0% found this document useful (0 votes)
5 views2 pages

Example: Example: Example

The document discusses various aspects of cybercrime, including its definition, characteristics, types of cyber offences, and legal implications. It highlights the differences between passive and active attacks, the significance of the Information Technology Act, 2000 in India, and the importance of digital signatures. Additionally, it covers specific cyber threats like SQL injection, email spoofing, and Bluetooth-related security threats.

Uploaded by

ARGHA DUTTA
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views2 pages

Example: Example: Example

The document discusses various aspects of cybercrime, including its definition, characteristics, types of cyber offences, and legal implications. It highlights the differences between passive and active attacks, the significance of the Information Technology Act, 2000 in India, and the importance of digital signatures. Additionally, it covers specific cyber threats like SQL injection, email spoofing, and Bluetooth-related security threats.

Uploaded by

ARGHA DUTTA
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

1. CYBERCRIME: DEFINITION AND CHARACTERISTICS 8.

DIFFERENCE BETWEEN PASSIVE ATTACKS AND ACTIVE ATTACKS


DEFINITION 4. SOFTWARE PIRACY AND ITS CONSEQUENCES Passive Attacks Active Attacks
Cybercrime is any illegal activity carried out using computers, networks, or the internet to steal data, Definition Involves monitoring or intercepting data Involves modifying, disrupting, or destroying
damage systems, or commit fraud.  Software piracy is the illegal copying, downloading, sharing, installation, or distribution of
without altering it. data or systems.
CHARACTERISTICS software without the permission of the copyright owner.
 It violates copyright laws and intellectual property rights.
Aims to damage, manipulate, or disrupt
 Technology-based: Uses computers and the internet. Aims to gather information secretly.
Consequences of Software Piracy operations.
 Global Reach: Can target victims anywhere in the world. Difficult to detect because no changes are Easier to detect due to noticeable system
 Financial Loss: Causes revenue loss to software developers and companies.
 Anonymity: Criminals can hide their identity. made to data. changes or disruptions.
 Legal Penalties: Individuals or organizations may face fines, lawsuits, or imprisonment.
 Fast Execution: Attacks spread quickly.  Security Risks: Pirated software often contains viruses, malware, or spyware. Affects system integrity, availability, or
 Data Targeted: Often aims to steal or misuse information. Does not affect system resources directly.
 No Technical Support: Users do not receive official updates, patches, or customer support. performance.
 Hard to Trace: Investigation and identification are difficult.  Reduced Innovation: Software companies may invest less in research and development due to Examples: Eavesdropping, traffic analysis, Examples: Hacking, malware attacks,
Conclusion: Cybercrime is a digital crime that poses serious threats to individuals, businesses, and losses. packet sniffing. DoS/DDoS attacks.
governments.
5. JURISDICTION IN CYBER LAW AND LEGISLATIVE JURISDICTION (4 MARKS)
2. DIFFERENT TYPES OF CYBER OFFENCES : Jurisdiction in Cyber Law 9. CYBER ATTACKS: CONCEPT AND EXAMPLES
Definition  Jurisdiction is the legal authority of a court or government to make and enforce laws related to
Definition
Cyber offences are illegal activities committed using computers, networks, or the internet. cyber activities and cybercrimes.  A cyber attack is an intentional attempt by an individual or group to gain unauthorized access
Types of Cyber Offences  It determines which country's laws apply to an online dispute or offence.
to, damage, disrupt, or steal information from computer systems, networks, or devices.
3. Hacking : Unauthorized access to a computer or network. Example: Breaking into a company's Legislative Jurisdiction Types of Cyber Attacks with Examples
database.  Legislative jurisdiction is the power of a government to create laws for persons, property, and
1. Malware Attack
4. Phishing: Sending fake emails or messages to steal personal information. Example: A fake activities.  Malicious software such as viruses, worms, or ransomware is used to harm a system.
bank email asking for login credentials.  In cyber law, it allows a country to make laws regarding cybercrimes, e-commerce, and online
 Example: Ransomware encrypting files and demanding payment.
5. Identity Theft: Stealing and misusing someone's personal information. Example: Using another communications. 2. Phishing Attack
person's Aadhaar or bank details.  It is based on principles such as territoriality (within the country's borders) and nationality
 Attackers trick users into revealing sensitive information through fake emails or websites.
6. Malware Attacks: Spreading malicious software such as viruses, worms, or ransomware. (for its citizens).  Example: A fake bank email asking for login credentials.
Example: Ransomware locking a user's files and demanding payment. Conclusion 3. Denial of Service (DoS) Attack
7. Cyber Stalking: Repeatedly harassing or threatening someone online. Example: Sending  Legislative jurisdiction helps governments regulate cyberspace and take legal action against
 Overloads a server or network with excessive traffic, making it unavailable.
threatening messages through social media. cyber offences.  Example: Flooding a website with requests to crash it.
8. Online Fraud: Cheating people through fake websites, advertisements, or transactions. 4. Hacking
Example: Fake e-commerce websites collecting money without delivering products.  Unauthorized access to a computer system or network.
 Example: Breaking into a company's database and stealing customer data.
6. DIFFERENCE BETWEEN JURISDICTION TO PRESCRIBE AND JURISDICTION TO Effects of Cyber Attacks
3. FORGERY IN CYBERCRIME AND ITS LEGAL IMPLICATIONS ENFORCE  Data theft and financial loss.
Definition of Forgery in Cybercrime Jurisdiction to Prescribe Jurisdiction to Enforce  Service disruption.
 Forgery in cybercrime refers to the creation, alteration, or manipulation of electronic Refers to the power of a state to make laws Refers to the power of a state to implement and  Loss of privacy and reputation.
documents, digital signatures, emails, certificates, or records with the intention to deceive or and regulations. enforce laws.
commit fraud. 10. UNCITRAL MODEL LAW AND ITS RELEVANCE IN CYBER LAW
It determines what conduct is considered It involves investigation, arrest, prosecution,
 It is done using computers, networks, or digital technologies. Definition
legal or illegal. and punishment of offenders.
Examples  UNCITRAL Model Law is a model legal framework developed by the United Nations
 Creating fake digital certificates. Based on principles such as territoriality, Generally limited to the state's own territory
nationality, and universality. unless international cooperation exists. Commission on International Trade Law (UNCITRAL) to facilitate and standardize electronic
 Altering electronic documents or records. commerce and electronic communications across countries.
 Forging digital signatures. Legislative bodies (Parliament/Congress) Police, courts, and enforcement agencies Key Features
 Sending fake emails pretending to be another person. exercise this power. exercise this power.  Gives legal recognition to electronic records and documents.
Legal Implications Example: A country enacts a cybercrime law Example: Authorities arrest and prosecute a  Recognizes electronic signatures as valid.
 Considered a criminal offence under cyber laws and criminal laws. applicable to its citizens. cybercriminal under that law.  Promotes uniformity in international electronic transactions.
 The offender may face:  Removes legal barriers to e-commerce.
o Imprisonment. Relevance in Cyber Law
o Monetary fines.  Provides a legal basis for electronic contracts and online transactions.
o Both imprisonment and fines, depending on the severity of the offence.  Enhances trust in e-commerce and digital communication.
 Victims can claim compensation for losses caused by the forgery.  Helps countries develop cyber laws consistent with international standards.
 Supports cross-border electronic trade and business.

