e-Commerce&CyberSecurity TYBCA
Unit-1
Unit 1: Introduction to Electronic Commerce
1.1 Concepts of e-Commerce
1.2 Aims of e-Commerce
1.3 e-Commerce Framework
1.4 e-Commerce Consumer Applications
1.5 e-Commerce Organizational Applications
1.6 Introduction to m-Commerce
1.1 Concepts of e-commerce
E-commerce, short for electronic commerce, refers to the buying and
selling of goods or services over the internet. This can include a wide range of
activities, from purchasing physical products from an online retailer to booking
travel arrangements, buying digital products such as music or e-books, and
using online marketplaces to buy and sell goods and services.
E-commerce has become increasingly popular in recent years due to the
convenience and accessibility it offers to both consumers and businesses. For
consumers, e-commerce eliminates the need to physically travel to a store and
allows for easy price comparisons and product reviews. For businesses, e-
commerce provides a low-cost way to reach a global audience and gather
valuable data on customer behavior and preferences.
E-commerce can take place on various platforms and channels, including:
Online market places like Amazon and Flipkart
Businesses web sites and mobile apps
Social media platforms like Instagram, Facebook and TikTok
Online classifieds like Craigslist and Gumtree
Subscription-based services like Netflix and Spotify
There are many different types of e-commerce, including business-to-consumer
(B2C), consumer-to-consumer (C2C), business-to-business (B2B), and mobile
commerce (M- commerce).
e-Commerce&CyberSecurity TYBCA
1.2 Aims of e-Commerce
The aims of e-commerce can vary depending on the type of business and its
target market, but some common goals include:
Increasing sales and revenue: E-commerce allows businesses to reach a
global audience, which can lead to increased sales and revenue.
Improving customer service: E-commerce allows businesses to provide
customers with a convenient and personalized shopping experience,
which can improve customer satisfaction and loyalty.
Expanding market reach: E-commerce allows businesses to expand
beyond their local market and sell to customers all over the world.
Lowering costs: E-commerce can lower overhead costs associated with
traditional brick-and-mortar stores, such as rent, utilities, and staffing.
Gainingcustomerinsights:E-
commerceallowsbusinessestocollectdataoncustomer behavior and
preferences, which can be used to improve products and services and
target marketing efforts.
Improving inventory management: E-commerce allows businesses to
have a better track of their inventory, this way they can reorder when
needed and avoid stockouts.
Automation:E-commerce allows businesses to automate many
process,such as order processing, invoicing, and shipping, which can save
time and reduce errors.
Building a brand: E-commerce allows businesses to create a strong
online presence and build a brand through online marketing and social
media.
Increasing customer engagement: E-commerce allows businesses to
engage with customers through personalized communications, social
media, and other digital channels.
Creating new revenue streams: E-commerce allows businesses to
explore new business models, such as subscription-based services and
digital products, which can create new revenue streams.
e-Commerce&CyberSecurity TYBCA
Benefits of E-commerce:
E-commerce offers a wide range of benefits for both consumers and
businesses, including:
Increased reach: E-commerce allows business store to global
audience, which can lead to increased sales and revenue.
Convenience: E-commerce allows customers to shop from the comfort
of their own homes, without the need to leave their house or wait in
line.
24/7 availability: E-commerce websites are open 24/7, allowing
customers to shop at any time.
Lower costs: E-commerce businesses do not have the same costs
associated with traditional brick-and-mortar stores, such as rent,
utilities, and staffing.
Personalization and targeting: E-commerce allows businesses to
collect data on customer behavior and preferences, which can be used
to personalize the shopping experience and target marketing efforts.
Increased competition: E-commerce creates a level playing field for
small and large businesses, as customers can easily compare prices and
products from different sellers.
Better inventory management: E-commerce allows businesses to
have a better track of their inventory, this way they can reorder when
needed and avoid stock outs.
Automation:E-commerce allow sbusinesses to automate many
process,such as order processing, invoicing, and shipping, which can
save time and reduce errors.
Globalization:E-commerce allows businesses to expand beyond their
local market and sell to customers all over the world
e-Commerce&CyberSecurity TYBCA
Easy Comparison and research: E-commerce allows customers to
easily compare products and prices from different vendors, as well as
read product reviews and research products before making a purchase.
Limitations of E-commerce:
There are several limitations of ecommerce, including:
Limited physical interaction: Online shopping does not allow
customers to physically examine or test products before purchasing,
which can lead to dissatisfaction with the product or difficulty in
determining the right fit.
Shipping and handling issues: Ecommerce relies on shipping and
handling to deliver products to customers, which can result in delays,
damage, or lost packages.
Lack of personal interaction: Shopping online can lack the personal
interaction and assistance that customers may receive when shopping
in-store.
Limited payment options: Some ecommerce platforms may not
accept certain forms of payment, such as cash or checks, which can
limit the ability of some customers to make purchases.
Cyber security concerns: Ecommerce is vulnerable to cyber attacks
and fraud, which can lead to financial loss and damage to customer
trust.
Shipping Cost: Shipping cost may be higher for some remote
locations and for heavy item.
Return Policy and Process: Some e-commerce sites have strict return
policies, which can make it difficult for customers to return items that
do not meet their expectations.
e-Commerce&CyberSecurity TYBCA
1.3 e-Commerce Framework
An architectural framework of e-commerce is a structured model that defines
both technological and functional aspects of an online business. It includes
user interactions with applications, databases, and security layers. A robust
architectural framework improves efficiency and customer satisfaction.
A well-structured framework ensures that different technological components
work cohesively, reducing the risk of system failures. Businesses of any scale
benefit from having an established framework because it helps manage
increased traffic volumes, expand product offerings, and integrate new
features smoothly. A comprehensive structure aligns business objectives with
technological innovations, ensuring sustainability in the competitive e-
commerce market.
Core Components of an E-Commerce Framework
1. Presentation Layer
The presentation layer comprises user interfaces such as websites and mobile
applications that allow customers to browse products and complete
transactions. This component ensures an enjoyable shopping experience.
A well-designed presentation layer prioritizes aesthetics, usability, and
accessibility. This includes responsive web design, mobile optimization, and
interactive elements that promote user engagement. An intuitive user
interface simplifies product searches, displays information clearly, and
facilitates seamless purchasing. Personalization features like AI-driven
recommendations enhance customer satisfaction and drive business growth.
2. Business Logic Layer
This layer oversees the core functionality of an e-commerce platform,
including:
Product catalog management
e-Commerce&CyberSecurity TYBCA
Order processing systems
Payment gateway integrations
Customer Relationship Management (CRM)
A robust business logic layer ensures efficient execution of business rules,
from product searches to final transactions. It speeds up order fulfillment,
optimizes pricing strategies, and enhances overall shopping experiences.
Businesses should ensure this layer accommodates new features, seasonal
shifts, and changing customer preferences.
3. Data Management Layer
Data management is crucial in any e-commerce architecture. This layer
includes database storage for:
Product details
User information
Transaction histories
Content management systems (CMS) enhance decision-making by providing
insights into customer behavior, sales trends, and inventory levels. Effective
data organization allows businesses to optimize marketing strategies, improve
customer engagement, and increase operational efficiencies. Big data
analytics provides a competitive advantage by enabling targeted promotions,
demand forecasting, and personalized user experiences.
4. Application Layer
The application layer integrates third-party services such as:
Payment gateways (e.g., PayPal, Stripe)
Inventory management systems
Logistics providers
This layer ensures seamless transactions and enhances platform functionality.
Third-party applications boost automation, reduce manual errors, and
improve efficiency. Businesses should invest in API connectivity to ensure
e-Commerce&CyberSecurity TYBCA
all services work harmoniously. Additionally, this layer should support
emerging technologies like AI chatbots, blockchain transactions, and
augmented reality shopping experiences.
5. Security Layer
Security is essential for protecting sensitive information in e-commerce
platforms. This layer includes:
Encryption protocols
SSL certificates
Fraud detection mechanisms
User authentication processes
A secure e-commerce platform builds customer trust and safeguards against
cyber threats like data breaches, phishing attacks, and payment fraud.
Businesses should implement multi-layered security measures, including
two-factor authentication, end-to-end encryption, and real-time threat
monitoring. Compliance with regulations like GDPR and PCI DSS ensures
responsible data handling and reduces legal risks.
6. Network Infrastructure
E-commerce requires a stable network infrastructure comprising:
Cloud computing services
Content Delivery Networks (CDNs)
Hosting solutions
An effective network infrastructure enhances website speed, uptime, and
content delivery. Cloud solutions enable businesses to scale dynamically in
response to traffic spikes. CDNs improve performance by distributing content
across global servers, ensuring fast load times. Investing in high-performance
network infrastructure reduces downtime and ensures seamless connectivity
between e-commerce components.
e-Commerce&CyberSecurity TYBCA
1.4 E-Commerce Consumer Applications
e-commerce consumer applications refer to digital platforms—primarily mobile
apps and web portals—that facilitate the direct purchase of goods and services by
individual end-users. These applications are the primary interface for Business-to-
Consumer (B2C) and Consumer-to-Consumer (C2C) transactions, accounting
for an estimated 60% of all online sales.
Core Types of Consumer E-commerce Applications
Retail and Online Shopping: The most prevalent form, where consumers
browse digital storefronts to buy physical or digital goods. Examples
include Amazon, walmart and specialized fashion apps
like Nykaa or Zalando.
e-Commerce&CyberSecurity TYBCA
Mobile Commerce (m-Commerce): Apps specifically optimized for smart
phones and tablets. They leverage device-specific features like push
notifications for promotions and GPS for real-time delivery tracking.
Consumer-to-Consumer (C2C) Marketplaces: Platforms that enable
individuals to sell to one another, often featuring auction or bidding systems.
Key examples include eBay, Etsy, and Facebook Marketplace.
Digital Service Platforms: Applications for non-physical purchases, such
as Netflix (streaming), Airbnb (booking), and Zomato (food delivery).
Personal Finance and Internet Banking: Apps that allow consumers to
pay bills, transfer funds, manage investments, and check account balances
without visiting a physical bank.
Key Features for Consumers
Personalization: Using AI to provide tailored product recommendations based on
browsing history and preferences.
Seamless Checkout: Features like "one-click purchasing" and integrated digital
wallets (Apple Pay, Google Pay) to reduce friction during transactions.
Interactive Content: AR and VR integrations that allow "virtual try-ons," such as
visualizing furniture in a room (e.g., IKEA app).
Customer Support: Real-time assistance through AI-driven chatbots and live
messaging systems.
Order Transparency: Real-time inventory insights and step-by-step tracking of
shipments.
e-Commerce&CyberSecurity TYBCA
1.5 E-Commerce Organizational Applications
Supply Chain Management: Automated stock monitoring and timely restocking
avoid over stock/stockouts.
• Order Fulfillment and Logistics: Systems automate invoicing, shipment
tracking, and delivery updates.
• Customer Relationship Management (CRM): Platforms like Salesforce
analyze buyer data to run loyalty programs and personalized campaigns.
e-Commerce&CyberSecurity TYBCA
• Payroll & Billing: Automating employee payments and vendor invoices.
• Workflow Automation: Tools such as Slack and JIRA improve team
communication and task management even across locations.
1.6 Introduction to m-Commerce
• Definition: Mobile commerce involves conducting e-commerce activities through
mobile devices like smartphones and tablets.
• Examples:
o Mobile shopping apps (Amazon, Myntra) optimized for small screens with push
notifications for deals.
e-Commerce&CyberSecurity TYBCA
o Mobile wallets and payments (Apple Pay, Google Pay) enable quick, secure
checkouts.
o On-demand services such as Uber or Zomato rely on m-commerce for bookings,
payments, and order tracking.
• Advantages: Convenience, location-based services, instant notifications, and
biometric security.
• Example: A customer orders food via Zomato app, pays using UPI, and tracks
delivery live on their phone.
Unit 2: Network Infrastructure of e-Com , Payment and Security
2.1. Concepts of Information Way
2.2. Components of I-Way
2.2.1. Network Access Equipment
2.2.2. Local on-ramps
2.2.3. Global Information Distribution Network
2.3. Transaction Models
2.4 e-Commerce Payments and Security Issues
2.4.1. e-Commerce Payment Systems
2.4.2. Debit Card Based, Credit Card Based ,. Risks & EPS
2.4.3. e-Cash, e-Cheque, e-wallet
2.5. Security on Web, SSL
2.1. Concepts of Information Way
The Information Way refers to the systematic process through which information is
generated, collected, processed, stored, transmitted, and utilized. It explains how
raw data is transformed into meaningful information and how it flows from one point
to another to support communication, learning, planning, and decision-making.
1. Data
Data are raw facts, figures, symbols, or observations.
Data by itself has no meaning.
Examples: numbers, dates, names, marks, temperature readings.
Data can be qualitative (descriptive) or quantitative (numerical).
2. Information
Information is processed data that has meaning and value.
It helps in understanding situations and making decisions.
Good information should be accurate, relevant, timely, complete, and
reliable.
Example: “Average marks of students is 75%” (processed from raw marks).
3. Information Processing
Information processing involves converting data into useful information. It includes:
Collection – Gathering data from various sources.
Organization – Arranging data in a structured form.
Analysis – Examining data to identify patterns or trends.
Interpretation – Giving meaning to analyzed data.
Presentation – Displaying information using tables, charts, or reports.
4. Information Storage
Storage means saving information for future use.
Can be manual (files, registers, books) or digital (hard disks, cloud storage,
databases).
Proper storage ensures easy retrieval, security, and long-term preservation
of information.
5. Information Transmission
Transmission refers to transferring information from one person or system to
another.
Can occur through:
o Printed documents
o Telephone and mobile communication
o Email and internet
o Social media and networks
Effective transmission requires clear channels, correct format, and minimal
distortion.
6. Information Use
Information is used for:
o Decision-making
o Planning and forecasting
o Learning and education
o Problem-solving
o Monitoring and control
The value of information depends on how well it is applied.
7. Feedback
Feedback is the response received after information is used.
It helps in:
o Improving accuracy
o Correcting errors
o Enhancing future information processes
Feedback ensures continuous improvement in the information flow.
8. Importance of Information Way
Improves efficiency and productivity
Supports informed decision-making
Enhances communication
Reduces uncertainty
Helps organizations and individuals achieve goals
2.2 Components of I-Way
I-Way (Information Way) is the communication infrastructure used for creation,
access, transmission and distribution of information.
Main Components of I-Way:
1. Network Access Equipment
2. Local On-Ramps
3. Global Information Distribution Network
2.2.1 Network Access Equipment
➡️ Devices that allow users to connect to the I-Way
1. Routers: These devices are responsible for directing data traffic between different
[Link] and
can also be used to connect multiple networks together.
A router is a networking device that forwards data packets between computer
networks. It is connected to two or more networks and determines the best path for a
data packet to take based on its destination IP address.
Routers use routing tables and protocols to determine the most efficient path for data
packets to travel. When a data packet is sent from a device on network to a device on
another network, the router receives the packet and consults its routing table to
determine the best path to forward the packet.
The router then uses network protocols such as IP (Internet Protocol) and ICMP
(Internet Control Message Protocol) to forward the packet to the next hop on its way
to the final destination.
Routers also have the ability to perform Network Address Translation (NAT)to allow
multiple devices on a private network to share a single public IP address. They also
provide security by using firewall rules to control access to and from the network.
Routers also have Quality of Service (QoS) features that allows to prioritize certain
types of traffic like video conferencing over others like file downloads, this ensures
that critical applications get the bandwidth they need to function properly.
2. Switches: These devices are used to connect multiple devices within a network.
They forward data packets to the appropriate device based on their MAC address.
A switch is a networking device that connects devices on a network and forwards
data between them. It operates at the data link layer (layer 2) of the OSI model and
uses MAC addresses to forward data to the appropriate device. Switches are
commonly used to connect devices in a local area network (LAN) and can also be
used to connect LANs to other networks, such as a wide area network(WAN)or the
Internet.
3. Access Points: These devices are used to provide wireless network access to
mobile devices such as laptops and smartphones. They use wireless protocols such
asWi-Fi and Bluetooth to transmit data.
4. Firewalls: These devices are used to enforce security policies and protect a
network from unauthorized access. They can be hardware or software-based, and
use rules and filters to block or allow specific types of network traffic.
5. VPN concentrators: These devices are used to create and manage virtual private
networks (VPNs), which allow remote users to securely access a network.
6. Load balancers: These devices are used to distribute network traffic across
multiple servers, in order to ensure that no single server is overwhelmed.
7. Proxies: These devices are used to filter and redirect network traffic, in order to
improve network performance and security.
Meaning:
Hardware used by users to access information networks.
Examples:
Computer, Laptop
Mobile phone, Tablet
Modem
Router
Switch
Network Interface Card (NIC)
Functions:
Connects user to network
Sends and receives data
Converts signals for transmission
Importance:
Entry point to I-Way
Determines speed and quality of access
2.2.2 Local On-Ramps
➡️ Local connection points between users and global network
1. Telecom based infrastructure
Telecom based infrastructure refers to the physical and technological components that
makeup a telecommunications network. This helps in transferring the information
such as text, audio, video and all other information from the one place to another
place.
2. Cable TV based infrastructure
Cable TV based infrastructure refers to the physical and technological components
that makeupacabletelevisionnetworkthishelpsontransferringthepopularchannelsdata as
broadcasting to home.
3. Wireless infrastructure
Wireless infrastructure refers to the physical and technological components that make
up a wireless network, which is used to transfer the data using wireless technologies.
4. Commercial on-line infrastructure
Commercial online infrastructure refers to the physical and technological components
that make up an e-commerce platform, which includes web servers, database servers,
content delivery servers, payment gateway, customer service and support, logistics
and fulfillment.
Meaning:
Access networks that connect homes, offices, schools to I-Way.
Examples:
Internet Service Providers (ISP)
Local Area Network (LAN)
Cable TV network
Telephone network
Wi-Fi hotspots
Technologies Used:
Dial-up
Broadband
DSL
Fiber-optic
Wireless / 4G / 5G
Functions:
Provides first level connectivity
Transfers local data traffic
Importance:
Acts as a bridge to global network
Affects speed and reliability
2.2.3 Global Information Distribution Network
➡️ Worldwide backbone of communication
1. Data centers: Large facilities that house servers, storage devices, and networking equipment
that store and process data.
2. Transmission networks: The physical and wireless infrastructure that connects data centers
and other devices, including fiber-optic cables, satellite links, and cellular networks.
3. Content delivery networks(CDNs):Distributed systems that help to deliver web content and
media to users more efficiently by replicating and caching content on servers located closer to
users.
4. Network service providers (NSPs): Companies that own and operate the infrastructure and
networks that make up the GIDN, such as internet service providers(ISPs) and cloud
providers.
5. Applications and services: Platforms and tools that allow users to access and share
information, such as social media, search engines, and e-commerce sites.
All these different components work together to create a global network that allows for the
rapid and efficient distribution of information to users all around the world.
Meaning:
High-speed global network that distributes information across countries.
Components:
Internet backbone
Fiber-optic cables
Satellites
International gateways
Data centers
Services Supported:
Email
World Wide Web
Video conferencing
E-commerce
Cloud services
Online streaming
Importance:
Enables global communication
Supports digital economy
Fast and secure data transfer
2.3 Transaction Models
A Transaction Model describes the way in which business transactions are
carried out electronically between different participants using the Information Way
(I-Way).
It explains who is involved in the transaction and how information, money, and
services are exchanged.
Transaction models are mainly used in e-commerce and e-business.
Meaning of Transaction
A transaction is an exchange of:
Goods
Services
Information
Money
between two or more parties.
Need for Transaction Models
To understand online business relationships
To define roles of buyers and sellers
To ensure smooth and secure electronic transactions
To support different types of e-commerce activities
Types of Transaction Models
1. Business to Business (B2B)
Business-to-business (B2B) e-commerce refers to the buying and selling of goods or services
between companies over the internet. This can include a wide range of activities, from
purchasing raw materials and supplies to selling finished products to other businesses.B2B e-
commerce is often characterized by high-value transactions, complex products or services, and
long-term relationships between buyers and sellers.
B2B e-commerce platforms, such as Alibaba and ThomasNet, have become increasingly
popular in recent years as a way for businesses to efficiently connect with suppliers, customers,
and partners.
Meaning:
Transactions between two or more businesses.
Examples:
Manufacturer selling raw materials to a wholesaler
Company purchasing software from another company
Features:
Large transaction value
Long-term relationships
Automated systems (EDI)
Bulk orders
Advantages:
Reduced cost
Faster transactions
Better supply chain management
2. Business to Consumer (B2C)
Business-to-Consumer(B2C)e-commerce refers to the buying and selling of goods and
services directly between a business and consumers over the internet. This includes online
retail websites, such as Amazon and Walmart, as well as digital marketplaces, such as Etsy
and Uber. B2C e-commerce allows businesses to reach a global customer base, offer a wider
range of products and services, and provide a convenient and efficient shopping experience for
consumers. Many businesses also use B2C e-commerce as away to generate additional
revenue streams and increase brand awareness.
Meaning:
Transactions between a business and end consumer.
Examples:
Online shopping websites
Food delivery apps
Online ticket booking
Features:
High number of customers
Small transaction value
Easy payment methods
User-friendly interface
Advantages:
Convenience
24×7 availability
Wide choice of products
3. Consumer to Consumer (C2C)
Consumer-to-Consumer(C2C)e-commerce refers to the buying and selling of goods and
services directly between consumers over the internet. This can include online marketplaces,
such as eBay and Craigslist, as well as social media platforms and mobile apps that enable
individuals to sell goods and servicestootherindividuals.C2Ce-commerce provides a platform
for individuals to buy and sell goods and services without the need for a traditional business
intermediary. This can enable econsumers to find unique or hard-to-find items and also allows
them to sell their own goods and services. C2C e-commerce can also provide a source of
additional income for individuals who are looking to make money from their hobbies or
interests.
Meaning:
Transactions between individual consumers.
Examples:
Online resale platforms
Auction websites
Peer-to-peer marketplaces
Features:
Platform acts as intermediary
Direct interaction between users
Negotiated pricing
Advantages:
Low cost
Easy to sell used items
Wider reach
4. Consumer to Business (C2B)
Consumer-to-Business (C2B) e-commerce refers to a type of e-commerce where consumers
offer goods and services to businesses, instead of the traditional business-to-consumer (B2C)
model where businesses offer goods and services to consumers. Examples of C2B e-
commerce include online platforms where individuals can sell their products,such as stock
photos, videos, and designs to business and web sites for freelance work where individuals can
offer their services to businesses.C2Be-commerce can be beneficial for businesses, as they can
access a wider pool of talent and resources while also reducing costs. Additionally, it can also
be beneficial to individuals, as it allows them to leverage their skills and resources to earn
income
Meaning:
Individuals offer products or services to businesses.
