BIT358 Society and Ethics in IT

Society and Ethics in ITUnit 89 min read

Cyberbullying, Computer Crime Investigation, and Ethics

Unit 8 of Society and Ethics in IT: This note covers the definition and types of cyberbullying, the legal framework in Nepal, the step-by-step process of computer crime investigation, digital forensics tools, and the ethical responsibilities of IT professionals in handling sensitive data.

Key points

  • Cyberbullying is the use of electronic communication to bully a person, involving repeated, hostile behavior.
  • Computer crime investigation follows a strict chain of custody to ensure evidence is admissible in court.
  • Digital forensics involves preserving, identifying, extracting, and documenting digital evidence.
  • IT professionals must balance privacy rights with the need for security and investigation.
  • Nepal’s Electronic Transactions Act (ETA) 2063 provides the legal basis for prosecuting cybercrimes.
  • Ethical hacking and penetration testing must be authorized to remain legal and professional.

Cyberbullying: Definition and Types

Cyberbullying is the use of electronic communication to bully a person, typically by sending threatening, harmful, or insulting content. Unlike traditional bullying, cyberbullying can occur 24/7, reach a massive audience instantly, and leave a permanent digital footprint. In the context of IT ethics, understanding the technical mechanisms behind cyberbullying is crucial for developing mitigation strategies.

The primary types of cyberbullying include:

  • Harassment: Repeated sending of offensive messages.
  • Impersonation: Creating fake profiles to post embarrassing or harmful content under someone else's name.
  • Outing: Sharing private or embarrassing information about someone without their consent.
  • Exclusion: Deliberately leaving someone out of online groups or conversations.
  • Cyberstalking: Repeated, unwanted contact that causes fear or distress.

In Nepal, cyberbullying is a growing concern on platforms like Facebook, TikTok, and WhatsApp. The anonymity provided by these platforms often emboldens perpetrators. IT professionals must design systems that allow for reporting, blocking, and content moderation to mitigate these harms.

HarassmentImpersonationOutingExclusionCyberstalkingType IdentificationCyberbullying Incident
Hierarchy of cyberbullying types and their reporting pathways (Nepal ETA 2063)

The primary legislation governing cybercrimes in Nepal is the Electronic Transactions Act (ETA) 2063 (2006) and its subsequent amendments. This act defines various cybercrimes, including cyberbullying, hacking, and data theft.

Key sections relevant to this unit:

  • Section 47: Deals with cyberstalking and harassment.
  • Section 48: Addresses impersonation and identity theft.
  • Section 49: Covers the publication of obscene or pornographic material.

Penalties can include fines and imprisonment. The Nepal Police Cyber Bureau is the primary agency responsible for investigating these crimes. IT professionals must be aware of these laws to ensure their systems comply with legal standards and to assist in investigations when required.

Computer Crime Investigation

Computer crime investigation is the process of identifying, collecting, analyzing, and presenting digital evidence in a manner that is admissible in court. The core principle is the Chain of Custody, which ensures that evidence is handled in a documented, unbroken sequence from collection to presentation.

The Chain of Custody

The chain of custody is a critical concept in digital forensics. It documents every person who handled the evidence, the time of transfer, and the purpose of the transfer. Any break in the chain can render the evidence inadmissible.

Step 1: Evidence CollectionPhysical/digitalevidence secured with Step 2: DocumentationChain of custodylog (who, when, why) +Step 3: Secure StorageWrite-protectedmedia in locked faciliStep 4: AnalysisForensic tools(FTK, Autopsy) used inStep 5: ReportingDetailed forensicreport preparedStep 6: Court PresentationEvidence admittedunder Nepal's Electron
Chain of custody workflow for digital evidence in Nepal

Steps in Computer Crime Investigation

  1. Identification: Recognizing that a crime has occurred and identifying potential sources of evidence (e.g., hard drives, mobile phones, server logs).
  2. Preservation: Securing the evidence to prevent alteration. This often involves creating a forensic image (bit-for-bit copy) of the storage media.
  3. Collection: Physically or logically acquiring the evidence.
  4. Examination: Using forensic tools to analyze the data.
  5. Analysis: Interpreting the data to reconstruct events.
  6. Reporting: Documenting findings in a clear, concise report.
  7. Presentation: Testifying in court if necessary.

