0% found this document useful (0 votes)
25 views38 pages

Introduction to Cyber Security Concepts

The document provides an overview of security concepts, including definitions of security, bugs, threats, vulnerabilities, and types of cyber attacks. It discusses the importance of cybersecurity in protecting sensitive information and outlines various cybercrime types, including phishing, ransomware, and insider threats. Additionally, it highlights the motives behind cyber crimes and the classification of cybercrime against individuals, property, organizations, and society.

Uploaded by

Anwesha Jana
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
25 views38 pages

Introduction to Cyber Security Concepts

The document provides an overview of security concepts, including definitions of security, bugs, threats, vulnerabilities, and types of cyber attacks. It discusses the importance of cybersecurity in protecting sensitive information and outlines various cybercrime types, including phishing, ransomware, and insider threats. Additionally, it highlights the motives behind cyber crimes and the classification of cybercrime against individuals, property, organizations, and society.

Uploaded by

Anwesha Jana
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Module 1

Introduction to Security
 Security is “the quality or state of being secure, to be free from danger.
 In other words, protection against adversaries from those who would do harm,
intentionally or otherwise, is the objective.
BUG
 An error or flaw in software that causes it to produce incorrect or unexpected
results.
Fault
 A manifestation of a bug; the actual point in the code or system that fails
Failure
 When a system or component does not perform its intended function.
Asset
 A resource of value such as the data in a database or on the file system, or a
system resource.
Threats
 Threats are malicious activities or events that can negatively impact computer
systems, networks, and data.
 These threats can range from malware and phishing attacks to data breaches
and denial-of-service attacks, aiming to disrupt, damage, or steal information.
 Common threats like malware, viruses, worms, spyware, Ransomware,
Phishing, Data breaches, DOS and DDOS attacks, SQL Injection, Inside threat
etc….
Vulnerability
 A weakness or a gap in security program that can be exploited by threats to
gain unauthorized access to an asset.
Attacks
 Attacks are malicious attempts to disrupt, disable, or gain unauthorized access
to computer systems, networks, or devices. They can involve stealing, altering,
or destroying data, and are often aimed at causing harm, financial loss, or
reputational damage.
Exploit
 A piece of code or technique that takes advantage of a vulnerability.
Risk
 The potential for loss or damage when a threat exploits a vulnerability.
Mitigation
 Steps taken to reduce the risk or impact of security issues.
Patch
 A software update intended to fix bugs or vulnerabilities.
Introduction to Cyber Security
 Cyber security focuses on protecting computers, networks, programs and data
from unintended or unauthorized access, change or destruction.
Need of Cyber Security
 Many different fields collect, process and store a great deal of confidential
information on computers and transmit that data across networks to other
computers.
 With the growing volume of cyber attacks, on-going attention is required to
protect sensitive business and personal information, as well as safeguard
national security.
CIA Triad

Confidentiality Integrity Availability

Private, secret, Consistent, reliable, Available


secure accurate
Types of Threat
 Malware
 Phishing
 Ransomware
 Social Engineering
 Insider Threat
 Denial of Service Attack
Malware
 It is a malicious software used or created by hackers to damage or disrupt
computer operation, gather sensitive information, or gain access to private
computer systems.
 While it is often software, it can also appear in the form of scripts or code.
 It includes worms, Trojan horse, spyware, adware, most rootkits and other
malicious programs
Phishing:
 Phishing uses fraud emails, email attachments, text messages or phone calls to
make people share their personal data including, login credentials, credit card
details, etc.
 While checking E-Mail one day a user finds a message from the bank
threatening him/her to close the bank account if he/she doesn’t reply
immediately.
 Although the message seems to be suspicious from the contents of the
message , it is difficult to conclude that it’s a fake Email.
 This message and other such messages are the example of Phishing, in
addition to stealing personal and financial data and can infect system with
viruses and also a method of Online ID theft in various cases.
 Most people associate Phishing with E-mail messages that spoof or mimic
banks, credit card companies or other ecommerce businesses.
 These messages look authentic and attempt to get users to reveal their
personal information.
 It is believed that Phishing is an alternative spelling of “fishing” , as in “to fish
for information .” The first documented use of “Phishing” was in 1996
Ransomware
 Ransomware is a type of malware which prevents you from accessing your
device and the information stored on it, usually by encrypting (converted into
some secret code) your files. A criminal group will then demand a ransom in
exchange for decryption. The computer itself may become locked, or the data
on it might be encrypted, stolen or deleted.
Social Engineering:
 Social Engineering is the “technique to influence “ and “persuasion to deceive”
people to obtain the information or perform some action.
 Social Engineers exploit the natural tendency of a people to trust social
engineer’s word, rather than exploiting computer security holes.
 It is generally agreed that people are the weak link in security and this
principle makes social engineering possible.
 A social engineer uses telecommunication or internet to get them do
something that is against the security practices or policies of the organization.
 Social Engineering involves gaining information or unauthorized access
privileges by building inappropriate trust relationships with insiders.
Insider Threat
 Insiders are the ones who work within the organization.
 The insider threat is a threat that is caused by the insider who might have the
entire access to the network and holds the authorized access to all the
information of their organization.
DOS Attack:
 In this act, the attacker floods the bandwidth of the victim’s network or fills his
Email box with spam mail depriving him of the services he is entitled to access
or provide.
 Although the means to carry out , motives for , and target of a DoS attack may
vary, it generally consists of the concerted efforts of person or people the
Internet site or service from functioning efficiently or at all, temporarily or
indefinitely.
 The attackers typically targets sites or services hosted on high-profile web
servers such as banks, credit card payment gateways, mobile phone network,
etc.
Cyber Café and Cyber Crime
 Cyber cafés can be used to commit anonymous crimes such as:
1. Sending malicious emails
2. Hacking attempts
3. Fraudulent transactions
 Due to shared systems and lack of user tracking, they pose a security risk.
Introduction to Cyber Crime
 Cybercrime is any illegal behavior , directed by means of electronics
operations, that targets the security of computer systems and the data
processed by them.
 Lack of information security give rise to cybercrimes.
Features of Cyber Crime
1. Anonymous nature
2. Global reach
3. Low cost, high damage
4. Technically advanced
5. Difficult to trace
Cyber Criminals
 1. Hackers: Individuals who break into systems for challenge or profit.
 2. Crackers: Malicious users who break into systems to cause damage.
 3. Script Kiddies: Inexperienced users using existing tools.
 4. Disgruntled Employees: Insiders misusing access.
 5. Cyber Terrorists: Attack systems to instill fear or disrupt.
Cyber Criminals
 Cybercrime involves such activities as child pornography, credit card fraud,
cyberstalking, demoing another online, gaining unauthorized access to the
computer system, ignoring copyright, software licensing and trademark
protection, software piracy and stealing another’s identity to perform criminal
acts.
 Cyber criminals are those who conduct such acts. They can be categorized into
three groups:
 1. Type I
 2. Type II
 3. Type III
Type I: Cybercriminals- hungry for recognition
 Hobby Hackers
Type II: Cybercriminals- not interested in recognition
 Financially motivated hackers
 Organized criminals
Type III: Cybercriminals- The insiders
 Formal employee seeking revenge
Motives Behind Cyber Crimes
1. Financial Gain
2. Political Agenda
3. Revenge
4. Entertainment
5. Cyber Warfare
6. Ideological Beliefs
Information Security
 Information security, often referred to as InfoSec, refers to the processes and
tools designed and deployed to protect sensitive business information from
modification, disruption, destruction, and inspection.
 Information security (InfoSec) protects all forms of information, digital and
physical. Cybersecurity protects all forms of digital information, including
computers, handheld devices, cloud, and networks.
Program Security
 Program security in cybersecurity refers to the measures and practices
designed to protect computer programs and software from malicious attacks,
unauthorized access, and other security threats.
 It encompasses a range of techniques and strategies implemented throughout
the software development lifecycle to ensure that software remains secure
and functions as intended.
 Security implies some degree of trust that the program enforces expected
confidentiality, integrity, and availability.
Malicious and Non-malicious Attacks
 Malicious attacks are intentional actions with the goal of causing harm or
disruption to a computer system or network.
 Examples:
 These include malware infections (viruses, ransomware, spyware), phishing
attacks, denial-of-service attacks, and data breaches executed by hackers.
 Non-malicious attacks are cyber incidents that occur due to unintentional
actions, negligence, or lack of awareness on the part of users or
administrators.
 Examples:
 These include accidental data breaches due to human error, misconfigured
systems, or the spread of malware through phishing emails accidentally
opened by employees.
Classification of Cybercrime
Cybercrimes are classified as follows:
1. Cybercrime against individual
2. Cybercrime against property
3. Cybercrime against organization
4. Cybercrime against society
5. Cyber Crimes Against Government
6. Crime emanating from Usenet newsgroups
Cybercrime against individual
 Electronic Mail Spoofing and other online fraud
 Phishing, Spear Phishing
 Spamming
 Cyberdefamation
 Cyberstalking and harassment
 Computer Sabotage
 Password Sniffing
Email Spoofing
 A spoofed email is the one that appears to originate from one source but
actually has been sent from another source.
 Attackers create fake email addresses that closely resemble legitimate ones,
often mimicking those of banks, companies, or even individuals within an
organization.
 The emails often contain urgent or alarming messages, urging recipients to
click on malicious links, download attachments, or provide personal
information.
 Criminals have used spoofed emails to trick companies into transferring funds
to fraudulent accounts.
Phishing
 Phishing is a form of social engineering and a scam where attackers deceive
people into revealing sensitive information or installing malware such
as viruses, worms, adware, or ransomware.
 Spear Phishing: Spear phishing is a targeted phishing attack that uses
personalized messaging, especially e-mails, to trick a specific individual or
organization into believing they are legitimate. It often utilizes personal
information about the target to increase the chances of success.
Spamming
 People who create electronic spams are spammers.
 Spam is the abuse of electronic messaging systems to send unsolicited bulk
message indiscriminately .
 Although the most widely recognized form of spam is Email spam, term is
applied to similar abuses in other media: instant messaging scam , web search
engine scam, scam in blogs , wiki scam, online classified Ads spam social
networking scam video sharing sites, etc
Cyberdefamation
 Whoever , by words either spoken or intended to be read, or by signs or by
visible representations, makes or publishes any imputation concerning any
person intending to harm , or knowing or having reason to believe that such
imputation will harm , the reputation of such person , is said , expect in the
cases hereinafter expected, to defame that person.
 Cyberdefamation happens when the above takes place in an electronic form.
 In other words,” cyberdefamation occurs when defamation takes place with
the help of computers and/or the internet, for example, someone publishes
defamatory matter about someone on a website or sends an Email containing
defamatory information to all the friends of that person
Cyberstalking
