UNIT 5: FUNDAMENTALS OF CYBER SECURITY
I. CYBERCRIME & CRIMINALITY (FOUNDATIONS)
Definition & Conceptualization of Cyber Crime
-
Core Definition: Any illegal activity that involves a computer, its systems, or networks as a tool, target, or place of criminal conduct. It encompasses crimes where technology is central to the act.
-
Evolution & Growth: Driven by:
-
Proliferation of the internet and mobile devices.
-
Increased digital dependency for commerce, communication, and governance.
-
Anonymity and borderless nature of cyberspace.
-
-
Key Elements:
-
Actus Reus: The wrongful act (e.g., hacking, data theft).
-
Mens Rea: The criminal intent or knowledge.
-
Causation: Link between the act and the harm.
-
Computer/Network Involvement: The use of a computing device or network is indispensable.
-
Challenges & Nature of Cyber Crime
-
Jurisdictional Challenges: Cybercrime often crosses international borders. Lack of harmonized global laws and mutual legal assistance treaties (MLATs) create enforcement gaps.
-
Technical Complexities & Anonymity: Use of encryption, proxy chains, and cryptocurrencies (e.g., Bitcoin) obscures attacker identity and traceability.
-
Nature of Criminality: The virtual environment alters traditional crime dynamics.
-
Example 1: A salami attack (financial fraud) causes aggregate economic damage without individual victims noticing immediately.
-
Example 2: Cyber defamation can have a viral, permanent impact on reputation, unlike physical defamation.
-
Cybercriminals: Profiles & Motivations
-
Hackers Classification:
| Hat Color | Primary Motivation | Typical Activity | Ethical Stance | | :--- | :--- | :--- | :--- | | White Hat | Security testing, improvement (with permission) | Penetration testing, vulnerability research | Ethical/Lawful | | Black Hat | Personal gain, fame, malice, espionage | Unauthorized access, data theft, malware | Unethical/Illegal | | Grey Hat | Mixed motives; may violate laws but no malicious intent | Unauthorized access to expose vulnerabilities, may demand payment for fixes | Ambiguous |
-
Extremist/Insurgent Groups: Motivated by ideology. Objectives include propaganda dissemination, fundraising (via crypto), recruitment, and launching disruptive attacks (e.g., DDoS) against state/corporate targets.
-
Teenage Web Vandals:
-
Motivations: Thrill-seeking, peer recognition, curiosity, rebellion, perceived low risk of punishment.
-
Psychological/Social Factors: Identity exploration, sense of power in a virtual space, lack of awareness about consequences, influence of online subcultures.
-
Impact: Defacement of websites, disruption of services, erosion of trust in digital platforms.
-
II. TAXONOMY OF CYBERCRIMES & ATTACK VECTORS
Fraud & Financial Crimes
-
Online Fraud: Broad category using deception for financial gain (e.g., advance fee fraud, identity theft, auction fraud). Safeguarding: User awareness, multi-factor authentication (MFA), secure payment gateways.
-
Salami Technique:
-
Concept: Slicing off small, often negligible, amounts of money from a large number of accounts/transactions.
-
Mechanism: Exploiting system rounding errors or automated transaction processing. The aggregate sum is significant.
-
Example: A bank employee writes a program to deduct 0.05¢ from every customer's interest calculation and credits it to a personal account.
-
-
Software Piracy:
-
Definition: Unauthorized copying, distribution, or use of copyrighted software.
-
Forms & Persistence Factors:
| Form | Description | Persistence Factors | | :--- | :--- | :--- | | Softlifting | Installing a single licensed copy on multiple machines | Cost, convenience, casual attitude | | Counterlifting | Selling illegal copies as originals | Profit motive, weak enforcement | | Online Piracy | Downloading/distributing via P2P, torrents, cracking sites | Anonymity, global reach, high-speed internet |
-
-
Internet Time Theft: Unauthorized use of another's paid internet connection (e.g., Wi-Fi piggybacking). Example: Using a neighbor's unsecured Wi-Fi without permission.
Communication-Based Attacks
-
Email-Based Crimes:
-
Email Spoofing: Forging email headers (From, Return-Path) to make an email appear as if it originates from a trusted source. Impact: Phishing, reputation damage, bypassing spam filters.
