0% found this document useful (0 votes)
20 views32 pages

Understanding Cybercrime: Key Concepts

Uploaded by

kimia.barthson
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
20 views32 pages

Understanding Cybercrime: Key Concepts

Uploaded by

kimia.barthson
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

The ICT University

Spring 2025 Continuous Assessment No 1

School of ICT

By

Barthson Kimia Ta’bi

ICTU20223052

[Link]@[Link]

Course Code: CYS 3251

Course Title: Computer/Network Forensics

Instructor: Engr. Daniel Moune


Chapter 1: Entering the World of Cybercrime

Summary

Understanding Cybercrime

Cybercrime is made up of criminal or illegal activities carried out through information and
communication technologies, whose main target is computers and destroying cyberspace.
These crimes can range from identity theft to phishing scams.

While traditional crimes like murder and theft are not directly influenced by technology
that is computers inclusive, the planning and of such acts have increasingly involved ICTs
as decades pass by.

Differences Between Cybercrime and Traditional Crime

Cybercrime differs from traditional crime primarily in the method of execution.

Cybercriminals can function anonymously meaning remotely or from anywhere around


the world using computers, meanwhile traditional crimes require physical interaction most
at times with the victim.

Traditional Crimes Utilizing Technology

Theft: Criminals now involve themselves in online theft through e-commerce platforms,
stealing goods or sensitive information like credit card numbers without coming into
contact directly with the user.

Fraud: Traditional fraud operandum’s have evolved into complicated online scams such as
phishing, where attackers impersonate legitimate entities that is pretending to be an
organization or entity you are not to steal personal information.

Categories of Cybercrime

Cybercrime can be categorized into two main types:


Internal Cybercrime: Targets individual users within an organization. Examples are
identity theft and phishing scams that tamper or destroy personal information.

External Cybercrime: Involves attacks from outside an organization meaning not from
within the organization, leading to financial losses or data breaches. examples are hacking
and ransomware attacks.

Online Vandalism

Online vandalism, or in other words digital vandalism, consist of activities like website
defacement, where unauthorized users modify a website’s content, and social media abuse,
where harmful or illegal content is posted to damage a user’s reputation.

Malware Defined

Malware refers to malicious software designed to harm or exploit systems. examples


include viruses, worms, and Trojan horses, each serving different harmful purposes.

Understanding Botnets

A botnet is a network of compromised computers controlled remotely by cybercriminals.


Devices become infected through malware and connect to a central server that issues
commands, enabling the attacker to perform tasks such as data theft and DDoS attacks.

Embezzlement Explained

Embezzlement involves the fraudulent mismanagement of funds or property by individuals


entrusted with managing those assets or commodities. This can occur in both physical and
digital environments depending on the scenario.

Copyright Infringement

Copyright infringement occurs when an individual uses, reproduces, or distributes


copyrighted material without permission from the copyright holder, leading to legal
consequences.

Dangers of Online Prescription Drug Sales


The online sale of prescription drugs poses significant risks, including exposure to
counterfeit medications that may be harmful and a lack of regulation among online sellers,
which complicates the verification of their legitimacy.

Challenges in Investigating Cybercrime

Investigating cybercrime presents several challenges for authorities, including the


anonymity of criminals who use VPNs and other techniques to hide their identities.
Additionally, the rapid evolution of technology means that cybercriminals continuously
adapt, requiring law enforcement to stay updated on new threats and security measures.

This chapter highlights the intricate relationship between traditional crimes and modern
technology, illustrating the complexities of cybercrime in today’s digital world.

Chapter 1 Entering the World of Cybercrime

Critical thinking question:

Are there any crimes at all that have not been touched by information, communication and
computer technologies?

Information and communication technologies have greatly impacted the world of today.
Even though traditional crimes such as vandalism, murder and theft are not directly
influenced by technology, they still play a role in the perpetration and planning of these
crimes. In addition to this, even the methods of investigation of such crimes used have seen
a great improvement over time due to technological advancement.

In conclusion, it is difficult to identify a crime which has not been touched by technology due
to the fact that ICTs have a minimal impact and influence on how these crimes are executed.

Review Questions

1. What is Cybercrime
Cybercrime refer to criminal and illegal activities carried out by attackers over a
network targeting computers and endangering the cyberspace.

2. How does computer crime differ from traditional crime?

Computer crimes refer to all illegal activities which are facilitated or carried out using
computers enabling the attackers to be able to maintain their anonymity and execute
their plans from anywhere in the world while traditional crime involves the
perpetrator to get in contact with the victim physically to be able to carry out the
crime.

3. Identify two or three traditional crimes in which computers are now used as an
instrument. How has the nature of these crimes changed as a result of technology?

Theft: Theft typically involved physical acts, such as breaking and entering or
shoplifting. With the rise of technology in the commerce sector, criminals can now engage in
theft through e-commerce platforms, stealing goods or conducting fraud without physical
interaction. Also, criminals can steal sensitive information, such as credit card numbers or
personal data, through hacking, leading to identity theft.

Fraud: Traditional fraud might involve scams or deceitful practices in person or via
mail. With the advancement of technology, cybercriminals can execute complex scams like
phishing, where they impersonate legitimate entities to steal sensitive information.