 The dictionary meaning of stalking is an “act or process of following or trying
to approach somebody or something”
 Cyberstalking has been defined as the use of information and communication
technology , particularly the internet , by an individual or group of individual
to harass another individual , group of individuals or organizations.
 The behavior includes false accusation, monitoring, transmission of threats, ID
theft, damage to data, gathering information for harassment purpose, etc.
 It refers to the use of internet and /or electronics communication devices to
stalk another person.
 It involves harassing or threatening behavior that an individual can conduct
repeatedly, for example, following a person, visiting a person’s home or
business places, making phone calls, leaving written messages.
Computer Sabotage
 The use of internet to hinder the normal functioning of a computer system
through the introduction or worms, viruses or logic bombs, is referred as
“Computer Sabotage”.
 It can be used to gain economic advantage over a competitor , to promote the
illegal activities of terrorists or to steal the data or programs for extortion
purpose.
Password Sniffing
 Password sniffers are the programs that monitor and record the name and
password of the network users as they login, jeopardizing security at a site.
 Whoever install sniffer can then impersonate authorized user and login to
access restricted documents
Cybercrime against Property
 Credit card frauds
 Intellectual Property (IP) crimes
 Internet Time Theft
Credit card frauds
 Information security requirements for anyone handling credit cards have been
increased dramatically recently.
 Millions of dollars may be lost annually by consumers who have credit cards
and calling card numbers stolen from online databases.
 Security measures are improving , and traditional methods of law enforcement
seem to be sufficient for prosecuting the thieves of such information.
 Bulletin boards and other online services are frequent targets for hackers who
want to access large databases of credit card information.
Intellectual Property (IP) crimes
 The U.S. Copyright law states that a copyright can be registered for “original
works of authorship fixed in any tangible medium of expression… from which
they can be perceived, reproduced, or otherwise communicated, either
directly or with the aid of a machine or device.”
 Copyright protects artifacts, expression of idea—not the ideas themselves.
 Patents are unlike copyright in that they protect inventions, tangible objects,
or ways to make, not works of mind
 Trade Secret is unlike a patent or copyright in that it must be kept a secret. The
information has a value only as a secret, and an infringer is one who divulges
the secret. Once divulged, the information usually cannot be made secret
again.
 Intellectual property (IP) crime in cybersecurity involves the theft, misuse, or
infringement of intellectual property rights through digital means.
Internet Time Theft
 Such a theft occurs when an unauthorized person uses the internet hours paid
for by another person.
 Basically, time theft occurs comes under hacking because the person who gets
access to someone else’s ISP use ID and password , either by hacking or by
gaining access to it by illegal means , uses it to access the internet without the
other person’s knowledge.
Cybercrime against organization
 Unauthorized accessing to computer
 Password Sniffing
 Denial of service attack
 Virus Attack/dissemination of viruses
 Email Bombing/mail bombs
 Salami attack/salami technique
 Logic Bomb
 Trojan Horse
 Data Diddling
 Industrial Spying
 Computer network intrusions
 Software Piracy
Email Bombing/mail bombs
 Email Bombing refers to sending a large number of Emails to the victim to
crash victim’s Email account or to make victim’s mail servers crash.
 Computer program can be written to instruct a computer to so such task on a
repeated basis.
 In recent years, terrorism has hit the internet in the form of mail bombings.
 By instructing a computer to repeatedly send Email to a specified person’s
Email address, the cybercriminal can overwhelm the recipient’s personal
account and potentially shut down entire system.
Salami attack/salami technique
 These attacks are used for committing financial crimes.
 The idea here is to make the alterations so insignificant that in a single case it
would go completely unnoticed.
 Example: A bank employee inserts a program , into the bank’s servers, that
deducts a small amount of money ( say 2rupees or a few cents in a month )
from the account of every customer.
 No account holder will probably notice this unauthorized debit , but the bank
employee will make a sizable amount every month.
Logic Bomb
 A logic bomb is a piece of code intentionally inserted into a software system
that will set off a malicious function when specified conditions are met.
 It remains dormant until a specific set of predefined conditions or triggers are
met, at which point it executes a destructive action. These actions can range
from deleting files or corrupting data to disrupting entire systems.
 For example, a programmer may hide a piece of code that starts deleting files.
 Software that is inherently malicious, such as viruses and worms, often contain
logic bombs that execute a certain payload at a pre-defined time or when
some other condition is met. This technique can be used by a virus or worm to
gain momentum and spread before being noticed.
Trojan Horse
 Trojan Horse is a program in which malicious or harmful code is contained
inside apparently harmless programming or data in such a way that it can get
control and cause harm, for example, ruining the file allocation table on the
hard disk.
 A Trojan Horse may get widely redistributed as part of a computer virus.
 The term Trojan Horse comes from Greek mythology about the Trojan War.
 Trojan can get into the system in a number of ways, including from a web
browser, via Email or in a bundle with other software downloaded from the
Internet.
 Unlike viruses or worms, Trojans do not replicate themselves but they can be
equally destructive.
 Trojan appears harmless, but once the infected code is executed, Trojans kicks
in and perform malicious functions to harm the computer system without the
user’s knowledge.
 Some typically examples of threats by Trojans are as follows:
1. They erase, overwrite or corrupt data on a computer.
2. They help to spread other malware such as viruses.
3. They deactivate or interface with antiviruses.
4. They allow remote access to your computer
5. They upload and download files without your knowledge.
6. Unlike computer viruses and worms, trojans generally do not attempt to inject
themselves into other files or otherwise propagate themselves
7. They gather E-Mail addresses and use them for Spam.
8. They log keystrokes to steal information such as passwords and credit card
numbers.
9. They copy fake links to false websites, display porno sites, play sounds/videos
and display images.
10. They slow down, restart or shutdown the system.
11. The reinstall themselves after being disabled.
12. They disable the task manager.
13. They disable the control panel.
Data Diddling
 Data Diddling attack involves altering raw data just before it is processed by a
computer and then changing it back after the processing is completed.
 Electricity boards in India have been the victims to data diddling programs
inserted when private parties computerized their systems.
Industrial Spying
 Spying is not limited to governments. Corporations , like governments often
spy on the enemy.
 The internet and privately networked systems provide new and better
opportunities for espionage.
 “Spies” can get information about the product finances, research and
development and marketing strategies, an activity known as Industrial Spying.
Computer network intrusions
 Computer networks pose a problem by way of security threat because people
can get into them from anywhere.
 A network intrusion is an unauthorized attempt to access, steal, damage, or
disrupt a computer network or system. It involves malicious actors gaining
access to a network without permission, potentially compromising its
confidentiality, integrity, or availability. These intrusions can take various
forms, including malware infections, denial-of-service attacks, and data
breaches.
Software Piracy
 “Software Piracy” is defined as a theft of software through the illegal copying
of the genuine programs or the counterfeiting and distribution of products
intended to pass for the original.
 There are many examples of software piracy:
1. End-user copying: friends loaning disks to each other, or organizations under-
reporting the number of software installations they have made or
organizations not tracking their software licenses.
2. Hard disk loading with illicit means- hard disk vendors load pirated software.
1. Counterfeiting- Large Scale duplication and distribution of illegally copied
software
2. Illegal download from the internet- by intrusion, by cracking serial numbers,
etc
 Beware that those who buy pirated software have a lot to lose.
 (A) getting untested software that may have been copied thousands of times
over.
 (B) the software ,if pirated ,may potentially contain hard drive infecting
viruses.
 (C) there is no technical support in the case of software failure, that is ,lack of
technical product support available to the properly licensed users
 (D)there is no warranty protection, etc
Cybercrime against society
 Forgery
 Cyber Terrorism
 Web Jacking
Forgery
