0% found this document useful (0 votes)
21 views16 pages

Understanding Cyber Safety and Security

59+6312

Uploaded by

aryanudiya
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
21 views16 pages

Understanding Cyber Safety and Security

59+6312

Uploaded by

aryanudiya
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

CYBER SAFTY AND

SCEURITY
 INTRODUCTION TO CYBER CRIME
What is cybercrime?
Cybercrime is any criminal activity that involves a computer, networked device
or a network.

While most cybercrimes are carried out in order to generate profit for the
cybercriminals, some cybercrimes are carried out against computers or
devices directly to damage or disable them. Others use computers or
networks to spread malware, illegal information, images or other materials.
Some cybercrimes do both -- i.e., target computers to infect them with a
computer virus, which is then spread to other machines and, sometimes,
entire networks.

A primary effect of cybercrime is financial. Cybercrime can include many


different types of profit-driven criminal activity, including ransomware attacks,
email and internet fraud, and identity fraud, as well as attempts to steal
financial account, credit card or other payment card information.

Cybercriminals may target an individual's private information or corporate data


for theft and resale. As many workers settle into remote work routines due to
the pandemic, cybercrimes are expected to grow in frequency in 2021, making
it especially important to protect backup data.

Defining cybercrime
The U.S. Department of Justice (DOJ) divides cybercrime into three
categories:

1. crimes in which the computing device is the target -- for example, to gain
network access;

2. crimes in which the computer is used as a weapon -- for example, to


launch a denial-of-service (DoS) attack; and
3. crimes in which the computer is used as an accessory to a crime -- for
example, using a computer to store illegally obtained data.

The Council of Europe Convention on Cybercrime, to which the U.S. is a


signatory, defines cybercrime as a wide range of malicious activities, including
the illegal interception of data, system interferences that compromise network
integrity and availability, and copyright infringements.

The necessity of internet connectivity has enabled an increase in the volume


and pace of cybercrime activities because the criminal no longer needs to be
physically present when committing a crime. The internet's speed,
convenience, anonymity and lack of borders make computer-based variations
of financial crimes -- such as ransomware, fraud and money laundering, as
well as crimes such as stalking and bullying -- easier to carry out.

Cybercriminal activity may be carried out by individuals or groups with


relatively little technical skill, or by highly organized global criminal groups that
may include skilled developers and others with relevant expertise. To further
reduce the chances of detection and prosecution, cybercriminals often choose
to operate in countries with weak or non-existent cybercrime laws.

How cybercrime works


Cybercrime attacks can begin wherever there is digital data, opportunity and
motive. Cybercriminals include everyone from the lone user engaged in
cyberbullying to state-sponsored actors, like China's intelligence services.

Cybercrimes generally do not occur in a vacuum; they are, in many ways,


distributed in nature. That is, cybercriminals typically rely on other actors to
complete the crime. This is whether it's the creator of malware using the dark
web to sell code, the distributor of illegal pharmaceuticals
using cryptocurrency brokers to hold virtual money in escrow or state threat
actors relying on technology subcontractors to steal intellectual property (IP).
Cybercriminals use various attack vectors to carry out them cyberattacks and
are constantly seeking new methods and techniques for achieving their goals,
while avoiding detection and arrest.

Cybercriminals often carry out their activities using malware and other types of
software, but social engineering is often an important component for executing
most types of cybercrime. Phishing emails are another important component
to many types of cybercrime but especially so for targeted attacks, like
business email compromise (BEC), in which the attacker attempts to
impersonate, via email, a business owner in order to convince employees to
pay out bogus invoices.

Types of cybercrime
As mentioned above, there are many different types of cybercrime. Most
cybercrimes are carried out with the expectation of financial gain by the
attackers, though the ways cybercriminals aim to get paid can vary. Some
specific types of cybercrimes include the following:

 Cyberextortion: A crime involving an attack or threat of an attack coupled


with a demand for money to stop the attack. One form of cyberextortion is
the ransomware attack. Here, the attacker gains access to an
organization's systems and encrypts its documents and files -- anything of
potential value -- making the data inaccessible until a ransom is paid.
Usually, this is in some form of cryptocurrency, such as bitcoin.

 Crypto jacking: An attack that uses scripts to mine cryptocurrencies within


browsers without the user's consent. Crypto jacking attacks may involve
loading cryptocurrency mining software to the victim's system. However,
many attacks depend on JavaScript code that does in-browser mining if
the user's browser has a tab or window open on the malicious site. No
malware needs to be installed as loading the affected page executes the
in-browser mining code.

 Identity theft: An attack that occurs when an individual access a computer


to glean a user's personal information, which they then use to steal that
person's identity or access their valuable accounts, such as banking and
credit cards. Cybercriminals buy and sell identity information on darknet
markets, offering financial accounts, as well as other types of accounts,
like video streaming services, webmail, video and audio streaming, online
auctions and more. Personal health information is another frequent target
for identity thieves.

 Credit card fraud: An attack that occurs when hackers infiltrate retailers'
systems to get the credit card and/or banking information of their
customers. Stolen payment cards can be bought and sold in bulk on
darknet markets, where hacking groups that have stolen mass quantities of
credit cards profit by selling to lower-level cybercriminals who profit through
credit card fraud against individual accounts.

 Cyberespionage: A crime involving a cybercriminal who hacks into


systems or networks to gain access to confidential information held by a
government or other organization. Attacks may be motivated by profit or by
ideology. Cyberespionage activities can include every type of cyberattack
to gather, modify or destroy data, as well as using network-connected
devices, like webcams or closed-circuit TV (CCTV) cameras, to spy on a
targeted individual or groups and monitoring communications, including
emails, text messages and instant messages.

 Software piracy: An attack that involves the unlawful copying, distribution


and use of software programs with the intention of commercial or personal
use. Trademark violations, copyright infringements and patent violations
are often associated with this type of cybercrime.

 Exit scam: The dark web, not surprisingly, has given rise to the digital
version of an old crime known as the exit scam. In today's form, dark web
administrators divert virtual currency held in marketplace escrow accounts
to their own accounts -- essentially, criminals stealing from other criminals.

 INTRODUCTION TO Cyber Safety:

What is Cyber Security?


Cyber Security is a process that’s designed to protect networks and devices from
external threats. Businesses typically employ Cyber Security professionals to protect
their confidential information, maintain employee productivity, and enhance customer
confidence in products and services.

The world of Cyber Security revolves around the industry standard of confidentiality,
integrity, and availability, or CIA. Privacy means data can be accessed only by
authorized parties; integrity means information can be added, altered, or removed only
by authorized users; and availability means systems, functions, and data must be
available on-demand according to agreed-upon parameters.

The main element of Cyber Security is the use of authentication mechanisms. For
example, a user name identifies an account that a user wants to access, while a
password is a mechanism that proves the user is who he claims to be.

What Motivates Cyber Criminals?

The main motive behind the cybercrime is to disrupt regular business activity and critical
infrastructure. Cybercriminals also commonly manipulate stolen data to benefit
financially, cause financial loss, damage a reputation, achieve military objectives, and
propagate religious or political beliefs. Some don’t even need a motive and might hack
for fun or simply to showcase their skills.

So, who are these cybercriminals? Here’s a breakdown of the most common types:

 Black-Hat Hackers

Black-hat hackers use fake identities to conduct malicious activities for a profit

 Gray-Hat Hackers

They work both with malicious intent and as legitimate security analysts

 White-Hat Hackers

White-hat hackers work as security analysts to detect and fix flaws and protect against
malicious hackers
 Suicide Hackers

They aim to openly bring down the critical infrastructure for a social cause

 Script Kiddies

They are unskilled hackers who run scripts and software created by more experienced
hackers

 Cyber Terrorists

They create fear by disrupting large-scale computer networks; motivated by religious or


political beliefs

 State-Sponsored Hackers

They penetrate government networks, gain top-secret information, and damage information
systems; paid by a hostile government

