1/34
Vocabulary flashcards covering key terms, cyber operations, international law principles, power metrics, threat classifications, and hacker types from the provided lecture notes.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Computer Network Exploitation (CNE)
Spying using computers to infiltrate target networks to extract and gather sensitive intelligence data.
Computer Network Attack (CNA)
Operations that include actions designed to destroy or otherwise incapacitate enemy networks.
GhostNet
A vast electronic spying operation discovered in 2009 that infiltrated at least 1,295 computers in 103 countries, including those of the Dalai Lama.
Red October
A highly sophisticated cyber-espionage campaign discovered in 2013 targeting governmental, political, and research institutions using malware with a resurrection mode.
The Mask (Careto)
An advanced persistent threat campaign likely backed by an unknown Spanish-speaking national government that silently intercepted sensitive data from government agencies and energy companies starting in 2007.
Advanced Persistent Threat (APT)
A sophisticated cyber campaign directed by highly skilled attackers aimed at infecting, spying on, and stealing from specific, highly sought-after targets over a long period.
OSINT (Open Source Intelligence)
Overtly available information found, selected, and acquired from publicly available sources.
HUMINT (Human Intelligence)
Intelligence collected through interpersonal contact via human collection officers, which can provide accurate internal network information and bridge air-gapped systems.
CYBERINT (Cyber Intelligence)
Obtaining prior knowledge of threats and vulnerabilities to information communications systems through a variety of technical means.
Intelligence Preparation of the Battlespace (IPB)
Providing an understanding of the physical, political, electronic, cyber, and other dimensions of the battlespace to aid decision-making.
jus ad bellum
The laws determining when resorting to war is justified and what constitutes an act of war.
jus in bello
The rules for lawful conduct of armed conflict after the decision to resort to military action is made, imposing duties to use restraint and minimize suffering.
Distinction
A principle of jus in bello requiring combatants to ensure attacks are directed at legitimate military objectives and to minimize collateral damage.
Necessity
A principle of jus in bello stating that the application of force must be limited to only the amount necessary to accomplish a valid military objective.
Proportionality
A principle of jus in bello limiting the use of force to situations in which the expected military advantage outweighs the expected collateral damage to civilians.
UN Charter Article 2(4)
Requires UN members to refrain in their international relations from the threat or use of force against the territorial integrity or political independence of any state.
UN Charter Article 51
Ensures the inherent right of individual or collective self-defense if an armed attack occurs against a member of the United Nations.
Tallinn Manual
A document created by international law scholars that identifies the international law applicable to cyber warfare and sets out black-letter rules governing such conflicts.
Rule 1 (Sovereignty)
A state may exercise control over cyber infrastructure and activities within its sovereign territory.
Rule 11 (Use of Force)
A cyber operation constitutes a use of force when its scale and effects are comparable to non-cyber operations rising to the level of a use of force.
levée en masse
In an international armed conflict, inhabitants of unoccupied territory who engage in cyber operations as part of a general uprising to repel an invasion enjoy combatant immunity.
Cyber Power
The ability of a nation-state to establish control and exert influence within and through cyberspace, in support of and in conjunction with other domain-elements of national power.
Composite Index of National Capabilities (CINC)
An indexed variable creating a single robust measure of power based on resources, calculated as CINCScore=6x1+x2+x3+x4+x5+x6.
Cyber Power Index Equation
A formula for digital power weighted by various infrastructure and regulatory factors, calculated as CyberPower=NDV(MUD+LRF+ESC+TI+IA+MBA)×TSC.
Cyber Power Simplified Equation
An unweighted calculation of a nation's cyber power defined as CyberPower=DF×T, where F is theoretical cyber force, T is demonstrated threat capability, and D is digital vulnerability.
National Digital Vulnerability
The systemic vulnerability of a nation to threats emanating from cyberspace, typically measured by the percentage of individuals within the country using the Internet.
Threat (Agent)
Anything capable of performing unauthorized actions against software or systems, possessing skills, access, and resources.
Unstructured Threat
Attacks typically mounted by a single person or a small, loosely affiliated group, using well-documented flaws and going after low-hanging fruit.
Structured Threat
Organized groups of attackers, such as criminal syndicates or hacking groups, who deliberately choose specific targets and rely on slow scanning or previously unpublished flaws.
Highly Structured Threat
Highly organized actors, such as nation-states or terrorists, who devote large amounts of time to coordinate efforts and utilize zero-day attacks.
Opportunistic Attack
An attack using a brute-force approach against thousands of targets to find a handful of vulnerable systems, often for financial gain.
Focused Attack
An attack that seeks to compromise a specific system or individual user via highly sophisticated, custom-designed attack mechanisms.
Black Hat Hackers
Individuals who use their skills with malicious intent to damage, destroy, disrupt, or further a financial or political agenda.
White Hat Hackers
Security professionals who use their skills to help improve security for an organization or the industry.
Gray Hat Hackers
Individuals who help expose flaws in organizations or technology without the permission of the vendor or organization.