Saturday, March 13, 2010

Perry4Law Launched Online Dispute Resolution Centre In India

Online dispute resolution (ODR) in India is in its infancy stage and it is gaining prominence day by day. With the enactment of Information Technology Act, 2000 (IT Act 2000) in India, e-commerce and e-governance have been given a formal and legal recognition. Even the traditional arbitration law of India has been reformulated and now India has Arbitration and Conciliation Act, 1996 in place that is satisfying the harmonised standards of UNCITRAL Model. Even the Code of Civil Procedure, 1908 has been amended and section 89 has been introduced to provide methods of alternative dispute resolution (ADR) in India.

However, India is clinging to its traditional core and is shying away from trying new experiments. India is not using information and communication technology (ICT) for dispute resolution whether it pertains to traditional litigation in courts in the form of e-courts or contemporary out of court dispute resolution in the form of online dispute resolution. Fortunately, the first ever Techno-Legal Online Dispute Resolution Centre of India has been launched by Perry4Law that would cater the dispute resolution, training, educational and many more such crucial requirements in India.

There is a lack of training among police, lawyers, judges, etc regarding use of information and communication technology (ICT) for legal, judicial and ADR /ODR purposes. Judges in India need cyber law training, e-courts training, ADR/ODR training, etc that allow them to effectively understand and use ICT for judicial and ADR/ODR purposes.

ODR has many benefits but it has failed to arouse interest of Indians. The present centre has been established at the right moment when backlog of cases has overburdened Indian courts too much. It is high time that the courts in India must also encourage out of court settlements whether through ADR or ODR. The best situation would be when the parties to the disputes actively use ADR/ODR for resolving their disputes.

SOURCE: MYNEWS

E-Judiciary Training And Consultancy Centre Launched By Perry4Law

India is facing mammoth backlog of cases. Now it is absolutely clear that with the present judicial strength and framework, we need a miracle to resolve this problem. One solution that can change this scenario is the use of information and communication technology (ICT) for judicial dispensation in India. In short, e-courts in India can help to resolve this problem.

India is at the initial stages of establishment of electronic courts (e-courts). Though India has done a good job by computerising the courts at various levels yet it is still far from the establishment of even the first e-court of India. It seems the e-courts project of India needs a techno-legal training boost.

Perry4Law and PTLB have launched the first ever e-courts training and consultancy centre of India and perhaps first of its kind in the World. A “prototype” of the same is available to the public and stakeholders till the final website is out.

Efforts in the direction of establishment of e-courts in India have been in process since 2003 and significant development in the sphere of computerisation has already been achieved. It is at this stage that there seems to be stagnation of e-court project of India and this initiative by Perry4Law would facilitate in the smooth and hassle free migration of e-court project to the next level.

India must understand that E-courts are much more that mere connectivity and computerisation of traditional courts. The moment e-filing, presentation, contest and adjudication of the cases in an online environment would start, India would surely be capable of establishing e-courts.

SOURCE: MYNEWS

Wednesday, March 10, 2010

Cyber Crimes In India Are Growing Incessantly

Cyber crimes in India are increasing at a rapid rate. The matter is made worst by a weak and ineffective cyber law of India. Though the law minister of India had declared for a separate enactment to deal with growing cyber crimes yet the proposal seems to have been dumped for the time being.

In India cyber crime are tried under both the traditional Indian Penal Code and the Information Technology Act, 2000 (IT Act 2000). However, police is not aware of the minutiae of the cyber law of India. This makes it extremely difficult to prove most cyber crimes, says leading techno-legal expert of India Praveen Dalal.

Even under the IT Act 2000, cyber crimes investigations in India are not up to the mark. This is because of lack of “cyber forensics” capabilities. The collection and presentation of electronic evidence to prove cyber crimes have posed a challenge to investigation, prosecution agencies and the judiciary in the absence of legal enablement of ICT systems in India.

Cyber-related techno-legal acumen and knowledge are not well developed in India. These require a sound working and practical knowledge of information technology as well as relevant legal knowledge. Cyber laws, international telecommunications laws, cyber forensics, digital evidencing and cyber security pose difficult and sometimes hard to understand legal challenges to the courts. This explains why there are almost no convictions of cyber criminals in India. Judges in India must fill in this legal gap.

India needs a good combination of laws and technology, in harmony with the laws of other countries and keeping in mind common security standards. In the era of e-governance and e-commerce, a lack of common security standards can create havoc for global trade as well as military matters.

Information technology is a double-edged sword that can be used for destructive as well as constructive work. It has now created a fifth dimension in addition to land, sea, air and space, though unlike the other four dimensions, it is completely made and controlled by humans. Till now India has absolutely failed to control this fifth element. Let us hope that the Indian government would do the needful as soon as possible.

Friday, March 5, 2010

E-Courts Training And Consultancy Centre Launched In India

India is at the initial stages of establishment of electronic courts (e-courts). Though India has done a good job by computerising the courts at various levels yet it is still far from the establishment of even the first e-court of India. It seems the e-courts project of India needs a techno-legal training boost.

Perry4Law and PTLB have launched the first ever e-courts training and consultancy centre of India and perhaps first of its kind in the World. A “prototype” of the same is available to the public and stakeholders till the final website is out.

Efforts in the direction of establishment of e-courts in India have been in process since 2003 and significant development in the sphere of computerisation has already been achieved. It is at this stage that there seems to be stagnation of e-court project of India and this initiative by Perry4Law would facilitate in the smooth and hassle free migration of e-court project to the next level.

India must understand that E-courts are much more that mere connectivity and computerisation of traditional courts. The moment e-filing, presentation, contest and adjudication of the cases in an online environment would start, India would surely be capable of establishing e-courts.

SOURCE: GROUND REPORT

Thursday, February 25, 2010

How To Become A Successful Cyber Law Professional And Consultant

Every cyber law career aspirant’s first question is how to become a successful cyber law professional? If you are one of those cyber law diplomas, certificate or degree holder who cannot get a decent job out of the same, perhaps you may also ask the same question.

Although there is no sure shot formula and definite answer for the same but the maxim “well begun is half done” perfectly applies to this question. In my personal opinion the cyber law aspirant must keep in mind his or her ultimate goal of education while pursuing any cyber law course.

Cyber law is a complex area of study hence the students or professionals must rightly choose the most appropriate institution. Merely obtaining any diploma, certificate or even degree is of no use till the same can fetch a good job. Here comes the importance of “skill development and appropriate training”.

A welcome development in this crucial direction has already taken place. The world renowned techno-legal firm Perry4Law has officially launched the cyber law coaching, education, training and internship segment of its PTLB division. The course or program aims at “skill development” of not only those who are pursing cyber law course for the first time but also for those who wish to refine their existing concepts and knowledge of cyber law.

A “contact point” has also been established for effective information sharing and declaring important notices. Those interested in getting world class coaching, education, training and internship must keep a good track of the same.

So my answer to the question posed above is that all cyber law course aspirants must concentrate more upon the “professional aspect” rather than the “academic aspect” of their cyber law education to be a successful professional.

Tuesday, February 23, 2010

First Online Techno-Legal Learning And Training Institution Launched In India

Legal education in India is in the process of transformation. However, there are urgent educational and legal reforms that must be undertaken by India as soon as possible. One such area that requires urgent attention is the amalgamation of legal education with information and communication technology (ICT). For instance, cyber law is an important facet of such an interaction of technology and law.

Indian educational system is more academic than professional. As a result although India has good population that is academically sound yet when it comes to practical and real life experience and work, they do not perform reasonably well. Various studies and research in India have suggested that out of the educated masses only 15 to 25% are fit for being absorbed at job places.

In short, India is running short of institutions that can impart good techno-legal skill development education, training and coaching. Perry4Law and PTLB have launched the first ever “Techno-Legal Online Coaching, Training and Education Centre” in India that aims at developing the skill and talent of the students and professionals seeking a good career in cyber law and allied fields.

Interested students, teachers and partners wishing to be part of the project as well as future projects and initiatives of Perry4Law must contact it as soon as possible. The contemporary skill requirements are multi disciplinary in nature where a computer science student or professional must also have basic level of legal knowledge. The proposed initiative keeps this in mind and students and professionals from all the educational streams are encourage getting themselves enrolled.

The government of India must also come up with a good educational policy as well as sound legal reforms so that legal sector may meet the contemporary international standards and requirements.

