0% found this document useful (0 votes)
9 views19 pages

Cyber Security Overview and Challenges

The document provides an overview of cyber security, defining it as the protection of internet-connected systems from attacks and unauthorized access. It discusses the importance of internet governance, challenges in establishing regulations, and various types of cyber threats and crimes, including cyber warfare, cyber terrorism, and online frauds. Additionally, it categorizes cybercriminals and outlines different forms of cybercrime affecting individuals, organizations, and society.

Uploaded by

shubham03270210
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
9 views19 pages

Cyber Security Overview and Challenges

The document provides an overview of cyber security, defining it as the protection of internet-connected systems from attacks and unauthorized access. It discusses the importance of internet governance, challenges in establishing regulations, and various types of cyber threats and crimes, including cyber warfare, cyber terrorism, and online frauds. Additionally, it categorizes cybercriminals and outlines different forms of cybercrime affecting individuals, organizations, and society.

Uploaded by

shubham03270210
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

NAME: Ayushi Sen

ENROLLMENT
NO:07711804423
UNIT-1

Introduction to Cyber Security


Cyber security is the most concerning matter as cyber threats and attacks are
overgrowing. Attackers are now using more sophisticated techniques to target the
systems. Individuals, small-scale businesses or large organizations, are all being impacted.
So, all these firms whether IT or non-IT firms have understood the importance of Cyber
Security and are focusing on adopting all possible measures to deal with cyber threats.

What is cyber security?


"Cyber security is primarily about people, processes, and technologies working together to
encompass the full range of threat reduction, vulnerability reduction, deterrence,
international engagement, incident response, resiliency, and recovery policies and
activities, including computer network operations, information assurance, law
enforcement, etc."

OR

Cyber security is the body of technologies, processes, and practices designed to protect
networks, computers, programs and data from attack, damage or unauthorized access.

•The term cyber security refers to techniques and practices designed to protect digital
data.
•The data that is stored, transmitted or used on an information system.

OR

Cyber security is the protection of Internet-connected systems, including hardware,


software, and data from cyber attacks.

It is made up of two words one is cyber and other is security.

•Cyber is related to the technology which contains systems, networks and programs or
data.
•Whereas security related to the protection which includes systems security, network
security and application and information security.

What is Internet Governance?


Internet governance refers to the mechanisms, policies, and principles that guide the use
and development of the Internet. It involves various stakeholders, including governments,
private sector entities, technical experts, and civil society, working together to ensure the
effective functioning, security, and accessibility of the global network.

Challenges and Constraints:


1. Global Nature: The Internet operates globally, making it challenging to establish
universally accepted rules and regulations that cater to the diverse needs and legal
frameworks of different countries.

2. Cybersecurity Threats: The increasing frequency and sophistication of cyber threats


pose a significant challenge to Internet governance. Addressing issues such as hacking,
data breaches, and cyber attacks requires international cooperation.

3. Privacy Concerns: Balancing the need for security with individuals' right to privacy is a
constant challenge. Issues such as data collection, surveillance, and the protection of
personal information create tensions in Internet governance discussions.

4. Content Regulation: Determining what content is acceptable or legal on the Internet is a


complex task, with different countries and cultures having varying perspectives on
issues such as hate speech, misinformation, and online extremism.

5. Digital Divide: The uneven distribution of Internet access and resources globally creates
a digital divide. Bridging this gap and ensuring equal access for all is a persistent
challenge.

6. Intellectual Property: Protecting intellectual property rights while fostering innovation is


a delicate balance. Disputes over copyright infringement, patent issues, and digital
piracy contribute to the challenges in Internet governance.

7. Net Neutrality: The concept of net neutrality, which advocates for equal treatment of all
Internet traffic, faces challenges as some entities seek to prioritize or throttle certain
types of content or services.

8. Fragmentation: Divergent regulations and policies among countries can lead to the
fragmentation of the Internet. This may hinder the seamless flow of information and
services across borders.

9. Emerging Technologies: Rapid advancements in technologies such as artificial


intelligence, blockchain, and the Internet of Things present new governance
challenges, including ethical considerations and potential risks.

