Felicity Mae M.
Sy BSIT 401B
INFORMATION ASSURANCE AND SECURITY
03 LAB 1
a. The article talks about the risks we face whenever we go online and how
cybercriminals use different types of attacks. Some threats may damage an operating
system, while others focus on stealing personal data, money, or login credentials. The
author explains that cyberattacks are divided into two main types: passive and active.
Passive attacks involve quietly monitoring a system or network without altering any
data, which makes them very hard to detect. Active attacks, on the other hand, use
the information gathered from passive attacks to break into systems, modify data, or
block access. The article points out that modern malware and hackers are smarter
than ever, so stronger protections are needed. It emphasizes the importance of
encryption, safe online practices, and awareness to reduce the risk. Finally, it
reminds us that everyone is a potential target, no matter how small or unimportant
we may think we are.
b. Passive attacks are like silent observers. Hackers only watch, collect, and scan for
weaknesses without changing anything in the system. Since nothing is altered, these
attacks are almost invisible and very difficult to detect. Active attacks, on the other
hand, are more aggressive. Hackers modify data, disrupt services, or impersonate
other users to gain higher privileges. Passive attacks mainly affect confidentiality,
while active attacks go further by threatening integrity and availability. The main
difference is visibility: passive attacks usually go unnoticed, while active attacks are
more likely to be noticed because they interfere with the system or communication.
c. To avoid passive and active attacks, organizations and individuals need to strengthen
their cybersecurity practices. First, using strong encryption is important so attackers
cannot read private messages or data. Regular system updates and patches also help
close security gaps. People should be careful not to share sensitive information
publicly, especially on social media. Setting up firewalls, intrusion detection
systems, and monitoring tools can help detect suspicious activities. Strong
passwords and multi-factor authentication make it harder for hackers to gain access.
Just as important, users need to be educated about safe online behavior since human
error is often the weak point. Lastly, having a clear response plan ensures that if an
attack happens, it can be contained and resolved quickly.