0% found this document useful (0 votes)
18 views54 pages

Understanding Security Threats and Malware

This document discusses various cybersecurity threats faced by businesses and ways to prevent them. It talks about security threats like insider threats, viruses, worms, phishing attacks, drive-by downloads, exploit kits and malvertising. It provides details on what each of these threats are and how they can damage organizations. The document also recommends various measures organizations can take to prevent these security threats like limiting employee access, training users, implementing two-factor authentication, updating antivirus software, not downloading suspicious files etc. It discusses that malware can affect both Windows and Mac devices and outlines steps to prevent malware infections.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
18 views54 pages

Understanding Security Threats and Malware

This document discusses various cybersecurity threats faced by businesses and ways to prevent them. It talks about security threats like insider threats, viruses, worms, phishing attacks, drive-by downloads, exploit kits and malvertising. It provides details on what each of these threats are and how they can damage organizations. The document also recommends various measures organizations can take to prevent these security threats like limiting employee access, training users, implementing two-factor authentication, updating antivirus software, not downloading suspicious files etc. It discusses that malware can affect both Windows and Mac devices and outlines steps to prevent malware infections.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

GROUP 5

Security & Privacy


Data & Privacy:
Contents
What You Need to Know

• Responses of Business Companies and Security Threats


• Damages of Malware and Combating Malware
• Philippines Laws on Computer Internet Crimes
Responses of
Business
Companies and
Reporters
Adrian Dulay
Diether
Security Threats
Lontoc
A Security Threat is a malicious act that aims to corrupt or steal
data or disrupt an organization's systems or the entire
organization. A security event refers to an occurrence during
which company data or its network may have been exposed and
an event that results in a data or network breach is called a
security incident.
Insider Threats

An insider threat occurs when individuals close to an organization who have


authorized access to its network intentionally or unintentionally misuse that access to
negatively affect the organization's critical data or systems.
Ways to prevent Insider Threats:
•Limit employees access to only the specific resources they need to do their jobs.

·Train new employees and contractors on security awareness before allowing them to access the
network. Incorporate information about unintentional and malicious insider threat awareness into
regular security training

·Set up contractors and other freelancers with temporary accounts that expire on specific dates, such
as the dates their contracts end

·Implement two-factor authentication, which requires each user to provide a second piece of
identifying information in addition to a password.

·Install employee monitoring software to help reduce the risk of data breaches and the theft of
intellectual property by identifying careless, disgruntled or malicious insiders.
Viruses and
Viruses and worms are malicious software programs (malware) aimed at destroying an
organization's systems, dataworms
and network. A computer virus is a malicious code that replicates
by copying itself to another program, system or host file. It remains dormant until someone
knowingly or inadvertently activates it, spreading the infection without the knowledge or
permission of a user or system administration.?

A computer worm is a self-replicating program that doesn't have to copy itself to a host
program or require human interaction to spread. Its main function is to infect other computers
while remaining active on the infected system. Worms often spread using parts of an
operating system that are automatic and invisible to the user. Once a worm enters a system, it
immediately starts replicating itself, infecting computers and networks that aren't adequately
protected.
Preventing viruses and worms

To reduce the risk of these types of information security threats caused by viruses
or worms,
companies should install antivirus and antimalware software on all their systems
and networked devices and keep that software up to date. In addition,
organizations must train users not to download attachments or
click on links in emails from unknown senders and to avoid downloading free
software from untrusted
Phishing attacks?
Phishing attacks are a type of information security threat that employs social engineering to trick
users into breaking normal security practices and giving up confidential information, including names,
addresses, login credentials, Social Security numbers, credit card information and other financial
information. In most cases, hackers send out fake emails that look as if they're coming from legitimate
sources, such as financial institutions, eBay, PayPal -- and even friends and colleagues.

In phishing attacks, hackers attempt to get users to take some recommended action, such as clicking on
links in emails that take them to fraudulent websites that ask for personal information or install malware
on their devices. Opening attachments in emails can also install malware on users' devices that are
designed to harvest sensitive information, send out emails to their contacts or provide remote access to
their devices.
Preventing phishing attacks

Enterprises should train users not to download attachments


or click on links in emails from unknown senders and avoid
downloading free software from untrusted websites.
Drive-by Download Attacks
In a drive-by download attack, malicious code is downloaded from
a website via a browser, application or integrated operating system
without a user's permission or knowledge. A user doesn't have to
click on anything to activate the download. Just accessing or
browsing a website can start a download. Cybercriminals can use
drive-by downloads to inject banking Trojans, steal and collect
personal information as well as introduce exploit kits or other
malware to endpoints.
Prevention for Drive-by Download
Attacks

