Skip to content

Computer Science · Ch 12 — Security Aspects

Network Security Threats

12.9

Network Security Threats

What a Network Security Threat Is

A network security threat is any potential danger that can compromise the confidentiality, integrity, or availability of data travelling over a network. When a computer connects to a network — especially the internet — it becomes exposed to a wide range of malicious activities. The threat may come from an outsider trying to break in, or from an insider misusing legitimate access. Understanding these threats is the first step toward defending against them, because each threat exploits a different weakness and demands a different countermeasure.

The textbook groups the major network security threats into several distinct categories. Each one is described below in the order the book presents them.

Malware

Malware, short for malicious software, is any program designed to harm a computer system, steal data, or disrupt normal functioning. It is the broadest category of threat and includes several specific types.

Virus — A virus is a piece of code that attaches itself to a legitimate program or file and spreads when that file is executed or shared. It needs a host to travel and a user action (like opening an infected attachment) to activate. Once active, it can corrupt files, slow the system, or delete data.

Worm — Unlike a virus, a worm is a standalone program that replicates itself and spreads across a network without any human action. It exploits vulnerabilities in the operating system or network protocols to move from one machine to another, often consuming bandwidth and memory until systems crash.

Trojan Horse — A Trojan disguises itself as a useful or harmless program — a game, a screensaver, or a software update — but carries a hidden malicious payload. It does not replicate itself like a virus or worm; instead, it tricks the user into installing it, after which it can open backdoors, steal passwords, or delete files.

Spyware — Spyware secretly monitors a user's activity without consent. It can record keystrokes, capture login credentials, track browsing habits, and send that information to a remote attacker. It often arrives bundled with free software downloads.

Adware — Adware automatically displays unwanted advertisements, often in pop-up windows. While less harmful than spyware, it is intrusive, slows the system, and can redirect the browser to promotional or malicious websites.

Ransomware — Ransomware encrypts the victim's files and demands a payment — usually in cryptocurrency — to restore access. Even after payment, there is no guarantee the attacker will release the data. It has become one of the most financially damaging threats, with attacks on hospitals, schools, and government agencies costing millions.

Rootkit — A rootkit is a collection of tools that gives an attacker administrator-level control over a system while hiding its own presence. It can conceal other malware, disable security software, and remain undetected for long periods, making it extremely difficult to remove.

Phishing

Phishing is a social engineering attack in which the attacker impersonates a trusted entity — a bank, an online store, or a government office — to trick the victim into revealing sensitive information such as usernames, passwords, or credit card numbers. It is usually carried out through fake emails or messages that contain a link to a fraudulent website that looks identical to the legitimate one. When the user enters their details, the attacker captures them.

A related variant is spear phishing, where the attack is targeted at a specific individual or organisation using personal information to make the message more convincing. Phishing relies on human error rather than technical weakness, which is why awareness and caution are the primary defences.

Sniffing

Sniffing is the act of intercepting and examining data packets as they travel across a network. An attacker uses a packet sniffer — a software tool — to capture unencrypted traffic and read its contents, which may include passwords, emails, or financial data. Sniffing is especially dangerous on public Wi-Fi networks, where all traffic on the same network can be captured easily. Encryption (such as HTTPS) is the main protection, because even if packets are intercepted, the attacker cannot read them.

Spoofing

Spoofing is the forging of a network identity to trick systems or users into believing the attacker is someone else. Common forms include:

  • IP spoofing — falsifying the source IP address in a packet to hide the attacker's identity or impersonate a trusted host.
  • Email spoofing — forging the sender address of an email so it appears to come from a known contact.
  • DNS spoofing — corrupting the domain name system so that a legitimate website address resolves to a malicious IP address, redirecting users to fake sites.

Spoofing is often used as a stepping stone for other attacks, such as phishing or session hijacking.

Denial of Service (DoS) and Distributed Denial of Service (DDoS)

A Denial of Service attack aims to make a service unavailable to legitimate users by overwhelming it with a flood of requests, traffic, or malformed data. The server becomes so busy responding to the attack that it cannot serve real users, effectively shutting the service down.

In a Distributed Denial of Service attack, the attacker uses many compromised computers — often forming a botnet — to launch the flood simultaneously from multiple sources. This makes the attack far harder to block, because traffic comes from thousands of different IP addresses rather than one. DDoS attacks have taken down major websites, online gaming services, and even parts of the internet infrastructure.

SQL Injection

SQL injection is an attack on web applications that use a database. The attacker enters malicious SQL code into an input field — such as a login box or a search bar — instead of the expected plain text. If the application does not properly validate or sanitise user input, the database executes the injected code, allowing the attacker to view, modify, or delete data, bypass authentication, or even take control of the database server. It is one of the oldest and most common web vulnerabilities, and it is prevented by using parameterised queries and input validation.

Man-in-the-Middle (MITM) Attack

In a Man-in-the-Middle attack, the attacker secretly intercepts and relays communication between two parties who believe they are talking directly to each other. The attacker can eavesdrop on the conversation, steal data, or alter the messages before forwarding them. This is often done on unsecured networks, where the attacker positions themselves between the victim and the server. Strong encryption and mutual authentication are the key defences, because they ensure that even intercepted messages cannot be read or modified.

Identity Theft

Identity theft occurs when an attacker steals a person's personal information — such as name, date of birth, Aadhaar number, bank account details, or credit card information — and uses it to commit fraud. The thief may open new accounts, make purchases, take loans, or file false tax returns in the victim's name. The victim often discovers the crime only after significant financial or reputational damage has already occurred. Identity theft is usually a downstream consequence of other threats like phishing, spyware, or data breaches.

Summary of Threats and Their Nature

| Threat | Primary Target | Key Characteristic |

|---|---|---| …