• Shuffle
    Toggle On
    Toggle Off
  • Alphabetize
    Toggle On
    Toggle Off
  • Front First
    Toggle On
    Toggle Off
  • Both Sides
    Toggle On
    Toggle Off
Front

How to study your flashcards.

Right/Left arrow keys: Navigate between flashcards.right arrow keyleft arrow key

Up/Down arrow keys: Flip the card between the front and back.down keyup key

H key: Show hint (3rd side).h key

image

PLAY BUTTON

image

PLAY BUTTON

image

Progress

1/183

Click to flip

183 Cards in this Set

  • Front
  • Back
Privilege escalation
Exploiting a bug in software to gain elevated privileges.
For example Buffer overflow exploit of a web browser might allow a virus, rootkit or trojan to run with system privileges rather than logged on user.
Virus
code designed to infect computer files or disks. Could also delete or change system settings or files
worm
type of virus that spreads through memory and network connections rather than infecting files
trojan
Malware that is disguised as another program to trick the user into installing it
spyware
software that monitors the users activities. Installed without user consent. Key logging
spam
junk messages sent over email
adware
software that monitors users internet activity and displays correspondingly targeted ads or collects data for marketing purposes
rootkits
typically a trojan that modifies system files often at the kernel level to conceal its presense
botnet
a network of computers that have been compromised by a trojan/rootkit/worm malware.. Can be used for identity theft or spam amoung other things
logic bomb
malicious code that is set to run under particular circumstances or in responce to a defined event.
System risks as pertaining to the BIOS
Boot order allows hacker to insert any type of malicious code on to the network
System risks as pertaining to USB devices
Theft of the device, data theft, unauthorized software or services
System risks as pertaining to Cell phones
Triangulation, privacy, theft, sim card cloning
What is triangulation
The carrier can use the cell system to triangulate the location of a phone within a few meters
Define privacy as it applies to cell phones
It is possible to intercept digital mobile communications using a digital trunking scanner
System risks as pertaining to the BIOS
Boot order allows hacker to insert any type of malicious code on to the network
System risks as pertaining to USB devices
Theft of the device, data theft, unauthorized software or services
System risks as pertaining to Cell phones
Triangulation, privacy, theft, sim card cloning
What is triangulation
The carrier can use the cell system to triangulate the location of a phone within a few meters
Define privacy as it applies to cell phones
It is possible to intercept digital mobile communications using a digital trunking scanner
System risks as pertaining to Removeable storage
capacity and ease of portability, allow data theft
theft, delivering infected files via the removeable storage
System risks as pertaining to network attached storage
Exploit attack of the NAS OS gaining access to the data. Also istallation of rogue NAS devices
Hotfix
update designed for and released to particular customer. May be included in later service packs
Service pack
A collection of software updates, hotfixes and in some cases new features and enhancements
Patch
Minor updates to programs that are distributed with only the changes and not the whole program
Patch management
identifiing, testing, and deploying application and OS updates
group policies
on windows domain per user and per computer settings can be deployed via group policy objects, attached to active directory containers such as domains and organization units. Group policy can be used to configure security settings such as password policies, account restictions, firewall status.
security templates
settings for service and policy configuration for a server operating in a certain role (web server, mail server, file/print server)
what can be used to compare the current configuration of a server to the baseline identified in a security template
Security configuration and analysis tool
configuration base lines
settings for services and policy for a server operating in a particular role (web server, mail server...)
Appropriate procedures to establish application security for ActiveX
educate users , browser settings Vendors can sign using certificates
Appropriate procedures to establish application security for Java
should only be enabled on sites that have been confirmed as safe for scripting. Browser settings
Appropriate procedures to establish application security for browser
Educate users, updates and patches
Appropriate procedures to establish application security for Buffer Overflows
input should be tested to ensure that it is the sort of data expected by the program
Appropriate procedures to establish application security for cookies.
educate users, browser settings
Appropriate procedures to establish application security for SMTP open relays
