0% found this document useful (0 votes)
2 views21 pages

Module-1

The document provides an overview of cybercrime, defining it as crimes conducted using computers and the Internet, with various types including cyberterrorism, identity theft, and online fraud. It categorizes cybercriminals into three types based on their motivations and outlines different classifications of cybercrimes against individuals, property, organizations, and society. Additionally, it discusses the Indian IT Act 2000, which aims to regulate cyber activities and punish cybercrimes.

Uploaded by

papri_karekal
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views21 pages

Module-1

The document provides an overview of cybercrime, defining it as crimes conducted using computers and the Internet, with various types including cyberterrorism, identity theft, and online fraud. It categorizes cybercriminals into three types based on their motivations and outlines different classifications of cybercrimes against individuals, property, organizations, and society. Additionally, it discusses the Indian IT Act 2000, which aims to regulate cyber activities and punish cybercrimes.

Uploaded by

papri_karekal
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Module-1

Introduction to Cybercrime and Laws

Cybercrime: Definition and Origins of the word

Cyberspace:
“cyberspace” is where users mentally travel through matrices of data. Conceptually,
“cyberspace” is the “nebulous place” where humans interact over computer networks. The term
“cyberspace” is now used to describe the Internet and other computer networks. In terms of
computer science. “cyberspace” is a worldwide network of computer networks that uses the
Transmission Control Protocol/internet Protocol (TCP/IP) for communication to facilitate
transmission and exchange of data.

Cyberterrorism:
Cyberterrorism is the premeditated, politically motivated attack against information,
computer systems, computer programs and data which result in violence against noncombatant
targets by sub national groups or clandestine agents.

Cybercrime Definition:
Cybercrime can be defined as “a crime conducted in which a computer was directly and
significantly instrumental.” This definition is not universally accepted.

Here is yet another definition: “cybercrime (computer crime) is any illegal behavior, directed by
means of electronic operations, that-targets-the-security of computer systems and the data
processed by them. In a Wider sense, “computer-related crime” can be any illegal behavior
committed by means of, or in relation to, a computer system or network; however, this is not
cybercrime.

Computer-related crime, Computer crime, Internet crime, E-crime; High-tech crime, etc.
are the other synonymous terms. Cybercrime specifically can be defined in a number of ways: a
few definitions are:

1. Crime committed using a computer and the Internet to steal a person's identity (identity theft)

2. Crimes completed either on or with a computer.

3. Any illegal activity done through the Internet or on the computer.


4. All criminal activities are done using the medium of computers, the Internet, cyberspace and
the WWW.

Cybercrime refers to the act of performing a criminal act using cyberspace as the
communications vehicle. Some people argue that a cybercrime is not a crime as it is a crime
against software and not against a person or property.

However, while the legal systems around the world scramble o introduce laws to combat
cybercriminals, two types of attack are prevalent:

1. Techno-crime: A premeditated act against a system or systems, with the intent to copy,
steal, prevent access, corrupt or otherwise deface or damage parts of or the complete computer
system.

2. Techno Vandalism: It is a term used to describe a hacker or cracker who breaks into a
computer system with the sole intent of defacing and or destroying its [Link] Vandals
can deploy 'sniffers' on the Internet to locate soft (insecure) targets and then execute a range of
commands using a variety of protocols towards a range of ports. If this sounds complex - it is!
The best weapon against such attacks is a firewall which will hide and disguise your
organization's presence on the Internet.

Cybercrime and information security


Lack of information security gives rise to cybercrime.

Cybersecurity: means protecting information, equipment, devices, computer, computer resource,


communication device and information stored therein from unauthorized access, use, disclosure,
disruption, modification or destruction.

Who are cybercriminals:


Cybercrime involves such activities as child pornography; credit card fraud;
cyberstalking; defaming anothe online; gaining unauthorized access to computer systems;
ignoring copyright, software licensing and trademark protection; overriding encryption to make
illegal copies; software piracy and stealing another's identity (known as identity theft) to perform
criminal acts. Cybercriminals are those who conduct such acts. They can be categorized into
three groups that reflect their motivation.

1. Type I: Cybercriminals — hungry for recognition

+ Hobby hackers;

+ IT professionals (social engineering is one of the biggest threat);


+ politically motivated hackers;

+ terrorist organizations.

2. Type Il: Cybercriminals — not interested in recognition

+ Psychological perverts;

+ financially motivated hackers (corporate espionage);

+ state-sponsored hacking (national espionage, sabotage);

3. Type Ill: Cybercriminals — the insiders

+ Disgruntled or former employees seeking revenge;

+ competing companies using employees to gain economic advantage through damage


and/or theft.

Thus, the typical “motives” behind cybercrime seem to be greed, desire to gain power
and/or publicity, desire for revenge, a sense of adventure, looking for thrill to access forbidden
information, destructive mindset and desire to sell network security services.

===============================================================

Classification of Cybercrimes:
[Link] against individual

● Electronic mail (E-Mail) Spoofing and other online frauds


● Phishing, Spear Phishing and its various other forms such as Vishing
● Cyberdefamation
● Cyberstalking and harassment.
● Computer sabotage.
● Pornographic offenses
● Password sniffing

2. Cybercrime against property

● Credit card frauds


● Intellectual property (IP) crimes: Basically, IP crimes include software piracy,
copyright infringement, trademarks violations, theft of computer source code, etc.
● Internet time theft: It is explained in Section 1.5.4-as-well as in Chapter 11

3. Cybercrime against organization


● unauohorzedacceing of computer: Hacking is one method of doing this and
hacking is a punishable offense
● Password sniffing
● Denial-of service attacks (known as DoS attacks)
● Virus attack/dissemination of viruses
● E-Mail bombing/mail bombs
● Salami attack/Salami technique
● Logic bomb
● Trojan Horse
● Data diddling
● Crimes emanating from Usenet newsgroup
● Industrial spying/industrial espionage
● Computer network intrusions
● Software piracy

[Link] against Society

● Forgery
● Cyberterrorism
● Web jacking

[Link] emanating from Usenet newsgroup

● Usenet groups may carry very offensive, harmful, inaccurate material


● Postings that have been mislabeled or are deceptive in another way
● Hence service at your own risk

Email Spoofing:

A spoofed E-Mail is one that appears to originate from one source but actually has been sent
from another source.

Spamming:

Spam is abuse of electronic messaging systems to send unsolicited bulk messages


indiscriminately. A spam may be Spam Instant messaging spam, Usenet group spam,Web search engine
spam, Spam in blogs, wiki spam, Online classified ads spam, Mobile phone messaging spam, Internet forum
spam, Social networking spam. Search engine spamming is alteration or creation of a document with the
intent to deceive an electronic catalog or a filing system; some web authors use “subversive techniques” to
ensure that their site appears more frequently or in higher number in returned search results. Avoid the
following web publishing techniques:

● Repeating keywords
● Use of keywords that do not relate to the content on the site
● Use of fast meta refresh
● change to the new page in few seconds.
● Redirection
● IP cloaking:
● including related links, information, and terms.
● Use of colored text on the same color background
● Tiny text usage
● Duplication of pages with different URLs
● Hidden links

Cyber defamation:

The tort of cyber defamation is considered to be the act of defaming, insulting, offending or otherwise
causing harm through false statements pertaining to an individual in cyberspace.

Example: someone publishes defamatory matter about someone on a website or sends an containing
defamatory information to all friends of that person. It may amount to defamation when-

● If imputation to a deceased person would harm the reputation of that person, and is intended to be
hurtful to the feelings of his family or other near relatives
● An imputation is made concerning a company or an association or collection of people as such.
● An imputation in the form of an alternative or expressed ironically
● An imputation that directly or indirectly, in the estimation of others, lowers the moral or intellectual
character of that person, or lowers the character of that person in respect of his caste or of his calling,
or lowers the credit of that person.

Types of defamation

Libel : written defamation

Slander: oral defamation

When failed to prove, the person who made the allegations may still be held responsible for defamation.

Internet Time Theft:

It Occurs when an unauthorized person uses the Internet hours paid for by another person. It
comes under hacking because the person get access to someone else’s ISP user ID and password,
either by hacking or by gaining access to it by illegal means and uses the internet without the
other person’s knowledge. This theft can be identified when Internet time is recharged often,
despite infrequent usage. This comes under “identity theft”.

Salami attack/ salami technique:

They are used for committing financial crimes. The alterations made are so insignificant that in a
single case it would go completely unnoticed. Example: a bank employee inserts a program, into
the bank’s server that deduces a small amount from the account of every customer every month.
The unauthorized debit goes unnoticed by the customers, but the employee will make a sizable
amount every month.

Data diddling:
Data diddling involves changing data input in a computer. In other words, information is
changed from the way it should be entered by a person typing in the data. Usually, a virus that
changes data or a programmer of the database or application has pre-programmed it to be
changed. For example, a person entering accounting may change data to show their account, or
that or a friend or family member, is paid in full. By changing or failing to enter the information,
they are able to steal from the company.

Forgery:

The act of forging something, especially the unlawful act of counterfeiting a document or
object for the purposes of fraud or deception. Something that has been forged, especially a
document that has been copied or remade to look like the original. Counterfeit currency notes,
postage, revenue stamps, marksheets, etc., can be forged using sophisticated computers, printers
and scanners.

Web jacking:

This term is derived from the term hi jacking. In these kinds of offenses the hacker gains
access and control over the web site of another. He may even change the information on the site.
The first stage of this crime involves “password sniffing”. The actual owner of the website does
not have any more control over what appears on that [Link] may be done for fulfilling
political objectives or for money.

Industrial spying/ Industrial Espionage:

Industrial espionage is the covert and sometimes illegal practice of investigating


competitors to gain a business advantage. The target of investigation might be a trade secret such
as a proprietary product specification or formula, or information about business plans. In many
cases, industrial spies are simply seeking any data that their organization can exploit to its
advantage.

Hacking:

Every act committed toward breaking into a computer and/ or network is hacking.
Purpose Greed, Power, Publicity, Revenge, Adventure, Desire to access forbidden information,
Destructive mindset. Hacking vs. Cracking - Malicious attacks on computer networks are
officially known as cracking , while hacking truly applies only to activities having good
intentions. Most non-technical people fail to make this distinction, however. Outside of
academia, its extremely common to see the term "hack" misused and be applied to cracks as
well.

Online frauds:

Fraud that is committed using the internet is “online fraud.” Online fraud can involve
financial fraud and identity theft. Online fraud comes in many forms. viruses that attack
computers with the goal of retrieving personal information, to schemes that lure victims into
wiring money to fraudulent sources,
“phishing” s that purport to be from official entities (such as banks or the Internal
Revenue Service) that solicit personal information from victims to be used to commit identity
theft, to fraud on online auction sites (such as Ebay) where perpetrators sell fictional goods.

spoofing to make the user to enter the personal information : financial fraud

Illegal intrusion: log-in to a computer illegally by having previously obtained actual


password. Creates a new identity fooling the computer that the hacker is the genuine operator.
Hacker commits innumerable number of frauds.

Pornographic offenses: Child pornography

Means any visual depiction, including but not limited to the following: Any photograph
that can be considered obscene and/ or unsuitable for the age of child viewer.

Software piracy

Theft of software through the illegal copying of genuine programs or the counterfeiting
and distribution of products intended to pass for the original. It can be done byEnd-user copying,
Hard disk loading with illicit means, Counterfeiting, Illegal downloads from internet.

Buying Pirated software have a lot to lose:

Getting untested software that may have been copied thousands of times.