-
Spamming: Sending bulk, unsolicited messages (email, SMS, social media). Impact: Clogs networks/inboxes, phishing vector, malware distribution, productivity loss.
-
Distinction: Spoofing vs. Spamming
| Feature | Email Spoofing | Spamming | | :--- | :--- | :--- | | Primary Goal | Deception, impersonation | Mass dissemination | | Volume | Can be targeted, low-volume | Inherently high-volume | | Method | Header forgery | Bulk sending (may or may not spoof) |
-
-
Phishing: Social engineering attack using deceptive communications (email, SMS, websites) to trick victims into revealing sensitive data (credentials, credit card numbers) or installing malware.
Network & Infrastructure Attacks
-
DoS & DDoS:
-
Mechanism: DoS: Single source floods a target (server, network) with traffic/requests to exhaust resources (bandwidth, CPU). DDoS: Coordinated attack from multiple compromised systems (botnet).
-
Objectives: Disrupt services, cause financial loss, distract from another attack, extortion.
-
Impact: Service unavailability, reputational damage, revenue loss.
-
-
Network Intrusion Techniques:
-
General Methods: Exploiting vulnerabilities, weak authentication, misconfigurations.
-
Prevention: Firewalls, IDS/IPS, network segmentation, strong authentication, regular patching.
-
Password Sniffing: Capturing passwords as they travel over a network.
-
Techniques: Using packet sniffers (e.g., Wireshark) on unencrypted traffic (HTTP, FTP, Telnet), ARP poisoning on LANs.
-
Data Compromise: Direct theft of credentials for subsequent unauthorized access.
-
-
Wireless Network Attacks:
-
Wi-Fi Sniffing: Capturing wireless packets to read unencrypted data or crack encryption (WEP/WPA).
-
Rogue Access Point (Evil Twin): Unauthorized AP set up to mimic a legitimate one, tricking users to connect.
-
Man-in-the-Middle (MITM): Attacker intercepts and potentially alters communication between two parties (e.g., via ARP spoofing on Wi-Fi).
-
-
Session Hijacking: Taking over a valid, authenticated user session.
- Initiation Methods: Predicting/stealing session tokens (from cookies, URLs), IP spoofing, cross-site scripting (XSS) to steal cookies.
-
Web & System Compromise
-
Web Jacking:
-
Definition: Forcible takeover of a victim's website by compromising credentials or exploiting vulnerabilities, followed by redirection or defacement.
-
Differentiation from Hacking: Web jacking is a specific type of hacking focused on taking control and redirecting a website, often for ransom or political statement. Traditional hacking may have broader goals (data theft, espionage).
-
Techniques/Vulnerabilities: Password brute-forcing, SQL injection, XSS, exploiting unpatched CMS/plugins.
-
Implications: Loss of control, brand damage, phishing via the legitimate URL, revenue loss.
-
Countermeasures: Strong, unique passwords, MFA, regular software updates, web application firewall (WAF), intrusion detection.
-
-
Web Server Hacking:
-
Steps: Reconnaissance → Vulnerability Scanning (e.g., using Nikto) → Exploitation (e.g., buffer overflow, command injection) → Privilege Escalation → Maintenance (backdoors) → Cleanup.
-
Preventive Measures: Harden OS/server, disable unnecessary services, apply patches, use WAF, configure logging/monitoring, least privilege principle.
-
Malware & Surveillance
-
Viruses & Worms:
-
Evolution: From simple boot-sector viruses to polymorphic, file-infecting, macro, and ransomware variants. Worms are self-replicating without user action.
-
Challenges: Polymorphism (changes code to evade signature detection), zero-day exploits, fileless malware, rapid propagation.
-
Types: File infector, macro, boot sector, polymorphic, metamorphic, ransomware, worm.
-
-
Trojan Horses: Malicious code disguised as legitimate software. Functionality: Creates backdoors, steals data, downloads other malware, spies on user activity. Does not self-replicate.
-
Spyware & Keyloggers:
-
Spyware: Software that secretly gathers user information (browsing habits, credentials) and transmits it to a third party.
-
Keyloggers: Specific type of spyware that records keystrokes.
