0 ratings0% found this document useful (0 votes) 37 views272 pagesUntitled
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content,
claim it here.
Available Formats
Download as PDF or read online on Scribd
Lorena MIHAES$ Diana IONITA
ENGLISH
FOR
CYBEh-SECURITY
AWARENESS
CavalliotiINTRODUCTION
English for Cyber-Security Awareness is a course for upper-intermediate students enrolled
in the BA and MA studies, both from the Foreign Languages and Literatures (Applied
Modern Languages, The Culture and Language of the European Organizations) as well as
Business Administration and Affairs, Communication and Public Relations at the University
of Bucharest.
This book is also aimed at providing a guide for all the readers interested in cyber-attacks,
showing the main risks as well as solutions for different types of this phenomenon.
The key word is awareness: the readers will become aware of a phenomenon which is
present in all their activities, they will become aware of the features of this phenomenon, of
the risks as well as of the solutions to those risks.
This course includes twenty-four units having the following structure:
+ Background information introduces the text.
« A section of activities including exercises aimed at developing reflection on that
topic (2), writing skills (2s), reading skills (CQ) and speaking skills (), together
with a variety of drilling exercises (2).The activities are presented in a gradual way,
from simple to complex. There are exercises which ask the learner to make decisions,
to express opinions, to use the specialised terminology in contexts of their own, thus
stimulating the readers’ creativity.
© Focus on language and language development section 28S\ includes both
lexical and grammar topics as well as a range of activities.
* Specialised terminology focuses on a selection of the main specialised terms used in
that particular text.
The originality of this book relies in personalizing the aquired information, filling in a gap
regarding textbooks on English specialised vocabulary for Cyber Security.
At the end of each unit, the learner will be able to use appropriate information and phrases in
appropriate situations with a good command of the English grammar.
The purpose of our endavour is twofold: on the one hand, to make the readers aware of the
cyber security issues, on the other hand, to provide a useful instrument facilitating the study
of the new concepts, English specialised vocabulary and grammar issues under one and the
same topic .
N.B. This course does not include the key to exercises since it is meant to be used as teaching
material for the above-mentioned types of students. The key to exercises will be solved by the
students individually and corrected by their teacher during the seminar classes.
Lorena Mihiies
Diana IonitaABLE OF CONTENTS
Unit 4: Cyberattack - An Overview
Unit 2: Cyberattacks: Means and Methodologies
Unit: Examples of Cyber-Attacks
Unit4: Equifax Says Cyberattack May Have Affected 143 Million in the U.S. (Part I)
Unit: Equifax Says Cyberattack May Have Affected 143 Million in the U.S. (Part I)
Unit 6: Cyber jihadists (Part!)
Unit 7: Everything Is Hackable (Part I)
Unit8: Cyber Terrorism Is ‘Biggest Threat to Aircraft”
Unit9: Cyber-crime
Unit 10: Quantum Computers
Unit 4: Cyber Attack in Australia 2017: Business Hit by Ransomware
Unit 12: Everything Is Hackable (Part Il)
Unit 13: Israet's Computer-security Firms
Unit 14: Cyber-jhadists (Part I)
Unit 15: The Intemet of Stings
Unit 16: Cyber-warfare. Digital doomsters
Unit 17: The Truth behind the "Biggest Cyber Attack in History"
Unit 18: How to Combat a Cyber Attack
Unit 19: Virtual Libraries
Unit 20: Deloitte Identifies 14 Business Impacts of a Cyberattack
Unit 21: Cyber Terrorism — How Reals the Threat? (Part |)
Unit 22: Cyber Terrorism — How Reali the Threat? (Part I!)
Unit 23: Big Brother Is Watching You
Unit 24: Digital Privacy
50
61
72
85
96
107
119
130
141
151
163
175
186
196
208
218
229
239
249
261Unit 1
Cyberattack - An Overview
BACKGROUND INFORMATION
1. Definition
In computers and computer networks an attack is any attempt to expose, alter, disable, destroy, steal or gain
unauthorized access to or make unauthorized use of an Asset, A cyberattack is any type of offensive
manoeuvre that targets computer information systems, infrastructures, computer networks, or personal
computer devices. Depending on context, cyberattacks can be labeled as a cyber campaign, cyberwarfare or
cyberterrorism. A cyberattack can be employed by nation-states, individuals, groups, society or
organizations. A cyberattack may originate from an anonymous source.
A cyberattack may steal, alter, or destroy a specified target by hacking into a susceptible system.
Cyberattacks can range from installing spyware on a personal computer to attempting to destroy the
infrastructure of entire nations. Legal experts are seeking to limit the use of the term to incidents causing
physical damage, distinguishing it from the more routine data breaches and broader hacking activities,
Since the late 1980s, cyberattacks have evolved several times to use innovations in information technology
as vectors for committing cybercrimes.
CNSS Instruction No. 4009 dated 26 April 2010 by Committee on National Security Systems of United
States of America’ defines an attack as: Any kind of malicious activity that attempts to collect, disrupt, deny,
degrade, or destroy information system resources or the information itself.
The increasing dependencies of modern society on information and computers networks (both in private
and public sectors, including military) has led to new tems like cyber attack and cyberwarfare.
2, Cyberwarfare and cyberterrorism
Cyberwarfare utilizes techniques of defending and attacking information and computer networks that
inhabit cyberspace, often through a prolonged cyber campaign or series of related campaigns. It denies an
opponent's ability to do the same, while employing technological instruments of war to attack an
opponent’ critical computer systems. Cyberterrorism, on the other hand, is "the use of computer network
tools to shut down critical national infrastructures (such as energy, transportation, government operations)
of to coerce or intimidate a government or civilian population "That means the end result of both
cyberwarfare and cyberterrorism is the same, to damage critical infrastructures and computer systems
linked together within the confines of cyberspace.
3. Factors
Spectacularity factor
‘The spectacularity factor is a measure of the actual damage achieved by an attack, meaning that the attack
Creates direct losses (usually loss of availability or loss of income) and gamers negative publicity. On
February 8, 2000, a Denial of Service attack severely reduced traffic to many major sites, including
Amazon, [Link], CNN, and eBay (the attack continued to affect still other sites the next day). Amazon
reportedly estimated the loss of business at $600,000.
Vulnerability factor
Vulnerability factor exploits how vulnerable an organization or government establishment is to cyber-
attacks. An organization can be vulnerable to a denial of service attack, and a government establishment
can be defaced on a web page. A computer network attack disrupts the integrity or authenticity of data,
Usually through malicious code that alters program logic that controls data, leading to errors in output.4, Professional hackers to cyberterrorists
Professional hackers, either working on their own or employed by the government or military service, can
find computer systems with vulnerabilities lacking the appropriate security software. Once found, they can
infect systems with malicious code and then remotely control the system or computer by sending
commands to view content or to disrupt other computers. There needs to be a pre-existing system flaw
within the computer such as no antivirus protection or faulty system configuration for the viral code to
‘work. Many professional hackers will promote themselves to cyberterrorists where a new set of rules
govern their actions. Cyberterrorists have premeditated plans and their attacks are not born of rage. They
need to develop their plans step-by-step and acquire the appropriate software to carry out an attack. They
usually have political agendas, targeting political structures. They also target civilians, civilian interests and
civilian installations. As previously stated cyberterrorists attack persons or property and cause enough harm
to generate fear.
5. Types of attack
Anattack can be active or passive.
‘An “active attack” attempts to alter system resources or affect their operation.
A "passive attack" attempts to learn or make use of information from the system but does not affect system
resources (¢.g., wiretapping).
‘Types of attacks
© Passive
Computer and network surveillance
Network: Wiretapping, Fiber tapping, Port scan, Idle scan
© Host: Keystroke logging, Screen scraping, Backdoor
+ Active
© Denial-of-service attack
© Spoofing
© Network: Man-in-the-middle, Man-in-the-browser, ARP poisoning, Ping flood, Ping of
death, Smurf attack
© Host: Buffer overflow, Heap overflow, Stack overflow, Format string attack
(Adapted from Wikipedia, the free encyclopedia)
stop and think 8
Exercise 1
Which is the significance of the following sentence, in your opinion:
The increasing dependencies of modern society on information and computers networks (both in private
and public sectors, including military) has led to new terms like cyber attack and cyberwarfare.speaking OF
Exercise 2
Identity the five most representative key words underlying the meaning of cyberattack. Choose from
the words below:
to breach, to destroy, malicious activity, to warn, crime,
War, attempy, threat, negociate, army.
Provide your comments on the lines below.
drills ?
Exercise 3
Read the following sentences and fill in the missing word:
a
Cyberwarfare utilizes ... of defending and attacking information.
A "passive attack" does not affect... resources,
There are two types of factors.
Cyberattack is any kind of... on activity,
The attacks are of two types:
‘Some professional hackers work on their own or may be employed by
. on apersonal
- the infrastructure of
Cyberattacks can range from installing.
‘computer to attempting to .
entire nations.
Cyberattacks can infect systems with ...... code,
Cyberattack, oF... is the result of the increasing
dependencies of modem society on information and computers networks.speaking OF
Exercise 4
Work with a partner and identify four effects of cyberattacks on institutions, computers, etc:
writing 2
Exercise 5
Write about your opinion on hackers, their activity and special skills. What actions should be taken
against them?reading (2
Exercise 6
Read the following paragraph and elaborate on it by providing concrete examples of acti
governments should take in order to defend themselves from cyberattacksy ns Betions that
Vulnerability factor exploits how vulnerable an organization or Bovernment establishment is to cyber-
attacks. An organization can be vulnerable to a denial of service attack, and a government establishment
can be defaced on a web page.
drills 2
Exercise 7
Collocations: words that go together. Match words from column A and column B:
A B
1. cyber a. scraping
2._to generate _ ». tapping
3._ computer _ ¢. attack
4. screen 4. factor
5._to carry out . maneuver
6._ wire £. surveillance
7._ civilian g. hacker
8._ offensive fh, network
9. network [Link]
10. system j-population
11. professional an attack
12. vulnerability 1. fear
5 10:...45 1writing 2
Exercise 8
‘Translate into English:
Efectul general al terorismului cibernetic este acela de a genera frica si de a specula vulnerabilitiile din
sistemul de calculatoare ale diferitelor banci, guverne, institufii nationale sau private, din cele mai diverse
domenii.
Am devenit tot mai dependenti de sistemele informatizate, devenind astfel vulnerabili in fafa atacurilor
cibernetice.
Un astfel de atac poate distruge integritatea datelor, folosind un asa numit cod malitios.
Hackerii igi au propia agenda de operare, fintele lor fiind persoane private, insititufii administrative, uncle
chiar cu carater militar. Bi lucreaz& fie pe cont propiu, fie ca angajafi ai unor refele. Scopul acestora este de
a depista punctele slabe ale calculatorului side a distruge baza de date.
10reading 2
Exercise 9
Read the text again and match the following words with their corresponding definitions:
A B
[Link] a. an incident where information is stolen or taken from a system without the
knowledge or authorization of the system's owner.
2. hacker ’. a method of bypassing normal authetification or encryption in a computer
system- a tiny computer-within-2-computet
3. cyberwarfare ‘ca person who uses computers to gain unauthorised access to data.
4. data breach 4d. close observation, especially of a suspected spy or criminal; here of a
network or computer system.
5. wiretapping ¢. the action of using a computer program to copy data from a website.
6. keystroke logging
7, sereen scraping
fa series of messages sent by smb attempting to break into a computer to
Tearn which computer network sevices, each associated with a ,well-
known’ port number, the computer provides; in this way the assailant gets an
idea where to probe for weakness.
g the quality or state of being exposed to the possibility of being
attacked/harmed, either physically or emotionally.
8. backdoor
h. the action of recording logging the keys struck on a keyboard, typically
covertly, so that the person using the keyboard is unaware that their actions
are being monitored.
9. idle scaning
10. port scan
11. network surveillance
i. an attempt by hackers to damage or destroy a computer network or system
{j. the use of computer technology to disrupt the activities of a state or
organization, especially the deliberate attacking of information systems for
strategic or military purposes.
. sending spoofed packets to a computer to find out what services are
available.
12, vulnerability
the practice of connecting a listening device to a telephone line to monitor
conversations secretly.
Man-in-the-middle:.
105 Boose
drills ?
Exercise 10
312...
Look up the following specialised terms in the dictionary and provide their definitions:
WFormat string attack:
reading £0
Exercise 11
Read the following sentences and label them as TRUE or FALSE:
1. Spectacularity factor exploits how vulnerable an organization or government establishment is to cyber-
attacks.
2. In computers and computer networks, an attack is any attempt to expose, alter, disable, destroy, steal or
gain unauthorized access to or make unauthorized use of an Asset.
3. The increasing dependencies of modem society on information have led to new terms like hacking.
4, Professional hackers can protect systems with malicious codes.
