Module II: Comprehensive Notes on Information System Threats and Attacks
Attack Basic Concepts
Definition of Attack: An attack is any attempt to gain unauthorized access to a system or to deny authorized users from accessing the system. It is important to note that an attack is an attempt and does not necessarily guarantee a successful breach.
Purpose: The primary purpose of an attack is to violate one or more of the three basic properties of security: confidentiality, integrity, and availability of data.
Attacker: An individual or group of individuals who strives to violate a system’s overall security. Attacks can vary in kind and origin.
Computer Crime: This occurs when an attacker breaks a specific law or regulation during an attack.
Classifications of Attacks
Active vs. Passive Attacks
Active Attack: These attacks attempt to alter system resources or affect their operation, thereby compromising the security principles of integrity or availability. Examples include:
Denial-of-Service (DoS) attack
Spoofing
Mixed threat attack
Network-based active attacks:
Man-in-the-middle
Man-in-the-browser
ARP poisoning
Ping flood
Ping of death
Smurf attack
Host-based active attacks:
Buffer overflow
Heap overflow
Stack overflow
Format string attack
Passive Attack: These attacks attempt to learn or make use of information from the system without affecting system resources, thereby compromising the confidentiality principle. Examples include:
Computer and network surveillance
Network-based passive attacks:
Wiretapping
Fiber tapping
Port scan
Idle scan
Host-based passive attacks:
Keystroke logging
Data scraping
Backdoor
Syntactic vs. Semantic Attacks
Syntactic Attack: These attacks use malicious software to disrupt or damage a computer system or network.
Virus: A self-replicating program that can attach itself to another program or file to reproduce. It can hide in unlikely locations in memory, change its digital footprint each time it replicates, and attach to various files to execute its code.
Worm: A self-sustaining running program that does not need another file to copy itself. Worms replicate over a network using protocols and often exploit known vulnerabilities. They can be used for industrial espionage to monitor server activities and transmit data back to the creator.
Trojan Horse: Designed to perform legitimate tasks while simultaneously performing unknown and unwanted activities. They can install keyboard loggers or backdoors and are often embedded in trial versions of commercial software.
Semantic Attack: These involve the modification of information or the dissemination of incorrect information to attack users' confidence. The goal is to cause a computer system to produce errors and unpredictable results.
Cyber Defamation: Publishing defamatory material against another person using computers or the internet through a virtual medium.
Pump-and-dump: An illegal scheme that boosts a stock price through recommendations based on false or exaggerated statements. Perpetrators sell their positions after the hype leads to a higher share price.
Broad Categories of Attacks
Military and Intelligence Attacks: Attempts to acquire secret information from law enforcement or defense agencies (e.g., defense strategies, sealed legal proceedings). Disclosure can cause serious damage and high costs for reformulating plans, such as revealing the location of a submarine fleet.
Business Attacks: Attempts to acquire sensitive data from commercial organizations. Disclosure can violate laws and cause a loss of market position (e.g., leaking a secret soft drink formula).
Terrorist Attacks: Coordinated attacks that coincide with physical attacks. By targeting communication and infrastructure control systems, attackers hinder the ability of emergency responders (police, fire) to react.
Grudge Attacks: Launched by disgruntled employees or customers for revenge. These attacks may destroy data or disclose damaging information for vengeance rather than reward.
Fun Attacks: These have no real purpose other than providing a rush or ego satisfaction for the attacker. The underground hacker community associates prestige with compromising secure systems.
Attacker Capabilities, Inhibitors, and Amplifiers
Attacker Capability
Attacker capability is the ability to use appropriate means (knowledge, time, expertise, and tools) and opportunity to exploit vulnerabilities. Common components include:
Software and Technology
Facilities
Education and Training
Methods and Books of Manuals
Threat Inhibitors
Factors that decrease the likelihood of a successful attack:
Fear of Capture: Perception of being identified and caught.
