1/147
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Confidentiality
Only authorized people can read or see the data
Integrity
Data is not altered without detection or authorization
Availability
Systems and data are accessible when needed
CIA triad
Confidentiality Integrity and Availability - the three core security goals
Asset
Anything of value that must be protected such as data servers or reputation
Threat
A potential cause of harm such as an attacker malware insider or natural disaster
Vulnerability
A weakness that a threat can exploit such as unpatched software or a weak password
Risk
The chance a threat exploits a vulnerability to harm an asset
Type 1 hypervisor
Runs directly on hardware (bare metal) such as ESXi or Hyper-V
Type 2 hypervisor
Runs on top of a host OS such as VirtualBox or VMware Workstation
Symmetric encryption
One shared secret key encrypts and decrypts - fast and used for bulk data
Asymmetric encryption
Public/private key pair - public encrypts or verifies and private decrypts or signs - slow
Key distribution problem
The main weakness of symmetric encryption - how to share the key safely
Hybrid encryption
Asymmetric exchanges a symmetric key and then symmetric encrypts the data - used in TLS and PGP
Plaintext
Original readable data before encryption
Ciphertext
Unreadable encrypted output
Salt
Random non-secret value added to a password before hashing - defeats rainbow tables and is stored with the hash
IV or nonce
Random value so the same plaintext encrypts to different ciphertext each time - not secret
Encoding
Reversible format conversion with no key and no security such as Base64
Base64
Encoding that turns binary data into printable text so it can be stored or sent safely - not encryption
Hashing
One-way function that turns any input into a fixed-size digest
AES
Secure symmetric block cipher - the current standard
DES
Old symmetric cipher with a 56-bit key - insecure and should not be used
3DES
DES applied three times - deprecated
ECB mode
Encrypts identical blocks to identical ciphertext and leaks patterns - should not be used
GCM mode
Secure AES mode that provides encryption plus integrity (authenticated encryption)
CBC mode
AES mode that chains blocks using an IV
PBKDF2
Key derivation function that turns a password plus salt plus many iterations into a strong key - slow on purpose
PBKDF2 vs AES
PBKDF2 creates the key from a password and AES uses that key to encrypt the data
KDF
Key derivation function - derives a cryptographic key from a password or secret
bcrypt / scrypt / Argon2
Slow salted password hashing algorithms for storing passwords
RSA
Asymmetric algorithm based on factoring large primes - use 2048 bits or more
ECC
Elliptic curve cryptography - asymmetric with smaller keys at the same strength
Diffie-Hellman
Key exchange that lets two parties agree on a shared secret over an insecure channel
SHA-256
Secure hash function producing a 256-bit digest
MD5 and SHA-1
Broken hash functions with known collisions - should not be used
Collision
Two different inputs producing the same hash
Rainbow table
Precomputed table of hashes to passwords - defeated by salts
Dictionary attack
Hashing common words and passwords to find a matching hash
Brute force attack
Trying every possible key or password
Avalanche effect
A tiny input change completely changes the hash output
HMAC
Hash combined with a secret key to provide integrity and authenticity
Digital signature
Hash of a message encrypted with the sender's private key - provides authenticity integrity and non-repudiation
Creating a signature
Hash the message then sign the hash with the sender's private key
Verifying a signature
Hash the message and check it against the signature using the sender's public key
Non-repudiation
The sender cannot deny sending the message
Password manager design
Master password plus salt through PBKDF2 makes an AES key that encrypts the vault - stored Base64-encoded
Shor's algorithm
Quantum algorithm that breaks RSA and ECC and Diffie-Hellman
Grover's algorithm
Quantum algorithm that halves effective symmetric key strength - AES-256 stays safe
Quantum vulnerable
Asymmetric cryptography is more vulnerable to quantum than symmetric
Post-quantum cryptography
New algorithms resistant to quantum attacks such as ML-KEM (Kyber)
Certificate Authority (CA)
Trusted organization that verifies identity and signs certificates
Root CA
Top of the trust chain - self-signed and preinstalled in the OS or browser trust store - kept offline
Intermediate CA
Signed by the root and signs server certificates - protects the root
Chain of trust
Server certificate to intermediate CA to root CA
Two functions of a certificate
Authenticate the server identity and distribute its public key
Let's Encrypt
Free automated nonprofit CA issuing 90-day domain-validated certificates via ACME/certbot
ACME
Protocol Let's Encrypt uses to automatically prove domain control and issue certificates
TLS
Protocol that secures HTTPS with confidentiality integrity and authentication
TLS asymmetric use
Handshake - authenticate the server and exchange or agree on keys
TLS symmetric use
Encrypting the actual data after the handshake
Session key
Temporary symmetric key used for one connection only
Forward secrecy
Past sessions stay safe even if the server's private key is stolen later - uses ephemeral DH (ECDHE)
ECDHE
Ephemeral elliptic curve Diffie-Hellman - new keys per session that give forward secrecy
TLS handshake goal
Authenticate the server and agree on a shared session key and cipher suite
ClientHello
First handshake message - supported versions and cipher suites and key share
ServerHello
Server picks the cipher suite and sends its key share and certificate
Certificate warning causes
Expired - hostname mismatch - self-signed - untrusted CA - revoked - or man-in-the-middle
TCP SYN flood
Many half-open connections exhaust the server - an availability attack - defended by SYN cookies
ARP spoofing
Fake ARP replies map the attacker's MAC to the gateway IP - enables man-in-the-middle on a LAN
DNS spoofing / cache poisoning
Fake DNS answers send users to the attacker's IP
IP spoofing
Forging the source IP address of packets
Man-in-the-middle
Attacker secretly intercepts and can alter traffic between two parties
DDoS
Distributed denial of service - many machines flood a target - an availability attack
IP
Network layer protocol for addressing and routing packets - connectionless and best effort
TCP
Transport layer protocol for reliable ordered connection-oriented delivery
UDP
Transport layer protocol that is connectionless and fast with no delivery guarantee
Three-way handshake
TCP setup - SYN then SYN-ACK then ACK
Port
Identifies the application or service on a host
Socket
IP address plus port number
Port 22
SSH
Port 25
SMTP (email)
Port 53
DNS
Port 80
HTTP
Port 443
HTTPS
Network zone
Group of systems with the same trust level separated by firewalls
DMZ
Zone for public-facing servers between the internet and the internal network
Firewall role in zones
Sits at zone boundaries and controls which traffic may cross - default deny
Packet filter firewall
Stateless - checks each packet's IP and port and protocol alone
Stateful firewall
Tracks connection state and allows return traffic for established connections
Application firewall / WAF
Inspects Layer 7 payload content
whois
Looks up domain registration info - registrar - name servers - dates
nmap
Scans networks for live hosts and open ports and services and OS
nmap -sS
SYN stealth scan
nmap -sV
Detects service versions
nmap -O
Detects the operating system
dig / nslookup
Query DNS records
DNS
Translates domain names into IP addresses
DNSSEC
Digitally signs DNS records so answers can be verified
DNS amplification
Small spoofed queries cause large responses sent to the victim