DEPARTMENT OF CSE - CYBER SECURITY
CYBER CRIME INVISTIGATION (CY4112PE)
IV B. Tech I Semester (NR21)
Prepared by
Mr. K. SRINIVASA RAO
Asst. professor
UNIT – I
UNIT- I
Introduction:
Introduction and Overview of Cyber Crime,
Nature and Scope of Cyber Crime,
Types of Cyber Crime:
Social Engineering,
Categories of Cyber Crime,
Property Cyber Crime.
CYBER CRIME
Cybercrime or a computer-oriented crime is a crime that includes a computer and a
network. The computer may have been used in the execution of a crime or it may be
the target. Cybercrime is the use of a computer as a weapon for committing crimes
such as committing fraud, identity theft, or breaching privacy. Cybercrime,
especially through the Internet, has grown in importance as the computer has become
central to every field like commerce, entertainment, and government. Cybercrime
may endanger a person or a nation’s security and financial
health. Cybercrime encloses a wide range of activities, but these can
generally be divided into two categories:
Crimes that aim at computer networks or devices. These types of crimes involve
different threats (like virus, bugs etc.) and denial-of-service (DoS) attacks.
Crimes that use computer networks to commit other criminal activities. These
types of crimes include cyber stalking, financial fraud or identity theft.
Cyber Crime
Classification of Cyber Crime:
Cyber Terrorism –
Cyber terrorism is the use of the computer and internet to perform violent acts that result in loss of life. This
may include different type of activities either by software or hardware for threatening life of citizens.
In general, Cyber terrorism can be defined as an act of terrorism committed through the use of cyberspace or
computer resources.
Cyber Extortion –
Cyber extortion occurs when a website, e-mail server or computer system is subjected to or threatened with
repeated denial of service or other attacks by malicious hackers. These hackers demand huge money in return
for assurance to stop the attacks and to offer protection.
Cyber Warfare –
Cyber warfare is the use or targeting in a battle space or warfare context of computers, online control
systems and networks. It involves both offensive and defensive operations concerning to the threat of cyber
attacks, espionage and sabotage.
CSE – CS, NRCM
Cyber Crime
Internet Fraud –
Internet fraud is a type of fraud or deceit which makes use of the Internet and could
include hiding of information or providing incorrect information for the purpose of
deceiving victims for money or property. Internet fraud is not considered a single,
distinctive crime but covers a range of illegal and illicit actions that are committed in
cyberspace.
Cyber Stalking –
This is a kind of online harassment wherein the victim is subjected to a barrage of
online messages and emails. In this case, these stalkers know their victims and
instead of offline stalking, they use the Internet to stalk. However, if they notice that
cyber stalking is not having the desired effect, they begin offline stalking along with
cyber stalking to make the victims’ lives more miserable.
CSE – CS, NRCM
Cyber Crime
Challenges of Cyber Crime:
People are unaware of their cyber rights-
The Cybercrime usually happen with illiterate people around the world who are unaware
about their cyber rights implemented by the government of that particular country.
Anonymity-
Those who Commit cyber crime are anonymous for us so we cannot do anything to that person.
Less numbers of case registered-
Every country in the world faces the challenge of cyber crime and the rate of cyber crime is increasing
day by day because the people who even don’t register a case of cyber crime and this is major challenge
for us as well as for authorities as well.
Mostly committed by well educated people-
Committing a cyber crime is not a cup of tea for every individual. The person who commits cyber crime
is a very technical person so he knows how to commit the crime and not get caught by the authorities.
No harsh punishment-
In Cyber crime there is no harsh punishment in every cases. But there is harsh punishment in some cases
like when somebody commits cyber terrorism in that case there is harsh punishment for that individual.
But in other cases there is no harsh punishment so this factor also gives encouragement to that person
who commits cyber crime.
CSE – CS, NRCM
Nature and Scope of Cyber Crime
Understanding Cyber Crime
Cyber crime refers to illegal activities conducted via the
internet or through the use of information technology. It
encompasses a wide range of offences including hacking,
data theft, online fraud, cyber terrorism and identity theft.
The anonymity provided by the digital space allows cyber
criminals to operate with a degree of impunity, making
cyber crime an appealing avenue for illicit activities.
CSE – CS, NRCM
Nature and Scope of Cyber Crime
Nature of Cyber Crime in India
The nature of cyber crime in India is multifaceted and constantly evolving.
The most common forms of cyber crime in the country include:
Phishing: Fraudulent attempts to obtain sensitive information such as usernames, passwords
and credit card details by disguising as a trustworthy entity in an electronic communication.
Ransomware: A type of malicious software designed to block access to a
computer system until a sum of money is paid.
Data Breaches: Unauthorised access and theft of personal or corporate data.
Online Scams: Various schemes that deceive users into paying money for fraudulent services or
goods.
Cyber Stalking and Harassment: Using the internet to stalk or harass an individual, group or
organisation.
Identity Theft: Stealing personal information to impersonate someone else for financial gain or
other benefits.
Nature and Scope of Cyber Crime
Scope of Cyber Crime in India
The scope of cyber crime in India is expansive and growing. Factors
contributing to the rise in cyber crime include:
Rapid Digitisation: As more services move online, from banking to
government documentation, the opportunities for cyber crimes increase.
Lack of Cybersecurity Awareness: Many users lack basic
cybersecurity knowledge, making them easy targets for cyber
criminals.
Inadequate Cybersecurity Infrastructure: Despite improvements,
many Indian businesses and organisations still do not invest sufficiently
in cybersecurity measures.
High Internet Penetration: With over 700 million internet users, the sheer
volume of digital transactions in India presents numerous opportunities for
cyber criminals.
Impacts of Cyber Crime
The impacts of cyber crime are profound and varied,
affecting economic, social and personal dimensions.
Economically, cyber crime leads to significant
financial losses for individuals and businesses.
Socially, it undermines trust in digital transactions.
On a personal level, victims of cyber crimes like
identity theft or online harassment can suffer severe
emotional and psychological distress.
Combatting Cyber Crime in India
The Indian government, along with private sector stakeholders, has
taken several steps to combat cyber crime:
Legal Framework: India has enacted various cyber laws, such as the
Information Technology Act, 2000, which provides legal recognition and
protection for transactions carried out by means of electronic data
interchange and other means of electronic communication.
Cyber Police Units: Specialised cyber crime police units and cells have
been established across the country to handle cyber crimes specifically.
Awareness Campaigns: The government and various NGOs are regularly
conducting awareness programs to educate the public about the risks of
cyber crime and the importance of cybersecurity.
Collaboration with International Agencies: India collaborates with
international bodies and foreign governments to enhance cyber security
measures and tackle cross-border cyber crimes.
TYPES OF CYBER CRIME
Two Main Types of Cybercrimes
Most cybercrime falls under two main categories:
Criminal activity that targets computers.
Criminal activity that uses computers.
Cybercrime that targets computers often involves
malware like viruses.
Cybercrime that uses computers to commit other
crimes may involve using computers to spread
malware, illegal information or illegal images.
TYPES OF CYBER CRIME
Cybercrimes include monetary crimes as well as non-monetary offences. The crimes
result in damage to persons, computers, or governments.
1. Child Pornography OR Child sexually abusive material (CSAM)
Child sexually abusive material (CSAM) refers to a material containing sexual images in any
form, of a child who is abused or sexually exploited. Section 67 (B) of the IT Act states that
“it is punishable for publishing or transmitting of material depicting children in the sexually
explicit act, etc. in electronic form.
2. Cyber Bullying
A form of harassment or bullying inflicted through the use of electronic or communication
devices such as computers, mobile phones, laptops, etc.
3. Cyber Stalking
Cyberstalking is the use of electronic communication by a person to follow a person, or
attempts to contact a person to foster personal interaction repeatedly despite a clear indication
of disinterest by such person; or monitors the internet, email or any other form of electronic
communication commits the offence of stalking.
4. Cyber Grooming
Cyber Grooming is when a person builds an online relationship with a young person and tricks
or pressures him/ her into doing a sexual act.
TYPES OF CYBER CRIME
[Link] Job Fraud
Online Job Fraud is an attempt to defraud people who are in need of employment by giving them
false hope/ promise of better employment with higher wages.
6. Online Sextortion
Online Sextortion occurs when someone threatens to distribute private and sensitive material using an
electronic medium if he/ she doesn’t provide images of a sexual nature, sexual favours, or money.
7. Phishing
Phishing is a type of fraud that involves stealing personal information such as Customer ID, IPIN,
Credit/Debit Card number, Card expiry date, CVV number, etc. through emails that appear to be from a
legitimate source.
8. Vishing
Vishing is an attempt where fraudsters try to seek personal information like Customer ID, Net Banking
password, ATM PIN, OTP, Card expiry date, CVV etc. through a phone call.
9. Smishing
Smishing is a type of fraud that uses mobile phone text messages to lure victims into calling back on a
fraudulent phone number, visiting fraudulent websites or downloading malicious content via phone or web.
10. Sexting
Sexting is an act of sending sexually explicit digital images, videos, text messages, or emails, usually by
cell phone.
SOCIAL ENGINEERING
What is social engineering?
Social engineering is a manipulation technique that exploits human error to obtain
private information or valuable data. In cybercrime, the human hacking scams
entice unsuspecting users to disclose data, spread malware infections, or give
them access to restricted systems. Attacks can occur online, in-person, and by
other interactions. Social
engineering scams are based on how people think and act.
Hackers try to exploit the user's knowledge. Thanks to technology's speed, many
consumers and employees are not aware of specific threats such as drive-by
downloads. Users cannot realize the value of personal data
like phone number. Many users are unsure of how best to protect themselves and
their confidential information. Social engineering attackers have two goals:
Subversion: Interrupting or corrupting data due to loss or inconvenience.
Theft: Obtaining valuable items such as information, access
SOCIAL ENGINEERING
How does social engineering work?
Most social engineering attacks depend on real
communication between attackers and victims.
Instead of using brute force methods to breach
the data, the attacker prompts the user to
compromise.
The attack cycle gives the criminals a reliable
process to deceive you. The stages of the social
engineering attack cycle are below:
Backward Skip 10sPlay Video
SOCIAL ENGINEERING
Prepare by gathering background information on a large group.
Infiltrate by building trust, establishing a relationship or starting a
conversation.
Establish the victim once more to confront the attack with
confidence and weakness.
Once the user takes the desired action, release it.
Many employees and consumers are unaware that certain
information can give hackers access to multiple networks and
accounts.
By sending messages for IT support personnel as legitimate users, they
grab your details - such as name, date of birth or address. It is a simple
matter to reset the password and get almost unlimited access. They can
steal money, spread social engineering malware, and many more.
SOCIAL ENGINEERING
Characteristics of Social Engineering Attack:
Social engineering attack centers on the attacker's use of
persuasion and confidence.
High emotions: Emotional manipulation gives attackers the
upper hand in any conversation. The below feelings are used
equally to explain to you.
Fear
excitement
Curiosity
Anger
Crime
Sadness
SOCIAL ENGINEERING
Types of Social Engineering Attacks:
Every type of cybersecurity attack involves some social engineering. For example,
classic email and virus scams are laden with social overtones. Some of the standard
methods used by social engineering attackers are below:
Phishing Attacks
Phishing attackers pretend to a trusted institution or person in an attempt to convince you to
uncover personal data and [Link] by using phishing are targeted in two ways:
Spam phishing is a widespread attack for some users. The attacks are non-personal and
try to capture any irresponsible person.
Phishing and whaling use personal information to target particular users. The whaling attacks
are aimed at high-profile individuals such as celebrities, upper management and higher
government [Link] it is direct communication or by a fake website, anything you
share goes directly into the seamster's [Link] can also be fooled into the next stage of
the phishing attack malware download. The methods used in phishing are unique methods of
delivery.
Voice phishing (Wishing) phone calls can be an automated messaging system recording all
your inputs. The person can speak with you to build trust.
SMS phishing (SMS) texts or mobile app messages may indicate a web link or follow-up via
a web link or phone number. A web link, phone number, or malware attachment may be used.
SOCIAL ENGINEERING
Angler phishing takes place on social media, where the
attacker mimics the customer service team of a trusted
company. They interrupt your communication with a brand and
turn the conversations into private messages, where they
escalate the attack.
Search engine phishing attempts to place links to fake
websites at the top of any search results. The advertisements
will be paid or use valid optimization methods to manipulate
search rankings. The links are given in email, text, social
media messages and online advertisements.
In-session phishing appears as an interruption to the
normal web browsing. For example, you can see
fake pop-ups on the webpages you are currently viewing.
SOCIAL ENGINEERING
Baiting Attack
Baiting abuses your natural curiosity of exposing
yourself as an attacker. The potential for something
exclusive is used to exploit us. An attack involves
infecting us with malware. Popular methods of baiting
are:
USB drives are left in public places, such as
libraries and parking lots.
Email attachment with details with free offer.
SOCIAL ENGINEERING
Physical Breach Attack
Physical violations include attackers, who would
otherwise present themselves as legitimate to access
unauthorized areas or information.
This type of attack is common in enterprise
environments, like the government, businesses, or
other organizations. Attackers pretend to be a
representative of a trusted vendor for the company.
Some attackers may have recently been fired in
retaliation against their former employers.
SOCIAL ENGINEERING
They obscure their identity but are reliable enough to avoid questions. It
requires little research on the part of the attacker and involves high risk.
Therefore, if someone is attempting this method, they have identified a
clear potential for a highly valued reward if successful.
Preceding Attack:Trusting uses a misleading identity as a "trust" to
establish trusts, such as applying directly to a vendor or facility
employee.
The approach requires the attacker to interact with you more actively.
Once exploited, they are convinced that you are legitimate.
Access tailgating attack: Tailgating or piggybacking is the act of
trapping any authorized staff member in a restricted-access area.
SOCIAL ENGINEERING
Quid pro quo Attack
The term quid pro quo roughly means "a favor for a
favor," which refers to exchanging your information for
some reward or other compensation in exchange for
phishing.
Offer to participate in giveaways or research studies
may make you aware of this type of attack.
Exploitation comes from making you happy for
something valuable that comes with little investment on
your end.
However, the attacker does not reward your data for you
Categories of Cyber Crime
Classification Of Cyber Crimes Cyber crimes can
be classified in to 4 major categories as the
following: (1) Cyber crime against
Individual (2) Cyber crime Against Property
(3) Cyber crime Against Organization
(4) Cyber crime Against Society
Categories of Cyber Crime
Against Individuals
(i) Email spoofing : A spoofed email is one in which the e-mail header
is forged so that the mail appears to originate from one source but
actually has been sent from another source.
(ii) Spamming : Spamming means sending multiple copies of unsolicited
mails or mass e-mails such as chain letters.
(iii) Cyber Defamation : This occurs when defamation takes place with
the help of computers and/or the Internet. E.g. someone publishes
defamatory matter about someone on a website or sends e-mails
containing defamatory information.
(iv) Harassment & Cyber stalking : Cyber Stalking Means following an
individual's activity over internet. It can be done with the help of many
protocols available such as e- mail, chat rooms, user net groups.
Categories of Cyber Crime
Against Property
(i) Credit Card Fraud : As the name suggests, this is a fraud that
happens by the use of a credit card.
This generally happens if someone gets to know the card number or
the card gets stolen.
(ii) Intellectual Property crimes : These include Software piracy:
Illegal copying of programs, distribution of copies of software.
Copyright infringement: Using copyrighted material without proper
permission.
Trademarks violations: Using trademarks and associated rights
without permission of the actual holder.
Theft of computer source code: Stealing, destroying or misusing the source
code of a computer. (iii) Internet time theft : This happens by the usage of the
Internet hours by an unauthorized person which is actually paid by another
person.
Categories of Cyber Crime
Against Organizations
(i) Unauthorized Accessing of Computer: Accessing the
computer/network without permission from the owner.
It can be of 2 forms: a) Changing/deleting data: Unauthorized changing of data. b)
Computer voyeur: The criminal reads or copies confidential or proprietary information,
but the data is neither deleted nor changed.
(ii) Denial Of Service : When Internet server is flooded with continuous bogus
requests so as to denying legitimate users to use the server or to crash the server.
(iii) Computer contamination / Virus attack : A computer virus is a computer program
that can infect other computer programs by modifying them in such a way as to include a
(possibly evolved) copy of it.
Viruses can be file infecting or affecting boot sector of the computer.
Worms, unlike viruses do not need the host to attach themselves to.
Categories of Cyber Crime
Against Society
(i) Forgery : Currency notes, revenue stamps, mark
sheets etc. can be forged using computers and high
quality scanners and printers.
(ii) Cyber Terrorism : Use of computer resources to
intimidate or coerce people and carry out the activities of
terrorism.
(iii) Web Jacking : Hackers gain access and control over
the website of another, even they change the content of
website for fulfilling political objective or for money.