Potentially contain hard-ware infecting viruses

No technical support in case of software failure

No warranty protection

No legal right to use the product

Computer sabotage

Computer sabotage involves deliberate attacks intended to disable computers or networks


for the purpose of disrupting commerce, education and recreation for personal gain, committing
espionage, or facilitating criminal conspiracy. It happens through viruses, worms, logic bombs.

E-mail bombing/mail bombs

In Internet usage, an bomb is a form of net abuse consisting of sending huge volumes of
to an address in an attempt to overflow the mailbox or overwhelm the server where the address is
hosted in a denial-of-service attack. It involves to Construct a computer to repeatedly send to a
specified person’s address. The attacker can overwhelm the recipient’s personal account and
potentially shut down the entire system.

Computer network intrusions


An intrusion to computer network from any where in the world and steal data, plant
viruses, create backdoors, insert trojan horse or change passwords and user names.

An intrusion detection system (IDS) inspects all inbound and outbound network activity
and identifies suspicious patterns that may indicate a network or system attack from someone
attempting to break into or compromise a system. The practice of strong password can prevent
this type of attacks.

Password sniffing

Password sniffers are programs that monitor and record the name and password of
network users as they login, jeopardizing security at a site. Through sniffers installed, anyone
can impersonate an authorized user and login to access restricted documents.

Credit card frauds

Credit card fraud is a wide-ranging term for theft and fraud committed using or involving
a payment card, such as a credit card or debit card, as a fraudulent source of funds in a
transaction. The purpose may be to obtain goods without paying, or to obtain unauthorized funds
from an account. Credit card fraud is also an adjunct to identity theft.

Identity theft

Identity theft is a fraud involving another person’s identity for an illicit purpose. The
criminal uses someone else’s identity for his/ her own illegal purposes. Phishing and identity
theft are related offenses

Examples:

Fraudulently obtaining credit

Stealing money from victim’s bank account

Using victim’s credit card number

Establishing accounts with utility companies

Renting an apartment

Filing bankruptcy using the victim’s name

===========================================================

The Indian IT ACT 2000 and amendments:


● India has the fourth highest number of internet users in the world with 45 million internet
users. 37% - in cybercafes and 57% are between 18 and 35 years
● The Information Technology (IT) Act, 2000, specifies the acts which are punishable.
Since the primary objective of this Act is to create an enabling environment for
commercial use of I.T.
● In India, the ITA 2000 was enacted after the United Nation General Assembly Resolution
A/RES/51/162 in January 30. 1997 by adopting the Model Law on Electronic Commerce
adopted by the United Nations Commission on International Trade Law.
● This was the first step toward the Law relating to E-Commerce at international level to
regulate an alternative form of commerce and to give legal status in the area of E-
Commerce.
● Cybercrimes are punishable under two categories: the ITA 2000 and the IPC.
● There are some noteworthy provisions under the ITA 2000, which is said to be
undergoing key changes very soon.
===================================

Cyberoffenses:How Criminals Plan Them – Introduction:


Cybercriminals use the World Wide Web and Internet to an optimal level for illegal activities.

These criminals take advantage of the widespread and lack of awareness about cybercrimes and
cyberlaws among people who are constantly using the IT infrastructure for official and personal
purposes.

→ Few terminologies

Hacker: A hacker is a person with strong interest in computers who enjoys learning and
experimenting with them. Hackers are usually very talented, smart people who understand
computers better than the others.

Brute force Hacking: it is a technique used to find passwords or encryption keys. It involves
trying every possible combination of letters, numbers, etc., until the code is broken.

Cracker: a cracker is a person who breaks into computers. They are computer criminals. Their
act include vandalism, theft and snooping in unauthorized areas.

Cracking: it is the act of breaking into computers. Cracking is a popular, growing subject on the
internet. Many sites are devoted to supplying crackers with programs that allow them to crack
computers (like guessing passwords)

Cracker tools: these are programs that break into computers. Like password crackers, Trojans,
viruses, war dialers and worms.

