NATIONAL CYBER SECURITY STRATEGY GREEN PAPER – SUPPORTING DOCUMENT
Malicious code
Over 50% of malware is undetected by antivirus solutions due to its dynamics, complexity,
sophistication and stealthiness. Malware detections are also noted to be predominant in open
environments, mainly academia and education (at 40%), where access to a variety of users, who do
not necessarily maintain robust end-point security, is high.
Web-based attacks
The threat is especially predominant in web browsers and is potentially enabled by malicious URLs.
Web application attacks/ Injection attacks
The threat consists mainly of feeding vulnerable servers and/or mobile applications with malicious
inputs or unexpected sequence of events so as to alter site content, breach information or inject
malicious code. Cloud computing as well as mobile applications and unsupported Web software are
seen as most likely victims of such a threat.
Botnet
A serious cyber threat, accounting for 34% of attacks and ranking first in attack statistics. Although
the number of botnet-infected computers has decreased from 3.5 million to 2.3 million during 2014,
mainly due to successful law enforcement activity, its decline cannot be taken for granted due to a
noted increase in sophistication and stealthiness in the technology.
Denial of Service (DDoS) attacks
A threat that is evolving in sophistication, stealthiness and unpredictability. In most cases, DDOS
attacks are noted to be launched in combination with other attacks as a means of distraction. The
main objectives of collateral attacks assessed are: virus and malware installation/activation, data
theft, loss of intellectual propertyand financial theft.
Spam
Although it has decreased due to succesful spam blocking practices and take downs of large spam
bots, it is still considered as serious mainly due to often succesful attempts by spammers to create
user confidence in their messages through social media and mobile devices.
12
Malta | National Cyber Security Strategy Green Paper – Supporting Document