←
Computer Literacy and Digital Awareness · Chapter 10

Cyber Security and Malware

What to remember

  • Cyber security protects computers, networks and data from attack, theft and damage. Malware is any harmful software; a virus needs a host file, a worm spreads by itself, and a Trojan pretends to be useful.
  • Phishing tricks people into giving passwords or money through fake messages. A firewall filters network traffic; encryption turns readable data into unreadable cipher text that only a key can open.
  • The Information Technology Act, 2000 is the main Indian law on cyber crime and electronic records. The cyber crime helpline and national reporting portal help victims report offences.

Cyber security: the basics

Cyber security rests on three goals, often called the CIA triad:

  • Confidentiality: only the right people can see the data.
  • Integrity: data is not changed without permission.
  • Availability: data and systems can be used when needed.

A threat is a possible danger. A vulnerability is a weakness. An attack is an attempt to use a weakness. A hacker who breaks in with bad intent is a black-hat hacker; an ethical (white-hat) hacker tests systems with permission.

Malware types

Malware means malicious software.

TypeHow it works
VirusAttaches to a file or program and spreads when that file is run or shared
WormSpreads by itself across a network without a host file; can slow networks
Trojan horseLooks like useful software but hides harmful code; does not copy itself
RansomwareLocks or encrypts files and demands money to restore them
SpywareSecretly watches what you do and sends the details out
AdwareShows unwanted advertisements
KeyloggerRecords the keys you press, to steal passwords
RootkitHides deep in the system to keep control without being seen
BotnetA group of infected computers controlled remotely
Logic bombHarmful code that triggers on a set condition or date

Signs of infection: slow computer, strange pop-ups, unknown programs, files missing or locked, and the browser home page changing. Antivirus software scans, detects and removes malware; it needs regular updates to know new threats.

Phishing and other attacks

AttackMeaning
PhishingFake emails or messages that look genuine and ask for passwords or bank details
Spear phishingPhishing aimed at one chosen person or group
VishingPhishing by voice call
SmishingPhishing by SMS
PharmingSending users to a fake website even when they type the right address
SpoofingPretending to be a trusted sender or device
Social engineeringTricking people, not machines, into giving access
DoS attackFloods a server so real users cannot reach it
DDoS attackA DoS attack from many computers at once
Man-in-the-middleAttacker secretly sits between two parties and reads their data
Brute forceTrying many passwords until one works
Identity theftUsing someone's personal details to act as them

Firewalls and encryption

A firewall is a security system, in hardware or software, that checks traffic between a trusted network and an untrusted one (such as the Internet) and blocks traffic that breaks its rules. It cannot stop a virus that a user installs knowingly.

Encryption changes plain text into cipher text using an algorithm and a key. Decryption changes it back.

KindKey usePoint
SymmetricOne shared secret keyFast; key sharing is the problem
AsymmetricA public key and a private keyPublic key encrypts, private key decrypts; used in digital signatures

A digital signature proves who sent a message and that it was not changed. A digital certificate, given by a certifying authority, links a public key to a person or website. HTTPS uses SSL/TLS, shown by a padlock in the browser. Hashing creates a fixed-length fingerprint of data and cannot be reversed. VPN (virtual private network) makes an encrypted tunnel over the Internet.

Authentication proves who you are. Methods: something you know (password, PIN), something you have (OTP device, card) and something you are (fingerprint, face). Two-factor authentication uses two of these.

Safe practices

  • Use long, different passwords for each account, with letters, numbers and symbols.
  • Turn on two-factor authentication.
  • Keep the operating system, browser and antivirus updated.
  • Do not click unknown links or open unexpected attachments.
  • Check that the site address begins with https before entering sensitive details.
  • Never share OTP, PIN, CVV or password with anyone, including a person who claims to be from a bank.
  • Take regular backups; follow the 3-2-1 idea (three copies, two kinds of storage, one kept away).
  • Avoid public Wi-Fi for banking; log out after use.
  • Download apps only from official stores.
  • Think before you post personal details on social media.

IT Act basics

The Information Technology Act, 2000 is the main Indian law for electronic records, digital signatures and cyber crime. It gave legal validity to electronic records and digital signatures and was amended in 2008. The Act has provisions against hacking, identity theft, cheating by impersonation using a computer, publishing obscene material, and cyber terrorism. Sections often asked in exams:

SectionSubject
43Damage to computer and data without permission; compensation
66Computer-related offences such as hacking
66CIdentity theft
66DCheating by impersonation using a computer
66FCyber terrorism
67Publishing or sending obscene material electronically

Adjudicating officers and appellate tribunals are set up under the Act. CERT-In (Indian Computer Emergency Response Team) is the national agency for responding to cyber security incidents. Cyber crimes can be reported on the national cyber crime reporting portal and through the helpline number given by the government; check the latest official release for the current details. Cyber law deals with the legal side; cyber ethics deals with right conduct online. Copyright, plagiarism and software piracy are also IP and ethics matters.

