Beruflich Dokumente
Kultur Dokumente
Cyber Crimes
GUJARAT POLICE
MANOJ AGARWAL
The transformation
Today, we should
be aware of
software
destroying
rockets and
missiles!
GUJARAT POLICE
MANOJ AGARWAL
IT Act 2000
Cyber Cases
Investigation & Forensics
GUJARAT POLICE
MANOJ AGARWAL
IT Act 2000
Objectives
E-Governance
Electronic Filing of Documents
MANOJ AGARWAL
Wrongs
Moral Wrongs
Civil Wrongs
Legal Wrongs
Feeling of
Aggrieved
Crimes
Police
has a
guilt
Punishment
Police has aapproaches
very
defined
role
Fine
limited rolethe
to STATE
play
Ortoboth
play Compensation
Criminal Court
GUJARAT POLICE
MANOJ AGARWAL
Crimes
Non-Cognizable Offences
Cognizable Offences
Police
has a very
Minor
offences
limitedseeks
role to
Aggrieved
redressalplay
Serious ones
Responsibility of the
STATE to to get the
offender punished
GUJARAT POLICE
MANOJ AGARWAL
MANOJ AGARWAL
MANOJ AGARWAL
MANOJ AGARWAL
GUJARAT POLICE
10
MANOJ AGARWAL
Punishment
imprisonment fine up to Rs 2 lakh
up to three years, and / or
11
MANOJ AGARWAL
Punishment
imprisonment up to three years, and / or
fine up to Rs 2 lakh
12
MANOJ AGARWAL
Hacking (contd.)
Covers crimes like
GUJARAT POLICE
13
MANOJ AGARWAL
Examples
GUJARAT POLICE
14
MANOJ AGARWAL
Punishment
On first conviction
imprisonment of either description up to five years and
fine up to Rs 1 lakh
On subsequent conviction
imprisonment of either description up to ten years and
fine up to Rs 2 lakh
Section covers
Internet Service Providers,
Search engines,
Pornographic websites
16
MANOJ AGARWAL
Punishment
Imprisonment up to 7 years
17
MANOJ AGARWAL
Punishment
Imprisonment up to 10 years and fine
Cognizable, Non-Bailable, Court of Sessions
GUJARAT POLICE
18
MANOJ AGARWAL
BUT..
All cyber crimes do not come under the
Information Technology Act, 2000.
Many cyber crimes come under the Indian
Penal Code
GUJARAT POLICE
19
MANOJ AGARWAL
Email spoofing
NDPS Act
Web-Jacking
Arms Act
GUJARAT POLICE
20
MANOJ AGARWAL
COMPUTER CRIME
STATISTICS
Average Computer Crime - $500K
Internet
- Internet is in 70 countries
- over 25 million users
- 10%/month growth rate
GUJARAT POLICE
21
MANOJ AGARWAL
Frequency of incidents
Denial of Service: Section
43
Virus: Section: 66, 43
Data Alteration: Sec. 66
U/A Access : Section 43
Email Abuse : Sec. 67,
500, Other IPC Sections
Data Theft: Sec 66, 65
22
MANOJ AGARWAL
my poster
23
MANOJ AGARWAL
GUJARAT POLICE
MANOJ AGARWAL
SECURITY TECHNOLOGIES
USED
Intrusion Detection Systems
Firewalls
Encrypted Files
Anti-virus software
Access Control
35
81
42
91
50
78
61
95
50
96
89
61
98
93
62
100
92
64
98
90
GUJARAT POLICE
25
MANOJ AGARWAL
26
MANOJ AGARWAL
GUJARAT POLICE
27
MANOJ AGARWAL
Storage Facility
Tool
GUJARAT POLICE
28
MANOJ AGARWAL
CASE - I
GUJARAT POLICE
29
MANOJ AGARWAL
FAKE E-MAIL ID
FAKE E-MAILS
SMS MESSAGES THROUGH NET.
