Computer crime, or cybercrime in India has been evolving rapidly in the 21st century. Technical support scams, along with impersonation of the IRS, are among the most common forms of confidence tricks used in order to receive money from unsuspecting victims.

The Information Technology Act, 2000, passed by the Parliament of India in May 2000, had aimed to curb cyber crimes and to provide a legal framework for e-commerce transactions.In 2001, India and United States had set up an India-US cyber security forum as part of a counter-terrorism dialogue.

Career in Ethical Hacking

,

What is Ethical Hacking?

With the growth of the Internet, computer security has become a major concern for businesses and governments. They want to be able to take advantage of the Internet for electronic commerce, advertising, information distribution and access, and other pursuits, but they are worried about the possibility of being HACKED. At the same time, the potential customers of these services are worried about maintaining control of personal information that varies from credit card numbers to social security numbers and home addresses.

In their search for a way to approach the problem, organizations came to realize that one of the best ways to evaluate the intruder threat to their interests would be to have independent computer security professionals attempt to break into their computer systems. This scheme is similar to having independent auditors come into an organization to verify its bookkeeping records.

In the case of computer security, these TIGER TEAMS or ETHICAL HACKERS would employ the same tools and techniques as the intruders, but they would neither damage the target systems nor steal information. Instead, they would evaluate the target systems’ security and re-port back to the owners with the vulnerabilities they found and instructions for how to remedy them

History and Now….

Whilst in the 80’s hacking was common only amongst computer programmers with vast experience and knowledge of multiple technologies, now almost anyone can hack given the availability of the fiercest software’s available freely on the internet. “You no longer need to be a genius to hack. I say all you need is the Internet and the Desire.

After the events of 9/11 of WTC , we are no longer able to expect a common and traditional mode of attack. An attack can come in any mode and from any source. The best way to defend ourselves is to think like the enemy as this will allow us to predict their next move.

In November 2002, the International Council of E-Commerce Consultants (EC-Council), a leading provider of e-Business certification and Internet Security programs, announced a new certification program designed to provide security education and training services for penetration testing professionals.

The EC-Council developed a unique five day security training course called “Ethical Hacking & Countermeasures,” which prepares students for the CEH exam 310-50. As the only course of its kind in the world leading to an Ethical Hacker Certification, it teaches how hackers hack, the tools they use, how to hack via Linux and Windows 2000, how to hack firewalls and how to implement an effective security framework for both e-commerce and day to day operation and how to apply countermeasures to avoid those risks. The Certified Ethical Hacker certification has become the fastest growing certification in the security industry.
There are four basic kinds of hacks:

IP Hack: Someone can be hired to hack a specific IP address, giving them little or no information beforehand (You have to be careful if the IP address is an overseas server. You cant hack the wrong IP address, like a foreign government’s computers, causing an international incident.);

Application Hack: A much more sophisticated hack that you can is diving deep into databases and down production servers. Only experienced hackers, with strict guidelines governing their actions, will be allowed to perform such tests. Organisation will never hire a “reformed” black-hat hacker for this type of test;

Physical Infrastructure Hack: This is where you can try to get into your facilities to access your systems or go dumpster diving looking for confidential information such as passwords discarded on sticky notes; and

Wireless Hack: Here you can exploit wireless access points from the back of a van. and report the findings back to employers instead of stealing  passwords. You can check out employers tele workers as well to see if home offices are a source of entry to there organisations network.

 

For any of these tests, a reputable firm with clearly defined methodologies to hire you, and you could be part of it.

 

Scope

Career as a Ethical Hacker with/with out necessary Certification Opens a wide range of scope due to lot foray of international organisations in India, Indians are known to be good mathematicians this gives them edge over other countries employees. A Ethical Hacker can see growth path towards handling a complete Networking Department  as he knows the things at system level. Loyalty towards profession and employee pay key role

Salaries are no bar for such a profession.

 

Digital Signature Laws in India

,

Digital signatures are given legal recognition under the Information Technology (IT) Act, enabling them to be as valid as signatures on paper. By affixing a digital signature to an electronic document, the writer or owner of the document may establish his rights over its content, and file a lawsuit if the same is violated.

