Section 3.18 Threat Actor Flashcards
Objectives 1.2 Summarise fundamental security concepts Objectives 2.1 Compare and contrast threat actors and motivations Objectives 2.2 Explain common threat vectors and attack surfaces (4 cards)
1
Q
Threat Actor
Section 3
A
An individual or entity responsible for causing harm, loss or damage to an organisation
2
Q
Threat Actor Intent
A
Specific objective or goal that a threat actor wants to achieve throught their attack
3
Q
Threat Actor Motivation
A
Underlying reason or driving forces that pushes a threat actor to carry out the attack
4
Q
10 motives
Threat Actor Motivations
A
- Data Exfiltration: unauthorised transfer of data from a computer
- Financial Gain: Ranswomware attacks or trying to gain access to bank accounts
- Blackmail: Attacker obtains sensitive information and threatens to release this information unless certain demands are met.
- Service Disruption: Conducting DDoS attack to flood networks which leaves people unable to access information.
- Philosophical or Political Beliefs: Hacktivism - use hacking to promote political agenda
- Ethical Reasons: Motivated to enhance security (PEN Tester) by exploiting organisations weaknesses subsequently enhancing them.
- Revenge: Powerful motivation - can be disgruntled employees or threat actors who feel they have been wronged
- Disruption or Chaos: Unauthorised hackers who just want to watch the world burn
- Espionage: Spying on individuals, organisations or nations to gather sensitive infotmation
- War: Cyber warfare can be used to disrupt a country’s infrastructure, compromise its national security, and to cause economic damage