Perfect Hrithick 🙏 — here’s your complete Cyber Security notes (Unit 1–5) in simple,
clear, and exam-depth explanations with examples.
All points from your syllabus are covered — none skipped or ignored.
You can directly read + write in exams easily.
🧭 CYBER SECURITY – FULL NOTES (Units 1 to
5)
📚 Maulana Abul Kalam Azad University of Technology ([Link]
CSE)
🧩 UNIT 1 – Introduction to Cyber Security
1️⃣Introduction
Cyber security means protecting computer systems, networks, and data from digital
attacks, theft, or damage.
Example: Antivirus and firewalls protect your system from hackers.
2️⃣Importance of Cyber Security
Protects personal and financial data
Maintains privacy
Prevents data loss and system damage
Supports national security
Builds trust in online services
Example: Banks protect online transactions using encryption.
3️⃣Challenges in Cyber Security
New and advanced attacks appear every day
Human mistakes (weak passwords)
Lack of awareness
Insider misuse
Sophisticated hacker tools
Example: The WannaCry ransomware attack spread because systems were not updated.
4️⃣Cyberspace
The virtual space created by interconnected computers and networks where data is
exchanged.
Example: Social media, cloud storage, and email exist in cyberspace.
5️⃣Cyber Threats
Actions that can harm a computer or network.
Examples:
Virus: Damages data
Phishing: Fake emails steal passwords
Spyware: Monitors user activity
Ransomware: Locks data until payment
6️⃣Cyber Warfare
Use of cyberattacks by a nation to harm another nation’s systems.
Example: Disabling another country’s power grid or defense network.
7️⃣CIA Triad
Basic model of information security:
C – Confidentiality: Only authorized people can access data.
I – Integrity: Data should remain unchanged.
A – Availability: Systems must work when needed.
Example: Online banking – your data must be private, accurate, and available 24/7.
8️⃣Cyber Terrorism
Using the internet to create fear or damage for political or religious purposes.
Example: Hacking into government websites or spreading fake news.
9️⃣Cyber Security of Critical Infrastructure
Protecting essential systems like electricity, water, hospitals, and transport from cyberattacks.
Example: Protecting hospital data from ransomware.
🔟 Cybersecurity – Organizational Implications
Organizations must:
Create security policies
Train employees
Use encryption & firewalls
Conduct audits
Backup data regularly
✅ Summary Table (Unit 1)
Topic Key Idea Example
Cyber Security Protect systems & data Antivirus
Challenges Human error, new threats Ransomware
Cyberspace Virtual network world Internet
Confidentiality, Integrity,
CIA Triad Bank data
Availability
Cyber
Internet for fear or attack Govt site hack
Terrorism
Critical Infra Power, hospitals, transport Smart grid
Org. Company
Security policy, training
Implications firewall
💻 UNIT 2 – Hackers and Cyber Crimes
1️⃣Types of Hackers
Type Description Example
Ethical hackers who test security Company security
White Hat
legally testers
Type Description Example
Illegal hackers who steal or
Black Hat Credit card thieves
destroy data
Hack for fun or challenge, not for
Grey Hat Find bug & tell admin
profit
Script
Use others’ hacking tools Beginner hacker
Kiddies
Hacktivists Hack for political/social cause Anonymous group
2️⃣Hackers and Crackers
Hackers: Access systems, sometimes legally (ethical).
Crackers: Break passwords and codes illegally to harm or steal.
Example: Cracking software license keys to use paid apps for free.
3️⃣Cyber-Attacks and Vulnerabilities
Attack: Action to harm or access a system
Vulnerability: Weakness that allows attack
Example: Unpatched software is a vulnerability; malware exploit is an attack.
4️⃣Malware Threats
Malware = Malicious Software.
Types:
Virus: Attaches to files, spreads (e.g., ILOVEYOU virus)
Worm: Self-replicating (e.g., Code Red worm)
Trojan: Looks safe but harmful (e.g., fake games)
Spyware: Monitors user activities
Ransomware: Locks files for ransom
5️⃣Sniffing
Capturing network data packets secretly to steal information like passwords.
Example: Wireshark tool used by attackers.
6️⃣Gaining Access
Attackers try to enter systems through stolen passwords, software bugs, or open ports.
Example: Logging in with stolen credentials.
7️⃣Escalating Privileges
Once inside, hacker increases their access rights.
Example: From normal user → admin → full control.
8️⃣Executing Applications
Running malicious programs or scripts to damage or steal data.
Example: Running a hidden malware executable file.
9️⃣Hiding Files
Hackers hide malware or illegal data in hidden folders or system files.
🔟 Covering Tracks
Attackers erase logs and histories to hide their identity.
Example: Deleting event logs after attack.
11️⃣Worms, Trojans, Viruses, Backdoors
Worms: Spread automatically
Trojans: Fake safe program, hidden malware
Viruses: Need a host file
Backdoor: Secret entry created for future access
✅ Summary Table (Unit 2)
Term Meaning Example
Security
White Hat Ethical hacker
tester
Black Hat Illegal hacker Data thief
Malware Harmful software Virus, Trojan
Stealing data
Sniffing Wireshark
packets
Backdoor Hidden access Secret login
Privilege User →
Increasing power
Escalation Admin
🧠 UNIT 3 – Ethical Hacking and Social Engineering
1️⃣Ethical Hacking
Definition: Legally breaking into systems to find and fix vulnerabilities.
Example: Company hires ethical hackers to test website security.
