Learning Aim B: Cyber Security


GCSE IT Mind Map on Learning Aim B: Cyber Security, created by James TIPPER on 05/05/2020.
Mind Map by James TIPPER, updated more than 1 year ago
Created by James TIPPER over 2 years ago

Resource summary

Learning Aim B: Cyber Security
    1. ATTACK
      1. A deliberate action, targeting an organizations digital system or data
      2. THREAT
        1. An incident or action which is deliberate or unintended that results in disruption, downtime or data loss
          1. EXTERNAL
            1. Caused outside the organization
            2. INTERNAL
              1. Caused by an incident inside an organization
          2. Cyber Security
            1. The range of measures that can be taken to protect computer systems, networks, and data from: unauthorized access or cyberattack
              1. This refers to someone gaining entry without permission to an organization’s system, software or data. This achieved by exploiting a security vulnerability
                1. HACKER
                  1. Is someone who seeks out and exploits these vulnerabilities.
                    1. Types of Hackers
                      1. White
                        1. working with organizations to strengthen the security of a system
                        2. Grey
                          1. Do it for fun and not with malicious intent
                          2. Black
                            1. They try to inflict damage by compromising security systems
                  2. WHY ARE SYSTEMS ATTACKED?
                    1. Personal Attack
                      1. Friends / family may attack each other if upset over something
                        1. Employees that are unhappy may attack the company
                        2. Information/Data Theft
                          1. Company information may also be stolen
                            1. Credit card and financial details are stolen to gain money
                            2. Disruption
                              1. Attacks such as Denial-of-Service stop websites working
                                1. Viruses can slow down computers and delete files
                                2. Industrial Espionage
                                  1. The aim is to find intellectual property such as designs or blueprints for products, business strategies or software source code
                                  2. Fun/Challenge
                                    1. Friends may give respect of hacking achievements
                                      1. There is a sense of achievement
                                        1. Hacking systems can be fun or a challenge
                                        2. Finacial Gain
                                          1. Ransoms can be made to prevent attacks from happening
                                            1. Ransomware can be used to encrypt a computer until you pay
                                              1. A payment is given to carry out an attack on a organization
                                            2. MaLWare (Malicious software)
                                              1. This is an umbrella term given to software that is designed to harm a digital system, damage data or harvest sensitive information.
                                                1. VIRUS
                                                  1. A piece of malicious code that attaches to a legitimate program. It is capable of reproducing itself and usually capable of causing great harm to files or other programs on the same computer
                                                  2. WORM
                                                    1. Similar to virus but unlike a virus it is a self contained program. It is capable of spreading on it own, without help from humans. Worms get around by exploiting vulnerabilities in operating systems and attaching themselves to emails. They self replicate at a tremendous rate, using up hard drive space and bandwidth, overloading servers.
                                                    2. Trojan Horse
                                                      1. A type of malware that is often disguised as legitimate software. Users are tricked into downloading it to their computer. Once installed the Trojan works undercover to carry out a predetermined task. Such as Backdoor for hackers to use, Installing harmful programs, Harvesting sensitive data. It is named after the wooden horse used by the ancient Greeks to infiltrate the city of Troy.
                                                      2. RootKit
                                                        1. A set of tools that give a hacker a high level administrative control, of a computer. They can then us this privileged position to: Encrypt files Install programs Change system configuration Steal data Much like a trojan, rootkits often come bundled with legitimate software.
                                                        2. Keyloggers
                                                          1. spyware that records every keystroke made on a computer to steal personal information
                                                          2. Ransomware
                                                            1. Encrypts files stored on a computer to extort or steal money from organisations. Victims must then pay a ransom to have the encrypted files unlocked. There is normally a deadline for the transaction to happen. Bitcoin is usually asked for as a form of payment as they are difficult to trace. If the payment is not made then the amount demanded may increase or the files are permanently locked. Ransomware is usually spread through e-mails or through infected websites.
                                                            2. Spyware
                                                              1. malicious software secretly installed to collect information from someone else's computer Cyber criminals harvest personal information such as: Passwords Credit card numbers and other details Email addresses With this information they can steal someone's identity, making purchases on their credit card etc Spyware works in the background on someones computer without it being noticed.
                                                            3. Social Engineering
                                                              1. Involves tricking people into divulging valuable information about themselves. Such as Passwords PIN numbers Credit card details
                                                                1. Phishing
                                                                  1. A way of attempting to acquire information, by pretending to be from a trustworthy source. examples are email spoofing, fake websites, spoof phone calls
                                                                  2. Spear Phishing
                                                                    1. Involves bespoke emails being sent to well-researched victims. eg. where somebody who holds a senior position within an organisation with access to highly valuable information uses it to target victims
                                                                    2. Man in the middle attack
                                                                      1. A form of eavesdropping where the attacker makes an independent connection between two victims and steals information to use fraudulently.
                                                                      2. Blagging
                                                                        1. A blagger invents a scenario to engage a targeted victim in a manner that increases the chance the victim will divulge information. For example a blagger might pretend to be a member of the IT department to inform them something is wrong with your PC and requires access to fix the problem
                                                                        2. Pharming
                                                                          1. Involves redirecting people to bogus, look-a -like websites without realising it has happened. The objective is to acquire sensitive personal information or to install malware
                                                                          2. Shoulder Surfing
                                                                            1. Acquiring sensitive information by someone peering over a users shoulder when they are using a device. It can also be done from a distance with the use of technology such as video cameras, drones etc
                                                                          Show full summary Hide full summary


                                                                          Project Communications Management
                                                                          Common Technology Terms
                                                                          Julio Aldine Branch-HCPL
                                                                          Network Protocols
                                                                          Shannon Anderson-Rush
                                                                          Kwame Oteng-Adusei
                                                                          Shannon Anderson-Rush
                                                                          HTTPS explained with Carrier Pigeons
                                                                          Shannon Anderson-Rush
                                                                          Introduction to the Internet
                                                                          Shannon Anderson-Rush
                                                                          Useful String Methods
                                                                          Shannon Anderson-Rush
                                                                          Historical Development of Computer Languages
                                                                          Shannon Anderson-Rush
                                                                          Web Designing & Development Full Tutorial
                                                                          Nandkishor Dhekane
                                                                          LAN and WAN
                                                                          Nathan Roberts