0% found this document useful (0 votes)
3 views6 pages

Cyber Crime and Forensics Overview

Uploaded by

civil.someswaran
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views6 pages

Cyber Crime and Forensics Overview

Uploaded by

civil.someswaran
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

UNIT I – INTRODUCTION TO CYBER

CRIME AND FORENSICS


1. Introduction to Traditional Computer Crime
Traditional computer crime refers to illegal activities conducted using computers as tools,
targets, or storage devices. Before the rise of the modern internet, computer crimes
involved:

 Unauthorized access to mainframe systems


 Password theft
 Physical theft of computer hardware
 Data alteration and sabotage
 Software piracy
 Telephone line tapping (phreaking)

Characteristics

 Occurred mostly in controlled environments (corporate/government labs)


 Limited number of attackers with high technical expertise
 Security relied heavily on physical protection, not network security

2. Traditional Problems Associated with Computer Crime


Despite technological progress, the core challenges remain similar:

Problem Explanation
Attribution difficulty Hard to identify the exact attacker due to anonymization.
Jurisdiction issues Crimes often cross national borders → legal conflicts.
Lack of evidence Digital evidence is volatile, easily deleted, altered, or encrypted.
Underreporting Organizations avoid reporting due to reputational risk.
Rapid tech evolution Criminals adapt faster than law enforcement.
Insider threats Majority of breaches historically linked to internal employees.

3. Role of ECD and ICT in Cybercrime


ECD (Electronic Communication Devices)

ECD includes mobile phones, tablets, modems, satellite phones, VoIP devices.

Role in Cybercrime
 SMS spoofing, SIM cloning
 Mobile malware attacks
 GPS-based stalking
 Illegal VoIP routing & call masking
 Dark web access through mobile TOR networks

ICT (Information and Communication Technology)

ICT integrates computing + communication technologies.

Role in Cybercrime

 Enables mass-scale cyber attacks using global connectivity


 Facilitates anonymous transactions (cryptocurrency, darknet)
 Allows automation of attacks (botnets, worms)
 Supports global cyber espionage and cyberterrorism

4. Classification of Cyber Crime


Cybercrime can be classified as:

A. Crimes Against Individuals

 Identity theft
 Cyberstalking & harassment
 Phishing & vishing
 Online defamation
 Revenge pornography
 Social media impersonation

B. Crimes Against Property

 Ransomware
 Intellectual property theft
 Unauthorized access & system breach
 Crypto-jacking
 Data theft & alteration

C. Crimes Against Organization

 Distributed Denial of Service (DDoS)


 Insider sabotage
 Corporate espionage
 Financial fraud & data breach
 Supply chain exploitation

D. Crimes Against Government / Nation


 Cyberwarfare
 Cyber espionage (APT attacks)
 Digital election manipulation
 Critical infrastructure attacks (power, telecom)
 Propaganda distribution & terrorism recruitment online

5. Present and Future of Cybercrime


Present Trends

 Mobile-based cybercrime dominates


 Ransomware attacks on hospitals, banks, and governments
 Dark Web marketplaces for drugs, weapons, stolen data
 Cryptocurrency-based laundering

Future Outlook

 AI-Driven attacks (deepfake fraud, AI phishing)


 IoT exploitation (smart homes, smart cars)
 Quantum-based cryptographic breaches
 Autonomous malware
 Space-based hacking (satellite hijacking)

6. Cyber Forensics
Cyber forensics is the scientific process of collecting, preserving, analyzing, and
presenting digital evidence in a legally admissible way.

Objectives

 Recover deleted or hidden data


 Trace attackers and reconstruct events
 Support criminal, civil, corporate investigations
 Maintain chain of custody

7. Steps in Forensic Investigation


1. Preparation
o Legal authorization, forensic tools, documentation
2. Identification
o Locate potential sources of digital evidence
3. Preservation
o Secure scene, prevent alteration (write blockers, imaging)
4. Collection
o Capture data using forensically sound methods
5. Examination
o Extract relevant data, recover deleted files
6. Analysis
o Reconstruct timeline, correlate logs
7. Documentation
o Report findings with chain of custody logs
8. Presentation
o Expert testimony in court

8. Forensic Examination Process


 Chain of Custody:
A documented trail showing evidence integrity.
 Timeline Reconstruction:
Using logs, file metadata, registry entries.
 Data Recovery:
Restoring deleted, formatted, or hidden files.
 Steganalysis:
Detection of hidden messages in media.

9. Types of Cyber Forensic (CF) Techniques


Technique Purpose
Disk Forensics Recovery of deleted data, partition analysis
Network Forensics Packet capture, intrusion tracing
Mobile Forensics SIM cloning evidence, call/SMS logs, GPS
Email Forensics Header tracing, spam analysis
Malware Forensics Reverse engineering, payload behavior
Cloud Forensics Logs & data from SaaS, IaaS, PaaS
IoT Forensics Smart devices, sensor logs, wearable data

10. Forensic Duplication and Investigation


Forensic Duplication

 Bit-by-bit copy of storage media


 Performed using write blockers to prevent alteration
 Output: Forensic Image (e.g., .dd, .E01)
Requirements

 Hash value verification (MD5/SHA-1/SHA-256)


 Documentation of storage chain

Investigation Focus

 Deleted file recovery


 Log analysis
 Detecting malware
 Timeline reconstruction
 User activity & footprints

11. Forensics Technology and Systems


Common Tools

 EnCase
 FTK (Forensic Toolkit)
 Autopsy / Sleuth Kit
 X-Ways Forensics
 Cellebrite (mobile)
 Wireshark (network)
 Volatility (memory forensics)

Hardware

 Write blockers
 Forensic imaging systems
 High-storage forensic servers

12. Understanding Computer Investigation


A computer investigation seeks to identify what happened, how, when, and by whom.

Core Activities:

 Log correlation (system/application/network logs)


 RAM analysis for live system artifacts
 Malware identification
 Browser history & cache review
 Tracing communication channels (VoIP, social media)
13. Data Acquisition
Data acquisition is the process of collecting digital evidence in a legally admissible
manner.

Types

Type Explanation
Live Acquisition Performed when system is running (RAM, network traffic)
Dead Acquisition When device is powered off (disk imaging)

Principles

 Maintain integrity → no data modification


 Use write blockers
 Calculate and verify hash values
 Document every action (chain of custody)

Conclusion
Cybercrime continues to evolve with technological advancements, leading to complex
security challenges. Cyber forensics plays a crucial role by scientifically collecting and
analyzing communication, device, and network evidence to ensure successful legal
prosecution and digital security.

You might also like