UNIT 2: CYBER CRIME: TYPES, ANALYSIS, AND INVESTIGATIVE APPROACHES
1.0 FOUNDATIONS OF CYBERCRIME
1.1 Defining Cybercrime
-
Core Definition: Cybercrime refers to any illegal activity that involves a computer, a network, or the internet. It can be the tool, target, or medium of the crime.
-
Nature and Extent (India vs. Global):
[!TIP] Exam focus: Compare India's legal framework (IT Act 2000) with global trends (e.g., US CFAA, EU GDPR).
-
India: High volume of reported crimes (phishing, financial frauds), often linked to rapid digitization (UPI, Aadhaar). Challenges include low cyber-literacy, under-reporting, and jurisdictional issues across states.
-
Global (Developed Nations): More sophisticated attacks (APT, ransomware), higher investment in cybersecurity, but also face threats from state-sponsored actors. Stronger legal frameworks and international cooperation (e.g., INTERPOL).
-
Global (Developing Nations): Often targets of opportunity; infrastructure vulnerabilities exploited. Limited resources for investigation and prevention.
-
1.2 Cybercrime vs. Conventional Crime
| Feature | Conventional Crime | Cybercrime |
|---|---|---|
| Jurisdiction | Geographical boundaries clear. | Transnational; attacker and victim can be continents apart. Complex legal overlaps. |
| Evidence | Physical (fingerprints, weapons). | Digital/Volatile (logs, IP addresses, metadata). Requires proper chain of custody. |
| Anonymity | Harder to achieve; risk of identification. | High degree possible via proxies, encryption, dark web. |
| Scale | Usually limited by physical presence. | Mass-scale possible from a single location (e.g., phishing emails). |
| Modus Operandi | Direct physical action. | Indirect, via code, networks, social engineering. |
Examples:
-
Conventional: Bank robbery (physical presence, teller threatened).
-
Cyber: Data breach (remote network exploit, no physical presence at victim's location).
1.3 Classifications & Taxonomy of Cybercrimes
A. Primary Classification (Based on Target):
-
Against Individuals: Cyberstalking, cyberbullying, phishing, identity theft, cyber defamation.
-
Against Property: Credit card fraud, data diddling, salami attacks, web jacking, ransomware.
-
Against Organizations: Hacking, denial-of-service (DoS), stealing trade secrets, insider threats.
-
Against Society: Pornography (child/obscene), online gambling, trafficking.
-
Against the Nation: Cyberterrorism, cyberwarfare, attacks on critical infrastructure (power grids).
B. Technical Classification:
| Computer as a TOOL | Computer as a TARGET |
|---|---|
| Crime committed using a computer to facilitate a traditional crime. | Crime where the computer/network/data is the primary objective. |
| Examples: Phishing, online fraud, stalking, copyright infringement. | Examples: Hacking, virus/worm attacks, DoS, data theft, logic bombs. |
2.0 TYPES AND MODUS OPERANDI OF CYBERCRIMES
2.1 Financial & Fraud Crimes
-
Credit Card Fraud:
-
Modus Operandi: Skimming (physical device on ATMs/POS), phishing (fake websites/emails), malware on e-commerce sites, data breaches from databases.
-
Preventive Measures: Use tokenization (PCI-DSS), virtual cards, 2FA, monitor statements, avoid public Wi-Fi for transactions.
-
-
E-commerce Frauds:
- Challenges: Fake websites/ads, non-delivery of goods, triangulation fraud (using stolen cards to buy goods for resale), friendly fraud (chargeback abuse), account takeover.
-
Cloud-based Frauds:
- Role: Exploiting misconfigured cloud storage (S3 buckets), compromised cloud credentials, cryptojacking (using cloud compute resources), ransomware-as-a-service (RaaS) hosted on cloud.
-
Salami Attacks:
-
Technique: Siphoning off tiny amounts (like "salami slices") from large numbers of accounts. E.g., deducting ₹0.10 from millions of bank accounts monthly.
-
Detection/Prevention: Regular audit trails and reconciliation of financial records; anomaly detection systems flagging micro-transactions.
-
-
Data Diddling:
-
Technique: Altering data before or during input into a system. E.g., changing employee salary data in HR software before payroll run.
-
Detection/Prevention: Input validation, hash functions (digital fingerprints) to verify data integrity, access controls, regular audits.
