Overview of Input Devices
Overview of Input Devices
An input device is a piece of hardware that is used to enter data into a computer.
Input devices are usually categorised as either manual or automatic.
Keyboard
Mouse
Touchpad
Joystick
Touchscreen
Concept keyboard
Scanner
Graphics tablet
Microphone
Digital camera
Keyboards
Practically all computers have QWERTY keyboards. These devices can be used to enter in data manually.
They are very efficient in the right hands and not so efficient if a user has limited training. In fact, they can be
very slow and mistakes are easy to make, although software tools can automatically fix many of them. A lot of
work has been done to ensure that keyboards are designed ergonomically. This means that they are designed in
a way that takes into account the 'design limitations' of a human being. There is a health and safety problem
known as Repetitive Strain Injury (RSI) for people who use keyboards all the time, such as secretaries. The
joints in their fingers can become 'worn'.
An important consideration for this kind of manual data input when used to transfer paper-based data into the
computer is the design of the user interface. Form-based interfaces should be used because they help the data
input operator enter data as quickly and as efficiently as possible. The form on the computer and the paper form
should be laid out in a very similar manner. There should be clear sections. In addition, tabbing should be used
and validation and verification techniques employed, for example.
Touch screens
This is another manual data input method. A touch screen enables a user to touch their VDU screen to make
selections. A plastic cover that has fine wires running through it can be placed over a VDU's screen. A user
makes a selection by touching the screen with their finger. The exact position can be calculated from the
signals sent back by the wires. Touch screens allow very fast selections from choices. They could be used in
places where people need to find out information but may have zero computer skills, for example, an
information system in a library or a museum. They would be of limited use if you had to type in a letter, for
example.
Graphics tablets
Another manual data input method is the graphics tablet. These are touch-sensitive pads that allow you to
'draw' on them with a stylus. The pressure from the stylus on the pad is sent to the computer, which reproduces
what was done on the pad in a drawing program or CAD program. These types of data input devices are far
more natural for designers to use than trying to use a keyboard and mouse to draw with.
Mouse
A mouse is a pointing and selecting device used with graphical user interfaces (GUI). There are different kinds
of mice around, each with their own advantages and disadvantages although they all broadly do they same
thing: point and select. A search on the Internet should enable you to quickly identify different sorts of mice.
These include:
Standard 2/3 button mice.
Mice with a scrolling wheel to allow you to better navigate applications and web pages.
Optical mice that aren't prone to collecting fluff and dirt and so don't need cleaning.
Mice that use radio waves to connect to the computer instead of wires, so that there is less clutter on the desk.
Ergonomically designed mice, for example, mice that are very small for the small hands of children.
Mice that can work with a serial port, a PS/2 port or a USB port.
Image capture
We will frequently want to capture images and get them into a computer. Images can be captured in a number
of ways. We will look at web cams, scanners, video capture cards and digital cameras.
Voice recognition
Voice recognition software is getting better every year! Using a microphone and some appropriate software, it
is possible to input data into a computer or directly into a tablet PC or phone. The software is not perfect. You
often have to teach it to recognise your voice accurately. If you have a cold or a throat problem, or a very
strong accent, it may reduce the accuracy of input. Nevertheless, it is still a fast way of inputting data.
Scanners
Images from magazines or photographs, for example, can be captured using scanners.
Typically, the image is placed on a flat screen or 'bed'.
A cover is placed over the image.
The image is divided up into sections or 'pixels' by the software. The user can tell the software what resolution
to use (how many pixels per square centimetre to split the picture up into). The higher the resolution, the better
the detail of the image but the bigger the file. Often, low resolution, smaller files will be perfectly adequate for
most uses.
A light is passed from one end of the flat bed to the other, so that it passes over the image and over each pixel.
When the light hits each pixel, it gets reflected back. The intensity of the reflection depends on the colour at
that pixel. Each pixel's information is stored.
The information about all of the pixels is used by the software to reconstruct a bit map image of the whole
picture.
Because bit maps are large files, they are often compressed. This can be done by telling the software to save the
image as a different file type that uses compression, such as GIF files or JPG files.
Software tools either within the scanning software or within a drawing package allow the user to manipulate an
image in various ways. These typically include allowing the user to 'crop' an image (select just a portion of an
image), allowing the user to improve the detail of the image, allowing the adjustment of colours and allowing
the user to add special effects such as making a photo image look antique.
Digital cameras
These cameras do not store images on film. They store images digitally in memory. The images are then
transferred to the computer. There are many points that could be made about digital cameras. The price of
digital cameras has been steadily falling over recent years. The amount of memory is a very important
consideration with these cameras, as is the ability of a camera to add memory. This is because storing images is
memory-intensive.
Cameras often allow the user to select between high resolution and low-resolution modes. If you use a high-
resolution mode, you will be able to take fewer pictures than low resolution mode.
You can immediately view photos and re-take or overwrite them if they are not what you want.
You can often add extra information easily, such as the date or information about the photo.
Many cameras allow you to add special effects as you take the picture.
Images can easily be combined into digital photo albums and distributed or emailed to friends.
Once the picture has been taken and transferred to the computer, it can be opened in a drawing package and
manipulated. Pictures can be cropped, colours changed and parts of the photo 'touched up', for example.
Camcorders
Video camera recorders, or camcorders, are cameras that store moving images. There is a wide range of types
of camera. Some camcorders store the moving images as analogue signals. You may have heard of VHS, Super
VHS or 8mm analogue camcorders. Analogue camcorder films lack really mint quality and lose quality if they
are copied. Films made using digital camcorders, on the other hand, have much better quality and don't lose
any quality if they are reproduced. This is because the films are stored digitally. Digital Video (DV) and Digital
8 are two of the common digital formats around. Typical features of digital camcorders include the ability to
zoom in, record sound, view films through a viewfinder, some have night viewing capabilities, time-lapse
photography, picture stability software and special effects.
Biometric devices
People are being increasingly identified using biometrics. This means using a unique part of your body to
identify you. Typical examples include fingerprint scanning in canteens, libraries, phones and ATMS, retinal
scanning for access to buildings and biometric data held in a chip in newer passports. Biometrics are very
convenient as you can't lose or forget a finger or your eye like you can a library card! It also reduces the need
for cash to be handled, which cuts down on costs and removes security issues. There are concerns about what
happens to the data, how it is stored and who has access to it, however, and the ever-present problem of hackers
stealing your data and using it for unauthorised or illegal activities.
Barcode readers
Optical mark reader (OMR)
Magnetic Ink Character Recognition (MICR)
Optical Character Recognition (OCR)
Magnetic stripe readers
Sensors
Smart Cards
Point-Of-Sale Terminal
Financial Transaction Terminal
Machine Vision System
When OMR sheets are completed, they can be scanned in automatically and the results produced straight away.
The data doesn't have to be typed in manually, which could introduce typing errors, takes time and can cost a
lot of money if there is a lot of data to enter. If you are not experienced filling in OMR sheets, they can cause
problems. It is easy to make a mistake. If this happens, you need to know how to correct it on the OMR sheet.
There is usually an elaborate set of procedures to follow if this situation arises. Estimates of the number of
OMR sheets rejected when used in questionnaires range from 10% up to 30%! In addition, if the OMR sheets
themselves get torn or creased, then they may get rejected.
OCR can be used to transfer spreadsheet information directly into a spreadsheet or to get textual information
from books into a word processor. You could easily use this method to scan the complete works of
Shakespeare, for example, and then you could analyse each work, to check that it has really been done by
Shakespeare! You could use this method to transfer human knowledge from books to computer to allow it to
then be searched easily, transferred and distributed, for example. OCR is used to read postcodes on letters by
the post office to enable speedy and cost-effective sorting of mail. It can be used to convert written documents
into a form that could then be output via speakers to people with problems with vision. Although software is
becoming ever more powerful, OCR is still only reliable for typed work. It still struggles to recognise
handwriting.
Bar codes
Bar codes are made up of black and white striped lines. The lines represent data in coded form. The data held in
a bar code can be retrieved by using a laser scanner. The data obtained can then be used to look up further
information held on computer.
Bar codes can be attached to libraries to speed up taking out and returning books. Membership systems that
require members’ details to be retrieved could employ barcodes. Supermarkets could use them for stock control
systems, to speed up the checkout process and to produce itemised receipts. Bar code systems have built in
validation techniques that greatly reduce errors. The data scanned can be integrated into management
information systems so that, for example, managers can tell which books are never taken out of a library and
should be removed, which members never attend an event or which products in a supermarket sell best on
Sundays. In supermarkets, bar codes are an integral part of the stock control system. One problem with any
system that is completely reliant on computerised systems, however, is what to do when the system breaks
down. A bar code for a product in a supermarket will typically contain:
the country of origin of the product
the manufacturer's identity number
the code for the actual product
the check digit, used to check that a number has been scanned in correctly.
When a cheque has been written, it will be paid in to the bank. It cannot yet be read automatically, because the
date and amount have been written on by hand. When a cheque is paid into a bank, an operator prints on the
cheque how much it is for and the date it was paid in. When all of the cheques for that day have been collected
together, they are loaded up into a special machine that batch processes them - it reads each cheque and adjusts
all the accounts as necessary. MICR cannot be considered completely automatic because some of the data must
be prepared before it can be entered into a computer. It is an example of a cross between an automatic data
input system and a manual one.
3. Smart Cards
Today the latest technology is the use of SIM (Subscriber Identity Module) which are adjusted on the cards. All
the basic identification data is stored on the SIM. This SIM also stores all the information relevant to the
transactions that occurred.
When the card is placed in the reader, the reader can read and write data on it. They are similar to Mobile SIMs
and have storage capacity up to 64K.
4. Scanners
They are very common and important today due to security reasons. The main importance of the scanner is that
it has the ability to read any item which passes through it.
We mainly see them at different places which are more susceptible to risk and where we want to check people.
5. Computer Scanner
It is a light-sensitive device that has the capability to translate text on the paper, magnetic characters, bar codes,
and all other images which are placed on its screen, into digital form so that a computer can read it. There are
two types of scanners; one is the coloured scanner and the other is a black and white scanner and both of these
types are available in two sizes which are handy and flatbed.
6. Optical Recognition
It is a type of scanner, different from the MICR, which has the capability of scanning a printed area and then
translates it into a form which is readable by the computer. Unlike MICR, it is not necessary that the printed
area must contain a magnetic material.
Three types of optical recognition systems which are the following:
a. Optical Mark Recognition
b. Optical Bar Recognition
c. Optical Character Recognition
7. Point-of-Sale Terminal
It is a method in which all the data regarding a transaction is captured at the time of the transactions. Bar codes
and MICR price tags which contain the information about the product’s cost and description is captured and
then a receipt is printed with all the details and then handed over to the consumer. They are also used in credit
cards in changing the account information of the credit card holder while he makes transaction using the card.
There is a logical arrangement of functions within the chip. With each part having a specific role to perform.
There are three main buses connecting all the parts together. These are the Data Bus, which carries the data, the
Address Bus which carries information on the location of the data and the Control Bus, which handles
commands to other devices such as the hard disk, the monitor and the graphics card
Purpose of a CPU
The CPU is often described as the 'brain' of the computer (although that isn't a technical term so don't write it in
an exam). The CPU is an electronic chip called a microprocessor.
The CPU fetches instructions from main memory (RAM), it decodes them and then executes them. The
instructions are provided by a computer program.
The purpose of the CPU is to process data. It is where all the searching, sorting, calculating and decision
making takes place within the computer.
So no matter what you do on your computer, whether it be writing an essay, looking at your photographs or
checking your emails, the CPU has dealt with all of the data and processing required to make these tasks
possible.
Another task performed by the CPU is to control all the other component parts of the computer for example:
Hard disk
DVD drive
Sound system
Graphics system
1. It controls the way data moves around the CPU by controlling the buses.
2. It controls and monitors the flow of data between the CPU and other components such as input devices,
memory, graphics card etc.
3. It executes the instructions provided by the program.
The collection of instructions it can carry out is called the 'instruction set' of the CPU. The instruction set is
hard-wired into the CPU when it was designed
This part of the CPU is responsible for managing how instructions are executed. It has some very important
jobs to do! It is in charge of fetching instructions and data from wherever they are stored in the memory unit. It
does this by sending control signals at the right time to various parts of the computer that then access the
correct memory unit location and retrieve the contents of that location. Its next very important job is to
interpret, or 'decode', an instruction so that it knows what has to be done. It has a special piece of equipment
called an 'instruction decoder' to do this. Once it has done this, it can then execute the instruction. It can send
signals to all the different parts of the CPU telling them what to do and when.
Any program you write or application you run is made up of a sequence of instructions. When you 'run' a
program, it is the control unit that is fetching, then decoding and finally executing every instruction, one after
another. Unsurprisingly, this is known as the 'fetch-decode-execute cycle' and is dealt with in another section.
Registers
No discussion about a CPU would be complete without mentioning the role of 'registers'. The registers are an
integral part of the CPU. They are a type of memory that can be accessed very quickly compared to other types
of memory. The pieces of information they hold are needed by the CPU to run each program instruction during
a 'fetch-decode-execute cycle' (more on this later) or they can be used to hold values that are generated as part
of the ALU working on data. There are a number of very special registers that do very specific jobs. We will
discuss them in much more detail in another section.
CISC
The above types of processors are sometimes referred to as CISC, or Complex Instruction Set Computers.
These processors can do complex operations, which can be carried out in just one instruction. They have many
different addressing modes and a wide range of instructions that can be used.
For example, a CISC processor might have a 'complicated' instruction designed into the hardware called
'POWER'. This can take one number from a register, find the power of that number, held in a different register,
and then store the result in yet a third register. So, 2 to the power 4 would be calculated as 16 and this would be
stored in a third register. This would all be done using one complex instruction, which might take about 3 or 4
CPU clock cycles to complete.
RISC
There are also CPUs that are known as RISC (pronounced ‘risk’), or Reduced Instruction Set Computers. RISC
processors such as ultra-SPARC and ALPHA use a much smaller, simpler set of instructions than CISC
processors and so to carry out any particular programming task may take many ‘fetch decode execute’ cycles.
RISC processors, however, are much more efficient at processing huge blocks of data than CISC.
CISC processors use instructions that are designed for the hardware so relatively little compilation is required.
The instructions themselves can include multi-clock cycle instructions and require very little RAM compared
to RISC instructions. This means smaller programs. Writing programs for CISC computers may be easier as the
instructions are similar to those found in high level languages. You don't have to include instructions that
manipulate registers, for example, as you would need to do in a RISC program.
Stress;
Eyestrain;
Wrist injuries;
Neck and back problems.
Employers can be sued if they do not take steps to protect employees.
Stress
Some of the ways that ICT systems can cause stress for workers:
Many people are afraid of computers and fear that they will be left behind or made redundant if they are
unable to learn new ICT skills quickly enough and keep up with the younger more computer-literate
generation;
ICT systems make information instantly available wherever you are. Mobile phones, pagers, portable
computers and the Internet make it possible to work anywhere. This means that some people find it
virtually impossible to forget about work and relax.
