Module II: Comprehensive Notes on Information System Threats and Attacks

Attack Basic Concepts

  • Definition of Attack: An attack is any attempt to gain unauthorized access to a system or to deny authorized users from accessing the system. It is important to note that an attack is an attempt and does not necessarily guarantee a successful breach.

  • Purpose: The primary purpose of an attack is to violate one or more of the three basic properties of security: confidentiality, integrity, and availability of data.

  • Attacker: An individual or group of individuals who strives to violate a system’s overall security. Attacks can vary in kind and origin.

  • Computer Crime: This occurs when an attacker breaks a specific law or regulation during an attack.

Classifications of Attacks

Active vs. Passive Attacks

  • Active Attack: These attacks attempt to alter system resources or affect their operation, thereby compromising the security principles of integrity or availability. Examples include:

    • Denial-of-Service (DoS) attack

    • Spoofing

    • Mixed threat attack

    • Network-based active attacks:

      • Man-in-the-middle

      • Man-in-the-browser

      • ARP poisoning

      • Ping flood

      • Ping of death

      • Smurf attack

    • Host-based active attacks:

      • Buffer overflow

      • Heap overflow

      • Stack overflow

      • Format string attack

  • Passive Attack: These attacks attempt to learn or make use of information from the system without affecting system resources, thereby compromising the confidentiality principle. Examples include:

    • Computer and network surveillance

    • Network-based passive attacks:

      • Wiretapping

      • Fiber tapping

      • Port scan

      • Idle scan

    • Host-based passive attacks:

      • Keystroke logging

      • Data scraping

      • Backdoor

Syntactic vs. Semantic Attacks

  • Syntactic Attack: These attacks use malicious software to disrupt or damage a computer system or network.

    • Virus: A self-replicating program that can attach itself to another program or file to reproduce. It can hide in unlikely locations in memory, change its digital footprint each time it replicates, and attach to various files to execute its code.

    • Worm: A self-sustaining running program that does not need another file to copy itself. Worms replicate over a network using protocols and often exploit known vulnerabilities. They can be used for industrial espionage to monitor server activities and transmit data back to the creator.

    • Trojan Horse: Designed to perform legitimate tasks while simultaneously performing unknown and unwanted activities. They can install keyboard loggers or backdoors and are often embedded in trial versions of commercial software.

  • Semantic Attack: These involve the modification of information or the dissemination of incorrect information to attack users' confidence. The goal is to cause a computer system to produce errors and unpredictable results.

    • Cyber Defamation: Publishing defamatory material against another person using computers or the internet through a virtual medium.

    • Pump-and-dump: An illegal scheme that boosts a stock price through recommendations based on false or exaggerated statements. Perpetrators sell their positions after the hype leads to a higher share price.

Broad Categories of Attacks

  • Military and Intelligence Attacks: Attempts to acquire secret information from law enforcement or defense agencies (e.g., defense strategies, sealed legal proceedings). Disclosure can cause serious damage and high costs for reformulating plans, such as revealing the location of a submarine fleet.

  • Business Attacks: Attempts to acquire sensitive data from commercial organizations. Disclosure can violate laws and cause a loss of market position (e.g., leaking a secret soft drink formula).

  • Terrorist Attacks: Coordinated attacks that coincide with physical attacks. By targeting communication and infrastructure control systems, attackers hinder the ability of emergency responders (police, fire) to react.

  • Grudge Attacks: Launched by disgruntled employees or customers for revenge. These attacks may destroy data or disclose damaging information for vengeance rather than reward.

  • Fun Attacks: These have no real purpose other than providing a rush or ego satisfaction for the attacker. The underground hacker community associates prestige with compromising secure systems.

Attacker Capabilities, Inhibitors, and Amplifiers

Attacker Capability

Attacker capability is the ability to use appropriate means (knowledge, time, expertise, and tools) and opportunity to exploit vulnerabilities. Common components include:

  • Software and Technology

  • Facilities

  • Education and Training

  • Methods and Books of Manuals

Threat Inhibitors

Factors that decrease the likelihood of a successful attack:

  • Fear of Capture: Perception of being identified and caught.

