Skip to content

Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Network Basics and Security

Cyber Threats and Network Attacks: Types and Differences

Updated 11 October 2026 · Fact-checked

Cyber threats are events or actors that can harm the confidentiality, integrity or availability of a network or its data. Network attacks include malware, phishing, DoS/DDoS, man-in-the-middle, spoofing and ransomware. To answer a question, define the attack, explain how it works, name the security goal it hits, and give a control.

Understand Cyber Threats and Network Attacks

Every cyber attack targets one or more of three goals, called the CIA triad: confidentiality (only authorised people see data), integrity (data is not altered without permission) and availability (systems work when needed). If you link each attack to the goal it breaks, you can explain any attack in an exam.

Malware is malicious software. A virus attaches itself to a file or program and spreads when a user runs that file. A worm spreads by itself across a network without needing a host file or user action. A trojan pretends to be useful software but carries a harmful payload; it does not self-replicate. Ransomware encrypts your files and demands payment for the key. Spyware secretly collects information. Ransomware mainly hits availability; spyware hits confidentiality.

Phishing is social engineering. The attacker sends a fake email, SMS or website that looks genuine, to trick you into giving passwords, OTPs or card details. It attacks the person, not the technology. Spoofing means faking an identity: an email sender address, an IP address, a caller ID or a website. Phishing often uses spoofing, but spoofing is the wider idea.

A Denial of Service (DoS) attack floods a server or network with requests so genuine users cannot get service. It comes from one source. A Distributed DoS (DDoS) uses many compromised devices, called a botnet, so it is harder to block. Both hit availability.

A man-in-the-middle (MITM) attack puts the attacker secretly between two parties. The attacker can read or alter the messages. Unsecured public Wi-Fi is a common setting. It hits confidentiality and integrity. Encryption such as HTTPS/TLS is the main defence.

Key rules to remember

CIA triad
Confidentiality + Integrity + Availability
Map each attack to the goal it breaks. DoS/DDoS: availability. MITM: confidentiality and integrity. Ransomware: mainly availability.
DoS vs DDoS
DoS = one source; DDoS = many sources (botnet)
Same aim: make a service unavailable. The difference is the number of attacking sources.
Virus vs worm vs trojan
Virus = needs host file; Worm = self-spreads; Trojan = disguised, no self-replication
This is the usual three-way comparison asked in exams.
Phishing vs spoofing
Phishing = tricking a person; Spoofing = faking an identity
Phishing commonly uses spoofing, but not all spoofing is phishing.

How to solve Cyber Threats and Network Attacks questions

Use this method for any question on cyber threats or network attacks, whether it asks you to define, differentiate or analyse a scenario.

  1. 1Read the question and note the verb: define, differentiate, identify or advise.
  2. 2Define the attack in one plain sentence.
  3. 3Explain how it works in two or three points.
  4. 4Name the security goal it affects (confidentiality, integrity, availability).
  5. 5For a scenario, match the facts to the attack: who is tricked, what is flooded, what is encrypted, who sits between.
  6. 6Give two or three preventive controls, such as updates, firewalls, encryption, backups and awareness training.
  7. 7Close with a one-line conclusion tied to the facts, and mention reporting to CERT-In or the police where an incident occurs.

Quickest way: Clue-word matching

When to use it: Use it for short scenario questions where you must name the attack fast.

  1. Fake email, link or OTP request: phishing.
  2. Server overloaded by traffic: DoS; if many devices are involved, DDoS.
  3. Files locked and money demanded: ransomware.
  4. Attacker secretly reads or alters messages between two parties: man-in-the-middle.
  5. Fake sender, IP or website identity: spoofing.
  6. Self-spreading across the network: worm; hidden in a useful-looking program: trojan.
  7. Add the CIA goal and one control to finish.

Common mistakes in Cyber Threats and Network Attacks

  • Saying a DDoS attack is just a bigger DoS attack.

    Students focus on volume rather than the source.

