Ama's classmate posts Ama's home address and phone number on a social media platform so that people can locate and harm her. Which form of cyberbullying is this?
Strand 2 · Network Systems for Transmitting Information
Information and Communication Technology Year 2 Learner Material, Section 5: Computer Network Security and Network Security Risks
This section is a continuation of year one lessons that introduced you to network systems for transmitting information. Here, you will learn and understand safety and security issues in the use of ICTs. The section is designed to help you understand and evaluate the risks associated with using ICTs which includes internet and network attacks such as cyberbullying, malware, botnets, denial-of-service attacks, spoofing, hardware theft and firewalls among others. You will also discuss the preventive mechanisms such as antivirus software, hardware and software firewalls to mitigate computer network and security risks.
KEY IDEAS
• Computer Network Security refers to the practice of protecting computer networks from unauthorised access, attacks, or damage. It involves a variety of technologies, policies, and procedures designed to safeguard the integrity, confidentiality, and availability of data and services on a network.
• Computer Security has to do with protecting the hardware such computers and servers and software like operating systems and applications from threats such as hackers or viruses.
• Information Security focuses on safeguarding the actual data itself. Whether it is personal information, financial data, or business secrets, ensuring that only authorised people can access it and that it remains private and accurate.
• Network Security Risks are the potential threats or vulnerabilities that can compromise the security of a network.
Cyberbullying is when someone uses the internet, social media, or other digital platforms to hurt, threaten, or embarrass another person. It can involve sending offensive messages, posting hurtful comments, spreading rumours, or sharing private information to make the victim feel bad or scared. Unlike bullying in person, cyberbullying can happen at any time and reach the victim anywhere, even in the safety of their own home. It’s a harmful behaviour that can have serious effects on the person’s mental and emotional well-being.
Table 5.1: Forms of Cyberbullying
S/N FORM EXPLANATION
1 Doxing Posting someone’s private information (like their home address or phone number) online to harm them or make them feel unsafe.
2 Cyberstalking Repeatedly sending threatening or abusive messages, or following someone online in a way that makes them feel unsafe or scared.
3 Trolling Posting offensive or provocative comments online just to upset or annoy someone, often in comment sections or forums.
4 Impersonation Pretending to be someone else online and saying or doing things that can harm the person being impersonated, like sending fake messages or posting embarrassing content.
5 Outing Sharing someone’s private information or personal photos online without their permission to embarrass or hurt them.
6 Harassing Messages
Sending hurtful, threatening, or mean messages through texts, emails, or social media.
7 Exclusion Intentionally leaving someone out of group chats, social media activities, or online games to make them feel unwanted or isolated.
8 Spreading Rumours
Sharing false or private information about someone online to make others believe something bad about them.
Figure 5.1: Some common effects of cyberbullying
Activity 5.1 Matching activity on effects of Cyberbullying This activity will help you understand the effects of cyberbullying on people.
In this activity, you are to write one word that best suits the image and the corresponding description. You can use Figure 5.1 as a guide.
Table 5.2: Some effects of Cyberbullying Image Description One word that matches image and description When you feel alone or separated from others. It is like being in a place where no one else is around, and you don’t feel connected to anyone. You might feel lonely, as if you are left out or not included in things A strong feeling of frustration or upset. You might feel it when things are not going your way, or when someone hurts or disrespects you. It is like an emotional fire inside you that can make you want to shout, argue, or even do something to get back at the person or situation that made you angry.
a feeling of deep sadness or hopelessness that lasts for a long time. It’s not just feeling sad for a day; it can make you feel like you don’t enjoy anything, have no energy, or that things will never get better. It can affect how you think, feel, and act.
When you feel very embarrassed or ashamed, especially in front of others. It is like being made to feel small or worthless, often because of something that happened or something someone said. It can make you feel like everyone is judging you.
When someone’s body or health is affected from feeling embarrassed, sad, upset or frustrated for being bullied online. This can make a person feel unwell.
Preventing Cyber Bullying
Preventing cyberbullying means taking steps to stop people from bullying others online. Figure 5.2 shows some common ways of preventing bullying online
Figure 5.2: Ways of preventing Cyberbullying
Activity 5.2 Creating a flyer on Preventing Cyberbullying
1. Pick three of the preventive measures of cyberbullying listed in Figure 5.2 and produce a flyer manually or digitally to educate computer uses on how to stay safe on the internet.