SOURCE: GROUND REPORT

Monday, February 22, 2010

Domain Name Protection In India

The original role of a domain name was to provide an address for computers on the Internet. The Internet has, however, developed from a mere means of communication to a mode of carrying on commercial activity.

With the increase of commercial activity on the Internet, a domain name is also used as a business identifier. Therefore, the domain name not only serves as an address for Internet communication but also identifies the specific Internet site. In the commercial field, each domain name owner provides information/services, which are associated with such domain names. Domain names are used in various networking contexts and application-specific naming and addressing purposes.

A domain name is an identification label to define a realm of administrative autonomy, authority, or control in the Internet, based on the Domain Name System (DNS). The Domain Name Systems (DNS) is a hierarchical naming system for computers, services or any resource participating in the internet. It associates different information with domain names assigned to each of the participants. Domain names are also used as simple identification labels to indicate ownership or control of a resource. Such examples are the realm identifiers used in the Session Initiation Protocol (SIP), the Domain keys used to verify DNS domains in e-mail systems, and in many other Uniform Resource Identifiers (URIs).

An important purpose of domain names is to provide easily recognizable names to numerically addressed Internet resources. This abstraction allows any resource (e.g., website) to be moved to a different physical location in the address topology of the network, globally on the internet or locally in an intranet.

In simple terms, Domain name is the address of a web site that is intended to be easily identifiable and easy to remember, such as yahoo.com. These user-friendly addresses for websites help connect computers and people on the Internet. Because they are easy to remember and use, domain names have become business identifiers and, increasingly, even trademarks themselves, such as amazon.com. By using existing trademarks for domain names – sony.com, for example – businesses attract potential customers to their websites.

Domain Name & Intellectual Property Rights

Now, the question that arises is that, “how are Domain Names and Intellectual Property rights (IPR) inter-related?” The answer lies in the understanding of Intellectual property rights. So what are these rights? Intellectual property (IP) is legal property right over creations of the mind, both artistic and commercial, and the corresponding fields of law. Under intellectual property law, owners are granted certain exclusive rights to a variety of intangible assets, such as musical, literary, and artistic works; ideas, discoveries and inventions; and words, phrases, symbols, and designs. The intellectual property rights provide creators of original works economic incentive to develop and share ideas through a form of temporary monopoly.

Originally, Domain Names were conceived and intended to function as an address, but with an increasing number of cases of registered domain names being illegally occupied (cyber squatting), it has posed additional problems in how to handle trademark disputes in cyberspace. Cyber squatting as an offence relates to the registration of a domain name by an entity that does not have an inherent right or a similar or identical trademark registration in its favour, with the sole view and intention to sell them to the legitimate user in order to earn illegal profits. An address in the cyber-space is imperative in the new e-economy for companies and individuals to be easily traceable by their consumers with the emergence of the Internet as an advertising forum, recruiting mechanism, and marketplace for products and services whereby companies doing business have a strong desire to register domain names akin to their products, trade names or trademarks. For example, owners of famous trademarks, such as Haier, typically register their trademarks as domain names, such as www.haier.com. Domain names may be valuable corporate assets, as they facilitate communication with a customer base. With the advancement of Internet communication, the domain name has attained as much legal sanctity as a trademark or trade name and, therefore, it is entitled to protection.

Another issue is the registration of names of popular brands with a slight spelling variation like pesi.com and radiff.com for the sole purpose of diverting traffic to their website through typing errors. ‘A significant purpose of a domain name is to identify the entity that owns the website.’ A domain name should not confuse the consumers as to the origins of the services or products defeating the principal of trademark law. In Rediff Communications Ltd. v. Cybertooth & Another the Bombay High Court while granting an injunction restraining the defendants from using the domain name ‘RADIFF’ or any other similar name, held that when both domain names are considered there is every possibility of internet users being confused and deceived into believing that both domain names belong to one common source and connection although the two belong to two different persons. Again the website using the domain name, ‘Naukari.com’ was held to be confusingly similar to that of the plaintiff, ‘naukri.com’, with a different spelling variant establishing prima facie inference of bad faith.

Domain name protection: Legal aspect

As stated earlier, the constant increase in the use of internet for commercial purposes has greatly increased the level of cyber crimes and other internet related offences. Thus, the legal protection of such domain names is a serious issue which must be dealt with. In order to do so, the Internet Corporation for Assigned Names and Numbers (‘ICANN’), a domain name regulatory authority, adopted a Uniform Domain Name Dispute Resolution Policy (‘UDRP’), which is incorporated into the Registration Agreement, and sets forth the terms and conditions in connection with a dispute between the registrant and any party other than the registrar over the registration and use of an Internet domain name registered. Upon entering into the Core Registration Agreement with ICANN while registering a domain name, one agrees to submit to proceedings commenced under ICANN’s Uniform Domain Name Dispute Resolution Policy. According to the ICANN policy, the registration of a domain name shall be considered to be abusive when all the following conditions are met:

(a) The domain name is identical or misleadingly similar to a trade or service mark in which the complainant has rights.


(b) The holder of the domain name has no rights or legitimate interests in respect of the domain name; and


(c) The domain name has been registered in bad faith.

The term ‘bad faith’ does not simply mean bad judgment but it implies the conscious doing of a wrong with a dishonest purpose. In order to prove bad faith, the following circumstances, if found, are sufficient evidence of bad faith registration:

(a) When there is an offer to sell, rent or otherwise transfer the domain name to the owner of the trademark or service mark, or to a competitor of the complainant for valuable consideration.

(b) When the respondent registers the domain name in order to prevent the owner of the trademark or service mark from reflecting the mark in a corresponding domain name, provided that you have engaged in a pattern of such conduct.

(c) When by using the domain name, a party has intentionally attempted to attract, for commercial gain, internet users to its website or other online location by creating a likelihood of confusion with the trade or service mark of the complainant.

INTA has consistently sought to protect domain names in the cyberspace in the same way as in any other media as these domain names can and often do work as trade marks. For the very same reason, INTA seeks to achieve the following six objectives:

(a) establishment of specific minimum standards for domain name registration;


(b) a publicly accessible domain name database, which contains up-to-date and accurate contact information;


(c) a uniform and easy-to-use dispute resolution policy which renders administrative – not legal – decisions;


(d) a reasonable mechanism whereby exclusions can be obtained and enforced for famous marks;


(e) a “go-slow” approach on the addition of new generic top-level domains (“gTLDs”); and


(f) a voice for trademark owners in the formulation of domain name policy.

INTA believes that when the above-mentioned six objectives are achieved, it would safeguard the trademark rights, which in this case would be the domain names.

Dispute Resolution

INTA believes that a reasonable administrative dispute resolution policy is an essential element of any plan for the administration of domain names on the Internet. Discretion for domain name policy should neither reside with the domain name registrars, nor with the registries. Any dispute policy needs to be consistent across the gTLD space. A lack of uniformity and specificity will only lead to confusion on the part of trademark and domain name holders, fundamental unfairness in the unequal treatment of rights in domain names and therefore inconsistent policies and precedent, chaos in the Internet community. If the goal is to create a system which is fair and predictable, and a relief to the current confusion and uncertainty, there can only be a single uniform system. There is no division among trademark holders on this point. A global marketplace and community requires a single set of global rules.

Therefore, any dispute resolution policy should be limited, at least during an appropriate interim period, to alleged instances of bad-faith activity by the domain name registrant.

Situation in India

Domain Name Issues


With the advancement of e-commerce, the domain names have come to acquire the same value as a trademark or the business name of a company. The value attached to domain names makes it lucrative for cyber criminals to indulge in domain name infringements and the global nature and easier and inexpensive procedure for registering domain names further facilitates domain name infringements. When a person gets a domain name registered in bad faith, i.e. in order to make huge profits by registering a domain name corresponding to a trademark of another person, with an intent to sell the domain name to the trademark owner at a higher price, such activities are known as cyber squatting. The IT Act does not deal with the domain name issues. In India the domain name infringement cases are dealt with according to the trademark law. The issue concerning protection of domain names came up before the Supreme Court of India in the case of Satyam Infoway Ltd. vs. Sifynet Solutions P. Ltd (2004(28) PTC 566). The court, in an authoritative decision has held that internet domain names are subject to the same legal norms applicable to other Intellectual Properties such as trademarks. It was further held by the Supreme Court of India that:

“The use of the same or similar domain name may lead to a diversion of users which could result from such user mistakenly accessing one domain name instead of another. This may occur in e-commerce with its rapid progress and instant (and theoretically limitless) accessibility to users and potential customers and particularly so in areas of specific overlap. Ordinary consumers/users seeking to locate the functions available less than one domain name may be confused if they accidentally arrived at a different but similar website which offers no such services. Such users could well conclude that the first domain name owner had misrepresented its goods and services through its promotional activities and the first domain owner would thereby lose their custom. It is apparent therefore that a domain name may have all the characteristics of a trade mark and could found an action for passing off.”

The court further held that there is no legislation in India which explicitly refers to dispute resolution in connection with domain names. The operation of the Trade Marks Act, 1999 is also not extra territorial and may not allow for adequate protection of domain names. This does not mean that domain names are not to be protected legally to the extent possible under laws of passing off.

However, with most of the countries providing for specific legislations for combating and curbing cyber squatting, India also needs to address the issue and formulate legal provisions against cyber squatting. For settlement of Disputes, WIPO has introduced a new mechanism called ICANN (Internet Corporation for Assigned Names and Numbers) for settlement of disputes relating to domain names. As the parties are given the right to file the case against the decision of ICANN in their respective jurisdictions, the decisions of ICANN is having only persuasive value for the domain users.

We know that a domain name is easy to remember and use, and is chosen as an instrument of commercial enterprise not only because it facilitates the ability of consumers to navigate the internet to find websites they are looking for, but also at the same time, serves to identify and distinguish the business itself, or its goods or services, and to specify its corresponding online internet location. Consequently where a domain name is used in connection with a business, the value of maintaining an exclusive identity becomes critical. As more and more commercial enterprises trade or advertise their presence on the web, domain names have become more and more valuable and the potential for dispute is high. Whereas a large number of trademarks containing the same name can comfortably co-exist because they are associated with different products, belong to business in different jurisdictions etc, the distinctive nature of the domain name providing global exclusivity is much sought after. The fact that many consumers searching for a particular site are likely, in the first place, to try and guess its domain name has further enhanced this value.

The law does not permit any one to carry on his business in such a way as would persuade the customers or clients in believing that the goods or services belonging to someone else are his or are associated therewith. It does not matter whether the latter person does so fraudulently or otherwise. The reasons are:

Honesty and fair play are, and ought to be, the basic policies in the world of business.When a person adopts or intends to adopt a name in connection with his business or services, which already belongs to someone else, it results in confusion and has propensity of diverting the customers and clients of someone else to himself and thereby resulting in injury

Thus, a Domain Name requires a strong, constant and instant protection under all the legal systems of the world, including India. This can be achieved either by adopting harmonization of laws all over the world or by jealously protecting the same in the municipal spheres by all the countries of the world.

Trademarks vs. Domain names

There is a distinction between a trademark and a domain name, which is not relevant to the nature of the right of an owner in connection with the domain name, but is material to the ’scope of the protection’ available to the right. The distinction lies in the manner in which the two operate.

A trademark is protected by the laws of a country where such trademark may be registered. Consequently, a trademark may have multiple registrations in many countries throughout the world.


On the other hand, since the internet allows for access without any geographical limitation, a domain name is potentially accessible irrespective of the geographical location of the consumers. The outcome of this potential for universal connectivity is not only that a domain name would require world wide exclusivity but also that national laws might be inadequate to effectively protect a domain name.

The defense available to such a complaint has been particularized “but without limitation”, in Rule 4 (c) as follows:


(i) Before any notice to the domain name owner/registrant, the use of, or demonstrable preparations to use, the domain name or a name corresponding to the domain name in connection with bona fide offering of goods or services; or


(ii) The domain name owner/registrant (as an individual, business, or other organization) has been commonly known by the domain name, even if it has acquired no trademark or service mark rights; or


(iii) The domain name owner/registrant is making a legitimate non-commercial or fair use of the domain name, without intent for commercial gain to misleadingly divert consumers or to tarnish the trademark or service mark at issue.

These rules indicate that the disputes may be broadly categorized as:

Disputes between trademark owners and domain name owners andBetween domain name owners inter se.

A prior registrant can protect its domain name against subsequent registrants. Confusing similarity in domain names may be a ground for complaint and similarity is to be decided on the possibility of deception amongst potential customers. The defenses available to a complaint are also substantially similar to those available to an action for passing off under trademark law.

As far as India is concerned, there is no legislation, which explicitly refers to dispute resolution in connection with domain names. But although the operation of the Trade Marks Act, 1999 itself is not extra territorial and may not allow for adequate protection of domain names, this does not mean that domain names are not to be legally protected to the extent possible under the laws relating to passing off

In India, the Trademarks Act, 1999 (Act) provide protection to trademarks and service marks respectively. A closer perusal of the provisions of the Act and the judgments given by the Courts in India reveals that the protection available under the Act is stronger than internationally required and provided.


Rule 2 of the UDNDR Policy requires the applicant to determine that the domain name for which registration is sought, does not infringes or violates someone else’s rights. Thus, if the domain name, proposed to be registered, is in violation of another person’s “trademark rights”, it will violate Rule 2 of the Policy.


In such an eventuality, the Registrar is within his right to refuse to register the domain name. This shows that a domain name, though properly registered as per the requirements of ICANN, still it is subject to the Trademarks Act, 1999 if a person successfully proves that he has ‘rights’ flowing out of the Act.

Conclusion

The protection of domain name under the Indian legal system is standing on a higher footing as compared to a simple recognition of right under the UDNDR Policy. The ramification of the Trademarks Act, 1999 are much wider and capable of conferring the strongest protection to the domain names in the world.

The need of the present time is to harmoniously apply the principles of the trademark law and the provisions concerning the domain names. It must be noted that the moment a decision is given by the Supreme Court and it attains finality, then it becomes binding on all the person or institutions in India.


It cannot be challenged by showing any ’statutory provision’ to the contrary. This is so because no statutory provision can override a ‘Constitutional provision’ and in case of a conflict, if any, the former must give way to the latter. This settled legal position becomes relevant when we consider the decision of the Supreme Court in Satyam case (supra) in the light of the above discussion. The various landmark judgments of the Supreme Court have conferred the ’strongest protection’ to the domain names in the world.

References:

(1) Praveen Dalal, Domain Name Protection Law In India.

(2) Praveen Dalal, Intellectual Property Rights In The Digital Era

(3) Praveen Dalal, Domain Name Protection: An Indian Perspective

(4) Praveen Dalal, Online Dispute Resolution In India

Best Online Cyber Law Education And Training In India

Cyber law is a subject that is less appreciated and even lesser applied in India. Whether it is the law making in this regard or its execution and enforcement, by and large cyber law scenario in India needs rejuvenation.

The position in this regard cannot be improved till we inculcate appropriate knowledge and skills at the initial stages of education. Cyber law education in India is at its infancy stage and is maturing towards a qualitative one. However, there is a growing need for good “Techno-Legal Institutions” that can manage the growing demand for cyber law coaching, education and training in India.

Fortunately, one such initiative has already been undertaken by Perry4Law and its Techno-Legal Segment known as Perry4Law Techno-Legal Base (PTLB). Perry4Law is the First and Exclusive Techno-Legal ICT Law Firm of India and is World renowned in techno-legal fields like cyber law, cyber forensics, cyber security, etc.

To cater the growing demands for qualitative techno-legal education in India and abroad, the coaching, training and education segment of PTLB has been launched. Presently, it would be providing “Online Cyber Law Coaching and Internship” to law graduates, law students, graduates and professionals of various disciplines and streams, etc. This is a golden opportunity for those who wish to make a mark in the field of cyber law. Since the seats are “limited” an early enrollment would be beneficial for the serious students.

To facilitate an effective two mode communications between students and teachers on the one hand and Perry4Law on the other, an online “Information Centre” has been established. This information platform would announce and publish all the relevant information regarding the proposed initiative from time to time. Students, teachers and other interested persons are advised to regularly visit this platform. This platform also contains many crucial and important information that must be read before finally applying.

For those who are looking forward for “Domain Specific” and “Highly Skilled Training”, a separate initiative has been launched by another segment of Perry4Law. The same would also be functional very soon.

SOURCE: MYNEWS

Friday, February 19, 2010

Indian Copyright Act 1957 Is Due For Amendments

The Union Cabinet today approved the proposal to introduce a Bill to amend the Copyright Act, 1957. The Ministry of Human Resource Development has proposed the amendments in order to gain clarity, remove operational difficulties and to address the newer issues that have emerged in the context of digital technology and the internet.

Amendments are being made to bring the Act in conformity with the World Intellectual Property Organisation (WIPO) Internet Treaties, namely WIPO Copyright Treaty (WCT) and WIPO Performances and Phonograms Treaty (WPPT) which have set the international standards in these spheres. The WCT deals with the protection for the authors of literary and artistic works such as writings, computer programmes, original databases, musical works, audiovisual works, works of fine art and photographs. The WPPT protects certain “related rights” which are the rights of the performers and producers of phonograms. While India has not yet signed the above two treaties it is necessary to amend domestic legislation to extend the copyright protection in the digital environment.

Amendments related to bring the Act in conformity with WCT and WPPT

Through a new section in the Act, it is proposed to ensure protection to the Right holders against circumvention of effective technological measures applied for purpose of protection of his rights like breaking of passwords etc. while maintaining an appropriate balance between the interests of the right holders on the one hand and of Technology innovators, Researchers and Educational Institutions on the other.

The existing Performers’ Rights are proposed to be further enhanced by introducing a new section to provide exclusive rights compatible with WPPT. “The Moral Rights of Performers” are proposed to be introduced in a new section.

Amendments have been proposed to protect the interests of researchers, students and educational institutions so as to ensure that Technological Measures do not act as a barrier for further development of the technology. These amendments also address the issue of access to information in the digital context and the liability of Internet service providers.

The period of copyright for photographers is proposed to be enhanced to “Life plus sixty years” instead of only sixty years as at present.

Amendment to protect the Music and Film Industry and address its concerns

Statutory licence for version recordings and authorship to ensure that while making a sound recording of any literary, dramatic or musical work the interest of the copyright holder is duly protected.

Term of copyright for cinematograph films has been extended by making the Producers and Principal director as joint authors.

A copyright term of 70 years to Principal Director which automatically extends the copyright term for the Producers for another 10 years provided he enters into an agreement with the Director;

Amendments to address the concerns of the physically challenged

The physically challenged need access to copyright material in specialized formats, e.g. Braille text, talking text, electronic text, large print etc. for the visually challenged and sign language for the aurally challenged. Currently the cost of production of material in such formats is very high. With additional requirement of royalty payments the price of such material to the target groups would be even higher.

A clause is proposed to be introduced as a fair deal clause to allow the production of copies of copyright material in formats specially designed for the physically challenged.

A separate compulsory licensing provision has been proposed to allow for publication of copyright works in formats other than specifically suited for the physically challenged.

Amendments for rights to authors

Amendment is proposed to give independent rights to authors of literary and musical works in cinematograph films, which were hitherto denied and wrongfully exploited, by the producers and music companies.

An amendment is proposed to ensure that the authors retain their right to receive royalties and the benefits enjoyed through the copyright societies.

Another amendment ensures that the authors of the works, particularly songs included in the cinematograph film or sound recordings, receive royalty for the commercial exploitation of such work.

It has been proposed to introduce a system of statutory licensing to ensure that the public has access to musical works over the FM Radio and Television networks and at the same time the owners of copyright works are also not subject to any disadvantages.

It is proposed to amend existing provisions to provide compulsory license through Copyright Board to publish or communicate to the public such work or translation where the author is dead or unknown or cannot be traced or the owner of the copyright work in such work cannot be found.

Other amendments

Amendments are being made for incidental changes, which are required in the context of digital technology to cover “storing of copyrights material by electronic means’.

Amendments in relation to operational facilities, such as registration of Copyright Societies by providing that only authors can register and procedure for tariff schemes of copyright societies and commercial distinction between assignment and licence; and Enforcement of rights such as border measures, disposal of infringing copies and presumption of authorship under civil remedies.

Background

In order to formulate the proposed amendments and to carry out wide-ranging consultations with all stakeholders, the Ministry of Human Resource Development had constituted a 30-member Core Group in the year 2005 under the Chairmanship of the Education Secretary with representatives of the other Ministries/Departments concerned with the subject and other key stakeholders like copyright-industry organizations, stakeholders, subject experts and Institutions of repute in related fields. The Core Group had deliberations at length in five sessions to cover all the provisions of the existing statute and made recommendations with regard to the proposed amendments. The Core Group then created a Drafting Committee to draw up the text of the proposed amendments and to fine-tune the recommendations of the Core Group.

SOURCE: PIB

Friday, February 5, 2010

Best Cyber Forensics Training, Techno-Legal Consultancy And Litigation Support Provider In India

Cyber Forensics is a very recent scientific development and countries all over the World are struggling hard to incorporate the same in their respective legal and judicial systems. Cyber forensics is also a part of legal enablement of ICT system that essentially creates a legal framework incorporating the prerequisites of cyber forensics.

Cyber Forensics is an important field of criminal investigation. However, it requires a sound expertise to be practiced. In India we have very few experts who can provide cyber forensics services in an appropriate manner. Presently, India does not possess the required capabilities and law enforcement machinery finds it really difficult to deal with modern cyber crimes.

As per Praveen Dalal, Managing Partner of Perry4Law and the leading Techno-Legal Expert of India, “Computer Forensics or Cyber Forensics in India has started gaining importance out of the necessity to deal with growing cyber crimes. Though India has taken some steps in the direction of enacting Information and Communication Technology (ICT) related law in the form of Information Technology Act, 2000 (IT Act, 2000), yet by and large it failed to provide a sound and secure law in this crucial direction. The result is too obvious. India has to depend upon foreign experts and institutions/universities for cyber forensics tasks”.

In the absence of governmental efforts in this regard, world renowned techno-legal firms like Perry4Law can be really helpful in fighting cyber crimes in India. Issues pertaining to hacking, data thefts, data security, cyber terrorism, financial frauds, privacy violations, etc must not be taken as lightly as has been done by India.

Perry4Law possesses techno-legal expertise for cyber law, cyber forensics, cyber security training, consultancy and solutions providing to various stakeholders. Perry4Law Techno-Legal Base (PTLB) is India’s first and most prominent techno-legal initiative that is providing techno-legal training to various players. It is also acting as India’s first and most effective Resource Centre for Cyber Forensics (RCCF) and cyber forensics software testing platform.

Perry4Law and PTLB provides techno-legal services in the fields like cyber law, cyber forensics, crime and criminal tracking network and systems (CCTNS), techno-legal training to police officers, lawyers and judges, national mission for delivery of justice and legal reforms (NMDJLR), etc.

The government of India must also take immediate steps to acquire indigenous capabilities at the national level. With the growing threats of cyber terrorism and cyber warfare, India should not be as complacent as it is.

Thursday, February 4, 2010

Cyber Genome Project: The New War Between Crackers And Regulators

The Defense Advanced Research Projects Agency (DARPA) of United States has recently announced one of the most crucial projects managed by it. It has revealed the initiation of “Cyber Genome Program”. The aim of the project is to trace the source of any digital information whether it is a document, malware or any other electronic communication.

As a part of this project, digital artifacts are collected from various live systems such as traditional computers, personal digital assistants, and/or distributed information systems such as cloud computers, from wired or wireless networks, or collected storage media. The format may include electronic documents or software.

According to Praveen Dalal, Managing Partner of Perry4Law and the leading Techno-Legal Expert of India, “The project is a very crucial one for the Internet in general and cyber security in particular. It would raise the standards and challenges for cyber security and cyber forensics and would take them to the next revolutionary level. However, the project requires tremendous techno-legal expertise that can be gathered through “collective expertise” only”.

At the same time the Cyber Genome Project would also involve many other legal issues as well. It would not be an easy ride for the project in the absence of an “International Harmonisation” as acts undertaken under the project may be found offending by many jurisdictions. This may also involve “retaliation actions” by those who may feel offended by such tremendous power over the Internet and interconnected networks, warn Praveen Dalal.

The project is at the very initial stage and till its maturity lots of troubles and doubts would be already removed. Let us hope that the project would be successful in preventing and remedying the cyber threats and cyber crimes worldwide, says Praveen Dalal.

SOURCE: ITVOIR

Wednesday, February 3, 2010

India Needs Good Convergence Laws

Convergence laws in India are in the process of formulation and so are policy related matters. Though the Communication Convergence Bill, 2001 has been formulated, it seems it has not been notified yet. According to experts like Praveen Dalal “India needs strong and effective convergence laws to meet the conflicting mandates of cyber security and free and open access to the telecommunication methods”.

Recently a task force for broadcasting authority of India has been constituted by the government of India. This announcement has been made after the recent constitution of a committee by the Delhi High Court.

There is an emergent need of formulating suitable policies and regulations in this regard. This requirement has been avoided by the government of India for a long period of time. India Government needs to come up with suitable policies and guidelines for effective convergence situation. With the growing demand for spectrum and Internet services, the government has to play a pro-active role so that the supply may match demand, says Praveen Dalal.

The Central Government of India is in the process of creating Broadcasting Authority of India (BAI) that would encompass all the television channels in the nation. The present Press Act of India is around 140-year old and requires changes with the current scenario of broadcasting industry in India. For this the government will be setting up a committee to provide recommendations on the same. Besides, the body is also expected to be considering issues such as that of spectrum and taxation for the media and broadcasting industry.

The government of India has lingered long upon important issues like spectrum allocation, wireless connectivity, rural connectivity, unlicensed spectrum management, etc. It is high time for it to do something in this regard.

SOURCE: ITVOIR

Monday, February 1, 2010

Cyber Security Of India

Policy making requires tremendous insight and far sightedness. The same is missing in India, at least regarding the areas of cyber law and cyber security. On the one hand India has a weak and criminal friendly cyber law whereas on the other hand it does not possess tech-savvy law enforcement machinery. Even lawyers and judges are not that much aware about the nitty-gritty of cyber laws.

This fact is evident from various decisions taken from time to time by various departments of Indian government. Whether it is the home ministry banning the use of Internet or chief justice of India recommending banning of pornography and hate sites or removing of bank account details from the sites none is appreciating the true requirement of Indian cyber law.

The fact remains that India is confused and is taking wrong decisions and is investing on the futile projects. For instance, blocking of a website can be simply bypassed by using proxy servers. Similarly, “phishing” is more dangerous and requires more stringent actions then merely removing the bank account details, enhancing cyber security of various government departments is more effective then banning the use of Internet, etc.

If this was not enough, India did what no nations would dare to do so. It made almost all the cyber crimes “bailable”. India has made its cyberspace a “free zone” and “safe heaven” for cyber criminals and cyber offenders. By succumbing to “industrial lobbying” the government of India has done great damage to the national security of India and cyber security of India.

According to the ICT Trends in India 2009 by Perry4Law, Indian efforts for streamlining use of ICT have further degraded from 2008. The year 2009 saw some major ICT pitfalls and bad decisions were made by the Indian government. Overall the year 2009 can be said to be “Blunder ICT Year” of India.

With these negative developments incessantly happening in India, not much can be expected from Indian government. However, a new ray of hope has been shown by law minister of India by stressing upon separate and effective laws to tackle cyber crimes in India. Only time would tell whether it is another “press statement” or India would be able to tackle the nuisance of cyber crimes.

Similarly, efforts must be made to strengthen cyber security of India especially keeping in mind the growing dangers of “cyber terrorism” and “cyber war” that India is facing. Even cyber security for defence forces of India must be streamlined. However, nothing is more pressing than safeguarding the critical ICT infrastructure of India. Since the legislature in India is almost an extension of executive branch, the political will of the executive must be gathered. Some constructive steps must be urgently taken for ensuring strong cyber law and effective cyber security in India as soon as possible.

AUTHOR: GUNJAN SINGH

SOURCE:
GROUND REPORT

Sunday, January 31, 2010

Urgent Measures Are Needed To Curb Cyber Crimes In India

India has finally shown some concerns towards the growing menace of cyber crimes in India. The government of India has shown an absolute apathy towards growing cyber crimes in India by making almost all the cyber crimes in India “bailable”. Through this process the government made India a safe heaven for cyber criminals. The cyber criminals are virtually free to do whatever they want because at best they can be caught and then have to be set free because Indian cyber law is toothless in this regard. Even these cyber criminals would be very difficult to nab as Indian law enforcement is not well trained to deal with cyber crimes.

India is confused regarding its cyber law and the same has resulted in cyberspace anarchy in India. The Indian political thinking is marred by gross confusion. There are growing incidences of exploitation of Indian cyberspace by cyber criminals and foreign powers. Praveen Dalal, Managing Partner of Perry4Law and the leading Techno-Legal Expert of India sent an open letter to the Government of India including the Prime Minister of India, President of India, Supreme Court of India, Ministry of Parliamentary Affairs, etc and brought to their attention the growing menace of cyber crimes in India.

Reacting immediately, the Law Minister M. Veerappa Moily announced the enactment of separate laws and creation of a specialised agency to deal with the menace of cyber crimes. Cyber crimes in India are increasing in the absence of a strong and stringent cyber law i.e. Information Technology Act 2000 (IT Act 2000). The ICT Trends of India 2009 have proved that India has failed to enact a strong and stringent Cyber Law in India. On the contrary, the Information Technology Act 2008 (IT Act 2008) has made India a “safe heaven” for cyber criminals, say cyber law experts of India.

The problem seems to be multi-faceted in nature. Firstly, the cyber law of India contained in the IT Act, 2000 is highly deficient in many aspects. Thus, there is an absence of proper legal enablement of ICT systems in India. Secondly, there is a lack of cyber law training to the police, lawyers, judges, etc in India. Thirdly, the cyber security and cyber forensics capabilities are missing in India. Fourthly, the ICT strategies and policies of India are deficient and needs an urgent overhaul. Fifthly, the Government of India is indifferent towards the “ICT reforms” in India. This results in a declining ranking of India in the spheres of e-readiness, e-governance, etc. While International communities like European Union, ITU, NATO, Department of Homeland Security, etc are stressing for an enhanced cyber security and tougher cyber laws, India seems to be treading on the wrong side of weaker regulatory and legal regime, says Praveen Dalal.

At last, somebody in the government has shown some concern regarding the growing menace of cyber crimes in India. However, the task is difficult since we do not have trained lawyers, judges and police officers in India. However, at least a step has been taken in the right direction by the law minister of India.

SOURCE: GROUND REPORT

Saturday, January 30, 2010

E-Voting In India

Electronic voting (e-voting) is a process that allows casting of votes through different electronic mechanisms. It includes both casting of votes as well as the counting of the same through electronic methods. The e-voting technology and platform may include punch cards, optical scan voting systems and specialised voting kiosks, telephone, SMS, etc.

The Gujarat State Election Commission is discussing plans to introduce voting through SMSes and over the Internet for municipal and panchayat elections. Previously, India has adopted the use of Electronic Voting Machines (EVMs) for elections. EVMs have revolutionised the Indian election process. EVMs have many advantages over the traditional paper based voting system. However, all the advantages are futile if they can be abused and the election results can be manipulated.

According to Praveen Dalal, Managing Partner of Perry4Law and the leading Techno-Legal Expert of India, “E-Voting in India must be accompanied by proper plan and adequate information and communication technology infrastructure. At the same time special emphasis must be given to the cyber security aspect of e-voting mechanism in India”.

While the use of e-voting may help expanding the voting community yet there must be a suitable policy and regulation to prevent and remedy misuses arising out of such voting system. The crucial question is what if e-voting is proved to be tainted subsequently after cyber forensics appraisal and a Government has been formed on the basis of that voting? Will the Election Commission declare such elections null and void? Will the President of India declare a re-election? Will the Supreme Court of India take cognisance of this fact, asks Praveen Dalal.

The attempt of Gujarat State is a good one in the right direction provided some basic safeguards and plans are formulated in advance. Every new system brings its own peculiar problems and the proposed e-voting system would also face the same. Only time would tell how effective this system would be?

AUTHOR: RAM KAUSHIK

Thursday, January 28, 2010

The Future Of Indian Cyber Law And Cyber Forensics

Cyber law of India is an essential part of legal enablement of ICT systems in India. The same must be strengthened by good cyber forensics capabilities in India. The present cyber law of India is not only a weak piece of legislation but also ineffective against the contemporary cyber crimes. Similarly, it is also violating human rights of Indian in the cyberspace. The bottom line is that Indian needs a good techno-legal expertise to tackle the growing menace of cyber crimes.

The information technology is a double edge sword, which can be used for destructive as well as constructive work. Thus, the fate of many ventures depends upon the benign or vice intentions, as the case may be, of the person dealing with and using the technology. For instance, a malicious intention forwarded in the form of hacking, data theft, virus attack, etc can bring only destructive results unless and until these methods have been used for checking the authenticity, safety and security of the technological device which has been primarily relied upon and trusted for providing the security to a particular organization. For instance, the creator of the “Sasser worm” has been hired as a “security software programmer” by a German firm, so that he can make firewalls, which will stop suspected files from entering computer systems.

