Cybersecurity vs. Network Security vs.
Information Security
Cybersecurity, network security and info security each serve a specific
purpose in your security infrastructure.
We are in a time where businesses are more digitally advanced than
ever, and as technology improves, organizations’ security postures must
be enhanced as well. Failure to do so could result in a costly data breach,
as we’ve seen happen with many businesses. The cybercrime landscape
has evolved, and threat actors are going after any type of organization,
so in order to protect your business’s data, money and reputation, it is
critical that you invest in an advanced security system. But before you
can start developing a security program for your organization, it’s
critical that you understand the different types of security and how they
all work together.
What is Information Security?
Information security (also known as InfoSec) ensures that both physical
and digital data is protected from unauthorized access, use, disclosure,
disruption, modification, inspection, recording or destruction.
Information security differs from cybersecurity in that InfoSec aims to
keep data in any form secure, whereas cybersecurity protects only digital
data. If your business is starting to develop a security program,
information security is where you should first begin, as it is the
foundation for data security.
Governance Framework
When you’re creating your information security program, you’ll want to
start with having the proper governance structure in place. Governance
is the framework established to ensure that the security strategies align
with your business objective and goals. Governance bridges the gap
between business and information security, so the teams can efficiently
work together. The framework also defines the roles, responsibilities and
accountabilities of each person and ensures that you are meeting
compliance.
CIA Triad
When InfoSec experts are developing policies and procedures for an
effective information security program, they use the CIA
(confidentiality, integrity and availability) triad as a guide. The
components of the CIA triad are:
Confidentiality: ensures information is inaccessible to
unauthorized people—most commonly enforced through
encryption—which is available in many forms
Integrity: protects information and systems from being modified by
unauthorized people; ensures the data is accurate and trustworthy
Availability: ensures authorized people can access the information
when needed and that all hardware and software are maintained
properly and updated when necessary
The CIA triad has become the de facto standard model for keeping your
organization secure. The three fundamental principles help build a
vigorous set of security controls to preserve and protect your data.
What is Cybersecurity?
Cybersecurity, a subset of information security, is the practice of
defending your organization’s networks, computers and data from
unauthorized digital access, attack or damage by implementing various
processes, technologies and practices. With the countless sophisticated
threat actors targeting all types of organizations, it is critical that your IT
infrastructure is secured at all times to prevent a full-scale attack on your
network and risk exposing your company’ data and reputation.
Social Engineering
When cyber-threat actors target your organization, they research not
only your business, but your employees as well. They know that
employees outside of IT security aren’t as aware of cyber threats, so they
execute cyberattacks that exploit human vulnerabilities. Through the
process of social engineering, threat actors manipulate people into
giving the access to sensitive information. The most common social
engineering attacks include:
Phishing: usually in the form of emails or chats, where the threat
actors pose as a real organization to obtain personal information
Pretexting: when a threat actor impersonates an authority figure or
someone that the target would easily trust in order to get their
personal information
Baiting: when threat actors leave a malware-infected device, such
as a USB or CD, in a place where it can be easily found by
someone, who would then use the infected device on their
computer and accidentally install the malware, giving the threat
actors access into the target’s system
Quid pro quo: when a threat actor requests personal information
in exchange for some form of reward, i.e. money, free gift or a free
service
As a business leader, it is your responsibility to build a culture of
security awareness and fill in the gaps in your team's cybersecurity
knowledge and understanding. It’s essential that your workforce be
informed of cybersecurity risks, so it will be less likely for an employee
to fall victim to an attack. Provide your employees the necessary training
and technology to strengthen your organization’s human firewall and
mitigate the possibility of a cyberattack.
What is Network Security?
Network security, a subset of cybersecurity, aims to protect any data that
is being sent through devices in your network to ensure that the
information is not changed or intercepted. The role of network security
is to protect the organization’s IT infrastructure from all types of cyber
threats including:
Viruses, worms and Trojan horses
Zero-day attacks
Hacker attacks
Denial of service attacks
Spyware and adware
Your network security team implements the hardware and software
necessary to guard your security architecture. With the proper network
security in place, your system can detect emerging threats before they
infiltrate your network and compromise your data.
There are many components to a network security system that work
together to improve your security posture. The most common network
security components include:
Firewalls
Anti-virus software
Intrusion detection and prevention systems (IDS/IPS)
Virtual private networks (VPN)
When your network security is compromised, your first priority should
be to get the attackers out as quickly as possible. The longer they stay in
your network, the more time they have to steal your private data.
According to Ponemon Institute’s 2013 Cost of Data Breach study,
excluding catastrophic or mega data security breaches, the average cost
of a data breach per compromised record in the U.S. is $188. The
average total cost to an organization in the U.S. is more than $5.4
million. The most effective method of lessening the total cost is by
getting the attackers out of your network as soon as possible.
Network security is the security provided to a network from
unauthorized access and risks. It is the duty of network administrators to
adopt preventive measures to protect their networks from potential
security threats.
Computer networks that are involved in regular transactions and
communication within the government, individuals, or business require
security. The most common and simple way of protecting a network
resource is by assigning it a unique name and a corresponding password.
Types of Network Security Devices
Active Devices
These security devices block the surplus traffic. Firewalls, antivirus
scanning devices, and content filtering devices are the examples of such
devices.
Passive Devices
These devices identify and report on unwanted traffic, for example,
intrusion detection appliances.
Preventative Devices
These devices scan the networks and identify potential security
problems. For example, penetration testing devices and vulnerability
assessment appliances.
Unified Threat Management (UTM)
These devices serve as all-in-one security devices. Examples include
firewalls, content filtering, web caching, etc.
Firewalls
A firewall is a network security system that manages and regulates the
network traffic based on some protocols. A firewall establishes a barrier
between a trusted internal network and the internet.
Firewalls exist both as software that run on a hardware and as hardware
appliances. Firewalls that are hardware-based also provide other
functions like acting as a DHCP server for that network.
Most personal computers use software-based firewalls to secure data
from threats from the internet. Many routers that pass data between
networks contain firewall components and conversely, many firewalls
can perform basic routing functions.
Firewalls are commonly used in private networks or intranets to prevent
unauthorized access from the internet. Every message entering or
leaving the intranet goes through the firewall to be examined for security
measures.
An ideal firewall configuration consists of both hardware and software
based devices. A firewall also helps in providing remote access to a
private network through secure authentication certificates and logins.
Hardware and Software Firewalls
Hardware firewalls are standalone products. These are also found in
broadband routers. Most hardware firewalls provide a minimum of four
network ports to connect other computers. For larger networks − e.g., for
business purpose − business networking firewall solutions are available.
Software firewalls are installed on your computers. A software firewall
protects your computer from internet threats.
Antivirus
An antivirus is a tool that is used to detect and remove malicious
software. It was originally designed to detect and remove viruses from
computers.
Modern antivirus software provide protection not only from virus, but
also from worms, Trojan-horses, adwares, spywares, keyloggers, etc.
Some products also provide protection from malicious URLs, spam,
phishing attacks, botnets, DDoS attacks, etc.
Content Filtering
Content filtering devices screen unpleasant and offensive emails or
webpages. These are used as a part of firewalls in corporations as well as
in personal computers. These devices generate the message "Access
Denied" when someone tries to access any unauthorized web page or
email.
Content is usually screened for pornographic content and also for
violence- or hate-oriented content. Organizations also exclude shopping
and job related contents.
Content filtering can be divided into the following categories −
Web filtering
Screening of Web sites or pages
E-mail filtering
Screening of e-mail for spam
Other objectionable content
Intrusion Detection Systems
Intrusion Detection Systems, also known as Intrusion Detection and
Prevention Systems, are the appliances that monitor malicious activities
in a network, log information about such activities, take steps to stop
them, and finally report them.
Intrusion detection systems help in sending an alarm against any
malicious activity in the network, drop the packets, and reset the
connection to save the IP address from any blockage. Intrusion detection
systems can also perform the following actions −
Correct Cyclic Redundancy Check (CRC) errors
Prevent TCP sequencing issues
Clean up unwanted transport and network layer options
As discussed in the first chapter, the Government of India enacted the
Information Technology (I.T.) Act with some major objectives to deliver
and facilitate lawful electronic, digital, and online transactions, and
mitigate cyber-crimes.
Salient Features of I.T Act
The salient features of the I.T Act are as follows −
Digital signature has been replaced with electronic signature to
make it a more technology neutral act.
It elaborates on offenses, penalties, and breaches.
It outlines the Justice Dispensation Systems for cyber-crimes.
It defines in a new section that cyber café is any facility from
where the access to the internet is offered by any person in the
ordinary course of business to the members of the public.
It provides for the constitution of the Cyber Regulations Advisory
Committee.
It is based on The Indian Penal Code, 1860, The Indian Evidence
Act, 1872, The Bankers' Books Evidence Act, 1891, The Reserve
Bank of India Act, 1934, etc.
It adds a provision to Section 81, which states that the provisions
of the Act shall have overriding effect. The provision states
that nothing contained in the Act shall restrict any person from
exercising any right conferred under the Copyright Act, 1957.
Scheme of I.T Act
The following points define the scheme of the I.T. Act −
The I.T. Act contains 13 chapters and 90 sections.
The last four sections namely sections 91 to 94 in the I.T. Act 2000
deals with the amendments to the Indian Penal Code 1860, The
Indian Evidence Act 1872, The Bankers’ Books Evidence Act
1891 and the Reserve Bank of India Act 1934 were deleted.
It commences with Preliminary aspect in Chapter 1, which deals
with the short, title, extent, commencement and application of the
Act in Section 1. Section 2 provides Definition.
Chapter 2 deals with the authentication of electronic records,
digital signatures, electronic signatures, etc.
Chapter 11 deals with offences and penalties. A series of offences
have been provided along with punishment in this part of The Act.
Thereafter the provisions about due diligence, role of
intermediaries and some miscellaneous provisions are been stated.
The Act is embedded with two schedules. The First Schedule deals
with Documents or Transactions to which the Act shall not apply.
The Second Schedule deals with electronic signature or electronic
authentication technique and procedure. The Third and Fourth
Schedule are omitted.
Application of the I.T Act
As per the sub clause (4) of Section 1, nothing in this Act shall apply to
documents or transactions specified in First Schedule. Following are the
documents or transactions to which the Act shall not apply −
Negotiable Instrument (Other than a cheque) as defined in
section 13 of the Negotiable Instruments Act, 1881;
A power-of-attorney as defined in section 1A of the Powers-of-
Attorney Act, 1882;
A trust as defined in section 3 of the Indian Trusts Act, 1882;
A will as defined in clause (h) of section 2 of the Indian
Succession Act, 1925 including any other testamentary disposition;
Any contract for the sale or conveyance of immovable property or
any interest in such property;
Any such class of documents or transactions as may be notified by
the Central Government.
Amendments Brought in the I.T Act
The I.T. Act has brought amendment in four statutes vide section 91-94.
These changes have been provided in schedule 1-4.
The first schedule contains the amendments in the Penal Code. It
has widened the scope of the term "document" to bring within its
ambit electronic documents.
The second schedule deals with amendments to the India Evidence
Act. It pertains to the inclusion of electronic document in the
definition of evidence.
The third schedule amends the Banker's Books Evidence Act. This
amendment brings about change in the definition of "Banker's-
book". It includes printouts of data stored in a floppy, disc, tape or
any other form of electromagnetic data storage device. Similar
change has been brought about in the expression "Certified-copy"
to include such printouts within its purview.
The fourth schedule amends the Reserve Bank of India Act. It
pertains to the regulation of fund transfer through electronic means
between the banks or between the banks and other financial
institution.
Intermediary Liability
Intermediary, dealing with any specific electronic records, is a person
who on behalf of another person accepts, stores or transmits that record
or provides any service with respect to that record.
According to the above mentioned definition, it includes the following −
Telecom service providers
Network service providers
Internet service providers
Web-hosting service providers
Search engines
Online payment sites
Online auction sites
Online market places and cyber cafes
Highlights of the Amended Act
The newly amended act came with following highlights −
It stresses on privacy issues and highlights information security.
It elaborates Digital Signature.
