Computer Awareness Study Material – Computer Security
Computer Awareness Study MaterialBanking AwarenessMarketing Aptitude
Computer security is also known as cyber security or IT security. Computer security is a branch of information technology known as information security, which is intended to protect computers. It is the protection of computing systems and the data that they store or access.
Methods to Provide Protection
There are four primary methods to provide protection
- System Access Control It ensures that unauthorised users do not get into the system by encouraging authorised users to be security conscious.
- Data Access Control It monitors who can access what data, and for what purpose.Your system might support mandatory access controls with these. The sytem determines access rules based on the security levels of the people, the files, and the other objects in your system.
- System and Security Administration It performs offline procedures that makes or breaks secure system.
- System Design It takes advantage of basic hardware and software security characteristics.
Components of Computer Security
Computer security is associated with many core areas. Basic components of computer security system are
- Confidentiality It ensures that data is not accessed by any unauthorised person.
- Integrity It ensures that information is not altered by any unauthorised person in such a way that it is not detectable by authorised users.
- Authentication It ensures that users are the persons they claim to be.
- Access Control It ensures that users access only those resources that they are allowed to access.
- Non-Repudiation It ensures that originators of messages cannot deny they are not sender of the message.
- Availability It ensures that systems work promptly and service is not denied to authorised users.
- Privacy It ensures that individual has the right to use the information and allows another to use that information.
- Stenography It is an art of hiding the existance of a message. It aids confidentiality and integrity of the data.
- Cryptography It is the science of writing information in a ‘hidden’ or ‘secret’ form and is an ancient art. It protects the data in transmit and also the data stored on the disk. Some terms commonly used in cryptography are
- Plain Text It is the original message that is an input.
- Cipher It is a bit-by-bit or character-bycharacter transformation without regard to the meaning of the message.
- Cipher Text It is the coded message or the encrypted data.
- Encryption It is the process of converting plain text to cipher text, using an encryption algorithm.
- Decryption It is the reverse of encryption, converting cipher text to plain text.
Sources of Cyber Attack
The most potent and vulnerable threat of computer users is virus attacks. A computer virus is a small software program that spreads from one computer to another and that interferes with computer operation. It is imperative for every computer user to be aware about the software and programs that can help to protect the personal computers from attacks.
The sources of attack can be
- Downloadable Programs Downloadable files are one of the best possible sources of virus. Any type of executable file like games, screen saver are one of the major sources. If you want to download programs from the Internet then it is necessary to scan every program before downloading them.
- Cracked Software These softwares are another source of virus attacks. Such cracked forms of illegal files contain virus and bugs that are difficult to detect as well as to remove. Hence, it is always a preferable option to download software from the appropriate source.
- E-mail Attachments These attachments are the most common source of viruses. You must handle E-mail attachments with extreme care, especially if the E-mail comes from an unknown sender.
- Internet Majority of all computer users are unaware as when viruses attack computer systems. Almost all computer users click or download everything that comes their way and hence unknowingly invites the possibility of virus attacks.
- Booting from Unknown CD When the computer system is not working, it is a good practice to remove the CD. If you do not remove the CD, it may start to boot automatically from the disk which enhances the possibility of virus attacks.
Malware:
Threats to Computer Security
Malware stands for malicious software. It is a broad term that refers to a variety of malicious programs that are used to damage computer system, gather sensitive information, or gain access to private computer systems. It includes computer viruses, worms, trojan horses, rootkits, spyware, adware, etc.
Some of them are described
Virus
VIRUS stands for Vital Information Resources Under Siege. Computer viruses or perverse softwares are small programs that can negatively affect the computer. It obtains control of a PC and directs it to perform unusual and often destructive actions. Viruses are copied itself and attached itself to other programs which further spread the infection. The virus can affect or attack any part of the computer software such as the boot block, operating system, system areas, files and application program.
Type of Virus
Some common types of viruses are
Resident Virus It fixes themselves into the system’s memory and get activated whenever the OS runs and infects all the files that are then
- It hides in the RAM and stays there even after the malicious code is executed, e.g. Randex, Meve, etc.
- Direct Action Virus It comes into action when the file containing the virus is executed. It infects files in the folder that are specified in the AUTOEXEC.bat file path. e.g. Vienna virus.
- Overwrite Virus It deletes the information contained in the files that it infects, rendering them partially or totally useless, once they have been infected. e.g. Way, Trj.Reboot, Trivial.88.D, etc.