 Counterfeit currency notes ,postage and revenue stamps ,marksheets, etc can
be forged using sophisticated computers, scanners and printers.
Cyber Terrorism
Web Jacking
 Web jacking occurs when someone forcefully takes control of a website (by
cracking the password and later changing it ).
 Thus, the first stage of this crime involves “password sniffing.”
 The actual owner of the website does not have any control over what appears
on that website.
Cybercrime against government
 Cyber warfare
 Hacking government websites
 Espionage and surveillance attacks
 Attacks on critical infrastructure
Crimes emanating from Usenet newsgroups
 Usenet is a popular means of sharing and distributing information on the web
with respect to specific topic or subjects.
 Its is a mechanism that allows sharing information in a many-to-many manner.
 In principle, it is possible to prevent the distribution of any newgroups.
 It is merely subject to self regulation and net etiquette.
 It is feasible to block the specific newsgroups; however, this cannot be
considered as a definitive solution to illegal or harmful content. It is possible to
put the usenet to following criminal use:
 1. Distribution/sale of pornographic materials
 2. Distribution/sale of pirated software packages
 3. Distribution of hacking software
 4. Sale of stolen credit card numbers
 5. Sale of stolen data/solen property.
Categories of Cybercrime
 It is categorized based on the following:
1. The target of the crime and
2. Whether the crime occurs as a single event or as a series of event.
Categories
1. Crimes targeted against individual
2. Crime targeted against property
3. Crime targeted against organizations
4. Single event of cybercrime
5. Series of events
Crimes targeted against individual:
 Cybercrimes often exploit human weaknesses such as greed and naivety.
 These crimes include financial fraud, the sale of non-existent or stolen items,
child pornography, copyright infringement, online harassment, and more.
 With the advancement of IT and the widespread use of the Internet, criminals
now have powerful tools to target a broader range of potential victims.
 However, this digital landscape also makes it increasingly difficult to trace and
apprehend the offenders.
Crime targeted against property
 Cybercrime can also involve the theft of mobile and electronic devices such as
cell phones, laptops, PDAs (Personal Digital Assistants), and removable media
like USB drives.
Such thefts can lead to loss of sensitive data and unauthorized access to
personal or professional information.
 Additionally, cybercriminals may transmit malicious software (malware)
designed to: Disrupt the normal functioning of computer systems and erase
data from the hard disk
 Damage or disable connected devices such as modems, CD/DVD drives, and
other peripherals
 These types of attacks can cause major technical and financial damage to
individuals and organizations.
Crime targeted against organizations
 Cyberterrorism is a distinct form of cybercrime that targets organizations or
governments.
 Attackers use computer tools and the Internet to create fear or chaos, often
by:
1. Stealing sensitive or classified information
2. Damaging software, programs, and important files
3. Inserting malicious code to gain control over networks or computer systems
 These actions are typically aimed at disrupting critical infrastructure, spreading
fear among citizens, and weakening national security.
Single event of cybercrime
 From the victim's perspective, a cybercrime may appear as a single event.
 For example, a user might unknowingly open an email attachment that
contains a virus, which then infects their system.
 This type of activity falls under hacking or fraud, depending on the intent and
outcome of the attack.
Series of events
 Cyberstalking involves repeated and targeted interactions by the attacker to
manipulate or harass the victim.
 For example, the attacker may engage with the victim through phone calls or
online chat rooms, building a relationship over time.
 Once trust is established, the attacker may exploit this relationship to commit
harmful acts.
How Criminals Plan the Attacks
 Criminals use many methods and tools to locate the vulnerabilities of their
target .
 The target can be an individual and/or an organization.
 Criminals plan passive and active attacks.
 Active attacks are usually used to alter the system whereas passive attacks
attempt to gain information about the target.
 Active attacks may affect the availability, integrity and authenticity of data
whereas passive attacks lead to breaches of confidentiality.
 In addition to the active and passive categories, attacks can be categorized as
either inside or outside.
 An attack originating and/or attempted within the security perimeter of an
organization is an inside attack; it is usually attempted by an “insider” who
gains access to more resources than expected.
 An outside attack is attempted by a source outside the security perimeter ,
maybe attempted by an insider and/or an outsider, who is indirectly
associated with the organization, it is attempted through the Internet or a
remote access connection.
Phases involved in planning Cybercrime
1. Reconnaissance(information gathering) is the first phase and is treated as
passive attacks
2. Scanning and scrutinizing the gathered information for the validity of the
information as well as to identify the existing vulnerabilities.
3. Launching an attack (gaining and maintaining the system access)
Reconnaissance
 Reconnaissance means "gathering information"—like a spy trying to learn
about an enemy before doing anything.
 In hacking:
It's the first step before an attack. Hackers collect information about a target
computer or network. This step is called footprinting.
 They try to learn things like:
What systems the target is using
What software or services are running
What weaknesses (vulnerabilities) exist
The goal is to find ways to break in later.
 There are two types of reconnaissance:
 Passive – Watching without being noticed (like reading public websites).
 Active – Directly interacting with the system (like sending test messages).
 So, before attacking, hackers do reconnaissance to plan their moves.
Passive Attack
 A passive attack is when information is collected about a person or a company
without them knowing. This can be done just by watching or by using the
Internet to search for details.
Usually, search engines are used to find this information quietly, without
alerting the target.
Some common ways passive attacks are done:
 Search engines like Google or Yahoo are used to find details about employees.
 Social media sites like Orkut or Facebook are checked to gather personal
information.
 Company websites are read to get contact details or email addresses of key
employees. This information can then be used for tricking them (social
engineering).
 Blogs, news articles, or press releases are read to learn about the company or
its people.
 Job advertisements are checked to find out what technologies (like servers or
devices) the company is using.
Active Attacks
 An active attack is when a hacker directly interacts with a network to check
or confirm the information they found earlier during a passive attack.
They try to find details ac :
 IP addresses
 Operating system type and version
 What services are running on the network
 This type of attack is risky because the hacker might be noticed or caught.
That’s why it is sometimes called “Rattling the doorknobs” or “Active
reconnaissance.”
 In simple terms, the hacker is "knocking" to see if the doors are locked
(checking security), but doing so might make someone notice the activity.
 There are special tools used for active attacks. These tools are also helpful in
vulnerability testing or penetration testing to find weak spots in a system.
Scanning and Scrutinizing Gathered Information
 Scanning is an important step to carefully look at the information collected
about a target.
The goal is to learn more details about the system and find weak spots.
 Here are the main types of scanning:
 1. Port scanning
 2. Network scanning
 3. Vulnerability scanning
 Port scanning: Find out which ports (doors to the system) are open or closed,
and what services are running there.
 Network scanning: Learn about IP addresses and how the computers in the
network are connected.
 Vulnerability scanning: Look for problems or weak points in the system that
could be used in an attack.
Attack(Gaining and Maintaining the system Access
 After scanning the system and collecting information, the attacker starts the
attack. The steps usually include:
Break the password to get into the system.
Use special tricks to get more control or permissions.
Run harmful programs or commands to damage or steal data.
Hide the files if needed, to avoid being noticed.
Remove the evidence by deleting logs so no one knows the attack happened.
Social Engineering
 Social engineering is a trick used to fool people into giving away information or
doing something they shouldn’t. Instead of hacking computers, social
engineers take advantage of people’s natural trust.
 Since people are usually the weakest part of security, attackers use this to their
advantage. They often contact people by phone or the internet and convince
them to break the rules without realizing it.
 The goal of social engineering is to get private information or special access by
gaining a person's trust. Social engineers are good at sounding normal and
trustworthy, so people don’t suspect anything. They study how people behave
to better trick them into giving away valuable information.