PROPERTY CYBER CRIME
CyberCrime Against Property–
This type of cybercrime against property employs
cyber vandalism, in which hackers utilize
software to access sensitive data and company
websites in order to steal the information of other
firms or bank details.
Crimes involving intellectual property, such as
copyright, patents, and trademarks, are a form of
property crime.
What are the ways in which a cybercrime against property can be committed
There are some ways in which a cybercrime against property can be committed.
Credit Card Fraud: As the name implies, this type of cybercrime against property fraud occurs when a credit
card is used. This typically occurs if the card is stolen or someone learns the card number. Intellectual
property offenses
Software piracy is another type of cybercrime against property which includes the illegal distribution of
copies of software and the copying of programs. There are three types of software piracy that constitute a
cybercrime against property.
End-User piracy- End-user piracy is the illegal duplication of licensed software, or to put it another
way, it’s the creation of counterfeit versions of the original software.
installing software on several computers using a single licensed copy of the program.
Internet Download -When software is downloaded illegally through the internet rather than being legally
purchased, the practice is known as internet piracy. The software can be downloaded through the internet
in a variety of ways. websites offering software downloads for free, in exchange for something, or for a
very low cost.
Peer-to-peer networks make it possible to download illegally obtained software.
Disk loading– This type of cybercrime against property typically occurs when a computer retailer sells a
brand-new computer with pirated software already installed. In India, it is fairly typical for customers to
request that the shop owners install a large amount of software when they purchase a new computer.
Counterfeit software– Counterfeit Software is another type of cybercrime against
property where Program counterfeiters manufacture unauthorized copies of the
software and sell it to consumers who mistakenly think they are purchasing the
original.
Since counterfeit software also comes in attractive packaging and with helpful
manuals, it can be very challenging to tell the difference between the two.
When a consumer tries to register for the program online but is unable to, they
discover that the product is not an authentic copy.
Copyright infringement is one of the biggest types of cyber crime against property
where the use of protected content without the required authorization.
The use of trademarks and related rights without the owner’s consent constitutes
a trademark violation.
Theft of computer source code refers to stealing, erasing, or improperly using a
computer’s source code.
Internet time theft is a type of cybercrime against property that occurs when
someone uses the hours allotted for using the Internet but is actually being paid by
someone else.
UNIT – II
Cyber Crime Issues:
Unauthorized Access to Computers,
Computer Intrusions,
White collar Crimes,
Viruses and Malicious Code,
Internet Hacking and Cracking,
Virus Attacks, Pornography,
Software Piracy,
Intellectual Property,
Mail Bombs, Exploitation,
Stalking and Obscenity in Internet.
Unauthorized Access to Computers
What is Unauthorized Access?
On our desktops and personal computers, we use passwords to ensure that no one else may
access our information without our consent. Basically, we want to keep illegal people out.
While the term "hacking" is commonly used to describe this criminal behaviour, it is
important to stress that it is not confined to physical access. Without your consent, someone
might be hundreds of miles away and yet have access to your files and your data.
The majority of users want to take precautions to prevent unauthorized access to their
computers.
Having a secure computer can bring peace of mind, whether it is to protect yourself from
viruses or to keep your private information safe. The parts that follow go over a variety of
techniques to protect your computer against intruders.
To continue, go through each part or pick one that interests you from the list below.
Unauthorized Access to Computers
Common Causes of Unauthorized Access
It takes time to gain access to our information and
data.
Either our inexperience or the hacker's superior
talents are to blame. Standard methods, on the other
hand, may result in a system being hacked, which is
simply preventable.
Unauthorized Access to Computers
Weak Passwords
A weak password is the best present you can give to a
hacker.
To safeguard the data and information we have access to, we
all have passwords for numerous accounts and devices.
Not all passwords, however, will pass the strong security
test.
Some of them are either fail to ensure our systems' security or
overly predictable.
While we all want to keep illegal computer access to a
minimum, the password we select must be both unique and
powerful, which is difficult to break by someone easily.
Unauthorized Access to Computers
What Makes Up A Weak Password?
A password should be one-of-a-kind and extremely tough to figure out.
The majority of individuals, on the other hand, do not have a strong password.
Phone numbers, pet names, date of birth, and the names of townspeople live in end
up being used as passwords, which lead to creating a weak password.
Weak passwords, in most scenarios, are usually made up of mere letters,
making them relatively easy to guess.
The majority of the time, a person's fundamental knowledge is sufficient to help
them guess passwords.
Actually, we all make passwords that are simple to remember the majority
of the time.
However, this should not come at the price of your secret information. Setting up
a password policy and ensuring that every employee follows it is the best approach
for organizations to prevent all of these issues.
Unauthorized Access to Computers
Social Engineering Attacks-Phishing
Sometimes you would have received promotional text messages or emails in order to ask you
to complete a form or click on a specific link. This form can have fields to enter your personal
information.
They look to be genuine emails from reputable sources at first sight. These emails, on the
other hand, are sent by hackers who are attempting to dupe you into disclosing sensitive
information.
Phishing is a term used to describe this type of deception.
Phishing is a method of obtaining confidential information through the use of
direct messages, social media, or emails.
The majority of the time, phishes will email malicious URLs to firm personnel and wait for
them to give up their personal information.
While you may unintentionally open the fake emails, you may not be aware that they
contain a virus.
The goal is to get malware onto your device and deceive you into giving over your
passwords as well as financial information.
Additionally, to safeguard your devices and data, you can always use an access
management software like Team stack.
Unauthorized Access to Computers
Insider Threats
Post-it notes are one of the most frequent methods in
terms of storing passwords.
To begin with, that is the most careless way in order to
store a person's passwords.
Surprisingly, some organizations haven't made
cybersecurity investments as they do not value their
data.
It is not the best way to keep track of your password;
even it is a careless way of password management.
It implies that anyone with access to your records
could utilize them for their own personal benefits.
Computer Intrusion
What is PC (Personal Computer) Intrusion?
When someone tries to access any part of our personal computer system then PC
intrusion occurs. Every Personal Computer (PC) which is connected to the internet
is a target of hackers and cybercriminals.
There are several ways an intruder can try to gain access to your computer. They can :
Access your computer to view, change, or delete information from your computer:
Once the attacker got access to the computer, initially attacker will attempt to view
the information, if the information is valuable attacker may sell the collection
information to gain financial benefits. An attacker may delete or change
information if the objective of the attack is to distract the smooth functionality of
computer.
Computer Intrusion
Crash or slow down your computer: The system may get crash if the attacker deletes
system files, bootstrap loader file, bootstrap loader file is responsible to load the
operating system. System performance may get slow if the system file is deleted
or modified.
Access your private data by examining the files on your system: Once the attacker
got access to the system, he may access private or sensitive data of the system. After
analysis of this data, an attacker may get valuable information that may be misused
or sold to a third party for financial gain.
Use your computer to access other computers on the Internet User’s computer is
connected in network, if the attacker got access user’s system. He may use the
user machine to get access to another network machine by executing various
commands such as ping, traceroute, dig, etc.
Computer Intrusion
Computer Intrusion
Personal Computer Intrusion can occur in any of the
following forms:
Sweeper Attack: Cybercriminals erase all the
information or data like cache, cookies, internet history,
or documents from the system by a malicious program.
Denial of Services: DDOS type of attack in which
attackers may shut down the PC services making it
irascible to its original user. All the system applications
and stored resources come to a halt.
Computer Intrusion
Computer Intrusion
Password Guessing
Most hackers crack passwords of system accounts
by guessing and gaining remote entry into our
personal computer system. Hackers can use this
form and may damage the security system in our
PC.
Computer Intrusion
Computer Intrusion
Snooping:
Snooping refers to opening and looking through files in an unauthorized
manner. Snooping may involve many types of things such as gaining
access to data in an unauthorized way, casually observing someone else’s
email, or monitoring the activity of
someone else’s computer through sophisticated snooping software.
It involves monitoring keystrokes pressed on the keyboard, capturing of
passwords and login information, interception of emails and other
private communication, and data transmission.
Eavesdropping:
When cyber vandals or attackers listen to a conversation that is traveling
over devices like computers, servers, or other network devices, it is
called eavesdropping.
White collar Crimes
What Is White-Collar Crime?
White-collar crime is a nonviolent crime often characterized
by deceit or concealment to obtain or avoid losing money or
property, or to gain a personal or business advantage.
Examples of white-collar crimes include securities fraud,
embezzlement, corporate fraud, and money laundering.
Entities that investigate white-collar crime include
the Securities and Exchange Commission (SEC),
the Financial Industry Regulatory Authority (FINRA), the
Federal Bureau of Investigation (FBI), and state authorities.
White collar Crimes
Understanding White-Collar Crime
"White-collar crime" is a term first coined by sociologist Edwin Sutherland in 1939
who defined it as a crime committed by a person of respectability and high social
status during his occupation. White-collar workers historically held non-laboring
office positions while blue-collar workers traditionally wore blue shirts and worked
in plants, mills, and factories.1
High-profile individuals convicted of white-collar crimes include Ivan Boesky,
Bernard Ebbers, Michael Milken, and Bernie Madoff. Their crimes have included
insider trading, accounting scandals, securities fraud,
and Ponzi schemes.
Rampant new white-collar crimes facilitated by the Internet include so- called
Nigerian scams, in which fraudulent emails request help in forwarding a
substantial amount of money to a criminal ring. Other common white-collar
crimes include tunneling, insurance fraud, and identity theft.
White collar Crimes
• KEY TAKEAWAYS
White-collar crime is a nonviolent crime of deceit or
concealment to obtain or avoid losing money or to
gain a personal or business advantage.
Securities fraud, embezzlement, corporate fraud, and
money laundering are white-collar crimes.
The Securities and Exchange Commission (SEC), the
Financial Industry Regulatory Authority (FINRA), the
Federal Bureau of Investigation (FBI), and state
authorities investigate white-collar crime.
Viruses and Malicious Code
Virus :
A virus is a malicious executable code attached to
another executable file which can be harmless or can
modify or delete data.
Resident and Non -resident viruses are two types of
Virus.
Antivirus software are used for protection against
viruses.
Virus is a type of Malware.
Viruses and Malicious Code
Malicious Code:
Malicious code is harmful computer programming
scripts designed to create or exploit system
vulnerabilities.
This code is designed by a threat actor to cause
unwanted changes, damage, or ongoing access to
computer systems.
Malicious code may result in back doors, security
breaches, information and data theft, and other
potential damages to files and computing systems.
Viruses and Malicious Code
What is malicious code?
Malicious code is the language hostile parties “speak” to manipulate computer systems into dangerous
behaviors. It is created by writing changes or add-ons to the existing programming of computer
programs, files, and infrastructure.
This threat is the foundational tool used to carry out the vast majority of cybersecurity attacks. Hackers
probe and find weaknesses that are based on the languages used to program computers. They then create
“phrases” known as scripts or lists of commands to abuse these vulnerabilities in these languages. These
scripts can be re-used and automated via macroinstructions, or macros for short.
Hackers and other threat actors would move very slowly if they were restricted to manual methods of
exploiting computer systems. Unfortunately, malicious code allows them to automate their attacks.
Some codes can even replicate, spread, and cause damage on their own. Other types of code may need
human users to download or interact with it.
The consequences of malicious code may often lead to any of the following:
Corruption of data
Distributed denial-of-Service (DDoS)
Credential theft and private info theft
Ransom and extortion
Nuisance and inconvenience
To help you protect yourself, let’s explore how these threats work.
Viruses and Malicious Code
How does a malicious code work?
Any programmed component of a computer system can be manipulated by malicious code. Large- scale
components such as computer networking infrastructure and smaller components like mobile or desktop
apps are all common targets.
Web services, such as websites and online servers, can also be targets. Malicious code can infect any
device using a computer to operate, such as:
Traditional computer devices — desktops, laptops, mobile phones, tablets.
IoT devices — smart home devices, in-vehicle infotainment systems (IVI).
Computer network devices — modems, routers, servers.
Attackers use malicious scripts and programs to breach trusted parts of computer systems. From
this point, they aim to do one or more of the following:
Expose users to malicious code, to infect them and spread it further.
Access private information on the breached systems.
Monitor the use of a breached system.
Breach deeper into a system.
Malicious code is created and used in a few distinct phases.
The malicious scripted code may need human interaction or other computer actions to trigger the
next event at each stage.
Notably, some code can even operate entirely autonomously. Most malicious code follows this
structure.
Viruses and Malicious Code
Probe and investigate for vulnerabilities.
Program by writing code to exploit vulnerabilities.
Expose computer systems to malicious code.
Execute the code through a related program or on its own.
Probing and programming are the setup phase of an attack. Before an attacker can breach a
system, they must first have the tools to break in.
They'll need to make the code if it doesn't already exist but may also use or modify existing
malicious code to prepare their attack.
The result of malicious scripting is either an auto-executable application that can activate itself and
take various forms.
Some may include macros and scripts in JavaScript, ActiveX controls, Power shell misuse, pushed
content, plug-ins, scripting languages, or other programming languages that are designed to enhance
Web pages and email.
Exposing computer systems may occur through direct interface ports like USB or online network
connections like mobile and Wi-Fi. Successful exposure only requires a way for the malicious code to
travel to your machine.
Exposure in widespread attacks relies on high-contact channels such as popular websites and email spam,
while more targeted efforts use social engineering methods like spear phishing. Some insider efforts can
even plant malicious code into a private network like a corporate intranet by direct USB drive connection
on a local end-user computer.
Viruses and Malicious Code
Execution occurs when an exposed system is compatible with the
malicious code.
Once a targeted device or system is exposed to malicious code, the resulting
attack may include unauthorized attempts of any of the following:
Modify data — unpermitted encryption, weaken security, etc.
Delete or corrupt data — website servers, etc.
Obtain data — account credentials, personal information, etc.
Access to restricted systems — private networks, email accounts, etc.
Executing actions — replicating itself, spreading malicious code,
remote device control, etc.
Viruses and Malicious Code
How does malicious code spread?
Malicious code may be used to breach systems on its own, enable secondary
malicious activity, or to replicate and spread itself. In any case, the original code
must move from one device to another.
These threats can spread over nearly any communications channel that transmits
data. Often, the vectors of spread include:
Online networks — intranets, P2P file-sharing, public internet websites, etc.
Social communications — email, SMS, push content, mobile messaging apps, etc.
Wireless connectivity — Bluetooth, etc.
Direct device interfaces — USB, etc.
Visiting infected websites or clicking on a bad email link or attachment are standard
gateways for malicious code to sneak its way into your system. However, this threat
can enter from legitimate sources as well as explicitly malicious ones. Anything
from public USB charging stations to exploited software update tools has been
misused for these purposes.
The “packaging” of malicious code isn’t always obvious, but public data
connections and any messaging service are the most important paths to watch.
Downloads and URL links are often used by attackers to embed dangerous code.
Viruses and Malicious Code
Types of malicious code
Many malicious code types can harm your computer by finding entry points that lead to your precious
data. Among the ever-growing list, here are some common culprits.
Viruses
Viruses are self-replicating malicious code that attaches to macro-enabled programs to execute. These files travel via
documents and other file downloads, allowing the virus to infiltrate your device. Once the virus executes, it can self-
propagate and spread through the system and connected networks.
Worms
Worms are also self-replicating and self-spreading code like viruses but do not require any further action to do so. Once a
computer worm has arrived on your device, these malicious threats can execute entirely on their own — without any assistance
from a user-run program.
Trojans
Trojans are decoy files that carry malicious code payloads, requiring a user to use the file or program to execute. These
threats cannot self-replicate or spread autonomously. However, their malicious payload could contain viruses, worms, or
any other code.
Cross-site scripting (XSS)
Cross-site scripting interferes with the user’s web browsing by injecting malicious commands into the web applications they
may use. This often changes web content, intercepts confidential information, or serves an infection to the user’s device itself.
Backdoor attacks
Application backdoor access can be coded to give a cybercriminal remote access to the compromised system. Aside from
exposing sensitive data, such as private company information, a backdoor can allow an attacker to become an advanced
persistent threat (APT).
Cybercriminals can then move laterally through their newly obtained access level, wipe out a computer's data, or even
install spyware. These threats can reach a high level: The U.S. Government Accountability Office has even warned about
the threat of malicious code against national security.
Viruses and Malicious Code
Examples of malicious code attacks
Malicious code can come in many forms and has been very active in the past. Among the
instances of these attacks, here are a few of the most well-known:
Emotet trojan
First appearing in 2014, the Emotet trojan evolved from its malware roots to become email
spam laden with malicious code. The attackers use phishing tactics like urgent email subject
lines (ex: "Payment Needed") to fool users into downloads.