Examples:
Freelancers providing services
Influencers promoting brands
Customers giving paid reviews
Features:
Customer-driven pricing
Flexible contracts
Skill-based transactions
Advantages:
Opportunity for individuals
Cost-effective for businesses
5. Business to Government (B2G)
Business-to-Government (B2G) e-commerce refers to the buying and selling of goods and
services between businesses and government entities over the internet. This can include
procurement of goods and services such as construction, technology, and consulting services.
B2G e-commerce can help government entities to reduce costs, increase efficiency and
transparency in procurement process, and also providing businesses with easy access to
government procurement opportunities. Many governments around the world have implemente
Electronic procurement systems to streamline the procurement process for goods and services. These
systems allow businesses to submit bids, invoices, and other documents electronically, making it easier
for them to do business with government agencies.
Meaning:
Transactions between business organizations and government.
Examples:
Online tenders
Tax payments
Government procurement portals
Features:
High security
Legal compliance
Large-scale transactions
Advantages:
Transparency
Reduced paperwork
Faster processing
6. Government to Citizen (G2C)
Meaning:
Government provides services directly to citizens.
Examples:
Online bill payments
E-governance services
Online certificates
Features:
Public service oriented
Easy access
Reduced corruption
Advantages:
Time-saving
Improved service delivery
Key Elements of Transaction Models
Participants (Buyer, Seller, Intermediary)
Information flow
Payment mechanism
Security and authentication
Delivery of goods/services
Advantages of Electronic Transaction Models
Faster transactions
Global reach
Lower operational cost
Improved efficiency
Better customer satisfaction
2.4 e-Commerce Payments and Security Issues
e-Commerce payment systems enable customers to pay electronically for goods
and services purchased online. Along with convenience, these systems must ensure
security, privacy, and trust to protect users from fraud and misuse.
2.4.1 e-Commerce Payment Systems
Meaning
An e-Commerce Payment System (EPS) is a method that allows electronic
transfer of money between buyers and sellers over the internet.
Objectives
Provide fast and convenient payment
Ensure security and confidentiality
Reduce cash handling
Support global transactions
Types of e-Commerce Payment Systems
Card-based payments
Internet banking
Mobile payments
Electronic cash
Electronic cheque
Electronic wallet
2.4.2 Debit Card Based, Credit Card Based Payments, Risks & EPS
A. Debit Card Based Payment System
Debit card-based payment systems allow users to pay for goods and services directly
from their bank accounts using cards, mobile wallets (Apple/Google Pay), or contactless
methods. Key components include EMV chips, magnetic stripes, and PIN/OTP
security for transactions at POS terminals, online, or ATMs. Major networks include
Visa, Mastercard, and RuPay.
Key Features and Types
Transaction Types: Includes EFTPOS (PIN-based online debit), offline debit
(signature-based), and Electronic Purse Card Systems.
Funding Source: Funds are deducted immediately from the cardholder’s bank account.
Security: Uses PINs, OTPs, and EMV chip technology to prevent unauthorized access.
Contactless Payments: Near Field Communication (NFC) technology allows "tap and
pay" for smaller, faster transactions.
Virtual Cards: Available for secure online transactions without a physical card.
Payment Processing Flow
1. Initiation: Card is swiped, inserted, tapped, or used online.
2. Authorization: The terminal sends data to the issuing bank to check for sufficient funds
and fraud checks.
3. Settlement: Funds are transferred from the customer's account to the merchant.
Advantages and Limitations
Pros: Wide global acceptance, eliminates the need for large amounts of cash, and
offers immediate, secure transactions.
Cons: Limited by the available balance in the user's account and potential for fraudulent
activity if cards are lost or stolen.
Major Debit Card Networks
International: Visa, Mastercard, American Express, Discover, JCB, and Diners Club.
Regional: RuPay (India), STAR, and Pulse
Meaning:
Payment is made directly from the customer’s bank account.
Amount is deducted immediately.
Process:
1. Customer enters debit card details
2. Bank verifies PIN/OTP
3. Amount is deducted
4. Payment is confirmed
Advantages:
Immediate payment
Lower risk of overspending
Widely accepted
Limitations:
Requires sufficient balance
Risk of card misuse if details are stolen
B. Credit Card Based Payment System
A credit card payment system is a multi-step process connecting customers, merchants, banks,
and networks (like Visa/Mastercard) to authorize and settle transactions, involving data capture
(swipe/tap/enter), secure transmission via a payment gateway/processor, issuing bank approval
(funds/fraud check), and eventual fund transfer (settlement) from issuer to merchant's bank, all
secured by encryption and standards like PCI DSS.
Key Players & Steps:
1. Initiation:
Customer presents card (swipe, tap, online entry) to merchant's system
(POS/Gateway).
2. Authorization:
a. Merchant's processor sends data to the Card Network (Visa, Mastercard).
b. Network routes request to the Issuing Bank (customer's bank).
c. Issuing bank checks card validity, funds, and fraud, then sends Approve/Decline back.
3. Clearing & Settlement:
d. Approved transactions are batched daily.
e. Funds move from the issuing bank, through the network, to the acquiring bank
(merchant's bank).
f. Merchant receives funds (minus fees) within days.
Core Components:
Cardholder: The person using the card.
Merchant: The business accepting the payment.
Payment Gateway/Processor: Securely handles data, acts as intermediary (e.g.,
Stripe, Square).
Card Network: Connects banks (Visa, Mastercard, Amex).
Issuing Bank: Customer's bank (e.g., Chase, Citi).
Acquiring Bank: Merchant's bank.
Security & Technology:
Encryption & Tokenization: Protects card data during transmission.
PCI DSS Compliance: Ensures secure handling of cardholder data.
NFC (Contactless): Uses Near Field Communication for tap payments (RFID).
Meaning:
Customer borrows money from the bank to make payment.
Payment is settled later.
Process:
1. Customer enters credit card details
2. Card issuer verifies transaction
3. Merchant receives payment
4. Customer pays bill later
Advantages:
Buy now, pay later
Easy refunds
International acceptance
Limitations:
Interest charges
Risk of overspending
Higher fraud risk
C. Risks in e-Commerce Payment Systems
Major Risks:
Identity theft
Credit/debit card fraud
Phishing attacks
Hacking and malware
Unauthorized access
Data leakage
D. Security in EPS (Electronic Payment Systems)
Security Measures:
Encryption
Secure Socket Layer (SSL)
Two-factor authentication (OTP)
Digital signatures
Firewalls
Secure payment gateways
Security Goals:
Confidentiality
Integrity
Authentication
Non-repudiation
2.4.3 e-Cash, e-Cheque, e-Wallet
A. e-Cash (Electronic Cash)
"E-cash" (electronic cash) is an umbrella term for various digital payment
systems designed to replicate the properties of physical currency, allowing for
secure, instant, and potentially anonymous transactions without physical money.
It exists in several forms, from traditional bank-operated systems to modern
crypto currencies.
While implementations vary, core e-cash systems generally involve:
1. Withdrawal: A user obtains e-cash from a bank or issuer, which is then stored in an
electronic or digital wallet (software on a computer, phone, or secure hardware device).
2. Payment: The user transfers the digital cash to a merchant or another individual, often
using cryptographic techniques to ensure security and prevent double-spending.
3. Deposit/Verification: The payee (merchant) then sends the e-cash to their bank for
verification and deposit into their account.
Key Features and Benefits
Convenience: E-cash allows for transactions online or through mobile devices, often
instantaneously and from anywhere in the world.
Security: It uses robust cryptographic techniques, such as digital signatures and
encryption, to prevent counterfeiting and fraud.
Privacy/Anonymity: A key goal of many e-cash designs is to offer transactional
anonymity similar to physical cash, protecting user privacy by making transactions
untraceable.
Accessibility: Some forms are designed to be accessible to those without traditional
bank accounts or reliable internet connectivity.
Meaning:
Digital form of money used for online transactions.
Features:
Similar to physical cash
Instant payments
Can be anonymous
Advantages:
Fast transactions
Low processing cost
Suitable for small payments
Limitations:
Risk of duplication
Limited acceptance
B. e-Cheque (Electronic Cheque)
An e-Cheque (electronic cheque) is a digital version of a paper cheque used to make
secure, paperless payments online. It functions like a traditional cheque but uses
electronic channels to transfer funds between bank accounts, typically through the
Automated Clearing House (ACH) network in the United States.
How E-Cheques Work
The process converts the information found on a paper cheque into a digital format that
is processed electronically.
1. Authorization: The payer provides authorization for the payment (usually via a secure
online form, a recorded phone call, or a signed agreement) and gives their bank
account and routing numbers to the payee.
2. Submission: The payee enters these details into a payment processing system and
submits the transaction to their bank.
3. Clearing: The payee's bank sends the request through the ACH network to the payer's
bank.
4. Verification and Fund Transfer: The payer's bank verifies the account details and
checks for sufficient funds. Once approved, the funds are debited from the payer's
account and credited to the payee's account.
5. Confirmation: Both parties receive electronic confirmation of the transaction. The entire
process generally takes between 3 to 5 business days for the funds to clear.
Key Features and Benefits
E-cheques offer several advantages over traditional paper cheques:
Speed: They are processed much faster than paper checks, which require physical
mailing and manual handling.
Security: Transactions are secure, using features like encryption, digital signatures,
and authentication through regulated networks to reduce the risk of theft or forgery
inherent in paper documents.
Cost-Effectiveness: E-cheques eliminate costs associated with paper, printing, and
postage. Processing fees for businesses are often significantly lower than those for
credit card transactions.
Convenience: Payments can be issued and deposited anytime from anywhere using
online banking portals or mobile apps, removing the need to visit a physical bank
branch.
Tracking: E-cheques can be easily tracked online, providing clear digital records and
simplified reconciliation processes for accounting.
Environmental Friendly: As a paperless solution, they reduce paper waste and the
environmental strain of transporting physical checks.
Limitations
Despite the benefits, there are a few drawbacks:
Processing Time: While faster than paper checks, e-cheques are not instantaneous
like wire transfers or credit card payments, as the ACH network processes transactions
in batches.
Insufficient Funds: E-cheques can still "bounce" if the payer has insufficient funds in
their account, similar to paper checks.
Acceptance: While gaining popularity, not all merchants or businesses universally
accept e-cheques as a payment method.
Meaning:
Digital version of a traditional cheque.
Features:
Uses digital signatures
Verified by banks
Suitable for high-value payments
Advantages:
Secure
Legal acceptance
Paperless transaction
Limitations:
Slower than cards
Requires bank approval
C. e-Wallet (Electronic Wallet)
An e-wallet (electronic wallet) is a software-based application or online service that
securely stores a user's payment information and credentials, enabling them to make
electronic transactions quickly and conveniently without the need for physical cash or
cards.
E-wallets can be accessed via computers, smartphones, and other connected devices,
and they are widely used for online shopping, in-store purchases (via contactless
payment), and peer-to-peer money transfers.