Classification of Social Engineering


 1. Human Based Social Engineering
 2. Computer Based Social Engineering
Human Based Social Engineering
 Impersonating an employee or valid user: The attacker acts like they work at
the company. For example, they might say they forgot their ID or are lost, so
someone lets them in or helps them. People are usually helpful, and attackers
take advantage of that.
 Posing as an important user: The attacker pretends to be someone important,
like a CEO or manager, and demands quick help. Lower-level workers may feel
scared or pressured and give access without asking questions.
 Using a third person: The attacker says they have permission from someone
else (like a manager), especially if that person is not around to confirm. This
helps them trick others into allowing access.
 Calling technical support: Attackers call help desks and ask for help like a
normal user would. Since tech support is trained to assist people, they can be
easily tricked into giving access or information.
 Shoulder Surfing: It is a technique of gathering information such as usernames
and passwords by watching over a person’s shoulder while he/she logs into
the system , thereby helping an attacker to gain the access to the system.
 Dumpster diving: It involves looking in the trash for information written on
pieces of paper or computer printouts. It is used to describe the practice of
rummaging through commercial or
 Residential trash to find useful free items that have been discarded. It is also
called as dumpstering ,binning, trashing,garbing or garbage gleaning.
Computer Based Social Engineering
 Fake Emails: Phishing
 Email Attachments: These are used to send malicious code to the victim’s
system, which will automatically ( eg keyloggers utility to capture passwords)
get executed. Viruses, trojans can be included cleverly into the attachments to
entice a victim to open the attachment .
 Pop up windows: These are also used in the similar manner as Email
attachments. Pop up windows with special offers or free stuff can encourage a
user to unintentionally install malicious software
Cyberstalking
 Cyberstalking means using the internet or electronic devices to bother or
threaten someone again and again.
 It includes:
1. Spreading lies
2. Watching or tracking someone online
3. Sending threats
4. Stealing someone's identity or damaging their data
5. Collecting personal details to trouble someone
 Examples:
1. Following someone online
2. Visiting their home or office
3. Making repeated phone calls
4. Sending messages
5. Damaging their property
 Because the internet is a big part of our lives, cyberstalkers can easily find and
misuse personal information with just a few clicks.
 There are two main types of stalkers:
Online Stalkers: These people use the internet to directly contact the victim. They
often use email and chat rooms instead of phone calls. The stalker makes sure the
victim knows they are being targeted. Sometimes, a third person is involved to help
harass the victim.
Offline Stalkers: These stalkers use traditional ways like following the victim or
watching their daily activities. They also search the internet (like message boards,
personal websites, or people search sites) to find more information. The victim
usually doesn't know that the internet is being used to help stalk them.
Types of stalkers
1. Rejected stalker
2. Intimacy seeker
3. Incompetent suitor
4. Resentful stalker
5. Predatory stalker
How Stalking Works
 Gathers personal data from social media
 Sends messages, emails, or posts harmful content
 Uses fake profiles or monitoring tools
 Escalates to threats or blackmail

Attacks on Mobile/Cell Phones


 Mobile phones are now a basic need and used by almost everyone.
 Because phones are cheaper and more people are using them, phone theft
has increased a lot.
 In India, theft mostly happens at public places like bus stops, railway stations,
and traffic signals.
 Due to many fake claims, insurance companies have stopped giving mobile
theft insurance.
 When someone loses their phone, the most important things at risk are:
Contact list ,personal information.
Why Mobile Devices Are Targeted by Viruses
 Main reasons why mobile phones get attacked:
 Many Users (Targets):
 A large number of people use mobile phones.
 Example: A mobile virus was found in June 2004 in Palm OS phones.
 A Trojan virus named "Mosquito" secretly sent SMS messages from
infected phones.
 Many Features (Functionality):
 Phones now act like mini-computers with important apps and data.
 This makes them more attractive to hackers who want to steal or damage
information.
 Many Ways to Connect (Connectivity):
 Smartphones can connect via SMS, MMS, Bluetooth, Wi-Fi, etc.
 More ways to connect = more chances for viruses to spread.
How to Protect from Mobile Malware Attacks
• Download only from trusted sources – Apps, games, videos, and ringtones
should come from safe places.
• Turn off Bluetooth when not in use or make it hidden.
• Allow beam (IR) transfers only from trusted sources.
• Install antivirus software on your mobile phone.
Mishing
 Mishing is a combination of mobile phone and Phishing.
 Mishing attacks are attempted using mobile phone technology. M-Commerce
is fast becoming a part of everyday life.
 If you use your mobile phone for purchasing goods/services and for banking,
you could be more vulnerable to a Mishing scam.
 A typical Mishing a uses call termed as Vishing or message (SMS) known as
Smishing.
 Attacker will pretend to be an employee from your bank or another
organization and will claim a need for your personal details. Attackers are very
creative and they would try to convince you with different reasons why they
need this information from you.
Vishing
 Vishing is the criminal practice of using social engineering over the telephone
system, most often using features facilitated by VoIP, to gain access to personal
and financial information from the public for the purpose of financial reward.
 The term is a combination of V – voice and Phishing .
 Vishing is usually used to steal credit card numbers or other related data used
in ID theft schemes from individuals.
 The most profitable uses of the information gained through a Vishing attack
include:
 ID theft;
 purchasing luxury goods and services;
 transferring money/funds;
 monitoring the victims’ bank accounts;
 making applications for loans and credit cards.
 The criminal can initiate a Vishing attack using a variety of methods, each of a
depends upon information gathered by a criminal and criminal’s will to reach a
particular audience.
 Internet E-Mail: It is also called Phishing mail
 Mobile text messaging: Refer to Smishing
 Voicemail: Here, victim is forced to call on the provided phone number, once
he/she listens to voicemail.
 Direct phone call: Following are the steps detailing on how direct phone call
works:
1. The criminal gathers cell/mobile phone numbers located in a particular region
and/or steals cell/mobile phone numbers after accessing legitimate voice messaging
company.
2. The criminal often uses a war dialer to call phone numbers of people from a
specific region, and that to from the gathered list of phone numbers.
3. When the victim answers the call, an automated recorded message is played to
alert the victim that his/her credit card has had fraudulent activity and/or his/her
bank account has had unusual activity. The message instructs the victim to call one
phone number immediately. The same phone number is often displayed in the
spoofed caller ID, under the name of the financial company the criminal is pretending
to represent.
4. When the victim calls on the provided number, he/she is given automated
instructions to enter his/her credit card number or bank account details with the help
of phone keypad.
5. Once the victim enters these details, the criminal (i.e., visher) has the necessary
information to make fraudulent use of the card or to access the account.
 Such calls are often used to harvest additional details such as date of birth,
credit card expiration date, etc.
Example of Vished calls
How to protect from vishing attacks
1. Be suspicious about all unknown callers.
2. Do not trust caller ID, It does not guarantee whether the call is really coming
from that number, that is from individual and/or company- caller ID Spoofing
is easy.
3. Be aware and ask questions, in case someone is asking for your personal or
financial information.
4. Call them back. If someone is asking you for your personal or financial
information, tell them that you will call them back immediately to verify if the
company is legitimate or not. In case someone is calling from a bank and/or
credit card company, call them back using a number displayed on invoice
and/or displayed on website.
5. Repot incidents: Report Vishing calls to t he nearest cyberpolice cell with the
number and name that appeared on the caller ID as well as the time of day
and the information talked about or heard in a recording.
Smishing
 Smishing is a criminal offense conduct by using social engineering techniques
similar to Phishing.
 The name is derived from “SMS Phishing”.
 SMS- Short Message Service- is the text messages communication component
dominantly used into mobile phones.
 Smishing uses call phone text messages to deliver a lure message to get the
victim to reveal his/her personal information.
 The popular technique to capture your information, victim is either provided
with a phone number to force the victim to call or provide a website URL to
force the victim to access the URL, and the victim gets connected to the bogus
websites and submits his/her personal information.
How it works:
 Victim receives a fake SMS
 Message contains malicious links or urgent requests
 Victim is lured into revealing personal information
Examples of Smishing

