*CYBER SECURITY
Cyber Security – History of Internet –
Impact of Internet – CIA Triad; Reason
for Cyber Crime – Need for Cyber
Security – History of Cyber Crime;
Cybercriminals – Classification of
Cybercrimes – A Global Perspective on
Cyber Crimes; Cyber Laws – The Indian IT
Act – Cybercrime and Punishment.
*What is Cyber Security?
What is Cyber Security?
*The technique of protecting internet-connected systems
such as computers, servers, mobile devices, electronic
systems, networks, and data from malicious attacks is
known as cybersecurity.
*We can divide cybersecurity into two parts one is cyber,
and the other is security. Cyber refers to the technology
that includes systems, networks, programs, and data.
* And security is concerned with the protection of systems,
networks, applications, and information. In some cases, it
is also called electronic information security or
information technology security.
Types of Cyber Security
*Every organization's assets are the combinations of a
variety of different systems.
*Therefore, we can categorize cybersecurity in the following
sub-domains:
*Network Security
*Application Security
*Information or Data Security
*Identity management
*Operational Security
*Mobile Security
*Cloud Security
*Disaster Recovery and Business Continuity Planning
*Network Security: It involves implementing the
hardware and software to secure a computer network
from unauthorized access, intruders, attacks,
disruption, and misuse. This security helps an
organization to protect its assets against external
and internal threats.
*Application Security: It involves protecting the
software and devices from unwanted threats. This
protection can be done by constantly updating the
apps to ensure they are secure from attacks.
Successful security begins in the design stage,
writing source code, validation, threat modeling,
etc., before a program or device is deployed.
*Information or Data Security: It involves
implementing a strong data storage mechanism to
maintain the integrity and privacy of data, both in
storage and in transit.
*Identity management: It deals with the procedure for
determining the level of access that each individual
has within an organization.
* Operational Security: It involves processing and
making decisions on handling and securing data assets.
*Mobile Security: It involves securing the
organizational and personal data stored on mobile
devices such as cell phones, computers, tablets,
and other similar devices against various malicious
threats. These threats are unauthorized access, device
loss or theft, malware, etc.
*Cloud Security: It involves in protecting the information
stored in the digital environment or cloud architectures
for the organization. It uses various cloud service
providers such as AWS, Azure, Google, etc., to ensure
security against multiple threats.
Disaster Recovery and Business Continuity Planning: It
deals with the processes, monitoring, alerts,
and plans to how an organization responds when any
malicious activity is causing the loss of operations or
data. Its policies dictate resuming the lost operations
after any disaster happens to the same operating
capacity as before the event.
What was the start of cybersecurity?
Cybersecurity history is interesting indeed. It is thought
to have started in 1971 when Bob Thomas, a computer
programmer with BBN, created and deployed a virus
that served as a security test. It was not malicious but
did highlight areas of vulnerability and security flaws in
what would become “the internet.”
The virus, named after a Scooby Doo villain, “Creeper,”
was designed to move across ARPANET (Advanced
Research Projects Agency Network) – the forerunner to
what we now call the internet. ARPANET was
established by the U.S. Department of Defense.
History of the Internet
* Initiallyin the 1960s, the Internet was started as a medium
for sharing information with government researchers.
* Duringthe time computers were larger in size and were
immovable.
* In case anyone had to access the information stored in any
computer, they had to travel to the location of the computer
or the other way to have magnetic computer tapes that
could be transported through the postal system of that time.
* Alongside, Escalated Cold War played a major role in the
creation of the internet.
* The Soviet Union had deployed the Sputnik satellite which
led the Defense Department of the United States to examine
the possibilities of communicating information despite
nuclear.
* The situation resulted in the development of ARPANET
(Advanced Research Projects Agency Network), which, later
on, evolved into the Internet. In the initial days, ARPANET
became a huge success with restricted participation where it
was accessible to academic and research institutions that
had contracts with the US Defense.
* Earlier there wasn’t any standard mechanism for
the computer networks that would enable
them to communicate with each other.
* Transfer Control Protocol (TCP/IP) which was
developed in 1970, was adopted as a new
communication protocol for ARPANET in 1983.
* The technology enabled various computers on
different networks to communicate with each
other and this is how the Internet was officially
born on January 1, 1983.
*An Overview From 1985 to 1995 The invention of
DNS, the widespread usage of TCP/IP, and the
popularity of email all contributed to an increase in
internet activity.
*Between 1986 and 1987, the network expanded
from 2,000 to 30,000 hosts.
*People were increasingly using the internet to send
messages, read news, and exchange files.
*The internet needed to be more user-friendly. In
1989, Tim Berners-Lee, a British computer scientist,
proposed a solution to his employer, CERN, the
international particle-research facility in Geneva,
Switzerland.
* He proposed a new method for organizing and
connecting all of the information available on CERN’s
computer network, making it quick and easy to
access. His idea for a “network of information”
evolved into the World Wide Web.
* The release of the Mosaic browser in 1993 introduced
the web to a new non-academic audience, and people
began to learn how simple it was to make their own
HTML websites
* Asa result, the number of websites increased from
130 in 1993 to over 100,000 at the beginning of 1996.
* By 1995, the internet and the World Wide Web had
become an established phenomenon, with over 10
million global users using the Netscape Navigator. The
Netscape Navigator was the most popular browser
at that point in time.
*What is DNS? DNS is short for Domain Name System.
*It functions as the internet’s version of a phone book,
converting difficult-to-remember IP addresses into
simple names.
*As the number of machines on the network grew, it
became impossible to keep track of all the different IP
addresses.
*The development of the Domain Name System (DNS)
in 1983 solved this problem. DNS was invented at the
University of Southern California by Paul Mockapetris
and Jon Postel.
*It was one of the breakthrough inventions that helped
in paving the way for the World Wide Web.
Impact of Internet
*The internet has had an incredible impact on society since
its inception.
*Ithas changed the way we communicate, do business, learn,
and even think.
*The internet has brought people from different parts of the
world together and has made information accessible to everyone
with an internet connection.
*One of the biggest impacts of the internet is on communication.
Social media platforms like Facebook, Twitter, and
Instagram have made it easy for people to connect with
others from anywhere in the world.
*People can share their thoughts, ideas, and experiences
instantly with their friends and family. Video conferencing tools
like Zoom have revolutionized remote communication, making it
possible for people to work and learn from anywhere in the
world.
*The internet has also had a significant impact on business.
*E-commerce websites like Amazon and eBay have made it
possible for people to shop from the comfort of their own
homes.
*Small businesses can now reach a global audience by creating
an online presence.
*The internet has also made it easier for people to work from
home, which has become increasingly important during the
COVID-19 pandemic.
*Education is another area that has been greatly impacted by
the internet.
*Online courses and tutorials have made it possible for people
to learn new skills from anywhere in the world.
*Massive open online courses (MOOCs) like Coursera and edX
have made higher education more accessible to people who
may not have the opportunity to attend a traditional university.
* However, the internet has also had some negative
impacts. Cyberbullying, online harassment, and identity
theft have become increasingly common.
* The internet has also made it easier for people to access
inappropriate content, which can have a negative impact
on young children.
* In conclusion, the internet has had a tremendous impact
on society.
* It has changed the way we communicate, do business,
learn, and even think. While there are some negative
impacts, the benefits of the internet far outweigh the
negatives.
* As the internet continues to evolve, it will be interesting
to see how it will shape our society in the future.
CIA Triad
When talking about network security, the CIA triad is one of the
most important models which is designed to guide policies for
information security within an organization.
CIA stands for :
1. Confidentiality
2. Integrity
3. Availability
These are the objectives that should be kept in mind while
securing a network
Confidentiality
Confidentiality means that only authorized
individuals/systems can view sensitive or classified
information.
The data being sent over the network should not be
accessed by unauthorized individuals.
The attacker may try to capture the data using different
tools available on the Internet and gain access to your
information.
A primary way to avoid this is to use encryption
techniques to safeguard your data so that even if the
attacker gains access to your data, he/she will not be able
to decrypt it.
Encryption standards include AES(Advanced Encryption
Standard) and DES (Data Encryption Standard).
Another way to protect your data is through a VPN
tunnel. VPN stands for Virtual Private Network and helps
the data to move securely over the network.
Integrity
The next thing to talk about is integrity.
