Skip to content
CY-601 · Cyber Crime Investigation & Digital Forensic/Quick Revision Short Notes

Cyber Crime Investigation & Digital Forensic (CY-601) - Unit 3 Short Notes

UNIT 3: CYBER CRIME INVESTIGATION & DIGITAL FORENSIC


1.0 FOUNDATIONS & CLASSIFICATIONS OF CYBERCRIME

1.1 Defining Cybercrime

  • Core Definition: Any illegal activity where a computer, network, or the internet is used as a tool, target, or medium.

    \boxed{\text{Cybercrime} = \text{Illegal Acts} \cap \text{Digital Environment}}

  • Nature & Extent in India:

    • Rapid growth post-Digital India; high volume of financial frauds (phishing, credit card scams).

    • Key legislation: IT Act 2000 (amended 2008), IPC provisions.

    • Challenges: Underreporting, low cyber literacy, judicial backlog.

  • Global Perspective:

    • Developed Countries: Advanced threats (APTs, ransomware), strong detection frameworks (e.g., US-CERT, Europol).

    • Developing Countries: Basic frauds (lottery scams, OTP frauds), infrastructure vulnerabilities.

    • [!TIP] Compare India’s high financial fraud volume with the West’s state-sponsored espionage.

1.2 Classifications & Taxonomy of Cybercrimes

  • Major Frameworks:

    1. Against Individuals: Identity theft, cyberstalking, cyberbullying.

    2. Against Property: Hacking, data theft, IPR violation, ransomware.

    3. Against Government: Cyberterrorism, website defacement, espionage.

    4. Against Society: Cyberpornography, online gambling, fake news.

  • Table: Classification with Examples

    | Class | Target | Examples | |-----------|------------|--------------| | Individual | Persons | Phishing, cyberstalking, cyber defamation | | Property | Digital assets | Ransomware, data diddling, salami attacks | | Government | State infrastructure | DDoS on govt portals, logic bombs in critical systems | | Society | Community | Spread of malware, online drug trafficking |

1.3 Cybercrime vs. Conventional Crime

  • Differentiating Factors:

    • Motive: Cybercrime → financial/ideological; Conventional → emotional/impulsive.

    • Modus Operandi: Digital tools (malware, phishing) vs. physical force.

    • Evidence: Electronic (logs, metadata, volatile) vs. physical (fingerprints, eyewitnesses).

    • Jurisdiction: Transnational (cloud, dark web) vs. local.

    • Anonymity: High (VPN, Tor, crypto) vs. low (CCTV, witnesses).

  • Comparison Table

    | Factor | Cybercrime | Conventional Crime | |------------|----------------|-----------------------| | Evidence Type | Digital footprints, volatile | Physical, durable | | Jurisdiction | Complex, cross-border | Usually local | | Scale | Mass impact (one attack → millions) | Limited to location | | Investigation | Requires digital forensics, log analysis | Scene of crime, forensics |


2.0 CYBERCRIME TAXONOMY: SPECIFIC ATTACKS & FRAUDS

2.1 Deception & Identity-Based Attacks

  • Phishing:

    • Concept: Fraudulent emails/websites to steal credentials/data.

    • Types: Spear phishing (targeted), whaling (executives), vishing (voice), smishing (SMS).

    • Threats: Leading cause of data breaches; enables further attacks (APTs).

  • Social Engineering:

    • Role: Manipulating humans to bypass technical controls.

    • Techniques: Pretexting, baiting (USB drops), quid pro quo, tailgating.

    • Psychological Levers: Authority, scarcity, familiarity, urgency.

  • Steganography:

    • Concept: Hiding data within innocent files (images, audio, video).

    • Cybersecurity Threat: Covert C2 communication, data exfiltration, malware delivery.

    • Detection: Statistical analysis, file size anomalies, entropy checks.

2.2 Financial & E-Commerce Frauds

  • Credit Card Frauds:

    • Modus Operandi: Skimming, phishing, data breaches (POS malware), CNP (Card-Not-Present) fraud.

    • Preventive Measures: EMV chips, tokenization, 3D Secure, AI-based anomaly detection, PCI DSS compliance.

  • E-commerce Frauds:

    • Challenges: Friendly fraud (false chargebacks), triangulation fraud (fake stores), delivery scams, account takeover.

    • Modern Landscape: Surge during COVID-19; cross-border complexities.

  • Cloud-based Frauds:

    • Role in Financial Crimes: Misconfigured cloud storage → data leaks; crypto-jacking; unauthorized access to cloud financial apps.

2.3 Data & System Manipulation Attacks

  • Data Diddling:

    • Concept: Altering data before/during entry (e.g., payroll, banking transactions).

    • Detection: Audit trails, checksums, reconciliation reports.

    • Prevention: Input validation, access controls, segregation of duties.

  • Salami Attacks:

    • Concept: Slicing tiny amounts from many accounts (e.g., rounding down interest).

    • Mechanism: Automated scripts; hard to detect due to negligible per-account loss.

  • Logic Bombs:

    • Definition: Malicious code triggered by a specific condition (date, event, user action).

    • How it Works: Embedded in legitimate software; activates to delete/corrupt data or disrupt systems.

    • Prevention: Code reviews, integrity checks (hash values), least privilege, monitoring for unusual triggers.

  • Web Jacking:

    • Concept: Hijacking a website by compromising DNS, session hijacking, or admin credentials.

    • Impact: Traffic redirection, phishing, defacement, reputational damage.

  • Cross-Site Scripting (XSS):

    • Concept: Injecting malicious scripts into trusted websites executed in user’s browser.

    • Types: Stored (persistent), Reflected (non-persistent), DOM-based.

    • Prevention: Input sanitization, output encoding, Content Security Policy (CSP) headers.

  • Hacking vs. Cracking:

    • Hacking: Broad term for unauthorized access; can be ethical (white hat) for security testing.

    • Cracking: Specifically malicious, breaking into systems to cause harm/theft.

    • [!TIP] In exams, emphasize intent: hacking = skill, cracking = crime.

2.4 Harassment & Defamation Crimes

  • Cyberstalking & Cyberbullying:

    • Methods: Harassing messages, fake profiles, doxxing, non-consensual sharing of intimate images.

    • Mental Health Impact: Anxiety, depression, PTSD, suicide risk (especially in youth).

    • Measures to Combat: Legal (IT Act Sections 66A, 67; IPC 354D), awareness programs, reporting portals, counseling.

  • Cyber Defamation:

    • Concept: False statements online harming reputation.

    • Legal Implications: Civil (damages for libel) and criminal (IT Act, IPC Sections 499, 500). Intermediary liability under IT Act.


3.0 IMPACT OF CYBERCRIME

3.1 Psychological Impact

  • On Individuals:

    • Trauma, loss of trust in digital systems, fear, insomnia, financial stress.
  • Cybercriminal Psychology:

    • Traits: Low empathy, high technical skill, sensation-seeking, moral disengagement.

    • Motivations: Financial gain (most common), ideology (hacktivism), thrill/ego, revenge.

  • Psychological Theories:

    • Routine Activity Theory: Crime occurs when motivated offender, suitable target, and absence of capable guardian converge online.

    • General Strain Theory: Stress/strain (e.g., unemployment) leads to criminal coping (cyber fraud).

3.2 Sociological Impact

  • On Individuals & Society:

    • Erosion of trust in online interactions; social fragmentation via fake news; normalization of illegal behavior.
  • On Corporations & Governments:

    • Loss of customer trust, operational disruption (e.g., NotPetya), increased security spending, regulatory scrutiny.

3.3 Economic Impact

  • On Governments:

    • Infrastructure damage (power grids, hospitals), espionage costs, national security threats, loss of intellectual property.
  • On Businesses:

    • Direct loss (fraud, theft), remediation costs, reputational damage, regulatory fines (GDPR, DPDP Act), increased insurance premiums.

    • \boxed{\text{IBM 2023: Avg. cost of data breach} = $4.35 \text{ million}}


4.0 INVESTIGATION & THREAT ANALYSIS

4.1 Intrusion Analysis & Kill Chain

  • Intrusion Analysis:

    • Concept: Systematic examination of digital evidence to understand attack vectors, tactics, techniques, and procedures (TTPs).

    • Importance: Attribution, improving defensive postures, legal admissibility of evidence.

  • Intrusion Kill Chain (Lockheed Martin):

    • Phases:

      1. Reconnaissance → 2. Weaponization → 3. Delivery → 4. Exploitation → 5. Installation → 6. Command & Control (C2) → 7. Actions on Objectives.
    • Role in Delaying/Degrading Adversary: Breaking attack into stages allows detection/disruption at each phase (e.g., block delivery, detect C2).

    • Diagram:

      DiagramCANVAS: Linear flowchart of 7 Kill Chain phases with defense examples at each stage

  • Key Indicators of Intrusion (IOAs):

    • Process: Identify suspicious activities (e.g., unusual login times, data exfiltration patterns, process anomalies).

    • Passive Discovery: Monitoring network traffic without active probing (e.g., SIEM, NetFlow analysis, DNS logs).

4.2 Log Analysis

  • Significance: Primary source for reconstructing events, establishing timelines, identifying attack patterns.

  • Methods:

    • Centralized logging (SIEM), log correlation, timeline analysis, statistical anomaly detection.

    • Tools: Splunk, ELK Stack (Elasticsearch, Logstash, Kibana), Graylog.

  • Identifying Intrusion Patterns:

    • Look for: Failed login spikes, unusual outbound traffic (data exfiltration), privilege escalation events, access to sensitive files at odd hours.

4.3 Modus Operandi (MO)

  • Definition: Distinctive pattern of behavior or method used by a criminal in committing crimes.

  • Importance:

    • Linking Crimes: Same MO across incidents suggests common offender/group.

    • Profiling: Helps infer offender characteristics (skill level, motivation).

    • Predictive Analysis: Anticipate future targets/tactics.

  • Example: Consistent use of a specific phishing lure (e.g., "HR bonus") or malware variant (e.g., Emotet) across campaigns.


5.0 OFFENDER PROFILING & PSYCHOLOGY

5.1 Psychological Profiling of Cybercriminals

  • Psychological Traits & Motivations:

    • Financial: Most common (ransomware gangs, fraudsters).

    • Ideological: Hacktivists (Anonymous), state-sponsored actors.

    • Thrill/Ego: Script kiddies, bragging rights in underground forums.

    • Revenge: Disgruntled employees (insider threats).

  • Psychological Theories:

    • Routine Activity Theory: See Section 3.1.

    • General Strain Theory: See Section 3.1.

    • Social Learning Theory: Criminal behavior learned from peers (dark web forums, mentorship).

5.2 Criminal Profiling in Cybercrime

  • Concept: Inferring offender characteristics (demographics, expertise, motivation) from crime scene evidence (digital artifacts, TTPs).

  • Significance/Relevance:

    • Narrows Suspect Pool: e.g., language in malware code suggests nationality.

    • Predictive: Anticipate future targets based on MO.

    • Attribution: Linking attacks to specific groups/nations (e.g., APT28 → Russia).

  • How Profiling Aids Investigation:

    • Guides forensic focus (e.g., look for insiders if revenge motive).

    • Informs interrogation strategies.

    • Supports legal proceedings with behavioral evidence.


6.0 FRAUD DETECTION & THE FRAUD TRIANGLE

6.1 The Fraud Triangle Theory (Cressey)

  • Three Elements:

    1. Pressure: Financial need, addiction, personal problems, performance targets.

    2. Opportunity: Weak internal controls, lack of oversight, excessive access privileges.

    3. Rationalization: "I deserve this", "I’ll pay it back", "the company cheats too".

  • Role in Fraud Detection & Prevention:

    • Detection: Identify red flags (e.g., employees under financial stress with system access).

    • Prevention: Remove opportunity via segregation of duties, audits, ethical culture, whistleblower channels.

    • \boxed{\text{Fraud occurs when all three elements converge.}}

6.2 Fraud Detection Techniques

  • Role in Identifying Cyber Threats: Detect anomalies in transactions, user behavior, system logs.

  • General Methods:

    • Data Analytics: Benford’s Law for number patterns, outlier detection.

    • Machine Learning: Unsupervised learning (clustering) for anomaly detection.

    • Continuous Monitoring: Real-time transaction screening, UEBA (User and Entity Behavior Analytics).

  • Countermeasures: Multi-factor authentication, approval hierarchies, automated alerts, regular reconciliations.


7.0 MALWARE: TYPES, DETECTION & PREVENTION

7.1 Malware Fundamentals

  • Definition: Malicious software designed to harm, steal, or gain unauthorized access.

    \boxed{\text{Malware} = \text{Malicious} + \text{Software}}

7.2 Types of Malware

  • Viruses vs. Worms vs. Logic Bombs:

    | Feature | Virus | Worm | Logic Bomb | |-------------|-----------|----------|----------------| | Propagation | Needs host file (e.g., .exe) | Self-replicating, network-based | No propagation; dormant until trigger | | Activation | User action (run file) | Automatic (exploits vulnerabilities) | Condition-based (date, event) | | Example | Macro virus, file infector | WannaCry, Conficker | Triggers on employee termination |

  • Other Types: Trojans (disguised as legit), Ransomware (encrypts data), Spyware (monitors), Adware, Rootkits, Botnets.

7.3 Malware Detection & Protection

  • Detection Techniques:

    • Signature-based: Known malware patterns (antivirus databases).

    • Heuristic: Suspicious behavior (e.g., modifying system files, self-replication).

    • Behavioral: Sandboxing, monitoring API calls, memory analysis.

  • Prevention Strategies:

    • Regular patching, least privilege, user training (phishing awareness), email/ web filtering, network segmentation, regular backups, application whitelisting.

8.0 TRENDS, FUTURE THREATS & COUNTERMEASURES

8.1 Global & Recent Trends in Cybercrime

  • Global Trends:

    • Ransomware-as-a-Service (RaaS), supply chain attacks (SolarWinds), state-sponsored espionage (APT groups), IoT-based attacks.
  • Recent Trends:

    • AI-powered attacks (deepfake phishing, automated vulnerability discovery), COVID-19 themed scams, remote work vulnerabilities (VPN exploits), cryptojacking.
  • Influence on Cybersecurity Policies:

    • Stricter regulations (GDPR, India’s DPDP Act), mandatory breach notifications, international cooperation (INTERPOL, Budapest Convention), shift to zero-trust architecture.

8.2 Detecting & Countering Future Threats

  • Detection Methods:

    • Threat intelligence sharing (ISACs), AI/ML for anomaly detection, deception technology (honeypots, honeytokens), proactive threat hunting.
  • Countermeasures:

    • Deny Access: Zero-trust model, MFA, network segmentation, strict access controls.

    • Mitigate Risks: Regular backups (air-gapped), incident response plans, security awareness training, purple teaming (collaborative red/blue teams).

    • Proactive Strategies: Red teaming exercises, continuous vulnerability assessment, cyber insurance.

[!TIP] Link trends to policies: e.g., rise in ransomware → mandatory ransom payment bans (e.g., US Cyber Incident Reporting Act).

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in