How to protect from Smishing Attacks


 Following are some of the tips to protect oneself from Smishing attacks:
1. Do not answer a text message that you have received asking for your personal
information. Even if the message seems to be received from your best friend,
do not respond, because he/she may not be the one who has actually sent it.
2. Avoid calling any phone numbers, as mentioned in the received message, to
cancel a membership and/or confirming a transaction which you have not
initiated but mentioned in the message. Always call on numbers displayed on
the invoice and /or appearing in the bank statements/passbooks.
Mobile Devices: Security Implications for organizations
 1. Managing Diversity and Proliferation of Hand-Held Devices
 2. Unconventional / Stealth Storage devices.
 3. Threats through Lost and Stolen Devices.
 4. Educating the laptop users
1. Managing Diversity and Proliferation of Hand-Held Devices
 Security at the organizational level is essential due to risks from mobile device
usage.
 Companies must set up security rules that match their goals and legal
requirements.
 Leadership support is critical – CEOs and directors must take cybersecurity
seriously.
 Security tools are useless without enforcement and proper policies.
 Senior executives may have risky access to networks, bypassing normal
procedures.
 Tracking mobile devices is often ignored, but it’s important for long-term
security.
 All employee devices should be registered, even if personally owned.
 Device usage should be monitored regularly to prevent misuse.
 When employees leave, their access must be removed (both digital &
physical).
 Company-owned devices must be returned, deactivated, and wiped clean.
2. Unconventional / Stealth Storage devices.
 Let’s focus on other small storage devices like:
1. CDs
2. USB drives (zip drives, memory sticks)
 As technology improves, these devices are becoming: Smaller in size, Available
in different shapes (like pens, watches, etc.)
 This makes them hard to detect and a big security risk for companies. So, it’s
better for companies to not allow employees to use these devices, because:
1. They can easily be hidden in bags or on the body
2. They can be used to secretly carry or steal important data
USB Port Threats from open USB ports.
 Viruses, worms, and Trojans can enter through USBs and harm the
organization.
 Companies need rules to block USB ports when giving devices to employees.
 But Windows systems often don’t let admins block USB ports easily.
 So, careless employees can:
 Plug in USBs, cameras, or MP3 players.
 Steal important data or put viruses into systems.
 And because this happens inside the company, firewalls and antivirus
won’t notice it.
How DeviceLock Software Helps
 This software gives control to IT admins to stop unauthorized USB use. It can:
1. Monitor who is using USB, Wi-Fi, Bluetooth, or CD drives.
2. Control access based on time and day.
3. Create a whitelist of approved USB devices (only those can be used).
4. Set USBs to read-only mode.
5. Stop disks from being accidentally or intentionally formatted.
[Link] through Lost and Stolen Devices
 Losing mobile devices (like phones, laptops, tablets) is becoming a big
cybersecurity problem.
 People often lose these devices while traveling, and this creates a risk for
companies.
 A survey in London showed that in just 6 months of 2001: 2,900 laptops, 1,300
PDAs, Over 62,000 mobile phones were left behind in cabs.
 Today, the number is likely much higher because more people now use mobile
devices.
 The real risk is not the device, but the data inside it.
 If lost or stolen, it can:
 Put the company into serious risk of sabotage and exploitation or damage to
its professional integrity
[Link] Data on Lost Devices
 When important data is stored on mobile devices, it's at risk if the device is
lost or stolen.
 Employees need to be careful because:
 1. Data is often stored permanently on the device.
 2. Apps may keep running in the background.
Protecting a data:
 Encrypt sensitive data – so others can't read it.
 Encrypt the full device – this helps protect files like spreadsheets even if
they’re outside a database.
 Data on hard disks or USB drives should also be protected.
 Many tools are available to help protect this data. Examples include:
 Encrypting server locations.
 Setting up a self-destruct option that deletes data if the device is lost
 Using apps that deletes data
 Organizations should have
 1. Have a clear policy on what to do if a device is lost or stolen.
 2. Employees should know how to report the loss quickly.
[Link] the Laptop Users
 Often it happens that the corporate laptop users could be putting their
company’s network at risk by downloading the non work related softwares
capable of spreading viruses .
Implementing Mobile device Security Policies
1. Determine whether the employees in the organization need to use mobile
computing devices at all, based on their risks and benefits within the
organization, industry and regulatory environment.
2. Implement additional security technologies, as appropriate to fit both the
organization and the types of devices used. Most (and perhaps all) mobile
computing devices will need to have their native security augmented with
such tools as strong encryption, device passwords and physical locks.
Biometrics techniques (retinal scans, iris scans, etc.) can be used for
authentication and encryption and have great potential to eliminate the
challenges associated with passwords.
3. 3. Standardize the mobile computing devices and the associated security tools
being used with them. As a matter of fundamental principle, security
deteriorates quickly as the tools and devices used become increasingly
disparate.
4. 4. Develop a specific framework for using mobile computing devices, including
guidelines for data-syncing, the use of firewalls and anti-malware software and
the types of information that can be stored on them.
5. 5. Centralize management of your mobile computing devices. Maintain an
inventory so that you know who is using what kinds of devices.
6. 6. Establish patching procedures for software on mobile devices. This can often
be simplified by integrating patching with syncing or patch management with
the centralized inventory database.
7. 7. Label the devices and register them with a suitable service that helps return
recovered devices to the owners.
8. 8. Establish procedures to disable remote access for any mobile devices
reported as lost or stolen. Many devices allow the users to store usernames
and passwords for website portals, which could allow a thief to access even
more information than on the device itself.
9. 9. Remove data from computing devices that are not in use or before re-
assigning those devices to new owners (in case of company-provided mobile
devices to employees). This is to preclude incidents through which people
obtain "old" computing devices that still had confidential company data.
10. 10. Provide education and awareness training to personnel using mobile
devices. People cannot be expected to appropriately secure their information
if they have not been told how.
BOTNET
 The dictionary meaning of Bot is "(computing) an automated program for
doing some particular task, often over a network.“
 Botnet is a term used for collection of software robots, or Bots, that run
autonomously and automatically. The term is often associated with malicious
software but can also refer to the network of computers using distributed
computing software.
 In simple terms, a Bot is simply an automated computer program. One can
gain the control of your computer by infecting them with a virus or other
Malicious Code that gives the access. Your computer system maybe a part of a
Botnet even though it appears to be operating normally. Botnets are often
used to conduct a range of activities, from distributing Spam and viruses to
conducting denial-of-service (DoS) attacks.
 A Botnet (also known as a zombie network) is a group of computers that have
been infected with harmful software. This software lets cybercriminals control
these computers without the owners knowing.
 These "zombie networks" help cybercriminals make money. They are cheap to
run and don’t need much technical skill to manage, which is why they are
becoming more common.
Protection against BOTS
 One can reduce the chances of becoming part of a Bot by limiting access into
the system. Leaving your Internet connection ON and unprotected is just like
leaving the front door of the house wide open. One can ensure following to
secure the system:
1. Use antivirus and anti-Spyware software and keep it up-to-date
2. Set the OS to download and install security patches automatically
3. Use a firewall to protect the system from hacking attacks while it is connected
on the Internet
4. Disconnect from the Internet when you are away from your computer
5. 5. Downloading the freeware only from websites that are known and
