Learning Objectives
By the end of this lesson, you will be able to:
- Describe the processes involved in, and the aim of carrying out, a range ofcyber security threats
- Explainbrute-force attacks,data interception,DDoS attacks,hacking, andmalware(viruses, worms, Trojan horses, spyware, adware and ransomware)
- Explainpharming,phishingandsocial engineering
- Explain how a range of solutions are used to help keep data safe from security threats, including:access levels,anti-malware(anti-virus and anti-spyware),authentication(username and password, biometrics, two-step verification),automating software updates,checking the spelling and tone of communications,firewalls,privacy settings,proxy servers, andSecure Socket Layer (SSL)
Key Terms
Cyber Security Threat
Any possible malicious attack that seeks to unlawfully access data, disrupt digital operations or damage information.
Brute-Force Attack
Uses trial-and-error to guess login info, encryption keys or find a hidden web page by working through all possible combinations.
Data Interception
Where data is intercepted during transmission using software called a packet sniffer that examines data packets as they travel around a network.
DDoS Attack
Distributed Denial of Service — an attempt at preventing users from accessing part of a network by flooding it with useless traffic.
Hacking
The act of gaining illegal access to a computer system without the owner's consent or knowledge.
Cracking
Where someone edits a program source code to find a back door in the software so the code can be exploited for a specific purpose.
Malware
Software specifically designed to disrupt, damage or gain unauthorised access to a computer system.
Virus
A piece of code that replicates itself and causes damage to computer systems by inserting its own code.
Worm
A subset of Trojan horse malware that can propagate or self-replicate from one computer to another without human activation.
Trojan Horse
A type of malware that downloads onto a computer disguised as a legitimate program.
Spyware
Software with malicious behaviour that gathers information about a person or organisation and sends it to another entity.
Adware
Malware that displays unwanted advertisements on a computer or mobile device.
Ransomware
Malware designed to deny access to files by encrypting them and demanding a ransom payment for the decryptor.
Pharming
Installing malicious code on a user's hard drive or web server to redirect the user to a fake website without their knowledge.
Phishing
Sending out legitimate-looking emails that trick users into clicking a link or attachment that leads to a fake website.
Social Engineering
The act of exploiting human weaknesses to gain access to personal information and protected systems.
Access Level
A type of permission that provides control over what data a user can access and what actions they are allowed to perform.
Anti-Malware
Software designed to detect, block and remove malware from a computer system.
Authentication
The process of verifying the identity of a user during the access process.
Biometrics
Authentication based on physiological characteristics such as fingerprints or retina scans, or behavioural characteristics such as typing patterns and voice recognition.
Two-Step Verification
Requires users to provide two authentication factors: something the user knows, something the user has, or something the user is.
Firewall
Software or hardware that sits between a user's computer and an external network, filtering information in and out.
Proxy Server
A system or router that acts as an intermediary between users and the internet, providing security and caching.
SSL
Secure Socket Layer — a protocol that allows data to be sent and received securely over the internet through encryption.
Privacy Settings
Controls within a browser or application that determine what information is shared and with whom.
1. What is Cyber Security?
Cyber security threatsrefer to any possible malicious attack that seeks to unlawfully access data, disrupt digital operations or damage information. Cyber threats can originate from various actors, including corporate spies, hacktivists, terrorist groups, hostile nation-states, criminal organisations, lone hackers and disgruntled employees.
High-Profile Cyber Attacks
- 2017 Equifax breach— compromised the personal data of roughly 143 million consumers, including birth dates, addresses and social security numbers.
- 2018 Marriott International breach— hackers accessed its servers and stole the data for roughly 500 million customers.
- In both instances, the cyber security threat was enabled by the organisation's failure to implement, test and re-test technical safeguards such asencryption,authenticationandfirewalls.
Cyber attackers can use an individual's or a company's sensitive data to steal information or gain access to their financial accounts, among other potentially damaging actions — which is why cyber security professionals are essential for keeping private data protected.
Activity 1: Cyber Security Basics
- Define the term "cyber security threat". [2]
- Give three examples of actors who might carry out a cyber attack. [3]
- Explain why organisations must implement technical safeguards. [2]
Solution:
- A cyber security threat is any possible malicious attack [1] that seeks to unlawfully access data, disrupt digital operations or damage information [1].
