0% found this document useful (0 votes)
9 views47 pages

Introduction to Cybersecurity Concepts

Introduction to cyber security

Uploaded by

Soumya Kamal
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
9 views47 pages

Introduction to Cybersecurity Concepts

Introduction to cyber security

Uploaded by

Soumya Kamal
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Introduction to Cyber security

Module-1
Introduction
• Cyberspace is a kind of virtual environment that emerged to be the
backbone of communication, commerce, entertainment, and
governance.
• With rapidly growing technology, cyberspace and associated risks are
an important consideration for every individual, business, and
government.
• The term cyberspace was first used by the American-Canadian
author William Gibson in 1982 in a story published in Omni magazine
and then in his book Neuromancer.
• In this science-fiction novel, Gibson described cyberspace as the
creation of a computer network in a world filled with artificially
intelligent beings.
Cyberspace -Definition
• Cyberspace is the environment in which communication over computer
networks occurs.
• Cyberspace is the virtual and dynamic space created by the machine
clones. Cyberspace mainly refers to the computer which is a virtual
network and is a medium electronically designed to help online
communications to occur.
• The primary purpose of creating cyberspace is to share information and
communicate across the globe.
• Cyberspace is that space in which users share information, interact with
each other; engage in discussions or social media platforms, and many
other activities.
• The whole Cyberspace is composed of large computer networks which
have many sub- networks. These follow the TCP or IP protocol.
Cyberspace vs. the Physical World
Cyberspace Physical World

