0% found this document useful (0 votes)
4 views40 pages

Chapter Two

The document discusses various computer threats, focusing on malicious code types such as viruses, Trojans, worms, and spyware, detailing their characteristics and examples. It also classifies computer attacks based on the attacker's goals, including reconnaissance, unauthorized access, and denial of service (DoS) attacks. Additionally, it highlights program flaws like buffer overflows and TOCTOU flaws, emphasizing the importance of controls to mitigate these vulnerabilities.

Uploaded by

enddeg4
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views40 pages

Chapter Two

The document discusses various computer threats, focusing on malicious code types such as viruses, Trojans, worms, and spyware, detailing their characteristics and examples. It also classifies computer attacks based on the attacker's goals, including reconnaissance, unauthorized access, and denial of service (DoS) attacks. Additionally, it highlights program flaws like buffer overflows and TOCTOU flaws, emphasizing the importance of controls to mitigate these vulnerabilities.

Uploaded by

enddeg4
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter Two

Computer Threat
By :
Andargie Mekonnen

05/01/2026 Andargie Mekonnnen 1


Computer threats
Computer threats refer to any potential danger that can cause harm to computer
systems, data, or networks.
❖These threats may come from external attackers, malicious insiders, or
unintentional user mistakes.

05/01/2026 Andargie Mekonnnen 2


Malicious Code
Malicious code refers to any software or script designed to harm, bypass security, or
steal information from a computer system.
❖It includes programs that replicate, hide, destroy data, spy on users, or provide
unauthorized access to attackers.
❖Malicious code is one of the biggest threats to computer security because it can spread
quickly, damage systems, and compromise sensitive information

05/01/2026 Andargie Mekonnnen 3


Malicious Code
Computer virus: is a malicious program that attaches itself to a legitimate file or
program and replicates when the infected file is executed.
❖It characterized by:
✓ Requires user action to activate (e.g., opening an infected file).
✓ Spreads from file to file or computer to computer.
✓ Can corrupt data, slow systems, or delete files.
❖How It Works
✓[Infected File] ---> User Opens File ---> Virus Executes ---> Replicates &
Spreads
05/01/2026 Andargie Mekonnnen 4
Malicious Code
❖Common Virus Actions
✓ Deleting files
✓ Corrupting system programs
✓ Slowing the computer
✓ Displaying unwanted messages

❖Example
✓ The ILOVEYOU Virus (2000) Spread through email as a text file. When opened, it
overwrote files and sent itself to all contact

05/01/2026 Andargie Mekonnnen 5


Malicious Code
Trojan horse is a program that appears legitimate and useful but secretly
performs malicious activities when executed.
❖Key Characteristics
✓ Does not replicate itself (unlike viruses/worms).
✓ Tricks the user into installation.
✓ Often installs backdoors for attackers.
❖How It Works
✓User Downloads "Free Game" → Installs → Hidden
Malicious Code Executes
05/01/2026 Andargie Mekonnnen 6
Malicious Code
❖Common Trojan Actions
✓Installing spyware
✓Stealing passwords
✓Giving remote control to attackers
✓Deleting files
❖Example
❖A fake “system update” that actually installs a keylogger.

05/01/2026 Andargie Mekonnnen 7


Malicious Code
Worm is a self-replicating malicious program that spreads across networks without
requiring user action.

❖Key Characteristics
✓ Spreads automatically using network vulnerabilities.
✓ Consumes bandwidth, slowing networks.
✓ May carry a destructive “payload”.

❖How It Spreads

✓Worm Infects Computer → Scans Network → Spreads to Other Systems


Automatically

05/01/2026 Andargie Mekonnnen 8


Malicious Code
❖Common Worm Actions

✓Flooding networks

✓Destroying files

✓Installing ransomware

❖Example

✓WannaCry (2017) :A worm that spread through Windows SMB vulnerability,


encrypting files and demanding ransom

05/01/2026 Andargie Mekonnnen 9


Malicious Code
Spyware is software that secretly monitors user behavior and sends data to a
third party without permission.

❖Key Characteristics
✓ Often installed without user awareness.
✓ Runs silently in the background.
✓ Can steal personal or financial information.

