1/49
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Access Control (AC)
Rules that govern what Identities can access which resources.
Access Control List (ACL)
Defines rights for each resource, from the perspective of the resource.
Capability List (CL)
Defines rights for each subject, from the perspective of the subject.
Discretionary Access Control (DAC)
Access is defined by the owner of the file.
Role-Based Access Control (RBAC)
Access is defined by a person's job or title.
Attribute Based Access Control (ABAC)
Access is defined by various parameters like work shift, location, or department(attributes), offering more flexibility then roles.
Mandatory Access Control (MAC)
Access Clarification that discriminates security policies into different types usually based on department or data sensitivity. (Bell LaPadula/Biba)
Bell LaPadula
Restricts confidentiality, allowing information flow from lower to higher security levels
NO READ UP
NO WRITE DOWN

Biba Model
Supports integrity limiting information flow from higher to lower levels.
NO READ DOWN
NO WRITE UP

Access Control Matrix
Extensively defines access rules in detail by individual rights for all subjects and objects.
Clark Wilson Model
A policy model that enforces integrity through certification and auditing.
Availability
Security principle that resources are accessible.
Confidentiality
Security principle that information should only be shared with appropriate parties.
Integrity
Security principle that communication should not be modified between parties.
Protocol
Defines what actions are to be taken to implement security goals.
Practice
Implements the actions in attaining security
Polymorphic Virus
Changes its code without changing its algorithm to evade static detection.
Logic Bomb
A Program that resides in the background until a specific sets of facts occurs
Autorun Virus
A virus that runs as soon as a disk or (USB) is started. "Boot sector viruses and rootkits are related but aren't on exam."
Trojan Horse
A malicious program that looks and acts like a benign program.
Worm
A malicious program that replicates and propagates on its own.
Stealth Virus
Catches kernel traces and calls to remove any revealing details.
Update Trojan
A malicious program disguised as a software update, leveraging normal maintenance procedures.
Distributed Denial of Service
An attack that uses multiple agents against a single victim to deny availability
Social Engineering
Using society's norms and expectations as a method to generate a desired response.
Side-Channel Attack
An attack that uses signals recovered during an indirect method of reception
Man-In-The-Middle
An attack conducted by an individual watching packets in the communication handshake process
Brute Force
An attack where all possible combinations (passwords) are attempted.
Phising
An email designed and sent to an unsuspecting victim to solicit into taking various actions( African Prince, single email)
Catfishing
A formal social engineering technique where a series of texts, or emails are used to gain the confidence of a potential victim (Multiple Interactions)
Spear Phising
A phishing attempt directed at a specific individual or company, tailored to their intrests.
Spoofing
Creating a fake object (like a login page, Randall did to his teacher) designed to open an attack surface against someone who uses it.
Buffer Overflow
Pushing an input value past the edge of memory allocated
Dumpster Diving
The act of targeting the recycle bin for secrets
Zero-Day
An attack or vulnerability seen in the public for the first time
Penetration Tester
An outside party hired to validate a company's security
Shoulder Surfing
Watching while someone types a password
Reverse Engineering
To break apart an application to figure out how it works by generating source code from the applications code and examining it,
Fratenize
Building an individual relationship for either benign or malfeasant purposes.
Port Probing
A research methodology that scans remote targets for potential attack openings.
Cascading
A method for defining rule priority by only following the first rule activated
Steganography
The act of hiding data within plain sight in another medium
SSH (secure shell)
An application layer protocol that ensures secrecy regardless of the underling network security. It was developed to provide secure remote access over unencrypted protocols like Telnet.
CVE( Common Vulnerbailites and Exposures)
A real time online public library with descriptions of known attack vectors and mitigating methods of all systems worldwide.
File System Structure of Linux
Linux uses a hierarchal file system starting with the root directory /(root)
Key directories include:
/bin (essential user command binaries)
/usr/bin (most user commands)
/lib,/lib32, lib64 Contain shared libraries for binaries.
Permissions
Linux permissions are represented in three groups (owner, group, others) and three types (read, write, execute)
D: Denotes a directory
R: Read Permission
W: Write Permission
X: Execute Permission
Redirection Links
Used to Point other directories or files, optimizing the file system structure.
Virus
attach itself to other code to propagate.
Firewall
Used to limit communication between internet networks
Script Virus
A virus composed of a sequence of instructions that are interpreted rather then executed directly (visual basic)