Definitions & Tools Flashcards
Asset (System Resource)
- Data in an information system
- Service provided by a system
- System capability (e.g., processing power, bandwidth, ..)
- Component of a system (hardware, software, ..)
Vulnerability
Flaw/weakness in a system’s design, implementation, functionality, or management
Threat
possible danger that might exploit a vulnerability
Risk
An expected loss (usually, in terms of probability) that a threat will exploit a particular vulnerability with a specific harmful result
Total Risk =
threat x vulnerabilities x asset
Adversary (Threat Agent)
An entity that attacks or is a threat to a system
Attack
An assault on security of a system. A deliberate attempt (in terms of method or technique) to evade security or security policy. A threat that has been carried out and causes violation of security when successful
Attack Vector
a path or means (method) by which an attacker can launch an attack against the target system
Attack Surface
- All (sum/collection) of the public and privately exposed system elements/connection points of the system
- Minimizing attack surface is a basic security measure
Attack Categories
Active, Passive, Insider, Outsider
Threat Consequence (1)
Unauthorized Disclosure
Exposure
Sensitive data directly released to unauthorized entity
Interception
Authorized entity directly access sensitive data while that are in transit between authorized end points
Inference
authorized entity indirectly access sensitive data through reasoning or, as by-products of communication
Intrusion
Authorized entity gains access by circumventing system’s security protections