← Back to Security Menu | 🏠 Hub
| Type | ဘာလုပ်တယ် | Example |
|---|---|---|
| 🦠 Virus | Files ကို infect လုပ် spread ဖြစ် | ILOVEYOU (2000) |
| 🐛 Worm | Network ကနေ auto spread | WannaCry |
| 🐴 Trojan | Useful software လို ဟန်ဆောင်ပြီး backdoor ဖွင့် | Emotet |
| 🔒 Ransomware | Files encrypt → money တောင်း | LockBit |
| 🕵️ Spyware | Keystrokes, passwords ခိုးတယ် | Pegasus |
| 💣 Rootkit | OS ထဲ hide ဝင်နေ hard to detect | ZeroAccess |
| 🚪 Backdoor | Secret remote access ဖွင့် | NetBus |
| 💰 Adware | Unwanted ads ပြ, data collect | DollarRevenue |
Phishing = Fake email/website နဲ့ credentials ခိုးတာ Types: 📧 Email Phishing — Mass fake emails (PayPal, bank, etc.) 🎯 Spear Phishing — Targeted specific person/company 🐋 Whaling — CEO/executives ကို target 📱 Smishing — SMS phishing 📞 Vishing — Voice call phishing Example phishing email: ┌─────────────────────────────────────────┐ │ From: support@paypa1.com │ │ Subject: Your account will be suspended │ │ │ │ Click here to verify: http://paypa1.ru │ └─────────────────────────────────────────┘ ⚠️ Clues: Misspelled domain, Urgency, Suspicious link
Social Engineering = Human psychology ကို exploit လုပ်တာ Techniques: 🎭 Pretexting — Fake identity (IT support လို ဟန်ဆောင်) 🤝 Baiting — USB drive ချပစ် (curiosity exploit) 🔄 Quid Pro Quo — Help offer → info ယူ 🚪 Tailgating — Physical access (secure area ဝင်) ⏰ Urgency — "ချက်ချင်း လုပ်ဖို့ လိုတယ်!" pressure Example: "IT Support ကနေ ဖုန်းဆက်တာပါ။ Server maintenance လုပ်နေတာ password ကို verify လုပ်ရဦးမယ်..." → Real IT ဟာ password မတောင်းဘူး!
DoS = Denial of Service (one source) DDoS = Distributed DoS (thousands of sources/botnet) Goal: Server/Service ကို overwhelm ဖြစ်အောင် → DOWN ဖြစ် Types: 📦 Volume-based — Bandwidth flood (UDP/ICMP) 🔗 Protocol — SYN flood (TCP handshake exhaust) 🌐 Application — HTTP flood (Layer 7, hardest to detect) DDoS impact: - Website DOWN → revenue loss - Record: 3.47 Tbps (Microsoft Azure, 2021)
MITM = User ↔ Server ကြားကနေ communication intercept Scenarios: ☕ Public WiFi (coffee shop) → Attacker same network 🔀 ARP Spoofing → Traffic redirect 🌐 DNS Spoofing → Fake website ညွှန် HTTP: User → "username=ko&password=1234" → [ATTACKER sees!] → Server HTTPS: User → [encrypted] → [ATTACKER sees gibberish] → Server
| Attack | Target | Defense |
|---|---|---|
| Brute Force | Passwords | Account lockout, strong passwords, MFA |
| Credential Stuffing | Reused passwords | Unique passwords per site, password manager |
| Zero-day | Unknown vulnerability | WAF, patch fast when released |
| Supply Chain | 3rd party software | Dependency audit, code signing |
← Security 01 | Next: Security 03 → Web Security →