0% found this document useful (0 votes)
3 views25 pages

Chapter 2 (Two)

The document provides an overview of cybersecurity, defining key terms such as cyberspace and cybersecurity, and outlining its importance in protecting data and systems from various threats. It details types of cyber threats and attacks, including natural and manmade threats, as well as measures for protection against them. Additionally, it discusses ethical issues, basic cybersecurity measures, and best practices for cloud security.

Uploaded by

Hidra Ramadhani
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views25 pages

Chapter 2 (Two)

The document provides an overview of cybersecurity, defining key terms such as cyberspace and cybersecurity, and outlining its importance in protecting data and systems from various threats. It details types of cyber threats and attacks, including natural and manmade threats, as well as measures for protection against them. Additionally, it discusses ethical issues, basic cybersecurity measures, and best practices for cloud security.

Uploaded by

Hidra Ramadhani
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Created by;

Mr. Hidra, R
Meaning of Cybersecurity
Cyberspace: Is the virtual world created by computers, the internet and digital
network.
Cybersecurity: Is the practice of keeping computer systems, networks, and data
safe from hackers or other unauthorized access.
Importance of studying cybersecurity:
✓ It help to protect data from hackers
✓ It safeguard system resources from cybercriminals
✓ It prevent identity theft
✓ It help to prevent lose money
✓ It help to protect devices and system from damage.
✓ It’s the key of staying safe
✓ It keep online information private.
Components of cybersecurity
Cyber Threats and Attacks
Cyber Threats: Is any event or situation that has the potential to cause harm
to a computer system or organization, weather it occurs accidentally or
intentionally.
Cyber Attacks: Is a deliberate and planned action aimed at breaching a
system security.
Types of Cyber Threats:
1. Natural threats: This is like natural disasters, i.e. earthquakes, floods,
fires, hurricanes etc.
2. Manmade threats: these are human actors, like theft, viruses, accidental
deletion, accidental damage hardware.
General security measures for protection from natural
threats
❑ Backup data

❑ Install computers in secure locations

❑ Install protective electrical devices

❑ Insulate computer from fire

❑ Maintain appropriate temperature or humidity.


Measures for protection against threats from human
actions
❑ Store data safely

❑ Encrypt data

❑ Install antivirus and antispyware programs

❑ Install firewall

❑ Backup data

❑ Keep computer in safe environment


Types of cyber attacks
1: Physical Based attacks: involves gaining physical access to
devices or equipment to steal data or install malicious tools.
Examples of common physical cyber attacks:
❑ Device theft:
❑ Keylogging devices:
❑ Shoulder surfing:
❑ Power interference attacks:
❑ Dumpster diving:
Cont..
2: Software based attacks: This exploit software, networks or user behavior
to access, steal, or damage information.
List of common software based cyber attacks
❑ Phishing: fake email or messages that trick you
❑ Malware:
❑ Ransomware: software that lock your files
❑ Password attack:
❑ SQL injection: use bad code to break into website
❑ DoS attack: sending too many fake request to crash your website
❑ DNS spoofing: Redirect you to fake websites
Cont..
❑ Man in the middle:

❑ Salami attack: steal small amount many times without being noticed

❑ Supply chain attack: hacking through another company software

❑ Identity theft: using someone else info to pretend to be them

❑ Spamming: sending lots of fake and unwanted emails.

❑ Cyber terrorism: Hacking an government website to send fake warning.

❑ Hacking: someone break into your account without permission


Hacking
Hacking: is unauthorized access or breach of information system,
often by exploiting security vulnerability.
Types of hackers
1. Black hat hackers: These break system with malicious intent
2. White hat hackers: These are ethical hackers who identifying
and fixing vulnerability criminal hackers
3. Grey hat hackers: These fall somewhere in between hacking
without permission and report vulnerability to the effected
parties after discovering them.
Ways hackers exploit vulnerabilities
➢ Hackers are people who use computer skills to access system or data
without permission

