Proliferation of Mobile and Wireless Devices Security Challenges • Phishing and Smishing: Phishing attacks, including smishing (phishing
Posed by Mobile Devices: via SMS), use deceptive messages to trick users into revealing sensitive
Proliferation of mobile and wireless devices is like the widespread growth information or downloading malware.
or spread of smartphones, tablets, and other wirelessly connected gadgets. It • Outdated Operating Systems: Not updating device operating systems
reflects the increasing number of these devices in our daily lives. can leave them vulnerable to known exploits.
• Poor Password Habits: Weak or reused passwords significantly increase
the risk of unauthorized access to devices and accounts.
Mitigation Strategies:
• Strong Authentication: Using strong passwords, multi-factor
authentication, and biometric methods can significantly enhance device
security.
• App Security: Downloading apps only from official app stores and
reviewing app permissions can reduce the risk of malicious apps.
• Secure Networks: Using a VPN or avoiding public Wi-Fi when
Specific Security Challenges: transmitting sensitive data can help protect against network attacks.
• Unsecured Public Wi-Fi: Public Wi-Fi networks are often easy targets • Mobile Device Management (MDM): MDM solutions can help
for hackers who can intercept data transmitted over these networks. organizations enforce security policies and manage devices, including
• Malicious Applications: Apps from untrusted sources can contain remote wiping capabilities.
malware or steal personal information. • User Education: Educating users about phishing, smishing, and other
• Stolen or Lost Devices: Mobile devices are easily lost or stolen, mobile threats is crucial for preventing attacks.
potentially exposing sensitive data if not secured with strong passwords • Antivirus and Security Software: Installing and regularly updating
or remote wipe features. antivirus and other security software can help detect and remove malware.
• Data Leakage: Unauthorized access to personal or corporate data can Attacks on Mobile/Cell Phores:
occur through various means, including weak passwords, unsecured Wireless and mobile devices have become ubiquitous in today's society, and
networks, or malicious applications. with this increased usage comes the potential for security threats. Wireless and
• Network Spoofing: Attackers can create fake Wi-Fi networks that mimic mobile device attacks are a growing concern for individuals, businesses, and
legitimate ones, tricking users into connecting and exposing their data. government.
11 | P a g e 12 | P a g e
The most common types of wireless and mobile device attacks: Bluejacking: Bluejacking is used for sending unauthorized messages to another
Bluetooth device. Bluetooth is a high-speed but very short-range wireless
SMiShing: Smishing become common now as smartphones are widely used. technology for exchanging data between desktop and mobile computers and other
SMiShing uses Short Message Service (SMS) to send fraud text messages or devices.
links. The criminals cheat the user by calling. Victims may provide sensitive Replay attacks: In a Replay attack an attacker spies on information being sent
information such as credit card information, account information, etc. Accessing between a sender and a receiver. Once the attacker has spied on the information,
a website might result in the user unknowingly downloading malware that infects he or she can intercept it and retransmit it again thus leading to some delay in data
the device. transmission. It is also known as playback attack.
War driving: War driving is a way used by attackers to find access points Bluesnarfing: It occurs when the attacker copies the victim's information from
wherever they can be. With the availability of free Wi-Fi connection, they can his device. An attacker can access information such as the user's calendar, contact
drive around and obtain a very huge amount of information over a very short list, e-mail and text messages without leaving any evidence of the attack.
period of time.
RF Jamming: Wireless signals are susceptible to electromagnetic interference
WEP attack: Wired Equivalent Privacy (WEP) is a security protocol that and radio-frequency interference. Radio frequency (RF) jamming distorts the
attempted to provide a wireless local area network with the same level of security transmission of a satellite station so that the signal does not reach the receiving
as a wired LAN. Since physical security steps help to protect a wired LAN, WEP station.
attempts to provide similar protection for data transmitted over WLAN with There are several types of attacks that target these devices, each with its own
encryption. WEP uses a key for encryption. There is no provision for key advantages and disadvantages:
management with Wired Equivalent Privacy, so the number of people sharing the
Wi-Fi Spoofing: Wi-Fi spoofing involves setting up a fake wireless access point
key will continually grow. Since everyone is using the same key, the criminal has
to trick users into connecting to it instead of the legitimate network. This attack
access to a large amount of traffic for analytic attacks.
can be used to steal sensitive information such as usernames, passwords, and
WPA attack: Wi-Fi Protected Access (WPA) and then WPA2 came out as credit card numbers. One advantage of this attack is that it is relatively easy to
improved protocols to replace WEP. WPA2 does not have the same encryption carry out, and the attacker does not need sophisticated tools or skills. However, it
problems because an attacker cannot recover the key by noticing traffic. WPA2 is can be easily detected if users are aware of the legitimate network's name and
susceptible to attack because cyber criminals can analyze the packets going other details.
between the access point and an authorized user.
