CYBER SAFTY AND
SCEURITY
INTRODUCTION TO CYBER CRIME
What is cybercrime?
Cybercrime is any criminal activity that involves a computer, networked device
or a network.
While most cybercrimes are carried out in order to generate profit for the
cybercriminals, some cybercrimes are carried out against computers or
devices directly to damage or disable them. Others use computers or
networks to spread malware, illegal information, images or other materials.
Some cybercrimes do both -- i.e., target computers to infect them with a
computer virus, which is then spread to other machines and, sometimes,
entire networks.
A primary effect of cybercrime is financial. Cybercrime can include many
different types of profit-driven criminal activity, including ransomware attacks,
email and internet fraud, and identity fraud, as well as attempts to steal
financial account, credit card or other payment card information.
Cybercriminals may target an individual's private information or corporate data
for theft and resale. As many workers settle into remote work routines due to
the pandemic, cybercrimes are expected to grow in frequency in 2021, making
it especially important to protect backup data.
Defining cybercrime
The U.S. Department of Justice (DOJ) divides cybercrime into three
categories:
1. crimes in which the computing device is the target -- for example, to gain
network access;
2. crimes in which the computer is used as a weapon -- for example, to
launch a denial-of-service (DoS) attack; and
3. crimes in which the computer is used as an accessory to a crime -- for
example, using a computer to store illegally obtained data.
The Council of Europe Convention on Cybercrime, to which the U.S. is a
signatory, defines cybercrime as a wide range of malicious activities, including
the illegal interception of data, system interferences that compromise network
integrity and availability, and copyright infringements.
The necessity of internet connectivity has enabled an increase in the volume
and pace of cybercrime activities because the criminal no longer needs to be
physically present when committing a crime. The internet's speed,
convenience, anonymity and lack of borders make computer-based variations
of financial crimes -- such as ransomware, fraud and money laundering, as
well as crimes such as stalking and bullying -- easier to carry out.
Cybercriminal activity may be carried out by individuals or groups with
relatively little technical skill, or by highly organized global criminal groups that
may include skilled developers and others with relevant expertise. To further
reduce the chances of detection and prosecution, cybercriminals often choose
to operate in countries with weak or non-existent cybercrime laws.
How cybercrime works
Cybercrime attacks can begin wherever there is digital data, opportunity and
motive. Cybercriminals include everyone from the lone user engaged in
cyberbullying to state-sponsored actors, like China's intelligence services.
Cybercrimes generally do not occur in a vacuum; they are, in many ways,
distributed in nature. That is, cybercriminals typically rely on other actors to
complete the crime. This is whether it's the creator of malware using the dark
web to sell code, the distributor of illegal pharmaceuticals
using cryptocurrency brokers to hold virtual money in escrow or state threat
actors relying on technology subcontractors to steal intellectual property (IP).
Cybercriminals use various attack vectors to carry out them cyberattacks and
are constantly seeking new methods and techniques for achieving their goals,
while avoiding detection and arrest.
Cybercriminals often carry out their activities using malware and other types of
software, but social engineering is often an important component for executing
most types of cybercrime. Phishing emails are another important component
to many types of cybercrime but especially so for targeted attacks, like
business email compromise (BEC), in which the attacker attempts to
impersonate, via email, a business owner in order to convince employees to
pay out bogus invoices.
Types of cybercrime
As mentioned above, there are many different types of cybercrime. Most
cybercrimes are carried out with the expectation of financial gain by the
attackers, though the ways cybercriminals aim to get paid can vary. Some
specific types of cybercrimes include the following:
Cyberextortion: A crime involving an attack or threat of an attack coupled
with a demand for money to stop the attack. One form of cyberextortion is
the ransomware attack. Here, the attacker gains access to an
organization's systems and encrypts its documents and files -- anything of
potential value -- making the data inaccessible until a ransom is paid.
Usually, this is in some form of cryptocurrency, such as bitcoin.
Crypto jacking: An attack that uses scripts to mine cryptocurrencies within
browsers without the user's consent. Crypto jacking attacks may involve
loading cryptocurrency mining software to the victim's system. However,
many attacks depend on JavaScript code that does in-browser mining if
the user's browser has a tab or window open on the malicious site. No
malware needs to be installed as loading the affected page executes the
in-browser mining code.
Identity theft: An attack that occurs when an individual access a computer
to glean a user's personal information, which they then use to steal that
person's identity or access their valuable accounts, such as banking and
credit cards. Cybercriminals buy and sell identity information on darknet
markets, offering financial accounts, as well as other types of accounts,
like video streaming services, webmail, video and audio streaming, online
auctions and more. Personal health information is another frequent target
for identity thieves.
Credit card fraud: An attack that occurs when hackers infiltrate retailers'
systems to get the credit card and/or banking information of their
customers. Stolen payment cards can be bought and sold in bulk on
darknet markets, where hacking groups that have stolen mass quantities of
credit cards profit by selling to lower-level cybercriminals who profit through
credit card fraud against individual accounts.
Cyberespionage: A crime involving a cybercriminal who hacks into
systems or networks to gain access to confidential information held by a
government or other organization. Attacks may be motivated by profit or by
ideology. Cyberespionage activities can include every type of cyberattack
to gather, modify or destroy data, as well as using network-connected
devices, like webcams or closed-circuit TV (CCTV) cameras, to spy on a
targeted individual or groups and monitoring communications, including
emails, text messages and instant messages.
Software piracy: An attack that involves the unlawful copying, distribution
and use of software programs with the intention of commercial or personal
use. Trademark violations, copyright infringements and patent violations
are often associated with this type of cybercrime.
Exit scam: The dark web, not surprisingly, has given rise to the digital
version of an old crime known as the exit scam. In today's form, dark web
administrators divert virtual currency held in marketplace escrow accounts
to their own accounts -- essentially, criminals stealing from other criminals.
INTRODUCTION TO Cyber Safety:
What is Cyber Security?
Cyber Security is a process that’s designed to protect networks and devices from
external threats. Businesses typically employ Cyber Security professionals to protect
their confidential information, maintain employee productivity, and enhance customer
confidence in products and services.
The world of Cyber Security revolves around the industry standard of confidentiality,
integrity, and availability, or CIA. Privacy means data can be accessed only by
authorized parties; integrity means information can be added, altered, or removed only
by authorized users; and availability means systems, functions, and data must be
available on-demand according to agreed-upon parameters.
The main element of Cyber Security is the use of authentication mechanisms. For
example, a user name identifies an account that a user wants to access, while a
password is a mechanism that proves the user is who he claims to be.
What Motivates Cyber Criminals?
The main motive behind the cybercrime is to disrupt regular business activity and critical
infrastructure. Cybercriminals also commonly manipulate stolen data to benefit
financially, cause financial loss, damage a reputation, achieve military objectives, and
propagate religious or political beliefs. Some don’t even need a motive and might hack
for fun or simply to showcase their skills.
So, who are these cybercriminals? Here’s a breakdown of the most common types:
Black-Hat Hackers
Black-hat hackers use fake identities to conduct malicious activities for a profit
Gray-Hat Hackers
They work both with malicious intent and as legitimate security analysts
White-Hat Hackers
White-hat hackers work as security analysts to detect and fix flaws and protect against
malicious hackers
Suicide Hackers
They aim to openly bring down the critical infrastructure for a social cause
Script Kiddies
They are unskilled hackers who run scripts and software created by more experienced
hackers
Cyber Terrorists
They create fear by disrupting large-scale computer networks; motivated by religious or
political beliefs
State-Sponsored Hackers
They penetrate government networks, gain top-secret information, and damage information
systems; paid by a hostile government
Hacktivists
Promote political agendas by secretly defacing and disabling websites
CONCEPT AND USE OF CYBER HYGIENE IN DAILY
LIFE:
What Is Cyber Hygiene and Why Does It Matter?
Cyber hygiene is a set of habitual practices for ensuring the safe handling of critical data
and for securing networks. It’s like personal hygiene, where you develop a v
routine of small, distinct activities to prevent or mitigate health problems. Cyber hygiene
practices include the inventory of all endpoints connected to a network, vulnerabilities
management, and the patching of software and applications.
As cyberattacks have increased around the world—interrupting businesses and government
operations, and often leading to massive ransomware pay-outs and damaged corporate
reputations—cyber hygiene has become a key method for creating operational resilience.
Consider the disruption caused by the COVID-19 pandemic, which created opportunities for
criminal hackers through email phishing, supply chain attacks, and password and malware
attacks that preyed on millions of remote workers’ devices. Already in the first half of 2021, the
global ransomware attacks have hit 304.7 million, surpassing last year’s total of 304.6 million.
In response, the White House has urged government and business leaders to protect themselves
by implementing foundational cyber hygiene best practices, noting that it is their critical
responsibility to protect against threats with a strengthening of our nation’s resilience against
cyberattacks. That’s because cyber hygiene is one of the surest ways to improve any
organization’s overall security posture and defend against threats now and in the future.
Why is cyber hygiene important?
Cyber hygiene helps prevent cybercriminals from breaching an organization’s network—or at
least raises the opportunity cost, making it so hard that the criminal gives up and goes looking for
another victim. It’s true that many of today’s attacks are increasingly sophisticated, relying on
social engineering to get a victim to divulge sensitive information, targeting “whales” (high-level
executives), or deploying malware in a supply chain that can then infect hundreds of others.
$304.7The total (in millions) of global ransomware attacks in the first half of 2021,
already surpassing last year’s total of $304.6 million
The fact is, most successful attacks are the result of routine lapses—failing to know
what endpoints are connecting to your network, to consistently and rapidly monitor and
deploy patch updates, to make the correct security configurations, and to rapidly identify and
resolve breaches before they can harm core business operations. Cyberattacks take advantage of
these missteps.
You can’t blame complacent or uninformed IT managers, administrators and security engineers.
Rather, the failures are a product of the complexity and dynamism of modern IT environments.
The typical business network includes an array of computers, servers, databases, virtual
machines, mobile devices, operating systems, applications, and tools, each of which is a potential
attack vector. If these aren’t regularly and properly maintained, it can result in lost or
misplaced data, unpatched software, outdated user privileges, and other issues. In this way, an
environment grows more vulnerable over time and leaves you with multiple points of exposure.
Cyber hygiene helps reduce those vulnerabilities by identifying risks and deploying mechanisms and
strategies to reduce or resolve them. By practicing cyber hygiene, organizations strengthen their security
posture and can more effectively defend themselves against devastating breaches.
How do you assess your cyber hygiene?
Cyber hygiene is assessed using a performance monitoring solution that scans your IT
environment to discover your various assets and to identify vulnerabilities. The results are
presented as a scorecard that quantifies the health of your IT estate. Vulnerabilities are given a
severity level of “critical,” “high,” “medium,” or “low” based on the Common Vulnerability
Scoring System (CVSS), an open industry standard for rating a computer system’s security
vulnerability.
These vulnerabilities can be sorted by asset criticality, so you can see which will have the most
significant business impact. For example, an unpatched vulnerability on the CEO’s laptop would
warrant more immediate attention than one on the interns.
“Cyber hygiene helps prevent breaching a
network—or makes it so hard that the
criminal gives up and goes looking for
other victims.”
Cyber hygiene assessments help overcome two of the biggest obstacles to effective security:
incomplete visibility into the IT environment and inadequate resources to respond to issues.
Risk scoring surfaces the most critical vulnerabilities and prioritizes them. This allows IT teams
to allocate their resources toward closing the most critical security gaps first before moving on to
lower priority issues.
What are the benefits of cyber hygiene?
Good cyber hygiene offers several benefits that ultimately put your organization in a better
position to defend against cyberattacks. Specifically, it helps you:
Locate unmanaged assets: You can’t protect what you can’t see. That’s why an accurate
inventory of all your assets is the foundation for strong cybersecurity. Good cyber hygiene
practices allow you to maintain an up-to-date asset inventory, identify vulnerabilities associated
with any particular asset, and quickly resolve security gaps.
Protect customer data: Cyber hygiene supports a range of proven security practices, such as
patch management, password discipline, appropriate administrator privileges, and other measures
that improve data protection.
