Information System Development, Acquisition, and Maintenance ◾ 233
◾ Distributed Denial-of-Service (DDoS) Attack—A type of DoS attack in which
the attacker installs a control program on multiple computers. e attacker
can command all systems under his or her control to attack. DDoS is more
effective than DoS because the number of attacking machines is limited only
by how many computers the hacker can get under his or her control. Malware
is often used to infect machines without the knowledge of the owner. DDoS
is also more difficult to stop because blocking a single IP address or network
range will not stop systems on other networks.
◾ Code Injection—A class of techniques in which an attacker introduces or
“injects” code into a computer p