Dynamic, exponential and undefined Well-defined, static and incremental

No fixed shape, rather as vast as human Fixed contours


imagination

• Cyberspace can be compared to a human brain where the


network of computers represent the innumerable neurons and
the connections between them.
• Therefore, it can be considered as a link between the physical
and the infinite world.
Overview of Computer Technology
• Computer technology refers to the use of electronic devices and
software to process, store, and communicate information.
• It has revolutionized various fields, including business, healthcare,
education, entertainment, and government sectors.
• Computers help in automating tasks, increasing efficiency, and
enhancing decision-making through data analysis.
• Key Components of Computer Technology
• Hardware: Physical components of a computer, such as:
• Central Processing Unit (CPU): The brain of the computer that processes data.
• Memory (RAM & ROM): Temporary and permanent storage for fast computing.
• Storage Devices: Hard drives, SSDs, USB drives, and cloud storage.
• Input/Output Devices: Keyboard, mouse, monitor, printer, etc.
• Software: Programs that run on computers, categorized as:
• System Software: Operating systems (Windows, Linux, macOS) that manage hardware and
applications.
• Application Software: Programs for specific tasks like MS Office, web browsers, and media
players.
• Utility Software: Security, backup, and optimization tools.
• Networking & Communication: Computers connect and communicate through:
• Internet & Intranet: Global and private networks for data exchange.
• LAN & WAN: Local Area Networks for small areas and Wide Area Networks for larger
regions.
• Wireless Technologies: Wi-Fi, Bluetooth, and mobile networks (4G, 5G).
Overview of Web Technology
• Web technology refers to the tools, programming languages, and
protocols used to develop and manage websites and web-based
applications.
• It has evolved significantly over the years.
• Stages of Web Evolution
• Web 1.0 (Static Web) – The first generation of the web with basic static
websites, primarily for reading content. No user interaction.
• Web 2.0 (Dynamic & Social Web) – Enhanced user interaction, allowing social
media, blogs, and dynamic websites (e.g., Facebook, YouTube).
• Web 3.0 (Intelligent Web) – Uses AI, machine learning, blockchain, and
decentralized technologies for more personalized experiences.
Web Technology: Terminologies
1. World Wide Web (WWW): The World Wide Web, commonly referred to as the
web, is a global system of interconnected documents and resources linked
through hyperlinks. It is accessed via web browsers.
2. Web Browsers: Web browsers like Google Chrome, Mozilla Firefox, and
Microsoft Edge allow users to access and interact with web content.
3. Web Development: Web development involves creating and maintaining
websites and web applications.
4. Web Servers: Web servers store and deliver web content to users' browsers
upon request. Popular web server software includes Apache, Microsoft IIS.
5. Web Security: Ensuring web security is critical to protect data and user privacy.
Measures include SSL/TLS encryption, secure authentication, and regular
security audits.
6. Web Standards: Organizations like the World Wide Web Consortium (W3C)
establish web standards to ensure compatibility and accessibility across
different devices and browsers.
• Key Components of Web Technologies
• Front-end Technologies (User Interface):
➢HTML (HyperText Markup Language): Defines web page structure.
➢CSS (Cascading Style Sheets): Adds design and styling.
➢JavaScript: Enhances interactivity (e.g., animations, dynamic content).
➢Frameworks: React, Angular, [Link] for efficient development.
• Back-end Technologies (Server-side processing):
➢Programming Languages: PHP, Python, Java, [Link] for server logic.
➢Databases: MySQL, MongoDB for storing and managing data.
➢APIs (Application Programming Interfaces): Enable communication between
different software components.
• Networking Technologies:
➢HTTP/HTTPS: Protocols for secure data transfer.
➢Cloud Computing: Services like AWS, Google Cloud for scalable web hosting.
➢CDN (Content Delivery Networks): Improve website speed and performance.
Components of Cyberspace
• Networks: These are the backbone of cyberspace and involve many
different interconnected networks of computers, servers, and
communication systems helping in data transmission.
• Hardware: This basically represents the real devices physically existing,
such as computers, routers, and servers, making up the physical
infrastructure of cyberspace. They serve a very important purpose.
• Software: Software pertains to the applications, operating systems,
and platforms that run on hardware to enable communication, data
processing, etc.
• Data: Data refers to information stored, transmitted, and processed
within cyberspace. These range from personal data to corporate
records and government databases.
• Protocols: Protocols refer to a set of rules and standards that define
how data is transmitted and received across the network. These
ensure that different systems can communicate with each other.
• Users: Users can consist of human beings and organizations that
approach cyberspace for any of the purposes: communication,
business, entertainment, and so on.
Characteristics of Cyberspace
• Borderless: Unlike physical space with geographical boundaries,
cyberspace connects users regardless of location.
• Dynamic: Cyberspace is constantly evolving with technological
advancements and the increasing number of users.
• Virtual Environment: It exists in a digital realm, not in the physical
world. Activities like communication, transactions, and data storage
occur in this virtual space.
• Anonymity and Identity Flexibility: Users can interact anonymously or
under different identities. This enables freedom of expression but also
poses security and ethical challenges.
• Lack of Central Governance: No single entity controls cyberspace. It is
regulated by various international, national, and private organizations.
• Speed and Accessibility: Information can be shared instantly across the
globe. Accessible through multiple devices like computers, smartphones,
and tablets.
• Data-Driven: Cyberspace is powered by vast amounts of data. Activities
such as browsing, messaging, and streaming all involve data transmission
and storage.
• Security and Vulnerability: Prone to cyber threats like hacking, phishing,
malware, and identity theft. Requires robust cybersecurity measures.
• Multi-Dimensional Use: Used for communication, education, business,
entertainment, governance, and more. Supports sectors like e-commerce,
e-learning, telemedicine, and digital banking.
• Constant Evolution: Cyberspace is dynamic and continuously evolving with
new technologies. Developments like AI, IoT, blockchain, and cloud
computing shape its future.
Architecture of cyberspace
• Cyberspace architecture refers to the structural framework and
infrastructure that supports the interconnected network of digital systems,