It clarifies rational security practices for corporate.
It focuses on the role of Intermediaries.
New faces of Cyber Crime were added.
Digital Signature
A digital signature is a technique to validate the legitimacy of a digital
message or a document. A valid digital signature provides the surety to
the recipient that the message was generated by a known sender, such
that the sender cannot deny having sent the message. Digital signatures
are mostly used for software distribution, financial transactions, and in
other cases where there is a risk of forgery.
Electronic Signature
An electronic signature or e-signature, indicates either that a person who
demands to have created a message is the one who created it.
A signature can be defined as a schematic script related with a person. A
signature on a document is a sign that the person accepts the purposes
recorded in the document. In many engineering companies digital seals
are also required for another layer of authentication and security. Digital
seals and signatures are same as handwritten signatures and stamped
seals.
Digital Signature to Electronic Signature
Digital Signature was the term defined in the old I.T. Act,
2000. Electronic Signature is the term defined by the amended act (I.T.
Act, 2008). The concept of Electronic Signature is broader than Digital
Signature. Section 3 of the Act delivers for the verification of Electronic
Records by affixing Digital Signature.
As per the amendment, verification of electronic record by electronic
signature or electronic authentication technique shall be considered
reliable.
According to the United Nations Commission on International Trade
Law (UNCITRAL), electronic authentication and signature methods
may be classified into the following categories −
Those based on the knowledge of the user or the recipient, i.e.,
passwords, personal identification numbers (PINs), etc.
Those bases on the physical features of the user, i.e., biometrics.
Those based on the possession of an object by the user, i.e., codes
or other information stored on a magnetic card.
Types of authentication and signature methods that, without falling
under any of the above categories might also be used to indicate
the originator of an electronic communication (Such as a facsimile
of a handwritten signature, or a name typed at the bottom of an
electronic message).
According to the UNCITRAL MODEL LAW on Electronic Signatures,
the following technologies are presently in use −
Digital Signature within a public key infrastructure (PKI)
Biometric Device
PINs
Passwords
Scanned handwritten signature
Signature by Digital Pen
Clickable “OK” or “I Accept” or “I Agree” click boxes
The faster world-wide connectivity has developed numerous online
crimes and these increased offences led to the need of laws for
protection. In order to keep in stride with the changing generation, the
Indian Parliament passed the Information Technology Act 2000 that has
been conceptualized on the United Nations Commissions on
International Trade Law (UNCITRAL) Model Law.
The law defines the offenses in a detailed manner along with the
penalties for each category of offence.
Offences
Cyber offences are the illegitimate actions, which are carried out in a
classy manner where either the computer is the tool or target or both.
Cyber-crime usually includes the following −
Unauthorized access of the computers
Data diddling
Virus/worms attack
Theft of computer system
Hacking
Denial of attacks
Logic bombs
Trojan attacks
Internet time theft
Web jacking
Email bombing
Salami attacks
Physically damaging computer system.
The offences included in the I.T. Act 2000 are as follows −
Tampering with the computer source documents.
Hacking with computer system.
Publishing of information which is obscene in electronic form.
Power of Controller to give directions.
Directions of Controller to a subscriber to extend facilities to
decrypt information.
Protected system.
Penalty for misrepresentation.
Penalty for breach of confidentiality and privacy.
Penalty for publishing Digital Signature Certificate false in certain
particulars.
Publication for fraudulent purpose.
Act to apply for offence or contravention committed outside India
Confiscation.
Penalties or confiscation not to interfere with other punishments.
Power to investigate offences.
Example
Offences Under The It Act 2000
Section 65. Tampering with computer source documents
Whoever knowingly or intentionally conceals, destroys or alters or
intentionally or knowingly causes another to conceal, destroy or alter
any computer source code used for a computer, computer program,
computer system or computer network, when the computer source code
is required to be kept or maintained by law for the being time in force,
shall be punishable with imprisonment up to three year, or with fine
which may extend up to two lakh rupees, or with both.
Explanation − For the purpose of this section “computer source code”
means the listing of programs, computer commands, design and layout
and program analysis of computer resource in any form.
Object − The object of the section is to protect the “intellectual
property” invested in the computer. It is an attempt to protect the
computer source documents (codes) beyond what is available under the
Copyright Law
Essential ingredients of the section
knowingly or intentionally concealing
knowingly or intentionally destroying
knowingly or intentionally altering
knowingly or intentionally causing others to conceal
knowingly or intentionally causing another to destroy
knowingly or intentionally causing another to alter.
This section extends towards the Copyright Act and helps the companies
to protect their source code of their programs.
Penalties − Section 65 is tried by any magistrate.
This is cognizable and non-bailable offence.
Penalties − Imprisonment up to 3 years and / or
Fine − Two lakh rupees.
The following table shows the offence and penalties against all the
mentioned sections of the I.T. Act −
Section Offence Punishment Bailability
and
Congizability
65 Tampering with Imprisonment up Offence is
Computer Source to 3 years or fine Bailable,
Code up to Rs 2 lakhs Cognizable
and triable by
Court of
JMFC.
66 Computer Related Imprisonment up Offence is
Offences to 3 years or fine Bailable,
up to Rs 5 lakhs Cognizable
and
66-A Sending offensive Imprisonment up Offence is
messages through to 3 years and Bailable,
Communication fine Cognizable
service, etc... and triable by
Court of JMFC
66-B Dishonestly receiving Imprisonment up Offence is
stolen computer to 3 years and/or Bailable,
resource or fine up to Rs. 1 Cognizable
communication lakh and triable by
device Court of JMFC
66-C Identity Theft Imprisonment of Offence is
either Bailable,
description up to Cognizable
3 years and/or and triable by
fine up to Rs. 1 Court of JMFC
lakh
66-D Cheating by Imprisonment of Offence is
Personation by using either Bailable,
computer resource description up to Cognizable
3 years and /or and triable by
fine up to Rs. 1 Court of JMFC
lakh
66-E Violation of Privacy Imprisonment up Offence is
to 3 years and Bailable,
/or fine up to Rs. Cognizable
2 lakh and triable by
Court of JMFC
66-F Cyber Terrorism Imprisonment Offence is
extend to Non-Bailable,
imprisonment Cognizable
for Life and triable by
Court of
Sessions
67 Publishing or On first Offence is
transmitting obscene Conviction, Bailable,
material in electronic imprisonment up Cognizable
form to 3 years and/or and triable by
fine up to Rs. 5 Court of JMFC
lakh On
Subsequent
Conviction
imprisonment up
to 5 years and/or
fine up to Rs. 10
lakh
67-A Publishing or On first Offence is
transmitting of Conviction Non-Bailable,
material containing imprisonment up Cognizable
sexually explicit act, to 5 years and/or and triable by
etc... in electronic fine up to Rs. 10 Court of JMFC
form lakh On
Subsequent
Conviction
imprisonment up
to 7 years and/or
fine up to Rs. 10
lakh
67-B Publishing or On first Offence is Non
transmitting of Conviction Bailable,
material depicting imprisonment of Cognizable
children in sexually either and triable by
explicit act etc., in description up to Court of JMFC
electronic form 5 years and/or
fine up to Rs. 10
lakh On
Subsequent
Conviction
imprisonment of
either
description up to
7 years and/or
fine up to Rs. 10
lakh
67-C Intermediary Imprisonment up Offence is
intentionally or to 3 years and Bailable,
knowingly fine Cognizable.
contravening the
directions about
Preservation and
retention of
information
68 Failure to comply Imprisonment up Offence is
with the directions to 2 years and/or Bailable, Non-
given by Controller fine up to Rs. 1 Cognizable.
lakh
69 Failure to assist the Imprisonment up Offence is
agency referred to in to 7 years and Non-Bailable,
sub section (3) in fine Cognizable.
regard interception or
monitoring or
decryption of any
information through
any computer
resource
69-A Failure of the Imprisonment up Offence is
intermediary to to 7 years and Non-Bailable,
comply with the fine Cognizable.
direction issued for
blocking for public
access of any
information through
any computer
resource
69-B Intermediary who Imprisonment up Offence is
intentionally or to 3 years and Bailable,
knowingly fine Cognizable.
contravenes the
provisions of sub-
section (2) in regard
monitor and collect
traffic data or
information through
any computer
resource for
cybersecurity
70 Any person who Imprisonment of Offence is
secures access or either Non-Bailable,
attempts to secure description up to Cognizable.
access to the 10 years and fine
protected system in
contravention of
provision of Sec. 70
70-B Indian Computer Imprisonment up Offence is
Emergency Response to 1 year and/or Bailable, Non-
Team to serve as fine up to Rs. 1 Cognizable
national agency for lakh
incident response.
Any service provider,
intermediaries, data
centres, etc., who
fails to prove the
information called for
or comply with the
direction issued by
the ICERT.
71 Misrepresentation to Imprisonment up Offence is
the Controller to the to 2 years and/ Bailable, Non-
Certifying Authority or fine up to Rs. Cognizable.
1 lakh.
72 Breach of Imprisonment up Offence is
Confidentiality and to 2 years and/or Bailable, Non-
privacy fine up to Rs. 1 Cognizable.
lakh.
72-A Disclosure of Imprisonment up Offence is
information in breach to 3 years and/or Cognizable,
of lawful contract fine up to Rs. 5 Bailable
lakh.
73 Publishing electronic Imprisonment up Offence is
Signature Certificate to 2 years and/or Bailable, Non-
false in certain fine up to Rs. 1 Cognizable.
particulars lakh
74 Publication for Imprisonment up Offence is
fraudulent purpose to 2 years and/or Bailable, Non-
fine up to Rs. 1 Cognizable.
lakh
Compounding of Offences
As per Section 77-A of the I. T. Act, any Court of competent jurisdiction
may compound offences, other than offences for which the punishment
for life or imprisonment for a term exceeding three years has been
provided under the Act.
No offence shall be compounded if −
The accused is, by reason of his previous conviction, is liable to
either enhanced punishment or to the punishment of different kind;
OR
Offence affects the socio economic conditions of the country; OR
Offence has been committed against a child below the age of 18
years; OR
Offence has been committed against a woman.
The person alleged of an offence under this Act may file an application
for compounding in the Court. The offence will then be pending for trial
and the provisions of Sections 265-B and 265-C of Cr. P.C. shall apply.
Cyber Laws are the sole savior to combat cyber-crime. It is only through
stringent laws that unbreakable security could be provided to the
nation’s information. The I.T. Act of India came up as a special act to
tackle the problem of Cyber Crime. The Act was sharpened by the
Amendment Act of 2008.
Cyber Crime is committed every now and then, but is still hardly
reported. The cases of cyber-crime that reaches to the Court of Law are
therefore very few. There are practical difficulties in collecting, storing
and appreciating Digital Evidence. Thus the Act has miles to go before it
can be truly effective.
In this tutorial, we have tried to cover all the current and major topics
related to Cyber Laws and IT Security. We would like to quote the
words of a noted cyber law expert and Supreme Court advocate Mr
Pavan Duggal to conclude this tutorial.
While the lawmakers have to be complemented for their admirable work
removing various deficiencies in the Indian Cyberlaw and making it
technologically neutral, yet it appears that there has been a major
mismatch between the expectation of the nation and the resultant effect
of the amended legislation. The most bizarre and startling aspect of the
new amendments is that these amendments seek to make the Indian
cyberlaw a cyber-crime friendly legislation; − a legislation that goes
extremely soft on cyber criminals, with a soft heart; a legislation that
chooses to encourage cyber criminals by lessening the quantum of
punishment accorded to them under the existing law; .... a legislation
which makes a majority of cybercrimes stipulated under the IT Act as
bailable offences; a legislation that is likely to pave way for India to
become the potential cyber-crime capital of the world.
Cyberspace
Cyberspace can be defined as an intricate environment that involves
interactions between people, software, and services. It is maintained by
the worldwide distribution of information and communication
technology devices and networks.
With the benefits carried by the technological advancements, the
cyberspace today has become a common pool used by citizens,
businesses, critical information infrastructure, military and governments
in a fashion that makes it hard to induce clear boundaries among these
different groups. The cyberspace is anticipated to become even more
complex in the upcoming years, with the increase in networks and
devices connected to it.