- Corporate spies [1]. Hacktivists or terrorist groups [1]. Criminal organisations or lone hackers [1].
- To protect against data breaches [1]. Failure to do so can allow attackers to steal personal and financial data [1].
Check Your Understanding: Cyber Security
1. What is a cyber security threat? [2 marks]
- [1]Any possible malicious attack
- [1]That seeks to unlawfully access data, disrupt digital operations or damage information
2. Name two high-profile cyber attacks mentioned in the lesson. [2 marks]
- [1]The 2017 Equifax breach
- [1]The 2018 Marriott International breach
3. Give two technical safeguards that organisations should implement. [2 marks]
- [1]Encryption
- [1]Authentication / Firewalls
4. Why is it important to test and re-test technical safeguards? [2 marks]
- [1]New vulnerabilities are discovered over time
- [1]Failure to keep safeguards updated can allow attackers to steal data
5. What can cyber attackers do with stolen sensitive data? [2 marks]
- [1]Steal information
- [1]Gain access to financial accounts
2. Types of Cyber Security Threats
- Hackers start with the most common passwords (e.g. 12345678, password, qwerty, 1234).
- Depending on password length and complexity, cracking takes from seconds to years.
- Old method but still effective and popular with hackers.
- Hackers gain personal data, hijack systems, and can ruin a website's reputation.
- The packet sniffer examines data packets as they are sent around a network or across the internet.
- Information gathered is sent back to a hacker.
- The attacker reads information without the user's knowledge.
- Acts as a proxy to read and insert false information into the communication.
- Usually temporary but can be very damaging.
- One method is toflood the network with useless traffic.
- Prevents access to websites and online services (e.g. banking).
- An internet server can only handle a finite number of requests; once exceeded, it can't service legitimate users.
- Can also target a user's email account by sending hundreds of messages, clogging it up.
- Can lead to identity theft or gaining personal information.
- Data can be deleted, changed or corrupted.
- Note:Encryption doesn't stop hacking — it just makes data useless, but a hacker can still delete or corrupt the data.
- Protection: firewalls, strong passwords, user IDs, anti-hacking software.
- Virus— replicates itself and inserts its own code into other files.
- Worm— self-replicates across a network without human activation.
- Trojan Horse— disguises itself as legitimate software.
- Spyware— gathers information and sends it to another entity.
- Adware— displays unwanted advertisements.
- Ransomware— encrypts files and demands payment for the decryptor.
- Redirects the user to a fake/bogus website without their knowledge.
- The creator can gain personal data such as bank account numbers.
- Can lead to fraud or identity theft.
- Protection:Anti-spyware software, look for HTTPS and the padlock sign in the URL.
- Emails often use large well-known companies (e.g. banks) to convince customers the email is authentic.
- The creator can gain personal data such as bank account numbers.
- Can lead to fraud or identity theft.
- Protection:Many ISPs filter out phishing emails; users should always be careful when opening emails or attachments.
Malware in Detail
Virus
A program or program code that can replicate/copy itself with the intention of deleting or corrupting files, or cause the computer to malfunction. Can cause the computer to crash, stop functioning normally, become unresponsive, delete files/data or corrupt files/data.
Worm
A subset of Trojan horse malware that can propagate or self-replicate from one computer to another without human activation after breaching a system. Typically spreads across a network through your Internet or LAN connection.
Trojan Horse
A type of malware that downloads onto a computer disguised as a legitimate program. Attackers hide malicious code within legitimate software to gain users' system access. Often delivered via an email attachment.
Spyware
Software with malicious behaviour that aims to gather information about a person or organisation and send it to another entity in a way that harms the user — for example, by violating their privacy or endangering their device security.
Adware
Malware that displays unwanted advertisements on a computer or mobile device.
Ransomware
Malware designed to deny a user or organisation access to files on their computer. It encrypts files and demands a ransom payment for the decryptor. Organisations are placed in a position where paying the ransom is the easiest and cheapest way to regain access to their files.
