Images, PDFs, text documents and other personal data stored on computers.
Protection of personal data stored on a computer.
Protect data owned by a person or company from theft or unauthorized use.
Protection of copyrighted or company data from theft or misuse.
Protect banking and financial information as Internet banking is widely used.
Protection of banking and financial data.
Protect sensitive defence and government-office data from cyber attacks or leakage.
Protection of sensitive defence and government data.
Authorized security testing, within the agreed scope.
May probe without authorization but not necessarily with malicious intent; lack of permission still matters.
Malicious, unauthorized activity for theft, damage or exploitation.
Security policy and legal framework: Information Technology Act, 2000; Information Technology (Amendment) Act, 2008; National Cyber Security Policy, 2013.
Skills and competence development.
Research and development.
Cyber monitoring • network security.
Software displaying advertisements. Some adware is unwanted or malicious and can track users or redirect browsers; it is not always harmless.
Opens a backdoor into a computer to provide a connection for other malware, viruses, spam or hackers.
Gaining access into a system specifically to commit a crime.
When someone breaks into a computer or network.
Hacking for politically or ideologically motivated reasons.
Malware that changes browser settings to redirect users to malicious sites or show advertisements; also called a browser hijacker.
A false or misleading warning/message, often spread through chain messages. Hoaxes can cause harm through misinformation or unsafe actions.
Spyware or hardware that tracks and records keystrokes, especially passwords and credit-card information.
Any “malicious software” designed to secretly access a computer.
Malware that examines network traffic to find usernames and passwords.
Website traffic is redirected to a bogus website, usually an e-commerce or banking site.
Cybercriminals try to obtain sensitive information such as credit-card numbers and passwords.
Phone networks are hacked to make free calls or charge calls to a different account.
Gaining network access by using a legitimate user’s connection, often when the user leaves without logging out.
Changes its digital footprint every time it replicates to evade antivirus software.
Having appropriated or gained control of an email address or other cyber personal information.
Malware that encrypts data or locks computers until a ransom is paid.
Malware pretending to be malware-removal software.
Tools that conceal malicious activity and help maintain privileged access; a rootkit is not merely a file disguised with an ordinary filename.
Blackmail schemes threatening to distribute sensitive or embarrassing private material unless a ransom is paid or sexual images/favors are provided.
Unauthorized capture/inspection of network traffic. Packet sniffers also have legitimate diagnostic uses; encryption protects content but not every metadata field.
Masquerading as a trusted source. Source examples: email spoofing, IP spoofing and address-bar spoofing.
Malware that gathers information about a user, often to track Internet use and deliver pop-up ads.
Time Bomb executes at a specific time/date; Logic Bomb executes when specified criteria are met.
Malware that copies itself and infects a computer and files.
Driving around to exploit or collect data from unsecured Wi-Fi networks.
Malware that self-replicates and sends itself to other computers in a network.
A compromised computer/device controlled remotely by an attacker, often as part of a botnet; “zombie” names the device, not the malware.
| Term | Source cue |
|---|---|
| Virus | Program/malware that infects system/files. |
| Worm | Self-replicates and sends itself to other computers. |
| Malware | Malicious software. |
| Trojan Horse | Malware disguised as legitimate software; not self-replicating by definition. |
| Hacker | Breaks into a computer/network. |
| White / Grey / Black Hat | Authorized testing / unauthorized probing without necessarily malicious intent / malicious unauthorized activity. |
| Password Cracking | Finding protected passwords. |
| Phishing | Obtaining sensitive information. |
| SMiShing | Phishing via text messages. |
| Vishing | Voice/phone phishing. |
| Ransomware | Encrypts data or locks computer until ransom is paid. |
| Rootkit | Conceals malicious activity and helps maintain privileged access. |
| Keylogger | Records keystrokes. |
| Spoofing | Masquerading as a trusted source. |
| Wardriving | Collecting/exploiting data from unsecured Wi-Fi while driving around. |