0% found this document useful (0 votes)
15 views3 pages

Understanding Cyber Security Basics

The document provides an overview of cyber security, detailing its principles such as confidentiality, integrity, and availability, along with authentication methods. It categorizes cyber attacks into web-based and system-based attacks, explaining various types including phishing and malware. Additionally, it discusses the challenges facing cybersecurity, including data breaches, insider threats, and the rise of ransomware attacks.

Uploaded by

dhanush kumar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
15 views3 pages

Understanding Cyber Security Basics

The document provides an overview of cyber security, detailing its principles such as confidentiality, integrity, and availability, along with authentication methods. It categorizes cyber attacks into web-based and system-based attacks, explaining various types including phishing and malware. Additionally, it discusses the challenges facing cybersecurity, including data breaches, insider threats, and the rise of ransomware attacks.

Uploaded by

dhanush kumar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

CYBER SECURITY

(A iliated to Bengaluru North University)


# 11/2,7 cross, Basavanapura Main Road,Gayathri Layout
th

K.R Puram, Bengaluru-36


Module 1 : Cyber Security

Concept of cyber security cybersecurity is the practice of protecting computer systems, networks, and data
from theft, damage, or unauthorized access. It encompasses a wide range of technologies, processes, and
practices designed to safeguard digital information and ensure the confidentiality, integrity, availability of
data.

 Confidentiality: This principle focuses on ensuring that sensitive information is only accessible to
authorized individuals or systems. It involves encryption, access controls, and data classification to
prevent unauthorized access or disclosure.
 Integrity: Integrity in cybersecurity means that data and systems are accurate and trustworthy. Any
unauthorized modification or tampering with data or systems should be detected and prevented.
Techniques like checksums and digital signatures are used to maintain data integrity.
 Availability: Availability ensures that systems and data are accessible when needed. Cyberattacks
can disrupt services or make them unavailable, so cybersecurity measures aim to prevent or mitigate
such disruptions through redundancy, load balancing, and disaster recovery planning.
 Authentication: Authentication is the process of ifying the identity of users, devices, or systems
trying to access resources. This can be achieved through passwords, biometrics, two-factor
authentication (2FA), and multi-factor authentication (MFA).

Cyber Attacks:

A cyber-attack is an exploitation of computer systems and networks. It uses malicious code to alter computer
code, logic or data and lead to cybercrimes, such as information and identity theft. Cyber-attacks can be
classified into the following categories:
1. Web-based attacks

2. System-based attacks

Web-based attacks

These are the attacks which occur on a website or web applications. Some of the important web-based
attacks are as follows-

 Injection attacks :It is the attack in which some data will be injected into a web application to
manipulate the application and fetch the required information.
 Session Hijacking :It is a security attack on a user session over a protected network. Web
applications create cookies to store the state and user sessions. By stealing the cookies, an attacker
can have access to all of the user data.

PREPARED BY KEERTHI K UNNI, IVDC 1


CYBER SECURITY
 Phishing: Phishing is a type of attack which attempts to steal sensitive information like user login
credentials and credit card number. It occurs when an attacker is masquerading as a trustworthy
entity in electronic communication.
 Denial of Service:It is an attack which meant to make a server or network resource unavailable to
the users.

System-based attacks

These are the attacks which are intended to compromise a computer or a computer network. Some of the
important system-based attacks are as follows-

 Virus :It is a type of malicious software program that spread throughout the computer files
without the knowledge of a user. It is a self-replicating malicious computer program that
replicates by inserting copies of itself into other computer programs when executed. It can also
execute instructions that cause harm to the system.
 Worm :It is a type of malware whose primary function is to replicate itself to spread to
uninfected computers. It works same as the computer virus. Worms often originate from email
attachments that appear to be from trusted senders.
 Trojan horse : it is a malicious program that occurs unexpected changes to computer setting and
unusual activity, even when the computer should be idle. It misleads the user of its true intent. It
appears to be a normal application but when opened/executed some malicious code will run in
the background.
Cyber Threat

A Cyber threat is any malicious act that attempts to gain access to a computer network without authorization
or permission from the owners. It refers to the wide range of malicious activities that can damage or disrupt
a computer system, a network or the information it contain.

