0% found this document useful (0 votes)
13 views11 pages

Cyber Crime Investigation Essentials

Module 4 covers the essentials of Cyber Crime Investigation, including its definition, objectives, phases, and the role of digital evidence. It classifies cyber crimes based on target, method, and motive, while also addressing the challenges faced in investigations such as technical, legal, and operational hurdles. Additionally, it discusses IP tracking, encryption methods, search and seizure procedures, recovering deleted evidence, and password cracking techniques.

Uploaded by

Vasanth
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views11 pages

Cyber Crime Investigation Essentials

Module 4 covers the essentials of Cyber Crime Investigation, including its definition, objectives, phases, and the role of digital evidence. It classifies cyber crimes based on target, method, and motive, while also addressing the challenges faced in investigations such as technical, legal, and operational hurdles. Additionally, it discusses IP tracking, encryption methods, search and seizure procedures, recovering deleted evidence, and password cracking techniques.

Uploaded by

Vasanth
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Module 4

Introduction to Cyber Crime Investigation, Classification of Cyber Crime, Challenges of


Cyber Crime, IP Tracking, Encryption and Decryption Methods, Search and Seizure of
Computers, Recovering Deleted Evidences, Password Cracking.

1. Introduction to Cyber Crime Investigation


1.1 Introduction
As the digital landscape expands, crimes conducted through cyberspace have become
increasingly complex. Traditional investigative methods that rely on physical evidence are
inadequate for uncovering digital traces left in cyberspace.

Cyber Crime Investigation involves specialized techniques to identify, collect, analyze, and
present digital evidence in cases where computers or networks are the medium, tool, or target
of the crime.
Example: When an online banking fraud occurs, investigators trace transaction logs, IP
addresses, and device identifiers to find the perpetrator.
1.2 Definition:
Cyber Crime Investigation is defined as:
“A systematic process of detecting, collecting, analyzing, and preserving digital evidence to
identify, apprehend, and prosecute offenders involved in cybercrimes.”
Simplified: It is the digital equivalent of a criminal investigation, focused on analyzing
electronic data instead of physical evidence.
1.3 Need for Cyber Crime Investigation
1. Increase in Cyber Offenses – Online scams, data theft, ransomware, and cyberstalking
require specialized investigation methods.
2. Legal Evidence – Courts accept digital evidence when it is scientifically collected and
authenticated.
3. Attribution of Offenders – IP tracking and digital fingerprints help identify anonymous
criminals.
4. Incident Response – Enables organizations to assess impact, recover data, and prevent
recurrence.
5. National Security – Cyber investigations aid intelligence agencies in preventing cyber
terrorism.
Example: In a phishing scam, investigators track fraudulent domains and payment wallets used
for transactions.
1.4 Objectives of Cyber Crime Investigation
1. Identification – Detect the source of attack, systems used, and affected resources.
2. Preservation – Protect volatile evidence from alteration or loss.
3. Analysis – Examine data for reconstructing events.
4. Attribution – Correlate evidence to identify suspects.
5. Reporting – Present findings in a form admissible in court.
1.5 Phases of Cyber Crime Investigation
1. Preparation – Setting up forensic tools, legal permissions, and planning.
2. Detection – Identifying occurrence and nature of cyber incident.
3. Collection – Acquiring digital evidence securely.
4. Analysis – Extracting, filtering, and interpreting data.
5. Documentation – Recording every action taken.
6. Presentation – Reporting findings to judicial authorities.
1.6 Role of Digital Evidence
Digital evidence includes emails, IP logs, browsing history, deleted files, and cloud data. It
must meet criteria of authenticity, integrity, reliability, and admissibility.
Example: Chat logs recovered from a suspect’s phone confirming extortion demands serve as
crucial evidence.

2. Classification of Cyber Crimes


2.1 Introduction
Cybercrimes can be classified on different bases — the target, the method used, or the
motivation of the attacker. Understanding classification helps investigators choose proper
forensic approaches.
2.2 Based on Target

Type Target Example

Identity theft, cyber


Crimes Against Individuals Personal identity or data
harassment

Digital assets, IP,


Crimes Against Property Hacking, ransomware
databases

Crimes Against
National security systems Cyber terrorism
Government/Society
Type Target Example

Corporate data or
Crimes Against Organizations Insider data theft
reputation

2.3 Based on Method of Attack


1. Technical Attacks – Hacking, malware, DDoS.
2. Social Engineering Attacks – Phishing, vishing, baiting.
3. Physical Access Attacks – Theft of storage media, unauthorized device connection.
4. Network-Based Attacks – Man-in-the-middle, sniffing, spoofing.

2.4 Based on Motive

Motive Description Example

Financial Gain Theft of money or data Online banking fraud

Disgruntled employees or personal


Revenge Website defacement
grudges

Political Ideological or hacktivist causes Cyber activism

Curiosity / Unauthorized access without


Thrill-seeking hackers
Challenge damage

Espionage Stealing confidential info Industrial spying

2.5 Comparative Table

Basis Category Example Case

Target Individual Online blackmail

Method Network DDoS on government site

Motive Financial Phishing for credit cards

3. Challenges of Cyber Crime


3.1 Introduction
Cybercrime investigations are more complex than traditional crimes because they occur in a
virtual environment with no physical evidence. Offenders exploit anonymity, using VPNs, fake
identities, and the dark web to conceal their location. Jurisdictional issues arise when crimes
cross international borders, making cooperation between countries difficult. Additionally, rapid
technological advancements and new attack methods constantly challenge investigators’ ability
to keep up.
3.2 Technical Challenges:
• Encryption & Anonymity: Strong encryption and hidden identities make accessing
evidence difficult.
• Large Data Volumes: Investigators must analyze millions of logs and files.
• Cloud Computing: Data stored across multiple countries complicates retrieval.
• Evolving Technology: Rapid advancements require constant tool and skill updates.
3.3 Legal Challenges:
• Jurisdiction Conflicts: Offenders and victims may be in different nations, causing legal
barriers.
• Lack of Uniform Cyber Laws: Varying privacy and data regulations hinder cooperation.
• Chain of Custody Issues: Mishandling evidence can make it inadmissible in court.
3.4 Operational Challenges:
• Limited Expertise: Shortage of trained cyber investigators.
• Resource Constraints: Forensic tools and infrastructure are expensive.
• Volatile Data Loss: Evidence in RAM or active sessions disappears if not captured
promptly.

3.5 Summary Table

Challenge Description Impact

Encryption Conceals data Delays investigation

Cloud Storage Cross-border data Legal hurdles

Tool Compatibility Varying OS/platforms Incomplete analysis

Skilled Personnel Shortage of experts Slower response

4. IP Tracking
4.1 Introduction:
Every online activity generates an IP (Internet Protocol) address, serving as a digital footprint.
IP tracking is an essential part of identifying sources of cyber activity.
4.2 Understanding IP Addresses
• IPv4 – 32-bit address (e.g., [Link])
• IPv6 – 128-bit address (e.g., 2001:0db8::1)
Each is assigned dynamically (temporary) or statically (permanent).
4.3 IP Tracking Process
1. Identify – Extract IP from logs, emails, or network traces.
2. Lookup – Determine ISP and geographic region.
3. Correlate – Compare timestamps with provider records.
4. Confirm – Validate ownership using legal requests.
4.4 Tools and Techniques

Tool Function

Wireshark Captures live packets

Traceroute Tracks routing path

nslookup / WHOIS Identifies domain owner

NetWitness / Xplico Network forensic analysis

4.5 Limitations
• VPNs and proxies mask true identity.
• Dynamic IPs change frequently.
• Requires ISP cooperation.

4.6 Example Case


In a phishing case, the suspect used a VPN. Investigators correlated timestamps and payment
trail with ISP logs to uncover the originating IP.

5. Encryption and Decryption Methods


5.1 Introduction
Encryption secures data by converting plain text into unreadable code. Decryption restores it
to its original form. While essential for privacy, it also complicates investigations.
5.2 Concept
Encryption converts readable data (plaintext) into an unreadable format (ciphertext) using a
key to protect confidentiality and prevent unauthorized access.
Decryption reverses this process, converting ciphertext back to plaintext using the correct key.
The security depends on the encryption algorithm and key strength.
Example:
A confidential email is encrypted before sending; only the recipient with the correct key can
decrypt and read it.

5.3 Types of Encryption


1. Symmetric Encryption – Same key for encryption/decryption (e.g., AES, DES).
2. Asymmetric Encryption – Public/private key pair (e.g., RSA).
3. Hashing – One-way transformation for integrity (e.g., SHA-256).

5.4 Common Algorithms

Algorithm Type Use Case

AES Symmetric File protection

RSA Asymmetric Secure email

Blowfish Symmetric VPN data

SHA-256 Hash Password storage

5.5 Role in Cyber Investigation


• Helps verify integrity of evidence through hashing.
• Investigators must decrypt evidence legally to access hidden data.
• Used to sign and authenticate digital documents.

5.6 Challenges
• Modern algorithms are computationally strong.
• Brute-force decryption consumes huge time/resources.
• Legal barriers in compelling disclosure of keys.
Example: Investigators used hash verification (SHA-1) to prove data integrity of seized drives.
6. Search and Seizure of Computers
6.1 Introduction
The first step in a cybercrime investigation is identifying and legally seizing electronic devices
that may contain evidence.
6.2 Legal Framework
Search and seizure must comply with national cyber laws (e.g., Information Technology Act
2000 in India) and require proper warrants.
6.3 Procedure
1. Obtain legal authorization.
2. Photograph the scene and device connections.
3. Disconnect from networks to prevent remote tampering.
4. Label, seal, and transport evidence securely.
5. Create forensic image before analysis.

6.4 Preservation of Evidence


Use write-blockers to prevent accidental modification. Maintain hash values to confirm
integrity.

6.5 Chain of Custody


Detailed documentation of who handled evidence, when, and for what purpose ensures
admissibility in court.
6.6 Do’s and Don’ts

Do’s Don’ts

Use forensic imaging tools Power on a device unnecessarily

Label all items Connect to the internet

Document every action Modify or open files directly

Example: Improperly accessing a suspect’s laptop without imaging invalidated evidence in a


cyber fraud case.
7. Recovering Deleted Evidences
7.1 Introduction
Criminals often delete files, emails, or logs to conceal their activities, but deletion usually
removes only the file’s reference—not the actual data. The information remains on the storage
device until overwritten. Using forensic tools such as Autopsy or EnCase, investigators can
scan unallocated space and recover deleted documents, images, or logs that serve as crucial
digital evidence in cybercrime cases.
7.2 Data Deletion Process
1. File reference removal: Deleting a file only removes its entry or pointer from the file
system, not the actual data.
2. Data remains intact: The file’s contents stay on the storage device until overwritten by
new data.
3. File system behavior: Systems like NTFS or EXT4 mark the deleted space as
“available,” but data blocks remain recoverable.
4. Forensic recovery: Investigators can use tools such as Autopsy or FTK Imager to
retrieve deleted files from unallocated space.
5. Overwriting effect: Once new data overwrites the old sectors, recovery becomes
impossible.
6. Example: Deleted documents from a suspect’s drive were recovered because the
storage area hadn’t yet been overwritten.
7.3 Recovery Techniques
1. File Carving – Extracting data fragments from unallocated space.
2. Metadata Analysis – Reconstructing filenames, timestamps.
3. Disk Imaging – Creating sector-by-sector copies.
4. Memory Dump – Recovering volatile data from RAM.
7.4 Tools Used

Tool Purpose

Autopsy / Sleuth Kit File recovery and timeline analysis

FTK Imager Image creation and data preview

Recuva Lightweight recovery utility

EnCase Professional forensic suite

7.5 Limitations:
• Overwritten sectors are unrecoverable.
• Encrypted drives resist standard recovery.
• Large datasets slow down scanning.
7.6 Example
Investigators recovered deleted chat archives revealing ransom negotiations, proving suspect
involvement.

8. Password Cracking
8.1 Introduction
Passwords act as digital keys that protect access to systems, accounts, and sensitive files. In
cybercrime investigations, accessing password-protected data is often essential to retrieve
hidden or encrypted evidence such as emails, documents, or transaction logs. Investigators use
authorized forensic methods and tools to recover passwords while maintaining legal
compliance and evidence integrity.
8.2 Password Storage and Hashing
8.2.1 What is hashing (vs encryption)?
• Hashing is a one-way mathematical transformation that maps an input (password) to a
fixed-length string (hash). You cannot practically reverse a secure hash to obtain the
original password.
• Encryption is two-way: ciphertext can be decrypted with a key. Passwords for
authentication should be hashed, not encrypted, so there is no reversible secret stored
on the server.
8.2.2 Why systems store hashes?
• Storing hashes prevents a compromised database from immediately revealing plaintext
passwords.
• During login, the system hashes the supplied password and compares it to the stored
hash; if they match, authentication succeeds.
8.3 Password Cracking Methods
1. Brute Force
o Tries every possible character combination.
o Strength: guaranteed (eventually).
o Weakness: extremely slow/costly for long/complex passwords.
o Defender: long passwords + MFA + rate limits.
2. Dictionary Attack
o Tests words from curated wordlists (common passwords, leaks).
o Strength: fast if password is predictable.
o Weakness: fails for random/complex passwords.
o Investigator tip: start with targeted wordlists (user/company terms).
3. Rainbow Tables
o Uses precomputed hash→password tables for fast lookup.
o Strength: very fast for unsalted hashes.
o Weakness: defeated by per-user salts; large storage required.
o Defender: unique salts + strong KDFs.
4. Hybrid Attack
o Combines dictionary words with mutations (adding numbers, substitutions).
o Strength: good for human-created variants.
o Weakness: more compute than pure dictionary; misses fully random secrets.
o Investigator tip: use rules reflecting likely user behavior.
5. Social Engineering
o Obtains credentials by manipulating people (phishing, pretexting, helpdesk
resets).
o Strength: can be very quick and bypass technical defenses.
o Weakness: legal/ethical risks; requires authorization.
o Defender: user training, strict helpdesk procedures, phishing tests.

8.4 Popular Tools

Tool Function

John the Ripper Offline password cracking

Cain & Abel Network password recovery

Hashcat GPU-accelerated cracking

Ophcrack Windows password recovery

8.5 Ethical and Legal Considerations


Cyber-investigators must act strictly within legal boundaries and uphold privacy rights while
recovering or cracking passwords.
1. Legal Authorization Required – Password recovery or decryption must be backed by a
valid warrant, court order, or written consent. Acting without permission is illegal and
renders evidence inadmissible.
2. Respect for Privacy Laws – Access must follow national data-protection rules (e.g., IT
Act, GDPR) and be necessary, proportionate, and limited to the scope of investigation.
3. Compelled Decryption – Forcing a suspect to reveal passwords may raise self-
incrimination issues; investigators must seek legal advice before requesting such
orders.
4. Cross-Border Access – When evidence or accounts lie in another country, investigators
must use mutual legal assistance or formal international cooperation, not direct hacking.
5. Documentation & Chain of Custody – Every action, tool, and authorization must be
logged to maintain evidence integrity and court admissibility.
6. Minimization & Safeguards – Only relevant data should be accessed; sensitive or third-
party information must be handled confidentially.
7. Ethical Conduct – Maintain professionalism, avoid unnecessary intrusion, and protect
individual rights while fulfilling investigative duties.

8.6 Case Example


In a data-theft case, investigators used Hashcat to recover encrypted ZIP files containing stolen
client data, which served as primary evidence.

Summary of Module 2:

Topic Core Concept Example Application

Cyber Crime Digital evidence discovery and


Online banking fraud
Investigation analysis

Classification Based on target, method, motive Cyber espionage

Cross-border data
Challenges Technical and legal hurdles
recovery

Locating offenders through network


IP Tracking Phishing investigation
trails

Encryption & AES decryption in data


Securing and decoding evidence
Decryption theft

Search & Seizure Legal evidence handling Court-authorized imaging

Recovery of Deleted
File and metadata reconstruction Recovered emails
Data

Password Cracking Accessing protected evidence Cracking ZIP archives

You might also like