The amount of information that ICT systems can produce is often far too much for anyone to take in.
This results in ‘information overload’, which causes workers to become stressed by the feeling that they
can’t cope with the information that they are receiving.
Workers can be monitored using ICT systems — the feeling of being constantly ‘watched’ caused by
this can be very stressful.
Repeating the same physical movements over and over again can cause a condition known as RSI.
Repeated presses on the keyboard and long periods of holding and moving a mouse cause a build-up of damage
to the hands, arms and shoulders.
Eyestrain
Spending long periods of time in front of a computer screen can cause eyestrain.
Some evidence suggests that working for long periods in front of a computer screen may increase the risk of
miscarriage during pregnancy.
Laws designed to protect people from workplace health hazards are administered by the Health and Safety
Executive.
Inspect workstations to make sure that they meet the required standards for health and safety;
Train employees how to use workstations correctly;
Make sure that employees take regular breaks or changes in activity;
Provide regular eye tests for workstation users and pay for prescription glasses
Workspace design
When purchasing new equipment or designing a working ICT environment, employers must consider:
The sets of instructions that humans give computers are called programs or software.
Software that carries out a particular type of task for a user is often called applications software.
A computer works through these stages by ‘running’ a program. A program is a set of step-by-step instructions
which tells the computer exactly what to do with input in order to produce the required output.
Input
This stage of computing is concerned with getting the data needed by the program into the computer.
Input devices are used to do this.
The most commonly used input devices are the mouse and the keyboard.
Processing
The instructions about what to do with the input are contained in a program.
During the processing stage the computer follows these instructions using the data which has just been
input.
What the computer produces at the end of this stage is called output.
Output
This stage of computing is concerned with producing the processed data as information in a form that is
useful to the user.
Output devices are used to do this.
The most commonly used output devices are the screen, which is also called a monitor or visual display
unit (VDU) and the printer.
Data is any collection of numbers, characters or other symbols that has been coded into a format that
can be input into a computer and processed.
Data on its own has no meaning, or context.
It is only after processing by a computer that data takes on a context and becomes information.
There are many types of data
All data ends up being stored as a series of numbers inside the computer.
Data can be input to the computer by the user in many different ways.
The main types of data that can be input into a computer and processed are numeric, text, dates,
graphics and sound.
Computer Systems
Hardware is the name that is given to any part of a computer that you can actually touch.
An individual piece of hardware is called a device.
The basic hardware of any computer consists of a central processing unit (CPU) along with input,
output and backing storage devices.
WORD PROCESSING
A word processor is an application that is used to write, edit, format and print text.
Before word processors, printed documents were typed directly on to the paper using manual typewriters.
The main problem with using typewriters was that if a mistake was made it could not be corrected without
leaving any trace. If a typist made too many mistakes, an entire document would have to be typed out again.
This method of producing printed documents was very slow and time-consuming.
The style of the text can be changed. Different styles of text are called fonts.
Each font has its own name. e.g., Arial, Times New Roman
Other effects that can be used to change the appearance of text are options to make it bold, italic or
underlined.
The cut facility of a word processor allows you to choose a section of text, 'cut it out ‘and 'paste' it back
in another place or just throw it away.
The copy facility allows you to choose part of your text and then paste a copy of it elsewhere in your
document.
Word-wrap means that when you are typing you don’t have to press the enter key 8 at the end of a
line; the word processor will begin a new line whenever one is needed.
Tabulation
Tabulation allows the tab key F to be set to jump forward a pre-set distance across the page each time it is
pressed.
Search and replace allows you to tell a word processor to look for one word and replace it with another.
In the example shown below the user wants the word ‘Chalk’ replaced by the word ‘Cheese’
Line spacing
Line spacing is used to change the amount of space between lines of text.
Normal text is single spaced.
Other common line spacing options available in a typical word processing package include ‘single’,
‘1.5 times’, and ‘double’.
Spell checker
A spell checker uses a built-in dictionary to check the spellings in your text.
When a spell checker finds words that are unknown, it will offer possible alternatives from its
dictionary and ask if you want to choose a replacement, delete the unknown word completely, keep the
word as it is, or enter your own alternative word.
Import / Export
The import facility makes it possible to include diagrams and pictures produced using other software
packages on the page along with your text.
The export facility is simply the opposite of import.
Export allows you to transfer work produced using the word processor into other software packages.
Justification
Justification is a feature that adds extra spaces to a block of text to line it up in a particular way.
Text can be left justified, right justified, centred or fully justified.
Mail merging
Mail merging allows the user to create a standard letter and then merge it with data from a spreadsheet,
database or other text file.
This file is called the source data file.
During the merging process data from fields in individual records in the source data file is inserted into
spaces that have been specially marked in the standard letter.
This produces a ‘personalised’ letter is produced for each record in the source data file.
System software includes the operating system and utility programs. Application software caries out user-
related tasks and can be classified as general-purpose, specialist or tailor-made.
General-purpose packages
A general-purpose application package is a type of software that can perform many different related tasks.
Word processors, spreadsheets, databases, graphics and presentation software are all examples of application
packages.
This type of software is sometimes called generic software. This means, for example, that any one of the many
different word processing packages that you could buy will all do the same general sorts of tasks as each other.
Most computer users buy application packages ‘off-the-shelf’. There are several good reasons for using this
type of ready-made software.
It is relatively cheap;
It is readily available and can be installed quickly and easily;
It will have been thoroughly tested so there will be very little chance of it having any serious faults or
‘bugs’;
It will be well supported with a lot of books about how to use it available as well as on-line help and
discussions on the Internet.
Database packages (e.g. MS Access, Lotus Approach, Paradox) are used to store and retrieve
information;
Spreadsheet packages (e.g. MS Excel, Lotus 123) are used for tasks that involve a lot of calculations
or for the production of graphs and charts;
Word processing packages (e.g. MS Word, WordPerfect) are used to produce text based documents
such as letters, reports and memos;
Desktop publishing (DTP) packages (e.g. MS Publisher, PageMaker, PagePlus) are used to produce
professional quality publications such as posters, books, newsletters, newspapers and magazines;
Graphics packages (e.g. Paint, PaintBrush, Serif Draw, Corel Draw) are used to produce and
manipulate artwork;
Computer-aided design (CAD) packages (e.g. 2D-Design, AutoCAD, TurboCAD) are used to
produce engineering designs and architectural plans;
Communications software (e.g. Internet Explorer, Netscape Communicator) is used to access the
Internet and send and receive e-mail;
Presentation graphics packages (e.g. PowerPoint, Lotus Freelance) are used to create slide shows and
presentations like this one which can be viewed on-screen or with a data or overhead projector;
Web page editors (e.g. MS FrontPage, Macromedia Dreamweaver) are used to create Web pages.
Integrated packages
An integrated package combines many different types of application together in one single package.
This type of software normally offers facilities for word processing, spreadsheets, databases, graphics,
presentation and communications.
Integrated packages are much cheaper than buying many different application packages but their
different applications have a limited number of features compared with individual application packages.
Microsoft WORKS is an example of an integrated package.
Tailor-made software
Sometimes an organisation finds that ‘off-the-shelf’ software will not do exactly what they want.
In this case they might decide to have special tailor-made, or bespoke software specially developed for
the purpose.
The main drawbacks of this approach are the high cost and long time that some programs take to
develop.
What is a Cache?
Cache is a form of auxiliary memory that holds data and instructions that an app or website needs regular
access to. It’s fast, easy to access, and allows whatever application or website that uses the files in the cache to
work faster.
Your cache takes up space on your device’s hard drive. As you access more websites and install more apps, the
amount of memory your cache needs increases. If you don’t clear your cache, you’ll find that your hard drive
starts filling up faster and the device itself may slow down.
It contains a bunch of information and data that apps and websites find useful. But if you aren’t careful, your
memory bank gets bogged down as you try to put too much stuff into it.
There are several cache types, each of which serves different purposes. Your device has its own cache, which is
divided into several levels. This CPU cache exists to retrieve frequently used information for your device.
Other caches relate to web browsers and apps, with each leveraging different types of cache.
Primary Cache L1
Secondary Cache L2
Primary Cache L1 - This cache type is part of the processor in your device’s central processing unit. It tends
to be extremely small, with its memory ranging between 2 and 64 kilobytes. As such, your device’s primary
cache isn’t designed to hold a lot of data.
Instructions get stored in the primary cache for your device to access when it needs them. When the
instructions aren’t useful anymore, they get deleted to make way for new instructions. The key benefit of a
primary cache is that it works at almost the same speed as your processor.
Secondary Cache L2 - Secondary caches are the middlemen between your device’s processor and the device’s
main memory. If a cache miss occurs, your device usually jumps down to the secondary cache to see if it can
find what it’s looking for. A cache miss refers to any failed attempt to pull an instruction out of a cache. In this
case, an instruction may not get loaded into your device’s primary cache quickly enough, leading to the device
searching the secondary cache instead.
This cache type is larger than the primary cache. It tends to range from 256 to 512 kilobytes. It’s also held
externally to the processor, meaning it needs to be connected using a high-speed bus.
Main Memory L3 Cache - Main memory cache is a bit misleading here because this cache tends to be faster
than your device’s main memory. However, it’s stored away from the CPU, which is why it’s named that way.
This is the largest of the three CPU-related caches. L3 cache tends to clock in at between 1 and 8 megabytes,
meaning it can hold a lot more instructions. If you have a multicore processor, you’ll usually find that your L3
cache serves all of the cores at the same time.
Have you ever wondered why a web page that you visit often tends to load faster than a page you’ve never
visited before? You can thank web caches for that.
Web caches store data from browsers, websites, and servers that allow them to quickly access information
needed to speed up loading times. Without web caching, your browser has to send a new request every single
time you access a web page. That’s slow.
If the information is already in a device’s cache, a website can deliver static content quickly. Delays only occur
when the user accesses something they haven’t seen before.
The idea behind the various types of web caches is that they limit the number of server requests your browser
makes. Fewer server requests lead to faster loading times, in addition to reducing the load placed on the server
behind a website. Webmasters save money on network costs because of this reduced load.
1. Site Cache
2. Browser Cache
3. Micro Cache
4. Server Cache
Site Cache - Also known as page cache, site cache stores data about a website the first time you visit it. If you
return to the website, it pulls the saved data from the site cache to allow certain elements to load faster. For
example, the files stored in a site cache allow the page to display static web content faster than it would with a
fresh request.
Website owners can determine how much time a file stays in the site cache.
If elements of the website are likely to stay static for years, the owner may set a file’s expiry date several years
into the future. But files related to dynamic elements of a website tend to have much shorter expiry dates.
These shorter dates act like triggers to tell the website when it needs to refresh the files stored in your device’s
site cache.
As a result, site caches are best used for websites that have a lot of static content. The more dynamic the
website is, the less of a use it has for site cache.
As a side-note, you have control over the site cache. Though the website owner may set an expiry date for their
cached files, you can choose to clear this cache at any time. The only downside to this is that it’ll take a few
extra seconds to load web pages you’ve visited before. Still, it’s a good choice to make if your device’s site
cache becomes so large that the stored data starts eating away at your hard drive.
Browser Cache - The browser cache is a type of site cache that’s built into your web browser. Much like a site
cache, it stores a cached version of most of the websites you visit. This enables the browser to load websites
faster, providing you with a better web surfing experience.
Browser caches work by storing elements of a website, such as HTML pages, multimedia content and images,
and CSS stylesheets. It then groups those elements with other files related to the website’s content to create a
faster browsing experience. Cached images and content load faster because your browser doesn’t have to
download them again to display them.
Your entire browsing history is stored in the browser cache, which means you can clear browsing data by
deleting your browser cache. That’s another key feature of this type of cache. It’s controlled by the user,
meaning you always have the option of clearing it if it starts to take up too much storage space.
As with a site cache, website owners can set expiry dates on the cached version of files stored in the browser
cache. This allows the site to serve you with updated files for dynamic elements while ensuring you keep the
same files for static content.
Micro Cache - A lot of website owners and web users aren’t aware of this type of cache memory. The micro
cache stores content for short periods to ensure they display correctly. For example, it’s commonly used to
store the static elements of a dynamic piece of content. The micro cache stores files for up to 10 seconds.
This short storage time means this is the least common type of web cache. There aren’t many websites that
benefit from using it. Those that do usually feature rapidly changing content with static elements.
A good example is a stock website. The numbers change constantly but the graphs and table diagrams remain
static. Those static elements are stored and refreshed in the micro cache every 10 seconds, with the more
dynamic elements changing as and when they need to.
You’re able to clear this type of cache memory. However, its extremely limited use means that doing so won’t
free up much storage space.
Server Cache - Server cache is a general term that covers several types of cache memory. These include object
caching, opcode caching, and content delivery network (CDN) caching. This is the only form of web caching
that you don’t control. Instead, it applies to the website owner because server caches store frequently accessed
data on the website’s server.
Think of the server cache as a method of storing data that a website owner knows that visitors will need
regularly. The site checks this form of temporary storage for requested data first before it searches the rest of
the server.
Most apps maintain their own caches to save files and data that the developer thinks users need quick access to.
These caches allow the app to pull frequently accessed data from the cache memory to serve it up to users.
Data stored in software caches vary depending on the application. Some store your search history or user
preferences. Others may store video thumbnails or background images. Whatever the stored content may be, all
software caches aim to reduce latency and provide a cost-effective way for users to access frequently accessed
content.
If a webpage or application needs to retrieve data from a database, it likely used data caching. That’s because
the input and output requests needed to pull data from databases are hardware-intensive. If users request the
same set of data often, and that data doesn’t change over time, it’s likely the developer will use data caching to
serve it up more quickly.
The data cache is maintained on the web or application server. Storing data in these caches lowers the demand
placed on servers, making the use of data caches a more cost-effective way to deliver data.
You likely won’t have control of the files stored in this type of cache memory.
Instead, the developer needs to create a way for themselves to clear the cache if the data it holds goes out of
date or becomes obsolete.
This is the type of cache those networks often used. Application and output caching are built into many
contentment management software packages. As with most other cache types on this list, they reduce server
overhead by storing static content that a user accesses regularly. If a page contains mostly written content, this
cache improves application performance by allowing the page to load faster.
They cache raw HTML in cache memory, which allows for the faster loading of static pages. Smart uses of this
type of cache can reduce webpage loading times by up to 50%.
This type of cache memory is for the big boys. The likes of Google and Amazon use distributed caching
because they have high-volume systems. This cache allows major companies to store data across several
distributed database servers. The data in each of these database servers is cached in different web servers.
Those web servers supply data to applications within the distributed cache.
The key difference between distributed caching and other cache types is that this type of cache never runs out
of storage space. If a storage limit is about to be reached, the company can simply add new servers to its pool
without disrupting the user experience. As such, distributed caching is a great way for high-volume systems to
account for increasing numbers of user visits.