including the internet, data centers, cloud services, and various
communication networks.
• Network Infrastructure
• At the core of cyberspace architecture lies the network infrastructure, which includes
physical and virtual components such as routers, switches, servers, and transmission
lines. These elements form the backbone of the internet and facilitate the
transmission of data between devices and systems.
• Data Centers
• Data centers serve as the centralized hubs for storing, processing, and managing vast
amounts of digital information. They house servers, storage systems, and networking
equipment, providing the necessary computing resources to support a wide range of
online services and applications.
• Protocols and Standards
• Cyberspace architecture relies on a multitude of protocols and standards to ensure
interoperability and seamless communication between different devices and platforms.
Examples include TCP/IP for internet communication, HTTP for web browsing, and
SMTP for email transmission.
• Cloud Computing Infrastructure
• The rise of cloud computing has significantly influenced cyberspace architecture, with
cloud providers offering scalable resources, virtualized environments, and on-demand
services to support diverse workloads and applications.
Architecture of cyberspace based on models
• Cyberspace is a vast, complex structure that transcends geographical
boundaries, providing a platform for communication, information sharing,
and business transactions.
• The architecture of cyberspace is based on a multi-layered model, which
includes:
• Physical Layer: This is the foundational layer consisting of hardware like
routers, switches, servers, and other networking devices that enable
communication between computers.
• Network Layer: This includes the protocols and services that enable
communication across different networks. The Internet Protocol (IP) and
Transmission Control Protocol (TCP) are the most common ones used for
data exchange.
• Application Layer: This is the user-facing layer, which includes websites,
apps, and platforms accessed via web browsers and mobile applications.
Communication and web technology
• Communication and web technology are integral components of the
modern digital landscape.
• They encompass a wide range of technologies and tools that facilitate
communication and the dissemination of information over the
internet.
• Some key aspects of communication and web technology are:
1. Internet: The internet is the foundation of web technology. It is a global
network of interconnected computers and servers that allows for the
transfer of data and information across the world.
2. Web Browsers: Web browsers like Chrome, Firefox, Safari, and Edge are
software applications that enable users to access and interact with websites
and web-based applications.
3. Websites: Websites are collections of web pages that are hosted on web
servers and can be accessed through a web browser. They are created using
various web technologies such as HTML, CSS, and JavaScript.
4. Web Development: Web development involves designing, creating, and
maintaining websites. Web developers use various programming languages
and frameworks to build web applications and sites.
5. Web Standards and Protocols: Various standards and protocols govern web
technology, including HTTP/HTTPS (for data transfer), HTML5, CSS3, and
more.
6. Mobile Web: Mobile web technology focuses on optimizing websites and
applications for mobile devices, ensuring a seamless user experience on
smartphones and tablets.
Internet
• The Internet is a global network of interconnected computers and
devices that allows users to access and share information and
devices, allowing them to communicate and exchange data.
• It enables users to access a wide range of services, such as websites,
emails, social media, online applications, and cloud storage.
• Through standardized communication protocols, the Internet
facilitates the sharing of information, resources, and media across
vast distances, making it an essential tool for worldwide:
• Education
• Business
• Entertainment
• Personal Communication
• History of the Internet
• The Internet came in the year 1960 with the creation of the first working model
called ARPANET (Advanced Research Projects Agency).
• It allowed multiple computers to work on a single network which was their
biggest achievement at that time.
• ARPANET uses packet switching to communicate multiple computer systems
under a single network.
• In October 1969, using ARPANET first message was transferred from one
computer to another. After that technology continues to grow.
• Components of the Internet:
• Web Servers: Computers that host websites and data.
• Clients: Devices (like computers or smartphones) used to access the internet.
• Routers & Switches: Devices that direct data to the right location.
• ISPs (Internet Service Providers): Companies that provide access to the internet.
Key Features of the Internet
• Global Connectivity : Connects computers and networks all over the world. Enables
instant communication and access to information from any location.
• Decentralized System: No single organization owns the entire internet. It is a network
of networks connected through Internet Service Providers (ISPs) and exchange points.
• Based on Protocols: Uses TCP/IP (Transmission Control Protocol/Internet Protocol) to
transmit data reliably.
• Access to Services: Web browsing (WWW), email, file sharing, streaming, e-
commerce, online education, social media, etc.
• Multimedia Support: Supports text, images, audio, video, and interactive content.
• Real-Time Communication: Facilitates live communication through chat, video calls,
and conferencing.
• Scalability: Can support millions of users and devices simultaneously.
Common Uses of the Internet
• Accessing websites and information (via the World Wide Web)
• Email communication
• Online banking and shopping
• Social networking
• Entertainment (streaming movies, music, games)
• Cloud computing and storage
• Research and education
• Telemedicine and e-governance
World Wide Web (WWW)
• The World Wide Web (WWW), often called the Web, is a system of
interconnected webpages and information that you can access using the Internet.
• It was created to help people share and find information easily, using links that
connect different pages together.
• The Web allows us to browse websites, watch videos, shop online, and connect
with others around the world through our computers and phones.
• All public websites or web pages that people may access on their local computers
and other devices through the internet are collectively known as the World Wide
Web or W3.
• Users can get further information by navigating to links interconnecting these
pages and documents.
• This data may be presented in text, picture, audio, or video formats on the
internet.
• The World Wide Web was invented by a British scientist, Tim Berners-
Lee in 1989.
• The first website is still online: [Link]

