Skip to content
CY-601 · Cyber Crime Investigation & Digital Forensic/Quick Revision Short Notes

Cyber Crime Investigation & Digital Forensic (CY-601) - Unit 1 Short Notes

1.0 INTRODUCTION & CORE CONCEPTS

1.1 Definition and Scope of Cybercrime

  • Definition: Cybercrime refers to illegal activities where a computer, network, or the Internet is used as a tool, target, or place of crime. It encompasses a wide range of offenses, from traditional crimes committed online (e.g., fraud, theft) to new, technology-dependent crimes (e.g., hacking, malware distribution).

  • Evolving Scope: Definitions vary across:

    • Legal Context: Specific acts defined in statutes (e.g., India's IT Act, 2000).

    • Technical Context: Focus on vulnerabilities exploited and attack vectors.

    • Sociological Context: Harm caused to individuals, society, and infrastructure.

  • Distinction:

    • Computer Crime: Broad term; any crime involving a computer.

    • Cybercrime: Subset of computer crime; requires a network (Internet) or cyberspace.

    • Digital Crime: Often used interchangeably; emphasizes the digital evidence trail.

1.2 Nature and Extent of Cybercrime

  • Global Statistics: Consistently high and rising. Reports from INTERPOL, UNODC, and cybersecurity firms show:

    • Financial losses in hundreds of billions USD annually.

    • Ransomware and phishing remain top threats.

  • India vs. Other Countries:

    • India: Rapidly increasing reported cases due to digital adoption (UPI, Aadhaar) and improved reporting mechanisms. Major issues: financial frauds, social media crimes, ransomware.

    • Developed Nations: Often face more sophisticated, state-sponsored attacks and critical infrastructure targeting.

    • Developing Nations: May suffer from underreporting, lack of resources, and vulnerable infrastructure.

  • Underreporting & Measurement Challenges:

    • Victim Reluctance: Fear, shame, lack of awareness.

    • Jurisdictional Complexity: Cross-border nature hinders unified reporting.

    • Lack of Standardized Metrics: Different agencies use different criteria.

1.3 Fundamental Differentiation: Cybercrime vs. Conventional Crime

Feature Conventional Crime Cybercrime
Transnationality Usually confined to one jurisdiction. Inherently borderless; attacker & victim can be continents apart.
Anonymity Harder to achieve; physical evidence often present. High degree of anonymity possible via Tor, cryptocurrencies, proxy chains.
Technical Complexity Often requires physical skill/opportunity. Requires technical/digital literacy; knowledge of OS, networks, code.
Evidence Volatility Physical evidence (fingerprints, DNA) is relatively stable. Digital evidence is volatile; can be altered, deleted, or time-stamped incorrectly.
Jurisdictional Challenges Clear territorial jurisdiction usually applies. Complex jurisdictional conflicts; multiple laws (local, national, international) may apply.

[!TIP] Exam Focus: Be ready to provide specific examples for each differentiating factor. E.g., for Anonymity: A drug deal (conventional) vs. a ransomware attack paid in Monero (cyber).


2.0 CLASSIFICATIONS & TAXONOMIES OF CYBERCRIMES

2.1 Primary Classifications (Based on Target/Objective)

Target Examples of Crimes
Against Persons Cyberstalking, cyberbullying, cyber defamation, online harassment, distribution of obscene material (child porn).
Against Property Financial Frauds (credit/debit card, online banking), e-commerce frauds, data diddling, salami attacks, identity theft, cloud-based frauds, intellectual property theft (software piracy).
Against Government/Infrastructure Cyberterrorism, attacks on critical infrastructure (power grids, dams), cyber espionage, defacement of government websites.
Against Society Hacking/cracking, spreading malware/viruses, software piracy, creating/distributing fake news, online gambling (where illegal).

2.2 Specific Attack Vectors & Techniques (Modus Operandi)

  • Social Engineering: Manipulating humans to breach security.

    • Phishing: Mass emails/SMSs pretending to be legitimate.

    • Spear-Phishing: Targeted phishing with personalized info.

    • Vishing/Smishing: Voice call/SMS-based phishing.