Even though this is a form of specialized cache reserved for high data loads, it still serves the same function as
most other cache types. Distributed caching allows cached data to be displayed quickly.
Though there are several cache types, they generally all serve the same purpose – loading cached data faster. If
users access the same data types regularly, developers can use cache memory to serve that data to them faster.
The result is webpages and applications that can access data in a matter of seconds, leading to a better
experience for the user.
The issue is that the benefits of cached data relate solely to the website or application using the cache.
As a cache fills up, it takes up storage space that you might want to use for something else. Different caches
can also affect your device. For example, mobile devices may run slower than they normally would as their
various cache folders fill up.
While it enables faster access to data, it can also slow down operating systems and use extensive amounts of
storage space. Thankfully, you have control of most cache types. Clearing cache is often a simple case of
navigating through a browser or applications settings menu to find the option to get rid of the stored files.
Ultimately, that choice depends on what you need from your device.
If you want faster application and website loading times, keeping files in cache is a good idea. But if you want
to free up storage space and optimize how the device itself runs, regular cache clearing is recommended.
Caches have several benefits relevant to the software or website that place files into them. They can store key
data, making it easier to fill out forms. Files in your cache also speed up the software or website they’re related
to.
Clearing the cache means deleting the files that are automatically stored in the cache when you visit a website
or open a new app. Clearing often allows you to free up space, which is particularly useful for devices that have
small hard drives. You may also speed up your device by clearing its cache.
Yes, it is ok. Clearing your cache has several benefits for device performance and speed. It also protects
personal information stored in the files inside your cache by preventing people from accessing them. Plus,
clearing your cache prevents your device from trying to use old data when you fill out forms.
HACKING
Hacking is a general term for a variety of activities that seek to compromise computers and networks. It refers
to any unauthorized intrusion into a device, network, or server which infringes on the privacy of their owners
and users and/or aims to damage or otherwise compromise computer-based properties like files, programs, and
websites. While the term can also refer to non-malicious activities, it is most often associated with malevolent
attempts to exploit system vulnerabilities for the benefit of the perpetrator.
The people who engage in hacking are commonly referred to as hackers. First used in a 1980 magazine article,
this term was popularized a few years later by the movies “Tron” and “WarGames”. Over the years, hackers
have become a staple of popular culture. However, the usual portrayal of hackers as self-taught, thrill-seeking
programming geniuses is not only stereotypical but also greatly exaggerated.
Although usually technical in nature, hacking doesn’t necessarily require excellent computational skills.
Hackers can also break into computers and systems using social engineering, a set of psychological tactics
designed to trick an unsuspecting target into giving hackers access to their data. What’s more, while hacking
does require at least some grasp of computer technology, anyone can go to the dark web to purchase the tools
they need to carry out an attack or hire a professional hacker to do it for them.
In addition to fun and thrill, hackers can be motivated by numerous other factors. These include financial gain,
theft of personal data, access to confidential information, the desire to take down websites, as well as idealism
and political activism. While some forms of hacking are completely legal, most of them are not and are
considered criminal offenses. Depending on the severity of their attack, hackers in the United States can serve
anywhere from a few weeks to 15 years in prison for computer tampering.
Hacking Types
Based on the intentions of hackers as well as the legality of their attacks, there are three main types of hacking.
They include the following:
Commonly referred to as ethical hacking, white hat hacking is always used for good. Instead of being the
stereotypical renegade whiz kids you see in movies, white hat hackers are often employed or contracted by
major companies to help them improve their security by identifying vulnerabilities in their system. Ethical
hackers use pretty much the same methods as all other hackers, but they always do it with permission from the
owner of the system. There are many courses and conferences on ethical hacking.
Black hat hacking is the opposite of white hat hacking, which is why it is often referred to as unethical. The
hackers behind black hat attacks are usually driven by personal or financial gain, although they can be
motivated by many other factors, as well. Because they don’t have an explicit permission from the owner to
hack their system, they use phishing emails and compromised websites to download and install malicious
software on potential victims’ computers and use it to steal the victims’ personal information.
Gray hat hacking falls somewhere between ethical and unethical. As a rule, gray hat hackers are never outright
malicious, though some of their moves could be interpreted as such. For example, they may hack into a
network without the owner’s permission to search for vulnerabilities. After that, they will usually contact the
owner and ask for a small fee to fix the issue. However, if the owner declines, hackers might share their
findings online, thus inviting their unethical peers to exploit these vulnerabilities.
There are dozens of different techniques hackers utilize to carry out their attacks. They range from malware
distribution and phishing email campaigns to surveillance and organized botnet activities. The five most
common hacking techniques nowadays include the following:
1. Fake WAP
Taking advantage of the fact that more and more people are using public WiFi to connect to the internet,
hackers have developed software that allows them to fake a wireless access point (WAP). When they want to
use free Wi-Fi, unsuspecting victims will see a list of legitimate-sounding WAP names (e.g. “McDonald’s
WiFi 2” or “JFK Airport WiFi”). However, once connected to the fake WiFi, they will give hackers instant
access to their device, allowing them to steal their personal data and files.
2. Keyloggers
A growing number of hackers are opting to use keyloggers, hardware-based or software-based tools that allow
them to record their victims’ keystrokes with the goal of stealing their personal information. Most software-
based keyloggers are designed like actual pieces of software and operate so close to the core of the system that
they can bypass most antivirus and antimalware programs. To protect their clients’ sensitive data, many online
banking services have incorporated mouse-controlled virtual keyboards.
3. DDoS Attacks
Hackers can also use malicious software to build botnets, large networks of remote-controlled internet-
connected devices. These botnets are most often used to launch distributed denial-of-service (DDoS) attacks
against websites and computer networks that the hackers behind them want to target. Together, the devices that
make up a botnet generate abnormal amounts of incoming traffic to a website or a network in order to
overwhelm their targets’ computational resources and restrict access to them.
4. Phishing
Perhaps the most common form of cybercrime, phishing involves the mass-sending of emails from seemingly
real addresses with the goal of tricking potential victims into opening the links or attachments included in them.
The targets will receive an email from someone claiming to be their bank, urging them to click on the included
link and confirm their password. When they click on the link, they will be taken to a fake online banking login
page, and all the information they enter will be sent directly to the hacker.
5. Cookie Theft
Most websites nowadays use cookies to allow for a more personalized experience. Similarly, web browsers use
cookies to store your passwords, bookmarks, and browsing history for faster surfing. To ensure your online
safety, you should only enter your login details on encrypted websites that use HTTPS, the secure version of
HTTPS. Otherwise, hackers may use the opportunity to intercept your data and hijack your browsing session.
From there, they can access your cookies, as well as your login details.
CYBERCRIME
The term cybercrime can refer to any criminal activity that involves a computer, either as the tool of the crime
or as its target. According to the Department of Justice, all cybercrime can be organized into three categories –
crimes that use computers as a weapon (e.g., hacker attacks), crimes that target a computer or another device
(e.g. to gain access to a network), and crimes where a computer is neither the main tool nor the main object but
still plays an important part (e.g. storing of illegally downloaded files).
With the increased availability of the internet in recent years, the nature of cybercrime has evolved. Not that
long ago, the bulk of cybercriminal activities involved illegal downloads of copyrighted content or hate speech
on the internet. Although they are nothing to laugh at, these acts are fairly benign in comparison to what has
come since. Nowadays, new cases of extortion, mass-surveillance, financial theft, data breaches, theft of
personal information, and espionage are making the headlines almost daily.
Cybercrime has been on an unprecedented rise as of late, so it perhaps shouldn’t come as a surprise that the
world economy is losing more than half a trillion dollars per year as a result of cybercriminal activity.
Although many law enforcement agencies around the world have started cracking down on cybercrime, the
increasing trend is showing no signs of decline. To avoid being persecuted, some cybercriminals have moved
to countries with weak cybercrime laws and switched from dollars to untraceable cryptocurrency.
As with offline criminal activities, most perpetrators of cybercriminal acts are motivated by financial gains. In
addition to money, cybercriminals can also be driven by their egos, a cause they believe in, personal vendettas,
a sense of notoriety, as well as the desire to improve their status in hacker circles.
Cybercrime Types
Cybercrime can come in many shapes and forms, some of which you might not necessarily associate with it.
For example, even the theft of a physical computer can be considered a cybercriminal activity if the perpetrator
intends to use the information stored on the computer for personal gain. If someone steals a flash drive with
valuable data that they plan to sell on the dark web, that also qualifies as a cybercrime.
DDoS Attacks
A DDoS attack is an acronym for a Distributed Denial of Service attack. It renders an online service
unavailable by bombarding it with traffic from multiple sources.
It is a type of Denial of Service (DoS) attack, which is an attack that comes from a single source: just one
network connection or one compromised device. DDoS attacks, in comparison, are attacks that come from
multiple sources.
Essentially, a Denial-of-Service attack is any method of preventing actual users from accessing a network
resource. That café example in the earlier analogy can be any sort of online resource: a game server or a
website for instance.
When the server or site is under DDoS attack it won’t be able to serve its actual purpose. As the attack
overwhelms that website or game server with fake traffic, the actual traffic—the people who want to join the
game server or visit the website—won’t be able to.
Most DDoS attacks are deployed via “botnets,” a network of bots, or an internet-connected network of
compromised devices controlled by a hacker. Botnets can number from just a handful of devices to literally
millions. Worse, as most botnets use compromised resources, the actual owners of the devices don’t even know
they’re being used for DDoS attacks.
Multiplying the sources of attacks amplifies the effectiveness of the attack while also helping conceal the
identity of the perpetrator.
To better understand how to stop a DDoS attack, you’ll need to grasp their different types first. DDoS attacks
fall under three broad categories, which depend on where the attack is focused:
1. Volume-based attacks – As the name suggests, this type of DDoS attack leverages volume. Volume-based
DDoS attacks are also aptly called “floods.” This is the most basic type and is the very definition of a DDoS
attack.
2. Protocol attacks – This type of DDoS attack focuses on sending waves of bots to specific protocols: e.g. the
web balancers, the firewalls, or the actual web servers that comprise the network resource it is trying to crash.
3. Application attacks – Considered the most serious and sophisticated type of DDoS attack, these attacks
target web applications by exploiting vulnerabilities within them. Also called “Layer 7 attacks,” application
attacks still function the same way, but they require much less brute force because they focus on weaknesses
within the target servers. It takes much less bot traffic to monopolize specific processes and protocols within
these weak points, and it also makes the attack much more difficult to detect because the low volume of traffic
generated may seem legitimate.
These most commonly used DDoS attacks derive from the three broad categories above:
UDP Flood
Applications use communications protocols to connect through the internet. The most typically used protocols
are Transmission Control Protocol (TCP or sometimes TCP/IP, with IP meaning Internet Protocol) and User
Datagram Protocol (UDP or UDP/IP). They send packets of data across the internet to establish connections
and send data properly.
A UDP flood is exactly what you would expect: a DDoS protocol attack targeting UDP.
The perpetrator sends the target UDP packets with false information—the targeted network resource will be
unable to match the UDP packet with the right associated applications, and will return an error message. Repeat
these enough times and the system can become overwhelmed, ultimately becoming unresponsive.
DNS Flood
Domain Name Servers (DNS) are computer servers that translate website URLs into their actual IP addresses.
For example, when you visit Facebook to check in on your friends and family, you type in Facebook[.]com into
your browser. What you’re actually telling your computer is to go to one of Facebook’s IP addresses (Facebook
has many, considering how much traffic it needs to accommodate). One such Facebook IP address is
[Link].
DNS servers translate the website name you know into their actual IP addresses.
So, what would happen if you use a DDoS attack to flood DNS servers so they won’t be able to perform this
function? That is the goal of a DNS flood.
SYN Flood
A SYN request is part of a “three-way handshake” connection sequence done through TCP. Don’t worry, it
might sound technical, but it’s pretty straightforward:
First, a SYN (synchronize) request is sent to a host. The host then sends back a SYN-ACK (synchronize-
acknowledgment) response. The host that requested the three-way handshake then finalizes the protocol with
an ACK (acknowledge) response. What this process does is it allows the two hosts or computers to negotiate
how they will communicate moving forward.
A SYN flood stops the three-way handshake at the first part. An attacker sends multiple SYN requests either
from fake IP addresses or simply does not respond back to the SYN-ACK response from the target. The
targeted system continues to wait for last part of the three-way handshake, the ACK response, for every
request.
Do this with enough speed and volume and you can bind the target system’s resources until no new
connections can be made, resulting in a denial of service.
HTTP Flood
HTTP stands for Hypertext Transfer Protocol, and is the foundation of data transfer for the internet. In fact, you
should see it in your browser address bar right now, with an additional “S” which stands for secure HTTP.
As with all other protocols, HTTP uses a few request types to send or request information, such as HTTP
POST and GET. An HTTP flood is typically used when hackers gain useful information from a website and
cover their tracks with a large number of HTTP POST or GET requests to overwhelm the web application or
server.
This method uses less bandwidth to execute, but can force servers to max out their resources.
Internet Control Message Protocol (ICMP) is an error-reporting protocol commonly used by the ping
diagnostic utility, among others. Basically, you “ping” a website to check whether you can access it. The ping
results can tell you some sorts of problems with connectivity, and from there you can begin to troubleshoot.
A ping sends a small packet of information to the target network resource (e.g. website), and that resource
sends a similarly sized packet of information back.
A ping flood is simply a deluge of ping requests, so much that the targeted system’s network bandwidth gets
clogged by trying to respond to every request.
Another DDoS attack that uses ping is called the Ping of Death, which instead of using high volumes of
similarly sized data packets, circumvents security measures and sends oversized or malformed data packets to
overburden the target system.
DDoS attacks are hard to identify. A system admin performing maintenance or even a technical problem with
particular network resources can produce symptoms similar to a DDoS attack. Still, it is best to stay vigilant
and look deeper into unusually slow performance and unavailability of services.
DDoS protection can be set up through network traffic monitoring and analysis via monitored firewalls or
intrusion detection systems—these can detect and identify DDoS attacks. System admins can also set up alerts
for anomalous traffic activities such as unusually high traffic loads or network packet drops that meet certain
criteria.
The bad news is that modern DDoS attacks can be so large and sophisticated that resolving one on your own is
next to impossible. You will have to call your ISP or a DDoS mitigation specialist to completely stop the
threat.
If you are experiencing an attack, there are a few things you can try that can buy you time to call your ISP or an
expert:
Overprovision bandwidth – increase your bandwidth availability to several times more than your current limit
to accommodate for sudden surges in traffic.