5. A passive attack attempts to alter system resources or affect their operation.
6. Cyberattacks can range from installing spyware on a personal computer to attempting to destroy the
infrastructure of entire nations.
7. Cyberterrorists have premeditated plans and their attacks are born of rage.
8. Cyberterrorists develop their plans step-by-step and acquire the appropriate hardware to carry out an
attack.
9. Acyberattack may originate from an anonymous source.
10. A computer network attack disrupts the integrity or authenticity of data.
(cc 2
[3
12On the dotted lines below, provide the correction of the FALSE sentences:
PSR
FOCUS ON LANGUAGE AND GRAMMAR DEVELOPMENT
A. Word Formation: Synonyms and Antonyms
drills
Exercise 12
Use the corresponding synonyms to the words below:
CL SYNONYMS
war
to destroy
damage
linked
major
authentic
logic
errors
appropriate |
Surveillance
idledeills ?
Exercise 13
Use the corresponding anonyms to the words below:
ANTONYMS
professional
to attack
to destroy
to find
to obey
software
to steal
to breach
adequate
to infect
active
B. Making Suggestions
Study the following examples:
Set - phrases
Examples
What about... vb-ing?
‘What about reading this article on cyerattacks?
Let Seeresoned
Let's find out more about computer system
protection.
Shall we.
Shall we warn people about this computer virus?
Why don't you wwe?
Why don’t you take actions against hackers?
Would you like to.
Would you like to find more information about
cyberterrorists?
How about.....vb-ing?
How about finding the vulnerable features of our
system?
You could.
You could be more cautious about this phenomenon:drills?
Exercise 14
Study the above-mentioned table and fill in the blanks:
.u t0 read this article together?
.» addressing the government on this issue?
2
3. protect your system against this virus?
4 .» talk about the latest cyberattack and see the consequences!
5. learn several lessons from this case-study?
6. _.Fesort toa specialised expert.
1. .. try to fix your own computer yourself?
Specialised terminology
‘cyber-attack _| An attempt by hackers to damage or destroy a computer network or system.
cyberwarfare | The use of computer technology to disrupt the activities of a state or organization,
especially the deliberate attacking of information systems for strategic or military
purposes.
cybercrime | Criminal activities carried out by means of computers or the Internet
data breach | An incident where information is stolen or taken from a system without the knowledge
| or authorization of the system's owner.
hacking Gaining unauthorized access to data in a system or computer.
spyware Software that enables a user to obtain covert information about another's computer
activities by transmitting data covertly from their hard drive.
wiretapping | The practice of connecting a listening device toa telephone line to monitor
conversations secretly
surveillance | Close observation, especially of a suspected spy or criminal.
Keystroke | The action of recording logging the keys struck on a keyboard, typically covertly, so
logging that the person using the Keyboard is unaware that their actions are being monitored.
port scanning | A series of messages sent by smb. attempting to break into a computer to learn which
computer network sevices, each associated with a well-known port number, the
computer provides; inthis way the assailant gets an idea where to probe for weakness.
idle scanning _| Sending spoofed packets to a computer to find out what services are available.
denial-of- | Acyber-attack in which the perpetrator seeks to make a network resource unavailable
service attack | by temporarily or indefinitely disrupting services of a host connected to the Internet.
spoofing ‘A fraudulent or malicious practice in which ‘communication is sent from an unknown
source disguised as a source known to the receiver.
15Unit 2
Cyberattacks: Means and Methodologies
BACKGROUND INFORMATION
Denial-of-service attacks, classified as “cyberattacks,” have been used by hackers since the mid-1980s,
‘Aimed primarily at specific sites and networks, denial-of-service attacks block the access of legitimate
users, rendering the entire site or network unavailable. This can be accomplished through any number of
‘methods, including the relentless transmission of irrelevant information to tie up a server so that legitimate
requests for information remain unanswered. Attackers can also use these cyberattacks to obstruct the
transmission of routing information; as a result, legitimate requests never reach their destination
Alternatively, computer hackers could use cyberattacks to obstruct communication between two servers or
networks so that information cannot be sent or received by either party. Cyberattacks can also include the
use of malware, a program whose name is derived from the combination of the words “malicious” and
“software;” such programs can destroy the victim’s system software or hardware, or tum the victim's
computer into a “zombie” system to be utilized in future attacks. The most common attacks known today
are flood attacks, logic/software attacks, mailbombing, permanent denial-of-service (PDoS) attacks,
accidental denial-of-service attacks, and distributed denial-of-service (DDoS) attacks.
Flood attacks overload systems by overwhelming them with irrelevant information or requests that tie up
the server so that legitimate user requests go unfulfilled. “Smurfing,” also known as ICMP flooding, is one
such type of attack that has commanded much attention from both hackers and cybercrime experts alike.
Smurf attacks shut down servers by sending the victim’s IP network address to broadcasting computers,
which in turn “broadcast” the IP address to other computers, beginning a chain reaction, These computers
then respond by sending information packets back to the victim's IP, overloading the server.
While flood attacks work to simply overload a server or system, logiclsoftware attacks force errors by
manipulating, and thereby breaking, communication protocols, these cyberattacks are usually most
effective on systems that have not kept their bug fixes up to date. The “Ping of Death” attack is an
example.
Hackers can utilize both flood and logic software attacks to disrupt an array of systems, from websites to
entire networks. Conversely, a “mailbombing” attack is much more limited in scope since it only targets e-
mail accounts and servers. The at-tacker uses a tool fo send thousands of e-mails at a time to a single
address, which renders the user unable to receive e-mail until the excess has been deleted. Mailbombing
attacks were most effective in the Tate 1990s, when space allotted for e-mail inboxes remained small.
Today, popular e-mail clients, such as Yahoo! or Gmail, grant their users an abundance of memory.
Permanent denial-of-service attacks cause significantly more damage. Known colloquially as “phlashing,”
this type of cyberattack is a relatively new phenomenon, first gaining significant press coverage in May
2008. Unlike other denial-of-service attacks that generally only cause service disruption, the permanent
denial-of-service attack effectively destroys system hardware; users must reinstall it in order to run the
system again. This cyberattack is carried out by a process known as “bricking a system;” a hacker sends the
targeted system false hardware updates tha, in turn, render the hardware in question completely useless.
It is important to note that denial-of-service attacks do not always occur intentionally. In 2006, the video
‘website YouTube was sued by Universal Tube & Rollform Equipment, a small Ohio-based company, for
initiating an accidental denial-of-service attack. This accidental cyberattack invariably forced the company
to purchase more bandwidth, and Universal Tube & Rollform Equipment sued YouTube as a result.
When executing a distributed denial-of-service attack, a hacker attacks a network or server through the use
of hundreds or thousands of “zombies,” computers whose security has been compromised; this allows the
hacker to silently take control of the target without the owner's knowledge. The hacker will often channel
16the attacks through other associates, called “handlers,” in order to further masquerade his or her identity.
‘The use of botnets, entire networks of zombies that can be “rented” online, in the case of Estonia’s 2007
Cyberwar isa prime example.
Lof-service attacks have existed in different forms since the mid-1980s, but distributed denial-of-
seevce attacks frst came into play as recently as 1999, The first documented case involved a hacker who
‘ed a network of 227 zombie computers to overload a single computer at the University of Minnesota,
The system was knocked offline for more than two days as a result. Since that time, distributed denial-of-
service attacks have been implemented to attack scores of online retailers and resources including
[Link], eBay, E*Trade, and CNN.
(Adapted from InernationalAffirs Review: Denial-of Service: The Es
tions for U.S National
tp [Link]/)
(Cyberwar and Is Impl
Security,
stop and think 8
Exercise 1
In your opinion, which are the hackers’ main targets? Give six examples.
17riner and identify the differences between denial-of-service attack and permanent
denial-of-service attack:
reading
Exercise 3
Read the text and rank the following types of cyber attacks from 1 to 6 (I = the most serious, 6= the
least serious):
Flood attacks, logic/software attacks, mailbo
ymbing, permanent denial-of-service (PDoS) attacks, accidental
denial-of-service attacks, distributed denial-of service (DDoS) attacks,
1
18drills ?
Exercise 4
Provide the two words contributing to the structure of the following blendings, according to the
following model:
malware: malicious + software
brunch...
camcorder:
laundromat.
Chunnel...
motel:
smog:
hi-tech.
hangry..
chillax.
bionic
emoticon...
slobish....
reading
Exercise 5
Read the following sentences and label them as TRUE or FALSE:
1. Permanent denial-of-service attacks cause significantly less damage than accidental denial-of-
service attacks.
2. Denial-of-service attacks always occur intentionally.
3. Hackers can utilize both flood and logic software attacks to disrupt an array of systems, from
websites to entire networks,
4. Mailbombing attack only targets e-mail accounts and servers.
5. Smurfing is also known as mailbombing.
6. Permanent denial-of-service attacks are also known colloquially as “phlashing”.
7. Permanent denial-of-service attack is carried out by a process known as “bricking a system”.
198. The attacker uses a tool to send thousands of e-mails at a time to a single address.
9. Smurf attacks shut down servers by sending the victim’s bank account to broadcasting computers.
10. The hacker will often channel the attacks through other associates, called “zombies”.
10
On the dotted lines below, provide the correction of the FALSE sentences:
20delle?
Exercise 6
Fill in the blanks using words from the text:
.. could use cyber-attacks to obstruct communication.
2. Denial-of-service attack effectively destroys system.
3, The hacker will often channel the attacks through other associates, called ...
4, ‘The accidental cyber-atack forces the company to purchase more...
5. Generally, flood attacks overload systems by overwhelming them with .
information.
6. Malware is derived from the combination of the words .... and “software”.
7. Denial-of-service attacks block the access of legitimate ...
8. Flood attacks work to simply overload a. OF system,
Logicisoftware attacks are usually most effective on systems that have not kept their
fixes up to date,
10, Frequently, computer hackers use cyberattacks to obstruct . . between two
Servers or networks so that information cannot be sent or received by either party
24iting os
Exercise 7
‘Translate into Romanian:
Mailbombing isto send or urge others to send massive amount of electronic mail to @ single system or
person, with intent o crash or spam the recipients system, A successful mail bom may cause the victim's
Eisk quo to be exhausted, the disk holding his mailbox to fill up, or his computer to spend large
proportion of is time processing mail.
Maifbombing is sometimes done in retaliation against someone persistently abusing usenet and violating
etiquette,
While it may inconvenience the intended victim, it will probably also inconvenience other users and
administrators of computers and networks involved,
Mailbombing is thus a serious offense itself.
22crills?
Exercise 8
Use the name of the people mentioned in the text:
can also use these cyberattacks to obstruct the transmission of routing information,
2. Distributed denial-of-service attacks have been implemented to attack scores of online
will often channel the attacks through other associates, called
ises a tool to send thousands of e-mails ata time to a single address,
5. The hacker takes control of the target without the...
'sknowledge.
6. Smurf attacks shut down servers by sending the .....
broadcasting computers.
’s IP network address 10
7. Popular e-mail . grant their users an abundance of memory.
crills ?
Exercise 9
Study the behaviour of the phrasal verb TO GET:
Get across
1. to communicate,
2. to make someone understand something.
Get along - Get on with
1. to have a good / friendly relationship with someone.
Get around
1.= to become known; to spread orto circulate.
2.= to find a way of avoiding a difficult or unpleasant situation, so that you do not have to deal with it.
23Get at
1. = to reach, to access to something
2. = 0 suggest something indirectly, to imply (used only inthe continuous tense)
Get away
1.-= to go away from someone or something.
2. = to escape from someone who is chasing you.
3.= to have a holiday.
Get down
1. to cause someone to be depressed.
Get down to
1.= to reach the point of dealing with something.
2. = to begin to work on something seriously. To give serious attention to something.
3. =to finally start doing something, after you have been avoiding it or after something has prevented you
from doing it.
Get on
1. = to put yourself on or in something.
2. = to remind someone to do something; to continue,
Get out of
1,= to avoid something.
2. =10 physically remove yourself from somewhere or something.
Get over
1. = to recover from something or return to your usual state of health or happiness.
2. =o overcome or deal with or gain control of something.
Use the correct form of the phrasal verb To Get in the sentences below:
1. Lam trying hard after my computer has been completely ruined by a virus.
2. 1 think it is high for the government and fix those serious problems about the
cyber attack,
3. The members of this IT deportment stat. with each other.
4. Authorities are in charge with the right message to the population.
‘5. Hackers shouldn't be allowed... Without punishment.
7. We should al .. con a short city break after such 4
‘turmoil.
8. The head of our department decided to ........ [Link] order to avoid dealing with this
mess again.
9... .with this project!
