Professional Documents
Culture Documents
04
04
Cyber Crimes
GUJARAT POLICE
The transformation Two years ago, we were afraid of rockets destroying Today, we should buildings and be aware of computer software centres... destroying rockets and missiles!
GUJARAT POLICE
IT Act 2000
Cyber Cases Investigation & Forensics
Issues to ponder
GUJARAT POLICE
Digital Signatures and Regulatory Regime Electronic Documents at par with paper documents
E-Governance
Electronic Filing of Documents
Wrongs
Moral Wrongs
Civil Wrongs
Legal Wrongs Crimes Police has a Punishment defined role Fine to play Or both Criminal Court
Feeling of Aggrieved guilt approaches Police has a very limited role the STATE to play Compensation
GUJARAT POLICE
Crimes
Non-Cognizable Offences
Police has Minor offencesa very limited role Aggrieved seeks to redressal play
Cognizable Offences
Serious ones Responsibility of the STATE to to get the offender punished
GUJARAT POLICE
Downloads, copies, extracts any data Introduces or causes to be introduced any viruses or contaminant Damages or causes to be damaged any computer resource
Destroy, alter, delete, add, modify or rearrange Change the format of a file
Charges the services availed by a person to the account of another person by tampering or manipulating any computer resource
Credit card frauds, Internet time thefts
Liable to pay damages not exceeding one crore to the affected party Investigation of
ADJUDICATING OFFICER Powers of a civil court
GUJARAT POLICE
GUJARAT POLICE
10
Punishment
imprisonment fine up to Rs 2 lakh up to three years, and / or
11
Punishment
imprisonment up to three years, and / or fine up to Rs 2 lakh
12
Hacking (contd.)
Covers crimes like
Trojan, Virus, worm attacks Logic bombs and Salami attacks Internet time theft Analysis of electromagnetic waves generated by computers
GUJARAT POLICE
13
Examples
State versus Amit Pasari and Kapil Juneja Delhi Police
M/s Softweb Solutions Website www.go2nextjob.com hosted Complaint of hacking by web hosting service
Criminal intimidation of employers and crashing the companys server Phoenix Global solutions
GUJARAT POLICE
14
Punishment
On first conviction imprisonment of either description up to five years and fine up to Rs 1 lakh On subsequent conviction imprisonment of either description up to ten years and fine up to Rs 2 lakh
Section covers
Internet Service Providers, Search engines, Pornographic websites
Person in charge of the computer resource fails to extend all facilities and technical assistance to decrypt the information. GUJARAT POLICE
16
MANOJ AGARWAL IPS
Punishment
Imprisonment up to 7 years
17
Punishment
Imprisonment up to 10 years and fine Cognizable, Non-Bailable, Court of Sessions GUJARAT POLICE
18
MANOJ AGARWAL IPS
BUT..
All cyber crimes do not come under the Information Technology Act, 2000. Many cyber crimes come under the Indian Penal Code
GUJARAT POLICE
19
Web-Jacking
Online sale of Arms
GUJARAT POLICE
20
21
Frequency of incidents
Denial of Service: Section 43 Virus: Section: 66, 43 Data Alteration: Sec. 66 U/A Access : Section 43 Email Abuse : Sec. 67, 500, Other IPC Sections Data Theft : Sec 66, 65
22
GUJARAT POLICE
Not very serious-some one has just pasted a poster over my poster
23
MANOJ AGARWAL IPS
12
1999
2000
2001
24
2001 CSI/FBI Computer Crime and Security Survey Of the organizations suffering security compromises in the last year 95% had Firewalls and 61%had IDSs !
%
35 81 50 96 89
%
42 91 61 98 93
%
50 78 62 100 92
%
61 95 64 98 90
25
26
GUJARAT POLICE
27
Storage Facility
Tool
GUJARAT POLICE
28
CASE - I
GUJARAT POLICE
29
FAKE E-MAIL ID
GUJARAT POLICE
30
GUJARAT POLICE
31
CASE 2
GUJARAT POLICE
32
GUJARAT POLICE
33
GUJARAT POLICE
34
GUJARAT POLICE
35
GUJARAT POLICE
36
CASE 3
GUJARAT POLICE
37
GUJARAT POLICE
38
CASE 4
GUJARAT POLICE
39
40
CASE 5
GUJARAT POLICE
41
GUJARAT POLICE
THE ACCUSED HER FORMER COLLEAGUE THE MISTAKE SHE HAS DONE GIVING VISITING CARD 42
CASE 6
GUJARAT POLICE
43
GUJARAT POLICE
CONTD.
FORENSIC ANALYSIS REVEALED
HOW THE COMPUTER WAS USED IN THE PRODUCTION OF COUNTERFEIT CURRENCY CURRENCY NOTES OF DENOMINATION OFNOT ONLY 500,1000 BUT ALSO RS 50, 100.
GUJARAT POLICE
FAKE POSTAL STAMPS THE ADDRESSES OF THE AGENTS WHO ARE CIRCULATING
45
MANOJ AGARWAL IPS
CASE 7
GUJARAT POLICE
46
THE DIRECTORATE OF CENTRAL EXCISE INTELLIGENCE PERSONS RAIDED A PLASTIC COMPANY OWNER RESIDENCE ON 10/11/2001 AND SEIZED AN AMOUNT OF RS.2 CRORE. PRODUCED 6000 CASH BILLS DATED PRIOR TO DATE OF RAID. THE BILLS WERE DATED TO APRILOCTOBER 2001
GUJARAT POLICE
47
CONTD.
THE DGCEI OFFICILS SEIZED 12 COMPUTERS WITH THE HELP OF COMPUTER FORENSIC EXPERTS FORENSIC EXAMINATION OF COMPUTER SYSTEMS REVALED
EXCISE EVASION TO THE TUNE OF 26 CRORES FROM 2000 ONWARDS BACK MONEY DETAILS THE BRIBES PAID TO THE EXCISE OFFICILS
48
MANOJ AGARWAL IPS
GUJARAT POLICE
CASE 8
GUJARAT POLICE
49
THE CASE WAS REFERRED ACCUSED PERSON LOST HIS PARENTS DURING 1984 RIOTS
GUJARAT POLICE
50
CASE - 9
GUJARAT POLICE
51
stored the incriminating material. ON FORENSIC ANALYSIS: ROLE OF Lo e T IP ADDRESSES OF PAKISTAN TELEPHONE NUMBERS CODED MESSAGES
GUJARAT POLICE
52
GUJARAT POLICE
53
GUJARAT POLICE
54
CASE-10
GUJARAT POLICE
55
56
GUJARAT POLICE
57
58
INVESTIGATION
A good investigation need network forensic, hardware forensic and software forensic.
The general approach to investigating the technical aspects of any computer related crime is:
Eliminate the obvious. Hypothesize the attack. Collect evidence, including, possibly, the computer themselves. Reconstruct the crime. Perform a trace back to the source computer. Analyze the source, target, and intermediate computer. Turn your finding and evidentiary material over corporate investigators or law enforcement for follow-up. GUJARAT POLICE
59
MANOJ AGARWAL IPS
Cyber Crimes ?
Any crime that involves computers and networks Includes crimes that do not rely heavily on computers
Alibi Harassment
Black mail
Extortion Frauds Murder
etc....
GUJARAT POLICE
60
Hardware as contraband or fruits of crime. Stolen computer system Hardware as in instrumentality Hardware designed exclusively to commit crime-sniffer Hardware as evidence. CD Writer to copy blue movies Pornography Information as contraband or fruits of crime. Pirated software Information as an instrumentality Hacking program Information as evidence. Key of investigation- we are searching this
GUJARAT POLICE
61
How to Proceed ?
GUJARAT POLICE
Pre-investigation intelligence. A must Visualize and access what you would encounter. Prepare accordingly.. Computer may be on / off Blank screen does not indicate a off computer If computer is on Note what all is on the screen If the screen saver is operational, move the mouse slightly.. Map all the connections & mark the matching ends Find out whether it is connected to the network. Decide on the next course of action..
62
MANOJ AGARWAL IPS
Strategy
If you shut down the computer in the usual way Fall in a trap If you pull out the chord Loose vital information on the RAM Good documentation of the Screen (photograph) will help resolve some of the discrepancies. Recommended strategy Ensure that all drives are empty Pullout the Chord from the computer (not from the electric board as it may be connected to a UPS)
GUJARAT POLICE
63
64
WEBSITE RELEATED CRIME Confirm identity of suspect by running the "who is' query".
65
E-MAIL CRIMES
The header will give the IP address. Run "who is" to ascertain the details of the service provider, whose Mail service was used by the suspect. If by analyzing circumstances, it is felt that the "who is "result is genuine, the location of suspect can be traced with the help of ISP. In case of forged/bogus or disguised/number letter mix-up e-mail identities, the ISP can help in identifying, the suspect with the help of the E-mail header by analyzing its contents and "message ID "(see boxes for forged/bogus, disguised senders details). The ISP will be able to help in locating a suspect, because when a person dials up to connect with an ISP, he/she is logged on to one of the Servers of the ISP. This server assigns ( depending on the port of entry) a specific IP address to the user. This IP address temporarily becomes the IP address of the user for that specific GUJARAT POLICE session. MANOJ AGARWAL
66
IPS
67
GUJARAT POLICE
70
Issues to address
GUJARAT POLICE
We cannot be masters of all trade Fighting cyber crimes has to be a team effort involving Law enforcement agencies Handle cyber evidence Use it to generate investigate trails Know when to call an expert for assistance Computer expert How to handle cyber evidence Generate investigative leads Call enforcement agencies for assistance Attorneys How to defend cyber evidence Determine whether it is admissible Forensic Scientists How to process it
71
QUESTIONS
GUJARAT POLICE
72
THANK YOU
GUJARAT POLICE
73