0% found this document useful (0 votes)
5 views12 pages

Cs Module 1 Notes

The document provides an overview of cyber security, emphasizing its importance in protecting individuals and organizations from increasing cyber threats. It defines key concepts such as cyberspace, internet governance, and the architecture of cyberspace, while also outlining various categories of cyber security and the challenges faced in the field. Additionally, it highlights the significance of communication and regulation in maintaining a secure digital environment.

Uploaded by

Prathyusha Rao
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views12 pages

Cs Module 1 Notes

The document provides an overview of cyber security, emphasizing its importance in protecting individuals and organizations from increasing cyber threats. It defines key concepts such as cyberspace, internet governance, and the architecture of cyberspace, while also outlining various categories of cyber security and the challenges faced in the field. Additionally, it highlights the significance of communication and regulation in maintaining a secure digital environment.

Uploaded by

Prathyusha Rao
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Cyber Security Module-I

Introduction to Cyber security

Cyber Security Introduction - Cyber Security Basics:


Cyber security is the most concerned matter as cyber threats and attacks are overgrowing. Attackers are now using
more sophisticated techniques to target the systems. Individuals, small-scale businesses or large organization, are
all being impacted. So, all these firms whether IT or non-IT firms have understood the importance of Cyber
Security and focusing on adopting all possible measures to deal with cyber threats.

What is cyber security?


"Cyber security is primarily about people, processes, and technologies working together to encompass the full
range of threat reduction, vulnerability reduction, deterrence, international engagement, incident response,
resiliency, and recovery policies and activities, including computer network operations, information assurance,
law enforcement, etc."
OR
Cyber security is the body of technologies, processes, and practices designed to protect networks, computers,
programs and data from attack, damage or unauthorized access.
 The term cyber security refers to techniques and practices designed to protect digital data.
 The data that is stored, transmitted or used on an information system.
OR
Cyber security is the protection of Internet-connected systems, including hardware, software, and data from cyber-
attacks.
It is made up of two words one is cyber and other is security.
 Cyber is related to the technology which contains systems, network and programs or data.
 Whereas security related to the protection which includes systems security, network security and
application and information security.

Communication in Cyber Security


Providing information on any risks or potential threats is a key part of any cybersecurity communication plan.
Because cybersecurity threats move rapidly, proper and effective communication is necessary to keep clients
informed. This means your teams must communicate both proactively and reactively for true security.
Communication is a foundational component of all work in cybersecurity. Communication happens in many
forms, written, spoken, and even non-verbal. It happens in large groups and small.

1
Cyber Security Module-I

Defining Cyberspace
Cyberspace can be defined as an intricate environment that involves interactions between people, software, and
services. It is maintained by the worldwide distribution of information and communication technology devices
and networks.
 With the benefits carried by the technological advancements, the cyberspace today has become a common
pool used by citizens, businesses, critical information infrastructure, military and governments in a fashion
that makes it hard to induce clear boundaries among these different groups. The cyberspace is anticipated
to become even more complex in the upcoming years, with the increase in networks and devices connected
to it.

Architecture of cyberspace
Cyberspace architecture refers to the structural framework and infrastructure that supports the interconnected
network of digital systems, including the internet, data centers, cloud services, and various communication
networks. It encompasses a broad spectrum of components, technologies, and protocols that enable the seamless
flow of information across the digital domain.
Key Components of Cyberspace Architecture
1. Network Infrastructure: Network infrastructure, which includes physical and virtual components such as
routers, switches, servers, and transmission lines.
2. Data Centers: Data centers serve as the centralized hubs for storing, processing, and managing vast
amounts of digital information.
3. Protocols and Standards: Cyberspace architecture relies on a multitude of protocols and standards to
ensure interoperability and seamless communication between different devices and platforms. Examples
include TCP/IP for internet communication, HTTP for web browsing, and SMTP for email transmission.
4. Cloud Computing Infrastructure: Cloud computing has significantly influenced cyberspace architecture,
with cloud providers offering scalable resources, virtualized environments, and on-demand services to
support diverse workloads and applications.

