11.1 Internet Worms Flashcards

1
Q

Virus

A

“Infection” of an existing program that results in modification of behavior

Typically require user action to spread, for example, opening an attachment on an email or running a executable file that a friend gave you on a USB key

Require user activity

spreads manually

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Worm

A

Code that propagates/replicates across the network

Is spread by exploiting flaws in existing programs or open services

Propagate automatically

spreads automatically

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Parasitic (Type of Virus)

A

infects executable files

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Memory-resident (Type of Virus)

A

infect running programs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Boot-sector (Type of Virus)

A

spreads when system is booted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Polymorphic (Type of Virus)

A

encrypt part of virus program using a randomly generated key

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the main difference between a worm and a virus?

A

Worms can spread automatically

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Worm Lifecycle

A
  1. Discover/ “scan” for vulnerable hosts

2. Infect vulnerable machines via remote exploit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the 3 steps in a worm’s “life cycle”?

A
  1. Scanning for vulnerable hosts
  2. Infect vulnerable host
  3. Remaining undetectable
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Increasing Initial Compromise Rate

A
  1. Hit List: List of vulnerable hosts

2. Permutation scanning: shared permutation of IP address lists. Start from own IP + work down

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What allowed Slammer to spread quickly?

A

UDP/connectionless transport

Could fit in a single packet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly