## Unit I – Internet & Computer Networks
### Introduction to Internet & Networking
- Internet is a worldwide collection of interconnected computer networks that use TCP/IP to
exchange data, share resources, and provide services like web, email, and file transfer.[1]
- Computer networking means connecting two or more devices so they can communicate and
share hardware, software, and data securely and efficiently.[2]
### Network Topologies
- Bus: All devices share one backbone cable; easy and cheap but if the main cable fails, the
whole network goes down and performance reduces as more devices are added.[3]
- Star: All devices connect to a central hub/switch; easy to install and isolate faults, but failure of
hub/switch stops the network and more cable is required.[3]
- Ring: Devices form a closed loop; data travels in one direction from node to node, giving
predictable performance, but a single break can disturb the ring unless dual rings are used.[4]
- Mesh: Every node connects to many others; provides high reliability and redundancy, suitable
for critical networks, but very expensive and complex to wire and manage.[4]
### Types of Networks
- PAN: Very small personal area (few meters) connecting devices like phone, laptop, and
headset using Bluetooth or USB.[5]
- LAN: Covers a small area like a room, building, or campus; high data rate, usually owned by
one organization, often uses Ethernet and Wi‑Fi.[5]
- MAN: Spans a city or large campus; interconnects multiple LANs using high‑speed links such
as fiber; often run by telecom or service provider.[5]
- WAN: Covers countries or continents using telephone lines, satellite links, or under‑sea cables;
the Internet is the largest WAN.[6]
### Network Devices: Nodes, Hosts & Others
- Node: Any device in a network capable of sending/receiving data, such as PCs, printers,
routers, or servers.[6]
- Host: A node that has an IP address and runs applications accessible over the network, such
as web or mail servers.[2]
- Repeater: Regenerates and amplifies signals to extend cable length without loss of quality.[7]
- Hub: Multi‑port repeater that blindly broadcasts incoming frames to all ports; simple but causes
collisions and wastes bandwidth.[1]
- Switch: Smarter hub that learns MAC addresses and forwards frames only to the correct port,
improving security and performance.[1]
- Bridge: Connects and filters traffic between two LAN segments based on MAC addresses,
reducing collisions.[7]
- Router: Connects different networks (LAN to WAN etc.) and forwards packets based on IP
addresses and routing tables; works at network layer.[1]
- Modem: Converts digital signals to analog and back for communication over telephone/cable
networks.[1]
### TCP/IP, IP Address & Related Concepts
- TCP/IP is a stack of protocols; TCP at transport layer ensures reliable, ordered, error‑checked
delivery while IP at network layer handles logical addressing and routing of packets.[1]
- IP address is a unique 32‑bit (IPv4) or 128‑bit (IPv6) logical address, usually written as four
decimal numbers, used to identify devices in a network.[2]
- Port numbers identify specific processes on a host, allowing multiple applications (web, email)
to use the network simultaneously.[3]
### Web Browsers, Web Servers, URL, Domain Name, WWW, Search Engines
- Web browser is client software (Chrome, Firefox etc.) that sends HTTP/HTTPS requests,
receives HTML/web data from servers, and displays pages with text, images, and multimedia.[3]
- Web server is hardware+software that stores website files and responds to browser requests,
often using HTTP/HTTPS and maintaining logs for monitoring.[3]
- URL (Uniform Resource Locator) specifies protocol, domain name, and path of a resource on
the web, e.g., [Link]
- Domain name is a human‑readable address mapped to IP via DNS, organized hierarchically
(.com, .in, .org etc.).[3]
- WWW is a huge collection of hyperlinked multimedia documents accessible over the Internet
using web protocols, created using HTML and related technologies.[3]
- Search engine indexes web pages using crawlers and returns ranked list of pages for user
queries based on relevance algorithms.[3]
### Internet vs Intranet vs Extranet
- Internet: Public global network; anyone can access with proper connectivity and permissions;
uses public IP addresses.[6]
- Intranet: Private network within an organization using internet technologies (TCP/IP, web
browsers) but accessible only to authorized members.[2]
- Extranet: Controlled extension of intranet that allows selected external users (customers,
suppliers) to access certain resources via secure connections like VPN.[8]
### Uses of Computer Networks
- Communication: Email, instant messaging, voice and video calls, and video conferencing,
supporting remote teamwork and telecommuting.[5]
- Resource sharing: Sharing of printers, storage, applications, databases, and internet
connection, reducing costs and improving efficiency.[5]
- Centralized data management, online learning, e‑governance, cloud computing, and