Phreaking: this is notorious art of breaking into phone or other communication systems.

War dialer: it is program that automatically dials phone numbers looking for computers on the
other end. It catalogs numbers so that the hackers can call back and try break in.

Categories of vulnerabilities that hackers typically search for can be explained by a


scenario shown below:
● Inadequate border protection
● Remote access servers(RASs) with weak access controls.
● Application servers with well-known exploits.
● Misconfigured systems and systems with default configurations.

========================================================

Categories of Cybercrime:
Cybercrime can be categorized based on the following:

1. Target of the crime :


a. Crimes targeted at individuals
b. Crimes targeted at property
c. Crimes targeted at organizations
2. Whether the crime occurs as a single event or a series of events
a. Single event cybercrime: hacking or fraud
b. Series of events: cyberstalking

I. Crimes targeted at individuals: The goal is to exploit human weakness such as greed
and naivety. These crimes include financial frauds, sale of non-existent or stolen items,
child pornography copyright violation, harassment, etc. with the development in the IT
and the Internet; thus, criminals have a new tool that allows them to expand the pool of
potential victims. However, this also makes it difficult to trace and apprehend the
criminals.
2. Crimes targeted at property: This includes stealing mobile devices such as cell
phone, laptops, personal digital assistant (PDAs), and removable medias (CDs and pcn
drives); transmitting harmful programs that can disrupt functions of the systems and/or
can wipe out data from hard disk, and can create the malfunctioning of the attached
devices in the system such as modem, CD drive, etc.
[Link] targeted at organizations: Cyberterrorism is one of the distinct crimes
against organisations/governments. Attackers (individuals or groups of individuals) use
computer tools and the Internet to usually terrorize the citizens of a particular country by
stealing the private information, and also to damage the programs and files or plant
programs to get control of the network and/or system
4. Single event of cybercrime: It is the single event from the perspective of the victim.
For example, unknowingly open an attachment that may contain virus that will infect the
system (PC/laptop). This is known as hacking or fraud.
5. Series of events: This involves the attacker interacting with the victims repetitively.
For example, attacker interacts with the victim on the phone and/or via chat rooms to
establish relationship first and then they exploit that relationship to commit the sexual
assault.
=============================================

How criminals Plan the Attacks:

The different types of attacks an attacker can plan are:


Active attack - Used to alter system, affects the availability, integrity and authenticity
of data
Passive attack - Attempts to gain information about the target and leads to breaches of
confidentiality
Inside attack -Attack originating and/or attempted within the security perimeter of an
organization and Gains access to more resources than expected.
Outside attack - Is attempted by a source outside the security perimeter, may be an
insider or an outsider , who is indirectly associated with the organization Attempted
through internet or remote access connection

The following phases are involved in planning cybercrime:


[Link] :
-information gathering , first phase, passive attack
2. Scanning and scrutinizing the gathered information
- for validity of the information as well as to identify the existing vulnerabilities
3. Launching an attack
- gaining and maintaining the system access
[Link] :
● A reconnaissance attack occurs when an adversary tries to learn information
about your network
● Reconnaissance is the unauthorized discovery and mapping of systems, services,
or vulnerabilities.
● Reconnaissance is also known as information gathering
● Reconnaissance is somewhat analogous to a thief investigating a neighborhood
for vulnerable homes, such as an unoccupied residence or a house with an easy-
to-open door or window. In many cases, intruders look for vulnerable services
that they can exploit later when less likelihood that anyone is looking exists.
● Is the preparatory phase to understand the system, its networking ports and
services and other aspects of security, that are needful for launching the attack
● An attacker attempts to gather information in two phases
○ Passive attack
○ Active attacks

