Unit 2: Malware and attacks
Information Security and Cyber Law notes · PTU syllabus (PGCA1932)
On this page
Unit summary
Malicious software and denial-of-service attacks are the most common threats faced by organisations. This unit covers viruses, worms, spam, Trojans, zombies, bots, keyloggers, phishing, spyware, backdoors and rootkits with preventive measures, and DoS attack types and defences.
After this unit you can
- Describe the types of malicious software
- Explain social-engineering attacks such as phishing and spam
- Apply preventive measures against malware
- Explain DoS and DDoS attacks and defences
PTU syllabus topics
- Types of malicious software — viruses
- worms
- spam
- Trojans
- zombies
- bots
- keyloggers
- phishing
- spyware
- backdoors
- rootkits
- preventive measures
- denial-of-service attack types and defenses
Virus
Needs a host file
Worm
Self-replicates over networks
Trojan
Disguised as useful software
Rootkit
Hides deep in the system
Spyware and keylogger
Steals information
Bot
Part of a remote-controlled botnet
Topic 1
Types of malicious software
Virus
Attaches to a host program and spreads when it runs
File infectors, macro viruses
Worm
Self-replicates across networks without a host
WannaCry (2017)
Trojan horse
Pretends to be useful but hides malicious code
Fake app installers
Ransomware
Encrypts data and demands payment
LockBit, WannaCry
Spyware and keyloggers
Secretly collect information
Banking credential stealers
Rootkit and backdoor
Hide presence; give hidden access
Kernel rootkits
Logic bomb
Triggers on a condition or date
Code deleting files on a set date
- 1Dormant
Idle, waiting
- 2Propagation
Copies itself into other programs
- 3Triggering
Activated by an event
- 4Execution
Performs its payload
- Virus types: boot sector, file infector, macro, polymorphic (changes code with each infection), stealth, metamorphic.
- Countermeasures: antivirus and EDR (signature, heuristic and behaviour-based detection), patching, least privilege, backups, user awareness.
Topic 2
Spam, phishing, zombies and bots
- Spam
- Unsolicited bulk e-mail; carrier for malware and scams
- Phishing
- Fake messages or sites stealing credentials — spear phishing (targeted), whaling (executives), smishing (SMS), vishing (voice)
- Zombie
- Compromised computer controlled remotely
- Botnet
- Network of zombies under a command-and-control server, used for DDoS, spam, crypto-mining
- Keylogger
- Records keystrokes
- Spyware and adware
- Covert monitoring; intrusive ads
- Backdoor
- Hidden entry bypassing authentication
- Rootkit
- Hides malware deep in the OS or firmware
Topic 3
Preventive measures
Prevention
Patching, least privilege, application whitelisting, disabling macros
Detection
Antivirus (signature, heuristic, behaviour), EDR, e-mail filtering
Awareness
Training to spot phishing; verify links and senders
Recovery
Offline backups (3-2-1 rule), incident response plan, reimaging
Topic 4
Denial-of-service attacks
- DoS makes a service unavailable by exhausting bandwidth, server resources or application capacity; DDoS uses many sources (botnets).
Flooding
Overwhelms bandwidth with traffic
ICMP flood, UDP flood
SYN flood
Half-open TCP connections exhaust the connection table
Spoofed SYN packets
Reflection and amplification
Small spoofed request triggers large reply to the victim
DNS, NTP, memcached amplification
Application layer
Expensive requests to web apps
HTTP GET floods, Slowloris
Distributed
Thousands of bots attack together
Mirai botnet (2016)
- 1Prevention
Over-provisioning, rate limiting, SYN cookies, ingress filtering (BCP 38)
- 2Detection
Traffic monitoring for anomalies
- 3Response
Filter at upstream ISP, scrubbing centres, CDN and DDoS protection services
- 4Recovery
Restore service; analyse and harden
Key terms
- Worm
- Self-replicating malware spreading without a host
- Botnet
- Network of compromised machines controlled remotely
- Phishing
- Deceptive messages to steal credentials
- SYN flood
- DoS exhausting half-open TCP connections
- Amplification attack
- Spoofed small requests causing large replies to the victim
Quick revision
- Virus, worm, Trojan, ransomware, spyware, rootkit, backdoor, logic bomb.
- Spam, phishing variants, zombies, bots, keyloggers.
- Prevention, detection, awareness, recovery.
- Flooding, SYN, amplification, application-layer, DDoS; defences.
Important exam questions
Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).
Short-answer questions
- Q1.Distinguish a virus and a worm.
- Q2.What is a rootkit?
- Q3.What is spear phishing?
- Q4.What is a botnet?
- Q5.How does a SYN flood work?
- Q6.Name two DoS defences.
Long-answer questions
- Q1.Explain the types of malicious software and preventive measures.
- Q2.Explain denial-of-service attacks and their defences.
Stuck on this unit?
Message SBS on WhatsApp for help with Information Security and Cyber Law, or to ask about studying M.Sc IT at Synetic.
