Cyber security (module-2)
Hacking definition
Hacking is the act of identifying and then exploiting weaknesses in a
computer system or network, usually to gain unauthorized access to
personal or organizational data. Hacking is not always a malicious activity,
but the term has mostly negative connotations due to its association with
cybercrime.
Types of Hacking/Hackers
Black Hat Hackers
Black hat hackers are the "bad guys" of the hacking scene. They go out of
their way to discover vulnerabilities in computer systems and software to
exploit them for financial gain or for more malicious purposes, such as to
gain reputation, carry out corporate espionage, or as part of a nation-state
hacking campaign.
These individuals’ actions can inflict serious damage on both computer
users and the organizations they work for. They can steal sensitive
personal information, compromise computer and financial systems, and
alter or take down the functionality of websites and critical networks.
White Hat Hackers
White hat hackers can be seen as the “good guys” who attempt to prevent
the success of black hat hackers through proactive hacking. They use their
technical skills to break into systems to assess and test the level of network
security, also known as ethical hacking. This helps expose vulnerabilities in
systems before black hat hackers can detect and exploit them.
The techniques white hat hackers use are similar to or even identical to
those of black hat hackers, but these individuals are hired by organizations
to test and discover potential holes in their security defenses.
Grey Hat Hackers
Grey hat hackers sit somewhere between the good and the bad guys. Unlike
black hat hackers, they attempt to violate standards and principles but
without intending to do harm or gain financially. Their actions are typically
carried out for the common good. For example, they may exploit a
vulnerability to raise awareness that it exists, but unlike white hat hackers,
they do so publicly. This alerts malicious actors to the existence of the
vulnerability.
What is Cybercrime?
Cybercrime can be defined as “The illegal usage of any communication
device to commit or facilitate in committing any illegal act”.
A cybercrime is explained as a type of crime that targets or uses a computer
or a group of computers under one network for the purpose of harm.
Cybercrimes are committed using computers and computer networks. They
can be targeting individuals, business groups, or even governments.
Most Common Cyber Crimes
Now that you understand what cybercrimes are, let’s discuss some common
cybercrimes.
Types of cybercrime
1. Phishing and Scam:
Phishing is a type of social engineering attack that targets the user and tricks
them by sending fake messages and emails to get sensitive information
2
about the user or trying to download malicious software and exploit it on
the target system.
2. Identity Theft
Identity theft occurs when a cybercriminal uses another person’s personal
data like credit card numbers or personal pictures without their permission
to commit a fraud or a crime.
3. Ransomware Attack
Ransomware attacks are a very common type of cybercrime. It is a type of
malware that has the capability to prevent users from accessing all of their
personal data on the system by encrypting them and then asking for a
ransom in order to give access to the encrypted data.
4. Hacking/Misusing Computer Networks
This term refers to the crime of unauthorized access to private computers or
networks and misuse of it either by shutting it down or tampering with the
data stored or other illegal approaches.
5. Internet Fraud
Internet fraud is a type of cybercrimes that makes use of the internet and it
can be considered a general term that groups all of the crimes that happen
over the internet like spam, banking frauds, theft of service, etc.
Other Types of Cybercrime
Here are another 9 types of cybercrimes:
1. Cyber Bullying
3
It is also known as online or internet bullying. It includes
sending or sharing harmful and humiliating content about
someone else which causes embarrassment and can be a
reason for the occurrence of psychological problems. It became
very common lately, especially among teenagers.
2. Cyber Stalking
Cyberstalking can be defined as unwanted persistent content
from someone targeting other individuals online with the aim
of controlling and intimidating like unwanted continued calls
and messages.
3. Software Piracy
Software piracy is the illegal use or copy of paid software with
violation of copyrights or license restrictions.
An example of software piracy is when you download a fresh
non-activated copy of windows and use what is known as
“Cracks” to obtain a valid license for windows activation. This is
considered software piracy.
Not only software can be pirated but also music, movies, or
pictures.
4. Social Media Frauds
The use of social media fake accounts to perform any kind of
harmful activities like impersonating other users or sending
intimidating or threatening messages. And one of the easiest
and most common social media frauds is Email spam.
