Skip to content

Latest commit

 

History

22 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

What is the problem:

Despite security advancements, individuals are experiencing more malware attacks on personal devices, leading to data loss and privacy breaches. Non-technical users lack cybersecurity awareness to address threats, and organizations struggle to detect advanced persistent threats (APTs), leaving users vulnerable.

Type of cyber threats:

Introduction These are the most common types of cybersecurity threats faced by individuals and businesses, emphasizing the need for strong cybersecurity policies and prevention strategies to mitigate these risks.

Common Cyber Threats for a Business:

  1. Malware

    • Definition: Malicious software designed to compromise the confidentiality, integrity, or availability of data.
    • Types: Includes viruses, worms, trojans, and spyware.
    • Impact: Can cause extensive damage and disruption to operations.
    • Preventive Measures:
      • Scan email attachments and restrict certain file types (e.g., .exe files).
      • Limit use of removable media in high-risk systems.
      • Regular updates of operating systems and applications.
  2. Ransomware

    • Definition: A specific type of malware that encrypts files on a victim's computer, requiring payment (usually in cryptocurrency) to regain access.
    • Impact: Prevents legitimate access, holds data hostage, and can be difficult to detect before damage occurs.
    • Preventive Measures:
      • Employee training on ransomware threats.
      • Strong information security controls.
      • Development of business continuity and incident response plans.
  3. Distributed Denial of Service (DDoS) Attacks

    • Definition: Attacks that overwhelm online services by flooding them with excessive traffic from multiple sources.
    • Impact: Makes websites or online services unavailable and can serve as a distraction for other malicious activities.
    • Preventive Measures:
      • Implement robust network security measures.
      • Monitor traffic for unusual patterns.
      • Develop a DDoS response strategy.
  4. Spam and Phishing

    • Definitions:
      • Spam: Unsolicited emails or messages.
      • Phishing: Attempts to deceive users into providing sensitive information by pretending to be a trustworthy entity.
    • Impact: Leads to identity theft and financial fraud.
    • Preventive Measures:
      • Employee training on identifying phishing attempts.
      • Use secure email gateways to filter out unsolicited messages.
      • Implement two-factor authentication for sensitive accounts.
  5. Corporate Account Takeover (CATO)

    • Definition: An attack where cybercriminals impersonate a business to perform unauthorized transactions.
    • Impact: Significant financial losses due to unauthorized wire and ACH transactions.
    • Preventive Measures:
      • Strengthen computer safeguards and access controls.
      • Regular audits of online banking systems.
  6. Automated Teller Machine (ATM) Cash Out

    • Definition: A type of fraud involving simultaneous large withdrawals from ATMs, often through compromised systems.
    • Impact: Can lead to substantial financial losses for institutions, particularly smaller ones.
    • Preventive Measures:
      • Review controls over ATM parameters and withdrawal policies.
      • Implement fraud detection measures and monitor suspicious activities.

Type of Cyber Threats for a Normal Person:

  1. Viruses

    • Malicious programs that attach themselves to legitimate software and spread to other files or computers when the infected program is executed.
  2. Worms

    • Self-replicating malware that spreads across networks without needing to attach to other programs. They can exploit vulnerabilities in the operating system.
  3. Trojan Horses

    • Malware disguised as legitimate software that tricks users into installing it. Once installed, it can create back doors for other malware or steal information.
  4. Spyware

    • Software that secretly monitors user activity and collects personal information, such as passwords and browsing habits, without consent.
  5. Adware

    • Software that automatically delivers advertisements, often in a disruptive way. While not always harmful, it can slow down devices and may be bundled with more malicious software.
  6. Ransomware

    • A type of malware that locks or encrypts files on a user’s device, demanding payment to restore access. This can be particularly devastating for personal or sensitive information.
  7. Rootkits

    • Tools that allow unauthorized users to gain control over a computer without being detected. They can hide other malware and operate stealthily in the background.
  8. Keyloggers

    • Software that records keystrokes made on a keyboard, capturing sensitive information such as passwords and credit card numbers.
  9. Browser Hijackers

    • Malware that alters a web browser's settings without permission, redirecting users to unwanted websites and changing homepage settings.
  10. Cryptojacking

    • Malware that uses a victim's device to mine cryptocurrencies without their knowledge, slowing down performance and increasing electricity bills.

Preventive Measures:

  • Keep operating systems and apps updated.
  • Use reputable antivirus and anti-malware software.
  • Be cautious of email attachments and links, especially from unknown sources.
  • Regularly backup important data.
  • Avoid downloading software from untrustworthy websites.

Solutions:

For a Tech Person: To effectively combat malware threats, organizations should adopt a multi-layered defense strategy. This includes deploying advanced Endpoint Detection and Response (EDR) solutions that utilize machine learning to identify and respond to Advanced Persistent Threats (APTs). Regular security audits and penetration testing can help uncover vulnerabilities before they are exploited. Implementing a Security Information and Event Management (SIEM) system allows for centralized monitoring and rapid threat mitigation. Additionally, comprehensive user education programs, including phishing simulations, enhance awareness of cybersecurity threats. Finally, a rigorous patch management policy ensures timely updates of all systems and applications to protect against known vulnerabilities. By integrating these measures, organizations can significantly reduce their risk of malware attacks and data breaches.

For a Non-Technical Person: To enhance cybersecurity for non-technical individuals, start by installing reputable antivirus and anti-malware software with real-time protection and automatic updates. Participate in basic cybersecurity training to recognize common threats like phishing emails and suspicious downloads. Practice safe browsing by verifying website legitimacy and being cautious with unfamiliar links. Regularly back up important files to an external hard drive or trusted cloud service to safeguard against data loss. Finally, enable two-factor authentication on sensitive accounts for added security. By following these straightforward steps, individuals can significantly improve their protection against malware and cyber threats.

Slides and Research doc https://gamma.app/docs/Cybersecurity-Challenges-and-Solutions-pp8outrielzfglz?mode=doc https://docs.google.com/document/d/1tG80qstEFJH_RiAdnq_vkALH6UEMpPC-ALogQjZd93s/edit?usp=sharing

Reference links:

  1. Massachusetts Division of Banks - Cybersecurity Guidelines for Financial Institutions

  2. Symantec Internet Security Threat Report

  3. Verizon DBIR - 2024 Data Breach Investigations Report

  4. CISA - Ransomware Guide

  5. McAfee Threats Report - 2024 Threats Predictions Report

  6. Cloudflare - DDoS Attack Types

  7. Imperva - DDoS Protection

  8. NIST - Framework for Improving Critical Infrastructure Cybersecurity

  9. CSO Online - The Importance of Cybersecurity for Businesses

  10. Kaspersky - How to Protect Yourself from Internet Threats

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages