Definition of malware.
We often speak of malware, we try to understand what they are and how they are defined.
Malware:
is defined as any malicious software created for the sole purpose of causing serious damage, or even the computer that is running. The term comes from the contraction of the words malicious software and and therefore has the literal meaning of "bad programs" in Italian is also known as malicious code .
The distribution of such software is increasing. It is estimated that in 2008 alone on the Internet have turned about 15 million of malware, including those circulated between January and August are the sum of the previous 17 years, and the numbers are probably destined to increase.
There are many types of malware, here is the best known and popular.
Virus:
A virus is software that is able, once executed, can infect files in order to reproduce, making copies of itself, usually without discovery by the user. The virus may or may not be directly harmful to the host operating system, but also, result in a waste of resources in terms of RAM, CPU and disk space. As a general rule it is assumed that a virus can damage only software directly to the machine that hosts it, although it may also indirectly cause damage to hardware, such as causing the overheating of the CPU by overclocking, or stopping the cooling fan.
Worm: A worm
(literally "worm") is a special category of malware that can self-replicate. It is similar to a virus, but unlike this does not need to bind to other executables to spread. The term comes from a science fiction novel of 1970 by John Brunner: the researchers were writing one of the first studies on distributed computing noted the similarities between your program and one in the book and adopted the name. One of the first worm was released on the network Internet Worm created by Robert Morris, the son of a senior NSA official November 2, 1988, when the Internet was in its infancy. This virus was able to strike between 4000 and 6000 machines, an estimated 4-6% of computers connected to the network at that time.
Trojan horse:
A Trojan or Trojan horse (English for Trojan Horse) is a type of malware. It owes its name to the fact that his features are hidden inside a seemingly useful program, so it is the user that you install and run a program, unknowingly, get and also running the trojan code hidden.
Usually the term Trojan is referred to the remote access trojan (RAT English also called Remote Administration Tool ), generally consist of two files: the file server, which is installed on the victim machine, and client files, used by the attacker to send instructions to the server is running.
Backdoor:
Backdoors in computer science are comparable to service ports (ie the back door) that overcome some or all safety procedures activated in a computer system.
can also be installed individually by some malware (viruses, worms or Trojan horses) so as to allow an external user to take remote control of the machine without the permission of the owner.
Keylogger:
A keylogger is, in the computer field, a tool that can intercept everything a user types on the keyboard of your computer.
Keyloggers are simple software programs that are running capturing every key you type and then, in some cases, forward that information to a remote computer.
Spyware:
Spyware is a type of software that collects information about a user's online activity (sites visited, purchases made online, etc.) without his consent, Transmitted via Internet to an organization that will use for profit, usually by sending targeted advertising. The data collection programs that are installed with your permission (though often denying the consensus is not installed the program) are not really spyware, provided that it is clear what data the user being subject to the collection and what conditions this happens (unfortunately this happens very rarely).
In a broader sense, the term spyware is often used to describe a wide range of malware (malicious software) from various functions, such as sending unsolicited advertisements (spam), changing the home page or the browser's Favorites list, or illegal activities such as the redirection on fake e-commerce sites (phishing) or the installation of fraudulent dialer for special rate numbers.
Rootkit:
A rootkit is a software program designed to have complete control over the system without authorization from the user or administrator. Recently, some computer viruses have taken advantage of the opportunity to act as a rootkit (process, file, registry key, network port) within the operating system.
While this technology is essential for the proper functioning of the operating system, over the years have been created Trojans and other programs malignant able to gain control of a local or remote computer hidden in a way, that is undetectable by the most common means of administration and control. Rootkits are typically used to hide backdoors. In recent years, however, has become much more common practice among the creators of malware using rootkit to make it more difficult to detect specific trojans and spyware, regardless of the presence in them of a backdoor function, thanks to the possibility of conceal the main processes. Due to the high level of priority with which they are running, the rootkit is very difficult to detect and remove with normal antivirus software. These are the malware
most popular and widespread.
0 comments:
Post a Comment