Malvertising
Duration: 1 min
This video lesson is available to enrolled students.
AI summary & chapters
AI Summary
An AI-generated summary of this video lecture.
The lecture introduces the concept of Malvertising, defining it as a portmanteau of "malware" and "advertising." The slide text explains that this practice involves injecting malicious code or malware-laden advertisements into legitimate online advertising networks and webpages. The instructor emphasizes the deceptive nature of the attack, where harmful content is hidden within standard ads. Handwritten notes clarify the components, labeling the process as "Malware + Advertising" and identifying the resulting software as "Adware."
Chapters
0:00 – 1:15 00:00-01:15
The session begins with the definition of Malvertising on the slide. The instructor writes "Malware + Advertising" to the right of the title. The diagram illustrates the attack chain: an Attacker creates a Malicious banner, which is sent to an Advertiser. The Advertiser places the ad on a Website with ad. The User visits the site, and User metadata is exchanged with the Malicious banner. A red arrow indicates a Redirect to a Drive-by-download. The instructor writes "Online ads" near the User icon and "Adware" near the download icon. At the bottom, "Polymorphic malware" is visible, hinting at the next topic.
Malvertising represents a significant security threat where malware is distributed through legitimate online advertising networks. The attack flow starts with an attacker injecting malicious code into an advertisement. This ad is then served by an advertiser to a legitimate website. When a user visits the webpage, the malicious ad is displayed. The interaction can lead to a redirect or a drive-by-download, compromising the user's device. The instructor highlights that this technique exploits trust in legitimate ad networks. The term "Adware" is used to describe the unwanted software installed. This demonstrates how third-party content can be a vector for cyberattacks.