-
2.2 Malware & Code-Based Attacks
-
Malware Definition: Malicious software designed to disrupt, damage, or gain unauthorized access to systems.
- Categories: Virus, Worm, Trojan, Ransomware, Spyware, Adware, Rootkit.
-
Virus vs. Worm vs. Logic Bomb:
| Feature | Virus | Worm | Logic Bomb | | :--- | :--- | :--- | :--- | | Propagation | Requires host file & user action (execution). | Self-replicating, spreads via network/email without user action. | No self-replication. Dormant code triggered by an event. | | Primary Goal | Corrupt/modify files, display messages. | Consume bandwidth, create botnets, drop other malware. | Execute malicious payload (delete files, erase data) on a trigger. | | Example | Macro virus in Word doc. | WannaCry (exploited SMB漏洞). | Employee resignation triggers data wipe. |
-
Logic Bomb Mechanism: Malicious code inserted into a system that activates upon a specific condition (date/time, login, file access). Prevention: code reviews, integrity checking, least privilege.
-
Detection & Protection: Antivirus/EDR (Endpoint Detection & Response), regular patching, application whitelisting, network segmentation, user awareness.
2.3 Social Engineering & Deception
-
Phishing: Sending fraudulent communications (email, SMS, call) to trick individuals into revealing sensitive data (passwords, credit card numbers) or clicking malicious links.
- Threat: Primary vector for initial compromise, credential theft, and malware delivery.
-
Steganography: Hiding malicious data/code within seemingly innocent files (images, audio, video). Evades detection by security scanners that only check file headers.
- Threat: Used for data exfiltration, command & control (C2) communication, distributing malware.
-
Role of Social Engineering: Human element is the weakest link. Exploits trust, authority, urgency, curiosity. Enables bypass of technical controls.
-
Crimes on Social Networking Sites:
- Examples: Fake profiles for romance scams, catfishing, cyberbullying, spreading malware via malicious links, corporate espionage via LinkedIn, doxxing (publishing private info).
2.4 Access & Integrity Attacks
-
Hacking vs. Cracking:
-
Hacking: Broad term for exploring systems to understand them, often with ethical intent (white hat).
-
Cracking: Unauthorized modification of software/systems for malicious intent (black hat), e.g., bypassing software licenses, breaking into systems.
-
-
Web Jacking: Taking control of a user's website without consent. Often via credential theft or session hijacking. Attacker redirects traffic or defaces site.
-
Cross-Site Scripting (XSS):
-
Concept: Injecting malicious client-side scripts (usually JavaScript) into a trusted website. When a victim visits, script executes in their browser.
-
Types: Stored (persistent), Reflected (non-persistent), DOM-based.
-
Impact: Steal session cookies, perform actions on behalf of user, phishing.
-
-
Intrusion: Unauthorized access to a system/network. Modus operandi involves reconnaissance, scanning for vulnerabilities, exploitation, maintaining access, and covering tracks.
3.0 ANALYSIS OF CYBERCRIMINAL BEHAVIOR & IMPACT
3.1 Psychological Profiling & Motivations
-
Psychological Traits & Motivations:
-
Traits: High technical skill, tolerance for ambiguity, risk-taking, sensation-seeking, social isolation (often).
-
Motivations: Financial gain (most common), thrill/ego, political/ideological (hacktivism), revenge, espionage.
-
-
Psychological Theories:
-
Routine Activity Theory: Crime occurs when a motivated offender, a suitable target, and absence of capable guardian converge in time/space. (Applies to phishing: attacker + victim with weak awareness + no email filter).
-
Strain Theory: Individuals engage in crime due to strain/pressure (financial, social) between societal goals and means to achieve them. Cybercrime offers perceived low-risk, high-reward means.
-
-
Significance of Profiling: Helps narrow suspect pool, predict future targets/tactics, understand group dynamics (e.g., organized crime vs. lone wolves), and develop effective interrogation strategies.
3.2 Fraud Analysis Framework
-
The Fraud Triangle (Cressey):
\boxed{\text{Fraud occurs when Pressure, Opportunity, and Rationalization converge.}}
-
Pressure (Motivation): Financial problems, addiction, greed, work stress.
-
Opportunity (Means): Weak internal controls, lack of supervision, access to assets, poor security.
-
Rationalization (Justification): "I'm just borrowing," "I deserve this," "the company cheats too."
