Chapter 4
FUNDAMENTALS OF CYBER SECURITY
Cybercrime refers to any illegal activity that involves computers, digital
devices, or networks as:
The target of the crime (e.g., hacking a website),
The tool used to commit the crime (e.g., using malware to steal data),
Examples:
Stealing credit card details via phishing emails.
Disabling a government website through a DDoS attack.
Spreading ransomware to lock and extort victims’ files.
Definitions
Cyberspace
Cybersquatting
Cyberpunk
Cyberwarfare
Cyberterrorism
Cybercrime and Its Foundations
“Cyber security is the protection of internet-connected
systems, including hardware, software and data, from
cyber attacks”.
• “Cybersecurity” means protecting information,
equipment, devices, computer, computer resource,
communication device and information stored therein from
unauthorized access, use, disclosure, disruption,
modification or destruction.
• Almost everyone is aware of the rapid growth of the
Internet.
• Given the unrestricted number of free websites, the
Internet has undeniably opened a new way of exploitation
known as cybercrime
CYBERCRIME: DEFINITION AND ORIGINS OF THE WORD
Definition: “A crime conducted in which a computer was directly
and significantly instrumental is called as a Cybercrime.”
Alternative definitions of Cybercrime are as follows:
1. Any illegal act where a special knowledge of computer
technology is essential for its perpetration (to commit a crime),
investigation or prosecution.
2. Any traditional crime that has acquired a new dimension or
order of magnitude through the aid of a computer, and abuses
that have come into being because of computers.
3. Any financial dishonesty that takes place in a computer
environment.
4. Any threats to the computer itself, such as theft of hardware or
software, damage and demands for money.
5. “Cybercrime (computer crime) is any illegal behavior, directed
by means of electronic operations, that targets the security of
computer systems and the data processed by them
The term “cybercrime” relates to a number of
other terms that may sometimes be used to
describe crimes committed using computers.
• Computer-related crime
• Computer crime
• Internet crime
• E-crime
• High-tech crime, etc. are the other
synonymous terms.
Cybercrime specifically can be defined in a
number of ways; a few definitions are:
1. A crime committed using a computer and the Internet
to steal a person’s identity (identity theft) or sell
contraband or stalk victims or disrupt operations with
malevolent programs.
2. Crimes completed either on or with a computer.
3. Any illegal activity done through the Internet or on the
computer.
4. All criminal activities done using the medium of
computers, the Internet, cyberspace and the WWW.
Cybercrime and Information Security
who are Cybercriminals?
Cybercriminals are individuals or groups who use computers
and the internet to commit illegal activities, causing harm to
individuals, businesses, and organizations. Their actions often
involve hacking, data theft, malware attacks, and financial
fraud, with the primary goal of financial gain, disruption, or
unauthorized access to data.
Cybercriminals employ a variety of tactics and techniques to
carry out their attacks, often leveraging technology to deceive
and defraud individuals and organizations. These tactics
include phishing, social engineering, malware, and
exploiting vulnerabilities in systems and networks. They may
also use fake websites, ransomware, and other methods to gain
access to sensitive information or extort money
Categories of Cybercriminals
Type I: Cybercriminals – Hungry for recognition
• Hobby Hackers
• IT professionals (social engineering)
• Politically motivated hackers
• Terrorist organization
Type II: Cybercriminals – Not interested in recognition
• Psychological perverts
• Financially motivated hackers
• Organized criminals
Type III: Cybercriminals – The insiders
• Formal employees seeking revenge
• Competing companies using employee to gain economic advantage
Types of Cybercrimes:-
Financial Crime
Cyber-enabled financial crimes involve using computers, networks, or the internet to steal money,
manipulate financial data, or commit fraud for monetary gain.
Technology-based execution: Uses online banking systems, payment gateways, or digital
wallets.
Often cross-border: Criminals operate from different countries.
Can be high-speed & automated: Large sums moved within seconds.
Bangladesh Bank Heist (2016)
Hackers breached the bank’s systems via phishing emails.
Sent fraudulent transfer requests via SWIFT network.
Nearly $1 billion targeted; $81 million stolen and laundered through casinos.
Forgery
Forgery in cybercrime refers to the act of creating, altering, or imitating digital documents,
certificates, or signatures with the intent to deceive and commit fraud.
Involves manipulation of digital files (PDFs, certificates, images).
Can target legal, financial, or identity documents.
Often used to bypass authentication or gain benefits illegally.
