Unit 2 of 4 · M.Sc IT Sem 4

Unit 2: Malware and attacks

Information Security and Cyber Law notes · PTU syllabus (PGCA1932)

3 min read4 topics8 exam questions
On this page
  1. Unit summary
  2. Types of malicious software
  3. Spam, phishing, zombies and bots
  4. Preventive measures
  5. Denial-of-service attacks
  6. Key terms
  7. Quick revision
  8. Important questions

Unit summary

Malicious software and denial-of-service attacks are the most common threats faced by organisations. This unit covers viruses, worms, spam, Trojans, zombies, bots, keyloggers, phishing, spyware, backdoors and rootkits with preventive measures, and DoS attack types and defences.

After this unit you can

  • Describe the types of malicious software
  • Explain social-engineering attacks such as phishing and spam
  • Apply preventive measures against malware
  • Explain DoS and DDoS attacks and defences

PTU syllabus topics

  • Types of malicious software — viruses
  • worms
  • spam
  • Trojans
  • zombies
  • bots
  • keyloggers
  • phishing
  • spyware
  • backdoors
  • rootkits
  • preventive measures
  • denial-of-service attack types and defenses
ClassificationMalware family
Malicious software
  • Virus

    Needs a host file

  • Worm

    Self-replicates over networks

  • Trojan

    Disguised as useful software

  • Rootkit

    Hides deep in the system

  • Spyware and keylogger

    Steals information

  • Bot

    Part of a remote-controlled botnet

1

Topic 1

Types of malicious software

ComparisonMalware types
How it works
Example

Virus

Attaches to a host program and spreads when it runs

File infectors, macro viruses

Worm

Self-replicates across networks without a host

WannaCry (2017)

Trojan horse

Pretends to be useful but hides malicious code

Fake app installers

Ransomware

Encrypts data and demands payment

LockBit, WannaCry

Spyware and keyloggers

Secretly collect information

Banking credential stealers

Rootkit and backdoor

Hide presence; give hidden access

Kernel rootkits

Logic bomb

Triggers on a condition or date

Code deleting files on a set date

ProcessPhases of a virus
  1. 1Dormant

    Idle, waiting

  2. 2Propagation

    Copies itself into other programs

  3. 3Triggering

    Activated by an event

  4. 4Execution

    Performs its payload

  • Virus types: boot sector, file infector, macro, polymorphic (changes code with each infection), stealth, metamorphic.
  • Countermeasures: antivirus and EDR (signature, heuristic and behaviour-based detection), patching, least privilege, backups, user awareness.
2

Topic 2

Spam, phishing, zombies and bots

Key termsOther threats
Spam
Unsolicited bulk e-mail; carrier for malware and scams
Phishing
Fake messages or sites stealing credentials — spear phishing (targeted), whaling (executives), smishing (SMS), vishing (voice)
Zombie
Compromised computer controlled remotely
Botnet
Network of zombies under a command-and-control server, used for DDoS, spam, crypto-mining
Keylogger
Records keystrokes
Spyware and adware
Covert monitoring; intrusive ads
Backdoor
Hidden entry bypassing authentication
Rootkit
Hides malware deep in the OS or firmware
3

Topic 3

Preventive measures

FrameworkMalware defence
  • Prevention

    Patching, least privilege, application whitelisting, disabling macros

  • Detection

    Antivirus (signature, heuristic, behaviour), EDR, e-mail filtering

  • Awareness

    Training to spot phishing; verify links and senders

  • Recovery

    Offline backups (3-2-1 rule), incident response plan, reimaging

4

Topic 4

Denial-of-service attacks

  • DoS makes a service unavailable by exhausting bandwidth, server resources or application capacity; DDoS uses many sources (botnets).
ComparisonDoS attack types
Mechanism
Example

Flooding

Overwhelms bandwidth with traffic

ICMP flood, UDP flood

SYN flood

Half-open TCP connections exhaust the connection table

Spoofed SYN packets

Reflection and amplification

Small spoofed request triggers large reply to the victim

DNS, NTP, memcached amplification

Application layer

Expensive requests to web apps

HTTP GET floods, Slowloris

Distributed

Thousands of bots attack together

Mirai botnet (2016)

ProcessDoS defence
  1. 1Prevention

    Over-provisioning, rate limiting, SYN cookies, ingress filtering (BCP 38)

  2. 2Detection

    Traffic monitoring for anomalies

  3. 3Response

    Filter at upstream ISP, scrubbing centres, CDN and DDoS protection services

  4. 4Recovery

    Restore service; analyse and harden

Key terms

Worm
Self-replicating malware spreading without a host
Botnet
Network of compromised machines controlled remotely
Phishing
Deceptive messages to steal credentials
SYN flood
DoS exhausting half-open TCP connections
Amplification attack
Spoofed small requests causing large replies to the victim

Quick revision

  • Virus, worm, Trojan, ransomware, spyware, rootkit, backdoor, logic bomb.
  • Spam, phishing variants, zombies, bots, keyloggers.
  • Prevention, detection, awareness, recovery.
  • Flooding, SYN, amplification, application-layer, DDoS; defences.

Important exam questions

Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).

Short-answer questions

  1. Q1.Distinguish a virus and a worm.
  2. Q2.What is a rootkit?
  3. Q3.What is spear phishing?
  4. Q4.What is a botnet?
  5. Q5.How does a SYN flood work?
  6. Q6.Name two DoS defences.

Long-answer questions

  1. Q1.Explain the types of malicious software and preventive measures.
  2. Q2.Explain denial-of-service attacks and their defences.

Stuck on this unit?

Message SBS on WhatsApp for help with Information Security and Cyber Law, or to ask about studying M.Sc IT at Synetic.

WhatsApp us