  • Fear of Failure: Belief that they will fail, especially if sensitive to the opinions of others.

  • Level of Technical Difficulty: Stronger target defenses usually deter attackers, though some may view it as a challenge to prove their skills.

  • Cost of Participation: High financial costs, time commitments, or equipment requirements.

  • Sensitivity to Public Perception: Fear of public disfavor.

  • Law Enforcement Activity: The presence of strong, tested laws and aggressive enforcement.

  • Target Vulnerability: Perceived state of protection.

  • Peer Perception: Lack of acknowledgement from peers for certain targets.

Threat Amplifiers

Factors that increase the likelihood of an attack:

  • Peer Pressure: Striving for prestige within a group.

  • Fame: Seeking recognition for actions.

  • Access to Information: The prospect of gaining useful information.

  • Changing High Technology: The cycle of new technology release, discovery of weaknesses, and subsequent exploitation.

  • De-skilling through Scripting: Automated scripts that allow less-skilled attackers to perform complex tasks.

  • Skills and Education Levels: As general technical literacy increases, so does the pool of potential attackers.

Attacker Motivations and Characteristics

Core Motivational Factors

  • Political: Furthering the cause of a political organization.

  • Religion: Religious conflicts driving system penetration.

  • Power: Demonstrating capability through system attacks.

  • Terrorism: Use of systems for propaganda and dissemination.

  • Curiosity: Unfocused and difficult to quantify.

  • Personal Gain: Various rewards and financial incentives.

Table: Characteristics and Targets of Attackers

Attacker

Target

Goals

Motivation

Damages

Nation State Actors

Governments and businesses running critical infrastructure

Steal sensitive info, disrupt enemy capabilities, create international incidents

National advantage

Extremely high

Cybercriminals

Companies with customer/financial data

Steal sensitive info to sell or directly steal money

Money

High

Hacktivists

Organizations conflicting with their beliefs

Cause disruption for attention or steal data to damage targets

Promote religion, politics, or cause

Medium

Script Kiddies

Networks/websites with minimal security

Gain access to show off or deface a website

Impress friends/gain credit

Low

Malware: Definitions and Forms

Malware (Malicious Software): An umbrella term for any malicious program or code harmful to systems. It is intentionally designed to cause damage to computers, servers, networks, or mobile devices by taking partial control. Programs acting secretly against user interests (e.g., the Sony rootkit that reported on listening habits) are also considered malware.

Common Forms of Malware

  • Adware: Software designed to display unwanted advertisements, often disguised as legitimate or piggybacked on other programs.

  • Spyware: Secretly observes user activities without permission and reports back to the author.

  • Virus: Attaches to another program and replicates by modifying other code.

  • Worm: Self-replicating malware that spreads over a network, usually destroying data.

  • Trojan Horse: Represents itself as useful to trick users, then provides unauthorized access to steal information.

  • Ransomware: Encrypts files or locks the device, demanding a ransom (often in cryptocurrency) for recovery.

  • Rootkit: Provides administrator privileges to the attacker while remaining hidden from users and the operating system.

  • Keylogger: Records all keystrokes to steal usernames, passwords, and credit card details.

  • Malicious Cryptomining (Cryptojacking): Installed by a Trojan to use the victim's hardware to mine cryptocurrency for the attacker.

  • Exploits: Takes advantage of system bugs. Linked to Malvertising, where legitimate sites pull malicious content that installs via "drive-by download" (no clicking required).

  • Backdoors: Bypasses normal authentication for future invisible access. Can be installed by Trojans, worms, or implants.

  • Browser Hijacker: Changes browser behavior, installs unwanted plugins, and redirects traffic.

  • Crimeware: Used to commit crimes for financial gain.

  • RAM Scraper: Harvests data being stored in the system's memory (RAM).

  • Rogue Security Software (Scareware): Tricks users into thinking they have a security problem so they will install fake tools.

  • Bot: An infected device performing harmful tasks. A Botnet is a large group of bots focused on a single task.

Malware Infection and Evolution

Signs of Malware Infection

  • System slowdowns or high resource usage (fan whirling at full speed).

  • Unexpected pop-up ads.

  • Repeated crashes, freezes, or Blue Screen of Death (BSOD).

