Module IV: Digital Security, Cyber Threats & Information Technology Law
Course Code: COM5EJ307 (4) • Computer Applications in Business
In a hyper-connected commercial ecosystem, the preservation of data integrity, confidentiality, and operational continuity is an existential business imperative. Module IV delivers an exhaustive academic analysis across two fundamental units: 1. Cyber Threats & Security Defenses: The CIA Triad of information security, comprehensive malware taxonomy (Viruses, Worms, Trojan Horses, Spyware, Ransomware), attack methodologies (Phishing, Social Engineering, Hacking, Denial of Service / DDoS, SQL Injection, Man-in-the-Middle), and multi-layered defensive countermeasures (Heuristic Antivirus, Next-Gen Firewalls, Symmetric vs Asymmetric Cryptography, Hash functions, Digital Signatures, and Public Key Infrastructure - PKI); 2. Biometrics, Cyber Hygiene & Cyber Law: Physiological and behavioral biometric authentication paradigms, multi-factor authentication (MFA), safe browsing hygiene, e-payment precautions, and an exhaustive statutory exposition of the Information Technology Act, 2000 (legal recognition of e-records, digital signatures, cyber offenses under Sections 43, 65, 66, 66C, 66D, 66F, intermediary liability under Section 79, CERT-In, and the Digital Personal Data Protection Act 2023).
Unit 4.1: Cyber Threats in Internet & E-Commerce & Security Countermeasures
1. Foundational Security Framework: The CIA Triad & Non-Repudiation
Information security in commercial data networks is anchored upon three non-negotiable core pillars, collectively known as the CIA Triad, augmented by the legal principle of Non-Repudiation:
- Confidentiality: Ensuring sensitive corporate databases, customer card credentials, and business plans are accessible strictly to authorized entities. Enforced via AES-256 encryption, access control lists (ACLs), and tokenization.
- Integrity: Safeguarding electronic transactions against unauthorized modification, insertion, or tampering during transit and storage. Enforced through cryptographic hash functions (SHA-256) and digital certificates.
- Availability: Ensuring critical e-commerce web storefronts, cloud servers, and banking portals remain continuously operational 24/7/365. Protected against hardware outages and DDoS floods via server clustering and cloud CDNs.
- Non-Repudiation: Cryptographic verification of authorship ensuring that neither the sender nor recipient of an electronic transaction can dispute or falsely deny transaction transmission. Achieved via asymmetric digital signatures.
2. Comprehensive Taxonomy of Malicious Software (Malware)
Malware (Malicious Software) comprises any software code intentionally designed to cause damage to a computer, server, client, or computer network:
1. Computer Viruses
A parasitic program that attaches itself to legitimate host files or executable binaries. It requires human intervention (such as opening an infected email attachment or executing a download) to replicate and spread. Includes Boot Sector viruses, File Infectors, and Macro viruses.
2. Computer Worms
A self-replicating autonomous program that does NOT require human intervention or a host file. Worms exploit operating system security flaws to propagate automatically across computer networks, exhausting network bandwidth and opening backdoors (e.g., Conficker, Code Red).
3. Trojan Horses
A deceitful program disguised as legitimate, useful software (such as a utility tool, invoice PDF, or media player) to trick users into running it. Once executed, it quietly drops a Remote Access Trojan (RAT), granting cyber adversaries unauthorized remote backdoor control over the machine.
4. Spyware & Keyloggers
Software covertly monitoring and logging user activities without consent. Keyloggers capture keystrokes pressed on the keyboard, harvesting banking login credentials, credit card details, and confidential emails, transmitting them silently to command-and-control servers.
Enterprise Threat Spotlight: Ransomware Extortion
Ransomware infiltrates corporate networks and utilizes unbreakable asymmetric cryptography (RSA-4096 / AES-256) to encrypt all company databases, file servers, and backups. Attackers demand millions in cryptocurrency (Bitcoin) in exchange for decryption keys. Modern strains practice "Double Extortion": exfiltrating proprietary customer data before encryption and threatening dark-web public disclosure if the ransom is unpaid.
3. Cyber Attack Methodologies & Threat Vectors
- Phishing: Fraudulent emails or websites masquerading as legitimate banks to harvest user credentials. Variants include Spear-Phishing (targeted to specific individuals), Whaling (targeting C-suite corporate executives), and Smishing/Vishing (via SMS and voice calls).
- Hacking: The unauthorized probing and exploitation of digital networks:White Hat: Ethical security professionals probing systems to patch flaws.Black Hat: Malicious cybercriminals breaching systems for financial theft or destruction.Grey Hat: Probing systems without authorization but without malicious intent.
- Denial of Service (DoS) & Distributed Denial of Service (DDoS): Overwhelming enterprise web servers with millions of fraudulent requests using globally distributed botnets of compromised IoT devices, rendering online services unavailable to paying customers.
- Man-in-the-Middle (MitM) Attacks: Adversary intercepts and alters data packets between two communicating parties without their knowledge (common on unencrypted public Wi-Fi).
- SQL Injection (SQLi): Injecting malicious SQL database query strings into web form inputs to bypass authentication, expose entire customer database tables, or drop enterprise tables.
4. Cybersecurity Countermeasures & Defensive Technologies
Modern Antivirus & EDR Suites
- Signature Matching: Scanning files against databases of known malware hash strings.
- Heuristic & Behavioral Analysis: Detecting abnormal active process activity (unauthorized encryption).
- Sandboxing: Detonating suspicious files inside isolated virtual environments safely.
Firewalls & Perimeter Defense
- Packet Filtering: Inspecting source/destination IP addresses and ports (Layer 3/4).
- Stateful Inspection: Tracking active TCP sessions to block unsolicited incoming packets.
- Next-Gen Firewalls (NGFW): Deep packet inspection analyzing Layer 7 application payloads.
5. Cryptography: Symmetric vs Asymmetric Cryptographic Frameworks
| Dimension | Symmetric Encryption (Secret Key) | Asymmetric Encryption (Public Key) |
|---|---|---|
| Key Architecture | Uses a single identical secret key for both encryption and decryption. | Uses a mathematically linked key pair: a Public Key (freely shared) and Private Key (confidential). |
| Algorithms | AES-128/256, DES, 3DES, Blowfish | RSA, Diffie-Hellman, ECC (Elliptic Curve) |
| Processing Speed | Extremely fast; optimal for bulk data and hard drive encryption. | Computationally intensive and slower; used for key exchange and digital signing. |
| Key Distribution | Dilemma: secret key must be securely transmitted to recipient in advance. | Solves key distribution: sender encrypts with recipient's public key; only recipient's private key can decrypt. |
6. Digital Signatures and Public Key Infrastructure (PKI)
A Digital Signature provides cryptographic authentication, message integrity, and non-repudiation for electronic documents:
The 3-Step Mechanics of a Digital Signature
- 1. Cryptographic Hashing: The electronic document is processed through a one-way mathematical hash function (SHA-256) to produce a unique fixed-length Message Digest / Hash Value.
- 2. Signing with Private Key: The sender encrypts the message digest using their Private Key. This encrypted hash is the Digital Signature, appended to the electronic document.
- 3. Verification with Public Key: The recipient decrypts the signature using the sender's Public Key to retrieve the hash, while independently calculating the hash of the received document. If both hashes match identically, it guarantees document authenticity and tampering-free transmission.
Public Key Infrastructure (PKI): Governed by licensed Certifying Authorities (CAs) (e.g., eMudhra, (n)Code) overseen by the Controller of Certifying Authorities (CCA), issuing digital certificates binding identities to public keys.
Unit 4.2: Biometrics, Cyber Hygiene & The Information Technology Act, 2000
1. Biometric Authentication Paradigms
Physiological Biometrics
- Fingerprint Scanning: Maps ridge endings and bifurcations (minutiae points); used in smartphones and AEPS micro-ATMs.
- Facial Recognition: Analyzes nodal facial geometry (distance between eyes, nose bridge, jawline).
- Iris Scanning: Analyzes intricate circular muscle patterns of the eye iris; highly accurate and virtually unforgeable (Aadhaar).
Behavioral Biometrics
- Keystroke Dynamics: Measures typing cadence, rhythm, key dwell times, and flight intervals.
