Nov 22, 2009

Exploring The Spyware Effects And Security Risks - I wrote this research paper thought should share with all

free web hosting
Open Discussion > MODERATED AREA > Computers > Computer Security Issues & Exploits

Exploring The Spyware Effects And Security Risks - I wrote this research paper thought should share with all

phpphp
The topic was improtant so thougth I should share it with you guys. As its written by me with all reference and never publish anywhere so no copyright issue:)
I have share important section here, rest you can read from attached file...


Abstract

Malicious software is referred to spyware that affects privacy and confidentiality of individuals and corporations and poses security risks. In this research paper, we presented different types of spywares, their behavior, how spyware works and spread? This paper also discussed the potentials of spyware to damage the computers. This report also shows investigative results of an experiment we conducted; to know the infections and risks of spyware in a computer with and without antispyware. It also includes some recommendation to prevent the spyware.

1. Introduction

Spyware is any technology which helps organization to gather information about a person or an organization without their knowledge [1]. There are large numbers of synonyms of spyware including sneakware, stealthware, snoopware, trackware, thiefware, scumware [2], that have popped up in the past year or so. Spyware gathers sensitive data or secretly monitor user's activities, especially the typing of passwords, PINs and credit cards numbers, email addresses and sends to individual or company through user's internet connection (backchannel)

[2]. Spyware is a package which contains two separate software components that perform two types of functionality. One component performs core functionality for which user has installed the software and second component perform gathering of information functionality and act as spyware [3]. Today spyware has become a big security risk that is effecting and damaging computers very rapidly. It is a relatively new phenomenon, and according to users of Microsoft, it affects more than 50 percent of Windows operating systems failures [3]. Dell estimated that 90% of Windows PCs have at least one spyware program on the base of a survey conducted on September 2004 [4]. Spyware can perform different function like capturing information, displaying ads, dialing a number etc by one program, but usually different types of spywares perform different functions. There are various types of spywares and a lot of such programs exist throughout the internet today. Spyware does not spread automatically, but mostly users themselves open the door [4]. Spyware can get or install into the computer with free downloads like screensavers, accounting software, games, movies players, web browsers, peer to peer file sharing etc that are bundled with some spywares or through ActiveX controls that are hidden in the source code of websites or pop-up advertisements while you browse the websites. These bundled programs and ActiveX controls can open doors to install a wide range of spyware programs onto a user's computers [6]. Spyware are evolving very rapidly and effecting not only individual but also corporations. If spyware is installed on the client user workstations, can significantly impact on business confidentiality of stored information. Spyware can also impact on the users' privacy, connected to the internet or intranet both at home or corporate environment [7]. America Online and the National Cyber Security Alliance (AOL/NCSA) performed spyware scan on 329 customer's computer and reported that 80% were infected with spyware programs and each customer's computer contained average of 93 spyware components [8]. The spyware have severe impacts on Reliability, Annoyance, Privacy, Security and Performance of user computers.

The goals and objectives of this study were as follows:



· To explore and analyze behavior of different types of spywares

· Identify the risks of spywares to individuals and corporations

· To Explore the potential of spyware to effect or damage the computers

· Scanning Selected computers for spyware

· Compiling and analyzing scanning result.



4.0 How Spyware works?



Spyware effect or attack on computer from different levels [15][16]. The levels vary from low to high security risks

for individuals and corporations. The low security risk level is simple cookie, in which user’s website information

stores, such as user name and password through which user can access the website without entering password

again and again. This level has minimal risk. But it is a security risk and in some situation we cannot tolerate this

kind of risk The other level of security risks is more dangerous for individual and corporations. The second level of security risk is associated cookies that can track and capture important information from user’s computer. The third

level is application based. It has severe security risks e.g. it can gain the control of the system.

4.1 First level: Basic cookies

The first level of spyware or low level spyware is considered simple cookie identification for single and specific site. Different websites require storing user information to identify the user from specific computer, when the user uses the website in future. The cookie identification allows this. In most cases it is useful because user agree before storing information and sharing it with the site. However it is considered type of spyware with low level security risks. Because user identification information is stored in the cookie that would be abused

[15].

4.2 Second level: Associated cookies

Associated cookies are great security risks for individuals and corporation. These cookies are associated with member site to identify a single user every time when user connects to the site. The user’s activities are tracked in the result of user’s interaction with the each member site.

These stored data can be shared with advertising companies that form an agreement with the member site. The member site gives a reference of advertising site on their site that can be in the form of an image or pixel. These are actually reference to the spyware data server. These references cause to connect the spyware data server to the user’s computer. The spyware server then looks for the recognizable cookie. If server fails to find the cookie, server sends a cookie with Unique ID that is called Global Unique Identifier (GUID) to recognize the object every time when connect to the member site. Now the spyware data server can track and capture different kinds of user’s activities exchanged with the member site through GUID. It can capture username, password, credit card, keystroke, email or any other information stored in the associated cookie through member site. The advertising company can share this information without the permission of the users. The worst thing in this scenario is user unawareness from these activities performed by member and spyware sites. Advertising company can use this information for direct marketing or can sell to any concern companies. The major security risk is that if sensitive data about an individual or corporation is exposed, the advertising company has no obligation to inform the users. As the advertising company don’t show their intent to capture the sensitive data [15].

4.3 Third level: Application based

The third level application based spyware cause severe security exposures and risks to individual and corporation.

The application based spywares gain the full control of the system without allowing user to restrict their functionality. As the user starts the computer, spyware activates. Spyware can get all types of data and can send it to the other sources. This type of spyware have not only the characteristics of first and second level spywares but also have abilities to install new application, upgrade new version and generate new advertisement without the user’s permission. Anyone can buy application based spyware to spy on anyone, widely available on internet. Mostly intelligence agencies and hacker communities use application for their concerns [15].

 

 

 


Comment/Reply (w/o sign-up)

rpgsearcherz
This is a great document in terms of explaining what spyware is and how it works. I didn't read the whole thing as I already know most of it but for anyone who doesn't understand the whole concept behind spyware (I get asked often "what is spyware?" - a lot of people don't even know what is going on in their PC's) this is a great eye-opener.

Comment/Reply (w/o sign-up)



Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

This textarea will convert to Rich-Text automatically (IE, Firefox, Chrome)

Similar Topics

Keywords : Exploring Spyware Effects Security Risks Research

  1. Spyware / Virus Removal Help Needed - (11)
    Hey guys all of a sudden in the last two days my computer has just been attacked by all types of
    malicous software! and im not even kidding when almost instantly it went from running with out a
    hitch to so much slow down and so many pop ups i had to run avg. 648 virus and trojans! All deleted
    or moved to the vault, thought i was out of the woods than i ran adaware 202 Critical and malicous
    objects I deleted them then i ran adaware again got over a hundred bad things again after the
    restart and then ran adaware as well and after deleting over 1000 bad things I was still ...
  2. Wireless Network Security - (17)
    Hello Everyone, I am setting up a wireless network for my house, im finally getting rid of the
    dial-up (cost justified it). My cable line will be installed soon, and I am going to wireless
    network it so my two desktop PCs can share the Internet access. I've heard the mysterious
    security issues, but most of them seem pretty obvious that you have to be ignorant to overlook, like
    changing the admin password on your router, etc. Anyway, what I am getting at here is a question:
    do you have any tips for securing a wireless network? Thanks! ...
  3. Is Symantec Really The Best In Security ? - (8)
  4. [ Aef ] Security Update For Aef Forum Software - Highly recommended (1)
    For the benefit of any or all AEF Forum Software users, there has been a Security Issue found in the
    BBcode handling of the software. A Patch file is available and it is as simple as uploading a
    replacement file to overwrite an existing file in the Install. File download and further
    details are available here . The Update is highly recommended since the vulnerability is
    now public and no telling what mischief could result on your Forums. ...
  5. Port Checking Test - Shields Up from Gibson Research (1)
    Here ya go, a free security check that tests how accessible your computer is on the Internet. Highly
    recommended. Shields Up from Gibson Research Port Checker: https://www.grc.com/x/ne.dll?bh0bkyd2
    ...
  6. Cpanel Exploit - security hole in cPanel to hack the servers of a hosting company (8)
    A pair days ago I read this new on Slashdot: cPanel Exploit Used to Circulate IE Exploit
    QUOTE "In a dangerous combination of unpatched exploits, hackers have used a previously
    undiscovered security hole in cPanel to hack the servers of a hosting company and use hundreds of
    hijacked sites to infect Internet Explorer users with malware using the unpatched VML exploit.
    cPanel, whose hosting automation software is used by many large hosting companies, has issued a fix.
    It's a local exploit, meaning the attacker must control a cPanel account on the target hosti...
  7. White Paper: Security Threat Report: 2008 - (0)
    I saw this white paper and I thought I bring down some interesting information that has come from
    2007 and leading into 2008. I have to say though that the information on this white paper is pretty
    darn mind blowing as I bounce some facts to everyone. Of course since I been getting into this
    since last year it is not all that surprising since I posted many topics about it as well.
    -Sophos currently sees 6,000 new infected webpages each day -One infected page every 14 seconds
    -Only about 1 in 5 of these sites is a hacker site -83 percent are hacked sites, or legitima...
  8. Security Warning 2008: Top 11 Malware Threats To Watch Out For - (0)
    Before I go into this topic I have to say, stop making up these crazy names. I know I just getting
    into the security side of things but still as long as there are computer problems and ways to sucker
    someone into downloading the stuff, the crazy names will still live on. QUOTE Lieware
    ADVERTISEMENT In 2007, there was a lot of "rogue anti-virus software," which is sometimes also
    referred to as "fake anti-virus software." But these terms are confusing because there's too
    much negation going on. Fake anti-virus software is not anti-virus software at all. So what ...
  9. New Security Hole Discovered In Excel - (0)
    Well I have to same I am bit surprise on this security flaw especially what it can do; in which all
    a user has to do is open a malicious Excel document and it allows the hackers to execute remote code
    on to your system. As far as how wide spread this vulnerability is, it hits every excel software
    from Excel 2000 to Excel 2003 SP2, and it also includes the Mac Version of Excel 2004 as well. OF
    course with the disappointment of Office 2007 by some people will still be running the 2003 versions
    on their computers. Right now the attacks are minimal and the question for t ...
  10. Security Commom Sense - (0)
    A very good article titled "Security Common Sense" in gnucitizen.org Below is the link to that
    article http://www.gnucitizen.org/blog/security-common-sense Website Link
    http://www.gnucitizen.org "We basically train a bunch of monkeys to click the yes button for
    every security warning." Don't you think many of us fall under the category? because most of
    the time we do not see what the dialog says, but press Yes, which might not treat you well
    sometimes... A good read....
  11. Symantec's Top 10 Internet Security Trends Of 2007 - (3)
    Well I saw this article and after reading it all just to find the top 10 security problems I thought
    I share them and give my thoughts about them. I know I know its horrible but what can I say, its me
    /laugh.gif" style="vertical-align:middle" emoid=":lol:" border="0" alt="laugh.gif" />. 1.) Data
    Breaches For the most part I am not surprise especially the big stories of 2007 which include the
    TJ Max breach of 45 million credit/debit cards; I believe that has been the biggest hack job ever in
    terms of stolen cards and id theft (somewhat). Oh lets not forget the al...
  12. Linux Security Tools - (5)
    Hi, I've posted some security tools and links in my last posts,I preferd to post new topic and