Communication and web technology


Web Technology
Web Technology refers to the various tools and techniques that are utilized in the process of communication between
different types of devices over the Internet. A web browser is used to access web pages. Web browsers can be defined
as programs that display text, data, pictures, animation, and video on the Internet.

Web Technology can be classified into the following sections:

 World Wide Web (WWW): The World Wide Web is based on several different technologies: Web
browsers, Hypertext Markup Language (HTML), and Hypertext Transfer Protocol (HTTP).
 Web Browser: The web browser is an application software to explore www (World Wide Web). It
provides an interface between the server and the client and requests to the server for web documents and
services.
 Web Server: Web server is a program which processes the network requests of the users and serves them
with files that create web pages. This exchange takes place using Hypertext Transfer Protocol (HTTP).

2
Cyber Security Module-I

 Web Pages: A webpage is a digital document that is linked to the World Wide Web and viewable by
anyone connected to the internet has a web browser.
 Web Development: Web development refers to the building, creating, and maintaining of websites. It
includes aspects such as web design, web publishing, web programming, and database management. It is
the creation of an application that works over the internet i.e., websites.

Internet
The Internet is a vast network that connects computers all over the world. Through the Internet, people can share
information and communicate from anywhere with an Internet connection.

 Internet security refers to security designed to protect systems and the activities of employees and other
users while connected to the internet, web browsers, web apps, websites, and networks.

 History of the Internet


The Internet came in the year 1960 with the creation of the first working model called ARPANET
(Advanced Research Projects Agency). It allowed multiple computers to work on a single network which was
their biggest achievement at that time. ARPANET uses packet switching to communicate multiple computer
systems under a single network. In October 1969, using ARPANET first message was transferred from one
computer to another. After that technology continues to grow.

 How Does the Internet Work?


The Internet works through a series of networks that connect devices around the world through telephone
lines. Users are provided access to the Internet by Internet service providers. The widespread use of mobile
broadband and Wi-Fi in the 21st century has allowed this connection to be wireless.

 Features of Internet
Major features of the Internet are listed below:

 Easy to Use: The software that is used to access the Internet or web browser is designed in such a way
that is very simple and can be easily learned and used. Also, it is easy to develop.
 Flexibility: Flexibility in terms of transfer of data. Basically, the internet network carries information in
digital form in a majority of cases instead of voice information in analog form.
 Accessibility: Internet service is a worldwide service and access to all. People located in remote or
anywhere interior can also use the Internet. Therefore, information through the internet flows across the
networks in a standardized manner.
 Interaction with Media and Flexibility of Communication: Businesses are expanding with the help of
the Internet. There is a high degree of interaction with the media due to internet service. Like, News,
magazines, publishing houses, etc. have extended their business with the help of Internet service. Also,
communication is flexible due to internet service. With the help of text voice, video people can
communicate easily.
 Low Cost and Security: The maintenance and development costs of Internet service are comparatively
low. Also, Internet service helped the security system both at an individual and national levels. For
example, CCTV cameras, etc.

3
Cyber Security Module-I

The Internet Infrastructure:

1. Local Area Networks (LAN)


2. Internet Service Providers (ISP)
3. The Domain Name System (DNS)
4. Cloud Services
5. The Internet
6. Intranets

1. Local Area Networks (LAN)


A LAN comprises cables, access points, switches, routers, and other components that enable devices to
connect to internal servers, web servers, and other LANs via wide area networks. A local area network (LAN)
consists of a series of computers linked together to form a network in a circumscribed location. The computers in
a LAN connect to each other via TCP/IP ethernet or Wi-Fi.
2. Internet Service Providers (ISP)
An internet service provider (ISP) is a company that provides access to the internet. ISPs can provide this
access through multiple means, including dial-up, DSL, cable, wireless and fiber-optic connections.
3. The Domain Name System (DNS)
The Domain Name System (DNS) is the phonebook of the Internet. Humans access information online
through domain names, like [Link] or [Link]. Web browsers interact through Internet Protocol
(IP) addresses. DNS translates domain names to IP addresses so browsers can load Internet resources.