Fear of Failure: Belief that they will fail, especially if sensitive to the opinions of others.
Level of Technical Difficulty: Stronger target defenses usually deter attackers, though some may view it as a challenge to prove their skills.
Cost of Participation: High financial costs, time commitments, or equipment requirements.
Sensitivity to Public Perception: Fear of public disfavor.
Law Enforcement Activity: The presence of strong, tested laws and aggressive enforcement.
Target Vulnerability: Perceived state of protection.
Peer Perception: Lack of acknowledgement from peers for certain targets.
Threat Amplifiers
Factors that increase the likelihood of an attack:
Peer Pressure: Striving for prestige within a group.
Fame: Seeking recognition for actions.
Access to Information: The prospect of gaining useful information.
Changing High Technology: The cycle of new technology release, discovery of weaknesses, and subsequent exploitation.
De-skilling through Scripting: Automated scripts that allow less-skilled attackers to perform complex tasks.
Skills and Education Levels: As general technical literacy increases, so does the pool of potential attackers.
Attacker Motivations and Characteristics
Core Motivational Factors
Political: Furthering the cause of a political organization.
Religion: Religious conflicts driving system penetration.
Power: Demonstrating capability through system attacks.
Terrorism: Use of systems for propaganda and dissemination.
Curiosity: Unfocused and difficult to quantify.
Personal Gain: Various rewards and financial incentives.
Table: Characteristics and Targets of Attackers
Attacker | Target | Goals | Motivation | Damages |
|---|---|---|---|---|
Nation State Actors | Governments and businesses running critical infrastructure | Steal sensitive info, disrupt enemy capabilities, create international incidents | National advantage | Extremely high |
Cybercriminals | Companies with customer/financial data | Steal sensitive info to sell or directly steal money | Money | High |
Hacktivists | Organizations conflicting with their beliefs | Cause disruption for attention or steal data to damage targets | Promote religion, politics, or cause | Medium |
Script Kiddies | Networks/websites with minimal security | Gain access to show off or deface a website | Impress friends/gain credit | Low |
Malware: Definitions and Forms
Malware (Malicious Software): An umbrella term for any malicious program or code harmful to systems. It is intentionally designed to cause damage to computers, servers, networks, or mobile devices by taking partial control. Programs acting secretly against user interests (e.g., the Sony rootkit that reported on listening habits) are also considered malware.
Common Forms of Malware
Adware: Software designed to display unwanted advertisements, often disguised as legitimate or piggybacked on other programs.
Spyware: Secretly observes user activities without permission and reports back to the author.
Virus: Attaches to another program and replicates by modifying other code.
Worm: Self-replicating malware that spreads over a network, usually destroying data.
Trojan Horse: Represents itself as useful to trick users, then provides unauthorized access to steal information.
Ransomware: Encrypts files or locks the device, demanding a ransom (often in cryptocurrency) for recovery.
Rootkit: Provides administrator privileges to the attacker while remaining hidden from users and the operating system.
Keylogger: Records all keystrokes to steal usernames, passwords, and credit card details.
Malicious Cryptomining (Cryptojacking): Installed by a Trojan to use the victim's hardware to mine cryptocurrency for the attacker.
Exploits: Takes advantage of system bugs. Linked to Malvertising, where legitimate sites pull malicious content that installs via "drive-by download" (no clicking required).
Backdoors: Bypasses normal authentication for future invisible access. Can be installed by Trojans, worms, or implants.
Browser Hijacker: Changes browser behavior, installs unwanted plugins, and redirects traffic.
Crimeware: Used to commit crimes for financial gain.
RAM Scraper: Harvests data being stored in the system's memory (RAM).
Rogue Security Software (Scareware): Tricks users into thinking they have a security problem so they will install fake tools.
Bot: An infected device performing harmful tasks. A Botnet is a large group of bots focused on a single task.