10. I think Susan is able now s-eand try forget about this incident.
24Bs
FOCUS ON LANGUAGE AND GRAMMAR DEVELOPMENT
A. Word Formation: Prefixation
‘Study the following examples of prefixes carrying a specific meaning:
Prefix Example Meaning
oo ‘co-author doing things together
mid midnight in the middle
over overdone Tmore than necessary
vunder- underdone Jess than necessary
1 rearrange doing itagain
elf selthelp Torfby oneself
sub subway under
ua undo doing the reverse
ceils
Exercise 10
Use the correct prefixes with the correct form of the root word in capitals:
1. You shouldn't interupt people in. SENTENCE
2. Workacoholic people have the tendency to .. WORK
3, Dont an wuthe impact of cyber-attacks. ESTIMATE,
4. This study isthe outcome of several... AUTHOR
255. Hackers are sometimes and attack even governments CONFIDENT
[Link] to... .this system from scratch. BUILD
7. Use a proper key 0. this door. Lock
8 Many people have the feeling that they are Pee PAY
9, When temperatures drop... pput on warm clothes. ZERO
B. Question Tags
Use
‘Short questions asking for agreement or confirmation.
b. Rule
Affirmative verb in the main clause—+ question tag: negative verb + inversion,
‘Negative verb in the main clause—+ question tag: affirmative verb + inversion
c. Examples
Affirmative verb in the main clause» question tag: negative
verb + inversion
Negative verb in the main clause» question tag
affirmative verb + inversion
‘She reads a lot, doesn't she?
‘She doesn't read a lot, does she?
They are winners, aren't they?
‘They aren’t winners, are they?
You can win, can't you?
You can’t win, can you?
He has gota safe computer, hasn't he?
He hasn't gota safe computer, has he?
4. Special cases
‘They have a shower, don't they?
Let's do it, shall we?
used to be a good surfer, didn't I?
Lam overworked, aren't I?
Don't use a faulty sticker, will you?
‘There is anew cyber attack, isn't there?
This is anew cyber attack, isn't it?
Everybody is here, aren't they?
SSNS K SNK
26drills ?
Exercise 11
Use the correct question tag in order to complete the following sentences:
1, Don’t underestimate hackers...
2, ‘They had a dea...
3. This study doesn’t emphasize the risks hackers take,
4, Lets take actions against cyber terrorism,
5, Wehave got the results here, .
6. There is a new type of cyber attack,.
7. Tam used to this type of virus.
8. You don’t agree,
9. This is your proposition...
10. Everybody should be well informed about cyberattacks,
Specialised terminology
malware
Software which is specifically designed to disrupt, damage, or gain authorized
access to a computer system,
zombie computer
‘A computer connected to the intemet that has been compromised by a hacker,
virus computer virus or trojan horse program and can be used to perform malicious tasks
of one sort or another under remote direction.
distributed denial- | The intentional paralysing of a computer network by flooding it with data sent
of-service (Dd0S) | simultaneously from many individual computers.
flood attack | A form of denial-of-service attack in which the attacker sends a succession of syn
requests to a target's system in an attempt to consume enough server resources 0
‘make the system unresponsive to legitimate traffic.
‘smurfing | A form of denial-of-service attack in which a large number of internet Control
Message Protocol (ICMP) packets with the intended victim's spoffed source IP are
broadcast to a computer network using an IP broadcast address.
phlashing ‘A form of denial-of-service attack that exploits a vulnerability in network-based
firmware updates.
botnet ‘Anetwork of private computers infected with malicious software and controlled as a
group without the owner's knowledge, e.g. to send spam.
27Unit 3
Examples of Cyber-Attacks
BACKGROUND INFORMATION
Cyber-attacks fall into one of three categories:
1. The criminal and the victim know each other (e.g. current or former employee/spouselpartner, The
motivating factor is money and/or revenge, and the main distinguishing feature is that the perpetrator ‘has or
had access to the victim's computer and able to prepare ther attack in advance, plant malware, ec, In this
category, cyber-spying also takes more of a role, via web cams, microphones, and keyloggers,
2. The criminal and the victim have some sort of relationship or the victim is somehow known tothe
criminal (eg. contact made via a social networking site ot victim is famous / rich / owns something ite
criminal wants). The selection of the victim is not random, however, they typically have not met in person
nor has the criminal had physical access to the victim’s computer.
3. The criminal does not know the victim and the victim is merely the random individual ensnared by the
criminal’s phishing scam or other similar technique. The sole motivation is financial gain.
Types
a. Emails with Attachments Containing Viruses/Malware
One of the most well-known methods of disseminating malware, the malicious software is hidden in a
email attachment. Once the attachment is opened, the malicious software executes and/or downloads onto
the computer.
b. Emails with Links to Poisoned or Malicious Websites
Often referred to as “phishing,” these emails appear (or attempt to appear) as legitimate correspondence
from a financial or other institution that the Tecipient would tend to trust and respond to. The links in these
emails, however, lead to a fake website in an attempt to trick the recipient into entering sensitive
information such as passwords and financial account numbers, while the malicious website may attempt to
install malware, viruses or spyware on the recipient's computer.
¢. Social Networking Pages/Profiles with Links to Malicious Websites
Similar to emails with links, this method is becoming more popular, particularly with the widespread use of
social networking sites such as Facebook, Twitter and Linkedin,
d. Probing Firewalls/IPSs/IDSs for Backdoors and Other Weaknesses
Here hackers simply send out transmissions en masse, in hopes of compromising any firewalV/IDS/IPS they
may chance across and thereby gaining access to the computer system behind it.
e. Inserting Malicious Packets into Legitimate Communic:
This is a newer technique, which relies on access to a stable of “zombie computers” in order to send out
large quantities of packets to a large number of recipients, targeting a specific port. This type of attack is
very difficult, if not impossible, to trace without packet capture.
ion Streams
£, Advertisements Disseminating Malware to Viewers
This method of ack i harder to voi, given the ubiquity of pad adverisemenss across the inte
Cybercriminals can place ads containing malicious code on legitimate websites that most visitors woul
tend to trust, by purchasing ads directly, hijacking the ad server or hacking someone else's ad account.
28g: Pre-Installed Malware
The past few years have yielded numerous reports of foreign-manufactured IT equipment, such as
computers, routers and switches, arriving out of the box with malware pre-installed. In September 2012,
Microsoft announced that it found new computers in China sold with malware pre-installed, and in April
2012 HP revealed that the previous year some of its switches shipped with malware-laden Flash cards
h, Malware Sold as Legitimate Software
Buying malware from no-name sellers can present dangers as well. Though it may provide the promised
function, it also may be embedded with malicious software. Fake antivirus programs have infected millions
of computers in this fashion with anything from trojans to spyware.
i, Advanced Persistent Threats (APTs)
The term APT does not entail any specific type of attack or infiltration technique, rather it refers to a
sustained (persistent) multi-pronged attempt to break into a specific organization’s or institution's data
networks. When used, it would upload and install a malicious file on the computer. APTS are generally
employed by teams of hackers intent on specific information and take place over the long term, lasting
months and years.
(http:/wwwwipcopper.comfexamples_of_attacks htm)
stop and think 8
Exercise 1
In your opinion, which could be the main ways to prevent email containing viruses?
2gdrills?
Exercise 2
Match beginnings with endings, in order to construct logical sentences:
Beginnings
Endings
1. The criminal and the victim
‘a. social networking pages/profiles with links to
malicious websites extremely popular.
2. There are three categories of
. is one of the motivating factors of cyber-attacks,
3. The widespread use of social networking sites
such as Facebook, Twitter and LinkedIn.
c. on purpose.
4, Phishing is a synonym of
d. to the computer system behind the firewall.
5. Money
e. damaged Microsoft system.
6. Buying malware from no-name sellers can be
£, a sustained (persistent) multi-pronged attempt to
break into a specific organization's or institution's
data networks.
7, Hackers select their victims
g, have some sort of relationship.
8, Hackers try to gain access
h. emails with links to malicious websites.
9. Computers with malware pre-installed
i. dangerous.
10. The term APT stands for
[Link]-attacks.
10
reading EQ
Exercise 3
Read the text and answer the following questions:
1. What type of cyber-attack contains a malicious software that is hidden in an email attachment?
2. Which are the categories of cyber attacks in which the hackers know or have a certain relationship
with the victims?
303, What motivates hackers in their criminal acts?
4, Which technique relies on zombie computers?
5, ATPis the abbreviated form; which is the long form?
6. How long is the impact of ATP?
7. What type of information do hackers try to enter?
dills?
Exercise 4
Use the correct form of to gain, to earn, to win in the following sentences:
1. Itis difficult to .... ... aocess to this system.
2. Shei really happy: she has just .... sou the Silver Cup.
3. Teachers should +. their students’ respect.
4, Hackers have generally ... the press’ curiosity
5. Hackers attack those victims who a lot of money.
6. They donot... ...a lot: they can barely survive.
at the lottery.
7. You may live a long time without .
8. Weneed to .........s0.0 a decent living.
9. Ifyou want to... sxperience in this field, you should practice a lot.
involves a lot of work.
wolves luck,
31drills ?
Exercise 5
Read the sentences and use the correct word/words to fill in the gaps:
zombie computes, to gain, hackers, cyber attack, victims, gain, packets, malware, poisoned, random
1. People with a huge financial .. are the main target.
2. Sometime, cyber-terrorists choose their victims at ..
3. By using
large number of recipients.
hackers send out large quantities of packets to a
4, They try all sorts of attacks in order to ..
access to the victims’ computer systems.
5. Some people tend to admire the .n for their ingenuity.
‘There were cases when computers arrived out of the box with ..
installed.
...can be grouped in three categories.
8. Emails with links to ..
. websites are a real danger.
‘There are types of cyber attacks which are very difficult to trace without
. capture.
10. The criminal and the
.. May or may not know each other.
writing 2
Exercise 6
‘Translate into Romanian:
“Email bombing,” despite its militaristic connotation, is an old form of cyber attacking, Bad actors use the
attack for a variety of reasons, but itis primarily flooding an unsuspecting person's inbox with messages in
an attempt to achieve something. Sometimes the flood of emails is an attempt to obscure a bad act such as
hacking someone’s phone account, ordering a new iPhone, and then flooding the victim's email box i
hopes of burying the new phone confirmation email. Other times the motives are revenge or more nefarious
objectives like disrupting the command and control of governmental agenEmail bombing is cheap and €28Y
to carry out. Someone can even hire out a service to do it for them that is virtually untraceable. A quick
search on Twitter shows several services willing to do a bad actor’s bidding. To give you an idea of how
32cheap it is, SMS bombing or email bombing costs around
one to two dollars a day, whereas a 30-day long
troll —which consists a combination of SMS bombing an
\d email bombing— only costs 30 dollars.
(https:/[Link]/emailing-bombing-old-new/)
33,reading 2
Exercise 7
Read the text below and look up the underlined words in the dictionary, providing their translation
into Romanian:
The digital marketing landscape is in a bit of an
one place where they know their reliable schemes
from desktop, and the tactics that once worked there seem
devices.
What's worse, new fraud tactics have continuously ouismarted once-reliable tracking methods. As
technology gets increasingly better, sophisticated mobile ad fraud tactics continue fo-evolve as well, And
there's reason for panio across the mobile ecosystem—mobile fraud is much more difficult to catch,
But there are solutions in the mobile marketing supply chain, Loopholes remain, but proactive mobile
growth platforms have established best practices on helping advertisers combat fraud and to smariy
navigate the complex mobile marketing landscape.
(ClkickZintps:/[Link]/3-ways-advertisers-combat-ad-fraud-mobile-marketng)
upheaval. Fraudsters have gotten wise and jumped tothe
have a chance: mobile. These bad actors have shifted
to have free reign when it comes to mobile
To evolve:
Mobile marketing supply chain...
‘To combat:
34TE
FOCUS ON LANGUAGE AND GRAMMAR DEVELOPMENT
A. Word Formation: Abbreviations
drills?
Exercise 8
Provide the long forms for the following abbreviations:
Long form ‘Abbreviated form
L ad
2 maths
3. flu
4. pram
5. doc
{6 bus
1. [vet
8. Zoo
9. hanky
| 10. IPS
i Ds
B. If Clauses
First conditional (Zero Conditional)
If Clause _[ Main Clause _| Use Example
Ife will future Real situation If you write to them, they will write back
Present (likely to happen in the immediately.
present or future)
General truth If you leave ice cream in the sun, it
melts
NB. If is followed by the verb in the Present Tense like time adverbials such as when, as soon as, by the
time, until, etc.
f/ When /As soon as I troubleshoot the error, I will et you know:
35Second conditional
YS
If Clause Main Clause | Use Example |
if +Subjunctive would+ Imaginary situationin | If this hacker made
infinitive | the present or future | mistakes, he would be
NB. (impossible or unlikely | caught immediately by
Subjunctive has the same form to happen) the authorities, |
as the Past tense, except for the |
verb to be (were) Af were you, I would |
install a strong antivirus
_ _ software in the system,
Third conditional
If Clause Main Clause | Use Example
If + Past Perfect Would have + | Imaginary situation in | Ifthey had had more
Past Participle | the past (regrets, advanced technology,
(third form) | unfulfilled wishes or | they would have been
plans) able to prevent the fraud.
daills 2
Exercise 9
Fill in the blanks using the correct verb form:
1. Ifyou work hard, (have) a lot of success.
2 TfL... . (be) you, I wouldn't admire hackers,
3. We would have had better results if our team (anticipate) the malware risks.
4, If the authorities had been more careful, the cyber terrorists .... ss (be) caught.
a Tf he.
