0% found this document useful (0 votes)
15 views21 pages

Understanding Cyber Attacks: Types & Risks

The document discusses cyber attacks, categorizing them into active and passive threats. Active attacks directly harm systems, including types like masquerade, modification of messages, repudiation, replay, and denial of service attacks, while passive attacks involve eavesdropping and traffic analysis without altering data. It emphasizes the importance of strong defense mechanisms and encryption to protect against these evolving cyber threats.

Uploaded by

akhilanalimela
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
15 views21 pages

Understanding Cyber Attacks: Types & Risks

The document discusses cyber attacks, categorizing them into active and passive threats. Active attacks directly harm systems, including types like masquerade, modification of messages, repudiation, replay, and denial of service attacks, while passive attacks involve eavesdropping and traffic analysis without altering data. It emphasizes the importance of strong defense mechanisms and encryption to protect against these evolving cyber threats.

Uploaded by

akhilanalimela
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

SECURITY ATTACKS

100522733082
100522733088
CYBER ATTACK
A cyber attack occurs when hackers try to penetrate
computer systems or networks with a personal agenda or
some purpose to damage or steal information by gaining
unauthorized access to computer systems. It can occur to
anyone, either companies or government agencies,
which can then have stolen data and financial [Link]
steal information by gaining unauthorized access to
computer systems. It can occur to anyone, either
companies or government agencies, which can then have
stolen data and financial losses.
• There are basically two forms of threats: active and
passive attacks. An active attack is an attack in which
attackers directly harm your computer systems. They
can create several problems, such as crashing files,
stealing data, etc. On the other hand, a Passive attack
refers to an attack in which the attackers quietly watch
and collect the information without your knowledge.
ACTIVE ATTACKS
• Active attacks are unauthorized actions that alter the
system or data. In an active attack, the attacker wil
directly interfere with the target to damage or gain
unauthorized access to computer systems and
networks. This is done by injecting hostile code into
communications, masquerading as another user, or
altering data to get unauthorized access. This may
include the injection of hostile code into
communications, alteration of data, and masquerading
as another person to get unauthorized access.
• Types of active attacks are as follows:
[Link] Attack

[Link] of Messages

[Link]

[Link] attacks

[Link] of Service Attacks(DoS)


Masquerade
• Masquerade attacks are considered one type of cyber
attack in which the attacker disguises himself to pose as
some other person and accesses systems or data. It
could either be impersonating a legal user or system
and demanding other users or systems to provide
information with sensitive content or access areas that
are not supposed to be accessed normally. This may
even include behaving like an actual user or even some
component of the system with the intention of
manipulating people to give out their private
information or allowing them into secured locations.
Modification of Messages
• This is when someone changes parts of a message
without permission, or mixes up the order of messages,
to cause trouble. Imagine someone secretly changing a
letter you sent, making it say something different. This
kind of attack breaks the trust in the information being
sent. For example, a message meaning “Allow JOHN to
read confidential file X” is modified as “Allow Smith to
read confidential file X”.
Repudiation
• Repudiation attacks are a type of cyber attack wherein
some person does something damaging online, such as
a financial transaction or sends a message one does not
want to send, then denies having done it. Such attacks
can seriously hinder the ability to trace down the origin
of the attack or to identify who is responsible for a given
action, making it tricky to hold responsible the right
person.
Replay
• It is a passive capturing of a message with an objective
to transmit it for the production of an authorized effect.
Thus, in this type of attack, the main objective of an
attacker is saving a copy of the data that was originally
present on that particular network and later on uses it
for personal uses. Once the data gets corrupted or
leaked it becomes an insecure and unsafe tool for its
users.
Denial of Service(DoS)
• Denial of Service (DoS) is a form of cybersecurity attack that involves
denying the intended users of the system or network access by flooding
traffic or requests. In this DoS attack, the attacker floods a target system
or network with traffic or requests in order to consume the available
resources such as bandwidth, CPU cycles, or memory and prevent
legitimate users from accessing them.
• There are several types of DoS attacks, including:
• Flood attacks: Here, an attacker sends such a large number of packets
or requests to a system or network that it cannot handle them all and the
system gets crashed.

• Amplification attacks: In this category, the attacker increases the


power of an attack by utilizing another system or network to increase
traffic then directs it all into the target to boost the strength of the attack.
PASSIVE ATTACKS
• A Passive attack attempts to learn or make use of information
from the system but does not affect system resources.
Passive Attacks are in the nature of eavesdropping on or
monitoring transmission. The goal of the opponent is to
obtain information that is being transmitted. Passive attacks
involve an attacker passively monitoring or collecting data
without altering or destroying it.
• Types of Passive attacks are as follows:
[Link] Release of Message Content

[Link] Analysis
The Release of Message Content
• A release of message content attack is an attack that
involves making confidential user data available to the
public over a network. Attackers can intercept
unprotected communication mediums like emails,
unencrypted data, and phone calls.
• Telephonic conversation, an electronic mail message, or
a transferred file may contain sensitive or confidential
information. We would like to prevent an opponent from
learning the contents of these transmissions.
Traffic Analysis
• Suppose that we had a way of masking (encryption)
information, so that the attacker even if captured the
message could not extract any information from the
message.
The opponent could determine the location and identity
of communicating host and could observe the frequency
and length of messages being exchanged. This
information might be useful in guessing the nature of
the communication that was taking place.
The most useful protection against traffic analysis is
encryption of SIP traffic. To do this, an attacker would
have to access the SIP proxy (or its call log) to
determine who made the call.
CONCLUSION
• The field of information security is challenged by both
active and passive attacks. Active attacks pose
significant risks, applying strong defense mechanisms
to prevent disruption and data loss. On the other side,
passive attacks emphasize the need to protect sensitive
information from unauthorized access through
encryption and user training. As cyber threats continue
to evolve and so our strategies must upgrade for
security and protection. By understanding the strategies
used by cybercriminals and implementing effective
security measures, individuals and organizations can
improve their defenses against both types of attacks,
ensuring the safety and integrity of their critical data.
THANK YOU

You might also like