• Key Components of WWW:


• Web Pages: Documents written in HTML (HyperText Markup Language).
• Web Browser: Software to access and display web pages (e.g., Chrome, Firefox,
Safari).
• Web Server: A computer that stores and delivers web pages to users on
request.
• HTTP (HyperText Transfer Protocol): A protocol used for transferring web pages
from server to client.
• URLs (Uniform Resource Locators): The web addresses used to locate resources
on the Web.
Advent of internet
• The advent of the internet marked a significant turning point in the history of
communication, technology, and society.
1. 1960s- The Precursor: ARPANET
2. 1970s- TCP/IP
3. 1980s-The Internet is Born
4. 1989- Invention of the World Wide Web
5. 1990s-Commercialization and Expansion
6. Late 1990s- Dot com Bubble
7. Early 2000s – Broadband and Social Media
8. 2010s- Mobile Internet and IoT
9. 2020s- Ongoing Evolution
• The history of the Internet can be segmented into three phases
1. Innovation Phase (1961 to 1974) − The fundamental building
blocks of the Internet—packet-switching hardware, a
communications protocol called TCP/ IP, and client/server
computing were conceptualized and then implemented in actual
hardware and software.
2. Institutionalization Phase (1975 to 1995) − large institutions
such as the U.S. Department of Defense (DoD) and the National
Science Foundation (NSF) provided funding and legitimization
for the fledging Internet.
3. Commercialization Phase (1995 to the present) − The U.S.
government encouraged private corporations to take over and
expand the Internet backbone as well as local service beyond
military installations and college campuses to the rest of the
population around the world
Internet infrastructure for data transfer and
governance
• Internet infrastructure for data transfer and governance encompasses
the physical and virtual systems, protocols, and regulations that
enable the secure, efficient, and reliable exchange of data across the
global network.
• This infrastructure plays a critical role in ensuring data privacy,
security, and compliance with regulations.
• Here are key components and considerations for internet
infrastructure related to data transfer and governance:
1. Network Infrastructure −
• Backbone Networks: High-speed, long-distance networks that form the core of
the internet, connecting major data centers and internet exchange points (IXPs).
• Last-Mile Connectivity: The connection from service providers to end-users,
including wired (e.g., fiber-optic, DSL) and wireless (e.g., 5G, Wi-Fi)
technologies.
• Data Centers: Facilities that house servers and storage devices, providing the
infrastructure for web hosting, cloud computing, and data storage.
2. Protocols and Standards −
• Internet Protocol (IP): The foundation of internet communication, ensuring data
packets can be routed across networks.
• Transport Layer Security (TLS): Encryption protocol for securing data in transit.
• Hypertext Transfer Protocol (HTTP) and HTTPS: Protocols for web data transfer,
with HTTPS adding a security layer.
• DNSSEC: Enhances the Domain Name System (DNS) by adding a layer of security
through digital signatures.(DNSSEC-Domain Name System Security Extensions)
3. Data Centers and Cloud Services −
• Major providers like Amazon Web Services (AWS), Microsoft Azure, and Google
Cloud offer robust infrastructure and tools for data storage and processing.
4. Data Governance and Regulation −
• Data Privacy Regulations: Compliance with laws like GDPR (in Europe), CCPA (in
California), and HIPAA (for healthcare data).
• Data Retention Policies: Guidelines for storing and managing data for specific
periods.
• Data Access Controls: Systems to restrict and monitor who can access and
modify data.
• Data Encryption: Ensuring data at rest and in transit is properly encrypted to
protect against unauthorized access.
5. Cybersecurity −
• Robust security measures, including firewalls, intrusion detection systems, and
regular security audits, are essential to protect data during transfer.
6. Internet Governance Bodies −
• Organizations like ICANN (Internet Corporation for Assigned Names and Numbers)
oversee domain name system management and policy.
• Multistakeholder governance models involve various stakeholders, including
governments, businesses, and civil society, in shaping internet governance.
7. Content Delivery Networks(CDNs) −
• CDNs like Akamai and Cloudflare optimize data delivery by caching content at various
locations worldwide, reducing latency.
8. Quality of Service (QoS) −
• Ensuring data transfer meets performance requirements, especially for applications like
video conferencing and online gaming.
9. International Collaboration −
• Cooperation among nations is essential to establish international norms and
agreements related to data transfer and governance.
10. Data Transfer Agreements −
• Agreements like Privacy Shield and Standard Contractual Clauses facilitate the lawful