2️⃣Concepts and Scopes
Steps in Ethical Hacking:
1. Reconnaissance (Information Gathering)
2. Scanning (Finding open ports)
3. Gaining Access
4. Maintaining Access
5. Clearing Tracks
3️⃣Threats and Attack Vectors
Threat Vector: Path used by attackers to access a target.
Examples:
Email attachments
USB drives
Websites with malware
Phishing links
4️⃣Information Assurance
Ensuring Confidentiality, Integrity, Availability of data.
Example: Data backups and access control.
5️⃣Threat Modelling
Process to identify possible threats to a system.
Example: Finding ways hackers could attack an online banking app.
6️⃣Vulnerability Assessment & Penetration Testing (VAPT)
Vulnerability Assessment: Finding weaknesses.
Penetration Testing: Exploiting weaknesses safely to test system
strength.
Example: Using tools like Nmap or Metasploit.
7️⃣Types of Social Engineering
Manipulating people to share confidential info.
Types:
Phishing: Fake emails
Pretexting: Fake identity
Baiting: Offering something attractive (e.g., free pen drive)
Tailgating: Following authorized person into restricted area
8️⃣Insider Attack
Attack by an employee or trusted person.
Example: Employee leaking company data.
9️⃣Preventing Insider Threats
Monitor user activities
Use role-based access control
Conduct background checks
Train employees
🔟 Social Engineering Targets and Defence Strategies
Targets: Employees, customers, managers
Defence: Awareness training, spam filters, verification process
✅ Summary Table (Unit 3)
Concept Meaning Example
Company testing
Ethical Hacking Legal hacking
security
Social Human
Phishing
Engineering manipulation
Insider Threat Attack from inside Employee misuse
Awareness,
Defence Training
controls
UNIT 4 – Cyber Forensics and Auditing
1️⃣Introduction to Cyber Forensics
Cyber forensics = investigating digital crimes by collecting and analyzing digital evidence.
2️⃣Computer Equipment and Storage Media
Evidence can be collected from:
Hard drives
USBs
Mobile phones
Cloud storage
3️⃣Role of Forensics Investigator
Identify digital evidence
Collect and preserve it safely
Analyze to find clues
Prepare legal reports
4️⃣Forensics Investigation Process
1. Identification – find evidence
2. Preservation – protect data from change
3. Analysis – study data
4. Documentation – record findings
5. Presentation – report to court
5️⃣Collecting Network-based Evidence
Capturing network logs, emails, IP addresses, or chat records.
Example: Tracing hacker’s IP from server logs.
6️⃣Writing Computer Forensics Reports
Detailed report including:
Case summary
Methods used
Evidence found
Conclusion
7️⃣Auditing
Regularly checking system or organization security.
8️⃣Plan an Audit
Steps:
1. Define goals
2. Choose audit tools
3. Collect data
4. Compare with standards
5. Report findings
9️⃣Information Security Management System (ISMS)
A framework for managing and improving security.
🔟 ISO 27001:2013
An international standard for ISMS — helps organizations protect data systematically.
✅ Summary Table (Unit 4)
Concept Description Example
Cyber Investigating Analyzing hacked
Forensics cybercrime PC
Evidence Digital data Emails, logs
Finds and reports
Investigator Cyber expert
clues
Company
ISO 27001 Security standard
certification
⚖️UNIT 5 – Cyber Ethics and Laws
1️⃣Introduction to Cyber Laws
Cyber law defines rules and punishments for crimes on the internet.
2️⃣E-Commerce and E-Governance
E-Commerce: Buying and selling online (Amazon, Flipkart)
E-Governance: Government services online (tax filing, Aadhaar)
3️⃣Certifying Authority and Controller
Certifying Authority (CA): Issues digital certificates to verify
identity.
Controller: Oversees all CAs under IT Act.
Example: CA ensures secure digital signatures for online contracts.
4️⃣Offences under IT Act
Some punishable acts:
Hacking (Section 66)
Identity theft (Section 66C)
Cyber fraud (Section 66D)
Publishing obscene content (Section 67)
5️⃣Computer Offences and Penalties under IT Act 2000
Offence Punishment
Up to 3 years jail + fine
Hacking
₹5 lakh
Identity Theft 3 years jail + fine ₹1 lakh
Publishing obscene 5 years jail + fine ₹10
material lakh
6️⃣Intellectual Property Rights (IPR)
Legal rights that protect digital creations like software, music, and photos.
Example: Copyright for software code.
7️⃣Network Layer – IPSec
IPSec (Internet Protocol Security) ensures secure data transfer between computers over
networks.
Provides:
Authentication
Encryption
Data Integrity
Example: Used in VPNs for secure remote access.
✅ Summary Table (Unit 5)
Topic Meaning Example
Cyber Law Rules for online crimes IT Act 2000
E-
Govt online service Aadhaar
Governance
CA & Digital certificate
Sign verification
Controller authority
Legal ownership of Software
IPR
creations copyright
IPSec Secure internet protocol VPN
🧾 FINAL QUICK REVISION (All Units)
Uni
Main Focus Key Idea
t
1 Cyber Basics CIA Triad, Cyber threats
Hackers &
2 Malware, Sniffing, Worms
Crimes
3 Ethical Hacking Social Engineering, VAPT
Evidence, Auditing, ISO
4 Forensics
27001
5 Ethics & Law IT Act 2000, IPR, IPSec
Would you like me to make this whole note into a clean, well-formatted PDF (for easy
reading and printing for your exam)?