misconfigurations).
-
Exploitation: Using tools/exploits (e.g., SQL injection, buffer overflow) to gain access.
-
Privilege Escalation: Moving from low-level to admin/root access.
-
Maintaining Access: Installing backdoors/rootkits.
-
Covering Tracks: Deleting logs, using encryption.
-
-
Password Sniffing:
-
Packet Sniffing: Capturing network traffic (using Wireshark, Ettercap) to extract unencrypted passwords.
-
Keylogging: Installing software/hardware to record keystrokes.
-
Impact: Compromises all accounts/services using the stolen password.
-
-
Prevention: Strong passwords, encryption (HTTPS, SSH), multi-factor authentication (MFA), network segmentation, IDS/IPS.
B. Denial-of-Service (DoS/DDoS) Attacks
-
DoS (Denial of Service):
-
Mechanism: Overwhelms a target system/service with excessive requests from a single source, exhausting resources (bandwidth, CPU, memory).
-
Objective: Make service unavailable to legitimate users.
-
-
DDoS (Distributed Denial of Service):
-
Mechanism: Coordinates attack from multiple compromised systems (Botnet). Attacker controls a network of infected devices (zombies).
-
Objective: Larger-scale, harder-to-mitigate disruption. Targets infrastructure (DNS, cloud services).
-
Impact: Financial loss, reputational damage, service outage.
-
-
Common DDoS Types: Volumetric (UDP/ICMP floods), Protocol (SYN flood), Application Layer (HTTP flood).
-
Prevention/Mitigation: Rate limiting, traffic filtering (blackholing), DDoS mitigation services (Cloudflare, Akamai), robust infrastructure.
C. Fraud and Deception
-
Phishing & Spear Phishing:
-
Phishing: Mass emails/SMS pretending to be legitimate entity to steal credentials/data.
-
Spear Phishing: Highly targeted phishing using personal details to increase credibility.
-
Technique: Fake login pages, malicious attachments/links.
-
-
Email Spoofing:
-
Mechanism: Forging email headers (
From:address) to appear as a trusted source. -
Distinction from Spamming: Spamming is sending bulk unsolicited emails; spoofing is the technique used to hide the sender's true identity in phishing/spam.
-
Impact: Undermines trust in email communication, enables phishing.
-
-
Salami Technique / Salami Attack:
-
Definition: A financial fraud where tiny amounts (like "salami slices") are systematically stolen from a large number of accounts/transactions.
-
Mechanism: Modifying code to divert fractions of a cent/unit from each transaction to the attacker's account.
-
Economic Impact: Significant cumulative theft; hard to detect due to small, individually negligible amounts.
-
Example: A banking Trojan siphoning ₹0.10 from every ₹10,000 transaction.
-
-
Online Fraud General Safeguards: User awareness, verify URLs/links, never share credentials, use secure payment gateways, monitor accounts regularly.
D. Malware-Based Attacks
| Malware Type | Definition & Core Functionality | Key Mechanism & Examples |
|---|---|---|
| Virus | Malicious code that attaches to a legitimate program/file and requires user execution to spread. | Infects executable files (.exe). Types: Boot sector, file infector, macro. |
| Worm | Standalone malware that self-replicates and spreads autonomously over networks without user action. | Exploits vulnerabilities (e.g., SQL Slammer, WannaCry). Consumes bandwidth/resources. |
| Trojan Horse | Disguised as legitimate software. Does not self-replicate. Creates backdoor for remote access/data theft. | Remote Access Trojans (RATs), banking Trojans. Delivered via email/downloads. |
| Spyware | Secretly monitors user activity and collects data (browsing habits, keystrokes). | Often bundled with freeware. Sends data to attacker. |
| Keylogger | Specific type of spyware that records every keystroke. | Hardware (USB) or software. Captures passwords, messages, credit card numbers. |
E. Data & Identity Theft
-
Password Attacks:
-
Brute Force: Trying all possible combinations (time-consuming, computationally expensive).
-
Dictionary Attack: Using a list of common words/passwords.