    Fix: State that DoS comes from one source and DDoS from many distributed devices, usually a botnet.

  • Calling every malware a virus.

    Virus is the most familiar word.

    Fix: Use virus only for code that needs a host file. Use worm, trojan, ransomware and spyware for the others.

  • Treating phishing and spoofing as the same thing.

    Phishing emails use spoofed sender addresses.

    Fix: Phishing is the deceptive act aimed at a person. Spoofing is the faking of an identity. Say so explicitly.

  • Saying a trojan replicates itself.

    Confusion with worms.

    Fix: A trojan relies on the user installing it. It does not self-replicate.

  • Listing attacks without effects or controls.

    Memorised definitions are written as a list.

    Fix: For each attack add the CIA goal affected and at least one control.

  • Ignoring the facts in a scenario question.

    Students write general theory.

    Fix: Quote the facts, match them to the attack, then advise.

Worked examples

Example 1

Differentiate between a DoS attack and a DDoS attack. (Short answer)

Show the solution
  1. Aim: both try to make a server, website or network unavailable to genuine users by overwhelming it.
  2. Source: a DoS attack is launched from a single machine or connection. A DDoS attack is launched from many machines at once.
  3. Method: DDoS usually uses a botnet, a group of infected devices controlled by the attacker, often without the owners' knowledge.
  4. Defence: a single-source DoS can often be stopped by blocking one address. DDoS is harder because traffic comes from many addresses that look genuine.
  5. Security goal: both affect availability.
  6. Controls: traffic filtering, rate limiting, firewalls, load balancing and DDoS protection services.

Answer: DoS comes from one source and DDoS from many distributed sources (a botnet). Both attack availability, but DDoS is harder to block.

Example 2

An employee of an Indian company receives an email that appears to come from the company's bank, asking her to click a link and enter her net-banking password. She does so. Later, unauthorised transfers occur. Identify the attack and advise the company.

Show the solution
  1. Identify: the email is a deceptive message asking for credentials. This is phishing.
  2. The sender address and website were made to look like the bank's. This involves spoofing.
  3. Goal affected: confidentiality, because the password was disclosed. Money loss also affects the company's finances.
  4. Immediate action: inform the bank, block the account and change passwords.
  5. Report the incident to the police cyber cell and to CERT-In, and preserve the email and logs as evidence.
  6. Preventive controls: staff awareness training, multi-factor authentication, email filtering, and a rule never to enter credentials through email links.

Answer: This is phishing using spoofing, breaching confidentiality. The company should contain the loss, report the incident, preserve evidence and strengthen awareness and authentication controls.

Exam tips

  • Differentiation questions (DoS vs DDoS, virus vs worm) are common. Answer in two columns of points, or as parallel sentences, with 3 to 4 distinguishing points.
  • Always link an attack to the CIA triad. It shows understanding and earns marks beyond definitions.
  • In scenario questions, write: identify the attack, apply the facts, state the control, then conclude.
  • Use plain examples with Indian context, such as a bank phishing email or a fake UPI link.
  • Cross-check the threat list with the IT Act offences topics so you can name the legal consequence when asked.

Practice questions from Network Basics and Security

Cyber Threats and Network Attacks: frequently asked questions

What is the difference between DoS and DDoS?

A DoS attack comes from one source, while a DDoS attack comes from many devices, usually a botnet. Both aim to make a service unavailable. DDoS is harder to stop because the traffic is spread over many addresses.

What is the difference between a virus, a worm and a trojan?

A virus attaches to a host file and spreads when the file is run. A worm spreads on its own across networks. A trojan disguises itself as useful software and does not replicate by itself.

How are phishing and spoofing different?

Phishing tricks a person into giving sensitive information. Spoofing means faking an identity such as an email address, IP address or website. Phishing often uses spoofing.

What is a man-in-the-middle attack?

It is an attack where someone secretly positions themselves between two communicating parties to read or alter messages. Using HTTPS/TLS encryption and avoiding unsecured public Wi-Fi reduces the risk.