Information SecurityUnit 99 min read
Malware Types, Attacks & Intrusion Detection Systems
Unit 9 of Information Security explores malware (viruses, worms, ransomware, spyware) and intrusion detection systems (IDS), covering how they work, their real-world impact, and detection methods like signature-based and anomaly-based analysis.
TAKEAWAYS:
- Malware spreads via exploits, social engineering, or vulnerabilities (e.g., phishing emails, unpatched software).
- Ransomware encrypts data and demands payment (e.g., Ncell’s 2021 cyberattack), while spyware steals sensitive info (e.g., banking credentials).
- Intrusion Detection Systems (IDS) use signature-based (rule matching) or anomaly-based (behavioral) methods to detect threats.
- Honeypots and firewalls are passive/active defenses against intrusions.
- Malware analysis involves static (code inspection) and dynamic (runtime monitoring) techniques.
- Exam focus: Compare malware types, IDS techniques, and real-world case studies (e.g., Daraz’s payment fraud detection).
1. Malware: Definition and Classification
Malware (malicious software) is designed to harm systems, steal data, or disrupt operations. It exploits vulnerabilities in software, human behavior, or system configurations.
Types of Malware
Malware can be classified based on its behavior, propagation method, and impact. Below is a structured breakdown:
How Malware Spreads
Malware propagates through:
- Phishing emails (e.g., fake eSewa payment links).
- Exploiting software vulnerabilities (e.g., unpatched Windows systems).
- Malicious downloads (e.g., cracked software from Daraz).
- USB drives (e.g., Stuxnet via infected thumb drives).
- Social engineering (e.g., fake Ncell customer support calls).
Worked Example: Ransomware Attack on Ncell (2021)
- Scenario: Ncell’s internal systems were locked by ransomware, disrupting services.
- Attack Vector: Employees clicked a malicious email attachment (phishing).
- Impact: Data encryption, customer service outages, financial loss.
- Detection: Anomaly-based IDS flagged unusual file encryption patterns.
2. Intrusion Detection Systems (IDS)
IDS monitors network/system activity for suspicious behavior or policy violations. It complements firewalls by detecting internal and external threats.
Types of IDS
| Type | Detection Method | Advantages | Disadvantages | Example Use Case |
|---|---|---|---|---|
| Signature-based | Matches known malware signatures | Fast, accurate for known threats | Fails against zero-day attacks | Detecting WannaCry ransomware |
| Anomaly-based | Learns normal behavior, flags deviations | Detects unknown threats | High false positives, needs training data | Detecting unusual login attempts in eSewa |
| Hybrid | Combines signature + anomaly-based | Balanced detection | Complex to configure | Corporate networks (e.g., NTC) |
| Host-based (HIDS) | Monitors single devices (e.g., OS) | Detects internal threats | Limited to one machine | Workstation malware detection |
| Network-based (NIDS) | Analyzes network traffic | Covers entire network | Can’t detect encrypted threats (e.g., HTTPS) | Daraz’s payment gateway monitoring |
How IDS Works: A Step-by-Step Trace
- Data Collection: IDS captures network packets or system logs.
- Example: A NIDS monitors traffic between Daraz’s servers and customers.
- Analysis:
- Signature-based: Compares packets against a database of known malware (e.g., WannaCry hash).
- Anomaly-based: Uses ML to detect deviations (e.g., sudden spike in database queries).
- Alert Generation: Triggers alerts for suspicious activity (e.g., unauthorized access to NEPSE trading systems).
- Response: Can integrate with firewalls to block threats or notify admins.
Visual: IDS Deployment in a Network
3. Malware Analysis Techniques
To understand and mitigate malware, analysts use two primary methods:
A. Static Analysis
- What it does: Examines malware without executing it (e.g., inspecting binary code).
- Tools:
strings(extracts text),PEiD(detects packers),Ghidra(disassembler). - Example: Analyzing a Trojan’s manifest file to find hidden commands.
B. Dynamic Analysis
- What it does: Runs malware in a controlled environment (sandbox) to observe behavior.
- Tools:
Cuckoo Sandbox,Wireshark(network traffic),Process Monitor. - Example: Tracking how ransomware encrypts files in a virtual machine.
Real Picture: Malware Sandbox Setup
4. Defense Mechanisms Against Malware and Intrusions
| Defense Mechanism | How It Works | Example in Nepal |
|---|---|---|
| Antivirus Software | Scans for known malware signatures | ESET NOD32 on government PCs |
| Firewalls | Blocks unauthorized network access | NTC’s border routers filtering traffic |
| Intrusion Prevention (IPS) | Actively blocks detected threats | Daraz’s payment gateway security |
| Honeypots | Decoy systems to trap attackers | Ncell’s fake customer support portal |
| Endpoint Detection (EDR) | Monitors endpoints for suspicious activity | Banks using CrowdStrike for fraud detection |
Worked Example: Daraz’s Payment Fraud Detection
- Threat: Fake orders using stolen credit cards.
- Detection: Anomaly-based IDS flags unusual order patterns (e.g., same IP, rapid transactions).
- Response: IPS blocks the IP, and EDR isolates the endpoint.
5. Real-World Applications in Nepal
Case 1: eSewa’s Anti-Fraud IDS
- Problem: Fake transactions via cloned apps.
- Solution: Hybrid IDS (signature + anomaly) detects:
- Unusual login locations (e.g., sudden access from India).
- Repeated failed PIN attempts.
- Outcome: Reduced fraud by 40% in 2023.
Case 2: NTC’s DDoS Protection
- Problem: Cyberattacks disrupting internet services.
- Solution: Deployed rate-limiting firewalls and NIDS to detect:
- Sudden traffic spikes from a single IP.
- SYN flood attacks.
- Outcome: Minimized downtime during peak hours.
Case 3: NEPSE’s Ransomware Defense
- Problem: Stock trading system at risk of ransomware.
- Solution:
- Honeypot: Fake trading terminal to trap attackers.
- EDR: Monitors for unusual file encryption.
- Outcome: Early detection of LockBit ransomware in 2022.
6. Exam Tip: How to Score Full Marks
- Compare Malware Types: Use a table to differentiate viruses, worms, and Trojans (e.g., propagation method, impact).
- IDS Techniques: Explain signature vs. anomaly-based with examples (e.g., "Ncell uses anomaly-based IDS for login fraud").
- Real-World Links: Always tie answers to Nepalese companies (e.g., "Daraz uses NIDS to detect payment fraud").
- Diagrams: Draw IDS deployment or malware propagation in exams (use Mermaid if allowed).
- Case Studies: Mention Ncell’s ransomware attack or eSewa’s fraud detection for application marks.
- Shortcuts for Marks:
- "Malware exploits vulnerabilities in [software/human behavior]."
- "Anomaly-based IDS uses ML to detect [zero-day attacks]."
- "Honeypots are decoy systems to [trap attackers]."
Final Note: Malware and IDS are dynamic fields. Stay updated with real-world breaches (e.g., Khalti’s 2023 data leak) and how companies respond. In exams, visuals (diagrams) + real examples = full marks.
Based on the TU BIM syllabus for Information Security (IT244), unit 9.
Discussion
Loading…