Well, the idea here is to make sure that data has not been modified.
Corruption of data is a failure to maintain data integrity.
To check if our data has been modified or not, we make use of a hash
function.
We have two common types: SHA (Secure Hash Algorithm) and
MD5(Message Direct 5).
Now MD5 is a 128-bit hash and SHA is a 160-bit hash if we’re using
SHA-1.
There are also other SHA methods that we could use like SHA-0, SHA-
2, and SHA-3. Let’s assume Host ‘A’ wants to send data to Host ‘B’ to
maintain integrity.
A hash function will run over the data and produce an arbitrary hash
value H1 which is then attached to the data.
When Host ‘B’ receives the packet, it runs the same hash function over
the data which gives a hash value of H2. Now, if H1 = H2, this means
that the data’s integrity has been maintained and the contents were not
modified.
Availability
This means that the network should be readily available
to its users.
This applies to systems and to data.
To ensure availability, the network administrator should
maintain hardware, make regular upgrades, have a plan for
fail-over, and prevent bottlenecks in a network.
Attacks such as DoS or DDoS may render a network
unavailable as the resources of the network get exhausted.
The impact may be significant to the companies and
users who rely on the network as a business tool. Thus,
proper measures should be taken to prevent such attacks.
Reasons behind cyber attacks
Every business, regardless of its size, is a potential
target of cyber attack.
That is because every business has key assets (financial
or otherwise) that criminals may seek to exploit.
By recognising the common motives behind cyber
attacks, you can build a better understanding of the risks
you may face, and understand how best to confront them.
Why do cyber attacks happen?
Most often, cyber attacks happen because criminals want
your:
business' financial details
customers' financial details (eg credit card data)
sensitive personal data
customers' or staff email addresses and login credentials
customer databases
clients lists
IT infrastructure
IT services (eg the ability to accept online payments)
intellectual property (eg trade secrets or product designs)
Cyber attacks against businesses are often deliberate
and motivated by financial gain. However, other
motivations may include:
* making a social or political point - eg through
hacktivism
*espionage - eg spying on competitors for unfair
advantage
*intellectual challenge - eg 'white hat' hacking
*The key point is that cyber security threats don't
always come from anonymous hackers or online
criminal groups.
*Vulnerabilities can arise within your own business too.
How are cyber criminals motivated?
Financial Gain
*The primary motivation of a hacker is money, and
getting it can be done with a variety of methods.
*They could directly gain entry to a bank or investment
account; steal a password to your financial sites and
then transfer the assets over to one of their own;
swindle an employee into completing a money
transfer through a complicated spear phishing
technique, or conduct a ransomware attack on your
entire organization.
* The possibilities are endless, but most hackers are
out to make a profit
Recognition & Achievement
*Some hackers are motivated by the sense of
achievement that comes with cracking open a major
system.
* Some may work in groups or independently, but, on
some scale, they would like to be recognized.
* This also ties into the fact that cyber criminals are
competitive by nature, and they love the challenge their
actions bring.
* In fact, they often drive one another to complete more
complicated hacks.
Insider Threats
*Individuals who have access to critical information or
systems can easily choose to misuse that access —to the
detriment of their organization.
*These threats can come from internal employees,
vendors, a contractor or a partner—and are viewed as
some of the greatest cyber security threats to
organizations.
*However, not all insider threats are intentional,
according to an Insider Threat Report from Crowd
Research Partners. Most (51%) are due to carelessness,
negligence, or compromised credentials, but the
potential impact is still present even in an unintentional
scenario.
Political Motivation –
*“Hacktivism” Some cyber criminal groups use their
hacking skills to go after large organizations.
*They are usually motivated by a cause of some sort,
such as highlighting human rights or alerting a large
corporation to their system vulnerabilities.
* Or, they may go up against groups whose ideologies
do not align with their own.
*These groups can steal information and argue that
they are practicing free speech, but more often than
not, these groups will employ a DDoS (Distributed
Denial of Service) attack to overload a website with
too much traffic and cause it to crash.
State Actors
* State-sponsored actors receive funding and
assistance from a nation-state.
*They are specifically engaged in cyber crime to
further their nation’s own interests.
*Typically, they steal information, including
“intellectual property, personally identifying
information, and money to fund or further espionage
and exploitation causes.”
* However, some state-sponsored actors do conduct
damaging cyberattacks and claim that their
cyberespionage actions are legitimate activity on
behalf of the state.
Corporate Espionage
*Thisis a form of cyber attack used to gain an
advantage over a competing organization.
*Conducted for commercial or financial purposes,
corporate espionage involves:
Acquiring property like processes or techniques,
locations, customer data, pricing, sales, research,
bids, or strategies
Theft of trade secrets, bribery, blackmail, or
surveillance.
Importance of Cybersecurity (need of
cybersecurity)
* Protecting Sensitive Data
*Prevention of Cyber Attacks
*Safeguarding Critical Infrastructure
*Maintaining Business Continuity
*Compliance with Regulations
*Protecting National Security
*Preserving Privacy
*Protecting Sensitive Data: With the increase in
digitalization, data is becoming more and more
valuable. Cybersecurity helps protect sensitive
data such as personal information, financial data,
and intellectual property from unauthorized access
and theft.
*Prevention of Cyber Attacks: Cyber attacks, such
as Malware infections, Ransomware, Phishing, and
Distributed Denial of Service (DDoS) attacks, can
cause significant disruptions to businesses and
individuals. Effective cybersecurity measures help
prevent these attacks, reducing the risk of data
breaches, financial losses, and operational
disruptions.
Safeguarding Critical Infrastructure: Critical
infrastructure, including power grids, transportation
systems, healthcare systems, and communication
networks, heavily relies on interconnected computer
systems. Protecting these systems from cyber
threats is crucial to ensure the smooth functioning of
essential services and prevent potential disruptions
that could impact public safety and national security.
Maintaining Business Continuity: Cyber attacks
can cause significant disruption to businesses,
resulting in lost revenue, damage to reputation, and
in some cases, even shutting down the business.
Cybersecurity helps ensure business continuity by
preventing or minimizing the impact of cyber
attacks.
*Compliance with Regulations: Many industries
are subject to strict regulations that require
organizations to protect sensitive data. Failure to
comply with these regulations can result in
significant fines and legal action. Cybersecurity
helps ensure compliance with regulations such as
HIPAA, GDPR, and PCI DSS.
*Protecting National Security: Cyber attacks
can be used to compromise national security by
targeting critical infrastructure, government
systems, and military installations. Cybersecurity
is critical for protecting national security and
preventing cyber warfare.
Preserving Privacy: In an era where personal
information is increasingly collected, stored, and
shared digitally, cybersecurity is crucial for
preserving privacy. Protecting personal data from
unauthorized access, surveillance, and misuse helps
maintain individuals’ privacy rights and fosters trust
in digital services..
History of cyber crimes
1940s: The time before crime 1950s: The
phone phreaks
1960s: All quiet on the Western Front
1970s: Computer security is born
1980s: From ARPANET to internet
1990s: The world goes online
2000s: Threats diversify and multiply
2010s: The next generation
Internet Time Theft
*Such a theft occurs when an unauthorized person
uses the Internet hours paid for by another person.
*Basically, Internet time theft comes under hacking
because the person who gets access to someone
else's ISP user ID and password, either by hacking
or by gaining access to it by illegal means, uses it
to access the Internet without the other person's
knowledge.
*However, one can identify time theft if the Internet
time has to be recharged often, even when one's
own use of the Internet is not frequent.
*The issue of Internet time theft is related to the
crimes conducted through "identity theft."
Salami attack/ salami technique
*These attacks are used for committing financial
crimes.
*The idea here is to make the alteration so
insignificant that in a single case it would go
completely unnoticed;
*for example a bank employee inserts a program,
into the bank's servers, that deducts a small
amount of money (say 2/- or a few cents in a
month) from the account of every customer.
*No account holder will probably notice this
unauthorized debit, but the bank employee will
make a sizable amount every month.
Data diddling
*A data diddling attack involves altering raw data just
before it is processed by a computer and then
changing it back after the processing is completed.
*Electricity Boards in -India have been victims to data
diddling programs inserted when private parties
computerize their systems.
*Data diddling involves changing data input in a
computer.
Forgery
*Counterfeit currency notes, postage and revenue
stamps, marksheets, etc. can be forged using
sophisticated computers, printers and scanners.