trustworthy
6. 6. Check regularly the folders in the mail box – “sent items” or “outgoing” – for
those messages you did not send
7. 7. Take an immediate action if your system is infected
Attack Vectors
 An “attack vector” is a path or means by which an attacker can gain access to a
computer or to a network server to deliver a payload or malicious outcome.
 Attack vectors enable attackers to exploit system vulnerabilities, including the
human element.
 Attack vectors include viruses, E-Mail attachments, webpages, pop-up
windows, instant messages, chat rooms, and deception.
 All of these methods involve programming (or, in a few cases, hardware),
except deception, in which a human operator is fooled into removing or
weakening system defenses.
 To some extent, firewalls and antivirus software can block attack vectors.
 However, no protection method is totally attack-proof.
 A defense method that is effective today may not remain so for long because
attackers are constantly updating attack vectors, and seeking new ones, in
their quest to gain unauthorized access to computers and servers.
 The attack vectors described here are how most of them are launched:
1. Attack by E-Mail: Harmful links or files are sent in emails. Sometimes attacks
combine the two vectors, so that if the message does not get you, the
attachment will. Spam is almost always carrier for scams, fraud, dirty tricks, or
malicious action of some kind. Any link that offers something “free” or
tempting is a suspect.
2. Attachments (and other files):Files like documents or images may contain
viruses, spyware, or other harmful software (malware). Once opened, they try
to install their payload (the harmful part).
3. 3. Attack by deception: Attackers trick users into making mistakes. This
includes scams, fake messages, or misleading websites. These often need the
user to click or do something for the attack to work. Social engineering and
hoaxes are other forms of deception that are often an attack vector too.
4. 4. Hackers: Unlike viruses, hackers are real people who can think, adapt, and
change their methods. They use tools and tricks to break into systems, often
using Trojan Horses to take control of a computer.
5. 5. Heedless guests (attack by webpage): Some websites are fake copies of real
ones. They trick you into giving personal info like your name, credit card
number, and more. These sites often come from spam emails. They may also
open pop-ups that install spyware or other harmful software.
6. 6. Attack of the worms: Worms are programs that spread from one computer
to another, often through email or the internet. Some worms install other
malware like Trojan Horses. Once inside your system, they look for more
computers to infect. If successful, hackers can control many infected
computers (called “zombies”) to cause trouble.
7. 7. Malicious macros: Macros are small programs inside tools like Microsoft
Word or Excel that automate tasks. But hackers can use them to spread
malware. Internet services rely on cozy connections between the computer
and the other computers on the Internet. If one is using P2P software then
his/her system is more vulnerable to hostile exploits.
8. 8. Foistware (sneakware): Foistware is the software that adds hidden
components to the system on the sly. Spyware is the most common form of
foistware. Sneak software often hijacks your browser and diverts you to some
"revenue opportunity" that the foistware has set up.
9. 9. Viruses: Viruses are harmful codes that spread by attaching themselves to
files, emails, or other software. These are malicious computer codes that hitch
a ride and make the payload.
Cloud Computing
 Cloud computing is the on-demand availability of computing resources like
storage and infrastructure, as services over the internet.
 It eliminates the need for individuals and businesses to self-manage physical
resources themselves, and only pay for what they use.
 A cloud service has three distinct characteristics which differentiate from
traditional hosting:
1. It is sold on demand- typically by the minute or the hour.
2. It is elastic in terms of usage- a user can have as much or as little of a service
as he/she wants at any given time.
3. The service is fully managed by the provider- a user just needs PC and Internet
connection.
4. One of the many advantages of cloud computing is that you only pay for what
you use.
5. This allows organizations to scale faster and more efficiently without the
burden of having to buy and maintain their own physical data centers and
servers.
Why Cloud Computing
1. Applications and data can be access from anywhere at any time.
2. Data may not be held on a hard drive on one user’s computer.
3. It could bring hardware costs down. One would need the Internet connection.
4. Organization do not have to buy a set of software or software licenses for
every employee and the organizations could pay a metered fee to a cloud
computing company.
5. Organization do not have to rent a physical space to store servers and
databases. Servers and digital storage devices take up space. Cloud computing
gives the option of storing data on someone else’s hardware, thereby
removing the need for physical space on the front end.
6. 6. Organization would be able to save money on IT support because
organizations will have to ensure about the desktop and continuous Internet
connectivity instead of servers and other hardware.
Types of Services
 Infrastructure as a service (IaaS)
 Platform as a service (PaaS)
 Software as a service (SaaS)
Infrastructure as a service (IaaS):
 It is like Amazon Web Services that provide virtual servers with unique IP
address and blocks of storage on demand.
 Customer benefits from an Application Programmable Interface(API) from
which they can control their servers.
 As customers can pay for exactly the amount of service they use, like
electricity or water, this service is also called as utility computing.
Platform as a service (PaaS):
 It is a set of software and development tools hosted on the provider’s servers.
 Developers can create applications using the provider’s API.
 Google Apps is the one of the most famous PaaS providers.
 Platform as a service (PaaS) offers all the hardware and software resources
needed for cloud application development. With PaaS, companies can focus
fully on application development without the burden of managing and
maintaining the underlying infrastructure.
Software as a service (SaaS)
 It is the broadest market.
 In this case, the provider allows the customer only to use its applications.
 The software interacts with the user through a user interface.
 These applications can be anything Web Based Email to applications such as
Twitter ,etc.
Cybercrime and Cloud Computing
Area: Elevated user access:
Risk: Any data processed outside the organization brings a level of risk as the
outsourced services may bypass the physical, logical and personnel controls and will
have elevated user access to such data.
How to remediate the risk: Customer should obtain as much information as he/she
can about the service provider, who will be managing the data and scrutinizing
vendor’s monitoring mechanism about hiring and oversight of privileged
administrators, and IT controls over the access privileges.
Area: Location of the data
Risk: The organizations that are obtaining cloud computing services may not be
aware about where the data is hosted and may not even know in which country it is
hosted.
How to remediate the risk: Organizations should ensure that the service provider is
committed to obey local privacy requirements on behalf of the organization to store
and process the data in the specific jurisdiction
Area: Segregation of the data
Risk: As the data will be stored under stored environment , encryption mechanism
should be strong enough to segregate the data from the other organizations, whose
data is also stored under the same server.
How to remediate the risk: Organizations should be aware of the arrangements
made by the service providers about segregation of the data .
In case of encryption mechanism , the service provider should display encryption
schemes and testing of the mechanism by the experts.
Area: Long term viability
Risk: In case of any major change in the cloud computing service provider , the
service provided is at the stake.
How to remediate the risk: Organizations should ensure getting their data in case of
major events.
Area: Recovery of the data
Risk: Business continuity in case of any disaster –availability of the services and data
without any disruption. Application environment and IT infrastructure across multiple
sites are vulnerable to total failure.
How to remediate the risk: Organizations should ensure the enforcement of
contractual liability over the service provider about the complete restoration of the
data with the stipulated timeframe.
Organization should be aware of the BCP/DRP established by the service provider.