4. What are the two main categories of cybercrime? Provide a few examples of each

Internal cybercrime

This category involves crimes targeting individual users and their personal information
internal of an organisation. Some examples include;

- Identity Theft: Stealing personal information (e.g., Social Security numbers, bank
account details) to impersonate someone else for financial gain.
- Phishing: Sending deceptive emails or messages to trick individuals into revealing
sensitive information, such as passwords or credit card number
- External Cybercrime

This category involves crimes aimed at businesses or institutions coming from someone
external from the organisation, often resulting in financial loss or data breaches. Some
examples include;

- Hacking: Unauthorized access to corporate networks to steal sensitive data,


intellectual property, or customer information.
- Ransomware Attacks: Malicious software that encrypts an organization’s data,
demanding payment for decryption keys.
5. How can vandalism occur online?

Online vandalism, often referred to as "digital vandalism," can occur in several ways. Here
are some common forms.

To begin, it can occur through Website Defacement Unauthorized which is the modification
of a website's content, often replacing it with offensive or misleading messages, images, or
graphics. For example, Hackers gaining access to a website and changing its homepage to
display inappropriate content. It can also occur through special media abuse which involves
posting harmful or malicious content on social media profiles, including spreading false
information users posting derogatory comments or images on someone’s profile or page.

6. What is Malware? Provide a few examples of it

Malware is a broad category of software designed by attackers or cybercriminals to


harm, exploit, or otherwise compromise computer systems, networks, or devices. It
can take various forms and serves different malicious purposes. A few examples of
malware include viruses, worms and Trojan horses.

7. What is a botnet? How does it work?


Botnet refer to a network of compromised computers known as bots typically
infected with malware and are controlled remotely by cybercriminals. Devices
become infected with malware, often through phishing emails, malicious downloads,
or vulnerabilities in software. Once infected, the device connects to a central server
controlled by the attacker. This server issues commands and manages the botnet,
allowing the attacker to control all infected devices. The botnet can be instructed to
perform various tasks, including DDoS attacks, data theft and spam distribution.

8. What is Embezzlement?

It refers to the fraudulent appropriation of funds or property by individuals who have


been entrusted with managing or overseeing those assets, particularly in digital
environments.

9. How does Copyright infringement occur?

Copyright infringement occurs when someone uses, reproduces, or distributes


copyrighted material without the permission of the copyright holder.

10. What are the dangers associated with online sales of prescription drugs?

The online sale of prescription drugs can be a problem for some reasons.

To begin it exposes one to Counterfeit Medications. Many online pharmacies sell fake
or substandard drugs that may contain harmful substances or incorrect dosages. Also,
it is a danger because of lack of Regulation Many online sellers operate without
proper licensing or oversight, making it difficult to ensure their legitimacy.

11. Which problems does cybercrime pose to authorities seeking to investigate it?

Cybercrime poses certain problems to authorities who are looking for ways to
investigate. Firstly, The Anonymity of Criminals. Cybercriminals often use techniques
to hide their identities, such as VPNs, proxies, or the dark web. The advancement in
technology has made it significantly easy for criminals to perpetrate such acts without
having direct contact with the victim. Also, the rapidly evolving nature of technology
prompts cybercriminals to continually adapt to the new technologies and security
measures implemented by relevant authorities; thus, authorities must constantly
update their tools and knowledge to keep up with evolving cyber threats.

Chapter 2 An Introduction to Computer Forensics Investigation and


Electronic Evidence

Summary
In the case of United States v. Aliaksandr Zhyltsou, the defendant faced hefty charges for using a
forged birth certificate to obtain a passport which is illegal. The prosecution attempted to introduce
social media or online evidence related to Zhyltsou, hence raising issues of hearsay and
authentication.

Hearsay, defined as an out-of-court statement offered to prove the truth of the matter being
discussed or case study, was essential to the case. The court ultimately ruled the social media posts
inadmissible or not useful due to insufficient authentication linking them to Zhyltsou.

The computer forensics process involves several key steps which are: documenting the electronic
crime scene, search and seizure, evidence keeping or preservation, data acquisition, data analysis,
case analysis, reporting, and testifying as an expert witness. Investigations can sometimes be
public, conducted by a group of assigned government agencies, or private, carried out by hired
investigators.

Understanding types of evidences is very important. They are: direct, circumstantial, hearsay, and
digital evidence. Direct evidence provides factual statements or proofs that means the individual
is certainly guilty, while circumstantial evidence requires several inferences. Hearsay may be
admissible under specific conditions, such as statements made during or shortly after an event or
based on third part witnesses.

Authentication of electronic evidence is important and can be achieved through line of custody or
in more advanced scenarios chain of custody, hash values and digital signatures Standards of
evidence outline the criteria for admissibility in court, ensuring that the legal process maintains
integrity and fairness in addressing cybercrime.

Practical Exercise

For this project, you must search for and interpret information in a cybercrime case that
dealt with admitting hearsay in criminal or civil court. Provide a brief description of the case
and discuss the role of the hearsay evidence in it. You should also identify why the evidence
was admissible (or inadmissible). In your analysis, do not forget to include other types of
evidence presented in the case (e.g., direct and circumstantial...). Finally, discuss the effect of
the challenges to the authenticity of the evidence on the outcome of the case.

