Security of Programs and Malware Types
In today’s digital landscape, protecting software from malicious threats is a critical skill for any cybersecurity professional. This course explores the fundamental concepts behind common…

A boot sector virus primarily infects which component of a computer system?
Which property distinguishes a polymorphic virus from a metamorphic virus?
In the context of malware, what is a 'bombe logique'?
Which of the following attacks exploits a flaw in input validation to execute arbitrary SQL commands?
A 'salami attack' is most likely to succeed against which type of software flaw?
Which statement correctly describes the role of a backdoor (porte arrière) in software development?
During a buffer overflow attack, what typically happens when the input exceeds the allocated buffer size?
Which of the following best explains why a 'stealth' (furtive) virus attempts to hide in a damaged sector?
A ransomware that encrypts files and demands payment in Bitcoin primarily exploits which security principle?
Understanding Program Security and Malware Types
In today’s digital landscape, protecting software from malicious threats is a critical skill for any cybersecurity professional. This course explores the fundamental concepts behind common malware families, their propagation mechanisms, and the vulnerabilities they exploit. By the end of this module, you will be able to differentiate between worms, viruses, polymorphic and metamorphic threats, and understand how attacks such as SQL injection, buffer overflows, and salami attacks operate.
1. Worms vs. Viruses: How They Spread
A frequent source of confusion is the distinction between worms and viruses. Both are self‑replicating, but their propagation strategies differ markedly.
- Worms replicate autonomously without needing to attach to a host program. They typically spread through network traffic, exploiting open ports or vulnerable services.
- Viruses require a host program to attach to. They rely on user actions—such as opening an infected file—to propagate.
Understanding this difference helps security analysts prioritize network monitoring (for worms) versus endpoint hygiene (for viruses).
2. Boot Sector and Master Boot Record (MBR) Infections
One of the oldest and most persistent malware vectors targets the boot sector of a storage device. A boot sector virus specifically infects the Master Boot Record (MBR), which contains the bootstrap loader executed by the BIOS during system start‑up.
- The MBR is executed before the operating system loads, giving the virus early control over the system.
- Because the MBR resides outside the file system, traditional antivirus scans that focus on user‑level files often miss these infections.
Mitigation strategies include using secure boot, regularly updating firmware, and employing specialized boot‑sector scanners.
3. Polymorphic vs. Metamorphic Viruses
Advanced malware strives to evade detection. Two sophisticated techniques are polymorphism and metamorphism:
- Polymorphic viruses encrypt their payload with a new encryption key for each infection. The decryption routine changes, but the underlying code remains the same.
- Metamorphic viruses go a step further: they rewrite their own code on each replication, producing a functionally identical but syntactically different version.
Because metamorphic viruses alter their structure, signature‑based detection becomes far less effective, prompting the need for behavior‑based and heuristic analysis.
4. Logical Bombs (Bombe Logique)
A logical bomb—sometimes called a "bombe logique" in French—is a piece of code that remains dormant until a specific condition is met. Unlike ransomware, which encrypts files, a logical bomb typically triggers a payload when a particular program is executed or a date is reached.
- Example triggers include the launch of a privileged application, a specific user login, or a predefined calendar date.
- Once activated, the bomb may delete files, corrupt data, or open a backdoor for further exploitation.
Detecting logical bombs requires code review and monitoring for unusual conditional statements within applications.
5. Exploiting Input Validation: SQL Injection
Among the most common web‑application attacks is SQL injection. This technique exploits insufficient input validation, allowing an attacker to inject arbitrary SQL commands into a query.
- Attackers can retrieve, modify, or delete database records, potentially exposing sensitive data.
- Mitigation involves using prepared statements, parameterized queries, and rigorous input sanitization.
Understanding the mechanics of SQL injection is essential for developers and security testers alike.
6. Salami Attacks: Small Fractions, Big Impact
A salami attack manipulates a software flaw that mishandles tiny monetary amounts. By repeatedly rounding down or ignoring fractions of a cent, an attacker can accumulate significant profit over time.
- Typical targets are financial applications that calculate interest, fees, or commissions.
- Preventing salami attacks requires precise arithmetic handling, such as using integer representations of currency (e.g., cents) and avoiding floating‑point rounding errors.
This subtle vulnerability underscores the importance of thorough testing in financial software.
7. Backdoors (Portes Arrière) in Software Development
A backdoor—or "porte arrière"—is an undocumented entry point intentionally added to a program, often for testing or debugging. While useful during development, leaving a backdoor in production creates a serious security risk.
- Backdoors bypass normal authentication mechanisms, granting unauthorized access.
- Best practice: remove all backdoors before release and conduct code reviews to ensure none remain.
Regulatory frameworks such as ISO/IEC 27001 explicitly require the elimination of undocumented access points.
8. Buffer Overflow Attacks
When input data exceeds the size of an allocated buffer, the excess bytes overwrite adjacent memory locations. This phenomenon, known as a buffer overflow, can alter program flow by overwriting return addresses or function pointers.
- The overwritten memory may redirect execution to malicious shellcode, granting the attacker control over the system.
- Mitigation techniques include stack canaries, address space layout randomization (ASLR), and bounds‑checking functions.
Understanding the mechanics of buffer overflows is foundational for both defensive coding and penetration testing.
9. Summary of Key Concepts
Below is a concise recap of the major topics covered:
- Worm vs. Virus: Autonomous replication vs. host‑program attachment.
- Boot Sector Virus: Infects the MBR, executing before the OS.
- Polymorphic vs. Metamorphic: Encryption key changes vs. code rewriting.
- Logical Bomb: Triggered payload based on specific conditions.
- SQL Injection: Exploits input validation to run arbitrary SQL.
- Salami Attack: Accumulates profit through tiny rounding errors.
- Backdoor: Undocumented entry that must be removed before production.
- Buffer Overflow: Overwrites adjacent memory, potentially hijacking execution flow.
10. Further Reading and Resources
To deepen your knowledge, explore the following reputable sources:
- Common Weakness Enumeration (CWE) – Detailed descriptions of software vulnerabilities.
- OWASP Top Ten – Essential guide to web application security risks.
- NIST Cybersecurity Framework – Best practices for risk management.
By mastering these concepts, you will be better equipped to design resilient software, detect malicious activity, and implement robust defenses against a wide range of cyber threats.