*Outside many colleges there are miscreants
soliciting the sale of fake marksheets or even
degree certificates.
*These are made using computers and high
quality scanners and printers.
*In fact, this is becoming a booming business
involving large monetary amount given to
student gangs in exchange for these bogus but
authentic looking certificates.
Web Jacking
*Web jacking occurs when someone forcefully takes
control of a website (by cracking the password and
later changing it).
*Thus, the first stage of this crime involves
"password sniffing."
*The actual owner of the website does not have any
more control over what appears on that website.
Newsgroup Spam/Crimes Emanating from
Usenet Newsgroup
* As explained earlier, this is one form of spamming.
* The word "Spam" was usually taken to mean excessive
multiple posting (EMP).
* The advent of Google Groups, and its large Usenet archive,
has made Usenet more attractive to spammers than ever.
* Spamming of Usenet newsgroups actually predates E-Mail
Spam.
* The first widely recognized Usenet Spam titled Global Alert
for All: Jesus is Coming Soon (though not the most famous)
was posted on 1 8 January 1994 by Clarence L Thomas IV, a
sysadmin at Andrews University.
* Itwas a fundamentalist religious tract claiming that "this
world's history is coming to a climax."
Industrial Spying/Industrial Espionage
* Corporations, like governments, often spy on the enemy.
* The Internet and privately networked systems provide new and
better opportunities for espionage.
* "Spies" can get information about product finances, research and
development and marketing strategies, an activity known as
"industrial spying."
* Cyberspies rarely leave behind a trail.
* Industrial spying is not new; in fact it is as old as industries
themselves.
* The use of the Internet to achieve this is probably as old as the
Internet itself.
* The reserved hunting field of a few hundreds of highly skilled
hackers, contracted by high-profile companies or certain
governments via the means of LAW organizations (it is said that
they get several hundreds of thousands of dollars, depending on the
"assignment").
Hacking
*Although the purposes of hacking are
many, the main ones are as follows:
1. Greed;
2. power;
3. publicity;
4. revenge;
5. adventure;
6. desire to access forbidden information;
7. destructive mindset.
*Every act committed toward breaking into a computer
and/or network is hacking and it is an offense.
*Hackers write or use ready-made computer programs
to attack the target computer.
*They possess the desire to destruct and they get
enjoyment out of such destruction.
*Some hackers hack for personal monetary gains, such
as stealing credit card information, transferring money
from various bank accounts to their own account
followed by withdrawal of money.
*They extort money from some corporate giant
threatening him to publish the stolen information that
is critical in nature.
Online frauds
* Thereare a few major types of crimes under the category of
hacking: Spoofing website and E-Mail security alerts, hoax mails
about virus threats lottery frauds and spoofing.
* InSpoofing websites and E-Mail security threats, fraudsters
create authentic looking websites that are actually nothing but a
spoof (see Chapter 5 for details of Spoofing).
* The purpose of these websites is to make the user enter personal
information which is then used to access business and bank
accounts.
* Fraudsters
are increasingly turning E-Mail to generate traffic to
these websites.
* Thiskind of online fraud is common in banking and financial
sector.
* Thereis a rise in the number of financial institutions' customers
who receive such E-Mails which usually contain a link to a spoof
website and mislead users to enter user ids and passwords on the
pretence that security details can be updated or passwords
changed.
Pornographic offenses: Child pornography
“Child pornography" means any visual depiction,
including but not limited to the following:
*1. Any photograph that can be considered obscene
and/or unsuitable for the age of child viewer;
*2. film, video, picture;
*3. computer-generated image or picture Of sexually
explicit conduct where the production of such visual
depiction involves the use of minor engaging in
sexually explicit conduct.
*Child pornography is considered an offense.
Unfortunately, child pornography is a reality Of the
Internet.
*The Internet is being highly used by its abusers to
reach and abuse children sexually, worldwide.
*In India too, the Internet has become a household
commodity in the urban areas of the nation.
*"Pedophiles" are people who physically or psychologically
coerce minors to engage in sexual activities, which the
minors would not consciously consent to.
