INTRODUCTION.
DAIM (Defensive Advanced Intelligent Malware) / MIAD (Defensive Advanced Intelligent Malware) is not only limited to protecting and defending us (blocking, neutralizing, deactivating, disabling, sterilizing, etc.) against cyberattacks from offensive malware, but also protects and defends us against any other type of cyberattack in general (based on offensive cyber-attackers/hackers, human-machine, AI robot clusters, automated malware cyber-weapons, cyber-criminals, crackers, etc.).

The DAIM (Defense and Information Management) system proactively neutralizes, blocks, and prevents any attempt at cyberattacks (based on malicious operations, situations, actions, processes, procedures, tactics, techniques, etc.) against any element or component of cybersecurity and privacy (both in the physical/analog world and in cyberspace). Let's examine some of the main assets, elements, components, factors, and dimensions against offensive cyberattacks offered by the cybersecurity and privacy systems used by the DAIM. The DAIM integrates a symbiosis of AI (deep neural networks, convolutional networks, intelligent agents, machine learning, genetic algorithms, deep learning, fuzzy sets, NLP, expert systems, etc.), ID (BigData-Data Analytics), IV, TH, ZT, ZK, IT, playbooks/BCs, regulations (such as NIST, ISO-27002:2022, ISO-23247, IEC-62443, etc.), etc.


cybersecurity-2-wAPPLICATION OF VISIBLE AND INVISIBLE ASPECTS BY DAIM AGAINST CYBERATTACKS.
DAIM is designed to neutralize, block, disable, mitigate, etc., any malicious attempt to carry out all types of operations, actions, maneuvers, movements, concealments, etc., on any of the countless dimensions that make up cybersecurity and privacy, such as the following:

(1) Confidentiality-privacy.

The DAIM is responsible for blocking and preventing attempts to monitor, steal and disclose information to all types of unauthorized entities, involving data from (business, intelligence, military, secret, private, critical, sensitive data, passwords-credentials, private and secret cryptographic keys, tokens, PII (Personally Identifiable Information), activities and operations of entities, health data, debit/credit card numbers from banks and loyalty-payment numbers in supermarkets, APPs, etc.). Possible offensive cyberattacks include: Espionage (of individuals, companies, nations, etc. using cyberweapons-spyware (such as Pegasus from NSO Group, Sourgum from Candiru, etc.) that intercept communications and access all the content of devices (mobiles, tablets, PCs, etc.), such as calendars, webcams, microphones, photos, videos, etc.) and associated clouds (cloud/fog/edge; APPs deployed at the edge often use containers) taking advantage of multiple cyber-attack vectors such as vulnerabilities-exploits (in the JavaScriptCore (jsc) binary to achieve code execution on iOS devices.

This vulnerability is used to maintain persistence after device reboot. The Log4j vulnerability and the Log4Shell exploit. The InstallerFileTakeOver exploit for Windows, etc.), IM, SMS, email, etc.), tracking, surveillance, monitoring, loitering agents, packet capture). Interception (wired, wireless, satellite, OTA, etc.) consists of gaining access to information within a system or being transmitted to or from a computing entity or device. Sniffers (wired or wireless) are used for this purpose; EM/electromagnetic signal receivers are employed to illegally capture sensitive information from EM emissions of systems; data leakage and its remote capture using electromagnetic emissions to illegally copy computer screen contents and internal computing processes can be prevented by enclosing the device or building in a metal or plastic Faraday cage that shields against EM waves and provides acoustic isolation.

cybersecurity-3-wIn Man-in-the-Middle (MITM) cyberattacks, data flowing from sender to receiver is intercepted by an intermediary enemy entity, which copies, exfiltrates, modifies, forwards it to cyber attackers/exfiltrates it, etc. Examples include the theft of keyless entry and start codes for vehicles (a solution is to store the card inside a metal or plastic Faraday cage with electromagnetic shielding). Another example is the theft of proximity card data, such as bank credit cards. For instance, a criminal on a bus might use an illegal card reader hidden in a backpack to charge the cardholder's purchases; a solution is to store the card inside a Faraday cage. Finally, there are widespread, intensive processes of reconnaissance and snooping. Exfiltration (is the unauthorized transmission, extraction, or deletion of information from an entity or system. We can capture or exfiltrate data from everything we type using a keylogger (software or hardware)). Time-attack (explores the contents of the web browser cache where passwords, keys, etc. are located).

Information leakage using side-channel attacks to capture secret keys, passwords, etc. Password hardcode (the leakage of secrets, passwords, private/secret keys, etc., because these secrets are embedded (written in plain text) in the source code of programs). Password attacks (capturing passwords by brute force where there is no mechanism to limit the number of retries, using keyloggers, packet capture, hashing, dictionary attacks, Trojans/spyware, etc., on devices and in the cloud). Exploitation of trust relationships and resource sharing, etc. Dumpster diving (which involves browsing, searching, and snooping through data in physical and digital garbage, in memory, and in cyberspace such as the cloud), session hijacking/theft (if a victim user logs in and communicates with a web server, and malware or a sniffer intercepts the session and copies the session identifier, the malware/cyber-attacker can then log in to the web server using that intercepted session identifier. Many websites try to keep the user's session open with malicious intent), and capture (recording what we say and do using the webcam of our mobile phone, tablet, smart TV, PC, smart children's toys (IoT), etc., based on malware such as creepware/spyware (two spyware families are Agent-Tesla and Formbook). This involves compromising the webcam and integrated microphone of a PC, smart TV, smartphone, tablet, smart children's toys that can see, speak, and hear, etc., and transmitting the recordings via electromagnetic waves or ultrasound. to a cybercriminal). The use of social engineering (allows them to extract vital information from people).

Reverse engineering of programs (executables, assemblies, code, etc.) reveals secrets, extracts vulnerabilities, and valuable information. DAIM (Data Analysis and Information Management) is designed to protect the confidentiality of any entity regarding what information it generates, communicates, stores, knows, or disseminates (deceived or unknowingly), about its activities (for example, through tracking malware, cookies, etc., IPs, MAC addresses, URLs, passwords, bank card numbers, generated health data, travel itineraries, web browsing history, eating habits, leisure activities, etc.), about the entity's geolocation (outdoor and indoor), about who the entity is and with whom it interacts (in the physical world and in cyberspace, applying nested anonymity and encryption technologies/steganography). Some confidentiality protection techniques consist of applying multiple layers of robust symmetric/asymmetric encryption with fault-tolerant key management, steganography, secret fragmentation (using key escrow/Shamir), etc. Distributed, replicated backups (or backup copies to recover stolen, encrypted, deleted, or damaged data) will be encrypted so that no one can snoop, not even in the cloud. VPN technology with proxy servers, nested decentralized anonymity techniques, ZT network technology, network segmentation, etc., will also be used. The mechanism called "oblivious transfer" (OT) allows entity A to copy content located on entity B (which stores a large amount of content) without B knowing which of B's ​​contents entity A has taken. Furthermore, entity A can only copy one piece of content per remote interaction (ensuring confidentiality regarding entity A's preferences, and A cannot know the rest of the content held by B). The mechanism called "digital commitment" allows entity A to predict an event in advance (for example, the winning team in a match) and commit to another entity B that knows it. To do this, entity A encrypts the prediction "it's like putting what A guessed into a virtual box with a key" and A sends the locked virtual box to entity B.

