Fundamentals of Cyber Security Notes
Complete study material for CY402 – Fundamentals of Cyber Security for RGPV CSE-Cyber Security / Cyber Security IV Semester. This page covers cyber crime, common cyber attacks, cyber law, digital evidence, cybercrime investigation concepts and important tools and methods used in cybercrime.
These notes are organized for concept understanding, revision and RGPV examination preparation.
About CY402 Fundamentals of Cyber Security
Cyber security deals with protecting computers, networks, applications, digital information and users from unauthorized access, misuse, disruption and other cyber threats.
CY402 introduces students to the basic concepts of cyber crime and its different forms. It also introduces the legal and evidentiary aspects of cyber crime, including electronic records, digital signatures and electronic communication.
The later part of the course introduces common cybercrime tools and attack techniques such as password cracking, keyloggers, spyware, viruses, worms, Trojan horses, denial-of-service attacks, wireless attacks and phishing.
CY402 Unit-wise Study Material
Introduction to Cyber Crime
Cyber crime refers to unlawful activities in which computers, computer networks, digital systems or online services are involved as a target, tool or environment.
- Introduction of Cyber Crime
- Challenges of Cyber Crime
- Classification of Cyber Crimes
- E-Mail Spoofing
- Spamming
- Internet Time Theft
- Salami Attack / Salami Technique
Challenges of Cyber Crime
Cyber crime presents several challenges because digital systems can cross geographical boundaries and attackers may operate anonymously. Investigation can also be difficult because electronic evidence may be distributed across different systems and jurisdictions.
E-Mail Spoofing
E-mail spoofing involves manipulating the apparent identity or sender information of an email so that the message appears to originate from another source.
Spamming
Spamming is the practice of sending large quantities of unwanted or unsolicited messages, commonly through email or other communication platforms.
Internet Time Theft
Internet time theft refers to unauthorized use of another person's or organization's internet access resources.
Salami Attack
A salami attack, also called the salami technique, involves making very small unauthorized changes or deductions that may individually appear insignificant but can accumulate into a meaningful gain.
Common Cyber Crimes and Cyber Criminals
- Web Jacking
- Online Frauds
- Software Piracy
- Computer Network Intrusions
- Password Sniffing
- Identity Theft
- Cyber Terrorism
- Virtual Crime
- Hackers
- Insurgents and Extremist Groups
- Web Server Hacking
- Session Hijacking
Web Jacking
Web jacking refers to unauthorized control, manipulation or redirection involving a website.
Online Fraud
Online fraud involves deceptive activities carried out through internet-based systems to obtain money, information or another unauthorized benefit.
Software Piracy
Software piracy involves unauthorized copying, distribution or use of software in violation of applicable licensing or copyright restrictions.
Identity Theft
Identity theft occurs when someone obtains and uses another person's identifying information without authorization.
Session Hijacking
Session hijacking refers to unauthorized takeover or misuse of an active communication session. Strong authentication, secure session management and encrypted communication are important defensive measures.
Cyber Crime and Criminal Justice
- Concept of Cyber Crime and the IT Act, 2000
- Hacking
- Teenage Web Vandals
- Cyber Fraud and Cheating
- Defamation
- Harassment and E-Mail Abuse
- Other IT Act Offences
- Monetary Penalties
- Jurisdiction and Cyber Crimes
- Nature of Criminality
- Strategies to Tackle Cyber Crime
- Trends in Cyber Crime
Cyber Crime and the IT Act, 2000
The Information Technology Act, 2000 forms an important part of India's legal framework dealing with electronic records, electronic communication and various technology-related offences.
Cyber Fraud and Cheating
Cyber fraud and cheating involve deceptive online activities intended to cause wrongful loss or obtain an unauthorized benefit.
Cyber Crime Jurisdiction
Jurisdiction becomes an important issue in cyber crime because an incident can involve users, servers, service providers and evidence located in different geographical regions.
Strategies to Tackle Cyber Crime
- User awareness and cyber security education
- Strong authentication practices
- Regular software and security updates
- Secure network configuration
- Monitoring and incident response
- Proper preservation of digital evidence
Electronic Evidence and Information Technology Law
- Indian Evidence Act, 1872 vs Information Technology Act, 2000
- Status of Electronic Records as Evidence
- Proof and Management of Electronic Records
- Relevancy of E-Evidence
- Admissibility of E-Evidence
- Probative Value of E-Evidence
- Proving Digital Signatures
- Proof of Electronic Agreements
- Proving Electronic Messages
Electronic Records as Evidence
Electronic records can become important sources of evidence in technology-related investigations. Their reliability depends on issues such as authenticity, integrity, relevance and proper handling.
Relevancy, Admissibility and Probative Value
Relevancy
Relevancy considers whether the evidence has a meaningful connection with the matter being investigated.
Admissibility
Admissibility concerns whether evidence satisfies the applicable legal requirements for acceptance.
Probative Value
Probative value relates to the extent to which evidence helps establish or support a fact under consideration.
Digital Signatures
Digital signatures provide a mechanism for establishing authenticity and integrity in electronic communication when implemented using appropriate cryptographic systems.
Tools and Methods in Cybercrime
- Proxy Servers and Anonymizers
- Password Cracking
- Keyloggers and Spyware
- Viruses and Worms
- Trojan Horses
- Backdoors
- DoS and DDoS Attacks
- Buffer and Overflow
- Attacks on Wireless Networks
- Phishing
- Methods and Techniques of Phishing
Proxy Servers and Anonymizers
Proxy servers can act as intermediaries between a user and another network service. Anonymizing technologies attempt to reduce the direct visibility of a user's network identity.
Password Cracking
Password cracking refers to attempts to discover passwords or authentication credentials. From a defensive perspective, strong passwords, multi-factor authentication, rate limiting and secure password storage are important protections.
Keyloggers and Spyware
A keylogger is software or hardware designed to record keyboard activity. Spyware is software intended to monitor or collect information about a user or system without appropriate authorization.
Virus and Worms
| Virus | Worm |
|---|---|
| Typically attaches itself to a host file or program. | Can self-propagate across systems or networks. |
| Usually requires execution of the infected host or file. | Can spread without requiring the same type of host-file attachment. |
Trojan Horse
A Trojan horse is a malicious program that is presented as or disguised as legitimate software or content.
Backdoor
A backdoor provides a method of bypassing normal authentication or security controls to obtain unauthorized access.
DoS and DDoS Attacks
A Denial-of-Service attack attempts to make a service or resource unavailable to legitimate users. A Distributed Denial-of-Service attack uses multiple systems or sources to generate the attack traffic.
Buffer Overflow
A buffer overflow occurs when a program writes more data into a memory buffer than the buffer is designed to hold. Secure programming practices, bounds checking, memory protection mechanisms and timely patching help reduce this risk.
Attacks on Wireless Networks
Wireless networks can face threats related to unauthorized access, weak authentication, insecure configurations and interception.
Phishing
Phishing is a social engineering technique in which an attacker attempts to deceive a target into revealing sensitive information or performing an unwanted action.
CY402 Quick Revision
| Unit | Major Topics |
|---|---|
| Unit 1 | Cyber Crime, challenges, e-mail spoofing, spamming, internet time theft and salami attack. |
| Unit 2 | Web jacking, online fraud, software piracy, network intrusion, identity theft, cyber terrorism, hackers and session hijacking. |
| Unit 3 | Cyber crime and criminal justice, IT Act 2000, hacking, cyber fraud, harassment, jurisdiction and strategies to tackle cyber crime. |
| Unit 4 | Electronic records, e-evidence, admissibility, probative value, digital signatures, electronic agreements and messages. |
| Unit 5 | Proxy servers, password cracking, keyloggers, spyware, viruses, worms, Trojans, backdoors, DoS/DDoS, buffer overflow, wireless attacks and phishing. |
CY402 Important Exam Questions
- Define cyber crime. Explain the major challenges associated with cyber crime.
- Explain e-mail spoofing, spamming, internet time theft and salami attack.
- Explain web jacking and online fraud.
- What is identity theft? Explain its impact.
- Explain computer network intrusion and password sniffing.
- Explain cyber crime and the Information Technology Act, 2000.
- Explain cyber fraud, cheating, defamation, harassment and e-mail abuse.
- Discuss jurisdiction issues related to cyber crimes.
- Explain electronic records as evidence.
- Explain relevancy, admissibility and probative value of electronic evidence.
- Explain digital signatures and their role in electronic transactions.
- Differentiate between virus and worm.
- Explain Trojan horses, backdoors and spyware.
- Explain DoS and DDoS attacks.
- What is phishing? Explain phishing methods and techniques.
- Explain buffer overflow and attacks on wireless networks.
Frequently Asked Questions – CY402
What is CY402?
CY402 is Fundamentals of Cyber Security in the supplied RGPV CSE-Cyber Security / Cyber Security IV Semester syllabus.
How many units are in CY402?
The supplied syllabus contains five units, covering cyber crime, cyber criminals, cyber crime and criminal justice, electronic evidence, and tools and methods in cybercrime.
Which topics are important in CY402?
Important areas include cyber crime, e-mail spoofing, online fraud, identity theft, IT Act 2000, electronic evidence, digital signatures, malware, DoS/DDoS attacks, buffer overflow and phishing.
Is this CY402 page useful for RGPV exams?
Yes. The page organizes the prescribed syllabus into readable explanations, revision points and exam-oriented questions.
How to Prepare CY402 for RGPV Exams
CY402 contains both conceptual and terminology-based topics. A good preparation strategy is to understand each cyber crime or security concept first and then learn its characteristics, examples, impact and defensive perspective.
- Read every unit once to understand the overall syllabus.
- Prepare short definitions for important terms.
- Learn differences such as virus vs worm and DoS vs DDoS.
- Revise IT Act and electronic evidence concepts according to the prescribed syllabus.
- Practice explaining cyber attacks in your own words.
- Before the examination, revise the important questions listed above.
Disclaimer and Study Reference
This page is educational study material prepared around the supplied RGPV CY402 syllabus. Legal provisions and cyber security practices can change over time. For legal or regulatory questions, students should consult the current official legal text and authoritative sources.
RGPV syllabus reference: CSE-Cyber Security / Cyber Security, IV Semester – CY402 Fundamentals of Cyber Security.