0% found this document useful (0 votes)
7 views14 pages

Understanding Cyber Attacks and Risks

A cyber attack is the intentional exploitation of a computer system or network, often resulting in compromised data and various cybercrimes. Small businesses are particularly vulnerable due to inadequate security measures, making them attractive targets for attackers seeking easy access and valuable data. The document also outlines types of malware, signs of internet trolling, cyber spying, hacking, and the importance of database management systems.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views14 pages

Understanding Cyber Attacks and Risks

A cyber attack is the intentional exploitation of a computer system or network, often resulting in compromised data and various cybercrimes. Small businesses are particularly vulnerable due to inadequate security measures, making them attractive targets for attackers seeking easy access and valuable data. The document also outlines types of malware, signs of internet trolling, cyber spying, hacking, and the importance of database management systems.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

ACC123

MODULE 18

What is a Cyber Attack?

●​ In short, a cyber attack is the deliberate exploitation of a computer system or network.


●​ For example, a hacker may use malicious code to exploit a vulnerability in the system.
●​ This code is designed to execute a command that leads to a disruption in the natural
sequence of events. As a result, the target ends up with compromised or stolen data.
This can then be used for various cybercrimes.

●​ cyber attack could leave you with several results that affect you negatively. That is to
say; you could be subject to anything from identity theft or fraud to ransomware, stolen
data, malware attacks, IP theft, website defacement, and more.

Who Is At Risk Of A Cyber Attack And Why?

●​ At first glance, it may seem counter-intuitive. But more than anyone else, small
businesses need to be wary of cyberattacks. Small businesses present a tempting target
for attackers for a few reasons.

●​ Small-to-medium businesses (SMBs) are less likely to have stringent security measures
and appropriate incident response plans in place. Therefore, attackers find SMBs far
easier to infiltrate and exploit.
●​ Additionally, they often don't have the means to defend or recover from an attack quickly,
so they'll cough up the dough in a ransomware attack to get their data back.

●​ The cost of a data breach is significantly more than most realize, and the financial hit is a
huge one that many small businesses may not recover. So, as they say, prevention is
better than cure.

●​ Above all, attackers are looking for two factors in a victim.


●​ Firstly, ease of access.
●​ Secondly, the potential reward.
●​ Small businesses often check that first box with minimal cybersecurity measures.
●​ Furthermore, depending on the type of business, the data onboard may be ultra juicy
and worth quite a bit financially. So, they may sell the information to other malicious
parties or hold the data hostage for a significant ransom.

9 CYBER ATTACKS

1.​ My email was hacked


2.​ System account details are compromised
3.​ My online storage was hacked
4.​ I received a blackmail email demand

rebyuwer ni jerom
ACC123

5.​ My social media has been hacked


6.​ Our network has been attacked
7.​ Fraudulent financial transaction
8.​ Infected with a malware cyber attack
9.​ Received a suspicious phone call

Malware

●​ Malware, or malicious software, is any program or file that is harmful to a computer user.
●​ Types of malware can include computer viruses, worms, Trojan horses, and spyware.
●​ These malicious programs can perform various functions such as stealing, encrypting,
deleting sensitive data, altering or hijacking core computing functions, and monitoring
users' computer activity without their permission.

Different types of malware contain unique traits and characteristics. Types of malware include:

●​ A virus is the most common type of malware which can execute itself and spread by
infecting other programs or files.

●​ A worm can self-replicate without a host program and typically spreads without any
human interaction or directives from the malware authors.

●​ A Trojan horse is designed to appear as a legitimate program to gain access to a


system. Once activated following installation, Trojans can execute their malicious
functions.

●​ Spyware is made to collect information and data on the device user and observe their
activity without their knowledge.

●​ Ransomware is designed to infect a user’s system and encrypt the data. Cybercriminals
then demand a ransom payment from the victim in exchange for decrypting the system’s
data

●​ A rootkit is created to obtain administrator-level access to the victim’s system. Once


installed, the program gives threat actors root or privileged access to the system.

●​ A backdoor virus or remote access Trojan (RAT) secretly creates a backdoor into an
infected system that allows threat actors to remotely access it without alerting the user or
the system’s security programs.