transfer of data across borders.
Internet Society
• Internet Society (ISOC) A professional membership society that promotes the
use and future development of the Internet.
• It has individual and organization members all over the world and is governed
by an elected board of trustees.
• ISOC coordinates various groups responsible for Internet infrastructure.
• These include
1. The Internet Engineering Task Force (IETF),
2. The Internet Architecture Board (IAB), and
3. The Internet Engineering Steering Group (IESG).
• The IETF develops technical standards for the Internet.
• The IAB has overall responsibility for the architecture and adjudicates on
disputes about standards.
• The IESG, along with the IAB, reviews standards proposed by the IETF.
Regulation of cyberspace
• Cyberspace spans worldwide, but it has no formal framework. The lack of
formal framework makes cyberspace nobody's domain .
• No single individual, entity, or government owns or controls cyberspace.
• Regulation in cyberspace is an emerging challenge.
• The default in cyberspace is anonymity. Anonymity encourages and
enhances the exercise of freedom. A child too shy to express himself in
physical space can feign to be somebody else in virtual space, and express
himself freely.
• Crimes of global repercussion are also committed with the use of the
internet. Trafficking of persons, child pornography, kidnapping for ransom,
and terrorism are perpetrated with the use of cyberspace. Freedom thus in
cyberspace should not be exercised without the concomitant responsibility
of its users.
• Practical Problems In Extending The Traditional Laws To Cyberspace
1. Multiple Jurisdictions-Because of anonymity of the Internet user,
absence of geographical boundaries in the cyberspace, and the cross
border effect of Internet transactions, all legal systems face legal
uncertainty.
2. Problem of Policing-The lack of technical knowledge, non-co-
operation among different police organization etc., make the problem
too difficult to be solved.
3. Expensive Process-Training of law enforcement officers to solve the
issue of cybercrime is very expensive.
4. Obtaining Digital Evidence- Another instance where the policing of
cybercrime becomes difficult is with regard to obtaining the digital
evidence
Concept of Cyber Security
• Cybersecurity is the practice of protecting computer systems,
networks, and data from digital attacks, damage, or unauthorized
access.
• Cybersecurity refers to defending vital systems and sensitive data
against online intrusions.
• Cybersecurity measures, also known as IT security, are designed to
thwart threats against networked systems and applications, whether
they originate from within or outside an organization.
• Cybersecurity is the study of finding various ways in which we can
restrict access to precious digital files and documents, with
encryption acting as locks which can be decrypted with one special
key.
• In fact, cybersecurity is the practice of defending computer systems
from malicious acts.
• The phrase of interest here is malicious actors. Malicious actors are
those that illegally and deliberately try to access a computer system
or a network to steal, manipulate or compromise the data stored on
them.
• It encompasses a wide range of technologies, processes, and
practices designed to safeguard digital information and ensure the
confidentiality, integrity, and availability of data.
1. Confidentiality: This principle focuses on ensuring that sensitive
information is only accessible to authorized individuals or systems. It
involves encryption, access controls, and data classification to prevent
unauthorized access or disclosure.
2. Integrity: Integrity in cybersecurity means that data and systems
are accurate and trustworthy. Any unauthorized modification or
tampering with data or systems should be detected and prevented.
Techniques like checksums and digital signatures are used to
maintain data integrity.
3. Availability: Availability ensures that systems and data are
accessible when needed. Cyberattacks can disrupt services or make
them unavailable, so cybersecurity measures aim to prevent or
mitigate such disruptions through redundancy, load balancing, and
disaster recovery planning.
4. Authentication: Authentication is the process of verifying the
identity of users, devices, or systems trying to access resources. This
can be achieved through passwords, biometrics, two-factor
authentication (2FA), and multi-factor authentication (MFA).
Categories
• Cybersecurity can be classified into a few categories, where each
category is its own field of study:
• Information Security: Deals with integrity and confidentiality of
data.
• Operational Security: Deals with the security of data when it’s
being processed and executed.
• Network Security: Deals with the security of the networks
connecting the computer system(s).
• Application Security: Deals with making sure that software and
