📁 Topic 5 · 5.2 Cyber Security
5.2a Cyber security threats
Edexcel 4CP0 · iGCSE Computer Science · ~12 min read
Notes

Malware

Malware (malicious software) is software designed to damage, disrupt, or gain unauthorised access to a computer system. Types include:

TypeHow it worksEffect
VirusAttaches to legitimate files; spreads when files are sharedCorrupts/deletes data, damages system files
WormSelf-replicates and spreads across networks without user actionSlows network/system, installs other malware
TrojanDisguised as legitimate softwareCreates backdoors for hackers, steals data
RansomwareEncrypts victim's filesDemands payment (ransom) for decryption key
SpywareRuns secretly in backgroundMonitors activity, steals passwords/data
AdwareDisplays unwanted advertsAnnoyance; may slow system; can track browsing

Social Engineering

Social engineering manipulates people rather than exploiting technical weaknesses. Common attacks:

Phishing

Fraudulent emails, messages, or websites that appear legitimate to trick users into revealing passwords, bank details, or personal information. Variants include:

  • Spear phishing — targeted at a specific individual or organisation
  • Smishing — phishing via SMS text messages
  • Vishing — phishing via voice calls

Pretexting

Creating a fabricated scenario (pretext) to gain someone's trust and extract sensitive information — e.g. pretending to be IT support.

Denial of Service (DoS) and DDoS Attacks

A DoS (Denial of Service) attack floods a server with so many requests that it cannot respond to legitimate users, effectively taking it offline.

A DDoS (Distributed Denial of Service) attack uses thousands of compromised computers (a botnet) to launch the attack simultaneously, making it much harder to block.

Man-in-the-Middle (MitM) Attacks

An attacker secretly intercepts and potentially alters communication between two parties who believe they are communicating directly with each other. Common on unsecured public Wi-Fi.

SQL Injection

Attackers insert malicious SQL code into a web form or URL to manipulate a database — potentially reading, modifying, or deleting data, or bypassing login authentication.

Brute Force Attacks

Systematically trying every possible combination of characters until the correct password is found. Automated tools can try millions of combinations per second — making short, simple passwords very vulnerable.

Further Attack Methods

Shoulder Surfing

Directly observing someone's screen or keyboard to obtain passwords, PINs, or other sensitive information — e.g. watching someone type their PIN at an ATM or looking over their shoulder in a café.

Pharming

Redirecting a user to a fake website without their knowledge, even when they type the correct web address. Achieved by poisoning DNS records or modifying the device's hosts file. Unlike phishing, the user does not need to click a fraudulent link.

USB Baiting (Physical Attacks)

Leaving infected USB drives in public places (e.g. car parks, offices) hoping that a curious person will plug one in. When connected, malware installs automatically. Also called a "baiting" attack.

Exploiting Unpatched Software

Attackers actively search for known vulnerabilities in software that has not been updated. Once a vulnerability is public knowledge, systems that have not applied the patch become easy targets. This is why regular software updates and patch management are critical.

📝 Exam Tip: Know the difference between technical attacks (malware, SQL injection, brute force, DoS) and social engineering attacks (phishing, pretexting). A question may describe a scenario and ask you to identify which type of attack it represents — focus on whether it exploits software/technical weaknesses or manipulates people.
⚠️ Common Mistakes
  • Saying a virus and a worm are the same — a virus needs a host file and human action to spread; a worm spreads automatically without human intervention
  • Confusing phishing with hacking — phishing uses deception to trick users; it does not directly exploit technical vulnerabilities
  • Saying DoS attacks "delete data" — a DoS attack overwhelms a server to make it unavailable; it does not typically delete data
← 5.1d Protocols Topic 5 · 5.2 Cyber Security Next: 5.2b Preventing cyber threats →
🔒
Pro Content
Subscribe to access all 47 Edexcel iGCSE lessons.
£7.99/month
or £59/year