- Boot Sector Virus It is also called Master Boot Sector Virus or Master Boot Record Virus. This type of virus affects the boot sector of a hard disk. e.g. Polyboot.B, AntiEXE, etc.
- Macros Virus It infects files that are created using certain applications or programs that contain macros, like .doc, .xls, .ppt, etc. e.g. Melissa.A.
- File System Virus It is also called Cluster Virus or Directory Virus. It infects the directory of your computer by changing the path that indicates the location of a file, e.g. Dir-2 virus.
- Polymorphic Virus It encrypts or encodes itself in an encrypted way, every time it infects a system. This virus then goes on to create a large number of copies, e.g. Elkern, Tuareg, etc.
- FAT Virus It is used to store all the information about the location of files, unusable space, etc. e.g. Link virus, etc.
- Multipartite Virus It may spread in multiple ways such as the operating system installed or the existance of certain files, e.g. Flip.
- Web Scripting Virus Many Websites execute complex code in order to provide interesting content. These sites are sometimes created with purposely infected code. e.g. JS Fortnight.
Some common viruses are tabulated below
Year | Name |
1971 | Creeper |
1982 | Elk Cloner |
1988 | The Morris Internet Worm |
1999 | Melissa |
2000 | I Love You |
2001 | Code Red |
2003 | SQL Slammer |
2003 | Blaster |
2004 | Sasser |
2010 | Stuxnet |
2011 | Trojan |
2012 | Rootkit |
2014 | Generic PUP |
2014 | Net Worm |
Effects of Virus
There are many different effects that viruses can have on your computer, depending on the types of virus. Some viruses can
- monitor what you are doing.
- slow down your computers performance.
- destroy all data on your local disk.
- affect on computer networks and the connection to Internet.
- increase or decrease memory size.
- display different types of error messages.
- decrease partition size.
- alter PC settings.
- display arrays of annoying advertising.
- extend boot times.
- create more than one partition.
Worms
A computer worm is a standalone malware computer program that replicates itself in order to spread to other computers. Often, it uses a computer network to spread itself, relying on security failures on the target computer to access it. Worms are hard to detect because they are invisible files.
e.g. Bagle, I love you, Morris, Nimda, etc.
Trojan
A Trojan, or Trojan Horse, is a non-self-replicating type of malware which appears to perform a desirable function but instead facilitates unauthorised access to the user’s computer system. Trojans do not attempt to inject themselves into other files like a computer virus. Trojan Horses may steal information, or harm their host computer systems. Trojans may use drive-by downloads or install via online games or Internet-driven applications in order to reach target computers. Unlike viruses, Trojan horses do not replicate themselves, e.g. Beast, Sub7.Zeus, ZeroAccess Rootkit, etc.
Spyware
It is a program which is installed on a computer system to spy on the system owner’s activity and collects all the information which is misused afterwards. It tracks the user’s behaviour and reports back to a central source.
These are used for either legal or illegal purpose. Spyware can transmit personal information to another person’s computer over the internet.
e.g. CoolWeb Search, FinFisher, Zango, Zlob Trojan, Keyloggers, etc.
Symptoms of Malware Attack
There is a list of symptoms of malware attack which indicates that your system is infected with a computer malware.
Some primary symptoms are
- Odd messages are displaying on the screen.
- Some files are missing.
- System runs slower.
- PC crashes and restarts again and again.
- Drives are not accessible.
- Antivirus software will not run or installed.
- Unexpected sound or music plays.
- The mouse pointer changes its graphic.
- System receives strange E-mails containing odd attachments or viruses.
- PC starts performing functions like opening or closing window, running programs on its own.
Some Other Threats to Computer Security
There are some other threats which are described below
- Spoofing It is the technique to access the unauthorised data without concerning to the authorised user. It accesses the resources over the network. It is also known as ‘Masquerade’. IP spoofing is a process or technique to enter in another computer by accessing its IP address. It pretends to be a legitimate user and access to its computer via a network.
- Salami Technique It diverts small amounts of money from a large number of accounts maintained by the system.
- Hacking It is the act of intruding into someone else’s computer or network. Hacking may result in a Denial of Service (DoS) attack. It prevents authorised users from accessing the resources of the computer. A hacker is someone, who does hacking process.
- Cracking It is the act of breaking into computers. It is a popular, growing subject on Internet. Cracking tools are widely distributed on the Internet. They include password crackers, trojans, viruses, war- dialers, etc.
