Cs Module 2 Notes
Cs Module 2 Notes
1. Cybercrime against Individual: Cybercrime against individuals primarily involves activities that involve
the use of the internet and computers as a tool to extract private information from an individual, either directly
or indirectly, and disclose it on online platforms without the person’s consent or illegally in order to degrade
the person’s reputation or cause mental or physical harm.
Cybercrime against an individual is a type of cybercrime that occurs in or through the use of the internet.
Sexual, ethnic, religious, or other forms of harassment exist.
Cybercrime against an individual’s property includes computer wreckage, the destruction of other people’s
property, the delivery of destructive programs, trespassing, and unlawful possession of computer
information.
Examples of Cybercrime against Individual includes e-mail spoofing, spamming, cyber defamation, cyber
harassments and cyber stalking.
1
Cyber Security Module-II
(i) Email spoofing: A spoofed email is one in which the e-mail header is forged so that the mail
appears to originate from one source but actually has been sent from another source.
(ii) Spamming: Spamming means sending multiple copies of unsolicited mails or mass e-mails such
as chain letters.
(iii)Cyber Defamation: This occurs when defamation takes place with the help of computers and/or
the Internet. E.g. someone publishes defamatory matter about someone on a website or sends e-
mails containing defamatory information.
(iv) Harassment & Cyber stalking: Cyber Stalking Means following an individual's activity over
internet. It can be done with the help of many protocols available such as e- mail, chat rooms, user
net groups.
2. Cybercrime Against Property: This type of cybercrime against property employs cyber vandalism, in which
hackers utilize software to access sensitive data and company websites in order to steal the information of
other firms or bank details. Crimes involving intellectual property, such as copyright, patents, and trademarks,
are a form of property crime.
Examples of Cybercrime against Property includes credit card frauds, internet time theft and intellectual
property crimes.
(i) Credit Card Fraud: As the name suggests, this is a fraud that happens by the use of a credit
card. This generally happens if someone gets to know the card number or the card gets stolen.
(ii) Intellectual Property crimes: These include Software piracy: Illegal copying of programs,
distribution of copies of software. Copyright infringement: Using copyrighted material without
proper permission. Trademarks violations: Using trademarks and associated rights without
permission of the actual holder. Theft of computer source code: Stealing, destroying or
misusing the source code of a computer.
(iii)Internet time theft: This happens by the usage of the Internet hours by an unauthorized person
which is actually paid by another person.
3. Cybercrime Against Organization: The main target here is organizations. Usually, this type of crime is done
by teams of criminals including malware attacks and denial of service attacks. These include unauthorized
accessing of computer, denial of service, computer contamination / virus attack, e-mail bombing, salami
attack, logic bomb, trojan horse and data diddling.
(i) Unauthorized Accessing of Computer: Accessing the computer/network without permission
from the owner. It can be of 2 forms:
a) Changing/deleting data: Unauthorized changing of data.
b) Computer voyeur: The criminal reads or copies confidential or proprietary information, but the
data is neither deleted nor changed.
(ii) Denial Of Service: A denial-of-service (DoS) attack is a cyberattack on devices, information
systems, or other network resources that prevents legitimate users from accessing expected
services and resources. This is usually accomplished by flooding the targeted host or network with
traffic until the target can't respond or crashes, the DoS attack deprives legitimate users (i.e.,
employees, members, or account holders) of the service or resource they expected.
When Internet server is flooded with continuous bogus requests so as to denying legitimate users
to use the server or to crash the server.
(iii)Computer contamination / Virus attack: A computer virus is a computer program that can
infect other computer programs by modifying them in such a way as to include a (possibly
2
Cyber Security Module-II
evolved) copy of it. Viruses can be file infecting or affecting boot sector of the computer. Worms,
unlike viruses do not need the host to attach themselves to.
(iv) Email Bombing: Sending large numbers of mails to the individual or company or mail servers
thereby ultimately resulting into crashing.
(v) Salami Attack: When negligible amounts are removed & accumulated in to something larger.
These attacks are used for the commission of financial crimes.
(vi) Logic Bomb: It is an event dependent program. As soon as the designated event occurs, it crashes
the computer, release a virus or any other harmful possibilities.
(vii) Trojan Horse: This is an unauthorized program which functions from inside what seems to be
an authorized program, thereby concealing what it is actually doing.
(viii) Data diddling: This kind of an attack involves altering raw data just before it is processed by a
computer and then changing it back after the processing is completed.
4. Cybercrime Against Society: This is the most dangerous form of cybercrime. These include Forgery, Cyber
Terrorism, Web Jacking.
(i) Forgery: Currency notes, revenue stamps, mark sheets etc. can be forged using computers and
high-quality scanners and printers.
(ii) Cyber Terrorism: Cyber terrorism (also known as digital terrorism) is defined as disruptive
attacks by recognised terrorist organisations against computer systems with the intent of
generating alarm, panic, or the physical disruption of the information system. Use of computer
resources to intimidate or coerce people and carry out the activities of terrorism.