cybersecurity-4-wOnce everyone knows the result, entity A sends entity B the cryptographic key—"it's like the key to open that virtual box sent earlier"—and B observes that A was right. The mechanism called "secure multi-party computation" or SMPC allows several entities that don't trust each other to perform shared calculations using each other's secret data, without revealing each other's secret data. Another confidentiality mechanism for a group of entities, each with its own secret data, involves encrypting it (with fully homomorphic encryption, meaning for all types of operations: addition, multiplication, etc.). Once the data is hidden and encrypted, the appropriate operations are performed, and finally, the result is decrypted, providing the plaintext result for all entities. One way to protect the confidentiality of physical documents is to integrate an incineration unit if someone unauthorized tries to open the room or safe where they are stored. A dead drop box is an access-controlled enclosure (lodge, mailbox, trash can, etc.) containing explosives, where confidential information is left. If an unauthorized person tries to access this confidential information, the enclosure or safe will explode. Bluetooth pairing/cloning allows one mobile phone to be copied/cloned with another, enabling the capture of the victim's data.

DAIM is designed to block, disable, and neutralize data leaks caused by steganography, subliminal channels, side-channels, EM emanations, information sharing, data leakage between virtual machines within a cloud server, eavesdropping/sniffers, webcams on smartphones, PCs, smart TVs, CCTV cameras, satellite cameras (malicious satellite surveillance using newly identified exploits/vulnerabilities in satellite networks), spy cameras, spyware/creepware, wiretapping, ping-sweep/port-scan, etc. It blocks all types of attempts to monitor web browsing, connected/autonomous vehicles, and city walking, etc. It proactively blocks keyloggers, cookie trackers, adware, cyber intrusions, data capture via EM emanations, and more. It will also block surveillance and reconnaissance in the physical world (using drones, sensors, mobile agents, etc.) and in cyberspace (blocking access to web browsers, social media, forums, metaverses, the Dark Web, etc.). DAIM will neutralize theft, kidnapping, and blackmail (related to data/files: using ransomware malware to encrypt or wipe data). It will also neutralize doxware, which steals sensitive data and demands money in exchange for not releasing it.

(2) Integrity.

The DAIM (Data Access Management Authority) is responsible for preventing/blocking the illegal modification, loss, or manipulation of information, software, firmware, data, programs/APIs, OTA updates, hardware, etc. Potential cyberattacks against system integrity include: Fabrication or insertion, which involves introducing/injecting new information, data, software, firmware, or even hardware into a system (using PUF technology as a solution), for example, in the supply chain; remote access; infected USB access; social engineering; etc. SIM swapping is a type of fraud that involves illegally duplicating a SIM card associated with a phone line without the owner's consent to impersonate the owner and access confidential information such as banking apps, emails, social media accounts, etc.

cybersecurity-5-wThe modification consists of changing the information, software, firmware, hardware (with hardware trojans), data, protocols, configurations, OTA updates, existing information, etc.; an example is altering the “data-streams” transmitted by a satellite. Distorting or altering reality (and everything it entails, such as information) or disinformation (the malicious manipulation of information is not a new phenomenon, but today it has become dangerously aggravated by technologies such as intelligent active intervention malware, synthetic media/deepfakes (generating hyper-realistic videos, audios, images, and texts such as "our nation is under attack," "an asteroid is falling that will annihilate life on half the Earth," etc.). Altering sensor data in connected/autonomous vehicles allows the vehicle and occupants to believe there are no obstacles when in fact there are, causing accidents ("fake ghosts"). Corruption (the alteration or degradation of the quality of information, existing data, protocols, software, firmware, hardware, QoS, etc., to render it unusable or isolate it). ARP poisoning (for example, through malware, which consists of changing the mappings between MAC/L2 and IP/L3 addresses in the ARP cache, allowing a A cyber attacker positions themselves between a legitimate sending entity and a legitimate receiving entity as an intermediary and carries out man-in-the-middle (MITM) attacks, identity theft, and cyberattacks that compromise confidentiality, integrity, availability, etc. DNS poisoning or pharming (for example, using malware to change the mappings between IP addresses/L3 and URLs/L5 in DNS tables), data diddling (changing data before storing it), and "salami" attacks (combining many small cyberattacks into one large attack) are all forms of cybercrime. Some mechanisms to protect integrity include digital signatures, hash functions like SHA-512, and First Error Correction (FEC) codes like Golay and CRC-4048. If a file is modified, backups are used to recover it. Hardware integrity protection uses PUF functions, while soft-firming uses WORM memory to prevent modification of stored information.