-
Social Engineering: Tricking user into revealing password (pretexting, phishing).
-
-
Session Hijacking (Cookie Hijacking):
-
Method of Initiation: Attacker steals a valid session token/cookie after user authenticates.
-
Techniques: Packet sniffing (if not using HTTPS), cross-site scripting (XSS) to steal cookies, session fixation.
-
Impact: Attacker impersonates the legitimate user on the website/application.
-
F. Wireless Network Attacks
-
Wi-Fi Sniffing: Capturing wireless traffic using tools (Aircrack-ng, Kismet). Can intercept unencrypted data.
-
Rogue Access Point (Evil Twin): An unauthorized AP set up with the same SSID as a legitimate network to lure users and intercept traffic.
-
Man-in-the-Middle (MitM) on Wireless:
-
Execution: Attacker positions themselves between user and AP (e.g., via ARP spoofing on a shared network, or via a rogue AP).
-
Impact: Eavesdropping, data alteration, session hijacking, credential theft.
-
G. Content-Related Offences
-
Spamming: Sending bulk unsolicited messages (Email, SMS, Social Media). Impact: Clogs networks, phishing vector, wastes productivity, spreads malware.
-
Cyber Defamation & Harassment:
-
Defamation: Publishing false statements online harming a person's reputation. Provision: IT Act Section 66A (now struck down) was used; now prosecuted under IPC Sections 499, 500.
-
Harassment: Threatening, offensive communication online (stalking, abusive messages). Covered under IT Act and IPC.
-
-
Email Abuse: General misuse of email (forgery, sending threats, obscene material). Broader than defamation.
H. Intellectual Property & Theft
-
Software Piracy: Unauthorized copying, distribution, or use of copyrighted software.
- Major Contributing Factors: High cost of genuine software, lax enforcement, cultural acceptance, ease of digital copying.
-
Forms of Piracy:
-
Softlifting: Installing a single licensed copy on multiple machines.
-
Counterlifting: Selling counterfeit copies with fake labels/packaging.
-
Online Piracy: Downloading/sharing via torrents, warez sites, peer-to-peer networks.
-
-
Internet Time Theft: Unauthorized use of someone else's paid internet connection (e.g., hacking into a Wi-Fi network). A form of service theft.
I. Web Jacking & Cyber Terrorism
-
Web Jacking:
-
Definition: Taking control of a website (not just defacing) by hijacking the domain name or server credentials. The attacker redirects traffic or holds the site for ransom.
-
Differentiation from Hacking: Goal is control/ownership, not just data theft or defacement.
-
Exploited Vulnerabilities: Weak domain registrar security, stolen admin credentials, DNS hijacking.
-
Impact: Loss of business, reputational damage, ransom demands.
-
-
Cyber Terrorism: Use of cyber attacks to cause fear, violence, or disruption for political/ideological goals. Theft in this context could be stealing sensitive data (e.g., defense plans) or funds.
-
Web Server Hacking (Prevention):
- Steps: Regular patching, secure configuration (disable unused services), firewalls, WAF (Web Application Firewall), intrusion detection, strong authentication, log monitoring, regular backups.
[!TIP] High-Frequency Link: Web Jacking is a frequent 7-mark question. Always differentiate it from simple hacking/defacement and mention DNS/domain hijacking as a key method.
III. LEGAL FRAMEWORKS: THE INFORMATION TECHNOLOGY ACT, 2000 (INDIA)
A. Overview and Objectives
-
Need: To provide legal recognition for electronic transactions, digital signatures, and to curb cyber crimes.
-
Positive Aspects: Legal validity for e-contracts/documents, defined cyber offences, adjudication framework, foundation for e-governance.