6. Unless they ..
7. If they couldn’t find the solution to the computer system, the board ...
them.
8 Ifl.....
36
(leave) the issue unsolved, he would have regretted afterwards.
+++ (tell) the truth, the government will not find the culprit.
(su)
(lose) all my data overnight, I would feel helpless.writing 2
Exercise 10
If Chain
Follow the example below and write an if-chain sequence starting like this:
Ifthe hacker were caught, 6 lines).
Model:
Ifwe had more money, we would install an antivirus software.
If we installed an antivirus software, the computer wouldn’t be infected.
Ifthe computer weren’t infected, we could save a lot of information on it
If we saved a lot of information, we would support the entire computer system of the company.
If we supported the entire computer system, we would be rich.
Ifthe hackers were caugh
37drills ?
Exercise 15
Underline the correct solution form the words in italics below:
1. We will do something right away when / if you ask for help.
2. If/when he behaved aggressively, everybody wanted to hire him.
3. We may agree if/as long as you comply with the regulations.
4. They could reach agreement if/ unless you admitted your deed.
5. He will not pay the price required by you if/ unless they solve this error.
6. If/When you want them to agree, send them a catalogue with samples for each software,
7. Assoon as/If they reach agreement, they will let us know.
8. If/ When you call your lawyer, we can start.
Specialised terminology
perpetrator person who carries out harmful, illegal, or immoral acts.
malware Software which is specifically designed to disrupt, damage, or gain
authorized access to a computer system.
packet capture A computer networking term for intercepting a data packet that is
crossing or moving over a specific computer network.
keylogger A computer programme that records every keystrole made by @
computer user, especially in order to gain fraudulent access 10
passwords and other confidential information.
random Made, done, or happening without method or conscious decision.
to ensnare To catch in or as ina trap.
ubiquity ‘The fact of appearing everywhere or of being very common.
to purchase To acquire smth. by paying for it.
to embed To enclose closely in or as if in a matrix, to make smth. an integral
part of, to insert into a computer.
38Unit 4
Equifax Says Cyberattack May Have Affected
143 Million in the U.S.
Part I
By Tara Siege! Bemard, Tiffany Hsu, Nicole Perlroth and Ron Lieber
BACKGROUND INFORMATION
Equifax, one of the three major consumer credit reporting agencies, said on Thursday that hackers had
gained access to company data that Potentially compromised sensitive information for 143 million
American consumers, including Social Security numbers and driver's license numbers.
The attack on the company represents one of the largest risks to personally sensitive information in recent
years, and is the third major cybersecurity threat for the agency since 2015-Equifax, based in Atlanta, is a
particularly tempting target for hackers. If identity thieves wanted to hit one place to grab all the data
needed to do the most damage, they would go straight to one of the three major credit reporting agencies.
Criminals gained access to certain files in the company’s system from mid-May to July by exploiting a
weak point in website software, according to an investigation by Equifax and security consultants. The
company said that it discovered the intrusion on July 29 and has since found no evidence of unauthorized
activity on its main consumer or commercial credit reporting databases. In addition to the other material,
hackers were also able to retrieve names, birth dates and addresses. Credit card numbers for 209,000
consumers were stolen, while documents with personal information used in disputes for 182,000 people
were also taken,
Other cyberattacks, such as the two breaches that Yahoo announced in 2016, have eclipsed the penetration
at Equifax in sheer size, but the Equifax attack is worse in terms of severity. Thieves were able to siphon
far more personal information — the keys that unlock consumers’ medical histories, bank accounts and
employee accounts.
“On a scale of 1 to 10 in terms of risk to consumers, this is a 10,” said Avivah Litan, a fraud analyst at
Gartner.
An EBLL spokesperson said the agency was aware of the breach and was tracking the situation.
Last year, identity thieves successfully made off with critical W-2 tax and salary data from an Equifax
website, And earlier this year, thieves again stole W-2 tax data from an Equifax subsidiary, TALX, which
provides online payroll, tax and human resources services to some of the nation’s largest corporations.
Cybersecurity professionals criticized Equifax on Thursday for not improving its security practices after
those previous thefts, and they noted that thieves were able to get the company’s crown jewels through a
simple website vulnerability.
“Equifax should have multiple layers of controls” so if hackers manage to break in, they can at least be
stopped before they do too much damage, Ms. Litan said.
Potentially adding to criticism of the company, three senior executives, including the company's chief
financial officer, John Gamble, sold shares worth almost $1.8 million in the days after the breach was
discovered. The shares were not part of a sale planned in advance, Bloomberg reported. The company
handles data on more than 820 million consumers and more than 91 million businesses worldwide and
‘Manages a database with employee information from more than 7,100 employers, according to iits website.
(Adapted from Sept. 7, 2017, New York Times)
39stop and think 8
Exercise 1
Which would have been your reaction if you had been a client of Equifax and such an attack on you,
personal data had happened?
a
drills?
Exercise 2
Match the words in the two columns according to the text above:
A B
T._ personal a._accounts
2._ medical b._agencies
(3. employee c.__databases
4 main d._data
S._unauthorized e._information
6._reporting f._ credit
T._sensitive g._consumer
8._license h._histories
9._ to manage i,_activity
10._ commercial je_mumbers I
_
1 2 3 4 5 7 8 9 10reading C2
Exercise 3
Read the text again and use the following words in contexts of your own:
database, credit card, hackers, website, consumers, risks, evidence, intrusion, shares, spokesperson
le
10.
drills ?
Exercise 4
Study the following examples:
I gain experience.
Twin at the Lottery.
Tearn my living.
Fill in the gaps with the correct verb:
1. This not easy 10 .....sessenn good salary nowadays.
2. They are so lucky: the ... the first prize in that competition.
3. This hard to... .. people’s trust and admiration,
4, Hackers . huge amounts of money for their risky endeavor.
[Link] boss .... _ respectability after finding proofs against those cyber criminals
6. She... sc ssdher living trying to meet both ends.
[Link] could . . the senior manager’s confidence.
4drills ?
Exercise 5
Use the following words in the gaps below:
to-employ, employer employee, unemployed, employment, unemployment employed
1. Asan. sas he should be strict.
2 _ is a serious issue nowadays.
3. They tty 10... sacs the best IT experts.
4. .. he proved his skills in the IT domain.
5. after making those errors, jeopardizing the whole computer system.
..of thousands of workers in this filed.
6. Government supports...
7. They got sucess . immediately after presenting the CV on troubleshooting computer
errors,
writing 2
Exercise 6
Translate into Romanian:
The increase in the rate of identity theft in the United States—highli i
se in | ighted by the massive Equifax data
breach earlier this year—has lawmakers at state and federal levels taking action. wes
Elected officials are pushing legislation to help victims and tighten regulations. The goal is to enact laws
that enhance security and protection measures, as well as provide remedies for consumers affected by data
breaches.
A central feature of much of the new legislation is to mandate free credit freezes and related acti
consumers whose data has been breached. Unless you're an identity theft victim, in which case credit
freezes are free, credit reporting agencies can charge up to $10 to freeze a single credit report and, possibly,
another fee to unfreeze it. With three major credit reporting agencies in possession of such data, #
consumer might want to pay three times for each freeze to ensure the best possible protection,
42speaking O
Exercise 7
Work with a partner and outline five actions you could take against Equifax as a potential victim of
the cyber-attack mentioned in the text:
43wiiting es
Exercise 8
Look up the following words in the dictionary and provide a definition for each of them:
WORD DEFINITION
payroll
theft
to break in |
sensitive
sensible
evidence
worldwide
to grab
stop and think 8
Exercise 9
Express your opinions on the following motto about safety:
A safer you is a safer me.
44|. We wonder: should we ......
drills ?
Exercise 10
Study the behavior of the Phrasal verb TO GIVE and fillin the gaps below:
«give something away = give something because you do not want or need it.
«give something away = tell something secret.
+ _ give somebody away = show where somebody is or what they are doing, when they are trying to
keep this a secret.
+ give in = accept that you are defeated, surrender.
+ give something in = give something to someone in authority = hand in,
+ give off something = produce a smell, heat, sound, etc,
+ give onto something = lead to a place.
+ give out = stop working properly, become weaker.
+ give something out = hand out.
+ give over = stop doing something that is annoying other people.
+ give up = stop trying to do something, surrender.
Don't push your team too hard; otherwise they will.
propery.
Ok...
.! You are better at computer programming.
They.
..trying since the competitors succeeded in fixing that problem faster.
Don’t insist: you might .
our scheme.
Our secret and the hackers can be wamed about
This device ..... a smell and some fumes: I am afraid it is completely ruined.
We should these obsolete computers, somebody else may need them.
‘The examiners ... ---the tests to all the candidates,
this bad habit: some people might feel annoyed.
Tn the end they were all congratulated upon and golden diplomas.
ind thus show our vulnerability, oF ............-.- and thus showing
that the competition is too harsh for us?
45DE
FOCUS ON LANGUAGE AND GRAMMAR DEVELOPMENT
A. Giving advice
Study the following structures below:
| Had better + Pres. Inf.
You'd better anticipate your boss’ requirements.
| Should + Pres. Inf.
You should be more cautious,
Shouldn't + Pres. Inf. You shouldn’t rely on the computer system only.
(iild advice +obligation)
Ought to + Pres. Inf. You ought to use an anti-virus protection..
(strong advice + obligation)
If were you,
IfI were you, I wouldn’t trust them.
Itis advisable
Itis advisable to call a troubleshooter.
Itwould be a good idea
Ttwould be a good idea to protect your personal data,
The best thing you can
‘The best thing you can do is address the authorities on this
issue,
I strongly advise you to
{strongly advise you to think twice before asking him to check
Your files,
drills?
Exercise 11
Provide your advice for the following situations using some of the above-stated structures:
1. Your company represents one of the largest risks to Personally sensitive information,
2. Criminals gained access to certain files in your company’s system,
463. You are a fraud analyst.
4, Hackers were able to retrieve names, birth dates and addresses of your customers.
B. Modal verbs expressing obligation and lack of obligation
Obligation
Structures Examples
must + short inf. You must obey the netiquette,
have to You have to obey the rules.
have got to You have got to install a stronger antivirus software,
should + Pres. Inf. You should fight against this malware.
ought (to) + Pres. Inf. You ought to protect your clients’ personal data against cyber attacks.
Have to expresses external obligation
‘Must expresses obligation imposed by the speaker.
Lack of obligation
Structures Examples
needn't + short inf. You needn't attend the meeting tomorrow.
don’t have to You don't have to attend the meeting tomorrow.
47writing es
Exercise 12
Rewrite the flowing sentences using the word in capitals.
1. You have to protect my customers’ data,
MUST.
2. There is no need to install this software.
HAVE..
3 It isn’t necessary for him to admit his fraud. He is innocent.
NEED.
4. It's not right that CEOs are allowed to shout at their employees.
SHOULD...
5. It's important to start this anti cyber attack campaign soon.
6, tis obligatory for the government to find the most appropriate means against the hackers.
7. The boss doesn’ tlike the way have solved this issue lately.
OUGHT TO..
8, The members of your team feel offended by your behavior.
SHOULD.
9. She must tell the truth.
HAVE TO...
48Specialised terminology
criminal A person who has committed a crime.
cyber security ‘The protection of internet-connected systems from cyber-attacks.
software ‘The programs and other operating information used by a computer.
hardware ‘The machines, wiring, and other physical components of a computer or
other electronic system.
to grab To grasp or seize suddenly and roughly.
intrusion The act of intruding or the state of being intruded.
to retrieve ‘To find or extract information stored in a computer.
breach An act of breaking or failing to observe a law, agreement, or code of
conduct.
severity ‘The seriousness of something bad or unpleasant.
worldwide Throughout the world.
49Unit 5
Equifax Says Cyberattack May Have Affected
143 Million in the U.S.
Part II
By Tara Siegel Bernard, Tiffany Hsu, Nicole Perlroth and Ron Lieber
BACKGROUND INFORMATION
Equifax also houses much of the data that is supposed to be a backstop against security breaches. The
agency offers a service that provides companies with the questions and answers needed for their account
recovery, in the event customers lose access to their accounts,
‘If that information js breached, you've lost that backstop,” said Patrick Harding, the chief technology
officer at Ping Identity, a Denver-based identity management company.