❖How Spyware Works


✓Installed Silently → Monitors Activity → Sends Data to Attacker

05/01/2026 Andargie Mekonnnen 10


Malicious Code
❖Types of Spyware
✓Keyloggers – Record keystrokes (e.g., passwords).
✓Adware – Displays unwanted ads and tracks behavior.
✓Tracking Cookies – Monitor browsing habits.
✓Screen Capture Software – Sends screenshots to attackers.
❖Example
✓A browser extension that secretly records login details.

05/01/2026 Andargie Mekonnnen 11


Malicious Code
Rootkit: Malware designed to hide its presence and other malware from detection.
✓Spread: Exploits, phishing, bundled software.
✓Characteristics: Stealthy, hard to detect, gains privileged system access.
Adware: Displays unwanted advertisements, often bundled with free software.
✓Spread: Software bundling, deceptive installers, malicious ads.
✓Characteristics: Floods ads, tracks browsing, slows system, not always malicious.
Backdoor: Method of bypassing normal authentication to gain remote access.
✓Spread: Often installed via trojans, exploits, or by malware.
✓Characteristics: Hidden access point, enables future attacks, persistent.
05/01/2026 Andargie Mekonnnen 12
Malicious Code
Ransomware: Malware that encrypts files and demands payment (ransom) for
decryption.
✓Spread: Email attachments, exploit kits, RDP attacks, malicious ads.
✓Characteristics: File encryption, ransom notes, often uses cryptocurrency
payments.
RAT (Remote Access Trojan): Malware that allows attackers to remotely control
an infected system.
✓Spread: Disguised as legitimate software, phishing, drive-by downloads.
✓Characteristics: Hidden operation, remote control, surveillance capability.
05/01/2026 Andargie Mekonnnen 13
Malicious Code
Keylogger: Records keystrokes to steal passwords, messages, and other sensitive
input.
✓Spread: Trojan horses, phishing, malicious downloads.
✓Characteristics: Stealthy logging, stores/sends keystroke data.
Cryptojacking: Unauthorized use of a victim’s computing resources to mine
cryptocurrency.
✓Spread: Malicious websites, infected ads, trojans.
✓Characteristics: Slows system, high CPU usage, runs hidden in browser or OS.

05/01/2026 Andargie Mekonnnen 14


Malicious Code
WireMDSG
Note: This is less common and may refer to:
✓A specific malware variant (possibly Wirenet/MDSG) targeting passwords.
✓Or a typo/abbreviation.
✓If it's Wirenet malware:
✓Definition: Trojan stealing saved passwords from browsers and email clients.
✓Spread: Email attachments, software cracks.
✓Characteristics: Targets macOS/Linux, extracts credentials, sends to C&C server.

05/01/2026 Andargie Mekonnnen 15


Malicious Code
Summary:
Type Needs User Action? Replicates? Main Goal Example
Virus Yes Yes Damage files, spread ILOVEYOU
Trojan Yes No Hide malicious intent Fake game that installs spyware
Worm No Yes Spread fast, disrupt networks WannaCry
Spyware No No Monitor and steal data Keylogger

Real-Life Example:
A student downloads a cracked software:
o It contains a Trojan → installs a backdoor.
o Attackers use it to install spyware → keylogger steals passwords.
o Later a worm spreads through the university network.
o Their files eventually get corrupted by a virus attached to documents.
This shows how different types of malicious code can combine to cause major damage.
05/01/2026 Andargie Mekonnnen 16
Class of Attacks
Computer attacks can be classified based on the attacker’s goal, method, or target.
Understanding these classes helps in designing effective defenses.
❖The main classes include:
✓ Reconnaissance (Information Gathering)
✓ Access (Unauthorized Access)
✓ Denial of Service (DoS) / Distributed Denial of Service (DDoS)

05/01/2026 Andargie Mekonnnen 17


Class of Attacks
Reconnaissance (Information Gathering) attacks are the initial stage of
a cyberattack, where an attacker gathers information about the target system, network, or
organization to find weaknesses.
❖Objective:
✓Identify vulnerabilities in systems or applications.
✓Collect useful information like IP addresses, domain names, network topology,
open ports, employee information, etc.

❖Techniques/Examples:
✓Footprinting: Using public sources (WHOIS, websites, social media) to gather
information about the target.
05/01/2026 Andargie Mekonnnen 18
Class of Attacks
✓Scanning: Using tools like Nmap to discover open ports and services.
✓Social Engineering: Gathering sensitive information from people, e.g., via phishing
emails.
❖Example:
✓An attacker uses Nmap to scan a company’s network and discovers an outdated
web server with known vulnerabilities. This information is then used for a potential
exploit.

05/01/2026 Andargie Mekonnnen 19


Class of Attacks
Access (Unauthorized Access) attacks occur when an
attacker attempts to gain unauthorized entry into a system, network, or
data.
❖Objective:
✓Gain control of systems or accounts.
✓Steal sensitive information like passwords, financial data, or personal records.

05/01/2026 Andargie Mekonnnen 20


Class of Attacks
❖Techniques/Examples:
✓Password Attacks: Brute force, dictionary attacks, or credential stuffing.
✓Exploiting Software Vulnerabilities: Taking advantage of unpatched software
bugs.
✓Backdoors and Trojans: Malicious software that grants access to attackers.
❖Example:
❖An attacker guesses weak passwords of employees’ accounts and logs into the
company’s internal system to steal confidential documents.

05/01/2026 Andargie Mekonnnen 21


Class of Attacks
Denial of Service (DoS) / Distributed Denial of Service (DDoS) attacks
aim to make a system, network, or service unavailable to legitimate users.
❖Objective:
✓ Overload the target system’s resources.
✓ Disrupt business operations or services.
❖Techniques/Examples:
✓ DoS Attack: Flooding a server with requests from a single source.
✓ DDoS Attack: Using multiple compromised systems (botnets) to flood a target simultaneously.
✓ Ping of Death / SYN Flood: Exploiting protocol weaknesses to crash systems.
❖Example: A popular website becomes unreachable because thousands of requests from a
botnet overwhelm its servers.
05/01/2026 Andargie Mekonnnen 22
Class of Attacks
Other Classes (Optional )
✓ Man-in-the-Middle (MitM): Intercepting communication between two parties to
eavesdrop or modify data.
✓ Malware Attacks: Using viruses, worms, ransomware, spyware, etc., to damage or
steal data.
✓ SQL Injection / Web Attacks: Exploiting web application vulnerabilities to access
databases.
✓ Physical Attacks: Unauthorized physical access to servers, computers, or storage
devices.

05/01/2026 Andargie Mekonnnen 23


Class of Attacks
Summary table
Class of Attack Objective Example
Reconnaissance Gather information Nmap scanning, social engineering
Password guessing, exploiting
Access Gain unauthorized entry
vulnerabilities
Denial of Service (DoS) Make system/service unavailable DDoS attack on website
Man-in-the-Middle Intercept/modify communication Eavesdropping on network traffic
Malware Damage/steal data Ransomware, virus
Web Application Attack Exploit application vulnerabilities SQL injection
Theft of hard drives, server
Physical Attack Gain access to physical resources
tampering

05/01/2026 Andargie Mekonnnen 24


Program Flaws
Program flaws are weaknesses or mistakes in software code that can be exploited by
attackers to compromise the security of a system. Identifying and correcting these flaws
is crucial for software security.
A buffer overflow occurs when a program writes more data to a buffer (a
temporary storage area) than it can hold, overwriting adjacent memory.
❖Impact:
✓ Can cause program crashes.
✓ May allow attackers to execute arbitrary code.
✓ Can lead to system compromise.

05/01/2026 Andargie Mekonnnen 25


Program Flaws
❖Example: A program has a buffer that stores 10 characters. If the user inputs 20
characters, the extra characters can overwrite adjacent memory and potentially allow
malicious code execution.
❖Prevention:
✓Properly validate input lengths.
✓Use safe functions that check boundaries (e.g., strncpy in C instead of strcpy).
✓Employ modern languages or frameworks with automatic bounds checking.

