胡文明
Increasing usage of the internet has also led to an increase in cyber-crimes/cyber-attacks. But how many types of cyber-attacks are you familiar with? In order to tackle cyber threats, you must be well aware of its nature.
What are cyber-attacks?
A cyber-attack is defined as an attack originated by a digital system against another digital device, website, or any other digital system and compromises1 its privacy, reliability or the data stored in it.
Not only these attacks are a threat to digital individuals but are a great threat to businesses as well.
Why are cyber-attacks initiated?
Before moving further to types of cyber-attacks, let us first have a look at the reasons for initiating cyber-attacks:
Acquiring unauthorized2 access to a digital network, system or its data.
Denial of service.
Virus or malware3 installation.
Hacking a website for unsolicited4 purposes.
To get access to personal and secure information of people and businesses.
Unauthorized use of a computer.
Types of cyber-attacks
Cyber-attacks can be of various types. You need to be aware of all those types of cyber-attacks to guarantee your utmost safety and security.
1) Malware
Malware is considered as software that is intentionally developed to disrupt computer, server, client, or computer network.
Malware can be in the form of scripts, executable codes, active content, and other malicious software.
These codes can be computer worms, viruses, ransomware5, Trojan horses, adware, spyware, or scare ware.
The most prominent6 damages caused by malware are:
As ransomware, it blocks access to key components of the network.
Installs harmful software/malware.
As spyware, they can steal valuable information from your system.
They can damage certain hardware components of your system and make them inoperable.
2) Phishing
The main aim of phishing is to steal restricted and private information such as credit card details, login ids, and passwords, etc.
By impersonating7 oneself as a reliable establishment in electronic com-munication. It is usually done through email spoofing or instant messaging.
They carry a link that directs users to a fake website which looks similar to the legitimate site and asks them to enter personal and secure information. It is a fraudulent activity intended to cheat users.
They bait the users by claiming to be from a reliable third group such as auction sites, online payment processors, social web sites, banks, or IT administrators.
3) Man-in-the-middle attack
In man-in-the-middle (MitM) the invader covertly8 modifies the chats and dialogues between two people who are communicating with each other.
In a man-in-the-middle attack, the communicators are made to believe that they are directly communicating with each other without any interference from any third party.
But the truth is that the whole communication is controlled by the invader while making the communicators believe that they are talking to each other. It is also known as eavesdropping.
The entry points for MitM
The invaders can easily take control of private chats over an unsecured public Wi-Fi. Invaders can inset9 between the device and the network and can take control of the private chats in the network. The communicators without having any idea pass all the conversation to the invaders.
It can also be done through malware. In such cases, the invader installs software on the victims device to process all his information.
4) Denial-of-service attack
In denial-of-service attack (DoS attack) the offender tries to make digital assets inaccessible to its anticipated users.
The offender provisionally10 inter-rupts services of a host who is linked to the Internet. It involves overflowing the besieged11 machine with surplus applications to burden it from fulfilling the legitimate requests.
5) SQL injection attack
A Structured Query Language (SQL) injection attack allows the intruders to run malicious SQL statements. These SQL statements have the power to take over the database server.
Using SQL injection intruders can overcome application security measures.
It allows them to pass through the validation and approval process of any web application.
It also allows them to recover the entire data from their database. It also gives access to intruders to add, modify, and delete data in the database.
An SQL injection allows intruders to fiddle with various databases including MySQL, Oracle, SQL Server, or others. It is widely used by attackers to get access over:
Personal data.
Intellectual property.
Customer information.
Trade secrets and more.
6) Zero-day attack
The zero-day vulnerability is a defect in the software, hardware or even the firmware.
It is hidden from the teams responsible for fixing this bug. It is referred to as zero-day as it has a zero-day time gap between the time it is detected and the first attack.
7) Cross-Site Scripting
In Cross-Site Scripting (XSS) attacks the malicious scripts are embedded to reliable websites.
The intruders send malicious code to different users by embedding them into a trusted website usually as a browser side script.
The web browser cannot recognize this malicious script and has no idea that it is unreliable, and hence it executes the script as it comes from a trusted source. But alas these malicious scripts have powers to access any session tokens, cookies, or any other secret information that is used by that site.
8) Credential reuse attack
With almost every personal account asking for IDs and passwords, we tend to reuse them for various accounts.
Reusing the same password can be a big threat to your security.
The intruders can steal your user-names and passwords from a hacked website and they get a chance to log in to your other accounts using the same IDs and passwords.
And if you have reused them they get a golden opportunity to peek into your private accounts including your bank account, email, your social media accounts, and many others.
9) Password attack
Passwords are the main gateways to securely enter into your personal accounts. Getting access to these passwords is an age-old and most convenient way to intrude into someones private account.
Our passwords are usually connected to our lifes incidents, people and places, and hackers take benefit of such details. They can even sniff into the network to gain access to unencrypted passwords.
Attackers can use either of the below given two approaches to hack your passwords:
Brute-force
Brute-force is just like any other guessing game where you apply your wits and logic and expect that one of your guesses might work.
Dictionary attack
In such attacks, attackers use a diction-ary of common passwords to intrude into the users computer and network.
The attackers copy encrypted file having the list of passwords, and use it to a dictionary of frequently used passwords. They then compare the results to take hold of the users password.
10) Drive-by download attack
Drive-by download attack is a common method used by hackers to spread malicious scripts or codes on users sys-tems.
Attackers embed a malicious script into an insecure websites pages. Whenever you visit such websites, the scripts will automatically install on your system or might redirect you to a website that is controlled by the attacker.
These attacks can occur by visiting a website, a pop-up window or an email message. Drive-by downloads do not require users input to get activated.
It does not require you to download/open any malicious attachment. It uses an operating system/web browser with inadequate security features.
随着互联网的逐渐普及,网络犯罪与网络攻击也与日俱增。而你又了解多少种网络攻击呢?为了应对网络威胁,你必须充分認清其本质。
什么是网络攻击?
网络攻击由一个数字系统发起,针对另一数字设备、网站或任何其他数字系统进行攻击,网络攻击有损被攻击对象的隐私、信誉或储存其中的数据。
这些攻击不仅危及互联网个人用户,也会对企业造成巨大威胁。
为什么发起网络攻击?
在进一步阐述网络攻击的类型之前,我们先来看看发起网络攻击的原因:
未经授权访问数字网络、系统或其数据;
拒绝服务;
安装病毒或恶意软件;
擅自入侵网站;
窃取个人与企业的私密、安全信息;
未经授权使用计算机。
网络攻击的类型
网络攻击有多种类型。为了最大程度保证安全,你需要了解所有类型的网络攻击。
1)恶意软件
恶意软件是指蓄意开发以破坏计算机、服务器、客户端或计算机网络的软件。
恶意软件形式多样,包括脚本、执行代码、活动内容以及其他恶意软件。
这些代码可能是计算机蠕虫、病毒、勒索软件、特洛伊木马、广告软件、间谍软件或恐吓软件。
恶意软件造成的最为显著的危害如下:
勒索软件会阻断对网络关键组件的访问;
安装有害软件或恶意软件;
间谍软件会从系统窃取有价值的信息。
它们可以破坏系统的某些硬件组件,令其无法运作。
2)网络钓鱼
网络钓鱼的主要目的是窃取机密、私密信息,如信用卡明细、登录名与密码等。……