    send he extra here : Network Sniffers # DSniff http://www.monkey.org/~dugsong/dsniff/ #
    Ethereal - full network protocol sniffer/analyzer http://www.ethereal.com/ # IPTraf - curses based
    IP LAN monitor http://iptraf.seul.org/ # TcpDump - network monitor and data acquisition
    http://www.tcpdump.org/ # KISMET - 802.11 wireless network detector, sniffer and intrusion
    detection system http://www.kismetwireless.net/ Online Tools # AutomatedScanning.com - commer...
  13. Sick Of Being Infected By Viruses, Spyware, Malware, Etc.? - How to keep your data safe from the nasties of the Interwebs (4)
    Viruses, spyware, malware, adware, and all that extraneous bull that we have to deal with nowadays
    are becoming more frequent. Obviously we don't want this crap on our computers so I advise you
    take precautions. * Avoid downloading anything from sites or people you don't know. Duh. *
    Don't even bother looking at attachments in spam. Duh. * If you receive an e-mail from someone
    you don't know, don't click on any of the links. Duh. * Anything other than a multimedia
    file or a text file is able to harbor extra crap you're not going to want. This ...
  14. Your Help Is Needed - dam virus or spyware damaged my pc help (6)
    Wup i just finished sweeping my pc with spysweeper, cause a spyware totally infected my pc, the
    damm thing disabled my wallaper, i could only change a color, plus damaged norton, change my home
    page, and installed a spysherrif program that was supposed to removed the spyware, of course you
    need to buy it, plus installed a thing that every3 minutes show me a message in the minitray(righ
    down corner), like if it was from windows, that tells me that my pc is infected. SpySweeper
    apparently removed all the thing, but i still cant change my wallpaper, someone please hellp ...
  15. Security Firm Kaspersky Lab Creates Ipod Virus - (1)
    With the flood of news coming about the .ani exploits it seems the tech world is recieve more news
    about new hacks, viruses and other bad stuff these days. Today Kaspersky Lab created a virus that
    is able to affect the Ipod, however, it is only affecting Ipod's that have linux installed and
    not the standard OS that comes with Ipod. The virus goes by the name of Podloso, although they say
    it doesn't show a current threat this virus does show the possiblity to install malware into
    devices such as the Ipod. They also mention that the virus does not copy it self...
  16. Security Guidelines For Internet Users - (6)
    Security Guidelines for Internet Users 1. Install an anti-virus software, you can free ones like
    AVG Free . Ensure that it's regularly updated - this is of the utmost importance. 2.
    Anti-virus software is not enough, the security can be tightened using a firewall software which
    will help you prevent unauthorized incoming and outgoing communications from your computer while
    connected to the Internet. 3. Disconnect your computer from the Internet when not in use. The
    longer you are connected to the Internet, the more opportunity you give for persons to gain un...
  17. Php Security Vulnerability - Beware From Spammers - If you notice your site becoming really slow, you may be a victim (1)
    QUOTE PHP Security If you are using PHP on your website we ask that you please read the
    following carefully. We have noticed a significant number of PHP websites are being compromised
    due to vulnerable PHP code. Spammers are scanning millions of websites on the Internet looking for
    PHP scripts that can be exploited to send spam. When they find a script that has a loophole they
    send thousands of email messages through the script, often taking down the website or severely
    impacting website performance. Generally these loopholes exploit code using paramet...
  18. Major Flaw In .ani File Found In Windows 98 Through Vista Creates Major Security Risk - Vista Aint that Secure at all (9)
    I was able to browse around this and found it interesting since this vunerability is found in 4
    Microsoft Operating Sytems, Windows 2000, Windows XP, Windows Vista, Windows 2003 Server. From the
    article Microsoft stated that their is a hole in the .ani files, which happen to be related tothe
    mouse cursor, when the mouse icon changes depending on what you do. They only mention that with
    this flaw it always hackers to break into someone computer and do their thing. But in another
    article relating to this attack it was mention that in order for this to happen a user has ...
  19. Brand New Security Holes Found And Patch On This Month Updates And Office Exploits - (0)
    Even though the fiasco with the .ANI exploit is still going strong microsoft released it's month
    updates this time they found 4 more critical breaches in it's systems (XP), most people should
    have gotten the update pop up screen yesterday. So here is the info on these critical flaws.
    http://go.microsoft.com/fwlink/?LinkId=84687 http://go.microsoft.com/fwlink/?LinkId=85130
    http://go.microsoft.com/fwlink/?LinkID=85163 http://go.microsoft.com/fwlink/?LinkID=85164
    http://go.microsoft.com/fwlink/?LinkId=80251 I don't know how reliable vista will be af...
  20. Trojan /spyware Protection---best---low Resource Util. - PROTECTION LOW RECURSES UTIL . (5)
    My eyes have been completely opened to all this spyware/Trojan junk... /ph34r.gif"
    style="vertical-align:middle" emoid=":ph34r:" border="0" alt="ph34r.gif" /> I'm behind a
    hardware firewall in my Router----running Windows firewall----using the very latest Nortons AV....
    I seem very secure against "viruses" /blink.gif" style="vertical-align:middle" emoid=":blink:"
    border="0" alt="blink.gif" /> But this spyware/trojan thing..... /tongue.gif"
    style="vertical-align:middle" emoid=":P" border="0" alt="tongue.gif" /> Oh my! /ohmy.gif"
    style="vertical-align...
  21. A Very Simple Security Tip - for Windows 2000/XP (13)
    We all know the difference between a limited user and an administrator user under Win2k/XP - you
    can't/can install major software, perform system maintainence, and other stuff. But using a