Cybersecurity
Cybersecurity denotes the technologies and procedures intended to
safeguard computers, networks, and data from unlawful admittance,
weaknesses, and attacks transported through the Internet by cyber
delinquents.
ISO 27001 (ISO27001) is the international Cybersecurity Standard that
delivers a model for creating, applying, functioning, monitoring,
reviewing, preserving, and improving an Information Security
Management System.
The Ministry of Communication and Information Technology under the
government of India provides a strategy outline called the National
Cybersecurity Policy. The purpose of this government body is to protect
the public and private infrastructure from cyber-attacks.
Cybersecurity Policy
The cybersecurity policy is a developing mission that caters to the entire
field of Information and Communication Technology (ICT) users and
providers. It includes −
Home users
Small, medium, and large Enterprises
Government and non-government entities
It serves as an authority framework that defines and guides the activities
associated with the security of cyberspace. It allows all sectors and
organizations in designing suitable cybersecurity policies to meet their
requirements. The policy provides an outline to effectively protect
information, information systems and networks.
It gives an understanding into the Government’s approach and strategy
for security of cyber space in the country. It also sketches some pointers
to allow collaborative working across the public and private sectors to
safeguard information and information systems. Therefore, the aim of
this policy is to create a cybersecurity framework, which leads to
detailed actions and programs to increase the security carriage of
cyberspace.
Cyber Crime
The Information Technology Act 2000 or any legislation in the
Country does not describe or mention the term Cyber Crime. It can be
globally considered as the gloomier face of technology. The only
difference between a traditional crime and a cyber-crime is that the
cyber-crime involves in a crime related to computers. Let us see the
following example to understand it better −
Traditional Theft − A thief breaks into Ram’s house and steals an
object kept in the house.
Hacking − A Cyber Criminal/Hacker sitting in his own house, through
his computer, hacks the computer of Ram and steals the data saved in
Ram’s computer without physically touching the computer or entering in
Ram’s house.
The I.T. Act, 2000 defines the terms −
access in computer network in section 2(a)
computer in section 2(i)
computer network in section (2j)
data in section 2(0)
information in section 2(v).
To understand the concept of Cyber Crime, you should know these laws.
The object of offence or target in a cyber-crime are either the computer
or the data stored in the computer.
Nature of Threat
Among the most serious challenges of the 21st century are the prevailing
and possible threats in the sphere of cybersecurity. Threats originate
from all kinds of sources, and mark themselves in disruptive activities
that target individuals, businesses, national infrastructures, and
governments alike. The effects of these threats transmit significant risk
for the following −
public safety
security of nations
stability of the globally linked international community
Malicious use of information technology can easily be concealed. It is
difficult to determine the origin or the identity of the criminal. Even the
motivation for the disruption is not an easy task to find out. Criminals of
these activities can only be worked out from the target, the effect, or
other circumstantial evidence. Threat actors can operate with
considerable freedom from virtually anywhere. The motives for
disruption can be anything such as −
simply demonstrating technical prowess
theft of money or information
extension of state conflict, etc.
Criminals, terrorists, and sometimes the State themselves act as the
source of these threats. Criminals and hackers use different kinds of
malicious tools and approaches. With the criminal activities taking new
shapes every day, the possibility for harmful actions propagates.
Enabling People
The lack of information security awareness among users, who could be a
simple school going kid, a system administrator, a developer, or even a
CEO of a company, leads to a variety of cyber vulnerabilities. The
awareness policy classifies the following actions and initiatives for the
purpose of user awareness, education, and training −
A complete awareness program to be promoted on a national level.
A comprehensive training program that can cater to the needs of
the national information security (Programs on IT security in
schools, colleges, and universities).
Enhance the effectiveness of the prevailing information security
training programs. Plan domain-specific training programs (e.g.,
Law Enforcement, Judiciary, E-Governance, etc.)
Endorse private-sector support for professional information
security certifications.
Information Technology Act
The Government of India enacted The Information Technology Act with
some major objectives which are as follows −
To deliver lawful recognition for transactions through electronic
data interchange (EDI) and other means of electronic
communication, commonly referred to as electronic commerce or
E-Commerce. The aim was to use replacements of paper-based
methods of communication and storage of information.
To facilitate electronic filing of documents with the Government
agencies and further to amend the Indian Penal Code, the Indian
Evidence Act, 1872, the Bankers' Books Evidence Act, 1891 and
the Reserve Bank of India Act, 1934 and for matters connected
therewith or incidental thereto.
The Information Technology Act, 2000, was thus passed as the Act
No.21 of 2000. The I. T. Act got the President’s assent on June 9, 2000
and it was made effective from October 17, 2000. By adopting this
Cyber Legislation, India became the 12th nation in the world to adopt a
Cyber Law regime.
Mission and Vision Cybersecurity Program
Mission
The following mission caters to cybersecurity −
To safeguard information and information infrastructure in
cyberspace.
To build capabilities to prevent and respond to cyber threats.
To reduce vulnerabilities and minimize damage from cyber
incidents through a combination of institutional structures, people,
processes, technology, and cooperation.
Vision
To build a secure and resilient cyberspace for citizens, businesses, and
Government.
Cyber Law - Objectives
The recent Edward Snowden revelations on the US surveillance program
PRISM have demonstrated how a legal entity network and computer
system outside a particular jurisdiction is subject to surveillance without
the knowledge of such legal entities. Cyber cases related to interception
and snooping are increasing at an alarming rate. To curb such crimes,
cyber laws are being amended quite regularly.
Emerging Trends of Cyber Law
Reports reveal that upcoming years will experience more cyber-attacks.
So organizations are advised to strengthen their data supply chains with
better inspection methods.
Some of the emerging trends of cyber law are listed below −
Stringent regulatory rules are put in place by many countries to
prevent unauthorized access to networks. Such acts are declared as
penal offences.
Stakeholders of the mobile companies will call upon the
governments of the world to reinforce cyber-legal systems and
administrations to regulate the emerging mobile threats and crimes.
The growing awareness on privacy is another upcoming trend.
Google’s chief internet expert Vint Cerf has stated that privacy
may actually be an anomaly.
Cloud computing is another major growing trend. With more
advancements in the technology, huge volumes of data will flow
into the cloud which is not completely immune to cyber-crimes.
The growth of Bitcoins and other virtual currency is yet another
trend to watch out for. Bitcoin crimes are likely to multiply in the
near future.
The arrival and acceptance of data analytics, which is another
major trend to be followed, requires that appropriate attention is
given to issues concerning Big Data.
Create Awareness
While the U.S. government has declared October as the National
Cybersecurity Awareness month, India is following the trend to
implement some stringent awareness scheme for the general public.
The general public is partially aware of the crimes related to virus
transfer. However, they are unaware of the bigger picture of the threats
that could affect their cyber-lives. There is a huge lack of knowledge on
e-commerce and online banking cyber-crimes among most of the
internet users.
Be vigilant and follow the tips given below while you participate in
online activities −
Filter the visibility of personal information in social sites.
Do not keep the "remember password" button active for any email
address and passwords
Make sure your online banking platform is secure.
Keep a watchful eye while shopping online.
Do not save passwords on mobile devices.
Secure the login details for mobile devices and computers, etc.
Areas of Development
The "Cyberlaw Trends in India 2013" and "Cyber law Developments in
India in 2014" are two prominent and trustworthy cyber-law related
research works provided by Perry4Law Organization (P4LO) for the
years 2013 and 2014.
There are some grave cyber law related issues that deserve immediate
consideration by the government of India. The issues were put forward
by the Indian cyber law roundup of 2014 provided by P4LO and Cyber
Crimes Investigation Centre of India (CCICI). Following are some
major issues −
A better cyber law and effective cyber-crimes prevention strategy
Cyber-crimes investigation training requirements
Formulation of dedicated encryption laws
Legal adoption of cloud computing
Formulation and implementation of e-mail policy
Legal issues of online payments
Legality of online gambling and online pharmacies
Legality of Bitcoins
Framework for blocking websites
Regulation of mobile applications
With the formation of cyber-law compulsions, the obligation of banks
for cyber-thefts and cyber-crimes would considerably increase in the
near future. Indian banks would require to keep a dedicated team of
cyber law experts or seek help of external experts in this regard.
The transactions of cyber-insurance should be increased by the Indian
insurance sector as a consequence of the increasing cyber-attacks and
cyber-crimes.
International Network on Cybersecurity
To create an international network on cybersecurity, a conference was
held in March 2014 in New Delhi, India.
The objectives set in the International Conference on Cyberlaw &
Cybercrime are as follows −
To recognize the developing trends in Cyberlaw and the legislation
impacting cyberspace in the current situation.
To generate better awareness to battle the latest kinds of
cybercrimes impacting all investors in the digital and mobile
network.
To recognize the areas for stakeholders of digital and mobile
network where Cyberlaw needs to be further evolved.
To work in the direction of creating an international network of
cybercrimes. Legal authorities could then be a significant voice in
the further expansion of cyber-crimes and cyber law legislations
throughout the globe.
Cyber Law - Intellectual Property Right
Intellectual property rights are the legal rights that cover the privileges
given to individuals who are the owners and inventors of a work, and
have created something with their intellectual creativity. Individuals
related to areas such as literature, music, invention, etc., can be granted
such rights, which can then be used in the business practices by them.
The creator/inventor gets exclusive rights against any misuse or use of
work without his/her prior information. However, the rights are granted
for a limited period of time to maintain equilibrium.
The following list of activities which are covered by the intellectual
property rights are laid down by the World Intellectual Property
Organization (WIPO) −
Industrial designs
Scientific discoveries
Protection against unfair competition
Literary, artistic, and scientific works
Inventions in all fields of human endeavor
Performances of performing artists, phonograms, and broadcasts
Trademarks, service marks, commercial names, and designations
All other rights resulting from intellectual activity in the industrial,
scientific, literary, or artistic fields
Types of Intellectual Property Rights
Intellectual Property Rights can be further classified into the following
categories −
Copyright
Patent
Patent
Trade Secrets, etc.
Advantages of Intellectual Property Rights
Intellectual property rights are advantageous in the following ways −
Provides exclusive rights to the creators or inventors.
Encourages individuals to distribute and share information and
data instead of keeping it confidential.
Provides legal defense and offers the creators the incentive of their
work.
Helps in social and financial development.
Intellectual Property Rights in India
To protect the intellectual property rights in the Indian territory, India
has defined the formation of constitutional, administrative and
jurisdictive outline whether they imply the copyright, patent, trademark,
industrial designs, or any other parts of the intellectual property rights.
Back in the year 1999, the government passed an important legislation
based on international practices to safeguard the intellectual property
rights. Let us have a glimpse of the same −
The Patents (Amendment) Act, 1999, facilitates the establishment
of the mail box system for filing patents. It offers exclusive
marketing rights for a time period of five years.
The Trade Marks Bill, 1999, replaced the Trade and Merchandise
Marks Act, 1958
The Copyright (Amendment) Act, 1999, was signed by the
President of India.
The sui generis legislation was approved and named as the
Geographical Indications of Goods (Registration and Protection)
Bill, 1999.
The Industrial Designs Bill, 1999, replaced the Designs Act,
1911.
The Patents (Second Amendment) Bill, 1999, for further
amending the Patents Act of 1970 in compliance with the TRIPS.
Intellectual Property in Cyber Space
Every new invention in the field of technology experiences a variety of
threats. Internet is one such threat, which has captured the physical
marketplace and have converted it into a virtual marketplace.
To safeguard the business interest, it is vital to create an effective
property management and protection mechanism keeping in mind the
considerable amount of business and commerce taking place in the
Cyber Space.
Today it is critical for every business to develop an effective and
collaborative IP management mechanism and protection strategy. The
ever-looming threats in the cybernetic world can thus be monitored and
confined.
Various approaches and legislations have been designed by the law-
makers to up the ante in delivering a secure configuration against such
cyber-threats. However it is the duty of the intellectual property right
(IPR) owner to invalidate and reduce such mala fide acts of criminals by
taking proactive measures.