Malware Infection and Evolution
Signs of Malware Infection
System slowdowns or high resource usage (fan whirling at full speed).
Unexpected pop-up ads.
Repeated crashes, freezes, or Blue Screen of Death (BSOD).
Mysterious loss of disk space.
Increased internet activity.
Browser homepage changes or new toolbars/extensions.
Antivirus products stop working or cannot be updated.
Historical Trends in Malware
The 1980s: Modern history begins with Elk Cloner (), which infected Apple II systems via floppy disks. Theoretical self-reproducing automata concepts date back to .
The 1990s: Rise of macro viruses targeting Microsoft Word and other Office applications.
2002 to 2007: Instant messaging worms spread via AOL AIM, MSN Messenger, and Yahoo Messenger.
2005 to 2009: Proliferation of adware. Around , lawsuits against adware companies led to many shutting down.
2007 to 2009: Shift to social networks (MySpace, later Facebook and Twitter) for phishing and malicious extensions.
2013: Launch of CryptoLocker, which collected approximately by the last quarter of . A copycat variant collected over from victims between and .
2013 to 2017: Ransomware became "king," peaking with major outbreaks in .
2017 to Present: Rise of cryptojacking due to the popularity of cryptocurrency mining.
Malware Detection and Defense
Detection Techniques
Signature Based: Searches for a specific sequence of bits (signature) embedded in the code. Uses string or pattern matching against a database. Primarily identifies known malware families.
Heuristic Based (Behavior/Anomaly Detection): A proactive technique with two steps: recording normal behavior and then watching for deviations (abnormal behavior) during an attack.
Specification Based: Monitors applications according to their system specifications to check for abnormal behavior based on defined system rules.
Comparison of Detection Techniques
Technique | Advantages | Disadvantages |
|---|---|---|
Signature Based | Detects known malware easily; uses fewer resources; widely available | Cannot detect unknown malware; database grows exponentially |
Heuristic Based | Detects known/unknown/new malware; identifies potential actions | Requires updates; high resource usage (time/space); high false positives |
Specification Based | Detects known/unknown/new malware; low false positives | High false negatives; inefficient for brand new malware; time-consuming to develop |
Specific Malware Defenses
Adware: Install anti-adware; disable pop-ups; uncheck "default" install boxes.
Backdoor/Crimeware: Use firewalls, IDS/IPS, SIEM, and strong/regularly updated passwords.
Bots/Botnets: Anti-malware software; network monitoring for botnet activity.
RAM Scraper: Harden POS systems; separate payment systems from non-payment systems; comply with data standards.
Ransomware: Maintain up-to-date backups; wipe and reboot if locked; user training; software patching.
Rootkit: If infected, format the hard drive and start over; maintain OS patches.
Virus/Worm: Keep antivirus signatures updated; deploy firewalls; exercise care with links and attachments.
Denial of Service (DoS)
Definition: An attack seeking to make a network resource unavailable to intended users by disrupting services. It violates the Availability property of the CIA Triad.
Impacts of DoS
Extortion: Demanding payment to stop the attack.
Sabotage: Competitors attacking websites for market share.
Brand Damage: Loss of reputation due to downtime.
Financial Losses: Lost sales or advertising revenue.
Types of DoS Attacks
Application-layer Flood: Flooding a service with requests from a spoofed IP address.
Distributed Denial of Service (DDoS): Requests sent from many locations simultaneously. Often utilizes "zombie" machines—compromised devices controlled by the attacker. DDoS is harder to shut down and the source is difficult to identify due to random distribution.
Unintended DoS: Caused by sudden, non-malicious popularity.
The Slashdot Effect: Traffic surge from news site links.
The Reddit Hug of Death: Similar surge from Reddit popularity.
Countermeasures
Purchase more Bandwidth: Handling traffic spikes.
Network Hardware Configuration: Dropping DNS responses from outside or incoming ICMP packets.
Protect DNS Servers: Implementing redundancy for the over domain names.