- Cybercrime Case Involving Hearsay Evidence: United States v. Vayner

Case Overview

In the case of United States v. Aliaksandr Zhyltsou, the defendant was accused of using a
forged birth certificate to obtain a passport. The prosecution sought to introduce evidence
from a social networking site that allegedly belonged to Zhyltsou, which included posts that
were relevant to the case. The primary issue revolved around the admissibility of this
evidence, particularly concerning hearsay and authentication challenges.

Role of Hearsay Evidence

Definition of Hearsay

Hearsay is defined as an out-of-court statement offered to prove the truth of the matter
asserted. In this case, the prosecution aimed to use social media posts as evidence of his
identity and intent, which could be considered hearsay since the posts were made outside of
the courtroom.

Admissibility of Hearsay Evidence

In Vayner, the court ultimately ruled that the social media evidence was inadmissible due to
insufficient authentication. The prosecution failed to provide adequate evidence that the
posts were indeed made by Zhyltsou, which is a critical requirement for establishing the
authenticity of hearsay evidence. The court emphasized that the government needed to
demonstrate a clear link between the defendant and the social media account to admit the
posts as evidence.

Other Types of Evidence Presented

1. Direct Evidence:
o The prosecution presented direct evidence, including witness testimonies that
linked Zhyltsou to the fraudulent activities. This included testimonies from
individuals who interacted with him during the process of obtaining the
passport.
2. Circumstantial Evidence:
o Circumstantial evidence was also introduced, such as the context of the forged
documents and the circumstances under which they were obtained. This
evidence suggested a pattern of fraudulent behaviour but did not directly link
Zhyltsou to the social media posts.

Challenges to Authenticity

Impact on the Case Outcome

The challenges to the authenticity of the social media evidence significantly impacted the
case. The court's decision to exclude the hearsay evidence meant that the prosecution lost a
crucial piece of evidence that could have supported their claims. Without the social media
posts, the prosecution had to rely more heavily on direct and circumstantial evidence, which
may not have been sufficient to secure a conviction.

Review Questions

1. What are computer forensics?

Computer forensics is a branch of digital forensics that focuses on the investigation


and analysis of computer systems, networks, and digital devices to uncover, preserve,
and present digital evidence in a legally admissible manner.

2. What are the major differences between public and private investigations?

There are several differences between public and private investigations. To begin
public investigations are carried out by government agencies which mostly include
forces of law and order while private investigations are conducted by private
investigators or firms hired by individuals.

Another major difference is the fact that the aim of public investigations is to enforce
law and prosecute criminal offences while private investigations focus on civil
matters which could be fraud, infidelity, missing persons, just to name a few.

3. What are the similarities and differences between criminal and civil law?

Criminal and civil law have certain similarities which will be explained

To begin both criminal and civil law operate within a structured legal system with
well-defined rules and regulations. Also, both protect the right of the parties involved
respectfully ensuring fair treatment and freedom to defend their case.

However, they have differences which cannot be undermined;

Firstly, criminal law aims to punish wrongdoers and maintain public order. It
addresses offenses against the state or society while civil law focuses on resolving
disputes between individuals or entities and providing compensation to the injured
party. Another difference is that in criminal law, the case is brought by the
government (prosecutor) against the accused (defendant) while in civil law The case
is brought by an individual or entity (plaintiff) against another individual or entity
(defendant).

4. Why do administrative agencies conduct investigations?

- To ensure that individuals and organizations comply with laws and regulations
within their jurisdiction. Investigations help identify violations and enforce
compliance.
- To protect public health, safety, and welfare by investigating potential hazards, unsafe
practices, or violations that could harm individuals or communities.
- To gather evidence for enforcing regulations and policies. This includes investigating
complaints, violations, or misconduct in areas such as environmental protection,
labour standards, and consumer rights.
- To monitor industries and sectors to ensure they operate within legal parameters.
Investigations help maintain oversight of practices that may affect public interests.

5. Describe the computer forensics process

The computer forensic process involves 8 steps which will be explained


subsequently;

-Step 1: Documenting the electronic crime scene

In this stage, forensic investigation processes are recorded in order to analyse and
preserve evidence.

-Step 2: Search and Seizure

At this stage, relevant information about the case is being collected. Such information
includes the description of the incident, the case name, the location of the incident,
relevant legislation, the extent of authority to search, creating a chain of custody
document, details of equipment to be seized, carrying out a search, approval from
local management and finally health and safety precautions.

-Step 3: Evidence Preservation

It involves the careful handling and documentation of evidence to ensure that it is free
from contamination. All physical or digital evidence collected are isolated and
secured to be able to maintain its true shape.

-Step 4: Data Acquisition

After collecting evidence, investigators can now process and examine the collected
data to extract information relevant to any particular case while protecting the
integrity of the data.

-Step 5: Data Analysis

This stage includes the analysis of the file’s contents and a check to verify if there any
traces of file modification. The root of the incident is also identified at this stage.

-Step 6: Case Analysis

The investigators now relate the data collected from evidence to the case details to be
able to understand exactly how the incident took place and how to prevent future
happenings.

-Step 7: Reporting

Here the outcome of the case analysis is documented and the report of the full
incident is made.

-Step 8: Testifying as an expert witness


The digital evidence is now presented in court. It however requires knowledge of new
evolving and complex technologies.