GUJARAT POLICE
30
MANOJ AGARWAL
GUJARAT POLICE
31
MANOJ AGARWAL
CASE 2
GUJARAT POLICE
32
MANOJ AGARWAL
FAKE POLICE
CONSTABLES
CASE:
A PERSON CAUGHT WITH FAKE
MOTOR VEHICLE LICENCE
POLICE SEIZED TWO HARD DISKS
GUJARAT POLICE
33
MANOJ AGARWAL
GUJARAT POLICE
34
MANOJ AGARWAL
GUJARAT POLICE
35
MANOJ AGARWAL
GUJARAT POLICE
36
MANOJ AGARWAL
CASE 3
GUJARAT POLICE
37
MANOJ AGARWAL
GUJARAT POLICE
38
MANOJ AGARWAL
CASE 4
GUJARAT POLICE
39
MANOJ AGARWAL
40
MANOJ AGARWAL
CASE 5
GUJARAT POLICE
41
MANOJ AGARWAL
GUJARAT POLICE
MANOJ AGARWAL
CASE 6
GUJARAT POLICE
43
MANOJ AGARWAL
FIR.NO 581/2001 PS
KOTWALI SPECIAL CELL
WASIM AHMED LILY@
WASIM
ASRAF
ARRESTED ON 12/10/01
ALONG WITH A TWO
SUIT CASES CONTAING
FAKE CURRENCYTO THE
TUNE OF 18.3 LAKHS
(1000,
500
DENOMINATIONS)
SEIZED
A
POLICE
COMPUTER,
SCANNER,
PRINTER
FROM
THE
ACCUSED.
GUJARAT POLICE
44
MANOJ AGARWAL
CONTD.
FORENSIC ANALYSIS REVEALED
HOW THE COMPUTER WAS USED IN THE
PRODUCTION OF COUNTERFEIT
CURRENCY
CURRENCY NOTES OF DENOMINATION
OFNOT ONLY 500,1000 BUT ALSO RS 50,
100.
45
MANOJ AGARWAL
CASE 7
GUJARAT POLICE
46
MANOJ AGARWAL
A CASE OF A PLASTIC
COMPANY
THE DIRECTORATE OF CENTRAL EXCISE
47
MANOJ AGARWAL
CONTD.
THE DGCEI OFFICILS SEIZED 12
COMPUTERS WITH THE HELP OF
COMPUTER FORENSIC EXPERTS
FORENSIC EXAMINATION OF
COMPUTER SYSTEMS REVALED
EXCISE EVASION TO THE TUNE OF 26
CRORES FROM 2000 ONWARDS
BACK MONEY DETAILS
THE BRIBES PAID TO THE EXCISE OFFICILS
GUJARAT POLICE
48
MANOJ AGARWAL
CASE 8
GUJARAT POLICE
49
MANOJ AGARWAL
FIR NO 76/02 PS
Mrs.
SONIA GANDHI RECEIVED
PARLIAMENT
STREET
THREATING E-MAILS
E- MAIL FROM
missonrevenge84@khalsa.com
missionrevenge84@hotmail.com
50
MANOJ AGARWAL
CASE - 9
GUJARAT POLICE
51
MANOJ AGARWAL
52
MANOJ AGARWAL
GUJARAT POLICE
53
MANOJ AGARWAL
GUJARAT POLICE
54
MANOJ AGARWAL
CASE-10
GUJARAT POLICE
55
MANOJ AGARWAL
KARNATAKA MEDICAL
EXAM(K- CET) SCAM
OCR BASED ANSWERED SHEET.
MODIFIED THE computer
(ANSWERS) PROGRAM AS PER
THE STUDENT ANSWERS SHEET.
MADE FAILED CANDIDATES
SUCCESSFUL.
--- THE AP INTERMEDIATE BOARD
MARKS SCANDAL.
GUJARAT POLICE
56
MANOJ AGARWAL
President CLINTONS
IMPEACHMENT TRIAL
GUJARAT POLICE
57
MANOJ AGARWAL
CLINTONS IMPEACHMENT
TRIAL
Forensic experts recovered deleted
data from Monica Lewinskyshome
computer as well as her computer at
the pentagon
Computer examinations of deleted
White House e-mail records exposed
the Clinton-Monica Lewinsky scandal
GUJARAT POLICE
58
MANOJ AGARWAL
INVESTIGATION
A good investigation need network forensic, hardware forensic and
software forensic.
The general approach to investigating the technical aspects of any
computer related crime is:
GUJARAT POLICE
59
MANOJ AGARWAL
Cyber Crimes ?
Any crime that involves computers and networks
Includes crimes that do not rely heavily on computers
Alibi
Harassment
Black mail
Extortion
Frauds
Murder
GUJARAT POLICE
etc....
60
MANOJ AGARWAL
61
MANOJ AGARWAL
How to Proceed ?
Pre-investigation intelligence.
A must
Visualize and access what you would encounter.
Prepare accordingly..
Computer may be on / off
Blank screen does not indicate a off computer
If computer is on
Note what all is on the screen
If the screen saver is operational, move the mouse slightly..
GUJARAT POLICE
MANOJ AGARWAL
Strategy
If you shut down the computer in the usual way
Fall in a trap
If you pull out the chord
Loose vital information on the RAM
Good documentation of the Screen (photograph) will help resolve
some of the discrepancies.
Recommended strategy
Ensure that all drives are empty
Pullout the Chord from the computer (not from the electric
board as it may be connected to a UPS)
GUJARAT POLICE
63
MANOJ AGARWAL
64
MANOJ AGARWAL
INVESTIGATION OF SEIZED
MATERIAL
WEBSITE RELEATED CRIME
INTERNET CRIME
In a 'simple' case of hacking it
would be possible to trace out
the IP address by the 'who is'
query.
GUJARAT POLICE
65
MANOJ AGARWAL
E-MAIL CRIMES
The header will give the IP address. Run "who is" to ascertain the
details of the service provider, whose Mail service was used by the
suspect.
If by analyzing circumstances, it is felt that the "who is "result is
genuine, the location of suspect can be traced with the help of ISP.
In case of forged/bogus or disguised/number letter mix-up e-mail
identities, the ISP can help in identifying, the suspect with the help
of the E-mail header by analyzing its contents and "message ID
"(see boxes for forged/bogus, disguised senders details).
The ISP will be able to help in locating a suspect, because when a
person dials up to connect with an ISP, he/she is logged on to one of
the Servers of the ISP. This server assigns ( depending on the port
of entry) a specific IP address to the user. This IP address
temporarily becomes the IP address of the user for that specific
session.
GUJARAT POLICE
66
MANOJ AGARWAL
CARDINAL RULES OF
COMPUTER FORENSICS
NEVER TRUST THE SUBJECT
OPERATING SYSTEM
NEVER MISHANDLE EVIDENCE
NEVER WORK ON ORIGINAL
EVIDENCE
USE PROPER SOFTWARE
UTILITIES
DOCUMENT EVERYTHING
GUJARAT POLICE
67
MANOJ AGARWAL
GUJARAT POLICE
MANOJ AGARWAL
STEPS TAKEN BY
COMPUTER FORENSIC
EXPERT
GUJARAT POLICE
MANOJ AGARWAL
70
MANOJ AGARWAL
Issues to address
We cannot be masters of all trade
Fighting cyber crimes has to be a team effort involving
Law enforcement agencies
Handle cyber evidence
Use it to generate investigate trails
GUJARAT POLICE
71
MANOJ AGARWAL
QUESTIONS
GUJARAT POLICE
72
MANOJ AGARWAL
THANK YOU
GUJARAT POLICE
73
MANOJ AGARWAL