CACS401 Cyber Law And Professional Ethics

Cyber Law And Professional EthicsUnit 311 min read

Cybercrime & Cybersecurity Fundamentals

Unit 3 of Cyber Law And Professional Ethics explores cybercrime definitions, its diverse forms (e.g., hacking, phishing), real-world threats, and foundational cybersecurity measures like encryption, firewalls, and incident response—with Nepal-specific examples like NTC/Ncell fraud and global cases like WhatsApp data br

TAKEAWAYS:

  • Cybercrime is illegal activity using digital tech (e.g., hacking, identity theft) with countermeasures like legal penalties and tech safeguards.
  • Malware (viruses, ransomware) and social engineering (phishing) are top threats, each requiring specific detection tools (antivirus, email filters).
  • Cybersecurity fundamentals include prevention (firewalls, encryption), detection (intrusion systems), and response (incident handling).
  • Nepal’s NTC/Ncell SIM fraud and Daraz payment scams illustrate real cybercrime risks and the need for local laws (e.g., Cyber Security Act 2073).
  • Encryption (e.g., AES) and authentication (biometrics) are critical for protecting data in apps like eSewa and Khalti.
  • Cybersecurity frameworks (e.g., NIST) provide structured approaches to mitigate risks in global IT infrastructure.

1. Defining Cybercrime

Cybercrime refers to criminal activities perpetrated using computers, networks, or digital systems. Unlike traditional crimes, cybercrimes exploit vulnerabilities in technology to commit fraud, theft, or harm. The Cyber Security Act, 2073 (2017) in Nepal criminalizes activities like hacking, identity theft, and unauthorized data access.

Key Characteristics of Cybercrime

mindmap:
  root((Cybercrime))
    - Digital Medium: Requires computers, networks, or digital devices
    - Global Reach: Transcends borders (e.g., cross-border fraud)
    - Anonymity: Often uses VPNs, Tor, or fake identities
    - Persistence: Can disrupt services (e.g., DDoS attacks)
    - Evolving Tactics: Constantly adapts to new tech (e.g., AI-driven phishing)

Real-World Example: NTC/Ncell SIM Swapping Fraud

How it works:

  1. Fraudster calls NTC/Ncell support, impersonating the victim.
  2. Uses social engineering (e.g., "My SIM is lost") to transfer the number.
  3. Accesses linked accounts (e.g., Ncell eWallet) to steal funds.

Countermeasure: Multi-factor authentication (MFA) with biometric verification (fingerprint/face ID) and real-time fraud alerts.


2. Types of Cybercrime and Countermeasures

Cybercrime is classified into technical crimes (exploiting software/hardware) and non-technical crimes (human-based, like phishing). Below is a comparison:

Type of Cybercrime Description Real-World Example Countermeasure
Hacking Unauthorized access to systems (e.g., government databases). Nepal Police cyberattack (2021) where hackers leaked data. Firewalls, intrusion detection systems (IDS).
Malware Malicious software (viruses, worms, ransomware). WannaCry ransomware (2017) encrypted global systems. Antivirus software, patch management.
Phishing Fraudulent emails/websites to steal credentials. Daraz fake "Order Confirmation" emails tricking users into revealing passwords. Email filters, user training.
Identity Theft Stealing personal data (SSN, bank details) for fraud. eSewa account hijacking via stolen OTPs. Strong passwords, OTP verification.
Cyberstalking Harassing via digital means (e.g., social media threats). Online harassment of journalists in Nepal. Block reporting, legal action.
Cyberterrorism Using cyberattacks to cause panic (e.g., power grid disruption). Stuxnet (2010) targeted Iran’s nuclear facilities. Critical infrastructure protection.

Worked Example: Phishing Attack on Khalti

Scenario: A user receives an email claiming to be from Khalti Support:

"Your Khalti account is locked! Click here to verify: [fake-link.com]"

2023-05-10Phishing emailsent to Khalti users (2023-05-11User credentialsharvested via fake por2023-05-12Fraudulenttransactions initiated2023-05-15Khalti securityteam detects pattern a
Timeline of a phishing attack on Khalti users

Steps to Detect & Prevent:

  1. Check sender email: Legitimate Khalti emails use @khalti.com.
  2. Hover over links: Fake URLs often redirect to malicious sites.
  3. Verify via official app: Contact Khalti support directly.
  4. Use browser extensions like uBlock Origin to block phishing sites.

Countermeasure Applied:

  • DMARC (Domain-based Message Authentication) to block spoofed emails.
  • User education on recognizing phishing tactics.

3. Cybersecurity Fundamentals

Cybersecurity protects systems, networks, and data from digital attacks. It consists of three pillars:

Firewalls: Block unauthorized accessEncryption: Scramble data (e.g., AES-256)Access Control: Role-based permissionsPreventionIntrusion Detection Systems (IDS): Monitor suspicious activiLog Analysis: Track unusual login attemptsDetectionIncident Handling: Steps to contain and recoverForensic Analysis: Investigate attacks (e.g., digital forensResponseCybersecurity Fundamentals
Hierarchical breakdown of Cybersecurity Fundamentals pillars

A. Prevention: Firewalls and Encryption

1. Firewalls

  • Types:
    • Packet-filtering firewall: Inspects headers (e.g., IP addresses).
    • Stateful inspection firewall: Tracks connection status.
    • Proxy firewall: Acts as an intermediary (e.g., school Wi-Fi firewalls).

Example: NTC uses next-generation firewalls to block DDoS attacks on its network.