More on authentication, backup and everyday safety

A strong password is long, unique and hard to guess. A passphrase made of several random words is easier to remember and still strong. A password manager stores many passwords safely. Biometrics use fingerprint, iris or face. CAPTCHA is a small test to separate humans from bots. A cookie can store login details, so log out on shared computers and clear saved data.

Updates and patches fix known weaknesses; delaying them leaves doors open. A zero-day weakness is one that is not yet known to the maker, so no fix exists. A sandbox runs suspicious programs in a safe, separate space. Quarantine isolates a suspected infected file. An intrusion detection system watches a network for signs of attack. Backup means keeping an extra copy of data; if ransomware strikes, a clean backup is the best recovery.

Online banking safety: type the official address yourself, do not use links from messages, check for https, and confirm that the bank will never ask for your PIN, CVV or OTP. If money is lost, inform the bank at once and report on the national cyber crime reporting portal or the helpline. Quick reporting improves the chance of stopping the transfer.

Social media safety: keep accounts private where possible, do not accept requests from strangers, and avoid sharing location, phone number or document photos. Cyberbullying and online stalking are offences under Indian law. Children should use parental controls, and everyone should be careful about fake news, fake job offers and fake lottery or prize messages, which are common tricks for fraud.

Digital footprint means the trail of data you leave online. Data protection means keeping personal data safe and using it only for the purpose it was given. The Digital Personal Data Protection Act is the Indian law about this; check the latest official release for details. Software piracy (using unlicensed software) is illegal. Using open-source or properly licensed software is the safe and legal choice.

Exam traps

  • Virus needs a host file; worm spreads on its own; Trojan does not replicate.
  • Phishing uses email or messages; vishing uses voice; smishing uses SMS.
  • DoS comes from one source; DDoS comes from many.
  • Firewall filters traffic; antivirus removes malware.
  • Symmetric encryption uses one key; asymmetric uses two.
  • Encryption protects secrecy; a digital signature proves origin and integrity.
  • Ransomware demands money; spyware only spies.
  • IT Act 2000 is a central law, not a state law.

One-liners

  • 1. The IT Act was passed in 2000.
  • 2. CIA triad: Confidentiality, Integrity, Availability.
  • 3. A worm needs no host file.
  • 4. A Trojan horse hides inside a useful-looking program.
  • 5. Ransomware locks files and asks for money.
  • 6. A keylogger records keystrokes.
  • 7. Phishing steals data through fake messages.
  • 8. A firewall filters network traffic by rules.
  • 9. Cipher text is encrypted data.
  • 10. A digital signature proves sender and integrity.
  • 11. CERT-In handles cyber security incidents in India.
  • 12. Two-factor authentication uses two proofs of identity.

Practice questions

  1. Malware means:

    1. Memory software
    2. Manual software
    3. Mail software
    4. Malicious software
    Answer

    D. Malicious software

    Malware is harmful software.

  2. Which malware spreads by itself across networks without a host file?

    1. Trojan
    2. Worm
    3. Keylogger
    4. Virus
    Answer

    B. Worm

    Worms self-replicate.

  3. Software that looks useful but hides harmful code is a:

    1. Worm
    2. Browser
    3. Firewall
    4. Trojan horse
    Answer

    D. Trojan horse

    Trojans disguise themselves.

  4. Malware that locks files and demands money is:

    1. Adware
    2. Ransomware
    3. Spyware
    4. Rootkit
    Answer

    B. Ransomware

    Ransomware demands a ransom.

  5. Malware that secretly watches user activity is:

    1. Worm
    2. Adware
    3. Ransomware
    4. Spyware
    Answer

    D. Spyware

    Spyware spies.

  6. Software that records every key pressed is a:

    1. Firewall
    2. Keylogger
    3. Worm
    4. Rootkit
    Answer

    B. Keylogger

    Keyloggers log keystrokes.

  7. A group of infected computers controlled remotely is a:

    1. Intranet
    2. Gateway
    3. Firewall
    4. Botnet
    Answer

    D. Botnet

    Botnets are controlled bot networks.

  8. Malware that hides deep in the system to keep hidden control is a:

    1. Worm
    2. Spam
    3. Adware
    4. Rootkit
    Answer

    D. Rootkit

    Rootkits hide.

  9. Fake emails that ask for passwords or bank details are called:

    1. Booting
    2. Phishing
    3. Spooling
    4. Caching
    Answer

    B. Phishing

    Phishing steals data via fake messages.

  10. Phishing carried out through SMS is called:

    1. Spoofing
    2. Vishing
    3. Smishing
    4. Pharming
    Answer

    C. Smishing

    Smishing uses SMS.

  11. Phishing carried out by voice call is called:

    1. Hashing
    2. Pharming
    3. Vishing
    4. Smishing
    Answer

    C. Vishing

    Vishing uses voice.

  12. Sending users to a fake website even when they type the correct address is:

    1. Sniffing
    2. Phishing
    3. Hashing
    4. Pharming
    Answer

    D. Pharming

    Pharming redirects users.

  13. An attack that floods a server from many computers is a:

    1. Spoofing
    2. DDoS attack
    3. Brute force
    4. Phishing
    Answer

    B. DDoS attack

    Distributed denial of service.

  14. Trying many passwords until one works is a:

    1. Brute force attack
    2. Pharming
    3. DDoS attack
    4. Smishing
    Answer

    A. Brute force attack

    Brute force guesses.

  15. A system that filters traffic between a trusted and an untrusted network is a:

    1. Firewall
    2. Modem
    3. Router only
    4. Browser
    Answer

    A. Firewall

    Firewall filters traffic by rules.

  16. Unreadable data produced by encryption is called:

    1. Plain text
    2. Source code
    3. Cipher text
    4. Cookie
    Answer

    C. Cipher text

    Cipher text is encrypted data.

  17. In symmetric encryption:

    1. Only a public key is used
    2. No key is used
    3. The same secret key is used to encrypt and decrypt
    4. Two different keys are used
    Answer

    C. The same secret key is used to encrypt and decrypt

    One shared key.

  18. In asymmetric encryption, the key used to decrypt is the:

    1. Shared key
    2. Private key
    3. Public key
    4. Session ID
    Answer

    B. Private key

    The public key encrypts; private key decrypts.

  19. A digital signature helps to prove:

    1. That the computer is virus-free
    2. That the network is fast
    3. That the message is secret
    4. Who sent a message and that it was not altered
    Answer

    D. Who sent a message and that it was not altered

    Origin and integrity.

  20. Two-factor authentication uses:

    1. Two email addresses
    2. Two antivirus programs
    3. Two passwords of the same kind
    4. Two different proofs of identity
    Answer

    D. Two different proofs of identity

    It adds a second proof.

  21. A VPN mainly:

    1. Prints documents
    2. Creates an encrypted tunnel over the Internet
    3. Increases hard disk size
    4. Removes all viruses
    Answer

    B. Creates an encrypted tunnel over the Internet

    VPN secures traffic.

  22. Confidentiality, Integrity and Availability together are known as the:

    1. OSI model
    2. CIA triad
    3. ACID rule
    4. TCP triad
    Answer

    B. CIA triad

    Basic security goals.

  23. Which of the following is the best password practice?

    1. Use your birth date
    2. Use the same password everywhere
    3. Share it with a friend
    4. Use long unique passwords with letters, numbers and symbols
    Answer

    D. Use long unique passwords with letters, numbers and symbols

    Strong, unique passwords are safer.

  24. What should you do with your OTP?

    1. Tell the bank caller
    2. Send it by email
    3. Never share it with anyone
    4. Post it online
    Answer

    C. Never share it with anyone

    OTPs are secret.

  25. The main Indian law on cyber crime and electronic records is the:

    1. Telegraph Act only
    2. Indian Post Office Act
    3. Information Technology Act, 2000
    4. Copyright Act, 1957
    Answer

    C. Information Technology Act, 2000

    The IT Act 2000 is the main law.

  26. Which agency is India's national agency for responding to cyber security incidents?

    1. CERT-In
    2. NIC
    3. TRAI
    4. UIDAI
    Answer

    A. CERT-In

    CERT-In handles incidents.

  27. Identity theft is covered under which IT Act section?

    1. 67
    2. 43
    3. 66F
    4. 66C
    Answer

    D. 66C

    Section 66C deals with identity theft.

  28. Cyber terrorism is covered under which IT Act section?

    1. 66F
    2. 43
    3. 66D
    4. 66C
    Answer

    A. 66F

    Section 66F is cyber terrorism.

  29. Cheating by impersonation using a computer is covered by Section:

    1. 67
    2. 66D
    3. 66F
    4. 66C
    Answer

    B. 66D

    66D is cheating by personation.

  30. Publishing obscene material electronically falls under Section:

    1. 66D
    2. 43
    3. 66F
    4. 67
    Answer

    D. 67

    Section 67 covers obscene content.

  31. Statement 1: A worm needs a host file to spread. Statement 2: A virus attaches to a file. Which is/are correct?

    1. 1 only
    2. 2 only
    3. Both 1 and 2
    4. Neither 1 nor 2
    Answer

    B. 2 only

    Worms spread by themselves.

  32. Statement 1: A Trojan horse copies itself. Statement 2: A Trojan disguises itself as useful software. Which is/are correct?

    1. 1 only
    2. 2 only
    3. Both 1 and 2
    4. Neither 1 nor 2
    Answer

    B. 2 only

    Trojans do not replicate.

  33. Statement 1: A DoS attack comes from one source. Statement 2: A DDoS attack comes from many computers. Which is/are correct?

    1. 1 only
    2. 2 only
    3. Both 1 and 2
    4. Neither 1 nor 2
    Answer

    C. Both 1 and 2

    Both correct.

  34. Statement 1: A firewall can filter network traffic. Statement 2: An antivirus can detect and remove malware. Which is/are correct?

    1. 1 only
    2. 2 only
    3. Both 1 and 2
    4. Neither 1 nor 2
    Answer

    C. Both 1 and 2

    Both correct.

  35. Statement 1: Symmetric encryption uses two keys. Statement 2: Asymmetric encryption uses a public and a private key. Which is/are correct?

    1. 1 only
    2. 2 only
    3. Both 1 and 2
    4. Neither 1 nor 2
    Answer

    B. 2 only

    Symmetric uses one key.

  36. Statement 1: HTTPS uses SSL/TLS. Statement 2: A padlock in the browser may show a secure connection. Which is/are correct?

    1. 1 only
    2. 2 only
    3. Both 1 and 2
    4. Neither 1 nor 2
    Answer

    C. Both 1 and 2

    Both correct.

  37. Statement 1: Spyware locks files for money. Statement 2: Ransomware demands payment. Which is/are correct?

    1. 1 only
    2. 2 only
    3. Both 1 and 2
    4. Neither 1 nor 2
    Answer

    B. 2 only

    Spyware spies; ransomware locks.

  38. Statement 1: Public Wi-Fi is the safest place for net banking. Statement 2: Backups help recover data after an attack. Which is/are correct?

    1. 1 only
    2. 2 only
    3. Both 1 and 2
    4. Neither 1 nor 2
    Answer

    B. 2 only

    Avoid public Wi-Fi for banking.

  39. Statement 1: The IT Act 2000 gave legal validity to electronic records. Statement 2: It is a state-level law. Which is/are correct?

    1. 1 only
    2. 2 only
    3. Both 1 and 2
    4. Neither 1 nor 2
    Answer

    A. 1 only

    It is a central law.

  40. Statement 1: Phishing tricks people, not just machines. Statement 2: Social engineering depends on human trust. Which is/are correct?

    1. 1 only
    2. 2 only
    3. Both 1 and 2
    4. Neither 1 nor 2
    Answer

    C. Both 1 and 2

    Both correct.

  41. Statement 1: Hashing can be easily reversed to get the original data. Statement 2: A hash gives a fixed-length fingerprint. Which is/are correct?

    1. 1 only
    2. 2 only
    3. Both 1 and 2
    4. Neither 1 nor 2
    Answer

    B. 2 only

    Hashing is one-way.

  42. Statement 1: Adware shows unwanted advertisements. Statement 2: A keylogger records keystrokes. Which is/are correct?

    1. 1 only
    2. 2 only
    3. Both 1 and 2
    4. Neither 1 nor 2
    Answer

    C. Both 1 and 2

    Both correct.

  43. Statement 1: A logic bomb triggers on a set condition. Statement 2: A botnet is a single infected file. Which is/are correct?

    1. 1 only
    2. 2 only
    3. Both 1 and 2
    4. Neither 1 nor 2
    Answer

    A. 1 only

    A botnet is a network of infected computers.

  44. Statement 1: A firewall can stop a virus that a user installs knowingly. Statement 2: Antivirus needs regular updates. Which is/are correct?

    1. 1 only
    2. 2 only
    3. Both 1 and 2
    4. Neither 1 nor 2
    Answer

    B. 2 only

    A firewall cannot stop a virus a user installs.

  45. Statement 1: Never click unknown links in messages. Statement 2: Apps should be installed only from official stores. Which is/are correct?

    1. 1 only
    2. 2 only
    3. Both 1 and 2
    4. Neither 1 nor 2
    Answer

    C. Both 1 and 2

    Both are safe practices.

Page 1 of 1
‹
›