-
-
Role in Detection/Prevention: Organizations can interrupt the triangle:
-
Reduce Opportunity via strong controls (segregation of duties, audits).
-
Identify and mitigate Pressure (employee assistance programs).
-
Foster ethical culture to reduce Rationalization.
-
3.3 Sociological & Economic Impact
-
Sociological Impact:
-
On Individuals: Mental health crisis from cyberbullying/stalking (anxiety, depression, suicide), erosion of trust, privacy invasion, reputational damage.
-
On Corporations: Loss of customer trust, brand damage, operational disruption, regulatory fines (GDPR), increased security costs.
-
On Governments: Erosion of public trust in institutions, threat to national security, disruption of public services.
-
On Society: Normalization of illegal behavior, digital divide exacerbation, fear of technology.
-
-
Economic Impact:
-
Direct Losses: Theft of funds, ransom payments, fraud losses.
-
Indirect Costs: Incident response, forensic investigation, system restoration, legal fees, increased insurance premiums, lost productivity, reputational loss leading to revenue drop.
-
Macro Impact: Hinders digital economy growth, deters foreign investment, increases national cybersecurity expenditure.
-
3.4 Cyber Harassment & Defamation
-
Cyberstalking & Cyberbullying:
-
Effects on Mental Health: Persistent fear, anxiety, depression, PTSD, social withdrawal, suicidal ideation. Victims feel unsafe even in their homes.
-
Combative Measures: Legal (IT Act sections 66A, 67; IPC sections), platform reporting tools, digital literacy & awareness, counseling, preservation of evidence (screenshots, logs).
-
-
Cyber Defamation:
-
Concept: Publishing false statements online that harm a person's reputation. Can be via posts, comments, fake profiles, deepfakes.
-
Legal Implications: Civil (damages for libel/slander) and criminal (IT Act, IPC). Challenges: jurisdiction, anonymity of poster, proof of publication and identification.
-
4.0 GLOBAL TRENDS & POLICY IMPLICATIONS
4.1 Global Trends in Cybercrime
-
Recent/Evolving Trends:
-
Ransomware-as-a-Service (RaaS): Lowers entry barrier for criminals.
-
Supply Chain Attacks: Targeting software vendors (e.g., SolarWinds) to reach multiple victims.
-
State-Sponsored Attacks: For espionage, sabotage, geopolitical influence.
-
IoT Botnets: Insecure devices (cameras, routers) used for large-scale DDoS.
-
AI-Powered Attacks: Automated phishing, deepfakes for disinformation, malware that evades detection.
-
Cryptocurrency Crime: Theft from exchanges, ransomware payments, money laundering.
-
-
Influence on Cybersecurity Policies:
-
Drives mandatory breach notification laws.
-
Spurs international cooperation (Budapest Convention, UN resolutions).
-
Leads to regulation of critical infrastructure (e.g., NIS2 Directive in EU).
-
Increases focus on cyber resilience and public-private partnerships.
-
4.2 Comparative Analysis: Developed vs. Developing Nations
| Aspect | Developed Nations | Developing Nations |
|---|---|---|
| Primary Threat | Advanced Persistent Threats (APTs), state-sponsored attacks, sophisticated ransomware. | Opportunistic attacks (phishing, basic malware), financial frauds, often using tools developed elsewhere. |
| Nature/Scale | Targeted, strategic. High impact on critical infrastructure. | Often mass-scale, volume-based. Targets individuals and SMEs. |
| Key Challenges | Attribution, defending against zero-days, securing legacy critical infrastructure. | Resource constraints, low cyber awareness, inadequate legal frameworks, under-reporting, lack of skilled workforce. |
| Policy Focus | Deterrence, active defense, international law, securing critical infrastructure. | Capacity building, basic cybersecurity hygiene, awareness campaigns, adapting international frameworks locally. |
5.0 INTRUSION ANALYSIS & THREAT DETECTION
5.1 Intrusion Analysis Fundamentals
-
Concept: The process of collecting, examining, and interpreting data to identify, understand, and respond to malicious activities within a network or system.
-
Critical Importance: Enables early detection of breaches, determines scope & impact of an attack, identifies adversary tactics, and provides evidence for legal/disciplinary action. It's the core of incident response.
5.2 Log Analysis for Intrusion Detection
-
Importance of Log Analysis: Logs are the primary forensic record of system/network activity. They provide a chronological account to reconstruct attacks, identify Indicators of Compromise (IoCs), and understand attacker behavior.