Cyber Law - Strategies For Cyber Security
To design and implement a secure cyberspace, some stringent strategies
have been put in place. This chapter explains the major strategies
employed to ensure cybersecurity, which include the following −
Creating a Secure Cyber Ecosystem
Creating an Assurance Framework
Encouraging Open Standards
Strengthening the Regulatory Framework
Creating Mechanisms for IT Security
Securing E-governance Services
Protecting Critical Information Infrastructure
Strategy 1 − Creating a Secure Cyber Ecosystem
The cyber ecosystem involves a wide range of varied entities like
devices (communication technologies and computers), individuals,
governments, private organizations, etc., which interact with each other
for numerous reasons.
This strategy explores the idea of having a strong and robust cyber-
ecosystem where the cyber-devices can work with each other in the
future to prevent cyber-attacks, reduce their effectiveness, or find
solutions to recover from a cyber-attack.
Such a cyber-ecosystem would have the ability built into its cyber
devices to permit secured ways of action to be organized within and
among groups of devices. This cyber-ecosystem can be supervised by
present monitoring techniques where software products are used to
detect and report security weaknesses.
A strong cyber-ecosystem has three symbiotic structures − Automation,
Interoperability, and Authentication.
Automation − It eases the implementation of advanced security
measures, enhances the swiftness, and optimizes the decision-
making processes.
Interoperability − It toughens the collaborative actions, improves
awareness, and accelerates the learning procedure. There are three
types of interoperability −
o Semantic (i.e., shared lexicon based on common
understanding)
o Technical
o Policy − Important in assimilating different contributors into
an inclusive cyber-defense structure.
Authentication − It improves the identification and verification
technologies that work in order to provide −
o Security
o Affordability
o Ease of use and administration
o Scalability
o Interoperability
Comparison of Attacks
The following table shows the Comparison of Attack Categories against
Desired Cyber Ecosystem Capabilities −
Case Study
The following diagram was prepared by Guilbert Gates for The New
York Times,which shows how an Iranian plant was hacked through the
internet.
Explanation − A program was designed to automatically run the Iranian
nuclear plant. Unfortunately, a worker who was unaware of the threats
introduced the program into the controller. The program collected all the
data related to the plant and sent the information to the intelligence
agencies who then developed and inserted a worm into the plant. Using
the worm, the plant was controlled by miscreants which led to the
generation of more worms and as a result, the plant failed completely.
Types of Attacks
The following table describes the attack categories −
Attack Category Description of
Attack
Attrition Methods used to
damage networks and
systems. It includes
the following −
distributed
denial of
service attacks
impair or deny
access to a
service or
application
resource
depletion
attacks
Malware Any malicious
software used to
interrupt normal
computer operation
and harm information
assets without the
owner’s consent.
Any execution from
a removable device
can enhance the
threat of a malware.
Hacking An attempt to
intentionally exploit
weaknesses to get
unethical access,
usually conducted
remotely. It may
include −
data-leakage
attacks
injection
attacks and
abuse of
functionality
spoofing
time-state
attacks
buffer and data
structure
attacks
resource
manipulation
stolen
credentials
usage
backdoors
dictionary
attacks on
passwords
exploitation of
authentication
Social Tactics Using social tactics
such as deception
and manipulation to
acquire access to
data, systems or
controls. It includes −
pre-texting
(forged
surveys)
inciting
phishing
retrieving of
information
through
conversation
Improper Usage (Insider Threat) Misuse of rights to
data and controls by
an individual in an
organization that
would violate the
organization’s
policies. It includes −
installation of
unauthorized
software
removal of
sensitive data
Physical Action/Loss or Theft of Equipment Human-Driven
attacks such as −
stolen identity
tokens and
credit cards
fiddling with or
replacing card
readers and
point of sale
terminals
interfering with
sensors
theft of a
computing
device used by
the
organization,
such as a laptop
Multiple Component Single attach
techniques which
contains several
advanced attack
techniques and
components.
Other Attacks such as −
supply chain
attacks
network
investigation
Strategy 2 − Creating an Assurance Framework
The objective of this strategy is to design an outline in compliance with
the global security standards through traditional products, processes,
people, and technology.
To cater to the national security requirements, a national framework
known as the Cybersecurity Assurance Framework was developed. It
accommodates critical infrastructure organizations and the governments
through "Enabling and Endorsing" actions.
Enabling actions are performed by government entities that are
autonomous bodies free from commercial interests. The publication of
"National Security Policy Compliance Requirements" and IT security
guidelines and documents to enable IT security implementation and
compliance are done by these authorities.
Endorsing actions are involved in profitable services after meeting the
obligatory qualification standards and they include the following −
ISO 27001/BS 7799 ISMS certification, IS system audits etc.,
which are essentially the compliance certifications.
'Common Criteria' standard ISO 15408 and Crypto module
verification standards, which are the IT Security product
evaluation and certification.
Services to assist consumers in implementation of IT security such
as IT security manpower training.
Trusted Company Certification
Indian IT/ITES/BPOs need to comply with the international standards
and best practices on security and privacy with the development of the
outsourcing market. ISO 9000, CMM, Six Sigma, Total Quality
Management, ISO 27001 etc., are some of the certifications.
Existing models such as SEI CMM levels are exclusively meant for
software development processes and do not address security issues.
Therefore, several efforts are made to create a model based on self-
certification concept and on the lines of Software Capability Maturity
Model (SW-CMM) of CMU, USA.
The structure that has been produced through such association between
industry and government, comprises of the following −
standards
guidelines
practices
These parameters help the owners and operators of critical infrastructure
to manage cybersecurity-related risks.
Strategy 3 − Encouraging Open Standards
Standards play a significant role in defining how we approach
information security related issues across geographical regions and
societies. Open standards are encouraged to −
Enhance the efficiency of key processes,
Enable systems incorporations,
Provide a medium for users to measure new products or services,
Organize the approach to arrange new technologies or business
models,
Interpret complex environments, and
Endorse economic growth.
Standards such as ISO 27001[3] encourage the implementation of a
standard organization structure, where customers can understand
processes, and reduce the costs of auditing.
Strategy 4 − Strengthening the Regulatory Framework
The objective of this strategy is to create a secure cyberspace ecosystem
and strengthen the regulatory framework. A 24X7 mechanism has been
envisioned to deal with cyber threats through National Critical
Information Infrastructure Protection Centre (NCIIPC). The Computer
Emergency Response Team (CERT-In) has been designated to act as a
nodal agency for crisis management.
Some highlights of this strategy are as follows −
Promotion of research and development in cybersecurity.
Developing human resource through education and training
programs.
Encouraging all organizations, whether public or private, to
designate a person to serve as Chief Information Security Officer
(CISO) who will be responsible for cybersecurity initiatives.
Indian Armed Forces are in the process of establishing a cyber-
command as a part of strengthening the cybersecurity of defense
network and installations.
Effective implementation of public-private partnership is in
pipeline that will go a long way in creating solutions to the ever-
changing threat landscape.
Strategy 5 − Creating Mechanisms for IT Security
Some basic mechanisms that are in place for ensuring IT security are −
link-oriented security measures, end-to-end security measures,
association-oriented measures, and data encryption. These methods
differ in their internal application features and also in the attributes of
the security they provide. Let us discuss them in brief.
Link-Oriented Measures
It delivers security while transferring data between two nodes,
irrespective of the eventual source and destination of the data.
End-to-End Measures
It is a medium for transporting Protocol Data Units (PDUs) in a
protected manner from source to destination in such a way that
disruption of any of their communication links does not violate security.
Association-Oriented Measures
Association-oriented measures are a modified set of end-to-end
measures that protect every association individually.
Data Encryption
It defines some general features of conventional ciphers and the recently
developed class of public-key ciphers. It encodes information in a way
that only the authorized personnel can decrypt them.
Strategy 6 − Securing E-Governance Services
Electronic governance (e-governance) is the most treasured instrument
with the government to provide public services in an accountable
manner. Unfortunately, in the current scenario, there is no devoted legal
structure for e-governance in India.
Similarly, there is no law for obligatory e-delivery of public services in
India. And nothing is more hazardous and troublesome than executing e-
governance projects without sufficient cybersecurity. Hence, securing
the e-governance services has become a crucial task, especially when the
nation is making daily transactions through cards.
Fortunately, the Reserve Bank of India has implemented security and
risk mitigation measures for card transactions in India enforceable from
1st October, 2013. It has put the responsibility of ensuring secured card
transactions upon banks rather than on customers.
"E-government" or electronic government refers to the use of
Information and Communication Technologies (ICTs) by government
bodies for the following −
Efficient delivery of public services
Refining internal efficiency
Easy information exchange among citizens, organizations, and
government bodies
Re-structuring of administrative processes.
Strategy 7 − Protecting Critical Information Infrastructure
Critical information infrastructure is the backbone of a country’s
national and economic security. It includes power plants, highways,
bridges, chemical plants, networks, as well as the buildings where
millions of people work every day. These can be secured with stringent
collaboration plans and disciplined implementations.
Safeguarding critical infrastructure against developing cyber-threats
needs a structured approach. It is required that the government
aggressively collaborates with public and private sectors on a regular
basis to prevent, respond to, and coordinate mitigation efforts against
attempted disruptions and adverse impacts to the nation’s critical
infrastructure.
It is in demand that the government works with business owners and
operators to reinforce their services and groups by sharing cyber and
other threat information.
A common platform should be shared with the users to submit
comments and ideas, which can be worked together to build a tougher
foundation for securing and protecting critical infrastructures.
The government of USA has passed an executive order "Improving
Critical Infrastructure Cybersecurity" in 2013 that prioritizes the
management of cybersecurity risk involved in the delivery of critical
infrastructure services. This Framework provides a common
classification and mechanism for organizations to −
Define their existing cybersecurity bearing,
Define their objectives for cybersecurity,
Categorize and prioritize chances for development within the
framework of a constant process, and
Communicate with all the investors about cybersecurity.
Cyber Law - Policies To Mitigate Cyber Risk
This chapter takes you through the various policies laid to minimize
cyber risk. It is only with well-defined policies that the threats generated
in the cyberspace can be reduced.
Promotion of R&D in Cybersecurity
Due to the ever-increasing dependence on the Internet, the biggest
challenge we face today is the security of information from miscreants.
Therefore, it is essential to promote research and development in
cybersecurity so that we can come up with robust solutions to mitigate
cyber risks.
Cybersecurity Research
Cybersecurity Research is the area that is concerned with preparing
solutions to deal with cyber criminals. With increasing amount of
internet attacks, advanced persistent threats and phishing, lots of
research and technological developments are required in the future.
Cybersecurity Research-Indian Perspective
In the recent years, India has witnessed an enormous growth in cyber
technologies. Hence it calls for an investment in the research and
development activities of cybersecurity. India has also seen many
successful research outcomes that were translated into businesses,
through the advent of local cybersecurity companies.
Threat Intelligence
Research work to mitigate cyber-threats is already being commenced in
India. There is a proactive response mechanism in place to deal with
cyber threats. Research and Development activities are already
underway at various research organizations in India to fight threats in
cyberspace.
Next Generation Firewall
Multi-identity based expertise such as Next Generation Firewall that
offers security intelligence to enterprises and enable them to apply best
suited security controls at the network perimeter are also being worked
on.
Secured Protocol and Algorithms
Research in protocols and algorithms is a significant phase for the
consolidation of cybersecurity at a technical level. It defines the rules for
information sharing and processing over cyberspace. In India, protocol
and algorithm level research includes −
Secure Routing Protocols
Efficient Authentication Protocols
Enhanced Routing Protocol for Wireless Networks
Secure Transmission Control Protocol
Attack Simulation Algorithm, etc.
Authentication Techniques
Authentication techniques such as Key Management, Two Factor
Authentication, and Automated key Management provide the ability to
encrypt and decrypt without a centralized key management system and
file protection. There is continuous research happening to strengthen
these authentication techniques.
BYOD, Cloud and Mobile Security
With the adoption of varied types of mobile devices, the research on the
security and privacy related tasks on mobile devices has increased.
Mobile security testing, Cloud Security, and BYOD (Bring Your Own
Device) risk mitigation are some of the areas where a lot of research is
being done.