5. Online Drug Trafficking
4
With the big rise of cryptocurrency technology, it became easy
to transfer money in a secured private way and complete drug
deals without drawing the attention of law enforcement. This
led to a rise in drug marketing on the internet.
Illegal drugs such as cocaine, heroin, or marijuana are
commonly sold and traded online, especially on what is known
as the "Dark Web".
6. Electronic Money Laundering
Also known as transaction laundering. It is based on unknown
companies or online business that makes approvable payment
methods and credit card transactions but with incomplete or
inconsistent payment information for buying unknown
products.
It is by far one of the most common and easy money laundering
methods.
8. Cyber Extortion
Cyber extortion is the demand for money by cybercriminals to
give back some important data they've stolen or stop doing
malicious activities such as denial of service attacks.
9. Intellectual-property Infringements
It is the violation or breach of any protected intellectual-
property rights such as copyrights and industrial design.
10. Online Recruitment Fraud
One of the less common cybercrimes that are also growing to
become more popular is the fake job opportunities released by
5
fake companies for the purpose of obtaining a financial benefit
from applicants or even making use of their personal data.
Active and Passive attacks in Information Security
It’s important to the distinction between active and
passive attacks can be blurry, and some attacks may
involve elements of both. Additionally, not all attacks
are technical in nature; social engineering attacks,
where an attacker manipulates or deceives users in
order to gain access to sensitive information, are also
a common form of attack.
Active attacks:
Active attacks are a type of cybersecurity attack in
which an attacker attempts to alter, destroy, or
disrupt the normal operation of a system or
network. Active attacks involve the attacker taking
direct action against the target system or network,
and can be more dangerous than passive
attacks, which involve simply monitoring or
eavesdropping on a system or network.
Types of active attacks are as follows:
Masquerade
Modification of messages
Repudiation
Replay
Denial of Service
6
Masquerade –
Masquerade is a type of cybersecurity attack in which an
attacker pretends to be someone else in order to gain
access to systems or data. This can involve
impersonating a legitimate user or system to trick other
users or systems into providing sensitive information or
granting access to restricted areas.
There are several types of masquerade attacks,
including:
Username and password masquerade: In a
username and password masquerade attack, an attacker
uses stolen or forged credentials to log into a system or
application as a legitimate user.
IP address masquerade: In an IP address
masquerade attack, an attacker spoofs or forges their IP
address to make it appear as though they are accessing
a system or application from a trusted source.
Website masquerade: In a website masquerade
attack, an attacker creates a fake website that appears to
be legitimate in order to trick users into providing
sensitive information or downloading malware.
Email masquerade: In an email masquerade attack,
an attacker sends an email that appears to be from a
trusted source, such as a bank or government agency, in
order to trick the recipient into providing sensitive
information or downloading malware.
7
Masquerade Attack
Modification of messages –
It means that some portion of a message is altered or that
message is delayed or reordered to produce an unauthorized
effect. Modification is an attack on the integrity of the original
data. It basically means that unauthorized parties not only
gain access to data but also spoof the data by triggering
denial-of-service attacks, such as altering transmitted data
packets or flooding the network with fake data.
Manufacturing is an attack on authentication. For example, a
message meaning “Allow JOHN to read confidential file X” is
modified as “Allow Smith to read confidential file X”.
8
Modification of messages
Repudiation –
Repudiation attacks are a type of cybersecurity attack
in which an attacker attempts to deny or repudiate
actions that they have taken, such as making a
transaction or sending a message. These attacks can
be a serious problem because they can make it
difficult to track down the source of the attack or
determine who is responsible for a particular action.
There are several types of repudiation attacks,
including:
Message repudiation attacks: In a message
repudiation attack, an attacker sends a message and
then later denies having sent it. This can be done
by using spoofed or falsified headers or by exploiting
vulnerabilities in the messaging system.
9
Transaction repudiation attacks: In a
transaction repudiation attack, an attacker makes a
transaction, such as a financial transaction, and then
later denies having made it. This can be done by
exploiting vulnerabilities in the transaction processing
system or by using stolen or falsified
credentials.