● Passive attacks:
● Involves gathering information about the target without his/ her knowledge.
● It is done usually by internet searches or by googling
○ Google or yahoo search: to locate information about employees
○ Surfing online community group: facebook; to gain information about an
individual
○ Organizations website: for personnel directory or information about key
employees; used in social engineering attack to reach the target
○ Blogs, newsgroups, press releases, etc
○ Going through job postings
● Network sniffing: information on Internet Protocol address ranges, hidden
servers or networks or services on the system.
● Tools used during passive attacks
○ Google earth
○ Internet Archive: permanent access for researchers , historians and
scholars to historical collections
○ Professional community: linkedIn
○ People Search
○ Domain Name Confirmation
○ WHOIS
○ Nslookup
○ Dnsstuff
→Active Attacks :
● It is called as rattling the doorknobs or Active reconnaissance
● Involves probing the network to discover individual hosts to confirm the
information gathered in the passive attack phase. Can provide confirmation to an
attacker about security measures in place.
● Tools used during active attacks
○ Arphound
○ Arping
○ Bing
○ Bugtraq
○ Dig
○ DNStacer
○ Dsniff
○ Filesnarf
○ FindSMB
2. Scanning and Scrutinizing gathered information
Is a key step to examine intelligently while gathering information about the target. The
objectives are:
● Port scanning
● Network scanning
● Vulnerability scanning

Port Scanning:
★ It is the act of systematically scanning a computer's ports.
★ Since a port is a place where information goes into and out of a computer, port scanning
identifies open doors to a computer.
★ It is similar to a thief going through your neighborhood and checking every door and
window on each house to see which ones are open and which ones are locked.
★ There is no way to stop someone from port scanning your computer while you are on
the Internet because accessing an Internet server opens a port, which opens a door to
your computer.
★ There are, however, software products that can stop a port scanner from doing any
damage to your system.
★ TCP (Transmission Control Protocol) and UDP (User Datagram Protocol) are two of
the protocols that make up the TCP/IP protocol suite which is used universally to
communicate on the Internet.
★ Each of these has ports 0 through available so essentially there are more than 65,000
doors to lock.
★ The first 1024 TCP ports are called the Well-Known Ports and are associated with
standard services such as FTP, HTTP, SMTP or DNS.
★ Some of the addresses over 1023 also have commonly associated services, but the
majority of these ports are not associated with any service and are available for a
program or application
★ A port scan consists of sending a message to each port, one at a time. The kind of
response received indicates whether the port is used and can therefore be probed for
weakness.
★ The result of a scan on a port is usually generalized into one of the following categories:
1. Open or accepted : The host sent a reply indicating that a service is listening on the
port.
2. Closed or not listening: The host sent a reply indicating that connections will be
denied to the port
3. Filtered or blocked: There was no reply from the host.

Network scanning: Understand IP Addresses and related information about the


computer network.
Vulnerability scanning: Understand the existing weaknesses in the system.

Scrutinizing phase Called as “enumeration” in the hacking world. The objective behind
this step is to identify:

● The valid user accounts or groups


● Network resources and/or shared resources
● OS and different applications that are running on the OS.

3. Attack (Gaining and Maintaining the System Access)

● After scanning and scrutinizing, the attack is launched using the following steps:
○ Crack the password
○ Exploit the privileges
○ Execute the malicious command/ applications
○ Hide the files
○ Cover the track – delete access logs, so that there is no trail of illicit activity.