6. When should a search be conducted onsite?

- When there is reasonable suspicion or evidence of a crime, such as fraud, theft, or


cybercrime, that may involve physical or digital evidence at a specific location.
- During ongoing investigations where immediate collection of evidence is necessary
to prevent destruction or tampering.
- When investigators have obtained a valid search warrant, granting them legal
authority to search a specified location for evidence.

7. When should a search be conducted offsite?

- When evidence is suspected to be stored at external locations, such as data centres,


cloud services, or physical storage facilities.
- To access digital records or data that are not immediately available onsite, such as
emails, databases, or backups stored offsite.
- When the investigation involves third parties, such as vendors or contractors, who
may hold relevant evidence outside the primary investigation site.

8. What is slack space?

Slack space refers to the unused space in a file system that remains in a storage
medium after a file is saved.

9. Which different types of evidence exist?

- Direct Evidence
- Circumstantial evidence
- Hearsay evidence
- Digital/Electronic evidence
- Forensic evidence
10. What is the difference between circumstantial and direct evidence?

Direct Evidence offers immediate proof of a fact while Circumstantial evidence


requires inference and reasoning to establish a connection.

11. When is hearsay evidence admissible in court?

- Statements made during or immediately after an event, describing or explaining it.


- Statements made for the purpose of medical diagnosis or treatment, including
descriptions of medical history or symptoms.
- Statements made by a witness that are consistent or inconsistent with their
testimony, used to support or challenge their credibility.

12. How can electronic evidence be authenticated?

Firstly, it can be authenticated using Chain of Custody which can be used to maintain
a detailed record of who collected, handled, and stored the evidence.

Also, using Digital Signatures. Using cryptographic techniques to verify the


authenticity and integrity of digital documents can be a good method for evidence to
be authenticated.

Another way to authenticate electronic evidence is making use of hash values. A


unique hash value can be created for each file at the time of collection.

13. What are the standards of evidence?

Standards of evidence refer to the criteria and levels of proof required for evidence
to be admissible in court.

Chapter 3 Laws regulating access to electronic evidence


Summary
This chapter explains concepts related to electronic communications and the legal accessories
governing
Traffic data refers to information gotten or gathered from network communications, while location
data indicates the geographic location of a device or user.
The chapter differentiates between content data, which includes the actual information transmitted
(like emails and messages), and non-content data, which includes metadata that provides context
but not substance I’m most case scenarios. This is a very important aspect of non-content data.
The Electronic Communications Privacy Act (ECPA) permits law enforcement to access stored
communications under specific conditions, allowing access to emails over 180 days with a
subpoena and enabling the collection of metadata without a warrant.

Providers may disclose emails voluntarily with user consent or in emergencies. The ECPA and the
USA PATRIOT Act regulate the interception of electronic communications, balancing law
enforcement needs with individual privacy rights. there's huge need for a balance between legal
balancing law enforcement and the need for individual privacy rights so as not to violate user rights

Various laws, such as the Privacy Act of 1974 and the Freedom of Information Act (FOIA), govern
personal information in government databases, ensuring privacy and security. The Sarbanes-Oxley
Act of 2002, in response to financial scandals, introduced critical sections aimed at enhancing
corporate accountability and protecting whistle-blowers, thus strengthening the integrity of
financial reporting

Review Questions

1. What is traffic data?

It refers to the information collected from network communications and activities


that can be used to investigate and analyse cyber incidents.

2. What is location data?


It refers to information that indicates the geographic position of a device or user at a
given time.

3. What are the differences between content and non-content telecommunications and
electronic communications data?

Content data refers to the actual information transmitted during a communication.


This includes the body of emails, text messages, voice calls, and any attachments or
files shared between users while non-content data, on the other hand, encompasses
information about the communication but does not include the actual content. This
includes metadata such as timestamps, sender and recipient information, IP
addresses, and the duration of calls. While non-content data does not reveal the
substance of the communication, it is invaluable for establishing timelines, identifying
participants, and tracing connections between individuals.

4. What does the ECPA permit law agencies to do?

- Access to Communications

The ECPA allows law enforcement agencies to obtain access to stored electronic
communications, such as emails and messages, under certain conditions. For
example, they can request access to content that has been stored for more than 180
days without a warrant, provided they have a subpoena. This provision is critical for
investigations where timely access to evidence is essential.

- Collection of Metadata

The ECPA also permits law enforcement to collect non-content data, such as
metadata, related to electronic communications without a warrant. This includes
information like the sender and recipient addresses, timestamps, and routing
information. This metadata can be crucial for establishing connections, timelines, and
patterns of behaviour in criminal investigations, even though it does not reveal the
actual content of the communications.
5. How can U.S agencies obtain subscriber records from telecommunications and
electronic communications service providers?

- Search Warrants

In cases where law enforcement seeks more detailed information, such as content of
communications or additional subscriber details, they may obtain a search warrant.
To secure a warrant, agencies must demonstrate probable cause to a judge, outlining
the relevance of the requested data to an ongoing investigation. This process provides
stronger legal authority for accessing sensitive information.

- Court Orders

Under the ECPA, law enforcement may also request court orders to obtain specific
subscriber records or communications data. This requires a higher standard than a
subpoena but is less stringent than a warrant. Agencies must show that the
information sought is relevant to an ongoing criminal investigation.

