Question

In: Computer Science

I. Malicious software can be classified by propagation method or payload. Explain the difference between the...

I. Malicious software can be classified by propagation method or payload. Explain the difference between the three common propagation methods: worm, virus and social engineering;

II. Explain the difference between a normal virus, a metamorphic virus and a polymorphic virus, including discussing how easy they are to detect by anti-virus software

Solutions

Expert Solution

The three common propagation methods are explained below:

  • Virus: In this type of propagation, the malware takes the form of virus which infects other executable/interpreted files by inserting/attaching its code/content into them. This propagation method requires the host file to be transmitted to other systems.
  • Worm: In this type of propagation, the malware takes the form of self-replicating worm which spreads to different systems on network on its own by exploiting software vulnerabilities.
  • Social Engineering: This propagation method requires tricking the users of system to bypass the security mechanisms to download/install the malware. The malware usually is hidden under the guise of some useful software, application or tool.

The three forms of virus are:

  • Normal Virus: A normal virus is a malware which infects other executable/interpreted files on the system by inserting/attaching its code/content to them. As the host file transmits to different systems on network, the virus also spreads infecting more files. A normal virus can be easily detected by a good antivirus software due to its consistent and known signature.
  • Polymorphic virus: This is a type of virus which changes its "appearance" as it propagates. This makes them harder to be detected than normal virus as its signature is not consistent.
  • The virus is able to change its appearance by encrupting its content using variable key encryption.
  • Metamorphic Virus: This is a type of virus which can edit and rewrite its own code, changing its structure as it propagates. Unlike Polymorphic virus, they don't just change the appearance by encryption and don't require variable encryption key. They are considered more advanced than polymorphic virus and are even more harder to detect as their whole code structure changes frequently.

Hope this is helpful please please kindly upvote if helpful it helps me alot please

please kindly dont downvote

THANK YOU IN ADVANCE


Related Solutions

Malicious software can be classified by propagation method or payload. Explain the difference between the three...
Malicious software can be classified by propagation method or payload. Explain the difference between the three common propagation methods: worm, virus and social engineering; Explain the difference between a normal virus, a metamorphic virus and a polymorphic virus, including discussing how easy they are to detect by anti-virus software
what is the difference between reverse_tcp and a reverse_ord_tcp payload?
what is the difference between reverse_tcp and a reverse_ord_tcp payload?
How can I explain the difference between quantitative and qualitative methods?
How can I explain the difference between quantitative and qualitative methods?
How can I explain difference between social inequality and social stratification?
How can I explain difference between social inequality and social stratification?
Explain the difference between the CPU and I/O cycles that make up a program. Can a...
Explain the difference between the CPU and I/O cycles that make up a program. Can a process run during an I/O cycle? Explain how the Process Control Block (PCB) is used to manage a process within the system.
Explain the difference between the cost method, the equity method, and the fair value method. Provide...
Explain the difference between the cost method, the equity method, and the fair value method. Provide examples to support your explanations.
Discuss the difference between quantitative data (discrete and continuous which can also be classified in terms...
Discuss the difference between quantitative data (discrete and continuous which can also be classified in terms of scale (i.e. the level of the scale) as interval or ratio scale) and qualitative data (nominal or ordinal). Examples can help!
Chapter – Cash Flows Explain the difference between the Direct Method and the Indirect Method. What...
Chapter – Cash Flows Explain the difference between the Direct Method and the Indirect Method. What is the concept of Free Cash Flow? How would an entry showing a loss on the sale of a piece of equipment be shown on the Cash Flow Statement? Show the entry below any explanation.
What is the difference between software copyrights and software patent ? NO plagiarism please.
What is the difference between software copyrights and software patent ? NO plagiarism please.
Can someone explain to me the difference between atomic mass, mass number, and atomic weight. I...
Can someone explain to me the difference between atomic mass, mass number, and atomic weight. I have 4 different textbooks saying different things and I am so confused. Is atomic mass and mass number the same thing? Or is atomic mass and atomic weight the same thing? Or are all three terms different things with different meanings? Can someone please clarify in simple terms the meaning of these three terms and give an example for each, thanks so much! I...
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT