1/34
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Cybersecurity
The engineering, operation and governance of trustworthy computing systems in the presence of intelligent adversaries
Course framing
Humans are the foremost vulnerability. Treat cybersecurity as a "social problem + technology", not a "technical problem + humans"
Orders of harm
1st: denial of service, degraded network, physical destruction, data theft/espionage. 2nd: user harms, cybersecurity behavior, trauma/anxiety/fear, threat perception. 3rd: national security, distrust in digital institutions, compromised privacy, commercial and electoral effects
Security attributes
Confidentiality, Integrity, Availability (CIA)
Dependability
Availability, reliability, safety, integrity, maintainability
Attack chain
Adversary Exploits a Vulnerability to cause a Technical Impact, which causes a broader impact. Anatomy: threat agents, attack vectors, security weaknesses, security controls, technical impacts, business impacts
Controls taxonomy
Fault prevention, fault tolerance, fault removal, fault forecasting
Risk
Risk = Threat × Vulnerability × Impact
Threat modeling (4 questions)
What are we working on / trying to protect (and from whom)? What can go wrong? What are we going to do about it? Did we do a good enough job?
Thinking as a defender
Security policy, threat model, risk assessment, countermeasures
Mickens
Your adversary is either Mossad or not-Mossad
Political psychology model
Cybersecurity event → emotional reaction → decision-making / attitudes and behaviors
Emotions from cyberattacks
Anger, fear/anxiety, perplexity
Cyber vs conventional attacks
Extenuating: less destructive, frequency of attacks, swifter timeframes. Exacerbating: complexity of the domain, broader attack surface, anonymity/attribution difficulties
Decision-making factors
Psychological (risk aversion, acting under pressure, anxiety, cognitive capacity). Socio-demographic (age, gender, political orientation, digital literacy). Situational (attacker identity, outcome, target, motivation)
Cognitive biases
Anchoring, confirmation, sunk cost fallacy. Also used against attackers: availability heuristic, scarcity/urgency
Reducing bias
Slow down and use structured decisions; seek disconfirming evidence; use data and metrics with stop conditions set in advance
Trust
A trusts B to do X. The willingness to be vulnerable based on positive expectations of an action
Trustworthiness
Ability, Benevolence, Integrity
Trust propensity
A stable personality predisposition to trust
Trust in technology
Functionality, helpfulness, reliability
Trust in AI
Promote it via anthropomorphization, algorithmic transparency (explainable AI), procedural accountability. Biases: automation bias vs algorithmic aversion
Schneider
The main danger is an accumulation of smaller attacks eroding public trust in government institutions
Agrafiotis harm types
Physical/digital, economic, psychological, reputational, social/societal
Ransomware harms to staff (Mott et al.)
Physical, economic, psychological, reputational, social/societal
IoT hacking victims (Rostami et al.)
Have I been hacked? Who hacked me? Why was I hacked? Dealing with the hack
Suler's six factors
Dissociative anonymity, invisibility, asynchronicity, solipsistic introjection, dissociative imagination, minimization of authority
Dark Tetrad
Machiavellianism, psychopathy, narcissism, sadism
Criminological theories
Rational choice, deterrence, self-control, social learning, neutralization
Xu et al. pathway
Affection for computers → curious exploration (initiation) → illicit excursion (growth) → criminal exploitation (maturation)
Hacker motivations (Chng et al.)
Curiosity, financial, notoriety, revenge, recreation, ideology, sexual impulses
Adversarial inference
Evidence → adversary hypotheses (motivation, resources, methods) → expected behavior → defensive decision → uncertainty
UI-bound adversary
Authenticated but adversarial user who exploits familiarity with the victim and/or device access, limited to what the UI allows
IPV attack categories
Ownership-based access, account/device compromise, exposure of private information