Skip to content
CY-601 · Cyber Crime Investigation & Digital Forensic/Quick Revision Short Notes

Cyber Crime Investigation & Digital Forensic (CY-601) - Unit 5 Short Notes

UNIT 5: CYBER CRIME INVESTIGATION & DIGITAL FORENSIC


I. FOUNDATIONS & CLASSIFICATIONS

Definition & Nature of Cybercrime

  • Definition: Cybercrime refers to illegal activities committed using computers, networks, or the internet as a tool, target, or place.

  • Nature:

    • Borderless: Transcends geographical boundaries.

    • Anonymity: Perpetrators can hide identity.

    • Digital Evidence: Evidence is volatile, intangible, and requires special handling.

    • Low Risk, High Reward: Often perceived as having a low chance of getting caught.

  • Nature & Extent: India vs. Other Countries:

    • India: Rapid digitization (UPI, Aadhaar) has increased attack surface. Challenges include low cyber literacy, under-reporting, and judicial backlog. IT Act, 2000 (amended) and IPC provisions are used.

    • Developed Countries (e.g., USA, EU): More advanced CERTs, stricter data protection laws (GDPR), higher public awareness, but face sophisticated state-sponsored attacks.

    • Developing Nations: Often lack resources, legislation, and trained personnel, becoming targets for both cybercriminals and as launching pads for attacks.

Classifications & Taxonomy of Cybercrimes

  • Primary Classifications:

    | Category | Target | Examples | | :--- | :--- | :--- | | Against Persons | Individual | Cyberstalking, cyberbullying, defamation, phishing | | Against Property | Digital/Physical Assets | Hacking, malware, DDoS, data theft, intellectual property theft | | Against Government | National Infrastructure | Cyberterrorism, website defacement, espionage | | Against Society | Public Order | Pornography, online gambling, sale of illegal substances |

  • Detailed Classification (Tool vs. Target):

    • Computer as a Tool: Using a computer to commit a traditional crime (e.g., online fraud, harassment).

    • Computer as a Target: Crime where the computer/system is the primary objective (e.g., hacking, malware infection, DDoS).

    • Computer as an Accessory: Using a computer to store evidence or plan crimes (e.g., storing illegal content).

  • Cybercrime in Developed vs. Developing Nations:

    • Developed: Focus on cyber espionage, critical infrastructure attacks, advanced persistent threats (APTs). Stronger legal frameworks.

    [!TIP] Exam often asks for key differences—focus on resources, legislation, and nature of attacks (sophisticated vs. opportunistic).

Conventional Crimes vs. Cybercrimes

Aspect Conventional Crime Cybercrime
Modus Operandi Physical presence, tangible tools Remote, digital tools, no physical presence needed
Evidence Physical (fingerprints, weapons), witnesses Digital (logs, metadata), volatile, easily altered
Jurisdiction Clear geographical boundaries Borderless; complex international jurisdiction
Anonymity Harder to maintain Easier via encryption, proxy, dark web
Impact Scale Localized Can be global instantly (e.g., worm)
Example Burglary, assault Phishing, ransomware, DDoS

II. TYPES, MODUS OPERANDI & ATTACK VECTORS

Financial & E-Commerce Frauds

  • Credit/Debit Card Frauds:

    • Modus Operandi: Skimming (card data theft), phishing (tricking into disclosure), vishing (voice phishing), malware on POS systems, data breaches.

    • Preventive Measures: Use chip cards, tokenization, 2FA, monitor statements, secure websites (HTTPS), avoid public Wi-Fi for transactions.

  • E-Commerce Frauds:

    • Challenges: Fake websites, non-delivery of goods, selling counterfeit items, triangulation fraud, return fraud.

    • Prevention: Seller verification, secure payment gateways, buyer reviews, OTP confirmation, AI for fraud pattern detection.

  • Cloud-Based Frauds:

    • Role: Exploiting misconfigured cloud storage (S3 buckets), compromised cloud credentials, insecure APIs, cryptojacking (using cloud resources for crypto mining).

Specific Cyber Attack Techniques & Malwares

  • Malware Fundamentals: Malicious software designed to harm, steal, or gain unauthorized access.

  • Viruses, Worms, and Logic Bombs:

    | Feature | Virus | Worm | Logic Bomb | | :--- | :--- | :--- | :--- | | Propagation | Needs host file/program; user action to spread | Self-replicates; spreads via network/email automatically | Does not replicate; dormant code | | Trigger | Executes when host file runs | Exploits vulnerabilities automatically | Triggered by specific event/date/time | | Impact | Corrupts/modifies files, steals data | Consumes bandwidth, creates botnets, drops other malware | Data deletion, system crash, sabotage | | Example | File infector virus | ILOVEYOU worm, WannaCry (worm-like) | Disgruntled employee sets bomb to delete files on last day |

  • Phishing & Variants:

    • Concept: Deceptive emails/messages to trick victims into revealing credentials or clicking malicious links.