Defend the network perimeter of your own web server – You can mitigate the effects of an ongoing DDoS
attack by tweaking some network perimeters:
o Rate limiting your router helps prevent your web server from being overwhelmed.
o Adding filters helps your router identify obvious sources of attacks.
o Create more aggressive timeouts for half-open connections. Some of the most common DDoS attacks
take advantage of half-open protocols to clog your bandwidth. More aggressive timeouts help close
ongoing DDoS attack vectors.
o Drop malformed and spoofed data packages.
o Set lower drop thresholds for SYN, UDP, and ICMP – three of the most common DDoS attacks.
Once you perform these tweaks, you could buy enough time for your ISP to get a handle on the DDoS attack,
or for a mitigation expert to resolve it.
Spoofing Attack
Spoofing is a fraudulent act in which communication from an unknown source is disguised as being from a
source that is known to and trusted by the recipient. A spoofing attack occurs when a person (referred to as a
spoofer) pretends to be someone else in order to trick their target into sharing their personal data or performing
some action on behalf of the spoofer. The spoofer will often take time and make an effort to build trust with
their target, thus ensuring that they will share their sensitive data more easily.
As a type of impersonation carried out via technological means, spoofing can take on many forms. In its most
primitive form, spoofing refers to impersonation via telephone. For example, when a caller on the other end
falsely introduces themselves as a representative of your bank and asks for your account or credit card info, you
are a victim of phone spoofing. To make their fake calls seem more believable, spoofers have also started using
software to fake caller IDs, an act known as phone number spoofing.
The most sophisticated forms of spoofing, however, are taking place online. In most cases, they involve the
sending of fraudulent emails to unsuspecting targets, but may also include the spoofing of devices and
addresses. Regardless of their type, most spoofing attacks are malicious. The attackers behind them usually aim
to gain access to the victim’s personal data, distribute malware, access private networks, create botnets for the
purpose of carrying out cyber-attacks, or cause financial losses to the victim.
Spoofing isn’t illegal in itself, as you might sometimes need to fake your phone number, your IP address, or
even your name to protect your identity and be able to access certain services that may otherwise be
unavailable in your location. However, it is illegal to use spoofing to defraud someone and engage in criminal
activity. Depending on the severity of their attack, spoofers may be fined and/or sentenced to prison. They may
also have to compensate their victim for any losses suffered as a result of the attack.
Spoofing Types
Cybercriminals employ a variety of methods and techniques to carry out spoofing attacks and steal their
victims’ sensitive information. Some of the most common types of spoofing include the following:
1. Email Spoofing
Email spoofing is the most prevalent form of online spoofing. Similar to phishing, spoofers send out emails to
multiple addresses and use official logos and header images to falsely introduce themselves as representatives
of banks, companies, and law enforcement agencies. The emails they send include links to malicious or
otherwise fraudulent websites and attachments infected with malicious software.
Some spoofers may also use social engineering techniques to trick the victim into disclosing information
voluntarily. They will often create fake banking or digital wallet websites and link to them in their emails.
When an unsuspecting victim clicks on that link, they will be taken to the fake site where they will have to log
in with their information, only to have that info sent to the spoofer behind the fake email.
2. DNS Spoofing
Each computer and each website on the internet are assigned their own unique IP address. For websites, this
address is different from the standard “www” internet address that you use to access them. When you type in a
web address into your browser and hit enter, the Domain Name System (DNS) quickly finds the IP address that
matches the domain name you entered and redirects you to it. Hackers have found ways to corrupt this system
and redirect your traffic to malicious websites. This is called DNS spoofing.
Also known as DNS cache poisoning, this method is used by cybercriminals to introduce corrupt DNS data on
the user’s end, thus preventing them from accessing the websites that they want to access. Instead, no matter
what web address they type in, the user will be redirected to the IP addresses defined by the hacker, which most
often hosts malicious software or fake forms that harvest the victim’s personal data.
3. IP Spoofing
As the name suggests, IP spoofing refers to the use of a fake IP address by the sender to either disguise their
real identity or to carry out cyber attacks. The sender assumes an existing IP address that doesn’t belong to
them in order to send out IP packets to networks they otherwise wouldn’t have access to. Since they’re coming
from a trusted address, the security system on the recipient’s end will see the incoming packets as part of the
normal activity and won’t be able to detect the threat until it’s too late.
Not all instances of IP spoofing are malicious. The virtual private network (VPN) technology is based on IP
spoofing, but its main purpose is to protect the users’ identity, allow them to access content that is otherwise
blocked due to internet censorship, and prevent cyber attacks while on a public Wi-Fi connection. Although
some countries like China and Turkey have outlawed the use of VPN, it is legal in most countries of the world
as long as it’s not used to engage in cybercriminal activities.
4. DDoS Spoofing
DDoS spoofing is a subtype of IP spoofing used by hackers to carry out Distributed denial-of-service (DDoS)
attacks against computers, networks, and websites. The attackers use various techniques to scan the internet for
computers with known vulnerabilities and use these flaws to install malicious software. This allows them to
create botnets, armies of “robot” computers, all remotely controlled by the hacker.
Whenever they want, the hacker can activate all the computers in their botnet and use their combined resources
to generate high levels of traffic to target websites and servers in order to disable them. Each of these
computers has their own unique IP address. Considering that botnets can comprise a million or more computers
with as many unique IPs, tracing the hacker’s actual IP address may prove impossible.
5. ARP Spoofing
Every internet-connected device has its own Media Access Control (MAC) address that is linked to the
device’s unique IP address via the Address Resolution Protocol (ARP). Cybercriminals can hack into their
target’s local area network and send false ARP data. As a result, the hackers’ MAC address will become linked
to the target’s IP address, thus giving them insight into their target’s incoming traffic.
Hackers opt for ARP spoofing to intercept sensitive data before it reaches the target computer. They may also
modify parts of the data so that the recipient can’t see them, while some hackers will stop the data in-transit,
thus preventing it from reaching the recipient. ARP spoofing attacks can only be carried out on local area
networks use ARP. In addition, the hacker must first gain access to the local area network.
Spoofing Examples
In 2006, unknown hackers carried out a major DNS spoofing attack – the first of its kind – against three
local banks in Florida. The attackers hacked the servers of the internet provider that hosted all three
websites and rerouted traffic to fake login pages designed to harvest sensitive data from unsuspecting
victims. This has allowed them to collect an undisclosed number of credit card numbers and PINs along
with other personal information belonging to their owners.
In June 2018, hackers carried out a two-day DDoS spoofing attack against the website of the American
health insurance provider, Humana. During the incident that was said to have affected at least 500
people, the hackers have managed to steal complete medical records of Humana’s clients, including the
details of their health claims, services received, and related expenses.
In 2015, unidentified hackers have used DNS spoofing techniques to redirect traffic from the official
website of Malaysia Airlines. The new homepage showed an image of a plane with the text “404 –
Plane Not Found” imposed over it. Although no data was stolen or compromised during the attack, it
blocked access to the website and flight status checks for a few hours.
Scams
An online scam is any use of internet technology to defraud people. Internet scams are carried out by
cybercriminals for some type of personal gain, financial or otherwise. Scammers use deceptive methods like
phishing emails, fake websites, and malicious software to gain access to their victims’ data, files, and personal
information. They may steal their victims’ credit card data and Social Security numbers, access their bank
accounts and medical records, or even trick them into willingly giving them their money.
For as long as there has been the internet, there have also been scammers hoping to trick inexperienced users
into sharing their sensitive information. The concept of internet fraud first caught public attention in the mid-
1990s, when reports about the use of stolen credit cards with celebrity names emerged. With the subsequent
boom in e-commerce, online scammers became craftier and started setting up fake shopping and auction
websites that looked just like the real thing to target unsuspecting shoppers.
Despite some major cybersecurity advancements in recent years, online fraud has experienced a sharp rise in
the social media age. According to statistics, internet scams have reached a record high in 2017, with more than
45,000 reported cases in the United States alone. Similarly, almost 7,000 Australians were victims of online
shopping scams in 2017, which has cost them just under $1 million (A$ 1.38 million). Globally, online scams
have so far cost businesses and individuals more than $100 billion.
Online scams and internet fraud in general have long been part of the U.S. Criminal Code. This legal document
prescribes a maximum sentence of 20 years for fraud in relation to computers, access devices, and personal
documents. Email fraudsters can get a maximum sentence of five years, whereas the owners of misleading or
deceptive websites with inappropriate content can get up to 10 years in prison.
There are numerous types of online scams, ranging from the impersonation of others on social media to fake
crowdfunding campaigns. Some of the most common types of scams include the following:
1. Spear Phishing
Spear phishing is the act of sending deceptive emails to individuals, groups, and organizations in an effort to
gain access to their private information. Instead of just randomly sending out these emails to millions of
addresses, hackers send them only to specific targets whose addresses they have acquired via social media or
stolen email records. To make the scam seem more realistic, hackers will often pretend that they are the
victim’s business partner and address them by their name rather than using a generic intro.
To acquire the victim’s personal information, scammers will ask them to fill out an urgent invoice or respond
to a false query. They may also attach a file to the mail and claim that it contains a very important document
that needs to be revised. Unsuspecting victims will download the attachment to their computer, only to have
malicious software installed on their computer. This, in turn, will allow the scammer to monitor not just the
victim’s PC but all other devices connected to the same network, too.
2. Lottery Scams
There’s probably not an internet user that hasn’t received at least one lottery scam email in their lifetime. Many
inexperienced users have fallen victim to this scam over years and sent money to the scammers. These
messages inform potential victims that they have won a large sum of money, but that they have to pay a small
fee in order to claim their prize. In some cases, scammers may even set up their own fake online payment
terminal that will also give them access to the victims’ credit card info.
Usually sent out around big holidays, greeting card scam emails inform you that you have received an animated
greeting card from a friend or a family member, but there’s a catch. Namely, to view your greeting card, you
must click on the link included in the mail and download a piece of software, usually Flash Player. However,
instead of Flash Player, you will download a piece of malicious software that will allow hackers to track your
activity, access your files and documents, and even record your keystrokes.
Also known as a Nigerian scam, an advance fee scam usually starts with a poorly written emotional email
allegedly sent by someone from a war-torn country whose parent has left them a large sum of money. They will
ask you to let them transfer the funds to your bank account in exchange for 20% of the sum.
If you respond to the email, the scammer might start a long chain of correspondence, asking you to pay various
fees and taxes to help them transfer the money. They will even send you forged documents to make the scam
more believable. Alternatively, they may ask you to provide your bank account info so they can transfer all the
funds at once. If you do, they will instead use the info to empty the account.
5. Killer Scams
Killer scams involve an email sent by an alleged assassin who has been hired by an unnamed person to murder
you. In this email, they will tell you that the only way to avoid death is to pay them thousands of dollars within
a small timeframe, typically no more than 48 hours. These emails may contain personal information collected
from your social media profiles to make the threat seem more real.
Thought by many to be a thing of the past, new killer scam cases recently made the news in the United States.
This time, however, scammers were seeking ransom in cryptocurrency rather than physical money. That way,
if the target fell for their scam, the authorities would have no way to catch them.
While some online scammers manage to stay anonymous and escape the law, many end up arrested and tried
for their cybercrimes. Some of the largest online scams uncovered by law enforcement in recent years include
the following:
In 2016, the Nigerian police arrested a 40-year-old man responsible for thousands of successful online
scams around the world. Known only as “Mike”, the man used spear phishing emails to install malware
on his victims’ computers and gather their personal data, earning more than $60 million in the process.
In June 2018, 74 people were arrested in the United States, Nigeria, Poland, Mauritius, and Canada for
their involvement in spear phishing and advanced fee scams. The arrested scammers have stolen
millions of dollars, with $16 million successfully recovered by the US authorities.
Also in June 2018, 95 professional scammers were arrested by Europol for carrying out more than
20,000 transactions using stolen or otherwise compromised credit cards. In doing so, they have obtained
more than $9 million (8 million euros).
Phishing
Phishing is any attempt to acquire somebody else’s personal information or other private details by deceptive
means. Perhaps the most prevalent type of internet fraud, phishing usually involves fraudulent emails or
websites that aim to trick the potential victim into sharing their sensitive information with the fraudster behind
them. Rather than using the information they acquire themselves, many fraudsters proceed to sell it on the dark
web, mostly to hackers and cybercriminals who specialize in identity theft.
With the advancements in cybersecurity, many cyber threats have come and gone, but phishing is still going
strong. The main reason phishing attacks remain as common as ever is their use of forgery, manipulation, and
social engineering techniques to deceit potential victims. As a rule, phishing emails are written as urgent-
sounding (albeit fake) notifications from internet providers, digital wallets, financial institutions, and other
organizations. In addition, many of them include logos and other official imagery.
Commonly referred to as phishers, the fraudsters responsible for these attacks will ask the potential victim to
provide a vital piece of personal information – be it their Social Security number, credit card details, or login
info. To add a sense of urgency to their message, they will offer an important reason why the victim should do
it. For example, they could lose access to their bank account or they may be locked out of their social media
profile if they fail to provide the requested info within the given timeframe.
To gather the information they need, phishers build fake websites that look just like the real thing. What’s
more, they also have very similar URLs, which make it even harder for victims to spot the fake. According to
recent statistics, more than 1.5 million new phishing sites are created every single month, with an average
lifespan ranging from three to five days per site. That amounts to almost 50,000 new sites every day, so it’s no
surprise that phishing is the main cause of data breaches around the globe.
Phishing Types
There are several types of phishing scams, some of them only possible via phone (i.e. voice phishing or
vishing) or text messages (i.e. SMS phishing or SMiShing). As far as online phishing scams are concerned, the
five most common types include the following:
Commonly known as deceptive phishing, spray and pray is the oldest and most primitive type of online
phishing. Phishers use this technique to send out a bunch of emails labeled “urgent”, where they are asking the
potential victim to update their PayPal password or enter their data in order to claim their lottery win. These
emails usually contain links to fake login pages. When a victim enters their personal data in these fake forms, it
is immediately stored on a remote server that the phisher has access to.
2. Spear Phishing
Spear phishing is much more sophisticated than deceptive phishing for the simple reason that it’s personalized.
Rather than sending a generic message, phishers target specific organizations, groups, or even individuals with
the goal of obtaining their personal information. They gather their names, email addresses, and other personal
info from networking sites like LinkedIn or hacked email records.
This type of phishing primarily targets businesses and organizations, which is why spear phishing emails are
somewhat different from deceptive emails. Although they follow a similar layout, spear phishing emails
usually include false queries or invoices from business partners. Phishers may claim that they have attached an
important document and ask the victim to download it on their computer. When they do, it will install
malicious software that spies on their activity and collects their personal information.
3. CEO Phishing
CEO phishing is a very sophisticated form of this online fraud that can also be very time-consuming for the
phisher behind it. It involves cybercriminals targeting staff in either human resources or finance departments of
an organization and posing as either the CEO of the company or some other high-level executive. They proceed
to exchange multiple messages with their target and gradually build up trust.