2. Encryption

  • Symmetric: Same key encrypts/decrypts (fast, used in Khalti payments).
  • Asymmetric: Public/private key pairs (used in SSL/TLS for secure browsing).

Worked Example: Secure eSewa Transaction

  1. User enters credentials → TLS encryption protects data in transit.
  2. Server verifies credentials → Digital signature ensures authenticity.
  3. Transaction processed → AES-256 encrypts payment details.

B. Detection: Intrusion Detection Systems (IDS)

IDS monitors networks for malicious activity. Types:

  • Network IDS (NIDS): Detects attacks on the network (e.g., Snort).
  • Host IDS (HIDS): Monitors single devices (e.g., OSSEC on a laptop).

Example: Ncell’s network IDS detects unusual login patterns from multiple countries (indicating a botnet).

C. Response: Incident Handling

Steps to Handle a Cyberattack:

  1. Detection: Identify the attack (e.g., unusual login spikes).
  2. Containment: Isolate affected systems (e.g., disconnect infected servers).
  3. Eradication: Remove malware (e.g., quarantine ransomware files).
  4. Recovery: Restore systems from backups.
  5. Lessons Learned: Update security policies.

Real-World Case: Daraz Payment System Breach (2022)

  • Incident: Hackers stole customer payment data via a SQL injection attack.
  • Response:
    • Containment: Daraz blocked all payment gateways temporarily.
    • Eradication: Patches were applied to the database.
    • Recovery: Affected users were notified and offered free credit monitoring.

4. Cybersecurity Threats in Nepal

Nepal faces unique cyber threats due to digital literacy gaps and lack of enforcement. Key issues:

A. Financial Fraud (eSewa/Khalti)

  • Problem: SIM swapping leads to account takeovers.
  • Example: In 2023, Ncell customers lost ₹50M via SIM fraud.
  • Solution: Biometric authentication (fingerprint/face ID) for transactions.

B. Data Leaks (NEPSE, Banks)

  • Problem: Unsecured databases (e.g., NEPSE’s 2021 data breach exposed investor details).
  • Solution: GDPR-like data protection laws and end-to-end encryption.

C. DDoS Attacks (NTC/Ncell)

  • Problem: Competitors launch DDoS attacks to disrupt services.
  • Solution: Cloud-based DDoS protection (e.g., AWS Shield).

5. Global Cybersecurity Standards

Nepal adopts international frameworks to improve cybersecurity:

  • NIST Cybersecurity Framework (USA): Used by Nepal Police’s cybercrime unit.
  • ISO 27001: Standard for information security management (adopted by Ncell).
  • GDPR (EU): Influences Nepal’s draft data protection law.

Comparison Table: Cybersecurity Standards

Standard Focus Area Nepal’s Adoption
NIST CSF Risk management, incident response. Used by Nepal Police’s cyber unit.
ISO 27001 Information security policies. Implemented by Ncell, NTC.
GDPR Data privacy and consent. Influencing Nepal’s draft law.
PCI DSS Payment card security. Mandatory for eSewa, Khalti.

In the Real World

  1. eSewa’s Encryption:

    • Uses TLS 1.3 and AES-256 to secure transactions. When you pay via eSewa, your card details are encrypted end-to-end, preventing hackers from intercepting data during transfer.
  2. Khalti’s Fraud Detection:

    • Implements machine learning models to flag unusual transactions. For example, if multiple login attempts come from different countries in a short time, Khalti’s system blocks the account and sends an alert to the user.
  3. Ncell’s SIM Fraud Prevention:

    • Uses biometric verification for high-value transactions (e.g., Ncell eWallet withdrawals). If a user tries to withdraw ₹10,000, the app prompts for a fingerprint scan before processing, reducing SIM-swapping risks.
  4. Pathao’s Ride-Hailing Security:

    • Protects user data with tokenization (storing only encrypted payment tokens) and GPS-based fraud detection. If a driver’s location suddenly jumps to another city, Pathao’s system flags the ride for review.

Exam Tip

  • Focus on definitions: Clearly explain cybercrime (e.g., "illegal activity using digital tech") and its types (hacking, phishing, malware).
  • Compare countermeasures: For each cybercrime type, mention specific tools (e.g., firewalls for hacking, antivirus for malware).
  • Nepal-specific examples: Always tie answers to local cases (e.g., NTC/Ncell fraud, Daraz breaches) to score higher.
  • Process-based questions: Expect diagrams or flowcharts for incident response steps or encryption processes (AES, TLS).
  • Short-answer practice: Memorize key terms:
    • IDS/IPS (Intrusion Detection/Prevention Systems),
    • MFA (Multi-Factor Authentication),
    • DDoS (Distributed Denial of Service),
    • SQL Injection (database attack).
  • Case studies: Study real breaches (e.g., WannaCry, NEPSE leak) and explain how they could have been prevented.

Visual Summary:

flowchart TD
    A["Cybercrime"] --> B["Hacking: SQL Injection"]
    A --> C["Phishing: Email/Link-based"]
    A --> D["Malware: Viruses/Worms"]
    B --> E["Countermeasure: Firewalls + WAF"]
    C --> F["Countermeasure: Email Filters + Awareness"]
    D --> G["Countermeasure: Antivirus + Sandboxing"]
    H["Cybersecurity Fundamentals"] --> I["Prevention: Encryption"]
    H --> J["Detection: SIEM + IDS"]
    H --> K["Response: Incident Response Plan"]

Based on the TU BCA syllabus for Cyber Law And Professional Ethics (CACS401), unit 3.

Discussion

Loading…