How to Protect Against Internet Threats | Free Antivirus
The Internet is a limitless world of information that provides ample opportunities for communication, education, organization of work and leisure, and at the same time represents a huge, daily replenishing database that contains information about users of interest to cybercriminals. There are two main types of threats that users can be exposed to technical and social engineering.
Technical threats
The main technical threats to users are malware, botnets, and DoS and DDoS attacks.
Malicious programs
The purpose of malware is to cause damage to a computer, server, or computer network. They can, for example, spoil, steal or erase data stored on the computer, slow down or completely stop the operation of the device. Malicious programs often "hide" in letters and messages with tempting offers from unknown persons and companies, in the pages of news sites or other popular resources that contain vulnerabilities. Users visit these sites and malware invisibly infiltrates the computer.
Also, malware spreads via e-mail, removable media or files downloaded from the Internet. Files or links sent by email can expose your device to infection.
Malicious programs can also hide under the guise of sound or graphic messages. For example, a beautiful screen saver that the user enjoys admiring may turn out to be a Trojan horse (read below for what it is). Links that appear in pop-ups and advertisements on various sites may also contain viruses.
Malware includes viruses, worms, Trojans.
A virus is a type of computer program, a distinctive feature of which is the ability to reproduce (self-replicate) and invisible to the user to penetrate into files, boot sectors of disks and documents. The name "virus" about computer programs came from biology precisely because of its ability to reproduce itself. A virus lying in the form of an infected file on the disk is not dangerous until it is opened or launched. It takes effect only when the user activates it. Viruses are designed to copy themselves by infecting computers, usually destroying files.
Worms are a type of virus. They fully live up to their name, since they spread by "crawling" from device to device. Just like viruses, they are self-replicating programs, but unlike viruses, the worm does not need the user's help to spread. He finds the loophole himself.
Trojans are malicious programs that are deliberately introduced by cybercriminals to collect information, destroy or modify it, disrupt the performance of a computer, or use its resources for unseemly purposes. Outwardly, Trojans look like legitimate software products and are not suspicious. Unlike viruses, they are fully prepared to perform their functions. This is what the cybercriminals are counting on: their task is to create a program that users will not be afraid to launch and use.
Attackers can infect a computer to make it part of it botnets are networks of infected devices located all over the world. Large botnets can include tens or hundreds of thousands of computers. Users often do not even know that their computers are infected with malware and are being used by hackers. Botnets are created by sending malicious programs in various ways, and the infected machines regularly receive commands from the botnet administrator, so that it becomes possible to organize coordinated actions of bot computers to attack other devices and resources.
DoS and DDoS attacks
The essence of a DoS attack is that an attacker tries to make a specific server temporarily unavailable, overload the network, processor, or overflow a disk. The aim of the attack is simply to disable the computer, not to obtain information, to seize all the resources of the victim computer so that other users do not have access to them. Resources include memory, processor time, disk space, network resources, etc.
There are two ways to carry out a DoS attack.
The first method exploits a vulnerability in the software installed on the attacked computer for a DoS attack. The vulnerability allows you to trigger a certain critical error that will lead to a malfunction of the system.
In the second method, the attack is carried out by simultaneously sending a large number of information packets to the attacked computer, which causes network congestion.
If such an attack is carried out simultaneously from a large number of computers, then in this case they speak of a DDoS attack.
To organize DDoS attacks, cybercriminals use a botnet - a special network of computers infected with a special type of virus. An attacker can control each such computer remotely, without the owner's knowledge. With the help of a virus or a program that cleverly masquerades as legal, malicious code is installed on the victim's computer, which is not recognized by the free antivirus and runs in the background. At the right time, at the command of the botnet owner, such a program is activated and starts sending requests to the attacked server, as a result of which the communication channel between the attacked service and the Internet provider fills up and the server stops working.
Social engineering
Most attackers rely not only on technology but also on human weakness, using social engineering to do so. This complex term denotes a way to obtain the necessary information not with the help of technical capabilities, but through ordinary deception and cunning. Social engineers apply psychological techniques to people through email, social media, and instant messaging. As a result of their skilful work, users voluntarily give out their data, not always realizing that they have been deceived.
Fraudulent messages most often include threats, such as closing user bank accounts, promises of huge winnings with little or no effort, and requests for donations from charities. For example, a message from an attacker might look like this: “Your account has been blocked. To restore access to it, you need to confirm the following data: phone number, email and password. Send them to such and such an e-mail address. " Most often, attackers do not leave the user time for reflection, for example, they ask to pay on the day they receive the letter.
Phishing
Phishing is the most popular method of attacking users and one of the methods of social engineering. It is a special type of Internet fraud. The purpose of phishing is to gain access to confidential data such as an address, phone number, credit card numbers, logins and passwords by using fake web pages. A phishing attack often happens in the following way: a letter comes to your e-mail with a request to enter the Internet banking system on behalf of an alleged bank employee. The letter contains a link to a false site, which is difficult to distinguish from the real one. The user enters personal data on a fake site, and the attacker intercepts them. Having taken possession of personal data, he can, for example, get a loan in the user's name, withdraw money from his account and pay with his credit cards,
There are many types and methods of attacks, but there are also a sufficient number of ways to defend against them. When using the Internet, we recommend that you meet the following requirements:

Comments
Post a Comment