Chapter 03: Network and Computer Attacks
any data stored on your computer. You need to make sure your users understand that this information
collection is possible and that spyware programs can register each keystroke entered. It’s that simple. This type
of technology not only exists, but is prevalent. It can be used to record and send everything a user enters to an
unknown person located halfway around the world.
37. What is the difference between spyware and adware?
The difference between spyware and adware is a fine line. Both programs can be installed without the user
being aware of their presence. Adware, however, sometimes displays a banner that notifies the user of its
presence. Adware’s main purpose is to determine a user’s purchasing habits so that Web browsers can display
advertisements tailored to that user. The biggest problem with adware is that it slows down the computer it’s
running on.
38. Explain the advantages of application whitelisting?
Whitelisting helps prevent malicious code from being introduced into corporate networks. Application
whitelisting comes in a few different forms, but ultimately it allows only approved programs to run on a
computer. For example, programs such as Word.exe, Excel.exe, and Safari.exe would be whitelisted. All
programs not on the whitelist would be prevented from executing on the user’s computer, including that
malicious program attached to a phishing e-mail a user clicks on.
39. Explain how the two different types of keyloggers are used?
Keyloggers are hardware devices or software that can be used to capture keystrokes on a computer. Software
keyloggers behave like viruses or Trojan programs. A hardware keylogger is a small device-often smaller than
an inch long. It can usually be installed in less than 30 seconds. It’s a simple matter of unplugging the
keyboard, plugging the keylogging device into a USB port, and then plugging the keyboard into the
keylogging device’s USB port.
40. What is a DDoS attack?
A distributed denial-of-service (DDoS) attack is launched against a host from multiple servers or workstations.
In a DDoS attack, a network could be flooded with literally billions of packets; typically, each participant in
the attack contributes only a few of the total number of packets. If one server bombards an attacked server
with hundreds or even thousands of packets, available network bandwidth could drop to the point that
legitimate users notice a performance degradation or loss of speed. Now imagine 1000 servers or even 10,000
servers involved, with each server sending several thousand IP packets to the attacked server. There you have
it: a DDoS attack. Keep in mind that participants in the attack often aren’t aware their computers are taking
part in the attack. They, too, have been attacked by the culprit.
Match each item with a statement below.