Skip to content
← Computer Science

Computer Science · Class 12 Optional

Ch 12Security Aspects — Class 12 Computer Science, concept-first.

Security is easiest to guarantee in isolation. A computer with no link to any external device or network is free from the security threats that connectivity brings.

20

Q&A

13

Concepts

Not available

Exam weightage

Start learning — read this chapter →

Key concepts

Hover a concept to preview it and jump to its most relevant Q&A.

Firewall Configuration

Think of a firewall as the security guard at the gate of a large apartment complex. The guard has a list of rules: who is allowed in, who is allowed out, and what they are allowed to carry.

Start with this concept →

Chapter contents

The NCERT structure, section by section. Open a section to see its questions, then read the concept-first solution.

12.1

Threats and Prevention

Security is easiest to guarantee in isolation. A computer with no link to any external device or network is free from the security threats that connectivity brings.

12.2

Malware

Malware is a portmanteau of the words malicious and software. It refers to any software that is deliberately created to cause harm — whether that means damaging hardware, stealing data, or disrupting…

12.2.1

Virus

A computer virus is malicious software, but the name comes from biology. The term was coined by Fred Cohen in 1985, and the parallel with a biological virus is deliberate: a biological virus invades a…

12.2.2

Worms

A worm is a type of malware that causes unexpected or damaging behaviour on an infected computer system. What sets it apart from a virus is not what it does, but how it operates and spreads.

12.2.3

Ransomware

Ransomware is malware built around one simple, cruel idea: your data is your most valuable possession, and the attacker will hold it hostage until you pay.

12.2.4

Trojan

The story of the Trojan horse comes from ancient Greece. The Greeks could not break into the city of Troy by force, so they presented the king with a huge wooden horse.

12.2.5

Spyware

Spyware is malware built for surveillance. Its entire purpose is to watch a person or an organisation, quietly gather information about them, and pass that information on to someone else — all without…

12.2.6

Adware

An adware is a type of malware whose entire purpose is to make money for its creator through online advertising.

12.2.7

Keyloggers

A keylogger is a tool designed to record every key a user presses on a keyboard. It can exist as either malware or a physical hardware device.

(A)

Online Virtual Keyboard Vs On-Screen Keyboard

Both keyboards are security tools, but they work in fundamentally different ways. An online virtual keyboard is a software-based keyboard that appears on your screen and lets you click keys with your…

12.2.8

Modes of Malware distribution

A malware program, once written, still has to reach your machine before it can do any damage. The book lists four common routes it takes to get there.

12.2.9

Combating Malware

The first line of defence against malware is recognising that it exists and that it keeps evolving. No single tool or habit makes a system permanently safe, so the practical approach is a layered one:…

12.3

Antivirus

An antivirus is a software program designed to protect a computer system from malicious software. It is also commonly called anti-malware.

12.3.1

Methods of Malware Identification used by Antivirus

Antivirus software does not rely on a single trick to catch malware. Different threats behave differently, so the software uses several complementary methods.

(A)

Signature-based detection

Signature-based detection works like a digital fingerprint scanner for malware. The system keeps a database of known virus signatures — unique byte patterns or strings that appear in malicious files —…

(B)

Sandbox detection

Sandbox detection is a technique used to identify whether a program is running inside a sandboxed environment, which is often used by security researchers to safely analyze malware.

(C)

Data mining techniques

Data mining is the process of discovering hidden patterns and relationships in large datasets, and in this section you’ll see how SQL and Python can be used to pull out useful information from a datab…

(D)

Heuristics

Heuristics is a problem-solving approach that uses a practical method, not guaranteed to be optimal or perfect, but sufficient for reaching an immediate goal.

(E)

Real-time protection

Real-time protection is the shield that stays awake while you work — it watches every file you open, every program you run, and every download that lands on your system, checking each one against know…

12.4

Spam

Spam is a broad term that applies across many digital platforms — messaging apps, online forums, chat services, email, and even advertisements. But the form most people recognise is email spam.

12.5

HTTP vs HTTPS

Before you type your password into any website, the address bar tells you a story. If the URL begins with http://, the data you send travels in plain text — readable by anyone who intercepts it.

12.6

Firewall

A firewall is a network security system designed to protect a trusted private network from unauthorised access or traffic coming from an untrusted outside network — for example, the Internet, or even…

12.6.1

Types of Firewall

A firewall is a security tool that filters traffic, but not all firewalls work the same way. The difference comes down to where the firewall is placed and what it is protecting.

12.7

Cookies

2 Q

The word "cookie" comes from the Unix programmers' term magic cookie — a packet of data that a program receives and then sends back unchanged.

12.7.1

Threats due to Cookies

Cookies are small pieces of data a website asks your browser to store, and their usual job is to make your browsing smoother — remembering logins, preferences, or items in a cart.

12.8

Hackers and Crackers

People who break into computer systems are not always strangers with malicious intent. The section introduces two closely related terms — hackers and crackers — and treats them as people with deep tec…

12.8.1

White Hats: Ethical Hacker

A white hat hacker is someone who uses their technical knowledge not to break systems, but to find and help fix security flaws.

12.8.2

Black Hats: Crackers

A hacker who uses their technical skill for illegal or harmful purposes — breaking laws and disrupting security — is called a black hat hacker.

12.8.3

Grey Hats

The line between different kinds of hackers is rarely a clean one. While white hats and black hats sit at opposite ends of the spectrum, a large group of people fall somewhere in the middle.

12.9

Network Security Threats

A network security threat is any potential danger that can compromise the confidentiality, integrity, or availability of data travelling over a network.

12.9.1

Denial of Service

A Denial of Service (DoS) attack is not about stealing data or breaking into a system. It is about making a resource unusable.

12.9.2

Intrusion Problems

Before the book lists the attacks, it sets the stage with a definition. Network intrusion is any unauthorised activity on a computer network.

(A)

Asymmetric Routing

Asymmetric Routing is a network phenomenon where data packets travel from the source to the destination along one path, but the return traffic takes a completely different route.

(B)

Buffer Overflow Attacks

A buffer overflow attack happens when a program tries to store more data in a fixed-size memory buffer than it can hold, causing the extra data to spill into adjacent memory.

(C)

Traffic Flooding

Traffic Flooding is a denial-of-service attack where an attacker overwhelms a server or network with a massive volume of requests, making it unable to respond to legitimate users.

12.9.3

Snooping

Snooping is the act of secretly listening in on a conversation. In networking, that conversation is the stream of data packets moving across a channel, and snooping means capturing and analysing that…

12.9.4

Eavesdropping

The word eavesdropping comes from an old, literal practice: people would secretly listen to conversations happening inside a house by standing under the eaves — the overhanging edges of the roof.

Summary

- Threats are potential dangers to a system; vulnerabilities are weaknesses that threats exploit. A risk is the chance of loss when a threat meets a vulnerability.

Exercises