CACS401 Cyber Law And Professional Ethics

Cyber Law And Professional EthicsUnit 411 min read

Intellectual Property Rights & Digital Security

Unit 4 of Cyber Law And Professional Ethics explores how to legally protect creative and digital assets (IPR), the risks of unauthorized use, and security measures like digital signatures and the CIA triad to safeguard data—with real-world examples from Nepal and globally.

TAKEAWAYS:

  • Intellectual property (IP) includes patents, copyrights, trademarks, and trade secrets, all legally protected to incentivize innovation.
  • Plagiarism and piracy are IP violations; cyber-squatting (registering a domain to exploit a brand) is a growing digital threat.
  • Copyright protects original works (code, music, books) for 70 years post-author; fair use allows limited reuse (e.g., reviews).
  • Digital signatures use asymmetric encryption (public/private keys) to verify identity and authenticity in contracts and transactions.
  • The CIA triad (Confidentiality, Integrity, Availability) is the foundation of cybersecurity; breaches can cripple businesses (e.g., NTC data leaks).
  • Nepal’s Cyber Security Act (2075) and WIPO treaties enforce IPR; global platforms like Daraz and eSewa rely on IP protection for trust.

1. Intellectual Property (IP) and Its Types

Intellectual property (IP) refers to creations of the mind—such as inventions, literary works, designs, symbols, names, and images used in commerce—that are legally protected. Unlike physical property, IP is intangible but can be monetized, licensed, or enforced.

Types of Intellectual Property

Copyright (Original works: code, music, books)Patent (Inventions: processes, machines)Trademark (Brand names/logos: e.g., Daraz, Ncell)Trade Secret (Confidential info: e.g., Coca-Cola formula)Industrial Design (Aesthetic features of products)Intellectual Property
Classification of Intellectual Property types as per Nepali law (IPA 2075).

Why Protect IP?

  • Incentivizes innovation: Creators earn revenue from their work (e.g., a Nepali app developer monetizing a Pathao-like app).
  • Prevents exploitation: Without IP, competitors could copy ideas without compensation.
  • Economic growth: Strong IP laws attract investment (e.g., NEPSE-listed tech startups).

2. Plagiarism and Its Types

Plagiarism is the unauthorized use of someone else’s work without credit, a major IP violation in academia and industry.

Types of Plagiarism

Type Description Example
Direct Plagiarism Copying text verbatim without citation. Copy-pasting a Wikipedia article into an assignment.
Partial Plagiarism Borrowing sections without attribution. Using 3 sentences from a research paper without quotes.
Self-Plagiarism Reusing one’s own work without permission. Submitting the same thesis chapter in two different courses.
Mosaic Plagiarism Patchworking ideas from multiple sources without proper citation. Mixing quotes from 5 books into an essay without referencing.
Accidental Plagiarism Unintentional reuse due to poor citation practices. Forgetting to cite a source in a report.

(Image shows a Turnitin report highlighting matched text in red.)

Consequences of Plagiarism

  • Academic: Failure, expulsion (e.g., TU revoking degrees for plagiarized theses).
  • Professional: Lawsuits, fines (e.g., a Nepali software firm sued for copying a foreign UI design).
  • Reputational: Damage to personal/brand trust (e.g., a YouTuber’s channel banned for stolen content).

Copyright automatically protects original works (e.g., code, music, books) upon creation, but registration strengthens legal claims.

  1. Eligibility: Original works fixed in a tangible form (e.g., a Python script, a song recording).
  2. Duration: Life of the author + 70 years (Nepal follows WIPO conventions).
  3. Rights: Control over reproduction, distribution, adaptation (e.g., a Nepali band licensing its music to eSewa ads).

(Image shows the WIPO logo alongside a timeline: "70 years post-author death.")

Fair Use Copyright Infringement
Allows limited use for criticism, education, or parody. Unauthorized copying or distribution.
Example: Quoting a song in a YouTube review. Example: Streaming pirated movies on a local server.
Must transform the original work. No permission or license obtained.

Worked Example: Daraz’s Copyright Policy Daraz protects its product images and descriptions via copyright. If a seller copies a competitor’s listing without permission, Daraz can:

  1. Remove the listing.
  2. Issue a DMCA takedown notice (Digital Millennium Copyright Act).
  3. Sue for damages (e.g., ₹50,000–₹500,000 in Nepal under the Cyber Security Act).

4. Digital Signatures and Authentication

Digital signatures verify the identity and integrity of digital documents using asymmetric encryption.

How Digital Signatures Work

  1. Private Key: The sender signs the document (e.g., a contract) with their private key.
  2. Public Key: The recipient verifies the signature using the sender’s public key (published on a certificate).
  3. Hash Function: A unique fingerprint of the document ensures tamper-proofing.