6. When can a U.S government agency obtain a suspect’s email?

- With a Search Warrant

Law enforcement agencies can obtain a suspect’s email content if they secure a search
warrant. To obtain a warrant, the agency must demonstrate probable cause to a judge,
indicating that the emails are relevant to an ongoing investigation. This is the most
robust legal method for accessing email content, ensuring that privacy rights are
considered.

- With a Subpoena (for Older Emails)

For emails that have been stored for more than 180 days, agencies can access content
using a subpoena without needing a warrant. This allows them to obtain basic
information about the emails, such as sender, recipient, and timestamps, as well as
the content itself. However, this method is restricted to emails that meet the time
criteria.

- With a Court Order

In certain cases, law enforcement can request a court order to access email content
or records. This requires demonstrating that the information is relevant to an
investigation but does not require the same level of probable cause as a warrant.

7. When can providers disclose emails and records to the U.S government voluntarily?

- User Consent

Providers may disclose emails and records if they have obtained explicit consent from
the user. This can occur when a user agrees to share their information during an
investigation or through service agreements that allow for such disclosures.

- Emergency Situations

In cases of emergencies, such as imminent threats to life or safety, providers may


disclose information to law enforcement without a warrant. This exception allows
them to act quickly to prevent harm, such as in situations involving kidnapping or
other immediate dangers.

8. How does ECPA and USA Patriot Act regulate the interception of electronic
communications, government access to those communications and government
access to ISP records?

The Electronic Communications Privacy Act (ECPA) and the USA PATRIOT Act
establish key regulations regarding the interception of electronic communications
and government access to those communications and ISP records. The ECPA prohibits
unauthorized interception, requiring law enforcement to obtain a warrant based on
probable cause for real-time communications and allowing access to stored emails
over 180 days with a subpoena, while basic subscriber information can be accessed
with a subpoena. In contrast, the USA PATRIOT Act expands surveillance powers,
enabling roving wiretaps and broader definitions of relevant information, facilitating
easier interception. It allows for streamlined access to ISP records without a warrant
in certain situations and permits the use of National Security Letters (NSLs), which
allow the FBI to request specific records without a warrant, raising concerns about
privacy and civil liberties. Together, these laws balance law enforcement needs with
individual privacy protections.

9. Which laws regulate personal information stored in government databases?

Several laws regulate personal information stored in government databases in the


United States, ensuring privacy and security. The Privacy Act of 1974 governs how
federal agencies collect, maintain, use, and disseminate personal information,
granting individuals rights to access and correct their records. The Freedom of
Information Act (FOIA) allows individuals to request access to federal agency records,
promoting transparency while protecting sensitive information. The Federal
Information Security Modernization Act (FISMA) mandates security measures for
information systems, including personal data, while the Health Insurance Portability
and Accountability Act (HIPAA) specifically protects personal health information in
the healthcare sector. Additionally, the Children’s Online Privacy Protection Act
(COPPA) safeguards the personal information of children under 13, requiring
parental consent for data collection. Together, these laws create a framework for
protecting personal information in government databases.

10. Which sections of the Sarbanes-Oxley Act of 2002 were direct results of the financial
scandal of 2001 and 2002?

Key sections that were direct results of these scandals include:

- Section 404: This section mandates that companies establish and maintain internal
controls over financial reporting and requires annual assessments of their
effectiveness. It aims to prevent fraudulent financial practices.
- Section 302: This section requires senior executives to personally certify the accuracy
of financial reports. It holds executives accountable for misleading financial
statements, enhancing transparency and responsibility.
- Section 401: This section requires that financial statements disclose all material off-
balance-sheet transactions and relationships that may impact financial performance,
addressing issues related to hidden liabilities.
- Section 806: This section provides protections for whistle-blowers, encouraging
individuals to report fraudulent activities without fear of retaliation, thereby
promoting ethical behaviour within corporations.

Chapter 4 Searches and Seizures of Computers and Electronic Evidence

Summary
This chapter outlines the importance of privacy and the legal laws governing searches and
seizures in every cyber investigation. These standards must be upheld very high to maintain
sanity of cyber investigations
Privacy is an important as it protects personal information and maintains trust in digital systems.
Evidence obtained through illegal searches is typically inadmissible in court due to the
exclusionary rule, which deters law enforcement from violating Fourth Amendment rights. This
chapter is very essential in understanding legal standards governing searches and seizures in
various cyber investigations

The reasonable expectation of privacy test assesses whether individuals believe their digital
information is private and if society recognizes that belief as reasonable. Employees may have a
diminished expectation of privacy at work, especially on employer-provided devices.

Government agencies usually need a search warrant to access a suspect's computer, unless
exigent circumstances or consent are present. Warrantless searches can occur under specific
conditions, such as with consent, exigent circumstances, or during lawful arrests.
Portable electronic devices can be seized and searched if officers have probable cause or if the
device is within the arrestee's immediate control. Exigent circumstances involving computers
include the imminent destruction of evidence.

A third party may consent to a search if they have authority over the property being searched. It
is very important to use search protocols to ensure evidence is collected following due procedure
and in the neatest way possible, protecting individual rights and maintaining the investigation's
integrity or in other wors its sanity and confidentiality.