================================================================

Cybercafe and Cybercrimes


● An Internet café or cybercafé is a place which provides Internet access to the public,
usually for a fee.
● According to Nielsen Survey on the profile of cybercafes users in India:
○ 37% of the total population use cybercafes
○ 90% of this were males in age group years
○ 52% graduates and post graduates
○ > 50% were students
● Hence, it is extremely important to understand the IT security and governance practiced
in the cybercafes.
● The Cybercafe are used for many illegal activities like
○ either real or false terrorist communication.
○ for stealing bank passwords, fraudulent withdrawal of money
○ Keyloggers or spywares
● Some of the problems in Cybercafes
○ Pirated softwares: OS, browser, Office
○ Antiviruse software not updated
○ Cybercafes have installed “deep freeze” software
○ This software clears details of all activities carried out, when one clicks “restart”
button.
○ Annual Maintenance Contract(AMC): not in place
○ Is a risk bez a cybercriminal can install Malicious code for criminal activities
without any interruption
○ Pornographic websites and similar websites are not blocked
○ Owners have less awareness about IT Security and IT Governance.
○ IT Governance guide lines are not provided by cyber cell wing
○ No periodic visits to cybercafes by Cyber cell wing( state police) or Cybercafe
association
● Safety and security measures while using the computer in Cyber Cafe
○ Always Logout:
○ do not save login information through automatic login information
○ Stay with the computer
○ Clear History and temporary files
○ Be alert:
○ don’t be a victim of Shoulder surfing
○ Avoid Online Financial Transaction
○ Change passwords
○ Use Virtual Keyboards
○ Consider security warnings

=======================================================

Botnets: The fuel for Cybercrime


● Bot: “ an automated program for doing some particular task, often over a network”
● A botnet (also known as a zombie army) is a number of Internet computers that, although
their owners are unaware of it, have been set up to forward transmissions (including spam
or viruses) to other computers on the Internet.
● Any such computer is referred to as a zombie - in effect, a computer "robot" or "bot" that
serves the wishes of some master spam or virus originator.
● Most computers compromised in this way are home-based.
● According to a report from Russian-based Kaspersky Labs, botnets -- not spam, viruses,
or worms -- currently pose the biggest threat to the Internet.
● Botnet used for gainful purposes
○ Botnet creation
○ Botnet renting
○ Botnet Selling
○ DDoS attacks
○ Spamdexing
○ Phishing attacks
○ Malware and Adware installation
○ Spam attacks
○ Stealing confidential information
○ Selling Credit card and bank account details
○ Selling internet services and shops account
○ Selling personal identity information

Ways to secure the system from Botnets are :

● Use antivirus and anti-spyware :It is important to remove and/or quarantine the viruses.
The settings of these softwares should be done during the installations so that these
softwares get updated automatically on a daily basis.
● Install updates: OS companies issue the security patches for flaws that arc found in
these systems.
● Use firewall : A firewall is a software and/or hardware that is designed to block
unauthorized access while permitting authorized communications. It is a device or set of
devices configured to permit, deny, encrypt, decrypt, or proxy all (in and out) computer
traffic between different security domains based upon a set of rules and other criteria. A
firewall is different from antivirus protection. Antivirus software scans incoming
communications and files for troublesome viruses vis-I-vis properly configured firewall
that helps to block all incoming communications from unauthorized sources.
● Disconnect internet when not in use : Attackers cannot get into the system when the
system is disconnected from the Internet. Firewall, antivirus, and anti-Spyware softwares
are not foolproof mechanisms to get access to the system.
● Downloading the freeware only from websites that are known and trustworthy: It is
always appealing to download free software(s) such as games, file-sharing programs,
customized toolbars, etc. However, one should remember that many free software(s)
contain other software, which may include Spyware.
● Check regularly the folders in the mailbox — "sent items" or "outgoing" — for
those messages you did not send: If you do find such messages in your outbox, it is a
sign that your system may have infected with Spyware, and maybe a part of a Botnet.
This is not foolproof; many spammers have learned to hide their unauthorized access.
● Take an immediate action if your system is infected: if your system is found to be
infected by a virus, disconnect it from the Internet immediately. Then scan the entire
system with fully updated antivirus and anti-Spyware software. Report the unauthorized
accesses to ISP and to the legal authorities. There is a possibility that your passwords
may have been compromised in such cases, so change all the passwords immediately.