●​ Adware is used to track a user’s browser and download history to display pop-up or
banner advertisements that lure the user into purchasing. For example, an advertiser
might use cookies to track user visits better target advertising.

rebyuwer ni jerom
ACC123

●​ Keyloggers, also called system monitors, are used to see nearly everything users do on
their computer. This includes emails, opened web pages, programs, and keystrokes.

MALWARE SYMPTOMS

-​ Annoying pop-up messages


-​ Computer becomes sluggish and inoperable at times
-​ Files are missing or deleted w/out your knowledge
-​ Cyber attacks in corporate

MODULE 19

What Are Internet Trolls?

●​ An internet troll makes intentionally inflammatory, rude, or upsetting statements online to


elicit strong emotional responses in people or steer the conversation off-topic.
●​ They can come in many forms. Most trolls do this for their amusement, but other trolling
forms are done to push a specific agenda.

●​ Trolls have existed in folklore and fantasy literature for centuries. Online trolling has
been around for as long as the internet has existed.
●​ The term’s earliest known usage can be traced back to the 1990s on early online
message boards. Back then, it was a way for users to confuse new members by
repeatedly posting an inside joke. It’s since turned into a much more malicious activity.

You’ll find trolls anywhere online, including on Facebook and online dating sites. They’re
unfortunately pretty common.

Signs Someone Is Trolling

It can sometimes become difficult to tell the difference between a troll and someone who
genuinely wants to argue about a topic. However, here are a few tell-tale signs that someone is
actively trolling.

●​ Off-topic remarks: Completely going off-topic from the subject at hand. This is done to
annoy and disrupt other posters.

●​ Refusal to acknowledge evidence: Even when presented with hard, cold facts, they
ignore this and pretend they never saw it.

●​ Dismissive, condescending tone: An early indicator of a troll was that they would ask
an angry respondent, “Why you mad, bro?” This is a method done to provoke someone
even more, as a way of dismissing their argument altogether.

rebyuwer ni jerom
ACC123

●​ Use of unrelated images or memes: They reply to others with memes, photos, and
gifs. This is especially true if done in response to a very long text post.

●​ Seeming obliviousness: They seem oblivious that most people are in disagreement
with them. Also, trolls rarely get mad or provoked.

What is cyber spying?

●​ Cyber spying, or cyber espionage, is the act or practice of obtaining secrets, and
information without the permission or knowledge of the holder of the information from
individuals, competitors, rivals, groups, governments, and enemies for personal,
economic, political, or military advantage, using techniques and Internet, networks or
individual computers through the use of proxy servers, cracking methods on the
malicious software including Trojan horses and spyware.
●​ It may wholly be perpetrated online from computer desks of professionals on bases in
faraway countries.
●​ It may involve infiltration at home by computer-trained conventional spies and moles or,
in other cases, maybe the criminal handiwork of amateur malicious hackers and software
programmers.

●​ Cyber spying typically involves using such access to secrets and classified information
or control of individual computers or whole networks for strategic advantage and
psychological, political, and physical subversion activities and sabotage.
●​ More recently, cyber spying involves analyzing public activity on social networking sites
like Facebook and Twitter.

●​ Such operations, like non-cyber espionage, are typically illegal in the victim country while
fully supported by the highest level of government in the aggressor country.
●​ The ethical situation likewise depends on one’s viewpoint, particularly one’s opinion of
the governments involved.

What is hacking?

●​ Computer hackers are unauthorized users who break into computer systems to steal,
change or destroy information, often installing dangerous malware without your
knowledge or consent.
●​ Their clever tactics and detailed technical understanding help them access the
information you don’t want them to have.

How can hackers find me?

rebyuwer ni jerom
ACC123

●​ Anyone who uses a computer connected to the Internet is susceptible to the threats that
computer hackers and online predators pose.
●​ These online villains typically use phishing scams, spam email or instant messages, and
bogus websites to deliver dangerous malware to your computer and compromise your
computer security.

●​ Computer hackers can also access your computer and private information directly if a
firewall does not protect you.
●​ They can monitor your conversations or peruse the back-end of your website. Usually
disguised with a bogus identity, predators can lure you into revealing sensitive personal
and financial information, or much worse.

Types of Hackers

Hackers are classified according to the intent of their actions. The following list ranks hackers
according to their goal.

●​ Ethical hacker/White hat - mabuti


●​ Cracker/black hat - masama
●​ Grey hat - mekus mekus
●​ Script kiddies - hacker wannabes (uses prebuilt hacking tools)
●​ Hacktivist - hacker with a purpose (social, religious, political, etc.)
●​ Phreaker - uses telephones instead of computers

What are things that a hacker can do to me?

●​ While your computer is connected to the Internet, a hacker has installed malware on
your PC quietly transmits your personal and financial information without your knowledge
or consent.
●​ Or, a computer predator may pounce on the private information you unwittingly
revealed. In either case, they will be able to:

-​ Hijack your usernames and passwords


-​ Steal your money and open credit card and bank accounts in your name
-​ Ruin your credit
-​ Request new account Personal Identification Numbers (PINs) or additional credit cards
-​ Make purchases
-​ Add themselves oranalias that they control as an authorized user, so it’s easier to use
your credit
-​ Obtain cash advances
-​ Use and abuse your Social Security number
-​ Sell your information to other parties who will use it for illicit or illegal purposes

rebyuwer ni jerom
ACC123

Predators who stalk people while online can pose a serious physical threat. Using extreme
caution when agreeing to meet an online “friend” or acquaintance in person is always the best
way to keep safe.

How will I know if I’ve been hacked?

●​ Check the accuracy of your accounts, credit cards, and documents. Are there
unexplained transactions? Questionable or unauthorized changes? If so, dangerous
malware installed by predators or hackers may already be lurking.

What Is Online Identity theft?

●​ Identity theft affects millions of Americans every year and occurs when a fraudster steals
your identity—by gaining access to your personally identifiable information (PII)—to
commit fraud. While ID theft can happen In several ways, online ID theft occurs when
someone steals your digital PII, using scams like planting malicious software on your
computer instead of the old, simple technique of, say, stealing your purse.

●​ Your digital PII can include your driver’s license and bank-account numbers, as well as
any sensitive personal information that can be used to distinguish your identity—and
could allow fraudsters to present themselves as you.
●​ If a thief gains access to unique personal information like your Social Security number,
they can fill out employment forms and even file for a tax refund—all in your name.

How online ID theft happens, and what can you do?

●​ As we share our personal information online via social media and other digital formats,
we may be putting that info at risk of falling into the wrong hands.

●​ Fraudsters use high-tech and other ways to steal digital PII. Knowing what these tactics
are may help you protect yourself:

●​ - Phishing: occurs when cybercriminals send emails purporting to be from a financial


institution or other trusted organization, trying to trick you into opening attachments or
clicking on links and providing your PII. Ignore unsolicited emails and type in the URL
rather than clicking on an emailed link, say, your bank’s website to provide information,
online requests.

●​ - Pharming: occurs when your browser, compromised by a virus, is hijacked without your
knowledge. You type a legitimate website URL into the address bar, but you’re redirected
to a fake site that looks legitimate. There, cybercriminals can collect any PII you may
type into the website.

rebyuwer ni jerom
ACC123

●​ - Malicious software: Fraudsters may try to trick you into downloading “malware” that can
attack your computer and, possibly, reveal your PII. Consider purchasing online security
software for your computer, keeping it and your computer operating system
software—up to date.

●​ - Unsecure websites: Avoid online shopping and other activities on websites that aren’t
secure, and be cautious about the apps you use. Make sure you use only official, secure
websites with the “HTTPS” prefix—not “HTTP.”

●​ - Weak passwords used for both social and financial accounts can leave you vulnerable.
Strive to use unique, long, and strong passwords for each of your accounts. And when
possible, activate multi-factor authentication, which requires you to enter both your login
credentials and a secret code sent to your smartphone or another device before giving
you access to your account.

●​ - Discarded computers and mobile devices that haven’t been wiped of your PII can be
another point of access for a thief.

●​ They were targeting children online. Kids can give away personal information online
without realizing it. Help protect your children online; be vigilant in monitoring the
information they share when using any Internet-connected device.

●​ We’ve all received emails saying we’ve won a too-good-to-be-true prize—redeemed by


providing our personal information. As with anything in life, when something online
seems too good to be true, it probably is. Don’t respond to emails from someone you
don’t know. Don’t click on unknown links or attachments.

The bottom line? You can never be too careful when sharing your personal information online.

MODULE 20

●​ What is a Database? A database (or electronic database) is an organized collection of


data or information structured for efficient storage, retrieval, modification, and deletion.
A Database Management System (DBMS) facilitates these operations and responds to
queries.

●​ Database Structure: Databases are stored as files (or sets of files) containing records
(one or more fields). Fields represent aspects of the data. Records are often organized
into tables showing relationships between fields. Databases offer search, sorting, and
data aggregation capabilities.

●​ Data Retrieval: Queries are the primary method for retrieving information. DBMS power
lies in defining relationships between data to answer complex queries.

rebyuwer ni jerom
ACC123

●​ User Needs: Extensive databases must be easily manipulated by many users


simultaneously. Large organizations often have multiple, interconnected databases.
Different DBMS types (flat, hierarchical, network, relational, object-oriented) address
various needs.

●​ Database Evolution: Early databases were sequential (alphabetical, numerical,


chronological). Direct-access storage allowed random access via indexes. Different
database types (flat, hierarchical, network) offer varying levels of data linking and
complexity. Network databases, with their multiple linkages, are widely used in business
and e-commerce. Relational databases use SQL and are common for their flexibility.
Object-oriented databases handle complex data structures.

●​ Database Content and Use: Databases contain various data types (natural language
text, numbers, statistics, financial data, scientific/technical data). They are used in
various applications, from personal use to large-scale commercial and governmental
uses (airline reservations, medical records, legal records, etc.). Reference databases
provide access to bibliographic information.

●​ Data Warehousing: Modern trends involve combining separate databases into larger
"data warehouses." Data mining techniques analyze this combined data to identify
patterns and trends.

Characteristics and Benefits of a Database


●​ Some characteristics distinguish the database approach from the file-based system or
method. This chapter describes the benefits (and features) of the database system.

●​ Self-describing nature of a database system


○​ A database system is referred to as self-describing because it contains the
database itself and metadata, defining and describing the data and relationships
between the database tables.
○​ This information is used by the DBMS software or database users if needed.
○​ This separation of data and information about the data makes a database system
different from the traditional file-based system. The data definition is part of the
application programs.

●​ Insulation between program and data


○​ In the file-based system, the structure of the data files is defined in the
application programs. If a user wants to change the form of a file, all the
programs that access it might need to be changed.
○​ On the other hand, the data structure is stored in the database approach's
system catalog and not in the programs. Therefore, one change is all that is
needed to change the form of a file. This insulation between the programs and
data is also called program-data independence.

rebyuwer ni jerom
ACC123

●​ Support for multiple views of data


○​ A database supports multiple views of data. A view is a subset of the database,
which is defined and dedicated for particular users of the system.
○​ Various users in the system might have different views of the system. Each view
might contain only the data of interest to a user or group of users.

●​ Sharing of data and multiuser system


○​ Current database systems are designed for multiple users. That is, they allow
many users to access the same database at the same time.
○​ This access is achieved through features called concurrency control strategies.
These strategies ensure that the data accessed are always correct and that data
integrity is maintained.
○​ The design of modern multiuser database systems is a remarkable improvement
from those in the past, which restricted usage to one person at a time.

●​ Control of data redundancy


○​ Ideally, in the database approach, each data item is stored in only one database.
○​ In some cases, data redundancy still exists to improve system performance. Still,
such redundancy is controlled by application programming and kept to a
minimum by introducing as little redundancy as possible when designing the
database.

●​ Data sharing
○​ The integration of all the data, for an organization, within a database system has
many advantages. First, it allows for data sharing among employees and others
who have access to the system.
○​ Second, it gives users the ability to generate more information from a given
amount of data than possible without integration.