Mermaid Diagram: Digital Signature Process

sequenceDiagram
    participant Sender
    participant PrivateKey
    participant Document
    participant HashFunction
    participant PublicKey
    participant Recipient

    Sender->>PrivateKey: Signs document (private key)
    Document->>HashFunction: Creates hash
    HashFunction->>PrivateKey: Encrypts hash
    Sender->>Recipient: Sends document + signature
    Recipient->>PublicKey: Decrypts hash with sender’s public key
    Recipient->>HashFunction: Recreates hash from document
    Recipient->>PublicKey: Compares hashes (verifies authenticity)

Real-World Use: eSewa Transactions

  • When you pay via eSewa, the transaction is digitally signed to:
    • Prove you authorized the payment.
    • Prevent fraud (e.g., a hacker altering the amount).
  • The signature uses Nepal Rastra Bank’s public key for verification.

5. The CIA Triad: Confidentiality, Integrity, Availability

The CIA triad is the core of cybersecurity, ensuring data is:

  1. Confidential: Accessed only by authorized users (e.g., NTC’s customer data).
  2. Integral: Unchanged and accurate (e.g., bank transaction records).
  3. Available: Accessible when needed (e.g., Ncell’s network uptime).

Implementing CIA at Different Levels

Level Confidentiality Integrity Availability
Organizational Role-based access (RBAC), encryption (e.g., NEPSE’s data encryption). Checksums, hashing (e.g., audit logs for stock trades). Redundant servers, backup generators.
Network Firewalls (e.g., NTC’s VPN for employees). Firewall rules, IDS/IPS (e.g., blocking SQL injection). Load balancers, failover systems.
End User Strong passwords, MFA (e.g., Ncell’s SMS OTP). Antivirus software (e.g., blocking ransomware). Regular software updates.
(Image shows a shield for confidentiality, a lock for integrity, and a clock for availability.)

CIA Breach Example: NTC Data Leak (2022)

  • Issue: NTC’s customer database was exposed due to weak encryption (confidentiality breach).
  • Impact:
    • Integrity: Fake calls impersonating NTC staff.
    • Availability: Overloaded customer service lines.
  • Fix: NTC implemented:
    • Confidentiality: Tokenization of PII (Personally Identifiable Information).
    • Integrity: Blockchain for transaction logs.
    • Availability: Cloud-based failover systems.

6. Digital Security Threats and Countermeasures

Threat Description Countermeasure
Phishing Fake emails/tricks to steal credentials (e.g., "Reset your eSewa password"). Phishing awareness training, DMARC for emails.
Malware Viruses, ransomware (e.g., locking Daraz’s inventory data). Antivirus, regular patches.
Man-in-the-Middle (MitM) Intercepting data (e.g., hacking a Pathao rider’s payment). HTTPS, VPNs, TLS encryption.
Cybersquatting Registering domains like "daraz.com.ngo" to exploit Daraz’s brand. Trademark registration, ICANN dispute resolution.
Insider Threats Employees leaking data (e.g., a bank teller selling customer records). Access logs, mandatory vacations for sensitive roles.

(Image shows an email with "Urgent: Verify Account" and a suspicious link.)


In the Real World

  1. eSewa’s Digital Signatures

    • Idea: Uses digital signatures to authenticate transactions, preventing fraud in peer-to-peer payments.
    • How: Every transfer is signed with eSewa’s private key and verified with the sender’s public key, tied to their mobile number.
  2. Daraz’s Copyright Protection

    • Idea: Copyrights its product images and descriptions to prevent sellers from copying listings.
    • How: Automated tools scan for duplicate content; violators face takedowns or legal action under Nepal’s Cyber Security Act.
  3. NEPSE’s CIA Implementation

    • Idea: Protects stock market data with the CIA triad.
    • How:
      • Confidentiality: Only brokers with licenses access trade data.
      • Integrity: Every trade is logged with a timestamp and hash.
      • Availability: Multiple data centers ensure 24/7 access.

Exam Tip

  • Focus on definitions: Always start answers with clear definitions (e.g., "Intellectual property is...").
  • Link theory to Nepal: Use local examples (eSewa, Daraz, NTC) to show real-world application.
  • CIA triad is high-scoring: Explain how to implement it at three levels (organizational, network, end user) with examples.
  • Plagiarism types: Memorize the 5 types and their examples for short-answer questions.
  • Digital signatures: Draw the process (use the Mermaid diagram above) to explain how hashing + encryption work.
  • Past paper patterns:
    • 20 marks: Define IP + explain copyright/trademark protection (e.g., "How does Daraz protect its brand?").
    • 15 marks: CIA triad implementation (compare organizational vs. network levels).
    • 10 marks: Short-answer on threats (e.g., "What is cybersquatting? Give an example.").

Key Formula for Full Marks:

  1. Define the concept (1 mark).
  2. Explain with real examples (3–5 marks).
  3. Compare (if applicable, e.g., CIA at different levels) (2–3 marks).
  4. Link to Nepal/global laws (1–2 marks).
  5. Visual aid: Include a diagram/table where possible (bonus marks).

Based on the TU BCA syllabus for Cyber Law And Professional Ethics (CACS401), unit 4.

Discussion

Loading…