    • Variants: Spear phishing (targeted), whaling (targeting executives), vishing (voice), smishing (SMS).

    • Threat: Primary vector for malware delivery and credential theft.

  • Steganography: Hiding malicious code or data within innocent-looking files (images, audio). Used for data exfiltration or command-and-control.

  • Data Diddling: Altering data before or during input into a system (e.g., changing bank details, salary amounts). Detection via input validation, audit trails.

  • Salami Attacks: Slicing off tiny amounts from multiple accounts (e.g., rounding down interest, fractional cents) and aggregating them. Requires access to financial systems.

  • Social Engineering: Manipulating humans to bypass security (pretexting, baiting, quid pro quo). Largest attack vector.

  • Cross-Site Scripting (XSS): Injecting malicious scripts into trusted websites. Executes in victim's browser, steals cookies/session tokens.

  • Web Jacking: Taking control of a website by hacking DNS or server credentials and redirecting users to a fake site.

Cyber Offenses Against Individuals

  • Cyberstalking & Cyberbullying: Repeated harassment/threats online. Impact: Anxiety, depression, suicide. Measures: Legal provisions (IT Act, IPC), platform reporting, digital literacy, counseling.

  • Cyber Defamation: Publishing false statements online harming reputation. Legal Implications: Defamation laws (IPC Section 499/500) apply; IT Act Section 66A (now struck down) was previously used.

  • Crimes on Social Networking Sites: Identity theft, fake profiles, revenge porn, hate speech, grooming.

Hacking, Cracking & Unauthorized Access

  • Hacking vs. Cracking:

    | Hacking | Cracking | | :--- | :--- | | Exploration of systems for learning/improvement (ethical) | Unauthorized access with malicious intent (theft, damage) | | Often done with permission (penetration testing) | Always illegal | | Goal: Identify vulnerabilities to fix | Goal: Exploit vulnerabilities for gain |

  • Intrusion: Unauthorized access to a system/network. First step in many attack chains.


III. IMPACT ANALYSIS

Psychological Impact & Criminal Profiling

  • Psychological Traits & Motivations of Cybercriminals:

    • Traits: High technical skill, curiosity, sensation-seeking, low empathy, rationalization.

    • Motivations: Financial gain, thrill/ego, political ideology (hacktivism), revenge, espionage.

  • Psychological Theories:

    • Rational Choice Theory: Criminals weigh costs vs. benefits; low perceived risk in cybercrime.

    • Strain Theory: Pressure (financial, social) leads to crime; cybercrime offers easy solutions.

    • Social Learning Theory: Learning from peers in online communities/forums.

  • Criminal Profiling:

    • Significance: Analyzes digital footprints, MO, tools, and target selection to infer offender characteristics (skill level, motive, location).

    • Application: Links crimes, narrows suspect pool, predicts future targets.

  • Impact on Individual Victims: Psychological trauma (fear, anxiety), financial loss, reputational damage, invasion of privacy.

Sociological Impact

  • On Individuals: Erosion of trust in online interactions, social isolation, normalization of deviant behavior.

  • On Corporations: Reputational damage, loss of customer trust, operational disruption, increased security costs.

  • On Governments: Undermines public trust in institutions, threatens national security, challenges sovereignty.

Economic Impact

  • On Governments: Costs of infrastructure protection, incident response, lost tax revenue from cybercrime proceeds, national security expenditures.

  • On Businesses: Direct financial losses (theft, fraud), remediation costs, regulatory fines (GDPR), brand devaluation, increased insurance premiums.

  • Global Cost: Estimated in trillions of USD annually (e.g., $6 trillion+ by some reports), growing with IoT/cloud adoption.


IV. INVESTIGATION, ANALYSIS & DETECTION METHODOLOGIES

Intrusion Analysis & Kill Chain

  • Intrusion Analysis: Process of examining logs, network traffic, and system artifacts to identify, understand, and document a security breach.

    • Importance: Determines scope, impact, attacker TTPs (Tactics, Techniques, Procedures), and evidence for legal action.
  • Key Indicators of Intrusion (IoIs): Anomalies suggesting an attack (e.g., unusual login times, high outbound traffic, unknown processes, failed login spikes).