Transparent Mitigation: Using technology to allow legitimate users access without showing outdated content during an attack.
Load Balancers: Distributing traffic across multiple servers.
Social Engineering
Definition: A technique relying on human interaction to influence individuals to violate security protocols or divulge confidential information. It exploits a lack of security awareness and human psychological weaknesses.
Life Cycle of Social Engineering
Information Gathering: Collecting data on the victim's interests.
Engaging with Victim: Opening a conversation to build trust.
Attacking: Retrieving information from the target.
Closing Interaction: Shutting down communication without arising suspicion.
Cialdini’s Six Principles of Influence
Reciprocity: Returning a favor (e.g., free samples before a request).
Commitment and Consistency: Honoring a commitment made in writing or orally to maintain self-image.
Social Proof: Doing what others are doing.
Authority: Obeying authority figures.
Liking: Being easily persuaded by liked individuals.
Scarcity: Creating urgency through perceived lack of availability.
Social Engineering Attack Types
Baiting: Leaving infected physical devices (like USBs) for victims to find.
Honey Trap: Forming fake relationships for money or PII.
Phishing: Masquerading as a trusted source (e.g., email spoofing).
Spear Phishing: Targeting specific organizations/individuals.
Smishing: SMS-based phishing.
Vishing: Voice-based phishing (VoIP).
Whaling: Targeting high-profile individuals (CEOs, politicians).
Pretexting: Lying to gain access to privileged data.
Quid Pro Quo: Offering a service (like tech support) in exchange for access.
Tailgating (Piggybacking): Following someone into a secure area.
Waterholing: Infecting a trusted website used by a specific group.
Organizational Countermeasures
Training & Inoculation: Regular security awareness and frequent testing multiple times a year.
OPSEC (Operations Security): Identifying and protecting friendly actions that could be useful to an attacker.
Multi-factor Authentication (MFA): Requiring users to know something (password), have something (token), and be something (biometrics).
Vendor Risk Management: Continuous monitoring of third-party cybersecurity ratings.
Waste Management: Securely disposing of physical information ("dumpster diving" prevention).
Notable Social Engineers
Kevin Mitnick: U.S. hacker and consultant known for high-profile arrests in .
Susan Headley: Expert in pretexting and psychological subversion (-).
Badir Brothers: Ramy, Muzher, and Shaddle Badir (blind from birth) who used Brille-display computers for vishing fraud in Israel during the .
Frank Abagnale: Former con man and impostor () whose life was depicted in the movie Catch Me If You Can.
Questions & Discussion
Passive vs. Active Scenarios:
Capturing/replaying fund transfer instructions: Active.
Modifying packet header addresses: Active.
Network message flooding: Active.
Eavesdropping on website visits: Passive.
Facebook Hack (Sept ): Harvesting millions of phone numbers and email addresses. Possible goal: Data resale or secondary phishing; Motivation: Financial gain or personal gain.
Malware Scenarios:
Site redirection: Browser hijacker.
System error messages: Virus or generic Malware.
Program recording typing: Keylogger.
Gradual slowdown and total failure: Worm or Virus consuming resources.
Email Verification Test: A help desk email requests Name, Email Login, Password, DOB, and Alternate Email to save an account from deletion. Action: Do not respond; this is a phishing attempt. Help desks define passwords as sensitive and never request them.
PAG-IBIG Website Timeout: This is likely an unintended DoS or "unintended Denial of Service" rather than a malicious DDoS, caused by a legitimate surge in users attempting to update records simultaneously, similar to the Slashdot effect.
E-card Attachment: If a friend sends an unexpected attachment for an e-card, the safe action is to verify the sender's intent through a different communication method before clicking, as it may be a Trojan horse or virus.
Movie Reference (Ocean's Eleven): The team used social engineering (pretexting, tailgating, and diversion) to exploit casino vulnerabilities such as human trust and security procedures.