Theory
Technical Attacks
यह lesson technical cyber crimes cover करता है, वे attacks जो directly systems exploit करते हैं। ये कुछ families में आते हैं: unauthorised access (hacking), malware (virus, worm, trojan), email crimes (spoofing, spamming, bombing), और denial-of-service attacks।
ये exactly वे terms हैं जिन्हें students सबसे ज़्यादा confuse करते हैं, एक virus एक worm नहीं है एक trojan नहीं है; एक DoS एक DDoS नहीं है, तो हम हर family को crisp और clearly distinguished रखते हैं। इन distinctions को सही पाना exams के लिए और online store के सामने के threats actually समझने के लिए दोनों के लिए essential है।
Theory
Unauthorised Access और Hacking
Unauthorised access मतलब एक system, network, या data में बिना permission के जाना। Hacking ऐसा करने का act है, break in करने के लिए weaknesses exploit करना। एक बार अंदर, एक attacker data चुरा सकता है, इसे alter या delete कर सकता है, malware plant कर सकता है, या further attacks के लिए system इस्तेमाल कर सकता है।
यह foundational technical crime है: बहुत सी दूसरी unauthorised access से शुरू होती हैं। इसके against protect करना, strong passwords, authentication, patched software, किसी भी online business के लिए defence की first line है। इस lesson का बाकी हिस्सा cover करता है attackers access पाकर क्या करते हैं, या इसके बिना कैसे attack करते हैं: malware, email abuse, और denial of service।
At a glance
| Malware | यह कैसे फैलता है / काम करता है |
|---|---|
| Virus | एक file या program से attach होता है; तब फैलता है जब infected file run या share होती है (एक host चाहिए, usually user action) |
| Worm | Standalone और self-replicating; networks के across खुद फैलता है (कोई host नहीं, कोई user action नहीं चाहिए) |
| Trojan (Trojan Horse) | आपको इसे install करने के लिए trick करने के लिए legitimate software की तरह खुद को disguise करता है; फिर maliciously act करता है (self-replicate नहीं होता; deception पर rely करता है) |
Theory
Virus, Worm, Trojan: Key Differences
ये तीनों distinct हैं। एक virus को एक host चाहिए: यह एक file या program से attach होता है और तब फैलता है जब वह infected file run या share होती है, usually कुछ user action चाहिए होता है। एक worm standalone और self-replicating है: यह खुद को copy करता है और networks के across खुद फैलता है, बिना किसी host file के और बिना किसी user action के, यही वजह है worms explosively फैल सकते हैं। एक trojan न attach होता है न self-replicate करता है; इसके बजाय यह आपको install करने के लिए trick करने के लिए किसी legitimate चीज़ की तरह खुद को disguise करता है, फिर इसका damage करता है, यह replication पर नहीं deception पर rely करता है।
तो memory aid: virus attach होता है, worm खुद फैलता है, trojan disguise करता है। इन्हें confuse करना classic exam mistake है, तीनों behaviours को separate रखिए।
At a glance
| Attack | यह क्या करता है |
|---|---|
| Spoofing | Sender का email address fake करता है तो message किसी और से आता दिखे |
| Spamming | Bulk unsolicited email बहुत से recipients को भेजता है |
| Bombing | एक target की inbox को email के huge volume से flood करता है |
| DoS | एक system को ONE source से flood करता है इसे overwhelm करने के लिए, legitimate users को block करते हुए |
| DDoS | MANY compromised machines (एक botnet) से एक साथ flood करता है, रोकना harder |
Theory
Email Crimes और Denial of Service
Email crimes: spoofing sender का address fake करता है तो एक message किसी trustworthy से आता दिखे (phishing में इस्तेमाल)। Spamming bulk unsolicited email भेजना है। Bombing एक single target की inbox को email के huge volume से flood करता है इसे overwhelm करने के लिए।
Denial-of-service attacks एक service को unavailable बनाने का aim रखते हैं। एक DoS (Denial of Service) attack एक system को एक source से इतनी requests के साथ flood करता है कि legitimate users through नहीं आ सकते। एक DDoS (Distributed Denial of Service) same करता है पर एक साथ बहुत सी compromised machines से, एक botnet, जो इसे कहीं ज़्यादा powerful और block करना कहीं harder बनाता है (आप बस एक source नहीं काट सकते)। DoS एक attacker है; DDoS एक army है।
Quiz
कौन सा statement correctly एक worm को एक virus से distinguish करता है?