================================================================

Attack vector
● An attack vector is a path or means by which a hacker (or cracker) can gain access to a
computer or network server in order to deliver a payload or malicious outcome.
● Attack vectors enable hackers to exploit system vulnerabilities, including the human
element.
● Attack vectors include viruses, attachments, Web pages, pop-up windows, instant
messages, chat rooms, and deception. All of these methods involve programming (or, in a
few cases, hardware), except deception, in which a human operator is fooled into
removing or weakening system defenses.
● To some extent, firewalls and anti-virus software can block attack vectors.
● But no protection method is totally attack-proof.
● A defense method that is effective today may not remain so for long, because hackers are
constantly updating attack vectors, and seeking new ones, in their quest to gain
unauthorized access to computers and servers.
● If vulnerabilities are the entry points, then attack vectors are the ways attackers can
launch their assaults or try to infiltrate the building.
● In the broadest sense, the purpose of the attack vectors is to implant a piece of code that
makes use of a vulnerability. This code is called the payload, and attack vectors vary in
how a payload is implanted.
● The most common malicious payloads are viruses (which can function as their own
attack vectors), Trojan horses, worms, and spyware.
● If an attack vector is thought of as a guided missile, its payload can be compared to the
warhead in the tip of the missile.
● Different ways to launch Attack Vectors:
○ Attack by E-Mail: The hostile content is either embedded in the message or
linked to by the message, Sometimes attacks combine the two vectors, so that if
the message does not get you, the attachment will, Spam is almost always carrier
for scams, fraud, dirty tricks, or malicious action of some kind. Any link that
offers something “free” or tempting is a suspect.
○ Attachments (and other files): Malicious attachments install malicious computer
code. The code could be a virus, Trojan Horse, Spyware, or any other kind of
malware. Attachments attempt to install their payload as soon as you open them.
○ Attack by deception: Deception is aimed at the user/operator as a vulnerable
entry point. It is not just malicious computer code that one needs to monitor.
Fraud, scams, hoaxes, and to some extent. Spam, not to mention viruses, worms
and such require the unwitting cooperation of the computer's operator to succeed.
Social engineering and hoaxes are other forms of deception that are often an
attack vector too
○ Hackers : Hackers: Hackers/crackers are a formidable attack vector because,
unlike ordinary Malicious Code, people are flexible and they can improvise.
Hackers/crackers use a variety of hacking tools, heuristics, and social engineering
to gain access to computers and online accounts. ‘They often install a Trojan
Horse to commander the computer for their own use
○ Heedless guests (attack by webpage): Counterfeit websites are used to extract
personal information, Such websites look very much like the genuine websites
they imitate. One may think he/she is doing business with someone you trust.
However, he/she is really giving their personal information, like address, credit
card number, and expiration date. They are often used in conjunction with Spam,
which gets you there in the first place. Pop-up webpages may install Spyware,
Adware or Trojans.
○ Attack of the worms : Many worms are delivered as E-Mail attachments, but
network worms use holes in network protocols directly. Any remote access
service, like file sharing, is likely to be vulnerable to this sort of worm. In most
cases, a firewall will block system worms. Many of these system worms install
Trojan Horses. Next they begin scanning the Internet from the computer they
have just infected, and start looking for other computers to infect. If the worm is
successful, it propagates rapidly. The worm owner soon has thousands of
“zombie” computers to use for more mischief.
○ Malicious macros: Microsoft Word and Microsoft Excel are some of the
examples that allow macros. A macro does something like automating a
spreadsheet, for example. Macros can also be used for malicious purposes. All
Internet services like instant messaging, Internet Relay Chart (IRC), and P2P file-
sharing networks rely on cozy connections between the computer and the other
computers on the Internet. IF one is using P2P software then his/her system is
more vulnerable to hostile exploits.
○ Foistware (sneakware): Foistware is the software that adds hidden components
to the system on the sly. Spyware is the most common form of foistware.
Foistware is quasi-legal software bundled with some attractive software. Sneak
software often hijacks your browser and diverts you to some “revenue
opportunity” that the foistware has set up.
○ Viruses : These are malicious computer codes that hitch a ride and make the
payload. Nowadays, virus vectors include E-Mail attachments, downloaded files,
worms etc.

You might also like