-
Difference: All keyloggers are spyware, but not all spyware logs keystrokes (some monitor screens, network traffic).
-
Other Specific Offences
-
Cyber Defamation & Harassment: Publishing false, injurious statements online with intent to harm reputation. Provision: Addressed under Section 499 of IPC (read with Section 66A of IT Act, though Section 66A was struck down by SC in Shreya Singhal v. Union of India; now prosecuted under IPC and Section 67 for offensive content).
-
E-mail Abuse: Broad term covering unsolicited commercial email (spam), threatening emails, email bombs. Differentiation from Defamation: Defamation requires a false statement harming reputation. Email abuse includes non-defamatory but unwanted or malicious communications (e.g., threats, spam).
III. LEGAL FRAMEWORK: INFORMATION TECHNOLOGY ACT, 2000 (INDIA)
Overview & Objectives
-
Purpose: To provide legal recognition for electronic transactions, facilitate e-governance, and define cyber offences.
-
Positive Aspects:
-
Legal validity of electronic records/digital signatures.
-
Defined offences and penalties.
-
Framework for regulation of Certifying Authorities (CAs).
-
Provisions for interception, monitoring (Section 69) for national security.
-
Key Provisions Addressing Cyber Crimes
| Section | Offence / Provision | Key Purpose |
|---|---|---|
| 43 | Penalty & Compensation for damage to computer, etc. | Civil liability for unauthorized access, damage, theft. |
| 66 | Computer Related Offences | Punishment for acts covered under Sec 43 (criminal version). |
| 66A | Punishment for sending offensive messages (Struck down) | Formerly for grossly offensive/menacing information. |
| 66C | Punishment for identity theft | Fraudulent use of electronic signature/password. |
| 66D | Punishment for cheating by personation | Cheating using computer resource. |
| 67 | Punishment for publishing/transmitting obscene material | Obscene content in electronic form. |
| 68 | Power to issue directions for blocking access | To block public access to information. |
| 69 | Power to intercept, monitor, decrypt | For national security, public order, investigation. |
| 70 | Protected Systems & Critical Information Infrastructure | Unauthorized access to protected systems is punishable. |
Penalties & Adjudication
-
Monetary Penalties: Vary by offence. For Sec 43/66, compensation up to ₹1 Crore to the affected party. For Sec 66C/D, imprisonment up to 3 years and fine. For Sec 67, up to 5 years and fine up to ₹10 lakh.
-
Adjudication: Secretary, Department of Information Technology (or authorized officer) adjudicates compensation claims under Sec 43. Criminal offences under Sec 66-67 are tried by Judicial Magistrate of First Class.
Digital Signatures & Electronic Governance
-
Digital Signatures: Asymmetric cryptography-based electronic signature. Ensures authentication, integrity, and non-repudiation. Central to the IT Act's trust framework.
-
Electronic Agreements: Section 10A validates contracts formed through electronic communication. Enforceability stems from Indian Contract Act, 1872 (offer, acceptance, consideration) plus IT Act's recognition of electronic records/signatures.
-
E-signatures: Probative value is high if compliant with Section 3(2) of IT Act (attached to electronic record with intent to sign). Courts may require Section 65B certificate for primary electronic evidence.
IV. EVIDENCE, FORENSICS & PROCEDURAL LAW
Evolution of Evidence Law
-
Indian Evidence Act, 1872: Primarily dealt with documentary and oral evidence. Electronic records were not explicitly recognized.
-
Information Technology Act, 2000 (Amendments to IEA):
-
Section 3: Definition of "document" expanded to include electronic records.
-
Section 65B: Special provisions for admissibility of electronic records. An electronic record is admissible if:
-
It was produced/communicated by a computer regularly used for that purpose.
-
During that period, the computer was operating properly.
-
The record was reproduced/derived from information regularly fed into the computer.
-
A Section 65B certificate (signed by responsible official) accompanies it.
-
-
-
Evolution: Shift from a paper-centric to a digital-centric evidence framework, acknowledging the probative value of electronic data.
Electronic Records & Evidence
-
Status: Treated as documents under law. Primary evidence if original electronic record itself is produced (with 65B certificate). Secondary evidence if a printout/optical copy is produced.
