Easy-to-understand explanation of cyber attacks and cybersecurity

A cyber attack is an act that steals or alters data from a company’s or individual’s servers or computers via a network. The number of such attacks has increased dramatically over the past 10 years, causing damage such as leaks of personal information, large-scale server outages, and production line stoppages at semiconductor and automobile factories all over the world. Cyber ​​security is what is done to prevent damage caused by such cyber attacks. It aims to protect computers, servers, mobile devices, electronic systems, networks and data from malicious attacks by cybercriminals, some of which we can start doing right now. Here, we will provide an easy-to-understand explanation of cyber attacks and cybersecurity, as well as tips on how to protect yourself from cyber attacks.

Cyber ​​attacks and cybersecurity

First, I will provide an overview of what cyber attacks and cybersecurity are.

What is a cyber attack?

Cyber ​​attack is a term used to refer to attacks and destructive activities carried out through networks. Specifically, individuals, companies, government agencies, and other organizations are targeted by malware, SQL injection, and other methods with the purpose of disrupting core systems, taking down web services, and stealing confidential information and customer data. An attack will be carried out. Attacks against individuals include unauthorized login by stealing IDs and passwords and unauthorized use of credit cards by stealing payment information through phishing scams. Attacks targeting companies and organizations are even larger, and include mass leaks of customer information, website defacement and system downtime, and factory production line shutdowns.

What is cyber security?

Cybersecurity refers to measures and means to prevent digitized information from being tampered with or leaked due to cyber-attacks conducted via networks. The number of cyber attacks is increasing every year, and it is said that in 2021, approximately 16 million people in Japan alone fell victim to some type of cyber attack.
With cyber threats set to continue to grow, it’s no surprise that spending on cybersecurity is increasing around the world. Gartner predicts that spending on cybersecurity will reach $188.3 billion in 2023 and exceed $260 billion worldwide by 2026. National agencies in the United States, United Kingdom, and Australia have developed cybersecurity guidance and frameworks, advocating constant real-time monitoring of all electronic resources to detect cyberattacks at an early stage and stop their spread. The focus is on the inside.

Not only can digitized information be easily carried around on USB memory sticks, but it can also be accessed illegally through the cloud. Although digital data is highly convenient, it is always exposed to threats. As digitalization continues to advance, cybersecurity measures are expected to become even more important.

Five typical cyber attack methods

We will explain how cybercriminals carry out cyberattacks.
There are five representative methods:

Malware
Malware is an abbreviation for malicious software, and it is typically spread through unsolicited email attachments or fake programs disguised as software download links.
Malware can hack into your computer, collect data, and send it to criminals, or monitor your behavior and steal your credit card information. There are many types of malware, including the following:

 

A. Computer virus
It is a self-replicating program that parasitizes computer software like a virus and spreads throughout the computer system. It infects files one after another, interfering with programs and performing harmful operations that are not intended by the user.

B. Trojan horse
Malware that disguises itself as legitimate software or files and performs attacks such as data destruction. For installation, fake download links are used.
Malware has been around for a long time, but it continues to evolve, and in recent years, a multifunctional Trojan horse called Dridex that targets financial institutions has appeared. It had the ability to steal personal information and caused hundreds of millions of dollars in damage, mainly in the United States.
Another Trojan horse called Emotet has appeared that uses macros in Word and Excel files to make it difficult to detect. If infected, information such as email accounts, passwords, address books, etc. will be stolen.

C. Spyware
This is software that secretly records user actions and leaks information via a network. The purpose is to misuse user information, and there is a risk that credit card information may be stolen.

D. Ransomware
Ransom is a word that means ransom, and as the name suggests, it threatens to erase your data if you don’t pay the ransom.
There are several methods used by the attacker, such as encrypting files so that only the perpetrator can recover them, and demanding money in exchange for getting the files back.

E.Adware
As the name suggests, Ad is software that uses advertisements. Not all adware is malicious, as it is intended for promotion and advertising. However, malicious software may direct users to fake software pages and exploit personal information. It can also be used to spread malware.

 

2.SQL injection
SQL (structured query language) injection is a type of cyber attack that illegally infiltrates a database and steals data. Hacking involves injecting malicious SQL statements into web applications linked to databases.
The most common method is to enter a large number of SQL statements in the user ID/password input form. If you do not take sufficient measures against SQL injection, sensitive information stored in the database may be exposed.
SQL injections are carried out targeting companies that have a lot of customer information, such as e-commerce sites. Leaks of customer information are feared because they directly lead to a decline in a company’s credibility, and many actual damages have occurred to date.

3.Phishing scam

This is an act in which a cybercriminal impersonates a real company or organization, sends an email, directs the user to a fake website, and then steals login information, credit card information, etc.
In addition, there are cases where you receive an SMS disguised as a delivery notification, and cases where a warning such as “You have been infected with a virus, take measures now!” is displayed, which leads to phishing scams.

4.Man-in-the-middle attack
A man-in-the-middle attack is a type of cyberattack in which a cybercriminal intercepts communications between two parties. When using a public Wi-Fi network that does not have security measures in place, there is a risk that your communication data may be intercepted.

5.DoS attack
A DoS attack (denial of service attack) is a cyber attack that attempts to access the target network or server excessively or sends a large number of requests. Attacks place a heavy load on your computer, causing network delays and website access problems.

 

 

 

 

 

 

Leave a Reply

Your email address will not be published. Required fields are marked *