    • Pretexting: Creating a fabricated scenario to gain trust.

  • Malware-Based Attacks:

    • Virus: Needs host program to replicate; attaches to files.

    • Worm: Standalone; self-replicates over network without user action.

    • Trojan Horse: Disguised as legitimate software; creates backdoor.

    • Ransomware: Encrypts files/drives; demands ransom (often double extortion - threatens to leak data).

    • Spyware/Adware: Secretly monitors or displays ads.

    • Logic Bomb: Code that triggers malicious action when a specific condition is met (e.g., a date, login attempt).

  • Network/Web-Based Attacks:

    • Man-in-the-Middle (MitM): Intercepts/alters communication between two parties.

    • DoS/DDoS: Overwhelms a service/target with traffic to cause denial of service.

    • Cross-Site Scripting (XSS): Injects malicious scripts into trusted websites.

    • SQL Injection: Inserts malicious SQL code via input fields to manipulate databases.

    • Session Hijacking/Web Jacking: Takes over a user's authenticated session on a website.

  • Steganography: Hiding data within other files (e.g., image, audio, video).

  • Salami Attack: Incremental theft (e.g., rounding down transactions and siphoning fractions).

  • Data Diddling: Altering data before or during input (e.g., changing employee bank details in HR system).

2.3 Emerging & Niche Cybercrimes

  • Cryptocurrency Frauds: Ponzi schemes, fake ICOs, wallet theft, ransom demands in crypto.

  • Deepfakes & AI-Powered Disinformation: Synthetic media for fraud, blackmail, political manipulation.

  • IoT/OT Attacks: Exploiting vulnerabilities in smart devices (cameras, thermostats) and Industrial Control Systems (power plants, factories).


3.0 PSYCHOLOGICAL & SOCIOLOGICAL DIMENSIONS

3.1 Psychology of the Cybercriminal

  • Motivations:

    • Financial Gain: Most common (fraud, ransomware).

    • Thrill/Ego: "Hacking for fun," challenge, status in hacker communities.

    • Ideology (Hacktivism): Political/social causes (e.g., Anonymous).

    • Revenge/Coercion: Personal grudge, corporate espionage.

  • Psychological Traits & Profiles: Often exhibit narcissism, sensation-seeking, moral disengagement, sense of entitlement. Not all fit a "criminal profile"; many are otherwise ordinary.

  • Theoretical Frameworks:

    • Fraud Triangle (Most Critical): $$\displaystyle \boxed{\text{Pressure (Need) + Opportunity + Rationalization}} $$. All three elements must converge for fraud to occur.

    • Rational Choice Theory: Criminals weigh costs vs. benefits; cybercrime offers high reward, low perceived risk.

    • Social Learning Theory: Criminal behavior learned through association with peers (online forums, groups).

    • General Strain Theory: Stress/strain (financial, social) leads to negative emotions, which may lead to crime.

3.2 Sociological Impact of Cybercrime

Stakeholder Impact
Individuals Loss of privacy, psychological trauma (anxiety, depression from cyberbullying/stalking), financial ruin, reputational damage, identity theft.
Corporations/Orgs Direct financial losses, operational disruption, reputational harm, loss of customer trust, regulatory penalties (GDPR, DPDP Act), increased insurance costs.
Governments & Society Erosion of public trust in institutions, threat to national security (espionage, infrastructure attacks), social polarization (disinformation), economic instability.

3.3 Economic Impact Analysis

  • Direct Costs: Theft, fraud amounts, ransom payments, theft of intellectual property.

  • Indirect Costs: Incident response (forensics, legal), system recovery/rebuilding, legal fees & fines, increased cybersecurity insurance premiums, brand depreciation (loss of customer loyalty).

  • Macro-Economic: Reduced GDP growth, stifled innovation, loss of foreign investment, increased cost of doing business.


4.0 INVESTIGATIVE ANALYSIS & THREAT DETECTION

4.1 Intrusion Analysis & The Cyber Kill Chain

  • Concept: Lockheed Martin's Intrusion Kill Chain is a model to understand and disrupt cyber intrusions by identifying phases of an attack.

