Skip to content
CY-402 · Fundamental of Cyber Security/Quick Revision Short Notes

Fundamental of Cyber Security (CY-402) - Unit 4 Short Notes

UNIT 4: CYBER CRIME, LEGAL FRAMEWORK, AND COUNTERMEASURES


I. FOUNDATIONS OF CYBER CRIME

Definition and Evolution of Cyber Crime

  • Definition: Cyber crime refers to any illegal activity that involves a computer, a network, or the internet. It encompasses crimes where the computer is the tool (e.g., fraud, harassment) and crimes where the computer is the target (e.g., hacking, malware).

  • Evolution & Influence of Technology:

    • Pre-Internet: Limited to standalone systems (e.g., software piracy via floppy disks, physical access attacks).

    • Post-Internet/Mobile Proliferation: Explosion in scale, anonymity, and attack vectors.

      • Internet: Enabled global, remote attacks (phishing, DDoS, web defacement).

      • Mobile Devices: Created new vulnerabilities (SMS phishing, mobile malware, app-based fraud).

    • Nature of Criminality: Shift from localized, identifiable actors to a borderless, often anonymous digital realm where motivation (financial, ideological, thrill) often defines the criminal more than geography.

Challenges and Elements of Cyber Crime

  • Key Challenges:

    • Jurisdiction: Difficulty in determining which country's laws apply for cross-border crimes.

    • Anonymity: Use of proxies, dark web, encryption to hide identity.

    • Technical Complexity: Requires specialized knowledge for investigation and prosecution.

    • Lack of International Cooperation: Varying legal frameworks and extradition treaties.

    • Rapid Technological Change: Laws and defenses often lag behind new attack methods.

  • Fundamental Elements of a Cyber Offence:

    1. Actus Reus (Guilty Act): The technical act (e.g., unauthorized access, data alteration).

    2. Mens Rea (Guilty Mind): Intent or knowledge to commit the crime.

    3. Causation: The act must cause harm or have the potential to cause harm.

    4. Absence of Consent/Legality: The act is without lawful authority or consent.

Classification and Taxonomy of Cyber Crimes

Category Sub-Category & Examples Key Characteristics
Crimes Against Property & Finance Software Piracy:<br>• Softlifting: Copying software for personal use.<br>• Counterfeiting: Duplicating & selling fake copies.<br>• Online Piracy: Illegal distribution via websites/P2P.<br>Salami Attack: Slicing small amounts (e.g., rounding down transactions) from multiple accounts.<br>Internet Time Theft: Unauthorized use of paid internet/wifi.<br>Cyber Fraud: General deception for financial gain (e.g., online shopping scams, lottery fraud). Financial loss to individuals/companies. Often involves deception or unauthorized resource use.
Crimes Against Individuals & Communication Email Spoofing: Faking email headers to appear from legitimate source.<br>Spamming: Sending unsolicited bulk messages (email, SMS, social media).<br>Cyber Defamation/Harassment: Publishing false info/abusive content online.<br>Phishing: Deceptive emails/websites to steal credentials/data. Target individuals directly. Exploit trust and communication channels. High psychological impact.
Crimes Against Systems & Infrastructure Hacking: Unauthorized access to systems/network.<br>Password Sniffing: Capturing passwords via network monitoring.<br>Web Server Hacking: Steps: Recon → Scan → Gain Access → Maintain Access → Cover Tracks.<br>Web Jacking: Taking control of a website & redirecting its traffic.<br>Session Hijacking: Stealing a valid session token to impersonate a user.<br>Wireless Attacks: Wi-Fi sniffing, rogue APs, Man-in-the-Middle (MitM).<br>DoS/DDoS: Overwhelming a service to make it unavailable. Target IT infrastructure, data confidentiality, integrity, and availability (CIA triad).
Malware & Intrusive Tools Viruses: Attach to clean files, require user execution.<br>Worms: Self-replicate & spread via networks, no host file needed.<br>Trojan Horses: Disguised as legitimate software, create backdoors.<br>Spyware/Keyloggers: Secretly monitor activity & record keystrokes. Software-based threats designed to damage, steal, or control systems.

Profiles and Motivations of Cyber Criminals

  • Characteristics: Often young, tech-savvy, operate from locations with weak law enforcement. Can be lone actors or part of organized groups.

  • Motivations:

    • Financial Gain: Most common (fraud, ransomware, data theft).

    • Thrill/Challenge/Ego: "Joyriding," proving skill (common in Teenage Web Vandals).

    • Ideology/Politics: Hacktivism (e.g., Anonymous), cyber terrorism.

    • Revenge/Disgruntlement: Insider threats, ex-employee attacks.

    • Status/Recognition: Within criminal or hacking communities.

  • Teenage Web Vandals: Typically adolescents motivated by thrill, peer recognition, and curiosity. Factors: easy access to hacking tools, lack of awareness about consequences, perception of low risk, social/psychological issues (seeking identity/power).

  • Hackers vs. Extremist Groups/Insurgents:

    • Hackers: Often individual/small group, motivations vary (financial, ego, ideology). May follow a personal code.

    • Extremist Groups/Insurgents: Organized, politically/ideologically driven. Use cyber tools for propaganda, fundraising, communication disruption, and espionage. Goals are strategic, not just technical.


II. LEGAL FRAMEWORK: THE INFORMATION TECHNOLOGY ACT, 2000 (INDIA)

Overview and Objectives

  • Need: To provide legal recognition for electronic transactions, digital signatures, and to define cyber offences as traditional laws (IPC) were inadequate.

  • Major Objectives:

    1. Legal validity of electronic records/digital signatures.

    2. Regulation of Certifying Authorities (CAs).

    3. Definition of cyber crimes and penalties.

    4. Establishment of appellate tribunals.

  • Positive Aspects: Pioneering legislation, foundation for e-governance, specific provisions for emerging crimes (publishing obscene info, hacking).

Key Provisions Addressing Cyber Crimes

Section Offence Key Description
43 Penalty & Compensation Unauthorized access, download, disruption, etc. Civil liability (compensation to victim).
66 Hacking Criminal offence. Voluntarily accessing a computer with intent to cause loss/damage. Punishment: Up to 3 years or fine.
66A Sending Offensive Messages [Struck down by Supreme Court in 2015 as unconstitutional]
66B Receiving Stolen Computer/Device Dishonestly receiving/retaining stolen computer/comm device.
66C Fraudulent Use of Electronic Signature/Password Using another's electronic signature/password fraudulently.
66D Cheating by Personation Cheating using computer/communication device.
66E Violation of Privacy Capturing/publishing private images without consent.
66F Cyber Terrorism Accessing computer/system to threaten national unity/integrity/security.
67 Publishing Obscene Information Publishing/transmitting obscene material in electronic form.
67A Publishing Sexually Explicit Content Publishing/transmitting material depicting children in sexually explicit acts.
67B Publishing Information about Children Publishing info that could be used to groom or abuse children.

Penalties, Adjudication, and Enforcement

  • Monetary Penalties: Vary by offence. For example:

    • Section 43: Compensation determined by Adjudicating Officer (up to ₹1 Crore).

    • Section 66 & 66C-F: Imprisonment up to 3-5 years and/or fine (amount not always specified, left to court).

  • Adjudication Mechanism:

    • Adjudicating Officer: Secretary to Govt. (IT Dept.) at state/central level. Decides on compensation under Sec 43.

    • Appellate Tribunal: For appeals against Adjudicating Officer's orders. Further appeal to High Court.

    • Criminal Courts: For offences under Sec 66-67B (imprisonment cases).

  • Powers of Investigation:

    • Police Officer (not below Inspector rank): Can investigate offences, search/seize without warrant (subject to conditions).

    • Controller of Certifying Authorities: Regulates CAs.

    • IT Secretary/Adjudicating Officer: Can issue directions for compliance.

Electronic Governance and Agreements

  • Validation of Electronic Agreements: Section 10A (inserted by 2008 Amendment) explicitly states that contracts formed through electronic communication are valid and enforceable.

  • Enforceability Linkages:

    • Indian Contract Act, 1872: Principles of offer, acceptance, consideration, free consent still apply. Electronic records satisfy "writing" requirement.

    • IT Act: Provides legal recognition to electronic records (Sec 4) and digital signatures (Sec 5).

  • Digital Signatures: Asymmetric cryptography-based, provides authentication, integrity, and non-repudiation. Legally equivalent to handwritten signatures (Sec 5).

  • E-Signatures (under IT Act): Broader term including digital signatures and other notified forms (e.g., Aadhaar-based e-KYC). Have legal validity.


