Computer Security First Exam

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/97

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 10:23 PM on 10/2/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

98 Terms

1
New cards

Computer Security

the ability of a system to protect information and system resources with respect to confidentiality and integrity

2
New cards

Aspects of Security


  1. Prevention: take measures that prevent your assets from being damaged

  2. Detection: take measures so that you can detect when, how, and by whom an asset has been damaged

  3. Reaction: take measures so that you can recover your assets or to recover from a damage to your assets


3
New cards

Computer Security goals


  1. Confidentiality: Preventing, detecting or deterring the improper disclosure of information

  2. Integrity: Preventing, detecting, or deterring the improper modification of data

  3. Availability: Preventing, detecting, or deterring the unauthorized denial of service or data to legitimate users

  4. Authenticity: Ensuring that users of data/resources are the persons they claim to be

  5. Accountability: Able to trace breach of security back to responsible party


4
New cards

Confidentiality

Prevent unauthorized disclosure of information

5
New cards

Aspects of confidentiality

  1. Privacy: protection of personal data

  2. Secrecy: protection of data belonging to an organization


6
New cards

Integrity

Detection (and correction) of intentional and accidental modifications of data in a computer system

7
New cards

Availability

The property that a product’s services are accessible when needed and without undue delay

8
New cards

DoS

Denial of Service is the prevention of authorised access of resources or the delaying of time-critical operations

9
New cards

DDoS

Distributed Denial of Service occurs when multiple sources contribute to denial of service simultaneously

10
New cards

Accountability

  1. Audit information must be selectively kept and protected so that actions affecting security can be traced to the responsible party

  2. Users are identified and authenticated to have a basis for access control decisions.

  3. The security system keeps an audit log (audit trail) of security relevant events to detect and investigate intrusions.


11
New cards
<ol><li><p>Principles of Computer Security: Where to focus security controls?</p></li></ol><p></p>
  1. Principles of Computer Security: Where to focus security controls?


  1. Data: Format and content of data

  2. Operations: Operations allowed on data

  3. Users: Access control of data based on user


12
New cards
  1. Principles of Computer Security: Where to place security controls?


  1. Lower layers offer more generic control

  2. Higher layers allow most functionality and ease of use


<ol><li><p>Lower layers offer more generic control</p></li><li><p>Higher layers allow most functionality and ease of use</p></li></ol><p></p>
13
New cards
  1. Principles of Computer Security: Security, functionality and ease-of-use linked together?


  1. increasing Security hampers functionality & ease-of-use

  2. Most secure computer is the one not plugged in and buried in 30 cu. ft. of concrete!


<ol><li><p>increasing Security hampers functionality &amp; ease-of-use</p></li><li><p>Most secure computer is the one not plugged in and buried in 30 cu. ft. of concrete!</p></li></ol><p></p>
14
New cards
  1. Principles of Computer Security: Centralized or Decentralized Security Control?


  1. A central security authority provides much better control but may act as a bottleneck for productivity

  2. A decentralized security control provides ability to fine tune security control for applications making system easy to us


15
New cards
  1. Principles of Computer Security: How do you stop an attacker from getting access to a layer below your protection mechanism?


Tools to bypass protection mechanisms

  1. Recovery Tools: These can read the hard disks byte-to-byte without acquiescing to high level security checks

  2. Unix Devices: Unix treats physical memory devices like files, so, if improper access controls are defined a hacker can read disks

  3. Backups: Backups are made to recover data in a computer crash. If not stored properly data can be read from the backup media


<p>Tools to bypass protection mechanisms </p><ol><li><p>Recovery Tools: These can read the hard disks byte-to-byte without acquiescing to high level security checks </p></li><li><p>Unix Devices: Unix treats physical memory devices like files, so, if improper access controls are defined a hacker can read disks</p></li><li><p> Backups: Backups are made to recover data in a computer crash. If not stored properly data can be read from the backup media</p></li></ol><p></p>
16
New cards

Security Policy

A definition of information security with a clear statement of management's intentions

17
New cards

What can a security polocy include?

  1. Compliance with legislative and contractual requirements

  2. Security education, virus prevention and detection, and business continuity planning

  3. A definition of general and specific roles and responsibilities for the various aspects of information security program in business

  4. an explanation of the requirement and process for reporting suspected security incidents, and

  5. the process, including roles and responsibilities, for maintaining the policy document.


18
New cards

Medical records pose particular security problems. Assume that your medical records can be accessed on-line. On the one hand, this information is sensitive and should be protected from disclosure. On the other hand, in an emergency it is highly desirable that whoever treats you has access to your records. How would you draft your security policy and use prevention, detection and recovery to secure your records?

  1. Compliance & Accountability: Mandate strict compliance with health privacy regulations and establish clear penalties for unauthorized access.

  2. Audit Review & Incident Response: Routinely review emergency access logs to verify legitimate clinical need. If unauthorized access occurred, initiate immediate incident response and revoke compromised access credentials.

  3. Audit Logging: Maintain detailed, tamper-resistant audit trails that record every instance of record access, including user ID, timestamp, patient ID, and access type.


19
New cards

Eavesdropping

The interception of information intended for someone else during its transmission over a communication channel.

<p>The interception of information intended for someone else during its transmission over a communication channel. </p>
20
New cards

Man-in-the Middle

Alteration: unauthorized modification of information

<p>Alteration: unauthorized modification of information</p>
21
New cards

DoS

The interruption or degradation of a data service or information access

<p>The interruption or degradation of a data service or information access</p>
22
New cards

Masquerading

The fabrication of information that is purported to be from someone who is not actually the author

<p>The fabrication of information that is purported to be from someone who is not actually the author</p>
23
New cards

Repudiation

the denial of a commitment or data receipt.

  • This involves an attempt to back out of a contract or a protocol that requires the different parties to provide receipts acknowledging that data has been received.


24
New cards

Correlation and traceback

the integration of multiple data sources and information flows to determine the source of a particular data stream or piece of information.

<p>the integration of multiple data sources and information flows to determine the source of a particular data stream or piece of information.</p>
25
New cards

10 security principles

  1. Economy of mechanism: This principle stresses simplicity in the design and implementation of security measures.

  2. Fail-safe defaults: This principle states that the default configuration of a system should have a conservative protection scheme.

  3. Complete mediation: The idea behind this principle is that every access to a resource must be checked for compliance with a protection scheme.

  4. Open design: According to this principle, the security architecture and design of a system should be made publicly available.

  5. Separation of privilege: This principle dictates that multiple conditions should be required to achieve access to restricted resources or have a program perform some action.

  6. Least privilege: Each program and user of a computer system should operate with the bare minimum privileges necessary to function properly.

  7. Least common mechanism: In systems with multiple users, mechanisms allowing resources to be shared by more than one user should be minimized.

  8. Psychological acceptability: This principle states that user interfaces should be well designed and intuitive, and all security-related settings should adhere to what an ordinary user might expect.

  9. Work factor: According to this principle, the cost of circumventing a security mechanism should be compared with the resources of an attacker when designing a security scheme.

  10. Compromise recording: This principle states that sometimes it is more desirable to record the details of an intrusion than to adopt more sophisticated measures to prevent it.


26
New cards

Encryption and Decryption

The message M is called the plaintext. Alice will convert plaintext M to an encrypted form using an encryption algorithm E that outputs a ciphertext C for м.
C = E(M)
M = D(C)
The encryption and decryption algorithms are chosen so that it is infeasible for someone other than Alice and Bob to determine plaintext M from ciphertext C. Thus, ciphertext C can be transmitted over an insecure channel that can be eavesdropped by an adversary.

27
New cards

Cryptosystem

1. The set of possible plaintexts

2. The set of possible ciphertexts

3. The set of encryption keys

4. The set of decryption keys

5. The correspondence between encryption keys and decryption keys

6. The encryption algorithm to use

7. The decryption algorithm to use

28
New cards

Caesar Cipher

Replace each letter with the one "three over" in the alphabet.

<p>Replace each letter with the one "three over" in the alphabet.</p>
29
New cards

Symmetric Cryptosystems

Alice and Bob share a secret key, which is used for both encryption and decryption.

<p>Alice and Bob share a secret key, which is used for both encryption and decryption.</p>
30
New cards

Symmetric Key Distribution

Requires each pair of communicating parties to share a (separate) secret key.

<p>Requires each pair of communicating parties to share a (separate) secret key.</p>
31
New cards

Public-Key Cryptography

Separate keys are used for encryption and decryption.
Bob has two keys: a private key, SB, which Bob keeps secret, and a public key, PB, which Bob broadcasts widely.

  • In order for Alice to send an encrypted message to Bob, she need only obtain his public key, PB, use that to encrypt her message, M, and send the result, C = EpB (M), to Bob. Bob then uses his secret key to decrypt the message as M = DsB (C).


<p>Separate keys are used for encryption and decryption.<br>Bob has two keys: a private key, SB, which Bob keeps secret, and a public key, PB, which Bob broadcasts widely. </p><ul><li><p>In order for Alice to send an encrypted message to Bob, she need only obtain his public key, PB, use that to encrypt her message, M, and send the result, C = EpB (M), to Bob. Bob then uses his secret key to decrypt the message as M = DsB (C).</p></li></ul><p></p>
32
New cards

Public Key Distribution

Only one key is needed for each recipient

<p>Only one key is needed for each recipient</p>
33
New cards

Digital Signatures

Public-key encryption provides a method for doing digital signatures

To sign a message, M, Alice just encrypts it with her private key, SA, creating C = EsA(M).

Anyone can decrypt this message using Alice's public key, as M' = DPA(C), and compare that to the message M.

34
New cards

Cryptographic Hash Functions

A checksum on a message, M, that is:

  • One-way: it should be easy to compute Y=H(M), but hard to find M given only Y

  • Collision-resistant: it should be hard to find two messages, M and N, such that H(M)=H(N).

  • Examples: SHA-1, SHA-256.


35
New cards

Buffer Overflow

a very common attack mechanism
A condition at an interface under which more input can be placed into a buffer or data holding area than the capacity allocated, overwriting other information.

Attackers exploit such a

  • condition to crash a system or

  • to insert a specially crafted code that allows

  • them to gain control of the system.

programming error when a process attempts to store data beyond the limits of a fixed sized buffer

overwrites adjacent memory locations

  • locations could hold other program variables, parameters, or program control flow data

buffer could be located on the stack, in the heap, or in the data section of the process


36
New cards

Buffer Overflow Attacks

to exploit a buffer overflow an attacker needs:

  • to identify a buffer overflow vulnerability in some program that can be triggered using externally sourced data under the attacker’s control

  • to understand how that buffer is stored in memory and determine potential for corruption

identifying vulnerable programs can be done by:

  • inspection of program source

  • tracing the execution of programs as they process oversized input

  • using tools such as fuzzing to automatically identify potentially vulnerable programs


37
New cards

Stack Buffer Overflows

occur when buffer is located on the stack

  • also referred to as stack smashing

  • used by Morris Worm

  • exploits included an unchecked buffer overflow

  • are still being widely exploited


38
New cards

Stack Frame

  • when one function calls another it needs somewhere to save the return address

  • also needs locations to save the parameters to be passed into the called function and to possibly save register values


39
New cards

Shellcode

  • code supplied by attacker

  • often saved in buffer being overflowed

  • traditionally transferred control to a user command-line interpreter (shell)


40
New cards

Machine Code

  • specific to processor and operating system

  • traditionally needed good assembly language skillsto create

  • more recently a number of sites and tools have been developed that automate this process


41
New cards

Buffer Overflow Defenses

  1. Compile Time: aim to harden programs to resist attacks in new programs

  2. Run-time: aim to detect and abort attacks in existing programs


42
New cards

Compile-Time Defenses: Programming Language

use a modern high level language

  • not vulnerable to buffer overflow attacks

  • compiler enforces range checks and permissible operations on variables

Disadvantages:

  • additional code must be executed at run time to impose checks

  • flexibility and safety comes at a cost in resource use

  • distance from the underlying machine language and architecture means that access to some instructions and hardware resources is lost

  • limits their usefulness in writing code, such as device drivers, that must interact with such resources


43
New cards

Compile-Time Defenses: Safe Coding Techniques

  • C designers placed much more emphasis on space efficiency and performance considerations than on type safety

  • programmers need to inspect the code and rewrite any unsafe coding

  • programmers have audited the existing code base, including the operating system, standard libraries, and common utilities


44
New cards

Compile-Time Defenses: Language Extensions / Safe Libraries

Handling dynamically allocated memory is more problematic because the size information is not available at compile time

  • requires an extension and the use of library routines

    • programs and libraries need to be recompiled

    • likely to have problems with third-party applications

concern with C is use of unsafe standard library routines

  • one approach has been to replace these with safer variants

    • Libsafe is an example

    • library is implemented as a dynamic library arranged to load before the existing standard libraries


45
New cards

Compile-Time Defenses: Stack Protection

  • add function entry and exit code to check the stack for signs of corruption

  • use random canary

    • value needs to be unpredictable

    • should be different on different systems

  • Stackshield and Return Address Defender (RAD)

    • GCC extensions that include additional function entry and exit code

    • function entry writes a copy of the return address to a safe region of memory

    • function exit code checks the return address in the stack frame against the saved copy

    • if change is found, aborts the program


46
New cards

Executable Address Space Protection

use virtual memory support to make some regions of memory nonexecutable

  • requires support from memory management unit (MMU)

  • long existed on SPARC / Solaris systems

  • recent on x86 Linux/ Unix/Windows systems

issues

  • support for executable stack code

  • special provisions are needed


47
New cards

Run-Time Defenses: Address Space Randomization

manipulate location of key data structures

  • stack, heap, global data

  • using random shift for each process

  • large address range on modern systems means wasting some has negligible impact

randomize location of heap buffers

random location of standard library functions

48
New cards

Run-Time Defenses: Guard Pages

place guard pages between critical regions of memory

further extension places guard pages between stack frames and heap buffers

49
New cards

Heap Overflow

attack buffer located in heap

no return address


defenses

  • heap non-executable

  • randomizing the allocation of memory on the heap


50
New cards

Global Data Overflow

can attack buffer located in global data


defenses

  • non executable or random global data region

  • move function pointers

  • guard pages


51
New cards

Malware

is software that enters a computer system without the user’s knowledge or consent and then performs an unwanted and harmful action

52
New cards

Imprison: Ransomware

prevents a user’s endpoint device from properly and fully functioning until a fee is paid

<p>prevents a user’s endpoint device from properly and fully functioning until a fee is paid</p>
53
New cards

Imprison: Cryptomalware

is a type of malware that imprisons users and encrypts all files on the device so that none of them can be opened

<p>is a type of malware that imprisons users and encrypts all files on the device so that none of them can be opened</p>
54
New cards

Launch: Virus

There are two types of viruses: a file-based virus and a fileless virus

• A file-based virus is malicious code that is attached to a file that reproduces itself on the

same computer without any human intervention

• An armored file-based virus goes to great lengths to avoid detection

• Techniques include split infection and mutation

• The virus first unloads a payload to perform a malicious action, then the virus replicates itself by inserting its code into another file (on the same computer)

55
New cards

Launch: fileless virus

does not attach itself to a file but instead takes advantage of native services and processes that are part of the OS to avoid detection and carry out its attacks

56
New cards

Launch: Worm

is a malicious program that uses a computer network to replicate (sometimes called a network virus)

Designed to enter a computer through the network and then take advantage of a vulnerability in an application or an OS on the host computer

Actions that worms have performed include deleting files on the computer or allowing the computer to be remotely controlled by an attacker

57
New cards

Launch: Bot

Another type of malware allows the infected computer to be placed under the remote control of an attacker for the purpose of launching attacks

When hundreds, thousands, or even millions of bot computers are gathered into a logical computer network, they create a botnet under the control of a bot herder

Infected bot computers receive instructions through a command and control (C&C) structure from the bot herders

58
New cards

Snoop: Spyware

is tracking software that is deployed without the consent or control of the user

59
New cards

Snoop: Keylogger

  • A keylogger silently captures and stores each keystroke that a user types on the computer’s keyboard

  • The threat actor can then search the captured text for any useful information such as passwords, credit card numbers, or personal information

  • A keylogger can be a software program or a small hardware device


60
New cards

Deceive: Potentially Unwanted Program (PUP)

A PUP is software that the user does not want on their computer

61
New cards

Deceive: Trojan

A computer Trojan is an executable program that masquerades as performing a benign activity but also does something malicious

62
New cards

Deceive: Remote Access Trojan (RAT)

  • A RAT has the basic functionality of a Trojan but also gives the threat agent unauthorized remote access to the victim’s computer by using specially configured communication protocols

  • This creates an opening to the victim’s computer allowing the threat agent unrestricted access


63
New cards

Evade: Backdoor

A backdoor gives access to a computer, program, or service that circumvents any normal security protections

64
New cards

Evade: Logic bomb

A logic bomb is computer code that is typically added to a legitimate program but lies dormant and evades detection until a specific logical event triggers it

65
New cards

Evade: Rootkits

A rootkit is malware that can hide its presence and the presence of other malware on the computer

66
New cards
67
New cards

cross-site scripting (XSS) Attack

  • a website that accepts user input without validating it and uses that input in a response can be exploited

  • An attacker can take advantage in an XSS attack by tricking a valid website into feeding a malicious script to another user’s web browser


<ul><li><p>a website that accepts user input without validating it and uses that input in a response can be exploited </p></li><li><p>An attacker can take advantage in an XSS attack by tricking a valid website into feeding a malicious script to another user’s web browser</p></li></ul><p></p>
68
New cards

Injection

Attacks called injections introduce new input to exploit a vulnerability

One of the most common injection attacks (SQL injection) inserts statements to manipulate a database server

• SQL stands for Structured Query Language

• SQL injection targets SQL servers by introducing malicious commands into them

• By entering crafted SQL statements as user input, information from the database can be extracted or the existing can be manipulated

69
New cards

Request Forgery: Cross-Site Request Forgery (CSRF)

CSRF takes advantage of an authentication “token” that a website sends to a user’s web browser

If a user is currently authenticated on a website and is then tricked into loading another webpage, the new page inherits the identity and privileges of the victim, who may perform an undesired function on the attacker’s behalf

<p>CSRF takes advantage of an authentication “token” that a website sends to a user’s web browser</p><p>If a user is currently authenticated on a website and is then tricked into loading another webpage, the new page inherits the identity and privileges of the victim, who may perform an undesired function on the attacker’s behalf</p>
70
New cards

Request Forgery: Server-Site Request Forgery (SSRF)

• An SSRF takes advantage of a trusting relationship between web servers

• SSRF attacks exploit how a web server processes external information received from another server

• Some web applications are designed to read information from or write information to a specific URL

• If an attacker can modify that target URL, they can potentially extract sensitive information from the application or inject untrusted input into it

<p>• An SSRF takes advantage of a trusting relationship between web servers</p><p>• SSRF attacks exploit how a web server processes external information received from another server</p><p>• Some web applications are designed to read information from or write information to a specific URL</p><p>• If an attacker can modify that target URL, they can potentially extract sensitive information from the application or inject untrusted input into it</p>
71
New cards

Replay

Replay attacks are commonly used against digital identities

  • After intercepting and copying data, the threat actor retransmits selected and edited portions of the copied communications later to impersonate the legitimate user

Many digital identity replay attacks are between a user and an authentication server

72
New cards

Attacks on Software: Memory Vulnerabilities

• Some memory-related attacks are called resource exhaustion attacks because they “deplete” parts of memory and thus interfere with the normal operation of the program in RAM

• Other memory-related attacks attempt to manipulate memory contents such as buffer overflow attacks and integer overflow attacks

