Cyber Threats & Attacks :- 1. Cyber Threat (साइबर खतरा) :-
Cyber Threat ऐसी संभावित स्थिति, घटना या activity है जो किसी Computer System, Network, Application या Data को नुकसान पहुँचा सकती है।
Cyber Threat में attacker का उद्देश्य system को नुकसान पहुँचाना, information को चोरी करना, unauthorized access प्राप्त करना या services को प्रभावित करना हो सकता है।
उदाहरण
मुख्य उद्देश्य → Computer System, Network या Data को नुकसान पहुँचाने या प्रभावित करने की संभावना पैदा करना।
2. Cyber Attack (साइबर हमला) :-
Cyber Attack एक Malicious Activity है जिसमें attacker किसी Computer, Network, Application या Data को target करता है।
Cyber Attack के द्वारा attacker Data चोरी, Data Modification, Unauthorized Access या Service Disruption करने का प्रयास कर सकता है।
उदाहरण
मुख्य उद्देश्य → Target System, Network, Application या Data को नुकसान पहुँचाना या Unauthorized तरीके से प्रभावित करना।
3. DoS Attack :-
DoS = Denial of Service
DoS Attack में attacker किसी Server या Network Service पर बहुत अधिक requests या traffic भेजने का प्रयास करता है, जिससे system के resources अधिक व्यस्त हो सकते हैं और Legitimate Users service को access नहीं कर पाते।
सरल उदाहरण
मान लीजिए किसी website को एक समय में सीमित संख्या में users के लिए service देने के लिए design किया गया है। यदि attacker बहुत बड़ी संख्या में requests भेजता है, तो server के resources consume हो सकते हैं और सामान्य users को website access करने में समस्या हो सकती है।
Main Purpose
Service को Unavailable या Disrupted करना।
DoS Attack का प्रभाव
4. DDoS Attack :-
DDoS = Distributed Denial of Service
DDoS Attack में किसी Server या Online Service को बहुत अधिक traffic या requests भेजकर उसे unavailable या severely disrupted करने का प्रयास किया जाता है।
DoS की तुलना में DDoS में traffic Multiple Compromised Devices या Systems से आ सकता है।
इन compromised devices के समूह को सामान्यतः Botnet कहा जाता है।
Botnet क्या है?
Botnet compromised computers या devices का एक network/group होता है जिसे attacker remotely control कर सकता है।
Main Purpose
Target Service को Unavailable या Disrupted करना।
DDoS Attack का प्रभाव
5. MITM Attack :-
MITM = Man-in-the-Middle
MITM Attack में attacker दो parties के बीच होने वाली communication को secretly intercept या monitor करने का प्रयास करता है।
इसका उद्देश्य communication से information प्राप्त करना या communication को प्रभावित करना हो सकता है।
उदाहरण
मान लीजिए एक User और Website के बीच communication हो रही है। यदि attacker बीच में communication को intercept करने का प्रयास करता है, तो इसे Man-in-the-Middle Attack कहा जाता है।
Protection / बचाव
6. Spoofing :-
Spoofing में attacker किसी Trusted Person, Device, Website या Identity का रूप धारण करने की कोशिश करता है ताकि victim को deceive किया जा सके।
इसमें attacker अपनी वास्तविक identity को छिपाकर किसी trusted source जैसा दिखाई देने का प्रयास कर सकता है।
Common Types of Spoofing 1. Email Spoofing
Attacker email को किसी trusted व्यक्ति या organization से आया हुआ दिखाने का प्रयास करता है।
2. IP Spoofing
Attacker network communication में source IP address को बदलकर किसी दूसरे source जैसा दिखाई देने का प्रयास करता है।
3. Website Spoofing
Attacker किसी trusted website जैसी दिखाई देने वाली fake website बनाने का प्रयास करता है।
4. Caller ID Spoofing
Caller की identity या phone number को किसी दूसरे number जैसा दिखाने का प्रयास किया जाता है।
Purpose
Victim को Deceive या Mislead करना।
In English -
Cyber Threats & Attacks :- 1. Cyber Threat :-
A Cyber Threat is a potential situation, event, or activity that can cause harm to a Computer System, Network, Application, or Data.
In a Cyber Threat, the attacker may aim to damage the system, steal information, gain unauthorized access, or affect services.
Examples
Main Objective → To create a possibility of damaging or affecting a Computer System, Network, or Data.
2. Cyber Attack :-
A Cyber Attack is a Malicious Activity in which an attacker targets a Computer, Network, Application, or Data.
Through a Cyber Attack, the attacker may attempt Data Theft, Data Modification, Unauthorized Access, or Service Disruption.
Examples
Main Objective → To damage or unauthorizedly affect the Target System, Network, Application, or Data.
3. DoS Attack :-
DoS = Denial of Service
In a DoS Attack, an attacker attempts to send a very large number of requests or traffic to a Server or Network Service, which can make the system resources very busy and prevent Legitimate Users from accessing the service.
Simple Example
Suppose a website is designed to provide services to a limited number of users at a time. If an attacker sends a very large number of requests, the server resources may be consumed, and normal users may experience difficulty accessing the website.
Main Purpose
To make the Service Unavailable or Disrupted.
Effects of DoS Attack
4. DDoS Attack :-
DDoS = Distributed Denial of Service
In a DDoS Attack, an attacker attempts to make a Server or Online Service unavailable or severely disrupted by sending a large amount of traffic or requests.
Unlike DoS, in a DDoS Attack, the traffic may come from Multiple Compromised Devices or Systems.
The group of these compromised devices is commonly called a Botnet.
What is a Botnet?
A Botnet is a network/group of compromised computers or devices that can be remotely controlled by an attacker.
Main Purpose
To make the Target Service Unavailable or Disrupted.
Effects of DDoS Attack
5. MITM Attack :-
MITM = Man-in-the-Middle
In a MITM Attack, an attacker attempts to secretly intercept or monitor communication between two parties.
The purpose may be to obtain information from the communication or interfere with the communication.
Example
Suppose communication is taking place between a User and a Website. If an attacker attempts to intercept the communication between them, it is called a Man-in-the-Middle Attack.
Protection
6. Spoofing :-
Spoofing is an attack in which an attacker attempts to impersonate a Trusted Person, Device, Website, or Identity in order to deceive the victim.
In this attack, the attacker attempts to hide their real identity and appear as a trusted source.
Common Types of Spoofing 1. Email Spoofing
The attacker attempts to make an email appear as if it has come from a trusted person or organization.
2. IP Spoofing
The attacker attempts to change the source IP address in network communication so that it appears to come from another source.
3. Website Spoofing
The attacker attempts to create a fake website that looks like a trusted website.
4. Caller ID Spoofing
The caller's identity or phone number is made to appear as a different number.