What is Cyber Security?
  • Cybersecurity or cyber safety is described as security for systems connected to the Internet. It strengthens the safety of hardware, software and data, helps prevent data theft, and keeps documents/files safe.
  • Cyber + Security: “Cyber” relates to the Internet, information technology, computers, networks, applications and data; “Security” relates to protection.
  • The source includes system security, network security, application security and information security under the broader security idea.
Cyber Security overview visual
Source-derived visual: cyber security protects online systems, data, hardware and software.
Why Cyber Security is Needed

Personal Data

Images, PDFs, text documents and other personal data stored on computers.

Protection of personal data stored on a computer.

Copyright / Company Data

Protect data owned by a person or company from theft or unauthorized use.

Protection of copyrighted or company data from theft or misuse.

Banking & Financial

Protect banking and financial information as Internet banking is widely used.

Protection of banking and financial data.

National Security

Protect sensitive defence and government-office data from cyber attacks or leakage.

Protection of sensitive defence and government data.

Introduction & Meaning of “Cyber”
  • The term cyber security refers to security offered through online services to protect online information.
  • As more people connect to the Internet, security threats that can cause major harm also increase.
  • CYBER: a combining form related to information technology, the Internet and virtual reality.
  • Need: to protect data from theft or misuse and to safeguard systems from viruses.
Revision noteThis chapter follows the supplied PDF’s Chapter 13 content and terminology. Misleading malware definitions and policy references have been corrected.
Major Security Problems
VirusHackerMalwareTrojan horsesPassword cracking
Major cyber security threats visual
Five major security problems listed in the source.
Virus & Worms
  • A virus attaches to host files/programs and replicates when infected code runs. A worm can spread independently across networks.
  • Solution in source: install a security suite that protects the computer against threats such as viruses and worms.
Hacker
  • A hacker is described as a person who breaks into a computer by gaining administrative control.
  • Prevention mentions strong passwords and firewalls as effective security controls.
How to Prevent Hacking
Strong PasswordStrong passwords
FirewallProtection against unauthorized attacks
Security ControlsEffective security controls
Types of Hackers
White Grey and Black hat hackers
The source lists White Hat, Grey Hat and Black Hat hackers.

White Hat

Authorized security testing, within the agreed scope.

Grey Hat

May probe without authorization but not necessarily with malicious intent; lack of permission still matters.

Black Hat

Malicious, unauthorized activity for theft, damage or exploitation.

Malware
  • The word malware comes from malicious software.
  • It is described as software that infects and damages a computer system without the owner’s knowledge or permission.
  • Source prevention points: download an anti-malware program and activate network threat protection, firewall and antivirus.
Trojan Horses
  • A Trojan horse disguises malicious functionality as legitimate software. It is not a virus and does not self-replicate by definition; it can arrive through downloads, attachments or other routes.
  • How to avoid: security suites such as Avast Internet Security are mentioned as a way to prevent downloading Trojan horses.
Source wording alert
Virus = host-dependent replication; worm = independent replication; Trojan = deceptive software. These are different malware categories.
Password Cracking
  • Password attacks are described as attacks carried out by hackers who determine or find passwords for protected electronic areas and social networking sites.
Cyber Security Strategy — India
Cyber security strategy India source visual
Items listed by the source under “Cyber Security Strategy — India”.

Policy & Law

Security policy and legal framework: Information Technology Act, 2000; Information Technology (Amendment) Act, 2008; National Cyber Security Policy, 2013.

Capacity Building

Skills and competence development.

Research & Development

Research and development.

Monitoring & Network

Cyber monitoring • network security.

Adware & Backdoorr
Adware

Software displaying advertisements. Some adware is unwanted or malicious and can track users or redirect browsers; it is not always harmless.

Backdoor

Opens a backdoor into a computer to provide a connection for other malware, viruses, spam or hackers.

Cyber Terms — Part I
Cracking

Gaining access into a system specifically to commit a crime.

Hacking

When someone breaks into a computer or network.

Hacktivism

Hacking for politically or ideologically motivated reasons.

Hijackware

Malware that changes browser settings to redirect users to malicious sites or show advertisements; also called a browser hijacker.

Hoax

A false or misleading warning/message, often spread through chain messages. Hoaxes can cause harm through misinformation or unsafe actions.

Keylogger

Spyware or hardware that tracks and records keystrokes, especially passwords and credit-card information.

Malware

Any “malicious software” designed to secretly access a computer.

Password Sniffing / Password Stealer

Malware that examines network traffic to find usernames and passwords.

Phishing & Related Attacks
Phishing types diagram
Phishing family exactly as grouped in the supplied source.
Pharming

Website traffic is redirected to a bogus website, usually an e-commerce or banking site.

Phishing

Cybercriminals try to obtain sensitive information such as credit-card numbers and passwords.

Phreaking

Phone networks are hacked to make free calls or charge calls to a different account.

Piggybacking

Gaining network access by using a legitimate user’s connection, often when the user leaves without logging out.

More Cyber Terms
Polymorphic Virus

Changes its digital footprint every time it replicates to evade antivirus software.

Pwned

Having appropriated or gained control of an email address or other cyber personal information.

Ransomware

Malware that encrypts data or locks computers until a ransom is paid.

Rogue Security Software

Malware pretending to be malware-removal software.

Rootkit

Tools that conceal malicious activity and help maintain privileged access; a rootkit is not merely a file disguised with an ordinary filename.

Sextortion

Blackmail schemes threatening to distribute sensitive or embarrassing private material unless a ransom is paid or sexual images/favors are provided.

Malicious sniffing

Unauthorized capture/inspection of network traffic. Packet sniffers also have legitimate diagnostic uses; encryption protects content but not every metadata field.

Spoofing

Masquerading as a trusted source. Source examples: email spoofing, IP spoofing and address-bar spoofing.

Spyware

Malware that gathers information about a user, often to track Internet use and deliver pop-up ads.

Time Bomb / Logic Bomb

Time Bomb executes at a specific time/date; Logic Bomb executes when specified criteria are met.

Virus

Malware that copies itself and infects a computer and files.

Wardriving

Driving around to exploit or collect data from unsecured Wi-Fi networks.

Worm

Malware that self-replicates and sends itself to other computers in a network.

Zombie

A compromised computer/device controlled remotely by an attacker, often as part of a botnet; “zombie” names the device, not the malware.

Quick Recall
Core idea
Cyber Security protects Internet-connected systems, hardware, software and data from theft, misuse and attacks.
TermSource cue
VirusProgram/malware that infects system/files.
WormSelf-replicates and sends itself to other computers.
MalwareMalicious software.
Trojan HorseMalware disguised as legitimate software; not self-replicating by definition.
HackerBreaks into a computer/network.
White / Grey / Black HatAuthorized testing / unauthorized probing without necessarily malicious intent / malicious unauthorized activity.
Password CrackingFinding protected passwords.
PhishingObtaining sensitive information.
SMiShingPhishing via text messages.
VishingVoice/phone phishing.
RansomwareEncrypts data or locks computer until ransom is paid.
RootkitConceals malicious activity and helps maintain privileged access.
KeyloggerRecords keystrokes.
SpoofingMasquerading as a trusted source.
WardrivingCollecting/exploiting data from unsecured Wi-Fi while driving around.
Exam Trap
Phishing ≠ Pharming: source frames phishing as trying to get sensitive information from users, while pharming redirects website traffic to a bogus site.
Exam Trap
Time Bomb ≠ Logic Bomb: source distinguishes a specific time/date trigger from a specified-condition trigger.