0% found this document useful (0 votes)
13 views8 pages

Cyber Security 2

The document outlines key concepts related to cyber security, including definitions of cyber security, cyber space, cyber attacks, and various types of malware and cyber crimes. It also discusses the IT Act of 2000 in India, detailing its provisions and amendments aimed at addressing cyber crimes and digital transactions. Additionally, it highlights common cyber threats, including phishing, malware, and social engineering, as well as the latest reported cyber threats.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views8 pages

Cyber Security 2

The document outlines key concepts related to cyber security, including definitions of cyber security, cyber space, cyber attacks, and various types of malware and cyber crimes. It also discusses the IT Act of 2000 in India, detailing its provisions and amendments aimed at addressing cyber crimes and digital transactions. Additionally, it highlights common cyber threats, including phishing, malware, and social engineering, as well as the latest reported cyber threats.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

key concepts related to Cyber Security,

1. Cyber Security

Cyber Security is the practice of protecting computers, networks, systems, and data from digital attacks,
unauthorized access, and damage. It ensures safe use of the internet and digital devices.

2. Cyber Space

Cyber space refers to the virtual environment created by interconnected computer networks, especially
the internet, where communication and data exchange take place.

3. Cyber Attack

A cyber attack is a malicious attempt to damage, disrupt, or gain unauthorized access to computer
systems or networks.

Examples: hacking, malware attacks, phishing.

4. Cyber Crime

Cyber crime includes illegal activities performed using computers or the internet.

Examples: online fraud, identity theft, cyber bullying, data theft.

5. Malware

Malware is malicious software designed to harm or exploit systems.

Types:Virus,Worm,Trojan Horse,Ransomware,Spyware

6. Phishing

Phishing is a social engineering attack where attackers trick users into sharing sensitive information like
passwords or bank details through fake emails or websites.

7. Authentication

Authentication is the process of verifying the identity of a user.

Examples: passwords, OTPs, biometrics (fingerprint, face ID).

8. Authorization

Authorization determines what resources or actions a verified user is allowed to access in a system.

9. Confidentiality, Integrity, Availability (CIA Triad)

These are the core principles of cyber security:

Confidentiality: Data should be accessible only to authorized users

Integrity: Data should not be altered without permission

Availability: Systems and data should be available when needed


10. Encryption

Encryption is the process of converting data into a secret code to prevent unauthorized access. Only
authorized users can decrypt and read the data.

11. Firewall

A firewall is a security system that monitors and controls incoming and outgoing network traffic based on
predefined security rules.

12. Antivirus Software

Antivirus software detects, prevents, and removes malware from computer systems to keep them
secure.

13. Social Engineering

Social engineering involves manipulating people psychologically to gain confidential information rather
than using technical hacking methods.

14. IT Act (Information Technology Act, 2000)

The IT Act, 2000 is an Indian law that provides legal recognition to electronic transactions and prescribes
punishment for cyber crimes.

Introduction to digital payments:

• Digital payments are transactions that take place via digital or online modes, with no

physical exchange of money involved. This means that both parties, the payer and the payee,

use electronic mediums to exchange money.

• There are different modes and types of digital payments that are prevalent in India.

1. Banking Cards

2. USSD (Unstructured Supplementary Service Data)

3. UPI (United Payment Interface)

4. AEPS (Aadhaar enabled Payment System)

5. Mobile wallets

6. Point of Sale Machines (PoS)

7. Mobile Banking

8. Internet Banking

Social media platform


8. Hash tags and Trends: Hash tags are used to categorize and discover content related
to specific topics or trends. Many platforms also feature trending topics or hashtags that
highlight popular or relevant discussions.
9. Search and Discovery: Users can search for specific people, pages, or content, and
platforms often provide recommendations for users to discover new accounts and
content based on their interests and connections.
10. Analytics and Insights: Some platforms offer users and content creators access to
analytics and insights, which provide data on the performance of their posts,
engagement metrics, and audience demographics.
11. Advertising and Promotions: Social media platforms often offer advertising tools that
allow businesses and individuals to promote their content to a larger audience. This can
include paid ads, sponsored posts, and promoted content.
12. Live Streaming: Many platforms support live streaming, allowing users to broadcast live
video to their audience. Viewers can engage with the streamer in real-time through
comments and reactions.
13. Mobile Apps: Social media platforms typically offer mobile applications for smart
phones and tablets, making it easy for users to access and engage with the platform
while on the go.
14. Community Guidelines: Platforms have rules and community guidelines that users are
expected to follow. These guidelines aim to maintain a safe and respectful online
environment and often address issues like harassment, hate speech, and content policies.

Common Crime Targeting Computers And Mobiles:


Cybercrimes targeting computers and mobile devices are prevalent in the digital age, as these
devices store vast amounts of personal, financial, and sensitive information. Here are some common types
of cybercrimes that specifically target computers and mobile devices:
1. Malware Attacks:
 Computer Viruses: Malicious software that can replicate and infect other files or systems on a
computer.
 Trojans: Malware disguised as legitimate software, which can steal data or provide unauthorized
access to a device.
 Ransom ware: Malware that encrypts a user's data and demands a ransom for decryption, often
affecting both computers and mobile devices.
2. Phishing and Smishing:
 Phishing: Deceptive emails or messages that trick users into revealing sensitive information,
often targeting both computers and mobile devices.
 Smishing: Similar to phishing, but using SMS or text messages for the same purpose.
3. Mobile App Malware:
Malicious apps that are disguised as legitimate applications on mobile devices. These apps can
steal data, spy on users, or perform other harmful actions.
4. Mobile Device Theft:
The physical theft of mobile devices, which can result in unauthorized access to personal
information if the device is not properly secured.
5. Wi-Fi Network Attacks:
Cybercriminals may target Wi-Fi networks to intercept data transmitted between computers and
mobile devices, potentially gaining access to sensitive information.
6. SIM Card Swapping:
Attackers may use social engineering to convince mobile carriers to transfer a victim's phone
number to a new SIM card. This can allow them to gain access to the victim's accounts and
personal information.
7. Key logging:
Malicious software or hardware that records keystrokes on a computer or mobile device,
capturing passwords and other sensitive information.
8. Drive-By Downloads:
Infections that occur when visiting compromised or malicious websites, resulting in the automatic
download of malware onto the victim's device.
9. Mobile Banking and Payment Fraud:
Cybercriminals may target mobile banking apps and payment systems to steal funds or conduct
fraudulent transactions.
10. Mobile Device Malware Distribution:
Criminals may send malicious links or files through text messages or social media to infect
mobile devices.
11. Social Media Threats:
Cybercriminals may use social media platforms to impersonate individuals or organizations,
spread malware, or engage in other fraudulent activities.
12. Data Theft from Mobile Devices:
Unauthorized access to or theft of data stored on mobile devices, such as contact lists, photos,
messages, and documents.

IT Act 2000 and its amendments:


The Information Technology Act, 2000, is a crucial piece of legislation in India that deals with
various aspects of electronic commerce and digital transactions. It was enacted to provide legal
recognition to electronic transactions and facilitate electronic governance. The Act has undergone several
amendments over the years to adapt to the evolving digital landscape. As of my last knowledge update in
September 2021, here are some key provisions of the IT Act, 2000, and its notable amendments:
1. The Information Technology Act, 2000: The original IT Act, 2000, was enacted on June 9, 2000,
and came into effect on October 17, 2000. It provided legal recognition for electronic
documents, digital signatures, and electronic records.
2. Amendment Act of 2008: One of the most significant amendments to the IT Act came in 2008.
This amendment brought about several changes, including:
 Introducing new cybercrimes and penalties for offenses such as cyber terrorism, hacking,
and the spread of malicious software.
 Expanding the scope of the Act to cover data protection and privacy concerns.
 Introducing provisions for the appointment of a Chief Information Security Officer
(CISO) in government agencies.
 Strengthening the framework for the issuance of digital signatures and certificates.
 Providing legal protection to intermediaries like internet service providers from liability
for third-party content.
3. Amendment Act of 2011: The 2011 amendment further strengthened the legal framework for
dealing with cybercrimes and data protection. It also addressed issues related to the publication
of obscene content and the power of the Indian Computer Emergency Response Team (CERT-
In).
4. Amendment Act of 2020: The most recent amendment to the IT Act was introduced in 2020.
Some key provisions of this amendment include:
 Regulation of social media intermediaries: It required social media companies to appoint a
grievance officer, a nodal officer, and a chief compliance officer, all residing in India.
 Enhanced data protection measures: The amendment introduced stricter provisions related
to the protection of personal data and mandated the storage of critical personal data within
the country.
 Changes to the intermediary liability regime: The Act clarified the liability of intermediaries
for third-party content, making them responsible for removing or disabling access to
unlawful content within 36 hours of receiving notice.

