Types of Threats

M4-R5.1 · Chapter 5: Security and Future of IoT Ecosystem · 3 min read

Types of Threats 

1. Malware

  • Definition: A broad term for any malicious file or program designed to harm a computer or its user.

  • Common Examples: * Viruses: Infect other programs and spread.

    • Worms: Self-replicate across networks.

    • Trojan Horses: Disguise themselves as legitimate software.

    • Spyware: Secretly monitors and collects user data.

2. Adware

  • Definition: A specific type of malware focused on advertising.

  • Primary Action: Displays unsolicited, unwanted advertisements while a program is running.

  • Secondary Action: Often tracks and collects user information to serve highly customized, targeted ads without the user's consent.

3. Ransomware

  • Definition: A form of malware that holds a victim's data hostage.

  • How it Works: The attacker infiltrates the system and uses encryption to lock the victim out of their own files or computer system.

  • The Goal: The attacker demands a financial payment (the ransom) in exchange for the decryption key needed to unlock the data.

4. Phishing Attack

  • Definition: A deceptive attempt to steal highly sensitive personal or financial information.

  • Target Data: Usernames, passwords, credit card numbers, and bank account details.

  • The Goal: The attacker intends to either use the stolen information for direct financial gain (identity theft, fraud) or sell it to other criminals on the dark web.

5. DoS (Denial-of-Service) Attack

  • Definition: A malicious attack designed to disrupt the normal operations of a web property by overwhelming it.

  • Primary Strategies:

    • Flooding: Sending an overwhelming amount of traffic to a device or network until it cannot process legitimate requests.

    • Crashing Services: Exploiting specific security vulnerabilities in a system to force it to shut down entirely.

6. DDoS (Distributed Denial-of-Service) Attack

  • Definition: A massive, scaled-up version of a standard DoS attack.

  • The Difference: While a standard DoS attack typically uses a single internet connection to barrage a target, a DDoS attack utilizes thousands or even millions of connected devices.

  • Impact: Because the attack is distributed across so many devices, it is incredibly difficult to stop or block.

7. Botnet

  • Definition: A large group (or "network") of computers that have been infected with malware and hijacked by a malicious actor.

  • The "Bots": Every individual infected device within this network is referred to as a "bot."

  • Common Uses: Hackers use botnets to execute large-scale illegal tasks, including sending massive amounts of spam, stealing data, spreading ransomware, committing ad click fraud, or launching massive DDoS attacks.