What are typical phases of operation of a virus or worm


Assignment

Part 1

1) What are three broad mechanisms that malware can use to propagate?

2) What are four broad categories of payloads that malware may carry?

3) What are typical phases of operation of a virus or worm?

4) What mechanisms can a virus use to conceal itself?

5) What is the difference between machine-executable and macro viruses?

6) What means can a worm use to access remote systems to propagate?

7) What is a "drive-by-download" and how does it differ from a worm?

8) What is a "logic bomb"?

9) Differentiate among the following: a backdoor, a bot, a keylogger, spyware, and a rootkit? Can they all be present in the same malware?

10) List some of the different levels in a system that a rootkit may use.

11) Describe some malware countermeasure elements.

12) List three places malware mitigation mechanisms may be located.

13) Briefly describe the four generations of antivirus software.

14) How does behavior-blocking software work?

15) What is a distributed denial-of-service system?

Part 2

1) List and briefly define three classes of intruders.

2) What are two common techniques used to protect a password file?

3) What are three benefits that can be provided by an intrusion detection system?

4) What is the difference between statistical anomaly detection and rule-based intrusion detection?

5) What metrics are useful for profile-based intrusion detection?

6) What is the difference between rule-based anomaly detection and rule-based penetration identification?

7) What is a honeypot?

8) What is a salt in the context of UNIX password management?

9) List and briefly define four techniques used to avoid guessable passwords.

Part 3

1) List three design goals for a firewall.

2) List four techniques used by firewalls to control access and enforce a security policy.

3) What information is used by a typical packet filtering firewall?

4) What are some weaknesses of a packet filtering firewall?

5) What is the difference between a packet filtering firewall and a stateful inspection firewall?

6) What is an application-level gateway?

7) What is a circuit-level gateway?

8) What are the common characteristics of a bastion host?

9) Why is it useful to have host-based firewalls?

10) What is a DMZ network and what types of systems would you expect to find on such networks?

11) What is the difference between an internal and an external firewall?

Format your assignment according to the give formatting requirements:

a. The answer must be double spaced, typed, using Times New Roman font (size 12), with one-inch margins on all sides.

b. The response also includes a cover page containing the title of the assignment, the course title, the student's name, and the date. The cover page is not included in the required page length.

c. Also include a reference page. The references and Citations should follow APA format. The reference page is not included in the required page length.

Request for Solution File

Ask an Expert for Answer!!
Computer Network Security: What are typical phases of operation of a virus or worm
Reference No:- TGS03026929

Expected delivery within 24 Hours