- Phishing It is characterised by attempting to fraudulently acquire sensitive information such as passwords, credit cards details, etc by masquerading as a trustworthy person. Phishing messages usually take the form of fake notifications from banks providers, E-pay systems and other organisation. It is a type of Internet fraud that seeks to acquire a user’s credentials by deception.
- Spam It is the abuse of messaging systems to send unsolicited bulk messages in the form of E-mails. It is a subset of electronic spam involving nearly identical messages sent to numerous recipients by E-mails.
- Adware It is any software package which automatically renders advertisements in order to generate revenue for its author. The term is sometimes used to refer the software that displays unwanted advertisements. A software license is a document that provides legally binding guidelines on the use and distribution of software.
- Rootkit It is a type of malware that is designed to gain administrative level control over a computer system without being detected. Rootkits can change how the operating system functions and in some cases, can temper with the antivirus program and render it infective. Rootkits are also difficult to remove, in some cases, require a complete re-installation of the operating system.
Solutions to Computer Security Threats
Some safeguards (or solutions) to protect a computer system from accidental access, are described below
Antivirus Software
It is a application software that is designed to prevent, search for, detect and remove viruses and other malicious software like worms, trojans, adware and more. It consists of computer programs that attempt to identify threats and eliminate computer viruses and other malware.
Some Popular Antivirus
- Avast Avg
- K7 Kaspersky
- Trend Micro
- Quick Heal
- Symantec Norton
- McAfee
Digital Certificate
It is the attachment to an electronic message used for security purposes. The common use of a digital certificate is to verify that a user sending a message is who he or she claims to be, and to provide the receiver with the means to encode a reply. It provides a means of proving your identity in electronic transactions.
Digital Signature
It is an electronic form of a signature that can be used to authenticate the identity of the sender of a message or the signer of a document, and also ensure that the original content of the message or document that has been sent is unchanged.
Firewall
It can either be software-based or hardware-based and is used to help in keeping a network secure. Its primary objective is to control the incoming and outgoing network traffic by analysing the data packets and determining whether it should be allowed through or not, based on a predetermined rule set.
A network’s firewall builds a bridge between an internal network that is assumed to be secure and trusted, and another network, usually an external (inter) network, such as the Internet, that is not assumed to be secure and trusted. A firewall also includes or works with a proxy server that makes network requests on behalf of workstation users.
There are two forms of firewalls Hardware firewall and software firewall
Password
It is a secret word or a string of characters used for user authentication to prove identity or access approval to gain access to a resource, which should be kept secret from those who are not allowed to get access.
A password is typically somewhere between 4 to 16 characters, depending on how the computer system is setup. When a password is entered, the computer system is careful not to display the characters on the display screen, in case others might see it.
There are two common modes of password as follows
- Weak Password Easily remember just like names, birth dates, phone number, etc.
- Strong Password Difficult to break and a combination of alphabets and symbols.
File Access Permission
Most current file systems have methods of assigning permissions or access rights to specific users and group of users. These systems control the ability of the users to view or make changes to the contents of the file system. File access permission refers to privileges that allow a user to read, write or execute a file.
There are three specific permissions as follows
- Read Permission If you have read permission of a file, you can only see the contents. In case of directory, access means that the user can read the contents.
- Write Permission If you have write permission of a file, you can only modify or remove the contents of a file. In case of directory, you can add or delete contents to the files of the directory.
- Execute Permission If you have execute permission of a file, you can only execute a file. In case of directory, you must have execute access to the bin directory in order to execute it or cd command.
Terms Related to Security
- Eavesdropping The attacker monitors transmissions for message content.
- Masquerading The attacker impersonates an authorised user and thereby gain certain unauthorised privilege.
- Patches It is a piece of software designed to fix problems with a computer program or its supporting data. This includes fixing security vulnerabilities and other bugs and improving the usability and performance.
- Logic Bomb It is a piece of code intentionally inserted into a computer’s memory that will set off a malicious function when specified conditions are met. They are also called slag code and does not replicate itself
- Time bomb It is a piece of software, that is used to the explode at a particular time.
- Application Gateway This applies security mechanisms to specific applications such as File Transfer Protocol (FTP) and Telnet services.
- Proxy Server It can act as a firewall by responding to input packets in the manner of an application while blocking other packets.
