Cyber Security and Malware
What to remember
- Cyber security protects computers, networks and data from attack, theft and damage. Malware is any harmful software; a virus needs a host file, a worm spreads by itself, and a Trojan pretends to be useful.
- Phishing tricks people into giving passwords or money through fake messages. A firewall filters network traffic; encryption turns readable data into unreadable cipher text that only a key can open.
- The Information Technology Act, 2000 is the main Indian law on cyber crime and electronic records. The cyber crime helpline and national reporting portal help victims report offences.
Cyber security: the basics
Cyber security rests on three goals, often called the CIA triad:
- Confidentiality: only the right people can see the data.
- Integrity: data is not changed without permission.
- Availability: data and systems can be used when needed.
A threat is a possible danger. A vulnerability is a weakness. An attack is an attempt to use a weakness. A hacker who breaks in with bad intent is a black-hat hacker; an ethical (white-hat) hacker tests systems with permission.
Malware types
Malware means malicious software.
| Type | How it works |
|---|---|
| Virus | Attaches to a file or program and spreads when that file is run or shared |
| Worm | Spreads by itself across a network without a host file; can slow networks |
| Trojan horse | Looks like useful software but hides harmful code; does not copy itself |
| Ransomware | Locks or encrypts files and demands money to restore them |
| Spyware | Secretly watches what you do and sends the details out |
| Adware | Shows unwanted advertisements |
| Keylogger | Records the keys you press, to steal passwords |
| Rootkit | Hides deep in the system to keep control without being seen |
| Botnet | A group of infected computers controlled remotely |
| Logic bomb | Harmful code that triggers on a set condition or date |
Signs of infection: slow computer, strange pop-ups, unknown programs, files missing or locked, and the browser home page changing. Antivirus software scans, detects and removes malware; it needs regular updates to know new threats.
Phishing and other attacks
| Attack | Meaning |
|---|---|
| Phishing | Fake emails or messages that look genuine and ask for passwords or bank details |
| Spear phishing | Phishing aimed at one chosen person or group |
| Vishing | Phishing by voice call |
| Smishing | Phishing by SMS |
| Pharming | Sending users to a fake website even when they type the right address |
| Spoofing | Pretending to be a trusted sender or device |
| Social engineering | Tricking people, not machines, into giving access |
| DoS attack | Floods a server so real users cannot reach it |
| DDoS attack | A DoS attack from many computers at once |
| Man-in-the-middle | Attacker secretly sits between two parties and reads their data |
| Brute force | Trying many passwords until one works |
| Identity theft | Using someone's personal details to act as them |
Firewalls and encryption
A firewall is a security system, in hardware or software, that checks traffic between a trusted network and an untrusted one (such as the Internet) and blocks traffic that breaks its rules. It cannot stop a virus that a user installs knowingly.
Encryption changes plain text into cipher text using an algorithm and a key. Decryption changes it back.
| Kind | Key use | Point |
|---|---|---|
| Symmetric | One shared secret key | Fast; key sharing is the problem |
| Asymmetric | A public key and a private key | Public key encrypts, private key decrypts; used in digital signatures |
A digital signature proves who sent a message and that it was not changed. A digital certificate, given by a certifying authority, links a public key to a person or website. HTTPS uses SSL/TLS, shown by a padlock in the browser. Hashing creates a fixed-length fingerprint of data and cannot be reversed. VPN (virtual private network) makes an encrypted tunnel over the Internet.
Authentication proves who you are. Methods: something you know (password, PIN), something you have (OTP device, card) and something you are (fingerprint, face). Two-factor authentication uses two of these.
Safe practices
- Use long, different passwords for each account, with letters, numbers and symbols.
- Turn on two-factor authentication.
- Keep the operating system, browser and antivirus updated.
- Do not click unknown links or open unexpected attachments.
- Check that the site address begins with https before entering sensitive details.
- Never share OTP, PIN, CVV or password with anyone, including a person who claims to be from a bank.
- Take regular backups; follow the 3-2-1 idea (three copies, two kinds of storage, one kept away).
- Avoid public Wi-Fi for banking; log out after use.
- Download apps only from official stores.
- Think before you post personal details on social media.
IT Act basics
The Information Technology Act, 2000 is the main Indian law for electronic records, digital signatures and cyber crime. It gave legal validity to electronic records and digital signatures and was amended in 2008. The Act has provisions against hacking, identity theft, cheating by impersonation using a computer, publishing obscene material, and cyber terrorism. Sections often asked in exams:
| Section | Subject |
|---|---|
| 43 | Damage to computer and data without permission; compensation |
| 66 | Computer-related offences such as hacking |
| 66C | Identity theft |
| 66D | Cheating by impersonation using a computer |
| 66F | Cyber terrorism |
| 67 | Publishing or sending obscene material electronically |
Adjudicating officers and appellate tribunals are set up under the Act. CERT-In (Indian Computer Emergency Response Team) is the national agency for responding to cyber security incidents. Cyber crimes can be reported on the national cyber crime reporting portal and through the helpline number given by the government; check the latest official release for the current details. Cyber law deals with the legal side; cyber ethics deals with right conduct online. Copyright, plagiarism and software piracy are also IP and ethics matters.
More on authentication, backup and everyday safety
A strong password is long, unique and hard to guess. A passphrase made of several random words is easier to remember and still strong. A password manager stores many passwords safely. Biometrics use fingerprint, iris or face. CAPTCHA is a small test to separate humans from bots. A cookie can store login details, so log out on shared computers and clear saved data.
Updates and patches fix known weaknesses; delaying them leaves doors open. A zero-day weakness is one that is not yet known to the maker, so no fix exists. A sandbox runs suspicious programs in a safe, separate space. Quarantine isolates a suspected infected file. An intrusion detection system watches a network for signs of attack. Backup means keeping an extra copy of data; if ransomware strikes, a clean backup is the best recovery.
Online banking safety: type the official address yourself, do not use links from messages, check for https, and confirm that the bank will never ask for your PIN, CVV or OTP. If money is lost, inform the bank at once and report on the national cyber crime reporting portal or the helpline. Quick reporting improves the chance of stopping the transfer.
Social media safety: keep accounts private where possible, do not accept requests from strangers, and avoid sharing location, phone number or document photos. Cyberbullying and online stalking are offences under Indian law. Children should use parental controls, and everyone should be careful about fake news, fake job offers and fake lottery or prize messages, which are common tricks for fraud.
Digital footprint means the trail of data you leave online. Data protection means keeping personal data safe and using it only for the purpose it was given. The Digital Personal Data Protection Act is the Indian law about this; check the latest official release for details. Software piracy (using unlicensed software) is illegal. Using open-source or properly licensed software is the safe and legal choice.
Exam traps
- Virus needs a host file; worm spreads on its own; Trojan does not replicate.
- Phishing uses email or messages; vishing uses voice; smishing uses SMS.
- DoS comes from one source; DDoS comes from many.
- Firewall filters traffic; antivirus removes malware.
- Symmetric encryption uses one key; asymmetric uses two.
- Encryption protects secrecy; a digital signature proves origin and integrity.
- Ransomware demands money; spyware only spies.
- IT Act 2000 is a central law, not a state law.
One-liners
- 1. The IT Act was passed in 2000.
- 2. CIA triad: Confidentiality, Integrity, Availability.
- 3. A worm needs no host file.
- 4. A Trojan horse hides inside a useful-looking program.
- 5. Ransomware locks files and asks for money.
- 6. A keylogger records keystrokes.
- 7. Phishing steals data through fake messages.
- 8. A firewall filters network traffic by rules.
- 9. Cipher text is encrypted data.
- 10. A digital signature proves sender and integrity.
- 11. CERT-In handles cyber security incidents in India.
- 12. Two-factor authentication uses two proofs of identity.
Practice questions
Malware means:
- Memory software
- Manual software
- Mail software
- Malicious software
Answer
D. Malicious software
Malware is harmful software.
Which malware spreads by itself across networks without a host file?
- Trojan
- Worm
- Keylogger
- Virus
Answer
B. Worm
Worms self-replicate.
Software that looks useful but hides harmful code is a:
- Worm
- Browser
- Firewall
- Trojan horse
Answer
D. Trojan horse
Trojans disguise themselves.
Malware that locks files and demands money is:
- Adware
- Ransomware
- Spyware
- Rootkit
Answer
B. Ransomware
Ransomware demands a ransom.
Malware that secretly watches user activity is:
- Worm
- Adware
- Ransomware
- Spyware
Answer
D. Spyware
Spyware spies.
Software that records every key pressed is a:
- Firewall
- Keylogger
- Worm
- Rootkit
Answer
B. Keylogger
Keyloggers log keystrokes.
A group of infected computers controlled remotely is a:
- Intranet
- Gateway
- Firewall
- Botnet
Answer
D. Botnet
Botnets are controlled bot networks.
Malware that hides deep in the system to keep hidden control is a:
- Worm
- Spam
- Adware
- Rootkit
Answer
D. Rootkit
Rootkits hide.
Fake emails that ask for passwords or bank details are called:
- Booting
- Phishing
- Spooling
- Caching
Answer
B. Phishing
Phishing steals data via fake messages.
Phishing carried out through SMS is called:
- Spoofing
- Vishing
- Smishing
- Pharming
Answer
C. Smishing
Smishing uses SMS.
Phishing carried out by voice call is called:
- Hashing
- Pharming
- Vishing
- Smishing
Answer
C. Vishing
Vishing uses voice.
Sending users to a fake website even when they type the correct address is:
- Sniffing
- Phishing
- Hashing
- Pharming
Answer
D. Pharming
Pharming redirects users.
An attack that floods a server from many computers is a:
- Spoofing
- DDoS attack
- Brute force
- Phishing
Answer
B. DDoS attack
Distributed denial of service.
Trying many passwords until one works is a:
- Brute force attack
- Pharming
- DDoS attack
- Smishing
Answer
A. Brute force attack
Brute force guesses.
A system that filters traffic between a trusted and an untrusted network is a:
- Firewall
- Modem
- Router only
- Browser
Answer
A. Firewall
Firewall filters traffic by rules.
Unreadable data produced by encryption is called:
- Plain text
- Source code
- Cipher text
- Cookie
Answer
C. Cipher text
Cipher text is encrypted data.
In symmetric encryption:
- Only a public key is used
- No key is used
- The same secret key is used to encrypt and decrypt
- Two different keys are used
Answer
C. The same secret key is used to encrypt and decrypt
One shared key.
In asymmetric encryption, the key used to decrypt is the:
- Shared key
- Private key
- Public key
- Session ID
Answer
B. Private key
The public key encrypts; private key decrypts.
A digital signature helps to prove:
- That the computer is virus-free
- That the network is fast
- That the message is secret
- Who sent a message and that it was not altered
Answer
D. Who sent a message and that it was not altered
Origin and integrity.
Two-factor authentication uses:
- Two email addresses
- Two antivirus programs
- Two passwords of the same kind
- Two different proofs of identity
Answer
D. Two different proofs of identity
It adds a second proof.
A VPN mainly:
- Prints documents
- Creates an encrypted tunnel over the Internet
- Increases hard disk size
- Removes all viruses
Answer
B. Creates an encrypted tunnel over the Internet
VPN secures traffic.
Confidentiality, Integrity and Availability together are known as the:
- OSI model
- CIA triad
- ACID rule
- TCP triad
Answer
B. CIA triad
Basic security goals.
Which of the following is the best password practice?
- Use your birth date
- Use the same password everywhere
- Share it with a friend
- Use long unique passwords with letters, numbers and symbols
Answer
D. Use long unique passwords with letters, numbers and symbols
Strong, unique passwords are safer.
What should you do with your OTP?
- Tell the bank caller
- Send it by email
- Never share it with anyone
- Post it online
Answer
C. Never share it with anyone
OTPs are secret.
The main Indian law on cyber crime and electronic records is the:
- Telegraph Act only
- Indian Post Office Act
- Information Technology Act, 2000
- Copyright Act, 1957
Answer
C. Information Technology Act, 2000
The IT Act 2000 is the main law.
Which agency is India's national agency for responding to cyber security incidents?
- CERT-In
- NIC
- TRAI
- UIDAI
Answer
A. CERT-In
CERT-In handles incidents.
Identity theft is covered under which IT Act section?
- 67
- 43
- 66F
- 66C
Answer
D. 66C
Section 66C deals with identity theft.
Cyber terrorism is covered under which IT Act section?
- 66F
- 43
- 66D
- 66C
Answer
A. 66F
Section 66F is cyber terrorism.