Critical thinking Questions

1. What are your thoughts on the Carrey-Winnick approach? Is it beneficial or bad


news?

The Carrey-Winnick approach, which emphasizes a comprehensive and adaptive


strategy for addressing complex issues, can be seen as beneficial due to its focus on
collaboration and flexibility. This approach encourages stakeholders to engage in
dialogue and consider diverse perspectives, fostering innovative solutions. However,
it may also present challenges, such as potential indecisiveness or difficulty in
implementation if consensus is hard to achieve. Overall, its effectiveness largely
depends on the context and the commitment of participants to work together
constructively.

2. In your opinion what is the best strategy for reviewing information on computers
and why?

The best strategy for reviewing information on computers involves a systematic


approach that includes evidence preservation, thorough analysis, and
documentation. Utilizing forensic imaging tools to create exact copies of data ensures
that the original evidence remains unaltered, allowing for a reliable examination.
Following this, employing a combination of automated analysis tools and manual
review helps identify relevant data while minimizing oversight. Comprehensive
documentation of the processes and findings is essential for maintaining the chain of
custody and supporting legal proceedings. This methodical strategy not only
enhances the integrity of the investigation but also bolsters the credibility of the
findings in a court of law.

Review Questions

1. Why is privacy important?

It is important because it safeguards individuals' personal information and maintains


trust in digital systems. Protecting privacy ensures that sensitive data, such as
financial records and communications, is not improperly accessed or disclosed during
investigations.

2. Is all evidence illegally searched and seized inadmissible in court? Why do, you
think this is the case?

Evidence that is illegally searched and seized is generally inadmissible in court due to
the exclusionary rule. This legal principle is intended to deter law enforcement from
violating individuals' Fourth Amendment rights against unreasonable searches and
seizures.

3. How is the “reasonable expectation of privacy test” applied to computers?

The "reasonable expectation of privacy test" is applied to computers by evaluating


whether an individual has a subjective expectation of privacy in their digital
information and whether society recognizes that expectation as reasonable. Factors
considered include the nature of the data (e.g., personal emails vs. publicly accessible
information), the context in which it was stored (such as a personal device versus a
shared computer), and the measures taken to protect that information (like
passwords or encryption).

4. Does an employee have a reasonable expectation of privacy in a workplace?


An employee's reasonable expectation of privacy in the workplace can vary
significantly based on several factors, including company policies, the nature of the
workplace, and the specific circumstances. Generally, employees may have a
diminished expectation of privacy regarding communications on employer-provided
devices or networks, especially if there are clear policies stating that company
resources can be monitored.

5. When does the government need a search warrant to search and seize a suspect’s
computer?

The government typically needs a search warrant to search and seize a suspect's
computer when there is a reasonable expectation of privacy in the data stored on that
device. This requirement is rooted in the Fourth Amendment, which protects against
unreasonable searches and seizures. A warrant is necessary unless there are exigent
circumstances, such as imminent destruction of evidence, or if the suspect provides
consent.

6. What are some examples of warrantless searches? And under what circumstances
may they be conducted?

Warrantless searches can occur under specific circumstances, such as when an


individual consent to a search. Exigent circumstances allow law enforcement to act
without a warrant if there's an immediate threat to safety or risk of evidence
destruction. Searches incident to arrest enables police to search individuals and their
immediate surroundings during lawful arrests. The plain view doctrine permits the
seizure of evidence that is visible to officers lawfully present. Additionally, the
automobile exception allows searches of vehicles without a warrant if there's
probable cause. These exceptions aim to balance law enforcement needs with
individual privacy rights.
7. Under what circumstances can a portable electronic device be seized and searched
after a suspect is arrested?

A portable electronic device can be seized and searched after a suspect is arrested
under specific circumstances. Generally, if the arresting officers have probable cause
to believe that the device contains evidence related to the crime, they may seize it
without a warrant. Additionally, a search incident to arrest allows officers to examine
the device if it is within the immediate control of the arrestee.

8. Which type of exigent circumstances may arise with respect to computers?

Exigent circumstances related to computers can arise in several scenarios. One


common situation is the imminent destruction of evidence, where law enforcement
believes that data on a computer may be deleted or altered shortly. In such cases,
officers may act quickly to seize the device without a warrant to preserve that
evidence. Additionally, if a suspect is attempting to flee and there is a belief that the
computer contains crucial evidence, officers may seize it to prevent its potential loss.

9. When can a third-party consent to a search?

A third party can consent to a search when they have the authority or control over
the area or item being searched. This authority can arise in several situations, such as
when the third-party shares possession of the property with the suspect or has been
given permission by the suspect to access it.

10. Should search protocols be used in investigations? Why or why not?

Yes, search protocols should be used in investigations for several important reasons.
First, they ensure that evidence is collected systematically and consistently, which
helps maintain the integrity of the investigation. Following established protocols
minimizes the risk of overlooking critical evidence or contaminating it, which is
crucial for the case's success. Additionally, adhering to protocols helps protect the
rights of individuals involved, ensuring that searches are conducted legally and
ethically.

11. What should investigators do if a computer to be searched might contain privileged


information?