After some time, the phisher will suddenly ask their target to send them the employees’ personal information
or, more often, to transfer funds to an account they specify. In most cases, they will say that they need the
funds for a new contract and demand that the transfer is very urgent. As outrageous as it may sound, businesses
around the world have lost more than $5 billion so far as a result of CEO phishing.
Many people use online hosting services like Dropbox and Google Drive to back up their files for easy access
and sharing. Phishers are aware of this, which is why there have been countless attempts to compromise their
victims’ login credentials. The layout of the scam is much like deceptive phishing in that it involves fake login
pages. However, instead of looking for something specific, hackers want to access their victims’ online file
storage to harvest any valuable piece of information they can find there.
5. Cryptocurrency Phishing
Cryptocurrency phishing is a fairly new form of online fraud. To set it in motion, hackers create fake login
pages to cryptocurrency websites. When unsuspecting users enter their credentials using these fake pages, the
hackers instantly gain access to their victims’ digital accounts and can withdraw funds from them in a matter of
seconds. There has only been one major cryptocurrency phishing attack so far, but seeing as digital currency is
on the rise, it is safe to assume that there will be more of these in the future.
Phishing Examples
Some of the most destructive phishing attacks in recent years include the following:
In late 2014, hackers used spear phishing emails to harvest the Apple IDs of numerous Sony Pictures
employees. Assuming that most of the employees used the same password across multiple online
accounts, the hackers then used these credentials to log into their business emails. They succeeded in
their mission and went on to release thousands of personal emails and other confidential documents,
causing a major media storm in Hollywood.
In 2014 and 2015, hackers have targeted Anthem, a US-based health insurance provider. They have
used phishing emails to infect the computers of five employees with keyloggers, a type of spyware that
records their keystrokes. This allowed hackers to steal almost 80 million medical records from
Anthem’s servers, all of which included the patients’ Social Security numbers.
In 2017, a group of hackers sent phishing emails to the employees of three major restaurant chains in
the United States – Chipotle, Arby’s, and Chili’s. Attached to the emails was malicious software that
would quietly install itself on the target computers and give the hackers access to these businesses’
internal networks. Using this software, the hackers managed to steal more than 15 million credit card
records belonging to the customers of these three chains.
Identity Theft
Identity theft is the intentional use of somebody else’s identity for personal gain. If you’re a victim of identity
theft, the perpetrator can use your name, your photographs, your personal documents, and other identifying
information to commit a variety of acts for their own benefit. Depending on the type of information they
obtain, the perpetrators can withdraw funds from your bank account, obtain credit and tax benefits, open utility
accounts in your name, or steal your identity to commit other illegal acts.
While this may be difficult to pull off in the real world, online identity theft is one of the most common forms
of cybercrime today. In recent years, hundreds of businesses around the world have experienced major security
breaches where hackers have stolen their users’ personal data. The average cost of a single data breach for
affected businesses is about $4 million in lost profits and recovery expenses, whereas the global economy is
losing about $500 billion each year due to data breaches and cybercrime.
There are many ways how hackers can obtain your personal information. They can trick you into installing
malicious software on your computer or send you phishing emails that contain links to infected websites and
attachments with compromised installation files. More skilled hackers can use injection scripts to add extra
fields to web forms on reputable websites like online banking portals. Unsuspecting users will enter their
personal data unaware that it’s being sent to the hacker instead of their bank.
Once they obtain your personal information, hackers can use it for their own benefit or sell it to other
cybercriminals for immediate financial gain. According to research, there is a booming market of personal
information on the dark web, where stolen social security numbers are selling for $1, driver’s licenses for $20,
diplomas for up to $400, medical records for $1,000, and passports for $2,000. Identity thieves can buy the
information individually, in bulks according to the type of information, or in bundles.
Based on their goal and the nature of the personal information that was stolen, there are several types of
identity theft. Some of them are mostly relegated to the offline world, while some others are usually carried out
online. The five most common types of online identity theft include the following:
By far the most common type of online identity theft, financial identity theft occurs when cybercriminals steal
your personal data to take control of your existing financial accounts or create new ones in your name. For
example, hackers can utilize spyware or injection scripts to get your credit card number and use it to make
unauthorized payments online. Similarly, they can obtain your online banking login data and withdraw funds
from your account, either at once or gradually so that you don’t notice it as easily.
In addition to all this, identity thieves can also use your personal information to take out loans, credits, and
other financial services they might not otherwise be eligible for. If they default on their loans or fail to make
their credit payments, it will be noted on your financial record, thus hampering your own ability to take out
loans and credits in the future.
Considering that almost 40 million Americans don’t have health insurance, it shouldn’t come as a surprise that
medical identity theft is very prevalent in the United States. This type of identity theft involves the use of other
people’s information (usually their medical identification numbers) to access medical services and products.
For example, if a hacker obtains your health insurance number, they can use it to see a doctor, file claims with
your provider, or obtain prescription drugs – all in your name.
Medical records are fetching high prices on the black market, but the fact that others can use them to obtain
services in your name isn’t the only threat. If your records contain any sensitive information that you’d rather
keep private – from an HIV diagnosis to a plastic surgery – hackers could use it to blackmail you or damage
your reputation.
Several major data breach cases that made the news in recent years involved a theft of millions of Social
Security numbers from large online databases. After all, the Social Security number is perhaps one of the most
important assets of US citizens that many institutions use for identification, as well as for taxation purposes.
This means that the person who steals your Social Security number could use it to claim tax benefits or file a
fraudulent tax refund in your name.
The main problem with Social Security numbers in the United States is that they contain no biometric
information whatsoever. It is thus impossible to confirm that the person using a Social Security number is the
actual person they claim to be without the use of some other document. Hackers and identity thieves are using
this to their advantage and selling stolen Social Security numbers to illegal immigrants looking to find work in
the United States, as well as criminals in need of a false identity.
These types of frauds are usually very difficult to track because there’s no credit record associated with the
stolen Social Security number. However, as soon as the fraudster applies for a credit card, a record is created,
which they can then boost through a series of deceitful practices and techniques. This mainly targets financial
institutions that issue loans based on little-to-no personal information, although the real people who share their
name with the fraudster may sometimes run into trouble with the authorities.
Synthetic identity theft is closely connected to child identity theft, the act in which a person steals a minor’s
identity and uses it for their own financial gain. That’s because children’s Social Security numbers usually
have no information on them, which means that there’s also no credit record associated with them. This allows
fraudsters to use a child’s identity to build credit scores, obtain personal documents, and buy and invest in
properties.
This is one of the most common forms of identity theft in the United States, where more than a million victims
of identity theft each year are children. The main reason why identity thieves opt for it is that it usually takes up
to a decade before the victim even notices that someone else is using their Social Security number. This, in
turn, gives criminals a lot of time to get personal gain before being discovered.
Although no internet user is immune to online identity theft, hackers are primarily targeting major websites,
services, and network. This allows them to collect personal data from thousands if not millions of users in one
fell swoop rather than one user at a time. The majority of this information is obtained through data breaches.
Here are some of the biggest data breaches in recent years that involved the theft of sensitive personal
information:
Between May and July 2017, hackers breached Equifax, one of the three major credit reporting agencies
in the United States. During that time, the personal information of more than 143 million Americans
was compromised, with at least a few hundred thousand identities stolen.
In May 2015, hackers used the vulnerabilities in online software called “Get Transcript” to breach the
Internal Revenue Service (IRS). The IRS developed this software to give taxpayers easy access to their
credit history, but hackers used it to steal more than 700,000 Social Security numbers.
In 2005, in what was the then-largest hacker attack in history, hackers have managed to access the
servers of the credit-card-processing company CardSystems Solutions and steal the details of more than
40 million credit cards that the company was keeping unencrypted on its servers.
For several weeks in December 2014, hackers have breached Anthem, one of the largest health
insurance providers in the United States. During that time, they have managed to steal more than 78
million medical records that also included patients’ names and Social Security numbers.
Exploit Kits
As the name suggests, exploit kits are collections of exploits, pieces of software designed to take advantage of
bugs and security deficiencies on computers. Rather than having to develop these kits from scratch, hackers can
buy them ready-made on the dark web. What’s more, victims don’t have to visit a malicious website for their
computer to become infected. Cybercriminals can hack any legitimate site and embed an invisible HTML tag
that neither the owner nor the victim will notice until it’s too late.
When you visit a compromised website, the kit will search for any software vulnerabilities on your computer.
These may include an outdated version of a browser that contains a specific bug or security software that is
using outdated virus definitions. If it detects any fault, the kit will immediately launch a silent download of
malicious software on your computer. This, in turn, will allow hackers to monitor your online activity, steal
personal information, and gain access to files stored on your computer’s hard drive.
Social Engineering
Social engineering is an umbrella term for a variety of methods and techniques employed by hackers and other
cybercriminals with the goal of deceiving unsuspecting victims into sharing their personal data, opening links
to infected websites, or unknowingly allowing hackers to install malicious software on their computers. These
hackers manipulate their victims into bypassing the usual cybersecurity procedures in order to gain access to
the victims’ computers and/or personal information, usually for financial gain.
The term social engineering originated in social science, where it denotes any effort by the major change actors
(i.e. media, governments, or private groups) to influence or shape their target population’s behavior. In simpler
terms, social engineering involves the use of manipulation in order to achieve a goal, be it good (e.g. promoting
tolerance) or bad (e.g. warmongering). Although it dates all the way back to the late 19th century, the term
social engineering is now more closely associated with cybersecurity.
To successfully carry out their social engineering attacks, many hackers rely on their potential victims’
willingness to be helpful. Similarly, they may try to exploit their victims’ lack of technical knowledge. In most
cases, however, hackers will conduct research on the potential target. For individual targets, this involves a
thorough check of their social media accounts for any personal information that they have shared, including
their birthdays, email addresses, phone numbers, and the places they visit the most.
The process is somewhat different for business targets. Hackers need someone on the inside to gather
intelligence about the enterprise, its operations, employee structure, and the list of its business partners. Most of
them thus choose to target low-level employees who have access to this information. They will either trick the
target into sharing this information voluntarily or infect their computer with malicious software that will
monitor their network activity and send detailed reports directly to the hacker.
Social engineering comes in many shapes and forms. Some attacks can only be carried out offline, like
strangers being polite and counting on your kindness to enter your office building and acquire the information
they need in person. There are also some social engineering attacks that are carried out over the phone. Known
as vishing (voice phishing), they involve a person falsely introducing themselves as a fellow employee or a
trusted authority and directly asking for the information that they’re after.
When it comes to online social engineering, the five most common types include the following:
1. Spear Phishing
Whereas most phishing campaigns involve the mass-sending of emails to as many random addresses as
possible, spear phishing targets specific groups or individuals. Hackers – also known as phishers – will use
social media to gather information about their targets – sometimes referred to as spears – in order to be able to
personalize their phishing emails, thus making them seem more realistic and more likely to work.
In an effort to make their attacks look even more like the real thing, phishers will introduce themselves as a
friend, a business partner, or some outside institution that’s somehow related to the victim. For example, a
phisher may pose as a representative of the victim’s bank and ask them to provide the information they’re
looking for. What’s more, they may also use the official logo and imagery of the bank in question to make it
more difficult for the victim to tell that the message is not genuine.
2. Baiting
Baiting is different from most other types of online social engineering in that it also involves a physical
component. As the name suggests, baiting involves an actual physical bait that the victim must take in order for
the attack to be successful. For example, the hacker can leave a malware-infected USB stick on the victim’s
desk, hoping that they’ll take the bait and plug it into their computer. To increase their chances of success, the
hacker might also label the USB stick “important” or “confidential”.
If the victim takes the bait and plugs the USB stick into their computer, it will immediately install malicious
software on their PC. This, in turn, will give the hacker insight into their online and offline activity, as well as
access to their files and folders. If the infected computer is part of a network, the hacker will also gain instant
access to all other devices that make up this network.
3. Pretexting
Pretexting involves the use of a captivating pretext designed to grab the target’s attention and hooks them in.
Once they are immersed in the story, the hacker behind the attack will try to trick the potential victim into
providing valuable information. This type of social engineering is often seen in the so-called Nigerian email
scams that promise you a lot of money if you provide your bank account info. If you fall for it, not only will
you not see a dime but you may even lose the money that’s already in your account.
4. Contact Spamming
Contact spamming is perhaps the most widespread form of online social engineering. As the name suggests,
hackers use this method to send out spam messages to all of their victims’ contacts. Those emails will be sent
from the victims’ mailing list, which means that they’ll look more realistic to the recipient. More importantly,
they will be much less likely to end up in the spam folder of their inbox.
This method works in a very simple way. If you see an email sent from your friend with an informal subject
line (e.g. “Check this out!”), you may open it to find a textual link. The link is usually shortened, so there’s no
way to see what it is without clicking on it. However, if you click on it, an exact copy of the email will be sent
to all your contacts, thus continuing the spam chain. Additionally, the link may take you to a malicious website
and download spyware or some other malicious software on your computer.
Latin for “a favor for a favor”, quid pro quo is a type of social engineering that involves an exchange of favors
and services between a hacker and their unsuspecting target. Most often, hackers will pose as IT support
technicians and ask you for your login details so that they can run an allegedly important cybersecurity check.
In addition, they may ask you to disable your antivirus software or install a program they send you, thus
allowing them access to your computer and giving them a chance to install malware.
Some of the largest social engineering attacks in recent years include the following:
In 2017, more than a million Google Docs users received the same phishing email which informed them
that one of their contacts was trying to share a document with them. Clicking on the link included in the
email took them to a fake Google Docs login page, where many of the targets entered their Google
login data. This, in turn, gave hackers access to more than a million Google accounts, complete with
emails, contacts, online documents, and smartphone backups.
In 2007, a Michigan treasurer fell for a Nigerian pretexting scam that involved a fictional prince who
wanted to escape from Nigeria but needed help transferring his fortune out of the country. Over a few
months, the treasurer made several payments of $185,000 total ($72,000 of his own money) to the
hackers behind this email scam. It was later revealed that the rest of the funds came from the $1.2
million he had embezzled during his 13 years of public service.
In 2013, hackers managed to steal the credit card info of more than 40 million Target customers.
According to official accounts, the hackers first researched the major retail chain’s air-conditioning
subcontractor and targeted their employees with phishing emails. This allowed the hackers to access
Target’s network and steal the customers’ payment info. Although the perpetrator was never caught,
Target had to pay $18.5 million in 2017 to settle state claims.
Cybercrime Examples
With the number of online criminal activities on the rise, new examples of cybercrime can be found in the tech
news almost daily. Some of the most notorious cybercrimes in recent years have included the following:
The 2013 Yahoo! Data Breach – In 2013, cybercriminals have hacked Yahoo’s mail service and
gained access to the names, addresses, and phone numbers of at least 500 million registered users. It
was later revealed that the hackers had compromised all 3 billion registered accounts, making this the
largest data breach to date.
The 2016 Dyn Cyber Attack – In October 2016, a series of DDoS attacks against a Domain Name
System provider Dyn managed to take down several popular websites and services, including Twitter,
Spotify, Netflix, PayPal, and Amazon.