 A Threat by definition is a condition / circumstance which can cause damage to the system/asset.
 Threats can be intentional like human negligence or unintentional like natural disasters.
 A Threat may or may not be malicious.
 Chance to damage or information alteration varies from low to very high.
Cyber Attack

 An Attack by definition is an intended action to cause damage to system/asset.


 The attack is a deliberate action. An attacker has a motive and plan the attack accordingly.
 An Attack is always malicious.
 The chances of damaging or altering information is very high.
Issues and challenges of cyber security

Cybersecurity faces numerous issues and challenges due to the ever-evolving nature of technology and the
increasing sophistication of cyber threats. Some of the key issues and challenges in cybersecurity include:
[Link] Attacks: The constant threat of cyberattacks from various actors, including hackers,
cybercriminals, nation-states, and hacktivists, is a significant challenge. These attacks can take various
forms, such as malware, ransomware, phishing, and distributed denial of service (DDoS) attacks.

PREPARED BY KEERTHI K UNNI, IVDC 2


CYBER SECURITY
[Link] Breaches: Data breaches can have severe consequences for organizations and individuals. The theft
or exposure of sensitive data, such as personal information, financial records, or intellectual property, can
lead to financial losses, reputational damage, and legal liabilities.

[Link] Vulnerabilities: Software and hardware vulnerabilities are exploited by attackers to gain
unauthorized access or control over systems. Identifying and patching these vulnerabilities in a timely
manner is a constant challenge.

[Link] Threats: Insider threats, where individuals within an organization misuse their access and
privileges, can be particularly challenging to detect and prevent. This includes employees, contractors, or
partners who intentionally or unintentionally compromise security.

[Link] of Cybersecurity Awareness: Many individuals and employees lack awareness of cybersecurity
best practices, making them susceptible to social engineering attacks and other cyber threats.

[Link]: Ransomware attacks have surged in recent years, with cybercriminals encrypting data and
demanding a ransom for decryption keys. These attacks can disrupt critical operations and result in
significant financial losses.

PREPARED BY KEERTHI K UNNI, IVDC 3

Common questions

Powered by AI

Viruses, worms, and Trojan horses differ in their propagation and impact. Viruses are self-replicating programs that insert copies into other programs or files, activating only when the infected files are run by a user, often causing harm by executing malicious instructions . Worms, on the other hand, do not require user interaction to spread; they replicate themselves and spread through networks, often causing system slowdowns and network congestion . Trojan horses deceive users by appearing as legitimate software; once executed, they perform malicious actions in the background, such as stealing data or compromising system integrity . Understanding these differences is crucial for developing appropriate defenses against each type of malware.

Insider threats are significant in cybersecurity due to the potential for individuals with legitimate access to misuse their privileges, either intentionally or unintentionally, and compromise security . These threats are challenging to detect and prevent because insiders often already have access to sensitive information and systems. Organizations can mitigate insider threats by implementing strong access controls, monitoring user activity, regularly reviewing access rights, fostering a culture of ethical use of resources, and providing ongoing training on security awareness . Employing behavioral analytics can also help in identifying anomalous patterns indicative of insider threats.

Cybersecurity awareness plays a vital role in preventing cyber threats by equipping individuals with the knowledge to recognize and respond to potential attacks, such as phishing and social engineering attempts . To enhance awareness, organizations can conduct regular training sessions, simulating cyber attacks to teach employees how to recognize threats. Developing clear policies and procedures for reporting suspected incidents can encourage prompt action. Sharing updates on the latest threats and security practices helps keep employees informed. Creating a culture of continuous learning and vigilance can significantly reduce the likelihood of successful cyber attacks . Awareness efforts should be continuous and adaptive to evolving threats.