entertainment (streaming, online gaming) are other major uses.[6]
***
## Unit II – E‑Commerce Concepts & Models
### Introduction to E‑commerce
- E‑commerce is the use of electronic networks, mainly the Internet, to conduct commercial
transactions including marketing, ordering, payments, and after‑sales service.[9]
- Main characteristics include global reach, 24×7 availability, interactivity, personalization,
reduced transaction cost, and automation of business processes.[8]
### E‑commerce Business Models (B2B, B2C, C2C, C2B)
- B2B: Businesses sell to other businesses, usually in bulk; transactions often involve negotiated
prices, long‑term contracts, and integrated supply chains.[8]
- B2C: Businesses sell directly to final consumers via online stores; focus is on user‑friendly
websites, online marketing, customer support, and efficient logistics.[9]
- C2C: Individual consumers sell to other consumers using platforms that provide listing, search,
and payment facilities; platform earns fees or commission.[9]
- C2B: Individuals or small service providers offer products or services to companies, such as
freelance platforms where clients post projects and individuals bid.[10]
### Applications of E‑commerce
- Service industry: Online portals offer services like education, health consultation, online ticket
booking, hotel reservations, and utilities bill payments.[8]
- Retail sector: Virtual stores provide electronic catalogs, shopping carts, product comparison,
and home delivery, expanding market reach of retailers.[11]
- Financial services: Internet banking enables fund transfer, statement viewing, loan
applications; other services include online insurance and stock trading.[8]
- Travel & tourism: Websites and apps allow real‑time booking of flights, trains, buses, hotels,
and tour packages with dynamic pricing and reviews.[8]
### Future of E‑commerce
- Trends include growth of mobile‑first commerce, social commerce (shopping via social media),
voice‑based shopping, and personalized recommendations using data analytics.[11]
- Use of AI chatbots, automation in warehousing, drones for delivery, and cross‑border
e‑commerce is expected to increase.[8]
### Online Shopping & Web Portals
- Online shopping process: Customer browses catalog, selects items into cart, registers/logs in,
chooses payment and delivery options, and receives order confirmation and tracking.[11]
- Web portals act as gateways offering multiple services like news, email, search, and shopping
with personalization and single sign‑on.[5]
### Mobile Commerce & Services
- M‑commerce is e‑commerce conducted using mobile devices through apps or mobile web,
supporting activities like shopping, banking, ticketing, and content delivery.[6]
- Advantages: Portability, location‑based services, instant notifications, and support for
micro‑payments using mobile wallets or UPI.[6]
### Mobile Banking, WAP & WML, Mobile Information Devices, POS
- Mobile banking lets customers perform balance inquiry, fund transfer, bill payments, and
service requests using secure apps or SMS/USSD services.[6]
- WAP (Wireless Application Protocol) is an earlier standard that allowed limited web access on
basic phones; WML (Wireless Markup Language) is a lightweight markup language used to
create pages for WAP browsers.[11]
- Mobile information devices include smartphones, tablets, PDAs, and specialized handheld
terminals used in logistics and retail.[6]
- POS term describes the hardware and software at checkout counters that read cards/QR,
calculate totals, interact with payment gateways, and update inventory.[11]
***
## Unit III – Online Payment Systems & Security
### Online Payment Mechanism
- Online payment flows usually involve customer initiating order, website collecting payment
details, payment gateway securely forwarding data to acquiring bank, bank checking with card
network/issuer, and confirmation being sent back.[12]
- Systems include credit/debit cards, net banking, mobile wallets, UPI/instant payment systems,
and prepaid instruments.[12]
### Electronic Payment System: Legal Issues & Digital Currency
- Electronic payment systems must follow banking regulations, KYC norms,
anti‑money‑laundering rules, and data protection laws of the country.[12]
- Digital currency refers to value stored and transferred electronically, including cryptocurrencies
and central bank digital currency, raising issues of regulation, taxation, and consumer
protection.[2]
### E‑Cash & E‑Cheque
- E‑cash is stored in cards or software wallets and allows low‑value, quick payments sometimes
with limited anonymity similar to physical cash.[12]
- E‑cheque is an electronic version of a cheque where payer’s bank details and authorization
are transmitted digitally and verified using encryption and digital signatures.[12]
### Electronic Fund Transfer (EFT) – Advantages & Risks
- EFT enables direct transfer of money between bank accounts through electronic systems like
NEFT, RTGS, and IMPS without paper instruments.[13]
- Advantages include speed, reduced administrative cost, low human error, and convenience;