How E-Wallets Work
E-wallets streamline payments by securely storing a user's financial details (credit/debit
cards, bank account info) and automatically filling in the information during checkout.
Key technologies involved include:
Near-Field Communication (NFC): This technology enables contactless, in-store
payments by allowing two devices (e.g., your smartphone and a payment terminal) to
communicate wirelessly over a short distance.
QR Codes: Users can scan a Quick Response (QR) code with their phone camera to
initiate and complete payments, a popular method in many regions.
Tokenization & Encryption: To ensure security, sensitive card data is replaced with
unique, random codes (tokens) during a transaction. This means the actual card
number is never transmitted or stored by the merchant, greatly reducing the risk of
fraud.
Biometric Authentication: Many e-wallets use fingerprints, facial recognition, or a
secure PIN to verify the user's identity before authorizing a payment, adding an extra
layer of security.
Types of E-Wallets
E-wallets are often categorized based on their functionality and where they can be
used:
Closed Wallets: Issued by specific companies (merchants), funds can only be used to
make purchases within that single platform or ecosystem. Example: Amazon
Pay Balance (for Amazon orders only).
Semi-Closed Wallets: Can be used across a network of affiliated merchants and
service providers that have an agreement with the issuer, but generally do not allow
cash withdrawals. Examples: Paytm or PhonePe wallets in India.
Open Wallets: Offer the broadest range of functionality and are typically issued by
banks or regulated financial institutions. They allow for all transaction types, including
online/in-store payments, peer-to-peer transfers, and ATM cash withdrawals.
Examples: Google Pay, Apple Pay, and PayPal.
Cryptocurrency Wallets: Specialized wallets designed to store the public and private
keys needed to manage digital assets like Bitcoin or Ethereum.
Benefits
Convenience: Eliminates the need to carry a physical wallet with multiple cards and
cash.
Speed: Transactions are often instantaneous, requiring only a tap or a scan.
Enhanced Security: Robust security features like encryption, tokenization, and
biometrics protect financial data better than physical cards.
Financial Management: Many apps offer built-in tools for tracking expenses and
managing budgets.
Meaning:
Software application that stores payment information and digital money.
Examples:
Mobile wallets
Online wallets
Features:
Stores card details
Supports quick payments
Secure authentication
Advantages:
Easy to use
Fast checkout
Reduced need to enter card details
Limitations:
Internet dependent
Risk if mobile is lost or hacked
Comparison Table
| Payment Method | Speed | Security | Usage |
| Debit Card | Fast | High | Daily transactions |
| Credit Card | Fast | Medium | Online shopping |
| e-Cash | Very fast | Medium | Small payments |
| e-Cheque | Slow |Very High| Large payments |
| e-Wallet | Very fast | High | Mobile payments |
2.5 Security on Web, SSL
With the rapid growth of the internet and e-commerce, web security has become
extremely important. Web security ensures that data transmitted over the
internet is protected from unauthorized access, misuse, and attacks. One of the
most important technologies used for web security is SSL (Secure Sockets
Layer).
2.5.1 Security on Web
Meaning
Web security refers to the measures and technologies used to protect websites,
web applications, and online data from threats such as hacking, data theft, and
cyber-attacks.
Objectives of Web Security
Protect sensitive information (passwords, card details)
Ensure safe communication over the internet
Prevent unauthorized access
Maintain trust between users and websites
Common Web Security Threats
1. Hacking – Unauthorized access to systems
2. Phishing – Fake websites used to steal user data
3. Malware – Viruses, worms, spyware
4. Data interception – Stealing data during transmission
5. Identity theft – Misuse of personal information
Web Security Mechanisms
User authentication (username & password)
Encryption
Firewalls
Secure payment gateways
Digital certificates
Antivirus and anti-malware software
Security Requirements
Confidentiality – Data should be secret
Integrity – Data should not be altered
Authentication – Verify identity of users
Authorization – Grant proper access rights
Non-repudiation – Sender cannot deny transaction
2.5.2 SSL (Secure Sockets Layer)
Meaning
SSL (Secure Sockets Layer) is a security protocol that provides encrypted
communication between a web browser and a web server.
Websites using SSL start with:
https://
and display a padlock symbol in the browser.
The purpose of SSL is to ensure that all data passed between the web server and
browser remains private and integral.
• When a user connects to a website that uses SSL, the browser and the web server
establish an SSL connection using a process called an SSL Handshake. During the
SSL Handshake, the browser and web server exchange information to establish a
secure connection. This includes the browser providing the web server with a copy
of the SSL certificate, which the web server uses to verify the identity of the
website.
Once the SSL Handshake is completed, the browser and web server will use the
established SSL connection to encrypt all data that is exchanged between them.
This means that any sensitive information, such as login credentials or credit card
information, is encrypted before it is transmitted over the internet. This ensures
that the data can not be intercepted and read by anyone other than the intended
recipient.
SSL was succeeded by Transport Layer Security (TLS) which is an updated
version of SSL, but the two terms are often used interchangeably. SSL and TLS
are implemented in web browsers and servers to create a secure connection and
protect sensitive data in transit.
Websites that use SSL or TLS are identified by the prefix "https" in the URL, and
the padlock icon in the browser address bar. Websites that use SSL or TLS are
considered more secure and trustworthy than those that do not
Why SSL is Needed
Prevents data theft
Protects sensitive information
Builds customer trust
Ensures secure online transactions
How SSL Works (Simple Explanation)
1. Browser requests secure connection
2. Server sends SSL certificate
3. Browser verifies certificate
4. Encryption key is created
5. Secure data transmission begins
Components of SSL
Public key – Used for encryption
Private key – Used for decryption
Digital certificate – Verifies website identity
Certificate Authority (CA) – Trusted organization issuing certificates
Features of SSL
Data encryption
Authentication of server
Data integrity
Protection against man-in-the-middle attacks
Advantages of SSL
Secure data transmission
Protects passwords and card details
Improves website credibility
Required for e-commerce websites
Limitations of SSL
Does not protect against malware on user devices
Requires certificate management
Slight performance overhead
SSL vs Non-SSL Website
Feature SSL Website Non-SSL Website
URL https:// http://
Encryption Yes No
Data security High Low
Trust level High Low
Secure Socket Layer Protocol:
SSL Record Protocol
The SSL Record Protocol is a component of the Secure Sockets Layer (SSL)
protocol that is responsible for the fragmentation, compression, and encryption of
data exchanged between the client and server. The SSL Record Protocol works in
conjunction with the SSL Handshake Protocol and the SSL Change Cipher Spec
Protocol to establish a secure connection and exchange data.
The main components of the SSL Record Protocol include:
Record Layer: This is the layer that provides the core security services of the
SSL protocol, including data fragmentation, compression, and encryption.
Data Fragmentation: The Record Protocol fragment the application data into
manageable chunks before it is encrypted, this is done to avoid exceeding the
maximum transmission unit (MTU) of the underlying network.
Data Compression: The Record Protocol can also apply data compression to
the application data before it is encrypted, this can improve performance by
reducing the amount of data that needs to be transmitted.
Data Encryption: The SSL Record Protocol uses symmetric key encryption to
encrypt the application data. The encryption algorithm and key are agreed upon
during the SSL Handshake Protocol.
Data Integrity: The SSL Record Protocol uses a message authentication code
(MAC) to ensure that the data has not been tampered with during transmission.
Data format: The SSL Record Protocol defines a specific format for the data
that is sent and received. This format includes fields for the SSL version
number, the length of the data, and the data itself, as well as the MAC for data
integrity check.
Hand shake Protocol
The SSL Handshake Protocol is a component of the Secure Sockets Layer (SSL)
protocol that is responsible for the establishment of a secure connection between
the client and server. The Handshake Protocol works in conjunction with the SSL
Record Protocol and the SSL Change Cipher Spec Protocol to establish a secure
connection and exchange data.
The main components of the SSL Handshake Protocol include:
Client Hello: This is the initial message sent by the client to initiate the SSL
Handshake. The Client Hello message includes information about the client's
SSL version, supported cipher suites, and a random number called the client
random.
Server Hello: This is the message sent by the server in response to the Client
Hello. The Server Hello message includes information about the server's SSL
version, the chosen cipher suite, and a random number called the server
random.
Certificate: This is the message sent by the server to provide its digital
certificate to the client. The certificate includes information about the identity
of the server and a public key that can be used to encrypt the data.
Server Key Exchange: This is an optional message sent by the server in some
cases when the server has no certificate or the certificate doesn't contains the
public key.
Server Hello Done: This is the message sent by the server to indicate that the
server hello and certificate message (if applicable) are finished.
Client Key Exchange: This message sent by the client after the server hello
done, to provide the pre-master secret to the server, that both parties will use to
generate the session key.
Change Cipher Spec: This is a message sent by both the client and the server
to indicate that all future messages will be encrypted using the session key.
Finished: This is a message sent by both the client and the server to indicate
the completion of the SSL Handshake.
Once the SSL Handshake is completed, the SSL Record Protocol is used to encrypt
and decrypt data exchanged between the client and server.
Change Cipher Protocol
The SSL (Secure Sockets Layer) Change Cipher Spec Protocol is a part of the
SSL/TLS (Transport Layer Security) protocol suite used to provide secure
communications on the internet. It is used to signal the end of the SSL/TLS
handshake process and the beginning of the secure data transfer phase.
The Change Cipher Spec Protocol is used to notify the other party that the sender
will start using new cryptographic parameters for the secure data transfer. This is
done by sending a single message, called the Change Cipher Spec message,
which consists of a single byte with the value 1.
When the Change Cipher Spec message is received, the recipient of the
message will use the new cryptographic parameters (e.g. keys and algorithms)
to secure the data that is sent and received over the SSL/TLS connection. This
ensures that the data is protected by the strongest and most up-to-date
cryptographic algorithms available.
Alert Protocol
The SSL (Secure Sockets Layer) Alert Protocol is a part of the SSL/TLS
(Transport Layer Security) protocol suite used to provide secure communications
on the internet. It is used to convey important information and error messages
between the client and server during the SSL/TLS hand shake process. The SSL
Alert Protocol defines a set of alert messages that can be sent by either the client or
server to indicate the status of the SSL/TLS connection, such as a handshake
failure or a certificate problem. It uses a 2 byte format with the first byte being the
level (warning or fatal) and the second byte being the description of the alert.
Unit-3: Introduction to Cyber Crimes
3.1 Category of Cyber Crimes
3.2 Technical Aspects of Cyber Crimes
3.2.1 Unauthorized access & Hacking
3.2.2 Trojan, Virus and Worm Attacks
3.2.3 E-Mail related Crimes: Spoofing, Spamming, Bombing
3.2.4 Denial of Service Attacks
3.2.5 Distributed Denial of Service Attack
3.3 Various crimes :
3.3.1 IPR Violations (Software piracy, Copyright Infringement,
Trademarks Violations, Theft of Computer source code, Patent
Violations)
3.3.2 Cyber Squatting, Cyber Smearing, Cyber Stacking
3.3.3 Financial Crimes: ( Banking, credit card, Debit card related)
3.1 Category of Cyber Crimes
1. Cybercrime Against Individuals
These crimes are directed at a specific person and often involve personal harm,
emotional distress, or loss of privacy.
Cyber stalking: Following a person’s movements online, sending persistent
unwanted messages, or monitoring their digital life to cause fear or
harassment.