  • Phases (7 Stages):

    1. Reconnaissance: Research target.

    2. Weaponization: Couple exploit with backdoor (create malware).

    3. Delivery: Transmit weapon to target (email, USB, web).

    4. Exploitation: Trigger exploit to execute code.

    5. Installation: Install malware/backdoor on target.

    6. Command & Control (C2): Malware establishes channel to attacker's server.

    7. Actions on Objectives: Achieve goal (data exfiltration, destruction, ransomware encryption).

  • Role in Defense: "Break the chain" at any stage. Enables detection and response aligned with attacker TTPs (Tactics, Techniques, and Procedures).

  • Key Indicators:

    • IoCs (Indicators of Compromise): Artifacts of a breach (malicious IP, file hash, registry key).

    • TTPs: Behavioral patterns of the attacker (how they operate).

4.2 Log Analysis & Passive Discovery

  • Significance of Logs: Provide audit trail of system/network events (logins, file access, network connections). Essential for reconstruction and anomaly detection.

  • Identifying Intrusion Patterns:

    • Correlation: Link logs from firewalls, IDS/IPS, servers, endpoints.

    • Anomaly Detection: Baseline normal behavior; flag deviations (e.g., login at 3 AM from unusual country).

    • Signature-Based Analysis: Match log events against known attack patterns (IoCs).

  • Passive Discovery: Monitoring network/system activity without active probing. Used to detect:

    • Reconnaissance: Port scans, vulnerability scans from external IPs.

    • Lateral Movement: Unusual internal connections, pass-the-hash attempts.

    • Data Exfiltration: Large outbound data transfers to unknown locations.

4.3 Fraud Detection & Prevention Frameworks

  • Application of Fraud Triangle: Systems designed to remove "Opportunity" (strong controls) and increase "Rationalization" cost (clear policies, ethics training). "Pressure" is harder to control.

  • Detection Techniques:

    • Rule-Based Systems: Flag transactions above a limit, from blocked countries.

    • Data Analytics & AI/ML: Anomaly detection models identify unusual patterns (e.g., sudden change in vendor payment details).

    • Continuous Monitoring: Real-time analysis of transactions/user behavior.

  • Countermeasures to Deny Access:

    • Access Controls: Least Privilege Principle, Role-Based Access Control (RBAC).

    • Multi-Factor Authentication (MFA): Adds layers beyond password.

    • Network Segmentation: Limits lateral movement.

    • Application Whitelisting: Only approved software can run.

4.4 Criminal Profiling in Cybercrime

  • Concept: Behavioral and technical analysis to infer characteristics of an unknown offender based on crime scene (digital artifacts, TTPs).

  • Significance:

    • Link disparate crimes to a single actor/group.

    • Predict future targets based on victimology or tool preferences.

    • Narrow suspect pool by matching skill level, language, tools.

    • Understand sophistication & intent (script kiddie vs. APT).

  • Methods:

    • TTP Analysis: Unique malware code, command structures, tools (e.g., specific exploit kit).

    • Language & Timing: Native language in code comments, attack active times (timezone).

    • Tool Signatures: Custom tools leave fingerprints.

    • Target Selection & Tradecraft: Choice of targets, operational security (OPSEC) mistakes.


5.0 GLOBAL TRENDS, THREAT LANDSCAPE & POLICY

5.1 Recent & Evolving Global Trends in Cybercrime

  • Ransomware-as-a-Service (RaaS): "Business model" where developers lease ransomware to affiliates (e.g., LockBit, Conti). Double/Triple Extortion: Encrypt data + threaten to leak + DDoS attack.

  • Supply Chain Attacks: Compromise a trusted vendor/software provider to reach its customers (e.g., SolarWinds Orion).

  • State-Sponsored Activities & Cyber Warfare: Nations use cyber tools for espionage, sabotage, influence (e.g., Russia-Ukraine, Iran-Israel).

  • Targeting Remote Work & Cloud: Exploiting VPN vulnerabilities, misconfigured cloud storage (S3 buckets), and weak home security.

  • AI-Powered Attacks: Automated phishing (generative AI), AI-enhanced malware that evades detection, deepfake social engineering.