email Server should be configured to send mail that originates from its own domain
Appropriate procedures to establish application security for Instant messaging
Intrusion detection software
HIDS
Host intrusion detection system
Personal software firewalls
firewall implemented as application software running on the host
Antivirus
Software capable of detecting and removing virus infections
Anti-Spam
techniques tp prevent a user from being overwhelmed with spam
3DES
Triple Digital encryption standard
ACL
Access Control list
AES256
Advanced encription standard 256bit
AH
Authentication Header
ALE
Annulized Loss Expectancy
ARO
Annualized RAte of occurance
ARP
Address Resolution Protocol
AUP
Acceptable Use Policy
BIOS
Basic input/output system
BOTS
Network robots
CA
Certificate Authority
CAN
Controller Area Network
CCTV
Closed circuit TV
CHAP
Challenge Handshake Authentication protocol
CRL
Cirtification Revocation list
DAC
Discretionary Access Control
DDOS
Distrubuted Denial of Service
DES
Digital encryption Standard
DHCP
Dynamic Host Configuration Protocol
DLL
Dynamic Link Library
DMZ
Demiliterized zone
The idea is that traffic can not pass through it. If communication is required between hosts on either side of the DMZ a host within the DMZ acts as a proxy. It takes requests checks it, if it is valid it retransmits it to the destination
DNS
Domain Name Service
DOS
Denial of service
EAP
Extensible autentication Protocol
ECC
Eliptic curve cryptography
FTP
File transfer protocol
GRE
Generic Routing Encapsulation
HIDS
Host Intrusion Detection System
HIPS
Host intrusion Prevention system
HTTP
Hypertext transfer protocol
HVAC
Heating Ventilation Air Conditioning
ICMP
Internet control message protocol
ID
Identification
IM
Instant messaging
IMAP4
Internet message access protocol version 4
IP
Internet protocol
IPSEC
Intenet Protocol Security
IRC
Internet relay chat
ISP
Internet Service Provider
KDC
Key distribution Center
L2TP
Layer two Tunneliing protocol
LANMAN
Local area network manager
LDAP
Lightweight directory Access protocol
MAC
Mandatory access control / Media access control
MAC (message)
Message authentication code
MAN
Metropolitan Area Network
MD5
Message digest 5
MSCHAP
Microsoft challenge Handshake Authentication protocol
MTU
Maximum transmission Unit
NAC
Network access control
Means of ensuring endpoint security. Making sure that all devices conform to a health policy (patch level, antivirus, firewall protection)
NIDS
Network Based Intrusion detection system
Software designed to monitor network traffic
NIPS
Network based network intrusion prevention system
Can automatically take preventative action
NOS
Network operating System
NTFS
New Technology File sytem
NTLM
New Technology LANMAN
NTP
Network Time Protocol
OS
Operating system
OVAL
Open Vulnerability Assesment Lanaguage
PAP
Password authentication Protocol
PAT
Port address translation
PBX
Private branch exchange
PGP
Pretty Good Privacy
PII
Personally Identifiable Information
PKI
Public Key Infrastructure
PPP
Point to Point Protocol
PPTP
Point to Point Tunneling Protocol
RAD
Rapid appication Developement
Radius
Remoted Authentication Dial in User Server
RAID
Redundant Array of Inexpensive Disk
RAS
Remoter Access Server
RBAC
Role Based Access Control
RBAC
Rule Based Access control
RSA
Rivest, Shamir, & Adleman
S/MIME
Secure/ Multipurpose internet mail extionsions
SHA
Secure Hashing Alogorithm
SHTTP
Secure Hypertext transfer protocol
SLA
Service Level Agreement
SLE
Single Loss expectancy
SMTP
Simple mail transfer protocol
SNMP
Simple Network Mangement Protocol
SPIM
Spam over internet messaging
SSH
Secure shell
SSL
Secure Sockets layer
SSO
Single Sign on
STP
Shielded twisted pair
TACACS
Terminal access controller access control system
TCP/IP
Transmission Control Protocol / Internet protocol
TKIP
Temporal KEy Integrity Protocol
TLS
Transport layer security
TPM
Trusted platform module
UPS
Uninteruptable Power supply
URL
Unisversal Resource locator
USB
universal serial bus
UTP
Unshielded twisted pair
VLAN
Virtual Local Area Network
Virtual lan created by switching technology. Provides traffic management and protection against sniffing
VOIP
Voice over Internet Protocol
VPN
Virtual Private network
WEP
Wireless equivalent Privacy
WPA
WI-FI Protected Access
Antiquated protocols
MAny protocols used for network transport and services were designed without reguard for security. These need to be deployed with extra safeguards. Either using another protocol for security (ipsec or ssl) or by filtering traffic using a firewall
TCP/IP hijacking
A type of spoofing where the attacker disconnects the host and replaces it with his or her own spoofing the original hosts ip address.
Null Sessions
Windows NT and 2000 allowed access to the IPC$ share by default This allows an attacker to gain valuable information about the host (Fingerprinting)
Spoofing
Attacked disguises thier identity. Examples include IP spoofing, phishing
Man-in-the-middle
Attacker intercepts communication between two hosts
Replay
Attacked intercepts some sort of authentication data and reuses it to try to restablish a session
