High tech crime (HTC), also known as technology-enabled crime, makes use of information and communications technologies to infringe criminal laws.
Online tools are those digital goods or services that can be obtained from the internet.
Case Study- BPO Data Theft
Bank Fraud in Pune –
MPhasis Ltd MsourcE
Defrauded US Customers of Citi Bank
The crime was committed using "Unauthorized Access" to the "Electronic Account Space" of the customers .
Case Study- Case of Extortion of Money Through Internet
The complainant has received a threatening email demanding protection from unknown person.
Police registered a case u/s. 384/506/511 IPC.
The sender of the email used the email ID email@example.com & firstname.lastname@example.org and signed as Chengez Babar.
Measures to be taken…
1.avoid disclosing any information pertaining to oneself.
2.avoid sending any photograph online particularly to strangers and chat friends.
3.use latest and up date anti virus software to guard against virus attacks.
4.keep back up volumes so that one may not suffer data loss in case of virus contamination
5.never send your credit card number to any site that is not secured.
6.always keep a watch on the sites that your children are accessing.
7.use a security programme that gives control over the cookies and send information back to the site .
8.web site owners should watch traffic and check any irregularity on the site.
9.use of firewalls may be beneficial.
10. web servers running public sites must be physically separate protected from internal corporate network.
Jeffrey Lee Parson Sven Jaschan Chen Ing-Hau Benny
James Ancheta Andrew Schwarmkoff Jeremy Jaynes Spam Phishing Spam
Spam Viruses/Worms Industrial Espionage and Hackers Wi-Fi High Jacking
SPAM – It’s an electronics junk and an unsolicited, often commercial, message transmitted through the Internet as a mass mailing to a large number of recipients .
Spamming used to spread malicious payloads, phish, and pay using adware/malware, spyware
To address this problem, the U.S. Congress in 2003 passed legislation designed to curb spam. The law makes it illegal to send e-mail messages that use deceptive subject lines and false return addresses, providing fines and possible prison terms for violators.
The law requires all commercial e-mail messages, solicited or unsolicited, to include a valid postal address and an opt-out mechanism within the body of the text so that recipients can prevent future e-mail solicitations.
A self-duplicating computer program that spreads from computer to computer, interfering with data and software.
Some viruses are mere annoyances, but others can do serious damage.
Viruses can delete or change files, steal important information, load and run unwanted applications, send documents via electronic mail (e-mail).
A program that propagates itself across computers, usually by spawning copies of itself in each computer's memory.
A worm might duplicate itself in one computer so often that it causes the computer to crash.
Trojans : Also known as a Trojan horse, this is Software that appears to perform or actually performs a desired task for a user while performing a harmful task without the user's knowledge or consent.
THEFT OF TRADE SECRET
The secret removal, copying, or recording of confidential or valuable information in a company for use by a competitor .
Deleting data for fun
Turning computers into zombies
To commit crimes
Take down networks
Ethical/white hat hackers exist too
Help break into networks to prevent crimes
Wi-Fi High Jacking
60-70% wireless networks are wide open
Why are the Wi-Fi networks unprotected?
Most people say “Our data is boring”
But… criminals look for wireless networks to commit their crimes
And… the authorities will come knocking on your door…..
Wireless Fidelity (Wi-Fi)
Using antennas to create “ hot spots ”
Hotspots – Internet Access (sometimes free)
Newport Harbor - All the boats in Harbor have internet access
San Francisco Giants Stadium – Surf the web while catching a game
UMass (need to register, but it’s free)
Philadelphia, PA – just announced – entire city by 2006
CASE STUDY The Bank NSP Case The Bank NSP case is the one where a management trainee of the bank was engaged to be married. The couple exchanged many emails using the company computers. After sometime the two broke up and the girl created fraudulent email ids like “indianbar - associations” and sent emails to the boy’s foreign clients and to do this she used the banks computer. The boy’s company lost a large number of clients & took the bank to court. The bank was held liable for the emails sent using the bank’s system.
Case Study “Citi-Bank” 1995, First documented attack on US Bank
Attacked Citi-Bank system and obtained userids and passwords
Setup accounts in Banks throughout the world
Bank of America, Banco del Sud Argentina, Bank Artha Graha Indonesia
Transferred $12 million to the various accounts.
FBI & Interpol Arrested them and in Feb 1997 sentenced to 3 years in prison and ordered to pay $240,000.00 to Citi-Bank. Citi-Bank had been warned about lax security, but they ignored the warnings, Citi-Bank now extremely security conscious.
Types of Cyberattacks, by percentage (source- FBI)
Financial fraud: 11%
Sabotage of data/networks: 17%
Theft of proprietary information: 20%
System penetration from the outside: 25%
Denial of service: 27%
Unauthorized access by insiders: 71%
Employee abuse of internet privileges 79%
The proportion of cybercrime that can be directly or indirectly attributed to terrorists is difficult to determine. However, linkages do exist between terrorist groups and criminals that allow terror networks to expand inter- nationally through leveraging the computer resources, money laundering activities, or transit routes operated by criminals.
The use of information technology by terrorist groups and individuals to further their agenda. This can include use of information technology to organize and execute attacks against networks, computer systems and telecommunications infrastructures, or for exchanging information or making threats electronically. Examples are hacking into computer systems, introducing viruses to vulnerable networks, web site defacing, denial-of-service attacks, or terroristic threats made via electronic communication.
Cyberterrorism can have a serious large-scale influence on significant numbers of people. It can weaken countries' economy greatly, thereby stripping it of its resources and making it more vulnerable to military attack. Cyberterror can also affect internet-based businesses. Like brick and mortar retailers and service providers, most websites that produce income (whether by advertising, monetary exchange for goods or paid services) could stand to lose money in the event of downtime created by cyber criminals. As internet-businesses have increasing economic importance to countries, what is normally cybercrime becomes more political and therefore "terror" related.
What is it?
An autopsy of a computer or network to uncover digital evidence of a crime
Evidence must be preserved and hold up in a court of law
Growing field – Many becoming computer forensicsavvy
FBI, State and Local Police, IRS, Homeland Security
Defense attorneys, judges and prosecutors
Independent security agencies
White hat or Ethical Hackers
Programs offered at major universities such as URI
Smart Criminals don’t use their own computers
Use anti-virus software and firewalls - keep them up to date Keep your operating system up to date with critical security updates and patches Don't open emails or attachments from unknown sources Use hard-to-guess passwords. Don’t use words found in a dictionary. Remember that password cracking tools exist Back-up your computer data on disks or CDs often
Don't share access to your computers with strangers If you have a wi-fi network, password protect it Disconnect from the Internet when not in use Reevaluate your security on a regular basis Make sure your employees and family members know this info too!