1/93
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
CIAAAN
1. Confidentiality
2. Integrity
3. Availability
4. Authentication
5. Access Control
6. Non-Repudiation
Confidentiality
Keeping information secret from all except authorized users
Integrity
Ensuring data has not been altered by unauthorized users
Availability
Making sure data and services are available at all times
Access Control
Controlled access to resources based on user privileges
Non-repudiation
Preventing denial of previous commitments
Passive Attack
Attempts to view or make use of system information that does not affect resources
Active Attacks
Attempts to alter system resources or affect their operation.
Interception Attack
A passive attack where the attacker reads the contents of a message without changing it
Fabrication Attack
An active attack where the attacker sends info while pretending it's from a reliable resource
Interruption Attack
An active attack where the attacker cuts the connection between the target and the intended receiver
Modification Attack
An active attack where the attacker tampers with information in transition
Goals of security
1. Prevent
2. Detect
3. Respond
4. Recover
Single Loss Expectancy (SLE)
Asset Value X Exposure Factor
Annual Loss Expectancy
Single Loss Expectancy X Annual Rate Occurrence
Malware
Software with a malicious purpose
Virus
One of the two most common types of malware.
Designed to replicate and spread
Trojan Horse
The second most common type of malware.
Appears benign but secretly downloads malware to pc from within
Spyware
Software that tracks user activity and steals info
Logic bombs
Lay dormant until a specific condition is met, often a specific date
Hacking
The act of exploiting weaknesses in a system
Cracking
Unauthorized access to a computer system with malicious intent
Social Engineering
Manipulating or deceiving people into revealing confidential information or compromising security in any way
War-driving
Searching for unsecured Wi-FI connections while driving with a wireless-enabled device
War-dialing
Automatically dialing a large range of phone numbers to identify modems that can be exploited for unauthorized access
White Hat Hackers
Ethical hackers who are hired by companies in order to improve system security
Black Hat Hackers
Unethical hackers who maliciously exploit systems for personal gain
Grey Hat Hackers
A cross between black and white—they will often illegally break into systems merely to flaunt their expertise to the administrator of the system they penetrated, or to attempt to sell their services in repairing security breaches.
OSI model layers in order
Application
Presentation
Session
Transport -> Segments
Network -> Packets
Data Link -> Frames
Physical -> Bits
TCP
Transmission Control Protocol
Provides the most accurate, reliable transmission of data during the transport layer.
Includes acknowledgments and sequencing numbers
UDP
User Datagram Protocol
Provides the fastest data transmission at the network layer.
Personal Area Network (PAN)
Scale: Human
Distance: A few meters
Local Area Network (LAN)
Scale: Room or building
Distance: 100 meters or less
Campus Area Network (CAN)
Scale: Clusters of building
Distance: 1 mile or less
Metropolitan Area Network (MAN)
Scale: City
Distance: A few miles
Wide Area Network (WAN)
Scale: State, country, global
Distance: Up to thousands of miles
Bus Network Topology
All devices connect to a single central cable line.
Easy to set up, but prone to collisions
Ring Network Topology
Devices connect in a circular fashion, and data moves in one direction.
Avoids collisions by passing a token around, with the holder being the only one allowed to send data
Star Network Topology
Every device is connected to a central device, like a switch
Hub-and-Spoke Network Topology
Same as star topology, except that it connects networks rather than devices
Full Mesh Network Topology
Every device is connected to every other device, so no single device failure can bring down the network.
Partial Mesh Network Topology
Similar to full-mesh, except that only crucial devices have redundant paths between each other
Client-Server
Network architecture where client devices make requests, while server devices only respond to client devices
Peer-to-peer
Files or services shared between PCs, with each one being able to control permissions locally
Symmetric Key Encryption
The same key is used to encrypt and decrypt the message
Popular Symmetric Encryption Algorithms
1. DES - oldest, least secure.
2. 3DES - performs DES 3 times with improved key size
3. AES - Most widely used
Electronic Codebook Mode (ECB)
Each block of plaintext is encrypted independently of the others
Cipher Block Chaining Mode (CBC)
Each block of ciphertext is dependent on the last
Message Authentication Code (MAC)
A message is encrypted and then hashed; the resulting digest is then sent along with the message. The receiver then hashes the original message and compares it to the received digest. If they match, then the message was not tampered with in transmission.