The 2015 IRS Data Breach – In 2015, the Internal Revenue Service was hacked by cybercriminals,
who managed to steal more than 700,000 Social Security numbers, as well as other related personal
info. The attack was facilitated by exploit kits that took advantage of official IRS software used by
taxpayers to review their tax history.
MALWARE
By definition malware is an abbreviation of the words “malicious software “. It is a general term used to
classify files or software which cause damage to devices and their users. This damage can come in many forms,
often involving stealing data from a user’s computer, encrypting this data, or simply deleting it.
Key takeaway: Malware is software designed to cause harm to you or your devices. It includes many types of
programs, such as spyware, ransomware, trojan horses, rootkits and more. They can spread manually or
automatically. And range from being a mere inconvenience, to being incredibly destructive.
Depending on the intention of its creator, malware can range from being very sophisticated software, capable
of a number of functions to simply being something of a nuisance. There are many types of malware, which
differ based on their features or mode of operation. Some of these include:
Computer Virus
A computer virus is executable malicious software or code that self-replicates by taking control of other
programs on an infected computer. Designed to spread from one host computer to another, a computer virus
latches onto a piece of software or a document and remains there until a user opens the file in question. When
they do, the virus will start executing its code and cause damage to the host computer.
There are many ways how you can contract a computer virus – via file downloads, email attachments,
compromised software installations, or scam links on social media. You can then spread the virus by sharing
infected files or links with others. If your computer is part of a network, just one user opening a compromised
file on their desktop could be enough to take the entire network down.
Although there have been some “good” viruses with helpful effects on host machines, computer viruses are bad
by definition. When executed, they can spam your email and social media contacts, corrupt files on your hard
drive, and slow down your computer. Viruses can steal your passwords and change your login data to lock you
out of your email and social media profiles, online banking accounts, or even your computer. In the worst-case
scenario, they can wipe all the data from your hard drive in just seconds.
There are well over a million viruses in the world, with many more created daily. They are evolving very fast,
so those that were once considered extremely dangerous are now routinely taken care of by the best antivirus
software. Based on their severity and the way in which they can affect your machine, there are about a dozen
types of computer viruses. Here are the five worst types that you should know.
1. Macro Viruses
Perhaps the most common type of computer viruses, macro viruses attach themselves to files made in programs
that support macros, sequences of commands that can be executed with a simple keystroke. These viruses are
most commonly found in Microsoft Word documents and Excel spreadsheets.
Most often distributed via email attachments, macro viruses are activated when you open the infected file. If
you do it directly in your email client, the virus will then send the exact copy of the file to all addresses in your
contacts list. If you download the file to your computer and then open it, the macro virus will spread to
other .docx and .xls files on your computer network and alter their content.
2. File Infectors
Whereas macro viruses usually infect files made in Microsoft Office, file infectors attach themselves to
executable files with .exe and .com extensions. When you open an infected file to launch a program, you will
unknowingly launch the virus, too. The virus can then overtake the program and spread to other executable
files on your hard drive or your computer network.
The main purpose of file infectors is to compromise files and data on users’ machines and networks, create
peer-to-peer botnets, and disable security software on connected computers. Some file infectors will rewrite all
executable files that launch on startup, thus effectively taking control of the computer. There have also been
cases where macro viruses had completely reformatted infected hard drives.
3. Browser Hijackers
As their name suggests, browser hijackers take control over certain features in your web browser. They usually
change your homepage to some fake search engine and overwrite the settings so that you can’t change it. When
you type an address and hit Enter, the virus will take you to a completely different website and ask you to click
on a banner or sign up for something to access the site you want to see.
In most cases, browser hijackers are intended to generate revenue for their developers by showing clickable ads
within the browser. They are most often bundled with free software and browser toolbars that offer advanced
search features. Thankfully, they are easily detected by most antivirus programs.
Web scripting viruses target popular websites, usually in a very sneaky way. These viruses overwrite the code
of the website to insert links and videos that will install malicious software on users’ computers. In many cases,
website owners don’t even know that they’re hosting potentially harmful content. All an experienced hacker
has to do to infect a page is to write the malicious code and post it as a comment.
Some web scripting viruses do little more than serve you textual and visual ads to generate income for their
creators. However, some can steal your cookies and use the information to post on your behalf on the infected
website. Luckily, most antivirus programs will alert you when visiting a malicious website.
Although not as prevalent now as they once were, boot sector viruses can still appear in one form or the other.
Back when computers were booted from floppy disks, these viruses were very common. They would infect the
system partition of the hard drive and launch on computer startup.
Nowadays, these viruses are mostly distributed through surviving forms of physical media – USB and external
hard drives. They no longer pose a major threat, though, as most operating systems have safeguards that protect
the boot sector of the hard drive from malicious software. Even if they do somehow infect your systems, most
antivirus programs can remove boot sector viruses with ease.
Some of the most dangerous and/or most notorious examples of computer viruses include the following:
Melissa was a macro virus that spread via infected email attachments and caused $80 million in damages. Its
founder David L. Smith served a 20-month prison sentence and was forbidden from accessing computer
networks without authorization.
Yankee Doodle was a Bulgarian-made non-destructive file infector that would start playing the song “Yankee
Doodle” on infected computers every day at 5 PM.
Shamoon is a destructive virus that could wipe all data from a network of computers in a matter of seconds.
Developed as a weapon in cyberwarfare against the Saudi energy sector, it was isolated in 2014, only to make a
return (as “Shamoon 2”) two years later.
Klez was a macro virus that would disable antivirus software on the infected computer and spam the victim’s
email inbox to prevent them from receiving new messages.
Computer Worm
A computer worm is a malicious piece of software that replicates itself from one computer to another with the
goal of overtaking the entire network of computers. Most worms are designed to infiltrate systems by
exploiting their security failures, while very few also try to change the system settings. Even if they don’t, they
are still very dangerous as they take up a lot of bandwidth and other valuable resources.
If a worm is indeed malicious and not just used to breach the system security, the code designed to carry out
the attack is referred to as the payload. Payloads are usually created to change or delete files on a target
network, extract personal data from them, or encrypt them and seek a ransom from the victim.
Despite the fact that many people use the two terms interchangeably, computer worms are not the same as
computer viruses. For one, computer viruses by definition target individual computers, whereas worms target
networks of computers to create botnets. Furthermore, while viruses are usually bundled with legitimate files or
programs, computer worms are standalone and don’t require a host file.
Although there are no official statistics available, it is safe to say that there are well over a million computer
worms in the world, each designed for a specific purpose. Many of them have been isolated and are now
routinely detected and removed by most of the best antivirus software. However, new worms are being
developed almost daily and can sometimes go unnoticed by the user until it’s too late.
There is no universal classification of computer worms, but they can be organized into types based on how they
are distributed between computers. The five common types are as follows:
1. Internet Worms
Like they do with computer networks, computer worms also target popular websites with insufficient security.
When they manage to infect the site, internet worms can replicate themselves onto any computer being used to
access the website in question. From there, internet worms are distributed to other connected computers
through the internet and local area network connections.
2. Email Worms
Email worms are most often distributed via compromised email attachments. They usually have double
extensions (for example, .[Link] or .[Link]) so that the recipient would think that they are media files and
not malicious computer programs. When the victims click on the attachment, copies of the same infected file
will automatically be sent to addresses from their contacts list.
An email message doesn’t have to contain a downloadable attachment to distribute a computer worm. Instead,
the body of the message might contain a link that’s shortened so that the recipient can’t tell what it’s about
without clicking on it. When they click on the link, they will be taken to an infected website that will
automatically start downloading malicious software to their computer.
Instant messaging worms are exactly the same as email worms, the only difference being their method of
distribution. Once again, they are masked as attachments or clickable links to websites. They are often
accompanied by short messages like “LOL” or “You have to see this!” to trick the victim into thinking that
their friend is sending them a funny video to look at.
When the user clicks on the link or the attachment – be it in Messenger, WhatsApp, Skype, or any other
popular messaging app – the exact same message will then be sent to their contacts. Unless the worm has
replicated itself onto their computer, users can solve this problem by changing their password.
4. File-Sharing Worms
Although illegal, file-sharing and peer-to-peer file transfers are still used by millions of people around the
world. Doing so, they are unknowingly exposing their computers to the threat of file-sharing worms. Like
email and instant messaging worms, these programs are disguised as media files with dual extensions.
When the victim opens the downloaded file to view it or listen to it, they will download the worm to their
computer. Even if it seems that users have downloaded an actual playable media file, an executable malicious
file could be hidden in the folder and discreetly installed when the media file is first opened.
5. IRC Worms
Internet Relay Chat (IRC) is a messaging app that is mostly outdated nowadays but was all the rage at the turn
of the century. Same as with today’s instant messaging platforms, computer worms were distributed via
messages containing links and attachments. The latter was less effective due to an extra layer of protection that
prompted users to accept incoming files before any transfer could take place.
Jerusalem, the first known computer worm, was discovered in 1987. Since then, other computer worms have
made the news, either because of their devastating effects or due to the sheer scale of the attack. Some of the
most notorious examples of computer worms include the following:
The Morris Worm was launched in 1988 by Robert Morris, an American student who wanted to discover how
big the internet really was. To do this, he launched a few dozen lines of code, but he didn’t know that the code
was riddled with bugs that would cause a variety of problems on affected hosts. The result was thousands of
overloaded computers running on UNIX and a financial damage ranging between $10 million and $100 million.
The Storm Worm is an email worm launched in 2007. Victims would receive emails with a fake news report
about an unprecedented storm wave that had already killed hundreds of people across Europe. More than 1.2
billion of these emails were sent over the course of ten years in order to create a botnet that would target
popular websites. Experts believe that there are still at least a million infected computers whose owners don’t
know that they are part of a botnet.
SQL Slammer was unique in that it didn’t utilize any of the traditional distribution methods. Instead, it
generated a number of random IP addresses and sent itself out to them in hopes that they weren’t protected
by antivirus software. Soon after it hit in 2003, the result was more than 75,000 infected computers
unknowingly involved in DDoS attacks on several major websites.
Ransomware
Ransomware is malicious software that encrypts files on an infected computer, thus preventing the owner from
accessing them. The owner is asked to pay money in return for the decryption key that they can use to unlock
their files, hence the name ransomware. The ransom for private users is usually set at a few hundred dollars,
whereas business owners are typically asked to pay thousands. In most cases, hackers demand that the ransom
is paid in cryptocurrency so that it cannot be traced by the authorities.
Like all other types of malicious software, ransomware is mostly distributed through phishing emails that link
to malicious content or contain compromised attachments. In addition, users can unknowingly download it
when they visit infected websites that install malicious software on their computer without their consent.
Nowadays, ransomware is also distributed via social media and instant messaging apps.
When you install ransomware on your computer, it will encrypt your files in just seconds, so you won’t have
much time to react. As a rule, you should immediately see a splash screen that informs you about the
encryption and provides detailed payment instructions. If your screen isn’t locked, you may still be able to see
your files, but trying to open them will give you an error message. Some types of ransomware also show logos
of the FBI or Interpol to scare the victim into thinking that the police are involved.
Although it has been around since 1989, ransomware is still a fairly new and largely uninvestigated cyber
threat. While all 50 states in the United States have laws on hacking and data breaches, only a few have
regulations that pertain specifically to ransomware. In the states that do have them, ransomware attacks are
classified as either a felony or a misdemeanor and carry fines of up to $25,000 and 25 years in prison.
Ransomware Types
Based on the way they affect your computer’s functionality, most of today’s ransomware programs fall into
one of the following two types:
1. Computer Lockers
Also known as locker ransomware, computer lockers block your access to your computer’s interface, thus
preventing you from using it. If your computer is infected with locker ransomware, a splash screen with its
author’s message and payment instructions will appear on system startup. The author might also try to persuade
you that the ransom is actually a fine issued to you by a law enforcement agency.
This type of ransomware usually only prevents access to your computer’s interface and doesn’t affect the files
or the system. You may thus be able to remove the ransomware and keep all your files intact.
2. Data Lockers
Because they change individual files and don’t just block access to the computer interface, data lockers are
potentially more dangerous than computer lockers. Also known as crypto ransomware, this type of software
scans your computer for valuable files and changes their extension to one your computer won’t be able to
recognize. To unlock your files, you have to pay the ransom and obtain the decryption key.
The hackers behind data lockers are mainly targeting people who don’t back up their important data on a
regular basis. Faced with the possibility of losing all their files, the victims are more likely to pay the ransom,
though a good ransomware decryptor may help them regain access to their files without paying.
In the last few years, some new types of ransomware have popped up. These include:
Scareware – Usually masquerading as antivirus software, scareware uses pop-ups to inform the victim
about the alleged issues that have been found on their computer. Rather than directly extorting money
from them, scareware urges the victims to quickly purchase fake antivirus software that will fix all
these issues promptly. Once installed and paid for, however, the software instead acts like malware and
collects the victims’ personal information.
Leakware – Also known as doxware, this type of ransomware threatens the victim to publish their
personal information if they don’t pay the ransom. In most cases, the hackers behind leakware don’t
target specific files that may contain sensitive information. Instead, they are simply exploiting the fact
that many users store private information on their computers (photos, videos, credit card info, and
personal documents) and are hoping to cause panic.
Ransomware-as-a-Service (RaaS) – While not exactly a wholly different type of ransomware, RaaS is
an emerging business model that’s booming on the dark web. Rather than writing their own code,
aspiring hackers can make a deal with a third-party service that will develop the software for them and
immediately distribute it to potential victims. Under this deal, the RaaS provider gets to keep a portion
of the ransom, while the rest goes to the hacker.
Ransomware Examples
With new strains popping up almost daily and attacks becoming more and more devastating, rarely a week goes
by without at least one ransomware-related item making the tech news headlines. Here are five of the most
devastating ransomware attacks that have made the news in recent years.
1. WannaCry
Exploiting the flaws in the Windows Server Message Block protocol, WannaCry encrypted the files on
Windows computers and asked the victims to pay a ransom between $300 and $600 to obtain the decryption
key. The technology was based on EternalBlue, a hacking tool whose code was revealed as part of the NSA
leaks the year before. Launched in May 2017, this data locker infected more than 250,000 devices across the
globe in just four days, earning its authors almost $150,000 in Bitcoin.
2. CryptoLocker
CryptoLocker took the world by storm in 2013, infecting more than half a million computers via email
attachments and spam message. Although the threat has since been eliminated, there were several variants of
this data locker at the peak of its power. Together, they have helped their authors earn about $3 million in
ransom money, making CryptoLocker one of the most profitable pieces of ransomware.
3. CoinVault
Originally detected in 2014, CoinVault may not have had as strong an impact as some other ransomware
programs. With thousands of infected Windows computers – most of them in Central and Western Europe –
this ransomware strain has earned its authors little over $23,000. However, this is the first major ransomware
attack to make it to court. In July 2018, two Dutch brothers behind CoinVault, one of them a minor when the
ransomware was launched, were sentenced to 240 hours of community service.