Types of Cyber Security Threats


A threat in cybersecurity is a malicious activity by an individual or organization to corrupt or steal data,
gain access to a network, or disrupts digital life in general. The cyber community defines the following threats
available today:
 Malware
Malware means malicious software, which is the most common cyber attacking tool. It is used by
the cybercriminal or hacker to disrupt or damage a legitimate user's system. The following are the
important types of malware created by the hacker:
1. Virus: It is a malicious piece of code that spreads from one device to another. It can clean files
and spreads throughout a computer system, infecting files, stoles information, or damage device.
2. Spyware: It is a software that secretly records information about user activities on their
system. For example, spyware could capture credit card details that can be used by the
cybercriminals for unauthorized shopping, money withdrawing, etc.
3. Trojans: It is a type of malware or code that appears as legitimate software or file to fool us into
downloading and running. Its primary purpose is to corrupt or steal data from our device or do
other harmful activities on our network.
4. Ransom ware: It's a piece of software that encrypts a user's files and data on a device, rendering
them unusable or erasing. Then, a monetary ransom is demanded by malicious actors for
decryption.
5. Worms: It is a piece of software that spreads copies of itself from device to device without human
interaction. It does not require them to attach themselves to any program to steal or damage the
data.
6. Adware: It is an advertising software used to spread malware and displays advertisements on our
device. It is an unwanted program that is installed without the user's permission. The main
objective of this program is to generate revenue for its developer by showing the ads on their
browser.
7. Botnets: It is a collection of internet-connected malware-infected devices that allow
cybercriminals to control them. It enables cybercriminals to get credentials leaks, unauthorized
access, and data theft without the user's permission.
----------------------------
 Phishing
Phishing is a type of cybercrime in which a sender seems to come from a genuine organization like PayPal,
eBay, financial institutions, or friends and co-workers. They contact a target or targets via email, phone, or text
message with a link to persuade them to click on that links. This link will redirect them to fraudulent websites to
provide sensitive data such as personal information, banking and credit card information, social security numbers,
usernames, and passwords. Clicking on the link will also install malware on the target devices that allow hackers to
control devices remotely.
 Man-in-the-middle (MITM) attack
A man-in-the-middle attack is a type of cyber threat (a form of eavesdropping attack) in which a
cybercriminal intercepts a conversation or data transfer between two individuals. Once the cybercriminal places
themselves in the middle of a two-party communication, they seem like genuine participants and can get sensitive
information and return different responses. The main objective of this type of attack is to gain access to our business
or customer data. For example, a cybercriminal could intercept data passing between the target device and the
network on an unprotected Wi-Fi network.
 Distributed denial of service (DDoS)
It is a type of cyber threat or malicious attempt where cybercriminals disrupt targeted servers,
services, or network's regular traffic by fulfilling legitimate requests to the target or its surrounding
infrastructure with Internet traffic. Here the requests come from several IP addresses that can make the
system unusable, overload their servers, slowing down significantly or temporarily taking them offline, or
preventing an organization from carrying out its vital functions.
 Brute Force
A brute force attack is a cryptographic hack that uses a trial-and-error method to guess all
possible combinations until the correct information is discovered. Cybercriminals usually use this attack to
obtain personal information about targeted passwords, login info, encryption keys, and Personal
Identification Numbers (PINS).
 SQL Injection (SQLI)
SQL injection is a common attack that occurs when cybercriminals use malicious SQL scripts for
backend database manipulation to access sensitive information. Once the attack is successful, the malicious
actor can view, change, or delete sensitive company data, user lists, or private customer details stored in the
SQL database.
 Domain Name System (DNS) attack
A DNS attack is a type of cyber attack in which cyber criminals take advantage of flaws in the
Domain Name System to redirect site users to malicious websites (DNS hijacking) and steal data from
affected computers. It is a severe cyber security risk because the DNS system is an essential element of the
internet infrastructure.
Latest Cyber Threats
The following are the latest cyber threats reported by the U.K., U.S., and Australian governments :
Romance Scams
The U.S. government found this cyber threat in February 2020. Cybercriminals used this threat through dating
sites, chat rooms, and apps. They attack people who are seeking a new partner and duping them into giving away
personal data.
Dridex Malware
It is a type of financial Trojan malware identifies by the U.S. in December 2019 that affects the public, government,
infrastructure, and business worldwide. It infects computers through phishing emails or existing malware to steal
sensitive information such as passwords, banking details, and personal data for fraudulent transactions. The National
Cyber Security Centre of the United Kingdom encourages people to make sure their devices are patched, anti-virus
is turned on and up to date, and files are backed up to protect sensitive data against this attack.
Emotet Malware
Emoted is a type of cyber-attack that steals sensitive data and also installs other malware on our device. The
Australian Cyber Security Centre warned national organizations about this global cyber threat in 2019.
The following are the system that can be affected by security breaches and attacks:
o Communication: Cyber attackers can use phone calls, emails, text messages, and messaging apps for
cyberattacks.
o Finance: This system deals with the risk of financial information like bank and credit card detail. This
information is naturally a primary target for cyber attackers.
o Governments: The cybercriminal generally targets the government institutions to get confidential public
data or private citizen information.
o Transportation: In this system, cybercriminals generally target connected cars, traffic control systems, and
smart road infrastructure.
o Healthcare: A cybercriminal targets the healthcare system to get the information stored at a local clinic to
critical care systems at a national hospital.
o Education: A cybercriminals target educational institutions to get their confidential research data and
information of students and employees.
.

You might also like