 Hacktivists

Promote political agendas by secretly defacing and disabling websites

 CONCEPT AND USE OF CYBER HYGIENE IN DAILY


LIFE:
What Is Cyber Hygiene and Why Does It Matter?
Cyber hygiene is a set of habitual practices for ensuring the safe handling of critical data
and for securing networks. It’s like personal hygiene, where you develop a v

routine of small, distinct activities to prevent or mitigate health problems. Cyber hygiene
practices include the inventory of all endpoints connected to a network, vulnerabilities
management, and the patching of software and applications.
As cyberattacks have increased around the world—interrupting businesses and government
operations, and often leading to massive ransomware pay-outs and damaged corporate
reputations—cyber hygiene has become a key method for creating operational resilience.
Consider the disruption caused by the COVID-19 pandemic, which created opportunities for
criminal hackers through email phishing, supply chain attacks, and password and malware
attacks that preyed on millions of remote workers’ devices. Already in the first half of 2021, the
global ransomware attacks have hit 304.7 million, surpassing last year’s total of 304.6 million.
In response, the White House has urged government and business leaders to protect themselves
by implementing foundational cyber hygiene best practices, noting that it is their critical
responsibility to protect against threats with a strengthening of our nation’s resilience against
cyberattacks. That’s because cyber hygiene is one of the surest ways to improve any
organization’s overall security posture and defend against threats now and in the future.
Why is cyber hygiene important?
Cyber hygiene helps prevent cybercriminals from breaching an organization’s network—or at
least raises the opportunity cost, making it so hard that the criminal gives up and goes looking for
another victim. It’s true that many of today’s attacks are increasingly sophisticated, relying on
social engineering to get a victim to divulge sensitive information, targeting “whales” (high-level
executives), or deploying malware in a supply chain that can then infect hundreds of others.
$304.7The total (in millions) of global ransomware attacks in the first half of 2021,
already surpassing last year’s total of $304.6 million
The fact is, most successful attacks are the result of routine lapses—failing to know
what endpoints are connecting to your network, to consistently and rapidly monitor and
deploy patch updates, to make the correct security configurations, and to rapidly identify and
resolve breaches before they can harm core business operations. Cyberattacks take advantage of
these missteps.
You can’t blame complacent or uninformed IT managers, administrators and security engineers.
Rather, the failures are a product of the complexity and dynamism of modern IT environments.
The typical business network includes an array of computers, servers, databases, virtual
machines, mobile devices, operating systems, applications, and tools, each of which is a potential
attack vector. If these aren’t regularly and properly maintained, it can result in lost or
misplaced data, unpatched software, outdated user privileges, and other issues. In this way, an
environment grows more vulnerable over time and leaves you with multiple points of exposure.
Cyber hygiene helps reduce those vulnerabilities by identifying risks and deploying mechanisms and
strategies to reduce or resolve them. By practicing cyber hygiene, organizations strengthen their security
posture and can more effectively defend themselves against devastating breaches.
How do you assess your cyber hygiene?
Cyber hygiene is assessed using a performance monitoring solution that scans your IT
environment to discover your various assets and to identify vulnerabilities. The results are
presented as a scorecard that quantifies the health of your IT estate. Vulnerabilities are given a
severity level of “critical,” “high,” “medium,” or “low” based on the Common Vulnerability
Scoring System (CVSS), an open industry standard for rating a computer system’s security
vulnerability.
These vulnerabilities can be sorted by asset criticality, so you can see which will have the most
significant business impact. For example, an unpatched vulnerability on the CEO’s laptop would
warrant more immediate attention than one on the interns.

“Cyber hygiene helps prevent breaching a


network—or makes it so hard that the
criminal gives up and goes looking for
other victims.”
Cyber hygiene assessments help overcome two of the biggest obstacles to effective security:
incomplete visibility into the IT environment and inadequate resources to respond to issues.
Risk scoring surfaces the most critical vulnerabilities and prioritizes them. This allows IT teams
to allocate their resources toward closing the most critical security gaps first before moving on to
lower priority issues.
What are the benefits of cyber hygiene?
Good cyber hygiene offers several benefits that ultimately put your organization in a better
position to defend against cyberattacks. Specifically, it helps you:

 Locate unmanaged assets: You can’t protect what you can’t see. That’s why an accurate
inventory of all your assets is the foundation for strong cybersecurity. Good cyber hygiene
practices allow you to maintain an up-to-date asset inventory, identify vulnerabilities associated
with any particular asset, and quickly resolve security gaps.
 Protect customer data: Cyber hygiene supports a range of proven security practices, such as
patch management, password discipline, appropriate administrator privileges, and other measures
that improve data protection.
 Find outdated administrator privileges: It’s easy to lose track of administrative rights as people
move from one role or department to another or leave the company. But high-level administrative
controls pose a significant security risk, so it’s important to regularly audit who has
administrative privileges and how often they’re used. Outdated or long-forgotten privileges need
to be immediately updated or revoked.
 Identify rogue software: Remote work has led many workers to install unsanctioned
software on the devices and endpoints they use to connect to your network. That’s a problem.
Chances are, that software hasn’t been properly configured, patched, updated, or secured, making
it an attractive target for attackers. Cyber hygiene helps IT administrators gain visibility into all
the software installed and used on their network so they can manage it or remove it.
 Meet compliance requirements: By identifying and prioritizing security risks and empowering
IT teams to quickly remediate them, cyber hygiene makes it easier to track and report your
organization’s security status and ensures it’s always aligned with regulatory and compliance
requirements.
 INTRODUCTION TO SOCIAL
NETWORKS:

 Social Networking refers to grouping of individuals and organizations together via


some medium, in order to share thoughts, interests, and activities.

 There are several webs based social network services are available such as
Facebook, twitter, LinkedIn, Google+ etc. which offer easy to use and interactive
interface to connect with people with in the country an overseas as well. There are
also several mobile based social networking services in for of apps such as
WhatsApp, hike, Line etc.

What is Social Networking?


Social networking is an online platform that people uses to develop a social

relationship with others with similar thoughts and personal interest,

backgrounds, real-time connections or career activities. There are several


social media networking sites for instant messaging, sharing or posting views,

and much more. Trillions of people over the world connect through social

networking to share views on a personal level. But most people use social

networking to interact with their family and friends to gain knowledge or for

entertainment purposes. Business people use social media to plan the target

audience and execute it via attractive advertisements that pop out when

related to a search. It also helps them trace the audience’s ideas by throwing

multiple options to the customer, getting feedback from the client ends, and

promoting it in a reachable way by elevating their business to the next level.

The specialist also uses social media to enhance the knowledge in the related

fields and develop a network with like-mind people in a similar industry and

support each other in their career growth. It is termed as group-cantered,

which is described as websites that simplify the building of complex systems

to share the various types of content webspace. It offers an interaction space

to persist out the interaction of the person. The interactions via computer

networks support and build new social tie-ups. It is popularly emerging as an

online community.
The success of the social networking site can be visible in their supremacy in

civilization. For example, Facebook which connects trillions of people from

nook and corner of the world. An average of fourteen billion users is an active

user who logs in daily to see and update their news feed. LinkedIn is a career-

based social networking site where professionals share their opening related

to a product. The company publishes its achievements on the site to get the

world’s attention. Some unique features in social networking are that they

share a mutual connection with people and help us to contact our old missed

friends. The social network includes online shopping where people do not

even connect to a person sitting at home; he can get his things without

stepping out. The product will be delivered to his doorstep. It can be noticed

that the product you search for in Google, will be popped out in your

Facebook newsfeed, Instagram and Twitter advertisement. Other than this, it

will throw a notification that this product has some special offer codes.

Everything you search on google or discuss with your friends in some chatting

app is tracked and traced by social networking, which allows all the businesses

and corporates to develop their enterprise by fooling the people around.


Available Social networking Services
The following table describes some of the famous social networking services provided
over web and mobile:

S.N Service Description


.

