Unit 3: Cyber Investigation
Topics Covered: Concepts of Investigation, Cyber Investigation, Network Investigation, Investigating
Audit Logs, Web Attacks, Investigating Computer Intrusions, Profiling, Cyber Criminal Profiling, Stylo-
metric Techniques, Warranted Searches, Warrantless Searches, Undercover Techniques.
Introduction to Cyber Investigation
Cyber investigation means finding and collecting digital clues to catch people who do cyber crimes,
like hacking or fraud.
What It Does:
o Finds out who did the cyber crime.
o Collects proof that can be used in court.
o Helps stop more cyber crimes by learning how they happen.
Why It’s Important:
o Cyber crimes are increasing because everyone uses the internet.
o Attackers hide easily, so we need special ways to find them.
Main Challenges:
o Attackers use tools like VPNs to hide their location.
o Cyber crimes happen across countries, so laws are hard to apply.
o Technology changes fast, making it tough to keep up.
Concepts of Investigation
Cyber Investigation:
o It’s about looking at digital things like computers, phones, or USBs to find proof of a crime.
o Steps:
Step 1: Find the Problem: Notice something wrong, like a hacked email account.
Step 2: Keep Things Safe: Don’t let anyone change the proof (e.g., don’t turn off the
computer).
Step 3: Collect Proof: Take copies of data, like files or emails.
Step 4: Check the Proof: Look at the data to see what happened (e.g., find deleted
messages).
Step 5: Show the Proof: Write a report for the court to use.
o Example: If someone hacks a bank account, investigators check the computer to find clues
like the hacker’s email.
Network Investigation:
o This means checking internet traffic to find out how a cyber crime happened.
o What to Look For:
Traffic Logs: Show who connected to the system (e.g., a strange IP address).
Packet Data: Shows what data was sent (e.g., a virus file).
Firewall Alerts: Tell if someone tried to break in.
o Tools Used:
Wire Shark: Looks at internet data packets to find bad activity.
Nmap: Checks which doors (ports) on a system are open.
o Example: A company’s website stops working. Investigators use Wire Shark to see lots of
fake traffic from many IPs, showing a DDoS attack.
Investigating Audit Logs:
o Audit logs are like diaries that computers keep about what happens on them.
o Types of Logs:
System Logs: Show when the computer was turned on or off.
User Logs: Show who logged in and when (e.g., a login at midnight).
App Logs: Show what apps did (e.g., a banking app accessed).
o How to Use Logs:
Look for strange things, like someone logging in at odd hours.
Match log times with other clues, like when a file was stolen.
See what the attacker did, like if they changed or deleted files.
o Example: A company loses data. The logs show someone logged in at 3 AM from a new
location, which is suspicious.
Web Attacks and Computer Intrusions
Web Attacks:
o These are attacks on websites or online apps to steal data or cause harm.
o Types:
SQL Injection:
Attackers trick a website into giving them secret data.
How It Works: They type a special code (like "1=1") in a login box to get into
the database.
Example: An attacker gets customer names from a shopping website by
typing a code in the search bar.
Investigation: Check the website logs to see what codes were typed, and look
at the database for stolen data.
Cross-Site Scripting (XSS):
Attackers put bad scripts on a website to steal user info.
How It Works: They add a script to a comment box that runs when someone
visits the page.
Example: A script on a forum steals a user’s login details when they read a
post.
Investigation: Look at the website code for strange scripts and check user
logs for stolen data.
Phishing:
Attackers make fake emails or websites to trick people into giving their
passwords.
How It Works: They send an email pretending to be a bank, asking for login
details.
Example: A fake email says, “Your bank account is locked, click here to fix it,”
and steals the password.
Investigation: Check the email’s sender address and find where the fake
website is hosted.
Investigating Computer Intrusions:
o This means finding out how someone broke into a computer system.
o Steps:
Step 1: Find the Entry Point: Look for weak spots, like an open port (e.g., port 3389
for remote access).
Step 2: Trace the Attacker: Use the IP address to find where the attack came from
(e.g., another country).
Step 3: Check Logs: See what the attacker did (e.g., copied files or installed a virus).
Step 4: Look for Malware: Find any bad software the attacker left behind (e.g., a
virus to steal data).
Step 5: Write a Report: Note down everything to tell the police or court.
o Example:
A company’s server is hacked, and data is stolen.
Logs show someone used a weak password to log in.
The IP address leads to a known hacker group.
A virus is found that was sending data to the hacker.
Profiling and Cyber Criminal Profiling
Profiling:
o This is like making a picture of the attacker to understand who they are and what they
want.
o What to Look At:
What They Want: Money, secrets, or just to cause trouble.
How They Work: Do they use simple tricks or advanced tools?
Who They Attack: Banks, schools, or governments?
o Example: An attacker who only hacks banks probably wants money and might be part of a
big group.
Cyber Criminal Profiling:
o Behavior Analysis:
Look at what the attacker does to guess their goal.
Example: If they steal credit card details, they want money, not fame.
o Tool Usage:
See what tools they use to know how smart they are.
Example: Using a virus like WannaCry means they know advanced hacking tricks.
o Location Clues:
Check the language in messages or the time of attacks to guess where they are.
Example: If attacks happen at night in India, but morning in Russia, the attacker
might be in Russia.
o Mindset:
Look at how they talk in messages to understand their personality.
Example: A rude message in a ransom note shows the attacker might be bold and
not scared.
Stylo-metric Techniques:
o This means studying how someone writes to find out who they are.
o What to Check:
Words They Use: Do they use special words a lot?
How They Write: Short sentences, lots of emojis, or bad grammar?
Typing Style: Do they use “u” instead of “you”?
o How It Helps:
Match a hacker’s email to their old messages to find their real name.
o Example: A hacker sends a message saying, “Gimme money or I leak your data.” The same
style is found in a suspect’s old emails, linking them to the crime.
Legal Aspects of Investigation
Warranted Searches:
o This is when police get permission from a court to look at someone’s computer or phone.
o How It Works:
Police tell the court why they need to search (e.g., suspect has proof of a crime).
Court gives a paper (warrant) saying they can search.
They can only look at what the warrant says (e.g., only the suspect’s laptop).
o Example: Police get a warrant to check a suspect’s phone for messages about a hacking
case.
Warrantless Searches:
o Sometimes police search without a warrant if it’s very urgent.
o When It’s Allowed:
Danger Right Now: Like if a terrorist attack is happening.
Permission Given: If the person says, “You can look at my phone.”
Proof Might Be Lost: If waiting means the proof will be deleted.
o Example: Police take a suspect’s laptop during a cyber attack to stop it, without waiting for
a warrant.
Undercover Techniques:
o This is when investigators pretend to be someone else to catch the criminal.
o How They Do It:
Join secret online groups (like on the dark web) to talk to criminals.
Pretend to buy stolen data to find out who is selling it.
Act like a friend on social media to get the suspect to share secrets.
o Example: An investigator joins a hacking group online, pretends to be a hacker, and finds
out who is selling stolen passwords.
o Rules:
They can’t trick someone into doing a crime they wouldn’t do.
They need permission from their boss to do this.
Conclusion
Cyber investigation helps catch cyber criminals by finding digital clues and following the law.
It uses tools like logs and profiling to understand the crime and the criminal.
Legal steps like warrants make sure the proof can be used in court to punish the criminal.
Diagram: Cyber Investigation Process (Flowchart)