B. Key Offences and Penalties (Selected Sections)
| Section | Offence | Key Provision & Penalty |
|---|---|---|
| 43 | Damage to computer/system | Compensation to the affected person for unauthorized access, data alteration, disruption. (Civil liability). |
| 66 | Hacking | Imprisonment up to 3 years or fine (may extend to ₹5 lakh) or both. (Criminal liability). |
| 66A | Sending offensive messages | Imprisonment up to 3 years and fine. (Note: Supreme Court struck it down in 2015 as unconstitutional). |
| 66C | Identity theft (fraudulent use of electronic signature/password) | Imprisonment up to 3 years and fine (up to ₹1 lakh). |
| 66D | Cheating by personation using computer | Imprisonment up to 3 years and fine (up to ₹1 lakh). |
| 67 | Publishing obscene material in electronic form | First conviction: Imprisonment up to 3 years & fine (₹5 lakh). Subsequent: Up to 5 years & fine (₹10 lakh). |
| 67A | Publishing material depicting children in sexually explicit act | First: Up to 5 years & fine (₹10 lakh). Subsequent: Up to 7 years & fine (₹10 lakh). |
| 68 | Failure to comply with orders of Controller/Adjudicating Officer | Imprisonment up to 3 years or fine or both. |
-
Monetary Penalties: Amounts vary by section (e.g., up to ₹1 lakh for 66C/66D, up to ₹10 lakh for 67A). Section 43 provides for compensatory damages.
-
Adjudication Mechanism (Section 61):
-
Adjudicating Officer: Appointed by Central/State Government (not below rank of Director/Addl. Director).
-
Powers: Determine penalty under Sections 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 56, 57, 58, 59, 60.
-
Process: Inquiry, opportunity of hearing, order with reasons. Can impose penalty and order compensation.
-
C. Cyber Regulations Appellate Tribunal (CRAT)
-
Role: Appellate body against orders of Adjudicating Officers (under IT Act) and Controller (under Digital Signature Certificates).
-
Function: hears appeals, has powers of a civil court. Provides quicker resolution than regular courts for cyber disputes.
D. Electronic Governance and Contracts
-
Electronic Agreements: Valid and enforceable under IT Act Section 10-A (inserted by 2008 amendment) and Indian Contract Act, 1872 (meets offer, acceptance, consideration, free consent).
-
Proof of Electronic Agreements: Treated as electronic records under IT Act. admissible as evidence if conditions of Section 65B are met (see Unit IV).
-
Digital Signatures:
-
Legal Recognition: IT Act grants legal recognition to digital signatures (Section 3).
-
Role: Ensures authentication, integrity, and non-repudiation of electronic records.
-
Probative Value: A digitally signed document is presumed to be genuine and unaltered (Section 79). Strong evidence in court.
-
IV. ELECTRONIC EVIDENCE: LEGAL EVOLUTION AND MANAGEMENT
A. Evolution: Indian Evidence Act, 1872 vs. IT Act, 2000
| Aspect | Indian Evidence Act, 1872 | Information Technology Act, 2000 (Amendments) |
|---|---|---|
| Document Definition | "Document" meant physical writing, inscription, etc. | Added "electronic record" (Section 2(t)): data, record, image, sound stored/processed electronically. |
| Primary Evidence | Original document produced in court. | Electronic record printed/ stored on media is primary evidence (Section 65B(1)). |
| Secondary Evidence | Certified copies, oral evidence. | Printout/CD of electronic record is admissible as secondary evidence if Section 65B conditions are met. |
| Hearsay Rule | Strict; oral evidence of document content generally not allowed. | Section 65B creates a statutory exception for electronic records, bypassing hearsay concerns if procedure followed. |
B. Status and Admissibility of Electronic Records
-
Definition: Electronic Record (Sec 2(t)): data, record, image, sound stored/processed electronically. Electronic Evidence: Information derived from such records used in court.
-
Conditions for Admissibility (Section 65B):
-
The computer/device was regularly used by the person having lawful control.
-
The data was regularly fed into the computer in the ordinary course.
-
The computer was operating properly throughout the relevant period.
-
The duplicate copy (printout, CD) is a true reproduction of the original electronic record.
-
Certificate (Section 65B(4)): Must be signed by a person responsible for the computer's operation, detailing the process of extraction/reproduction.