One of the best ways a company can prevent drive-by download attacks
is to regularly update and patch systems with the latest versions of
software, applications, browsers, and operating systems. Users should
also be warned to stay away from insecure websites. Installing security
software that actively scans websites can help protect endpoints from
drive-by downloads.
Exploit Kits

An exploit kit is a programming tool that enables a person without any


experience writing software code to create, customize and distribute malware.
Exploit kits are known by a variety of names, including infection kit,
crimeware kit, DIY attack kit and malware toolkit. Cybercriminals use these
toolkits to attack system vulnerabilities to distribute malware or engage in
other malicious activities, such as stealing corporate data, launching denial of
service attacks or building botnets.
Preventing Exploit Kits

Deploy antimalware software as well as a security program that continually


evaluates if its security controls are effective and provide protection against
attacks.

Install antiphishing tools because many exploit kits use phishing or


compromised websites to penetrate the network.
Malvertising
Malvertising is a technique cybercriminals use to inject malicious code into
legitimate online advertising networks and web pages. This code typically
redirects users to malicious websites or installs malware on their computers or
mobile devices. Users' machines may get infected even if they don't click on
anything to start the download. Cybercriminals may use malvertising to deploy
a variety of moneymaking malware, including cryptomining scripts,
ransomware and banking Trojans.
Preventing APT attacks

To prevent malvertising, ad networks should add validation; this reduces the


chances a user could be compromised. Validation could include: Vetting
prospective customers by requiring legal business paperwork; two-factor
authentication; scanning potential ads for malicious content before publishing
an ad; or possibly converting Flash ads to animated gifs or other types of
content.
To mitigate malvertising attacks, web hosts should periodically check their
websites from an unpatched system and monitor that system to detect any
malicious activity. The web hosts should disable any malicious ads.

To reduce the risk of malvertising attacks, enterprise security teams should be


sure to keep software and patches up to date as well as install network
antimalware tools.
Damages of
Malware and
Combating
Reporters
Michael Ray
Mabini
Malware
Bren Francisco
Hardware Failure and
Data Loss or Data
Theft
What You Need to Know?

• How to prevent Malware infections?


• Does Malware affect MACS?
• Does Malware affect mobile devices?
How to prevent Malware?
• By using caution when using their computers or other personal devices, users may
avoid infection. This includes not opening attachments from unfamiliar email
addresses since they could include malware that looks like a valid file and come
from unreliable email domains. Such emails might even seem to be from reputable
businesses.
• Users should routinely update their anti-malware programs since hackers are
always coming up with new ways to circumvent security measures. Vendors of
security software respond by publishing updates that fix such flaws. Users risk
missing out on a patch that would have protected them against an avoidable
exploit if they fail to upgrade their software.
In enterprise settings, networks are larger than home networks, and there is more at stake
financially. There are proactive steps companies should take to enforce malware
protection. Outward-facing precautions include the following:
•Implementing dual approval for business-to-business (B2B) transactions; and
•Implementing second-channel verification for business-to-consumer (B2C)
transactions.
Business-facing, internal precautions include the following:
•Implementing offline malware and threat detection to catch malicious software
before it spreads;
•Implementing allow list security policies whenever possible; and
•Implementing strong web browser-level security.
Does malware affect macs?
•Malware can affect Macs as well as Windows. Historically, Windows devices are
considered to be a larger target for malware than Macs, in part because users can
download applications for macOS through the App Store.
•The company Malwarebytes reported in 2020 that for the first time ever, malware
on Macs is outpacing malware on PCs. This is in part due to the popularity of Apple
devices, drawing more attention from hackers.
Does malware affect mobile
devices?
•Malware can be found on mobile phones and can provide access to a device's components such as the
camera, microphone, GPS or accelerometer. Malware can be contracted on a mobile device if a user
downloads an unofficial application or clicks on a malicious link from an email or text message. A mobile
device can also be infected through a Bluetooth or Wi-Fi connection.
•Mobile malware more commonly found on devices that run the Android OS than iOS. Malware on Android
devices is usually downloaded through applications. Signs that an Android device is infected with malware
include unusual in data usage, a quickly dissipating battery charge, or calls, texts and emails being
increasessent to the device contacts without the user's initial knowledge. Similarly, if a user receives a
message from a recognized contact that seems suspicious, it may be from a type of mobile malware that
spreads between devices.
•Apple iOS devices are rarely infected with malware because Apple vets the applications sold in the App
Store. However, it is still possible for an iOS device to be infected with malicious code by opening an
unknown link found in an email or text message. iOS devices will also become more vulnerable if jailbroken
What is malware?
Malware, or malicious software, is any program or file that is
intentionally harmful to a computer, network or server. Types of
malware include computer viruses, worms, Trojan horses,
ransomware and spyware.

