☰ Contents · Computing

Computer viruses and protection

Lessons 33 · 1 lessons · N. I. Taylaqov (general editor), A. B. Akhmedov, M. D. Pardayeva, A. A. Abdug‘aniyev, U. M. Mirsanov. Informatics and Information Technologies, Grade 11, 1st edition. “Extremum-press”, Tashkent, 2018
33

Computer viruses and ways of protection

Textbook: pp. 118–123
GoalTells apart the kinds of malware (virus, worm, trojan, ransomware, spyware), lists the ways it spreads and the signs of infection, explains how antivirus works and protects a device against viruses.
New words
malware: any program made to harm a device or steal or damage data · zararli dasturtrojan: a harmful program disguised as a useful one · troyanransomware: malware that locks or encrypts files and demands money to restore them · fidya dasturichecksum (hash): a short value calculated from a file; if the file changes, the value changes · nazorat yig‘indisi (xesh)
Explanation

A computer virus is a harmful program that copies itself and spreads into other files. The general name is malware. Kinds: a virus attaches to files to spread; a worm spreads by itself through a network without attaching to a file; a trojan enters disguised as a useful program and steals data or takes control; spyware watches your passwords, messages and actions; ransomware encrypts files and demands money to open them; adware shows unwanted advertisements. History: in 1949–1951 John von Neumann developed the theory of self-reproducing machines; in 1971 the experimental program “Creeper” appeared on a network; in 1982 “Elk Cloner” for the Apple II became the first widespread personal computer virus; in 1986 the “Brain” virus appeared for the IBM PC. Ways of spreading: e-mail attachments and links, an infected flash drive, fake or “cracked” programs, suspicious sites, untrustworthy mobile apps, unprotected Wi-Fi and networks. Signs of infection: unexpected messages, windows and ads; the computer slowing down or freezing; unknown programs starting; files disappearing or changing extension; the antivirus switching off; strange activity in accounts. Antivirus methods: searching by signature (the “signature” of known viruses is in a database); heuristic analysis (a suspicious structure); behaviour monitoring (watching what a program does); an integrity checker (auditor) stores the checksums of files in advance and detects changes. The “detector, doctor, auditor, filter” division in older textbooks is now combined in one product. Protection rules: (1) keep the operating system and programs updated; (2) use a trusted antivirus (the Microsoft Defender built into Windows gives a good base too) and let its database update automatically; (3) download programs only from the official site or official store and avoid unlicensed “cracked” programs; (4) do not open unknown attachments and links; (5) scan a flash drive first and switch off autorun; (6) back up important files – the best defence against ransomware; (7) do not give apps unnecessary permissions. If infected: disconnect from the network, run a full scan, change passwords from another clean device, do not pay the ransom and contact an adult or an expert. Ethics: writing and spreading viruses is a crime; studying malware is done only under a teacher's supervision in an isolated environment.

Worked examples
A checksum (Python, tested): import hashlib ⏎ a = hashlib.sha256("salom".encode()).hexdigest()[:16] ⏎ b = hashlib.sha256("Salom".encode()).hexdigest()[:16] ⏎ print(a) ⏎ print(b) ⏎ print(a == b) The program prints 038f270ca678c66f, 441f71d48aacacdc and False: “salom” and “Salom” differ by one letter but their SHA-256 hashes are completely different. This is how an auditor works: it stores the hash of a file beforehand and compares it later; if they differ, the file has changed.
How a worm spreads: at first there is 1 infected computer; if every hour each infected one infects one more, the number doubles every hour: after 10 hours it is 2·2·2·2·2·2·2·2·2·2 = 1024. This is why quick isolation matters.
Class activity

“Path of a virus”: draw an invented infection event (for example through a flash drive) step by step: where it came in, how it spread, which signs appeared and which protective measures would have stopped it. Do not download or try a real virus.

Practice
1
Write the main difference between a virus and a worm.
2
How many computers are infected after 8 hours (1 at the start, doubling every hour)?
3
What is the most reliable defence against ransomware and why?
4
If you notice your computer is infected, write the first three actions.