Once on a device, Emotet has been known to run scripts that deliver viruses, install
command and control (C&C) malware for botnet recruitment, and more. This threat took a
short break in 2018 before returning to become an SMS malware threat in the process.
Stuxnet worm
Since 2010, the Stuxnet computer worm and its successors have been targeting national
infrastructure. Its first documented attack involved Iranian nuclear facilities via USB flash
drive, destroying critical equipment. Stuxnet has since ceased, but its source code has been
used to create similar highly targeted attacks through 2018.
Viruses and Malicious Code
How to protect against malicious code attacks
For most malicious threats, antivirus software with automatic updates,
malware removal capabilities, web-browsing security is the best defense.
However, preventing malicious code may not be possible with antivirus
software on its own.
Antivirus typically prevents and removes viruses and other forms of
malware — or malicious software — is a subcategory of malicious code.
The broader category of malicious code includes website scripts that can
exploit vulnerabilities to upload malware.
By definition, not all antivirus protection can treat certain
infections or actions caused by malicious code.
While antivirus is still essential for proactive infection removal and
defense, here are some valuable ways to protect yourself.
Viruses and Malicious Code
Install anti-scripting software to prevent JavaScript and related code from running
unauthorized.
Exercise caution against links and attachments. Any message containing URL links or
attachments — whether by email or text message — can be a vector for malicious code.
Activate your browser’s popup blocker to prevent scripts from serving malicious content
in unwanted browser windows.
Avoid using admin-level accounts for daily use. High-level permissions are usually
required to run scripts and programs automatically.
Utilize data backups to protect irreplaceable files and documents.
Be wary of using any public data connection. USB connections are generally overlooked
but can easily harbor malicious code. Public Wi-Fi is also a common threat that attackers
can use to deliver malicious code.
Use a properly configured firewall to block unauthorized connections. If malicious code
infiltrates your machine and connects outward to request malware payloads, a firewall can help
stop this. Be sure that your firewall is configured to block by default and white list any expected
and trusted connections.
Internet Hacking and Cracking
Hacking vs Cracking
To understand the difference between hacking and cracking, you
have to know what hacking is in the first place.
Hacking is the act of compromising digital devices to gain unauthorized
access. Although the media commonly uses the term “hacking” to refer to
illegal activities, people in the hacking community generally consider
themselves the good guys, while crackers are the bad guys.
This is because, in the hacking community, the goal of hacking is to
improve or alter security systems and programs.
Internet Hacking and Cracking
For example, many companies hire white hat hackers to
check their security systems and make them as hack- proof
as possible.
Cracking, on the other hand, is any kind of hacking
that’s done for personal gain or other malicious
reasons.
Crackers, also referred to as black hat hackers, might take
control over a system to destroy or steal information for
profit, attempt to scam people, or just cause damage for
the sake of it.
Virus Attacks
12 common types of malware attacks and how to
prevent them
Malware is one of the greatest security threats
enterprises face.
Security departments must actively monitor
networks to catch and contain malware before it can
cause extensive damage.
With malware, however, prevention is key. But to
prevent an attack, it is critical to first understand what
malware is, along with the most common types of
malware.
Virus Attacks
• Attackers use malware, short for malicious software, to intentionally harm and infect
devices and networks. The umbrella term encompasses many subcategories,
including the following:
• Viruses.
• Worms.
• Ransomware.
• Bots.
• Trojan horses.
• Keyloggers.
• Rootkits.
• Spyware.
• Fileless malware.
• Cryptojacking.
• Wiper malware.
• Adware.
Virus Attacks
Virus Attacks
• 1. Viruses
A computer virus infects devices and replicates itself across
systems. Viruses require human intervention to propagate.
Once users download the malicious code onto their devices
-- often delivered via malicious advertisements or phishing
emails -- the virus spreads throughout their systems.
Viruses can modify computer functions and applications;
copy, delete and exfiltrate data; encrypt data to perform
ransomware attacks; and carry out DDoS attacks.
Virus Attacks
Virus Attacks
The Zeus virus, first detected in 2006, is still used by
threat actors today. Attackers use it to create botnets
and as a banking Trojan to steal victims' financial data.
Zeus's creators released the malware's source code in
2011, enabling threat actors to create updated and
more threatening versions of the original virus.
Virus Attacks
Worms
A computer worm self-replicates and infects other computers
without human intervention. This malware inserts itself in
devices via security vulnerabilities or malicious links or files.
Once inside, worms look for networked devices to attack.
Worms often go unnoticed by users, usually disguised as
legitimate work files.
WannaCry, also a form of ransomware, is one of the most
well-known worms. The malware took advantage of the
EternalBlue vulnerability in outdated versions of Windows'
Server Message Block protocol. In its first year, the worm
spread to 150 countries. The next year, it infected nearly 5
million devices.
Virus Attacks
Virus Attacks
Ransomware
Ransomware locks or encrypts files or devices and forces victims to pay a ransom in exchange
for reentry. While ransomware and malware are often used synonymously, ransomware is a
specific form of malware.
Common types of ransomware include the following:
Locker ransomware completely locks users out of their devices.
Crypto ransomware encrypts all or some files on a device.
Extortionware involves attackers stealing data and threatening to publish it unless
a ransom is paid.
Double extortion ransomware encrypts and exports users' files. This way, attackers can
potentially receive payments from the ransom and/or the selling of the stolen data.
Triple extortion ransomware adds a third layer to a double extortion attack, for example,
a DDoS attack, to demand a potentially third payment.
Ransomware as a service, also known as RaaS, enables affiliates or customers to rent
ransomware. In this subscription model, the ransomware developer receives a percentage of
each ransom paid.
Virus Attacks
Bots
A bot is a self-replicating malware that spreads itself to other
devices, creating a network of bots, or a botnet. Once infected,
devices perform automated tasks commanded by the attacker.
Botnets are often used in DDoS attacks. They can also conduct
keylogging and send phishing emails.
Mirai is a classic example of a botnet. This malware, which
launched a massive DDoS attack in 2016, continues to target IoT
and other devices today. Research also shows botnets flourished
during the COVID-19 pandemic. Infected consumer devices --
common targets of Mirai and other botnets -- used by employees
for work or on the networks of employees working on company-
owned devices from home enable the malware to spread to
corporate systems.
Virus Attacks
Trojan horses
A Trojan horse is malicious software that appears legitimate to users.
Trojans rely on social engineering techniques to invade devices. Once inside
a device, the Trojan's payload -- malicious code
-- is installed to facilitate the exploit. Trojans give attackers backdoor access
to a device, perform keylogging, install viruses or worms, and steal data.
Remote access Trojans (RATs) enable attackers to take control of an
infected device. Once inside, attackers can use the infected device to infect
other devices with the RAT and create a botnet.
An example of a Trojan is Emotet, first discovered in 2014. Despite a global
takedown at the beginning of 2021, attackers have rebuilt Emotet and it
continues to help threat actors steal victims' financial information.
Virus Attacks
Keyloggers
A keylogger is surveillance malware that monitors keystroke patterns. Threat actors
use keyloggers to obtain victims' usernames and passwords and other sensitive data.
Keyloggers can be hardware or software. Hardware keyloggers are manually installed
into keyboards. After a victim uses the keyboard, the attacker must physically retrieve
the device. Software keyloggers, on the other hand, do not require physical access.
They are often downloaded by victims via malicious links or attachments. Software
keyloggers record keystrokes and upload the data to the attacker.
The Agent Tesla keylogger first emerged in 2014. The spyware RAT still plagues
users, with its latest versions not only logging keystrokes, but also taking screenshots
of victims' devices.
Password managers help prevent keylogger attacks because users don't need to
physically fill in their usernames and passwords, thus preventing a keylogger from
recording them.
Virus Attacks
Rootkits
A rootkit is malicious software that enables threat actors to remotely access and
control a device. Rootkits facilitate the spread of other types of malware, including
ransomware, viruses and keyloggers.
Rootkits often go undetected, because once inside a device, they can deactivate
antimalware and antivirus software. Rootkits typically enter devices and systems
through phishing emails and malicious attachments.
To detect rootkit attacks, cybersecurity teams should analyze network behavior.
Set alerts, for example, if a user who routinely logs on at the same time and in
the same location every day suddenly logs on at a different time or location.
The first rootkit, NTRootkit, appeared in 1999. Hacker Defender, one of the most
widely deployed rootkits of the 2000s, was released in 2003.
Virus Attacks
Spyware
Spyware is malware that downloads onto a device without the user's knowledge. It
steals users' data to sell to advertisers and external users. Spyware can track
credentials and obtain bank details and other sensitive data. It infects devices through
malicious apps, links, websites and email attachments. Mobile device spyware,
which can spread via Short Message Service and Multimedia Messaging Service, is
particularly damaging because it tracks a user's location and has access to the
device's camera and microphone. Adware, keyloggers, Trojans and mobile spyware
are all forms of spyware.
Pegasus is a mobile spyware that targets iOS and Android devices. It was first
discovered in 2016, at which time it was linked to Israeli technology vendor NSO
Group.
Virus Attacks
Fileless malware
Fileless malware, unlike traditional malware, does not involve
attackers installing code on victims' hard drives. Rather, it
uses living-off-the-land techniques to take advantage of legitimate and
presumably safe tools -- including PowerShell, Microsoft macros and
Windows Management Infrastructure -- to infect a victims' systems. Fileless
malware resides in computer memory.
Without an executable, it can evade file- and signature-based
detection tools, such as antivirus and antimalware.
Virus Attacks
Note that fileless malware might indeed have files, but the attacks leave no
files behind after completing the attack, making attribution difficult.
Frodo, Emotet and Sorebrect are examples of fileless malware.
Virus Attacks
Cryptojacking
Cryptomining -- the process of verifying transactions within a
blockchain -- is highly profitable but requires immense
processing power. Miners are rewarded for each blockchain
transaction they validate. Malicious cryptomining, known as
cryptojacking, enables threat actors to use an infected device's
resources -- including electricity and computing power -- to
conduct verification. This can lead to performance degradation
of the infected device and loss of money due to stolen resources.
Coinhive, Vivin, XMRig Lucifer, WannaMine and RubyMiner
are examples of cryptomining malware.
Virus Attacks
Wiper malware
Also known as wiperware or data wipers, this malware is
often categorized as a type of ransomware. Like ransomware,
its aim is to block access to the victim's data.
Unlike ransomware, it destroys the data rather than hold it for
a ransom.
The aim of wiper malware attacks is not financial gain, but to
erase data.
Malicious actors often use wiper malware to cover their
tracks after an attack.
NotPetya, Azov, HermeticWiper and WhisperGate are
examples of wiper malware.
Pornography
Cyber crime is a very wide term which involves offences related to computers or the
computer networks for the purpose of communication and to transfer the information
to another person in a very short span of time.
The use of internet and computers are getting people more closure in the modern
society for business and e-commerce purposes, hence we understand that there are
much advantages for the use of computers and internet and our society cannot even
function properly without them.
Cyber crime is defined as a crime in which a computer is the object of the crime
(hacking, phishing, spamming) or is used as a tool to commit an offense (child
pornography, hate crimes).
Pornography
Cyber criminals may use computer technology to access personal information,
business trade secrets or use the internet for exploitative or malicious purposes.
Criminals can also use computers for communication and document or data storage.
Criminals who perform these illegal activities are often referred to as hackers. Cyber
crime may also be referred to as computer crime.
Internet gives the facility to the people to connect world wide i.e to communicate
with any person irrespective of any place, time. the internet and the computers does
not bound any person with the territorial limits and gives the access to any person in
any of the jurisdiction. It enables the people to come up and share their new ideas,
views and take knowledge about anything they wish to know.
Pornography
The way in which people share their ideas, communicate, do online
transactions is one of the big reason that internet will continue to contour
the world. These kind of freedom also enables the computer experts to
indulge into other unlawful cyber criminal activities such as hacking,
bugging, cheating, fraud, etc.
With the regular use of internet in mold of websites and blogging, people
engage themselves in chatting on the internet without knowing the other
[Link] are many elements that have given birth to the sources
concerning about the society where the Pornography has been the major
issue in the society.
Pornography
Porn today is more freely and widely available on Internet than ever
before. Younger generation is
therefore able to access it very easily and quickly than ever.
This leads to the mentality of unemotional sex.
And all this is because we have grown up in a culture where parents feel
embarrassed, they are not comfortable to have a healthy conversation about
sex with their children.
Well then it’s time to open up and come out of our comfort zone to talk
about the most hush-
hush topic i.e. Pornography.
Pornography
According to City of Youngstown v. DeLoreto (USA , 1969) Pornography is the portrayal of
erotic behavior designed to cause sexual excitement. It is words, acts, or representations that
are calculated to stimulate sex feelings independent of the presence of another loved and
chosen human being.
It is divorced from reality in its sole purpose to stimulate erotic response.
It is preoccupied with and concentrates on sex organs for the purpose of sexual stimulation. It
emphasizes them and focuses on them in varying ways calculated to incite sexual desire.
The term Pornography refers to any work or art or form dealing with sex or sexual themes. It
involves images , videos of both man and woman involved in sexual activities and is
accessible on internet world wide.
Pornography has been defined as the sexual explicit depiction of persons, in words or images,
created with the primary, proximate aim and reasonable hope, of eliciting significant sexual
arousal on the part of the consumer of such material.
Pornography
There has not been only a single definition of the law of the word pornography applied all over the world.
The pornography or the pornographic material varies according to the vision and understanding of the
people of different culture across the world and it has been a difficult task to define the material/content to
be a pornographic content/material.
Basically pornography is nothing but marketing of man or woman sex, shown as object for those who get
involved into sexual acts.
Pornographers use the internet to sell their material to sex addicts and to the interested parties. Watching
and keeping of these kind of materials is illegal in India.
Nowadays pornography has become a kind of a business to the society as people indulge
themselves to gain the economical benefits from them.
They even put the hidden cameras and violates the privacy of the society ex: hotels , paying guest , hostels ,
changing rooms in shopping complex etc.
It has been a market for near about $1 trillion. Pornography has been in existence since the pre- historic
time as it was seen in the painting or rock arts.
Therefore, with emerging of time, there was invention of photography which gave rise to
pornography.
The world's first law criminalizing pornography was the English Obscene Publications Act 1857.
Software Piracy Intellectual
• What is Software Piracy?
Software Piracy is the illegal approach of copying,
distributing, modifying, selling, or using software that
is legally protected.
So in a simple term, we can say Software piracy is the
act of stealing legal software.
This software piracy refers to the unauthorized
copy and use of legal software and now this
critical problem has turned into a global issue.
Software Piracy Intellectual
Regulation for Software Piracy
Software piracy is illegal and there are strict laws for
these illegal activities. So monetary penalties are also
there for this lawbreaker who breaks these copyright laws
and creates copyright violations. End-User License
Agreement(EULA) is a license agreement that is mostly
used for software to protect its legality.
It is a contract between the manufacturer and the
end-user.
This rule defines the rules for legal software. One
common rule in EULA is that it prevents the user from
sharing the software with others.
Software Piracy Intellectual
Types of Software Piracy
Softlifting- Softlifting is the most common type of software piracy. In this piracy, the legal owner of the
software is one, but the users are multiple. For instance, someone purchases genuine software, and others will
illegally use that software by downloading the software to their computer. For example, many times we
borrow software from our colleagues and install a copy of that on our computers just to save money which
rises to softlifting one type of software piracy.
Hard-disk Loading- It is the most common type of software piracy which mainly happens in PC resell
shops. The shop owner buys a legal copy of the software and reproduces its copies on multiple computers
by installing it. Most of the time customers/PC users are not aware of these things and get the pirated version
of the software in the original S/W price or less than the original price. It is one type of Commercial software
piracy.
Counterfeiting- In counterfeiting the duplicates are created of genuine/legal software programs with the
appearance of authenticity. Then these duplicate software are sold out at a lower price.
Client-Server overuse – In client-server overuse, more copies of the software are installed than it has
licensed for. Mainly it is seen in local business sectors when they work under a local area n/w and install
the software in all the computers for use by many employees which is an unauthorized practice.
Online Piracy- In online piracy, the illegal software is acquired from online auction sites and blogs which
is mainly achieved through the P2P(Peer to Peer) file-sharing system. As it is acquired using the Internet,
often it is called Internet Piracy.
Software Piracy Intellectual
• What Are the Effects of Software Piracy?
Revenue Loss: Significant revenue losses for software
developers and companies.
Reduced Investment: Less investment in new product
development, research, and innovation
Malware and Viruses: Increased risk of malware, viruses,
and other malicious code.
Lack of Support: No access to official customer support,
leading to technical difficulties and reduced productivity.
Compatibility Issues: Potential incompatibility with other
software or hardware, causing operational inefficiencies.
Software Piracy Intellectual
How to Prevent Software Piracy?
Implement Digital Rights Management
technology.