Equifax said tht, in addition to reporting the breach to law enforcement, it had hired a cybersecurity firm
‘0 conduct a review to determine the scale ofthe invasion, The investigation is expected to wrap up in the
next few weeks.
Using the data stolen from Equifax, identity thieves can impersonate people with lenders, creditors and
Service providers, who rely on personal identity information from Equifax to make financial decisions
‘egarding potential customers. Equifax has created a website, [Link], t0 help
consumers determine whether their data was at risk. People can go to the Equifax website to see if their
information has been comy
the site provides an enrollment date for its protection service,
and it may not start for several days.
‘The company also suggests getting a free copy of your credit re
Equifax, Experian and TransUnion. These are available
contacting a law enforcement agency if you believe any s
Protection service, which is free for one
and not just the victims of the breach,
Port from the three major credit bureaus:
at [Link]. It also suggests
stolen information has already Equifax’s credit
‘year for consumers who enroll by Nov. 21, is avail
lable to everyone
Beyond compromising the personal data of million
national security threat. In recent years,
and federal agencies, siphoning detailed
assaults in an effort
S of consumers, the breach also poses a potential
Chinese nation-state hackers have breached insurers like Anthem
Personal and medical information. These hackers go wide in their
‘0 build databases of Americans’ personal information, which can be used for
“Cyberwar is in large part conducted through data mining and cyberintelligence,” Ms. Litan said. “This is
Also a Homeland Security risk as enemy nation states build databases of Americans that they then use o get
‘o their targets, for example a network operator at a power grid, or a defense contractor at a missile defense
company.”
“It is no exaggeration to suggest that a breach such as this — exposing highly sensitive personal and
Financial
information central for identity management and access to credit — represents a real threat to the
economic security of Americans,” he said in a statement.
(Sept. 7, 2017, New York Times)
50sing and think 8
Exercise 1
In your opinion, which were the mistakes made b;
Equifax taken to prevent the cyber attack?
Mistakes:
Grills ?
Exercise 2
'Y Equifax? Which previous actions should have
Match words from A to words from B to make compounds or collocations:
A B
1. cyber a base
2. cyber b. _provider
3 cyber c. breach
4. credit a war
5. web € threat
6. power f. security
7. data & card
8. security he intelligence
9. security i, grid
10. law i. bureau
I. credit k. date
12, service L enforcement
13, enrollment m, site
_ 2,314 17 9 [0 [nln le
51speaking O
Exercise 3
Work with a partner and identify the effects of Equifax cyber attack on Equifax on the US citizens:
drills ?
Exercise 4
Prefixes such as : il-, im-, un-, dis-, in-, ir- have the meaning of NON.
Provide the antonyms to the words below using one of these prefixes:
1 available:..
52honest:
comfortable:..
satisfied...
reading
Exercise 5
Read the text again and label the following statements as TRUE or FALSE:
1
2.
cybersecurity firm is able to conduct a review to determine the scale of the cyber attack.
Abreach may represent a real asset to the economic security of the citizens.
Cyberwar causes data mining and cyberintelligence.
. Equifax website doesn’t allow people see if their information has been compromised.
. People may contact a law enforcement agency in case of stolen information.
The site encourages customers to offer their last name and the last six digits of their Social
Security number, and they get confirmation about whether they were affected immediately.
- Abreach can compromise the personal data of millions of consumers.
- Abreach cannot pose a potential national security threat.
- Hackers try to ruin the databases of Americans’ personal information.
-—. 3 4 5 6 7On the dotted lines below, provide the correction of the FALSE sentences:
wiiting 2
Exercise 6
Translate into English:
La un an dupa atacul de la Equifax, autoritijile au redactat un raport examindnd cauzele bresei in
sistemul informafiilor cu caracter personal. Sunt sintetizate erorile din interiorul firmei, cu precddere lipsa
controlului intern, si folosirea inadecvat& a sistemului de securitate.
La data atacului cibernetic, se specula cd se vor lua masuri drastice referitor la protectia datelor de pe
carfile de credit.
Dimpotriva, nimic din acestea nu s-a intamplat
Actiunile Equifax au suferit o scidere major& initial, dar situafia s-a ameliorat simjtor ulterit
Compania continua s& primeasc& contracte mari din partea guvernului.daills?
Exercise 7
Use the correct following missing words in the text below:
telling, click, number, up, determine, digits, receive, breach, card, read, next, visit, website, enter, if
information,
You can .if your personal. Was among the breached data following the
the Equifax cybersecurity
a 1¢ information to understand the offering;
a -begin enrolment;
v
...0f Your social security.
nV OUs jour
your last name and the last six ..
¥ You will see a message
have been affected in the data...
..an enrolment date,
Y Whether you are affected or not, you will
Bauifax says that those who sign ....f0r its free offer do not have to provide a credit.
55speaking CF
Exercise 8
Speak with a partner, imagining that you are the representative of ‘Equifax company and your
y's client whose personal information have been breached, Use
partner is one of the com|
7, Follow the flow-chart below:
information provided in exe!
Equifax representative, Client
Greet your client
See Greet Equifax expert
Ask what the problem is. ge
5 eseribe your problem,
oe
jose
Give the first piece of advice. a
Ask for more details.
Explain the steps that should be followed.
"Ask more questions regarding the
necessity to provide your Social security
number.
Reassure your client on this issue.
ea :
Express gratitude.
Equifax representative
Client.
Equifax representative...Equifax representative...
FOCUS ON LANGUAGE AND GRAMMAR DEVELOPMENT
A. MAKE and DO seem to have the same translation : a face.
Yet, they are used separately in distinct contexts and collocations.
Study the table below:
MAKE DO
Make the bed Do the room
Make a phone-call Do The Law/The Languages/
Make London Do London
Make an appointment Do the housechores
Make a cake Do the cooking
Make peace/war Do the washing
Make excuses Do the washing-up
Make apologies Do the dusting
Make room for Do the shopping -
Make an offer Do the letters
Make a start Do well at school
Make a fortune Do one's best
Make friends Do anything
57drills ?
Exercise 9
Use either MAKE or DO to fill in the gaps:
LT. my homework.
2. She Will... anything to succeed.
3. The agency
\im an offer.
4. Hackers... _a fortune after a massive attack.
. certain that those errors are corrected in due time.
6. The company ... __oa mistake ignoring the consequences ofthis cyber attack.
Il the house chores, whereas he... nothing.
7. She...
8. Iwill wy to _an appointment with a representative of the government.
9. She is an efficient secretary: she .........all the letters leaving only one or two for her boss to
answer.
B. MODAL VERBS EXPRESSING PROHIBITION
Structures Examples
imustn’t+ bare infinitive ‘You mustn't use this infested computer.
can't +bare infinitive You can't miss this appointment (you are not allowed)
to be not to You are not to trust this hacker.(it is against the rules)
N.B. Must isthe only verb in English whose negative form does not refer to its opposite meaning in
the affirmative form.
Must: trebuie
Mustn’t : nu ¢ voie
Must in the negative is replaced by needn’t,
58voriting
Exercise 10
Rewrite the following sentences using the appropriate words in capitals:
1, Itis against the rules to contact hackers in this activity.
BE..
2. It is forbidden to steal personal data.
MUST...
3. None is allowed to smoke in here.
CAN'T...
4. Itis prohibited to breach a government agency.
MUST...
5. You are not allowed to ignore those safety actions.
CAN’T..
6. Ttis against the rules for this company to use their customers as target for eyberwar.
ARE.
1. Itis forbidden to use this infested computer
MUST..
8. Hikers are not allowed to throw rubbish in the woods,
CAN'T.
9. Itis against the rules to take those rare books at home.
BE...
10. NO smoking!"
CAN'T.
59Specialised terminology
cyberwar
‘The use of computer technology to disrupt the activities of a
state or organization, esp. the deliberate attacking of
information systems for strategic ot military purposes.
Cyber Threat Intelligence
The collection of intelligence using open source intelligence
(OSINT), social media intelligence (SOCMINT), human
intelligence (HUMINT), technical intelligence or intelligence |
from the deep and dark web. Its mission is to research and
analyze trends and technical developments in Cybercrime,
Hacktivism and Cyberespionage.
black market
An illegal traffic or trade in officially controlled or scarce
commodities.
to expose
‘To make smth. visible by uncovering it. To reveal the true,
objectionable nature of smb. or smth.
law enforcement
The action or activity of compelling observance of or
compliance with the law.
scale ‘The size or extent of smth,
digit Any of the numerals from 0 to 0, esp. when forming part of a
umber.
anthem ‘A communications agency that helps companies find their
‘most powerful voice to forge meaningful connections and
: shared purpose with their communities of interest.
data mining ‘The practice of examining large pre-existing databases in
order to generate new information,
hacktivism
The use of technology to promote a political agenda or @
social change.
60Unit 6
Cyber-jihadists
Tech Giants Are under Fire for Facilitating Terrorism
(Part I)
BACKGROUND INFORMATION
‘There is no doubt that the way IS uses the intemet adds greatly to the fear that terrorists set out to foster.
But security experts differ in their assessment of its overall impact. “If there is a message that resonates, it
will get out there,” says Nigel Inkster, a former intelligence officer. What the internet has changed, he says,
is the speed at which the message travels, and its ubiquity.
‘Although online jihadist content can trigger or reinforce radicalisation, it is rarely enough on its own.
Creating a terrorist usually requires grooming through offline social networks that provide the camaraderie
of shared purpose and the personal bonds which create feelings of obligation.
There is, however, broad agreement that the internet both amplifies the impact of terrorism and launches
some disaffected youths on the path to jihad. The violent images they view desensitise them. Propaganda
validates their extremist ideology, provides them with the support of a community and primes them to act
by emphasising purification through sacrifice.
All this puts the big internet firms in a bind. They have no interest in helping users spread extremism, and
already ban pro-terrorist content in their terms and conditions. But they have been slow to police fake news
and extremist propaganda, lest they be accused of making editorial judgments about what can be shared on
their platforms. They have mostly relied on reporting systems, whereby users flag extremist content and
companies decide whether to remove it after reviewing it. This is cumbersome, slow and costly. Facebook
recently announced that it plans to double its workforce of content moderators, hiring another 3,000.
Mark Zuckerberg, Facebook's boss, has said he wants to invest in artificial intelligence to root out terrorist
propaganda, but that it will take many years to develop new tools, In the meantime, the social network and
other platforms must rely on human moderators, who have to make difficult judgments. Facebook's
guidelines, which were recently leaked, show how hard itis to distinguish posts that should be removed
from those that are offensive but permissible. For example, posting “I’m going to destroy the Facebook
Dublin office” is allowed, but posting “I’m going to bomb the Facebook Dublin office” is not, because itis
‘more specific in suggesting a weapon.
Some firms are experimenting with new tactics. Jigsaw, a sister company of Google, has tested a “redirect
method”, showing ads and videos that counter IS propaganda to people who search for extremist material
n Google and YouTube. Microsoft is trying something similar for its search engine, Bing. Last year
Google, Facebook, Twitter and Microsoft agreed to work together on a database, where they mark terrorist
content With a unique identifier. Other companies can spot tagged content and remove it from their own
Platforms. But the database is at an early stage and includes only the worst material,
Firms are waking up to the fact that if they do not find ways to work with governments, they will be forced
to do 0. They fear laws along the lines of one recently proposed in Germany that would see them fined
Vast sums unless they speedily remove any content that has been flagged as hate speech. They also have a
‘growing commercial interest in cracking down on terrorist content, which hurts their brands and could cut
Tevenue. In recent months some of YouTube's clients pulled their ads after realising that they were
appearing next to extremist videos.
The idea of. forcing firms to put “back doors” into their software that authorities could use to spy on
terrorists has been largely abandoned. It would make the software less secure for al its users, might violate
61Fee-speeth protections in America and would anyway be impossible, since some messaging apps,
including Telegram (developed by a Russian) are beyond the reach of Western laws.
The authorities do, however, have other options. Once an intelligence agency has access toa targets phone
ot laptop, almost anything is possible. These devices’ built-in cameras and microphones make them
excellent for bugging. Or the spooks can install covert monitoring software to see what is being displayed
‘on the screen and to log a user's keystrokes. Since messages must be decrypted before their recipients can
read them, this makes it possible to bypass even the strongest encryption.
Governments and tech firms now broadly accept that they have a common interes in establishing global
standards for exchanging data across borders. Brad Smith, the president of Microsoft, argued for a change
in the legal framework, which he said “impedes America's allies’ legitimate law-enforcement
investigations” and exposes American tech firms to potential conflicts of jurisdiction. Greate legal
certainty, less confrontation and more co-operation between governments and firms will not drive jihadist
propaganda off the internet altogether. Bu they should clear the worst material from big sites, Rep stop
some terrorists—and absolve tech firms from the charge of complicity with evi.