  • Mysterious loss of disk space.

  • Increased internet activity.

  • Browser homepage changes or new toolbars/extensions.

  • Antivirus products stop working or cannot be updated.

Historical Trends in Malware

  • The 1980s: Modern history begins with Elk Cloner (19821982), which infected Apple II systems via floppy disks. Theoretical self-reproducing automata concepts date back to 19491949.

  • The 1990s: Rise of macro viruses targeting Microsoft Word and other Office applications.

  • 2002 to 2007: Instant messaging worms spread via AOL AIM, MSN Messenger, and Yahoo Messenger.

  • 2005 to 2009: Proliferation of adware. Around 20082008, lawsuits against adware companies led to many shutting down.

  • 2007 to 2009: Shift to social networks (MySpace, later Facebook and Twitter) for phishing and malicious extensions.

  • 2013: Launch of CryptoLocker, which collected approximately 27 million27 \text{ million} by the last quarter of 20132013. A copycat variant collected over 18 million18 \text{ million} from 1,0001,000 victims between 20142014 and 20152015.

  • 2013 to 2017: Ransomware became "king," peaking with major outbreaks in 20172017.

  • 2017 to Present: Rise of cryptojacking due to the popularity of cryptocurrency mining.

Malware Detection and Defense

Detection Techniques

  • Signature Based: Searches for a specific sequence of bits (signature) embedded in the code. Uses string or pattern matching against a database. Primarily identifies known malware families.

  • Heuristic Based (Behavior/Anomaly Detection): A proactive technique with two steps: recording normal behavior and then watching for deviations (abnormal behavior) during an attack.

  • Specification Based: Monitors applications according to their system specifications to check for abnormal behavior based on defined system rules.

Comparison of Detection Techniques

Technique

Advantages

Disadvantages

Signature Based

Detects known malware easily; uses fewer resources; widely available

Cannot detect unknown malware; database grows exponentially

Heuristic Based

Detects known/unknown/new malware; identifies potential actions

Requires updates; high resource usage (time/space); high false positives

Specification Based

Detects known/unknown/new malware; low false positives

High false negatives; inefficient for brand new malware; time-consuming to develop

Specific Malware Defenses

  • Adware: Install anti-adware; disable pop-ups; uncheck "default" install boxes.

  • Backdoor/Crimeware: Use firewalls, IDS/IPS, SIEM, and strong/regularly updated passwords.

  • Bots/Botnets: Anti-malware software; network monitoring for botnet activity.

  • RAM Scraper: Harden POS systems; separate payment systems from non-payment systems; comply with data standards.

  • Ransomware: Maintain up-to-date backups; wipe and reboot if locked; user training; software patching.

  • Rootkit: If infected, format the hard drive and start over; maintain OS patches.

  • Virus/Worm: Keep antivirus signatures updated; deploy firewalls; exercise care with links and attachments.

Denial of Service (DoS)

Definition: An attack seeking to make a network resource unavailable to intended users by disrupting services. It violates the Availability property of the CIA Triad.

Impacts of DoS

  • Extortion: Demanding payment to stop the attack.

  • Sabotage: Competitors attacking websites for market share.

  • Brand Damage: Loss of reputation due to downtime.

  • Financial Losses: Lost sales or advertising revenue.

Types of DoS Attacks

  • Application-layer Flood: Flooding a service with requests from a spoofed IP address.

  • Distributed Denial of Service (DDoS): Requests sent from many locations simultaneously. Often utilizes "zombie" machines—compromised devices controlled by the attacker. DDoS is harder to shut down and the source is difficult to identify due to random distribution.

  • Unintended DoS: Caused by sudden, non-malicious popularity.

    • The Slashdot Effect: Traffic surge from news site links.

    • The Reddit Hug of Death: Similar surge from Reddit popularity.

Countermeasures

  • Purchase more Bandwidth: Handling traffic spikes.

  • Network Hardware Configuration: Dropping DNS responses from outside or incoming ICMP packets.

  • Protect DNS Servers: Implementing redundancy for the over 300 million300 \text{ million} domain names.

  • Transparent Mitigation: Using technology to allow legitimate users access without showing outdated content during an attack.