• A buffer overflow attack occurs when a process attempts to store data in RAM beyond the boundaries of a fixed-length storage buffer

  • This extra data overflows into the adjacent memory locations

• In an integer overflow attack, an attacker changes the value of a variable to something outside the range that the programmer had intended by using an integer overflow

73
New cards

Attacks on Software: Improper Exception Handling

• Some attacks are the result of poor coding on the part of software developers

• Software that allows the user to enter data but has improper input handling features does not filter or validate user input to prevent a malicious action

• Another improper exception handling situation is a NULL pointer/object dereference

  • When an application dereferences a pointer that has a value of NULL, it typically will cause a program to crash or exit


74
New cards

Attacks on Software: Attacks on External Software Components

• In addition to attacking the software directly, threat actors also target external software components

• These include the following:

  • Application program interface (API)

  • Device driver

  • Dynamic-link library (DLL)


75
New cards

Which type of application attack might use the following syntax? ‘whatever’ AND email IS NULL;

SQL injection

76
New cards

Which of the following is a concern of using AI and ML in cybersecurity?

Tainted training data

77
New cards

Use the knowledge about malware you gained from this module to answer the following question: With the trend towards employees working from home, which type of malware do you think presents the most risk for organizations and their employees? Why? What are some things that can be done to mitigate the risks?

Ransomware and Remote Access Trojans (RATs) present the greatest risk to work-from-home environments because remote employees often operate on less secure home networks, enabling attackers to easily gain unauthorized control or encrypt critical shared corporate data. These risks can be mitigated by enforcing Multi-Factor Authentication (MFA), deploying Endpoint Detection and Response (EDR) tools, securing remote access with VPNs, and conducting regular phishing awareness training.

78
New cards

Attack Vectors

An attack vector is a pathway or avenue used by a threat actor to penetrate a system

79
New cards

Social Engineering Attacks

Social engineering is a means of eliciting information (gathering data) by relying on the weaknesses of individuals

80
New cards

Social Engineering Attacks: Impersonation

is masquerading as a real or fictitious character and then playing the role of that person with a victim

81
New cards

Social Engineering Attacks: Phishing

is sending an email message or displaying a web announcement that falsely claims to be from a legitimate enterprise in an attempt to trick the user into surrender private information or taking action

82
New cards

Social Engineering Attacks: Redirection

is when an attacker directs a user to a fake lookalike site filled with ads for which the attacker receives money for traffic generated to the site

83
New cards

Social Engineering Attacks: Spam

is unsolicited email that is sent to a large number of recipients

<p>is unsolicited email that is sent to a large number of recipients</p>
84
New cards

Social Engineering Attacks: Hoaxes

are false warnings, often contained in an email message claiming to come from the IT department

85
New cards

Social Engineering Attacks: Physical Procedures

  • Dumpster Diving involves digging through trash receptacles to find information that can be useful in an attack

  • Tailgating occurs when an authorized person opens an entry door, one or more individuals can follow behind and also enter

  • Shoulder Surfing allows an attacker to casually observe someone entering secret information, such as the security codes on a door keypad


86
New cards

Which type of attack is NOT a form of social engineering attack?

Zero day

87
New cards
<p>MitM and MitB attacks</p>

MitM and MitB attacks

88
New cards
<p>Privilege Escalation</p>

Privilege Escalation

89
New cards
<p>DNS Hijacking/ Poisoning</p>

DNS Hijacking/ Poisoning

90
New cards
<p>ARP Spoofing Attack</p>

ARP Spoofing Attack

91
New cards
<p>TCP/IP Hijacking</p>

TCP/IP Hijacking

92
New cards
<p>DoS and DDoS</p>

DoS and DDoS

93
New cards
<p>Smurf Attack</p>

Smurf Attack

94
New cards
<p>Spoofing</p>

Spoofing

95
New cards
<p>Driver Manipulation</p>

Driver Manipulation

96
New cards
<p>Refactoring</p>

Refactoring

97
New cards
<p>Pass the Hash</p>

Pass the Hash

98
New cards
<p>Typosquatting</p>

Typosquatting