5.2 Influence on Cybersecurity Policies & Frameworks

  • Driving Regulatory Changes: Trends force new laws:

    • GDPR (EU): Strict data breach notification, heavy fines.

    • India's DPDP Act, 2023: Data protection, cross-border transfer rules.

    • Sector-Specific: HIPAA (health), PCI-DSS (payments).

  • National Strategies: Countries publish National Cybersecurity Strategies focusing on resilience, deterrence, international cooperation.

  • International Cooperation: Budapest Convention (first international cybercrime treaty); newer frameworks for attribution and response.

  • Shift in Posture: From purely reactive to proactive, intelligence-led, and risk-based security.

5.3 Methods for Detecting Future Threats & Countering Effectively

  • Threat Intelligence (TI): Sharing IoCs and TTPs via ISACs (Information Sharing and Analysis Centers), OSINT.

  • Predictive Analytics & Threat Hunting: Proactive, hypothesis-driven search for hidden threats within network, using TI and behavioral analytics.

  • Red Teaming & Purple Teaming:

    • Red Team: Simulates adversary attack to test defenses.

    • Purple Teaming: Collaborative process where Red & Blue (defense) teams work together to improve detection/response.

  • Deception Technology: Deploy honeypots (single decoy) / honeynets (network of decoys) to attract, detect, and study attackers in isolation.

  • Building Resilience:

    • Incident Response (IR) Planning: Tested IR playbooks.

    • Robust Backups: 3-2-1 Rule (3 copies, 2 media, 1 offsite).

    • Regular Patching & Vulnerability Management.


6.0 SPECIALIZED CRIME CATEGORIES & CASE STUDIES

6.1 Financial & E-Commerce Frauds

  • Modus Operandi:

    • Credit/Debit Card Fraud: Skimming (physical devices on ATMs/POS), phishing for details, data breaches of merchant databases, card-not-present fraud.

    • Online Shopping Scams: Fake websites/ads, non-delivery of goods, triangulation fraud (fake storefront using stolen cards).

    • Payment Gateway Attacks: Exploiting vulnerabilities to process fraudulent transactions or steal stored card data.

  • Preventive Measures:

    • Consumers: Use MFA, check HTTPS, monitor statements, use virtual cards.

    • Businesses: PCI-DSS compliance, tokenization, address verification (AVS), CVV checks, behavioral analytics for transactions.

6.2 Personal Harassment & Defamation

  • Cyberstalking & Cyberbullying:

    • Methods: Relentless online harassment, monitoring via spyware, posting private info (doxxing), impersonation.

    • Impact: Severe anxiety, depression, PTSD, suicidal ideation. Often targeted at women and minors.

  • Cyber Defamation:

    • Definition: Publishing false statements online that harm a person's reputation.

    • Legal Implications (India): IT Act, 2000 (Sec. 66A - now struck down, but related provisions) and IPC (Sec. 499, 500 - defamation). Challenges: Proof of authorship, jurisdiction, intermediary liability.

  • Combating Measures:

    • Legal: Report to police (cyber cell), send legal notices, file defamation suits.

    • Technical: Preserve evidence (screenshots, logs with metadata), request takedowns from platforms under IT Rules, 2021.

    • Social: Awareness programs, counseling, digital literacy.

6.3 Social Media & Networking Site Crimes

  • Common Crimes:

    • Fake Profiles & Impersonation: For fraud, reputational harm, catfishing.

    • Privacy Violations: Sharing private photos/videos without consent (revenge porn).

    • Rumor Mongering & Incitement: Spreading fake news leading to violence.

    • Recruitment: For terrorism, radicalization, or illegal activities.

  • Platform Challenges: Scale of content, cross-border jurisdiction, anonymity, encrypted messaging (WhatsApp, Telegram).

  • Mitigation:

    • Platforms: Robust community guidelines, AI-based content moderation, easy reporting mechanisms, account verification.

    • Users: Strong privacy settings, critical thinking, not sharing sensitive info.

    • Law Enforcement: Coordination with platforms via ** Mutual Legal Assistance Treaties (MLATs)**, digital evidence collection training.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in