Connecting to the internet exposes computer systems to numerous threats. Security is paramount as it ensures the integrity, confidentiality and availability of information. Security should be approached as a series of complementary layers: workstation protection, network filtering, user awareness and regular updates.

1. Malware

Malware (malicious software) is any computer programme designed to harm a system or its user. There are several categories:

Virus: a programme that replicates itself by attaching itself to legitimate host files. It becomes active when the infected file is run.

· Boot virus (system virus): infects the boot sector (MBR/VBR). Difficult to remove, causes serious system malfunctions.

· File virus: infects executable files (.exe, .com). Activates when the host programme is run.

· Macro virus: spreads via macros in Office documents (Word, Excel). It copies itself into the global template (NORMAL.DOT) and infects all documents created thereafter.

· Script virus: uses scripting languages (VBScript, JavaScript) to spread via email and web browsers.

Worms: unlike viruses, worms do not need to infect a file to replicate. They spread autonomously via network connections, exploiting vulnerabilities or email address books. They spread very quickly (WannaCry infected 230,000 machines in 24 hours in 2017).

Trojan horses: hide within a legitimate programme. They become active as soon as the host programme is used. Variation: the logic bomb is triggered on a specific date or under specific conditions.

Ransomware:encrypts all files on the computer and any accessible network shares, rendering the system unusable. The victim must pay a ransom in cryptocurrency (untraceable) to obtain the decryption key — which is not always provided. Ransomware attacks are increasingly targeting businesses, hospitals and local authorities (ransoms of several million euros).

Spyware / Adware: collects information (cookies, passwords, browsing habits, bank details) and transmits it to remote servers for malicious or advertising purposes.

Rootkits: hide within the operating system or the BIOS/UEFI, making them very difficult to detect. They allow persistent and covert access to the compromised machine.

2. Antivirus and workstation protection

Antivirus software is an essential tool for any computer connected to the internet.

Modern solutions combine two complementary methods:

· Signature-based detection: compares files and processes against a database of known malware signatures. Effective against known threats, but requires daily updates.

· Behavioural detection (heuristic): analyses programme behaviour to detect suspicious activity (massive file encryption, unexpected connections) – effective against new threats (zero-day).

Components of comprehensive antiviral protection:

· Real-time protection (resident): continuously monitors all files and processes running on the computer. Represented by an icon in the system tray.

· Scheduled scan: comprehensive scan of memory and storage media (recommended weekly).

· Automatic definition updates: essential — without updates, effectiveness declines exponentially in the face of new threats.

· Additional modules: anti-spam, banking protection, parental controls, password manager.

💡 Best practices for personal safety

Install a reputable antivirus programme and keep it up to date. Schedule a full scan once a week. Never open attachments in unsolicited emails. Be wary of fake antivirus software (scareware) that displays false alerts to trick you into installing malware. Use two-factor authentication (2FA) on all important accounts. Back up your data regularly (the 3-2-1 rule: 3 copies, 2 different media, 1 off-site).

 

3. Firewall

A firewall is a system or group of systems that enhances security between the internal network and the internet. It acts as a central point for incoming and outgoing network traffic,and applies filtering rules that define what is permitted or prohibited.

The firewall determines:

· Which internal services are accessible from outside the network (e.g. a public web server on port 443, but no direct SSH access).

· Which external entities can access authorised internal services (filtering by source IP address, geo-blocking).

· Which external services are accessible from internal machines (e.g. allow HTTP/HTTPS, block P2P protocols).

a) Types of firewalls

Packet-filtering firewall (stateless): analyses each packet individually based on IP addresses and ports (OSI layers 3 and 4). Simple and fast, but without connection context. Router ACLs (Access Control Lists).

Stateful firewall: maintains a state table of established TCP/UDP connections. Allows return traffic corresponding to legitimate connections initiated from the inside. Standard for modern firewalls.

Web Application Firewall (WAF): inspects the content of requests up to Layer 7 (application). It can analyse and filter HTTP/HTTPS, SQL and XML traffic to detect SQL injections, XSS and so on.

NGFW (Next Generation Firewall): combines stateful filtering, SSL/TLS inspection, application identification (App-ID), intrusion prevention (IPS), sandboxing of suspicious files, and real-time threat intelligence. Examples: Palo Alto, Fortinet, Cisco Firepower.

Criteria for selecting a firewall:

· Level of protection (list of blocked attacks, SSL/TLS inspection).

· Supported authentication methods (LDAP, Active Directory, certificates).

· Maximum throughput and number of concurrent connections.

· Built-in VPN options (IPsec, SSL VPN, SD-WAN).

· Flexible security policies and ease of administration.

· Scalability and manufacturer support (signature update licences).

ℹ DMZ — Demilitarised Zone

The DMZ (Demilitarised Zone) is an intermediate network segment between the internet and the internal network, hosting servers that are accessible from outside the network (web, email, DNS). It is protected by two firewalls: one between the internet and the DMZ, and the other between the DMZ and the internal network. This means that even if a DMZ server is compromised, the internal network remains protected.

 

4. Social threats — Spam and phishing

Spam: unsolicited emails (advertisements, scams) sent in bulk. They may contain viruses, links to fake websites (phishing), or simply be a nuisance due to the sheer volume. Modern anti-spam filters (heuristics + AI + blacklists) block over 99% of spam before it reaches the inbox.

Phishing: an attempt to steal someone’s identity via email or text message (smishing). The attacker pretends to be a trusted entity (bank, mobile operator, government agency) to obtain login details, bank details or to execute malware. Spear phishing targets a specific person or organisation with a personalised message.

Vishing: phishing over the phone. The attacker calls the victim, pretending to be a member of technical support, a bank or a government agency.

Social engineering: psychological manipulation designed to persuade a user to disclose confidential information or carry out actions that compromise security. The human factor is the weakest link in security.

5. Data Protection (GDPR)

The GDPR (General Data Protection Regulation), which came into force in May 2018, provides a Europe-wide framework for the processing of personal data.

It requires organisations (companies, government bodies) to:

· Transparency: informing users about the collection and use of their data.

· Explicit consent for any data collection that is not strictly necessary for the service.

· The right of access, rectification, erasure (‘right to be forgotten’) and data portability.

· Data minimisation: collect only what is necessary (privacy by design).

· Reporting data breaches to the relevant authority (the CNIL in France) within 72 hours.

· Penalties of up to 4% of global annual turnover or €20 million.

Modifié le: vendredi 9 octobre 2026, 09:56