Integrate anti-tamper mechanisms
Regularly updates the software.
Use software license management tools
Using the updated Wi-Fi security protocols.
Reporting malicious software
Software Piracy Intellectual
Examples of Software Piracy
Using cracked or pirated software obtained from unauthorized
websites.
Using license key cracking tools to illegally activate the software.
Sharing software licenses beyond the intended use.
Using a single-user license without legal licensing on several
computers.
Changing software to turn off copy protection mechanisms.
Selling fake software copies.
Unauthorized transmission of confidential software.
Buying software without a valid license key or special permission.
Selling the contents of a software package individually rather than as a
whole.
Software Piracy Intellectual
Software Piracy Drawbacks
Many times it fails or malfunctions.
No warranty on the product as it is acquired
illegally.
Risk of security issues.
No upgrade or improvement in features and
functionality
High risk of virus and malware infection to the
computer.
Software Piracy Intellectual
Conclusion
Software piracy is an important problem that poses serious issues
for software creators and businesses.
It is the unauthorized copying, distribution, or usage of software, which
violates licensing agreements established to protect intellectual property
rights.
Software piracy can take numerous forms, including soft lifting,
hard disc loading, fraud, client-server misuse, and internet piracy.
These illegal activities result in significant financial losses, higher risk
of malware and viruses, a lack of support, and compatibility issues.
Mail Bombs
What is an Email Bomb?
An email bomb is a malicious attempt to flood an
individual's or an organization's email inbox with an
overwhelming number of messages. The goal of these
attacks can range from causing inconvenience and
frustration to crippling email servers and, in some
cases, spreading malware or stealing sensitive
information.
Mail Bombs
What are the dangers of email bombs?
Email bombs can be quite dangerous for both individuals and
organizations. These harmful attacks can flood a target's
inbox and potentially cause it to stop working. Some other
dangers of email bombing are:
It can disrupt communication, slow down work, and even
lead to the loss of important messages.
It can spread harmful software or trick people into revealing
sensitive information, which can put their privacy and security
at risk.
Additionally, the large number of incoming emails can stress
email servers and sometimes lead to extra costs for increasing
server capacity.
Mail Bombs
What are the different types of email bomb
attacks?
Email bombs can take various forms and are a cause
of concern for both individuals and businesses.
Let's take a look at the different types of email
bomb attacks.
Mail Bombs
1. Attachment attack
An attachment attack involves sending emails with large and often malicious
attachments. These attachments can be documents, images, or executable
files that consume substantial server resources when opened. Recipients
may unwittingly open these attachments, leading to malware infection or
system crashes.
2. List-linking attack
In a list-linking attack, attackers exploit mailing lists or group emails. They
send a barrage of messages to a mailing list, causing a domino effect as each
recipient generates more emails in response. This can overwhelm the
intended recipient and the entire mailing list, causing collateral damage.
Mail Bombs
3. Mass mailing attack
A mass mailing attack involves bombarding a single recipient with an
enormous number of emails. Attackers automate this process, often
employing bots or scripts to execute the attack. Mass mailing attacks can
lead to email service disruptions, and the sheer volume of messages can
make it challenging to identify genuine emails from the fake ones.
4. Reply-all attack
The reply-all attack is a particularly notorious type of email bomb. It occurs
when an email is inadvertently sent to a large group, and recipients start
replying to all, creating a never-ending thread. This results in a deluge of
emails that can bring email servers to a grinding halt.
Mail Bombs
5. Zip bomb attack
A zip bomb attack uses compressed files to wreak havoc. Attackers send
an email with a highly compressed, oversized file. When the recipient
attempts to open it, the file expands to an absurdly large size,
overwhelming system resources and potentially causing crashes.
Mail Bombs
How do you defend against email bombs?
Now that we know how critical it is to protect yourself or your
organization from email bomb attacks, let's find out what you can do
to diffuse such a threat. We have multiple strategies that you can
implement to defend against email bombs.
1. Strict security policies and training
Establish and enforce strict security policies for email usage. Train
employees on recognizing phishing emails and suspicious
attachments. Encourage them to report any unusual email activity
promptly.
Mail Bombs
2. Email delivery software with anti-malware features
Invest in email delivery software with robust anti-malware or spam
filters like SpamTitan or Area1. Such softwares can detect and
quarantine malicious attachments, protecting your network from
email bomb threats.
3. Implement CAPTCHA
To prevent automated attacks, consider implementing CAPTCHA
(Completely automated public turing test to tell computers and
humans apart) challenges in your email system. CAPTCHAs require
users to prove they are human by completing tasks that bots can't.
Mail Bombs
This ensures that incoming emails are generated by humans, making it more
challenging for bots to flood your inbox with emails.
4. Use bulk email filters
Implement bulk email filters that identify and divert mass emails into a
separate folder or quarantine. It can help reduce the impact of email bomb
attacks on your inbox.
5. Enable tarpitting
Tarpitting is a method that helps to slow down the speed at which email
connections are approved. When you activate tarpitting, you can stop email
bombs by decreasing the number of incoming messages. Nonetheless, it's
crucial to use this technique carefully to avoid causing difficulties for
legitimate email senders.
Mail Bombs
Takeaway
Email bomb attacks are a constant digital threat today.
Protecting your inbox is vital because these attacks can
harm both individuals and organizations.
Without proper defense, email bombs can disrupt your
email service, introduce malware, and cause considerable
frustration.
So, to safeguard your communication, learn about the
different attack types and put strong defenses in place.
With the right knowledge and precautions, you can avoid
any harmful consequences that might occur.
Exploitation, Stalking and Obscenity in
Internet
In Cyber Stalking, a cyber criminal uses the internet to threaten somebody
consistently. This crime is often done through email, social media, and other online
mediums. Cyber Stalking can even occur in conjunction with the additional ancient
type of stalking, wherever the bad person harasses the victim offline. There’s no
unified legal approach to cyber Stalking, however, several governments have moved
toward creating these practices punishable by law. Social media, blogs, image-
sharing sites, and lots of different ordinarily used online sharing activities offer cyber
Stalkers a wealth of data that helps them arrange their harassment.
It includes actions like false accusations, fraud, information destruction,
threats to life, and manipulation through threats of exposure. It has stalkers
take the assistance of e-mails and other forms of message applications,
messages announced to an online website or a discussion cluster, typically
even social media to send unwanted messages and harass a specific person
with unwanted attention. Cyber Stalking is typically cited as internet
stalking, e-stalking, or online stalking.
What is Cyberstalking?
Cyberstalking is the use of the internet or digital tools to repeatedly harass,
threaten, or stalk someone. It includes sending unwanted messages,
hacking accounts, or spreading lies online. The goal is often to scare or
distress the victim. Cyberstalkers often use social media, email, or other
online platforms. Cyberstalking involves using digital platforms to
intimidate or control someone by continuously monitoring or harassing
them online, they can track
the victim’s online activity.
Cyberstalkers may impersonate their victims, post false information, or
make threatening comments. They often create multiple
accounts to avoid detection and can track the victim’s location or personal
activities using GPS or spyware. Cyberstalking can results into offline
threats and is a serious situation of destruction of privacy which can often
requires legal action to stop. Cyberstalking is harmful and illegal.
Some of the Examples of Cyberstalking are as
follows
Repeated Unwanted Messages
False Profiles
Tracking Online Activity
Hacking Accounts
Posting Private Information
Threatening Comments
Monitoring via GPS or Spyware
Consequences of Cyberstalking
Legal consequences can include fines, restraining orders, or
sentence to imprisonment.
Victims may experience anxiety, depression, and fear which can
affects their mental health.
Public harassment or false information can harm the victim’s
reputation causing reputational damage.
Personal privacy is compromised, making the victim feel vulnerable.
Financial costs may arise from legal fees, security measures, or
identity theft.
Fear of being targeted can lead to social withdrawal and isolation.
Cyberstalking can also escalate to
Types of Cyber Stalking
Webcam Hijacking: Internet stalkers would attempt to trick you into
downloading and putting in a malware-infected file that may grant them
access to your webcam. the method is therefore sneaky in that it’s
probably you wouldn’t suspect anything strange.
Observing location check-ins on social media: In case you’re adding
location check-ins to your Facebook posts, you’re making it overly simple
for an internet stalker to follow you by just looking through your social
media profiles.
Catfishing: Catfishing happens via social media sites, for example,
Facebook, when internet stalkers make counterfeit user-profiles and
approach their victims as a companion of a companions.
Visiting virtually via Google Maps Street View: If a stalker discovers the
victim’s address, then it is not hard to find the area, neighbourhood, and
surroundings by using Street View. Tech-savvy stalkers don’t need that too.
Installing Stalkerware: One more method which is increasing its
popularity is the use of Stalkerware. It is a kind of software or spyware
which keeps track of the location, enable access to text and browsing
history, make an audio recording, etc. And an important thing is that it runs
in the background without any knowledge to the victim.
Looking at geotags to track location: Mostly digital pictures contain
geotags which is having information like the time and location of the picture
when shot in the form of metadata. Geotags comes in the EXIF format
embedded into an image and is readable with the help of special apps. In
this way, the stalker keeps an eye on the victim and gets the information
about their whereabouts.
How to Help Protect Yourself Against Cyberstalking
Develop the habit of logging out of the PC when not in use.
Remove any future events you’re close to attending from the social networks if
they’re recorded on online approaching events and calendars.
Set strong and distinctive passwords for your online accounts.
Cyber Stalkers can exploit the low security of public Wi-Fi networks to snoop on
your online activity. Therefore, avoid sending personal emails or sharing your
sensitive info when connected to an unsecured public Wi-Fi.
Make use of the privacy settings provided by the social networking
sites and keep all info restricted to the nearest of friends.
Do a daily search on the internet to search out what information is accessible
regarding you for the public to check.
How to Report Cyberstalking
To report cyberstalking you must follow such steps:
Document Evidence: Save screenshots, messages, emails, and URLs showing the
harassment.
Block and Report: Immediately block the stalker and report their behavior to the platform
or service.
Contact Authorities: Report the incident to local law enforcement or a cybercrime
department and provide them all of the evidences.
File a Complaint: Contact relevant cybercrime reporting agencies or hotlines, like
the Internet Crime Complaint Center (IC3) or local equivalents.
Inform Your ISP: Notify your internet service provider (ISP) about the
cyberstalking.
Seek Legal Advice: Consult a lawyer to understand your rights and potential legal actions
for the help in the court of law.
Get Support: Reach out to organizations or support groups for help and guidance.
Cyberstalking Laws
In India, cyberstalking and related offenses are covered by laws like the Information
Technology Act, 2000 and the Indian Penal Code. Here are key points:
Identity Theft: It’s illegal to impersonate someone online under Section 66C of the
Information Technology Act.
Obscene Material: Sharing or publishing obscene content online is prohibited by
Section 67 of the Information Technology Act.
Stalking: Section 354D of the Indian Penal Code deals with stalking, including
online stalking where someone follows or monitors another person electronically.
Insulting Modesty: Section 509 of the Indian Penal Code makes it illegal to insult a
person’s modesty, including online harassment.
Threats: Sections 503 and 506 of the Indian Penal Code address criminal
intimidation, including threats made online.
These laws provide legal protection against cyberstalking and allow victims to seek
help and justice through legal channels in India.
Introduction to Cyber Crime
Investigation
Conclusion
Cyberstalking is a serious problem that can deeply affect
targetted victims emotionally and invade their privacy. It
involves ongoing harassment, threats, and monitoring
online, which can sometimes lead to real- life danger.
While dealing with cyberstalking, it requires people to be
aware of it, stay vigilant, and take legal action if needed to
protect themselves and their rights online. By educating
people about the dangers of cyberstalking and promoting
safer internet habits, we can prevent these incidents and
make the online world safer for everyone.
Introduction to Cyber Crime
Investigation
UNIT – III
Investigation: IP Tracking,
Introduction to Cyber E-Mail Recovery,
Crime Investigation, Hands on Case Studies.
Investigation Tools, Encryption and Decryption
eDiscovery, Methods,
Digital Evidence Collection, Search and Seizure of
Evidence Preservation, Computers,
E-Mail Investigation, Recovering Deleted Evidences,
E-Mail Tracking, Password Cracking.
Introduction to Cyber Crime
Investigation
What is Cybercrime Investigation?
Investigating computer crimes is about finding and stopping bad
activities that happen on computers and digital devices. It involves using
special tools and methods to examine crimes like
hacking, phishing, malware, data breaches, and identity theft. The people
who do this job are called computer crime investigators.
They carefully look for evidence that law enforcement can use to
catch the people doing these wrong things.
For individuals and companies, investigating computer crimes is very
important to protect them from increasing threats of these crimes. It also
ensures justice for victims. Investigating these crimes is very important
because they keep evolving and can lead to dangerous consequences for
anyone, including governments and businesses.
Introduction to Cyber Crime
Investigation
Top 5 Cybercrimes
There are many bad things people can do online. Here are the top 5 cybercrimes that
companies and people need to know about.
1. Phishing and Scams: Some people with malicious intent send counterfeit messages or
emails to misguide you into giving them your private information or downloading malware
on your computer.
2. Stealing Someone’s Identity: Criminals use somebody else’s details such as
credit card numbers, and photos without permission to undertake illegal activities.
3. Ransomware Attacks: It is when bad software locks your files and data on a
computer, the criminals demand money before they unlock your files.
4. Hacking and Misusing Computer Networks: This occurs when someone gains
unauthorized access to private computers or networks and tampers with them or steals data.
5. Internet Fraud: All the wrong things that people do while on the internet including
sending spam, and stealing from banks, among other unlawful actions fall under it.
Introduction to Cyber Crime
Investigation
Types of Cyber Criminals
There are different kinds of bad people who do cybercrime. Here are five types of them.
1. Hackers: These persons are computer experts who penetrate unauthorized systems by
stealing information or causing damage. While some hack for money, others do it to
practice their ability or out of conviction.
2. Insiders: These could either be actual staff or non-full-time workers who gain more
rights on a company’s network than required, and use these illicitly to steal data, vandalize
things, and perpetrate other illegal acts.
3. Crime Groups: This refers to gangs that engage in cybercrimes for financial gain and can
be very adept at hiding.
4. Government-Sponsored: Attacking one nation’s computing infrastructure as a way to
obtain secret data, hamper their operations, or get an upper hand is currently being done by
several states.
5. Cyberterrorists: These individuals or groups initiate such attacks via the internet for
reasons of political backlash towards society. Often there are political motivations behind the
actions of many such people.
Introduction to Cyber Crime
Investigation
How to Become a Cyber Crime Investigator?
Get the Right Education: Take classes about computers, cybersecurity, or related topics.
Some colleges have special programs to teach you the skills that are needed for investigating
computer crimes.
Develop Important Skills: You need technical skills like understanding computers and
networks. You also need skills like thinking critically and working well under pressure.
Take courses, get certifications, and learn on the job.
Gain Experience: Try to get internships, volunteer work, or entry-level jobs in
cybersecurity or computer forensics. Look for chances to work with police, government
agencies, or cybersecurity companies.
Keep Learning: Computer crimes are always changing, so you need to stay updated on new
threats and technologies. Attend conferences, read industry news, and join online groups.
Certifications: Getting certified, like with a Certified Ethical Hacker or Certified
Information Systems Security Professional, shows your expertise and can help you get hired.
Introduction to Cyber Crime
Investigation
Cybercrime Investigation Techniques
Investigating computer crimes requires using many technical and non-technical methods.
Digital forensics is one of the most important.
Digital forensics involves preserving, collecting, and analyzing digital evidence. It may
include recovering deleted files, examining data details, or investigating network traffic
logs. Special software like EnCase, FTK, and Autopsy is used.
Besides digital forensics, investigators can use other ways to collect evidence and identify
suspects. Examples may involve interviewing witnesses, reviewing surveillance camera
footage, and tracking money flow. Investigators might pretend to be victims or create fake
profiles on social media to trick suspects into revealing information. This act is called social
engineering.
Cooperation is also important in investigating computer crimes, sometimes involving
multiple agencies and organizations. Investigators are supposed to share information with law
enforcement, government entities, or
private cybersecurity companies to pool resources together. Working together helps detect
trends, follow up on suspects, and learn from each other’s best practices.
Introduction to Cyber Crime
Investigation
Cybercrime Investigation Tools
Investigators use special tools and programs to collect, save, and study digital evidence when
looking into cybercrimes. These tools help identify the bad people, track what they did, and
gather proof to build a case against them.
1. Digital Forensics Software: These programs recover deleted files, look at data details,
and check network logs. Common ones are EnCase, FTK, and Autopsy.
2. Network Monitoring Tools: These watch network traffic, spot suspicious activities,
and track data movement. Examples of network monitoring tools are Wireshark, tcpdump,
and Netscout.