Identity Theft: The fraudulent acquisition and use of a person's private
identifying information (passwords, social security numbers, credit card
details) for financial gain.
Phishing & Social Engineering: Using deceptive emails or messages to
trick individuals into revealing sensitive data. In 2025, this often includes
Vishing (voice) and Smishing (SMS).
Cyberbullying/Harassment: Using social media or messaging platforms to
humiliate, threaten, or intimidate a person.
Dissemination of Prohibited Material: Sharing private images without
consent (revenge porn) or distributing obscene content.
2. Cybercrime Against Property
These crimes target digital or physical assets rather than the person themselves.
The motive is usually financial or destruction of value.
Hacking & Unauthorized Access: Breaking into a computer system or
network to steal, modify, or destroy data.
Intellectual Property (IP) Crimes: Software piracy, unauthorized
distribution of copyrighted music/movies, and trademark infringement
(Cybersquatting).
Cyber Vandalism: The deliberate destruction or defacement of a person's
digital property, such as damaging a private database or altering a website.
Online Fraud: Scams involving e-commerce, fake auctions, or fraudulent
investment schemes.
3. Cybercrime Against Organizations
These attacks target businesses or institutions to disrupt operations or steal
corporate secrets.
Ransomware: Encrypting an organization's critical data and demanding a
ransom (often in cryptocurrency) to unlock it.
DoS and DDoS Attacks: Flooding a company’s server with excessive
traffic to make their website or services unavailable to legitimate users.
Cyber Espionage: Hacking into a competitor's system to steal trade secrets,
client lists, or sensitive business strategies.
Supply Chain Attacks: Attacking a small software vendor to gain
"backdoor" access into the systems of much larger organizations that use
that software.
4. Cybercrime Against Government and Society
These are the most severe categories, often affecting the security and stability of a
nation.
Cyber terrorism: Attacks on critical infrastructure—such as power grids,
water supply systems, or air traffic control—to cause widespread panic and
physical damage.
Cyber Warfare/State-Sponsored Attacks: Nation-states using hacking to
disrupt another country’s elections, military communications, or financial
systems.
Forgery & Counterfeiting: Using high-end digital tools to create fake
currency, passports, or government documents.
Online Drug Trafficking: Using the Dark Web and encrypted
communication to sell illegal substances across borders.
3.2 Technical Aspects of Cyber Crimes
The technical aspects of cybercrime involve exploiting vulnerabilities in software,
networks, and human psychology using various methods. Key techniques include:
Malware
Malware (malicious software) is an umbrella term for programs designed to
disrupt, damage, or gain unauthorized access to computer systems.
Mechanism: Malware typically infects a device via malicious email attachments,
compromised websites, or infected USB drives. Once inside, it can perform
various malicious actions.
Types:
o Viruses: Attach to legitimate files and require user interaction to replicate and
spread.
o Worms: Self-replicate and spread across networks by exploiting security
vulnerabilities without human action.
o Trojans: Masquerade as legitimate software to trick users into downloading them,
often creating "backdoors" for attackers to access the system remotely.
o Ransomware: Encrypts a victim's files and demands payment (ransom) for the
decryption key.
o Spyware: Secretly monitors user activity and collects sensitive information like
keystrokes and browsing history, sending it to the attacker.
Phishing
Phishing is a social engineering technique where attackers masquerade as a
trustworthy entity to trick individuals into revealing sensitive information.
Mechanism: Attackers send fraudulent messages (emails, texts, instant messages)
containing malicious links or attachments. These links often lead to fake websites
that are pixel-perfect clones of legitimate ones. When the user enters their
credentials or personal information on the fake site, the attacker captures the data.
Techniques:
o Link Manipulation: The displayed link text appears legitimate, but the actual
destination URL is malicious, sometimes using visually similar characters
(homograph attacks) or typo squatting domain names.
o Sense of Urgency: Messages often use alarming language (e.g., "your account will
be suspended") to prompt victims into acting quickly without verifying the source.
o Man-in-the-Middle (MitM) Phishing: Advanced techniques using tools that
intercept communication in real-time, allowing attackers to bypass multi-factor
authentication (MFA) by stealing session tokens.
Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS) Attacks
These attacks aim to make a network resource or service unavailable to legitimate
users by overwhelming it with excessive traffic or requests.
Mechanism: A single machine is used in a DoS attack, while a DDoS attack
leverages multiple compromised systems (a botnet) to launch a coordinated attack,
making it harder to mitigate and trace. The goal is to consume all available
resources (bandwidth, CPU, memory) so the system cannot process legitimate
traffic.
Types:
o Volumetric Attacks: Flood the network with a massive amount of seemingly
legitimate traffic (e.g., DNS amplification attacks).
o Protocol Attacks: Exploit weaknesses in network protocol stacks (e.g., SYN
floods) to consume server resources.
o Application-Layer Attacks: Target specific web application functions with low-
volume, high-impact requests to exhaust server resources (e.g., HTTP floods,
Slowloris attacks).
SQL Injection (SQLi)
SQL injection is a code injection technique that exploits vulnerabilities in a web
application's database interactions.
Mechanism: Attackers insert malicious SQL code into input fields (like login
forms or search boxes) that are not properly sanitized or validated. This
manipulates the backend database queries, allowing the attacker to bypass
authentication, view, modify, or delete sensitive data stored in the database.
Techniques: Various methods such as Union-based, Boolean-based, and Time-
based injection are used to extract information depending on how the application
responds to the malicious queries.
Cross-Site Scripting (XSS)
XSS attacks involve injecting malicious scripts into a trusted website to be
executed by the victim's browser.
Mechanism: The attacker injects malicious JavaScript code into a web page (e.g.,
in a comment section or URL parameter). When other users visit the compromised
page, the malicious script runs in their browser. This script can hijack user
sessions, steal cookies, redirect users to malicious sites, or capture sensitive data
the user enters.
Types:
o Stored XSS: The malicious script is permanently stored on the target server (e.g.,
in a database) and is delivered to all users who access the affected page.
o Reflected XSS: The malicious script is "reflected" off a web application to the
user, typically via a malicious link that the user clicks.
3.2.1 Unauthorized access & Hacking
Unauthorized access is the act of entering a computer system, network, program,
or data without the owner's permission. This is similar to physical trespassing in
the real world. Hacking, in the context of cybercrime, involves gaining
unauthorized control of a victim's computer or system, often with malicious intent
to cause damage, steal data, or commit fraud.
Key Distinctions
Feature Unauthorized Access Hacking
Intent Can be accidental or simply Typically implies malicious
involve accessing data without intent, such as data theft,
permission, not necessarily sabotage, or financial gain.
causing harm.
Method Can occur through various Often involves more technical
means, including tailgating methods like exploiting software
(physical access), weak access vulnerabilities, using malicious
controls, or stolen credentials. code, or bypassing security
mechanisms.
Consequence Violates security policies and Leads to more severe
can lead to data breaches. consequences, including system
damage, data theft, identity theft,
and significant financial loss.
Common Techniques Leading to Unauthorized Access and Hacking
Compromised Passwords: Attackers use stolen or weak passwords to gain initial
entry.
Phishing & Social Engineering: Manipulating individuals into revealing sensitive
information, like login details.
Insider Threats: Employees, current or former, misusing their legitimate access
privileges for personal gain.
Exploiting Vulnerabilities: Taking advantage of weaknesses in software or
network infrastructure to bypass security.
Prevention and Safeguards
Organizations and individuals can implement several measures to prevent
unauthorized access:
Access Controls: Enforcing strong authentication methods, such as multi-factor
authentication (MFA), and regularly updating software.
Principle of Least Privilege (PoLP): Ensuring users only have the minimum
access necessary to perform their jobs.
Monitoring User Activity: Detecting unusual login attempts or access patterns to
identify potential breaches quickly.
Physical Security: Securing physical access to data centers and ensuring devices
are locked when unattended.
Security Awareness Training: Educating employees to recognize social
engineering and phishing attempts.
For more information on cyber security practices, numerous resources are available
from organizations like the Cyber security & Infrastructure Security Agency
(CISA) in the U.S.
3.2.2 Trojan, Virus and Worm Attacks
Viruses, worms, and Trojans are all forms of malicious software (malware) with
key differences in how they spread and operate.
Virus: A virus attaches itself to legitimate files or programs and requires a user
action (like opening an infected file) to activate and spread. They can corrupt files,
steal data, or disrupt operations.
Worm: Worms are self-replicating and spread across networks without needing
human help or a host program. They exploit system vulnerabilities to spread
rapidly, often consuming significant network bandwidth or system resources and
causing slowdowns or crashes.
Trojan Horse: A Trojan is malware disguised as legitimate or useful software that
tricks users into installing it. Unlike viruses and worms, Trojans do not self-
replicate. Once activated, they can steal sensitive data, create backdoors for remote
access, or install other malware.
Key Distinctions
Feature Virus Worm Trojan Horse
Self- Yes, but Yes, it is standalone No, it does not
Replicating requires a host software. replicate itself.
program to
attach to.
Requires Yes, typically No, it spreads Yes, tricks user into
User Action? needs user to autonomously via network installation and
open/run a file. vulnerabilities. execution.
Primary Modify or Consume system resources Steal data, provide
Goal delete data, (bandwidth/memory) and remote access
disrupt system. spread. (backdoor), install
more malware.
Detection Antivirus Antivirus and firewall can Can be harder to
software is detect and remove. detect as it appears
generally legitimate; antivirus
effective. is necessary.
Prevention
Effective protection against these threats involves a multi-layered approach:
Use and regularly update reliable antivirus/anti-malware software from a trusted
vendor like Microsoft Defender or others.
Be cautious about opening email attachments or clicking suspicious links from
unknown senders.
Only download software from official and trustworthy sources (e.g., the official
Google Play store for Android apps).
Keep your operating system and applications updated with the latest security
patches.
Employ social engineering awareness training to recognize and avoid being tricked
into installing malicious programs.
3.2.3 E-Mail related Crimes: Spoofing, Spamming, Bombing
E-mail related crimes like spoofing, spamming, and bombing exploit email
protocols to deceive recipients, distribute malware, and disrupt services. These
crimes are often used as components of larger attacks like phishing and denial-of-
service (DoS) attacks.
Email Spoofing
Email spoofing involves altering the sender's address and other parts of the email
header to make a message appear to originate from a legitimate, trusted source,
such as a colleague, bank, or reputable company. This is possible because the
original email protocol (SMTP) lacks robust authentication mechanisms.
Goal: To trick the recipient into trusting the email's authenticity so they will
perform a harmful action, such as revealing sensitive information (passwords,
credit card numbers), transferring funds, or clicking a malicious link/attachment.
Examples: An email that appears to be from a system administrator requesting
users to change their passwords, or an email from a CEO asking an employee to
wire corporate funds.
Counter measures: Organizations can implement email authentication protocols
like SPF (Sender Policy Framework), DKIM (Domain Keys Identified Mail), and
DMARC (Domain-based Message Authentication, Reporting, and Conformance)
to verify the sender's identity.
Email Spamming
Spamming (also known as junk mail) refers to sending a large volume of
unsolicited and unwanted emails to numerous users or mailing lists. While often
associated with advertising, spammers can also be cyber criminals using mass
mailings to spread malware or phishing scams.
Goal: To reach a vast number of potential victims efficiently, often to promote a
product, distribute malicious content, or gather data for other criminal activities.
Mechanism: Spammers often use botnets (networks of compromised computers)
to send millions of spam emails without the owners' knowledge, making the attacks
difficult to trace.
Counter measures: Robust email filters and anti-malware software are essential
for detecting and filtering spam messages before they reach a user's inbox.
Email Bombing
Email bombing is a form of Denial-of-Service (DoS) attack that involves
repeatedly sending a massive number of emails to a specific email address in a
short amount of time. The goal is to overwhelm the target's inbox and email server,
making the email account unusable.
Goal: To disrupt the victim's operations or to distract them with a flood of emails
while a more critical, legitimate email (e.g., a security alert about a compromised
account) goes unnoticed.
Mechanism: Attackers may use mass mailing, exploit subscription services to
generate thousands of confirmation emails, or use "attachment bombs" with large,
meaningless data files to consume system resources.
Counter measures: Anti-spam filters, rate-limiting measures on mail servers, and
advanced threat monitoring tools can help detect and mitigate email bombing
attacks.
These email-related crimes are punishable by law in many jurisdictions, often
under specific information technology acts.
3.2.4 Denial of Service Attacks
A Denial of Service (DoS) attack is a malicious attempt to disrupt the normal
functionality of a network, system, or application, making it unavailable to its
intended, legitimate users. This is typically achieved by overwhelming the target
with an excessive volume of traffic or requests, or by exploiting specific software
vulnerabilities that cause the system to crash or consume all available resources.
How DoS and DDoS Attacks Work
The key distinction is the source of the attack.
DoS Attack: Originates from a single source or computer system.
Distributed Denial of Service (DDoS) Attack: Originates from multiple,
distributed sources simultaneously, often a "botnet" (a network of compromised
devices like computers and IoT devices controlled by a single attacker via
malware). DDoS attacks are significantly harder to mitigate due to their scale and
distributed nature, which makes distinguishing malicious traffic from legitimate
traffic a challenge.
The goal in either case is to consume finite resources, such as CPU, memory, disk
space, or network bandwidth.
Primary Categories and Examples
DoS/DDoS attacks generally fall into three main categories based on which layer
of the network connection they target:
Volumetric Attacks (Layer 3/4): These attacks aim to consume all available
bandwidth between the target and the Internet by generating a massive volume of
traffic. The magnitude is measured in bits per second (Bps).
o Examples: UDP floods, ICMP floods, and DNS amplification, which uses open
DNS servers to magnify a small request into a large response directed at the victim.
Protocol Attacks (Layer 3/4): These attacks exploit weaknesses in the network
protocol stack (specifically Layers 3 and 4 of the OSI model), consuming server
resources like firewalls and load balancers. The magnitude is measured in packets
per second (PPS).
o Examples: SYN floods, where an attacker initiates many TCP handshake requests
with spoofed IP addresses but never completes the connection, leaving ports open
and exhausting server resources.
Application-Layer Attacks (Layer 7): These attacks target specific web
applications, aiming to exhaust server resources with seemingly legitimate but
malicious requests that are computationally expensive for the server to process.
The magnitude is measured in requests per second (RPS).
o Examples: HTTP floods, and Slowloris attacks, which attempt to keep many
connections to a web server open for as long as possible by sending partial
requests.
Mitigation and Prevention
While no single method guarantees full protection, a layered defense strategy is
most effective.
Preparedness: Develop a comprehensive DDoS-response plan with defined roles
and procedures before an attack occurs.
Traffic Monitoring: Use network security and monitoring services to detect
anomalous traffic spikes and irregular network performance, which can be early
indicators of an attack.
Mitigation Tools:
o Rate Limiting: Restricting the number of requests a server accepts within a
specific timeframe can help manage some attacks.
o Cloud-based Protection: Many organizations leverage specialized cloud-based
DDoS protection services (such as those offered by Cloud flare, Akamai,
or Microsoft Azure) that can absorb and filter malicious traffic using large,
distributed networks.
o Web Application Firewalls (WAFs): These tools can filter malicious application-
layer (Layer 7) requests based on predefined rules.
o Black holing: As an extreme measure, network administrators can route all traffic
(legitimate and malicious) to a "null route" and drop it from the network,
effectively taking the service offline to stop the attack
3.2.5 Distributed Denial of Service Attack
A Distributed Denial of Service (DDoS) attack is a malicious cyber attempt to
disrupt the normal functionality of a targeted server, service, or network by
overwhelming it with a flood of Internet traffic from multiple compromised
devices. The primary goal is to make the online resource unavailable to legitimate
users, thereby causing operational downtime, financial losses, and reputational
damage.
How a DDoS Attack Works
DDoS attacks differ from a single-source Denial of Service (DoS) attack by
leveraging multiple systems to maximize impact and evade simple detection or
blocking. The process generally involves two main stages:
1. Botnet Creation: The attacker infects numerous internet-connected devices
(computers, smart phones, and especially vulnerable IoT devices like cameras and
routers) with malware. These compromised devices become "bots" or "zombies"
and form a network called a botnet, which the attacker controls remotely via
command-and-control (C2) servers.
2. Launching the Attack: Once the botnet is established, the attacker sends
instructions to all bots to simultaneously send an overwhelming volume of requests
or packets to the victim's IP address. This massive surge in traffic consumes the
target's network bandwidth or system resources (CPU, memory, connection ports),
causing legitimate requests to be delayed, denied, or the entire service to crash.
Types of DDoS Attacks
DDoS attacks target different layers of the Open Systems Interconnection (OSI)
model. The main categories include:
Volumetric Attacks (Layer 3/4): These are the most common and aim to
consume all available bandwidth between the target and the rest of the internet.
Examples include:
o UDP Floods: Attacker sends a flood of User Datagram Protocol (UDP) packets to
random ports on the target, which consumes resources as the victim sends back
"destination unreachable" messages.
o ICMP Floods: Inundates the target with ICMP echo requests (pings), forcing it to
use significant resources to respond to each one.
o DNS Amplification: The attacker spoofs the victim's IP address and sends small
DNS requests to open DNS servers, which respond with large data packets directed
at the victim, amplifying the attack traffic significantly.
Protocol Attacks (Layer 3/4): These attacks exploit weaknesses in network
protocols to exhaust server resources like firewalls and load balancers.
o SYN Flood: The attacker sends numerous TCP "Initial Connection Request"
(SYN) packets with spoofed source IPs, but never sends the final acknowledgment
(ACK). This leaves the target's ports in a "half-open" state, eventually exhausting
its capacity to accept new, legitimate connections.
Application-Layer Attacks (Layer 7): These attacks target specific
vulnerabilities in web applications with seemingly legitimate, low-volume requests
that require significant server processing power.
o HTTP Flood: The attacker sends an excessive number of HTTP GET or POST
requests, similar to constantly refreshing a web browser on multiple computers,
overwhelming the server's application capacity.
o Slowloris: This attack keeps many simultaneous HTTP connections open to a web
server by sending partial requests very slowly, consuming all available connections
over time.
Mitigation and Prevention
While a single firewall is generally insufficient to stop a DDoS attack, a multi-
layered defense strategy can help.
Develop an Action Plan: Proactive preparation is key. Create a a plan with
defined roles and procedures for detection, prevention, and mitigation before an
attack occurs.
Use DDoS Protection Services: Specialized cloud-based DDoS protection
services can filter malicious traffic before it reaches the target network.
Implement Traffic Monitoring: Use traffic analytics tools to spot unusual spikes
or patterns (e.g., a flood from a single IP range or an unusual geolocation) that may
indicate an attack is underway.
Employ Defense Mechanisms: Techniques such as black hole routing (dropping
all traffic to the target during an attack), rate limiting (restricting the number of
requests a server accepts), and Web Application Firewalls (WAFs) can be part of a
robust defense.
Secure IoT Devices: Regularly update software and change default passwords on
all Internet of Things devices to prevent them from becoming part of a botnet.
3.3 Various crimes :
3.3.1 IPR Violations (Software piracy, Copyright Infringement,
Trademarks Violations, Theft of Computer source code, Patent Violations)
IPR violations, like software piracy, copyright theft, trademark abuse, source code
stealing, and patent infringement, involve unauthorized use of creative/innovative
works, leading to civil lawsuits (injunctions, damages) or even criminal penalties
(fines, jail) for illegal copying, distribution, or branding, impacting creators' rights
and digital assets. These infringements exploit digital creations, from
music/movies (piracy) to patented designs and unique software code, undermining
innovation and fair compensation.
Here's a breakdown of each type:
Software Piracy: Illegally copying, distributing, or using software without a valid
license, often through mass duplication or illicit downloads.
Copyright Infringement: Using protected creative works (music, books, software,
films) without permission, violating the owner's rights to reproduce, display, or
distribute.
Trademark Violations: Using a similar logo, name, or design (e.g., counterfeit
luxury goods) that confuses consumers into thinking it's the original brand,
harming its reputation.
Theft of Computer Source Code: Stealing or unauthorized access to the
underlying code of software, often considered a trade secret or copyright
infringement.
Patent Violations: Making, using, or selling a product or process that falls under
someone else's patented invention without their consent.
Consequences:
Civil: Injunctions to stop infringement, monetary damages, or account of profits.
Criminal: Fines, imprisonment, especially for large-scale counterfeiting or
organized piracy.
These violations often intersect in cybercrime, with actions like selling fake
software online being both copyright and trademark infringement.
3.3.2 Cyber Squatting, Cyber Smearing, Cyber Stacking
Cybersquatting
Cybersquatting is the illegal practice of registering, using, or trafficking a domain
name in "bad faith" with the intent to profit from the goodwill of a trademark or
personal name belonging to someone else. The perpetrator (cybersquatter)
typically registers a domain name identical or confusingly similar to an existing
brand with the goal of selling it to the rightful owner at an inflated price or using it
for malicious purposes like phishing.
Key characteristics include:
Bad Faith Intent: The core element that makes the act illegal is the intent to profit
unfairly from another's trademark.
Types: This can include "typosquatting" (registering common misspellings of
popular domain names, like [Link] instead of [Link]) or registering the
names of famous individuals or companies.
Legal Action: Trademark owners can pursue legal action, in the U.S. under
the Anticybersquatting Consumer Protection Act (ACPA), or through international
policies like the Uniform Domain Name Dispute Resolution Policy (UDRP)
administered by WIPO.
Cyber Smearing (Cyber Defamation)
Cyber smearing, also known as cyber defamation, is the act of publishing false
and defamatory material about an individual, group, or organization using
electronic means such as the internet or email. Defamation involves causing injury
to a person's reputation in the eyes of a third party.
Key aspects include:
Platform: It typically occurs on social media, blogs, forums, or through mass
emails.
Content: This can involve posting false accusations, rumors, or sharing personal
information to cause embarrassment or humiliation.
Legal Recourse: Victims can sue the perpetrators for damages in civil court. A
notable example involved an employee sending defamatory emails about his
employer and the managing director.
Cyberstalking
Cyberstalking is the use of the internet or other electronic means to repeatedly
harass, threaten, or monitor someone, causing the victim to feel fear or significant
emotional distress. It is a serious crime motivated by a desire to control, intimidate,
or influence a victim, often involving a known perpetrator such as a former partner
or acquaintance.
Key characteristics include:
Persistence and Intent: It involves repeated, unwanted behavior with the intent to
cause distress or fear.
