Common Types of Attacks: Distributed Denial of Service; Man in the Middle, Email Attack; Password Attack, Malware

एक system के सामने आने वाले common attacks हर एक अलग तरीके से काम करता है: एक DDoS इसे traffic से overwhelm करता है, एक man-in-the-middle secretly communication intercept करता है, email attacks users को deceive करते हैं, password attacks logins crack या चुराते हैं, और malware system को infect करता है।

11 min read · 6 cards · 2 checks

Read in: English · हिन्दी · ગુજરાતી


Theory

वे Attacks जिनके Against आपको Defend करना है

एक system defend करने के लिए, आपको जानना पड़ता है यह कैसे attack होगा। कुछ attack types बार-बार recur होते हैं, और हर एक एक अलग mechanism से काम करता है, तो हर एक को एक अलग defence चाहिए।

यह lesson common ones lay out करता है: DDoS, man-in-the-middle, email attacks, password attacks, और malware। कुछ से आप मिल चुके हैं; यहाँ इन्हें attacker के toolkit की तरह collect किया गया है, हर एक के लिए defence के साथ। एक attack कैसे काम करता है यह जानना इसे रोकने का पहला step है, तो mechanisms को distinct रखिए।

At a glance

Attackयह कैसे काम करता हैKey Defence
DDoSTarget को बहुत से bots से flood करता है इसे overwhelm करने के लिएDDoS mitigation, filtering
Man-in-the-MiddleSecretly दो parties के बीच communication intercept करता हैEncryption (SSL/TLS)
Email AttackPhishing, spoofing, या malicious attachments के through users को deceive करता हैUser awareness, spam/malware filters
Password AttackPasswords crack या चुराता है (brute force, theft)Strong passwords, two-factor authentication
MalwareSystem को infect करता है (virus, worm, trojan, ransomware)Antivirus, patching, caution

Theory

हर एक कैसे काम करता है

एक DDoS एक target को एक botnet से flood करता है इसे unavailable बनाने के लिए (crime unit से)। एक man-in-the-middle (MITM) attack में attacker secretly दो parties के बीच position लेता है, इनकी communication intercept करते हुए, और possibly alter करते हुए, अक्सर एक insecure network पर; encryption (SSL/TLS) intercepted data को unreadable बनाकर और identities verify करके इसे defeat करता है।

Email attacks email का इस्तेमाल deceive या infect करने के लिए करते हैं: phishing, spoofing, malicious attachments। Password attacks passwords पाने की कोशिश करते हैं, brute force (बहुत से combinations try करना), dictionary guessing, या theft से; strong passwords और two-factor authentication इनके against defend करते हैं। Malware malicious software है (virus, worm, trojan, ransomware, spyware) जो एक system को infect और harm करता है; antivirus, patching, और caution risk कम करते हैं। अलग mechanism, अलग defence।

Quiz

एक attacker secretly आपके device और एक website के बीच एक insecure Wi-Fi network पर खुद को position करता है, आपके exchange करते data को intercept करते हुए। यह किस तरह का attack है, और इसके against क्या defend करता है?

  1. एक DDoS attack; stronger passwords से defended
  2. एक man-in-the-middle attack; encryption (SSL/TLS) से defended, जो intercepted data को unreadable बनाता है और identity verify करता है
  3. एक password attack; antivirus से defended
  4. Malware; DDoS mitigation से defended
Show the answer

एक man-in-the-middle attack; encryption (SSL/TLS) से defended, जो intercepted data को unreadable बनाता है और identity verify करता है

दो parties के बीच communication secretly intercept करना एक man-in-the-middle (MITM) attack है, और key defence encryption (SSL/TLS) है: अगर data encrypted है, एक interceptor सिर्फ़ unreadable ciphertext देखता है, और certificate check confirm करता है आप genuine site से बात कर रहे हैं, attacker से नहीं। Option A गलत है: एक DDoS एक service को traffic से overwhelm करता है (यह communication intercept नहीं करता), और passwords interception के against defend नहीं करते। Option C इसे galat नाम देता है: एक password attack passwords crack/चुराता है, और antivirus malware को target करता है, दोनों में से कोई interception describe नहीं करता। Option D गलत है: malware malicious software है, और DDoS mitigation availability defend करता है, interception नहीं। Attack को defence से match कीजिए: MITM encryption से beaten होता है।

Think first

हर Attack Type को इसका खुद का Specific Defence क्यों चाहिए?