  • Load Balancers: Distributing traffic across multiple servers.

Social Engineering

Definition: A technique relying on human interaction to influence individuals to violate security protocols or divulge confidential information. It exploits a lack of security awareness and human psychological weaknesses.

Life Cycle of Social Engineering

  1. Information Gathering: Collecting data on the victim's interests.

  2. Engaging with Victim: Opening a conversation to build trust.

  3. Attacking: Retrieving information from the target.

  4. Closing Interaction: Shutting down communication without arising suspicion.

Cialdini’s Six Principles of Influence

  • Reciprocity: Returning a favor (e.g., free samples before a request).

  • Commitment and Consistency: Honoring a commitment made in writing or orally to maintain self-image.

  • Social Proof: Doing what others are doing.

  • Authority: Obeying authority figures.

  • Liking: Being easily persuaded by liked individuals.

  • Scarcity: Creating urgency through perceived lack of availability.

Social Engineering Attack Types

  • Baiting: Leaving infected physical devices (like USBs) for victims to find.

  • Honey Trap: Forming fake relationships for money or PII.

  • Phishing: Masquerading as a trusted source (e.g., email spoofing).

    • Spear Phishing: Targeting specific organizations/individuals.

    • Smishing: SMS-based phishing.

    • Vishing: Voice-based phishing (VoIP).

    • Whaling: Targeting high-profile individuals (CEOs, politicians).

  • Pretexting: Lying to gain access to privileged data.

  • Quid Pro Quo: Offering a service (like tech support) in exchange for access.

  • Tailgating (Piggybacking): Following someone into a secure area.

  • Waterholing: Infecting a trusted website used by a specific group.

Organizational Countermeasures

  • Training & Inoculation: Regular security awareness and frequent testing multiple times a year.

  • OPSEC (Operations Security): Identifying and protecting friendly actions that could be useful to an attacker.

  • Multi-factor Authentication (MFA): Requiring users to know something (password), have something (token), and be something (biometrics).

  • Vendor Risk Management: Continuous monitoring of third-party cybersecurity ratings.

  • Waste Management: Securely disposing of physical information ("dumpster diving" prevention).

Notable Social Engineers

  • Kevin Mitnick: U.S. hacker and consultant known for high-profile arrests in 19951995.

  • Susan Headley: Expert in pretexting and psychological subversion (1970s1970\text{s}-1980s1980\text{s}).

  • Badir Brothers: Ramy, Muzher, and Shaddle Badir (blind from birth) who used Brille-display computers for vishing fraud in Israel during the 1990s1990\text{s}.

  • Frank Abagnale: Former con man and impostor (age15−21age 15-21) whose life was depicted in the movie Catch Me If You Can.

Questions & Discussion

  • Passive vs. Active Scenarios:

    • Capturing/replaying fund transfer instructions: Active.

    • Modifying packet header addresses: Active.

    • Network message flooding: Active.

    • Eavesdropping on website visits: Passive.

  • Facebook Hack (Sept 20182018): Harvesting millions of phone numbers and email addresses. Possible goal: Data resale or secondary phishing; Motivation: Financial gain or personal gain.

  • Malware Scenarios:

    • Site redirection: Browser hijacker.

    • System error messages: Virus or generic Malware.

    • Program recording typing: Keylogger.

    • Gradual slowdown and total failure: Worm or Virus consuming resources.

  • Email Verification Test: A help desk email requests Name, Email Login, Password, DOB, and Alternate Email to save an account from deletion. Action: Do not respond; this is a phishing attempt. Help desks define passwords as sensitive and never request them.

  • PAG-IBIG Website Timeout: This is likely an unintended DoS or "unintended Denial of Service" rather than a malicious DDoS, caused by a legitimate surge in users attempting to update records simultaneously, similar to the Slashdot effect.

  • E-card Attachment: If a friend sends an unexpected attachment for an e-card, the safe action is to verify the sender's intent through a different communication method before clicking, as it may be a Trojan horse or virus.

  • Movie Reference (Ocean's Eleven): The team used social engineering (pretexting, tailgating, and diversion) to exploit casino vulnerabilities such as human trust and security procedures.