Malware spreading in a network – testing cyber defences

Computer ScienceDigital Safety & EthicsAges 15–16

Loading…

Share Report a problem

A school computer network has several rooms and a file server. Malware gets in through e-mail attachments, USB sticks or unpatched vulnerabilities and then spreads from computer to computer. Switch software updates, antivirus, firewall, user training and backups on or off to watch infections and data loss day by day, try a ransomware scenario and compare defence strategies.

Lesson: Online safety: malware and how to defend against it

What it shows

Malware enters a network through three common doors: an e-mail attachment someone opens, an infected USB stick, or an attack from the Internet on an unpatched vulnerability. Inside, a worm copies itself to every computer that still has the hole, quickly within a room and more slowly between rooms. Ransomware hides for two days, then encrypts files on the machine and on the shared server. Updates close the holes, training and antivirus stop many infections, a firewall blocks outside attacks, and only separate backups bring encrypted files back. The probabilities are illustrative assumptions, not measured statistics.

How to use

Choose the malware type and press Play, or use Add 1 day to go step by step. Click a healthy computer to plug in an infected USB stick. Tick Software updates, Antivirus, Firewall, User training and Daily backups one at a time and watch the graph of infected computers and data lost. Finally press Run comparison to see all strategies averaged over many runs.

Parameters you can change

  • Number of computers 12–48 computers
  • Type of malware File-damaging worm, Ransomware
  • Length of the simulation 10–60 days
  • Software updates
  • Antivirus
  • Firewall
  • User training
  • Daily backups

Questions to explore

  1. Why does malware spread so fast through a network where many computers have not been updated?
  2. After a ransomware attack, which defence lets you recover the files without paying the ransom?
  3. Why is using several layers of defence together better than relying on just one?