सारे attacks रोकने वाला एक ही security measure क्यों न हो? फिर tap कीजिए।

Show the answer

क्योंकि हर attack एक अलग mechanism से एक DIFFERENT weakness exploit करता है, तो एक defence जो एक को block करता है दूसरे के against कुछ नहीं करता; effective security को इसलिए LAYERS चाहिए, हर एक एक specific threat address करते हुए। सोचिए attacks कितने differently operate करते हैं। एक man-in-the-middle attack UNPROTECTED communication exploit करता है, तो defence ENCRYPTION (SSL/TLS) है, जो intercepted data को useless बना देता है; पर encryption एक DDoS को रोकने में कुछ नहीं करता, जो limited CAPACITY exploit करता है आपको traffic से flood करके, और इसके बजाय traffic filtering और mitigation चाहिए। एक password attack WEAK या STOLEN credentials exploit करता है, strong passwords और two-factor authentication से defended, पर इनमें से कोई भी MALWARE नहीं रोकता, जो vulnerable software और user mistakes exploit करता है, और antivirus, patching, और caution से counter होता है। Email attacks deception के through HUMAN trust exploit करते हैं, तो main defence user AWARENESS plus filters है, ऐसी चीज़ जिसे कोई technical control अकेले पूरी तरह solve नहीं करता। क्योंकि vulnerabilities distinct हैं, weak encryption, एक fragile password, unpatched software, human gullibility, कोई single measure इन सबको cover नहीं कर सकता; हर gap को इसके लिए suited control से बंद करना पड़ता है। यही DEFENCE IN DEPTH (layered security) का principle है: आप multiple, complementary defences deploy करते हैं तो system attacks की पूरी range के against protected रहे, और अगर एक layer fail हो, बाकी अभी भी खड़ी रहें। इसका मतलब यह भी है security कभी एक product से 'done' नहीं होती; यह technical controls (encryption, authentication, antivirus, filtering) और human practices (awareness, caution) का एक ongoing combination है। अलग attacks, अलग weaknesses, तो अलग, layered defences, यही exactly वजह है हर attack type समझना matter करता है। कोई single shield हर attack नहीं रोकता; आपको हर एक के लिए right defence चाहिए, साथ में layered।

Summary

Key takeaways

  • Common attacks हर एक एक अलग mechanism से काम करते हैं और इन्हें एक अलग defence चाहिए।
  • DDoS एक target को एक botnet से flood करता है इसे unavailable बनाने के लिए; mitigation और filtering से defended।
  • Man-in-the-middle secretly communication intercept करता है; encryption (SSL/TLS) से defended।
  • Email attacks phishing, spoofing, और malicious attachments के through deceive या infect करते हैं; user awareness और filters से defended।
  • Password attacks passwords crack या चुराते हैं (brute force, theft); strong passwords और two-factor authentication से defended।
  • Malware system को infect करता है; antivirus, patching, और caution से defended।
  • Memory hook: हर attack का अपना defence है, तो सबको cover करने के लिए layered security (defence in depth) चाहिए।

Study this properly

This page is the lesson to read. In Gri-Learn the same topic is a graded deck: the self-checks are scored and your weak topics are tracked. Free to start.

Start this topic

Already have an account? Sign in

More from Cyber Security Fundamentals

Gri-Learn · syllabus-mapped B.C.A. lessons in English, Hindi and Gujarati

Common Types of Attacks: Distributed Denial of Service; Man in the Middle, Email Attack; Password Attack, Malware · E-Commerce and Cyber Security (Minor-6-01) · Gri-Learn