-
Proof & Management: Requires establishing authenticity, integrity, and source. Managed through forensic imaging, hash value verification, and chain of custody.
-
Chain of Custody: Chronological documentation of the seizure, custody, control, transfer, analysis, and disposition of electronic evidence. Relation to Forensics: Critical for ensuring evidence is not tampered with, maintaining its admissibility in court.
Admissibility of Electronic Evidence
-
Assessment Criteria (Courts):
-
Relevance: Must relate to the fact in issue.
-
Authenticity: Proven source and integrity (via 65B certificate, expert testimony, hash values).
-
Reliability: Trustworthiness of the system that generated/recorded it.
-
Compliance with Sec 65B: Proper certificate is mandatory for secondary evidence (printout, CD).
-
-
Role of Digital Signatures: Provide strong evidence of origin (who signed) and integrity (tamper-evident). A valid digital signature significantly bolsters the authenticity of an electronic record.
V. MITIGATION STRATEGIES & COUNTERMEASURES
General Strategies to Tackle Cyber Crime
-
Legal: Robust, updated laws (like IT Act), international cooperation (Bilateral/Multateral agreements), specialized cyber courts.
-
Technical: Firewalls, IDS/IPS, encryption, MFA, antivirus/EDR, secure coding practices.
-
Managerial: Security policies, incident response plans, regular audits, employee training, risk assessment.
-
Awareness: Public education campaigns, workshops on phishing, safe browsing, password hygiene.
Technical Countermeasures & Privacy Tools
-
Proxy Servers:
-
Functioning: Acts as an intermediary between client and internet. Forwards requests, hides client's IP from the destination server.
-
Role: Access control, content filtering, caching, basic anonymity.
-
-
Anonymizers (e.g., Tor, VPNs):
-
Functioning: Use layered encryption and multiple relay nodes to obscure both source IP and traffic content from network observers.
-
Role: Strong anonymity, bypassing censorship, protecting privacy on public Wi-Fi.
-
-
Differentiation: Proxy vs. Anonymizer
| Feature | Proxy Server | Anonymizer (Tor/VPN) | | :--- | :--- | :--- | | IP Hiding | Hides IP from destination server | Hides IP from destination and network observers | | Encryption | Often none (transparent proxies) | End-to-end encryption (between client and exit node) | | Traffic Analysis | Proxy operator can see all traffic | No single node sees both source & destination (Tor) | | Primary Use | Control, caching, basic masking | Strong anonymity, privacy protection |
Preventive Measures for Specific Attacks (See respective sections above)
-
Web Jacking: MFA, strong passwords, WAF, patching.
-
Spamming: Email filters (SPF, DKIM, DMARC), user education, anti-spam laws.
-
Software Piracy: License management, activation servers, legal enforcement, affordable pricing models.
-
Wireless Attacks: Use WPA3, disable WPS, use enterprise authentication, monitor for rogue APs.
-
Password Sniffing: Use encrypted protocols (HTTPS, SSH, SFTP), VPNs on untrusted networks.
VI. SPECIALIZED TOPICS & TRENDS
Trends in Cyber Crime
-
Ransomware-as-a-Service (RaaS): Lower barrier for entry.
-
Supply Chain Attacks: Targeting software vendors to reach multiple victims (e.g., SolarWinds).
-
AI-Powered Attacks: Automated phishing (deepfake audio/video), vulnerability discovery.
-
Cryptojacking: Unauthorized use of victim's resources to mine cryptocurrency.
-
IoT Botnets: Massive networks of compromised smart devices for DDoS.
-
Fileless Malware: Resides in memory, leaves no disk footprint.
-
Double Extortion Ransomware: Steals data before encryption, threatens public leak.
Network Forensics
-
Brief Overview: The capture, recording, and analysis of network traffic to investigate security incidents, identify attacks, and gather legal evidence.
-
Role in Investigations: Reconstructs attack timelines, identifies compromised systems/intruders, correlates events from multiple sources (firewall logs, IDS alerts, packet captures).
World Wide Web (WWW)
- Basic Explanation: An information system where web resources (documents, images, videos) are identified by URLs, interlinked by hypertext links, and accessed via the internet using the HTTP/HTTPS protocol. It is a service built on top of the internet's infrastructure.