1. Facebook
Allows to share text, photos, video etc. It also offers interesting online games.

2. Google+
It is pronounced as Google Plus. It is owned and operated by Google.

3. Twitter
Twitter allows the user to send and reply messages in form of tweets. These tweets are the small
messages, generally include 140+ characters.

4. Faceparty
Faceparty is a UK based social networking site. It allows the users to create profiles and interact
with each other using forums messages.

5. LinkedIn
LinkedIn is a business and professional networking site.

6. Flickr
Flickr offers image hosting and video hosting.

7. Ibibo
Ibibo is a talent based social networking site. It allows the users to promote one’s self and also
discover new talent.

8. WhatsApp
It is a mobile based messaging app. It allows to send text, video, and audio messages

9. Line
It is same as WhatsApp. Allows to make free calls and messages.

10. Hike
It is also mobile based massager allows to send messages and exciting emoticons.

Common questions

Powered by AI

Cyberextortion involves threats of attacks or actual attacks combined with demands for a ransom, typically in cryptocurrency, to cease the attack. It poses a significant threat globally as it can paralyze organizations by encrypting critical data, thus coercing victims into paying ransom to retrieve or avoid public exposure of sensitive information .

State-sponsored hackers distinguish themselves by targeting government networks to acquire top-secret information or disrupt critical infrastructure. Unlike financially-motivated hackers, they are usually motivated by national interests and are funded to compromise national security for military and strategic advantages. Their operations tend to be more sophisticated and impactful due to state backing .

Ransomware attacks inflict dual impacts on businesses by disrupting operations and forcing substantial financial payouts, often damaging reputations in the process. The White House has emphasized the importance of cyber hygiene as a countermeasure, advocating for practices such as regular software updates, robust access control, and incident response planning to strengthen resilience against such attacks .

Black-hat hackers conduct malicious activities for profit using fake identities. Gray-hat hackers operate with mixed intent, sometimes acting maliciously and at other times offering security services. White-hat hackers, however, are ethical hackers who aim to improve security by identifying and rectifying vulnerabilities before malicious hackers can exploit them .

The rise of cyber hygiene practices has fortified organizations by enhancing their security posture through activities like regular patch management, password discipline, and prompt incident response. With increased cyberattacks post-2020, these practices help ensure system resilience, keeping critical data secure from breaches while allowing businesses to maintain operations despite remote work vulnerabilities triggered by the pandemic .

Social networking platforms extend beyond mere communication, providing businesses with tools for targeted advertising, customer feedback collection, and brand promotion. These platforms enable businesses to reach specific demographics, understand consumer preferences through direct interactions, and enhance brand visibility, all of which contribute to strategic marketing and business growth .

Social engineering is crucial in cybercrimes, particularly in attacks like business email compromise (BEC). It involves manipulating individuals to divulge confidential information, using tactics such as phishing emails to impersonate business owners. This enables attackers to convince employees to pay out fake invoices, thus achieving their financial objectives by exploiting human psychology rather than technical vulnerabilities .

Managing endpoint inventory is crucial for cybersecurity as it ensures visible insight into all devices connected to the network. This allows organizations to identify vulnerabilities, apply necessary patches, and prevent unauthorized software, thereby reducing the attack surface cybercriminals could exploit. Effective endpoint management is part of upholding cyber hygiene, which significantly contributes to resilient security posture .

Credit card fraud is exacerbated by the sale of stolen cards in bulk on darknet markets. These platforms enable hacking groups to profit significantly by selling pilfered payment information to smaller cybercriminals who then execute fraud on individual accounts. This underground economy not only poses immense financial risks to consumers and businesses but also complicates law enforcement efforts due to the anonymity provided by such markets .

Cyber hygiene refers to the habitual practices and measures taken to ensure the security of networks and data. Much like personal hygiene forestalls health problems, cyber hygiene aims to prevent data breaches by maintaining security protocols like software updates and vulnerability management. These routines help organizations mitigate risks and protect their digital environments .

You might also like