Here is how pedophiles operate:
Step 1: Pedophiles use a false identity to trap the
children/teenagers (using "false identity" which in itself is
another crime called "identity theft"). ID theft is addressed
in Chapter 5.
Step 2: They seek children/teens in the kids' areas on the
services, such as the Teens BB, Games BB or chat areas
where the children gather.
Step 3: They befriend children/teens.
Step 4: They extract personal information from the
child/teen by winning his/her confidence.
Step 5: Pedophiles get E-MAil address of the child/teen
and start making contacts on the victim's E-Mail address
as well. Sometimes, these E-Mails contain sexually
explicit language.
Step 6: They start sending pornographic images/text to
the victim including child pornographic images in order
to help child/teen shed his/her inhibitions so that a
feeling is created in the mind of the victim that what is
being fed to him is normal and that everybody does it.
Step 7: At the end of it, the pedophiles set up a meeting
with the child/teen out of the house and then drag
him/her into the net to further sexually assault him/her
or to use him/her as a sex object.
Software piracy
* Cybercrime investigation cell of India defines "software
piracy" as theft of software through the illegal copying of
genuine programs or the counterfeiting and distribution of
products intended to pass for the original.
* There are many examples of software piracy: end-user
copying — friends loaning disks to each other, or
organizations under-reporting the number of software
installations they have made, or organizations not tracking
their software licenses;
* hard disk loading with illicit means — hard disk vendors
load pirated software; counterfeiting — large-scale
duplication and distribution of illegally copied software;
* illegal
downloads from the Internet — by intrusion, by
cracking serial numbers, etc.
*Beware that those who buy pirated software have a lot
to lose:
(a) getting untested software that may have been
copied thousands of times over
(b) the software, if pirated, may potentially contain hard-
drive-infecting viruses,
(c) there is no technical support in the case of software
failure, that is, lack of technical product support available
to properly licensed users
(d) there is no warranty protection
(e) there is no legal right to use the product, etc.
Computer sabotage
* The use of the Internet to prevent the normal functioning
of a computer system through the introduction of worms,
viruses (refer to Chapter 4) or logic bombs, is referred to
as computer sabotage.
* It can be used to gain economic advantage over a
competitor, to promote the illegal activities of terrorists or
to steal data or programs for extortion purposes.
* Logic bombs are event-dependent programs created to do
something only when a certain event (known as a trigger
event) occurs.
* Some viruses may be termed as logic bombs because
they lie dormant all through the year and become active
only on a particular date
E-mail bombing/mail bombs
*E-Mail bombing refers to sending a large number of
E-Mails to the victim to crash victim's E-Mail account
(in the case of an individual) or to make victim's mail
servers crash (in the case of a company or an E-Mail
service provider).
*Computer program can be written to instruct a
computer to do such tasks on a repeated basis.
*In recent times, terrorism has hit the Internet in the
form of mail bombings.
*By instructing a computer to repeatedly send E-Mail
to a specified person's E-Mail address, the
cybercriminal can overwhelm the recipient's personal
account and potentially shut down entire systems.
Usenet Newsgroup as the Source of Cybercrimes
*Usenet is a popular means of sharing and distributing
information on the Web with respect to specific topic
or subjects.
*Usenet is a mechanism that allows sharing informatiOn
in a many-to-many manner.
*The newsgroups are spread across 30,000 different
topics. In principle, it is possible to prevent the
distribution of specific newsgroup.
*It is possible to put Usenet to following criminal use:
Distribution/sale of pornographic material;
distribution/sale of pirated software packages;
distribution of hacking software;
sale of stolen credit card numbers. Refer to Chapter I I,
Section 11.4.2, Illustration 5;
sale of stolen data/stolen property.
Computer network intrusions
* Computer Networks pose a problem by way of security
threat because people can get into them from anywhere
* Thepopular movie "War Games" illustrated an extreme but
useful example of this.
* "Crackers" who are often misnamed " Hackers"" II can break
into computer systems from anywhere in the world and
steal data, plant viruses, create backdoors, insert Trojan
Horses or change user names and passwords.
* Network intrusions are illegal, but detection and
enforcement are difficult.
* Current laws are limited and many intrusions go
undetected.
* The cracker can bypass existing password protection by
creating a program to capture logon IDs and passwords.