DOS
Denial of Service
A network attack that aims to disrupt a service by overloading it
Domain name kiting
register a domain
delete the domain within 5 days
reregister the domain
DNS Poisoning
Manipulates DNS host records
ARP Poisening
Address resolution protocol maps mac addresses to ip addresses. ARP Poisening injects false IP/Mac lookup in to the ARP cache
Network interconnections
ensure physical security of the infrastructure (Cabeling, servers, switches)
Subnetting
IP network can be divided into a number os subnets. Communication between any two subnets must be challenged by a router
Telephony
refers to carrying voice traffic over data network.
Firewall
a range of devices and software products designed to restrict access from one network zone to another, to defined IP addresses or TCP/UDP application ports
Proxy Server
Mediates communication between a client and another server.Can fillter and often modify communications as well as providing caching services
Honeypot
A computer set up to entice attackers with the purpose of discovering attack strategies and weakneses in security configurations
Internet content filters
A software application or gateway that filters internet content requests. Can work on the basis of keywords, urls, time of day total browsing time
Protocol analyzers
Software that intercepts network traffic (packet sniffer) and displays the captured packets for analysis. AAlowing inspection of the packet headers and payload. Unless it is encrypted.
Vampire tap
A connector used on old ethernet networks for joining a host to a thicknet cable via a drop cable
Data Emanation
Unless shielded, all electrical cable leaks. Data emanation is more of a concern for wireless media. It is imparative that wireless communications use a strong encryption syste
War driving
Using a notebook with suitable software to detect unsecured or poorly secured wireless LANS
SSID broadcast
Identifies a particular wireless LAN. Broadcasting the sSSID makes the network publicly visible. Disabling the SSID broadcast is no substitute for enforcing authentication and encryption
Blue jacking
Hijacking a bluetooth device using some software exploit.
Blue Snarfing
Sending someone an unsolicited message or picture using a bluetooth connection
Rogue access points
Device attached to the network without permission. There are various scanning and monitoring software available to detect rogue devices
Weak encryption
if a cryptographic function has faults such as known weak keys or insufficient bit strength. An attack can be formulated to exploit this. Fake a digital signature, decrypt a document, or intercept wireless communications.
Implicit deny
unless something has specifically been granted access it should be denied access
least privilege
something should be granted the minimun necessary privileges or information to perform its role
Seperation of duties
duties that require no one person be able to perform the entire task
Job rotation
prevents any one person from performing the same role or task for too long
Group Policies
Can be used to configure security settings such as password policy , account restrictions, firewall status
Password policy
addresses issues like weak passwords, reusing passwords, writing passwords down, not changing password regularly
Logical tokens
A single sign on system such as Kerberos issues users a software token to present as confirmation that they have been previously authenticated
One Factor Authentication
one proof of identity
password
voice submission
finger print scan
token
smart card
certificate
Two factor Authentication
Two credentials
smart card and pin
finger print scan and password
Three factor Authentication
Three credentials
Smart card, Pin, Password
Single Sign On
System such as Kerberos centralizes user authentication in one module then negotiates with applications on behalf of the user to obtain service tickets
Biometric Reader
Authentication based on a record (template) of some information about their physical attributes such as fingerprints, or iris pattern obtained via a biiometric reader
Remote authentication
When a user authenticates with a remote server. Important to keep the communications private through the use of encryption.
Kerberos
Single sign on authentication scheme where clients authenticate once to a key distribution center and are granted service tickets to use particular applications without having to log on to each application seperately
Mutual authentication
Typically a cliemt authenticates to a server. In many circumstances it may be necessary for the server to authenticate to the client also (to prevent man in the middle attacks)
802.1x
Remote authentication framework with particular emphasis on wireless access. Defines how devices should provide support for Extensible Authentication Protocol (EAP) EAP allows authentication by a number of methods including smart cards and certificates
TACACS
Terminal Access controller access control system an alternative to RADIUS developed by CISCO