●​ Enforcement of integrity constraints


○​ Database management systems must provide the ability to define and enforce
certain constraints to ensure that users enter valid information and maintain data
integrity.
○​ A database constraint is a restriction or rule that dictates what can be entered or
edited in a table, such as a postal code using a particular format or adding a valid
city in the City field.
○​ There are many types of database constraints. Data type, for example,
determines the sort of data permitted in a field, for example, numbers only.
○​ Data uniqueness, such as the primary key, ensures that no duplicates are
entered. Constraints can be Simple(field-based) or complex (programming).

●​ Restriction of unauthorized access

rebyuwer ni jerom
ACC123

○​ Not all users of a database system will have the same accessing privileges. For
example,one user might have read-only access (i.e., the ability to read a file but
not make changes).
○​ In contrast, another might have read and write privileges, which can read and
modify a file.
○​ For this reason, a database management system should provide a security
subsystem to create and control different types of user accounts and restrict
unauthorized access.

●​ Data independence
○​ Another advantage of a database management system is how it allows for data
independence.
○​ In other words, the system data descriptions or data describing data (metadata)
are separated from the application programs.
○​ Data independence is possible because changes to the data structure are
handled by the database management system and are not embedded in the
program itself.

●​ Transaction processing
○​ A database management system must include concurrency control subsystems.
○​ This feature ensures that data remains consistent and valid during transaction
processing, even if several users update the same information.

●​ Provision for multiple views of data


○​ By its very nature, a DBMS permits many users to access its database either
individually or simultaneously.
○​ Users don't have to be aware of how and where the data they access is stored.

●​ Backup and recovery facilities


○​ Backup and recovery are methods that allow you to protect your data from loss.
○​ The database system provides a separate process from a network backup for
backing up and recovering data.
○​ If a hard drive fails and the database stored on the hard drive is not accessible,
the only way to recover the database is from a backup.
○​ If a computer system fails in the middle of a complex update process, the
recovery subsystem is responsible for ensuring that the database is restored to
its original state. These are two more benefits of a database management
system.

MODULE 21

What Is in A Database?

rebyuwer ni jerom
ACC123

●​ A database is a software-based container structured to collect and store information to


be retrieved, added to, updated, or removed automatically.
●​ Database programs are software applications designed to make databases and create
all the programming necessary to fill them or delete them as needed.
●​ The structure of a database is in the table, which consists of rows and columns of
information. The columns identify the data ( attributes) in the table, and the rows are the
records of data. Tables look just lika spreadsheet, but tables can be manipulated and
updated, which makes a database a valuable tool.

Database Models

●​ Database model defines a database structure. The model used most is the relational
database model.
●​ The tables in this model must relate, or link, to each other, with each table holding
specific information or attributes (columns) about each record (row).
●​ For example, a veterinarian may have a table called "Patients"—with columns titled
"Patient's name," "Patient type," and "ID number"—and a second table called "Patient's
Owner"—with columns titled "ID number," "Owner name," "Owner address" and "Owner
phone number." The first table links to the second table by the ID number. The ID
number's relationship is how a report or query request finds records that belong together
and can return an accurate response.

Designing A Database

●​ Database design is an art based on business requirements. The business requirements


must be understood before an accurate and helpful database can be designed.
●​ Business requirements can also be called business processes. The tables should hold
no more than one set or module of information.
●​ For instance, in the previous example, the "Patient" table should not contain information
about the patients' visits. Instead, a separate table would hold a visit ID number and the
date and the time of the visit, and the patient ID number linking it to the patient. A fourth
table titled "Billing" would be created to identify the payment amount, payment type, and
the visit ID paid for with the patient ID. Billing and visits are business processes.

Working With A Database

●​ Entering records fills a database with data. Once the database is structured correctly, an
interface is built. This interface is placed between the tables and the user.
●​ It gives the user a different view of the database. Based on our example above. An
interface might provide the user a "New User" entry page.
●​ The user can enter the pet's name, the owner's information, and the date and type of the
first visit on this page.

rebyuwer ni jerom
ACC123

●​ All this information is contained in three different tables located behind the interface. Still,
the user only needs to interact with the entry page (a single form) while the data drops
into the correct tables. This is achieved by linking the tables via simple programming.