Cyber Forensics
Cyber Forensics is the application of analysis techniques to collect and
recover data from a system or a digital storage media. Some of the
specific areas where research is being done in India are −
Disk Forensics
Network Forensics
Mobile Device Forensics
Memory Forensics
Multimedia Forensics
Internet Forensics
Reducing Supply Chain Risks
Formally, supply chain risk can be defined as −
Any risk that an opponent may damage, write some malicious function
to it, deconstruct the design, installation, procedure, or maintenance of a
supply item or a system so that the entire function can be degraded.
Supply Chain Issues
Supply chain is a global issue and there is a requirement to find out the
interdependencies among the customers and suppliers. In today’s
scenario it is important to know − What are the SCRM
problems? and How to address the problems?
An effective SCRM (Supply Chain Risk Management) approach
requires a strong public-private partnership. Government should have
strong authorities to handle supply chain issues. Even private sectors can
play a key role in a number of areas.
We cannot provide a one-size-fits-all resolution for managing supply
chain risks. Depending on the product and the sector, the costs for
reducing risks will weigh differently. Public Private Partnerships should
be encouraged to resolve risks associated with supply chain
management.
Mitigate Risks through Human Resource Development
Cybersecurity policies of an organization can be effective, provided all
its employees understand their value and exhibit a strong commitment
towards implementing them. Human resource directors can play a key
role in keeping organizations safe in cyberspace by applying the
following few points.
Taking Ownership of the Security Risk Posed by Employees
As most of the employees do not take the risk factor seriously, hackers
find it easy to target organizations. In this regard, HR plays a key role in
educating employees about the impact their attitudes and behavior have
on the organization’s security.
Ensuring that Security Measures are Practical and Ethical
Policies of a company must be in sync with the way employees think
and behave. For example, saving passwords on systems is a threat,
however continuous monitoring can prevent it. The HR team is best
placed to advise whether policies are likely to work and whether they are
appropriate.
Identifying Employees who may Present a Particular Risk
It also happens that cyber-criminals take the help of insiders in a
company to hack their network. Therefore it is essential to identify
employees who may present a particular risk and have stringent HR
policies for them.
Creating Cybersecurity Awareness
Cybersecurity in India is still in its evolution stage. This is the best time
to create awareness on issues related to cyber security. It would be easy
to create awareness from the grass-root level like schools where users
can be made aware how Internet works and what are its potential threats.
Every cyber café, home/personal computers, and office computers
should be protected through firewalls. Users should be instructed
through their service providers or gateways not to breach unauthorized
networks. The threats should be described in bold and the impacts
should be highlighted.
Subjects on cybersecurity awareness should be introduced in schools and
colleges to make it an ongoing process.
The government must formulate strong laws to enforce cybersecurity
and create sufficient awareness by broadcasting the same through
television/radio/internet advertisements.
Information Sharing
United States proposed a law called Cybersecurity Information
Sharing Act of 2014 (CISA) to improve cybersecurity in the country
through enhanced sharing of information about cybersecurity threats.
Such laws are required in every country to share threat information
among citizens.
Cybersecurity Breaches Need a Mandatory Reporting Mechanism
The recent malware named Uroburos/Snake is an example of growing
cyber-espionage and cyber-warfare. Stealing of sensitive information is
the new trend. However, it is unfortunate that the telecom
companies/internet service providers (ISPs) are not sharing information
pertaining to cyber-attacks against their networks. As a result, a robust
cybersecurity strategy to counter cyber-attacks cannot be formulated.
This problem can be addressed by formulating a good cybersecurity law
that can establish a regulatory regime for obligatory cybersecurity
breach notifications on the part of telecom companies/ISPs.
Infrastructures such as automated power grids, thermal plants, satellites,
etc., are vulnerable to diverse forms of cyber-attacks and hence a breach
notification program would alert the agencies to work on them.
Implementing a Cybersecurity Framework
Despite the fact that companies are spending on cybersecurity initiatives,
data breaches continue to occur. According to The Wall Street
Journal, "Global cybersecurity spending by critical infrastructure
industries was expected to hit $46 billion in 2013, up 10% from a year
earlier according to Allied Business Intelligence Inc." This calls for the
effective implementation of the cybersecurity framework.
Components of Cybersecurity Framework
The Framework comprises of three main components −
The Core,
Implementation Tiers, and
Framework Profiles.
The Framework Core
The Framework Core is a set of cybersecurity activities and applicable
references that having five simultaneous and constant functions −
Identify, Protect, Detect, Respond, and Recover. The framework core
has methods to ensure the following −
Develop and implement procedures to protect the most critical
intellectual property and assets.
Have resources in place to identify any cybersecurity breach.
Recover from a breach, if and when one occurs.
The Implementation Tiers
The Framework Implementation Tiers define the level of sophistication
and consistency an organization employs in applying its cybersecurity
practices. It has the following four levels.
Tier 1 (Partial) − In this level, the organization’s cyber-risk
management profiles are not defined. There is a partial consciousness of
the organization’s cybersecurity risk at the organization level.
Organization-wide methodology to managing cybersecurity risk has not
been recognized.
Tier 2 (Risk Informed) − In this level, organizations establish a cyber-
risk management policy that is directly approved by the senior
management. The senior management makes efforts to establish risk
management objectives related to cybersecurity and implements them.
Tier 3 (Repeatable) − In this level, the organization runs with formal
cybersecurity measures, which are regularly updated based on
requirement. The organization recognizes its dependencies and partners.
It also receives information from them, which helps in taking risk-based
management decisions.
Tier 4 (Adaptive) − In this level, the organization adapts its
cybersecurity practices "in real-time" derived from previous and current
cybersecurity activities. Through a process of incessant development in
combining advanced cybersecurity technologies, real-time collaboration
with partners, and continuous monitoring of activities on their systems,
the organization’s cybersecurity practices can quickly respond to
sophisticated threats.
The Framework Profile
The Framework Profile is a tool that provides organizations a platform
for storing information concerning their cybersecurity program. A
profile allows organizations to clearly express the goals of their
cybersecurity program.
Where do You Start with Implementing the Framework?
The senior management including the directors should first get
acquainted with the Framework. After which, the directors should have a
detailed discussion with the management about the organization’s
Implementation Tiers.
Educating the managers and staff on the Framework will ensure that
everyone understands its importance. This is an important step towards
the successful implementation of a vigorous cybersecurity program. The
information about existing Framework Implementations may help
organizations with their own approaches.
Cyber Law - Network Security
Network security is the security provided to a network from
unauthorized access and risks. It is the duty of network administrators to
adopt preventive measures to protect their networks from potential
security threats.
Computer networks that are involved in regular transactions and
communication within the government, individuals, or business require
security. The most common and simple way of protecting a network
resource is by assigning it a unique name and a corresponding password.
Types of Network Security Devices
Active Devices
These security devices block the surplus traffic. Firewalls, antivirus
scanning devices, and content filtering devices are the examples of such
devices.
Passive Devices
These devices identify and report on unwanted traffic, for example,
intrusion detection appliances.
Preventative Devices
These devices scan the networks and identify potential security
problems. For example, penetration testing devices and vulnerability
assessment appliances.
Unified Threat Management (UTM)
These devices serve as all-in-one security devices. Examples include
firewalls, content filtering, web caching, etc.
Firewalls
A firewall is a network security system that manages and regulates the
network traffic based on some protocols. A firewall establishes a barrier
between a trusted internal network and the internet.
Firewalls exist both as software that run on a hardware and as hardware
appliances. Firewalls that are hardware-based also provide other
functions like acting as a DHCP server for that network.
Most personal computers use software-based firewalls to secure data
from threats from the internet. Many routers that pass data between
networks contain firewall components and conversely, many firewalls
can perform basic routing functions.
Firewalls are commonly used in private networks or intranets to prevent
unauthorized access from the internet. Every message entering or
leaving the intranet goes through the firewall to be examined for security
measures.
An ideal firewall configuration consists of both hardware and software
based devices. A firewall also helps in providing remote access to a
private network through secure authentication certificates and logins.
Hardware and Software Firewalls
Hardware firewalls are standalone products. These are also found in
broadband routers. Most hardware firewalls provide a minimum of four
network ports to connect other computers. For larger networks − e.g., for
business purpose − business networking firewall solutions are available.
Software firewalls are installed on your computers. A software firewall
protects your computer from internet threats.
Antivirus
An antivirus is a tool that is used to detect and remove malicious
software. It was originally designed to detect and remove viruses from
computers.
Modern antivirus software provide protection not only from virus, but
also from worms, Trojan-horses, adwares, spywares, keyloggers, etc.
Some products also provide protection from malicious URLs, spam,
phishing attacks, botnets, DDoS attacks, etc.
Content Filtering
Content filtering devices screen unpleasant and offensive emails or
webpages. These are used as a part of firewalls in corporations as well as
in personal computers. These devices generate the message "Access
Denied" when someone tries to access any unauthorized web page or
email.
Content is usually screened for pornographic content and also for
violence- or hate-oriented content. Organizations also exclude shopping
and job related contents.
Content filtering can be divided into the following categories −
Web filtering
Screening of Web sites or pages
E-mail filtering
Screening of e-mail for spam
Other objectionable content
Intrusion Detection Systems
Intrusion Detection Systems, also known as Intrusion Detection and
Prevention Systems, are the appliances that monitor malicious activities
in a network, log information about such activities, take steps to stop
them, and finally report them.
Intrusion detection systems help in sending an alarm against any
malicious activity in the network, drop the packets, and reset the
connection to save the IP address from any blockage. Intrusion detection
systems can also perform the following actions −
Correct Cyclic Redundancy Check (CRC) errors
Prevent TCP sequencing issues
Clean up unwanted transport and network layer options
Cyber Law - I.T ACT
As discussed in the first chapter, the Government of India enacted the
Information Technology (I.T.) Act with some major objectives to deliver
and facilitate lawful electronic, digital, and online transactions, and
mitigate cyber-crimes.
Salient Features of I.T Act
The salient features of the I.T Act are as follows −
Digital signature has been replaced with electronic signature to
make it a more technology neutral act.
It elaborates on offenses, penalties, and breaches.
It outlines the Justice Dispensation Systems for cyber-crimes.
It defines in a new section that cyber café is any facility from
where the access to the internet is offered by any person in the
ordinary course of business to the members of the public.
It provides for the constitution of the Cyber Regulations Advisory
Committee.
It is based on The Indian Penal Code, 1860, The Indian Evidence
Act, 1872, The Bankers' Books Evidence Act, 1891, The Reserve
Bank of India Act, 1934, etc.
It adds a provision to Section 81, which states that the provisions
of the Act shall have overriding effect. The provision states
that nothing contained in the Act shall restrict any person from
exercising any right conferred under the Copyright Act, 1957.
Scheme of I.T Act
The following points define the scheme of the I.T. Act −
The I.T. Act contains 13 chapters and 90 sections.
The last four sections namely sections 91 to 94 in the I.T. Act 2000
deals with the amendments to the Indian Penal Code 1860, The
Indian Evidence Act 1872, The Bankers’ Books Evidence Act
1891 and the Reserve Bank of India Act 1934 were deleted.
It commences with Preliminary aspect in Chapter 1, which deals
with the short, title, extent, commencement and application of the
Act in Section 1. Section 2 provides Definition.
Chapter 2 deals with the authentication of electronic records,
digital signatures, electronic signatures, etc.
Chapter 11 deals with offences and penalties. A series of offences
have been provided along with punishment in this part of The Act.
Thereafter the provisions about due diligence, role of
intermediaries and some miscellaneous provisions are been stated.
The Act is embedded with two schedules. The First Schedule deals
with Documents or Transactions to which the Act shall not apply.
The Second Schedule deals with electronic signature or electronic
authentication technique and procedure. The Third and Fourth
Schedule are omitted.