3. Malware Analysis Tools: These study and take apart bad software to understand how it works
and where it came from. Tools like IDA Pro, OllyDbg, and Binary Ninja are used for malware
analysis.
4. Password Cracking Tools: These recover passwords from locked files, databases, or other
digital evidence. Tools like Cain and Abel, John the Ripper, and Hashcat are used in these
types of password cracking.
5. Social Media Tracking Tools: This Social media tracking tool follows what
suspects do on social media and collects evidence from those sites. Tools like
Hootsuite, Followerwonk, and Mention are used.
Introduction to Cyber Crime
Investigation
Cyber Crime Investigation Training
Investigating computer crimes is very complicated and constantly
changing, so it requires special training. There are several courses available
for those interested.
Police departments also offer training specifically designed for investigating
computer crimes. These programs teach practical skills for identifying and
investigating cybercrimes, as well as legal procedures for handling digital
evidence.
Certifications like Certified Cyber Crime Investigator (CI) or Certified
Computer Examiner (CCE) are also available. Getting certified shows
expertise and can help individuals get a job in this field.
Many colleges offer degrees in cybersecurity, digital forensics, or related areas.
These degree programs provide knowledge of technology and analytical skills
needed to tackle computer crime issues. Similarly, private companies also train in
specialized areas like studying malware, network analysis, or digital forensics. It’s
important to choose courses that match one’s career interests.
Introduction to Cyber Crime
Investigation
Conclusion
Investigating cyber crimes properly requires special
training. The best training programs come from police,
colleges, and companies, or have certifications. They
teach important skills like using digital forensics tools,
analyzing networks and malware, and
understanding cybercrime laws. People can get the right
training that matches their goals. This allows them to gain
expertise in the difficult but crucial job of catching
cybercriminals and stopping growing internet risks.
eDiscovery
What is eDiscovery? eDiscovery (Electronic
Discovery) is the process of identifying,
consolidating and formatting digital evidence in
compliance with legal requirements, analyzing it and
presenting in court.
eDiscovery
eDiscovery’s primary goals The goal of eDiscovery is
to facilitate the cooperation of technical experts who
are responsible for the investigation of digital evidence
with the client and his lawyers.
eDiscovery
Technicians ensure that digital evidence is secured so that the opposing side of the lawsuit has
no grounds to claim that evidence was somehow altered, planted, or destroyed while it was
being obtained, or that it was obtained in violation of procedural rules.
The digital evidence being sought is often found in a vast array of poorly structured data
from various sources: on company servers, in clouds, databases, archival copies of data,
IoT devices, etc.
It is almost impossible for an unprepared lawyer to find the required data by
working with such sources.
Technicians help select only the information that the client or his lawyers are interested
in from this mass of data.
Thus, they help the company to reduce the time it spends conducting an audit or internal
investigation.
Lawyers, judges, and attorneys are not experts on tech nical terminology. The task of
specialists is to explain to them the essence of the processes and methods used to identify,
consolidate, format in compliance with legal requirements, and extract digital evidence, as
well as the importance of the identified information, in a way that they will understand.
Digital Evidence
Collection
• Digital Evidence Collection in Cyber Security – Challenges Faced
• There are numerous challenges in collecting digital evidence in cyber security because
technology changes all the time and many new issues come up like the inconsistency of cyber
environments. Initially, the data volatility is a big challenge because important evidence is
completely altered or lost with ease in running systems if not captured on time. Also accessing
encrypted information or data that is protected poses its own difficulties thus one requires
more than just ordinary passwords but decryption methods as well as legal authorization in
order to access such information.
• Ensuring data integrity and authenticity is critical, as any alteration during collection can
render the evidence inadmissible in court. Additionally, legal and jurisdictional issues
often arise, especially when evidence spans multiple regions or countries, necessitating
compliance with diverse legal frameworks and international cooperation. Finally, the rapid
phase of technological advancement means forensic tools and methodologies must
constantly evolve to keep up with new forms of digital evidence and cyber threats,
demanding continuous training and adaptation by cybersecurity professionals.
Digital Evidence
Collection
Process Involved in Digital Evidence Collection
The main processes involved in digital evidence collection
are given below:
Data collection: In this process, data is identified and
collected for investigation.
Examination: In the second step the collected data is
examined carefully.
Analysis: In this process, different tools and techniques are
used and the collected evidence is analyzed to reach some
conclusion.
Reporting: In this final step all the documentation and
reports are compiled so that they can be submitted in
court.
Digital Evidence
Collection
Digital Evidence
Collection
Types of Collectible Data
The computer investigator and experts who investigate the seized devices
have to understand what kind of potential shreds of evidence could there be
and what type of shreds of evidence they are looking for. So, that they could
structure their search pattern. Crimes and criminal activities that involve
computers can range across a wide spectrum, they could go from trading
illegal things such as rare and endangered animals, and damaging
intellectual property, to personal data theft, etc.
Digital Evidence
Collection
has been deleted from the computer, they could be dead, can be encrypted, or The
files investigator should be familiar with a variety of tools, methods, and also
software to prevent the data from damaging during the data recovery process.
There are two types of data, that can be collected in a computer forensics investigation:
Persistent data: It is the data that is stored on a non-volatile memory type storage
device such as a local hard drive the external storage devices like SSDs, HDDs, pen
drives, CDs, The. The data on these devices is preserved even when the computer is
turned off.
Volatile data: It is the data that is stored on a volatile memory type storage such as
memory, registers, cache, RAM, or it exists in transit, that will be lost once the
computer is turned off or it loses power. Since volatile data is evanescent, an
investigator must know how to reliably capture it.
Digital Evidence
Collection
Types of Evidence
Collecting the shreds of evidence is important in any investigation to
support the claims in court. Below are some major types of evidence.
Real Evidence: These pieces of evidence involve physical or tangible evidence
such as flash drives, hard drives, and documents, an eyewitness can also be
considered as a shred of tangible evidence.
Hearsay Evidence: These pieces of evidence are referred to as out-of- court
statements. These are made in courts to prove the truth of the matter.
Original Evidence: These are the pieces of evidence of a statement that is made
by a person who is not a testifying witness. It is to prove that the statement was
made rather than to prove its truth.
Testimony: Testimony is when a witness takes oath in a court of law and gives
their statement in court. The shreds of evidence presented should be authentic,
accurate, reliable, and admissible as they can be challenged in court.
Evidence Preservation
Evidence Preservation – Step By Step By Brian Hughes, Vice
President of Sologic A version of this article was featured an issue of
Professional Safety magazine.
Looking back at your last incident investigation, did you exp erience
anything like this? • • • • • • While attending t o the needs of
injured and distressed employees, time‐sens itive evidence was
missed. While securing the area and bri nging it back to a safe mode,
circumstances that could hav e served as evidence had to be altered.
In the bustle to min imize costly downtime, resuming production
rushed the evi dence collection process. A piece of critical evidence
disap peared. The legal department wished it had more to demo
nstrate due diligence. A regulatory body’s requirement or r equest
could not be fulfilled.
Digital Evidence
Collection
Evidence is critical to any incident investigation because it is the data that supports the
conclusions of the investigation. The primary intent of an incident investigation is to identify
effective solutions
. In order to accomplish this, the investigation needs to uncover causes and how they relate to
one another. Evidence provides support for what the team concludes to be causes. It cultivates
a level o f confidence that correlates directly to the quality of the evidence collected. Evidence
is the founda tion for an investigation –
for the investigation team as well as for others reviewing the investigation results and
conclusions i n the future. Many companies do not have a formal evidence preservation policy
in place, so the pr ocess is ad hoc –
left up to the individual investigator or individuals on the team. Some highly regulated
companies, with the nature of their governing regulations, specify requirements for evidence
documentation. They tailor their evidence preservation policy to match the requirements of the
regulatory agency. But evidence documentation is not necessarily the same as evidence collection
or preservation. Ce rtainly regulatory requirements must be considered. However, a 2501
Washington Street, Midland,
MI 48642 [Link] 800-375-0414
Digital Evidence
Collection
Step 1: Assess the Significance
Ask a few simple questions in order to document the actual and pot ential
significance of the problem. You don’t want to overreact to a relatively
benign problem –
however, you certainly want to ensure that you accommodate the
requirements of an incident that has major significance. The follow ing
questions will help you assess the significance of the problem. 1
. 2. 3. 4. 5. 6. Safety: Were fatalities and/or injuries involved? En
vironmental Impact: Was there a major environmental release? Re venue:
What was the impact on revenue? (Money coming into the f irm) Costs:
What additional expenses were incurred? (Money flowi ng out of the firm)
Frequency: How often has this type of problem happened in the past?
Other: Different firms will have unique signif icance factors to capture,
such as regulatory impact, supplier qualit y rating, employee confidence,
drain on customer service departm ent, public image, etc. These should be
identified and considered.
Digital Evidence
Collection
Step 2: Secure the Scene
When possible, secure the scene of the incident. The purpose is to give the
investigation team the opportunity to document evidence and gather
information before it is disturbed. This can be crucial to an accurate root
cause analysis later. Depending on the incident, yo u may be required to
grant access to additional parties –
such as OSHA or the CSB. Get the legal department involved right away
to determine those authorized to access the area. Tape the ar ea off and
allow access only to authorized personnel. Assign an area gatekeeper
responsible for keeping a log of those who enter the co ntrolled area. This
log should include the name, company, time in a nd out, and purpose for
entry. If they remove evidence, document i t thoroughly via Step 3 below.
Evidence removed may not be physic al –
it may be pictures or notes. If necessary, identify a secure room to
store the evidence.
Digital Evidence
Collection
Step 3: Document and Secure the Evidence
Evidence will come in many forms. Maintain confidentiality and secrecy when requ ired!
Ensure that evidence is released only to authorized individuals. Use a log she et that includes
the following information: ‐ ‐ ‐ Evidence ID Number: This is a uniq ue identification number
that will be associated with this piece of evidence from t his point forward. Date: What time
and date was the evidence collected? Locatio n/Source: Where was the evidence collected?
2501 Washington Street, Midland,
MI 48642 [Link] 800-375-0414
o o o o o o o Physical Evidence: If dealing with a piece of physical evidence, do cument as
accurately as possible where the evidence was found. Depending on th e significance of the
event, creating a map of the affected area may be useful. Evi dence location can then be
documented relative to the incident location. Stateme nts: Statements should be taken from
witnesses. Make sure to document each per son’s name and contact information, as well as their
location relative to the incide nt. This is an initial interview –
you may need more information once the formal root cause analysis is under way
. However, the interview should be conducted by someone familiar with the root c ause analysis
process. This will help ensure that questions elicit causes as much as possible and minimize
story telling that is jaded by opinion, loyalties, etc.
Digital Evidence
Collection
Step 4: Destruction of Evidence
Sometimes it is appropriate to destroy evidenc e after
an investigation is completed. While so me
investigations will require the evidence to be held into
perpetuity, most will not. Storing electronic files is easy
and doesn’t take up mu ch space. However, storing
physical parts and equipment may not be necessary.
Your legal d epartment should advise regarding
evidence maintenance.
Digital Evidence
Collection
Step 5: Refine the Evidence Policy
It is safe to assume that you will not get it righ t the
first time.
Conduct a post‐investigation review to deter mine
opportunities for improvement. Refine y our policy
based upon lessons learned and dis tribute to the
organization.
E-Mail Investigation
Role of Email in Investigation
Emails play a very important role in business communications and have emerged as one of
the most important applications on internet. They are a convenient mode for sending
messages as well as documents, not only from computers but also from other electronic
gadgets such as mobile phones and tablets.
The negative side of emails is that criminals may leak important information about their
company. Hence, the role of emails in digital forensics has been increased in recent years. In
digital forensics, emails are considered as crucial evidences and Email Header Analysis has
become important to collect evidence during forensic process.
An investigator has the following goals while performing email forensics −
To identify the main criminal
To collect necessary evidences
To presenting the findings
To build the case
E-Mail Investigation
Challenges in Email Forensics
Email forensics play a very important role in investigation as most of the
communication in present era relies on emails. However, an email forensic
investigator may face the following challenges during the investigation −
Fake Emails
The biggest challenge in email forensics is the use of fake e-mails that are created by
manipulating and scripting headers etc. In this category criminals also use temporary email
which is a service that allows a registered user to receive email at a temporary address that
expires after a certain time period.
Spoofing
Another challenge in email forensics is spoofing in which criminals used to present an email
as someone else’s. In this case the machine will receive both fake as well as original IP
address.
Anonymous Re-emailing
Here, the Email server strips identifying information from the email message before
forwarding it further. This leads to another big challenge for email investigations.
E-Mail Investigation
Techniques Used in Email Forensic Investigation
Email forensics is the study of source and content of email as evidence to identify the actual
sender and recipient of a message along with some other information such as date/time of
transmission and intention of sender. It involves investigating metadata, port scanning as well
as keyword searching.
Some of the common techniques which can be used for email forensic
investigation are
Header Analysis
Server investigation
Network Device Investigation
Sender Mailer Fingerprints
Software Embedded Identifiers
In the following sections, we are going to learn how to fetch information using Python
for the purpose of email investigation.
E-Mail Tracking
E-mail tracking: What it is and how you can protect yourself
How does e-mail tracking work?
Researchers from Princeton University analyzed about 1,000 ad mailings. They found that
70% of the messages contained ad trackers — automatically downloading elements such as
invisible images that not only inform the sender when and how many times you opened the
message, but also transmit personal data (for example, your e-mail address) in the query
string. What’s more, the tracking domain query reveals your IP address, from which your
approximate location can be determined.
Such technologies allow the creators of ad mailings to target their messages more effectively.
For example, tracking is extremely useful for so-called A/B testing, which helps determine
which message topics and types (say, with or without emojis) people are more likely to click.
On top of that, ad trackers can store browser cookies so as to “recognize” you on other sites
that are not even related to the mailing topic.
That way, the advertising network gets more information about your interests, and they can
sell that information to advertisers. For example, if you opened a message about discounts on
sneakers, sports footwear ads could start hounding you online.
IP Tracking
How to protect yourself
If you use the Gmail webmail client, you’re ever so slightly in luck. This provider (and
possibly some others as well) download all images from the message to their servers before
passing them to you. That means advertising networks can’t store cookies in your browser or
learn your IP address — unless they pay Google for the information.
Users of other e-mail providers also have some good news: Tools for blocking Web trackers
work pretty well for e-mail tracking too, and you can use a VPN to hide your real IP address.
Here are a few tips to help protect against being tracked through your e-mail:
Disable automatic downloading of images in the mail client, and download images only from
trusted senders.
If imageless messages seem too boring, use a tool to block tracking, such as Private Browsing
in Kaspersky Internet Security.
Using a VPN, such as Kaspersky Secure Connection, will help conceal your real IP
address from advertisers.
IP Tracking
IP tracking involves identifying the geographical location and sometimes
additional details about a device based on its IP address. This process is
commonly used for various purposes, including security, targeted
advertising, and content localization. Here are some key points about IP
tracking:
Geolocation: IP addresses can be used to estimate the geographical
location of a device. This is done through databases that map IP address
ranges to specific locations. The accuracy can vary, with more precise
locations often available for larger IP address blocks.
ISP and Network Information: IP tracking can reveal information about
the Internet Service Provider (ISP) and the type of network (e.g., residential,
business, mobile).
Privacy Considerations: While IP tracking can provide useful data, it also
raises privacy concerns. Some people view it as an invasion of privacy,
especially if it's done without consent. Regulations like GDPR in Europe
and CCPA in California aim to protect user privacy and limit the use of
personal data.
IP Tracking
Use Cases:
Security: To detect and prevent fraudulent activities or unauthorized access.
Personalization: To provide localized content or advertisements based on user location.
Analytics: To gather demographic information about website visitors or app users.
Limitations:
Dynamic IP Addresses: Many users have dynamic IP addresses that change periodically,
which can affect tracking accuracy.
VPNs and Proxies: Users can mask their real IP addresses using VPNs or proxies,
making it harder to determine their true location.
Legal and Ethical Considerations: It's important to handle IP tracking
responsibly and in compliance with legal requirements. Users should be
informed about data collection practices, and their consent should be
obtained where necessary.
E-Mail Recovery, Hands
Determine the Problem
Identify why you can't access your email:
Forgotten password
Account compromised or hacked
Email account is locked or disabled
Two-factor authentication issues
2. Recover Password
If you’ve forgotten your password, follow these steps:
Visit the Email Provider’s Recovery Page: Most email services have a
"Forgot Password" or "Reset Password" link on their login page.
Follow the Instructions: You'll typically be asked to provide the email
address, and then you'll receive a password reset link or code.
Verify Your Identity: Some providers may ask for additional verification, such
as answering security questions, confirming a code sent to a linked phone number,
or confirming identity via a secondary email.