➢ They exploit weak password

➢ They trick people through phishing emails

➢ They use malicious code, attack public Wi-Fi

➢ They spread viruses and ransomware

➢ Note: to stay safe use strong passwords,


Cybercrime
Cybercrime: Is the use of computers or digital devices to carry out illegal or harmful
activities online.
It includes
❑ Hacking
❑ Online scams
❑ Cyberbullying
❑ Identity theft
❑ Spreading viruses
Classification of Cybercrime
❑ Against individuals:

❑ Against organization:

❑ Against government and national security:

❑ Against properties:

❑ Against society:
Catalyst of Cybercrime
Cyber crime occurs due to various factors or motivation,
❑ Financial gain
❑ Anonymity: hide themselves
❑ Political and ideological motives:
❑ Revenge:
❑ Curiosity and challenge: use for fun
❑ Weak cybersecurity
❑ Ineffective law enforcement:
❑ Cyber espionage: Governments may conduct cyberattack for political
Ethical issues and related principles
Ethical issue: it involves what is right or wrong when values conflict

1. Data Privacy: This involves protecting personal information


shared online or stored on digital devices

2. Cybersecurity ethics: are moral principals that includes the


protecting personal information respecting other privacy.
Basic cybersecurity measures
The key actions includes the following:

a. Use strong, unique passwords

b. Enabling two factors authentications

c. Regular updating software and antivirus

d. Avoid suspicious links or downloads

e. Being cautious when sharing personal information online

f. Using secure Wi-Fi connections


Types of cyber threats and their security measures
❑ Phishing: Avoid clicking unknown link
❑ Malware: Install antiviruses
❑ Ransomware: Implement strong backups
❑ Business Email compromise (BEC): Employee awareness and training
❑ Distributes Denial of Services (DDoS): Use special tools for security
measures to detect attack.
❑ Data Breaches: Use strong emails and focus on employee training
❑ Cyber building and harassment: protect yourself in online do not engage
with cyberbullies
❑ Spoofing: Secure communication protocols
Cont..
❑ Device by attack: Keep software and system updates
❑ SQL injection or XSS attack: Secure coding practices
❑ Password attacks: Implement strong authentications passwords
❑ Social engineering and psychological manipulation: Educate and
train employees or users, implement strong identity verifications.
❑ Supply chain attacks: Implement vendor risk management protocols
❑ Man in the middle attacks (MitM): Use strong encryption and
secure communication.
❑ Inside Threats: Implement strict access control, monitor and detect
suspicious activity.
Authentication
Authentication: Is the process of confirming that a person ( or
system) is truly who they claim to be allowing access to sensitive
systems, data or accounts.
Common authentication methods includes:

1. Username and password

2. Biometrics

3. Two factors authentication


Cont..
❑ A digital Signature: Is a method of providing that a message, document, or online
transaction is genuine and has not been altered.

❑ Firewall: Is an important security tools that helps protect computer network from
harmful attacks by blocking unwanted traffic and controlling what is comes in and out.

❑ Netiquette: Is a good behavior when using the internet.

❑ Streamgraph: Is a type of graph that shows data over time.

❑ Computer forensics: Is the process of investigating digital devices to find evidence of


cybercrimes.
Cont..
Steps for conducting computer forensics:
1. Identification
2. Preservation
3. Collection
4. Examination
5. Analysis
6. Documentation
7. Presentation
❑ Safe Browsing: Means using the internet in a way that protect personal
information and keep safe from online threats.
cont..
❑ Reporting Cybercrime: Is an essential step in stopping online criminals and
protecting yourself and others.

❑ Antivirus: Is a software that protect devices from harmful programs


Cloud Security
Cloud computing: Is a vital technology in today’s digital age.
Security challenges in cloud environments
❑ Data Breaches and Loss
❑ Unauthorized access
❑ Inside threats
❑ Insecure APIs and Interfaces
❑ Compliance and legal issues
❑ Denial of Services Attacks.
Cont..
Best practices for cloud security:

➢ Use strong password

➢ Keep software updated

➢ Limit access

➢ Monitor activity

➢ Backup data

➢ Share responsibility
This Makes an end of

Chapter Two

You might also like