(Adapted from [Link] economist. com/interational/2017/06/08/tech-giants-are-under-fire-forfaclitating terrorism)
stop and think 8
Exercise 1
very city seems to have its floating population of disaffected youths ~ school dropouts, oceasiona!
workers, drug users and dealers, skateboarders, hooligan, street people. How much ofa problem is
this? What are its dimensions? What are the social causes that influence the size and nature ofthis
population inthe big metropolises? Why do you think that some of them resort to radicalisaton?
sand are there social programs that can significantly diminish the number of young people who wind
up in this category?
62reading (2
Exercise 2
Answer the following questions based on the text:
1. What are the main two changes brought about by the intemet, according to Nigel Inkster?
[Link] the spreading of online jihadist content the main factor of radicalisation?
[Link] does the internet influence some disaffected youths?
4. Why do big internet firms have problems in controlling online extremist propaganda?
[Link] content moderation done by humans or by computer programs?
6. What kind of database do big internet firms try to create?
7. How do you explain the statement that governments try to put “back doors” into the software of the
intemet companies?
8. Which can be the side effects of stricter regulations regarding the content posted on the internet?
9- What isthe common interest of governments and tech firms?speaking O
Exercise 3
Do you think that governments and tech companies should do more to fight hate speech, extremism,
and content that promotes terrorism? Give your opinion on how much governments should interfere
with private businesses.
writing 2
Exercise 4
Translate into English:
Aproape de a fi invinsa pe teren, in Irak
cibernetic un ‘califat virtual’ de unde va
experi gi oficiali. $i risc& sa fie mai dificil
‘internetului intunecat’,
simpatizangi sii.
Sub presiunea unor puteri publice, furnizorii de servicii si marii actori ai internetului mondial au
introdus masuri si proceduri in incercarea de a impiedica folosirea de c&tre SI a rejelei mondiale pentru a se
organiza si a rispandi propaganda. insi, in ciuda intensificdrii vigilenfei autorititilor si rejelelor de
socializare, Statul Islamic a dat dovadi de o rezistenti semnificativa, datoriti usurinjei de acfiune,
caracterului modular, adaptabilitaii in fafa incercirilor de suprimarea a materialelor jihadiste online.
Gruparea ,reugeste astfel s& menting o diseminare suficienta pentru a atinge bazinul sau de simpatizanti si ®
face noi recrutiri”, adauga ei.
si in Siria, gruparea Statul Islamic va constitui in spafiul
ntinua lupta si fi va stimula pe sustindtorii sai, atrag atenfia
Il de a indeparta gruparea jihadist din colturile ascunse ale
de unde propaganda sa ar putea continua sé ii incite la acfiune pe membrii siPropaganda online a Statului Islamic, care a descris perioada 2014-2015, cfnd gruparea controla
regiuni imense din Siria si Irak, ca fiind ‘epoca de aut’, va fi ,extrem de dificil de combatut”, avertizears
Charlie Winter. .Nu poti si cenzurezi interetul. Autoriifile ipi indreapta atenfia asupra pati gresite a
internetului (refeaua de mare public), iar asta ¢ 0 problems (...) Jihadigti se ascund in internetul profund,
folosind criptii. Vor exista intotdeauna refugii pentru teroristi pe internet, indiferent ce spun politiceni””
completeazi el.
(hitps:/[Link]/)
65drills?
Exercise 5
‘Match the words in the two columns according to the text:
= 7 —
1 hate a._ moderators
2._ back, b._ apps
3.__disaffected c._agency
4, content d._giant
5._ intelligence e._ intelligence
6._unique f._ speech
7._ messaging g. enforcement
8._ artificial h,_ youths
9. tech i._ identifier
10. law j__door
1 2 3 4 3 6 7 8 9 10 |
drills ?
Exercise 6
Replace the underlined words/expressions in the following
sentences with words given in the box
bellow. Make any necessary changes:
cumbersome ‘camaraderie ubiquity
to impede toleak ina bind
to prime to bypass complicity
1. Their computers contained evidence of their collaboration with international terrorists.
2. They ignored the commitee and went straight to senior management,
3.1 was well prepared forthe meeting and gave avery succesful presentation,
4.A poor diet can hinder mental and physical growth,
5. He tried to lug the heavy luggage up the stairs,
6. Playing together in school would give them a feeling of fellowship and a sense of belonging.
667. He quit without giving notice and now we're really in ahole,
§.The price at which the van Gogh had sold was anonymously disclosed to the press, presumably by
somebody working for the auction house.
49, Recent developments in cognitive linguistics have highlighted the importance as well as the
‘omnipresence of metaphor in language.
PSK
FOCUS ON LANGUAGE AND GRAMMAR DEVELOPMEN'
A. 1. Phrasal verbs: VERB + OUT
eg... the fear that terrorists set out ro foster.
‘The most common meanings of out in phrasal verbs:
1. excluding: leave out, count out, force out, kick out, keep out, throw out, ec.
¢.g. The terrorists have driven out the residents of the village. (to drive out=to make something or someone
goaway)
2. removing: to clean out, 10 take out, to drop out, etc.
€8. She wiped out the explanation and started a new topic. (to wipe out= to erase something that is written)
3. extending from its surroundings (also figurativelly): jut out, stand out, etc.
©. The rocky peninsula juts out into the bay. (to jut our= to stick out beyond)
4. separating: to pick out, to spread out, etc.
©8. She picked out a pair of shoes from among the dozen the salesgir! had shown her. (to pick out=to
choose one from a large group)
5. distributing: ro share out, to hand out, etc.
In her will, she shared out her property to her nephews and nieces.
67Other meanings of out in phrasal verbs:
Phrasal verb Meaning
go out (of a fire) stop burning
| fill out complete a form
pass out i faint
draw out make something last for longer then usual or necessary
bring out make more noticeable
lash out (at somebody) criticise someone in an angry way
test out see how it works in a practical situation
drills?
Exercise 7
Complete these sentences using a phrasal verb with out. Put it in the correct form:
1. You need to
all the sections on this application.
2. He really
at me when I suggested that he had got everything wrong.
3. The teacher ....
the English books to the students
4, With the way he dresses, he always manages to ..
5. 1s so hot in here, I feel as though I'm going to
6. Many students ..
challenging program,
after the first year because they are not prepared for our
7. We
- the journey as much as we could but we still arrived early.
8. The lemon
.. the taste of the strawberries.
A.2. Phrasal Nouns
e.g. .. this makes it possible to bypass even the stron,
igest encryption. (phrasal verb)
‘Anew bypass around the city is being built. (phr
asal noun)
Like phrasal verbs, phrasal nouns consist of a verb combined with a particle. The particle may come before
or after the verb (e.g. bypass; warm-up). Ifthe particle is inthe first place, then the phrasal noun is never
written with a hyphen. If the particle comes second, then a hyphen is sometimes used, particularly if the
particle is up or in or if the phrasal noun is not frequent:
e.g, walk-on (a minor acting role, asin a play or on a television episode, usually without speaking lines)
68éaills ?
Exercise 8
Explain the meaning of the following phi
Bapitionary if necessary. g Phrasal nouns and then use them in sentences of your U:
own. Use
1. start-up
2. buyout =
8. letdown =
69B, The Present Simple
e.g. There is no doubt that the way IS uses the internet adds greatly tothe fear that terrorists set out to
{foster But security experts differ in their assessment of its overall impact.
The Present Simple is used in the following situations:
1. Generic sentences (imply the presence of always)
Smooth waters run deep.
Water boils at 100 degrees Celsius.
2. Habitual sentences (a situation is repeated with a certain frequency during an interval)
Large cyber attacks do not always have a direct and immediate effect on individuals.
3. Instantaneous value (sport commentaries, demonstrations, stage directions)
take this card from the pack and place it under the handkerchief,
4, Future value
Ifthere is a message that resonates, it will get out there.
5. Past value (historic Present - employment of the present tense when narrating past events)
He just walks into the room and sits down in front of the fire without saying a word to anyone.
drills ?
Exercise 9
‘Translate the following sentences into English paying attention to the use of Present Simple:
1. Securitatea cibemetic joacd un rol major pentru eliberarea potenfaluli piefeiunice digitale,
2. fn momentul in care primifi un e-mail, nu deschideti atagamente provenind de la persoane necunoscute.
3. Oda ce va fi infectat, calculatorul este folosit de cel care controleazd refeaua (botmaster) pentru
sustragerea de date confidentiale sau bancare,
4, Dacd calculatorul se va strica din nou, m& tem c& va trebui s& cumpariim altul, chiar dacd va trebui s&
scoatem multi bani din buzunar,
7045, Un barbat se duce sé-si viziteze prietenul gic uimit s8-1 giseasca jucdnd sah cu cAinele su,
6, Cea mai mare dintre cele dowd camere masoara zece met,
Specialised terminology
to flag
‘To mark (an Intemet page) for attention by attaching a small tab or flag to it.
content moderation
The practice of monitoring and applying a pre-determined set of
rules and guidelines to user-generated submissions to determine
best if the communication (a post, in particular) is permissible
or not.
artificial intelligence
‘Sometimes called machine intelligence, itis intelligence demonstrated by
‘machines, in contrast to the natural intelligence displayed by humans and
other animals. Computer science defines AI research as the study of
“intelligent agents": any device that perceives its environment and takes
actions that maximize its chance of successfully achieving its goals.
unique identifier
‘Any identifier which is guaranteed to be unique among ll identifiers used for
those objects and for a specific purpose.
tag
In information systems, a tag is a keyword or term assigned to a piece of
{information (such as an Internet bookmark, digital image, database record, or
computer file). This kind of metadata helps describe an item and allows it to
be found again by browsing or searching, Tags are generally chosen
informally and personally by the item's creator or by its viewer, depending on
the system, although they may also be chosen from a controlled vocabulary
to log
“To gain access to a secured computer system or online service by keying in
personal identification information.
jurisdiction
(Law) The right of a court to hear a particular case, based on the scope ofits
authority over the type of case and the partes to the case.
spook
(Slang) A secret agent; a spy.
keystrokes
‘A single operation of the mechanism of a typewriter or keyboard-operated
typesetting machine by the action of a key.
intelligence officer
‘A person employed by an organization to collect, compile and/or analyze
information (known as intelligence) which is of use to that organization. The
term of ‘Officer’ is a working title, it is not to be confused with rank as in the
police where sergeants are also Police Officers and enlisted Military ranks
tan be Intelligence Officers as well. Organizations which employ intelligence
officers include armed forces, police, civilian intelligence agencies, customs
agencies and private corporations.
nUnit 7
Everything Is Hackable
(Part I)
BACKGROUND INFORMATION
Over a couple of days, hundreds of thousands of point-of-sale printers in restaurants around the world
began behaving strangely. Some churned out bizarre
Pictures of computers and giant robots signed, “with
love from the hacker God himself”. When the hack
Avvay from matters of great scale and grand strategy, most hacking is either show-off vandali
criminal. It is also increasingly easy,
sm or simply
Obscure forums oil the trade in stolen credit-card details, sold in
fatches of thousands a atime. Data-dealrs hawk “exploits”: flaws in code that allow malicious attackers
to subvert systems. You can also buy “ransomware™ wi
these facilitating markets that coding skills are
computers created by software like Mirai,
them offline until a ransom is paid—can be rented by the hour, Just like « legitimate business, the bot.
herders will, fora few dollars extra, provide technical support if anything goes wrong.
ie (otal cost of all this hacking is anyone's guess (most small attacks, and man
But it is likely to rise, because the scope for malice is about to expand remarkably. “We are building a
world sized robot," says a security analyst, in the shape of the “Intemet ot Things”. The IoT is a buzz-
Phrase used to describe the computerisation of everything fro
toys, medical devices and light bulbs,
1m cars and electricity meters to children’s
“The default assumption is that everything is vulnerable,”
Says a computer scientist. The reasons for this
run deep. The vulnerabilities of computers stem from the basics of information technology, the culture of
Software development, the breakneck pace of online business growth, the economic incentives faced by
Computer firms and the divided interests of governments,
now entirely optional.
Botnets—flocks of compromised
which can then be used to flo.
od websites with traffic, knocking
big ones, go unreported).
The internet was originally a tool whereby academics shared re
were policed mostly by consensus and etiquette, including a strong presumption against use for commercial
gain. When Vint Cerf, one of the internet's pioneers, talked about building encryption into it in the 1970s,
he says his efforts were blocked by America’s spies, who saw cryptography as a weapon for states. Thus,
rather than being secure from the beginning, the net needs a layer of additional software half a million lines
long to keep things like creditcard details safe. New vulnerabilities and weaknesses in that layer are
reported every year.