Types of databases

Depending upon the usage requirements, there are the following types of databases available in
the market –

1. Centralised Database

●​ The information(data) is stored at a centralized location, and the users from different
locations can access this data. This type of database contains application procedures
that help users access the data even from a remote location.

●​ Various kinds of authentication procedures are applied for the verification and validation
of end-users. Likewise, the application procedures provide a registration number that
keeps track of and records data usage. The local area office handles this.

2. Distributed Database

●​ Just opposite of the centralized database concept, the distributed database has
contributions from the shared database and the information captured by local computers.
●​ The data is not in one place and is distributed at various sites of an organization. These
sites are connected with the help of communication links, which quickly access the
broadcast data.
●​ You can imagine a distributed database in which various portions of a database are
stored in multiple locations(physical). The application procedures are replicated and
distributed among multiple points in a network.

●​ There are two kinds of distributed Databases, namely homogeneous and


heterogeneous.
●​ The databases with the same underlying hardware and run over the same operating
systems and application procedures are known as homogeneous DDB, e.g., all physical
locations in a DDB.
●​ In comparison, the operating systems, underlying hardware, and application procedures
can be different at various sites of a DDB, known as heterogeneous DDB.

[Link] Database

●​ Data is collected and stored on personal computers, which is small and easily
manageable. The same department uses the data, and a small group of people can
access it.

rebyuwer ni jerom
ACC123

[Link] User Database

●​ The end-user is usually not concerned about the transaction or operations done at
various levels and is only aware of the product, which may be software or an application.
●​ Therefore, this is a shared database designed for the end-user, just like different levels'
managers. A summary of complete information is collected in this database.

[Link] Database

●​ These are the paid versions of the vast databases designed uniquely for the users who
want to access the information for help.
●​ These databases are subject-specific, and one cannot afford to maintain such huge
information. Access to such databases is provided through commercial links.

[Link] Database

●​ These are used for large sets of distributed data. There are some significant data
performance issues which are effectively handled by relational databases, such kind of
issues are easily managed by NoSQL databases.
●​ They are very efficient in analyzing large-size unstructured data stored at multiple virtual
servers of the cloud.

[Link] Database

●​ Information related to the operations of an enterprise is stored inside this database.


Functional lines like marketing, employee relations, customer service, etc., require such
kinds of databases.

[Link] Databases

●​ These databases are categorized by a set of tables where data gets fit into a pre-defined
category.
●​ The table consists of rows and columns where the column has an entry for data for a
specific type, and rows contain instances for that data defined according to the category.
●​ The Structured Query Language (SQL) is the standard user and application program
interface for a relational database.
●​ Various simple operations can be applied over the table, making these databases easier
to extend, join two databases with a common relation, and modify all existing
applications.

[Link] Databases

●​ Data has been explicitly stored over clouds, also known as a virtual environment, either
in a hybrid cloud or a public or private cloud.

rebyuwer ni jerom
ACC123

●​ A cloud database is a database that has been optimized or built for such a virtualized
environment. There are various benefits of a cloud database, some of which can pay for
storage capacity and bandwidth on a per-user basis. They provide scalability on demand
and high availability.
●​ A cloud database also allows enterprises to support business applications in a
software-as-a-service deployment.

[Link]-Oriented Databases

●​ An object-oriented database is a collection of object-oriented programming and relational


databases.
●​ Various items are created using object-oriented programming languages like C++, Java
which can be stored in relational databases. Still, object-oriented databases are
well-suited for those items.
●​ An object-oriented database is organized around objects rather than actions and data
rather than logic.
●​ For example, a multimedia record in a relational database can be a definable data
object instead of an alphanumeric value.

[Link] Databases

●​ The graph is a collection of nodes and edges where each node is used to represent an
entity, and each bite describes the relationship between entities. A graph-oriented
database, or graph database, is a NoSQL database that uses graph theory to store,
map, and query relationships.
●​ Graph databases are used for analyzing interconnections.
●​ For example, companies might use a graph database to mine data about customers
from social media.

rebyuwer ni jerom

You might also like