Week Ten- Revised notes COSC
Types of Threats:
- Virus:
- program that replicates itself and spreads to other files
- Can display a message or imagine, delete files or reformate your drive
- Usually combines with worms
- Worms:
- Malware that spreads from computer to computer
- Does Not necessary need to be activated to replicate itself
- Trojan horse:
- Program masking real intentions
- Example: game that masks intent to steal passwords
- Adware:
- Presents
- Pop-up, pop-under, overlays used for click fraud
- Spyware:
- Program that obtains users information via keystocks (keyloggers), copies of emails/chats or screenshots
- Usually used for identity theft
- Sometimes used on student or corporate computers
- Ransome:
- Encrypting or threatening to publish information unless a ransom is paid.
- Recent variant is cryptojacking
Malware at Scale: Bots
- Bots:
- Malware that turns client computers into “slaves”.
- Botnet:
- A network of captured computers
- Responds to attackers commands
- Spambots, adware for click fraud
Phishing:
- A deceptive online attempt by a third party to get confidential information for financial gain.
- “Fishing” for information
- No malware involved
- Online con artists who trick people into voluntarily giving what they requested.
- Offers to give you something as long as you respond with certain information
- Eg. email scams, account verification, etc.
Sniffing:
- Eavesdropping programs that monitor information traveling on a network like wiretapping.
- Positives:
- uses include troubleshooting Network traffic
- negatives(criminals use):
- capturing private information such as usernames passwords message
- recording instant messages or other communications
- getting cookies to log in
Spoofing:
- Pharming: Spoofing a website (often used for phishing purposes)
- Spam/ junk websites: sites promise some product or services but are simply collection of ads (often contain malware)
Cyber Vandalism: → Methods to intentionally disrupt, defend or destroy a site.
- Hackers: individuals who intend to gain unauthorized access to a computer.
- Black hats: hackers who act with intention of causing harm
- White hats: Harkers hired to help locate or fix security Flaws by hacking into the site externally .
- Grey Hats: Hackers who believe they are pursuing greater cause by breaking in and revealing system flaws also known as trolls.
- Script kiddies: people who do not know what they are doing
Threat Modeling:
- asset: what we want to protect
- Advertisement: who i want to protect my assets from
- Threats: How bad the consequences are if i fail
- Risk: the likelihood that particular threat against a particular asset will actually occur.
- Adversary capability: what it is able to do achieve its aims