(3) Availability.

The DAIM is designed to prevent any reduction in quality (for example, affecting Quality of Service (QoS) such as latency, bandwidth, speed, jitter, etc.), interruption, degradation, deterioration, slowdown, or blocking of access to resources to which an entity is authorized. The DAIM is designed to enable any authorized entity/user to access assets, services, devices, networks, etc., at any time, from any location, whenever needed, without delay. Possible cyberattacks include: Denial of Service (DoS) attacks (e.g., TCP SYN flood), Distributed Denied of Service (DDoS) attacks, Ping of Dead attacks (malware creates and sends an ICMP packet larger than 65535 bytes, which fragments and, upon reaching its destination, cannot handle the excessive size, causing the system to crash), smurf attacks (an ICMP/L3-based attack that floods the victim's system with ICMP packet traffic from a subnetwork; the malware first pings the subnetwork's broadcast address, and existing devices respond to the spoofed IP address (that of the target/victim system), exhausting the victim system's bandwidth and processing resources), use of RF (Radio-Frequency) jammers, and interference in the EM spectrum (to prevent vehicle locks from being opened with RF signals and even to prevent communication between people, alarms, drones, etc.).

cybersecurity-6-wThe DAIM will block all types of malicious jamming attempts by applying a redundant set of anti-jamming systems), buffer overflow (to overflow the buffer, stack, head), fraggle cyberattack (it is a cyberattack based on the UDP/L4 protocol (ports 7 and 19). The problem arises when a large amount of forged UDP traffic (with the IP address of the victim server) is sent to the router's broadcast address; the victim server tries to respond to everything it receives from the router, but the flood of packets continues and the victim server becomes bogged down due to the added activity), land cyberattack (the malware sends forged SYN packets to the victim using the victim's IP address and both source and destination addresses. The result is that the victim is constantly responding to itself, eventually crashing the system/victim), electrical disturbances (these are generated to interfere with, interrupt service, and even damage hardware; they are power outages, electrical flow disturbances, current fluctuations, micro-outages, changes in frequency/voltage, blackouts (power outages, gas outages, railway outages, etc. The DAIM will block all types of malicious attempts to cut off the electrical flow using a distributed redundant set of UPS/SAI systems with electrical signal conditioning), power spikes, power sags, brownouts (voltage drops due to different causes such as transformer failures, high demand for electrical power, etc.), electrical surges, etc. (These are combated with UPS/SAI, line conditioners, backup generators), etc.), attacks on the physical environment (temperature, water, humidity, dust, gas, fire, EMPs (Electro Magnetic Pulses; allows disrupting all electronic devices reached by their influence), graphite and neutron bombs, earthquakes, tsunamis, solar storms, blocking of the electromagnetic spectrum to block communications, etc.). To protect availability and accessibility, failover, fault tolerance, redundancy, and cyber resilience mechanisms are used, along with backups (DAIM will block all malicious attempts to delete, hijack, distort, etc., information using a redundant set of geographically distributed backup systems). Uninterruptible power supplies (UPS), multiple power providers, and battery banks with DC/AC inverters are also employed. The "dead man's switch" allows for the detection of whether something or someone has been disabled or has died, triggering a countermeasure.

Degradation (reducing the performance or effectiveness of a system, service, component, etc.). Disruption (the loss of any ability to use a cyber asset (system, service, CPS, network, etc.)). Corruption (changing the quality of existing information or data, protocols, software, firmware, etc., to the point of making them unusable or inaccessible). Jamming (interference with incoming satellite signals such as GPS) can disrupt mobile and vehicle navigation systems in an area. Interference in both directions of satellite-to-ground communication prevents the satellite from transmitting or receiving information.