Examples are hacking into computer systems, introducing viruses to vulnerable networks,
web site defacing, Denial-of-service attacks, or terroristic threats made via electronic
communication.[
(iii) Web Jacking: Hackers gain access and control over the website of another, even they change
the content of website for fulfilling political objective or for money.
3
Cyber Security Module-II
4
Cyber Security Module-II
1. Cyber Stalking: Cyberstalking is a crime committed when someone uses the internet and other
technologies to harass or stalk another person online. It includes attempting to contact the women via
social networking sites without any legitimate purpose, putting threatening messages on the chat page,
and constantly disturbing the victims with objectionable emails and messages to create mental distress.
Some of the common examples of cyberstalking are:
2. Cyber Defamation: This activity involves defaming the victim through blackmailing and disclosing
their details or modified pictures. It often involves extorting and seeking sexual favors from the victim.
3. Cyber Hacking: When asked to click on unauthorised URLs or download apps that leak all their
personal information on their phones, the women became victims of cyber hacking. The criminals
utilise these details for unauthorised monetary transactions and other unlawful activities.
4. Cyber Bullying: It is an act of regular harassment and bullying of the victim through the digital
communication device by posting abusive and misleading content, pictures, or videos and sending rape
and death threats. When something abusive is shared about anyone on online platforms which humiliates,
embarrasses or degrades the reputation of the person is called cyberbullying.
Prevent Cyberbullying: Manage privacy settings online, protect your passwords, keep clear
records,Block cyberbullies via user settings, Report cyberbullying to site admins, Stay safe online.
5. Cyber Grooming: In this case, a person builds a relationship with a woman through an online platform
and pressurizes her for undue favors.
5
Cyber Security Module-II
Law Enforcement Agencies (LEAs) take legal action in line with the Indian Penal Code and the Information
Technology Act, 2000 against cyber fraud and offenders. The CCPWC is one of the Ministry’s initiatives to
enforce these laws.
Financial frauds
Cybercrime in finance is the act of obtaining financial gain through profit-driven criminal activity, including
identity fraud, ransomware attacks, email and internet fraud, and attempts to steal financial account, credit card,
or other payment card information.
Credit Card/Debit Card Fraud- Cyber criminals steal the credit card/debit card details such as card
number, CVV code, expiry date of the card, PIN, OTP etc. using various techniques such as phishing,
vishing, skimming, Spoofing and commit online banking fraud.
Online Wallet KYC Fraud- Fraudsters use series of mobile numbers and call to the victims randomly
for updating KYC of online wallet and commit fraud by taking payment credentials using different
techniques like Google Form.
Online Sell Fraud- When people use the online websites like OLX/Quickr for selling their old items,
they receive call from fraudster also. Fraudster uses UPI collect money facility and send the request to
victim for accepting the same.
Cryptocurrency Fraud-Cryptocurrency payments do not come with legal protections. Scammers are
finding new ways to steal your money using cryptocurrency. There is possibility of scam if someone
requests you to pay through cryptocurrency.
SIM Swap Fraud- Using online SIM swap facility, cyber criminals get a new SIM card issued against
your mobile number through the mobile service provider. Further, using swapped SIM (new SIM),
fraudsters get One Time Password (OTP) and other SMS alerts required to carry out online transactions
through bank account.
6
Cyber Security Module-II
7
Cyber Security Module-II
Baiting. An attacker leaves a malware-infected physical device, such as a Universal Serial Bus flash
drive, in a place it is sure to be found. The target then picks up the device and inserts it into their
computer, unintentionally installing the malware.
Phishing. When a malicious party sends a fraudulent email disguised as a legitimate email, often
purporting to be from a trusted source. The message is meant to trick the recipient into sharing
financial or personal information or clicking on a link that installs malware.
Spear phishing. This is like phishing, but the attack is tailored for a specific individual or
organization.
Vishing. Also known as voice phishing, vishing involves the use of social engineering over the phone
to gather financial or personal information from the target.
Whaling. A specific type of phishing attack, a whaling attack targets high-profile employees, such as
the chief financial officer or chief executive officer, to trick the targeted employee into disclosing
sensitive information.
Pretexting. One party lies to another to gain access to privileged data. For example, a pretexting scam
could involve an attacker who pretends to need financial or personal data to confirm the identity of
the recipient.
Scareware. This involves tricking the victim into thinking their computer is infected with malware or
has inadvertently downloaded illegal content. The attacker then offers the victim a solution that will
8
Cyber Security Module-II
fix the bogus problem; in reality, the victim is simply tricked into downloading and installing the
attacker's malware.
Watering hole. The attacker attempts to compromise a specific group of people by infecting websites
they are known to visit and trust with the goal of gaining network access.
Diversion theft. In this type of attack, social engineers trick a delivery or courier company into going
to the wrong pickup or drop-off location, thus intercepting the transaction.
Honey trap. In this attack, the social engineer pretends to be an attractive person to interact with a
person online, fake an online relationship and gather sensitive information through that relationship.
Examples of common malware include viruses, worms, Trojan viruses, spyware, adware, and
ransomware.
The trojan virus disguises itself as legitimate software.
Ransomware blocks access to the network's key components.
whereas Spyware is software that steals all your confidential data without your knowledge.
