15: Threats and Attacks Flashcards
Give the 4 basic types of attacks ?
- Integrity attack
- Authenticity attack
- Confidentiality attack
- Denial-of-service attack (DDos)
Give examples of passive attacks ?
- Eavesdropping
- Traffic analysis
Give examples of active attacks ?
- Masquerades
- Replay attack
- Denial-of-service attack (DDos)
Give examples of low-tech attacks ?
- Guessing or stealing passwords
- Taking advantage of poor clerical controls
- Using pop-ups to ask users for data while masquerading
Give examples of destructive attacks ?
- Email bomb
- DDos: programs infect other programs which infect other programs
What is an integrity attack ?
Give example.
Data is modified.
Credit card transactions are modified.
What is an confidentiality attack ?
Give example.
Reading private data.
Stealing CC details.
What is an authenticity attack ?
Give example.
Masquerading.
Pop-ups
What is an DDos attack ?
Give example.
Flooding a server with requests to overload it and thus make it unavailable
Give the 6 security requirements ?
- Confidentiality
- Authentication
- Integrity
- Non-repudiation
- Access-control
- Availability
What is a computer virus ?
What could it do ?
A malignant code which attaches itself to files resident on a computer.
It could overwrite or send emails.
Give types of viruses ?
- Polymorphic
- Stealth
- Trojan horse
- Password crackers
- Sniffers
- Spoofing