Skip to main content

Command Palette

Search for a command to run...

Cyberattacks

Published
•5 min read•View as Markdown
Cyberattacks

A cyberattack is a deliberate action taken by a person or institution to violate the information system of an individual or organization.

The effect of an attack can not be overemphasized. A successful attack can cause an organization or an individual financial loss, damage to their reputation, disclosure of trade secrets and confidential information, legal liability. Its impact can be devastating; therefore, it is crucial to take cybersecurity seriously.

There are two classifications of attacks; passive attack and active attack.

PASSIVE ATTACK

A passive attack is an attack in which an intruder monitors a network for the sole purpose of information gathering. The attacker gains unauthorized access to the network or information system, monitors the network, and steals information without altering the information system.

Passive attacks are difficult to detect because there is no modification in the information system.

This attack is used in the reconnaissance stage of the cyber kill chain.

Examples of passive attacks include eavesdropping and traffic flow analysis.

ACTIVE ATTACK

In an active attack, the cybercriminal modifies a data stream, interferes with or interrupts an information system's normal functioning. It is easy to detect but difficult to prevent an active attack, and this is because of the diverse techniques used by cybercrime actors. As cybersecurity personnel, the goal is to detect this attack early to recover quickly from its effect.

Examples of active attacks include masquerading, replay, modification, and denial of service.

Examples of Attacks and the Cybersecurity Principle they breach

Whenever a cyberattack occurs, one or more cybersecurity principles are breached. These principles include confidentiality, integrity, availability, authentication, and non-repudiation.

Examples of attacks,

Eavesdropping: The traditional means of eavesdropping is listening to people's conversations. Technically, this occurs when an intruder intercepts the communication between two parties without their knowledge, gaining access to the data passed between the communicating parties.

This is an attack on the confidentiality of information.

Traffic flow analysis: In this attack, the attacker is interested in the size and frequency of the information transferred within a network. He monitors the network to know the number of packets sent and how often they are sent.

This is an attack on the confidentiality of information. Though the attacker has no access to the content of the packets, he is gaining insight into the network by studying the frequency and size of the packets.

Masquerading: This is the impersonation of an authorized person or system. In this attack, a cybercrime actor masks or uses a well-known email address, website, or computer system to communicate with an unsuspecting individual. This attack can be used to gain access to a person's information and spread malware through infected links or attachments.

This attack breaches the authentication of the authorized entity's identity. Authentication is the process of proving the identity of a person or system. It is the assurance that the communicating entity is truly who it said it is.

Replay: Replay is an attack in which an attacker intercepts a network and captures a legitimate message, delays the message, then retransmit it to the intended receiver. This is like masquerading; the receiving party believes the message is from a known source, whereas an intruder retransmitted it though it might not have been modified. This is a breach of authentication.

A replay attack can also constitute a breach of the integrity of a message. A delay in the delivery of information can lead to the violation of the integrity of the information. For instance, Ada and Kamsi are work colleagues, and a malicious actor intercepts their WhatsApp chat. Kamsi sends Ada a message, and the message was captured by the malicious actor who reads it and then resends it to Ada the next day without modifying the message.

Let's say the message Kamsi sent was, "You have a presentation tomorrow." She sent it on Sunday, and the presentation is scheduled to hold the next day, that is, Monday, but the information was delivered to Ada on Monday. Ada reads the message and thinks that the presentation is on Tuesday.

In this instance, the delay in the delivery of the information led to the misinterpretation of the message. The principle of integrity is about the authenticity of data and preventing unauthorized modification of the data.

Modification: In this attack, communication between two parties is intercepted, and information passed between the communicating parties is altered by an intruder. It also means tampering with an information system or infrastructure. Modification is an attack on the integrity of information or an information system.

Denial of service (DoS): This occurs when authorized users are unable to access information. This is an attack in which the crime actor shuts down a computer system, website, or network, making it inaccessible to legitimate users. This is done by flooding the target with so much traffic than it can handle, causing the target to crash. DoS is a violation of the principle of availability.

Most of the attacks mentioned above can be prevented by using multi-factor authentication. As an individual, using multi-factor authentication on your various social media accounts or websites can prevent an attacker from intruding into your communications.

Masquerading can be hard to detect, especially IP spoofing, but a phishing email can be detected if the email is carefully examined. One can avoid being a victim of phishing attacks by not clicking on links or opening email attachments in your email.

Denial of Service can be prevented by monitoring and analyzing your network, increasing your bandwidth, and creating a Denial of Service response plan.