These malicious programs steal, encrypt and delete sensitive


data; alter or hijack core computing functions and monitor end
users' computer activity.
What does malware do?
Malware can infect networks and devices and is designed to harm those
devices, networks and/or their users in some way.
Depending on the type of malware and its goal, this harm may present
itself differently to the user or endpoint.

No matter the method, all types of malware are designed to exploit


devices at the expense of the user and to the benefit of the hacker -- the
person who has designed and/or deployed the malware.
How do
malware
infections
happen?
Malware authors use a variety of physical and virtual
means to spread malware that infects devices and
networks.

For example, malicious programs can be delivered to a system


with a USB drive, through popular collaboration tools and by
drive-by downloads, which automatically download malicious
programs to systems without the user's approval or knowledge.
History of malware
The term malware was first used by computer scientist and security
researcher Yisrael Radai in 1990. However, malware existed long
before this.

One of the first known examples of malware was the Creeper virus in 1971, which
was created as an experiment by BBN Technologies engineer Robert Thomas.
Creeper was designed to infect mainframes on ARPANET. While the program did
not alter functions or steal or delete data, it moved from one mainframe to another
without permission while displaying a teletype message that read, "I'm the creeper:
Catch me if you can." Creeper was later altered by computer scientist Ray
Tomlinson, who added the ability to self-replicate to the virus and created the first
known computer worm.

Raymond Tomlinson
What are the different types of
malware?
• Virus is the most common type of malware that can execute itself and spread by
infecting other programs or files.

• Worm can self-replicate without a host program and typically spreads without any
interaction from the malware authors.

• Trojan horse is designed to appear as a legitimate software program to gain access


to a system. Once activated following installation, Trojans can execute their
malicious functions.

• Spyware collects information and data on the device and user and observes the
user's activity without their knowledge.
What are the different types of malware?
• Ransomware - is software that uses encryption to disable a target’s access to its data until a
ransom is paid. The victim organization is rendered partially or unable to operate until it pays,
but there is no guarantee that payment will result in the necessary decryption key or that the
decryption key provided will function properly.

• rootkit – a type of malware designed to give hackers access to and control over a target device
giving threat actors root or privileged access to the system.

• Adware - Adware tracks a user's browser and download history with the intent to display pop-
up or banner advertisements that lure the user into making a purchase. For example, an
advertiser might use cookies to track the web pages a user visits to better target advertising.

• Keyloggers, also called system monitors, track nearly everything a user does on their computer.
This includes emails, opened webpages, programs and keystrokes.
How to detect
• Users may be able to detect malwaremalware?
if they observe an unusual activity such as a sudden loss
of disk space, unusually slow speeds, repeated crashes or freezes, or an increase in unwanted
internet activity and pop-up advertisements.

• Antivirus and antimalware software may be installed on a device to detect and remove
malware. These tools can provide real-time protection or detect and remove malware by
executing routine system scans.

• Windows Defender, for example, is Microsoft antimalware software included in the Windows
10 operating system (OS) under the Windows Defender Security Center. Windows Defender
protects against threats such as spyware, adware, and viruses. Users can set automatic "Quick"
and "Full" scans, as well as set low, medium, high, and severe priority alerts.
How to remove
malware?
• Malwarebytes is an example of an antimalware tool that
handles the detection and removal of malware. It can remove
malware from Windows, macOS, Android, and iOS platforms.
Malwarebytes can scan a user's registry files, running
programs, hard drives, and individual files. If detected,
malware can then be quarantined and deleted. However, unlike
some other tools, users cannot set automatic scanning
schedules.
Philippines
Laws on
Reporters
Computer
Internet Crimes
Sherdelle
Cañeda
Hazel
Introductio
n or “Cybercrime Prevention Act of 2012” which
The Philippine Congress enacted Republic Act No. 10175
addresses crimes committed against and through computer systems on 12 September 2012. It includes penal
substantive rules, procedural rules and also rules on international cooperation.