Common questions

Powered by AI

Phishing and social engineering are both tactics used to manipulate human behavior for malicious purposes. Phishing involves fraudulent communications, often through email, that mimic legitimate sources to trick individuals into sharing personal information . Social engineering exploits people's natural tendency to trust, often through direct manipulation and persuasion to obtain confidential information or access . Both tactics rely on deceiving individuals by creating a false sense of legitimacy or urgency, thereby compromising security by leveraging human vulnerabilities rather than technical weaknesses .

DoS (Denial of Service) attacks and ransomware attacks impact organizations in distinct ways. DoS attacks focus on overloading an organization's network or resources, making services unavailable to legitimate users, which can result in loss of service and potential revenue . Ransomware attacks, by contrast, encrypt data or lock access until a ransom is paid, directly targeting an organization’s data integrity and access, often leading to significant downtime and financial costs associated with data recovery or ransom payments . While both impact operations, ransomware usually directly targets data, whereas DoS targets availability of services .

Cybercafés can contribute to cybercrime due to shared systems, lack of user tracking, and anonymity that these venues offer, allowing for activities such as sending malicious emails, hacking attempts, and fraudulent transactions . To mitigate these risks, cybercafés should implement user registration systems, monitor browsing activities, and restrict access to potentially harmful software downloads . Moreover, deploying firewalls and antivirus programs, coupled with awareness training for operators and users, can further reduce vulnerabilities associated with public computer networks .

Organizations can protect against threats from lost or stolen devices by implementing several measures. These include encrypting sensitive data on devices to prevent unauthorized access, setting up a self-destruct mechanism that deletes data if the device is reported lost or stolen, and establishing clear policies on reporting lost or stolen devices quickly . Furthermore, educating employees on the importance of securing devices and using apps designed to protect data can also mitigate risks .

The CIA triad in cybersecurity stands for Confidentiality, Integrity, and Availability. Confidentiality ensures that sensitive information is accessed only by authorized individuals, maintaining privacy and secrecy . Integrity involves safeguarding the accuracy and completeness of information, ensuring that data is reliable and trustworthy . Availability ensures that information and resources are accessible to authorized users when needed, supporting consistent and reliable access . Each component is essential for maintaining security, as they collectively provide a comprehensive framework for protecting information from diverse threats .

Elevated user access in cloud computing environments presents risks such as bypassing traditional security controls and unauthorized access to sensitive data . These risks can be mitigated by thoroughly vetting service providers, scrutinizing their monitoring mechanisms, and understanding who manages and accesses the data . Implementing stringent IT controls over access privileges and maintaining oversight of privileged administrators can further reduce these risks . Client organizations should obtain detailed information about the provider's identity management systems as part of their risk remediation strategy .

Insider threats can be particularly damaging to an organization because insiders, such as employees, already have trusted access to the organization’s systems and data, which they can exploit to carry out malicious activities or cause accidental harm . Unlike external threats, insiders do not need to breach perimeter defenses, allowing them to bypass many security measures unnoticed. This access can lead to more significant breaches, data theft, and operational disruption, particularly if an insider intentionally misuses their access for espionage or sabotage . Organizations must therefore establish robust internal controls, monitoring, and employee awareness programs to effectively mitigate these threats .

Reconnaissance in cybercrime planning is the process of gathering information about a target computer or network, constituting the first phase of an attack . This step, often performed passively, involves collecting data necessary for identifying vulnerabilities . Reconnaissance is vital as it allows attackers to understand the target's landscape, plan their approach, and maximize the efficacy of subsequent attack phases . By mapping out the target's systems and potential defenses, attackers can tailor their strategies to exploit specific weaknesses with precision .

The potential risks associated with data location in cloud computing stem from the fact that organizations might not be aware of where their data is hosted, which could include different legal jurisdictions that have varying privacy laws . To mitigate these risks, organizations should ensure that the service provider complies with local privacy requirements for storing and processing data. This includes obtaining assurances from the service provider regarding adherence to jurisdictional privacy laws, and selecting providers with transparent data hosting policies .

Vulnerabilities in a cybersecurity system refer to weaknesses or gaps that can be exploited by threats to gain unauthorized access to an asset . Exploits, on the other hand, are pieces of code or techniques that take advantage of these vulnerabilities to carry out an attack . In the risk management process, vulnerabilities represent potential entry points for threats, and exploits are the methods used to breach these points. Effective risk management involves identifying, assessing, and mitigating vulnerabilities to reduce the potential for exploits which could cause harm to the system .

You might also like