- एक worm को फैलने के लिए एक host file और user action चाहिए, जबकि एक virus खुद फैलता है
- एक worm standalone और self-replicating है, networks के across खुद फैलते हुए, जबकि एक virus एक file से attach होता है और तब फैलता है जब वह file run या share होती है
- एक worm और एक virus बिल्कुल same चीज़ हैं
- एक worm legitimate software की तरह खुद को disguise करता है, एक trojan की तरह
Show the answer
एक worm standalone और self-replicating है, networks के across खुद फैलते हुए, जबकि एक virus एक file से attach होता है और तब फैलता है जब वह file run या share होती है
एक worm standalone और self-replicating है: यह networks के across खुद फैलता है, बिना किसी host file के और बिना किसी user action चाहिए। एक virus, इसके contrast में, एक file या program से attach होता है और सिर्फ़ तब फैलता है जब वह infected file run या share होती है (इसे एक host चाहिए और usually user action)। Option A दोनों को reverse करता है (यह एक virus के behaviour को एक worm का describe करता है और vice versa)। Option C गलत है: ये genuinely अलग हैं, self-spreading worm vs host-dependent virus। Option D एक TROJAN (disguise/deception) describe करता है, एक worm नहीं। इन्हें straight रखिए: virus attach होता है, worm खुद फैलता है, trojan disguise करता है।
Think first
एक DDoS एक Plain DoS से इतना ज़्यादा रोकना Hard क्यों है?
दोनों एक system को traffic से flood करते हैं। Distributed version कहीं ज़्यादा dangerous क्यों है? फिर tap कीजिए।
Show the answer
क्योंकि एक DDoS एक की बजाय एक साथ MANY sources से आता है, जो इसे ज़्यादा overwhelming और सिर्फ़ attacker को काटकर block करना लगभग impossible दोनों बनाता है, 'distributed' हिस्सा exactly वह है जो easy defence को defeat करता है। एक plain DoS में, malicious traffic का flood एक SINGLE source (एक machine या address) से originate होता है। इसमें attacker के लिए एक weakness है: defender उस एक source को identify और BLOCK कर सकता है (इसका traffic filter out करना, इसका address ban करना), और attack रुक जाता है। यह इससे भी limited है कि एक machine कितना भेज सकती है। एक DDoS एक BOTNET इस्तेमाल करके दोनों limits हटा देता है, बहुत सी computers का एक large network जिसे attacker ने secretly compromise किया है (अक्सर दुनिया भर के ordinary लोगों के infected devices)। ये सब SIMULTANEOUSLY target को flood करते हैं। अब malicious traffic एक साथ हज़ारों DIFFERENT addresses से आता है, तो block करने के लिए कोई single source नहीं है, एक को block करना लगभग कुछ नहीं करता, और सबको block करना extremely hard है क्योंकि ये numerous हैं, globally scattered हैं, और legitimate users के traffic के साथ mixed हैं (आप real customers को block करने का risk लेते हैं)। हज़ारों machines की combined firepower भी किसी भी single source से कहीं ज़्यादा traffic generate करती है, बड़े systems को भी ज़्यादा easily overwhelm करते हुए। और क्योंकि real attacker botnet के पीछे hide होता है, इन्हें trace करना hard है। तो बहुत सी compromised machines के across distribution exactly वह है जो एक DDoS को एक single-source DoS से कहीं ज़्यादा powerful और defend करना कहीं harder बनाता है, यही वजह है large-scale DDoS attacks specialised mitigation चाहिए वाला एक serious threat हैं। एक source आप काट सकते हैं; हर जगह से एक army नहीं।
Summary
Key takeaways
- Unauthorised access (hacking) बिना permission के एक system या data में जाना है; बहुत सी दूसरी crimes यहीं से शुरू होती हैं।
- Malware behaviour से differ करता है: एक virus एक file से attach होता है और तब फैलता है जब यह run/share होती है; एक worm standalone है और networks के across खुद self-replicate करता है; एक trojan खुद को disguise करता है आपको install करने के लिए trick करने के लिए।
- Memory aid: virus attach होता है, worm खुद फैलता है, trojan disguise करता है (और सिर्फ़ worms बिना user action के self-replicate करते हैं)।
- Email crimes: spoofing sender का address fake करता है, spamming bulk unsolicited email भेजता है, bombing एक inbox को flood करता है।
- एक DoS attack एक system को ONE source से flood करता है इसे unavailable बनाने के लिए; एक DDoS एक साथ MANY compromised machines (एक botnet) से flood करता है।
- DDoS रोकना harder है क्योंकि block करने के लिए कोई single source नहीं है और combined traffic कहीं ज़्यादा है।
- Memory hook: hacking अंदर आता है, malware (virus/worm/trojan) infect करता है, email crimes mail abuse करते हैं, DoS/DDoS overwhelm करते हैं।