‘The innocent foundations of many computer systems remain a source for concern, So does the innocence
of many users. Send enough people an i i
search data. The first versions of the intemet
Good security cultures, both within software developers and between firms and their clients, take an
develop. This is one ofthe reasons to worry about the Internet of Things. “Some of the Companies mate
smart light bulbs, say, or electricity meters, are not computing companies, culturally speaking’ Sa
Graham Steel, who runs Cryptosense, a firm that carries out automated cryptographic analysis. A dal send
belonging to Spiral Toys, a firm that sells internet-connected teddy bears through which toddlers can
72ssages to their parens, lay unprotected online for sev
personal details and toddlers’ messages to be retrieved,
Even in firms that are aware of the issues, such as car companies, nailing down security can be hard. “The
big firms whose logos are on the cars you buy, they don’t really make cars,” points out Dr Fisher “They
assemble lots of components from smaller suppliers, and increasingly, each of those has code in it. It
realy hard forthe car companies to get an overview of everything that’s going in.”
On top of the effects of technology and culture there is a third fundamental cause of insecurity: the
economic incentives of the computer business. Internet businesses, in particular, value growth above almost
everything else, and time spent trying to write secure code is time not spent adding customers. “Ship it on
Tuesday, fix the security problems next week—maybe” is the attitude,
The long licence agreements that users of software must accept (almost always without reading them)
typically disclaim any liability on the part of a software firm if things go ‘wrong—even when the software
involved is specifically designed to protect computers against viruses and the like. Such disclaimers are not
always enforceable everywhere. But courts in America, the world’s biggest software market, have generally
been sympathetic. This impunity is one reason why the computing industry is so innovative and fast-
moving. But the lack of legal recourse when a product proves vulnerable represents a significant cost to
users.
Sometimes governments want computer security to be strong, because hacking endangers both their
citizens and their own operations. On the other hand, computers are espionage and surveillance tools, and
«easier to use as such if they are not completely secure. To this end, the NSA is widely believed to have built
deliberate weaknesses into some of its favoured encryption technologies.
(Adapted from hupsd/[Link]/stience-and-echnology/2017/04/08/computer-securty-s-broken from-top-10-
bottom ?frsc=dg%7Cc)
eral days towards the end of 2016, allowing
stop and think 8
Exercise 1
In your opinion, which are the vulnerabilities that the internet users face nowadays? Which are the
weaknesses that have already been overcome?
Past vulnerabilities (solved now):
Present vulnerabilities (still unsolved):
73Teading
Exercise 2
Answer the following questions based on the text:
1. What do you know about the history of the internet?
2. Who was the fist to talk about cryptography and why were his efforts to apply it blocked?
3. Explain in your own words what “the innocent foundations of many ‘computer systems” may mean,
4. What does the concept of “good security cultures” mean in connection with the internet?
5. How is industry impacted, from a security point of view, by the fact thatthe end products, such as cas, are
usually made up of components produced by various other companies?
6. Why do companies prefer to spend time gaining customers rather than trying to write secure codes?
7. How do companies protect themselves from liability onthe part of a software firm if things go wrong?
8. Do you read licence agreements when you buy a computer program?
9. What is the governments’ attitude towards computer security?
10. Do you think that itis possible to create an “unhackable” computer system? Explain,
74writing &
Exercise 3
‘Translate into Romanian:
Modern computer chips are typically designed by one company, manufactured by another and then
mounted on circuit boards built by third parties next to other chips from yet more firms, A further firm
vwrites the lowest-level software necessary for the computer to function at all. The operating system that lets
the machine run particular programs comes from someone else. The programs themselves from someone
alse again. A mistake at any stage, or in the links between any two stages, can leave the entire system
faulty—or vulnerable to attack. Peter Singer, a fellow at New America, a think-tank, tells the story of a
manufacturing defect discovered in 2011 in some of the transistors which made up a chip used on
‘American naval helicopters. Had the bug gone unspotted, it would have stopped those helicopters firing
their missiles. The chips in question were, like most chips, made in China. The navy eventually concluded
that the defect had been an accident, but not without giving serious thought to the idea it had been
deliberate.
(https:/[Link]-and-technology/2017/0408)
75drills ?
Exercise 4
Match the following wordsfidioms/expressions with their synonyms, and then make up sentences of
‘Your own to incorporate them:
1. to nail down a. inoffensive, harmless |
2. to instill b. imperfection
| 3 incentive ¢. to introduce
4. innocuous 4. dangerous
[Link] €. group, set
6. parlous fan imperfection, defect,
[Link] churn out [Link] make final "|
8. incentive [Link] produce quickly
9. batch i. cunning, deceitful
10. flaw jj stimulus
1 2 3 4 S16 7 10
76drills?
Exercise 5
Use the correct following missing words/expressions in the sentences bellow:
datacdeaters,ransomware, buzz-phrase, breakneck pace, flocks, show-off, default, legal recourse,
disclaimer, liability.
[It's also a good way to embarrass someone, especially the avid computer wizard
who thinks they know everything about software.
2, The computer graphics community has seen simulated bird
. before.
3. The Roman power was at its zenith when every citizen acknowledged his . . to fight
forthe State, but that it began to decline as soon as this obligation was no longer recognized.
4. Content marketing is the latest being used when discussing brand promotion.
5. Aspokeswoman for the Federal Agency could not confirm that the platform was misused by
6.1 know their use of it, yet am compelled to use it in my own way in...
phrase.
7. How to make the .. .. convincing enough is what bothers me.
8. Gone are the days when .. was developed and distributed by skilled cyber criminals,
9. Our case was dismissed, and we've now exhausted every possible ..
10. Previous strategies to harmonise technical regulations have not been able to keep up with the
of developments in the air transport sector,
7PSE
FOCUS ON LANGUAGE AND GRAMMAR DEVELOPMENT
A. 1. Collocations
~~ by demonstrating just how easy it was to seize control.
Accollocation is a group of words that are often used tog
combinations, if used inappropriately, sound “wron;
ether and sound natural in English. Some
12” to the native speaker.
A Mercedes has a powerfull engine. (NOT a strong engine).
Tonly have time for a quick meal. (NOT a fast meal).
Its allright if you make a few mistakes. (NOT do mistakes)
drills
Exercise 6
Make ten collocations from the words in the box:
happily forbidden strictly cold factor
contrast sharp make meal
pitch bitterly have watch
key excuse married dark
1
2.
3.
4.
5.
6. —
a |
8. — ——
9.
10. —
78drills?
Exercise 7
Choose the correct collocation:
1. The politicians need to make/iake/get action immediately!
2. He began by giving/paying/making tribute to two Armed Forces officers who died when their helicopter
crashed in Kabul, Afghanistan,
3. The dentist told me to close/shut/lock my mouth.
4. Itjust feels weird to finish/endi/stop a good relationship so abruptly,
5. Our database was hacked/backed/crashed last week.
6. Make sure you link/storage/back up all your files in the new computer.
7. The annual takeover/overtake/turnover amounts to 145 million Euros without any government grants.
8. The writer draws/does/creates an interesting parallel between traditional Romanian and Japanese music.
9. When money is slimvtight/hard, you should spend it wisely.
10. You made one hasty/prompt/brisk decision without considering the repercussions.
79A.2. Word Formation. Suffixes: -ware
You can also buy “ransomware”..
~-the culture of software development..
‘The suffix -ware (do not confuse it with. —wear, which is used for types of clothing), is used to form:
~ nouns denoting, collectively, items made from a particular substance:
glassware
~ nouns denoting, collectively,
items of a particular kind or fora particular use:
siftware
‘Not its modern use to form mass nouns denoting specific classes of computer software, based on use,
function, or method of distribution:
Groupware = software that integrates work on a single project by several concurrent users at separated
workstations.
drills?
Exercise 8
Find the words ending in ~ware, denoting the following (use the dictionary if necessary):
1. Computer software that obtains information from a user's computer without the user's knowledge or
consent
2. Any software used to disrupt computer or mobile operations
» gather sensitive information, gain access
‘o private computer systems, or display unwanted advertising.
3. Any software package that automatically renders advertisements in order to generate revenue for its
author.
4. A class of malware designed specifically to perpetrate identity theft in order to access a computer users
financial and retail accounts forthe purpose of taking funds from those accounts or completing,
unauthorized transactions that enrich the cyberthief.
805, Software whose users are encouraged to send the creator an e-mail message in lieu of payment or
registration.
6 Antcles made of iron, as household utensils, tools, and the lke.
7. Any malicious or unwanted software.
8, Software components that can be used for free on the condition that the user links back to the creator's
web site.
B. The Present Continuous
e.g. The rising damage caused by computer insecurity is, however, beginning to spur companies,
academics and governments into action.
The Present Continuous is used with the following values:
1. Temporary value— shows events in progress:
© atnow
Zam reading a book now.
* at present/currently
At the moment we are sending all the mail by courier, because
the Post Office ison strike.
* comparative degree
Unfortunately, more and more people are leaving our country.
2. Emotional value (annoyance, irritation); a frequency adverb is necessary:
You are always borrowing money from me!
[Link] value (personal arrangements), with an obligatory adverb of time:
Sorry, I can't help you, I'm leaving in the morning.
4. Temporary frame value (to create background):
He goes into the room and sees a lot of people there; some are smoking, some are drinking.
81drills ?
Exercise 9
‘Translate the following sentences into English paying attention to the use of the Present ‘Simple ang
the Present Continuous:
1. Oamenii din intreaga lume sunt din ce in ce mai preocupafi de securitatea ciberneticd,
2. {In seara aceasta ma intalnese cu un fost coleg de scoala generala.
3. inca ma mai doare Piciorul, dar ma simt din ce in ce mai bine.
4, in care hotel te cazezi de obicei cfind vizitezi Venetia?
5. Va scriu in legatura cu anunful din Daily News.
6. Noul meu calculator raméne fara baterie de fiecare dati cand jl iau cu mine la serviciu.
7. La sfrstul piesei de teatru, ambele famili igi dau seama cd ura lor a provocat moartea celor doi
indragostiti.
8. Afacerile pe intemet devin din ce in ce mai profitabile.
82drills?
Exercise 10
Pat each verb in brackets into either the Present Simple or the Present Continuous:
[Link] -- constantly (have) parties until the early hours of the morning.
2, They often. -~- (have) parties in their garden when the weather is fine,
3. In the north of the country, fewer and fewer people vs» (own) the houses they live in.
4, Although he ..
(own) several computer businesses, none of them is very profitable,
sl (cost) me a fortune at the moment to send my daughter to computer classes.
[Link]...
-~- (Cost) a fortune to fy first class to the States.
7. With growing concerns about the environment, people ...
paper products.
.. (begin) to use recycled
8. The show .. .. (begin) at seven p.m.
érills ?
Exercise 11
Write six true sentences about yourself using the words bellow and a verb in the correct tense:
this term, right now, every day, most weekends, at present, before dinner
83Specialised terminology
bot-herders Hackers who use automated techniques to scan specific network ranges
and find vulnerable systems, such as machines without current security
patches, on which to install their bot program. The infected machine
then has become one of many zombies™ in a botnet and responds to
commands given by the bot herder.
cryptography (computers) Any of various mathematical techniques for encrypting and
decrypting data in order to keep it private when transmitted or stored
electronically.
disclaimers (law) Avoluntary repudiation of a person's legal claim to something
impunity Exemption from punishment, penalty, or harm,
ability Money owed; debis or pecuniary obligations (opposed to assets).
logo (also called logotype) A graphic representation or symbol of a company
name, trademark, abbreviation, etc., often uniquely designed for ready
recognition,
malefactor Someone who has committed a crime or has been legally convicted of a
crime,
malice (law) The intent to commit an unlawful act without justification or
excuse,
ransomware ‘Malware that disables the normal operation of a computer until money
‘or other ransom is paid to the person or organization responsible for the
malware,
software developer | Apperson concemed with facets of the softwar
re development process,
including the research, design, programming, and testing of computer
software. Other job titles which are often used with similar meanings
are programmer, software analyst, and software engineer,
to unscramble (data)
To restore (a scrambled message) to intelligible form.Unit 8
Cyber Terrorism Is 'Biggest Threat to Aircraft’
‘The threat of cyber terrorism poses a major risk to aircrafts’ systems every time they
enter an airport, a senior Boeing executive has said.
By Nick Collins, Transport Correspondent
BACKGROUND INFORMATION
Nervous flies may Worry more about terrorists smuggling explosives into the cabin, but cyber attacks are
becoming one of the most significant threats to passenger aircraft, a senior Boeing executive has claimed.
Jeff Kohler, vice president of international business development for Boeing's defence arm, admitted to
being “very concerned” about threats to flying software and said aircraft were now in need of cyber
protection.
lanes are at risk every time they enter an airport because of the number of electronic systems they begin
sharing information with and the situation will cause “a lot of issues” in the coming years, he added.