The increasing sophistication of cyber threats presents several challenges to cybersecurity, including the constant threat of diverse cyberattacks, data breaches, security vulnerabilities, insider threats, and a lack of cybersecurity awareness . Organizations can address these challenges by implementing advanced threat detection and response systems to combat attacks, employing strict data protection measures to prevent breaches, regularly updating and patching software to mitigate vulnerabilities, monitoring and restricting insider access to sensitive data and systems, and enhancing cybersecurity training programs to improve employee awareness . Employing a comprehensive, layered security strategy can help manage the evolving threat landscape.

Web-based cyber attacks occur on websites or web applications and include injection attacks, session hijacking, phishing, and denial of service attacks. Injection attacks manipulate web applications by injecting malicious data, while session hijacking involves stealing cookies to access user data . Phishing involves deceiving individuals into revealing sensitive information by masquerading as a trustworthy entity, and denial of service attacks make network resources unavailable to users . In contrast, system-based attacks target computers or networks directly, including viruses, worms, and Trojan horses. Viruses are self-replicating programs causing harm by inserting themselves into other programs, worms spread through networks replicating themselves, and Trojan horses disguise themselves as benign applications to execute malicious code .

The core principles of cybersecurity include confidentiality, integrity, and availability. Confidentiality ensures that sensitive information is accessible only to authorized individuals or systems, typically through encryption, access controls, and data classification . Integrity involves maintaining the accuracy and trustworthiness of data and systems by using techniques like checksums and digital signatures to detect and prevent unauthorized modifications . Availability ensures that systems and data are accessible when needed, preventing disruptions through redundancy, load balancing, and disaster recovery planning . Each principle addresses different aspects of security, providing a comprehensive strategy for protecting digital information.

Redundancy and load balancing significantly enhance the availability aspect of cybersecurity by ensuring that systems and data remain accessible even in the face of disruptions or high demand. Redundancy involves creating multiple instances of critical system components, such as servers or data storages, so that if one fails, another can take over, thus preventing downtime . Load balancing distributes network traffic across several servers, avoiding overload on any single server and ensuring efficient use of resources . For example, in web services, using multiple data centers or cloud services with failover mechanisms ensures that service remains uninterrupted during outages. These strategies are essential for maintaining continuous operations and user access.

Authentication is a critical component of cybersecurity because it verifies the identity of users, devices, or systems attempting to access resources, thereby preventing unauthorized access to sensitive information . Common authentication methods include passwords, which are knowledge-based credentials, and biometrics, which utilize unique physical characteristics such as fingerprints or facial recognition. Two-factor authentication (2FA) and multi-factor authentication (MFA) add layers of security by requiring additional verification steps, such as a code sent to a mobile device . By ensuring that only authorized entities access protected systems and data, authentication helps maintain confidentiality and integrity.

Cyber threats vary in intentions and impact, ranging from malicious activities like information theft, system disruption, and unauthorized access to non-malicious threats like human error or natural disasters . Intentional threats typically involve attackers with a defined motive, such as stealing data or causing damage, making them always malicious and high-risk . Non-malicious threats may result from accidental actions, which can still compromise security. This variation affects cybersecurity by necessitating a comprehensive approach that addresses both intentional and unintentional threats using preventive, detective, and responsive measures tailored to each threat type . Understanding the nature of threats helps in strategizing effective defense mechanisms.

Data breaches can have severe consequences for organizations, including financial losses, reputational damage, and legal liabilities . The exposure of sensitive data such as personal information, financial records, or intellectual property can lead to loss of customer trust and competitive disadvantage. To minimize risks, organizations can implement data encryption, robust access controls, and regular security audits. Developing an incident response plan can help quickly address and mitigate the impact of breaches. Educating employees on data protection best practices and ensuring compliance with data protection regulations further bolster defenses against data breaches . A proactive approach is crucial to minimizing the fallout from potential breaches.

You might also like