CYBER CRIME & CYBER SECURITY TRENDS IN AFRICA 31 ATTACK ANALYSIS Attackers use various exploits to gain unauthorized access to a computer or an organization’s network. Motivations for these attacks can range from gaining financial profit, stealing sensitive information, disabling a network, establishing a C&C server, or using the system as a launching point for future attacks. Attacks can be active such as a brute-force attack that determines a user’s password, or passive such as a web-based attack that waits for a user to visit a malicious webpage in an attempt to infect the user’s computer with malicious code. Top Attacks Originating from Africa During the reporting period, there were 1,230,038 attack incidents over 363 different attack signatures originating from Africa. This accounted for less than 1% of the global attacks and as such, Africa was not a significant source of attacks globally. During the reporting period, the top attack originating in Africa was the Anonymous open proxy activity detected event with 463,762 incidents, accounting for 38% of the total Africa attacks (see Table 8 and Figure 9). The Anonymous open proxy activity detected event indicates access to an open proxy has been detected. This may allow a user to bypass firewall rules which block access to certain internet content which has been deemed to violate corporate policy. Open proxies are also widely used in repressed countries which the government restricts internet content to its citizens. Table 8. Top 10 Attacks Originating from Africa—2016 ATTACK RANK PERCENTAGE WITHIN AFRICA GLOBAL RANK GLOBAL PERCENTAGE Anonymous open proxy activity detected 1 38% 13 6% Bash CGI Environment Variable CVE-20146271 Attack 2 22% 13 6% Generic SSH Brute Force Attack 3 6% 17 2% Fake Scan Webpage 4 5% 12 5% Microsoft Windows LSASS Buffer Overrun Attack 5 4% 34 1% DNS Amplification Attack 6 2% 30 1% OpenSSL TLS 'heartbeat' Extension Information Disclosure 7 2% 23 1% Generic Wordpress Multiple Security Vulnerabilities 8 2% 23 1% Wordpress Arbitrary File Download 9 1% 13 2% Unix/Linux HTTP Server Security Bypass 10 1% 33 1%

Select target paragraph3