Boeing was the focus of a cyber security scare in 2008 when an analyst claimed the firm's flagship 787
Dreamliner passenger jet had a serious weakness in its on-board computer networks which could allow
passengers to take control of the aircraft,
‘report by US authorities found that a network in the cabin designed to give passengers Internet access
could be used to access the aircraft’s control, navigation and communication systems. Boeing claimed the
problem had been fixed before the official report was issued.
In 2011, the International Air Transport Association wamed airlines to “remain on their guard” against
cyber terrorism which it said poses “especially serious challenges for airlines that will be taking delivery of
the new generation of aircraft”.
The scenario from the film Die Hard 2, where an aircraft's system is tricked into thinking it is flying 200
metres higher than it really is, causing it to crash land, is “no longer merely a fictional scenario”, the LATA.
wamed atthe time.
Earlier this year MPs also warned that cyber attacks could "fatally compromise" the armed forces because
the government has not done enough to protect its technology against high-tech warfare.
Speaking at a security conference in Istanbul this month Mr Kobller and five other senior defence company
representatives were asked about the biggest threats to be faced in the next 10 years.
In footage broadcast by Nato Review, Mr Kohler said: “I don’t think we still understand critical
infrastructure protection and how cyber can affect that.
“From our commercial aircraft side we're very concerned about it. As commercial aeroplanes become more
and ra digital and electronic, we have actually started to put cyber protection into the software of our
aeropl
“If they enter an airport environment, they are starting to exchange information and so we have to be able
‘o protect the aircraft's software itself, so there's a lot of issues coming down the road just on cyber alone.”
Marin Hill, vice president of defence, EU and Nato affairs for electronic systems company Thales, added:
‘Every single item that we have depends on cyber.
‘All of our critical infrastructure is controlled by some sort of network. This has to be the area where we're
Boing to face problems and where we've got to spend a fortune.”
(The Telegraph, 27 Dec 2013)
85stop and think 8
Exercise 1
Which is the significance of the following sentence, in your opinion:
‘As commercial aeroplanes become more and more digital and electronic, we have actually started to py
cyber protection into the software of our aeroplanes.
drills ?
Exercise 2
Read the following sentences and fill in the missing word:
1, Senior defence company representatives were asked about the biggest threats to be faced in the
next... - years.
--claimed the problem had been fixed before the official report was issued.
3. The government has not done enough to
ts technology against high-tech warfare.
4. A serious weakness in its on-board computer networks could allow passengers to
take... .. of the aircraft.
5. Alll of our critical infrastructure is controlled by some sort of ....
6. The scenario from the film Die Hard 2 is no longer merely a ...........
scenario.
7. Commercial ..
become more and more digital and electronic.
8. Nervous fliers may worry more about terrorists ...
explosives into the cabin.
9, The threat of cyber terrorism
-» 4 major risk to aircrafts systems.
10. Aircraft were NOW if........sc..sccsn Of eyber protection,
86speaking
Exercise 3
Work with a partner and identify four major risks on aircrafts:
writing 2
Exercise 4
Write an opinion essay on Aeroplanes are the focus of a cyber security scare. Write 300-400 words
following the structure bellow:
Paragraph 1: Introduction (introduce the main topic)
Paragraph 2, 3, 4: Main Body
Paragraph 5: Other people’s opinions
Paragraph 6: Your own opinion
87drills 2
Exercise 5
Match words in the two columns in order to make correct collocations as in the above-mentioned
text:
A B
TL. security a. aircraft
2. defence b. aircraft
3. commercial c. software
4. fictional d. development
5. "passenger e ‘Teport
6. flying f. compan;
7. on-board g systems
8. official h. computer
9. communication i, conference
10. business n scenario
1 2 3 4 5 6 3 9 10m
88wring
Exercise 6
‘ranslate into Romani
What are things that a hacker can do to me?
While your computer is connected to the Internet, the malware a hacker has installed on your PC quietly
transmits your personal and financial information without your knowledge or consent. Or, a computer
predator may pounce onthe private information you unvitingly revealed. In either cas, they willbe able
to:
«Hijack your usermames and passwords
+ Steal your money and open credit card and bank accounts in your name
+ Ruin your credit
+ Request new account Personal Identification Numbers (PINs) or additional credit cards
+ Make purchases
+ Add themselves or an alias that they control as an authorized user so it’s easier to use your credit
«Obtain cash advances
+ Use and abuse your Social Security number
«Sell your information to other parties who will use it for illicit or illegal purposes
Predators who stalk people while online can pose a serious physical threat. Using extreme caution when
agreeing to meet an online “friend” or acquaintance in person is always the best way to keep safe.
How will I know if I've been hacked?
Check the accuracy of your personal accounts, credit cards, and documents. Are there unexplained
transactions? Questionable or unauthorized changes? If so, dangerous malware installed by predators or
hackers may already be lurking.
([Link] [Link]/us/en/resources/tips-articles/computer-security-threats-hackers)
89PSE
FOCUS ON LANGUAGE AND GRAMMAR DEVELOPMENT
A. WISH
Wish Structures
Wish + Past Tense
I wish you didn’t invite her.
Regret / wish about a present situation
Wish + Past Perfect
I wish I had had more time to deal with those risks.
Regret about a past situation
Wish + object + would + Present Infinitive
I wish hackers would stop doing so much harm..
I wish they could come in person.(but they live abroad)
Regret / complaint about the present.
Wish about something unlikely to happen
| wish + inanimate subject + would + Present Infinitive
I wish this Mr. Brown would stop shouting!
Wish for a change in the future which is
unlikely to happen.
1A word of caution
*[ wish I would stop doing this, (ungrammatical)
You can only refer to a different person than you:
wish he /shel they/ would cease talking.
90woiting
Exercise 7
‘translate into Romanian using the correct form of the verb to wish:
1.
yee NaH eRe D
Ce picat cf ea a parasit sedinfa atat de supiiratd,
AAs vrea ca acest hacker si inceteze atacurile,
Ce picat ca nu am prevazut toate aceste riscuri,
Ea ar dori s& nu fi tratat aceasta problema cu atta neglijenf&, acum e prea tarziu.
Compania ar dori s& discute aceast& problema cu dumneavoastrii in persoand.
As fi dorit s& fi infeles mesajul corect.
As vrea si fi acceptat oferta mai devreme, inteleg cd este tardiv acum.
Ag vrea si pot fi present la intalnire, dar stii cd sunt plecat din far’...
Ei ar vrea s ne poata da mai multe informafii.
As vrea si va accept oferta
As vrea si fi participat la intrunire, dar e tardiv acum.
B. The Present Perfect
Form:
Regular verbs: [ have danced
regular verbs: T have been
1Use:
Examples:
1. Thave lived in Bucharest for 20 years.
‘An action which took place in the past and continues at present.
2. have dyed my hair.
Indefinite action in the past with an effectlecho at present.
3. Thave visited Honolulu twice.
Thave never visited Honolulu.
‘An experience in the past which could be repeated /enriched.
Key Words
© This + time dimension
this afternoon/week/month/Monday//semester/year etc
Thave met the CEO twice this morning.
° For/Since
For= duration
Since=starting point
have written on this essay since 7 a.m, for four hours
+ Indefinite adverbs:
just/never/everi/just/seldonvrarely/often/always
Thave never visited Petra.
Thave just talked to her.
Thave often watched this movie.
92have arelyseldom drunk champagne,
rave you ever forgoten your mum's birthday?
« Already/Yet
have already visited this museum,
Have you visited this museum yet?
haven't visited this museum yet.
The Present Perfect Continuous
Have been + vb-ing
1, An action started in the past and continues to the present, giving emphasis to durat
effort.
Thave been writing this book for ages.
2. An action started in the past and continues to the present, giving emphasis to dura
effort + reproach,
Thave been waiting for you for ages.
3. An action started and finished in the past and continues, giving emphasis to the effect in the
resent,
Tthas been snowing all night long. (It stopped snowing, but the streets and the roofs are covered by
snow).
drills?
Exercise 8
Fill in the gaps using the following key words:
CverInever{just/for/since/always/rarely/often/yet/always
1. Thave.......... met my partners at that congress.
more than ten years.
2. They have investigated that hacker .....
3. Thave ... . met the investigator.
934. Rave you .....[Link] taken the floor ?
5. She hasn’t applied for this position .........
6. Thave........... trusted her to be an IT expert.
7. They have... lied about their previous experience.
8. Thave stayed with that company.........-last January,
9. He has behaved lke that in front of his parents
10. I haven’t seen this advertisement......
drills?
Exercise 9
Use the correct verb form:
1. They. (Work) inthe garden for hours.
2. you --sssses(enjoy) the article on cyber security issues?
3. on. --(have) a bad experience regarding virus attacks on
your software?
4. oe TIOVET sss stssee
-sveve(b8) face-to-face with a hacker.
5. All your colleagues are upset: they .
(wait) for you since
morning.
6. SNe osseessssessstessseeseeesseed Qty) t0 fix this problem but in vain,
1. We .-.-already... --iscussed cyber attack incidents and We
-osseeea(feach) a conclusion yet,
8. Nobody...... --o(Warn) us about those risks.
9, Hackers ...... (attack) a bank software this week.
10. To. +++,(study) this problem since 1998,
94Specialised terminology
smuggler
Smb. who takes goods or people into or out of a
country illegally,
threat
statement of an intention to inflict pain, injury,
damage, or other hostile action on smb. in
retribution for smth. done or not done.
flagship
merely
fortune
The best or most important thing owned or
produced by a particular organization,
Just, only.
Chance or luck as an arbitrary force affecting
human affairs,
= _Alarge amount of money or assets.
defense
~The action of defending from or resisting
attack.
~The case presented by or on behalf of the party
accused of a crime or being sued in a civil
lawsuit.
scenario
A postulated sequence or development of events
95Unit 9
Cyber-crime
The case of WannaCry
BACKGROUND INFORMATION
In 1933 Britain’s parliament was considering the Banditry bill—the government's response to a crime
wave, The problem was that criminals were using a newfangled invention, the motor car, to carry out
robberies faster than the police could respond. The bill’s proposed answer to these “‘smash-and-grab” raids
Was to create new powers to search cars and to construct road blocks.
Since then, the technology of theft has not stood still. On May 12th, for instance, security companies
noticed that a piece of malicious software known as WannaCry was spreading across the internet, first in
Britain and Spain, and then around the world. It would reach 230,000 computers in 48 hours, an
unprecedented scale of infection according to Europol. WannaCry rendered useless some of the computers
that help run Britain’s National Health Service (NHS), causing ambulances to be diverted and shutting
down non-emergency services.
Malicious software is designed to infect and damage computers. Sometimes, especially if the creators are
youngsters flexing their programming muscles, it is written for the sheer hell of it. Sometimes, it is the
‘work of governments, designed to harm the interests of rivals or enemies. Usually, though, itis written for
profit. This seems to have been the case for WannaCry, the modus operandi of which is to encrypt a
victim’s files and demand payment to reverse that encryption—a common technique, known as
ransomware. What makes the WannaCry attack special is its scale and the high-profile nature of its victims.
That public profile has led to the asking of questions similar to those which resulted in the Banditry bill.
WannaCry is a combination of two kinds of malware. One, known as a worm, is designed to spread from
computer to computer. The other, delivered by the worm, is the encrypting ransomware itself. It is this
combination that has made WannaCry so threatening. Ransomware is usually delivered one user at a time,
via spoof e-mails which tempt the recipient to click on a link or attachment that then downloads and
activates the software. In this case, a single click was able to infect an entire network.
The outbreak was terminated not by official action but by vigilantism. The malware had its head lopped off
by a security consultant who goes by the pseudonym “MalwareTech”—for not everyone in the complex
ecosystem of computer hacking is a bad guy. MalwareTech discovered that every time a copy of WannaCry
‘runs, it pings out onto the internet a request for a response from a non-existent web address. This behaviour
is intended to check that the copy in question is truly out in the wild, and is not being examined in a
“sandbox”, a closed piece of software in which security researchers can dissect digital bugs to learn their
secrets.
The simplicity of stifling WannaCry suggests the whole thing was a bit of a botched job—as does the
apparent business model of its creators. Professional ransomware operations come with fully operational
call centres in which real people answer calls from distressed owners of infected machines in order to walk
them through the process of getting their files back (and paying the ransom, of course).
WannaCry has none of these. It simply asked for payment, into a particular account, of a sum in bitcoin.
Moreover, Check Point, a computer-security consultancy in Israel, has shown that WannaCry’s encryption
software is so badly assembled that decrypting a user's data after payment has been made is practical
impossible. Properly organised ransomware criminals, alive to the advantages of repeat business, usvallY
do unencrypt the hostage data once the money has been paid.
In contrast to its encryption software, however, WannaCry's worm, which spread it so fast, is ®
sophisticated piece of coding. That is because it reuses software stolen several months ago from America’s
96