The clause for digital signatures has been defined under Section 4 of the IT Act to primarily facilitate e-governance and e-commerce. Remember, this section of the IT Act overrides other laws, such as the Consumer Protection Act, which tends to become general legislations to facilitate electronic transactions.

Legalities for Creating a Valid Digital Signature

Section 14 of the IT Act has established certain guidelines for creating a valid and secured digital signature.

The section states that at the time of fixing a digital signature:

  • It should be unique.
  • It’s security procedure must be agreed to by both parties.
  • It is capable of identifying all parties or subscribers of the electronic document.

 

Limits to Recognition of Digital Signature

Digital signatures on all electronic records and contracts are considered valid under section 4 of the IT Act, except in the case of:

  • A will.
  • A negotiable instrument.
  • A document of title.
  • A contract for disposition of an immovable property.
  • A trust or power of attorney.
  • A document notified by the Central Government.

Indian laws, including the Indian Contract Act, require these documents to be written and attested in writing. Further, in India, paper documents are perceived to be far more reliable and trustworthy than electronic documents.

Some may argue that having these limitations on legal recognition of digital signatures would bar the growth of electronic transactions. However, these laws are meant to safeguard the interest of the online visitors.

To obtain a legally valid digital certificate as per Indian IT Act from the licensed Certifying Authorities (CA) operating under the Root Certifying Authority of India (RCAI), Controller of Certifying Authorities (CCA) of India. (http://www.cca.gov.in/) >

Steps for obtaining Digital Certificate

  1. Visit the site of the licensed CA using internet browser.
  2. Apply for a digital certificates
  • Digital Signature,non-repudiation certificate(used for Signing) and
  • Key Encipherment Certificate (used for encrypting Bid Document) with Organization name for the designated individual with organization name.
  • Ensure the Digital Certificate is legally valid in India.
  1. For making payment for Digital Certificate and submission of documents required for issue of the Digital Certificate, follow the instructions on the CA’s website.

Links to some licensed CA’s are provided below:

http://www.tcs-ca.tcs.co.in
http://www.safescrypt.com
http://www.mtnltrustline.com
http://www.ncodesolutions.com

What is a USB Token?

  • It is secure Device, used specifically to carry Digital Certificates.
  • USB Tokens offer military grade security and the contents are also encrypted internally.
  • A virus cannot affect USB Token, and the digital Certificate stored would always be secure.
  • When you insert the Token, it automatically copies the certificate to the browser and when you remove the Token it automatically removes the certificate from the browser.
  • The Private key never leaves the Token and signing takes place within the Token itself. So, the security is guaranteed.

 

CYBER CRIMES AND THE LAW

,

In the era of cyber world as the usage of computers became more popular, there was expansion in the growth of technology as well, and the term ‘Cyber’ became more familiar to the people. The evolution of Information Technology (IT) gave birth to the cyber space wherein internet provides equal opportunities to all the people to access any information, data storage, analyse etc. with the use of high technology. Due to increase in the number of netizens, misuse of technology in the cyberspace was clutching up which gave birth to cyber crimes at the domestic and international level as well.

Though the word Crime carries its general meaning as “a legal wrong that can be followed by criminal proceedings which may result into punishment” whereas Cyber Crime may be “unlawful acts wherein the computer is either a tool or target or both”.

The world 1st computer specific law was enacted in the year 1970 by the German State of Hesse in the form of ‘Data Protection Act, 1970’ with the advancement of cyber technology. With the emergence of technology the misuse of technology has also expanded to its optimum level and then there arises a need of strict statutory laws to regulate the criminal activities in the cyber world and to protect technological advancement system. It is under these circumstances Indian parliament passed its “INFORMATION TECHNOLOGY ACT, 2000” on 17th oct to have its exhaustive law to deal with the technology in the field of e-commerce, e-governance, e-banking as well as penalties and punishments in the field of cyber crimes.