Packet Sniffing: Packet sniffing involves intercepting and analyzing the data
packets that are transmitted over a wireless network. This attack can be used to
capture sensitive information such as email messages, instant messages, and web
13 | P a g e 14 | P a g e
traffic. One advantage of this attack is that it can be carried out without the user's into several categories, depending on the method used, the target and the intent
knowledge. However, the attacker needs to be in close proximity to the victim of the attacker.
and must have the technical skills and tools to intercept and analyze the data.
One way to classify network attacks is by their intent. Some attacks are designed
Bluejacking: Bluejacking involves sending unsolicited messages to Bluetooth- to disrupt the normal operation of a network or its resources, while others are
enabled devices. This attack can be used to send spam, phishing messages, or designed to steal sensitive information or take control of network resources.
malware to the victim's device. One advantage of this attack is that it does not
Another way to classify network attacks is by the method used. Some attacks
require a network connection, and the attacker can be located anywhere within
involve exploiting known vulnerabilities in network software or hardware, while
range of the victim's Bluetooth signal. However, it requires the attacker to have
others use social engineering techniques to trick users into revealing sensitive
the victim's Bluetooth device's address and is limited to devices that have
information.
Bluetooth capabilities.
Denial of Service (DoS) Attack
SMS Spoofing: SMS spoofing involves sending text messages that appear to
• A DoS attack is when someone tries to crash a website or online service by
come from a trusted source, such as a bank or a government agency. This attack
sending too much traffic to it.
can be used to trick users into revealing sensitive information or downloading
malware. One advantage of this attack is that it can be carried out without the • The goal is to overload the system so that real users can't access it.
user's knowledge. However, it requires the attacker to have the victim's phone • A DoS attack can come from one computer or from many infected
number, and it can be easily detected if users are aware of the legitimate source computers working together (called a botnet). Even simple DoS attacks can
of the message. cause big problems and stop services from working properly.
Malware: Malware is software designed to infect a device and steal or damage Distributed Denial of Service (DDoS) Attacks
data. Malware can be distributed through email attachments, software downloads, • A DDoS attack is when a hacker tries to shut down a website or online
or malicious websites. One advantage of this attack is that it can be carried out service by sending too much traffic to it.
remotely, without the attacker needing to be physically close to the victim. • Instead of using one computer, the hacker uses many computers that have
However, it requires the attacker to have a way to deliver the malware to the been infected with a virus. These computers (called a botnet) all send data
victim's device, such as through a phishing email or a fake website. to the target at the same time.
Network and Computer Attacks • This huge amount of traffic makes the website slow or completely stops it
from working, so real users can’t use it.
A network attack is any attempt to disrupt, compromise or gain unauthorized
• It’s hard to stop because the attack comes from many places, not just one.
access to a computer network or its resources. Network attacks can be classified
15 | P a g e 16 | P a g e
Phishing Attacks • If the website is not coded properly, this code can trick the database into
giving away sensitive information, like usernames, passwords, or customer
• A phishing attack is when someone tries to trick you into giving away
data.
personal information like passwords or bank details.
• An attacker can also use it to change, delete, or steal data — and in some
• It usually happens through fake emails or messages that look like they’re
cases, even control the server.
from a real company (like your bank or a popular website).
• These messages may ask you to click a link or fill in your details on a fake Remote code execution attacks
website. The goal is to steal your information or get into your accounts.
• A Remote Code Execution (RCE) attack happens when a hacker is able
Man-in-the-Middle Attack to run their own code on someone else's computer or server from far away.
As the name indicates, a man-in-the-middle attack occurs when someone between • This can let them take control, steal data, or damage the system.
you and the person with whom you are communicating is actively monitoring, • RCE attacks usually happen because of security flaws in software, like
capturing, and controlling your communication transparently. For example, the unpatched programs, weak passwords, or bad system settings. Once inside,
attacker can re-route a data exchange. When computers are communicating at low the attacker can run harmful commands and do serious damage.
levels of the network layer, the computers might not be able to determine with
whom they are exchanging data.
Sniffing attacks
A sniffing attack is a type of network attack that involves intercepting and
analyzing network traffic in order to extract sensitive information. A sniffer, also
known as a packet sniffer or network analyzer, is a tool or software used to capture
and analyze network packets. Attackers use sniffing tools to capture and analyze
network traffic in order to steal sensitive information, such as login credentials,
financial information, or other sensitive data.
SQL injection
• SQL injection is a type of hacking attack where someone puts harmful code
into a website's input box (like a login form).
17 | P a g e 18 | P a g e