Theory
The attacks you must defend against
To defend a system, you need to know how it will be attacked. A few attack types recur again and again, and each works by a different mechanism, so each needs a different defence.
This lesson lays out the common ones: DDoS, man-in-the-middle, email attacks, password attacks, and malware. Some you have met; here they are gathered as the attacker's toolkit, with the defence for each. Knowing how an attack works is the first step to stopping it, so keep the mechanisms distinct.
At a glance
| Attack | How it works | Key defence |
|---|---|---|
| DDoS | Floods the target from many bots to overwhelm it | DDoS mitigation, filtering |
| Man-in-the-middle | Secretly intercepts communication between two parties | Encryption (SSL/TLS) |
| Email attack | Deceives users via phishing, spoofing, or malicious attachments | User awareness, spam/malware filters |
| Password attack | Cracks or steals passwords (brute force, theft) | Strong passwords, two-factor authentication |
| Malware | Infects the system (virus, worm, trojan, ransomware) | Antivirus, patching, caution |
Theory
How each works
A DDoS floods a target from a botnet to make it unavailable (from the crime unit). A man-in-the-middle (MITM) attack has the attacker secretly position between two parties, intercepting, and possibly altering, their communication, often on an insecure network; encryption (SSL/TLS) defeats it by making the intercepted data unreadable and verifying identities.
Email attacks use email to deceive or infect: phishing, spoofing, malicious attachments. Password attacks try to obtain passwords, by brute force (trying many combinations), dictionary guessing, or theft; strong passwords and two-factor authentication defend against them. Malware is malicious software (virus, worm, trojan, ransomware, spyware) that infects and harms a system; antivirus, patching, and caution reduce the risk. Different mechanism, different defence.
Quiz
An attacker secretly positions themselves between your device and a website on an insecure Wi-Fi network, intercepting the data you exchange. What kind of attack is this, and what defends against it?
- A DDoS attack; defended by stronger passwords
- A man-in-the-middle attack; defended by encryption (SSL/TLS), which makes intercepted data unreadable and verifies identity
- A password attack; defended by antivirus
- Malware; defended by DDoS mitigation
Show the answer
A man-in-the-middle attack; defended by encryption (SSL/TLS), which makes intercepted data unreadable and verifies identity
Secretly intercepting communication between two parties is a man-in-the-middle (MITM) attack, and the key defence is encryption (SSL/TLS): if the data is encrypted, an interceptor sees only unreadable ciphertext, and the certificate check confirms you are talking to the genuine site, not the attacker. Option A is wrong: a DDoS overwhelms a service with traffic (it does not intercept communication), and passwords do not defend against interception. Option C misnames it: a password attack cracks/steals passwords, and antivirus targets malware, neither describes interception. Option D is wrong: malware is malicious software, and DDoS mitigation defends availability, not interception. Match attack to defence: MITM is beaten by encryption.
Think first
Why does each attack type need its own specific defence?
Why not have one security measure that stops all attacks? Then tap.
Show the answer
Because each attack exploits a DIFFERENT weakness through a different mechanism, so a defence that blocks one does nothing against another; effective security therefore needs LAYERS, each addressing a specific threat. Consider how differently the attacks operate. A man-in-the-middle attack exploits UNPROTECTED communication, so the defence is ENCRYPTION (SSL/TLS), which makes intercepted data useless; but encryption does nothing to stop a DDoS, which exploits limited CAPACITY by flooding you with traffic, and needs traffic filtering and mitigation instead. A password attack exploits WEAK or STOLEN credentials, defended by strong passwords and two-factor authentication, but neither of those stops MALWARE, which exploits vulnerable software and user mistakes, and is countered by antivirus, patching, and caution. Email attacks exploit HUMAN trust through deception, so the main defence is user AWARENESS plus filters, something no technical control alone fully solves. Because the vulnerabilities are distinct, weak encryption, a fragile password, unpatched software, human gullibility, no single measure can cover them all; each gap must be closed by the control suited to it. This is the principle of DEFENCE IN DEPTH (layered security): you deploy multiple, complementary defences so that the system is protected against the full range of attacks, and if one layer fails, others still stand. It also means security is never 'done' with one product; it is an ongoing combination of technical controls (encryption, authentication, antivirus, filtering) and human practices (awareness, caution). Different attacks, different weaknesses, so different, layered defences, which is exactly why understanding each attack type matters. No single shield stops every attack; you need the right defence for each, layered together.
Summary
Key takeaways
- Common attacks each work by a different mechanism and need a different defence.
- DDoS floods a target from a botnet to make it unavailable; defended by mitigation and filtering.
- Man-in-the-middle secretly intercepts communication; defended by encryption (SSL/TLS).
- Email attacks deceive or infect via phishing, spoofing, and malicious attachments; defended by user awareness and filters.
- Password attacks crack or steal passwords (brute force, theft); defended by strong passwords and two-factor authentication.
- Malware infects the system; defended by antivirus, patching, and caution.
- Memory hook: each attack has its own defence, so layered security (defence in depth) is needed to cover them all.