  • Intrusion Kill Chain (Lockheed Martin):

    [!TIP] Memorize the 7 phases—they are very high frequency.

    1. Reconnaissance: Research target.

    2. Weaponization: Couple exploit with backdoor.

    3. Delivery: Transmit weapon (email, USB, web).

    4. Exploitation: Trigger exploit to gain foothold.

    5. Installation: Install malware/backdoor.

    6. Command & Control (C2): Establish remote control channel.

    7. Actions on Objectives: Achieve goal (data exfiltration, destruction).

    • Role: Helps defenders detect early (at Delivery/Exploitation) and degrade adversary at each phase (e.g., email filtering blocks Delivery, patching blocks Exploitation).

Fraud Detection & The Fraud Triangle

  • Fraud Triangle Theory (Donald Cressey):

    \boxed{Fraud = Pressure + Opportunity + Rationalization}

    • Pressure: Financial need, greed, addiction.

    • Opportunity: Weak controls, access, lack of supervision.

    • Rationalization: "I deserve it," "I'll pay it back."

  • Role in Detection: Identifying Opportunity (control weaknesses) is key for prevention. Profiling for Pressure and Rationalization aids investigation.

  • Fraud Detection Techniques: Data analytics (anomaly detection), Benford's Law (numerical analysis), whistleblower channels, continuous auditing, AI/ML for pattern recognition.

Log Analysis & Modus Operandi

  • Importance of Log Analysis:

    • Provides chronological record of events.

    • Identifies attack vectors, timeline, and affected systems.

    • Source of digital evidence for legal proceedings.

  • Process of Log Analysis:

    1. Collection: Aggregate logs from systems, network devices, applications.

    2. Normalization: Convert to common format.

    3. Correlation: Link events from different sources (e.g., firewall + server log).

    4. Analysis: Look for anomalies, IoIs, patterns.

    5. Documentation: Create timeline and report.

  • Modus Operandi (MO):

    • Definition: Distinctive pattern of behavior, methods, and tools used by a criminal.

    • Importance: Links crimes to same offender/group; helps predict future attacks; crucial for profiling.

    • Example: A hacker always uses a specific exploit kit, leaves a unique signature in malware code, and attacks at a certain time.


V. PREVENTIVE MEASURES, TRENDS & FUTURE CHALLENGES

Countermeasures & Prevention Strategies

  • Countermeasures to Deny Access:

    • Technical: Firewalls, IDS/IPS, access controls (RBAC), encryption, network segmentation, MFA.

    • Administrative: Security policies, background checks, least privilege, regular audits.

  • Preventive Measures for Specific Attacks:

    • Phishing: User training, email filtering, DMARC/SPF/DKIM, URL scanning.

    • Malware: Antivirus/EDR, patching, application whitelisting, sandboxing.

    • Logic Bombs: Code review, integrity monitoring, least privilege, separation of duties.

    • Credit Card Fraud: Tokenization, PCI DSS compliance, fraud detection algorithms.

  • Methods for Detecting Future Threats:

    • Proactive: Threat hunting, red teaming, penetration testing.

    • Predictive: Threat intelligence feeds, AI/ML for anomaly detection, behavioral analytics.

Global Trends & Policy Implications

  • Recent & Global Trends:

    • Ransomware-as-a-Service (RaaS).

    • Supply chain attacks (SolarWinds).

    • Cryptocurrency-related crimes (ransom payments, mixing).

    • State-sponsored attacks and cyber warfare.

    • AI-powered attacks (deepfakes, automated phishing).

  • Influence on Policies & Frameworks:

    • Drives national cybersecurity strategies (e.g., India's National Cyber Security Policy).

    • Leads to international cooperation (Budapest Convention, UN negotiations).

    • Shapes regulations (GDPR, India's DPDP Act) focusing on data protection and breach notification.

    • Promotes public-private partnerships for threat sharing.

Emerging Challenges

  • Technology Evolution: IoT (massive attack surface), AI (both for defense and offense), Cloud (shared responsibility confusion), Quantum computing (breaking encryption).

  • Jurisdictional Hurdles: No global cyber law; extradition difficulties; conflicting national laws.

  • Legal & Evidentiary: Cross-border evidence collection, encryption vs. privacy, attribution challenges.

  • Skills Gap: Shortage of trained cyber forensic investigators and analysts globally.

  • Anonymity Tools: Tor, cryptocurrencies, bulletproof hosting enable criminals.

[!TIP] Exam Focus: Always connect trends to policy (e.g., "Ransomware surge leads to mandatory breach disclosure laws"). For challenges, emphasize jurisdiction and attribution as core issues in cybercrime investigation.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in