7 - Malicious Code Flashcards
1
Q
Botnets
A
Network of computers infected by malicious code
C2 is a control server or machine that relays with individual bots
Extract info, Ddos, etc
2
Q
APT
A
Targeted at individual organizations
Low and slow
Unique
3
Q
Malware analysis
A
Static - what would happen if executed
Dynamic
- different granularity
- execute the program
4
Q
Viruses, backdoors, logic bombs, Trojan horses, worms
A
Virus - infect program by modifying it and then self copy
Backdoor - secret entry point into program or system
Logic bomb - wait and perform malicious activity when activated
Trojan horse - hidden in useful program, executes when main program is run
Worm - use network connections to spread, exploiting vulnerability