11. INFORMATION TECHNOLOGY ACT, 2000 – OVERVIEW LEGAL ASPECTS OF CYBER LAW IN INDIA DENIAL OF SERVICE (DOS) ATTACK
Introduction Introduction Definition
 The Information Technology Act, 2000 is India's main law for regulating electronic  Cyber law in India governs the use of computers, networks, the internet, and electronic  A Denial of Service (DoS) attack is a cyber attack in which an attacker floods a computer,
transactions and cyber activities. transactions. server, or network with excessive requests, making it unavailable to legitimate users.
 It came into force on 17 October 2000.  The main legislation is the Information Technology Act, 2000. How It Works
Objectives Key Legal Aspects  The attacker sends a large number of requests or data packets to the target.
 Provide legal recognition to electronic records and digital signatures.  Legal Recognition of Electronic Records – Electronic documents are legally valid.  The target's resources become overloaded.
 Promote e-commerce and e-governance.  Digital/Electronic Signatures – Recognized for authentication of online transactions.  Legitimate users cannot access the service.
 Prevent and punish cybercrimes.  Cybercrime Regulation – Provides penalties for hacking, identity theft, phishing, and cyber Examples
Key Features terrorism.  Flooding a website with thousands of requests until it crashes.
 Recognizes electronic documents and digital signatures.  E-Commerce and E-Governance – Supports online business transactions and government  Sending a large number of fake connection requests to a server (SYN Flood Attack).
 Defines cyber offences and penalties. services.  Overloading an online banking website to disrupt its services.
 Provides a legal framework for secure online transactions.  Data Protection and Privacy – Requires organizations to protect sensitive personal Effects
Significance information.  Website or service downtime.
 Encourages digital business and online services. Importance  Loss of revenue and productivity.
 Protects users against cyber threats.  Ensures secure electronic communication and transactions.  Reduced system performance.
 Provides a legal framework for electronic communication.  Protects individuals and organizations from cyber offences. DIFFERENCE BETWEEN DOS AND DDOS ATTACKS
Conclusion  Promotes trust in digital platforms and online services.  DoS (Denial of Service)  DDoS (Distributed Denial of Service)
 The IT Act, 2000 is the foundation of cyber law in India, ensuring legal validity of electronic PUBLIC KEY CERTIFICATE AND ITS SIGNIFICANCE  Attack is launched from a single  Attack is launched from multiple computers or
transactions and protection against cybercrimes. Definition computer or source. devices.
IMPORTANT AMENDMENTS MADE IN THE IT ACT  A Public Key Certificate (PKC) is a digital document that links a user's identity with their
 Difficult to detect and stop because of multiple
Introduction public key.  Easier to detect and block.
 The Information Technology (Amendment) Act, 2008 updated the IT Act, 2000 to address new  It is issued by a trusted Certifying Authority (CA).
sources.
cyber threats and technological developments. Contents of a Public Key Certificate  Generates less traffic compared
 Generates massive traffic, causing severe disruption.
Important Amendments  Name of the certificate holder. to DDoS.
 Digital Signature replaced by Electronic Signature to support broader authentication methods.  Public key of the holder.  Less powerful and less effective.  More powerful and highly effective.
 Section 66A introduced penalties for offensive online messages (later struck down by the  Certificate serial number.  Example: One attacker flooding a  Example: A botnet of thousands of infected devices
Supreme Court in 2015).  Validity period. website with requests. attacking a website simultaneously.
 Section 66C added punishment for identity theft.  Digital signature of the Certifying Authority.
 Section 66D added punishment for cheating by personation using computer resources. Significance CYBERCRIME CASE STUDIES
 Section 66F introduced provisions related to cyber terrorism.  Verifies the identity of users or organizations.
Phishing Attack: Fake emails used to steal banking credentials. WannaCry Ransomware: Malware
 Section 43A made companies responsible for protecting sensitive personal data.  Ensures secure online communication.
encrypted files and demanded ransom. Identity Theft: Stolen personal information used for fraud.
Significance  Helps in encryption and digital signatures. Prevents impersonation and fraud in electronic
Conclusion: These cases show how cybercriminals steal data, money, and disrupt services.
 Strengthened cyber security laws. transactions. PREVENTIVE MEASURES AGAINST CYBERCRIME AND IDENTITY THEFT: Use strong
 Improved protection against online fraud and identity theft. TROJAN HORSES AND BACKDOORS passwords. Enable two-factor authentication (2FA). Avoid suspicious links and emails. Keep software
 Enhanced data protection and privacy measures. Definition and antivirus updated. Do not share personal information online.
LIMITATIONS OF THE INFORMATION TECHNOLOGY ACT Trojan Horse
Introduction  A Trojan Horse is a type of malware that appears to be legitimate software but performs
 Although the Information Technology Act, 2000 is India's primary cyber law, it has certain malicious activities when executed. SCRIPT KIDDIES AND THEIR ROLE IN CYBERCRIME
limitations in dealing with modern cyber threats. Backdoor Definition
Limitations  A Backdoor is a hidden method of bypassing normal authentication to gain unauthorized
 Script Kiddies are inexperienced hackers who use pre-written hacking tools and scripts created
 Rapid technological changes make some provisions outdated. access to a computer system. by others to attack computer systems.
 Limited coverage of data privacy and personal data protection. Working  They usually have limited technical knowledge.
 Difficulty in handling cross-border cybercrimes due to jurisdiction issues. Trojan Horse Characteristics
 Challenges in enforcement because cybercriminals often remain anonymous.  Disguises itself as useful software or a file.
 Depend on readily available hacking software.
 Lack of awareness among users regarding cyber laws and rights.  Tricks users into downloading or installing it.
 Lack deep understanding of cybersecurity.
Impact  Once activated, it can steal data, damage files, or install other malware.
 Often attack systems for fun, curiosity, or recognition.
 Makes investigation and prosecution of cybercrimes difficult. Backdoor Role in Cybercrime
 May not adequately address emerging threats such as AI-based attacks and advanced cyber  Often installed by malware such as a Trojan.
 Launch DoS/DDoS attacks using automated tools.
fraud.  Creates a secret entry point into the system.
 Deface websites and disrupt online services.
 Allows attackers to remotely access and control the system without the user's knowledge.
 Spread malware or viruses using downloaded scripts.
Examples  Attempt unauthorized access to systems and networks.
 A fake software update containing malicious code (Trojan).
 A hidden program that lets hackers log into a system without a password (Backdoor).
SQL INJECTION (SQLI) BLUETOOTH-RELATED SECURITY THREATS
Definition Introduction ROLE AND IMPORTANCE OF DIGITAL SIGNATURES UNDER THE IT ACT
 SQL Injection (SQLi) is a cyber attack in which an attacker inserts malicious SQL commands  Bluetooth is a wireless technology used for communication between devices over short Definition
into an application's input fields to manipulate the database. distances.  A Digital Signature is an electronic signature used to verify the identity of the sender and the
How It Works  If not properly secured, it can be exploited by attackers. authenticity of electronic documents.
 The attacker enters malicious SQL code in forms, login pages, or URLs. Major Security Threats Importance
 The application executes the injected SQL query. 1. Bluejacking  Provides legal validity to electronic records.
 This allows unauthorized access to the database.  Sending unsolicited messages to nearby Bluetooth-enabled devices.  Ensures authenticity and integrity of documents.
Consequences  Usually causes annoyance but may be used for phishing.  Supports secure online transactions.
 Data Theft – Sensitive information such as usernames, passwords, and bank details may be 2. Bluesnarfing  Helps prevent fraud and forgery.
stolen.  Unauthorized access to a device to steal contacts, messages, or other data. Conclusion
 Data Modification – Attackers can alter or delete database records. 3. Bluebugging  Digital signatures make electronic transactions secure, reliable, and legally recognized under
 Unauthorized Access – Attackers may bypass login authentication.  Attackers gain control of a device through Bluetooth vulnerabilities. the IT Act
EMAIL SPOOFING  They may make calls, send messages, or access data. CERTIFYING AUTHORITY (CA)
Definition 4. Malware Transmission Definition
 Email spoofing is a cyber attack in which the sender's email address is forged to make the  Malware can spread between devices through insecure Bluetooth connections.  A Certifying Authority (CA) is a trusted organization authorized to issue Digital Signature
message appear as if it came from a trusted person or organization. ROLE OF PROXY SERVERS IN CYBERCRIME Certificates (DSCs).
How It Works Definition  Under the Information Technology Act, 2000, it verifies the identity of individuals or
 The attacker changes the "From" address in an email.  A Proxy Server is an intermediary server that acts between a user's device and the internet. organizations before issuing certificates.
 The email appears to come from a legitimate source.  It hides the user's real IP address by forwarding requests on their behalf. Functions
 The recipient is tricked into opening links, downloading attachments, or sharing sensitive Role in Cybercrime  Issues Digital Signature Certificates.
information.  Hides Identity: Cybercriminals use proxy servers to conceal their real location and identity.  Verifies the identity of applicants.
Examples  Bypasses Restrictions: Helps attackers access blocked websites or restricted networks.  Ensures secure electronic transactions.
 An email appearing to be from a bank asking the user to provide account details.  Avoids Detection: Makes it difficult for investigators to trace the source of an attack. ROLE OF CERTIFYING AUTHORITY (CA) IN ISSUING DIGITAL CERTIFICATES
 A fake email from a company manager instructing an employee to transfer money.  Supports Illegal Activities: Can be used in hacking, phishing, spamming, and other Definition
 An email pretending to be from a popular online service requesting a password reset. cybercrimes.  A Certifying Authority (CA) is a trusted organization that issues Digital Signature Certificates
Example (DSCs).
BUFFER OVERFLOW ATTACK  A hacker uses a proxy server to launch an attack on a website, making the attack appear to Role of CA
Definition originate from the proxy server instead of their own device.  Verifies the identity of the applicant.
 A Buffer Overflow Attack occurs when a program receives more data than its allocated PHISHING AND DIFFERENT PHISHING METHODS  Issues digital certificates after successful verification.
memory buffer can hold. Definition  Links the user's identity with their public key.
 The extra data overwrites adjacent memory locations, causing the program to crash or execute  Phishing is a cyber attack in which attackers impersonate a trusted person or organization to  Maintains records of issued certificates.
malicious code. trick users into revealing sensitive information such as passwords, bank details, or OTPs.  Ensures authenticity and security of electronic transactions.
How It Works Different Phishing Methods CYBER FORGERY AND TRADITIONAL FORGERY
 The attacker sends excessive input to a program. 1. Email Phishing Definition of Cyber Forgery
 The buffer exceeds its storage capacity.  Fake emails are sent pretending to be from banks, companies, or government agencies.  Cyber Forgery is the creation, alteration, or use of electronic documents, digital signatures, or
 Memory is overwritten, allowing unauthorized actions or system crashes.  Example: An email asking you to verify your bank account details. online records with the intent to deceive or commit fraud.
Example 2. Spear Phishing Cyber Forgery Traditional Forgery
 A login program allocates 20 characters for a username.  A targeted phishing attack aimed at a specific individual or organization. Involves electronic or digital documents. Involves physical documents or signatures.
 If an attacker enters 100 characters, the extra data may overwrite memory and execute  Example: An employee receives a fake email appearing to come from their manager.
malicious code. 3. Smishing Done using computers and the internet. Done manually using paper and ink.
 This can give the attacker unauthorized access to the system.  Phishing conducted through SMS or text messages. Can be carried out remotely from anywhere. Usually requires physical access to documents.
Consequences  Example: A message claiming that you have won a prize and asking you to click a link. Examples: Fake digital certificates, altered Examples: Forged cheques, fake signatures on
 System crashes or application failures. 4. Vishing electronic records. documents.
 Unauthorized access to the system. Execution of malicious code. Data theft or corruption.  Phishing carried out through phone calls.
ONLINE IDENTITY THEFT METHODS  Example: A caller pretending to be a bank representative asking for OTPs. PASSWORD CHECKING AND RANDOM CHECKING
Definition 5. Clone Phishing Password Checking
 Online Identity Theft is the stealing and misuse of a person's personal information without permission.  A legitimate email is copied and modified with malicious links or attachments.  Verifies a user's identity by matching the entered password with the stored password.
Methods  Example: A fake version of a previous genuine company email.  Prevents unauthorized access.
 Phishing: Fake emails or websites used to steal login credentials.
 Email Spoofing: Forged emails that appear to come from trusted sources. Random Checking
 Malware/Spyware: Software that secretly collects personal information.  Randomly checks user activities or system records.
 Social Engineering: Tricking users into revealing sensitive data.  Helps detect security violations and suspicious activities.

You might also like