The attackers use a whole range of different methods, some of which have been
included, by way of example, in the following list:
• denial of service attacks using privately owned hacked computers
• use of spyware
• interception or manipulation of data transfers
• taking advantage of weaknesses, or using malware, such as computer viruses
and worms.
The fact that the majority of PCs use standard software, from internet applications
to complex administration systems, makes it easy for attackers to find vulnerabilities.
Automated attacks that make use of security gaps in these programmes cause
enormous damage in many systems at exactly the same time, before a response
is possible or vulnerabilities could be patched.
In the meantime, organized criminals have shifted their attention away from
single PCs towards routers, firewalls and other security applications intended to
protect the IT systems of businesses and public administrations. This new type of
attack affects not only individual PCs, but possibly thousands of PCs in the attached
network. In the worst-case scenario, manipulation of central IT systems may cause
the entire information infrastructure to collapse, resulting in significant economic
damage.
Page 4