UNIT 3: CYBER CRIME INVESTIGATION & DIGITAL FORENSIC
1.0 FOUNDATIONS & CLASSIFICATIONS OF CYBERCRIME
1.1 Defining Cybercrime
-
Core Definition: Any illegal activity where a computer, network, or the internet is used as a tool, target, or medium.
\boxed{\text{Cybercrime} = \text{Illegal Acts} \cap \text{Digital Environment}}
-
Nature & Extent in India:
-
Rapid growth post-Digital India; high volume of financial frauds (phishing, credit card scams).
-
Key legislation: IT Act 2000 (amended 2008), IPC provisions.
-
Challenges: Underreporting, low cyber literacy, judicial backlog.
-
-
Global Perspective:
-
Developed Countries: Advanced threats (APTs, ransomware), strong detection frameworks (e.g., US-CERT, Europol).
-
Developing Countries: Basic frauds (lottery scams, OTP frauds), infrastructure vulnerabilities.
-
[!TIP] Compare India’s high financial fraud volume with the West’s state-sponsored espionage.
-
1.2 Classifications & Taxonomy of Cybercrimes
-
Major Frameworks:
-
Against Individuals: Identity theft, cyberstalking, cyberbullying.
-
Against Property: Hacking, data theft, IPR violation, ransomware.
-
Against Government: Cyberterrorism, website defacement, espionage.
-
Against Society: Cyberpornography, online gambling, fake news.
-
-
Table: Classification with Examples
| Class | Target | Examples | |-----------|------------|--------------| | Individual | Persons | Phishing, cyberstalking, cyber defamation | | Property | Digital assets | Ransomware, data diddling, salami attacks | | Government | State infrastructure | DDoS on govt portals, logic bombs in critical systems | | Society | Community | Spread of malware, online drug trafficking |
1.3 Cybercrime vs. Conventional Crime
-
Differentiating Factors:
-
Motive: Cybercrime → financial/ideological; Conventional → emotional/impulsive.
-
Modus Operandi: Digital tools (malware, phishing) vs. physical force.
-
Evidence: Electronic (logs, metadata, volatile) vs. physical (fingerprints, eyewitnesses).
-
Jurisdiction: Transnational (cloud, dark web) vs. local.
-
Anonymity: High (VPN, Tor, crypto) vs. low (CCTV, witnesses).
-
-
Comparison Table
| Factor | Cybercrime | Conventional Crime | |------------|----------------|-----------------------| | Evidence Type | Digital footprints, volatile | Physical, durable | | Jurisdiction | Complex, cross-border | Usually local | | Scale | Mass impact (one attack → millions) | Limited to location | | Investigation | Requires digital forensics, log analysis | Scene of crime, forensics |
2.0 CYBERCRIME TAXONOMY: SPECIFIC ATTACKS & FRAUDS
2.1 Deception & Identity-Based Attacks
-
Phishing:
-
Concept: Fraudulent emails/websites to steal credentials/data.
-
Types: Spear phishing (targeted), whaling (executives), vishing (voice), smishing (SMS).
-
Threats: Leading cause of data breaches; enables further attacks (APTs).
-
-
Social Engineering:
-
Role: Manipulating humans to bypass technical controls.
-
Techniques: Pretexting, baiting (USB drops), quid pro quo, tailgating.
-
Psychological Levers: Authority, scarcity, familiarity, urgency.
-
-
Steganography:
-
Concept: Hiding data within innocent files (images, audio, video).
-
Cybersecurity Threat: Covert C2 communication, data exfiltration, malware delivery.
-
Detection: Statistical analysis, file size anomalies, entropy checks.
-
2.2 Financial & E-Commerce Frauds
-
Credit Card Frauds:
-
Modus Operandi: Skimming, phishing, data breaches (POS malware), CNP (Card-Not-Present) fraud.
-
Preventive Measures: EMV chips, tokenization, 3D Secure, AI-based anomaly detection, PCI DSS compliance.
-
-
E-commerce Frauds:
-
Challenges: Friendly fraud (false chargebacks), triangulation fraud (fake stores), delivery scams, account takeover.
-
Modern Landscape: Surge during COVID-19; cross-border complexities.
-
-
Cloud-based Frauds:
- Role in Financial Crimes: Misconfigured cloud storage → data leaks; crypto-jacking; unauthorized access to cloud financial apps.
2.3 Data & System Manipulation Attacks
-
Data Diddling:
-
Concept: Altering data before/during entry (e.g., payroll, banking transactions).
-
Detection: Audit trails, checksums, reconciliation reports.
-
Prevention: Input validation, access controls, segregation of duties.
-
-
Salami Attacks:
-
Concept: Slicing tiny amounts from many accounts (e.g., rounding down interest).
-
Mechanism: Automated scripts; hard to detect due to negligible per-account loss.
-
-
Logic Bombs:
-
Definition: Malicious code triggered by a specific condition (date, event, user action).
-
How it Works: Embedded in legitimate software; activates to delete/corrupt data or disrupt systems.
-
Prevention: Code reviews, integrity checks (hash values), least privilege, monitoring for unusual triggers.
-
-
Web Jacking:
-
Concept: Hijacking a website by compromising DNS, session hijacking, or admin credentials.
-
Impact: Traffic redirection, phishing, defacement, reputational damage.
-
-
Cross-Site Scripting (XSS):
-
Concept: Injecting malicious scripts into trusted websites executed in user’s browser.
-
Types: Stored (persistent), Reflected (non-persistent), DOM-based.
-
Prevention: Input sanitization, output encoding, Content Security Policy (CSP) headers.
-
-
Hacking vs. Cracking:
-
Hacking: Broad term for unauthorized access; can be ethical (white hat) for security testing.
-
Cracking: Specifically malicious, breaking into systems to cause harm/theft.
-
[!TIP] In exams, emphasize intent: hacking = skill, cracking = crime.
-
2.4 Harassment & Defamation Crimes
-
Cyberstalking & Cyberbullying:
-
Methods: Harassing messages, fake profiles, doxxing, non-consensual sharing of intimate images.
-
Mental Health Impact: Anxiety, depression, PTSD, suicide risk (especially in youth).
-
Measures to Combat: Legal (IT Act Sections 66A, 67; IPC 354D), awareness programs, reporting portals, counseling.
-
-
Cyber Defamation:
-
Concept: False statements online harming reputation.
-
Legal Implications: Civil (damages for libel) and criminal (IT Act, IPC Sections 499, 500). Intermediary liability under IT Act.
-
3.0 IMPACT OF CYBERCRIME
3.1 Psychological Impact
-
On Individuals:
- Trauma, loss of trust in digital systems, fear, insomnia, financial stress.
-
Cybercriminal Psychology:
-
Traits: Low empathy, high technical skill, sensation-seeking, moral disengagement.
-
Motivations: Financial gain (most common), ideology (hacktivism), thrill/ego, revenge.
-
-
Psychological Theories:
-
Routine Activity Theory: Crime occurs when motivated offender, suitable target, and absence of capable guardian converge online.
-
General Strain Theory: Stress/strain (e.g., unemployment) leads to criminal coping (cyber fraud).
-
3.2 Sociological Impact
-
On Individuals & Society:
- Erosion of trust in online interactions; social fragmentation via fake news; normalization of illegal behavior.
-
On Corporations & Governments:
- Loss of customer trust, operational disruption (e.g., NotPetya), increased security spending, regulatory scrutiny.
3.3 Economic Impact
-
On Governments:
- Infrastructure damage (power grids, hospitals), espionage costs, national security threats, loss of intellectual property.
-
On Businesses:
-
Direct loss (fraud, theft), remediation costs, reputational damage, regulatory fines (GDPR, DPDP Act), increased insurance premiums.
-
\boxed{\text{IBM 2023: Avg. cost of data breach} = $4.35 \text{ million}}
-
4.0 INVESTIGATION & THREAT ANALYSIS
4.1 Intrusion Analysis & Kill Chain
-
Intrusion Analysis:
-
Concept: Systematic examination of digital evidence to understand attack vectors, tactics, techniques, and procedures (TTPs).
-
Importance: Attribution, improving defensive postures, legal admissibility of evidence.
-
-
Intrusion Kill Chain (Lockheed Martin):
-
Phases:
- Reconnaissance → 2. Weaponization → 3. Delivery → 4. Exploitation → 5. Installation → 6. Command & Control (C2) → 7. Actions on Objectives.
-
Role in Delaying/Degrading Adversary: Breaking attack into stages allows detection/disruption at each phase (e.g., block delivery, detect C2).
-
Diagram:
DiagramCANVAS: Linear flowchart of 7 Kill Chain phases with defense examples at each stage
-
-
Key Indicators of Intrusion (IOAs):
-
Process: Identify suspicious activities (e.g., unusual login times, data exfiltration patterns, process anomalies).
-
Passive Discovery: Monitoring network traffic without active probing (e.g., SIEM, NetFlow analysis, DNS logs).
-
4.2 Log Analysis
-
Significance: Primary source for reconstructing events, establishing timelines, identifying attack patterns.
-
Methods:
-
Centralized logging (SIEM), log correlation, timeline analysis, statistical anomaly detection.
-
Tools: Splunk, ELK Stack (Elasticsearch, Logstash, Kibana), Graylog.
-
-
Identifying Intrusion Patterns:
- Look for: Failed login spikes, unusual outbound traffic (data exfiltration), privilege escalation events, access to sensitive files at odd hours.
4.3 Modus Operandi (MO)
-
Definition: Distinctive pattern of behavior or method used by a criminal in committing crimes.
-
Importance:
-
Linking Crimes: Same MO across incidents suggests common offender/group.
-
Profiling: Helps infer offender characteristics (skill level, motivation).
-
Predictive Analysis: Anticipate future targets/tactics.
-
-
Example: Consistent use of a specific phishing lure (e.g., "HR bonus") or malware variant (e.g., Emotet) across campaigns.
5.0 OFFENDER PROFILING & PSYCHOLOGY
5.1 Psychological Profiling of Cybercriminals
-
Psychological Traits & Motivations:
-
Financial: Most common (ransomware gangs, fraudsters).
-
Ideological: Hacktivists (Anonymous), state-sponsored actors.
-
Thrill/Ego: Script kiddies, bragging rights in underground forums.
-
Revenge: Disgruntled employees (insider threats).
-
-
Psychological Theories:
-
Routine Activity Theory: See Section 3.1.
-
General Strain Theory: See Section 3.1.
-
Social Learning Theory: Criminal behavior learned from peers (dark web forums, mentorship).
-
5.2 Criminal Profiling in Cybercrime
-
Concept: Inferring offender characteristics (demographics, expertise, motivation) from crime scene evidence (digital artifacts, TTPs).
-
Significance/Relevance:
-
Narrows Suspect Pool: e.g., language in malware code suggests nationality.
-
Predictive: Anticipate future targets based on MO.
-
Attribution: Linking attacks to specific groups/nations (e.g., APT28 → Russia).
-
-
How Profiling Aids Investigation:
-
Guides forensic focus (e.g., look for insiders if revenge motive).
-
Informs interrogation strategies.
-
Supports legal proceedings with behavioral evidence.
-
6.0 FRAUD DETECTION & THE FRAUD TRIANGLE
6.1 The Fraud Triangle Theory (Cressey)
-
Three Elements:
-
Pressure: Financial need, addiction, personal problems, performance targets.
-
Opportunity: Weak internal controls, lack of oversight, excessive access privileges.
-
Rationalization: "I deserve this", "I’ll pay it back", "the company cheats too".
-
-
Role in Fraud Detection & Prevention:
-
Detection: Identify red flags (e.g., employees under financial stress with system access).
-
Prevention: Remove opportunity via segregation of duties, audits, ethical culture, whistleblower channels.
-
\boxed{\text{Fraud occurs when all three elements converge.}}
-
6.2 Fraud Detection Techniques
-
Role in Identifying Cyber Threats: Detect anomalies in transactions, user behavior, system logs.
-
General Methods:
-
Data Analytics: Benford’s Law for number patterns, outlier detection.
-
Machine Learning: Unsupervised learning (clustering) for anomaly detection.
-
Continuous Monitoring: Real-time transaction screening, UEBA (User and Entity Behavior Analytics).
-
-
Countermeasures: Multi-factor authentication, approval hierarchies, automated alerts, regular reconciliations.
7.0 MALWARE: TYPES, DETECTION & PREVENTION
7.1 Malware Fundamentals
-
Definition: Malicious software designed to harm, steal, or gain unauthorized access.
\boxed{\text{Malware} = \text{Malicious} + \text{Software}}
7.2 Types of Malware
-
Viruses vs. Worms vs. Logic Bombs:
| Feature | Virus | Worm | Logic Bomb | |-------------|-----------|----------|----------------| | Propagation | Needs host file (e.g., .exe) | Self-replicating, network-based | No propagation; dormant until trigger | | Activation | User action (run file) | Automatic (exploits vulnerabilities) | Condition-based (date, event) | | Example | Macro virus, file infector | WannaCry, Conficker | Triggers on employee termination |
-
Other Types: Trojans (disguised as legit), Ransomware (encrypts data), Spyware (monitors), Adware, Rootkits, Botnets.
7.3 Malware Detection & Protection
-
Detection Techniques:
-
Signature-based: Known malware patterns (antivirus databases).
-
Heuristic: Suspicious behavior (e.g., modifying system files, self-replication).
-
Behavioral: Sandboxing, monitoring API calls, memory analysis.
-
-
Prevention Strategies:
- Regular patching, least privilege, user training (phishing awareness), email/ web filtering, network segmentation, regular backups, application whitelisting.
8.0 TRENDS, FUTURE THREATS & COUNTERMEASURES
8.1 Global & Recent Trends in Cybercrime
-
Global Trends:
- Ransomware-as-a-Service (RaaS), supply chain attacks (SolarWinds), state-sponsored espionage (APT groups), IoT-based attacks.
-
Recent Trends:
- AI-powered attacks (deepfake phishing, automated vulnerability discovery), COVID-19 themed scams, remote work vulnerabilities (VPN exploits), cryptojacking.
-
Influence on Cybersecurity Policies:
- Stricter regulations (GDPR, India’s DPDP Act), mandatory breach notifications, international cooperation (INTERPOL, Budapest Convention), shift to zero-trust architecture.
8.2 Detecting & Countering Future Threats
-
Detection Methods:
- Threat intelligence sharing (ISACs), AI/ML for anomaly detection, deception technology (honeypots, honeytokens), proactive threat hunting.
-
Countermeasures:
-
Deny Access: Zero-trust model, MFA, network segmentation, strict access controls.
-
Mitigate Risks: Regular backups (air-gapped), incident response plans, security awareness training, purple teaming (collaborative red/blue teams).
-
Proactive Strategies: Red teaming exercises, continuous vulnerability assessment, cyber insurance.
-
[!TIP] Link trends to policies: e.g., rise in ransomware → mandatory ransom payment bans (e.g., US Cyber Incident Reporting Act).