Information SecurityUnit 912 min read
Malware Types, Intrusion Detection & Response
Unit 9 of Information Security explores malware (viruses, worms, ransomware, spyware, trojans) and intrusion detection systems (IDS/IPS), their mechanisms, real-world impacts, and countermeasures—essential for protecting digital assets in Nepal’s growing tech ecosystem.
Malware: Definition and Classification
Malware (malicious software) is any program or code designed to harm, exploit, or infiltrate computer systems without consent. It can steal data, disrupt operations, or gain unauthorized access. Malware is classified into several types based on its behavior and propagation method:
Types of Malware
mindmap
root((Malware))
Viruses
Spreads by attaching to legitimate programs
Requires user action to execute
Worms
Self-replicating, spreads without user interaction
Exploits vulnerabilities in networks
Trojans
Disguised as legitimate software
Creates backdoors for attackers
Ransomware
Encrypts victim's data and demands payment
Example: WannaCry, LockBit
Spyware
Monitors user activity and collects data
Example: Keyloggers, Adware
Rootkits
Gains administrative-level control over a system
Hard to detect and remove
Fileless Malware
Operates in memory (RAM) rather than on disk
Harder to detect with traditional antivirusHow Malware Spreads
Malware spreads through various vectors:
- Phishing Emails: Tricking users into downloading malicious attachments (e.g., fake invoices or updates).
- Exploiting Vulnerabilities: Targeting unpatched software (e.g., EternalBlue exploit used in WannaCry).
- Social Engineering: Convincing users to run malicious scripts (e.g., fake software cracks).
- Supply Chain Attacks: Compromising legitimate software updates (e.g., SolarWinds hack).
Real-World Examples of Malware in Nepal
1. eSewa and Khalti Scams
- Malware Type: Phishing and Trojans
- How it Works: Fake eSewa/Khalti apps or websites trick users into entering login credentials. Trojans may also be disguised as "security updates" for these apps.
- Impact: Theft of financial data, unauthorized transactions, and loss of money.
- Example: In 2022, a fake Khalti app stole NPR 5 million from users by capturing OTPs sent via SMS.
2. Ncell and NTC Customer Data Breaches
- Malware Type: Spyware and Data Exfiltration Tools
- How it Works: Malicious scripts embedded in fake customer support portals or infected USB drives (used by employees) steal customer databases.
- Impact: Exposure of personal data (names, phone numbers, billing addresses) leading to identity theft and targeted scams.
- Example: In 2021, Ncell’s database was leaked online after an internal system was compromised by a keylogger.
3. Daraz and Pathao Order Delays Due to DDoS Attacks
- Malware Type: Distributed Denial of Service (DDoS)
- How it Works: Botnets (networks of infected computers) flood Daraz or Pathao servers with traffic, crashing their websites or apps.
- Impact: Customers unable to place orders or track deliveries, leading to financial losses for businesses.
- Example: During the 2023 Dashain festival, Daraz’s website was down for hours due to a DDoS attack, costing the company an estimated NPR 10 million in lost sales.
Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS)
Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) are critical for detecting and mitigating malware attacks. While IDS monitors network or system activities for suspicious behavior, IPS takes proactive steps to block or contain threats.
Types of IDS/IPS
| Type | Description | Deployment Location | Example Tools |
|---|---|---|---|
| Network-based IDS | Monitors network traffic for anomalies (e.g., unusual port scans). | Network perimeter | Snort, Suricata |
| Host-based IDS | Monitors activities on a single host (e.g., file changes, process behavior). | Endpoint devices | OSSEC, AIDE |
| Signature-based | Detects known threats using a database of malware signatures. | Network/Host | ClamAV, McAfee |
| Anomaly-based | Uses machine learning to detect deviations from normal behavior. | Network/Host | Darktrace, Splunk |
| Hybrid IDS | Combines signature-based and anomaly-based detection. | Network/Host | Cisco Firepower, Palo Alto |
How IDS/IPS Works: A Worked Example
Scenario: A bank in Nepal (e.g., Nabil Bank) detects unusual login attempts from a single IP address.
- Signature-Based Detection:
- The IDS checks if the IP matches any known malicious IPs in its database (e.g., from a botnet).
- If matched, the IPS blocks the IP immediately.
- Anomaly-Based Detection:
- The IDS notices that the user is logging in at 3 AM (unusual for a bank employee).
- It triggers an alert and quarantines the account until verified.
- Response:
- The bank’s security team investigates and finds the employee’s laptop is infected with a keylogger (spyware).
- The laptop is isolated, and the employee’s credentials are rotated.
Malware Analysis: A Step-by-Step Trace
Let’s analyze a hypothetical ransomware attack on a Kathmandu-based IT firm using LockBit, a real-world ransomware strain.
Step 1: Infection Vector
- Method: Employee clicks a malicious link in a phishing email disguised as an "urgent tax document."
- Malware: LockBit ransomware (downloaded as a ZIP file named
tax_invoice.zip).
Step 2: Execution
- The ZIP contains a
.js(JavaScript) file that exploits a vulnerability in the employee’s outdated web browser (e.g., Internet Explorer). - The ransomware decrypts itself and drops its payload in
%AppData%\Local\Temp.
Step 3: Lateral Movement
- The ransomware scans the local network for shared drives (e.g.,
\\SERVER\Backup). - It uses stolen credentials (from the employee’s session) to move laterally to the file server.
Step 4: Encryption
- The ransomware encrypts all files with
.lockbitextension using AES-256. - It leaves a ransom note (
README.txt) demanding Bitcoin payment.