05/01/2026 Andargie Mekonnnen 26


Program Flaws
Time-of-Check to Time-of-Use (TOCTOU) Flaws: occur when a program checks a
condition (time-of-check) but the condition changes before the program actually uses the
resource (time-of-use).
❖Impact:
✓ Can allow attackers to bypass security checks.

✓ May result in unauthorized access or privilege escalation.

❖Example:
✓A program checks if a user has permission to access a file.
✓Between the check and actual file access, an attacker replaces the file with a malicious
one.
✓The program unknowingly executes or modifies the malicious file.
❖Prevention:
✓ Use atomic operations where checking and using resources happen together.

✓ Implement proper locking mechanisms to prevent changes between check and use.

05/01/2026 Andargie Mekonnnen 27


Program Flaws
Incomplete mediation occurs when a program fails to fully validate access or inputs,
allowing attackers to bypass security checks.
❖Impact:
✓ Unauthorized access to resources or data.
✓ Can be exploited to escalate privileges or corrupt data.

❖Example:A web application checks user permissions only at login but does not verify
them for each action. A user might manipulate URLs to access restricted data.
❖Prevention:
✓ Validate every access to resources, not just at initial authentication.
✓ Use centralized access control mechanisms.

05/01/2026 Andargie Mekonnnen 28


Program Flaws
❖Summary Table:
Program Flaw Definition / Impact Example Prevention
Writing beyond Validate input
Inputting 20 chars
Buffer Overflow buffer limits; may lengths, safe
into a 10-char buffer
execute code functions
Condition changes
Replacing a file after Atomic operations,
TOCTOU Flaws between check and
permission check locking mechanisms
use
Bypassing
Incomplete Security checks not permission checks Validate every
Mediation applied consistently via URL access, cent
manipulation

05/01/2026 Andargie Mekonnnen 29


Controls to Protect Against Program Flaws in Execution
Program flaws, if left unmitigated, can be exploited to compromise systems. Various
controls can be applied to reduce the risk of exploitation during program execution.
Operating system (OS) support and administrative controls are
mechanisms provided by the OS and organizational policies to enforce security and prevent
exploitation of program flaws.
❖Key Concepts and Techniques:
1. Memory Protection:
✓ OS ensures that each process has access only to its allocated memory.
✓ Prevents one process from overwriting memory used by another process.
✓ Helps mitigate buffer overflow attacks.
05/01/2026 Andargie Mekonnnen 30
Controls to Protect Against Program Flaws in Execution
✓Example: Modern OSs like Windows, Linux, and macOS use virtual memory and
segmentation to isolate processes.
2. Privilege Separation:
✓Programs run with the minimum privileges needed to perform their tasks.
✓Limits the impact if a program is exploited.
✓Example: A web server runs as a low-privilege user instead of an administrator.
3. Access Control Mechanisms:
✓OS enforces rules about which users or processes can access files, memory, or
devices.
✓Prevents unauthorized resource use that could exploit program flaws.
05/01/2026 Andargie Mekonnnen 31
Controls to Protect Against Program Flaws in Execution
[Link] Controls (Policies and Procedures):
✓Security policies define how software should be installed, updated, and monitored.
✓Procedures ensure that patches are applied promptly and system configurations follow
security best practices.
✓Regular audits and monitoring detect unusual behavior that might indicate
exploitation attempts.
Example:
✓Enforcing strong password policies and user permissions.
✓Restricting software installation to trusted administrators.

05/01/2026 Andargie Mekonnnen 32


Controls to Protect Against Program Flaws in Execution
5. Logging and Auditing:
✓ OS logs system events, errors, and access attempts.
✓ Helps administrators detect attacks targeting program flaws.

Summary Table
Control Type Purpose / How it Helps Example
Isolate process memory, prevent
Memory Protection Virtual memory, segmentation
overflow exploits
Limit damage from exploited Running services as non-admin
Privilege Separation
programs users
File permissions, device access
Access Control Mechanisms Enforce proper resource access
rules
Ensure policies, procedures, and Patch management, security
Administrative Controls
patching audits
System logs, intrusion detection
Logging and Auditing Detect exploitation attempts
systems (IDS)
05/01/2026 Andargie Mekonnnen 33
Program Security Defences
Program security defences are strategies and measures applied during software
development and operation to prevent exploitation of program flaws. These defenses
reduce vulnerabilities and enhance the overall security of software systems.
Software development controls are practices incorporated during the software
development lifecycle to prevent, detect, and mitigate security vulnerabilities. Testing
techniques verify that the software is secure and functions correctly.
❖Key Controls:
[Link] Coding Practices:
✓ Writing code to prevent common vulnerabilities such as buffer overflows, SQL injections, and cross-
site scripting (XSS).
✓ Example: Validating input, using parameterized
05/01/2026 queries for databases.
Andargie Mekonnnen 34
Program Security Defences
2. Code Reviews and Peer Reviews:
✓Developers review each other’s code to identify flaws, errors, and security weaknesses.
✓Helps catch mistakes that automated tools might miss.
[Link] Analysis (Source Code Analysis):
✓Tools analyse source code without executing it to find potential vulnerabilities.
✓Example tools: SonarQube, Fortify.
[Link] Analysis (Runtime Testing):
✓Tests the program while it is running to find vulnerabilities that only appear during
execution.
✓Example: Fuzz testing, penetration testing.
05/01/2026 Andargie Mekonnnen 35
Program Security Defences
[Link] Testing and Integration Testing:
✓Ensures individual modules work correctly and interact securely with other modules.
[Link] Management:
✓Applying updates and patches promptly to fix known vulnerabilities.
✓Example: During development of a web application, developers implement input
validation, perform code reviews, and use automated testing tools to identify and fix
security flaws before deployment.

05/01/2026 Andargie Mekonnnen 36


Program Security Defences
Database Management Systems (DBMS) Security: DBMS security refers to
measures that protect the confidentiality, integrity, and availability of data stored in
databases. Databases are often critical targets for attackers, so securing them is essential.
❖Key Security Measures:
[Link] Control:
✓Only authorized users can access or modify database records.
✓Use role-based access control (RBAC) or discretionary access control (DAC).
[Link] and Authorization:
✓Strong password policies, multi-factor authentication (MFA), and permissions
management ensure only legitimate users access data.
05/01/2026 Andargie Mekonnnen 37
Program Security Defences
Database Management Systems (DBMS) Security
[Link] Encryption: Encrypt data at rest (stored in the database) and in transit (when transmitted
over networks).
[Link] and Recovery: Regular backups protect against data loss from attacks or system
failures.
[Link] Trails and Logging: Track database activity to detect unauthorized access or suspicious
behaviour.
[Link] Injection Prevention: Use prepared statements, parameterized queries, and input validation
to prevent attackers from manipulating database queries.
✓Example: An e-commerce site’s database uses encrypted passwords, role-based access for
administrators and employees, and logs all login attempts to detect suspicious activity.
05/01/2026 Andargie Mekonnnen 38
Program Security Defences
Summary
Defense Area Purpose / How it Helps Example
Secure Coding Practices Prevent common vulnerabilities Input validation, parameterized queries
Identify flaws missed by individual
Code Reviews & Peer Reviews Peer code review sessions
developers
Static Analysis Detect potential vulnerabilities in code Tools like SonarQube, Fortify
Find vulnerabilities during program
Dynamic Analysis Fuzz testing, penetration testing
execution
Ensure modules function correctly and
Unit & Integration Testing Testing modules in isolation & together
securely
Patch Management Fix known vulnerabilities promptly Updating software libraries & frameworks
DBMS Access Control Restrict data access to authorized users Role-based access control (RBAC)
Authentication & Authorization Verify user identity and permissions Strong passwords, MFA
Data Encryption Protect data confidentiality AES encryption for stored data
Backup & Recovery Prevent permanent data loss Daily backups to secure storage
Logging login attempts and database
Audit Trails & Logging Detect unauthorized activity
changes
SQL Injection Prevention Prevent query manipulation Prepared statements, input validation
05/01/2026 Andargie Mekonnnen 39
THE END!
THANK YOU!
QUESTIONS?
05/01/2026 Andargie Mekonnnen 40

You might also like