UNIT I – INTRODUCTION TO CYBER
CRIME AND FORENSICS
1. Introduction to Traditional Computer Crime
Traditional computer crime refers to illegal activities conducted using computers as tools,
targets, or storage devices. Before the rise of the modern internet, computer crimes
involved:
Unauthorized access to mainframe systems
Password theft
Physical theft of computer hardware
Data alteration and sabotage
Software piracy
Telephone line tapping (phreaking)
Characteristics
Occurred mostly in controlled environments (corporate/government labs)
Limited number of attackers with high technical expertise
Security relied heavily on physical protection, not network security
2. Traditional Problems Associated with Computer Crime
Despite technological progress, the core challenges remain similar:
Problem Explanation
Attribution difficulty Hard to identify the exact attacker due to anonymization.
Jurisdiction issues Crimes often cross national borders → legal conflicts.
Lack of evidence Digital evidence is volatile, easily deleted, altered, or encrypted.
Underreporting Organizations avoid reporting due to reputational risk.
Rapid tech evolution Criminals adapt faster than law enforcement.
Insider threats Majority of breaches historically linked to internal employees.
3. Role of ECD and ICT in Cybercrime
ECD (Electronic Communication Devices)
ECD includes mobile phones, tablets, modems, satellite phones, VoIP devices.
Role in Cybercrime
SMS spoofing, SIM cloning
Mobile malware attacks
GPS-based stalking
Illegal VoIP routing & call masking
Dark web access through mobile TOR networks
ICT (Information and Communication Technology)
ICT integrates computing + communication technologies.
Role in Cybercrime
Enables mass-scale cyber attacks using global connectivity
Facilitates anonymous transactions (cryptocurrency, darknet)
Allows automation of attacks (botnets, worms)
Supports global cyber espionage and cyberterrorism
4. Classification of Cyber Crime
Cybercrime can be classified as:
A. Crimes Against Individuals
Identity theft
Cyberstalking & harassment
Phishing & vishing
Online defamation
Revenge pornography
Social media impersonation
B. Crimes Against Property
Ransomware
Intellectual property theft
Unauthorized access & system breach
Crypto-jacking
Data theft & alteration
C. Crimes Against Organization
Distributed Denial of Service (DDoS)
Insider sabotage
Corporate espionage
Financial fraud & data breach
Supply chain exploitation
D. Crimes Against Government / Nation
Cyberwarfare
Cyber espionage (APT attacks)
Digital election manipulation
Critical infrastructure attacks (power, telecom)
Propaganda distribution & terrorism recruitment online
5. Present and Future of Cybercrime
Present Trends
Mobile-based cybercrime dominates
Ransomware attacks on hospitals, banks, and governments
Dark Web marketplaces for drugs, weapons, stolen data
Cryptocurrency-based laundering
Future Outlook
AI-Driven attacks (deepfake fraud, AI phishing)
IoT exploitation (smart homes, smart cars)
Quantum-based cryptographic breaches
Autonomous malware
Space-based hacking (satellite hijacking)
6. Cyber Forensics
Cyber forensics is the scientific process of collecting, preserving, analyzing, and
presenting digital evidence in a legally admissible way.
Objectives
Recover deleted or hidden data
Trace attackers and reconstruct events
Support criminal, civil, corporate investigations
Maintain chain of custody
7. Steps in Forensic Investigation
1. Preparation
o Legal authorization, forensic tools, documentation
2. Identification
o Locate potential sources of digital evidence
3. Preservation
o Secure scene, prevent alteration (write blockers, imaging)
4. Collection
o Capture data using forensically sound methods
5. Examination
o Extract relevant data, recover deleted files
6. Analysis
o Reconstruct timeline, correlate logs
7. Documentation
o Report findings with chain of custody logs
8. Presentation
o Expert testimony in court
8. Forensic Examination Process
Chain of Custody:
A documented trail showing evidence integrity.
Timeline Reconstruction:
Using logs, file metadata, registry entries.
Data Recovery:
Restoring deleted, formatted, or hidden files.
Steganalysis:
Detection of hidden messages in media.
9. Types of Cyber Forensic (CF) Techniques
Technique Purpose
Disk Forensics Recovery of deleted data, partition analysis
Network Forensics Packet capture, intrusion tracing
Mobile Forensics SIM cloning evidence, call/SMS logs, GPS
Email Forensics Header tracing, spam analysis
Malware Forensics Reverse engineering, payload behavior
Cloud Forensics Logs & data from SaaS, IaaS, PaaS
IoT Forensics Smart devices, sensor logs, wearable data
10. Forensic Duplication and Investigation
Forensic Duplication
Bit-by-bit copy of storage media
Performed using write blockers to prevent alteration
Output: Forensic Image (e.g., .dd, .E01)
Requirements
Hash value verification (MD5/SHA-1/SHA-256)
Documentation of storage chain
Investigation Focus
Deleted file recovery
Log analysis
Detecting malware
Timeline reconstruction
User activity & footprints
11. Forensics Technology and Systems
Common Tools
EnCase
FTK (Forensic Toolkit)
Autopsy / Sleuth Kit
X-Ways Forensics
Cellebrite (mobile)
Wireshark (network)
Volatility (memory forensics)
Hardware
Write blockers
Forensic imaging systems
High-storage forensic servers
12. Understanding Computer Investigation
A computer investigation seeks to identify what happened, how, when, and by whom.
Core Activities:
Log correlation (system/application/network logs)
RAM analysis for live system artifacts
Malware identification
Browser history & cache review
Tracing communication channels (VoIP, social media)
13. Data Acquisition
Data acquisition is the process of collecting digital evidence in a legally admissible
manner.
Types
Type Explanation
Live Acquisition Performed when system is running (RAM, network traffic)
Dead Acquisition When device is powered off (disk imaging)
Principles
Maintain integrity → no data modification
Use write blockers
Calculate and verify hash values
Document every action (chain of custody)
Conclusion
Cybercrime continues to evolve with technological advancements, leading to complex
security challenges. Cyber forensics plays a crucial role by scientifically collecting and
analyzing communication, device, and network evidence to ensure successful legal
prosecution and digital security.