*The practice of "strong password" is therefore
important (password strength is explained in Chapter
4).
Password sniffing
*Password Sniffers are programs that monitor and
record the name and password of network users
as they login, jeopardizing security at a site.
*Whoever installs the Sniffer can then
impersonate an authorized user and login to
access restricted documents.
*Laws are not yet set up
to adequately prosecute
a person for impersonating another person
online.
*Laws designed to prevent unauthorized access
to information may be effective in apprehending
crackers using Sniffer programs.
Credit card frauds
* Information security requirements for anyone handling
credit cards have been increased dramatically recently
* Millions
of dollars may be lost annually by consumers who
have credit card and calling card numbers stolen from
online databases.
* Securitymeasures are improving, and traditional methods
Of law enforcement seem to be sufficient for prosecuting
the thieves of such information.
* Bulletin boards and other online services are frequent
targets for hackers Who want to access large databases of
credit card information.
* Such attacks usually result in the implementation of
stronger security systems.
* Security ofcardholder data has become one of the biggest
issues facing the payment card industry.
Identity theft
* Identity theft is a fraud involving another person's identity for
an illicit purpose.
* This occurs when a criminal uses someone else's identity for
his/her own illegal purposes.
* Phishing
and identity theft are related offenses (the topic is
addressed in Chapter 5).
* Examples include fraudulently obtaining credit, stealing
money from the victim's bank accounts, using the victims
credit card number establishing accounts with utility
companies, renting an apartment using the victim's name.
* In most cybercrime forms, computers and/or other digital
devices end up getting used as one or a combination of the
following:
1. As the tool for committing cybercrime;
2. crime involving attack against the computer;
3. use for storing information related to
cybercrime/information useful for committing cybercrime.
CHAPTER -2
Cyberoffenses: How Criminals Plan Them
* Technologyis a "double-edged sword" as it can be used for
both good and bad purposes.
* People with the tendency to cause damages or carrying out
illegal activities will use it for bad purpose.
* Computers and tools available in IT are also no exceptions;
like other tool, they are used as either target of offense or
means for committing an offense.
* Chapter 1 provided an overview of hacking, industrial
espionage, network intrusions, password sniffing, computer
viruses, etc.
* They are the most commonly occurring crimes that target
the computer.
*Cybercriminal use the World Wide Web and Internet
to an optimum level for all illegal activities to store
data, contacts, account information, etc
*The criminals take advantage Of the widespread lack
of awareness about cybercrimes and cyberlaws
among the people who are constantly using the IT
infrastructure for official and personal purposes.
*People who commit cybercrimes are known as
"Crackers“.
*An attacker would look to exploit the vulnerabilities
in the networks, most often so because the networks
are not adequately protected.
*The categories of vulnerabilities that hackers typically
search for are the following:
1. Inadequate border protection (border as in the sense
of network periphery);
2. remote access servers (RASs) with weak access
controls;
3. application servers with well-known exploits;
4. misconfigured systems and systems with default
configurations.
Fig. 2.2 illustrates a small network highlighting specific
occurrences of several vulnerabilities described
Categories of Cybercrime
Cybercrime can be categorized based on the
following:
1. The target of the crime and
2. whether the crime occurs as a single event or as a
series of events.
*Crimes targeted at individuals: The goal is to exploit
human weakness such as greed and naivety These
crimes include financial frauds, sale of non-existent
or stolen items, child pornography (explained in
Section 1.5.13, Chapter 1), copyright violation,
harassment, etc.
*with the development in the IT and the Internet;
thus, criminals have a new tool that allows them to
expand the pool of potential victims.
*However, this also makes difficult to trace and
apprehend the criminals.
*Crimes targeted at property: This includes
stealing mobile devices such as cell phone, laptops,
personal digital assistant (PDAs), and removable
medias (CDs and pen drives); transmitting harmful
programs that can disrupt functions of the systems
and/or can wipe out data from hard disk, and can
create the malfunctioning of the attached devices in
the system such as modem, CD drive, etc.
*Crimes targeted at organizations:
Cyberterrorism is one of the distinct crimes against
organiztions/governments. Attackers (individuals or
groups of individuals) use computer tools and the
Internet to usually terrorize the citizens of a
particular country by stealing the private
information, and also to damage the programs and
files or plant programs to get control of the network
and/or system (see Box 2.3).