These methods may also be used for checking the authenticity, safety and security of one’s technological device, which has been primarily relied upon and trusted for providing the security to a particular organization. In fact, a society without protection in the form of “self help” cannot be visualized in the present electronic era.

Thus, we must concentrate upon securing our ICT and e-governance bases before we start encashing their benefits. The same can be effectively achieved if we give due importance to this fact while discussing, drafting and adopting policies decisions pertaining to ICT in general and e-governance in particular. The same is also important for an effective e-commerce base and an insecure and unsafe ICT base can be the biggest discouraging factor for a flourishing e-commerce business. The factors relevant for this situation are too numerous to be discussed in a single work. Thus, it would be better if we concentrate on each factor in a separate but coherent and holistic manner. The need of the hour is to set priority for a secure and safe electronic environment so that its benefits can be reaped to the maximum possible extent.

Prevalence of Cyber Crime

The prevalence of Cyber crime throughout the world has frustrated law enforcement agents and legislators alike. According to an article published in the American Criminal Law Review, at least half of all businesses in the United States alone have been the victims of cyber crime or some sort of security breach. Cyber Crime is such a detrimental type of offense not only because of the type of damage that it can do to individuals and businesses but also because of the costs involved in cyber crime. These costs are most often associated with the repair of a computer system or network. There are also costs associated with the compromise of data that often occurs. This is particularly costly because of the damage that it can do to the reputation of a business and organizations. Customers can become more apprehensive about shopping at a franchise that has experienced computer security problems or going to a bank that has been the victim of cyber crime. For this very reason, the article points out that some businesses and organizations that have been affected by Cyber Crime do not report breaches in security.

Cyber Crimes in India

India is on the verge of a technology revolution and the driving force behind the same is the acceptance and adoption of Information and Communication Technology (ICT) and its benefits. This technology revolution may, however, fail to bring the desired and much needed result if we do not adopt a sound and country oriented e-governance policy. A sound e-governance policy presupposes the existence of a sound and secure e-governance base as well. The security and safety of various ICT platforms and projects in India must be considered on a priority basis before any e-governance base is made fully functional. This presupposes the adoption and use of security measures more particularly empowering judiciary and law enforcement manpower with the knowledge and use of cyber forensics and digital evidencing.

Cyber Forensics and Its Need

The concepts of cyber security and cyber forensics are not only interrelated but also indispensably required for the success of each other. The former secures the ICT and e-governance base whereas the latter indicates the loopholes and limitations of the adopted measures to secure the base. The latter also becomes essential to punish the deviants so that a deterrent example can be set. There is, however, a problem regarding acquiring expertise in the latter aspect. This is so because though a computer can be secured even by a person with simple technical knowledge the ascertainment and preservation of the evidence is a tough task. For instance, one can install an anti-virus software, firewall, adjust security settings of the browser, etc but the same cannot be said about making a mirror copy of hard disk, extracting deleted files and documents, preserving logs of activities over internet, etc. Further one can understand the difficulty involved in the prosecution and presentation of a case before a court of law because it is very difficult to explain the evidence acquired to a not so techno savvy judge. The problem becomes more complicated in the absence of sufficient numbers of trained lawyers in this crucial field.

The Cyber Forensics has given new dimensions to the Criminal laws, especially the Evidence law. Electronic evidence and their collection and presentation have posed a challenge to the investigation agencies, prosecution agencies and judiciary. The scope of Cyber Forensics is no more confined to the investigation regime only but is expanding to other segments of justice administration system as well. The justice delivery system cannot afford to take the IT revolution lightly. The significance of cyber forensics emanates from this interface of justice delivery system with the Information Technology.

The growing use of IT has posed certain challenges before the justice delivery system that have to be met keeping in mind the contemporary IT revolution. The contemporary need of Cyber Forensics is essential for the following reasons:

(a) The traditional methods are inadequate: The law may be categorized as substantive and procedural. The substantive law fixes the liability whereas the procedural law provides the means and methods by which the substantive liability has to contended, analyzed and proved. The procedural aspects providing for the guilt establishment provisions were always there but their interface with the IT has almost created a deadlock in investigative and adjudicative mechanisms. The challenges posed by IT are peculiar to contemporary society and so must be their solution. The traditional procedural mechanisms, including forensic science methods, are neither applicable nor appropriate for this situation. Thus, “cyber forensics” is the need of the hour. India is the 12th country in the world that has its own “Cyber law” (IT Act, 2000). However, most of the people of India, including lawyers, judges, professors, etc, are not aware about its existence and use. The traditional forensic methods like finger impressions, DNA testing, blood and other tests, etc play a limited role in this arena.

(b) The changing face of crimes and criminals: The use of Internet has changed the entire platform of crime, criminal and their prosecution. This process involves crimes like hacking, pornography, privacy violations, spamming, phishing, pharming, identity theft, cyber terrorisms, etc. The modus operendi is different that makes it very difficult to trace the culprits. This is because of the anonymous nature of Internet. Besides, certain sites are available that provides sufficient technological measures to maintain secrecy. Similarly, various sites openly provide hacking and other tools to assist commission of various cyber crimes. The Internet is boundary less and that makes the investigation and punishment very difficult. These objects of criminal law will become a distant reality till we have cyber forensics to tackle them.

(c) The need of comparison: There is a dire need to compare the traditional crimes and criminals with the crimes and criminal in the IT environment. More specifically, the following must be the parameters of this comparison:

a. Nature of the crime
b. Manner/Methods of commission of the crime,
c. Purpose of the crime,
d. Players involves in these crimes, etc.

Thus, Cyber Forensics is required to be used by the following players of criminal justice system:

a. Investigation machinery- Statutory as well as non-statutory
b. Prosecution machinery, and
c. Adjudication machinery- Judicial, quasi-judicial or administrative.
d. Jurisdictional dilemma: The Internet is not subject to any territorial limits and none can claim any jurisdiction over a particular incidence. Thus, at times there is conflict of laws. The best way is to use the tool of Cyber Forensics as a “preventive measure” rather than using it for “curative purposes”.

The growing use of ICT for administration of all the spheres of our daily life cannot be ignored. Further, we also cannot ignore the need to secure the ICT infrastructures used for meeting these social functions. The threat from “malware” is not only apparent but also very worrisome. There cannot be a single solution to counter such threats. We need a techno-legal “harmonized law”. Neither pure law nor pure technology will be of any use. Firstly, a good combination of law and technology must be established and then an effort must be made to harmonies the laws of various countries keeping in mind common security standards. In the era of e-governance and e-commerce a lack of common security standards can create havoc for the global trade in goods and services. The tool of Cyber Forensics, which is not only preventive but also curative, can help a lot in establishing a much needed judicial administration system and security base.

Cost of Computer Security Breach

Many CEOs and CIOs are slow to invest in computer security because they do not know how to measure their Return on Investment (ROI). No one has shown them the actual costs associated with not investing in computer security. The objective of this paper is to provide the information security officer with objective data about the actual cost of computer security breaches to commercial companies. The information presented herein can be used as input into the ROI analyses to support security procurements.

How Cost Is Measured

In the commercial world, the cost of a cyber security breach is measured by both “tangibles” and “intangibles.” The tangibles can be calculated based on estimates of:

(a) Lost business, due to unavailability of the breached information resources
(b) Lost business, that can be traced directly to accounts fleeing to a “safer” environment
(c) Lost productivity of the non-IT staff, who have to work in a degraded mode, or not work at all, while the IT staff tries to contain and repair the breach
(d) Labor and material costs associated with the IT staff’s detection, containment, repair and reconstitution of the breached resources
(e) Labor costs of the IT staff and legal costs associated with the collection of forensic evidence and the prosecution of an attacker
(f) Public relations consulting costs, to prepare statements for the press, and answer customer questions
(g) Increases in insurance premiums
(h) Costs of defending the company in any liability suits resulting from the breached company’s failure to deliver assured information and services.

Not all of these tangible costs will occur with each breach; some will only occur with major, well-publicized breaches. The intangibles refer to costs that are difficult to calculate because they are not directly measurable, but are nevertheless very important for business. Many of these intangibles are related to a “loss of competitive advantage” that results from the breach. For example, a breach can affect an organization’s competitive edge through:

(a) Customers’ loss of trust in the organization
(b) Failure to win new accounts due to bad press associated with the breach
(c) Competitor’s access to confidential or proprietary information.