    limited user on a day-to-day basis also provides you with decent protection from a bunch of threats:
    if the malware is running under your limited-rights user, it can only do as much as you can. For
    instance, a limited rights user can't edit the HKLM hive of the Registry, so any malware running
    under the same user won't be able to touch that area. It's extremely simple t...
  22. Virus-spyware Protection An Detection - (3)
    Best Online Scanners: QUOTE HouseCall http://housecall.trendmicro.com/ Panda
    http://www.pandasoftware.com/activescan/ BitDefender Online
    http://www.bitdefender.com/scan8/ie.html eTrust Antivirus Scanner
    http://www3.ca.com/securityadvisor/virusinfo/scan.aspx Jotti.org single file scanner
    http://virusscan.jotti.org/ Online malware scan Utilizes 8 major Antivirus Scans to analyze
    individual files. AV "sandbox" component provides detailed analysis. Libraries and further
    information: Symantec http://securityresponse.symantec.co...er/vinfodb.html ...
  23. List Of Security Sites - (7)
    List of security sites, I'll try to update the list as soon as I can . with compilations of
    recent security threats, Global Incident Analysis Center (GIAC), GIAC training, and Reading Room
    http://www.sans.org/ http://www.infragard.net/ http://www.cert.org/security-improvement/
    CERT Security Improvement Modules,including general information on firewalls and intrusion
    detectors. excellent set of papers on firewalls, viruses, e-commerce, etc. http://www.icsa.net/
    http://www.gocsi.com/ (Source of the annual "CSI/FBI Computer Crime and Security Su...
  24. Security Not Safe - (2)
    Hi everyone!!!!!!! This is the last one!! /tongue.gif" style="vertical-align:middle" emoid=":P"
    border="0" alt="tongue.gif" /> Ok guys, I heard somewhere that if we protect some page with
    password, it is steel not safe at all, if we dont hace a secure connction (http s ://...) How is it
    true? is there a posibility that some one can see a page, even if it is protected by password? (the
    scrit in tha page don't allow IDs that didn't past from the login page) is that script
    sufficent? thanks a lot to every one /biggrin.gif" style="vertical-align:middle" e...
  25. Rootkits - the security threats that no one's heard of (2)
    a security threat to be concerned with is the increasing prevalence of viruses containing advanced
    rootkits to hide their actions or data on the computer. even from the anti-stuff tools. a
    rootkit was originally a name for tools that hackers/crackers would use to maintain root on
    unix/linux machines. root is the uber user with all the permissions on a linux box. on windows
    these tools can be used to hide data on the harddrive and in the registry by manipulating the way
    the data is stored. THe windows api(the thing windows uses to communicate to the hardware) read...
  26. Spyware On Surveys - (0)
    ezyreward.com really is bad. The surveys they want you to take to get prizes(like a free domain name
    from Optionom.com) got me a virus/spyware. Website: *******.net(I blocked the full website address
    so hackers won't use this website to give people viruses/spyware) Also..... There's a code
    online for VB(not VBScript) that makes a popup blocker. If you do VB, you could compile it for your
    own use. LINK: http://www.freevbcode.com/ShowCode.Asp?ID=3921 Download code(ZIP):
    http://www.freevbcode.com/source/NoPopUp.zip Hope you like it /smile.gif" style="vertica...
  27. Rootkits, And How To Detect Them - simple firewall or anti-spyware scanners are not enough (1)
    Firstly, here's a definately of a RootKit. QUOTE A set of software tools frequently used by
    a third party (usually an intruder) after gaining access to a computer system. These tools are
    intended to conceal running processes, files or system data, which helps an intruder maintain access
    to a system without the user's knowledge. Rootkits are known to exist for a variety of operating
    systems such as Linux, Solaris and versions of Microsoft Windows. Hence from this defination, we
    know that RootKit is not something you would want on your computer. RootKits w...
  28. Mcafee Finds Lots Of World Cup Related Spyware - "lama world cup screensaver" brings up 45.5% risky results (0)
    McAfee Finds Lots Of World Cup Related Spyware As the world cup season draws to an end,
    many of us may have downloaded ample amounts of World Cup merchandise from the internet to show our
    support for our home nation. Some of us may've downloded themes for our computer which probably
    consisted a few wallpapers or even screensavers. Nothing wrong with that? Security firm McAffee®
    says differently. It google searched, "world cup screensaver" followed by 736 popular footballers
    and recorded for each player how many dangerous sites came up when you typed tha...
  29. Light To Heavy Security Tips - Some (helpful?) Suggestions (4)
    (excessively long intro, skip to 'suggestions' for immediate tips) Its almost 2 am and I
    just finished an email detailing some ideas I had to keep systems a little more secure than usual (
    tips that can be applied to most any Windows users system ). I dont feel like re-editing it so it
    doesnt sound I copied and pasted it from my email, cause I did, and its late. Please note THIS IS
    NOT SPAM. I did write all of this, just in an email before I copied and pasted it here. These are
    entirely valid and ( I hope ) helpful tips for most anyone. Of course I hate just yap...
  30. Stopping Spam And Its Effects! - (0)
    Stopping SPAM and its effects ----------------------------------- SPAM or unsolicited mail usually
    comes to your mailbox from 'anonymous' sources. They are most frequently as a result of you
    giving out your address on a site. But your mail providers (usually) work very hard to stop these
    kind of messages from clogging your limited() space. There aer many things about that, but we
    won't get into those. The thing Yahoo is using right now is Yahoo's DomainKeys. Read more
    about the technical details here. Here's the effects of this system... 1) Most o...