FINAL CONSIDERATIONS.
A cyberattack using social engineering can be of two types: hunting (aimed at extracting information through minimal interaction with the target) and farming (aimed at establishing a sustained relationship over time to exploit the victim and extract a large amount of information). According to F5 Labs, DDoS cyberattacks grew by 55% between January 2020 and March 2021, and 54% used multiple cyberattack vectors. Gartner predicts that 60% of organizations/companies will phase out VPNs in favor of Zero Trust (ZT) network access by 2023. According to the OSCINR (Open Source Cybersecurity Intelligence Network and Resource), 60% of all medical devices (IoMT, appliances, etc.) lack patches/updates.

REFERENCES.
- Areitio, J. “Information Security: Networks, Computing and Information Systems”. Cengage Learning-Paraninfo. 2021.
- Areitio, J. “Duality of Advanced Intelligent Malware (Offensive and Defensive), Action Points and Transparent Expansion Operations”. Conectrónica Magazine. No. 245. October 2021.
- Areitio, J. “Elements and Approaches for the Design and Synthesis of Advanced Defensive Intelligent Malware”. Conectrónica Magazine. No. 246. November 2021.
- Areitio, J. “Development of Advanced Defensive Intelligent Malware. Neutralization of Offensive Malware Actions”. Conectrónica Magazine. No. 247. February 2022.
- Areitio, J. “Automatic Actions of Advanced Defensive Intelligent Malware”. Conectrónica Magazine. No. 248. March 2022.
- Areitio, J. “Exploring the dynamics of the blocking operation used by the DAIM/MIAD”. Conectrónica Magazine. No. 249. April 2022.
- Areitio, J. “Low-level defense and protection maneuvers and operations orchestrated by the DAIM/MIAD against offensive cyberattacks”. Conectrónica Magazine. No. 250. May-June 2022.
- Areitio, J. “New areas of action for the DAIM/MIAD against offensive cyberattacks using privacy secrets – cybersecurity”. Conectrónica Magazine. No. 251. September 2022.
- Kaschner, H. “Cyber ​​Crisis Management: The Practical Handbook on Crisis Management and Crisis Communication”. Springer. 2022.
- Velu, VK “Mastering Kali Linux for Advanced Penetration Testing: Become a Cybersecurity Ethical Hacking Expert Using Metasploit, Nmap, Wireshark, and Burp Suite”. Packt Publishing. 2022.
- Zegart, AB “Spies, Lies and Algorithms: The History and Future of American Intelligence”. Princeton University Press. 2022.
- Wittkop, J. “The Cybersecurity Playbook for Modern Enterprises: An End-to-End Guide to Preventing Data Breaches and Cyber ​​Attacks.” Packt Publishing. 2022.
- Bravo, C. and Kitchen, D. “Mastering Defensive Security: Effective Techniques to Secure Your Windows, Linux, IoT, and Cloud Infrastructure.” Packt Publishing. 2022.
- DiMaggio, J. “The Art of Cyberwarfare: An Investigator's Guide to Espionage, Ransomware, and Organized Cybercrime.” Not Starch Press. 2022.
- Mansour, G. “UNHACKABLE: Your Online Security Playbook: Recreating Cyber ​​Security in an Unsecure World”. Writes Publishing House. 2020.
- Grimes, RA “Ransomware Protection Playbook”. Wiley. 2021.
- Batina, L., Bäck, T., Buhan, I. and Picek, S. “Security and Artificial Intelligence: A Crossdisciplinary Approach”. Springer. 2022.
- Skulkin, O. “Incident Response Techniques for Ransomware Attacks: Understand Modern Ransomware Attacks and Build an Incident Response Strategy to Work Through Them.” Packt Publishing. 2022.