Even the military environment has similar cost issues. In the military, the tangible costs are measured in human lives, replacement costs of equipment, and prolonged military operations. The intangibles would include loss of tactical advantage, loss of international prestige, and impaired negotiating positions.

Hypothetical Examples of the Cost Impact of Security Breaches

Forrester Research1 estimated the tangible and intangible costs of computer security breaches in three hypothetical situations. Their analysis indicated that, if thieves were to illegally wire $1 million from an on-line bank, the cost impact to the bank would be $106 million. They also estimated that, in the hypothetical situation that cyber techniques are used to divert a week’s worth of tires from an auto manufacturer; the auto manufacturer would sustain losses of $21 million. Finally, they estimated that if a law firm were to lose significant confidential information, the impact would be almost $35 million. Does this sound unrealistic? Remember, that Forrester used both tangibles and intangibles in their estimates, including the loss of confidential information and reputation. The sections below present the results of analyses of real world cost impacts of cyber events, using largely tangible costs as the means of estimating impact.

Real World Examples of Cost Impacts

Cost Impacts on Individual Companies


In December, 1998 Ingram Micro, a PC wholesaler, had to shut down its main data center in Tucson, Arizona due to an electrical short. While the reason for the shutdown was not a security breach, the loss of Ingram’s Internet business and electronic transactions from 8:00 AM to 4:00 PM mimicked what could happen with a Distributed Denial of Service (DDOS) attack or a major intrusion. As a result of its one day of lost sales and system repairs, Ingram estimates that it lost a staggering $3.2 million. This figure is comparable to Forrester’s projection of a $21 million loss for an auto manufacturer who is unable to get tires for a week. To estimate the cost impact of the types of breaches that happen daily to companies, one can turn to the annual surveys of the Computer Security Institute (CSI) (www.gosci.com) and the FBI. For the past five years, the CSI-FBI “Computer Crime and Security Survey” has been a major source of information on the frequency and impact of computer security breaches, through their polling of commercial, non-profit, and government organizations. Their Year 2000 report was based on a survey of 643 information security professionals from organizations throughout the United States. Typically, the respondents represent organizations that have already made some commitment to computer security. In the 1999 survey, 91% of the respondents had firewalls, 42% had intrusion detection systems, and 34% were using digital certificates in their companies. Of the 643 respondents in the year 2000, 90% had detected cyber attacks on their organizations; and 74% reported financial losses associated with those attacks. Of the total sample of respondents, 42% (273 people) were able to quantify their exact losses, which totaled $265,589,940, or $972,857 cost impact per organization across all types of breaches.


The highest impact came from theft of proprietary information, reported by 66 people. Their total losses came to $66,708,000 or $1,010,727 cost impact per organization for theft of proprietary information. While this may seem like a lot, the average cost impact of theft of proprietary information in their 1999 survey was even greater -- $1,847,652. The sabotage of data or networks was reported by 61 respondents, for a total loss of $27,148,000 or an average loss of $445,049 per organization. This loss was significantly higher than the 1999 average loss of $163,740 associated with sabotage. While these estimates are presumably based on tangible costs to the company, one can infer that the respondents are very aware of and sensitive to the intangible costs of a tarnished reputation that could result from media treatment of security breaches. I base this conclusion, on some interesting data in the 1999 survey. In 1999, 48% of those respondents who had been subjected to an intrusion did not report it. Among the most important reasons cited for their decision not to report those breaches were the fear of negative publicity and the use of the information by competitors.

Cost Impacts across Industries

Some research and consulting firms such as Computer Economics (www.computereconomics.com) measure the impact of computer breaches across several companies or industries. Computer Economics5 has estimated that in 1999 businesses around the globe spent $12.1 billion to combat the effect of computer viruses. Their estimate was based on tangibles such as lost productivity, network down time, and expenses incurred to get rid of the virus infections. The ILOVEYOU virus and its copycats have also been studied for their financial impacts across industries. According to Computer Economics the ILOVEYOU virus and its variants caused $6.7 billion in damage in the first five days.

The FBI, in their testimony before the Senate Subcommittee on Technology, Terrorism and Government Information, cites the Yankee Group’s estimate that industries around the world lost $1.2 billion to the DDOS attacks on e-commerce in February 2000. Their estimate was based on lost capitalization, lost revenues and the costs of security upgrades.

The Cost of Piracy

A different form of security breach – software piracy – also has a cost impact across the software industry. International Planning and Research, an independent research firm, estimated that software vendors lost $12.2 billion 1999 due to software piracy. They estimate that one out of three pieces of software used by businesses around the world is pirated copies.

The financial impact of computer security breaches has been quantified by several sources. The best estimate of the impact of security breaches on a single organization can be found in the CSI-FBI survey of over 600 organizations. They concluded that the average cost impact of security breaches on each organization is over $972,000 per year.

Hacking Technique, How Hackers Do It

Every day, hackers compromise systems using these attacks. Being aware of how these attacks are performed, you can raise awareness within your organization for the importance of building and maintaining secure systems.

Many organizations make the mistake of addressing security only during installation, and then never revisit it. Maintaining security is an ongoing process, and it is something that must be reviewed and revisited periodically. Using the information in this article, you can try hacking into your organization’s datacenter, high-end server, or other system to determine where basic attacks would succeed. Then, you can address security weaknesses to prevent unauthorized users from attacking the system.

Tricks

A trick is a “mean crafty procedure or practice...designed to deceive, delude, or defraud.” Hackers use tricks to find short cuts for gaining unauthorized access to systems. They may use their access for illegal or destructive purposes, or they may simply be testing their own skills to see if they can perform a task. Given that most hackers are motivated by curiosity and have time to try endless attacks, the probability is high that eventually they do find a sophisticated method to gain access to just about any environment. However, these aren’t the types of attacks we address in this article, because most successful intrusions are accomplished through well-known and well-documented security vulnerabilities that either haven’t been patched, disabled, or otherwise dealt with. These vulnerabilities are exploited every day and shouldn’t be.

Finding Access Vulnerabilities

What generally happens is that an advanced or elite hacker writes a scanning tool that looks for well-known vulnerabilities, and the elite hacker makes it available over the Internet. Less experienced hackers, commonly called “script kiddies,” then run the scanning tool 24 x 7, scanning large numbers of systems and finding many systems that are vulnerable. They typically run the tool against the name-spaces associated with companies they would like to get into.

The script kiddies use a list of vulnerable IP addresses to launch attacks, based on the vulnerabilities advertised by a machine, to gain access to systems. Depending on the vulnerability, an attacker may be able to create either a privileged or non privileged account. Regardless, the attacker uses this initial entry (also referred to as a “toe-hold”) in the system to gain additional privileges and exploit the systems the penetrated system has trust relationships with, shares information with, is on the same network with, and so on.
Once a toe-hold is established on a system, the attacker can run scanning tools against all the systems connected to the penetrated system. Depending on the system compromised, these scans can run inside an organization’s network.

Finding Operating System Vulnerabilities

As mentioned previously, hackers first look for vulnerabilities to gain access. Then they look for operating system (OS) vulnerabilities and for scanning tools that report on those vulnerabilities.

Finding vulnerabilities specific to an OS is as easy as typing in a URL address and clicking on the appropriate link. There are many organizations that provide “full disclosure” information. Full disclosure is the practice of providing all information to the public domain so that it isn’t known only to the hacker community.

Attacking Solaris OE Vulnerabilities

Let’s use Solaris 2.6 OE as an example. A well-known vulnerability, for which patches are available, is the sadmind exploit. Hackers frequently use this vulnerability to gain root access on Solaris 2.6 OE systems. Using only a search engine and the CVE number, found by searching through the Mitre site listed previously, it is possible to find the source code and detailed instructions on how to use it. The entire process takes only a few minutes. The hacker finds the source code on the Security Focus web site and finds detailed instructions on the SANS site.

Tools

Hackers use a variety of tools to attack a system. Each of the tools we cover in this article has distinct capabilities. We describe the most popular tools from each of the following categories:
(a) Port scanners
(b) Vulnerability scanners
(c) Rootkits
(d) Sniffers

Port scanners are probably the most commonly used scanning tools on the Internet. These tools scan large IP spaces and report on the systems they encounter, the ports available and other information, such as OS types. The most popular port scanner is Network Mapper (Nmap).The Nmap port scanner is described as follows on the Nmap web site:


Nmap (“Network Mapper”) is an open source utility for network exploration or security auditing. It was designed to rapidly scan large networks, although it works fine against single hosts. Nmap uses raw IP packets in novel ways to determine what hosts are available on the network, what services (ports) they are offering, what operating system (and OS version) they are running, what type of packet filters/firewalls are in use, and dozens of other characteristics. Nmap runs on most types of computers, and both console and graphical versions are available. Nmap is free software, available with full source code under the terms of the GNU GPL3.


