Daily current affairs on DailyCA
DailyCA NotesStudy notes for competitive exams My revisionsRevisions

Malware, Phishing and Network Attacks

Basic 5 min read Updated

Saved in this browser only. See all revisions due

Key points

  • CIA triad: Confidentiality, Integrity, Availability
  • A virus needs a host file; a worm spreads by itself
  • A Trojan disguises itself and usually does not self-replicate
  • Ransomware encrypts data and demands payment
  • Whaling targets senior officers; vishing uses calls and smishing uses SMS
  • In pharming the user reaches a fake site even after typing the correct address
  • DDoS attacks availability; MITM intercepts communication
On this page
  1. The CIA triad
  2. Types of malware
  3. Social engineering and phishing
  4. Network attacks

The CIA triad

Information security rests on three goals:

  • Confidentiality: only authorised people see the information, achieved through encryption and access control.
  • Integrity: information is not altered without authority, protected by hashing and digital signatures.
  • Availability: information is there when needed, supported by backups, RAID and protection against denial-of-service attacks.

Types of malware

MalwareKey featureNote
VirusAttaches to a host file and spreads when that file runsNeeds a host
WormSelf-replicates across a networkNeeds no host file
Trojan HorseLooks legitimate but hides a malicious functionUsually does not self-replicate
RansomwareEncrypts files and demands paymentWannaCry, 2017
SpywareSecretly collects user informationRuns in the background
KeyloggerRecords keystrokes to capture passwordsSteals login details
AdwareDisplays unwanted advertisementsPop-ups
RootkitHides deep in the system to keep privileged accessHard to detect
Logic BombTriggers when a date or condition is metDormant until then
BotnetNetwork of infected machines controlled remotelyUsed for DDoS and spam

Key point

A virus needs a host file; a worm does not. Any question describing self-replication without a host is pointing at a worm.

Social engineering and phishing

Social engineering exploits human trust, fear or urgency rather than technology.

VariantChannel or target
PhishingMass fake e-mails or websites
Spear phishingAimed at one specific person or group
WhalingAimed at senior officers such as the Director or Registrar
VishingVoice calls
SmishingSMS messages
PharmingDNS manipulation sends a correctly typed address to a fake site

Other techniques include baiting with an infected pen drive, tailgating into a restricted area behind an authorised person, and Business Email Compromise, where a fraudster posing as a senior officer demands an urgent transfer or gift vouchers.

Network attacks

  • DoS and DDoS: flooding a server so it stops responding. This attacks availability.
  • Man-in-the-Middle: intercepting communication between two parties, a real risk on public wi-fi.
  • SQL Injection: inserting malicious database commands through a web form.
  • Zero-day attack: exploiting a flaw for which no patch yet exists.

Exam tip

Look for one decisive feature: does it need a host, does it spread by itself, does it pretend to be legitimate, or does it wait for a condition. That single test removes three options.

Practice questions

Answer all, then check. Explanations appear after checking.

1Which type of malware replicates itself and spreads across a network without attaching to a host file?
2In information security, the CIA triad stands for:
3A phishing attack carried out through SMS text messages is known as:
4A phishing attack aimed specifically at senior officials such as the Director or Registrar is called:
5Malware that encrypts the files on a computer and demands payment for the decryption key is called:

Finished this topic? Tick it off.

Saved in this browser only. See all revisions due