Internet provides a medium and platform for exchange of information or data i.e. text messages, pictures, images, vedios, executables, softwares and everything in electronic form.
Any information in digital form traveling via internet is prone to attack because it is being transferred via public channel.
The very nature of internet provides insecurity as everything is accessible and all information travels among common public medium. The information can be easily snooped and hacked if due care is not taken to ensure its security and confidentiality.
The following factors provide breeding ground for cyber criminals:
(i) Anonymity
(ii) Time lapse between crime committed and detection of criminal is much longer and detection is far more difficult than the real world crime. This is due to lack of technical skills in police force.
(iii) Controversy in legal issues like jurisdiction and applicable laws.
(iv) Global impact
The areas of major concerns of security of information are:
- Confidentiality:
The confidential data e.g. – Credit card data , user’s password , confidential documents having sensitive information etc demands an extra effort in technology to ensure security to maintain its security to maintain its integrity. Various techniques used for ensuring data confidentiality are:
a) SSL
b) Encryption
c) Use of Digital Signatures
d) Cryptography
- Authenticity:
Authenticity of the sender i.e. how to ascertain the identity of sender, in other words, is the sender of email, document etc the person he claims to be?
This is important because the technological advancement provides ways to impersonate other person to such an extent that the name and email address of the sender can be used to prima facie indicate that the email is sent by him but in actual the originator is altogether a different person. So, one has to be very cautious.
- Integrity:
This is important to ensure that the data is not altered while transmitting i.e. the received message is exactly same as the sent message.
- Non-Repudiation:
This is important to ensure that the originator cannot later repudiate that he did not sent the message or email. This impact greatly in e-commerce activities like online trading, online shopping, online contracts etc.