Public Key Certification
Certifying that a public key belongs to a specific entity.
When you visit a site, it presents you with its information and a certificate signed by a CA. Your PC hashes the info and then compares the digest to the certificate sent to you (after it was deciphered with the CA's public key).
Digital Envelope
How a secure session is created between your PC and another entity. Your PC creates a new random symmetric key, which is then encrypted using the receiver's public key. Now a common key has been securely sent and symmetric encryption can begin
Digital signature
a means of electronically signing a document with data that cannot be forged. A message is hashed and encrypted with the sender's private key, then sent. The receiver then decrypts using the sender's public key. If it works, then the data is untampered and sent from the expected source.
Identity Assurance Level 1
No need to link the applicant to a specific real-life identity
Identity Assurance Level 2
Provide evidence for the claimed identity with remote proofing
Identity Assurance Level 3
Requires physical presence
Authenticator Assurance Level 1
Authentication through ID and password
Authenticator Assurance Level 2
Requires possession of two authentication factors
Authenticator Assurance Level 3
Requires possession of two authentication factors, with them being hardware-based
Secret
Password, PIN, answers to prearranged questions
Token
Smart card, electronic keycard
Static Biometrics
Fingerprints, retina, face
Dynamic Biometrics
Voice pattern, handwriting characteristics, and typing rhythm
Salt
A random string of characters that is added to a password before it is hashed; this adds security by making dictionary attacks much harder to complete
Dictionary Attack
A password attack that creates encrypted versions of common passwords and compares them against those in a stolen password file.
Rainbow Table Attack
attempts to discover the password from the hash using databases of precomputed hashes for all salts
Subject
An entity capable of accessing the database
1. Owner
2. Group
3. Others
Object
A resource to which access is controlled
Access Rights
Describes how a subject may access an object
Discretionary Access Control (DAC)
Controls access based on the identity of the requester
Mandatory Access Control (MAC)
Controls access based on comparing security labels with security clearances
Role-Based Access Control (RBAC)
Controls access based on the roles that users have within the system and on rules stating what accesses are allowed to users in given roles
Attribute-based access control (ABAC)
Controls access based on attributes of the user, the resource to be accessed, and current environmental conditions
Typical Access Rights
select, insert, update, delete, references
SOCK_STREAM
Socket type for TCP connections.
SOCK_DGRAM
Socket type for UDP communication.
Steps to set up a TCP server
1. Create a socket
2. Bind to port number
3. Listen for connections
4. Accept Connection requests
5. Send and receive data
SYN flag
This flag is used when first establishing a TCP connection to make sure the receiving end knows to examine the sequence number field
ACK flag
Flag response from receiver to acknowledge SYN flag.
Confirms connection
FIN flag
Indicates termination of a TCP connection
RST flag
Reset flag resets or drops a connection
3-Way Handshake (TCP)
SYN, SYN/ACK, ACK
SYN flooding attack
Attacker fills up the victim's SYN request queue by sending a multitude of requests using spoofed IPs
SYN cookies
Countermeasure to SYN flooding attacks. Instead of leaving connections half-open, the server will take the received data, hash it, and send it back. If the request is legitimate, the info will come back (+1), and the server will rehash it. If it matches the original value, then it will open up a connection.
Reflection Attacks
Attacker sends requests to an intermidiate server, but with the victim's spoofed ip. Therefore, the server floods the victim with inrequited responses
DNS Amplification
Attack which relies on the large amount of DNS information that is sent in response to a spoofed query on behalf of the victimized server
Smurf IP Attack
When an attacker pings a bunch of machines using the victim's IP, it leads to all those devices flooding the victim with unrequited ping responses
SSH port
22
Telnet port
23
SMTP port
25
FTP port
20, 21
DNS port
53
HTTP Port
80
TFTP port
69
HTTPS port
443