If a computer to be searched might contain privileged information, investigators


should take several precautions to protect that information. They should first identify
and isolate the device to prevent tampering and seek a warrant that outlines the
search's scope, addressing the handling of privileged materials. It is crucial to have
legal counsel present during the search to ensure compliance with laws regarding
attorney-client privilege or other protected communications. Investigators should
employ a protocol to segregate potentially privileged information from relevant
evidence and refrain from examining or using that information until its privileged
status is determined, often through a review by a judge or legal experts. This
approach ensures that individual rights are respected while allowing the
investigation to proceed effectively.

CHAPTER 5: Cyber laws: which statute for which crime?


SUMMARY

Viruses

Computer viruses are malicious software programs modified to replicate themselves


and spread from one computer to another, often causing damage or disruption. A
popular example is the ILOVEYOU virus, which spread through email, overwriting files
and sending copies to contacts in the victim's address book. This incident shows the
potential for widespread harm and the challenges of maintaining such cybercrimes.

The creator, Onel de Guzman, faced no punishment due to inadequate laws addressing
cyber threats at that time.

Types of malwares

Malware can be arranged into several groups (Trojan horses, viruses, and worms.) A
Trojan Horse is a deceptive program that masquerades as legitimate software but
causes harm when executed; it does not have the ability to self-replicate. In contrast, a
virus is a program that attaches itself to files and propagates when those files are run,
potentially corrupting or deleting data. A worm is a program capable of replicating itself
and spread to other systems thus significant threats to network security.

Spyware in comparison to Adware

knowing the difference between spyware and ware is very important in


understanding online threats. Spyware is malicious software that collects user
information without permission, often controlling user activities and stealing sensitive
data which ought not to be taken. This type of software can lead to privacy violations
and financial losses. On the other hand, adware automatically displays or downloads
advertisements, usually tracking user behavior to deliver targeted ads. While adware
can be intrusive, it is not always harmful and may sometimes come bundled with free
software.

Legal Framework for DoS/DDoS Attacks The legal framework for addressing
cybercrimes includes U.S.C. § 1030, part of the Computer Fraud and Abuse Act (CFAA). This
statute enables prosecution for individuals who launch DoS (Denial of Service) or DDoS
(Distributed Denial of Service) attacks. Specifically, § 1030(a)(5) addresses intentional
damage to computer systems, including the transmission of programs that cause harm.
Such attacks often involve unauthorized access to networks, aligning with the prohibitions
outlined in the statute. However, there are debates about the vagueness of the term
"damage" in legal interpretations, which can complicate prosecutions.

TCP Handshake and SYN Flood Attacks

The TCP handshake is a critical process used to establish connections between clients
and servers, typically involving three steps: SYN, SYN-ACK, and ACK. A SYN flood attack
is a malicious attempt to overwhelm a server by sending a flood of SYN requests
without completing the handshake process. This exploitation prevents legitimate users
from establishing connections, highlighting the need for effective countermeasures.

Types of Fraud

Various types of fraud exist, including identity theft, credit card fraud, insurance fraud,
investment fraud, mortgage fraud, and charity scams. Each type poses unique
challenges and risks to individuals and organizations.

Investment Fraud Types


Investment fraud can appear in several modules, with the two most common being
Ponzi schemes and pump and dump schemes.

A Ponzi scheme involves paying returns to earlier investors using the capital of newer
investors, rather than from profit generated by legitimate business activities.

whereas in a pump and dump scheme, the stock price is artificially inflated through
wrong statements, allowing perpetrators to sell with massive gain while leaving later
investors with worthless shares that is little or nothing.

Intellectual Property (IP)

Intellectual property is made up of creations of the mind, such as inventions, literary


works, and designs. Protecting IP is very important for encouraging innovation,
fostering economic growth, ensuring consumer satisfaction, and providing legal
recourse against unauthorized usage.

Trade Secrets

Trade secrets are confidential business information that provides a competitive edge.
The theft of trade secrets should be criminalized to protect businesses from losses and
maintain fair competition.

Cyber Harassment vs. Cyber Stalking

Cyber harassment involves repeated unwanted online behavior aimed at intimidating


individuals, while cyber stalking is a more severe form that includes a pattern of threats
and obsessive behavior intended to instill fear. Understanding these distinctions is
crucial for addressing online safety.

Critical thinking questions


In 2023, a victim named Sarah discovers that her personal information has been used to
open several credit accounts without her knowing about them.
After noticing unauthorized transactions had been carried out on her bank statements,
Sarah calls her bank and learns that someone has used her Social Security number to apply
for credit cards and loans not just one plenty of them.
These fraudulent deeds lead to significant financial losses and damage to her credit details
leaving her in massive debt. The woman was left in pains and she cried bitterly about them.