devices are threat-free.
Types of Threats
1. Malware Threats: Malware is software that malicious actors inject
into a network or a computer system for their own personal gain.
Malware includes Viruses, Worms, Trojans, Ransomware and
Spyware. Malware enters networks and computer systems when
someone on the inside opens a suspicious email or clicks on an
unverified link, resulting in malicious software being
downloaded. Malware can secretly transmit data from computer
systems and block access to networks.
2. Phishing: The act of targeting victims with fraudulent emails or
website links that are made to look like they’re originating from a
reputable source. The purpose of this attack is to tricking users into
revealing sensitive information.
3. Man in the Middle Attack: The attacker secretly listens to the
conversation between two parties and, when sufficient information is
gained, pretends to be one of the parties to trick the other into revealing
sensitive information. A man-in-the-middle attack is a type of cyber threat
where a cybercriminal intercepts communication between two individuals
in order to steal data. For example, on an unsecure WiFi network, an
attacker could intercept data being passed from the victim’s device and the
network.
4. Denial of Services This act entails the attacker flooding the server or a
network with bad requests to overwhelm the systems and disrupt the
services.
5. SQL Injection : This act results in a malicious SQL query being given as
input by the attacker into a form that interferes with the backend
database.
6. Zero-day Exploit: This occurs when a vulnerability in a system or
network is revealed, but the vulnerability isn’t patched yet. The attacker
tries to take advantage of that vulnerability in that time frame.
7. DNS Attack: The DNS server is made to act in an abnormal way so that
the attacker can direct the victim’s requests to a website of his choice.
Cyber Attack
• Any potential harmful attack that aims to gain unauthorized access to
data, interfere with digital activities or contaminate information is
referred to as a cyber security threat.
• Cyber threats may come from a variety of sources,
including corporate espionage, hacktivists, terrorist organizations,
adversarial nation-states, criminal organizations, lone hackers, and
disgruntled workers.
• Cyber attackers can utilize sensitive data from an individual or an
organization to steal information or get access to bank accounts,
among other potentially harmful acts, which is why cyber security
specialists are critical for keeping private data secure.
Types of Cyber Attacks
• Cyber-attacks can be mainly divided into the following types:
• Web-based Attacks
• System-based attacks
1. Web-based attacks:-
• These are the attacks which occur on a website or web
applications. Some of the important web-based attacks are as
follows:
I. Injection attacks :It is the attack in which some data will be injected into
a web application to manipulate the application and fetch the required
information.
II. Session Hijacking :It is a security attack on a user session over a
protected network. Web applications create cookies to store the state
and user sessions. By stealing the cookies, an attacker can have access to
all of the user data.
III. Phishing: Phishing is a type of attack which attempts to steal sensitive
information like userlogin credentials and credit card number. It occurs
when an attacker is masquerading as a trustworthy entity in electronic
communication.
IV. Denial of Service: It is an attack which meant to make a server or
network resource unavailable to the users. It accomplishes this by
flooding the target with traffic or sending it information that triggers a
crash.
2. System-based attacks :-
• These are the attacks which are intended to compromise a computer or a
computer network. Some of the important system-based attacks are as
follows.
I. Virus :It is a type of malicious software program that spread throughout the
computer files without the knowledge of a user. It is a self-replicating malicious
computer program that replicates by inserting copies of itself into other computer
programs when executed. It can also execute instructions that cause harm to the
system.
II. Worm :It is a type of malware whose primary function is to replicate itself to spread
to uninfected computers. It works same as the computer virus. Worms often
originate from email attachments that appear to be from trusted senders.
III. Trojan horse : it is a malicious program that occurs unexpected changes to computer
setting and unusual activity, even when the computer should be idle. It misleads the
user of its true intent. It appears to be a normal application but when
opened/executed some malicious code will run in the background.
Difference between Cyber Threat and Cyber Attack
Cyber Threat Cyber Attack
Threats can be intentional or unintentional. The attack is intentional.

