1/78
Comprehensive vocabulary flashcards covering concepts, architectures, threat categories, attack responses, security services and mechanisms, standards organizations, penetration testing roles, models, certifications, and frameworks from Week 1 of Computer & Network Security.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Cybersecurity
The collection of tools, policies, security concepts, security safeguards, guidelines, risk management approaches, actions, training, best practices, assurance, and technologies that can be used to protect the cyberspace environment and organization and users’ assets.
Information Security
Preservation of confidentiality, integrity, and availability of information.
Network Security
Protection of networks and their service; prevent unauthorized modification, destruction or disclosure; provide assurance that networks perform their critical functions correctly.
CIA Triad
Confidentiality, integrity, and availability.
Confidentiality (data confidentiality)
Assures that private or confidential information is not made available or disclosed to unauthorized individuals.
Privacy
Assures that individuals control or influence what information related to them may be collected and stored and by whom and to whom that information may be disclosed.
Data Integrity
Assures that data and programs are changed only in a specified and authorized manner.
System Integrity
Assures that a system performs its intended function in an unimpaired manner, free from deliberate or inadvertent unauthorized manipulation of the system.
Availability
Assures that systems work promptly and service is not denied to authorized users.
Authenticity
Property of being genuine and being able to be verified and trusted.
Accountability
The security goal that generates the requirement for actions of an entity to be traced uniquely to that entity.
OSI Security Architecture — Security attack
Any action that compromises the security of information owned by an organization.
OSI Security Architecture — Security mechanism
A process (or a device incorporating such a process) that is designed to detect, prevent, or recover from a security attack.
OSI Security Architecture — Security service
A processing or communication service that enhances the security of the data processing systems and the information transfers of an organization.
Security services vs. mechanisms
Security services are intended to counter security attacks, and they make use of one or more security mechanisms to provide the service.
Threat
A potential for violation of security, which exists when there is a circumstance, capability, action, or event that could breach security and cause harm.
Attack
An assault on system security that derives from an intelligent threat; a deliberate attempt to evade security services and violate the security policy of a system.
Passive attack
Attempts to learn or make use of information from the system; does not affect system resources.
Active attack
Alters system resources and affects their operation; involves modification of a data stream or creating a false data stream.
Release of message contents
A passive attack in which the contents of a telephone conversation, an e-mail, or a file may be accessed by unauthorized people.
Traffic analysis
A passive attack in which opponents observe the pattern of messages even if content is hidden by encryption, including communicating hosts and frequency and length of messages.
Why passive attacks are difficult to detect
They do not involve any alteration of the data; message traffic is sent and received in an apparently normal fashion.
Passive attack defense emphasis
Emphasis is on prevention rather than detection.
Masquerade
Takes place when one entity pretends to be a different entity.
Replay
Involves the passive capture of a data unit and subsequent retransmission to produce an unauthorized effect.
Data modification attack
Some portion of a legitimate message is altered, or messages are delayed or reordered to produce an unauthorized effect.
Denial of Service (DoS)
Prevents or inhibits the normal use or management of communications facilities.
Active attack response
Difficult to prevent due to variety of potential vulnerabilities; dealt with by detection followed by recovery.
Authentication security service
Concerned with assuring that a communication is authentic.
Peer entity authentication
Provides for the corroboration of the identity of a peer entity in an association.
Data origin authentication
Provides for the corroboration of the source of a data unit. It does not provide protection against the duplication or modification of data units.
Access control security service
The ability to limit and control the access to host systems and applications via communications links.
Data confidentiality service
The protection of transmitted data from passive attacks.
Traffic-flow confidentiality
Requires that an attacker not be able to observe the source and destination, frequency, length, or other characteristics of the traffic on a communications facility.
Connection-oriented integrity service
Assures that messages are received as sent with no duplication, insertion, modification, reordering, or replays.
Connectionless integrity service
Generally provides protection against message modification only in a larger context.
Nonrepudiation
Prevents either sender or receiver from denying a transmitted message.
Availability security service
Protects a system to ensure its availability; addresses the security concerns raised by denial-of-service attacks.
Reversible cryptographic mechanism
An encryption algorithm that allows data to be encrypted and subsequently decrypted.
