Malware Flashcards
How is malware classifed
How it spreads and the payload, as if they need a host program/are independent and whether it replicates or not
Attack Kit
A toolkit which provides a variety of payloads that novices can deploy
Attack Sources
Pollitically motivated, criminals, organised crime, organisations that sell services, national gov agenices
APTS Meaning
Advanced Persistent Threats
APTS Definition
Persistent use of variety of intrusion tech to selected targets.
APTS Characteristics
Advanced (wide variety of tech), persistent (attacks over extended period of time), threats (active involvement of people increases threat liklihood)
Aim of APTS?
From stealing Intellectual property to disrupting a network
APTS techniques
Social engineering, spear phishing, drive by downloads
Intent of APTS?
to infect target and use other tools to maintain access
Virus
Malware which infects a program and modifies to include a copy. Secretely run when the host program is run
Virus Components
Infection Mechanism (Vector), Trigger (Logic Bomb), Payload
Virus Phases
Dormant, Triggering, Propagation, Execution
Triggering Phase
Virus is activated caused by system events
Dormant Phase
Virus is idle. will be activated. not all have this.
Propagation Phase
Places a copy in programs
Execution Phase
Function is performed, may be harmless or damaging
Macro + Scripting Viruses
Attaches itself to documents and uses macro programming capabilities of documents application to execute and propagate
Why are macro viruses threatening
Platform dependent, infect documents not code, easily spread, traditional file access system control struggles to find them, much easier to write/modify than traditional viruses