Methods: Methods include sending threatening emails or messages, excessively
liking or tagging posts, hacking accounts, spreading lies online, posting the
victim's personal information (doxing), or using GPS/spyware to track a victim's
location.
Legality: Cyberstalking is a criminal offense in many jurisdictions and can result
in restraining orders, probation, and imprisonment. In India, specific sections of the
Indian Penal Code (IPC) and the Information Technology Act address this crime.
3.3.3 Financial Crimes: ( Banking, credit card, Debit card related)
Financial crimes related to banking, credit cards, and debit cards involve the
unauthorized use of financial systems and personal information for illicit gain.
Common types include:
Card-Related Fraud
Card Skimming: Thieves place small, hidden electronic devices (skimmers) on
ATMs or Point-of-Sale (POS) terminals (like at gas pumps or restaurants) to steal
the card's magnetic strip data and PIN. This information is then used to create
counterfeit cards.
Card-Not-Present (CNP) Fraud: This occurs when a fraudster uses stolen card
details (card number, expiration date, CVV) to make unauthorized online or phone
purchases without having the physical card.
Lost or Stolen Cards: Physical theft of the card, followed by its use for purchases
or ATM withdrawals before the legitimate owner reports it missing.
Counterfeit Cards: Fraudsters use stolen card data to manufacture fake physical
credit or debit cards, which are then used to make unauthorized transactions.
Banking & Identity-Related Fraud
Identity Theft/Application Fraud: Criminals steal personal information (name,
address, Social Security/Aadhaar/PAN number, etc.) to open new bank accounts or
apply for new credit cards/loans in the victim's name.
Account Takeover (ATO): Fraudsters gain unauthorized access to an existing
bank or credit card account, often by stealing login credentials, and then change
contact details, make purchases, or transfer funds.
Phishing/Vishing/Smishing: Scammers use deceptive emails, phone calls, or text
messages (posing as bank representatives or other legitimate entities) to trick
individuals into revealing sensitive information like account numbers, PINs, or
OTPs.
Wire Transfer Fraud: Gaining unauthorized access to a bank account to initiate
illicit wire transfers to accounts controlled by the fraudster.
Mobile Banking Threats: This can involve malware or Trojans installed on a
victim's device to capture banking credentials and other sensitive data, or SIM
swap fraud where a criminal gains control of a victim's mobile number to bypass
two-factor authentication.
How to Protect Yourself
Monitor statements: Regularly check your bank and card statements for any
unfamiliar transactions, no matter how small.
Secure information: Never share sensitive details like PINs, passwords, or the
CVV number with anyone, including those who claim to be bank officials.
Use strong passwords and multi-factor authentication: This adds a crucial layer
of security to online accounts.
Be cautious online and with communication: Avoid clicking on suspicious links
in emails or texts, and only use secure (HTTPS) websites for online banking and
purchases.
Report immediately: If your card is lost or stolen, or you notice suspicious
activity, contact your bank's fraud department immediately.
Shred documents: Securely destroy any documents containing personal or
financial information before discarding them.
Victims in India can also use the national cybercrime helpline (1930) or report
incidents online at the National Cybercrime Reporting Portal.
Unit-4: Cyber Security Fundamentals
4.1 Concepts of Cyber Security
4.1.1 Types of Threats
4.1.2 Advantages of Cyber Security
4.2 Basic Terminologies:
4.2.1 IP Address, MAC Address
4.2.2 Domain name Server(DNS)
4.2.3 DHCP, Router, Bots
4.3 Common Types of Attacks:
4.3.1 Distributed Denial of Service
4.3.2 Man in the Middle, Email Attack
4.3.3 Password Attack, Malware
4.4 Hackers:
4.4.1 Various Vulnerabilities:
[Link] Injection attacks, Changes in security settings
`[Link] Expouser of Sensitive Data
[Link] Breach in authentication protocol
4.4.2 Types of Hackers: White hat and Black hat
Cyber security is the practice of protecting digital systems, networks, and data from
malicious attacks. Its fundamental concepts are based on the CIA Triad (Confidentiality,
Integrity, and Availability), and effective cybersecurity provides numerous advantages
for individuals and organizations.
4.1 Concepts of Cyber Security
The core principles of cyber security are embodied in the CIA Triad model.
Confidentiality: This principle ensures that sensitive information is not disclosed to
unauthorized individuals, entities, or processes. Measures like data encryption, strong
access controls, and multi-factor authentication (MFA) help maintain confidentiality.
Integrity: Integrity guarantees that data is accurate, consistent, and trustworthy,
preventing unauthorized modification or deletion. Cryptographic checksums, file
permissions, and robust data backups are used to ensure data integrity.
Availability: This ensures that authorized users can access the systems, applications,
and data when needed. This is achieved through measures like redundant systems,
disaster recovery plans, load balancing, and having sufficient bandwidth to defend
against denial-of-service attacks.
4.1.1 Types of Threats
Cyber threats are malicious activities designed to steal data, disrupt operations, or
cause damage to digital systems.
Malware: A broad term for malicious software that includes viruses, worms, Trojans,
spyware, and ransomware. Malware is often spread through email attachments,
malicious websites, or infected USB drives and can be used to gain unauthorized
access, steal data, or damage systems.
Phishing and Social Engineering: These tactics involve manipulating people into
revealing sensitive information, such as login credentials or credit card numbers, often
by impersonating a trustworthy entity in electronic communication. Spear phishing is a
more targeted version aimed at specific individuals.
Ransomware: A type of malware that encrypts a victim's files or locks their system and
demands payment (ransom), usually in crypto currency, for their return. Attackers may
also use "double extortion" by threatening to leak stolen data publicly.
Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS) Attacks: These
attacks aim to make a network resource or service unavailable to legitimate users by
overwhelming it with excessive traffic from a single source (DoS) or multiple
compromised systems (DDoS or botnet).
Man-in-the-Middle (MitM) Attacks: In a MitM attack, a cybercriminal intercepts and
potentially modifies the communication between two parties without their knowledge,
often by exploiting unsecure Wi-Fi networks.
Injection Attacks: Attackers insert malicious code into vulnerable applications, typically
web forms or input fields, to manipulate the application or its database. Common
examples include SQL injection and cross-site scripting (XSS).
Insider Threats: Security risks that originate from within an organization, which can be
malicious (e.g., a disgruntled employee stealing data) or unintentional (e.g., an
employee accidentally falling victim to a phishing scam).
4.1.2 Advantages of Cyber Security
Implementing robust cyber security measures provides numerous benefits for both
individuals and organizations:
Protection of Sensitive Data: Cyber security safeguards personal information,
financial details, and intellectual property from unauthorized access or theft, helping
prevent identity theft and fraud.
Business Continuity: Effective security measures ensure that systems and services
remain operational during and after a cyber incident, minimizing costly downtime and
disruptions.
Financial Security: It helps individuals and businesses avoid significant financial
losses that result from data breaches, fraud, and cyber extortion.
Reputation and Trust: A strong security posture builds trust and confidence with
customers, partners, and stakeholders, enhancing the organization's reputation and
credibility.
Regulatory Compliance: It helps organizations comply with data protection laws and
regulations (such as GDPR or HIPAA), avoiding hefty legal penalties and fines
associated with non-compliance.
Enhanced Defense: By using layered security approaches (e.g., firewalls, antivirus,
encryption, MFA), cyber security provides a resilient defense against evolving and
sophisticated cyber threats.
4.2 Basic Terminologies:
4.2.1 IP Address and MAC Address
IP (Internet Protocol) Address
An IP address is a unique logical identifier assigned to a device on a network that uses
the Internet Protocol for communication. It operates at the Network Layer (Layer 3) of
the OSI model and is used for routing data across different networks, including the
global Internet.
Function:
o Host Identification: Uniquely identifies a device's connection to a specific network.
o Location Addressing: Enables data packets to be routed across different networks to
their correct destination.
Format & Types:
o IPv4: A 32-bit address represented in dotted-decimal notation (e.g., [Link]).
o IPv6: A 128-bit address in hexadecimal format to accommodate the growing number of
internet devices (e.g., 2400:cb00:2048:1::c629:d7a2).
Assignment: Typically assigned dynamically by a DHCP server or statically by a
network administrator; it changes when the device connects to a different network.
MAC (Media Access Control) Address
A MAC address is a unique hardware identifier hard-coded into a device's Network
Interface Controller (NIC) by its manufacturer. It operates at the Data Link Layer (Layer
2) and is used for communication within a single local network segment.
Function:
o Device Identification: Uniquely identifies a specific physical device within a local area
network (LAN).
o Local Delivery: Network switches use MAC addresses to ensure data frames are
delivered to the correct physical device on the local network.
Format: A 48-bit address (or sometimes 64-bit) typically displayed as six groups of two
hexadecimal digits separated by colons or hyphens (e.g., 00:1A:2B:3C:4D:5E). The first
half identifies the manufacturer (OUI).
Permanence: Intended to be permanent and generally does not change, although it
can be spoofed using software.
4.2.2 Domain Name Server (DNS)
The Domain Name System (DNS) is a hierarchical and distributed naming system that
acts as the "phonebook of the Internet". It translates human-readable domain names
(like [Link]) into the numerical IP addresses that computers use to locate and
communicate with each other.
How it Works (The DNS Lookup Process):
1. Query Initiated: A user types a domain name into a web browser.
2. Resolver Checks Cache: The device's local cache is checked for the IP address. If not
found, a query is sent to a DNS recursive resolver (usually provided by the ISP).
3. Root Server Query: The resolver queries one of the 13 global root name servers.
4. TLD Server Referral: The root server refers the resolver to the appropriate Top-Level
Domain (TLD) server (e.g., for .com, .org, etc.).
5. Authoritative Server Referral: The TLD server refers the resolver to the domain's
authoritative name server, which holds the actual IP address record.
6. IP Address Returned: The authoritative server provides the IP address to the resolver,
which in turn sends it back to the original device's browser.
7. Connection: The browser uses the IP address to connect to the website's server.
4.2.3 DHCP, Router, and Bots
DHCP (Dynamic Host Configuration Protocol)
DHCP is a network management protocol that automates the process of assigning IP
addresses and other crucial network configuration parameters (like subnet masks,
default gateways, and DNS server addresses) to devices (clients) on a network. This
eliminates the need for manual configuration and prevents IP address conflicts.
How it Works (DORA process):
o Discover: A new client device broadcasts a DHCPDISCOVER message to the network to
find available DHCP servers.
o Offer: DHCP servers on the network respond with a DHCPOFFER message containing a
proposed IP address, subnet mask, lease duration, and other details.
o Request: The client selects one offer and broadcasts a DHCPREQUEST message to
formally accept the offered configuration.
o Acknowledge: The chosen server sends a DHCPACK message to confirm the lease and
finalize the configuration, allowing the client to join the network.
Router
A router is a networking device that connects two or more different networks (e.g., a
home LAN to the Internet WAN) and forwards data packets between them. It functions
as a traffic manager, using IP addresses to determine the best path (route) for each
packet to reach its destination efficiently.
Key Functions:
o Inter-Network Connectivity: Primary function is to link separate networks together.
o Routing/Forwarding: Uses an internal routing table and routing protocols (like OSPF
or BGP) to select the optimal path for data packets based on their destination IP
address.
o Network Address Translation (NAT): Allows multiple devices within a private network
to share a single public IP address when communicating with the Internet, conserving
addresses and adding a layer of security.
o Security: Often includes built-in firewall capabilities to filter traffic and protect the
internal network from unauthorized external access.