Amendatory bills on cybercrime investigations are under work in the Philippines, with new provisions being
introduced on procedural powers, responsibilities, and extradition. The aim is for the amendments to provide
a structured approach for prosecutors and investigators on cybercrime investigations and to further align
national legislation with the Budapest Convention.

In India, The Information Act, 2000 was enacted to regulate cyber crimes. The Act is based on the United
Nations Model law on electronic commerce, 1996 recommended by the General Assembly of the United
Nations in the year 1997. The Information Act, 2000 was later amended in the year 2008to improve certain
provisions of the original Act.
Cybercrime Prevention act of
Philippines
The Fundamentals of the
Act
Cybercrime also called computer crime is the use of a computer as an instrument to further illegal ends
such as committing fraud trafficking child pornography, intellectual property violations, stealing
identities or violation of privacy. The difference between traditional criminal offences from
cybercrime is the use of the computer in committing such offences. Majorlycybercrime is an attack on
the information of Individuals, governments or corporations.

To combat and prevent cybercrime, the government of the Philippines introduced the Republic Act
No.101175 or Cyber Prevention Act of 2012. This Act was signed by the President of the Philippines
Mr. Benigno Aquino on September 12th of 2012. The original goal of this Act was to penalize acts like
cybersex, child pornography, identity theft etc.
The key provisions of the Cybercrime
Prevention Act of 2012
There are sixteen types of cybercrime covered under the Cybercrime Prevention Act of
2012.
Illegal Access:
Access to a computer or any application without permission.

Illegal Interception:
Interception of any non-public communication of computer
data to, from, or within a computer system by an unauthorised
person.

Data Interference:
Unauthorized tampering with, destroying, deleting, or
deteriorating computer data, electronic documents, or
electronic data messages, as well as the introduction or
transmission of viruses. This provision can also cover
authorised activity if the person’s behaviour went beyond the
agreed-upon scope and resulted in the damages listed in this
provision.
Misuse of devices:

Unauthorized use, possession, production, sale, procurement, importation, distribution, or otherwise


making available of gadgets, computer programmes, or other materials developed or adapted for
committing any of the acts listed in Republic Act 10175. Unauthorized use of a computer password,
access code, or similar data that allows the entire or a portion of a computer system to be accessed with
the intent of using it to perpetrate any of the offences listed in Republic Act 10175.

Cybersquatting:

Acquisition of a domain name in bad faith on the internet to profit, deceive, harm reputation, and prevent
others from registering it. This includes trademarks that were already registered at the time of registration,
names of people other than the registrant, and trademarks that were purchased with intellectual property
interests in them. Those who get domain names of prominent brands and individuals who in turn are used
to damage their reputation can be sued under this provision. Note that freedom of expression and
infringement on trademarks or names of persons are usually treated separately. A party can exercise
freedom of expression without necessarily violating the trademarks of a brand or the names of persons.
Computer related Forgery:

Unauthorized input, alteration, or deletion of computer data that results in inauthentic data with the
intent that it be considered or acted on for legal purposes as if it were authentic, regardless of whether
the data is directly readable and intelligible; or the act of knowingly using computer data that is the
product of computer-related forgery as defined here to perpetuate .

Computer-related Fraud:

Unauthorized access to, alteration of, or deletion of computer data or programmes, or interference
with the operation of a computer system, with the purpose to cause damage.

Computer-related Identity Theft:

Unauthorized acquisition, use, abuse, transfer, possession, change, or deletion of an individual’s


identifying information, whether natural or legal.
Cybersex:
For favour or consideration, willful engagement, maintenance, control, or operation,
directly or indirectly, of any lascivious presentation of sexual organs or sexual activity
via a computer system.

Child Pornography:
Unlawful or banned activities conducted through a computer system, as defined and
punished by Republic Act No. 9775 or the Anti-Child Pornography Act of 2009.
Cybersex: Child Pornography:

For favour or consideration, willful Unlawful or banned activities conducted


engagement, maintenance, control, or through a computer system, as defined and
operation, directly or indirectly, of any punished by Republic Act No. 9775 or the
lascivious presentation of sexual organs or Anti-Child Pornography Act of 2009.
sexual activity via a computer system.
Libel

Acts of libel that are illegal or forbidden under Article 355 of the Revised Penal
Code, as amended, and are committed using a computer system or any other
similar means that may be created in the future. Penal Code Revision According to
Article 355 Libel is defined as defamation of character by writings or other means.
Libel committed by writing, printing, lithography, engraving, radio, phonograph,
painting, theatrical exhibition, cinematographic exhibition, or any other similar
means is punishable by prison correctional for the minimum and medium periods,
or a fine ranging from 200 to 6,000 pesos, or both, in addition to any civil action
that the offended party may bring.
Aiding or Abetting in the commission of cybercrime:

Anyone who knowingly assists or abets the conduct of any of


the offences listed in this Act will be held accountable.