Activity 2: Cyber Security Threats
- Explain what is meant by a brute-force attack. [2]
- Describe how data interception works. [2]
- Explain the difference between a virus and a worm. [3]
- Describe what a Trojan horse is. [2]
Solution:
- A brute-force attack uses trial-and-error to guess login info [1]. Hackers work through all possible combinations hoping to guess correctly [1].
- Data interception uses a packet sniffer [1]. The sniffer examines data packets as they travel around a network and sends the information back to a hacker [1].
- A virus replicates itself by inserting its code into other files [1]. A worm self-replicates from one computer to another without human activation [1]. A worm spreads across a network through an internet or LAN connection [1].
- A Trojan horse is malware that downloads onto a computer disguised as a legitimate program [1]. Attackers hide malicious code within legitimate software to gain system access [1].
Check Your Understanding: Cyber Threats
1. What is a DDoS attack? [2 marks]
- [1]An attempt to prevent users from accessing part of a network
- [1]Usually by flooding the network with useless traffic
2. What is phishing? [2 marks]
- [1]Sending out legitimate-looking emails to trick users
- [1]The user clicks a link/attachment and is sent to a fake website to steal personal data
3. What is ransomware? [2 marks]
- [1]Malware that encrypts files and denies access to them
- [1]Demands a ransom payment for the decryptor to regain access
4. Explain the difference between hacking and cracking. [2 marks]
- [1]Hacking is breaking into a computer system to steal personal data without the owner's consent
- [1]Cracking is editing a program's source code to find a back door so the code can be exploited or changed for a specific purpose
5. What is social engineering? [2 marks]
- [1]The act of exploiting human weaknesses to gain access to personal information and protected systems
- [1]Relies on manipulating individuals rather than hacking computer systems
6. Describe two things a user can do to protect against a Trojan horse. [2 marks]
- [1]Never open or download email attachments from unknown sources
- [1]Delete these messages before opening them to remove the threat
3. Keeping Data Safe from Security Threats
Access Levels
- A type of permission that controls what data a user can access and what actions they are allowed to perform.
- Administrator:Full access to the system.
- Standard:Limited access to the system.
- Guest:No access to the system.
Anti-Malware (Anti-Virus & Anti-Spyware)
- Anti-virusscans your device for known viruses and monitors the behaviour of all programs, notifying if any suspicious behaviour is detected.
- Goal is to block and remove all malware as quickly as possible.
- Real-time scanning:continuously scans the system and reacts to threats as they are encountered.
- Automatic updates:updates the system once new malware is found.
- Remove threats:removes malware found on the system.
Anti-Malware Detection Techniques
- Signature-based detection:uses a set of known software components and their digital signatures to identify previously identified malicious behaviour.
- Behaviour-based detection:identifies malicious software by examining how it behaves, rather than what it looks like.
- Sandboxing:an isolated environment from the rest of the system used to test potentially malicious files and remove them before they can do damage.
- Traffic filtering:blocks access to suspicious servers and sites involved with malware distribution.
- Proactive security:scans, detects and removes known threats such as spyware, Trojans and adware.
Authentication
- Username and password:the most popular authentication scheme. Both are checked against a secure file to confirm identity.
- Biometrics:based on physiological characteristics (fingerprint, retina scans) or behavioural characteristics (typing patterns, voice recognition). Scans are matched against a saved database.
- Two-step verification (2FA):requires two authentication factors — something the user knows (password/PIN), something the user has (ID card, smartphone), or something the user is (fingerprint, eye scan).
Firewalls
- Can be eithersoftwareorhardware.
- Sits between the user's computer and an external network (e.g. the internet) and filters information in and out.
- Checks whether incoming or outgoing data meets a given set of criteria.
- If data fails the criteria, the firewall blocks the traffic and gives a warning.
- Logs all incoming and outgoing traffic for later interrogation.
- Keeps a list of undesirable IP addresses to block.
- Helps prevent viruses or hackers from entering the computer or internal network.
Privacy Settings
- Controls within a browser or application that determine what information is shared and with whom.
- Users can control what information sites can use and show (location, camera, pop-ups, etc.).
- Includes options for clearing browsing data, cookies, cache.
- Chrome's safety check helps keep users safe from data breaches, bad extensions and more.