-
Process of Log Analysis:
-
Collection: Aggregate logs from all sources (firewalls, IDS/IPS, servers, endpoints, applications).
-
Normalization: Convert logs to a common format for correlation.
-
Analysis: Use SIEM (Security Information & Event Management) tools to correlate events, detect anomalies, and identify patterns.
-
Investigation: Drill down into specific alerts to determine legitimacy and context.
-
-
Passive Discovery of Intrusion Activities: Monitoring without active probing of the network. Relies on analyzing existing log data and network traffic for suspicious patterns (e.g., unusual outbound traffic, failed login spikes, known malicious IPs).
5.3 The Intrusion Kill Chain
-
Concept & Stages (Lockheed Martin): A model to describe the progression of a cyber attack from reconnaissance to action on objectives.
-
Reconnaissance: Research target (OS, employees, network).
-
Weaponization: Couple exploit with backdoor (e.g., create malicious PDF).
-
Delivery: Transmit weaponized payload (email, USB, web).
-
Exploitation: Trigger vulnerability to execute code.
-
Installation: Install malware/backdoor on system.
-
Command & Control (C2): Establish channel for remote control.
-
Actions on Objectives: Achieve goal (data exfiltration, destruction, ransomware encryption).
-
-
Role in Defense: Allows defenders to "break the chain" at any stage. E.g., email filtering (Delivery), patching (Exploitation), network segmentation (C2), DLP (Actions on Objectives). Delays and degrades adversary tactics by forcing them to restart or use more resources.
5.4 Countermeasures & Detection Techniques
-
Countermeasures to Deny Access:
-
Preventive: Firewalls, access control lists (ACLs), network segmentation, application whitelisting, principle of least privilege.
-
Deterrent: Strong authentication (MFA), legal warnings, decoy systems (honeypots).
-
-
Methods for Detecting Future Threats:
-
Threat Intelligence: Using feeds of known IoCs (IPs, hashes) and Tactics, Techniques, and Procedures (TTPs).
-
Behavioral Analytics/UEBA: Establishing baselines of "normal" user/entity behavior and flagging anomalies.
-
Deception Technology: Deploying decoys/honeytokens to detect lateral movement.
-
Predictive Analytics: Using ML/AI on historical data to predict attack likelihood.
-
-
Role of Fraud Detection Techniques: Patterns like unusual transaction volumes, geolocation mismatches, and salami slicing are analogous to cyber intrusion patterns (lateral movement, data exfiltration). Techniques like anomaly detection and link analysis are directly applicable to finding hidden attacker activity within networks.
6.0 INVESTIGATIVE TOOLS & METHODOLOGIES
6.1 Modus Operandi (MO) in Investigation
-
Definition: The characteristic pattern of behavior, methods, and techniques used by a criminal to commit a crime.
-
Importance:
-
Linking Crimes: Same MO across incidents suggests a single perpetrator or group.
-
Identifying Perpetrator: Unique signatures (e.g., specific coding style in malware, unique phishing email templates) can point to known threat actors.
-
Predicting Future Targets: Understanding MO helps anticipate next moves.
-
-
Example: A hacker consistently uses a specific SQL injection payload and uploads a webshell named
shell.phpto compromised servers. This MO can be used to attribute other attacks with the same signature.
6.2 Profiling in Cybercrime Investigation
-
Criminal Profiling: The process of inferring the characteristics (psychological, demographic, behavioral) of an unknown offender from the analysis of their criminal actions (MO, signature, crime scene).
-
Relevance in Cybercrime:
-
Helps narrow down from millions of potential internet users.
-
Distinguishes between script kiddies (use existing tools, low sophistication) vs. advanced hackers (custom code, stealth).
-
Infers motivation (financial vs. ideological) from target selection and tactics.
-
Assists in prioritizing leads and allocating investigative resources.
-
-
Distinction from General Behavioral Analysis:
-
Profiling: Inductive/Deductive reasoning from crime facts to offender traits. Focuses on the unknown perpetrator.
-
Behavioral Analysis: Broader study of any behavior (known or unknown). In cyber, includes analyzing malware code, network traffic patterns, and attacker TTPs to build threat actor profiles (e.g., APT28, Lazarus Group). Often more technical and evidence-based.
-