Fake University Degree Scam (India, 2019)
Criminals ran an online service selling fake degrees.
Used forged digital seals and scanned signatures.
Hundreds of fake certificates sold for jobs and visas.
Web defacement
Web defacement is a cybercrime where an attacker gains unauthorized access to a website and modifies
its visual appearance or content, usually replacing legitimate pages with their own messages, images, or
propaganda.
Real-World Example Malaysian Airlines Website Defacement (2015)
Hackers replaced the homepage with a political message and altered images.
Claimed responsibility as part of cyber protest.
Damaged the company’s global reputation during an already sensitive period.
Data diddling
Data diddling is the act of altering or modifying data before it is entered into a computer system or
during its processing, usually to commit fraud or manipulate outcomes.
It often occurs at the input stage where data integrity is weakest.
Occurs before data storage or during transmission.
Can be manual (done by a person entering data) or automated (via scripts/malware).
Difficult to detect without audit trails.
Real-World Example Payroll Fraud Case
Employee responsible for salary processing changes his own pay amount from ₹50,000 to ₹80,000 before
final submission.
Company pays inflated amount for several months before detection.
Email frauds
Email frauds involve deceptive messages sent via email to trick recipients into revealing sensitive
information, sending money, or downloading malicious software. They are one of the most common
forms of social engineering attacks.
Disguised to look authentic (using fake sender addresses, logos, and formatting).
Often urgent or emotional to pressure the recipient into acting quickly.
May contain malicious attachments or links to phishing websites.
Real-World Example Nigerian Prince Scam
Victim receives email from a “royal” asking for help to transfer millions of dollars.
Victim is asked to send a small processing fee, but the money is never returned.
Has scammed people worldwide for decades.
Hacking
Hacking is the unauthorized access, intrusion, or control of computer systems, networks, or
data with the intent to steal, alter, damage, or disrupt operations.
Hackers may exploit security vulnerabilities in hardware, software, or human behavior.
Can be malicious (black hat) or ethical (white hat for security testing).
Often involves bypassing authentication mechanisms.
May use specialized software tools, scripts, or malware.
Real-World Example Yahoo Data Breach (2013–2014)
Attackers compromised 3 billion Yahoo accounts.
Stole emails, passwords, and security questions.
Led to major financial losses and legal settlements.
Tampering
In cybercrime, tampering refers to the unauthorized alteration, modification, or
interference with data, software, hardware, or network configurations to cause harm, gain
advantage, or bypass security controls. It can occur physically (hardware tampering) or
digitally (data/code tampering).
Involves changing rather than just stealing or deleting. Can target data integrity
(changing values), system behavior (modifying code), or security settings (weakening
controls). Often part of larger attacks such as fraud or espionage.
Real-World Example Stuxnet Worm (2010)
Targeted Iran’s nuclear program. Tampered with the control system’s code to make
centrifuges malfunction while showing false readings. Caused physical damage without
immediate detection.
Spamming
Spamming is the act of sending large volumes of unsolicited messages —
usually via email, but also through instant messaging, social media, and
SMS — often for advertising, phishing, or spreading malware.
Real-World Example
In 2010, a botnet called Rustock was responsible for over 40% of the world’s
spam emails, promoting fake pharmaceuticals.
Pharming
Pharming is a cybercrime where users are redirected from a legitimate
website to a fraudulent one without their knowledge, even if they type the
correct web address.
It is often considered a more advanced form of phishing because it doesn’t
rely solely on tricking the victim through fake emails — it manipulates the
internet infrastructure itself.
Real-World Example Brazilian Banking Pharming Attack (2017):
Cybercriminals altered DNS settings on over 180,000 routers, redirecting
users to fake banking portals and stealing credentials.
Spyware
Spyware is malicious software that secretly monitors and collects
information from a user’s device without their consent.
It can record browsing habits, keystrokes, login credentials, and even
capture screenshots.
Real-World Example
CoolWebSearch Spyware (2000s) – Hijacked browsers, altered search
results, and collected user browsing history to sell to advertisers.
Botnet
A botnet is a network of internet-connected devices that have been
infected with malware and are controlled remotely by a cybercriminal,
known as a botmaster.
Each infected device, called a zombie, can be used to perform
coordinated cyberattacks.
Real-World Example
Mirai Botnet (2016): Infected IoT devices (like cameras, routers) and
launched massive DDoS attacks, taking down Twitter, Netflix, and other
major websites.
Planning and Execution of Cyber
Offenses
How Stalking works?
