Data Backup: How to Protect Your Business
Have you ever imagined if, because of a theft, a system failure, or even because you forgot to log out of your account on someone else's computer, somebody got into your account and started deleting all the content you produced? For blogs, that would be a headache. For companies and businesses, then, a disaster!
We often believe that the files we keep on our computers are safe from all the accidents that used to happen when information was stored in books. It's as if all the bits and code behind the machine automatically saved every change and every piece of information we produce as we fill the black screen in front of us. Unfortunately, but very unfortunately, that's not what happens. Just like printed paper, if you don't make a copy or try to shield your files from the possible calamities our computers are subject to, the file will be lost if something does happen.
The file, in the case of merchants, means information ranging from the inventory list to the personal information of their customers. Nesses casos, as repercussões não se limitam à perda de dados que facilitam a análise operacional e o planejamento financeiro e mercadológico; se outras pessoas não autorizadas tiverem informações sensíveis, tanto do comércio em questão quanto de seus clientes, não há limites para o que essa pessoa possa fazer. Em outras palavras, se isso acontecer não é apenas o planejamento do estabelecimento que estará comprometido, mas também a marca e o nome do mesmo, if their customers' information is leaked.
Beyond the theft of information – and possible identity fraud – there's also the concern about the installation of malware (read: viruses, Trojan horses, among other creations that wreck the computer) on the company's own site or blog. Malware is an English term, coined from the joining of the terms “Malicious” and “Software”. In other words, it's malicious software created for different purposes, from the theft of confidential information to granting control of the machine to the person who wrote the code in the first place. When malware invades the site of a corporate site, the headaches spread not only inside the company, but also to all the users who visit the site in question.
TYPES OF MALWARE
Since creativity is used for good purposes as much as for evil ones, there's no way to predict the new methods of digital intrusion that will emerge in the future. However, there's a vast encyclopedia of viruses and malware employed for these nefarious ends, discovered during the attacks in which they were used. We've gathered a few that are commonly used in this type of attack, so you understand what they can do to the corporate network when activated:
virus
O virus is considered a program that multiplies on the infected computer, causing slowdowns that, in the end, make the computer unusable. This type of malware acts the same way as ferns; they “mount” on top of existing programs, being activated the moment the program is opened. That way, they manage to hide inside programs already installed on the computer, turning the eradication of that program into a big game of Whack-a-Mole. No pior caso, o vírus pode chegar a corromper ou excluir dados do computador, ou até chegar a ter acesso à conta de e-mail cadastrado no computador infectado, podendo espalhar ou apagar todas as informações de um disco rígido.
Worms
These Worms (or “Earthworms”) are viruses similar to those described above, with the only difference being that they don't attach themselves to existing programs on the computer. The name was coined because of the virus's method of infection, which tends to spread through the computer or network by exploiting vulnerabilities in them. Normally, these programs are used to “numb” the computer, and are hard to detect until the replication reaches a proportion that makes connecting to and using the computer itself impossible. This is due to the fact that these programs consume system resources to spread and sustain themselves.
Trojan Horses
These Trojan Horses got this playful name from the way they infect the computer in question. Just like the legend of the battle of Troy, in which the Greeks devised a wooden horse to hide their best soldiers inside, and thus be able to invade the citadel under the pretext of having given up and left the horse as a gift, this virus gets into the computer through seemingly legitimate software, which users download voluntarily. In other words, in the same way that the King of Troy let the horse into his city – even against the efforts of his son and Trojan general, Hector -, the user himself, looking to save money by downloading a fake copy of a useful program, lets this virus into his system. Unlike the “Worms” and “virus”, the Trojan Horse does not replicate itself, but it can be programmed to carry out any kind of damage possible, even wiping the HD (Hard Drive) of the computer and deleting every file inside it.
Rootkits
These Rootkits can be understood through an etymological analysis of the word. “Root” means “root”, and “kit” can be loosely translated as “toolbox”. This way, the Rootkit can be understood as software that gives access to the computer's root code, creating a back door for its creator to have access to everything that exists on the infected HD (Hard Drive), if he so wishes. Beyond having access to all the information, this program also manages to hide itself and the processes and programs contained in it, making it go unnoticed by conventional detection methods.
Remote Access Trojan
Commonly known as RATs (“Remote Access Trojans”), these programs provide all the information needed to gain access to the root code of the infected computer. With them, wrongdoers can access and steal crucial information, both from the company and from the person in question. This malware is used to give manual access to the program's creator, allowing him to access the computer remotely, as if he were sitting in front of the CPU. In most sustained attacks on companies, these programs are used as a way to scout the system before the attack. With them, hackers can get past the most complex authentication barriers, spreading the infection to the point of gaining access to essential system programs as well as obtaining confidential data.
Botnets
These bots are malware that let the hacker have complete, remote control of the infected computer. It turns the machine into a zombie, carrying out predefined tasks automatically without the user's knowledge. A botnet, in turn, is a network of computers infected with these bots, commonly used for DDoS attacks (these attacks cause sites and servers to be overloaded through constant, recurring and mass access to websites). A botnet is made up of 20 infected computers, which – along with their respective connections – are used to attack institutions at every level. Normally, these programs are used to carry out attacks on banks, making their services unusable for a set amount of time until a solution is found.
Now that you understand the scope and variety of methods available for corporate intrusion – and there are plenty of them! -, you'll be able to protect yourself better. In any case, it's practically impossible to prevent attacks from happening, or to shield yourself 100% from them. However, even if privileged information is obtained by wrongdoers, it's possible to keep everything from going down the drain if they decide to delete it too. Run regular backups so you can keep making accurate analyses about your business. If you don't know how to make a backup, don't worry! Read the post: How to Choose the Right Backup for Your Data