10. Lack of Universal Standards: The absence of universally agreed-upon standards for
various aspects of the Internet, including protocols, cybersecurity measures, and data
governance, poses challenges to creating a cohesive global framework.

Cyber Threats
1. Cyber Squatting
● Definition: Cyber Squatting involves registering, selling, or using a domain name
with the intent of profiting from someone else's trademark. The squatter typically
offers the domain to the trademark owner at an inflated price.
● Example: Registering a domain name similar to a well-known brand and trying to sell
it to the brand owner for a profit.

2. Cyber Warfare
● Definition: Cyber Warfare refers to actions by a nation-state or international
organization to attack and damage another nation's computers or information
networks. It is often considered an extension of traditional warfare into the digital
realm.
● Example: Disabling a country's critical infrastructure like power grids,
communication networks, or financial systems through cyber attacks.

3. Cyber Terrorism

● Definition: Cyber Terrorism involves the use of computer networks to


create fear or threaten significant harm in pursuit of political, religious,
or ideological goals. Unlike cyber warfare, it is often conducted by non-
state actors.
● Example: Hacking into a government network to steal sensitive data or
disrupt services to cause panic among the population.

4. Cybercrime

● Definition: Cybercrime encompasses illegal activities carried out using


computers or the internet. This can include identity theft, financial fraud,
hacking, and other forms of malicious activities.
● Example: Phishing scams where cybercriminals trick individuals into
revealing personal information, like credit card numbers or passwords.

5. Cyber Offenses

● Definition: Cyber Offenses refer to any criminal activity that targets or uses a
computer or network. This term is often used more broadly to include any
illegal activity facilitated by or involving the internet or digital technologies.
● Example: Unauthorized access to a computer system, distribution of
malware, or denial of service attacks (DDoS).

Who are Cybercriminals?


Cybercrime involves such activities as child pornography, credit card fraud, cyberstalking,
defaming another online, gaining unauthorized access to computer systems, ignoring
copyright, software licensing and trademark protection, overriding encryption to make
illegal copies, software piracy and stealing another’s identity (known as identity theft).
Cybercriminals are those who conduct such acts.

They can be categorized into three groups:

1. Type I: Cybercriminals - hungry for recognition

● Hobby hackers
● IT professionals (social engineering is one of the biggest threat)
● politically motivated hackers
● Terrorist organizations
2. Type II: Cybercriminals - not interested in recognition
● Psychological perverts
● Financially motivated hackers (corporate espionage)
● State-sponsored hacking (national espionage, sabotage)
● Organized criminals

3. Type III: Cybercriminals - the insiders

● Disgruntled or former employees seeking revenge


● Competing companies using employees to gain economic advantage
through damage and/or theft.

Classification of Cybercrimes
Cybercrimes are classified as follows:

1. Cybercrime against Individual


● E-Mail Spoofing
● Phishing, and its other forms
● Spamming
● Cyberdefamation
● Cyberstalking and harassment
● Computer sabotage
● Pornographic offenses
● Password sniffing

2. Cybercrime against Property


● Credit card frauds
● Intellectual property (IP) crimes

3. Cybercrime against Organization


● Unauthorized accessing of computer
● Password sniffing
● Denial-of-service attacks (DoS attacks)
● Virus attack
● E-mail bombing/mail bombs
● Salami attack/ Salami technique
● Logic bomb
● Trojan Horse
● Data diddling
● Crimes emanating from Usenet newsgroup
● Industrial spying/ industrial espionage
● Computer network intrusions
● Software piracy

4. Cybercrime against Society


● Forgery
● Cyberterrorism
● Web jacking

5. Crimes emanating from Usenet newsgroup

Some of the cybercrime forms are mentioned below:

1. E-Mail Spoofing
Email spoofing is the process of sending emails with a forged sender address. It deceives
the recipient into believing that the email is sent by someone they know or trust. It’s
usually a phishing tool designed to take over your online accounts, send malware, or steal
money.

For example, an attacker could send an email that appears to be from PayPal. The
message alerts the reader that their account has been limited. And to check the account
details, the user should click on the link.

2. Spamming
Spamming in cybersecurity is the act of sending unsolicited messages, often with
commercial or malicious purposes, to a large number of people. E-mails, texts & instant
messages can be used as forms of communication. Spamming can be used to spread
malware, steal personal information, or promote scams & phishing schemes. It can also be
used to overload networks & servers, causing them to crash. It is important for individuals
to be cautious when opening emails or messages from unknown senders, & to avoid
clicking on suspicious links or providing personal information.

3. Cyberdefamation
Cyber defamation, also known as online defamation, refers to the act of making false
statements about someone on the internet that harm their reputation. This can include
posting defamatory content on social media, blogs, forums or other online platforms.
Cyber defamation can take various forms, such as spreading rumours, making false
accusations or posting negative reviews with the intent to harm someone’s reputation. It
can have serious consequences, including damage to the victim’s personal or professional
life, loss of job opportunities or mental health issues.

4. Internet Time Theft


This occurs when an unauthorized person uses the Internet hours paid for by another
person. Basically, Internet time theft comes under hacking because the person who gets
access to someone else’s ISP user ID and password, either by hacking or by gaining access
to it by illegal means, uses it to access the Internet without the other person’s knowledge.

5. Salami Attack/Salami Technique


These attacks are used for committing financial crimes. The idea here is to make the
alteration so insignificant that in a single case it would go completely unnoticed. For
example, a bank employee inserts a program into the bank’s server that deducts a small
amount of money (say Rs.2/- or a few cents in a month) from the account of every
customer. No account holder will probably notice this unauthorized debit, but the bank
employee will make a sizable amount every month.

6. Data Diddling
A data diddling attack involves altering raw data just before it is processed by a computer
and then changing it back after the processing is completed. Electricity Boards in India
have been victims to data diddling programs inserted when private parties computerize
their systems.

7. Forgery
Counterfeit currency notes, postage and revenue stamps, marksheets, etc. can be forged
using sophisticated computers, printers and scanners. Outside many colleges there are
miscreants soliciting the sale of fake marksheets or even certificates. These are made
using computers and high quality scanners and printers. In fact, this is becoming a
booming business involving large monetary amount given to students gangs in exchange
for these bogus but authentic looking certificates.

8. Web Jacking
Web jacking occurs when someone forcefully takes control of a website (by cracking the
password and later changing it). Thus, the first stage of this crime involves “password
sniffing”. The actual owner of the website does not have any more control over what
appears on that website.

9. Newsgroup Spam/Crimes Emanating from Usenet Newsgroup


Usenet newsgroups are discussion forums that originated in the early days of the internet,
allowing users to share messages, articles, and files on various topics. They are structured
like bulletin boards, where people post messages (known as "articles") in different
categories, called newsgroups. These newsgroups cover a wide range of subjects, from
technology and science to hobbies and entertainment.

They have become a platform for spam and criminal activities due to their anonymity and
decentralized structure. Common forms of spam include unsolicited ads, malware
distribution, phishing, and SEO link spamming. Crimes on Usenet involve the distribution of
illegal content like pirated media and child exploitation, drug trade discussions, hate
speech, extremist ideologies, and fraudulent schemes. In response, ISPs filter harmful
content, while law enforcement monitors for criminal activity. Anti-spam tools and
community moderation also help mitigate misuse.

10. Industrial Spying/Industrial Espionage


Industrial spying, also known as industrial espionage, refers to the illegal and unethical
practice of gathering confidential information from a business or organization, often for
competitive advantage. The goal is typically to steal trade secrets, proprietary technology,
business strategies, or other sensitive data that can be used by competitors to gain an
upper hand in the market. This type of espionage can be conducted by rival companies,
foreign governments, or insiders within the targeted organization.

11. Hacking
The main purposes of hacking are as follows:
1. Greed
2. Power
3. Publicity
4. Revenge
5. Adventure
6. Desire to access forbidden information.
7. Destructive mindset
Every act committed toward breaking into a computer and/or network is Hacking and it is
an offense. Hackers write or use ready-made computer programs to attack the target
computer.