Application of the I.T Act
As per the sub clause (4) of Section 1, nothing in this Act shall apply to
documents or transactions specified in First Schedule. Following are the
documents or transactions to which the Act shall not apply −
Negotiable Instrument (Other than a cheque) as defined in
section 13 of the Negotiable Instruments Act, 1881;
A power-of-attorney as defined in section 1A of the Powers-of-
Attorney Act, 1882;
A trust as defined in section 3 of the Indian Trusts Act, 1882;
A will as defined in clause (h) of section 2 of the Indian
Succession Act, 1925 including any other testamentary disposition;
Any contract for the sale or conveyance of immovable property or
any interest in such property;
Any such class of documents or transactions as may be notified by
the Central Government.
Amendments Brought in the I.T Act
The I.T. Act has brought amendment in four statutes vide section 91-94.
These changes have been provided in schedule 1-4.
The first schedule contains the amendments in the Penal Code. It
has widened the scope of the term "document" to bring within its
ambit electronic documents.
The second schedule deals with amendments to the India Evidence
Act. It pertains to the inclusion of electronic document in the
definition of evidence.
The third schedule amends the Banker's Books Evidence Act. This
amendment brings about change in the definition of "Banker's-
book". It includes printouts of data stored in a floppy, disc, tape or
any other form of electromagnetic data storage device. Similar
change has been brought about in the expression "Certified-copy"
to include such printouts within its purview.
The fourth schedule amends the Reserve Bank of India Act. It
pertains to the regulation of fund transfer through electronic means
between the banks or between the banks and other financial
institution.
Intermediary Liability
Intermediary, dealing with any specific electronic records, is a person
who on behalf of another person accepts, stores or transmits that record
or provides any service with respect to that record.
According to the above mentioned definition, it includes the following −
Telecom service providers
Network service providers
Internet service providers
Web-hosting service providers
Search engines
Online payment sites
Online auction sites
Online market places and cyber cafes
Highlights of the Amended Act
The newly amended act came with following highlights −
It stresses on privacy issues and highlights information security.
It elaborates Digital Signature.
It clarifies rational security practices for corporate.
It focuses on the role of Intermediaries.
New faces of Cyber Crime were added.
Cyber Law - Signatures
Digital Signature
A digital signature is a technique to validate the legitimacy of a digital
message or a document. A valid digital signature provides the surety to
the recipient that the message was generated by a known sender, such
that the sender cannot deny having sent the message. Digital signatures
are mostly used for software distribution, financial transactions, and in
other cases where there is a risk of forgery.
Electronic Signature
An electronic signature or e-signature, indicates either that a person who
demands to have created a message is the one who created it.
A signature can be defined as a schematic script related with a person. A
signature on a document is a sign that the person accepts the purposes
recorded in the document. In many engineering companies digital seals
are also required for another layer of authentication and security. Digital
seals and signatures are same as handwritten signatures and stamped
seals.
Digital Signature to Electronic Signature
Digital Signature was the term defined in the old I.T. Act,
2000. Electronic Signature is the term defined by the amended act (I.T.
Act, 2008). The concept of Electronic Signature is broader than Digital
Signature. Section 3 of the Act delivers for the verification of Electronic
Records by affixing Digital Signature.
As per the amendment, verification of electronic record by electronic
signature or electronic authentication technique shall be considered
reliable.
According to the United Nations Commission on International Trade
Law (UNCITRAL), electronic authentication and signature methods
may be classified into the following categories −
Those based on the knowledge of the user or the recipient, i.e.,
passwords, personal identification numbers (PINs), etc.
Those bases on the physical features of the user, i.e., biometrics.
Those based on the possession of an object by the user, i.e., codes
or other information stored on a magnetic card.
Types of authentication and signature methods that, without falling
under any of the above categories might also be used to indicate
the originator of an electronic communication (Such as a facsimile
of a handwritten signature, or a name typed at the bottom of an
electronic message).
According to the UNCITRAL MODEL LAW on Electronic Signatures,
the following technologies are presently in use −
Digital Signature within a public key infrastructure (PKI)
Biometric Device
PINs
Passwords
Scanned handwritten signature
Signature by Digital Pen
Clickable “OK” or “I Accept” or “I Agree” click boxes
Cyber Law - Offence & Penalties
The faster world-wide connectivity has developed numerous online
crimes and these increased offences led to the need of laws for
protection. In order to keep in stride with the changing generation, the
Indian Parliament passed the Information Technology Act 2000 that has
been conceptualized on the United Nations Commissions on
International Trade Law (UNCITRAL) Model Law.
The law defines the offenses in a detailed manner along with the
penalties for each category of offence.
Offences
Cyber offences are the illegitimate actions, which are carried out in a
classy manner where either the computer is the tool or target or both.
Cyber-crime usually includes the following −
Unauthorized access of the computers
Data diddling
Virus/worms attack
Theft of computer system
Hacking
Denial of attacks
Logic bombs
Trojan attacks
Internet time theft
Web jacking
Email bombing
Salami attacks
Physically damaging computer system.
The offences included in the I.T. Act 2000 are as follows −
Tampering with the computer source documents.
Hacking with computer system.
Publishing of information which is obscene in electronic form.
Power of Controller to give directions.
Directions of Controller to a subscriber to extend facilities to
decrypt information.
Protected system.
Penalty for misrepresentation.
Penalty for breach of confidentiality and privacy.
Penalty for publishing Digital Signature Certificate false in certain
particulars.
Publication for fraudulent purpose.
Act to apply for offence or contravention committed outside India
Confiscation.
Penalties or confiscation not to interfere with other punishments.
Power to investigate offences.
Example
Offences Under The It Act 2000
Section 65. Tampering with computer source documents
Whoever knowingly or intentionally conceals, destroys or alters or
intentionally or knowingly causes another to conceal, destroy or alter
any computer source code used for a computer, computer program,
computer system or computer network, when the computer source code
is required to be kept or maintained by law for the being time in force,
shall be punishable with imprisonment up to three year, or with fine
which may extend up to two lakh rupees, or with both.
Explanation − For the purpose of this section “computer source code”
means the listing of programs, computer commands, design and layout
and program analysis of computer resource in any form.
Object − The object of the section is to protect the “intellectual
property” invested in the computer. It is an attempt to protect the
computer source documents (codes) beyond what is available under the
Copyright Law
Essential ingredients of the section
knowingly or intentionally concealing
knowingly or intentionally destroying
knowingly or intentionally altering
knowingly or intentionally causing others to conceal
knowingly or intentionally causing another to destroy
knowingly or intentionally causing another to alter.
This section extends towards the Copyright Act and helps the companies
to protect their source code of their programs.
Penalties − Section 65 is tried by any magistrate.
This is cognizable and non-bailable offence.
Penalties − Imprisonment up to 3 years and / or
Fine − Two lakh rupees.
The following table shows the offence and penalties against all the
mentioned sections of the I.T. Act −
Section Offence Punishment Bailability
and
Congizability
65 Tampering with Imprisonment up Offence is
Computer Source to 3 years or fine Bailable,
Code up to Rs 2 lakhs Cognizable
and triable by
Court of
JMFC.
66 Computer Related Imprisonment up Offence is
Offences to 3 years or fine Bailable,
up to Rs 5 lakhs Cognizable
and
66-A Sending offensive Imprisonment up Offence is
messages through to 3 years and Bailable,
Communication fine Cognizable
service, etc... and triable by
Court of JMFC
66-B Dishonestly receiving Imprisonment up Offence is
stolen computer to 3 years and/or Bailable,
resource or fine up to Rs. 1 Cognizable
communication lakh and triable by
device Court of JMFC
66-C Identity Theft Imprisonment of Offence is
either Bailable,
description up to Cognizable
3 years and/or and triable by
fine up to Rs. 1 Court of JMFC
lakh
66-D Cheating by Imprisonment of Offence is
Personation by using either Bailable,
computer resource description up to Cognizable
3 years and /or and triable by
fine up to Rs. 1 Court of JMFC
lakh
66-E Violation of Privacy Imprisonment up Offence is
to 3 years and Bailable,
/or fine up to Rs. Cognizable
2 lakh and triable by
Court of JMFC
66-F Cyber Terrorism Imprisonment Offence is
extend to Non-Bailable,
imprisonment Cognizable
for Life and triable by
Court of
Sessions
67 Publishing or On first Offence is
transmitting obscene Conviction, Bailable,
material in electronic imprisonment up Cognizable
form to 3 years and/or and triable by
fine up to Rs. 5 Court of JMFC
lakh On
Subsequent
Conviction
imprisonment up
to 5 years and/or
fine up to Rs. 10
lakh
67-A Publishing or On first Offence is
transmitting of Conviction Non-Bailable,
material containing imprisonment up Cognizable
sexually explicit act, to 5 years and/or and triable by
etc... in electronic fine up to Rs. 10 Court of JMFC
form lakh On
Subsequent
Conviction
imprisonment up
to 7 years and/or
fine up to Rs. 10
lakh
67-B Publishing or On first Offence is Non
transmitting of Conviction Bailable,
material depicting imprisonment of Cognizable
children in sexually either and triable by
explicit act etc., in description up to Court of JMFC
electronic form 5 years and/or
fine up to Rs. 10
lakh On
Subsequent
Conviction
imprisonment of
either
description up to
7 years and/or
fine up to Rs. 10
lakh
67-C Intermediary Imprisonment up Offence is
intentionally or to 3 years and Bailable,
knowingly fine Cognizable.
contravening the
directions about
Preservation and
retention of
information
68 Failure to comply Imprisonment up Offence is
with the directions to 2 years and/or Bailable, Non-
given by Controller fine up to Rs. 1 Cognizable.
lakh
69 Failure to assist the Imprisonment up Offence is
agency referred to in to 7 years and Non-Bailable,
sub section (3) in fine Cognizable.
regard interception or
monitoring or
decryption of any
information through
any computer
resource
69-A Failure of the Imprisonment up Offence is
intermediary to to 7 years and Non-Bailable,
comply with the fine Cognizable.
direction issued for
blocking for public
access of any
information through
any computer
resource
69-B Intermediary who Imprisonment up Offence is
intentionally or to 3 years and Bailable,
knowingly fine Cognizable.
contravenes the
provisions of sub-
section (2) in regard
monitor and collect
traffic data or
information through
any computer
resource for
cybersecurity
70 Any person who Imprisonment of Offence is
secures access or either Non-Bailable,
attempts to secure description up to Cognizable.
access to the 10 years and fine
protected system in
contravention of
provision of Sec. 70
70-B Indian Computer Imprisonment up Offence is
Emergency Response to 1 year and/or Bailable, Non-
Team to serve as fine up to Rs. 1 Cognizable
national agency for lakh
incident response.
Any service provider,
intermediaries, data
centres, etc., who
fails to prove the
information called for
or comply with the
direction issued by
the ICERT.
71 Misrepresentation to Imprisonment up Offence is
the Controller to the to 2 years and/ Bailable, Non-
Certifying Authority or fine up to Rs. Cognizable.
1 lakh.
72 Breach of Imprisonment up Offence is
Confidentiality and to 2 years and/or Bailable, Non-
privacy fine up to Rs. 1 Cognizable.
lakh.
72-A Disclosure of Imprisonment up Offence is
information in breach to 3 years and/or Cognizable,
of lawful contract fine up to Rs. 5 Bailable
lakh.
73 Publishing electronic Imprisonment up Offence is
Signature Certificate to 2 years and/or Bailable, Non-
false in certain fine up to Rs. 1 Cognizable.
particulars lakh
74 Publication for Imprisonment up Offence is
fraudulent purpose to 2 years and/or Bailable, Non-
fine up to Rs. 1 Cognizable.
lakh
Compounding of Offences
As per Section 77-A of the I. T. Act, any Court of competent jurisdiction
may compound offences, other than offences for which the punishment
for life or imprisonment for a term exceeding three years has been
provided under the Act.
No offence shall be compounded if −
The accused is, by reason of his previous conviction, is liable to
either enhanced punishment or to the punishment of different kind;
OR
Offence affects the socio economic conditions of the country; OR
Offence has been committed against a child below the age of 18
years; OR
Offence has been committed against a woman.
The person alleged of an offence under this Act may file an application
for compounding in the Court. The offence will then be pending for trial
and the provisions of Sections 265-B and 265-C of Cr. P.C. shall apply.