-
-
Proof & Management: Must establish chain of custody and integrity. Certificate under 65B is crucial for court acceptance.
C. Chain of Custody in Digital Forensics
-
Concept: A documented, unbroken chronological record of the seizure, custody, control, transfer, analysis, and storage of digital evidence.
-
Critical Importance:
-
Forensic Soundness: Proves evidence is the same as collected, not altered.
-
Court Acceptance: Essential for establishing authenticity and reliability. Any break can lead to evidence being inadmissible.
-
Accountability: Tracks who handled evidence and when.
-
D. Role of Digital Signatures in Evidence
-
Authentication: Verifies the origin (who signed) and integrity (not altered after signing) of an electronic record.
-
Probative Value (Section 79): A presumption in favor of a digitally signed document being genuine. Shifts burden of proof to the challenger to show tampering.
-
Establishing Non-Repudiation: Signer cannot later deny having signed the document.
[!TIP] Exam Killer: Section 65B is VERY HIGH FREQUENCY. Memorize its 4-5 conditions and the requirement of a certificate. Contrast it with the old Evidence Act's treatment of "documents."
V. TACKLING CYBER CRIME: STRATEGIES AND TOOLS
A. Comprehensive Strategies to Tackle Cyber Crime
-
Legal/Regulatory:
-
Robust, updated laws (like IT Act).
-
Specialized cyber courts/tribunals (CRAT).
-
International treaties (Budapest Convention) for cross-border cooperation.
-
-
Technical:
-
Preventive: Firewalls, IDS/IPS, encryption, MFA, patch management.
-
Detective: SIEM, log analysis, forensic tools.
-
Responsive: Incident response teams, malware analysis, system restoration.
-
-
Educational/Awareness:
-
Public campaigns on safe internet use, phishing recognition.
-
Training for law enforcement, judiciary on cyber forensics and law.
-
Cyber hygiene education in schools/colleges.
-
-
International Cooperation:
-
Challenges: Different legal systems, extradition hurdles, lack of harmonized laws, evidence sharing protocols.
-
Need: Mutual Legal Assistance Treaties (MLATs), joint cyber crime units, real-time threat intelligence sharing (e.g., Interpol's I-24/7).
-
B. Technical Countermeasures and Privacy Tools
-
Proxy Servers:
-
Function: Intermediary server between client and internet. Forwards requests, hides client's IP from the destination server.
-
Types:
-
Forward Proxy: Serves internal clients accessing external internet.
-
Reverse Proxy: Serves external clients accessing internal servers (load balancing, security).
-
Anonymous Proxy: Hides client's IP address from the destination server.
-
-
Role: Access control, caching, content filtering, basic anonymity.
-
-
Anonymizers:
-
Function: Tools/services (like Tor, VPNs) that encrypt traffic and route it through multiple nodes, making traffic analysis and IP tracing extremely difficult.
-
Purpose: Strong anonymity, bypassing censorship, protecting privacy.
-
Distinction from Proxy:
-
Proxy: Single hop; may not encrypt traffic; server can see original request.
-
Anonymizer (Tor/VPN): Multi-hop, strong encryption, no single node knows both source and destination. Higher effectiveness for anonymity.
-
-
-
General Prevention for Specific Attacks:
-
Web Jacking: Strong domain registrar security (2FA), DNSSEC, monitor DNS records.
-
Network Intrusions: Network segmentation, least privilege, regular vulnerability scanning, network access control (NAC).
-
Wireless Attacks: Use WPA3, disable WPS, use enterprise authentication, monitor for rogue APs, use VPN on public Wi-Fi.
-
[!TIP] High-Frequency Comparison: Proxy vs. Anonymizer is a classic question. Emphasize: Proxy = single hop, basic IP hiding. Anonymizer (Tor/VPN) = multi-hop + encryption, strong anonymity.
\boxed{\text{Study Focus: IT Act Sections (43, 66, 66C/D, 67), Section 65B (Electronic Evidence), DDoS vs DoS, Proxy vs Anonymizer, Salami Technique, Web Jacking, Hacker Types}}