Looking for Exploring, The, Spyware, Effects, And, Security, Risks
Spyware /
Virus
Removal Help
Needed
Wireless
Network
Security
Is Symantec
Really The
Best In
Security ?
[ Aef ]
Security
Update For
Aef Forum
Software
Highly
recommended
Port
Checking
Test Shields
Up from
Gibson
Research
Cpanel
Exploit
security
hole in
cPanel to
hack the
servers of a
hosting
company
White Paper:
Security
Threat
Report: 2008
Security
Warning
2008: Top 11
Malware
Threats To
Watch Out
For
New Security
Hole
Discovered
In Excel
Security
Commom Sense
Symantec'
;s Top 10
Internet
Security
Trends Of
2007
Linux
Security
Tools
Sick Of
Being
Infected By
Viruses,
Spyware,
Malware,
Etc.? How to
keep your
data safe
from the
nasties of
the
Interwebs
Your Help Is
Needed dam
virus or
spyware
damaged my
pc help
Security
Firm
Kaspersky
Lab Creates
Ipod Virus
Security
Guidelines
For Internet
Users
Php Security
Vulnerabilit
y - Beware
From
Spammers If
you notice
your site
becoming
really slow,
you may be a
victim
Major Flaw
In .ani File
Found In
Windows 98
Through
Vista
Creates
Major
Security
Risk Vista
Aint that
Secure at
all
Brand New
Security
Holes Found
And Patch On
This Month
Updates And
Office
Exploits
Trojan
/spyware
Protection--
-best---low
Resource
Util.
PROTECTION
LOW RECURSES
UTIL .
A Very
Simple
Security Tip
for Windows
2000/XP
Virus-spywar
e Protection
An Detection
List Of
Security
Sites
Security Not
Safe
Rootkits the
security
threats that
no one's
heard of
Spyware On
Surveys
Rootkits,
And How To
Detect Them
simple
firewall or
anti-spyware
scanners are
not enough
Mcafee Finds
Lots Of
World Cup
Related
Spyware
"lama
world cup
screensaver&
quot; brings
up 45.5%
risky
results
Light To
Heavy
Security
Tips Some
(helpful?)
Suggestions
Stopping
Spam And Its
Effects!

Searching Video's for Exploring, The, Spyware, Effects, And, Security, Risks
See Also,
advertisement


Exploring The Spyware Effects And Security Risks - I wrote this research paper thought should share with all

Affordable Web Hosting, Low cost Web Hosting - ComputingHost.com