risks involve technical failures, wrong account entries, unauthorized access, and fraud.[13]
### Digital Token‑based E‑payment & Smart Cards
- Tokenization replaces sensitive card data with randomly generated tokens that are useless if
intercepted, increasing security during online transactions.[14]
- Smart cards contain an embedded chip capable of storing data securely and performing
cryptographic operations, hence used for EMV cards, ID cards, and transit cards.[14]
### Payment Gateways & Risk Management
- Payment gateway acts as a bridge between merchant site and banking network, encrypting
sensitive data, performing basic fraud checks, and returning authorization results.[12]
- Risk management includes setting transaction limits, monitoring patterns, using 2‑factor
authentication, address verification, blacklists, and chargeback procedures.[14]
### Cryptography: Concepts & Types
- Cryptography aims to provide confidentiality, integrity, authentication, and non‑repudiation by
converting readable data into ciphertext and back.[4]
- Symmetric key cryptography uses one shared key for both encryption and decryption (e.g.,
AES), while asymmetric key cryptography uses key pairs (public and private, e.g., RSA).[4]
### Authentication & Access Control
- Authentication methods range from something user knows (password, PIN), something user
has (token, mobile phone), to something user is (biometrics like fingerprint, face).[4]
- Access control ensures only authorized users can access resources using mechanisms like
user accounts, roles, permissions, and access control lists.[7]
### Data Encryption & Decryption; Public & Private Key
- Encryption uses algorithms and keys to transform plaintext into ciphertext before sending over
insecure networks.[4]
- Decryption uses corresponding key to restore original data, with safety depending on secrecy
and size of keys.[4]
- In public key systems, public key is openly distributed while private key is kept secret; data
encrypted with one key can only be decrypted with the other.[4]
### Digital Signature, E‑check Certification & Digital Certification
- Digital signature is created by hashing the message and encrypting the hash with sender’s
private key, allowing receiver to verify authenticity and integrity using sender’s public key.[14]
- E‑check certification involves verifying and certifying parties engaged in e‑cheque transactions,
often using digital certificates and secure protocols.[12]
- Digital certificates issued by Certificate Authorities bind a public key to an entity’s identity and
provide basis for trust in secure web protocols like HTTPS.[14]
***
## Unit IV – E‑commerce Security & IT Law
### Threats in E‑commerce
- Technical threats include malware, viruses, worms, Trojan horses, SQL injection, cross‑site
scripting, denial‑of‑service attacks, and sniffing of unencrypted data.[12]
- Non‑technical threats involve phishing emails, identity theft, credit card fraud, fake websites,
insider misuse, and social engineering tricks on employees or customers.[12]
### Fraud Prevention & E‑commerce Data Protection
- Organisations use encryption, secure coding, fraud detection software, address and CVV
verification, 2‑factor authentication, and regular security audits to prevent fraud.[15]
- Data protection practices include collecting minimal personal data, storing it in encrypted form,
restricting access through roles, regular backups, and safe disposal policies.[15]
### PCI Compliance & Data Privacy Laws
- PCI DSS is a set of technical and operational requirements for companies processing card
payments, such as maintaining secure networks, encrypting cardholder data, and testing
security systems regularly.[15]
- Data privacy laws (like GDPR‑style regulations and Indian rules) require transparency,
consent, purpose limitation, data subject rights, and security safeguards for personal data.[16]
### Security of Client & Service Provider
- Client‑side security focuses on updated operating system and browser, antivirus, firewalls, safe
browsing habits, and avoiding suspicious links or downloads.[12]
- Service‑provider security demands hardened servers, firewalls, intrusion detection/prevention
systems, secure software development, segregation of duties, and incident response plans.[15]
### Security Issues over the Web
- Major issues are packet sniffing, man‑in‑the‑middle attacks, session hijacking, weak
authentication, and vulnerabilities in web applications or plugins.[12]
- Use of HTTPS/TLS, secure cookies, input validation, regular patching, and security testing
helps in reducing these risks.[15]
### Cyber Law – IT Act 2000 (India)
- IT Act 2000 gives legal recognition to electronic records and digital signatures, enabling
electronic contracts, e‑governance services, and online commerce in India.[14]
- The Act defines numerous cyber offences such as hacking, tampering with computer source
code, identity theft, cyber pornography, and cyber terrorism, and specifies penalties and
procedures, later strengthened by the 2008 amendment.[17]