It hides the true network addresses and used to intercept all messages entering and leaving the network.
QUESTION BANK
1. A ……….. is anything that can cause harm.
- vulnerability
- phishing
- threat
- spoof
- None of these
2. A ……….. is a small program embedded inside of a GIF image.
- Web bug
- cookie
- spyware application
- spam
- None of these
3. A hacker contacts your phone or E-mails and attempts to acquire your password is called
- spoofing
- phishing
- spamming
- buging
- None of these
4. The unauthorised real-time interception of a private communication such as a phone call, instant message known as
- Replay
- Eavesdropping
- Patches
- Payloads
- None of these
5. Hackers often gain entry to a network be pretending to be at a legitimate computer
- spoofing
- forging
- IP spoofing
- All of these
- None of these
6. The main reason to encrypt a file is to
- reduce its size
- secure it for transmission
- prepare it for backup
- include it in the start-up sequence
- None of the above
7. Mechanism to protect network from outside attack is
- firewall
- antivirus
- digital signature
- formatting
- None of these
8. …………… is a form of virus explicitly designed to hide itself from detection by antivirus software.
- Stealth virus
- Polymorphic virus
- Parasitic virus
- Macro virus
- None of these
9. The first PC virus was developed in
- 1980
- 1984
- 1986
- 1988
- 1987
10. Abuse messaging systems to send unsolicited is
- phishing
- spam
- malware
- firewall
- adware
11. ………… are often delivered to PC through an E-mail attachment and are often designed to do harm.
- Viruses
- Spams
- Portals
- E-mail messages
- None of these
12. The first computer virus is
- creeper
- PARAM
- the famous
- HARLIE
- None of these
13. A time bomb occurs during a particular
- data or time
- logic and data
- time
- All of these
- None of these
14. First boot sector virus is
- computed
- mind
- brain
- Elk Cloner
- None of these
15. Which virus spreads in application software?
- Macro virus
- Boot virus
- File virus
- Antiyirus
- None of these
16. Some viruses have a delayed payload, which is sometimes called a
- time
- anti-virus
- bomb
- All of these
- None of these
17. An antivirus is a(n)
- program code
- computer
- company name
- application software
- None of these
18. It is a self-replicating program that infects computer and spreads by inserting copies of itself into other executable code or documents.
- Keylogger
- Worm
- Virus
- Cracker
- None of these
19. Like a virus, it is a self-replicating program. It also propagates through computer network.
- Spyware
- Worm
- Cracker
- Phishing scam
- None of these
20. What is an E-mail attachment?
- A receipt sent by the recipient
- A separate document from another program sent along with an E-mail message
- A malicious parasite that feeds off your messages and destroys the contents
- A list of Cc : or Bcc : recipients
- A friend to whom E-mail is sent regularly
21. Password enables users to
- get into the system quickly
- make efficient use of time
- retain confidentiality of files
- simplify file structure
- None of the above
22. A program designed to destroy data on your computer which can travel to infect other computers, is called a
- disease
- tarpedo
- hurricave
- virus
- None of these
23. Antivirus software is an example of
- business software
- an operating system
- a security
- an office suite
- None of the above
24. Hackers
- all have the same motive
- is another name of users
- many legally break into computer as long as they do not do any damage
- are people who are allergic to computers
- break into other people’s computer
25. Which was the first PC boot sector virus?
- Creeper
- Payload
- Bomb
- Brain
- None of these
26. There are viruses that are triggered by the passage of time or on a certain date.
- Boot-sector viruses
- Macro viruses
- Time bombs
- Worms
- None of these
27. It is the process of finding errors in software code
- Debugging
- Compiling
- Testing
- All of these
- None of these
28. ………… is the process of finding errors in software code?
- Compiling
- Testing
- Running
- Debugging
- None of the above
29. Which one of the following is a cryptographic protocol used to secure http connection? [RBI Grade B 2009]
- Stream Control Transmission Protocol(SCTP)
- Transport Layer Security (TLS)
- Explicit Congestion Notification (ECN)
- Resource Reservation Protocol (RRP)
- None of the above
30. A firewall operated by [SBI Clerk 2010]
- the pre-purchase phase
- isolating intranet from extranet
- screening packets to/from the network and provide controllable filtering of network traffic
- All of the above
- None of the above .