● They possess the desire to destroy and they get enjoyment out of such
destruction.
● Some hackers hack for personal monetary gains, such as stealing credit card
information, transferring money from various bank accounts to their own
account followed by withdrawal of money.
● They extort money from some corporate giant threatening him to publish the
stolen information that is critical in nature.
● Hackers attack government websites to receive wide press coverage.

12. Online Frauds


Online frauds are deceptive activities conducted over the internet with the intent to steal
money, personal information, or other assets from individuals or businesses. These types
of fraud have become increasingly common as digital transactions and online interactions
have grown. They often rely on exploiting human vulnerabilities or weaknesses in
cybersecurity.

Common Types of Online Frauds:

● Phishing:
➢ Description: Fraudsters send fake emails or messages that appear to be from
legitimate companies or institutions (e.g., banks, social media platforms) to
trick people into providing sensitive information like passwords, credit card
numbers, or social security numbers.
➢ Example: Receiving an email that looks like it's from your bank asking you to
verify your account by clicking a link and entering your credentials.

● Identity Theft:
➢ Description: Cybercriminals steal someone's personal information, such
as social security numbers or financial data, to impersonate them for
fraudulent purposes, including opening bank accounts or applying for
loans.
➢ Example: Someone using your personal information to take out a
loan or file a fraudulent tax return in your name.

● Credit Card Fraud:


➢ Description: This involves stealing or illegally using someone’s credit card
details to make unauthorized purchases or transactions.
➢ Example: Your credit card number is stolen and used to make online
purchases without your consent.

● Online Shopping Scams:


➢ Description: Fake online stores or fraudulent sellers deceive customers
by offering non-existent products or not delivering items after receiving
payment.
➢ Example: Buying an item from an online store, paying for it, but never
receiving the product.
● Investment Fraud:
➢ Description: Fraudsters promote fake investment opportunities, often
promising high returns with little risk, to trick people into investing money.
➢ Example: A website offering unusually high returns for investing in
cryptocurrency or stocks, but disappearing once funds are deposited.

● Lottery and Prize Scams:


➢ Description: Victims are notified via email or message that they’ve won a
lottery or prize, but to claim it, they must first pay a fee or provide
personal information.
➢ Example: Receiving an email claiming you’ve won a foreign lottery and
asking for your banking details to transfer the winnings.

● Romance Scams:
➢ Description: Fraudsters create fake profiles on dating websites or social
media to form relationships with victims and eventually request money,
claiming they need help with emergencies or other personal issues.
➢ Example: Someone you’ve been communicating with online for months asks
you to wire money for an emergency.

● Work-From-Home Scams:
➢ Description: Scammers offer fake job opportunities, particularly work-
from-home positions, but ask victims to pay upfront for training,
supplies, or software.
➢ Example: Applying for a remote job that asks you to pay for training
materials, but the job offer turns out to be fake.

● Tech Support Scams:


➢ Description: Fraudsters pose as technical support agents from reputable
companies, claiming there’s a problem with your computer or device, and
request payment to fix it or access to your system.
➢ Example: Getting a pop-up or phone call stating that your computer has
been infected, and you need to pay for "support" to fix it.

● Advance Fee Fraud:


➢ Description: Victims are promised large sums of money (such as inheritance,
business loans, or investment returns) in exchange for paying a small
advance fee. Once the fee is paid, the fraudsters disappear.
➢ Example: Someone claiming to be a foreign official offers you a large
inheritance in exchange for paying a processing fee upfront.

13. Computer Sabotage


Intentional harm or damage to computer systems, data, or networks to disrupt
services or cause financial loss. Example:
● An employee deletes critical company data before quitting, resulting in business
disruption.
● In 2010, the Stuxnet worm was used to sabotage Iran’s nuclear program by
damaging centrifuges used for uranium enrichment.