Attempt in the commission of cybercrime:

Any person who willfully attempts to commit any of the


offences enumerated in this Act shall be held liable.
All crimes defined and penalized by the Revised Penal Code, as
amended, and special laws, if committed by, through and with
the use of information and communications technologies shall be
covered by the relevant provisions of this Act.
Aiding or Attempt in the
Abetting in the commission of
commission of cybercrime:
cybercrime:
Anyone who knowingly assists or abets the Any person who willfully attempts to commit any of
conduct of any of the offences listed in this Act the offences enumerated in this Act shall be held liable.
will be held accountable.
All crimes defined and penalized by the Revised Penal
Code, as amended, and special laws, if committed by,
through and with the use of information and
communications technologies shall be covered by the
relevant provisions of this Act.
Corporate Liability:
(Section 9): When any of the punishable acts herein defined are knowingly committed on behalf of or
for the benefit of a juridical person by a natural person acting either individually or as part of an organ
of the juridical person who has a leading position within, based on: (a) a power of representation of the
juridical person provided the act committed falls within the scope of such authority; or (b) an authority
to make decisions on behalf of the juridical person. It also includes the commission of any of the penal
acts made possible due to the lack of supervision, provided that the act committed falls within the
scope of such authority; or(c) an authority to exercise control inside the juridical person.
Advantages and
Disadvantages of the
Cybercrime Prevention
Act of 2012
Cybersex, Cyberbullying, Child pornography are
now offences and such offenders can be
Advantages punished. The children’s rights are protected by
this Act.

All kinds of businesses using the internet as a


medium are protected by this Act.
Provisions of this act now define the offence of
cybersquatting and this deters people from the act
Advantages of cybersquatting.

Provisions that penalizes online identity theft.


This provision protects the individual’s privacy
and its protection.
Ambiguity in the terms given in the Act such as the
term online libel is not defined anywhere which can
lead to different interpretations. Ambiguity can be
seen in the provision of real-time data collection.

The implementation and execution of this Act


yearly cost a huge cost to the government.
Disadvantages
Disadvantages

The ambiguity in the Act may lead to the freedom of speech. The
ambiguities like the absence of a proper definition of online libel may
lead to confusion. Sometimes the expression of some truth may be
misinterpreted as Libel. People may be restrained from expressing
themselves.
Malpractice
a dereliction of professional duty or a failure to exercise an ordinary degree of
professional skill or learning by one (such as a physician) rendering
professional services which results in injury, loss, or damage.
Examples of Medical
Malpractice
• Failure to diagnose or misdiagnosis.
• Misreading or ignoring laboratory results.
• Unnecessary surgery.
• Surgical errors or wrong site surgery.
• Improper medication or dosage.
• Poor follow-up or aftercare.
• Premature discharge.
• Disregarding or not taking appropriate patient
history.
Philippine Activist Arrested for Cyber-
libel
Charges Against Walden Bello Spotlight Criminal Defamation
Laws
Philippine police on Monday arrested Walden Bello, a 76-year-old social
activist, academic, and former congressman, at his home in Quezon City on
charges of cyber-libel. The arrest was based on allegations by Jefry Tupas, a
former information officer for Vice President Sara Duterte. Bello spent the
night in jail before being released after paying bail.

Tupas, who worked for Duterte when she was mayor of Davao City,
filed two counts of cyber-libel against Bello in March for a Facebook
post alleging that Tupas was involved in illegal drugs after attending a
party in November 2021 that was raided by the police.
Bello, a leftist progressive voice well-known in the Philippines and Southeast Asia,
unsuccessfully ran for vice president in May. He used his candidacy as a platform to
highlight progressive and social justice issues during the campaign. He is a long-
time critic of the late Ferdinand Marcos, father of President Ferdinand Marcos Jr,
and of former President Rodrigo Duterte, father of Vice-President Duterte. Sara
Duterte denied any role in the libel case.
The Philippines’ cyber-libel law, passed in 2012, has been used several times against
journalists, columnists, critics of the government, and ordinary social media users.
The Office of Cybercrime at the Department of Justice reported that 3,700 cyber-
libel cases were filed as of May 2022.

You might also like