31. Which of the following is a criminal activity attempting to acquire sensitive information such as passwords, credit cards, debits by masquerading as a trustworthy person or business in an electronic communication? [IBPS Clerk 2010]
- Spoofing
- Phishing
- Stalking
- Hacking
- None of these
32. Which one of the following is a key function of firewall? [SBI PO 2010]
- Monitoring
- Deleting
- Copying
- Moving
- None of these
33. Junk E-mail is also called [Union Bank of India 2011]
- spam
- spoof
- sniffer script
- spool
- None of these
34. A person who uses his or her expertise to gain access to other people computers to get information illegally or do damage is a [Allahabad Bank PO 2011]
- spammer
- hacker
- instant messenger
- All of these
- None of these
35. Vendor created program modifications are called [Allahabad Bank PO 2011]
- patches
- antiviruses
- hales
- fixes
- overlaps.
36. The ………… of a threat measures its potential impact on a system. [IBPS Clerk 2011]
- vulnerabilities
- counter measures
- degree of harm
- susceptibility
- None of these
37. A digital signature is [SBI Clerk 2011]
- scanned signature
- signature in binary form
- encrypting information
- handwritten signature
- None of the above
38. Which of the following a computer’s memory, but unlike a virus, it does not replicate itself ? [SBI PO 2011]
- Trojan horse
- Logic bomb
- Cracker
- Firewall
- None of these
39. Computer virus is [IBPS Clerk 2011]
- a hardware
- windows tool
- a computer program
- a system software
- None of the above
40. A program designed to destroy data on your computer which can travel to “infect” other computers is called a [RBI Grade B 2012]
- disease
- torpedo
- hurricane
- virus
- infector
41. If your computer rebooting itself then it is likely that [SBI Clerk 2012]
- It has a virus
- It does not have enough memory
- There is no printer
- There has been a power surge
- It need a CD-ROM
42. Viruses trojan horses and worms are [IBPS Clerk 2012]
- able to harm computer system
- unable to detect if present on computer
- user-friendly applications
- harmless applications resident on computer
- None of the above
43. To protect yourself from computer hacker intrusions you should install a [RBI Grade B 2012]
- firewall
- mailer
- macro
- script
- None of these
44. The legal right to use software based on specific restrictions is granted via a [RBI Grade B 2012]
- software privacy policy
- software license
- software password manager
- software log
- None of the above
45. ………. are attempts by individuals to obtain confidential information from you by falsifying their identity. [IBPS PO 2011, IBPS Clerk 2013]
- Phishing trips
- Computer viruses
- Spyware scams
- Viruses
- Phishing scams
46. All of the following are examples of real-security and privacy risks except [SBI PO 2011, IBPS Clerk 2014]
- hackers
- spam
- viruses
- identify theft
- None of the above
47. Which of the following refers to dangerous programs that can be ‘caught’ of opening E-mail attachments and downloading software from the Internet? [SBI PO 2014]
- Utility
- Virus
- Honey Pot
- Spam
- App
48. Which of the following enables to determine how often a user visited a Website? [IBPS Clerk 2014]
- Hackers
- Spammers
- Phish
- Identity thefts
- Cookies
49. What is a person called who uses a computer tp cause harm to people or destroy critical systems? [IBPS Clerk 2014]
- Cyber Terrorist
- Black-hat-Hacker
- Cyber Cracker
- Hacktivist
- Other than those given as options
50. Verification of a login name and password is known as [IBPS Clerk 2014]
- configuration
- accessibility
- authentication
- logging in
- Other than those given as options
51. ………. refers to the unauthorised copying and distribution of software. [IBPS Clerk 2014]
- Hacking
- Software piracy
- Software literacy
- Cracking
- Copyright
52. Software such as Viruses, Worms and Trojan Horses that has a malicious content, is known as [IBPS Clerk 2014]
- Malicious software (malware)
- adware
- scareware
- spyware
- firewall
53. ……… are often delivered to a PC through an mail attachment and are often designed to do harm. [IBPS PO 2015]
- Portals
- Spam
- Viruses
- Other than those given as options
- E-mail messages
54. A computer virus normally attaches itself to another computer program known as a [IBPS PO 2015]
- host program
- target program
- backdoor program
- Bluetooth
- Trojan horse
55. If you are allowing a person on the network based on the credentials to maintain the security of your network, then this act refers to the process of [IBPS PO 2016]
- Authentication
- Automation
- Firewall
- Encryption
- Decryption
ANSWERS
Leave a Reply