Single event of cybercrime: It is the single event
from the perspective of the victim. For example,
unknowingly open an attachment that may contain virus
that will infect the system (PC/laptop).This is known as
hacking or fraud.
Series of events: This involves attacker interacting
with the victims repetitively. For example, attacker
interacts with the victim on the phone and/or via chat
rooms to establish relationship first and then they
exploit that relationship to commit the sexual assault
(refer to Section 2.4 on "Cyberstalking").
How criminals plan the attack
*Criminals use many methods and tools to locate
the vulnerabilities of their target, The target can
be an individual and/or an organization.
*Criminals plan passive and active attacks
*Active attacks are usually used to alter the system
(i.e., computer network) whereas passive attacks
attempt to gain information about the target.
*Active attacks may affect the availability, integrity
and authenticity of data whereas passive attacks
lead to breaking of confidentiality.
The following phases are involved in
planning cybercrime:
1. Reconnaissance (information gathering) is the
first phase and is treated as passive attacks.
2. Scanning and scrutinizing the gathered
information for the validity of the information
as well as to identify the existing
vulnerabilities.
3. Launching an attack (gaining and maintaining
the system access).
Reconnaissance
* literalmeaning of " Reconnaissance" is an act of
reconnoitering — explore, Often with the goal Of finding
something or somebody (especially to gain information about
an enemy or potential enemy).
* In the world Of "hacking," reconnaissance phase begins with
"Footprinting" — this is the preparation toward pre attack
phase, and involves accumulating data about the target's
environment and computer architecture to find ways to
intrude into that environment.
* Footprinting gives an overview about system vulnerabilities
and provides a judgment about possible exploitation of those
vulnerabilities.
* The objective of this preparatory phase is to understand the
system, its networking ports and services, and any other
aspects of its security that are needful For launching the
attack-Thus, an attacker attempts to gather information in two
phases: passive and active attacks.
Passive Attacks
*A passive attack involves gathering information about a target
without his/her (individual's or company's) knowledge.
* It can be as simple as watching a building to identify what time
employees enter the building premises.
* Itis usually done using Internet searches or by Googling (i.e.,
searching the required information with the help of search
engine Google) an individual or company to gain information.
* Google or Yahoo search: People search to locate
information about employees
* Surfingonline community groups like Orkut/Facebook will
prove useful to gain the information about an individual.
* Organization\ website may provide a personnel directory
or information about key employees, for example, contact
details, E-Mail addrcss, etc. These can be used in a social
engineering attack to reach the target.
*Blogs,newsgroups, press releases, etc. are generally
used as the mediums to gain information about the
company or employees.
*Going through the job postings in particular job
profiles for technical persons can provide information
about type of technology, that is, servers or
infrastructure devices a company maybe using on its
network.
Active Attacks
* An active attack involves searching the network to discover
individual hosts to confirm the information (IP addresses,
operating system type and version, and services on the
network) gathered in the passive attack phase.
* It involves the risk Of detection and is also called " Rattling
the doorknobs“ or "Active reconnaissance."
* Active reconnaissance can provide confirmation to an
attacker about security measures in place (e.g., whether
the front door is locked?), but the process can also increase
the chance of being caught or raise a suspicion
Scanning and Scrutinizing Gathered
Information
*Scanning is a key step to examine intelligently
while gathering information about the target.
The objectives of scanning are as follows
1. Port scanning: Identify open/close ports and
services.
2. Network scanning; Understand IP Addresses
and related information about the computer
network systems.
3. Vulnerability
scanning: Understand the existing
weaknesses in the system.
*The scrutinizing phase is always called "enumeration"
in the hacking world. objective behind this step is to
identify:
1. The valid user accounts or groups;
2. Network resources and/or shared resources;
3. OS and different applications that are running on the
OS
Attack (Gaining and Maintaining the System
Access)
After the scanning and enumeration, the attack is
launched using the following steps
1. Crackthe password (we will address it in
Chapter 4);
2. exploit the privileges
3. execute the malicious commands/ applications
4. hide the files (if required),
5. Cover the tracks — delete the access logs, so
that there is no trail illicit activity