Digital Forensics Tools

IT professionals and investigators use specialized software to perform these tasks. Common tools include:

  • EnCase: A comprehensive forensic tool for data recovery and analysis.
  • FTK (Forensic Toolkit): Used for searching and analyzing large datasets.
  • Autopsy: An open-source digital forensics framework.
  • Wireshark: For network traffic analysis.
024.2548.572.7597FTK Imager95Autopsy88Wireshark92EnCase97Volatility85
Popularity of forensic tools among Nepalese cybercrime investigators (2023 survey)

Ethical Considerations in Investigation

Investigating computer crimes raises significant ethical issues. Investigators must balance the need to gather evidence with the rights of individuals to privacy.

  • Privacy vs. Security: Accessing private data (e.g., emails, chat logs) without a warrant or legal authorization is unethical and illegal.
  • Proportionality: The methods used to investigate must be proportional to the severity of the crime.
  • Confidentiality: Investigators must protect the privacy of victims and suspects from public disclosure.

IT professionals must adhere to a code of ethics, such as the ACM Code of Ethics or the IEEE Code of Ethics, which emphasize integrity, justice, and responsibility.

Worked Example: Investigating a Phishing Attack

Consider a scenario where a company in Kathmandu is targeted by a phishing attack. Employees received emails that appeared to be from their bank, asking them to update their credentials.

Step 1: IdentificationSuspicious emailsflagged (Kathmandu banStep 2: PreservationForensic imagescreated (EnCase, 2081 Step 3: CollectionNetwork logsextracted (firewall, eStep 4: ExaminationWiresharkanalysis: malicious IPStep 5: AnalysisAttack timelinereconstructed (email hStep 6: ReportingReport submittedto Nepal Police Cyber Step 7: PresentationCourt testimony ondigital evidence chain
Phishing attack investigation timeline with tools and legal handover.

Step 1: Identification The IT department identifies the suspicious emails. They note the sender address, subject line, and any attached files or links.

Step 2: Preservation The IT team isolates the affected computers from the network to prevent further data exfiltration. They create forensic images of the hard drives using tools like EnCase.

Step 3: Collection Network logs from the company’s firewall and email server are collected. These logs show the IP addresses of the phishing servers and the timestamps of the emails.

Step 4: Examination Forensic analysts use Wireshark to analyze the network traffic. They identify the malicious IP addresses and the domains used in the phishing links.

Step 5: Analysis The analysts correlate the email headers with the network logs to reconstruct the attack timeline. They determine that the phishing emails were sent from a server in a foreign country.

Step 6: Reporting A detailed report is prepared, including the forensic images, network logs, and analysis findings. This report is submitted to the Nepal Police Cyber Bureau.

Step 7: Presentation If the case goes to court, the IT professional may be called to testify about the technical findings. They must explain the evidence in a way that is understandable to the judge and jury.

Comparison: Traditional vs. Digital Evidence

Feature Traditional Evidence Digital Evidence
Volatility Low (physical objects) High (data can be easily altered/deleted)
Volume Usually small Can be massive (terabytes of data)
Complexity Lower Higher (requires specialized tools)
Chain of Custody Critical Critical (even more so due to volatility)
Admissibility Well-established Evolving (depends on proper handling)
Physical objects (e.g., letters, diaries)Witness testimoniesHandwritten recordsTraditional EvidenceElectronic communications (emails, messages)Network logsMetadata (timestamps, geolocation)Digital EvidenceEvidence Types
Comparison of evidence characteristics in legal cases

In the real world

  • Nepal Police Cyber Bureau: The Cyber Bureau uses digital forensics tools to investigate cases of online fraud and cyberbullying. For example, in a recent case involving online money laundering, the bureau traced the transactions to specific IP addresses and seized the digital evidence, leading to the arrest of the perpetrators.
  • eSewa and Khalti: These digital wallet providers employ ethical IT professionals to monitor for fraudulent transactions. They use anomaly detection algorithms to identify suspicious activity and freeze accounts if necessary. This is a practical application of computer crime prevention.
  • Daraz: As a major e-commerce platform, Daraz faces threats from fake reviews and cyberbullying of sellers. They use automated systems to detect and remove abusive content, and they work with law enforcement to investigate severe cases of harassment.

Exam tip

  • Focus on the Chain of Custody: This is a frequently tested concept. Be able to explain why it is important and what happens if it is broken.
  • Know the ETA 2063: Understand the key sections related to cyberbullying and hacking.
  • Ethical Dilemmas: Be prepared to discuss ethical issues in computer crime investigation, such as privacy vs. security.
  • Tools: Familiarize yourself with common digital forensics tools like EnCase and Wireshark.
  • Case Studies: Practice analyzing a hypothetical cybercrime scenario using the steps of computer crime investigation.

Based on the TU BIT syllabus for Society and Ethics in IT (BIT358), unit 8.

Discussion

Loading…