1/81
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
CIA triad
Confidentiality, Integrity, Availability
Confidentiality
Only authorized people can see the data
Integrity
Data is accurate and unaltered
Availability
Authorized users can access data when needed
AAA
Authentication, Authorization, Accounting
Authentication
Proving who you are
Authorization
What you are allowed to do
Accounting
Recording what a user did
Three layers of protection
Products, people, and policies & procedures
Security vs. convenience
Inversely related - more security usually means less convenience
Asset
Something of value that needs protecting
Threat
A type of action that could cause harm
Threat actor
A person or group who carries out an attack
Vulnerability
A weakness that allows a threat to cause harm
Exploit
Taking advantage of a vulnerability
Risk
The likelihood that a threat actor will exploit a vulnerability
Why attacks are hard to prevent
Easy-to-use attack tools, faster and more sophisticated attacks, vulnerabilities found faster than patched, confused users
Cybercriminals
Motivated by financial gain; organized and well funded
Script kiddies
Low-skill attackers using tools written by others; want thrills/attention
Brokers
Find vulnerabilities and sell them to the highest bidder
Insiders
Employees or contractors with trusted access; revenge, money, or carelessness
Cyberterrorists
Motivated by ideology; aim to cause fear and disruption, often targeting infrastructure
Hacktivists
Motivated by political or social causes
State actors
Government-backed attackers serving national interests (espionage); most resources, long stealthy attacks
Five key elements of a comprehensive security strategy
Block attacks, update defenses, minimize losses, manage risk, send secure information
Authentication elements
Something you know, something you have, something you are (also somewhere you are, something you do)
Hashing
Turning a password into a fixed-length string with a one-way algorithm
Digest
The fixed-length output of a hash algorithm; what the server stores instead of the password
How password login is checked
The typed password is hashed and its digest compared to the stored digest
Why passwords are weak
People can only remember short, simple passwords, so they reuse them and pick predictable ones
Brute force attack
Trying every possible combination of characters
Dictionary attack
Trying common words and known passwords
Password spraying
Trying a few common passwords against many accounts
Rainbow table
Precomputed digests used to crack stolen password hashes quickly
Credential stuffing
Reusing username/password pairs leaked from another breach
Social engineering
Tricking people into breaking security; targets human psychology, not technology
Social engineering psychological approaches
Authority, intimidation, urgency, scarcity, consensus, familiarity, trust
Phishing
Fake messages or sites that trick users into giving up information
Spear phishing
Phishing targeted at specific people
Whaling
Phishing aimed at executives or wealthy targets
Vishing
Voice phishing (phone calls)
Smishing
Phishing by text message (SMS)
Typo squatting
Registering misspelled domain names to catch users' typing errors (URL hijacking)
Hoax
A false warning that tricks users into a harmful action, like deleting a file
Identity theft
Using someone's personal information to open accounts or make purchases in their name
First step in creating a defensive stance
Identify the assets that need protection
Strong password
Long (length matters most), unique, not based on personal info; passphrases help
Password manager
Software that generates and securely stores passwords
Two-factor authentication (2FA)
Login requiring two different types of authentication
Two steps of avoiding identity theft
1) Deter thieves by protecting personal info; 2) Monitor financial statements and credit reports
Malware
Software that enters a computer without consent and performs harmful actions
Zero-day attack
Exploits a flaw before the vendor knows about it or has a patch
How malware is classified
By the primary action it performs
Kidnap malware
Ransomware
Eavesdrop malware
Spyware and keyloggers
Masquerade malware
PUPs, Trojans, RATs
Launchpad malware
Viruses, worms, bots/botnets
Sidestep malware
Backdoors, logic bombs, rootkits
Ransomware
Holds a computer or its data hostage until a ransom is paid
Blocking (locker) ransomware
Locks the user out of the device
Crypto-malware
Ransomware that encrypts the user's files
Spyware
Secretly collects information about the user
Software keylogger
A program that records keystrokes
Hardware keylogger
A small physical device between keyboard and computer that records keystrokes
PUP (potentially unwanted program)
Unwanted but not clearly malicious software, like adware or toolbars
Trojan
Looks like useful software but hides malware
RAT (remote access Trojan)
A Trojan that also gives the attacker remote control of the computer
Virus
Attaches to a file and needs user action to spread
Two types of viruses
File-based and fileless
Worm
Spreads by itself across networks with no user action
Bot / botnet
Infected computer controlled by a bot herder; many bots form a botnet used for spam or DDoS
Backdoor
A hidden way to bypass normal security for secret access
Logic bomb
Dormant code that activates when a specific condition is met
Rootkit
Hides malware by altering the operating system so normal tools can't detect it
Patch
A vendor software update that fixes security flaws
Most important step to protect your computer
Keep it patched / install updates promptly
Antivirus vs. antimalware
Antivirus mainly finds viruses via signatures; antimalware covers more threats (spyware, rootkits, ransomware) often with behavior-based detection
Firewall
Hardware or software that filters network traffic by rules
Software (host-based) firewall
Runs on one computer; can control which apps send/receive traffic, including outbound
Hardware (network) firewall
Separate device protecting all devices on a network by filtering incoming traffic
Best defense against ransomware
Current backups you can restore from
Ways to create backups
External drive (local) or cloud/online backup; keep one copy disconnected