1. Using the web and other resources research the Conficker malware and Koobface malware.

Select one (1) of the pieces of malware and write a complete overview of each piece of malware. Describe what type of malware it is: (e.g. virus, worm, DoS, blended, botnet, or various other types). You need to explicitly identify and provide a description of the key attributes including: how the infection occurs, what triggers it and what the payload is.

Note that there are typically several different infections, payloads, triggers, defenses that need to be discussed. This is true for many examples of malware and not just Conficker and Koobface.

This information is readily available on the internet. Therefore the value you will add is to provide your information so that each of the attributes is clearly identified, labeled and described. A cut and paste of information without adding value will not be a good answer.Present your finding using the template provided below.

2. Describe what a social engineering attack is.

Provide 3 examples of social engineering attacks and describe how they could be used to undermine the security of your IT infrastructure.

How can social engineering attacks be defended against?

3. Assume you have a computing environment consisting of a mix of machines running three (3) Windows platforms with the following operating systems; XP, Vista and Windows 7. There are also machines running Linux and Apple iOS. Your environment runs a mix of email and various office applications (e.g. word processing, spreadsheet, slide presentation, database). There is regular use of internet sites both for business and some personal use. There are also laptops, mobile phones and tablets that connect wirelessly to your network.

The environment is spread across a wide geographic area. While it might be tempting to have a solution that uses one type of system, such as Windows 7 this is not a possibility given the problem statement. The heterogeneity of the platforms in the environment is typical of the complexity faced by many organizations today. The environment is as defined and you must deal with the stated variation and complexity.

What do you consider to be the major risks to your environment and why? Describe the risks and vulnerabilities involved in the above stated environment.

4. Explain what spyware is?

Provide an example of a specific piece of spyware. Explain the key attributes of it using the following template.

5. Provide a description of a malware attack that affected your home or work assets. If you have never experienced a malware attack find someone that has and conduct an interview with them to answer the questions.

Identify the type of malware it is and the attributes of the attack.

Describe the damage the malware caused and how the attack was responded to.

What could have been done to prevent this attack?Why weren't these steps taken initially?