- Voice Recognition: Analyzes vocal tract frequency acoustics, pitch, and speech cadence.
- Signature Dynamics: Measures pen velocity, stroke angle, and pressure curves during live digital signing.
2. Multi-Factor Authentication (MFA) & E-Payment Cyber Hygiene
Multi-Factor Authentication (MFA) validates identities across multiple independent factors:
Essential Cyber Hygiene for Safe Digital Payments
- Always verify the HTTPS padlock in browser address bars prior to entering banking credentials.
- Never perform financial banking transactions on unencrypted public Wi-Fi networks (use cellular data or a VPN).
- Never disclose CVV numbers, OTP codes, or UPI PINs over the telephone; legitimate banking staff never solicit PINs.
- Enable instant SMS and email transaction alerts to immediately detect and report fraudulent debits.
3. The Information Technology Act, 2000 (IT Act, 2000)
Enacted on June 9, 2000 (effective October 17, 2000), the Information Technology Act, 2000 (Act No. 21 of 2000) is India's foundational statute governing cyber activities, electronic commerce, digital signatures, and cybercrimes, modeled on the UNCITRAL Model Law on Electronic Commerce (1996).
- Grants legal recognition to electronic data interchange (EDI) contracts and digital electronic records.
- Confers legal recognition to digital signatures for authentication of digital transactions.
- Facilitates electronic filing of forms and e-governance documents with public authorities.
- Amends the Indian Penal Code, 1860, Indian Evidence Act, 1872, Bankers' Books Evidence Act, 1891, and RBI Act, 1934 to admit electronic evidence in courts.
4. Landmark Sections & Cyber Offences under the IT Act
| Section | Statutory Heading & Offence | Prescribed Penalty / Punishment |
|---|---|---|
| Section 4 | Legal recognition of electronic records | Confers statutory parity: electronic records satisfy legal mandates requiring written forms. |
| Section 5 | Legal recognition of digital signatures | Digital signatures legally satisfy any statutory requirement for physical signatures. |
| Section 43 | Damage to computer systems, data theft, virus introduction | Civil compensation payable up to Rs. 1 crore to the affected entity. |
| Section 43A | Failure of corporate bodies to protect sensitive personal data | Liable to pay unlimited civil compensation to the affected victim. |
| Section 65 | Tampering with computer source documents | Imprisonment up to 3 years, or fine up to Rs. 2 lakh, or both. |
| Section 66 | Computer-related offences (Hacking & data destruction) | Imprisonment up to 3 years, or fine up to Rs. 5 lakh, or both. |
| Section 66C | Punishment for Identity Theft (stealing passwords, signatures) | Imprisonment up to 3 years, and fine up to Rs. 1 lakh. |
| Section 66D | Cheating by personation using computer resource (Phishing) | Imprisonment up to 3 years, and fine up to Rs. 1 lakh. |
| Section 66E | Violation of bodily privacy (publishing images without consent) | Imprisonment up to 3 years, or fine up to Rs. 2 lakh, or both. |
| Section 66F | Cyber Terrorism (threatening sovereignty or critical infrastructure) | Rigorous imprisonment for life. |
| Section 70 | Unauthorized access to Protected Systems (critical infrastructure) | Imprisonment up to 10 years and fine. |
| Section 79 | Intermediary Liability & "Safe Harbor" Protection | Exempts network providers and social media platforms from liability for third-party content. |
5. Institutional Authorities: CCA, CERT-In & The DPDP Act, 2023
- Controller of Certifying Authorities (CCA - Section 17): Statutory executive authority licensing and regulating Certifying Authorities issuing Digital Signature Certificates.
- Indian Computer Emergency Response Team (CERT-In - Section 70B): National nodal incident response agency forecasting threats and issuing mandatory cyber incident reporting guidelines within 6 hours.
- Digital Personal Data Protection Act, 2023 (DPDP Act): Comprehensive privacy law imposing financial penalties of up to Rs. 250 crores on Data Fiduciaries for data breaches.
Download Module 4 Notes (PDF)
Calicut University • FYUGP 2024 Syllabus
Finished this module?
Continue reading the next module or return to the subject overview.