4. Cloud Services(Cloud computing)


Cloud services are application and infrastructure resources that exist on the Internet. Third-party providers
contract with subscribers for these services, allowing customers to leverage powerful computing resources
without having to purchase or maintain hardware and software.
 The main three types of cloud computing are public cloud, private cloud, and hybrid cloud. Within
these deployment models, there are four main services: infrastructure as a service (IaaS), platform as a
service (PaaS), software as a service (SaaS), and serverless computing.
5. The Internet
The Internet connects ISPs, the DNS, and Cloud Services together, and allows them to communicate.
6. Intranets
A private network utilized by a company might be referred to as an intranet. Its main objectives are to support
safe staff communication, information archiving, and teamwork. Employees can create profiles, submit, like,
comment on, and share posts using social intranet features that are common in contemporary intranets.

World wide web(WWW)


 The World Wide Web -- also known as the web, WWW or W3 -- refers to all the public websites or pages
that users can access on their local computers and other devices through the internet. These pages and
documents are interconnected by means of hyperlinks that users click on for information.
 The World Wide Web is abbreviated as WWW and is commonly known as the web. The WWW was
initiated by CERN (European library for Nuclear Research) in 1989.

4
Cyber Security Module-I

 WWW can be defined as the collection of different websites around the world, containing different
information shared via local servers (or computers).
 History:
It is a project created, by Timothy Berner Lee in 1989, for researchers to work together effectively at CERN.
is an organization, named the World Wide Web Consortium (W3C), which was developed for further
development of the web. This organization is directed by Tim Berner’s Lee, aka the father of the web.
 Working of WWW:
The World Wide Web is based on several different technologies: Web browsers, Hypertext Markup
Language (HTML) and Hypertext Transfer Protocol (HTTP). A Web browser is used to access web pages.
Web browsers can be defined as programs which display text, data, pictures, animation and video on the
Internet. Hyperlinked resources on the World Wide Web can be accessed using software interfaces
provided by Web browsers. Initially, Web browsers were used only for surfing the Web but now they
have become more universal. Web browsers can be used for several tasks including conducting searches,
mailing, transferring files, and much more. Some of the commonly used browsers are Internet Explorer,
Opera Mini, and Google Chrome.
 Component of the Web: There are 3 components of the web:

1. Uniform Resource Locator (URL): serves as a system for resources on the web.
2. Hyper Text Transfer Protocol (HTTP): specifies communication of browser and server.
3. Hyper Text Markup Language (HTML): defines the structure, organization and content of a
webpage.

Internet governance
 Internet governance refers to the rules, policies, standards and practices that coordinate and shape
global cyberspace.
Internet governance is the development and application by Governments, the private sector and civil society, in
their respective roles, of shared principles, norms, rules, decision-making procedures, and programs that shape
the evolution and use of the Internet.
 Law professor Yochai Benkler developed a conceptualization of Internet governance by the
idea of three "layers" of governance:
 Physical infrastructure layer (through which information travels)
 Code or logical layer (controls the infrastructure)
 Content layer (contains the information signaled through the network)

Internet society
The Internet Society (ISOC) is an international nonprofit organization that handles Internet standards,
education and policy development. Founded in 1992, ISOC’s mission is to ensure open Internet development by
enhancing and supporting Internet use for organizations and individuals worldwide.
 The Internet Society supports and promotes the development of the Internet as a global technical
infrastructure, a resource to enrich people's lives, and a force for good in society.
 The Internet Society believes that principles such as openness, user choice and control, and edge based
intelligence.