Data repudiation attacks: In a data repudiation
attack, an attacker modifies or deletes data and then
later denies having done so. This can be done by
exploiting vulnerabilities in the data storage system or
by using stolen or falsified credentials.
Replay –
It involves the passive capture of a message and its
subsequent transmission to produce an authorized
effect. In this attack, the basic aim of the attacker is
to save a copy of the data originally present on that
particular network and later on use this data for
personal uses. Once the data is corrupted or leaked it
is insecure and unsafe for the users.
10
Replay
Denial of Service –
Denial of Service (DoS) is a type of cybersecurity
attack that is designed to make a system or network
unavailable to its intended users by overwhelming it
with traffic or requests. In a DoS attack, an attacker
floods a target system or network with traffic or
requests in order to consume its resources, such as
bandwidth, CPU cycles, or memory, and prevent
legitimate users from accessing it.
There are several types of DoS attacks, including:
Flood attacks: In a flood attack, an attacker sends
a large number of packets or requests to a target
system or network in order to overwhelm its
resources.
Amplification attacks: In an amplification attack,
an attacker uses a third-party system or network to
amplify their attack traffic and direct it
towards the target system or network, making the
attack more effective.
To prevent DoS attacks, organizations can
implement several measures, such as:
[Link] firewalls and intrusion detection systems to
monitor network traffic and block suspicious activity.
[Link] the number of requests or connections
that can be made to a system or network.
[Link] load balancers and distributed systems to
distribute traffic across multiple servers or networks.
[Link] network segmentation and access
controls to limit the impact of a DoS attack.
11
Denial of Service
Passive attacks
A Passive attack attempts to learn or make use of
information from the system but does not affect
system resources. Passive Attacks are in the
nature of eavesdropping on or monitoring
transmission. The goal of the opponent is to
obtain information that is being transmitted.
Passive attacks involve an attacker passively
monitoring or collecting data without altering or
destroying it. Examples of passive attacks include
eavesdropping, where an attacker listens in on
network traffic to collect sensitive information,
and sniffing, where an attacker captures and
analyzes data packets to steal sensitive
information.
Types of Passive attacks are as follows:
The release of message content
Traffic analysis
12
The release of message content –
Telephonic conversation, an electronic mail message,
or a transferred file may contain sensitive or
confidential information. We would like to prevent an
opponent from learning the contents of these
transmissions.
Passive attack
Traffic analysis –
Suppose that we had a way of masking (encryption)
information, so that the attacker even if captured the
message could not extract any information from the
message.
The opponent could determine the location and
identity of communicating host and could observe the
frequency and length of messages being exchanged.
This information might be useful in guessing the
nature of the communication that was taking place.
13
The most useful protection against traffic analysis is
encryption of SIP traffic. To do this, an attacker would
have to access the SIP proxy (or its call log) to
determine who made the call.
Traffic analysis
Threats
Cybersecurity threats are acts performed by individuals with
harmful intent, whose goal is to steal data, cause damage to or
disrupt computing systems. Common categories of cyber
threats include malware, social engineering, man in the middle
(MitM) attacks, denial of service (DoS), and injection attacks—
we describe each of these categories in more detail below.
vulnerability
14
A vulnerability in cyber security is a weakness in an
organization's information system, system processes, or
internal controls. Vulnerabilities are targets for cybercrimes and
can be exploited through points of vulnerability.
Target of Evaluation (TOE)
This is the most common usage in cybersecurity standards like
the Common Criteria (CC). A TOE refers to the specific system,
product, or component undergoing security evaluation. It's
basically the "thing" being assessed for its security properties.
So, if a company wants to demonstrate the security of their
antivirus software, the software becomes the TOE.
Cyber Attack
A cyberattack is a malicious and deliberate attempt by an
individual or organization to breach the information system of
another individual or organization. Usually, the attacker seeks
some type of benefit from disrupting the victim’s network.
exploit
An exploit in cybersecurity defines a tool, software code, or
method that takes advantage of a computer system (or
software) vulnerability to carry out a malicious task. Many
exploits are carried out through the use of malware, which is a
general term that defines any manner of malicious software.
15