Network and Cyber SecurityUnit 1010 min read
Cyber Law & Digital Forensics: Acts, Evidence & Investigation
Unit 10 of Network and Cyber Security covers Nepal’s cyber laws (Electronic Transactions Act, Cyber Security Act), digital evidence rules, forensic investigation processes, and real-world case studies like eSewa frauds and Ncell SIM cloning. Learn how courts admit digital proof, how investigators recover deleted data,
Core Concepts
1. Cyber Law in Nepal: Key Acts and Definitions
Cyber law in Nepal is primarily governed by three key acts:
- Electronic Transactions Act (ETA) 2008: Legalizes electronic contracts, digital signatures, and e-commerce (e.g., Daraz, eSewa).
- Cyber Security Act (CSA) 2018: Mandates data protection, cybercrime penalties, and government oversight (e.g., NTC blocking illegal websites).
- Digital Signature Act 2008: Validates electronic signatures for legal agreements (e.g., online loan applications in banks like NMB).
classDiagram
class ETA2008 {
+ Legalizes e-contracts
+ Defines digital signatures
+ Governs e-commerce
}
class CSA2018 {
+ Cybercrime penalties
+ Data protection rules
+ Government oversight
}
class DigitalSignatureAct {
+ Validates e-signatures
+ Used in loans/agreements
}
ETA2008 --> "Enables" DigitalSignatureAct
CSA2018 --> "Regulates" ETA2008Real-World Example:
- eSewa’s Legal Framework: When you pay utility bills via eSewa, the transaction is legally binding under the ETA 2008 because it uses a digital signature (your eSewa PIN acts as a biometric signature). If a dispute arises, courts accept eSewa’s records as valid evidence.
2. Digital Evidence: Admissibility and Chain of Custody
Digital evidence must meet three criteria to be admissible in court:
- Relevance: Must relate to the crime (e.g., WhatsApp chats in a blackmail case).
- Authenticity: Must prove the data hasn’t been tampered with (e.g., hash values of seized hard drives).
- Integrity: Must show an unbroken chain of custody (who handled the evidence and when).
stateDiagram-v2
[*] --> EvidenceCollected
EvidenceCollected --> SeizedByInvestigator: "With timestamp"
SeizedByInvestigator --> StoredInTamperProofFacility: "Hash verified"
StoredInTamperProofFacility --> PresentedInCourt: "Chain of custody log"
PresentedInCourt --> [*]Worked Example:
- Ncell SIM Cloning Case (2021):
- Evidence: Investigators seized a cloned SIM card and its IMEI logs.
- Process:
- The SIM was stored in a forensically clean bag (chain of custody).
- A hash of the SIM’s firmware was taken immediately to prove integrity.
- In court, the hash matched the original Ncell database records, proving the SIM was illegally duplicated.
- Outcome: The accused was convicted under CSA 2018 (Section 10) for unauthorized access to telecom data.
3. Digital Forensics Investigation Process
Forensic investigations follow a structured workflow to avoid contamination:
| Step | Action | Tools Used |
|---|---|---|
| Identification | Define scope (e.g., "recover deleted WhatsApp messages"). | FTK Imager, Autopsy |
| Preservation | Create a bit-by-bit copy of the device (write-blocker used). | Guymager, dd (Linux) |
| Collection | Gather data (RAM, HDD, cloud backups). | Cellebrite, Magnet AXIOM |
| Analysis | Reconstruct events (e.g., timeline of file accesses). | Timeline Explorer, Volatility |
| Reporting | Document findings in a court-admissible format. | EnCase, Excel (with hashes) |
| Presentation | Explain findings to judges/juries (e.g., "User X deleted file Y at time Z"). | PowerPoint, court-approved reports |
Used to prevent altering evidence during collection (Image: Tony Webster from Minneapolis, Minnesota, United States, CC BY-SA 2.0, via Wikimedia Commons)
Real-World Example:
- Pathao Driver Fraud (2022):
- Crime: A driver used a cloned Pathao app to charge extra fares.
- Forensics:
- Investigators seized the driver’s phone and created a forensic image.
- Using Autopsy, they found modified app logs showing fake trip records.
- The chain of custody proved the phone hadn’t been tampered with.
- Legal Outcome: Pathao provided the logs as evidence under ETA 2008, leading to the driver’s arrest.
4. Types of Digital Evidence
| Evidence Type | Example | How It’s Collected | Legal Weight in Nepal |
|---|---|---|---|
| Electronic Data | Emails, WhatsApp chats | Screenshots + metadata extraction | High (ETA 2008, Section 5) |
| Log Files | Server access logs (e.g., NTC) | SIEM tools (Splunk, ELK) | Medium (CSA 2018, Section 12) |
| Metadata | EXIF data in photos (e.g., Daraz seller photos) | ExifTool, Photorec | High (proves tampering) |
| Network Traffic | Hacking attempts (e.g., NEPSE scams) | Wireshark, tcpdump | High (CSA 2018, Section 9) |
| Biometric Data | Fingerprint on a stolen phone | AFIS (Automated Fingerprint System) | Very High (Biometric Act 2011) |
Worked Example:
- Daraz Seller Scam (2023):
- Evidence: A seller listed fake products. Investigators found:
- Metadata in images: EXIF data showed the photos were edited (originally from a stock site).