5
Cyber Security Module-I

Regulation of cyberspace
 The Role of Regulation in Cyberspace: Regulation is crucial in ensuring cyberspace's safe, secure,
and responsible use. As the digital realm continues to expand and evolve, effective regulation is
essential to protect individuals, businesses, and governments from cyber threats, uphold privacy
rights, foster trust, and promote responsible behavior. Here are some critical aspects of the role of
regulation in cyberspace:
 The role of government in the regulation of cyberspace comes in picture by virtue of sovereignty,
territoriality (over its subjects who might be victim of cybercrime), public interest (addressing
cybersecurity issues which are posed to its subjects) and national security.
 Another model of cyberspace regulation relates to the regulation by the market i.e., self-regulation by
the key market players or the private institutions.

 The private players are the major stakeholders in the cyberspace due to which they have a great
impact on the policies formulated by the government.

Basics of Cybersecurity

 Cybersecurity refers to the protection of computer devices, systems, networks and programs from
cyberattacks. Cyberattacks are a globally increasing and evolving threat to sensitive data. Attackers use
new methods, which are powered by social engineering, artificial intelligence and machine learning, to
bypass security checks. Our reliance on new technology is increasing, and this reliance would continue as
we introduce smart Internet devices, which have access to our networks via Bluetooth and Wi-Fi.
 Cybersecurity is important, because it helps us protect our sensitive data, personally identifiable
information (PII), protected health information (PHI), private information, intellectual property data, and
governmental and industry information systems from theft and damage attempted by criminals and
adversaries.
 Why is cyber security important?
Listed below are the reasons why cyber security is so important in what’s become a predominant digital
world:
 Cyber-attacks can be extremely expensive for businesses to endure.
 In addition to financial damage suffered by the business, a data breach can also inflict untold
reputational damage.
 Cyber-attacks these days are becoming progressively destructive. Cybercriminals are using more
sophisticated ways to initiate cyber-attacks.
 Regulations such as GDPR are forcing organizations into taking better care of the personal data they
hold.

Categories of Cyber Security

 Network security is the practice of securing a computer network from intruders, whether targeted attackers or
opportunistic malware.

 Application security focuses on keeping software and devices free of threats. A compromised application
could provide access to the data its designed to protect. Successful security begins in the design stage, well
before a program or device is deployed.

6
Cyber Security Module-I

 Information security protects the integrity and privacy of data, both in storage and in transit.  Operational
security includes the processes and decisions for handling and protecting data assets. The permissions users
have when accessing a network and the procedures that determine how and where data may be stored or shared
all fall under this umbrella.

 Disaster recovery and business continuity define how an organization responds to a cyber-security incident
or any other event that causes the loss of operations or data. Disaster recovery policies dictate how the
organization restores its operations and information to return to the same operating capacity as before the event.
Business continuity is the plan the organization falls back on while trying to operate without certain resources.

 End-user education addresses the most unpredictable cyber-security factor: people. Anyone can accidentally
introduce a virus to an otherwise secure system by failing to follow good security practices. Teaching users to
delete suspicious email attachments, not plug-in unidentified USB drives, and various other important lessons is
vital for the security of any organization.

Issues and challenges of cyber security


Cybercriminals are becoming more skilled with each passing day, changing what they target, how they affect
organizations and their methods of attack for different security systems. Other factors that are driving the
growth in cybercrime include:

● The distributed nature of the Internet;


● The ability of cybercriminals to attack targets outside their jurisdiction, thus rendering policing extremely
difficult;
● The increasing profitability and ease of doing commerce on the dark web; and
● The rapid proliferation of mobile devices and the Internet of Things.

The recent important cybersecurity challenges are


1. Ransomware Evolution
Ransomware is a type of malware in which the data on a victim's computer is locked, and payment is demanded
before the ransomed data is unlocked. After successful payment, access rights returned to the victim. Ransomware
is the bane of cybersecurity, data professionals, IT, and executives.
2. Blockchain Revolution
Blockchain technology is the most important invention in computing era. It is the first time in human history
that we have a genuinely native digital medium for peer-to-peer value exchange. The blockchain is a technology
that enables cryptocurrencies like Bitcoin. The blockchain is a vast global platform that allows two or more parties
to do a transaction or do business without needing a third party for establishing trust.
3. IoT Threats
IoT stands for Internet of Things. It is a system of interrelated physical devices which can be accessible through
the internet. The connected physical devices have a unique identifier (UID) and have the ability to transfer data
over a network without any requirements of the human-to-human or human-to-computer interaction. The
firmware and software which is running on IoT devices make consumer and businesses highly susceptible to
cyber-attacks.
4. AI Expansion
AI short form is Artificial intelligence. The misuse of AI has escalated, as attackers use generative AI tools for
phishing emails, keystroke monitoring malware and basic ransomware code.

