Society and Ethics in ITUnit 89 min read
Cyberbullying, Computer Crime Investigation, and Ethics
Unit 8 of Society and Ethics in IT: This note covers the definition and types of cyberbullying, the legal framework in Nepal, the step-by-step process of computer crime investigation, digital forensics tools, and the ethical responsibilities of IT professionals in handling sensitive data.
Key points
- Cyberbullying is the use of electronic communication to bully a person, involving repeated, hostile behavior.
- Computer crime investigation follows a strict chain of custody to ensure evidence is admissible in court.
- Digital forensics involves preserving, identifying, extracting, and documenting digital evidence.
- IT professionals must balance privacy rights with the need for security and investigation.
- Nepal’s Electronic Transactions Act (ETA) 2063 provides the legal basis for prosecuting cybercrimes.
- Ethical hacking and penetration testing must be authorized to remain legal and professional.
Cyberbullying: Definition and Types
Cyberbullying is the use of electronic communication to bully a person, typically by sending threatening, harmful, or insulting content. Unlike traditional bullying, cyberbullying can occur 24/7, reach a massive audience instantly, and leave a permanent digital footprint. In the context of IT ethics, understanding the technical mechanisms behind cyberbullying is crucial for developing mitigation strategies.
The primary types of cyberbullying include:
- Harassment: Repeated sending of offensive messages.
- Impersonation: Creating fake profiles to post embarrassing or harmful content under someone else's name.
- Outing: Sharing private or embarrassing information about someone without their consent.
- Exclusion: Deliberately leaving someone out of online groups or conversations.
- Cyberstalking: Repeated, unwanted contact that causes fear or distress.
In Nepal, cyberbullying is a growing concern on platforms like Facebook, TikTok, and WhatsApp. The anonymity provided by these platforms often emboldens perpetrators. IT professionals must design systems that allow for reporting, blocking, and content moderation to mitigate these harms.
Legal Framework in Nepal
The primary legislation governing cybercrimes in Nepal is the Electronic Transactions Act (ETA) 2063 (2006) and its subsequent amendments. This act defines various cybercrimes, including cyberbullying, hacking, and data theft.
Key sections relevant to this unit:
- Section 47: Deals with cyberstalking and harassment.
- Section 48: Addresses impersonation and identity theft.
- Section 49: Covers the publication of obscene or pornographic material.
Penalties can include fines and imprisonment. The Nepal Police Cyber Bureau is the primary agency responsible for investigating these crimes. IT professionals must be aware of these laws to ensure their systems comply with legal standards and to assist in investigations when required.
Computer Crime Investigation
Computer crime investigation is the process of identifying, collecting, analyzing, and presenting digital evidence in a manner that is admissible in court. The core principle is the Chain of Custody, which ensures that evidence is handled in a documented, unbroken sequence from collection to presentation.
The Chain of Custody
The chain of custody is a critical concept in digital forensics. It documents every person who handled the evidence, the time of transfer, and the purpose of the transfer. Any break in the chain can render the evidence inadmissible.
Steps in Computer Crime Investigation
- Identification: Recognizing that a crime has occurred and identifying potential sources of evidence (e.g., hard drives, mobile phones, server logs).
- Preservation: Securing the evidence to prevent alteration. This often involves creating a forensic image (bit-for-bit copy) of the storage media.
- Collection: Physically or logically acquiring the evidence.
- Examination: Using forensic tools to analyze the data.
- Analysis: Interpreting the data to reconstruct events.
- Reporting: Documenting findings in a clear, concise report.
- Presentation: Testifying in court if necessary.
Digital Forensics Tools
IT professionals and investigators use specialized software to perform these tasks. Common tools include:
- EnCase: A comprehensive forensic tool for data recovery and analysis.
- FTK (Forensic Toolkit): Used for searching and analyzing large datasets.
- Autopsy: An open-source digital forensics framework.
- Wireshark: For network traffic analysis.
Ethical Considerations in Investigation
Investigating computer crimes raises significant ethical issues. Investigators must balance the need to gather evidence with the rights of individuals to privacy.
- Privacy vs. Security: Accessing private data (e.g., emails, chat logs) without a warrant or legal authorization is unethical and illegal.
- Proportionality: The methods used to investigate must be proportional to the severity of the crime.
- Confidentiality: Investigators must protect the privacy of victims and suspects from public disclosure.
IT professionals must adhere to a code of ethics, such as the ACM Code of Ethics or the IEEE Code of Ethics, which emphasize integrity, justice, and responsibility.
Worked Example: Investigating a Phishing Attack
Consider a scenario where a company in Kathmandu is targeted by a phishing attack. Employees received emails that appeared to be from their bank, asking them to update their credentials.
Step 1: Identification The IT department identifies the suspicious emails. They note the sender address, subject line, and any attached files or links.
Step 2: Preservation The IT team isolates the affected computers from the network to prevent further data exfiltration. They create forensic images of the hard drives using tools like EnCase.
Step 3: Collection Network logs from the company’s firewall and email server are collected. These logs show the IP addresses of the phishing servers and the timestamps of the emails.
Step 4: Examination Forensic analysts use Wireshark to analyze the network traffic. They identify the malicious IP addresses and the domains used in the phishing links.
Step 5: Analysis The analysts correlate the email headers with the network logs to reconstruct the attack timeline. They determine that the phishing emails were sent from a server in a foreign country.
Step 6: Reporting A detailed report is prepared, including the forensic images, network logs, and analysis findings. This report is submitted to the Nepal Police Cyber Bureau.
Step 7: Presentation If the case goes to court, the IT professional may be called to testify about the technical findings. They must explain the evidence in a way that is understandable to the judge and jury.
Comparison: Traditional vs. Digital Evidence
| Feature | Traditional Evidence | Digital Evidence |
|---|---|---|
| Volatility | Low (physical objects) | High (data can be easily altered/deleted) |
| Volume | Usually small | Can be massive (terabytes of data) |
| Complexity | Lower | Higher (requires specialized tools) |
| Chain of Custody | Critical | Critical (even more so due to volatility) |
| Admissibility | Well-established | Evolving (depends on proper handling) |
In the real world
- Nepal Police Cyber Bureau: The Cyber Bureau uses digital forensics tools to investigate cases of online fraud and cyberbullying. For example, in a recent case involving online money laundering, the bureau traced the transactions to specific IP addresses and seized the digital evidence, leading to the arrest of the perpetrators.
- eSewa and Khalti: These digital wallet providers employ ethical IT professionals to monitor for fraudulent transactions. They use anomaly detection algorithms to identify suspicious activity and freeze accounts if necessary. This is a practical application of computer crime prevention.
- Daraz: As a major e-commerce platform, Daraz faces threats from fake reviews and cyberbullying of sellers. They use automated systems to detect and remove abusive content, and they work with law enforcement to investigate severe cases of harassment.
Exam tip
- Focus on the Chain of Custody: This is a frequently tested concept. Be able to explain why it is important and what happens if it is broken.
- Know the ETA 2063: Understand the key sections related to cyberbullying and hacking.
- Ethical Dilemmas: Be prepared to discuss ethical issues in computer crime investigation, such as privacy vs. security.
- Tools: Familiarize yourself with common digital forensics tools like EnCase and Wireshark.
- Case Studies: Practice analyzing a hypothetical cybercrime scenario using the steps of computer crime investigation.
Based on the TU BIT syllabus for Society and Ethics in IT (BIT358), unit 8.
Discussion
Loading…