Cheating by impersonation using a computer is covered by Section:
- 67
- 66D
- 66F
- 66C
Answer
B. 66D
66D is cheating by personation.
Publishing obscene material electronically falls under Section:
- 66D
- 43
- 66F
- 67
Answer
D. 67
Section 67 covers obscene content.
Statement 1: A worm needs a host file to spread. Statement 2: A virus attaches to a file. Which is/are correct?
- 1 only
- 2 only
- Both 1 and 2
- Neither 1 nor 2
Answer
B. 2 only
Worms spread by themselves.
Statement 1: A Trojan horse copies itself. Statement 2: A Trojan disguises itself as useful software. Which is/are correct?
- 1 only
- 2 only
- Both 1 and 2
- Neither 1 nor 2
Answer
B. 2 only
Trojans do not replicate.
Statement 1: A DoS attack comes from one source. Statement 2: A DDoS attack comes from many computers. Which is/are correct?
- 1 only
- 2 only
- Both 1 and 2
- Neither 1 nor 2
Answer
C. Both 1 and 2
Both correct.
Statement 1: A firewall can filter network traffic. Statement 2: An antivirus can detect and remove malware. Which is/are correct?
- 1 only
- 2 only
- Both 1 and 2
- Neither 1 nor 2
Answer
C. Both 1 and 2
Both correct.
Statement 1: Symmetric encryption uses two keys. Statement 2: Asymmetric encryption uses a public and a private key. Which is/are correct?
- 1 only
- 2 only
- Both 1 and 2
- Neither 1 nor 2
Answer
B. 2 only
Symmetric uses one key.
Statement 1: HTTPS uses SSL/TLS. Statement 2: A padlock in the browser may show a secure connection. Which is/are correct?
- 1 only
- 2 only
- Both 1 and 2
- Neither 1 nor 2
Answer
C. Both 1 and 2
Both correct.
Statement 1: Spyware locks files for money. Statement 2: Ransomware demands payment. Which is/are correct?
- 1 only
- 2 only
- Both 1 and 2
- Neither 1 nor 2
Answer
B. 2 only
Spyware spies; ransomware locks.
Statement 1: Public Wi-Fi is the safest place for net banking. Statement 2: Backups help recover data after an attack. Which is/are correct?
- 1 only
- 2 only
- Both 1 and 2
- Neither 1 nor 2
Answer
B. 2 only
Avoid public Wi-Fi for banking.
Statement 1: The IT Act 2000 gave legal validity to electronic records. Statement 2: It is a state-level law. Which is/are correct?
- 1 only
- 2 only
- Both 1 and 2
- Neither 1 nor 2
Answer
A. 1 only
It is a central law.
Statement 1: Phishing tricks people, not just machines. Statement 2: Social engineering depends on human trust. Which is/are correct?
- 1 only
- 2 only
- Both 1 and 2
- Neither 1 nor 2
Answer
C. Both 1 and 2
Both correct.
Statement 1: Hashing can be easily reversed to get the original data. Statement 2: A hash gives a fixed-length fingerprint. Which is/are correct?
- 1 only
- 2 only
- Both 1 and 2
- Neither 1 nor 2
Answer
B. 2 only
Hashing is one-way.
Statement 1: Adware shows unwanted advertisements. Statement 2: A keylogger records keystrokes. Which is/are correct?
- 1 only
- 2 only
- Both 1 and 2
- Neither 1 nor 2
Answer
C. Both 1 and 2
Both correct.
Statement 1: A logic bomb triggers on a set condition. Statement 2: A botnet is a single infected file. Which is/are correct?
- 1 only
- 2 only
- Both 1 and 2
- Neither 1 nor 2
Answer
A. 1 only
A botnet is a network of infected computers.
Statement 1: A firewall can stop a virus that a user installs knowingly. Statement 2: Antivirus needs regular updates. Which is/are correct?
- 1 only
- 2 only
- Both 1 and 2
- Neither 1 nor 2
Answer
B. 2 only
A firewall cannot stop a virus a user installs.
Statement 1: Never click unknown links in messages. Statement 2: Apps should be installed only from official stores. Which is/are correct?
- 1 only
- 2 only
- Both 1 and 2
- Neither 1 nor 2
Answer
C. Both 1 and 2
Both are safe practices.