IP Tracking
Recover a Hacked Account
If your account has been compromised:
Go to the Account Recovery Page: Use the email provider’s recovery tools to regain access.
Secure Your Account: Once you regain access, change your password and review account
settings for any unauthorized changes.
Contact Support: If you’re unable to recover the account through standard methods, contact
your email provider’s customer support for assistance.
4. Account Locked or Disabled
If your account is locked or disabled:
Follow Provider’s Instructions: Check any emails or notifications from your provider about
why the
account was locked and how to recover it.
Contact Support: Reach out to the provider’s support team if you can’t resolve the issue
through
automated tools.
5. Two-Factor Authentication Issues
If you’re having trouble with two-factor authentication (2FA):
Use Backup Codes: If you’ve set up backup codes, use one of those to regain access.
Recovery Options: Most services offer recovery options, such as an alternate email address or
phone number. Follow the provided steps.
IP Tracking
General Tips
Check for Typing Errors: Make sure you’re entering the correct
email address and password.
Update Security Settings: After recovery, review and update your
security settings, including changing passwords and updating recovery
options.
7. If Recovery Attempts Fail
Provide Documentation: Some email providers may require
additional proof of identity if standard recovery methods don’t work.
Be prepared to provide any requested documentation.
Create a New Account: If you can’t recover the old account and it’s critical
to have email access, consider creating a new email account and updating
your contacts.
Encryption and Decryption Methods
Encryption and decryption are crucial techniques for securing data by
making it unreadable to unauthorized users and then restoring it to a
readable format for authorized users. Here’s an overview of common
encryption and decryption methods:
1. Symmetric Encryption
Symmetric encryption uses the same key for both encryption and
decryption. The main challenge with symmetric encryption is securely
distributing the key.
AES (Advanced Encryption Standard): Widely used for its security
and efficiency. AES supports key sizes of 128, 192, and 256 bits.
DES (Data Encryption Standard): Older and less secure, DES has
largely been replaced by AES. It uses a 56-bit key.
3DES (Triple DES): An enhancement of DES that applies the DES
algorithm three times to each data block for improved security
Encryption and Decryption Methods
Advantages:
Fast and efficient.
Suitable for large amounts of data.
Disadvantages:
Key distribution can be challenging.
If the key is compromised, all encrypted data is at risk.
2. Asymmetric Encryption
Asymmetric encryption uses a pair of keys: a public key for encryption and a private key for
decryption. This method is used for secure key exchange and digital signatures.
RSA (Rivest-Shamir-Adleman): One of the most widely used asymmetric encryption algorithms. It
relies on the difficulty of factoring large prime numbers.
ECC (Elliptic Curve Cryptography): Provides the same level of security as RSA with smaller key sizes,
making it more efficient.
Advantages:
Secure key exchange.
Digital signatures can verify authenticity and integrity.
Disadvantages:
Slower compared to symmetric encryption.
Requires careful management of keys.
Encryption and Decryption Methods
Hash Functions
Hash functions are used to create a fixed-size hash value (digest) from input
data of arbitrary size. They are not encryption algorithms but are often used in
conjunction with encryption.
SHA-256 (Secure Hash Algorithm 256-bit): Part of the SHA-2 family,
commonly used in various security applications.
MD5 (Message Digest Algorithm 5): Now considered weak and vulnerable
to collisions, MD5 should not be used for security-critical applications.
Advantages:
Useful for integrity checking and password storage (when combined with salting).
Fast and efficient.
Disadvantages:
Not reversible, so they cannot be used to recover the original data.
Weak hash functions (like MD5) can be vulnerable to attacks.
Encryption and Decryption Methods
Hybrid Encryption
Hybrid encryption combines symmetric and asymmetric encryption
to leverage the strengths of both methods.
Example: An asymmetric algorithm (e.g., RSA) is used to securely
exchange a symmetric key (e.g., AES). Once the symmetric key is
shared, it is used for encrypting the actual data.
Advantages:
Provides both secure key exchange and efficient data encryption.
Balances the security and performance of encryption.
Disadvantages:
Complexity in implementation.
Requires managing both types of keys.
Encryption and Decryption Methods
Common Applications
Secure Email: PGP (Pretty Good Privacy) and S/MIME (Secure/Multipurpose
Internet Mail Extensions) use encryption to secure email communication.
Web Security: TLS (Transport Layer Security) uses a combination of symmetric and
asymmetric encryption to secure data transmitted over the internet.
File Encryption: Tools like VeraCrypt or BitLocker use symmetric encryption to protect
files and drives.
Key Management
Effective key management is crucial for the security of encryption systems. It
involves:
Generating strong keys.
Distributing keys securely.
Storing keys safely.
Regularly updating and retiring keys.
Search and Seizure of Computers
Search and seizure of computers involves legal procedures used by law enforcement agencies to obtain
and examine digital evidence from computers and other electronic devices. This process must adhere to
legal standards to ensure evidence is collected lawfully and remains admissible in court. Here’s an
overview of the key aspects:
1. Legal Framework
**1.1. Search Warrants:
Requirement: In most jurisdictions, law enforcement must obtain a search warrant from a judge or magistrate
before searching a computer. The warrant must be based on probable cause and specify the places to be
searched and the items to be seized.
Scope: The warrant defines the scope of the search. A broader search may require additional legal
justification.
**1.2. Consent:
Voluntary Consent: If the owner or custodian of the computer consents to the search, a warrant may not
be necessary. However, consent must be voluntary and informed.
Revocation of Consent: The consent can be revoked at any time, which may limit the scope of the search.
**1.3. Legal Protections:
Fourth Amendment (U.S.): In the U.S., the Fourth Amendment protects against unreasonable
searches and seizures. Similar protections exist in other countries under their respective legal
frameworks.
Search and Seizure of Computers
2. Search Procedures
**2.1. Seizure of Equipment:
Immediate Seizure: Law enforcement may seize computers and related devices if they are relevant to the
investigation. This includes laptops, desktops, external drives, and mobile devices.
Inventory and Documentation: Seized equipment should be documented and inventoried to maintain a chain of custody.
**2.2. Forensic Examination:
Preservation: Before analysis, the digital evidence must be preserved to prevent alteration. This often involves creating
a forensic image (bit-by-bit copy) of the storage device.
Analysis: Forensic experts use specialized tools and techniques to examine the digital evidence. This
includes searching for files, metadata, deleted data, and communications.
**2.3. Handling Evidence:
Chain of Custody: Maintaining a chain of custody is critical to ensure that the evidence remains unaltered and is admissible
in court. Each person who handles the evidence must be documented.
Documentation: Detailed records of the search, seizure, and examination processes must be kept.
3. Challenges and Considerations
**3.1. Encryption:
Access Issues: Encrypted data may pose challenges. Law enforcement may need to use legal means to
compel individuals to decrypt data or seek assistance from experts.
Legal Constraints: In some jurisdictions, compelling decryption may raise legal issues, particularly regarding self-
incrimination.
**3.2. Privacy Concerns:
Scope of Search: The search must be limited to the scope defined in the warrant or consent. Searching beyond this scope
may violate privacy rights.
Data Sensitivity: Sensitive information, such as personal communications or medical records, must be handled with
care and confidentiality.
Search and Seizure of Computers
3.3. International Issues:
Jurisdiction: Digital evidence may be stored in different countries, complicating the search and seizure
process. International treaties and agreements may be required to access evidence across borders.
Data Protection Laws: Different countries have varying data protection laws that must be
considered when handling digital evidence.
4. Best Practices for Law Enforcement
Training: Law enforcement personnel should be trained in digital forensics and the legal aspects of digital
evidence handling.
Collaboration: Working with digital forensic experts and legal advisors ensures compliance with best
practices and legal standards.
Up-to-Date Tools: Utilizing the latest forensic tools and techniques helps in effectively analyzing and
preserving digital evidence.
5. Implications for Individuals
Understanding Rights: Individuals should be aware of their rights regarding searches and seizures. This
includes knowing when to consent or challenge the search.
Legal Representation: Consulting with legal professionals can help navigate issues related to search
and seizure, especially if facing allegations involving digital evidence.
Evidences, Password Cracking.
Recovering Deleted Evidence
When data is deleted from a computer, it doesn't always vanish immediately. Here’s how forensic experts
typically approach recovery:
**1.1. File Deletion Basics:
File Deletion: When a file is deleted, it is often removed from the file system's directory structure but remains on the
disk until overwritten. This is why data recovery is sometimes possible.
Overwriting: As new data is written to the disk, it can overwrite the space previously occupied by deleted files, making
recovery more difficult.
**1.2. Recovery Techniques:
File Carving: This technique involves searching for file signatures and structures to recover files even if
they have been deleted or corrupted.
Forensic Tools: Specialized tools like EnCase, FTK Imager, and PhotoRec are used to recover deleted files. These tools can
scan the disk for remnants of deleted data and reconstruct files.
Metadata Analysis: Metadata such as timestamps and file sizes can provide clues about deleted files and help in their
recovery.
**1.3. Recovery Challenges:
Encryption: If files were encrypted before deletion, recovering the data may be more complex without the decryption keys.
File Fragmentation: Fragmented files may be harder to recover if the fragments are spread across different
parts of the disk.
Hardware Damage: Physical damage to storage media can complicate recovery efforts. In such cases, specialized
hardware recovery services may be needed.
Recovering Deleted
Evidences, Password Cracking.
Password Cracking
Password cracking involves recovering passwords from stored data
or hashed values. This is commonly done in both security testing and
forensic investigations.
**2.1. Password Hashing:
Hashing Algorithms: Passwords are often stored as hashed values
using algorithms like MD5, SHA-1, or SHA-256. Hashing
transforms the password into a fixed-size string of characters.
Salting: Adding a random value (salt) to passwords before hashing
can make attacks more difficult by preventing the use of
precomputed hash tables (rainbow tables).
Recovering Deleted
Evidences, Password Cracking.
Brute Force: This method involves trying every possible combination of
characters until the correct password is found. It is time-consuming and generally
impractical for complex passwords.
Dictionary Attacks: This method uses a list of common passwords or phrases to
guess the password. It is faster than brute force but limited by the dictionary
used.
Rainbow Tables: Precomputed tables of hash values for common passwords are
used to quickly match hashes. Salting can mitigate the effectiveness of rainbow
tables.
Hybrid Attacks: Combining dictionary attacks with brute force techniques to
improve efficiency, such as appending numbers or symbols to dictionary words.
**2.3. Tools for Password Cracking:
John the Ripper: A popular open-source tool that supports various hashing
algorithms and has both dictionary and brute-force capabilities.
Hashcat: A powerful password recovery tool that supports GPU acceleration,
making it faster for complex
password cracking.
Recovering Deleted
Evidences, Password Cracking.
Cain & Abel: An older tool that supports multiple cracking methods and is used
for both password recovery and network sniffing.
**2.4. Legal and Ethical Considerations:
Authorization: Password cracking should only be performed with proper
authorization and for legitimate purposes, such as legal investigations or
security testing.
Data Privacy: Ensure that any recovered data is handled with care and in
accordance with relevant data protection laws.
**2.5. Preventative Measures:
Strong Passwords: Use complex, long passwords that are resistant to brute-force
attacks.
Multi-Factor Authentication (MFA): Implement MFA to add an additional layer of
security beyond just passwords.
Regular Updates: Keep hashing algorithms and security measures up-to-date to
protect against evolving threats.
UNIT – IV
Digital Forensics:
Introduction to Digital Forensics,
Forensic Software and Hardware,
Analysis and Advanced Tools,
Forensic Technology and Practices
Introduction to Digital Forensics
Digital forensics is a branch of forensic science
focused on recovering, analyzing, and presenting data
from electronic devices in a manner that is admissible
in court. It plays a crucial role in investigating
cybercrimes, corporate fraud, and other incidents
involving digital evidence.
Here’s an introduction to the key aspects of
digital forensics
Definition and Purpose
Digital Forensics involves the collection, preservation,
analysis, and presentation of digital evidence. The primary
purpose is to uncover and document digital evidence that can
help in investigations, legal proceedings, or security
assessments.
2. Key Phases of Digital Forensics
**2.1. Identification:
Objective: Identify and locate potential sources of digital evidence.
Sources: Computers, smartphones, tablets, servers, external
storage devices, cloud storage, and network devices.
**2.2. Collection:
Objective: Collect digital evidence in a manner that preserves its
integrity.
Techniques: Create forensic images (bit-by-bit copies) of storage
media to avoid altering original data.
Tools: Write-blockers to prevent changes to the original data, and
specialized software for imaging.
**2.3. Preservation:
Objective: Ensure that digital evidence remains unchanged and intact.
Methods: Secure storage of digital evidence, maintaining chain of
custody, and documenting every
action taken.
Analysis:
Objective: Examine and interpret the collected data to
uncover relevant information.
Techniques:
File System Analysis: Examine file structures, metadata, and
deleted files.
Data Carving: Recover files that have been deleted or
corrupted.
Network Forensics: Analyze network traffic to identify
anomalies or malicious activities.
Malware Analysis: Investigate malicious software to
understand its behavior and impact.
Types of Digital Forensics
**3.1. Computer Forensics:
Focus: Investigates data from computers, including desktops and laptops.
Techniques: Analyzing file systems, registry entries, and system logs.
**3.2. Mobile Device Forensics:
Focus: Recovers and analyzes data from smartphones, tablets, and other
mobile devices.
Techniques: Extracting data from internal storage, SIM cards, and memory cards.
**3.3. Network Forensics:
Focus: Analyzes network traffic to identify security incidents or
unauthorized activities.
Techniques: Capturing and examining network packets, analyzing logs, and
detecting anomalies.
*3.4. Cloud Forensics:
Focus: Investigates data stored in cloud environments
and services.
Techniques: Analyzing cloud service provider logs,
recovering cloud-based data, and ensuring compliance
with cloud service agreements.
**3.5. IoT Forensics:
Focus: Investigates data from Internet of Things (IoT)
devices like smart home devices and wearable's.
Techniques: Extracting data from device firmware,
communication logs, and sensor data.
Introduction to Digital Forensics
**4.1. Forensic Tools:
EnCase: A comprehensive forensic suite for collecting and analyzing
digital evidence.
FTK (Forensic Toolkit): Provides disk imaging, file analysis, and
reporting features.
Autopsy: An open-source digital forensics platform for analyzing hard
drives and smartphones.
**4.2. Techniques:
Write Protection: Prevents changes to digital evidence during collection.
Hashing: Verifies the integrity of data by comparing hash values before
and after analysis.
Data Recovery: Uses specialized tools to recover deleted or corrupted
files.
Introduction to Digital Forensics
Legal and Ethical Considerations
**5.1. Legal Framework:
Warrants and Consent: Ensure that searches and
seizures comply with legal requirements.
Chain of Custody: Maintain a detailed record of who
handled the evidence and when.
**5.2. Ethical Considerations:
Privacy: Respect the privacy of individuals and handle
sensitive data with care.
Objectivity: Ensure that analysis and findings are
impartial and unbiased.
Introduction to Digital Forensics
6. Challenges in Digital Forensics
**6.1. Encryption: Encrypted data may be difficult to access
without proper keys or passwords. **6.2. Volume of Data:
Large amounts of data can be challenging to process and
analyze. **6.3. Legal and Jurisdictional Issues: Cross-
border investigations may involve complex legal and
jurisdictional challenges.
Conclusion
Digital forensics is a rapidly evolving field that combines
technical expertise with legal knowledge to handle digital
evidence effectively. Its applications range from criminal
investigations to corporate security, and it plays a crucial
role in the modern legal system.
Analysis and Advanced
Tools
Analysis and advanced tools in digital forensics are
essential for recovering, examining, and interpreting
digital evidence from various devices and media.
These tools help forensic experts to handle complex
cases involving large volumes of data, encrypted
information, and sophisticated digital environments.
Here’s an overview of key analysis techniques and
advanced tools used in digital forensics:
Analysis and Advanced
Tools
Advanced Analysis Techniques
**1.1. File System Analysis:
File Carving: Recovers files without relying on file system metadata
by identifying file signatures.
Useful for recovering fragmented or deleted files.
Metadata Analysis: Examines file metadata (e.g., creation
dates, modification dates) to gather evidence about file history
and user activity.
**1.2. Network Forensics:
Traffic Analysis: Monitors and analyzes network traffic to
identify unusual patterns, unauthorized access, or data exfiltration.
Packet Analysis: Examines individual network packets to reconstruct
data flows and detect anomalies or malicious activities.
Analysis and Advanced
Tools
**1.3. Memory Forensics:
Volatile Data Analysis: Analyzes data in RAM to uncover running
processes, network connections, and potentially malicious
software.
Memory Imaging: Captures a snapshot of system memory for
analysis, helping to recover data that may not be stored on disk.