The investigation reveals that Sarah's information was stolen through a phishing attack.
The cyber hacker operating under a false personality gained access to Sarah's email and
personal information by sending her a deceptive email that appeared to be from her bank
and was very similar to it pushing her to accept it hence entering sensitive information on a
scam website. This was also due to improper orientation and lack of cyber aware

Evidence to Collect
As an investigator, several types of evidence should be collected to build a case against the
perpetrator:

Digital Forensics from Devices:

Computers and Smartphones: Analyse devices used by the suspect to identify malware,
phishing emails, and any tools used to create fake identities.
Log Files: Examine browser history and download logs to trace the suspect's online
activities and identify the phishing site.
Email Evidence:

Phishing Emails: Collect and analyse the phishing email sent to Sarah, including metadata
(timestamps, sender information) to trace its origin.
Victim's Email Account: Investigate Sarah's email account for any forwarded messages or
suspicious activity that could indicate how her information was compromised.
Financial Records:

Bank Statements: Review unauthorized transactions to identify patterns and potential links
to the suspect.
Credit Reports: Obtain Sarah's credit report to gather information about all accounts
opened in her name and any associated addresses or phone numbers.
Witness Testimonies:

Victim Statements: Obtain detailed accounts from Sarah about her interactions and the
timeline of events.
Bank and Credit Reporting Agency Representatives: Gather statements from
representatives who can confirm the fraudulent accounts and any actions taken.
Social Media Activity:

Analyse the suspect’s social media profiles for any evidence of identity theft, such as
boasting about fraudulent activities or connections to other victims.
Conclusion
Collecting this evidence is critical to establishing a timeline of events, linking the suspect to
the crime, and demonstrating the methods used to commit identity theft. This
comprehensive approach will aid in the prosecution of the perpetrator and provide justice
for the victim.
Review questions

1) What Are Viruses on Computers?


Computer viruses are malicious software programs modified to replicate themselves and
spread from one computer to another, often causing damage or disruption.

Example: The ILOVEYOU Virus WHICH WAS VERY POPULAR AND COMMON

• Impact: This virus overwrote files and sent itself to contacts in the victim's
address book, causing serious harm, and it is essential to know it was spread via
email causing serious havoc

• Perpetrator: Because laws at the time did not adequately address such
cybercrimes, Onel de Guzman, the creator, was initially unpunished.

2. Differentiate Between a Worm, Virus, and Trojan Horse

Trojan Horse: A malicious program that looks authentic or real but, when run,
causes harm. It’s also worth noting that the trojan horse is not self-replicating.

A virus is an application that affixes itself to files and propagates when those
files are run.

It spreads, can corrupt files and the system

Worm: An individualistic program that is capable of replicating itself to spread to


other systems without a need to attach itself to existing files causing serious havoc.

3. Difference Between Spyware and Adware

Spyware: Malicious software that collects user information without consent, often
monitoring activities and stealing data.

Adware: Software that automatically displays or downloads advertisements, often tracking


user behavior to deliver targeted ads. While it can be intrusive, it’s not always malicious.

4. U.S.C. &1030 and DOS/DDOS Attacks

U.S.C.& 1030 is part of the Computer Fraud and Abuse Act (CFAA). The relevant sections
that could be used against someone who launched a DoS or DDoS attack include:

1030(a)(5): This section addresses intentional damage to a computer system, including


transmission of a program that causes damage or loss.
Why It Could Be Used: Unauthorized Access: DDoS attacks often involve unauthorized
access to computers and networks, making them liable under this section.

Intent to Cause Damage: The intent behind DDoS attacks aligns with the prohibitions
outlined in the statute

If someone argues that this section cannot be used:

Legal Ambiguity: Some might claim that the interpretation of "damage" is too vague or
that the specific actions of a DDoS attack do not fit neatly within the statutory definitions.

5. TCP Handshake and SYN Flood Attack

TCP Handshake: A process used to establish a connection between a client and server,
typically involving three steps: SYN, SYN-ACK, and ACK.

SYN Flood Attack: An attack where an attacker sends a flood of SYN requests to a server
without completing the handshake, overwhelming the server and preventing legitimate
connections.

6. Types of Fraud People Engage In

• Identity theft, Credit card fraud, Insurance fraud, Investment fraud, Mortgage, fraud
Charity scams

7. Two Types of Investment Fraud

Ponzi Scheme: A type of investment fraud where returns are paid to earlier investors
using the capital from newer investors, rather than from profit earned

Pump and Dump: This involves inflating the price of a stock (often through false or
misleading statements) to sell at a profit, leaving later investors with worthless shares.

8. What Is Intellectual Property?

Intellectual Property (IP) refers to creations of the mind, such as inventions, literary and
artistic works, designs, symbols, names, and images used in commerce.

Why Should It Be Protected?

Encourages Innovation: Protection incentivizes creators to develop new ideas and


products.

Economic Growth: IP contributes to economic development and job creation.

Consumer Trust: Protecting IP helps ensure quality and authenticity for consumers.
Legal Rights: It provides legal recourse against unauthorized use or infringement

9. What Are Trade Secrets?

Trade Secrets are practices, designs, formulas, processes, or any confidential business
information that provides a competitive edge.

Why Should the Theft of Trade Secrets Be Criminalized?

Economic Impact: Theft can lead to significant financial losses for businesses.

Fair Competition: Protecting trade secrets maintains a level playing field among
competitors.

Encourages Innovation: Criminalizing theft fosters an environment where companies can


invest in research and development without fear of losing their competitive advantages.

10. Difference Between Cyber Harassment and Cyber Stalking

Cyber Harassment: Involves repeated and unwanted online behavior aimed at harming or
intimidating an individual. It may not involve a pattern of behavior and can occur in various
forms, such as abusive messages.

Cyber Stalking: A more severe form of harassment that involves a repeated pattern of
threatening or obsessive behavior intended to control or intimidate the victim. It often
includes monitoring, threats, and a direct intent to instill fear.

You might also like