- Payment logs: eSewa transaction IDs matched the seller’s account but showed no delivery.
- Legal Action: Daraz provided these logs to police under ETA 2008 (Section 7), leading to a NRS 50,000 fine and account suspension.
- Evidence: A seller listed fake products. Investigators found:
5. Cybercrime Investigation Tools
| Tool | Purpose | Example Use Case |
|---|---|---|
| FTK Imager | Create forensic disk images | Seizing a hacker’s laptop in a ransomware case |
| Autopsy | File carving and timeline analysis | Recovering deleted WhatsApp chats |
| Wireshark | Packet analysis (e.g., DDoS attacks) | Investigating Ncell network breaches |
| Volatility | RAM forensics (malware analysis) | Catching a keylogger in a bank’s system |
| Cellebrite | Mobile device extraction | Pathao driver fraud investigation |
6. Jurisdiction and International Cooperation
Nepal follows dual jurisdiction for cybercrimes:
- Domestic: Prosecuted under CSA 2018 and Penal Code 2017.
- International: Cooperates with Interpol and ASEAN Cybercrime Task Force for cross-border crimes (e.g., hacking from India to Nepal).
Example:
- 2020 NEPSE Hack: Hackers defaced NEPSE’s website. Investigators:
- Traced the IP to a VPN in Singapore.
- Worked with Interpol to identify the suspect in India.
- Used CSA 2018 (Section 11) to prosecute the local enabler.
7. Ethical and Legal Challenges
| Challenge | Nepal’s Approach | Risk if Ignored |
|---|---|---|
| Privacy vs. Surveillance | CSA 2018 allows government monitoring but requires warrants. | Unlawful spying (e.g., NTC blocking sites without due process). |
| Jurisdiction Over Cloud Data | ETA 2008 says data stored abroad is admissible if legally obtained. | Evidence rejected in court (e.g., Google Drive logs). |
| Anonymity in Dark Web | CSA 2018 (Section 8) bans VPNs for illegal activities. | Hard to trace crimes (e.g., drug sales on Tor). |
Real-World Example:
- NTC vs. VPN Providers (2021):
- Issue: NTC blocked VPNs to stop piracy, but this also cut off legitimate users (e.g., expats accessing Nepali banks).
- Legal Battle: Courts ruled that CSA 2018 must balance surveillance and privacy, leading to a partial lift on restrictions.
In the Real World
eSewa’s Fraud Detection:
- Idea Used: Digital signatures + log analysis (ETA 2008).
- How: When you transfer money, eSewa generates a unique transaction ID (digital signature) and logs it. If a user reports fraud, eSewa’s forensic team uses Autopsy to check if the transaction was altered. In 2022, this helped recover NRS 20 million in fake transactions.
Ncell’s SIM Cloning Crackdown:
- Idea Used: Chain of custody + hash verification (CSA 2018).
- How: Ncell’s security team deploys Cellebrite to extract IMEI logs from seized phones. They then compare the phone’s hash value with Ncell’s database. In 2023, this method led to 500 arrests for SIM cloning.
Daraz’s Seller Verification:
- Idea Used: Metadata analysis + ETA 2008 compliance.
- How: Daraz uses ExifTool to check product images for edits. If a seller uploads a photo from a stock site, Daraz flags it under ETA 2008 (Section 6). This reduced fake listings by 40% in 2023.
Exam Tip
Memorize Key Sections:
- ETA 2008: Sections 5 (digital evidence), 7 (e-commerce disputes).
- CSA 2018: Sections 8 (VPNs), 9 (hacking), 10 (SIM cloning), 12 (logs).
- Penal Code 2017: Section 188 (cyber fraud), Section 190 (data theft).
Case Study Patterns:
- Exams often ask: "How would you investigate [scenario] under Nepali law?"
- Answer Structure:
- Identify the act (e.g., "This falls under CSA 2018, Section 9").
- Describe the forensic steps (e.g., "Use FTK Imager to create a forensic copy").
- Mention admissibility (e.g., "The hash value proves integrity per ETA 2008").
Common Pitfalls:
- ❌ Saying "all digital evidence is admissible" → Wrong: Must prove chain of custody.
- ❌ Ignoring jurisdiction → Wrong: Cloud data needs ETA 2008 compliance.
- ❌ Mixing CSA 2018 and Penal Code → Wrong: CSA covers cybercrimes; Penal Code covers fraud.
Visuals in Exams:
- Draw a chain of custody flowchart (like the Mermaid diagram above).
- Sketch a forensic workstation setup (IMAGE: forensic workstation).
- Label a digital evidence hierarchy (e.g., "Logs > Metadata > Content").
Final Note: Always tie your answers to real cases (eSewa, Ncell, Daraz) and specific sections of the acts. Examiners love when you say: "Under CSA 2018, Section 10, SIM cloning is punishable by 3–7 years in prison, as seen in the 2021 Ncell case where investigators used Cellebrite to extract IMEI logs."
Based on the PU BE Computer (PU) syllabus for Network and Cyber Security (CMP426), unit 10.
Discussion
Loading…