Proxy Servers
- Acts as an intermediary between the user and a web server.
- Prevents direct access to the web server; if an attack is launched, it hits the proxy server instead.
- Can filter traffic and direct invalid traffic away from the web server.
- Uses a cache to speed up access to previously visited websites.
- Keeps the user's IP address secret, improving security.
Secure Socket Layer (SSL)
- A protocol (set of rules) that allows data to be sent and received securely over the internet.
- When a user logs onto a website, SSL protects the data — only the user's computer and the web server can make sense of what is transmitted.
- A user knows SSL is being applied when they see thepadlockin the address bar.
- Uses include: online shopping/payment systems, email, cloud-based storage, intranet/extranet, VPN, video chat, social media, online gaming, instant messaging.
How SSL Works — 5 Steps
How a Firewall Works
Checking the Spelling and Tone of Communications
- Malicious emails can be difficult to identify, but there are steps to determine whether emails are legitimate or fake.
- Check the sender's email address and domain name — a suspicious email address could be similar to a real one (e.g. missing letters).
- Verify that you know the sender and that the email is from the company it claims to be.
- Look for grammatical errors or typos.
- Consider what is being offered — if it looks too good to be true, it may be a phishing email.
- Most companies do not ask for sensitive or personal information in an email.
- Hover over links on a computer to find out their real destination; if it doesn't match the link displayed, assume it's unsafe and don't click it.
Activity 3: Keeping Data Safe
- Name the three access levels and explain what each allows. [3]
- Describe two authentication methods. [4]
- Explain how a firewall helps keep data safe. [3]
- Describe the role of SSL in keeping data safe. [3]
Solution:
- Administrator [1]:Full access to the system.Standard [1]:Limited access to the system.Guest [1]:No access to the system.
- Username and password [2]:The most popular authentication scheme. Both are checked against a secure file to confirm identity.Biometrics [2]:Uses physiological characteristics (fingerprint or retinal scans) or behavioural characteristics (typing patterns and voice recognition). Scans are matched against a saved database.
- Sits between the user's computer and an external network [1]. Checks whether incoming or outgoing data meets a given set of criteria [1]. Blocks traffic that fails the criteria and gives a warning [1].
- SSL is a protocol that allows data to be sent and received securely over the internet [1]. When a user logs onto a website, SSL protects the data [1]. Only the user's computer and the web server are able to make sense of what is transmitted [1].
Check Your Understanding: Keeping Data Safe
1. What are access levels? [2 marks]
- [1]A type of permission that controls what data a user can access
- [1]And what actions they are allowed to perform
2. What is sandboxing? [2 marks]
- [1]An isolated environment from the rest of the system
- [1]Used to test potentially malicious files and remove them before they cause damage
3. Describe two-step verification. [2 marks]
- [1]Requires two authentication factors
- [1]A combination of something the user knows, something the user has, or something the user is
4. Give two functions of a proxy server in a security system. [2 marks]
- [1]Prevents direct access to the web server / if an attack is launched it hits the proxy server instead
- [1]Traffic is examined/filtered / invalid traffic is declined
5. How can a user tell that a website is using SSL? [1 mark]
- [1]A padlock sign appears in the address bar / the URL starts with https://
6. Why should users check the spelling and tone of emails? [2 marks]
- [1]Phishing emails often contain grammatical errors or typos
- [1]Checking helps users identify whether an email is legitimate or fake, avoiding data theft
Key Takeaways
- Cyber security threatsare malicious attacks that seek to access data, disrupt operations or damage information.
- Brute-force attacksuse trial-and-error to guess passwords or encryption keys.
- Data interceptionuses packet sniffers to read data during transmission.
- DDoS attacksflood a network with useless traffic to prevent legitimate access.
- Hackingis gaining illegal access;crackingis editing source code to exploit software.
- Malwareincludes viruses (replicate and insert code), worms (self-replicate across networks), Trojan horses (disguised as legitimate), spyware (gather information), adware (unwanted ads) and ransomware (encrypts files for ransom).
- Pharmingredirects users to fake websites;phishinguses fake emails to steal data;social engineeringexploits human weaknesses.
- Access levels(Administrator, Standard, Guest) control what users can access and do.
- Anti-malwareuses signature-based detection, behaviour-based detection, sandboxing, traffic filtering and proactive security.
- Authenticationincludes username/password, biometrics (fingerprints, retina scans) and two-step verification.
- Firewallsfilter incoming and outgoing traffic based on criteria and block anything suspicious.
- Proxy serversact as intermediaries, protect web servers, cache content and keep IP addresses secret.
- SSLencrypts data sent over the internet and is indicated by a padlock in the browser.
- Users shouldcheck the spelling and toneof emails to avoid phishing attacks.
Question Bank
1. Viruses, pharming and phishing are all examples of potential internet security issues. Explain what is meant by each of these three terms. [6 marks]
- [1]Virus — a program that replicates itself
- [1]With the intention of deleting or corrupting files, or causing the computer to malfunction
- [1]Pharming — malicious code installed on a hard drive or web server
- [1]Which redirects the user to a fake website without their knowledge
- [1]Phishing — sending out legitimate-looking emails
- [1]That trick the user into clicking a link/attachment to a fake website
2. (a) Explain what is meant by a denial of service attack. [2 marks]
- [1]An attempt to prevent users from accessing part of a network
- [1]By flooding it with useless traffic / sending more requests than the server can handle
2. (b) Name and describe two other potential security threats when using the internet. [4 marks]
- [1]Brute-force attack — uses trial-and-error to guess login info
- [1]Hackers work through all possible combinations hoping to guess correctly
- [1]Phishing — legitimate-looking emails
- [1]Trick the user into clicking a link to a fake website that steals personal data
3. Describe the role of a web browser in requesting and displaying the web pages for a website. [3 marks]
- [1]Sends a request to the web server
- [1]Receives web pages back from the web server
- [1]Converts HTML to display the web page
4. A company stores personal details of its customers on a computer system behind a firewall. Explain, with reasons, what else the company should do to keep this data safe. [6 marks]
- [1]Use encryption — so that if data is intercepted it is meaningless to the hacker
- [1]Use strong passwords / authentication — to prevent unauthorised access
- [1]Use access levels — to restrict what employees can access
- [1]Install anti-malware software — to detect and remove malicious software
- [1]Keep software up to date — to fix security vulnerabilities
- [1]Use a proxy server — to prevent direct access to the web server
5. Six statements about firewalls are shown. Tick to show whether each statement is true or false. [6 marks]
- Firewalls can monitor incoming and outgoing traffic →True
- Firewalls operate by checking traffic against a set of rules →True
- Firewalls can prevent malicious and other cyber attacks →True
- Firewalls can't run unless a set of rules is defined →False
- Firewalls can be software →True
- Firewalls can be hardware →True
6. Online banking is increasing in popularity. Online banking can be a risk as it can raise a number of security issues. SSL can be used as a security method to make online banking safer. Identify and describe three other security methods that could be used to make online banking safer. [6 marks]
- [1]Two-step verification — requires two authentication factors
- [1]Such as something the user knows and something the user has
- [1]Encryption — encodes data so it can only be read by authorised parties
- [1]So if intercepted, data is meaningless without the decryption key
- [1]Anti-malware software — detects and removes malicious software
- [1]That could be used to steal login details or financial information
7. Explain how a proxy server can help keep a web server safe from attack. [3 marks]
- [1]Prevents direct access to the web server / sits between user and web server
- [1]If an attack is launched it hits the proxy server instead of the web server
- [1]Traffic is examined/filtered and invalid traffic is declined
8. Describe the difference between a virus and a worm. [3 marks]
- [1]A virus inserts its own code into other files to replicate
- [1]A worm self-replicates without human activation
- [1]A worm typically spreads across a network through an internet or LAN connection
9. What is the difference between anti-virus and anti-malware? [2 marks]
- [1]Anti-virus software scans for known viruses and detects new threats of infection
- [1]Anti-malware provides broader protection against all types of malware including spyware, Trojans, adware and ransomware
10. How does facial recognition work as an authentication method? [3 marks]
- [1]A picture of your face is captured from a photo or video
- [1]Facial recognition software recognises the geometry of your face
- [1]A facial signature is computed and compared to a database of known faces to make a determination