Find outdated administrator privileges: It’s easy to lose track of administrative rights as people
move from one role or department to another or leave the company. But high-level administrative
controls pose a significant security risk, so it’s important to regularly audit who has
administrative privileges and how often they’re used. Outdated or long-forgotten privileges need
to be immediately updated or revoked.
Identify rogue software: Remote work has led many workers to install unsanctioned
software on the devices and endpoints they use to connect to your network. That’s a problem.
Chances are, that software hasn’t been properly configured, patched, updated, or secured, making
it an attractive target for attackers. Cyber hygiene helps IT administrators gain visibility into all
the software installed and used on their network so they can manage it or remove it.
Meet compliance requirements: By identifying and prioritizing security risks and empowering
IT teams to quickly remediate them, cyber hygiene makes it easier to track and report your
organization’s security status and ensures it’s always aligned with regulatory and compliance
requirements.
INTRODUCTION TO SOCIAL
NETWORKS:
Social Networking refers to grouping of individuals and organizations together via
some medium, in order to share thoughts, interests, and activities.
There are several webs based social network services are available such as
Facebook, twitter, LinkedIn, Google+ etc. which offer easy to use and interactive
interface to connect with people with in the country an overseas as well. There are
also several mobile based social networking services in for of apps such as
WhatsApp, hike, Line etc.
What is Social Networking?
Social networking is an online platform that people uses to develop a social
relationship with others with similar thoughts and personal interest,
backgrounds, real-time connections or career activities. There are several
social media networking sites for instant messaging, sharing or posting views,
and much more. Trillions of people over the world connect through social
networking to share views on a personal level. But most people use social
networking to interact with their family and friends to gain knowledge or for
entertainment purposes. Business people use social media to plan the target
audience and execute it via attractive advertisements that pop out when
related to a search. It also helps them trace the audience’s ideas by throwing
multiple options to the customer, getting feedback from the client ends, and
promoting it in a reachable way by elevating their business to the next level.
The specialist also uses social media to enhance the knowledge in the related
fields and develop a network with like-mind people in a similar industry and
support each other in their career growth. It is termed as group-cantered,
which is described as websites that simplify the building of complex systems
to share the various types of content webspace. It offers an interaction space
to persist out the interaction of the person. The interactions via computer
networks support and build new social tie-ups. It is popularly emerging as an
online community.
The success of the social networking site can be visible in their supremacy in
civilization. For example, Facebook which connects trillions of people from
nook and corner of the world. An average of fourteen billion users is an active
user who logs in daily to see and update their news feed. LinkedIn is a career-
based social networking site where professionals share their opening related
to a product. The company publishes its achievements on the site to get the
world’s attention. Some unique features in social networking are that they
share a mutual connection with people and help us to contact our old missed
friends. The social network includes online shopping where people do not
even connect to a person sitting at home; he can get his things without
stepping out. The product will be delivered to his doorstep. It can be noticed
that the product you search for in Google, will be popped out in your
Facebook newsfeed, Instagram and Twitter advertisement. Other than this, it
will throw a notification that this product has some special offer codes.
Everything you search on google or discuss with your friends in some chatting
app is tracked and traced by social networking, which allows all the businesses
and corporates to develop their enterprise by fooling the people around.
Available Social networking Services
The following table describes some of the famous social networking services provided
over web and mobile:
S.N Service Description
.
1. Facebook
Allows to share text, photos, video etc. It also offers interesting online games.
2. Google+
It is pronounced as Google Plus. It is owned and operated by Google.
3. Twitter
Twitter allows the user to send and reply messages in form of tweets. These tweets are the small
messages, generally include 140+ characters.
4. Faceparty
Faceparty is a UK based social networking site. It allows the users to create profiles and interact
with each other using forums messages.
5. LinkedIn
LinkedIn is a business and professional networking site.
6. Flickr
Flickr offers image hosting and video hosting.
7. Ibibo
Ibibo is a talent based social networking site. It allows the users to promote one’s self and also
discover new talent.
8. WhatsApp
It is a mobile based messaging app. It allows to send text, video, and audio messages
9. Line
It is same as WhatsApp. Allows to make free calls and messages.
10. Hike
It is also mobile based massager allows to send messages and exciting emoticons.