7
Cyber Security Module-I

5. Serverless Apps Vulnerability


Serverless architecture and apps is an application which depends on third-party cloud infrastructure or on a
back-end service such as google cloud function, Amazon web services (AWS) lambda, etc. The serverless apps
invite the cyber attackers to spread threats on their system easily because the users access the application locally
or off-server on their device. Therefore, it is the user responsibility for the security precautions while using
serverless application.

Cyberlaws
Cyber Law also called IT Law is the law regarding Information-technology including computers and internet. It
is related to legal informatics and supervises the digital circulation of information, software, information security
and ecommerce.
Importance of Cyber Laws
 Cyber laws are important to punish criminals who commit serious crimes related to the computer such as
hacking, online harassment, data theft, disrupting the online workflow of any enterprise, attacking another
individual or website.
 Cyber laws decide different forms of punishment depending on the type of law you broke, who you offended,
where you violated the law, and where you live.
 It is important to bring criminal behind the bars, as most cybercrimes do not enter the category of common
crime and it may lead to denial of justice.
 These crimes may endanger the confidentiality and financial security of a nation therefore these problems should
be addressed lawfully.

IT Act 2000 and its amendments

The Information Technology Act, 2000 also Known as an IT Act is an act proposed by the Indian Parliament
reported on 17th October 2000. This Information Technology Act is based on the United Nations Model law on
Electronic Commerce 1996 (UNCITRAL Model) which was suggested by the General Assembly of United
Nations by a resolution dated on 30th January, 1997.
The IT Act has 13 chapters and 90 sections. The last four sections that starts from ‘section 91 – section 94’, deals
with the revisions to the Indian Penal Code 1860.
The IT Act, 2000 has two schedules:
 First Schedule – Deals with documents to which the Act shall not apply.
 Second Schedule – Deals with electronic signature or electronic authentication method.

8
Cyber Security Module-I

The offences and the punishments in IT Act 2000:


The offences and the punishments that falls under the IT Act, 2000 are as follows:
1. Tampering with the computer source documents.
2. Directions of Controller to a subscriber to extend facilities to decrypt information.
3. Publishing of information which is obscene in electronic form.
4. Penalty for breach of confidentiality and privacy.
5. Hacking for malicious purposes.
6. Penalty for publishing Digital Signature Certificate false in certain particulars.
7. Penalty for misrepresentation.
8. Confiscation.
9. Power to investigate offences.
10. Protected System.
11. Penalties for confiscation not to interfere with other punishments.
12. Act to apply for offence or contravention committed outside India.
13. Publication for fraud purposes.
14. Power of Controller to give directions.

9
Cyber Security Module-I

Amendments
A major amendment was made in 2008. It introduced Section 66A which penalized sending "offensive
messages". It also introduced Section 69, which gave authorities the power of "interception or monitoring or
decryption of any information through any computer resource". Additionally, it introduced provisions
addressing - pornography, child porn, cyber terrorism and voyeurism. The amendment was passed on 22
December 2008 without any debate in Lok Sabha. The next day it was passed by the Rajya Sabha. It was signed
into law by President Pratibha Patil, on 5 February 2009.
Cyber-crime and offences
 Cybercrime is criminal activity that either targets or uses a computer, a computer network or a networked device.
 Most, but not all, cybercrime is committed by cybercriminals or hackers who want to make money. Cybercrime
is carried out by individuals or organizations.
 Some cybercriminals are organized, use advanced techniques and are highly technically skilled. Others are
novice hackers.
 Rarely, cybercrime aims to damage computers for reasons other than profit. These could be political or personal.
 Most cybercrime falls under two main categories:
 Criminal activity that targets
 Criminal activity that uses computers to commit other crimes.

Cyber-crime usually includes the following −

 Unauthorized access of the computers


 Data diddling
 Virus/worms attack
 Theft of computer system
 Hacking
 Denial of attacks
 Logic bombs
 Trojan attacks
 Internet time theft
 Web jacking
 Email bombing
 Salami attacks
 Physically damaging computer system.

How Can Indian Businesses and Organizations Mitigate Cyber Security Threats?

 Despite the government’s measures, cyber-crime still runs rampant, as India is constantly facing serious
DDoS (Distributed Denial of Service) attacks, phishing, spoofing, credit card, and online transaction fraud.
 Here are 8 essential strategies and proactive measures that any Indian business can take to prevent
cybersecurity threats and mitigate cybersecurity incidents:

10
Cyber Security Module-I

1. Create Strong Passwords

 One of the most fundamental steps in improving an organization's cybersecurity posture is implementing
strong passwords and credentials in their systems.
 Indian organizations need to have passwords that:
 Contain at least nine characters;
 Contain alphanumeric characters;
 Don’t contain any personal info;
 Are unique and have not been used previously

2. Deploy Multi-Factor Authentication

 According to a 2020 Microsoft report, Indian organizations are investing more heavily in integrated
security solutions, such as multi-factor authentication, in response to the pandemic’s volatile threat
landscape.
 Multi-factor authentication (MFA) is a key security mechanism within a zero-trust architecture. MFA adds
an extra layer of security to corporate accounts in the event employee credentials are compromised.

3. Encrypt Data
 Encryption is the process by which a readable message is converted to an unreadable form to prevent
unauthorized parties from reading it.
 Data encryption is crucial to improving Indian organizations’ IT infrastructure security and plays a major
part in security risk mitigation strategies.
 Encryption renders data unreadable, preventing bad actors from compromising sensitive information even
if they gain unauthorized access to internal systems.

4. Create Backups
 Creating regular weekly or monthly backups is also an important method of safeguarding information.
With effective back-up practices (like the 3-2-1 rule), organizations can both safeguard their data and
prevent complete data loss if a security incident occurs.

5. Regularly Update Systems and Software


 In August 2022, the Indian government issued a high-priority warning for Windows users, asking them to
update their devices immediately. The Indian Computer Emergency Response Team (CERT-In), under the
Ministry of Electronics and Information Technology (MEITY), alerted that the new Windows operating
systems have a severe vulnerability and advised users to update their systems to the newest patches.

6. Install Firewalls
 Indian organizations have the option to use firewalls to better defend their networks from cyber attacks.
Reliable firewall software can improve security and protect your systems from brute force attacks and
prevent irreversible damages from cyber security incidents.
 Additionally, Indian organizations can use firewalls to:

 Monitor their network traffic;


 Promote and encourage better data privacy policies;
 Detect and identify suspicious activity;

11
Cyber Security Module-I

 Prevent complex spyware from unauthorized access to systems.

7. Manage the Attack Surface

 The attack surface includes all the hardware, software, SaaS services, and cloud assets that are accessible
from the Internet that process or store an organization’s data.
 Attack surface management (ASM) involves the continuous discovery, inventory, classification,
prioritization, and security monitoring of these assets.

8. Manage Third-Party Vendor Risks


 To properly address third-party risks, Indian organizations must implement an effective Vendor Risk
Management (VRM) program which can provide security teams with critical insights into vendors’
security postures.
 Advanced VRM solutions, like Up Guard, automate the critical Vendor Risk Management processes, such
as:
 Performing risk assessments before onboarding vendors to determine if their levels of risk are worth
taking on;
 Continuously monitoring the third-party attack surface for cyber threats and vulnerabilities affecting
your vendors;
 Tiering vendors based on their level of risk and business impact to prioritize remediation efforts;

 Regularly assessing vendors’ regulatory compliance throughout the lifecycle with routine security
questionnaires.

12

You might also like