Cybercrime and cloud computing
Ethical Hacking
Ethical hacking is the legal and professional
practice of testing computer systems, networks,
and applications. This is done to find and fix
security weaknesses before malicious hackers
can exploit them.
It involves using hacking techniques, but with
permission and a positive goal. The aim is to
protect digital assets and improve overall
cybersecurity.
Ethical hacking plays a crucial role in:
Strengthening an organization’s security
posture.
Ensuring compliance with cybersecurity
standards.
Building resilience against cyberattacks.
Uses hacking techniques with prior
approval from the system owner.
Key aspects of Ethical Hacking
Reporting: Ethical hackers report back to the organization with the results
of the tests.
Permission-Based: This permission becomes necessary to differentiate
their job from criminal hacking jobs
Objective: The main goal is to find the holes before hostile attackers can
penetrate them. This includes discovering system, application, and
network vulnerabilities that an attacker could exploit.
Methodology: Ethical hackers perform these steps using a variety of tools
and techniques, similar to criminal hackers. It includes scanning for
vulnerabilities testing to break in, and accessing control measures
available.
Importance of Ethical Hacking
Enhance Security: Identify and address flaws to stop
data breaches and cyberattacks.
Compliance: Meet security standards set by the
industry and regulatory requirements.
Management of risk: Assess and reduce potential
threats to the assets of the organization
Occurrence Reaction: Enhance the company's
capacity to respond to security incidents and
recover from them.
Types of Ethical Hacking
Hacking the network: involves testing the infrastructure of the
network in order to find flaws in the protocols, configurations, and
devices of the network
Hacking Web Applications: Centers around distinguishing
shortcomings in web applications, for example, SQL injection or
cross-website prearranging (XSS) weaknesses
Hacking the system: Targets working frameworks and programming
to find security defects that could be taken advantage of.
Social Designing: attempts to manipulate individuals into revealing
confidential information or performing actions that could
compromise security, putting the human element to the test.
Hacking into wireless networks: involves identifying potential
dangers in wireless communications and evaluating the security of
wireless networks.
Types of Ethical Hackers
White Hat Hackers: Here, we look for bugs and ethically report
them to the organization. We are authorized as a user to test for
bugs in a website or network and report it to them. White hat
hackers generally get all the needed information about the
application or network to test for, from the organization itself.
They use their skills to test it before the website goes live or
attacked by malicious hackers. To become a white hat hacker,
you can earn a bachelor's degree in computer science,
information technology, or cybersecurity. In addition, certifications
such as Certified Ethical Hacker (CEH) and Certified Information
Systems Security Professional (CISSP) are highly recommended.
Black Hat Hackers: Here, the organization doesn't allow the user to test it. They
unethically enter inside the website and steal data from the admin panel or
manipulate the data. They only focus on themselves and the advantages they
will get from the personal data for personal financial gain. They can cause
major damage to the company by altering the functions which lead to the loss
of the company at a much higher extent. This can even lead you to extreme
consequences.
Grey Hat Hackers: They sometimes access to the data and violates the law. But
never have the same intention as Black hat hackers, they often operate for the
common good. The main difference is that they exploit vulnerability publicly
whereas white hat hackers do it privately for the company. One criticism of
Grey Hat hackers is that their actions can still cause harm. Even if they do not
steal or damage data, their unauthorized access to computer systems can still
disrupt operations and cause financial losses for companies. Additionally, there
is always the risk that a Grey Hat hacker will accidentally cause damage while
attempting to identify vulnerabilities.
Blue Hat hackers: They are much like the script kiddies, are
beginners in the field of hacking. If anyone makes angry a
script kiddie and he/she may take revenge, then they are
considered as the blue hat hackers. Blue Hat hackers
payback to those who have challenged them or angry
them. Like the Script Kiddies, Blue hat hackers also have no
desire to learn.
Green Hat hackers : They are also amateurs in the world of
hacking but they are bit different from script kiddies. They
care about hacking and strive to become full-blown
hackers. They are inspired by the hackers and ask them
few questions about. While hackers are answering their
question they will listen to its novelty.
Red Hat Hackers: They are also known as the
eagle-eyed hackers. Like white hat hackers, red
hat hackers also aims to halt the black hat
hackers. There is a major difference in the way
they operate. They become ruthless while dealing
with malware actions of the black hat hackers.
Red hat hacker will keep on attacking the hacker
aggressively that the hacker may know it as well
have to replace the whole system.