Title: Critical Infrastructure Protection Role of CERTIn
1Critical Infrastructure ProtectionRole of
CERT-In
Dr. Gulshan Rai Director Indian computer
Emergency Response Team (CERT-In) Department of
Information Technology Ministry of Communications
Information Technology New Delhi
2Internet Infra in INDIA
Critical Infrastructure protection Role of
CERT-In
3Nature of Cyber Crimes
- Web defacement
- Scanning and probing of Infrastructure
- Denial of Service and Distributed Denial of
Service attacks - Injection of Malicious Codes
- Virus
- Bots
- Crimeware
- Data Theft and Data Manipulation
- Phishing
- Identity Theft
- Financial Frauds
- Web espionage
- Social engineering scams
4Challenges in resolving cyber crimes
-
- Organised online crimes
- Borderless crime
- Delayed response
- Lack of evidence
4
Critical Infrastructure protection Role of
CERT-In
5How CERT-In can help investigation
- Threat reports
- Impact of major worms and viruses
- Surveys on current state of security in Indian
Industry - Profiling the attackers/cyber criminals
- Technical parameters
- Software/hardware components exploited
- Cyber Forensics
- Help in collection and preserving the evidence
and investigation - Training
- Early watch and warning
- Analysis of Traffic data to find imminent threats
6CERT-In Work Process
CERT-In Work Process
Critical Infrastructure protection Role of
CERT-In
7Enabling legal provisions
- The Information Technology (Amendment) Act, 2008
cover the following Legal Provisions for
tackling cyber security related crimes and
violations- -
- Data Protection
- - Corporate bodies to implement best
practices to protect data - - Heavy Compensation to affected user
(Section 43 A) -
- Breach of Confidentiality Privacy
- - Intermediary and service providers
not to disclose personal information of
subscriber/user acquired - by them while providing services
- - Penalties in form of Imprisonment and Fine
(Section 72 A) -
- Pornography including child
pornography (Section 67A and B) -
- Computer related offences
- - Expansion of list of offences
(Section 66 expanded) - - Identity theft (Section 66C)
- - Phishing (Section 66D)
- - Spoofing and SPAM (Section 66A)
- - E-Commerce Frauds (Section 66 C and D)
Critical Infrastructure protection Role of
CERT-In
8CERT- In website
Critical Infrastructure protection Role of
CERT-In
9Thank you Incident Response HelpDesk Phone 1800
11 4949 FAX 1800 11 6969 e-mail incident at
cert-in.org.in http//www.cert-in.org.in