CS 3237 Cram Sheet

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/34

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 4:49 AM on 9/29/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

35 Terms

1
New cards

Cybersecurity

The engineering, operation and governance of trustworthy computing systems in the presence of intelligent adversaries

2
New cards

Course framing

Humans are the foremost vulnerability. Treat cybersecurity as a "social problem + technology", not a "technical problem + humans"

3
New cards

Orders of harm

1st: denial of service, degraded network, physical destruction, data theft/espionage. 2nd: user harms, cybersecurity behavior, trauma/anxiety/fear, threat perception. 3rd: national security, distrust in digital institutions, compromised privacy, commercial and electoral effects

4
New cards

Security attributes

Confidentiality, Integrity, Availability (CIA)

5
New cards

Dependability

Availability, reliability, safety, integrity, maintainability

6
New cards

Attack chain

Adversary Exploits a Vulnerability to cause a Technical Impact, which causes a broader impact. Anatomy: threat agents, attack vectors, security weaknesses, security controls, technical impacts, business impacts

7
New cards

Controls taxonomy

Fault prevention, fault tolerance, fault removal, fault forecasting

8
New cards

Risk

Risk = Threat × Vulnerability × Impact

9
New cards

Threat modeling (4 questions)


What are we working on / trying to protect (and from whom)? What can go wrong? What are we going to do about it? Did we do a good enough job?

10
New cards

Thinking as a defender

Security policy, threat model, risk assessment, countermeasures

11
New cards

Mickens

Your adversary is either Mossad or not-Mossad

12
New cards

Political psychology model

Cybersecurity event → emotional reaction → decision-making / attitudes and behaviors

13
New cards

Emotions from cyberattacks

Anger, fear/anxiety, perplexity

14
New cards

Cyber vs conventional attacks

Extenuating: less destructive, frequency of attacks, swifter timeframes. Exacerbating: complexity of the domain, broader attack surface, anonymity/attribution difficulties

15
New cards

Decision-making factors

Psychological (risk aversion, acting under pressure, anxiety, cognitive capacity). Socio-demographic (age, gender, political orientation, digital literacy). Situational (attacker identity, outcome, target, motivation)

16
New cards

Cognitive biases

Anchoring, confirmation, sunk cost fallacy. Also used against attackers: availability heuristic, scarcity/urgency

17
New cards

Reducing bias

Slow down and use structured decisions; seek disconfirming evidence; use data and metrics with stop conditions set in advance

18
New cards

Trust

A trusts B to do X. The willingness to be vulnerable based on positive expectations of an action

19
New cards

Trustworthiness

Ability, Benevolence, Integrity

20
New cards

Trust propensity


A stable personality predisposition to trust

21
New cards

Trust in technology


Functionality, helpfulness, reliability

22
New cards

Trust in AI

Promote it via anthropomorphization, algorithmic transparency (explainable AI), procedural accountability. Biases: automation bias vs algorithmic aversion

23
New cards

Schneider

The main danger is an accumulation of smaller attacks eroding public trust in government institutions

24
New cards

Agrafiotis harm types

Physical/digital, economic, psychological, reputational, social/societal

25
New cards

Ransomware harms to staff (Mott et al.)

Physical, economic, psychological, reputational, social/societal

26
New cards


IoT hacking victims (Rostami et al.)

Have I been hacked? Who hacked me? Why was I hacked? Dealing with the hack

27
New cards

Suler's six factors

Dissociative anonymity, invisibility, asynchronicity, solipsistic introjection, dissociative imagination, minimization of authority

28
New cards

Dark Tetrad

Machiavellianism, psychopathy, narcissism, sadism

29
New cards

Criminological theories

Rational choice, deterrence, self-control, social learning, neutralization

30
New cards

Xu et al. pathway

Affection for computers → curious exploration (initiation) → illicit excursion (growth) → criminal exploitation (maturation)

31
New cards

Hacker motivations (Chng et al.)

Curiosity, financial, notoriety, revenge, recreation, ideology, sexual impulses

32
New cards

Adversarial inference

Evidence → adversary hypotheses (motivation, resources, methods) → expected behavior → defensive decision → uncertainty

33
New cards

UI-bound adversary

Authenticated but adversarial user who exploits familiarity with the victim and/or device access, limited to what the UI allows

34
New cards

IPV attack categories

Ownership-based access, account/device compromise, exposure of private information

35
New cards