  • Cyber Crimes Actually Means: It could be hackers vandalizing your site, viewing confidential information, stealing trade secrets or intellectual property with the use of internet. It can also include ‘denial of services’ and viruses attacks preventing regular traffic from reaching your site. Cyber crimes are not limited to outsiders except in case of viruses and with respect to security related cyber crimes that usually done by the employees of particular company who can easily access the password and data storage of the company for their benefits. Cyber crimes also includes criminal activities done with the use of computers which further perpetuates crimes i.e. financial crimes, sale of illegal articles, pornography, online gambling, intellectual property crime, e-mail, spoofing, forgery, cyber defamation, cyber stalking, unauthorized access to Computer system, theft of information contained in the electronic form, e-mail bombing, physically damaging the computer system etc.
  • Classifications Of Cyber Crimes: Cyber Crimes which are growing day by day, it is very difficult to find out what is actually a cyber crime and what is the conventional crime so to come out of this confusion, cyber crimes can be classified under different categories which are as follows:
  1. Cyber Crimes against Persons:

There are certain offences which affects the personality of individuals can be defined as:

  • Harassment via E-Mails: It is very common type of harassment through sending letters, attachments of files & folders i.e. via e-mails. At present harassment is common as usage of social sites i.e. Facebook, Twitter etc. increasing day by day.
  • Cyber-Stalking: It means expressed or implied a physical threat that creates fear through the use to computer technology such as internet, e-mail, phones, text messages, webcam, websites or videos.
  • Dissemination of Obscene Material: It includes Indecent exposure/ Pornography (basically child pornography), hosting of web site containing these prohibited materials. These obscene matters may cause harm to the mind of the adolescent and tend to deprave or corrupt their mind.
  • Defamation: It is an act of imputing any person with intent to lower down the dignity of the person by hacking his mail account and sending some mails with using vulgar language to unknown persons mail account.
  • Hacking: It means unauthorized control/access over computer system and act of hacking completely destroys the whole data as well as computer programmes. Hackers usually hacks telecommunication and mobile network.
  • Cracking: It is amongst the gravest cyber crimes known till date. It is a dreadful feeling to know that a stranger has broken into your computer systems without your knowledge and consent and has tampered with precious confidential data and information.
  • E-Mail Spoofing: A spoofed e-mail may be said to be one, which misrepresents its origin. It shows it’s origin to be different from which actually it originates.
  • SMS Spoofing: Spoofing is a blocking through spam which means the unwanted uninvited messages. Here a offender steals identity of another in the form of mobile phone number and sending SMS via internet and receiver gets the SMS from the mobile phone number of the victim. It is very serious cyber crime against any individual.
  • Carding: It means false ATM cards i.e. Debit and Credit cards used by criminals for their monetary benefits through withdrawing money from the victim’s bank account mala-fidely. There is always unauthorized use of ATM cards in this type of cyber crimes.
  • Cheating & Fraud: It means the person who is doing the act of cyber crime i.e. stealing password and data storage has done it with having guilty mind which leads to fraud and cheating.
  • Child Pornography: It involves the use of computer networks to create, distribute, or access materials that sexually exploit underage children.
  • Assault by Threat: refers to threatening a person with fear for their lives or lives of their families through the use of a computer network i.e. E-mail, videos or phones.
  1. Crimes Against Persons Property:

As there is rapid growth in the international trade where businesses and consumers are increasingly using computers to create, transmit and to store information in the electronic form instead of traditional paper documents. There are certain offences which affects persons property which are as follows:

  •  Intellectual Property Crimes: Intellectual property consists of a bundle of rights. Any unlawful act by which the owner is deprived completely or partially of his rights is an offence. The common form of IPR violation may be said to be software piracy, infringement of copyright, trademark, patents, designs and service mark violation, theft of computer source code, etc.
  • Cyber Squatting: It means where two persons claim for the same Domain Name either by claiming that they had registered the name first on by right of using it before the other or using something similar to that previously. For example two similar names i.e. www.yahoo.com and www.yaahoo.com.
  • Cyber Vandalism: Vandalism means deliberately destroying or damaging property of another. Thus cyber vandalism means destroying or damaging the data when a network service is stopped or disrupted. It may include within its purview any kind of physical harm done to the computer of any person. These acts may take the form of the theft of a computer, some part of a computer or a peripheral attached to the computer.
  • Hacking Computer System: Hacktivism attacks those included Famous Twitter, blogging platform by unauthorized access/control over the computer. Due to the hacking activity there will be loss of data as well as computer. Also research especially indicates that those attacks were not mainly intended for financial gain too and to diminish the reputation of particular person or company.
  • Transmitting Virus: Viruses are programs that attach themselves to a computer or a file and then circulate themselves to other files and to other computers on a network. They usually affect the data on a computer, either by altering or deleting it. Worm attacks plays major role in affecting the computerize system of the individuals.
  • Cyber Trespass: It means to access someone’s computer without the right authorization of the owner and does not disturb, alter, misuse, or damage data or system by using wireless internet connection.
  • Internet Time Thefts: Basically, Internet time theft comes under hacking. It is the use by an unauthorised person, of the Internet hours paid for by another person. The person who gets access to someone else’s ISP user ID and password, either by hacking or by gaining access to it by illegal means, uses it to access the Internet without the other person’s knowledge. You can identify time theft if your Internet time has to be recharged often, despite infrequent usage.
  1. Cybercrimes Against Government:

There are certain offences done by group of persons intending to threaten the international governments by using internet facilities. It includes:

  •  Cyber Terrorism: Cyber terrorism is a major burning issue in the domestic as well as global concern. The common form of these terrorist attacks on the Internet is by distributed denial of service attacks, hate websites and hate e-mails, attacks on sensitive computer networks etc. Cyber terrorism activities endanger the sovereignty and integrity of the nation.
  • Cyber Warfare: It refers to politically motivated hacking to conduct sabotage and espionage. It is a form of information warfare sometimes seen as analogous to conventional warfare although this analogy is controversial for both its accuracy and its political motivation.
  • Distribution of pirated software: It means distributing pirated software from one computer to another intending to destroy the data and official records of the government.
  • Possession of Unauthorized Information: It is very easy to access any information by the terrorists with the aid of internet and to possess that information for political, religious, social, ideological objectives.
  1. Cybercrimes Against Society at large:

An unlawful act done with the intention of causing harm to the cyberspace will affect large number of persons. These offences includes:

  •  Child Pornography: It involves the use of computer networks to create, distribute, or access materials that sexually exploit underage children. It also includes activities concerning indecent exposure and obscenity.
  • Cyber Trafficking: It may be trafficking in drugs, human beings, arms weapons etc. which affects large number of persons. Trafficking in the cyberspace is also a gravest crime.
  • Online Gambling: Online fraud and cheating is one of the most lucrative businesses that are growing today in the cyber space. There are many cases that have come to light are those pertaining to credit card crimes, contractual crimes, offering jobs, etc.
  • Financial Crimes: This type of offence is common as there is rapid growth in the users of networking sites and phone networking where culprit will try to attack by sending bogus mails or messages through internet. Ex: Using credit cards by obtaining password illegally.
  • Forgery: It means to deceive large number of persons by sending threatening mails as online business transactions are becoming the habitual need of today’s life style.

Affects To Whom: Cyber Crimes always affects the companies of any size because almost all the companies gain an online presence and take advantage of the rapid gains in the technology but greater attention to be given to its security risks. In the modern cyber world cyber crimes is the major issue which is affecting individual as well as society at large too.

Need of Cyber Law: information technology has spread throughout the world. The computer is used in each and every sector wherein cyberspace provides equal opportunities to all for economic growth and human development. As the user of cyberspace grows increasingly diverse and the range of online interaction expands, there is expansion in the cyber crimes i.e. breach of online contracts, perpetration of online torts and crimes etc. Due to these consequences there was need to adopt a strict law by the cyber space authority to regulate criminal activities relating to cyber and to provide better administration of justice to the victim of cyber crime. In the modern cyber technology world it is very much necessary to regulate cyber crimes and most importantly cyber law should be made stricter in the case of cyber terrorism and hackers.