Threats may or may not be malicious. The attack is malicious.

Circumstances that can cause damage. The objective is to cause damage.

The chance for information alteration and damage is very


Information may or may not be altered or damaged.
high.

The threat is comparatively hard to detect. Comparatively easy to detect.

Can be blocked by control of vulnerabilities. Cannot be blocked by just controlling the vulnerabilities.

Can be initiated by the system itself as well as by An attack is always initiated by an outsider (system or
outsiders. user).

These can be classified into Viruses, Spyware, Phishing,


Can be classified into Physical, internal, external,
Worms, Spam, Botnets, DoS attacks, Ransomware, and
human, and non-physical threat sats.
Breaches.
Issues and challenges of cyber security
• Issues in Cybersecurity
• Data Breaches – Unauthorized access and theft of sensitive data.
• Malware Infections – Viruses, ransomware, spyware disrupting systems.
• Phishing & Social Engineering – Tricking users into giving confidential data.
• Weak Passwords & Authentication – Easy-to-guess credentials leading to
attacks.
• Unpatched Software – Outdated systems with exploitable vulnerabilities.
• Insider Threats – Employees or partners misusing access.
• Cloud Security Risks – Data exposure or misconfiguration in cloud
services.
• Challenges in Cybersecurity
• Evolving Threat Landscape – Attackers constantly developing new
techniques.
• Shortage of Skilled Professionals – Not enough trained cybersecurity
experts.
• Balancing Security & Usability – Making systems secure without
affecting user experience.
• Rapid Technology Changes – IoT, AI, and 5G introduce new
vulnerabilities.
• Advanced Persistent Threats (APT) – Long-term, targeted cyber
espionage.
• Lack of Awareness & Training – Human error remains a major cause of
breaches.
• Regulatory Compliance – Meeting global data protection laws.
• Attribution Difficulty – Hard to identify who is behind an attack.

You might also like