Irreversible cryptographic mechanisms
Include hash algorithms and message authentication codes, which are used in digital signatures and authentication.
Data integrity mechanism
Mechanisms used to assure the integrity of a data unit or stream of data units.
Digital signature
Data appended to, or a cryptographic transformation of, a data unit that allows a recipient to prove the source and integrity of the data unit and protect against forgery.
Authentication exchange
A mechanism intended to ensure the identity of an entity by means of information exchange.
Traffic padding
The insertion of bits into gaps in a data stream to frustrate traffic analysis attempts.
Routing control
Enables selection of particular physically or logically secure routes for certain data and allows routing changes, especially when a breach of security is suspected.
Notarization
The use of a trusted third party to assure certain properties of a data exchange.
Access control mechanism
A variety of mechanisms that enforce access rights to resources.
NIST
a U.S. federal agency that deals with measurement science, standards, and technology.
Internet Society
A professional membership society that provides leadership in addressing issues that confront the future of the Internet.
RFC
Request for Comments; Internet standards and related specifications are published as RFCs.
ITU
International Telecommunication Union; an organization within the United Nations System in which governments and the private sector coordinate global telecom networks and services.
ISO
International Organization for Standardization; a nongovernmental organization that promotes development of standardization and related activities.
Penetration test
Attempt to break into a company’s network to find the weak links.
Vulnerability assessment
Tester attempts to enumerate all vulnerabilities found in an application or on a system.
Security test
Tester analyzes a company’s security policy and procedures and reports any vulnerabilities to management.
Hacker (U.S. DOJ definition)
A person who accesses a computer or network without the owner’s permission; the U.S. Department of Justice labels all illegal access as hacking.
Cracker
Breaks into systems to steal or destroy data.
Ethical hacker
Performs most of the same activities a hacker does, with the permission of the owner or company.
Penetration tester / security tester
An ethical hacker; hired by companies to perform penetration tests.
Script kiddies / packet monkeys
Inexperienced people who copy code or use tools created by knowledgeable programmers without understanding how they work.
Hacktivist
A person who hacks computer systems for political or social reasons.
Script
A set of instructions that runs in sequence to perform tasks on a computer system.
Penetration tester duties
Perform vulnerability, attack, and penetration assessments; discovery and scanning for open ports and services; apply appropriate exploits; document discoveries and report to the client.
White box model
Tester is told what network topology and technology the company is using; may be given a floor plan and permitted to interview IT personnel and employees.
Black box model
Tester is not given any diagrams or details about the technologies used; burden is on the tester to find details. Tests security personnel’s ability to detect an attack.
Gray box model
Hybrid of the white and black box models; company gives tester only partial information.
Acceptable Use Policy (ISP)
A section of the ISP contract to read; running scanning software that slows down network access or prevents users from accessing network components might create problems.
Legal precautions before security testing
Keep abreast of local laws, know what is allowed, read your ISP Acceptable Use Policy, and contact local law enforcement agencies before installing hacking tools where appropriate.
Illegal actions in security testing
Accessing a computer without permission; destroying data without permission; copying information without the owner’s permission; installing viruses on a network; denying users access to network resources.
Written contract
Using a contract is good business and may be useful in court; have an attorney read your contract before signing.
Skills needed to be a security tester
Knowledge of network and computer technology; ability to communicate with management and IT personnel; understanding of applicable laws; ability to apply necessary tools.
CompTIA Security+
A minimum certification for network security personnel, or equivalent knowledge; Network+ level knowledge is a prerequisite according to the slides.
CompTIA Network+
Network knowledge level listed as a prerequisite for Security+ in the slides.
CompTIA PenTest+
Advanced certification verifying skills in planning and scoping assessments, legal and compliance requirements, scanning, penetration testing, analysis, and reporting.
Offensive Security Certified Professional
Advanced certification requiring hands-on abilities; covers network and application exploits, writing scripts, and trying exploits on vulnerable systems.
Certified Ethical Hacker
EC-Council certification; the multiple-choice exam is based on 22 domains according to the slides.
Red team
People with varied skills who act as attackers and simulate real-world cyberattacks by performing penetration tests.
Blue team
Defenders who protect an organization’s infrastructure and data; roles include recovery, incident response, and log analysis.
Purple team
A hybrid cooperative approach involving red and blue teams.