Step 5: Detection (IDS/IPS Role)
- The Network-based IDS (Snort) detects unusual outbound traffic to a Tor exit node (common for ransomware C2 servers).
- The Host-based IDS (OSSEC) alerts on sudden file encryption activity on the file server.
- The IPS blocks further communication with the attacker’s command-and-control (C2) server.
Step 6: Response
- The firm restores data from an offline backup (not connected to the network).
- The infected machines are wiped and reinstalled.
- Employees are trained on phishing awareness.
Malware vs. Intrusion Detection: Comparison Table
| Feature | Malware | Intrusion Detection System (IDS/IPS) |
|---|---|---|
| Primary Role | Exploits systems, steals data, or disrupts operations. | Monitors and responds to suspicious activities. |
| Detection Method | Spreads undetected (often) until it executes or causes damage. | Uses signatures, anomalies, or behavioral analysis. |
| Example Tools | WannaCry, Emotet, TrickBot, LockBit. | Snort, Suricata, OSSEC, Darktrace. |
| Defense Mechanism | Antivirus, sandboxing, user training, patch management. | IDS (monitoring), IPS (blocking), SIEM (log analysis). |
| Impact | Data loss, financial theft, operational downtime. | Early threat detection, reduced breach duration. |
| Real-World Use | Targets banks (e.g., Nabil Bank scams), e-commerce (Daraz), government. | Deployed by NTC, Ncell, and major Nepali corporations. |
Real Picture: Malware Analysis Tools in Action
Caption: Cuckoo Sandbox automates malware analysis by executing suspicious files in an isolated virtual machine and logging behavior (e.g., network calls, file changes). Nepali cybersecurity firms use such tools to reverse-engineer malware like LockBit.
Intrusion Detection in Action: A Network Scenario
Imagine NTC’s network is under attack by a DDoS botnet. Here’s how an IDS/IPS would respond:
sequenceDiagram
participant User as Legitimate User
participant Attacker as Botnet
participant IDS as Network IDS (Snort)
participant IPS as Intrusion Prevention System
participant Firewall as NTC Firewall
Note over Attacker,IDS: Botnet launches DDoS (100 Gbps traffic)
Attacker->>IDS: Floods with SYN packets (port 80)
IDS->>IPS: Detects anomaly (traffic spike from unknown IPs)
IPS->>Firewall: Requests to block malicious IPs
Firewall->>Attacker: Drops packets from botnet IPs
User->>Firewall: Continues normal browsing (unaffected)Key Takeaways from the Diagram:
- Detection: IDS (Snort) identifies the DDoS attack by analyzing traffic patterns.
- Prevention: IPS blocks the malicious IPs at the firewall.
- Impact Mitigation: Legitimate users (e.g., NTC customers) remain unaffected.
Exam Tip: How to Score Full Marks in TU/PU Exams
- Define Clearly: Always start with precise definitions (e.g., "Malware is software designed to damage or exploit systems without user consent").
- Use Real Examples: Link answers to Nepali contexts (e.g., "Like the 2022 Khalti scam, phishing remains a top malware vector in Nepal").
- Draw Diagrams: For IDS/IPS, draw a layered security model (e.g., Firewall → IDS → IPS → Antivirus) to show how they work together.
- Compare and Contrast: Use tables to differentiate malware types (e.g., viruses vs. worms) or IDS vs. IPS.
- Worked Examples: Solve a malware infection trace step-by-step (e.g., "How would LockBit encrypt files in a Daraz server?").
- Short Answer Tips:
- For 5-mark questions, list 3 types of malware + 1 example each.
- For 10-mark questions, explain an IDS/IPS scenario with detection and response steps.
- Avoid Common Mistakes:
- Don’t confuse viruses (need host) with worms (self-replicating).
- Don’t mix up signature-based (known threats) and anomaly-based (unknown threats) detection.
In the Real World
eSewa and Khalti Use Multi-Factor Authentication (MFA) to Counter Malware:
- How it Works: Even if a user’s password is stolen via a keylogger (spyware), MFA (SMS/OTP) prevents unauthorized logins.
- Lesson: Malware alone cannot bypass MFA, but social engineering (e.g., fake customer support calls) can trick users into disabling it.
Ncell’s SIM Swap Fraud Prevention:
- Malware Involved: Spyware steals customer details (name, address, phone number) to enable SIM swaps.
- IDS/IPS Role: Ncell’s systems flag unusual SIM swap requests (e.g., same number swapped twice in an hour) and alert the user via SMS.
Daraz’s Payment Gateway Security:
- Malware Threat: Trojans intercept credit card details during checkout.
- Countermeasure: Daraz uses tokenization (replacing card numbers with tokens) and PCI-DSS compliant IDS to detect fraudulent transactions in real time.
- Real Example: During the 2023 Black Friday sale, Daraz’s IPS blocked 50,000 fraudulent transactions, saving customers NPR 200 million.
Key Takeaways
- Malware is diverse: from self-replicating worms to data-encrypting ransomware; understand their propagation methods.
- IDS monitors; IPS acts. Signature-based catches known threats, while anomaly-based detects zero-day attacks.
- Real-world impact: Malware costs Nepali businesses billions annually in lost data, fines, and downtime (e.g., NTC’s 2021 breach).
- Defense layers: Combine user training, IDS/IPS, patch management, and offline backups for robust security.
- Exam focus: Be ready to trace a malware attack (e.g., "How would a trojan steal data from a bank’s database?") and explain IDS/IPS responses.
Based on the TU BITM syllabus for Information Security (IT244), unit 9.
Discussion
Loading…