**1.4. Malware Analysis:
Static Analysis: Examines malware code and files without execution
to identify signatures,
behaviors, and potential threats.
Dynamic Analysis: Executes malware in a controlled environment
(sandbox) to observe its behavior and interactions with the system.
Analysis and Advanced
Tools
1.5. Data Correlation:
Timeline Analysis: Constructs a timeline of events
based on file metadata, system logs, and other data
sources to understand the sequence of activities.
Cross-Reference: Correlates data from multiple sources
(e.g., logs, files, network traffic) to build a
comprehensive picture of the incident.
**1.6. Cloud Forensics:
API Integration: Uses APIs provided by cloud service
providers to extract data from cloud environments.
Log Analysis: Analyzes cloud service logs to identify
user activity, access patterns, and potential breaches.
Analysis and Advanced
Tools
2. Advanced Forensic Tools
**2.1. EnCase:
Features: Comprehensive suite for acquiring,
analyzing, and reporting on digital evidence.
Supports a wide range of file systems and devices.
Strengths: Powerful indexing and searching
capabilities, robust reporting features.
**2.2. FTK Imager:
Features: Tool for creating forensic images of
storage media. Includes features for file analysis and
evidence collection.
Analysis and Advanced
Tools
Strengths: Lightweight and efficient, supports a variety of
image formats.
**2.3. Autopsy:
Features: Open-source digital forensics platform that
provides a graphical interface for examining disk images,
recovering files, and analyzing metadata.
Strengths: Extensible with plugins, cost-effective,
suitable for a wide range of forensic tasks.
**2.4. X1 Social Discovery:
Features: Focuses on collecting and analyzing data
from social media, cloud services, and web-based
applications.
Analysis and Advanced
Tools
2.5. Sleuth Kit:
Features: Collection of command-line tools and
libraries for digital forensics analysis. Includes
tools for file system analysis, disk imaging, and
file recovery.
Strengths: Versatile and open-source, suitable for
advanced users and custom forensic workflows.
Analysis and Advanced
Tools
*2.6. Volatility Framework:
Features: Open-source tool for memory forensics. Allows analysis of system memory to
extract information about processes, network connections, and other volatile data.
Strengths: Highly customizable and extensible, supports various operating systems and
memory formats.
**2.7. Kali Linux:
Features: Linux distribution that includes a wide range of penetration testing and
digital forensics tools. Useful for security assessments and forensic analysis.
Strengths: Comprehensive suite of tools for various aspects of cybersecurity and forensics.
**2.8. Magnet AXIOM:
Features: Integrates data from computers, mobile devices, and cloud services into a single
platform for analysis.
Strengths: Advanced data recovery and analysis capabilities, user-friendly
interface.
Analysis and Advanced
Tools
*2.9. Cellebrite UFED:
Features: Specializes in mobile device forensics.
Provides tools for data extraction, analysis, and
reporting from smartphones and tablets.
Strengths: Comprehensive support for various
mobile operating systems and devices.
Analysis and Advanced
Tools
3. Best Practices for Using Forensic Tools
**3.1. Maintain Chain of Custody:
Document every step of the evidence handling process to
ensure its integrity and admissibility in court.
**3.2. Use Write Blockers:
Prevent modifications to the original data when creating
forensic images or conducting analysis.
**3.3. Follow Standard Operating Procedures:
Adhere to established forensic methodologies and protocols to
ensure consistency and reliability in your analysis.
Analysis and Advanced
Tools
**3.4. Regularly Update Tools:
Keep forensic tools up-to-date to ensure compatibility with
new technologies and to incorporate the latest features and
fixes.
**3.5. Training and Certification:
Obtain relevant training and certifications to effectively use
forensic tools and to stay current with industry best
practices.
Analysis and Advanced
Tools
Conclusion
Advanced analysis techniques and forensic tools are
vital for effectively handling complex digital
evidence.
They enable forensic experts to recover, analyze, and
present data in a way that supports investigations
and legal proceedings.
By utilizing these tools and following best practices,
digital forensic professionals can ensure accurate and
reliable results.
Forensic Technology and Practices
1. Forensic Technology
**1.1. Data Acquisition Tools:
Forensic Imagers: Tools like FTK Imager and EnCase create bit-by-bit
copies of storage devices, preserving the original data’s integrity while
allowing analysis.
Write Blockers: Devices that prevent modification of data on a storage device
during imaging, ensuring that the original evidence remains unchanged.
**1.2. Data Analysis Tools:
Disk Analysis: Tools such as Autopsy and Sleuth Kit examine file systems,
recover deleted files, and analyze metadata.
Network Forensics: Tools like Wireshark and NetworkMiner capture and
analyze network traffic to uncover security incidents and unauthorized activities.
Memory Forensics: Volatility Framework analyzes volatile data in RAM to
uncover running processes, network connections, and malware.
Forensic Technology and Practices
**1.3. Data Recovery Tools:
File Carving: Tools such as PhotoRec recover files based on file signatures rather than file system
metadata.
Data Recovery Software: Programs like R-Studio and Recuva help recover deleted or damaged files from
storage media.
**1.4. Mobile Forensics:
Extraction Tools: Cellebrite UFED and X1 Social Discovery are used to extract and analyze data
from mobile devices, including text messages, call logs, and app data.
**1.5. Cloud Forensics:
API Integration: Tools that interact with cloud service APIs to retrieve data from cloud platforms.
Log Analysis: Analyzing logs from cloud services to trace user activity and identify potential security
incidents.
**1.6. Malware Analysis Tools:
Static Analysis: Tools like IDA Pro and Ghidra analyze malware code without executing it to identify its
structure and potential threats.
Dynamic Analysis: Cuckoo Sandbox provides a controlled environment to execute and observe
malware behavior.
Forensic Technology and Practices
2. Forensic Practices
**2.1. Evidence Collection:
Preservation: Ensure that digital evidence is preserved in its original state by creating
forensic images and using write blockers.
Documentation: Keep detailed records of the evidence collection process, including
the date, time, and individuals involved.
**2.2. Chain of Custody:
Tracking: Document every person who handles the evidence, along with the date
and time, to maintain the integrity and authenticity of the evidence.
Security: Store evidence in secure locations to prevent tampering or unauthorized access.
**2.3. Analysis Procedures:
Forensic Analysis: Follow systematic procedures to examine and interpret digital evidence,
including file system analysis, data recovery, and metadata examination.
Corroboration: Cross-reference findings from different sources (e.g., file systems,
network logs) to build a comprehensive understanding of the case.
Forensic Technology and Practices
*2.4. Reporting:
Clear and Concise Reports: Prepare detailed reports that
summarize findings, methodologies, and conclusions in a
manner that is understandable to non-technical audiences.
Expert Testimony: Provide expert testimony in court to
explain forensic findings and the methodologies used.
**2.5. Legal Compliance:
Search Warrants and Consent: Obtain proper authorization
before searching or seizing digital evidence.
Privacy Laws: Adhere to data protection and privacy laws
to ensure compliance with legal and ethical standards.
Forensic Technology and Practices
3. Emerging Trends in Forensic Technology
**3.1. Artificial Intelligence and Machine Learning:
Automated Analysis: AI and machine learning algorithms assist in automating data analysis, pattern
recognition, and anomaly detection.
Predictive Analytics: AI tools can help predict potential security threats and vulnerabilities based on
historical data.
**3.2. Blockchain Forensics:
Cryptocurrency Analysis: Tools for analyzing blockchain transactions and identifying patterns or
illicit activities related to cryptocurrencies.
Smart Contracts: Examination of smart contracts on blockchain platforms to understand their
execution and impact.
**3.3. Internet of Things (IoT) Forensics:
IoT Device Analysis: Techniques for investigating data from smart devices, including home
automation systems and wearables.
Data Integrity: Ensuring the accuracy and completeness of data from diverse IoT devices.
**3.4. Cloud and Virtualization Forensics:
Virtual Machine Analysis: Techniques for examining virtual machines and snapshots to recover
evidence from virtualized environments.
Cloud Data Management: Tools and practices for handling and analyzing data stored in cloud
services.
Forensic Technology and Practices
4. Best Practices for Digital Forensics
**4.1. Continuous Education:
Stay updated with the latest advancements in forensic technology and
best practices through continuous training and certification.
**4.2. Tool Validation:
Regularly test and validate forensic tools to ensure their reliability
and accuracy.
**4.3. Collaboration:
Work with other forensic experts, law enforcement, and legal
professionals to ensure comprehensive investigations and effective
handling of evidence.
**4.4. Ethical Standards:
Adhere to ethical guidelines and standards to maintain the
credibility and integrity of forensic investigations.
Conclusion
Forensic technology and practices are critical for
effectively handling digital evidence and
supporting investigations.
By utilizing advanced tools, following systematic
procedures, and adhering to legal and ethical
standards, digital forensic professionals can ensure
accurate and reliable outcomes in their
investigations.
UNIT – V
Laws and Acts:
Laws and Ethics,
Digital Evidence Controls,
Evidence Handling Procedures,
Basics of Indian Evidence ACT IPC and CrPC,
Electronic Communication Privacy ACT,
Legal Policies.
Laws and Ethics
Laws and ethics are fundamental to the practice of
digital forensics, ensuring that the collection,
analysis, and presentation of digital evidence are
conducted within legal boundaries and ethical
standards.
This ensures the integrity and admissibility of
evidence while protecting individuals' rights and
privacy.
Laws and Ethics
1. Legal Considerations in Digital Forensics
**1.1. Search and Seizure:
Search Warrants: In many jurisdictions, law enforcement
must obtain a search warrant before examining or seizing
digital evidence. The warrant must be based on probable
cause and specify the scope of the search.
Consent: Evidence can also be collected with the voluntary
consent of the owner or custodian of the digital devices.
Consent must be informed and unequivocal.
Exigent Circumstances: In urgent situations where
immediate action is necessary to prevent evidence
destruction or harm, authorities might act without a
warrant.
Laws and Ethics
*1.2. Chain of Custody:
Documentation: Every person who handles the evidence must be documented, along with the time and date
of their involvement. This ensures the evidence's integrity and helps prove that it hasn't been tampered
with.
Storage: Evidence should be stored securely to prevent unauthorized access or alterations. This often
involves using evidence lockers or secure digital storage solutions.
**1.3. Privacy Laws:
Data Protection Regulations: Laws like the General Data Protection Regulation (GDPR) in the
European Union and the California Consumer Privacy Act (CCPA) in the U.S. regulate how personal
data should be handled, including during forensic investigations.
Confidentiality: Forensic practitioners must ensure that sensitive personal information is kept
confidential and only disclosed to authorized parties.
**1.4. Legal Admissibility:
Admissibility Standards: Evidence must be collected and handled according to legal standards to be
admissible in court. This includes following proper procedures and maintaining the chain of custody.
Expert Testimony: Forensic experts may be called to testify about their findings and the methods
used. Their testimony must be clear, accurate, and based on reliable principles and methods.
Laws and Ethics
2. Ethical Considerations in Digital Forensics
**2.1. Integrity:
Objective Analysis: Forensic professionals must conduct their work objectively, without bias or
preconceived notions. Their goal is to uncover the truth, not to support a particular outcome.
Accuracy: Ensuring that analysis and reporting are accurate and reliable is crucial for maintaining the credibility of the
forensic process.
**2.2. Respect for Privacy:
Minimization: When collecting and analyzing data, forensic experts should limit their scope to what is relevant to the
investigation, avoiding unnecessary intrusion into personal or unrelated information.
Confidentiality: Maintain confidentiality of sensitive information encountered during investigations,
respecting privacy rights and legal obligations.
**2.3. Professional Competence:
Training and Skills: Forensic practitioners should continually update their skills and knowledge to stay current with
technological advancements and forensic methodologies.
Certification: Obtaining relevant certifications (e.g., Certified Forensic Computer Examiner (CFCE), Certified
Information Systems Security Professional (CISSP)) helps ensure professional competence.
**2.4. Ethical Reporting:
Honest Reporting: Reports should accurately reflect the findings and not be altered to fit a particular
narrative or desired outcome.
Disclosure of Limitations: Forensic experts should disclose any limitations or uncertainties in their findings,
providing a balanced view of the evidence.
**2.5. Compliance with Legal and Ethical Standards:
Adherence to Protocols: Follow established legal and ethical protocols for evidence handling, analysis, and reporting.
Avoiding Conflicts of Interest: Ensure that personal interests or external pressures do not influence forensic
activities or findings.
Digital Evidence Controls
Digital evidence controls are essential practices
and protocols designed to ensure the integrity,
confidentiality, and proper handling of digital
evidence throughout the investigative process.
These controls are critical for maintaining the
admissibility and reliability of evidence in legal
proceedings.
Here’s a comprehensive guide to digital evidence
controls:
Digital Evidence Controls
1. Evidence Collection Controls
**1.1. Chain of Custody:
Documentation: Maintain detailed records of all individuals who handle the evidence, including dates,
times, and actions taken. This ensures that the evidence's integrity is preserved and provides a clear history
of its handling.
Logbooks: Use chain of custody forms or logbooks to document transfers and handling of evidence.
**1.2. Forensic Imaging:
Write Protection: Use hardware or software write blockers to prevent modification of the original
data during the imaging process.
Bit-by-Bit Copy: Create a bit-by-bit copy of the storage media to ensure that all data, including
deleted and hidden files, is preserved.
**1.3. Secure Storage:
Physical Security: Store physical evidence in secure locations such as locked evidence rooms or safes
to prevent unauthorized access.
Digital Security: Use encryption and access controls to protect digital copies of evidence.
Digital Evidence Controls
2. Evidence Preservation Controls
**2.1. Preservation Techniques:
Bit-for-Bit Copy: Ensure that forensic images are exact copies of the
original data, preserving every bit of information.
Data Integrity: Use hashing algorithms (e.g., MD5, SHA-256) to create
checksums for the evidence. Compare checksums before and after handling
to verify that data has not been altered.
**2.2. Handling Procedures:
Minimal Handling: Minimize direct interaction with the original
evidence to reduce the risk of accidental alteration.
Use of Forensic Tools: Utilize forensic tools designed to handle
evidence without altering it. These tools should be validated and
calibrated regularly.
Digital Evidence Controls
3. Evidence Analysis Controls
**3.1. Controlled Environment:
Forensic Workstations: Conduct analysis on forensic workstations or environments that are isolated
from other networks to prevent contamination or unauthorized access.
Data Integrity: Use verified and validated forensic software to analyze data, ensuring that tools used
are up-to-date and free of vulnerabilities.
**3.2. Verification of Findings:
Peer Review: Have findings reviewed by another qualified forensic expert to ensure accuracy and
reliability.
Reproducibility: Document analysis procedures and results to allow for reproducibility of findings
by other experts.
**3.3. Documentation:
Detailed Records: Maintain comprehensive documentation of all analytical processes, including
methodologies, tools used, and findings.
Reporting: Prepare clear, accurate, and objective reports summarizing the evidence analysis. Ensure
that reports are understandable to non-technical audiences, such as judges and juries.
Digital Evidence Controls
4. Evidence Presentation Controls
**4.1. Court Admissibility:
Compliance with Legal Standards: Ensure that all evidence handling and
analysis procedures comply with legal standards and regulations to make
the evidence admissible in court.
Expert Testimony: Be prepared to provide expert testimony to explain the
methods used and the findings. Ensure that testimony is clear, concise, and
based on reliable principles.
**4.2. Data Security:
Presentation Formats: Use secure and standardized formats for
presenting digital evidence in court, such as encrypted disks or secure
digital files.
Preventing Tampering: Ensure that evidence presented in court is
protected from tampering or unauthorized access.
Digital Evidence Controls
5. Evidence Management Controls
**5.1. Access Controls:
Authorization: Limit access to digital evidence to authorized personnel only. Implement role-based
access controls and ensure that permissions are appropriately assigned.
Authentication: Use strong authentication methods to access evidence, including multi-factor
authentication if available.
**5.2. Backup and Recovery:
Regular Backups: Implement regular backups of digital evidence and forensic images to protect
against data loss.
Recovery Procedures: Develop and test procedures for recovering data from backups to ensure that
evidence can be restored if needed.
**5.3. Retention and Disposal:
Retention Policies: Establish and follow retention policies for how long digital evidence should be kept.
This may be dictated by legal requirements or organizational policies.
Secure Disposal: Use secure methods for disposing of evidence when it is no longer needed,
including data wiping or physical destruction of storage media.
Digital Evidence Controls
6. Compliance and Auditing
**6.1. Compliance with Standards:
Industry Standards: Adhere to industry standards and guidelines for
digital evidence handling, such as those from the National Institute of
Standards and Technology (NIST) and the International Organization
for Standardization (ISO).
Legal Requirements: Follow relevant laws and regulations governing
digital evidence, including data protection and privacy laws.
**6.2. Regular Audits:
Internal Audits: Conduct regular internal audits of evidence handling
and management practices to ensure compliance with protocols and
identify areas for improvement.
External Audits: Engage external auditors or independent experts to
review evidence handling procedures and practices.
Digital Evidence Controls
Conclusion:
Digital evidence controls are crucial for ensuring the
integrity, security, and admissibility of digital evidence.
By implementing robust controls for collection,
preservation, analysis, presentation, and management,
forensic professionals can maintain the reliability of
evidence and uphold the legal and ethical standards of
their work.
Proper adherence to these controls also helps in
mitigating risks related to evidence tampering or loss.
Evidence Handling Procedures
Evidence handling procedures are crucial in
digital forensics to ensure that digital evidence is
collected, preserved, analyzed, and presented in a
way that maintains its integrity and admissibility in
court.
Proper handling helps prevent contamination, loss,
or alteration of evidence, ensuring that it remains
reliable and credible throughout the investigative
process. Here’s a detailed guide on evidence
handling procedures:
Evidence Handling Procedures
1. Evidence Collection
**1.1. Initial Assessment:
Identify Evidence: Determine which digital devices or media may
contain relevant evidence, including computers, mobile devices,
external drives, and cloud storage.
Plan: Develop a plan for evidence collection that includes steps for
safely and securely handling the devices.
**1.2. Preparation:
Secure Environment: Conduct evidence collection in a controlled
environment to minimize risks of contamination. This may involve using
a clean room or forensic lab.
Tools: Gather necessary tools, such as write blockers, forensic
imaging software, and appropriate documentation forms.
Evidence Handling Procedures
**1.3. Collection Process:
Use Write Blockers: Connect the storage media to forensic
workstations using write blockers to prevent any modification of the
data.
Create Forensic Images: Make bit-by-bit copies of the storage devices to
preserve the original data. Ensure that images include all partitions and
hidden areas.
Document: Record all details of the collection process, including
device information, date and time, and personnel involved.
**1.4. Handling Physical Devices:
Minimize Handling: Avoid touching the device's internal
components or removing any parts unless necessary.
Labeling: Clearly label all evidence with unique identifiers and include
information about its origin, collection date, and handling history.
Evidence Handling Procedures
Evidence Preservation
**2.1. Data Integrity:
Hashing: Calculate and record hash values (e.g., MD5, SHA-256) for
forensic images to verify that data has not been altered. Recalculate hash
values periodically to check for integrity.
Secure Storage: Store forensic images and physical evidence in secure
locations with controlled access. Use encryption for digital evidence to
protect confidentiality.
**2.2. Handling Procedures:
Minimize Access: Restrict access to evidence to authorized
personnel only. Implement access controls and logging to track
interactions with the evidence.
Prevent Alteration: Ensure that any analysis or handling of evidence
does not modify the original data. Use forensic tools that operate in a
read-only mode when working with evidence.
Evidence Handling Procedures
3. Evidence Analysis
**3.1. Environment Setup:
Forensic Workstations: Use dedicated forensic workstations or environments isolated from
other
networks to perform analysis. These systems should be equipped with validated forensic tools.
Data Integrity Checks: Verify the integrity of forensic images before beginning
analysis by comparing hash values with the original calculations.
**3.2. Analysis Procedures:
Document: Keep detailed records of all analysis steps, including tools used, methods
employed, and findings.
Forensic Tools: Utilize industry-standard forensic tools and software for analysis. Ensure that
these
tools are up-to-date and properly validated.
**3.3. Findings and Reporting:
Corroboration: Cross-reference findings from different sources to validate evidence and
ensure a comprehensive understanding.
Reporting: Prepare clear, accurate, and comprehensive reports detailing the findings,
methodologies used, and any relevant observations. Ensure that reports are understandable
to non-technical audiences.
Evidence Handling Procedures
4. Evidence Presentation
**4.1. Court Admissibility:
Adherence to Protocols: Ensure that all handling, preservation, and
analysis procedures comply with legal and regulatory standards to
maintain evidence admissibility.
Expert Testimony: Be prepared to provide expert testimony in court to
explain the evidence, the analysis conducted, and the conclusions drawn.
**4.2. Data Security:
Secure Formats: Use secure and standardized formats for presenting
digital evidence, such as encrypted files or secure disks.
Access Control: Ensure that evidence presented in court is
protected from tampering or unauthorized access.
Evidence Handling Procedures
5. Evidence Management
**5.1. Access Controls:
Authorization: Limit access to evidence to authorized individuals based on their role and
need. Implement role-based access controls.
Authentication: Use strong authentication methods to access evidence, including multi-
factor authentication if possible.
**5.2. Backup and Recovery:
Regular Backups: Implement a backup strategy for forensic images and related
data to protect against data loss.
Recovery Procedures: Develop and test procedures for recovering data from backups
to ensure that evidence can be restored if needed.
**5.3. Retention and Disposal:
Retention Policies: Follow established retention policies for how long evidence should be
kept, based on legal requirements and organizational guidelines.
Secure Disposal: Use secure methods to dispose of evidence when it is no longer
needed, including data wiping or physical destruction of storage media.
Evidence Handling Procedures
6. Compliance and Auditing
**6.1. Compliance with Standards:
Adherence to Guidelines: Follow industry standards and guidelines for
digital evidence handling, such as those from the National Institute of
Standards and Technology (NIST) and the International Organization
for Standardization (ISO).
Legal Requirements: Ensure compliance with relevant laws and
regulations governing digital evidence handling and data protection.
**6.2. Regular Audits:
Internal Audits: Conduct regular internal audits to review evidence
handling practices and ensure adherence to protocols.
External Audits: Engage external auditors or independent experts to
assess evidence handling procedures and provide recommendations for
improvements.
Evidence Handling Procedures
7. Best Practices for Evidence Handling
**7.1. Training and Education:
Ongoing Training: Provide regular training for personnel involved in evidence handling to ensure
they are familiar with current best practices and legal requirements.
Certification: Obtain relevant certifications to validate expertise in digital forensics and evidence
handling.
**7.2. Clear Procedures:
Standard Operating Procedures: Develop and maintain clear standard operating procedures (SOPs) for
evidence collection, preservation, analysis, and presentation.
Checklists: Use checklists to ensure that all necessary steps are followed during evidence handling.
**7.3. Documentation:
Detailed Records: Maintain comprehensive documentation of all evidence handling processes,
including collection, preservation, analysis, and presentation activities.
Audit Trails: Keep audit trails of all interactions with evidence to ensure transparency and
accountability.
Evidence Handling Procedures
Conclusion:
Evidence handling procedures are vital for ensuring
the integrity and reliability of digital evidence
throughout the investigative process. By
implementing robust controls for collection,
preservation, analysis, and presentation, forensic
professionals can maintain the credibility of their
work and uphold legal and ethical standards.
Proper training, adherence to best practices, and
continuous improvement are key to effective
evidence handling.
Basics of Indian
Evidence
The basics of Indian Evidence Law are primarily
governed by the Indian Evidence Act, 1872, which
provides the framework for the admissibility,
relevance, and weight of evidence in Indian courts.
This law is fundamental for legal practitioners and
anyone involved in the judicial process in India.
Here's a comprehensive overview of its key
principles:
Basics of Indian
Evidence
1. Overview of the Indian Evidence Act, 1872
The Indian Evidence Act, 1872, aims to provide a consistent set of rules for presenting evidence in legal
proceedings, ensuring that evidence is both relevant and reliable. It covers various types of evidence,
including oral, documentary, and electronic evidence, and addresses how evidence should be presented
and evaluated.
2. Key Principles
**2.1. Admissibility of Evidence:
Relevance: Evidence must be relevant to the case. Section 5 of the Act states that only relevant
evidence is admissible.
Admissibility Criteria: Evidence must be admissible under the law. The court will determine the
admissibility based on relevance, the nature of the evidence, and compliance with statutory
requirements.
**2.2. Types of Evidence:
Oral Evidence: Testimony provided by witnesses in court. It is governed by Sections 59 and 60,
which stipulate that oral evidence must be direct and come from witnesses who have firsthand
knowledge.
Documentary Evidence: Written or recorded evidence, including contracts, letters, and electronic
records. It is governed by Sections 61 to 78.
Electronic Evidence: Includes data from digital devices and communications. Sections 65A and 65B
provide specific provisions for the admissibility of electronic records.
Basics of Indian
Evidence
**2.3. Burden of Proof:
Definition: The burden of proof refers to the obligation to prove the
allegations made. It rests with the party who asserts the fact.
Sections 101 and 102: Section 101 places the burden of proving a fact on
the party who asserts it, while Section 102 provides that the burden of
proof lies on the party who would fail if no further evidence is presented.
**2.4. Presumptions and Inferences:
Presumptions: Certain presumptions are made under the law unless
disproven. For example, Sections 113 and 114 deal with
presumptions regarding the existence of certain facts.
Inferences: Courts can draw reasonable inferences from the evidence
presented. This allows the judge to determine the likely truth based on
the available evidence.
Basics of Indian
Evidence
**2.5. Documentary Evidence:
Proof of Documents: Documents must be proved by providing the original or a certified
copy, as per Sections 61 to 78.
Electronic Records: To be admissible, electronic records must meet the criteria established
in Section 65B, which requires that the data be accurately reproduced from a reliable source
and that proper procedures for data preservation are followed.
**2.6. Witness Testimony:
Competency of Witnesses: Witnesses must be competent to testify, meaning they must be able
to understand the questions and provide relevant answers. Sections 118 to 120 cover the
competency and examination of witnesses.
Impeachment of Witnesses: The credibility of a witness can be challenged. Sections 133 to
145 address the process of impeachment and cross-examination.
**2.7. Confessions and Admissions:
Confessions: Statements made by an accused person admitting guilt are governed
by Sections 24 to 30. A confession must be voluntary and not coerced.
Admissions: Statements made by a party in a case that admit certain facts are admissible
under Sections 17 to 23.
Basics of Indian
Evidence
3. Specific Provisions and Recent Amendments
**3.1. Electronic Evidence:
Section 65A and 65B: These sections were added by the Information Technology Act, 2000, to address
the admissibility of electronic records. They stipulate that electronic records must be produced in a
manner that ensures their authenticity and integrity.
**3.2. Testimonial Privileges:
Section 122: Provides that a married woman cannot be compelled to disclose any communication made to
her by her husband during marriage.
Section 126: Provides that an attorney cannot disclose communications between himself and his
client without the client’s consent.
**3.3. Expert Evidence:
Section 45: Expert opinions on technical matters or specialized knowledge are admissible. Experts must
be qualified in their field and their opinions should assist the court in understanding complex issues.
**3.4. Hearsay Rule:
General Rule: Hearsay evidence, or evidence based on what someone else has said outside of court, is
generally inadmissible. However, there are exceptions, including statements made in the course of
business, and statements against interest.
Basics of Indian
Evidence
4. Practical Considerations
**4.1. Preservation of Evidence:
Ensure that all evidence is preserved in its original state to maintain its
integrity. This applies to both physical and electronic evidence.
**4.2. Proper Documentation:
Maintain thorough documentation of all evidence collection, handling, and
analysis processes to support the validity and reliability of the evidence in
court.
**4.3. Legal Counsel:
Consult with legal professionals to ensure compliance with the Evidence Act and
other relevant laws, particularly when dealing with complex or sensitive
evidence.
**4.4. Continuous Learning:
Stay updated with amendments to the Evidence Act and relevant case law to ensure
that practices and procedures remain current and compliant with legal standards.
Basics of Indian
Evidence
Conclusion:
The Indian Evidence Act, 1872, provides a
comprehensive framework for handling evidence in
legal proceedings, focusing on the relevance,
admissibility, and proper presentation of evidence.
Understanding these principles is crucial for legal
practitioners, investigators, and forensic experts to
ensure that evidence is effectively managed and
utilized in the judicial process.
Electronic Communication Privacy ACT,
Legal Policies.
The Electronic Communications Privacy Act
(ECPA), enacted in the United States in 1986, is a
key piece of legislation that governs the
interception, access, and disclosure of electronic
communications.
The ECPA was designed to address the growing use
of digital communications and ensure privacy
protections in the evolving technological landscape.
Below is a comprehensive overview of the ECPA and
its related legal policies:
Electronic Communication Privacy ACT,
Legal Policies.
1. Overview of the Electronic Communications Privacy Act (ECPA)
**1.1. Purpose and Scope:
Purpose: The ECPA aims to protect the privacy of electronic communications
and data from unauthorized interception and access.
Scope: It applies to various forms of electronic communications, including emails,
telephone conversations, and stored communications.
**1.2. Structure: The ECPA is divided into three main sections:
Title I: Wiretap Act: Regulates the interception of wire, oral, and
electronic communications.
Title II: Stored Communications Act (SCA): Governs access to stored
electronic communications and transactional records.
Title III: Pen Register Act: Controls the use of pen registers and trap and trace
devices to capture dialing, routing, addressing, and signaling information.
Electronic Communication Privacy ACT,
Legal Policies.
2. Key Provisions of the ECPA
**2.1. Wiretap Act (Title I):
Prohibition: Prohibits the unauthorized interception of wire, oral, or electronic communications. This includes
listening to or recording conversations without consent.
Exceptions: Law enforcement agencies may intercept communications with a court order or if one party consents to the
interception. There are specific procedures for obtaining a wiretap warrant.
Penalties: Unauthorized interception can result in criminal and civil penalties, including fines and imprisonment.
**2.2. Stored Communications Act (SCA) (Title II):
Access to Stored Communications: Regulates access to communications stored by service providers, such as emails in a
user's account. It sets requirements for government access and requires subpoenas or court orders for disclosure.
Privacy Protections: Provides protections for the contents of communications and the records of communications,
such as email metadata.
Exceptions: There are exceptions for certain types of access, such as with user consent or in emergencies.
**2.3. Pen Register Act (Title III):
Pen Registers and Trap and Trace Devices: Regulates the use of devices that capture dialing, routing, addressing, and
signaling information. These devices do not capture the content of communications but record metadata.
Authorization: Law enforcement must obtain a court order to use these devices, demonstrating that the
information sought is relevant to an ongoing investigation.
Electronic Communication Privacy ACT,
Legal Policies.
3. Legal Policies and Considerations
**3.1. Privacy Protections:
Consent: One of the key principles under the ECPA is the requirement for consent. In general, interception or
access to communications requires consent from at least one party involved.
Expectations of Privacy: The ECPA protects communications from unauthorized interception and access based on a
reasonable expectation of privacy.
**3.2. Law Enforcement Access:
Court Orders and Warrants: Law enforcement must obtain court orders or warrants to intercept communications or access
stored data, except in certain emergencies or with consent.
Service Provider Compliance: Service providers are required to comply with legal orders and requests for
information but are protected from liability for actions taken in compliance with such orders.
**3.3. International Considerations:
Cross-Border Data Requests: Accessing electronic communications across borders can be complex due to varying privacy
laws and international treaties. The ECPA does not directly address international data requests but must be considered in the
context of global privacy and data protection regulations.
**3.4. Recent Amendments and Developments:
Modernization: There have been calls for updating the ECPA to reflect advancements in technology and changing privacy
expectations. The Email Privacy Act and other proposed amendments aim to modernize the law, particularly regarding
access to email and cloud-based communications.
**3.5. Related Legislation:
USA PATRIOT Act: The PATRIOT Act expanded surveillance capabilities and affected how the ECPA is applied,
especially concerning terrorism investigations.
Foreign Intelligence Surveillance Act (FISA): FISA governs surveillance for foreign intelligence purposes and may
intersect with ECPA provisions.
Electronic Communication Privacy ACT,
Legal Policies.
4. Compliance and Best Practices
**4.1. For Individuals:
Awareness of Rights: Understand your rights under the ECPA regarding the privacy of your
electronic communications.
Consent: Be mindful of consent requirements when communicating electronically or sharing
information online.
**4.2. For Organizations:
Policies and Procedures: Develop and implement policies for handling electronic
communications and data access to ensure compliance with the ECPA and other relevant
laws.
Legal Counsel: Consult with legal experts to navigate complex scenarios involving electronic
communications and privacy laws.
**4.3. For Law Enforcement:
Proper Procedures: Follow legal procedures for obtaining warrants or orders for
intercepting communications or accessing stored data.
Training: Stay updated on legal requirements and best practices for handling electronic
evidence and privacy concerns
Electronic Communication Privacy ACT,
Legal Policies.
Conclusion:
The Electronic Communications Privacy Act (ECPA)
is a crucial law designed to protect the privacy of
electronic communications and data. It establishes
guidelines for the interception, access, and disclosure of
electronic communications, balancing privacy rights with
law enforcement needs.
Understanding the ECPA and its related legal policies is
essential for individuals, organizations, and law
enforcement agencies to ensure compliance and protect
privacy.