AP® Cybersecurity review sheet from Aim for Five (aimforfive.com/cybersecurity/units/4/4-1)
Unit 4 · Topic 4.1
4.1 Device Vulnerabilities and Attacks
Devices store, process and send all the world's data, from servers to insulin pumps. This topic covers the four kinds of computing devices, the main types of malware and how to tell them apart, the common weak spots adversaries exploit, and how to rate device risks.
Key terms
- embedded computer (IoT)
- virus vs. worm
- trojan and remote access trojan (RAT)
- ransomware
- rootkit
- fileless malware
Kinds of computing devices
- Servers provide services to other computers, like DNS, DHCP (handing out IP addresses) or file transfer. Any computer can act as a server, but business servers usually have more processing power and storage than a personal computer.
- Personal computers are built for one person's work or fun: desktops, laptops and notebooks.
- Handheld (mobile) computers are smaller and run on batteries: phones, tablets and wearables like smart watches.
- Embedded computers are built into a machine to control its parts. They tend to be slower and cheaper, with little storage. When an everyday object has an embedded computer and a network connection, it's usually called an Internet of Things (IoT) device. They're in cars, trains and planes; in critical infrastructure like electrical substations and water treatment pumps; in medical equipment like IV pumps, MRI scanners, pacemakers and insulin pumps; and in washing machines, coffee makers and thermostats.
Types of malware
Malware is any software written to do harm: wreck a device or network, or let an adversary in. It's usually one tool in a bigger plan. Learn the defining feature of each type:
| Type | Defining feature |
|---|---|
| Virus | Activates only when a user runs or opens an infected file |
| Worm | Spreads from computer to computer with no human action |
| Trojan | Hides inside software that looks harmless |
| Remote access trojan (RAT) | A trojan that gives the adversary remote control of the device |
| Ransomware | Encrypts files, then demands payment for the key, usually with a deadline |
| Spyware | Tracks what the user does and reports back |
| Keylogger | Records keystrokes (software or a hardware plug) so passwords can be pulled out |
| Logic bomb | Waits for a condition, like a date or a certain operating system, before acting |
| Rootkit | Burrows into the operating system, controls almost everything and hides itself |
| Fileless malware | Lives in memory (RAM) and misuses programs already installed, leaving no malware file |
Common device weak spots
- Unpatched software. Adversaries write exploits for known flaws, which can let them crash the system, watch the user, switch on a webcam or microphone, or take full control.
- Weak authentication. Easy-to-guess passwords, or users tricked into giving them up.
- No BIOS or UEFI password. The BIOS or UEFI is the firmware that starts the computer. Without a password on it, an adversary can boot into a special mode, like recovery mode, with high privileges, or boot their own operating system from an external drive and change user accounts and passwords.
- Autorun turned on. A malware-loaded drive runs automatically when it's plugged in.
- Open ports, which give adversaries a way to connect.
- No firewall, or a misconfigured one, so malicious data isn't filtered out.
- No anti-malware software, which makes installing malware easier.
Rating device risks
A compromised device can let an adversary impersonate a user, control the device remotely, ransom its data or wipe it. How serious that is depends on how critical the device's services and data are.
| Rating | Pattern | Example |
|---|---|---|
| High | Sensitive data or critical operations could be compromised | A payroll server missing last month's patch for a known critical flaw |
| Moderate | Weak authentication, or a flaw that's less likely to be exploited | Smart irrigation controllers at a farm that can be managed remotely with just a username and password, no MFA |
| Low | Little impact if exploited | A classroom display computer with an unused service port open |
Worked examples
Try each one yourself first, then open the solution.
- Example 1
Identifying the malware
Name the malware in each case. (a) After an employee opens an emailed "invoice" file, nothing happens until the first of the next month, when payroll files are deleted. (b) Within an hour, the same malicious program appears on 300 computers, and none of their users clicked anything. (c) A free photo-editing app works normally, but it also lets a stranger browse the user's files and run commands from far away.
Show the solutionHide the solution
- Step 1: (a) The key detail is waiting for a date before acting. That's a logic bomb. (It needed the user to open a file to get in, but its defining behavior is the trigger condition.)
- Step 2: (b) Spreading between computers with no human action is a worm.
- Step 3: (c) Malicious code hidden in software that looks harmless is a trojan; because it gives remote control, it's a remote access trojan (RAT).
Answer: (a) Logic bomb. (b) Worm. (c) Remote access trojan (RAT).
- Example 2
Linking a weakness to an attack
A library's public computers have no BIOS/UEFI password and autorun is on for USB drives. Explain how an adversary could exploit each weakness and recommend fixes.
Show the solutionHide the solution
- Step 1: No BIOS/UEFI password: the adversary can change the startup settings to boot their own operating system from a USB drive, then use tools to create an account or reset passwords.
- Step 2: Autorun on: the adversary plugs in a drive loaded with malware, and the computer runs it automatically.
- Step 3: Fixes: set a BIOS/UEFI password (and block booting from external drives), turn off autorun, and consider disabling USB ports on public machines.
Answer: Without a BIOS/UEFI password, an adversary can boot their own OS from a drive and change accounts; with autorun on, an inserted drive's malware runs automatically. Set a BIOS/UEFI password, disable autorun and consider disabling USB ports.
Common mistakes
- Mixing up viruses and worms. A virus needs a user to run or open a file; a worm spreads on its own.
- Calling any malware that demands money spyware. Encrypting files and demanding payment is ransomware.
- Thinking anti-malware that scans files will easily catch fileless malware. It lives in memory and uses legitimate programs, so there may be no malicious file to scan.
- Rating a device's risk without asking what it does. The same flaw is far more serious on a server with sensitive data than on a display screen.
On the exam
- Malware questions usually describe behavior and ask for the type. Find the one defining clue: needs a user (virus), spreads alone (worm), disguised (trojan), remote control (RAT), encrypts for payment (ransomware), waits for a condition (logic bomb), hides in the OS (rootkit), lives in memory (fileless).
- When explaining how a weakness could be exploited, name the specific weakness, what the adversary does with it and the result.
Connected topics
Videos
Check yourself: 4.1 Device Vulnerabilities and Attacks
4 questions on 4.1 Device Vulnerabilities and Attacks. Pick an answer to see if you got it, and why.
A hospital's insulin pumps each contain a small computer that controls how much insulin is delivered. Which type of computing device is this?
A school has a computer whose only job is to hand out IP addresses (DHCP) and look up names (DNS) for all the other devices on its network. Which type of computer is this?
Why are embedded devices, such as smart thermostats, often harder to protect with security software than laptops?
Investigators find no suspicious files on a compromised computer. Instead, malicious code was running in memory and using the computer's own legitimate administration tools. What type of malware is this?
0 of 4 answered