Cyber Law - Summary
Cyber Laws are the sole savior to combat cyber-crime. It is only through
stringent laws that unbreakable security could be provided to the
nation’s information. The I.T. Act of India came up as a special act to
tackle the problem of Cyber Crime. The Act was sharpened by the
Amendment Act of 2008.
Cyber Crime is committed every now and then, but is still hardly
reported. The cases of cyber-crime that reaches to the Court of Law are
therefore very few. There are practical difficulties in collecting, storing
and appreciating Digital Evidence. Thus the Act has miles to go before it
can be truly effective.
In this tutorial, we have tried to cover all the current and major topics
related to Cyber Laws and IT Security. We would like to quote the
words of a noted cyber law expert and Supreme Court advocate Mr
Pavan Duggal to conclude this tutorial.
While the lawmakers have to be complemented for their admirable work
removing various deficiencies in the Indian Cyberlaw and making it
technologically neutral, yet it appears that there has been a major
mismatch between the expectation of the nation and the resultant effect
of the amended legislation. The most bizarre and startling aspect of the
new amendments is that these amendments seek to make the Indian
cyberlaw a cyber-crime friendly legislation; − a legislation that goes
extremely soft on cyber criminals, with a soft heart; a legislation that
chooses to encourage cyber criminals by lessening the quantum of
punishment accorded to them under the existing law; .... a legislation
which makes a majority of cybercrimes stipulated under the IT Act as
bailable offences; a legislation that is likely to pave way for India to
become the potential cyber-crime capital of the world.
Conclusion
Today’s network environment is full of dangerous attackers, hackers,
crackers, and spammers. Authentication, authorization and auditing are
the most important issues of security on data communication. An
authentication system must provide adequate security for its intended
environment, otherwise it fails to meet its primary goal. A proposed
system should at minimum be evaluated against common attacks to
determine if it satisfies security requirements. We classify the types of
attacks on knowledge-based authentication into two general categories:
guessing and capture attacks. In successful guessing attacks, attackers
are able to either exhaustively search through the entire theoretical
password space, or predict higher probability passwords (i.e., create a
dictionary of likely passwords) so as to obtain an acceptable success rate
within a manageable number of guesses. Guessing attacks may be
conducted online through the intended login interface, or online if some
variable text (e.g., hashes) can be used to assess the correctness of
guesses. Authentication systems with small theoretical password spaces
or with identifiable patterns in user choice of passwords are especially
vulnerable to guessing attacks.
Fake websites which appear very similar to the original ones are being
hosted to achieve this. Phishing is an attempt by an individual or a group
to get confidential information such as passwords and credit card
information from unsuspecting victims for identity theft, financial gain
and other fraudulent activities. Authentication is the first line of defense
against compromising confidentiality and integrity. The various
authentication systems were introduced but even they are also suffering
from shoulder surfing and screen dump attacks.
1.2 Authentication
Security has become an inseparable issue as information technology is
ruling the world. As a result of the astonishingly rapid advancement of
various kinds of Internet technologies, more information are transmitted
to all parts of the world from everywhere through the net. Some of the
objects transmitted online may be important secret images, and in such
cases the senders have to take information security issues into
consideration before they can trustingly enjoy the speed and
convenience that nothing in this world but the Internet can offer.
Cryptography is the study of mathematically related techniques to
achieve Information Security in terms of confidentiality, data security,
entity authentication and data origin authentication. However, it is not
the only means of providing information security.
Cryptography includes a set of techniques to achieve confidentiality
(amongst others) when transmitting or storing data. Traditional
cryptographic schemes require end users to employ complex operations
for encryption as well as decryption. An alternative to encrypt messages
is Visual
Cryptography (VC), where the decryption is completely performed by
the human visual system. Visual cryptography[1] is a new technique
which provides information security which uses simple algorithm unlike
the complex, computationally intensive algorithms of traditional
cryptography. This technique allows Visual information (pictures, text,
etc) to be encrypted in such a way that their decryption can be performed
by the human visual system, without any complex cryptographic
algorithms. VC schemes hide the secret image into two or more images
which are called shares. The secret image can be recovered simply by
stacking the shares together without any complex computation involved.
The shares are very safe because separately they reveal nothing about
the secret image.
1.3 Passwords
Generally passwords are used to provide security to a user in a website.
But, password capture attacks involve directly obtaining the password,
or part thereof, by capturing login credentials when entered by the user,
or by tricking the user into divulging their password. Shoulder surfing,
phishing, and some kinds of malware are common forms of capture
attacks. In shoulder surfing, credentials are captured by direct
observation of the login process or through some external recording
device such as a video camera. Phishing is a type of social engineering
where users are tricked into entering their credentials at a fraudulent
website recording user input.
Malware uses unauthorized software on client computers or servers to
capture keyboard, mouse, or screen output, which is then parsed to and
login credentials. As will be seen, early graphical password systems
tended to focus on one particular strength, for example being resistant to
shoulder surfing, but testing and analysis showed that they were
vulnerable to one or more other types of attacks. Except in very specific
environments, these would not provide adequate security. Often playing
an important role related to security is the particular process of encoding
or discretization used to transforming the user input into discrete units
that can be identified by the system and used for comparison during
password re-entry. As will be seen, some schemes require that the
system retains knowledge of the exact secret (or portion thereof), either
to display the correct set of images to the user or to verify password
entries. In other cases, encoded or discretized passwords may be hashed,
using a one-way cryptographic hash, to provide additional security in
case the password level is compromised.
Since such a stream of passwords is almost impossible to remember
(certainly for me), the hapless user is forced to write these passwords
down, adding to the insecurity. Thus passwords need to be protected by
cryptographic techniques, whether they are stored or transmitted.
Several simple techniques can help make the old-fashioned form of
passwords easier to memorize. First, the system can present a user with a
list of possible random passwords from which to choose. With such a
choice, there may be one password that is easier for a given user to
remember. Second, the most common passwords are limited to 8
characters, and experience has shown that users have a hard time picking
such a short password that turns out to be secure.
If the system allows passwords of arbitrary length (fairly common now),
then users can employ pass phrases: a phrase or sentence that is not
going to be in dictionaries yet is easy for the given user to remember.
Personal physical characteristics form the basis for a number of
identification methods now in use. The characteristics or biometrics
range from finger prints to iris patterns, from voice to hand geometry,
among many examples. A simple system password scheme would just
have a secret file holding each user’s account name and the
corresponding password. There are several problems with this method: if
someone manages to read this file, they can immediately pretend to be
any of the users listed. Also, someone might find out about a user’s
likely passwords from passwords used in the past.
For the reasons above and others, early UNIX systems protected
passwords with a one-way function. Along with the account name, the
one-way function applied to the password is stored. Thus given a user A,
with account name NA and password PA, and given a fixed one-way
function h, the system would store NA and h (PA ) as a table entry in the
password ‘le, with similar entries for other users. When A supplies his
password to the system, the software computes h of his password and
compares this result with the table entry. In this way the systems
administrators themselves will not know the passwords of users and will
not be able to impersonate a user.
In early UNIX systems it was a matter of pride to make the password
file world readable. A user would try to guess other’s passwords by
trying a guess P: first calculate h (P) and then compare this with all table
entries. There were many values of P to try, such as entries in a
dictionary, common names, special entries that are often used as
passwords, all short passwords, and all the above possibilities with
special characters at the beginning or the end. These ‘cracker’ programs
have matured to the point where they can always find at least some
passwords if there are quite a few users in the system. Now the password
file is no longer public, but someone with root privileges can still get to
it, and it sometimes leaks out in other ways.
To make the attack in the previous paragraph harder (that attack is
essentially the same as cipher text searching), systems can first choose h
the one-way function to be more execution time intensive. This only
slows down the searches by a linear factor. Another approach uses an
additional random table entry, called a salt. Suppose for example that
each password table entry has another random t-bit field (the salt),
different for each password. When A first puts his password into the
system (or changes it), he supplies PA. The system chooses the salt and
calculates EA = h (PA, SA), where h is fixed up to handle two inputs
instead of one.
The password file entry for A now contains A, SA, and EA. With this
change, an attack on a single user is the same, but the attack of the
previous paragraph on all users at the same time now takes either an
extra factor of time equal to either 2t or the number of users, whichever
is smaller. Without the salt, an attacker could check if ‘Vachaspati’ were
the password of any user by calculating h (‘Vachaspati’) and doing a fast
search of the password ‘le for this entry. With the salt, to check if A is
using ‘Vachaspati’ for example, the attacker must retrieve A’s salt SA
and calculate h (‘Vachaspati’, SA). Each user requires a different
calculation, so this simple device greatly slows down the dictionary
attack.
Text Password:
Password strength is a measure of the effectiveness of a password in
resisting guessing and brute-force attacks. In its usual form, it estimates
how many trials an attacker who does not have direct access to the
password would need, on average, to guess it correctly. The strength of a
password is a function of length, complexity, and unpredictability [2]
However, other attacks on passwords can succeed without a brute search
of every possible password. For instance, knowledge about a user may
suggest possible passwords (such as pet names, children’s names, etc.).
Hence estimates of password strength must also take into account
resistance to other attacks as well. Using strong passwords lowers
overall risk of a security breach, but strong passwords do not replace the
need for other effective security controls. The effectiveness of a
password of a given strength is strongly determined by the design and
implementation of the authentication system software, particularly how
frequently password guesses can be tested by an attacker and how
securely information on user passwords is stored and transmitted. Risks
are also posed by several means of breaching computer security which
are unrelated to password strength.
Determining Password Strength:
There are two factors to consider in determining password strength: the
ease with which an attacker can check the validity of a guessed
password, and the average number of guesses the attacker must make to
find the correct password. The first factor determined by how the
password is stored and what it is used for, while the second factor is
determined by how long the password is, what set of symbols it is drawn
from and how it is created.
Password Guess Validation:
The most obvious way to test a guessed password is to attempt to use it
to access the resource the password was meant to protect. However, this
can be slow and many systems will delay or block access to an account
after several wrong passwords are entered. On the other hand, systems
that use passwords for authentication must store them in some form to
check against entered values. Usually only hash value of a password is
stored instead of the password itself. If the hash is strong enough, it is
very hard to reverse it, so an attacker who gets hold of the hash value
cannot directly recover the password. However, if the cryptographic
hash data files have been stolen, knowledge of the hash value lets the
attacker quickly test guesses.
Password Creation:
Passwords are created either automatically (using randomizing
equipment) or by a human. The strength of randomly chosen passwords
against a brute force attack can be calculated with precision. Commonly,
passwords are initially created by asking a human to choose a password,
sometimes guided by suggestions or restricted by a set of rules. This
typically happens at the time of account creation for computer systems
or Internet Web sites. In this case, only estimates of strength are
possible, since humans tend to follow patterns in such tasks, and those
patterns may assist an attacker [3].
Password strength depends on symbol set and length:
Increasing the number of possible symbols from which random
passwords are chosen will increase the strength of generated passwords
of any given length. For example, the printable characters in the
American Standard Code for Information Interchange (ASCII) character
set (roughly those on a standard U.S. English keyboard) include 26
letters (in two case variants), 10 digits, and 33 non-alphanumeric
symbols (i.e., punctuation, grouping, etc.), for a total of 94 symbols (95
if space is included). However the same strength can always be achieved
with a smaller symbol set by choosing a longer password. In the
extreme, binary passwords can be very secure, even though they only
use two possible symbols. Thus a 14 character password consisting of
only random lowercase letters has the same strength (4.7??14 = 65.8
bits) as a ten character password chosen at random from all printable
ASCII characters (65.55 bits).
Guide Lines for Passwords:
Common guidelines for choosing good passwords are designed to make
passwords less easily discovered by intelligent guessing [4-7]:
‘ Password length should be around 12 to 14 characters if permitted, and
longer still if possible while remaining memorable
‘ Use randomly generated passwords where feasible
‘ Avoid any password based on repetition, dictionary words, letter or
number sequences, usernames, relative or pet names, romantic links
(current or past), or biographical information (e.g., ID numbers,
ancestors names or dates).
‘ Include numbers, and symbols in passwords if allowed by the system
‘ If the system recognizes case as significant, use capital and lower-case
letters
‘ Avoid using the same password for multiple sites or purposes
‘ If we write our passwords down, keep the list in a safe place, such as a
wallet or safe, not attached to a monitor or in an unlocked desk drawer
Protecting passwords:
Computer users are generally advised to “never write down a password
anywhere, no matter what” and “never use the same password for more
than one account.” However, an ordinary computer user may have
dozens of password-protected accounts. Users with multiple accounts
needing passwords often give up and use the same password for every
account. When varied password complexity requirements prevent use of
the same (memorable) scheme for producing high-strength passwords,
overly simplified passwords will often be created to satisfy irritating and
conflicting password requirements. A Microsoft expert was quoted as
saying at a 2005 security conference: “I claim that password policy
should say we should write down our password. I have 68 different
passwords. If I am not allowed to write any of them down, guess what I
am going to do? I am going to use the same password on every one of
them [2].
Limitations of alphanumeric passwords:
The main problem with the alphanumeric passwords is that once a
password has been chosen and learned the user must be able to recall it
to log in. But, people genarally forget their passwords. If a password is
not frequently used it will be even more susceptible to forgetting.
The recent surveys have shown that users select short, simple passwords
that are easily guessable, for example, personal names of their family
members, names of pets, date of birth etc. [8].The most important issue
is having a password that can be remembered reliably and input quickly.
They are unlikely to give priority to security over their need to get on
with their work.
1.3.1 Graphical Passwords
Like text passwords, graphical passwords[9] are knowledge-based
authentication mechanisms where users enter a shared secret as evidence
of their identity. However, where text passwords involve alphanumeric
and/or special keyboard characters, the idea behind graphical passwords
is to leverage human memory for visual information, with the shared
secret being related to or composed of images or sketches.
Graphical password technique is one of methods which may provide
more secure and more efficiency system for authentication. A set of
secure passwords needs to be long enough and random , but that will be
a problem for human to remember. Everyone will forget their settings
everyday if they didn’t use again. The research results showed that,
when users forget their password, they can only remember part of the
correctness. Usable and easy memorization is the main research issues of
graphical password authentication.
1.4 Visual Cryptography
One of the best known techniques to protect data is cryptography. It is
the art of sending and receiving encrypted messages that can be
decrypted only by the sender or the receiver.
Cryptography
Figure 1.1 Sequences of Steps in Cryptography
Visual Cryptography is a secret-sharing method that encrypts a secret
image into several shares but requires neither computer nor calculations
to decrypt the secret image. Instead, the secret image is reconstructed
visually: simply by overlaying the encrypted shares the secret image
becomes clearly visible .
A Visual Cryptography Scheme (VCS) [1] on a set ?? of n participants is
a method of encoding a ‘secret’ image into n shares such that original
image is obtained only by stacking specific combinations of the shares
onto each other. It is a cryptographic technique that allows for the
encryption of visual information such that decryption can be performed
using the human visual system. We can achieve this by one of the
following access structure schemes.
‘ (2, 2)- Threshold VCS scheme- This is a simplest threshold scheme
that takes a secret message and encrypts it in two different shares that
reveal the secret image when they are overlaid.
‘ (n, n) -Threshold VCS scheme- This scheme encrypts the secret image
to n shares such that when all n of the shares are combined will the
secret image be revealed.
‘ (k, n) -Threshold VCS scheme- This scheme encrypts the secret image
to n shares such that when any group of at least k shares are overlaid the
secret image will be revealed.[10]
In case of (2, 2) VCS, each pixel P in the original image is encrypted
into two sub pixels called shares.
VCS with random shares the traditional VCS or simply the VCS. In
general, a traditional VCS takes a secret image as input, and outputs
shares that satisfy two conditions:
1) any qualified subset of shares can recover the secret image;
2) any forbidden subset of shares cannot obtain any information of the
secret image other than the size of the secret image.
Visual Cryptography
Plaintext (in form of image)
Encryption ( creating shares)
Channel (Fax, Email)
Decryption (Human Visual System)
The choice of shares for a white and black pixel is randomly determined
(there are two choices available for each pixel). Neither share provides
any clue about the original pixel since different pixels in the secret
image will be encrypted using independent random choices. When the
two shares are superimposed, the value of the original pixel P can be
determined. If P is a black pixel, we get two black sub pixels; if it is a
white pixel, we get one black sub pixel and one white sub pixel.
The basic principle of the visual cryptography scheme (VCS) was first
introduced by Naor and Shamir. VCS is a kind of secret sharing scheme
that focuses on sharing secret images[11]. The idea of the visual
cryptography model proposed in is to split a secret image into two
random shares (printed on transparencies) which separately reveals no
information about the secret image other than the size of the secret
image. The secret image can be reconstructed by stacking the two
shares. The underlying operation of this scheme is logical operation OR.
VCS has many special applications, for example, transmitting military
orders to soldiers who may have no cryptographic knowledge or
computation devices in the battle field. Many other applications of VCS,
other than its original objective(i.e., sharing secret image), have been
found, for example, authentication and identification, watermarking and
transmitting passwords etc.,
Let us go through the practical example:
The figure shown below shows generation and dissolving that image
Captcha into two shares using (2, 2) VCS. Image also shows
reconstructed image Captcha from the shares. As we can see, Share1 and
share2 are shares of Image Captcha and Reconstructed Image Captcha is
also shown in the Figure
Figure 1.4 Shares Generation
In the next sections we’ll discuss about Literature Survey,
Implementation, Results, Conclusion and Future Scope.
1.5 Alternatives to Password Authentication
The numerous ways in which permanent or semi-permanent passwords
can be compromised has prompted the development of other techniques.
Unfortunately, some are inadequate in practice, and in any case few have
become universally available for users seeking a more secure alternative.
‘ Single-use passwords are only valid once makes many potential attacks
ineffective. Most users find single use passwords extremely
inconvenient. They have, however, been widely implemented in
personal online banking, where they are known as Transaction
Authentication Numbers (TANs). As most home users only perform a
small number of transactions each week, the single use issue has not led
to intolerable customer dissatisfaction in this case.
‘ Time-synchronized one-time passwords are similar in some ways to
single-use passwords, but the value to be entered is displayed on a small
(generally pocketable) item and changes every minute or so.
‘ Pass Window one-time passwords are used as single-use passwords,
but the dynamic characters to be entered are visible only when a user
superimposes a unique printed visual key over a server generated
challenge image shown on the user’s screen.
‘ Access controls based on public key cryptography e.g. SSH. The
necessary keys are usually too large to memorize and must be stored on
a local computer, security token or portable memory device, such as a
USB flash drive or even floppy disk.
‘ Biometric methods promise authentication based on unalterable
personal characteristics, but currently (2008) have high error rates and
require additional hardware to scan, for example, fingerprints, irises, etc.
They have proven easy to spoof in some famous incidents testing
commercially available systems, for example, the gummie fingerprint
spoof demonstration [12] and because these characteristics are
unalterable, they cannot be changed if compromised; this is a highly
important consideration in access control as a compromised access token
is necessarily insecure.
‘ Single sign-on technology is claimed to eliminate the need for having
multiple passwords. Such schemes do not relieve user and administrators
from choosing reasonable single passwords, nor system designers or
administrators from ensuring that private access control information
passed among systems enabling single sign-on is secure against attack.
As yet, no satisfactory standard has been developed.
‘ Non-text-based passwords, such as graphical passwords or mouse-
movement based passwords [13]. Graphical passwords are an alternative
means of authentication for log-in intended to be used in place of
conventional password; they use images, graphics or colors instead of
letters, digits or special characters. One system requires users to select a
series of faces as a password, utilizing the human brain’s ability to recall
faces easily [14]. In some implementations the user is required to pick
from a series of images in the correct sequence in order to gain access
[15]. Another graphical password solution creates a one-time password
using a randomly-generated grid of images. Each time the user is
required to authenticate, they look for the images that fit their pre-
chosen categories and enter the randomly-generated alphanumeric
character that appears in the image to form the one-time password [16,
17] .So far, graphical passwords are promising, but are not widely used.
Studies on this subject have been made to determine its usability in the
real world. While some believe that graphical passwords would be
harder to crack, others suggest that people will be just as likely to pick
common images or sequences as they are to pick common passwords.
‘ 2D Key (Two-Dimensional Key) is a 2D matrix-like key input method
having the key styles of multiline passphrase, crossword,
ASCII/Unicode art, with optional textual semantic noises, to create big
password/key beyond 128 bits to realize the MePKC (Memorizable
Public-Key Cryptography) using fully memorizable private key upon the
current private key management technologies like encrypted private key,
split private key, and roaming private key.
‘ Cognitive passwords use question and answer cue/response pairs to
verify identity.
1.6 Problems Suited to a Neural Network:
Although there are many problems that neural networks are not suited
for there are also many problems that a neural network is quite useful for
solving. In addition, neural networks can often solve problems with
fewer lines of code than a traditional programming algorithm. It is
important to understand what these problems are. Neural networks are
particularly useful for solving problems that cannot be expressed as a
series of steps, such as recognizing patterns, classifying into groups,
series prediction and data mining.
1.6.1 Validating Neural Networks:
Once a neural network has been trained it must be evaluated to see if it is
ready for actual use. This final step is important so that it can be
determined if additional training is required. To correctly validate a
neural network, validation data must be set aside that is completely
separate from the training data.
As an example, consider a classification network that must group
elements into three different classification groups. We are provided with
10,000 sample elements. For this sample data the group that each
element should be classified into is known. For such a system we would
divide the sample data into two groups of 5,000 elements. The first
group would form the training set. Once the network was properly
trained the second group of 5,000 elements would be used to validate the
neural network.
It is very important that a separate group always be maintained for
validation. First training a neural network with a given sample set and
also using this same set to predict the anticipated error of the neural
network a new arbitrary set, will surely lead to bad results. The error
achieved using the training set will almost always be substantially lower
than the error on a new set of sample data. The integrity of the validation
data must always be maintained.
This brings up an important question. What exactly does happen if the
neural network that we have just finished training performs poorly on
the validation set? If this is the case, then we must examine what,
exactly, this means. It could mean that the initial random weights were
not good. Rerunning the training with new initial weights could correct
this. While an improper set of initial random weights could be the cause,
a more likely possibility is that the training data was not properly
chosen.
If the validation is performing badly this most likely means that there
was data present in the validation set that was not available in the
training data. The way that this situation should be solved is by trying a
different, more random, way of separating the data into training and
validation sets. If this fails, we must combine the training and validation
sets into one large training set. Then new data must be acquired to serve
as the validation data [18].
For some situations it may be impossible to gather additional data to use
as either training or validation data. If this is the case then we are left
with no other choice but to combine all or part of the validation set with
the training set. While this approach will forgo the security of a good
validation, if additional data cannot be acquired this may be our only
alternative.
1.7 Phishing
Phishing is an act of attempting to acquire sensitive information of a
person by masquerading as a trust worthy entity in electronic
transaction. Phishing is typically carried out by e-mail spoofing or
instant messaging. Phishing e-mails contain links to websites infected
with malware
List of Phishing Techniques:
There are three types of phishing attacks. They are listed below.
Spear phishing
Phishing attempts directed at specific individuals or companies have
been termed as spear phishing.
Clone phishing
This is a type of phishing attack where a legitimate, and previously
delivered, email containing an attachment or link has had its content and
recipient’s address is taken and used to create an almost identical or
cloned email. The attachment or Link within the email is replaced with a
malicious version and then sent from an email address spoofed to appear
to come from the original sender. It may claim to be a re-send of the
original or an updated version to the original.
Whaling
Several recent phishing attacks have been directed specifically at senior
executives and other high profile targets within businesses, and the term
whaling has been coined for these kinds of attacks.
Working of Phishing
Phishing is generally carried out through e-mail spoofing. Here, attacker
sends a mail to the person whose details he wants to track. In the mail
attacker hides his true identity and generally he sends a link which
appears similar to the genuine website like bank website etc.., Here,
attacker adds some message to mislead the user. For e.g., In the mail
attacker may send a message saying ‘We are updating our database so
we request you to click the following link and update your data in our
site.’ Innocent users think it is true and they login to the site providing
their credentials and thus falling prey for Phishing attack.