Penalty For Damage To Computer System: According to the Section: 43 of ‘Information Technology Act, 2000’ whoever does any act of destroys, deletes, alters and disrupts or causes disruption of any computer with the intention of damaging of the whole data of the computer system without the permission of the owner of the computer, shall be liable to pay fine upto 1crore to the person so affected by way of remedy. According to the Section:43A which is inserted by ‘Information Technology(Amendment) Act, 2008’ where a body corporate is maintaining and protecting the data of the persons as provided by the central government, if there is any negligent act or failure in protecting the data/ information then a body corporate shall be liable to pay compensation to person so affected. And Section 66 deals with ‘hacking with computer system’ and provides for imprisonment up to 3 years or fine, which may extend up to 2 years or both.

 

Case Study-Attacks on Cyberspace: 

  • Worm Attack: The Robert Tappan Morris well Known as First Hacker, Son of former National Security Agency Scientist Robert Morris, was the first person to be prosecuted under the ‘Computer and Fraud Act, 1986’. He has created worm while at Cornell as student claiming that he intended to use the worm to check how large the internet was that time. The worm was uncontrollable due to which around 6000 computer machines were destroyed and many computers were shut down until they had completely malfunctioned. He was ultimately sentenced to three years probation, 400 hours of community service and assessed a fine of $10500. So there must be strict laws to punish the criminals who are involved in cyber crime activities.
  • Hacker Attack: Fred Cohen, a Ph.D. student at the University of Southern California wrote a short program in the year 1983, as an experiment, that could “infect” computers, make copies of itself, and spread from one machine to another. It was beginning & it was hidden inside a larger, legitimate program, which was loaded into a computer on a floppy disk and many computers were sold which can be accommodate at present too. Other computer scientists had warned that computer viruses were possible, but Cohen’s was the first to be documented. A professor of his suggested the name “virus”. Cohen now runs a computer security firm.
  • Internet Hacker: Wang Qun, who was known by the nickname of “playgirl”, was arrested by chinese police in the Hubei province first ever arrest of an internet hacker in China. He was a 19 year old computing student, arrested in connection with the alleged posting of pornographic material on the homepages of several government-run web sites. Wang had openly boasted in internet chat rooms that he had also hacked over 30 other web sites too.

 

Preventive Measures For Cyber Crimes:

Prevention is always better than cure. A netizen should take certain precautions while operating the internet and should follow certain preventive measures for cyber crimes which can be defined as:

  • Identification of exposures through education will assist responsible companies and firms to meet these challenges.
  • One should avoid disclosing any personal information to strangers via e-mail or while chatting.
  • One must avoid sending any photograph to strangers by online as misusing of photograph incidents increasing day by day.
  • An update Anti-virus software to guard against virus attacks should be used by all the netizens and should also keep back up volumes so that one may not suffer data loss in case of virus contamination.
  • A person should never send his credit card number to any site that is not secured, to guard against frauds.
  •  It is always the parents who have to keep a watch on the sites that your children are accessing, to prevent any kind of harassment or depravation in children.
  • Web site owners should watch traffic and check any irregularity on the site. It is the responsibility of the web site owners to adopt some policy for preventing cyber crimes as number of internet users are growing day by day.
  • Web servers running public sites must be physically separately protected from internal corporate network.
  •  It is better to use a security programmes by the body corporate to control information on sites.
  • Strict statutory laws need to be passed by the Legislatures keeping in mind the interest of netizens.
  • IT department should pass certain guidelines and notifications for the protection of computer system and should also bring out with some more strict laws to breakdown the criminal activities relating to cyberspace.
  • As Cyber Crime is the major threat to all the countries worldwide, certain steps should be taken at the international level for preventing the cybercrime.
  • A complete justice must be provided to the victims of cyber crimes by way of compensatory remedy and offenders to be punished with highest type of punishment so that it will anticipate the criminals of cyber crime.

Conclusion:

Since users of computer system and internet are increasing worldwide, where it is easy to access any information easily within a few seconds by using internet which is the medium for huge information and a large base of communications around the world. Certain precautionary measures should be taken by netizens while using the internet which will assist in challenging this major threat Cyber Crime.