14. E-mail Bombing


Flooding a target’s email inbox with massive amounts of emails, causing disruption to email
services or making the inbox unusable. Example:

● A disgruntled user sends thousands of automated emails to a company's support


inbox to slow down or crash their email system.
● In 1996, the Internet Liberation Front used email bombing to target the
Massachusetts Institute of Technology (MIT) email servers.

15. Computer Network Intrusion


Unauthorized access to a computer network, often to steal data, install malware, or disrupt
operations. Example:
● A hacker gains access to a company’s internal network by exploiting weak
security protocols and steals customer information.
● The Equifax data breach (2017) was a result of a network intrusion that led to
the theft of personal data of over 140 million people.

16. Password Sniffing


Capturing and stealing passwords as they are transmitted over a network using
packet sniffers or malware. Example:
● A cybercriminal uses a tool like Wireshark to monitor network traffic at a
coffee shop’s public Wi-Fi and capture login credentials of users accessing
unsecured websites.
● In 2009, a phishing attack targeting Gmail users led to attackers sniffing
passwords, gaining unauthorized access to emails.

17. Credit Card Frauds


Description: Unauthorized use of someone’s credit card information to make
purchases or withdraw money. Example:
A hacker steals credit card details from an online store and uses them to make
unauthorized purchases.
The Target data breach (2013) saw hackers stealing 40 million credit and debit
card numbers from Target’s customers.

18. Identity Theft


Description: Using someone else's personal information (like name, Social Security
number, credit card details) without permission, often for financial gain. Example:

● A cybercriminal uses another person’s Social Security number to open a


credit card account and racks up huge debts in their name.
● The Yahoo data breach (2013) exposed over 3 billion users’ data, making
many vulnerable to identity theft.

19. Pornographic Offenses


Description: Crimes related to the creation, distribution, or possession of illegal
pornographic content, especially involving minors. Example:
● Someone downloads or distributes child pornography, which is illegal in most
countries.
● In 2014, a FBI operation led to the takedown of an illegal online platform that
distributed child exploitation material.

20. Software Piracy


The illegal copying, distribution, or use of software without proper licensing or
authorization. Example:
● A person downloads a cracked version of Microsoft Office from a torrent website
instead of buying a legitimate license.
● In 2009, The Pirate Bay, a torrent site, was taken to court for enabling users to
download pirated software, games, and movies.

Cybercrime-Mobile and Wireless Devices

1. Proliferation of Mobile and Wireless Devices

With the rapid growth of mobile devices (smartphones, tablets, etc.) and wireless networks,
cybercriminals have shifted their focus to these platforms. The increase in mobile usage
makes them a prime target for various forms of cyberattacks, including:

● Mobile Malware: Malicious software targeting mobile operating systems like Android
or iOS.
● Phishing: Mobile devices are highly vulnerable to phishing attempts through
emails, SMS, and social media.
● Data Theft: Mobile apps can collect and misuse personal data or share it with
third parties without user consent.

Example:
The Pegasus spyware attack targeted high-profile individuals' mobile devices to steal
sensitive data via vulnerabilities in messaging apps like WhatsApp.

2. Authentication Service Security

Mobile devices rely on various authentication methods, such as passwords, biometrics


(fingerprint, facial recognition), and two-factor authentication (2FA). If these authentication
mechanisms are compromised, they can lead to unauthorized access.

● Vulnerabilities in Authentication: Attackers may exploit weak passwords, or bypass


biometric security through spoofing techniques.
● SIM Swap Attacks: Hackers trick mobile carriers into transferring control of a
victim’s phone number to another SIM card, allowing them to intercept 2FA
codes and access accounts.

Example:
In 2021, T-Mobile experienced a data breach where attackers used stolen information to
perform SIM swapping and access user accounts.
3. Attacks on Mobile Phones

Cybercriminals use various methods to compromise mobile devices, including:

● Mobile Malware: Trojans, ransomware, and spyware targeting mobile devices.


● Man-in-the-Middle (MITM) Attacks: Attacks where cybercriminals intercept
communication between the user and service providers, especially on
unsecured public Wi-Fi networks.
● Phishing & SMiShing (SMS Phishing): Attackers send deceptive SMS messages
to trick users into revealing personal information or installing malware.

Example:
In 2020, Joker malware affected over 1,700 Android apps, infecting devices and stealing
users' SMS messages, contact lists, and device information.

4. Security Implications for Organizations

The widespread use of mobile devices in business environments creates several security
challenges for organizations:

● BYOD (Bring Your Own Device) Policies: Allowing employees to use their own
devices for work can introduce security risks like data leakage and malware
infection.
● Data Loss and Breaches: Sensitive organizational data can be lost or stolen if
mobile devices are lost, stolen, or compromised by hackers.
● Insecure Mobile Applications: Business apps might have vulnerabilities, putting
sensitive company information at risk.

Example:
In 2018, Uber suffered a data breach due to poorly implemented mobile security
protocols, leading to the exposure of millions of users' and drivers' data.

5. Measures for Handling Mobile Devices

Organizations and individuals should adopt strict security measures to protect mobile
devices from cyberattacks:

For Individuals:

● Use Strong Authentication: Enable multi-factor authentication (MFA) and use


strong passwords combined with biometrics.
● Install Security Software: Use antivirus and anti-malware software specifically
designed for mobile devices.
● Regular Updates: Ensure the device’s operating system, apps, and security
patches are updated frequently.
● Avoid Public Wi-Fi: Use Virtual Private Networks (VPNs) to secure
communications when accessing the internet over public Wi-Fi networks.
● App Permissions: Be cautious of permissions requested by mobile apps, and only
download apps from trusted sources like Google Play or the Apple App Store.

For Organizations:

● Mobile Device Management (MDM): Implement MDM solutions to control and


monitor employees' mobile devices, ensuring compliance with corporate
security policies.
● Encrypt Data: Enable encryption on all mobile devices to protect sensitive data,
especially for corporate devices or employees’ BYOD devices.
● Secure Communication Channels: Use encrypted communication
channels for business-critical data and prohibit the use of unsecured
apps or services.
● Security Awareness Training: Train employees on how to identify phishing
attacks, secure their devices, and maintain good cyber hygiene.
● Remote Wipe Capabilities: Implement solutions that allow for remotely wiping
sensitive data from a lost or stolen device.

Example:
Many organizations use MDM solutions like VMware Workspace ONE or Microsoft Intune
to manage corporate-owned and BYOD mobile devices securely.

Conclusion:

As mobile and wireless devices become more ubiquitous, they also become prime targets
for cybercriminals. Both individuals and organizations need to prioritize mobile security by
implementing robust authentication, malware protection, and data encryption to reduce
the risk of cyberattacks.

Cyber Offenses
Cyber offenses refer to illegal activities carried out using computers, networks, or the
internet. These crimes can take various forms and target individuals, businesses, or
governments. Let's break down key categories and types of offenses related to
cybercrime:

1. Categories of Cyber Offenses

Cyber offenses are generally divided into the following categories:

● Cyber-Dependent Crimes: Crimes that can only occur using computers or networks,
such as hacking, DDoS (Distributed Denial of Service) attacks, and malware
distribution.
● Cyber-Enabled Crimes: Traditional crimes that are expanded or facilitated by
the use of technology, such as fraud, identity theft, and stalking.
● Crimes Against Individuals: Targeting individuals with offenses like cyberstalking,
harassment, and identity theft.
● Crimes Against Organizations or Businesses: These include data breaches,
ransomware attacks, and corporate espionage.
● Crimes Against Governments: These include cyberterrorism, hacking into
government systems, and espionage.

2. Types of Cyber Attacks

Cyberattacks are the execution of offensive actions to compromise computer systems,


networks, or data. Common types include:

● Phishing: A fraudulent attempt to obtain sensitive information by posing as a


trustworthy entity, usually via email.
● Malware: Malicious software (like viruses, worms, ransomware, spyware) designed
to damage or gain unauthorized access to a computer system.
● Denial of Service (DoS) or Distributed Denial of Service (DDoS) Attacks:
Overwhelming a system or network with traffic to cause it to crash or become
unusable.
● Man-in-the-Middle (MITM) Attacks: Intercepting and potentially altering the
communication between two parties without their knowledge.
● SQL Injection: An attack targeting databases by injecting malicious SQL code
into a web application, compromising data.
● Zero-Day Exploits: Attacks that occur when hackers exploit a software
vulnerability before developers have a chance to fix it.

Example:
The WannaCry ransomware attack in 2017 affected hundreds of thousands of computers
globally, locking users out of their systems until a ransom was paid.

3. Social Engineering

Social Engineering refers to manipulating people into performing actions or revealing


confidential information. It exploits human psychology rather than technical vulnerabilities.

● Phishing: Sending fake emails that appear to be from legitimate organizations to


trick users into revealing personal information.
● Pretexting: Pretending to be someone in a position of authority to extract
information from a victim.
● Baiting: Offering something enticing, like free software or gifts, to trick a user into
downloading malware.
● Tailgating: Physically following an authorized person into a restricted area to bypass
security.

Example:
An attacker might pose as an IT technician and ask employees for their passwords to "fix"
an issue, which the attacker then uses for malicious purposes.
4. Cyberstalking

Cyberstalking is the use of electronic communication to harass or stalk an individual, often


with malicious intent. It involves tracking, threatening, or intimidating a person by using
the internet, social media, or other digital platforms.

● Harassment: Sending threatening or obscene messages repeatedly.


● Monitoring: Continuously following someone's online activities or using tracking
technologies to monitor their movements.
● Doxxing: Publishing private or sensitive information about someone without their
consent, often to harass or embarrass them.

Example:
In 2014, a case involving a college student in the U.S. led to the arrest of a cyberstalker who
had been harassing the victim through anonymous social media accounts for months.

5. Botnets

A Botnet is a network of computers that have been infected with malware and are
controlled remotely by cybercriminals, often without the owners' knowledge. These
computers, called “bots” or “zombies,” can be used for:

● Launching DDoS Attacks: Overwhelming a network with traffic from thousands of


infected computers.
● Spreading Malware: Botnets can distribute malware across multiple devices in a
coordinated attack.
● Sending Spam Emails: Botnets are frequently used to send out mass spam or phishing
emails.
● Cryptojacking: Using infected devices’ processing power to mine cryptocurrencies
without the owner’s consent.

Example:
The Mirai Botnet (2016) infected IoT (Internet of Things) devices and used them to launch
one of the largest DDoS attacks ever recorded, taking down major websites like Twitter,
Reddit, and Netflix.

6. Cloud Computing Security

As more businesses and individuals rely on cloud computing to store data and run
applications, the risk of cybercrime in this domain has increased. Key concerns include:

● Data Breaches: Unauthorized access to sensitive data stored on the


cloud due to misconfigurations or weak access controls.
● Account Hijacking: Cybercriminals gaining access to user credentials for cloud
services, allowing them to manipulate or steal data.
● Insecure APIs: Cloud services rely on APIs for communication, which can be
vulnerable to attacks if not properly secured.
● Denial of Service (DoS) Attacks: Cloud services can be targeted by DDoS
attacks, overwhelming the system and causing service outages.

Measures to Mitigate Cloud Security Risks:

● Encryption: Encrypting sensitive data both at rest and in transit.


● Access Control: Implementing multi-factor authentication (MFA) to secure accounts.
● Regular Audits: Conducting security audits to ensure compliance with best practices.

Example:
In 2019, the Capital One data breach occurred when a misconfigured Amazon Web Services
(AWS) firewall allowed a hacker to steal sensitive customer data stored in the cloud.

Conclusion:

Cybercrime in the modern age has evolved beyond traditional attacks, now encompassing
sophisticated social engineering tactics, mobile vulnerabilities, and cloud security issues.
With the rise of botnets and cyberstalking, organizations and individuals must adopt a
proactive approach to security, using encryption, multi-factor authentication, and regular
monitoring to mitigate threats.

You might also like