4. Bad Rabbit
Bad Rabbit first made the news in late 2017, though it was already distributed via fake Flash updates as early
as June that year. This piece of ransomware mainly targeted computers in Russia and the rest of Eastern
Europe, blocking access to files on infected devices. Still active, Bad Rabbit asks users to pay about $300 in
Bitcoin to receive the decryption code and regain access to their files.
5. NotPetya
First released in 2016, Petya was updated after the leaked NSA documents revealed the existence of the
EternalBlue hacking tool. Renamed NotPetya, this updated version still looked like ransomware, but rather
than decrypting the victim’s files upon payment, it would completely wipe them. NotPetya caused a lot of
damage to networks around the world, but Ukraine’s public transport and banks were hit the hardest, prompting
claims that the program was part of a Russian-orchestrated cyber attack.
Trojan Horse
In cybersecurity terms, a Trojan horse is a piece of malware that can damage, steal, or otherwise harm your
data or your computer network. Often referred to simply as a Trojan, this malicious software is usually
disguised as a legitimate computer program. Once downloaded and installed on your system, it allows hackers
to spy on your online activity, access and copy files from your hard drive, modify and delete your data, hamper
the performance of your computer, and even steal your personal information.
Trojan horses first appeared as non-malicious software back in the mid-1970s and have gone through numerous
stages of development since. In the late eighties, the first-ever type of ransomware was the so-called AIDS
Trojan distributed on floppy discs. During the early 2000s, Trojans have evolved to allow their creators to take
full control of the infected computer using the remote administration technology.
Nowadays, Trojan horses are distributed the same way as most other types of malware. Unsuspecting victims
may download a Trojan under the assumption that they’re downloading a legitimate piece of free software
(e.g., file-sharing software, audio/video codec packs, or free security programs). It may also end up on their
computer if they click on links and download attachments contained in suspicious emails or visit malicious
and/or adult-oriented websites that are riddled with pop-ups and redirecting links.
Many refer to Trojans as viruses, but that’s incorrect. While viruses can self-execute and self-replicate, Trojans
cannot do that. Instead, the user has to execute a Trojan themselves by launching the program or installation
that the Trojan is bundled with. As far as replication goes, Trojans don’t have the ability to reproduce or infect
other files, which makes it much easier to remove them from an infected system.
There are many types of Trojan horses in circulation, some of them more harmful than the others. Thankfully,
most of them are routinely detected and removed by the best antivirus software. According to various statistics,
Trojans account for anywhere between 25 and 80 percent of all malware infections around the world. Some of
the most common types of Trojan horses include the following:
1. Backdoor Trojans
As the name suggests, these types of Trojan horses have a backdoor of sorts, a secret passage through which
hackers can access your computer and take control of it. Depending on how sophisticated they are, backdoor
Trojans can be used to monitor your web traffic and online activity, run and/or terminate tasks and processes,
upload files without your knowledge, and change your computer settings.
In most cases, hackers use backdoor Trojans to build botnets, large networks of remote-controlled computers
that they can recruit to carry out cyber attacks against other computers, networks, websites, and online services.
These botnet backdoor Trojans are usually very sophisticated, which allows them to avoid detection even by
some of the most popular cybersecurity solutions.
2. Downloader Trojans
Downloader Trojans don’t have a backdoor component that would allow hackers direct access to your
computer, but they still perform actions on your computer that could benefit the hacker. Namely, these Trojan
horses are programmed to download a variety of files and programs to your hard drive. These can include
misleading apps, configuration settings, and upgrades to the malware that’s installed on your PC.
Trojan downloaders, as they’re sometimes called, can also download and install other unrelated pieces of
malicious software on your computer. In the past few years, hackers have started selling the so-called “pay-per-
install” services, where they offer aspiring hackers a chance to distribute malicious software via their existing
network in return for money. To do this, a hacker only needs to release an update of their Trojan downloader,
which prompts it to download the malware in question on all infected computers.
Distributed Denial-of-Service (DDoS) Trojans are types of malware designed to carry out attacks against
computer networks. They are usually downloaded and installed on numerous computers at once via spam mail
campaigns, turning those machines into parts of a botnet. These Trojans have a backdoor component, which
allows hackers to activate their botnet army to perform coordinated attacks.
Once activated, these computers will start generating unusual amounts of traffic to websites, servers, or
networks that the hacker is targeting. The ultimate goal is to drain the computational resources of these
websites and networks and take them offline so that users and visitors cannot access them.
4. Banking Trojans
With the growing popularity of online banking services, banking Trojans have become more common than
ever. In the first six months of 2018, these Trojan horses have overtaken ransomware as the most widespread
form of malicious software. As their name suggests, these Trojans are designed to steal the victims’ financial
information and online banking credentials through the use of phishing techniques.
Unlike some other types of malware, banking Trojans allow hackers to use script injections to add extra fields
to online forms. In addition, they can redirect the victim to a fake login page that looks just like the real thing,
complete with the logo of the bank. However, instead of going to their bank and being used solely for login
purposes, the victim’s information is forwarded to the hacker responsible for the Trojan.
Although they have been around for well over a decade, fake antivirus Trojans are still very common and
powerful. They are downloaded the same way as all other Trojans – via compromised email attachments,
suspicious links, and visits to malicious websites. Once installed, they masquerade as antivirus software and
constantly inform the victim about non-existent security threats found on their computer.
These Trojans are somewhat similar to ransomware. No matter how many times the victim closes the window,
the pop-ups with false alerts will keep appearing (often while the victim is doing something else on their
computer) and prompting the victim to pay to download the full version of the software. To do this, they will
have to enter their credit card info, which will be sent to the author of the Trojan.
Some of the best-known examples of Trojan horse attacks in recent years include the following:
In 2011, the computers in the Japanese parliament building were infected with a Trojan horse allegedly
created by the Chinese government. The Trojan was installed after a member of the parliament opened
an infected email, but the extent of the attack was never disclosed.
In 2010, a Trojan horse also known as Zeus or Zbot was used by Eastern European hackers to attack a
number of businesses and municipal officials in the region and take control of their banking accounts.
The creators of this Trojan had stolen a total of $70 million.
In 2007, a backdoor Trojan named the Storm Worm was distributed to millions of computers worldwide
through emails about a fictional storm wave that was killing people across Europe. Though to have
been created by Russian hackers, this Trojan was used to create botnets and orchestrate attacks against
popular websites and cybersecurity companies.
Spyware
Spyware is malicious software that infects computers and other internet-connected devices and secretly records
your browsing habits, the websites you visit, and your online purchases. Some types of spyware also record
your passwords, login credentials, and credit card details. This information is then forwarded to the spyware
author, who can either use it for their own personal gain or sell it to a third party.
Like all other types of malicious software, spyware is installed on your computer without your consent. It is
usually bundled with legitimate software that you have intentionally downloaded (like file-sharing programs
and other freeware or shareware applications), but you can also unwittingly download it by visiting malicious
websites or clicking on links and attachments in infected emails. As soon as you install it, spyware will attach
itself to your operating system and start running quietly in the background.
The term spyware was coined in the mid-1990s, but the software itself had existed long before that. At first,
developers would add a spyware component to their programs to track their usage. They would then approach
potential advertisers with these stats or utilize them to detect any unlicensed use of the software. By the early
noughties, however, more than 90 percent of computer users worldwide had their machines infected with some
form of spyware, unknowingly installed without their permission.
Nowadays, there are many spyware programs in circulation, some even bundled with hardware. Rather than
targeting individual users, the creators of spyware aim to gather as much data as possible and sell it to
advertisers, spammers, scammers, or hackers. With new forms of malicious software being released every few
seconds, no one is safe from spyware. Even the companies you trust use spyware to track your behavior, which
you have allowed them to do when you accepted their End User License Agreement.
Spyware Types
All forms of spyware can be divided into the following five categories:
1. Infostealers
As the name suggests, infostealers are programs that have the ability to scan infected computers and steal a
variety of personal information. This information can include browsing histories, usernames, passwords, email
addresses, personal documents, as well as media files. Depending on the program, infostealers store the data
they collect either on a remote server or locally for later retrieval.
In most cases, infostealers exploit browser-related security deficiencies to collect your private data. They
sometimes also use the so-called injection scripts to add extra fields to web forms. When you type in the
requested information and hit “Submit”, instead of going to the website owner, the information will go directly
to the hacker, who can then potentially use it to impersonate you on the internet.
2. Password Stealers
Password stealers are very similar to infostealers, the only difference being that they are specially designed to
steal login credentials from infected devices. First detected in 2012, these pieces of spyware don’t steal your
passwords as you type them. Instead, they attach themselves to the browser to extract all your saved usernames
and passwords. In addition, they can also record your system login credentials.
Most password stealers are routinely removed by reliable security software, but some types still manage to
avoid detection by changing their file hashes before each attack. As with infostealers, the creators of password
stealers can choose whether they want to store the collected data on a remote server or in a hidden file on your
hard drive.
3. Keyloggers
Sometimes referred to as system monitors, keyloggers are spyware programs that record the keystrokes typed
on a keyboard connected to an infected computer. While hardware-based keyloggers record each keystroke in
real time, software-based keystroke loggers collect periodic screenshots of the currently active windows. This,
in turn, allows them to record passwords (if they are not encrypted on-screen), credit card details, search
histories, email and social media messages, as well as browser histories.
While keyloggers are mostly used by hackers to gather sensitive data from unsuspecting victims, they have also
found a more practical use in recent years. Namely, some business owners utilize them to monitor the activity
of their employees, while concerned parents may install them on their children’s computers to ensure that they
are safe online. Some law enforcement agencies in the United States have also used keyloggers to arrest
notorious criminals and crack down on drug dealers.
4. Banker Trojans
Banker Trojans are programs that are designed to access and record sensitive information that is either stored
on or processed through online banking systems. Often disguised as legitimate software, banker Trojans have
the ability to modify web pages on online banking sites, alter the values of transactions, and even add extra
transactions to benefit the hackers behind them. Like all other types of spyware, banker Trojans are built with a
backdoor, allowing them to send all the data they collect to a remote server.
These programs usually target financial institutions ranging from banks and brokerages to online financial
services and electronic wallet providers. Due to their sophisticated design, banking Trojans are often
undetected even by the state-of-the-art security systems of some financial institutions.
5. Modem Hijackers
With the gradual shift from dial-up to broadband in the last decade, modem hijackers have become a thing of
the past. They are perhaps the oldest type of spyware that would attack its victims while they were browsing
the internet. As a rule, a pop-up ad would appear, prompting the user to click on it. When they did, it would
initiate a silent download of a file that would then take control of their dial-up modem.
Once in charge of the computer, the modem hijacker would disconnect the phone line from its current local
connection and instead connect it to an international one. Most hackers would premium-priced phone numbers
(usually intended for adult chat lines) that were registered in countries with insufficient cybercrime legislation
like China, Russia, and some South American countries. The victims would usually only become aware of the
problem when they saw their $1,000+ phone bill early next month.
Spyware Examples
With the development of cybersecurity technologies over the years, many spyware programs have disappeared,
while some other, more sophisticated forms of spyware have emerged. Some of the best-known examples of
spyware include the following:
CoolWebSearch – This program would take advantage of the security vulnerabilities in Internet
Explorer to hijack the browser, change the settings, and send browsing data to its author.
Gator – Usually bundled with file-sharing software like Kazaa, this program would monitor the
victim’s web surfing habits and use the information to serve them with better-targeted ads.
Internet Optimizer – Particularly popular in the dial-up days, this program promised to help increase
internet speeds. Instead, it would replace all error and login pages with advertisements.
TIBS Dialer – This was a modem hijacker that would disconnect the victim’s computer from a local
phone line and connect them to a toll number designed for accessing pornographic sites.
Zlob – Also known as Zlob Trojan, this program uses vulnerabilities in the ActiveX codec to download
itself to a computer and record search and browsing histories, as well as keystrokes.
Rootkit: This type of malware is created to grant cybercriminals administrator-level clearance on a target’s
computer. This access enables them to modify the user’s computer system. Additionally, it is used to hide the
presence of other malware within this computer system.
Backdoor Virus: This type of malware creates a ‘backdoor’ within a target’s computer. Through this
backdoor, cybercriminals are able to access a computer without the knowledge of the user. Backdoors are
created by other forms of malware, such as worms or Trojan horses. Using a backdoor, cybercriminals also
evade the computer’s security programs. One type of backdoor virus is a Remote Access Trojan (RAT).
The best way to remove malware is by installing one of the top antivirus software (like Norton, BitDefender,
Intego or Panda). These tools scan your system, detect the malware and then delete it. All fully automatic. On
top of that, they prevent future malware from being installed on your device.
Of course, there are a few dedicated anti-malware tools you can download for free, but these are not a full
solution. They are often focused on removing malware that is already installed on your device, rather than
preventing new malware from being installed. They curve the infection, rather than prevent it.
The antivirus software in our comparison not only include anti-malware, but also a range of other features that
keep you safe both online and offline. Examples are firewalls, spam filters, parental controls, hardened
browsers for online payments, password managers, online backup, website advisors and many more.
One of the earliest forms of malware was the Creeper virus. Created by BBN Technologies engineer Robert
Thomas in 1971, it was made as an experiment to infect mainframes of the time with ARPANET. It was not
created with any malicious intent, nor was it programmed to steal or encrypt data. It simply moved between
mainframes and displayed the message, “I’m the creeper: Catch me if you can.”
The initial version did not self-replicate, but this feature was later added by Ray Tomlinson, making ‘The
Creeper’ the very first worm. Malware then began appearing within the tech industry; the 1980s saw the
creation of various worms and viruses that infected personal computers. As there was no internet at this time,
infection was mainly transferred via floppy disks. These viruses were first created for the Apple
II and Macintosh computers; then the IBM PC and MS-DOS when they became more popular. The internet led
to an even wider boom in the creation and spread of malware, which could now be found in websites and
downloadable internet files.
The spread of malware largely depends on the intent of the creator. For many viruses and worms, the spread is
carried out with the intention of reaching as many computers as possible. As such, the infection occurs when
data is shared. This could happen over the internet with downloaded files, email attachments, malicious links or
via drive-by downloads, completed without the user’s knowledge.
It also happens when people share files offline with infected computer systems or when sharing certain media.
More personal infections are sometimes carried out by physically using USB drives that carry the malware.
This is often the case when installing backdoors and rootkits that allow the creators remote or administrator
access to the victim’s computer.
Advancements in cybersecurity are often matched with advancements in malware. These new strains are
programmed with more sophisticated techniques for evading detection from antimalware programs and
computer users alike. These techniques range from simple tactics, such as the use of web proxies (to hide the IP
addresses of the creators) to the more sophisticated file-less malware. In the latter case, the malware avoids
detection by hiding within the system’s RAM. Malware also takes advantage of vulnerabilities in computer
security. They do this by exploiting similarities in operating systems to infect multiple systems. Alternatively,
they exploit defects in security software.