2. Your flyer should have explanations to your chosen preventive measures.
Malware (malicious software) is any type of computer program designed to harm or disrupt a computer, network, or device. It can steal your information, damage your files, slow down your system, or even give someone else control over your device without your permission.
Types of Malwares
There are many types of malwares, each with specific functions and purposes.
Table 5.3: Types of Malwares
S/N TYPE DESCRIPTION
1 They are types of malwares that often take the form of a piece of code inserted in an application, program, or system and they are deployed by victims themselves. They can seize applications, send infected files to contact lists and also steal data.
2 A worm spreads itself from one computer to another without needing any help from people. It can travel through the internet, email, or other networks automatically, infecting new systems as it goes. The main problem with worms is that they can spread very quickly, causing damage by slowing down systems, stealing information, or even crashing networks.
3 This type of malware tricks users into thinking it is something safe or useful. Once it is inside a computer, it can cause a lot of damage such as stealing your personal information (like password), give hackers access to your computer and damage files or make your system to slow down.
Unlike worms or viruses, Trojans don’t spread by themselves.
4 Spyware is designed to secretly monitor and collect a user’s
activities without their knowledge, often to steal sensitive information like passwords, credit card numbers, or personal data.
5 Adware is software that automatically delivers unwanted advertisements. While often not malicious by nature, some adware can track user behaviour and interfere with the system’s performance.
How malware spread
1. USB Drives/Removal Drives: If you plug an infected USB drive into your computer, the malware can transfer from the drive to your system. This can happen without you realising it.
2. Email attachments: Malware often hides in attachments to emails that look like legitimate messages. When you open the attachment, the malware infects your computer.
3. Social media and Links: Malware can spread through fake links or posts on social media. If you click on these links, you might be tricked into downloading malware or visiting a harmful website.
4. Infected Websites: Some websites contain hidden malware that can automatically download to your computer when you visit them. This can happen even if you do not click anything.
5. Fake Software Downloads: Malware can disguise itself as free software, games, or updates. When you download and install it, you are actually getting malware instead of the program you thought off.
Prevention and protection from Malwares
1. Avoid Downloading from Untrusted Sites: Only download software from trusted websites, and be cautious of free programs or games, as they may carry malware.
2. Use Antivirus Software: Install and regularly update antivirus software. It helps detect and block malware before it can cause damage.
3. Be Careful with Emails and Attachments: Don’t open email attachments or click on links from unknown or suspicious senders. Scan email files with anti- virus before you open its content.
4. Keep Software Updated: Make sure your operating system, web browser, and apps are up-to-date. Updates often include security patches that fix vulnerabilities that malware could exploit.
5. Use Strong Passwords: Use strong, unique passwords for your accounts and enable two-factor authentication (2FA) when available. This can help protect your personal information from being stolen by malware.
6. Disconnect from Untrusted Networks: Avoid using public Wi-Fi for sensitive
activities (like online banking) because it’s easier for malware to spread over unsecured networks. Use a VPN if you need to connect to public Wi-Fi.
Activity 5.3 Research Activity on Malware
In groups of no more than five, pick one type of malware that you have learned so far.
Research on the following:
1. It’s history
2. How it spreads
3. Include recent examples of attacks and dangers that it brings to computer users
4. How to prevent that particular malware In your groups, create a presentation with your findings together and present to the whole class for discussion and feedback
Botnets are groups of infected devices, often called zombies or bots. These devices can be anything like computers, phones, or even smart appliances. Botnets are one of the most common and serious types of malwares. They work together without the owner’s knowledge to do things for the hacker. For example, a hacker might use a botnet to:
1. Flood a website with traffic to make it crash.
2. Steal personal information like passwords or bank details.
3. Send spam emails to infect even more devices.
The main danger of botnets is that they can control many devices at once, making them very powerful for cybercriminals.
Figure 5.3: Botnet
Denial-of-service attacks _(A) Denial-of-service (DoS) attack is when a hacker tries to make a website or online service stop working by overpowering it with too many requests or traffic. The goal is to make the service unavailable to its users Imagine a website like a classroom with a limited number of seats. If too many people try to sit in that classroom at the same time, the classroom gets crowded and real members of the class cannot get a seat to sit on. In the same way, during a DoS attack, the target system gets so much traffic that it crashes or slows down and legitimate users cannot access the website or service.
Figure 5.4: Denial-of-service attack (DoS) Characteristics of a denial-of-service attack (DoS) ₁. Overloads the Server: A DoS attack floods a website or server with so much traffic that it becomes overwhelmed and can’t handle normal requests. This causes the server to slow down or crash.
2. Targets a Single System: In a typical DoS attack, all the traffic comes from one source (a single computer or device) controlled by the attacker.
3. Makes the Website Unavailable: The main goal of a DoS attack is to make a website or online service temporarily unavailable, meaning legitimate users can’t access it.
4. No Data Theft: Unlike other types of attacks, a DoS attack doesn’t usually steal information. Its main purpose is to disrupt access to the site, not to compromise personal data.
5. Temporary Impact: While a DoS attack can cause serious disruptions, it usually doesn’t cause permanent damage. The website or service can often be restored once the attack stops.
Types of Denial-of-service Attack
Figure 5.5: Types of Denial-of-service attack Protection against denial-of-service (DoS) attacks
1. Pre-emptive measures: These measures help prepare your system to handle potential DoS attacks before they happen, making it more resilient and reducing the chances of an attack succeeding.
2. Post-attack response refers to the actions you take after a DoS attack has happened to minimise damage, fix the issues, and prevent future attacks.
Table 5.4: Pre-emptive Measure and Post-Attack Response on DoS Pre-emptive Measure Post-Attack Response Set Up Web Application Firewalls (WAF) that filters and monitors incoming traffic to your website, blocking suspicious requests that may come from a DoS attack.
Identify the Attack: The first step is to understand what happened. You need to check your logs, network traffic, and systems to see how the attack occurred and which parts of your system were affected.
Implement Rate Limiting to controls how many requests a user or device can make to your server in a certain period of time. This helps prevent attackers from flooding your system with too many requests at once.
Block the Attack Source: If possible, find the attacker’s IP address or source of the attack and block it from accessing your network or website Have multiple servers, networks, or data centres in different locations. By spreading the load, it becomes harder for a DoS attack to bring down all systems simultaneously, ensuring your service remains available.
Restore Services: Once the attack has been stopped, work on getting your website or service back up and running. This may involve rebooting servers, restarting services, or removing harmful data that was affected.
Use a Content Delivery Network
(CDN): this feature distributes your website’s content across multiple servers around the world, so even if one server gets overloaded, others can handle the traffic to make it much harder for attackers to target a single server.
Evaluate the Damage: Check if there was any data loss, security breaches, or other harm done during the attack. Make sure your systems are clean and secure before allowing normal operations.
Set up real-time monitoring to track incoming traffic patterns. Early detection of unusual spikes in traffic can help you identify and stop a potential DoS attack before it causes major damage.
Improve Defences: After the attack, analyse what went wrong and strengthen your security measures. This could involve adding firewalls, increasing server capacity, or improving your traffic filtering to be ready for future attacks.
Effects of DoS Attacks
When someone tries to stop a website or online service from working by overwhelming it with too many requests at once, it results in some negative impacts on the individual users and the organisations
Figure 5.6: Effects of DoS Attacks
Distributed denial of service (DDoS) attack A distributed denial of service (DDoS) attack is when many computers or devices team up to overload a website or online service, making it slow or even crash. Think of a website as a small shop with one door. If thousands of people rush in at once, the shop can’t serve its usual customers, and everyone gets stuck outside.
In a DDoS attack, the traffic comes from many computers or devices, often without the owners knowing. These devices are infected with harmful software that makes them part of a “botnet” controlled by the attacker. The attacker then sends a flood of requests to the website from these devices, causing it to become very slow or crash, blocking regular users from accessing it.
Activity 5.4 Effects of denial-of-service attacks (DoS)
1. In groups of at most five members, pick one effect of DoS from Figure 5.6 and discuss how denial of service can result in your chosen effect.
2. Present your findings to the whole class for feedback and discussion Spoofing Spoofing in cybersecurity is when a hacker pretends to be someone or something they are not, in order to deceive others and gain unauthorised access or information.
How does spoofing works?
Spoofing works by faking or pretending to be someone else to trick people into believing it is a trusted source. Here’s how it typically works:
1. Fake Identity: The person doing the spoofing will create a fake email address, phone number, or website that looks like it is from a real, trusted source
2. Deceptive Message: They send a message (email, text, etc.) that looks official, asking you to do something, such as clicking a link, entering personal information, or downloading a file.
3. Since the message looks real, you might think it is safe and respond. But in reality, it is the attacker trying to steal your information or install harmful software on your device.
Types of spoofing ₁. Email spoofing: The attacker sends an email that looks like it is from a trusted source such as your bank or a friend but in reality, it is not from them.
2. IP spoofing: The attacker fakes the IP address of their device to make it look like the traffic is coming from a trusted source, often to bypass security checks.
3. Website spoofing: A hacker creates a fake website that looks like a real one such as a fake login page to trick users into entering their personal information.
4. Caller ID or phone spoofing: The attacker makes it look like a phone call is coming from a trusted number when it is really from them, often used in scams.
5. DNS spoofing: The attacker changes the records of a domain name server (DNS) so that when you try to visit a website, you are sent to a fake one instead.
Now that you have gone through some common computer and information security risks, let us take this activity to boost your understanding of these risks, how they are caused, the effect they may pose on users and how they can be prevented as well as practices that protect our digital devices and information systems from these risks.
Activity 5.5 Computer and Information Security Risks
1. In groups of not more than five, pick one risk associated with using ICT, including internet and network attacks (cyberbullying, malware, denial-of- service attacks) and discuss strategies for preventing and addressing your chosen risk.
2. Create a presentation to be delivered to the whole class explaining the effects of your chosen risk.
3. Deliver your presentation to the whole class.
4. Allow other groups to ask questions and make contributions.
Intrusion Detection Systems (IDS)
An Intrusion Detection System (IDS) watches for any unusual or suspicious activity, such as someone trying to break in or cause harm. It acts as a security guard for your computer or network, looks out for danger and helps protect your system from threats.
How IDS works Monitoring: The IDS constantly keeps an eye on the traffic and actions happening on the system or network, looking for signs of possible threats, like hackers trying to access your data or malicious software trying to spread.
Detection: If it detects something suspicious (like someone trying to hack into your system or a virus trying to enter), it raises an alert to warn the system administrators or security team.
Protection: While an IDS does not stop the attack directly, it helps people respond quickly before the damage becomes serious.
_(An) Intrusion Prevention System (IPS) is like an active security guard for your network or computer. Unlike an Intrusion Detection System (IDS), which just alerts you about threats, an IPS actively stops them before they can cause harm to your system. IPS watches for threats and actively stops them from causing damage to your system.
How IPS works
1. Monitoring: The IPS constantly monitors the network traffic and system
activities, just like a security camera watches a building.
2. Detection: It looks for any suspicious activity or known patterns of attacks, like hackers trying to get in or harmful software trying to spread.
3. Prevention: When the IPS spots something dangerous, it does not just send an alert rather, it takes action to block the threat immediately. For example, it can stop harmful traffic, block the attacker’s access, or even disconnect a malicious device from the network.
Activity 5.6 Differentiating between IDS and IPS.
Now that you know what IDS and IPS are and how they both work, complete
Table 5.5 to clearing state their differences based on the given criteria in the table.
Table 5.5: Differences between IDS and IPS Criteria IDS (Intrusion Detection System) IPS (Intrusion Prevention System) Purpose Detects and actively stops threats Action Alerts the user or admin about possible threats Response to Threats Does not stop the attack, only alerts Location in Network Typically placed in a “monitoring” position, after traffic enters the network Placed in-line with the traffic flow to actively block threats Impact on Traffic Can delay or block traffic to prevent attacks
Example Alerts when someone tries to hack into a network Use Used for both detection and prevention of attacks Similarities between IDS and IPS
1. Purpose: Both IDS and IPS are designed to detect and monitor suspicious
activities or threats on a network or system to help protect it from attacks.
2. Security Role: Both serve as part of a network security system, helping to identify potential security breaches, such as hacking attempts, malware, or unauthorised access.
3. Use of Signatures: Both systems often rely on signatures or patterns of known attacks to detect threats. These signatures are used to recognise malicious
activity based on previous attacks.
4. Traffic Monitoring: Both IDS and IPS monitor network traffic for unusual or suspicious behaviour, looking for signs of attacks or malicious activities.
Network Access Control (NAC)
It is a security system that helps control who or what can access a network. It guards your network, making sure only authorised devices or users are allowed in. NAC ensures that only trusted, secure devices and users can access your network, helping to prevent unauthorised access and protect against security risks.
How NAC works ₁. Checking devices: Before allowing any device such as a computer, smartphone, or tablet to connect to the network, NAC checks if the device is safe. It checks whether the device has the latest security updates or if it is running antivirus software.
2. Granting access: If the device meets the security standards, the NAC lets it access the network. If not, it either blocks the device or gives it limited access to certain resources until it becomes secure.
3. Ongoing monitoring: Once the device is connected, NAC continues to monitor its behaviour to ensure it does not pose a threat or become compromised Security Patch Management This is the process of regularly updating software and systems to fix security problems or weaknesses. These updates are called patches, and they are released by software makers to protect against new threats or vulnerabilities.
How security patch management works
1. Identifying Vulnerabilities: Sometimes, software or systems have weaknesses that hackers can exploit to cause harm. When these weaknesses are discovered, the software maker creates a patch to fix them.
2. Installing Patches: Security patches are released by the software maker, and the system or device needs to install them. This is usually done automatically or manually, depending on the settings.
3. Regular Updates: It is important to keep applying patches regularly so that your systems stay protected against new security threats. This keeps everything up to date and less vulnerable to attacks.
Activity 5.7 Multimedia activity on IDS/IPS/NAC/Patch management.
1. Click on this link to watch the video - Firewalls and IDS/IPS: Essential Tools for Network Security || Part 5
2. Make notes from the video and discuss your thoughts and findings with the class. .
3. Relate the content of the video to your experiences on IDS/IPS/NAC/Patch Management.
4. Identify its uses, advantages, and limitations, relating it to your own ideas and experiences.
5. Share your ideas with the whole class for a discussion
Activity 5.8 Research on IDS, IPS, NAC and patch management
1. In groups of not more than five, pick one mechanism that can reduce network security attacks (IDS/IPS/NAC/Patch management) and discuss how it works to prevent threats.
2. Create a presentation elaborating the benefits of your chosen mechanism that can reduce network security attacks.
3. Deliver your presentation to the whole class for feedback and discussion
4. Allow other groups to ask questions and make contributions.
An antivirus is a software program designed to protect your computer or device from harmful programs called viruses and other threats such as malware. These harmful programs can damage your device, steal your information, or make it slow.
How Antivirus Works
₁. The antivirus checks your files and programs to see if any of them have viruses or other harmful software.
2. If it finds something dangerous, the antivirus will stop it from spreading or causing damage.
3. It helps keep your digital devices safe from new viruses by regularly updating its protection.
4. If a virus is found, the antivirus can remove it, so your device works properly again.
Figure 5.6: Ways of obtaining best protection Firewalls A firewall is like a security guard for your computer or network. Its job is to control the flow of data that comes in and goes out, and decide what is safe and what is not.
Firewalls can be a physical device that sits between your computer or network and the internet (Hardware-based) or a program running on your computer or device that checks for any bad or unwanted traffic (Software-based). They helps protect your system by keeping bad things out while letting the safe stuff pass through.
Figure 5.7: Hardware Firewall
Table 5.6: How software and hardware firewalls work Software firewall Hardware firewall When your computer wants to communicate with the internet such as loading a website, sending an email, or using an app, the firewall checks whether this action is safe. If it thinks the action is suspicious or harmful, it blocks it. (Traffic Filtering) The hardware firewall is usually placed between your home or office network and your internet connection such as your router.
You can set rules on the firewall about what is allowed or not. For example, you might let your web browser and email program connect to the internet, but block a suspicious program from accessing the network.
(Custom Rules) It checks all incoming and outgoing data and blocks any harmful traffic, such as hackers trying to access your network.
Table 5.7: Examples of software and hardware firewalls Software firewall Hardware firewall Windows Defender Firewall: Built into Windows computers, it monitors and controls incoming and outgoing traffic based on a set of security rules.
Cisco ASA (Adaptive Security
Appliance): A more advanced firewall used by businesses to protect their networks from cyber threats.
Figure 5.8: Deployment of a Firewall in a SOHO
Activity 5.9 Computer and Information Security Risks Prevention
1. In groups of not more than five, create a presentation to be delivered to the whole class on the need to use firewalls and antiviruses on computers systems and networks. In your presentation, include real-life examples to illustrate how these technologies protect computer systems and networks from threats.
2. Deliver your presentation to the whole class.
3. Allow other groups to ask questions and make contributions.
Ama's classmate posts Ama's home address and phone number on a social media platform so that people can locate and harm her. Which form of cyberbullying is this?
Which type of malware is designed to secretly monitor and collect a user's activities without their knowledge?
Which statement correctly distinguishes a botnet from a denial-of-service (DoS) attack?
Which of the following best describes an Intrusion Prevention System (IPS)?
A school places a physical device between its local network and the internet connection. The device checks all incoming and outgoing data and blocks harmful traffic. What is this device called?