Bots (Internet Bots)
A bot (short for robot) is a software application or script that runs automated tasks
(scripts) over the Internet, usually performing simple and structurally repetitive jobs at a
much higher rate than a human could.
Types & Uses:
o Good Bots: Perform useful functions such as search engine crawlers (web spiders)
that index content for search results, or customer service chat bots that answer simple
queries.
o Bad Bots (Malicious Bots): Used for harmful activities, including:
o Spamming: Sending unsolicited messages or content.
o Malware Distribution: Spreading harmful software.
o DDoS Attacks: Overwhelming online services with traffic to cause a denial of service.
o Data Theft: Scraping data from websites.
o Botnets: Large networks of compromised devices (bots) controlled by a single attacker
to perform coordinated malicious tasks.
4.3 Common Types of Attacks:
4.3.1 Distributed Denial of Service (DDoS)
A Distributed Denial of Service (DDoS) attack is a malicious attempt to disrupt the
normal traffic of a targeted server, service, or network by overwhelming it with a flood of
Internet traffic.
Mechanism: Attackers use a network of compromised internet-connected devices
(computers, IoT devices, etc.) known as a botnet. These devices, or "bots," are
controlled remotely by the attacker without their owners' knowledge. The botnet then
simultaneously sends an overwhelming volume of requests to the target's IP address,
exhausting the server's resources and bandwidth, making it unavailable to legitimate
users.
Types of DDoS Attacks:
o Volumetric Attacks: These attacks consume all available bandwidth between the
target and the internet by sending massive amounts of data or requests, such as UDP
or ICMP floods.
o Protocol Attacks: These exploit weaknesses in the network protocol stack (Layers 3
and 4 of the OSI model) to consume server resources, such as in a SYN flood attack
where the attacker initiates many connection requests but never completes the
"handshake".
o Application Layer Attacks: These target specific vulnerabilities in web applications
(Layer 7 of the OSI model) with seemingly legitimate but resource-intensive requests
(e.g., HTTP floods).
Impact: Service disruption/downtime, loss of revenue, damage to reputation, and
potential vulnerability to other simultaneous attacks.
Mitigation: Proactive defense strategies, traffic monitoring, rate limiting, and leveraging
specialized cloud-based DDoS protection services can help filter malicious traffic.
4.3.2 Man-in-the-Middle (MitM) and Email Attacks
Man-in-the-Middle (MitM)
A Man-in-the-Middle attack occurs when a threat actor secretly inserts themselves
between two communicating parties (e.g., a user and a website) to intercept, relay, or
modify their communications.
Mechanism: The attacker positions themselves in the communication channel and
makes both parties believe they are communicating directly with each other. This often
involves exploiting unsecure Wi-Fi networks or using spoofing techniques to fool users
into connecting to a malicious system.
Common Techniques:
o Wi-Fi Eavesdropping: Creating malicious public Wi-Fi hotspots to capture data from
connecting devices.
o IP/DNS/HTTPS Spoofing: Altering IP addresses or DNS records to redirect users to a
fake website that appears legitimate.
o SSL Stripping: Downgrading a secure HTTPS connection to an unencrypted HTTP
connection to read data in plain text.
Impact: Theft of sensitive data (login credentials, financial info), unauthorized access to
accounts, identity theft, and potential installation of malware.
Email Attacks
Email attacks primarily use social engineering to manipulate individuals into performing
actions that compromise their security.
Phishing: Attackers send fraudulent emails that appear to be from a legitimate, trusted
source to trick recipients into revealing sensitive information (passwords, credit card
numbers) or clicking malicious links/attachments that install malware. Phishing is often a
primary entry point for other attacks.
Spoofing: This involves faking the sender's identity, email address, or domain to make
the message appear authentic. In a Business Email Compromise (BEC) attack, an
attacker might impersonate a high-ranking executive to deceive an employee into
transferring company funds to a fraudulent account.
4.3.3 Password Attacks and Malware
Password Attacks
These attacks aim to gain unauthorized access to accounts by obtaining or guessing
login credentials.
Brute-Force Attacks: The attacker uses automated tools to systematically guess
passwords by trying a vast number of combinations until the correct one is found.
Credential Stuffing: This technique uses username and password pairs leaked from
one data breach to attempt to log into other, unrelated accounts, assuming users reuse
credentials across different services.
Other Methods: Dictionary attacks (using lists of common words), key logging
(recording keystrokes), and social engineering (tricking users into revealing passwords)
are also common.
Malware
Malware (malicious software) is a general term for any software designed to disrupt
computer operation, gather sensitive information, or gain unauthorized access to
computer systems.
Ransomware: A type of malware that encrypts a victim's files or locks their entire
system, demanding a ransom (usually in crypto currency) for decryption or restoration of
access. Paying the ransom does not guarantee the return of data.
Viruses: Self-replicating malicious programs that spread by inserting copies of
themselves into other programs or files when a user executes the infected host
program. They can cause system damage or steal data.
Trojans (Trojan Horses): Malware disguised as a legitimate application or file. Once
executed, it performs malicious actions in the background, such as opening a
"backdoor" for attackers to access the system.
Worms: Similar to viruses, but they can self-replicate and spread across networks
without requiring user interaction, often exploiting network vulnerabilities to infect other
machines.
Hackers exploit various vulnerabilities to compromise systems. The vulnerabilities listed
are major weaknesses that can lead to significant data breaches and system control
loss.
4.4 Hackers:
4.4.1 Various Vulnerabilities:
[Link] Injection Attacks, Changes in Security Settings
Injection Attacks
Injection attacks occur when untrusted data is sent to a code interpreter (like a database
or operating system command line) as part of a command or query, tricking the
interpreter into executing unintended commands.
SQL Injection (SQLi): An attacker injects malicious SQL code into user input fields to
manipulate the database. This can lead to unauthorized access, data theft, data
modification, or even full control of the database server.
Command Injection: The attacker injects OS commands into a vulnerable application,
which are then executed by the system with the application's privileges. This can result
in data exposure, privilege escalation, or complete system compromise.
Cross-Site Scripting (XSS): This is a type of script injection where an attacker injects
malicious scripts (e.g., JavaScript) into content that is then delivered to other users'
browsers. This can be used to hijack user sessions, steal cookies, or control the user's
browser.
Vulnerability Cause: Inadequate input validation and sanitization of user-supplied data
are the root causes.
Mitigation: Use parameterized queries (prepared statements), rigorous input validation
and output encoding, and enforce the principle of least privilege.
Changes in Security Settings (Security Misconfiguration)
This is a very common vulnerability, often a result of using default configurations,
incomplete configurations, or displaying overly descriptive error messages that reveal
system information.
Notes:
o Using default passwords or settings for software/devices.
o Having unnecessary features, services, or ports enabled.
o Misconfigured access controls or network settings (e.g., leaving a service accessible to
the internet that should be internal).
o Failing to apply security patches and updates in a timely manner.
Mitigation: Implement a secure installation process, remove all unused features,
update software regularly, and use minimal, generalized error messages.
[Link] Exposure of Sensitive Data
This vulnerability occurs when applications fail to properly protect sensitive information
(e.g., financial records, passwords, personal data, health information) in transit or at
rest.
Notes:
o Storing passwords in plain text or using weak, outdated hashing algorithms (like MD5 or
SHA-1).
o Transmitting sensitive data over unencrypted channels (like HTTP instead of HTTPS).
o Inadequate key management or hardcoding cryptographic keys in source code.
o Verbose error messages that reveal database structure or internal application workings.
Impact: Leads to privacy breaches, identity theft, financial fraud, and significant
regulatory fines (e.g., GDPR, CCPA).
Mitigation: Encrypt all sensitive data at rest and in transit, use strong, modern
encryption protocols, implement strict access controls, and avoid unnecessary storage
of sensitive data.
[Link] Breach in Authentication Protocol
Authentication vulnerabilities refer to flaws in the login or session management
processes that allow attackers to compromise user accounts or assume legitimate user
identities.
Notes:
o Weak Passwords: Allowing users to set easily guessable passwords or failing to
enforce strong password policies.
o Missing Rate Limiting: Failure to limit repeated login attempts, enabling brute-force or
credential stuffing attacks.
o Insecure Session Handling: Vulnerabilities in how user sessions are managed can
lead to session hijacking.
o Flawed Multi-Factor Authentication (MFA): Implementation errors that allow an
attacker to bypass 2FA.
o Weak Account Recovery: Vulnerable "forgot password" processes that can be
exploited to gain access.
Impact: Unauthorized access to user accounts, privilege escalation (if admin accounts
are compromised), and full system control.
Mitigation: Mandate strong passwords, implement MFA, use rate limiting on login
attempts, ensure secure session management, and conduct regular security audits of
the authentication logic.
4.4.2 Types of Hackers: White hat and Black hat
Hackers are categorized primarily by their motivation and whether their actions are
legal, leading to the classifications of white hat (ethical defenders) and black
hat (malicious criminals).
White Hat Hackers (Ethical Hackers)
White hat hackers are cybersecurity professionals who use their skills for defensive and
protective purposes.
Intent: Their goal is to protect systems and data by identifying and fixing security flaws
before malicious actors can exploit them.
Legality/Authorization: They operate within legal and ethical boundaries and always
have explicit permission from the system owners (e.g., their employers or clients) to
access networks and systems.
Motivation: They are driven by professional responsibility, ethical standards, and a
desire to enhance overall cybersecurity. They are typically paid employees or
contractors.
Methods: They use the same techniques as black hat hackers but within a controlled,
legal framework. Common methods include:
o Penetration testing to simulate real-world attacks and uncover vulnerabilities.
o Vulnerability assessments to identify weaknesses in systems and recommend fixes.
o Social engineering tests to find weaknesses in an organization's "human firewall".
Outcome: They help strengthen an organization's security posture, prevent data
breaches, and ensure compliance with security regulations. They often have formal
certifications.
Black Hat Hackers (Malicious Actors)
Black hat hackers are cybercriminals who break into computer networks with malicious
intent.
Intent: Their primary goal is to exploit vulnerabilities for personal or financial gain,
revenge, political reasons, or simply to cause disruption and harm.
Legality/Authorization: Their actions are illegal, as they access systems without
authorization or permission from the owner.
Motivation: They are typically motivated by self-serving reasons such as financial
profit, stealing sensitive information for sale on the dark web, or personal vendettas.
Methods: They use various malicious tactics, including:
o Deploying malware, ransomware, and spyware.
o Conducting phishing attacks to steal credentials.
o Performing Denial of Service (DDoS) attacks.
o Exploiting security flaws for data theft and fraud.
Outcome: Their actions result in data breaches, financial losses, system damage, and
identity theft for individuals and organizations.
Summary of Differences
Aspect White Hat Hackers Black Hat Hackers
Intent Ethical and protective Malicious and harmful
Legality Fully legal, operate within law Illegal and punishable by law
Authorization Always have permission to access Access systems without consent
systems
Motivation Improve security, protect data Financial gain, revenge, chaos
Role Defenders, security consultants, IT Criminals, malicious actors
experts
Outcome Strengthened security, prevention of Data breaches, financial loss, system
attacks damage