There are other forms of software which sometimes act in similar ways to malware, but are not strictly
considered to be malware. The distinction is based on the fact that while these sometimes cause harm to the
user’s computer, they were not created with any malicious intent.
One such program is adware. The most likely impact of these are the endless and annoying ads they spawn.
This sometimes negatively affects the performance of a computer. However, adware has been known to be
bundled with actual malware. There are also situations where regular software causes unintentional harm to the
user’s computer due to malfunctions. This happens because of errors in their code; this type of software is
labeled as bugs.
The effects of cybercrime can be devastating, which is why you should take steps to protect yourself. First of
all, you need to use the best antivirus software (like Norton, BitDefender, Intego or Panda) to ensure that your
computer is protected from adware, spyware, ransomware, and all other types of malicious software. Keep all
the software on your computer regularly updated to prevent the hackers from gaining access to your personal
information.
If you find a suspicious email in your inbox, don’t open any attachments or click on any links contained in it.
Always use strong passwords that combine letters, numbers, and symbols. Make sure to have a different
password for each service you use. If you need help keeping your passwords organized, you can use a reliable
password manager. You might also consider using a paid virtual private network (VPN) to add an extra layer of
protection when browsing the internet from a public Wi-Fi connection.
Like all software on your computer, you need to keep your antivirus program regularly updated, as well. Using
the best antivirus software will allow you to monitor your computer’s health in real time and schedule regular
scans to ensure that no threat goes undetected. These programs will also automatically check for database
updates, thus keeping your computer protected against the latest threats.
ANTIVIRUS SOFTWARE
As the name suggests, antivirus software is an application or a suite of programs that finds and removes viruses
on computers and networks. In addition to viruses, most of today’s antivirus programs are also capable of
detecting and removing other types of malicious software, including worms, Trojans, adware, spyware,
ransomware, browser hijackers, keyloggers, and rootkits. Besides being able to identify and remove these
threats, the best antivirus software can also prevent them from infecting your system.
When you run a virus scan, your antivirus program will scan your hard drive and all currently connected
external storage devices for potential threats. The program will inspect each individual file and simultaneously
look up the findings in its database of known viruses to detect a possible threat. If it does, depending on the
severity of the threat, it will either delete, quarantine, or repair the infected file. The program will also monitor
the behavior of all the software on your computer and look for any red flags.
Whereas once you had to run antivirus scans manually, most of today’s antivirus programs allow you to enable
automatic scans and set up a scan schedule that best works for you. As a rule, it is recommended to run an
automatic scan once a week. Additionally, you can also run manual scans of your computer, as well as specific
files and directories. Antivirus scans are designed as background processes, which means that they shouldn’t
use up too much of your computational resources or slow down your computer.
Since computer viruses are a constant threat across all platforms, today’s antivirus software is designed to
provide protection on all operating systems and all internet-connected devices. This includes desktop and
laptop computers running Microsoft Windows and macOS, as well as smartphones running iOS and Android.
Statistics show that more than 360,000 new pieces of malware are released daily. For maximum protection,
the best antivirus software will also automatically update virus definitions at least once a day.
All antivirus programs can be organized into the following three categories:
Standalone antivirus software is a specialized tool designed to detect and remove certain viruses. It is
commonly referred to as portable antivirus software because it can also be installed on a USB drive and used
by administrators to run an emergency scan of an infected system. However, most portable programs aren’t
designed to provide real-time protection and download new virus definitions daily, which is why they cannot
substitute internet security suites that include a variety of additional features.
As mentioned above, security software suites are more than just antivirus programs. In addition to being able to
detect and remove viruses, they are also equipped to fight all other types of malicious software and provide
round-the-clock protection for your computer and files. Most of these program packages include anti-spyware,
firewall, and parental controls features. Some also include additional functionality like password managers, a
VPN, and even a standalone antivirus program bundled with the suite.
Cloud-based antivirus software is a fairly new type of antivirus technology that analyzes your files in the cloud
rather than your computer in order to free up your computational resources and allow for a faster response.
These programs typically consist of two parts – the client that is installed on your computer and runs periodic
virus and malware scans without taking up too much memory and the web service that processes the data
gathered by the client and inspects it for matches in its virus and malware database.
With millions of active viruses and malicious programs costing the global economy billions of dollars each
year, it’s no surprise that there are numerous antivirus programs available on the market. They differ in terms
of price, the platform they are designed for, functionality, as well as added features.
Some of the best antivirus programs available right now include the following:
1. Bitdefender
Bitdefender Total Security is a comprehensive security suite that provides optimal protection against viruses
and all types of malicious software. Compatible with the four major operating systems and smart homes, this
user-friendly antivirus software also includes a free VPN with a 200MB daily limit, parental controls, webcam
protection, a password manager, and a tool specifically designed to fight ransomware. This security suite is
very competitively priced and will provide 24/7 protection for up to five devices.
2. Norton
Symantec’s Norton has been around for almost three decades and is without a doubt one of the most
recognizable names in cybersecurity. Its security software suite Norton Security Premium is compatible with
all four major platforms as well as smart homes and comes with a variety of excellent features. Although it
doesn’t include a free VPN service, it offers parental controls and a whopping 25GB of online storage space.
This is great for owners of multiple gadgets, as one license protects up to 10 devices.
3. Panda
Panda is another excellent antivirus program that offers excellent protection from all known cyber threats.
Known for its fast performance, this antivirus software is only compatible with Windows, macOS, and
Android. Despite not supporting iOS, the suite comes with a VPN service with a 150MB daily limit, a
password manager, parental controls, and a standalone USB antivirus program. Designed to provide protection
for up to five devices, Panda Antivirus also includes a full Android malware scanner.
4. McAfee LiveSafe
McAfee LiveSafe is unique in that a single license is valid for an unlimited amount of devices. Compatible
with all four major operating systems, this security suite provides superior malware protection for Windows
and Android-powered machines without affecting their performance. Although the parental control function is
not as advanced as the competition, the inclusion of McAfee’s True Key password manager more than makes
up for it. Equipped with facial recognition functionality, it will keep all your login data extra-safe.
5. BullGuard
Another security software suite designed primarily for Windows and Android, BullGuard offers a high level of
antivirus and anti-malware protection without slowing down your computer. Although there’s no VPN
included in the package, there are plenty of bells and whistles here, including a game booster, cloud backup,
parental control, and safe browsing functionality. However, macOS users can only run antivirus scans, while
the suite is incompatible with iOS. A single license is valid for up to five devices.
The market is flooded with antivirus programs that claim to provide optimal protection for your computer, your
files, and your personal data. With such strong competition, finding the best antivirus software may prove
difficult. When choosing an antivirus program for your personal use, you need to consider its effectiveness
against cyber threats, its performance, the features it includes, the operating systems it is compatible with, as
well as the number of devices it can protect.
While there are plenty of free antivirus programs, they might not be such a great choice, even for a budget-
conscious buyer. For one, they never provide full protection against all threats, which means that you’ll also
have to install at least one additional anti-malware program on your PC. Most of them are also ad-supported,
which is why they’re often classified as adware. What’s more, they may even include a spyware component so
that the authors can track your browsing activity and display better-targeted ads.
Although it’s not free, the best antivirus software is often available at a sizeable discount. These programs are
the only way to ensure that your computer and your files are protected at any given time. They will monitor
your computer 24/7 to detect and remove any existing viruses and malware, as well as to ward off all incoming
threats. In addition to your computer, they will also protect your smartphones, tablets, smart television sets, and
all other internet-connected devices without slowing them down.
FILE EXTENSION
A file extension (also known as a filename extension, file type, or file suffix) is the last part of a file name.
This element is separated from the actual file name by a dot(.) and typically consists of three to four
characters. The file extension can be used to identify the type of file format as well as which applications can
be used to open and edit the file.
For example, a PDF file is a Portable Document Format file which can be opened with programs such as
Adobe Reader. Since file extensions are not standardized, it is possible for one extension to be used for
different file types. Some operating systems hide file extensions so that inexperienced users cannot accidentally
modify them.
Command-driven;
Menu-driven ;
Graphical or GUI.
Menu-driven systems offer the user lists of options which they can select by pressing a particular key
on the keyboard.
The main advantage of menu-driven systems is that they are easy to use.
The main disadvantage of menu-driven systems is getting to one particular option can often involve
working through many different menu screens.
To use a command-driven system to communicate with the computer, the user has to type in special
command words. DOS, which stands for Disk Operating System, is a very commonly used command-
driven user interface.
The main advantage of command driven interfaces is that they can be quick to use as long as the user
knows the correct commands.
The main disadvantage of command-driven interfaces is that they are very difficult to use if the user is a
beginner or doesn’t know the correct commands.
Command-driven systems can be very unfriendly and confusing for non-computer experts to use.
Graphical user interfaces
The most widely used type of graphical user interfaces are WIMP systems.
WIMP stands for Windows Icons Menu Pointer.
Options are represented by small pictures or 'icons' arranged inside rectangular boxes called windows.
The main advantage of graphical user interfaces is that they are very easy to use, especially for a
beginner.
The main disadvantage is the amount of memory space they need. A graphical user interface needs a lot
of RAM to run properly and takes up a large amount of hard disk space.
The ultimate goal of information security is to maintain the CIA triad within an organization. The elements of
the CIA triad are:
Confidentiality: This means ensuring that only the authorized users have access to information. Whenever a
company suffers from a data breach or data leak and individuals’ information is accessed by criminals, the
public or employee’s that don’t have the proper authorization, confidentiality has been compromised. Some of
the key security controls that you can use to maintain confidentiality are:
Encryption: Encrypting information ensures that even if an unauthorized user is able to get access to the
information, without the decryption key the information will be in an unreadable format and therefore
confidentiality will be maintained.
Strong Passwords: By having strong passwords it reduces the chances of someone being able to access
accounts or resources by guessing the password.
Two factor authentication: 2FA supplements traditional login information (username and password) by
requiring an additional code before granting someone access to a resource.
Identity and Access Management (IAM): IAM is the practice of ensuring that only the correct
individuals are given access to resources. It follows something called the “least privilege model”, this
means that users should only be given access to the resources needed to do their job and nothing more.
This helps to enforce the confidentiality of information.
Proper Technical Controls: Technical controls include things like firewalls and security groups. These
controls prevent people from accessing the company’s network and prevents them from obtaining
company information without authorization.
Physical Locks and Doors: Physical security measures like cabinet locks, vaults, biometric scanners and
door locks prevents people from physically sneaking into the company and taking company documents.
Many companies like KFC and coca cola keep their intellectual property and trade secrets in secure
vaults.
Integrity: To protect information from being modified by unauthorized people and ensures that the
information is trustworthy and accurate. Anytime information is modified by someone that isn’t authorized to
do so, whether it was someone inside the company or outside, it is a violation of the information’s integrity. An
example would be if the CFO sends a document to be examined or reviewed by the director of finance. The
director of finance may try to manipulate the information without the CFO knowing in order to make his/her
department look better, launder money etc. You need to have a means of knowing whether or not a document
has been modified without your knowledge so that you can trust that document’s integrity. Also, in the event
data is lost, you need to be able to recover all of that data or at least most of it from a trusted source. Some
controls you can use to maintain integrity are:
Hashes: A hash is the output of a hashing algorithm such as MD5 or SHA. A hash algorithm takes a
message of any size and creates a fixed sized value called a hash (eg 12 characters long). If any
character in the original message is changed, it will result in a different hash being generated. By
creating a hash of a message when you first receive it, you can later test to see if that message has been
altered in any way.
For example, say I have a word document on March 10th 2020, I use a hash algorithm to generate the
hash 123456789. Then on March 15th, I want to check if anyone has modified that file, I can use the
hash algorithm again and if the hash created is not the same, I know someone changed the contents of
that file.
Secure Backups: By creating secure backups if you ever have doubts about the integrity of the data on a
system you can reboot that system using the information you have in your backups. Hashes can be used
with your backups to ensure that they have not been altered in any way. This way you can be confident
that the information you are using to reboot your systems is accurate. A good example of when you will
need this is if your company ever suffers a ransomware attack and is unable to recover your data.
User access controls: By controlling what information users have edit access to, you limit the potential
for users to edit information without permission.
Notice how the hash changes significantly just because of a period at the end.
Availability: To ensure that the information is accessible to authorized people whenever it is needed. An
example of this would be a website like Netflix. For most companies they want availability of at least 99.99%,
which means that 99.99% of the time you go to Netflix you should be able to access the services that you want.
In order to do this there are several practices you can implement to ensure that your company will have a high
uptime:
Off site backups: Having off site backups ensures that if something happens you have a copy of data to
restart your systems and keep your business going.
Disaster Recovery & Business Continuity Planning: These plans outline how your company should
respond to certain types of situations such as earthquakes, floods, fires, hurricanes etc
Redundancy: This is when you make multiple instances of network devices and lines of communication
so that if one device or line fails it doesn’t cause a loss of availability.
Failover: This is a backup node (system) that automatically switches into production in the event that
the primary system fails.
Virtualization: This is the process of creating a software (virtual) version of something that physically
exists. Usually this takes one piece of hardware and enables it to run multiple operating systems in
virtual machines (VMs), this way you can have redundancy even though you only have 1 physical
machine.
Proper Monitoring of the environment: You want to have proper monitoring through tools like a SIEM.
This way you will know as soon as there is a problem in your environment and you can address the
issue asap.
This an example of redundancy from Amazon Web Services resiliency recommendations
In addition to these three principles, there is a fourth principle that is very popular.
Non-Repudiation: This means that users cannot deny that they have performed a particular action and it
enables you to hold people accountable for their actions. It’s important that people can be held accountable for
their actions and that people know they will be held accountable so that it deters negative behaviour. Also, in
the event that someone does something against company policy or the law they can be punished and corrective
action taken. Here are some tools that will allow you to enforce non repudiation:
Account logging and Monitoring: It’s important to log the activities of users on different accounts so
that you know who did what and can trace that back to an individual. Typically, each user should also
have their own account so that no one can deny that they performed an action.
Digital Signatures: Digital signatures function similar to written signatures; they verify an individual's
identity. Usually used to sign messages or contracts.
Read Receipts: When you send an email, text or notification most platforms allow you to request some
type of read receipt. This confirms that the person received the message and records the time.
Digital Signatures Explained
Final Thoughts
The CIA triad along with non repudiation are the 4 main goals of information security. Not only are they
important for the protection of the company interest’s but they also help to protect consumer’s by keeping their
information out of the hands of people that shouldn’t have it. Additionally, there are many privacy laws and
regulations that require companies to take reasonable steps to protect the information of their customers. It’s
important that companies implement multiple security controls for each of the three elements of the triad to
ensure that they are sufficiently protected.