Nmap is an excellent security tool because it allows you to determine which services are being offered by a system. Because Nmap is optimized to scan large IP ranges, it can be run against all IP addresses used by an organization, or all cable modem IP addresses provided by an organization. After using Nmap to find machines and identify their services, you can run the Nessus vulnerability scanner against the vulnerable machines.


Nmap supports an impressive array of scan types that permit everything from TCP SYN (half open) to Null scan sweeps. Additional options include OS fingerprinting, parallel scan, and decoy scanning, to name a few. Nmap supports a graphical version through xnmap. For more information about Nmap,

Vulnerability Scanners

This section describes tools available for scanning vulnerable systems. Vulnerability scanners look for a specific vulnerability or scan a system for all potential vulnerabilities. Vulnerability tools are freely available. We focus on the most popular and best-maintained vulnerability scanner available, Nessus. The Nessus vulnerability tool is described on the Nessus web site:
The “Nessus” Project aims to provide to the Internet community a free, powerful, up-to-date and easy to use remote security scanner. A security scanner is a software which will remotely audit a given network and determine whether bad guys (aka ‘crackers’) may break into it, or misuse it in some way. Unlike many other security scanners, Nessus does not take anything for granted. That is, it will not consider that a given service is running on a fixed port—that is, if you run your web server on port 1234, Nessus will detect it and test its security. It will not make its security tests regarding the version number of the remote services, but will really attempt to exploit the vulnerability. Nessus is very fast, reliable and has a modular architecture that allows you to fit it to your needs.

Nessus provides administrators and hackers alike with a tool to scan systems and evaluate vulnerabilities present in services offered by that system. Through both its command line and GUI-based client, Nessus provides capabilities that are invaluable. Running Nessus is much more convenient in its GUI mode. For more information about Nessus, refer to their web site.

Rootkits

The term rootkit describes a set of scripts and executables packaged together that allow intruders to hide any evidence that they gained root access to a system. Some of the tasks performed by a rootkit are as follows:


(a) Modify system log files to remove evidence of an intruder’s activities.
(b) Modify system tools to make detection of an intruder’s modifications more difficult.
(c) Create hidden back-door access points in the system.
(d) Use the system as a launch point for attacks against other networked systems.

Sniffers

Network sniffing, or just “sniffing,” is using a computer to read all network traffic, of which some may not be destined for that system. To perform sniffing, a network interface must be put into promiscuous mode so that it forwards, to the application layer, all network traffic, not just network traffic destined for it.

The Solaris OE includes a tool called snoop that can capture and display all network traffic seen by a network interface on the system. While being relatively primitive, this tool can quite effectively gather clear-text user IDs and passwords passing over a network. Many popular protocols in use today such as Telnet, FTP, IMAP, and POP-3 do not encrypt their user authentication and identification information. Once a system is accessed, an intruder typically installs a network sniffer on the system to gain additional user ID and password information, to gather information about how the network is constructed, and to learn.

Techniques

In this section, we describe two different attack scenarios to demonstrate how easily a hacker can gain access to an unsecured system. These successful attacks simulate the following scenarios:
(a) Attacks from the Internet
(b) Attacks from employees

In both attack scenarios, after the hacker establishes a root account, the hacker wants to maintain access to the system and establish additional privileges to access the rest of the environment. We correlate the tools that the hacker uses to find vulnerabilities, gain access, and establish additional privileges.

Attacks From the Internet

In this scenario, a hacker uses the Nessus vulnerability scanner to locate a system running Solaris 2.6 OE that has not been protected from the sadmind remote procedure call (RPC) service vulnerability. Let’s see how the sadmind exploit works against the victim system. After the hacker gains access, the hacker uses a rootkit to gain and maintain root access. The header of the sadminindex.c program provides the following information on its usage: The author of the sadmindex program made things even easier by providing example stack pointer values. Some tinkering with the sp value was necessary in this example to get the exploit to work; however, it didn’t take much trial and error because the next offset tried was 0xefff9588.

Attacks From Employees

In this scenario, an employee has user access privileges to the system, however, the employee is not authorized to have root access privileges. This scenario is very common. It usually occurs when accounts are left logged on and systems are insecure, thus providing an intruding employee the opportunity to perform unauthorized actions. The ability of malicious internal users to gain additional privileges on Solaris OE systems is a very real security issue. Unfortunately, it is frequently overlooked or ignored by administrators and managers who say, “That could never happen here” or “We have to trust all of our employees.” Serious security incidents occur in situations like these.

Most systems have different types of users. Authorized individuals are systems administrators, operators, database administrators, hardware technicians, and so forth. Each class of user has permissions and privileges defined by user ID and group IDs on the system. Most of these users do not have a root password or permission to use it.

Once on a system, malicious users and intruders can use buffer overflow attacks to gain root privileges. For example, on August 10th, 2001, a buffer overflow against xlock was released. (The xlock executable is a utility for locking X-windows displays.) This utility is useful to attack because it is installed with the setuid root command, due to its need to authorize access to the display when it is locked. A quick search through a few web sites provides the sample source code, which only has 131 lines of code.

Now that the attacker has root privileges on the system, it is easy to use a sniffer, install back doors, maintain and gain additional access privileges using rootkits, and perform tricks and subsequent attacks.

Future of Cyber Crime and Conclusion

What's in the future for Internet Crime and Punishment? With every new avenue opening up on the Internet, comes more possibilities for criminal intent. The difference now and in the future is, technology and human services are now in place or coming into place, to make these individuals or organizations accountable for their actions. Laws and punishments for even the smallest Internet crimes are now on the books, or in the process of being created. Make no mistake; once something is on the Internet, it is fact. It is traceable and punishable. No matter how hard someone tries to cover it up, erase it or disassociate from their actions, once the footprint is made, it can't be unmade. Somewhere there is a way to track that footprint. Law enforcement across the globe will enforce it.

The Internet has not only drawn people together, it has drawn international crime fighting agencies together in a common purpose. The Internet is not a free playground anymore. It is a global arena. Internet crime will take the punch.

Referred Works

[1] Praveen Dalal, Cybercrime and cyberterrorism: Preventive defense for cyberspace violation

[2] Praveen Dalal, Cybersecurity in India: An Ignored World

[3] Praveen Dalal, ICT Strategy in India: The Need of Rejuvenation

[4] Techtalk, India Caught On The Wrong Foot Of Cyber Anarchy

[5] Praveen Dalal, Private defence in cyberspace

[6] Praveen Dalal, Techno-Legal Compliance In India: An Essential Requirement

[7] Praveen Dalal, Cyber Forensics In India

[8] Noack, David. Computer Viruses Cost $12 Billion in 1999”, APB News, Jan. 20, 2000

[9] “Love Bug Damage Costs Rise to $6.7 Billion” Press release by Computer Economics, May 9, 2000

[10] “Statement for the Record of Guadalupe Gonzalez, Special Agent in Charge, Phoenix Field Division, FBI on Cybercrime” before the Special Field Hearing, Senate Committee on Judiciary, Subcommittee on Technology, Terrorism, and Government Information, Washington, DC

[11] Noack, David. “Businesses Use $12 Billion of Stolen Software” APB News, May 25, 2000,

[12] Salkeyer, Alex. “Who Pays When a Business Is Hacked?” Business Week Online: Daily Briefing, May23, 2000.

[13] “Cyber attacks rise from outside and inside corporations”, Press Release from Computer Security Institute

[14] “Ninety percent of survey respondents detect cyber attacks, 273 organization report $265,589,940 in financial losses”, Press Release from Computer Security Institute, March 22, 2000

[15] Howe, Carl; McCarthy, John C.; Buss, Tom; and Davis, Ashley. “The Forrester Report: Economics of Security”, February, 1998

[16] Webster’s Third New International Dictionary, Merriam-Webster, Inc., Springfield, MA, 1986, page 2442.

[17] Common Vulnerability and Exposures (CVE)

[18] NMap

[19] Nessus

[20] Amit Sachan, Future Of Cyber Crime