Understanding Confidentiality Attacks

A confidentiality attack tries to capturehost. Port scans can also help gather more
confidential data (such as username, password,information about the target system such as
credit card numbers and data in emails) so anwhat operating system it's running.
attacker can use that data for malicious intent.Dumpster Diving: Many companies throw away
Confidentiality attacks often go undetectedconfidential data without properly shredding it. An
because the attacker makes a copy of the data,attacker can rummage through a company's trash
rather than trying to change the data or takein hopes of discovering data that could be used to
down the system. There are several differentcompromise network resources.
types or methods to a confidentiality attack:Wiretapping: If an attacker gains access to a
Packet Capture: A packet capture utility cannetwork wiring closet, they can then physically
capture data that is sent across the network ortap into a telephone line and eavesdrop on the
from a PC's NIC card. The packets can containconversation. They could also insert a hub inline
username and password, credit card numbers,with the network cable and receive copies of the
social security card numbers or anything that is indata.
plain text. An attacker can read this data from aSocial Engineering: Phone techniques can be used
packet capture utility and use it for maliciousto obtain information from end users. For
intent.example someone could pose as a member of
Ping sweep and port scan: Some attacks startthe IT department and ask for the end users
with a scan of the network to identify devices tologin information.
target on the network. A ping sweep will ping aElectromagnetic interfaces interception: Data is
range of IP addresses and wait for a reply. A pingoften transmitted over a wire, often called a
reply might indicate that there is a networknetwork cable. Attackers can copy data traveling
resource at those IP addresses. Once a collectionover the wire by intercepting the EMI being
of IP addresses is identified, a port scan can beemitted by the wire. The EMI emissions are
ran to see what services are available on thesometimes called emanations.