Theory
The technical attacks
This lesson covers the technical cyber crimes, the attacks that exploit systems directly. They fall into a few families: unauthorised access (hacking), malware (virus, worm, trojan), email crimes (spoofing, spamming, bombing), and denial-of-service attacks.
These are exactly the terms students most often confuse, a virus is not a worm is not a trojan; a DoS is not a DDoS, so we keep each family crisp and clearly distinguished. Getting these distinctions right is essential both for exams and for actually understanding the threats an online store faces.
Theory
Unauthorised access and hacking
Unauthorised access means getting into a system, network, or data without permission. Hacking is the act of doing so, exploiting weaknesses to break in. Once inside, an attacker may steal data, alter or delete it, plant malware, or use the system for further attacks.
This is the foundational technical crime: many others begin with unauthorised access. Protecting against it, strong passwords, authentication, patched software, is the first line of defence for any online business. The rest of this lesson covers what attackers do with access, or how they attack without it: malware, email abuse, and denial of service.
At a glance
| Malware | How it spreads / works |
|---|---|
| Virus | Attaches to a file or program; spreads when the infected file is run or shared (needs a host, usually user action) |
| Worm | Standalone and self-replicating; spreads across networks by itself (no host, no user action needed) |
| Trojan (Trojan horse) | Disguises itself as legitimate software to trick you into installing it; then acts maliciously (does not self-replicate; relies on deception) |
Theory
Virus, worm, trojan: the key differences
These three are distinct. A virus needs a host: it attaches to a file or program and spreads when that infected file is run or shared, usually requiring some user action. A worm is standalone and self-replicating: it copies itself and spreads across networks by itself, with no host file and no user action, which is why worms can spread explosively. A trojan neither attaches nor self-replicates; instead it disguises itself as something legitimate to trick you into installing it, then does its damage, it relies on deception, not replication.
So the memory aid: virus attaches, worm self-spreads, trojan disguises. Confusing them is the classic exam mistake, keep the three behaviours separate.
At a glance
| Attack | What it does |
|---|---|
| Spoofing | Fakes the sender's email address to appear to come from someone else |
| Spamming | Sends bulk unsolicited email to many recipients |
| Bombing | Floods one target's inbox with a huge volume of email |
| DoS | Floods a system from ONE source to overwhelm it, blocking legitimate users |
| DDoS | Floods from MANY compromised machines (a botnet) at once, harder to stop |
Theory
Email crimes and denial of service
Email crimes: spoofing fakes the sender's address so a message appears to come from someone trustworthy (used in phishing). Spamming is sending bulk unsolicited email. Bombing floods a single target's inbox with a huge volume of email to overwhelm it.
Denial-of-service attacks aim to make a service unavailable. A DoS (Denial of Service) attack floods a system from one source with so many requests that legitimate users cannot get through. A DDoS (Distributed Denial of Service) does the same but from many compromised machines at once, a botnet, which makes it far more powerful and much harder to block (you cannot just cut off one source). DoS is one attacker; DDoS is an army.
Quiz
Which statement correctly distinguishes a worm from a virus?
- A worm needs a host file and user action to spread, while a virus spreads by itself
- A worm is standalone and self-replicating, spreading across networks by itself, while a virus attaches to a file and spreads when that file is run or shared
- A worm and a virus are exactly the same thing
- A worm disguises itself as legitimate software, like a trojan
Show the answer
A worm is standalone and self-replicating, spreading across networks by itself, while a virus attaches to a file and spreads when that file is run or shared
A worm is standalone and self-replicating: it spreads across networks on its own, with no host file and no user action needed. A virus, by contrast, attaches to a file or program and spreads only when that infected file is run or shared (it needs a host and usually user action). Option A reverses the two (it describes a virus's behaviour as a worm's and vice versa). Option C is wrong: they are genuinely different, self-spreading worm vs host-dependent virus. Option D describes a TROJAN (disguise/deception), not a worm. Keep them straight: virus attaches, worm self-spreads, trojan disguises.
Think first
Why is a DDoS so much harder to stop than a plain DoS?
Both flood a system with traffic. Why is the distributed version far more dangerous? Then tap.
Show the answer
Because a DDoS comes from MANY sources at once instead of one, which makes it both more overwhelming and nearly impossible to block by simply cutting off the attacker, the 'distributed' part is exactly what defeats the easy defence. In a plain DoS, the flood of malicious traffic originates from a SINGLE source (one machine or address). That has a weakness for the attacker: the defender can identify that one source and BLOCK it (filter out its traffic, ban its address), and the attack stops. It is also limited by what one machine can send. A DDoS removes both limits by using a BOTNET, a large network of many computers that the attacker has secretly compromised (often ordinary people's infected devices around the world). All of them flood the target SIMULTANEOUSLY. Now the malicious traffic pours in from thousands of DIFFERENT addresses at once, so there is no single source to block, blocking one does almost nothing, and blocking them all is extremely hard because they are numerous, scattered globally, and mixed in with legitimate users' traffic (you risk blocking real customers). The combined firepower of thousands of machines also generates far more traffic than any single source could, more easily overwhelming even large systems. And because the real attacker hides behind the botnet, they are hard to trace. So the distribution across many compromised machines is precisely what makes a DDoS so much more powerful and so much harder to defend against than a single-source DoS, which is why large-scale DDoS attacks are a serious threat requiring specialised mitigation. One source you can cut off; an army from everywhere you cannot.
Summary
Key takeaways
- Unauthorised access (hacking) is entering a system or data without permission; many other crimes start here.
- Malware differs by behaviour: a virus attaches to a file and spreads when it is run/shared; a worm is standalone and self-replicates across networks by itself; a trojan disguises itself to trick you into installing it.
- Memory aid: virus attaches, worm self-spreads, trojan disguises (and only worms self-replicate without user action).
- Email crimes: spoofing fakes the sender's address, spamming sends bulk unsolicited email, bombing floods one inbox.
- A DoS attack floods a system from ONE source to make it unavailable; a DDoS floods from MANY compromised machines (a botnet) at once.
- DDoS is harder to stop because there is no single source to block and the combined traffic is far greater.
- Memory hook: hacking gets in, malware (virus/worm/trojan) infects, email crimes abuse mail, DoS/DDoS overwhelm.