Malware, Phishing and Network Attacks
Saved in this browser only. See all revisions due
Key points
- CIA triad: Confidentiality, Integrity, Availability
- A virus needs a host file; a worm spreads by itself
- A Trojan disguises itself and usually does not self-replicate
- Ransomware encrypts data and demands payment
- Whaling targets senior officers; vishing uses calls and smishing uses SMS
- In pharming the user reaches a fake site even after typing the correct address
- DDoS attacks availability; MITM intercepts communication
The CIA triad
Information security rests on three goals:
- Confidentiality: only authorised people see the information, achieved through encryption and access control.
- Integrity: information is not altered without authority, protected by hashing and digital signatures.
- Availability: information is there when needed, supported by backups, RAID and protection against denial-of-service attacks.
Types of malware
| Malware | Key feature | Note |
|---|---|---|
| Virus | Attaches to a host file and spreads when that file runs | Needs a host |
| Worm | Self-replicates across a network | Needs no host file |
| Trojan Horse | Looks legitimate but hides a malicious function | Usually does not self-replicate |
| Ransomware | Encrypts files and demands payment | WannaCry, 2017 |
| Spyware | Secretly collects user information | Runs in the background |
| Keylogger | Records keystrokes to capture passwords | Steals login details |
| Adware | Displays unwanted advertisements | Pop-ups |
| Rootkit | Hides deep in the system to keep privileged access | Hard to detect |
| Logic Bomb | Triggers when a date or condition is met | Dormant until then |
| Botnet | Network of infected machines controlled remotely | Used for DDoS and spam |
Key point
A virus needs a host file; a worm does not. Any question describing self-replication without a host is pointing at a worm.
Social engineering and phishing
Social engineering exploits human trust, fear or urgency rather than technology.
| Variant | Channel or target |
|---|---|
| Phishing | Mass fake e-mails or websites |
| Spear phishing | Aimed at one specific person or group |
| Whaling | Aimed at senior officers such as the Director or Registrar |
| Vishing | Voice calls |
| Smishing | SMS messages |
| Pharming | DNS manipulation sends a correctly typed address to a fake site |
Other techniques include baiting with an infected pen drive, tailgating into a restricted area behind an authorised person, and Business Email Compromise, where a fraudster posing as a senior officer demands an urgent transfer or gift vouchers.
Network attacks
- DoS and DDoS: flooding a server so it stops responding. This attacks availability.
- Man-in-the-Middle: intercepting communication between two parties, a real risk on public wi-fi.
- SQL Injection: inserting malicious database commands through a web form.
- Zero-day attack: exploiting a flaw for which no patch yet exists.
Exam tip
Look for one decisive feature: does it need a host, does it spread by itself, does it pretend to be legitimate, or does it wait for a condition. That single test removes three options.
Practice questions
Answer all, then check. Explanations appear after checking.
Finished this topic? Tick it off.
Saved in this browser only. See all revisions due