III. DIGITAL EVIDENCE AND LEGAL PROCEDURE

Evolution of Evidence Law: IEA 1872 vs. IT Act 2000

Aspect Indian Evidence Act, 1872 Information Technology Act, 2000
Definition of "Document" Only tangible, physical documents. Expanded to include electronic records (Sec 2(t)).
Proof of Documents Primary (original) and secondary (copies) evidence rules. Electronic records are admissible if Section 65B conditions are met (certificate of authenticity).
Relevancy Based on physical/oral testimony. Explicitly includes electronic records as relevant facts.
Key Change Did not contemplate digital evidence. Amended IEA to incorporate Sec 65A (special provisions for electronic evidence) and Sec 65B (admissibility of electronic records).

Status and Management of Electronic Records as Evidence

  • Legal Status: Electronic records (emails, SMS, logs, database entries, files) are documents under Sec 2(t) of IT Act and are admissible in court.

  • Proof & Management (Sec 65B): For an electronic record to be admissible without producing the original device, a certificate under Sec 65B(4) is mandatory. The certificate must:

    1. Identify the electronic record.

    2. Describe how it was produced.

    3. State that the computer/system was in regular use and properly operated.

    4. State that the information was fed in the ordinary course.

    5. Be signed by a person in responsible official position.

  • Relevancy & Admissibility: Must be relevant to the case. The court assesses authenticity, reliability, and integrity (was it tampered?).

Digital Signatures and E-Signatures in Evidence

  • Digital Signature (PKI-based): Provides strong probative value.

    • Authentication: Confirms the signer's identity.

    • Integrity: Detects any alteration after signing.

    • Non-Repudiation: Signer cannot deny signing.

    • Legal Presumption: Courts may presume that a digital signature was affixed by the subscriber (Sec 79A of IT Act rules).

  • E-Signatures (notified): May have lower assurance than digital signatures but are still legally valid if they meet the notified standards (e.g., Aadhaar e-Sign). Probative value depends on the technology's reliability.

Chain of Custody in Digital Forensics

  • Concept: A documented, unbroken chronological record of the control, transfer, analysis, and disposition of digital evidence from seizure to presentation in court.

  • Critical Relationship to Admissibility: A broken or poorly documented chain raises doubts about evidence integrity and authenticity. The prosecution must prove the evidence presented is the same as seized and has not been altered. Sec 65B certificate implicitly addresses this by attesting to the system's integrity.

Judicial Assessment of Electronic Evidence

Courts evaluate based on:

  1. Source & Integrity: Was the source reliable? Is there a Sec 65B certificate?

  2. Generation & Storage: How was the record created/stored? Were proper security measures in place?

  3. Transmission: If transmitted, was the channel secure? Any evidence of interception?

  4. Access & Control: Who had access? Can tampering be ruled out?

  5. Compliance with Sec 65B: Is the certificate complete and from a responsible person?

  6. Corroboration: Is there other evidence supporting the electronic record?


IV. COUNTERMEASURES, STRATEGIES, AND TOOLS

General Strategies to Tackle Cyber Crime

  • Multi-Stakeholder Approach:

    • Government: Enact/update laws, establish CERT-In, cyber cells, international treaties.

    • Industry/Organizations: Implement security policies, employee training, incident response teams.

    • Individuals: Practice cyber hygiene, use security software, report incidents.

  • Three-Pillar Strategy:

    1. Legal: Robust laws (IT Act), swift prosecution, international cooperation.

    2. Technical: Deploy security tools, patch systems, secure configurations.

    3. Awareness: User education on threats (phishing, piracy), ethical use.

Technical Countermeasures and Prevention

Attack/Threat Prevention/Mitigation Strategies
Web Jacking • Use strong, unique passwords & 2FA for admin panels.<br>• Regularly update CMS/plugins.<br>• Implement Web Application Firewalls (WAF).<br>• Monitor DNS records for unauthorized changes.<br>• Restrict admin access by IP.
Spamming • Use email filtering/spam traps.<br>• Implement Sender Policy Framework (SPF), DKIM, DMARC.<br>• User education on not clicking links/opening attachments.<br>• Report spam to ISPs.
Phishing • User awareness (check URLs, sender addresses).<br>• Anti-phishing toolbars/browser features.<br>• Email security gateways.<br>• Multi-Factor Authentication (MFA).
Password Sniffing • Use encrypted protocols (HTTPS, SSH, SFTP).<br>• VPNs for remote access.<br>• Network segmentation.<br>• Avoid public Wi-Fi for sensitive transactions; use personal hotspot or VPN.
Web Server Hacking • Hardening: Remove unnecessary services, change defaults.<br>• Regular Patching of OS, web server, applications.<br>• Secure Configuration: Least privilege, strong passwords, disable directory listing.<br>• WAF & IDS/IPS to detect/block attacks.<br>• Regular Security Audits & Penetration Testing.
DoS/DDoS • Rate Limiting at network/application level.<br>• DDoS Mitigation Services (Cloudflare, Akamai).<br>• Traffic Scrubbing centers.<br>• Load Balancers & Redundant Servers to distribute traffic.<br>• Blackholing/Routing malicious traffic to null route.
Wireless Attacks • WPA3/WPA2-PSK (AES) encryption.<br>• Strong, unique passwords for Wi-Fi.<br>• Disable WPS (vulnerable).<br>• MAC Address Filtering (supplemental).<br>• Rogue AP Detection via Wireless IDS.<br>• Use of Enterprise Authentication (802.1X) for organizations.<br>• VPN for all public Wi-Fi use.

Tools and Technologies

  • Proxy Servers: Intermediate server between client & internet.

    • Function: Can cache content, filter requests, hide client IP from destination server.

    • Role: Basic privacy, content filtering, access control. Does not encrypt traffic between client and proxy.

  • Anonymizers (e.g., Tor, I2P):

    • Function: Route traffic through multiple, encrypted volunteer relays (onion routing). Hides both source IP and destination from any single relay.

    • Distinction from Proxies: Provides stronger anonymity through multi-layer encryption and distributed network. Can bypass censorship but may be slower. Proxies are single-hop and often controlled by a single entity.

  • Firewalls: Network security device (hardware/software) that monitors and controls incoming/outgoing traffic based on predetermined security rules.

  • Intrusion Detection System (IDS): Monitors network/system for malicious activity and alerts administrators (e.g., Snort).

  • Intrusion Prevention System (IPS): Actively monitors and can automatically block/prevent detected threats in real-time. Often inline with traffic.

Role of Awareness and Education

  • Combat Social Engineering (Phishing, Spoofing): Teach users to verify senders, check URLs, avoid urgent requests for credentials/data.

  • Curb Software Piracy & Vandalism: Promote understanding of intellectual property rights and ethical use of technology. Highlight legal penalties and security risks (malware in pirated software).

  • General Cyber Hygiene: Strong passwords, MFA, software updates, data backup, safe browsing habits.


V. EMERGING TRENDS & SYNTHESIS

Trends in Cyber Crime (from exam context)

  • Targeted Attacks & APTs: Moving from broad spam to spear-phishing, tailored malware.

  • Ransomware-as-a-Service (RaaS): Lowering barrier to entry for cybercriminals.

  • Cryptocurrency in Crime: Used for ransom payments, money laundering.

  • IoT-Based Attacks: Exploiting vulnerabilities in smart devices (cameras, appliances).

  • AI-Powered Attacks: Automated phishing, deepfakes for fraud/disinformation.

  • Supply Chain Attacks: Targeting software vendors to reach multiple victims (e.g., SolarWinds).

Impact of Cyber Crime

  • Individuals: Financial loss, identity theft, emotional distress, reputational damage.

  • Organizations: Financial losses (fraud, ransom), operational disruption, data breach costs, reputational harm, regulatory fines.

  • National Infrastructure: Threat to power grids, banking, defense systems, public services (cyber terrorism). Compromises national security and sovereignty.

Interconnection of Topics

  • Legal Gaps Enable Crime: Lack of international cooperation/jurisdiction allows criminals to operate from safe havens.

  • Technical Measures Need Legal Backing: Effective investigation/prosecution requires admissible digital evidence (Chain of Custody, Sec 65B).

  • Awareness Supports Both: User education reduces success of social engineering, complementing technical controls like firewalls/IDS.

  • Example Synthesis: A phishing attack (technical crime) leads to financial fraud. To prosecute:

    1. Technical: Email headers/IP logs must be preserved with proper chain of custody.

    2. Legal: Offence falls under IT Act Sec 66D/420 IPC. Evidence must meet Sec 65B for admissibility.

    3. Strategy: Prevention relies on user awareness and MFA.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in