Adware is software that displays advertising content such as banners on a user's screen.
A computer virus is a program, wherein a code copies itself and replicates itself to other programs/files
on a device and may result in corrupting or damaging the device. Examples of computer virus include
Creeper, Blaster, Slammer, etc. Time taken by a virus to spread in the system is lesser in comparison to a
worm.
A computer worm is an independent malicious program, which when enters a system can start causing
harm/damage to the device. Examples of computer worm include Morris worm, storm worm, etc. A
worm can quickly spread through a device.
Use antivirus software. It can protect your computer against malware. Avast Antivirus, Norton
Antivirus, and McAfee Antivirus are a few of the popular antivirus software.
Use firewalls. Firewalls filter the traffic that may enter your device. Windows and Mac OS X have
their default built-in firewalls, named Windows Firewall and Mac Firewall.
Stay alert and avoid clicking on suspicious links.
Update your OS and browsers, regularly.
9
Cyber Security Module-II
10
Cyber Security Module-II
1. Reconnaissance and compromise: The initial reconnaissance period prior to an attack involves
criminals researching and gathering information about the target organization. They look for
network ranges, IP addresses and domain names.
2. Obtain credentials: Attackers use various tools to help them steal credentials, allowing them
to upgrade their access to administrator level
3. Submit fraudulent messages: Attackers infiltrate the network using malicious programmers
that allow them to hide in multiple systems and inject malware into critical systems. At this
point, they can start to submit fraudulent payment instructions by impersonating an operator or
approver.
4. Hide evidence: Once fraudulent payments have been sent, attackers proceed to cover their
tracks, hiding evidence of their actions. Using various tools and techniques, they delete or
manipulate records.
11
Cyber Security Module-II
Cyber Extortion
occurs when a hacker illegally accesses your organization's sensitive data or systems and then demands money
in return for allowing you to either regain control or stop the attack. If you have an ecommerce site, for example,
and a hacker launches a distributed denial-of-service (DDoS) attack, users may be unable to purchase your
products or services—not until you pay the amount the hacker is asking for.
Some examples of extortion include the mob demanding money from a business in order to keep it from
harm
Cyber warfare is usually defined as a cyber-attack or series of attacks that target a country. It has the potential to
wreak havoc on government and civilian infrastructure and disrupt critical systems, resulting in damage to the
state and even loss of life.
12
Cyber Security Module-II
What is cryptojacking?
Cryptojacking is a threat that embeds itself within a computer or mobile device and then uses its resources to
mine cryptocurrency. Cryptocurrency is digital or virtual money, which takes the form of tokens or "coins." The
most well-known is Bitcoin, but there are approximately 3,000 other forms of cryptocurrency.
Cybercriminals hack into devices to install cryptojacking software. The software works in the background,
mining for cryptocurrencies or stealing from cryptocurrency wallets.
The complaint regarding commission of cyber crime can be made to the in-charge of the cyber crime
cells which are present almost in every city.
1930 is national cybercrime helpline. If you fall victim to a financial fraud, you can call this number with
necessary details, such as your name, contact information, your account number along with the details of
the account that you transferred the money to.
To file a complaint alleging commission of a cyber crime the following documents must be provided:
1. In case of e-mail abuse, vulgar e-mail etc. the following information should be provided:
1. Extract the extended headers of offending e-mail and bring soft copy as well hard copy of offending e-
mail.
2. Please do not delete the offending e-mail from your e-mail box.
3. Please save the copy of offending e-mail on your computers hard drive.
1. Server Logs
2. Copy of defaced web page in soft copy as well as hard copy format, if your website is defaced
3. If data is compromised on your server or computer or any other network equipment, soft copy of original
data and soft copy of compromised data.
4. Access control mechanism details i.e.- who had what kind of the access to the compromised system
5. List of suspects – if the victim is having any suspicion on anyone.
6. All relevant information leading to the answers to following questions –
1. what ? (what is compromised)
13
Cyber Security Module-II
Remediation activities focus on fixing a problem to avoid or prevent the arrival of a risk. For
example, in the cybersecurity world, remediation measures are usually related to patching
vulnerabilities with software updates, to eliminate those weak spots in your cyber defenses.
Mitigation measures focus on reducing the potential damage of a threat, to levels that are tolerable
for the company or that can be accepted based on a cost-benefit analysis. Mitigation activities
address vulnerabilities that can’t be addressed via remediation — perhaps because remediation of
one issue might cause other risks, or the costs of downtime would be too high to be worth the cost.
Example: Regularly scan and take inventory of your network devices and software, Remove
unnecessary or unexpected hardware and software from the network.
Cyber Law
• Cyber Law also called IT Law is the law regarding Information-technology including computers and
the internet. It is related to legal informatics and supervises the digital circulation of information,
software, information security, and e-commerce.
• Cyber law deals with the legal aspects of cyberspace, the internet, and computing. In a broader view,
cyber law handles the issues of intellectual property, contract, jurisdiction, data protection laws, privacy,
and freedom of expression in the digital space.
14
Cyber Security Module-II
15
Cyber Security Module-II
16