OPS Flashcards
Microphones, vibrations sensors
Acoustical Detection
Relevant, sufficient, reliable, does not have to be tangible
Admissible Evidence
The process of categorizing attack alerts produced from an IDS in order to distinguish false positives from actual attacks
Alarm filtering
A signal suggesting a system has been or is being attacked.
Alert/Alarm
Systematic assessment of threats and vulnerabilities that provides a basis for effective management of risk.
Analysis
When resolving a single failure (though system administrators are needed to resolve additional failures
Automatic Recovery
Higher level of recovery defining prevention against the undue loss of protected objects
Automatic Recovery Without Undo Loss
Alarm to local fire or police
Auxiliary Station Systems
Tape: sequential, slow read, fast write 200GB an hour, historically
cheaper than disk (now changing), robotic libraries
Disk: fast read/write, less robust than tape
Optical drive: CD/DVD. Inexpensive
Solid state: USB drive, security issues, protected by AES
Backup Storage Media
Primary: used at the trial because it is the most reliable.
Original documents are used to document things such as contracts
Best Evidence
Placeholders for literal values in SQL query being sent to the database on a server; Used to enhance performance of a database
Bind Variables
Focus on illegally obtaining an organization’s confidential information. The use of the information gathered usually causes more damage than the initial event itself.
Business Attacks
Less than 10mins travel time for e.g. an private security firm
Central Stations
Collection, analysis and preservation of data
Forensics uses bit-level copy of the disk
Chain of Custody
Maintaining full control over requests, implementation, traceability, and proper documentation of changes.
Change Control
Electrical
Cipher Lock
Used to help assume another fact
Cannot stand on its own to directly prove a fact
Circumstantial Evidence
Europe, South America
Civil Law
The assignment of a level of sensitivity to data (or information) that results in the specification of controls for each level of classification.
Classification
organization way of classifying data by factors such as criticality, sensitivity and ownership.
Classification Scheme
Overwriting media to be reused
Clearing
3 digits with wheels
Combination Lock
USA, UK Australia Canada (judges)
Common Law
3 types of harm:
unauthorized intrusion
unauthorized alteration or destruction
malicious code
Computer Crime Laws
Irrefutable, cannot be contradicted
Requires no other corroboration
Conclusive Evidence
A value an organization places on an IDS based on past performance and analysis to help determine its ability to effectively identify an attack
Confidence value
Collection of component CI’s that make another CI
Configuration
Component whose state is recorded
Configuration item (CI)
Mitigate damage by isolating compromised systems from the network.
Containment
Supports or substantiates other evidence presented in a case
Corroborative Evidence
Unused network space that may detect unauthorized activity
Darknet
Individuals and departments responsible for the storage and safeguarding of computerized data.
Data Custodian
A database that contains the name, type, range of values, source and authorization for access for each data element
Data Dictionary
Is a country or location that has no laws or poorly enforced laws
Data Haven
The property that data meet with a priority expectation of quality and that the data can be relied upon.
Data Integrity
Siphoning out or leaking information by dumping computer files or stealing computer reports and tapes.
Data Leakage
Systems attempt to detect and block exfiltration attempts. These systems have the capability of scanning for keywords and patterns.
Data Loss Prevention (DLP)
Individuals, normally managers or directors, who have responsibility for the integrity, accurate reporting and use of computerized data.
Data Owner
Real-time data backup ( Data Mirroring)
Database Shadowing
External communications
Debriefing / Feedback
Protection of stored or displayed information by removal/reduction of the magnetic field (demagnetization).
Degauss
Identification and notification of an unauthorized and/or undesired action
Detection
Bolt down hardware
Device Lock
Only modified files, doesn’t clear archive bit. Advantage: full and only last one needed, Intermediate time between.
Differential backup
Can prove fact by itself and does not need any type of backup.
Testimony from a witness; one of their 5 senses.
Oral: case can’t stand on it alone
Oral: does not need other evidence to substantiate
Direct Evidence
Senses a break or change in a circuit magnets pulled lose, wires door, pressure pads
Electromechanical Detection
Periodic, automatic and transparent backup of data in bulk.
Electronic Vaulting
Occurs after a failure happens in an uncontrolled manner. E.g. when a low privileged user tries to access restricted memory segments
Emergency Restart Failure
Can scan files stored on a system as well as files sent to external devices, such as printers. For example, an organization ? can prevent users from copying sensitive data to USB flash drives or sending sensitive data to a printer.
Endpoint-based DLP
The legal action of luring an intruder, like in a honeypot
Enticement
Refers to the amount of privileges granted to users, typically when first provisioning an account. A user audit can detect when employees have excessive privileges
Entitlement
The illegal act of inducing a crime; the individual had no intent of committing the crime at first
Entrapment
Malicious act of gathering proprietary, secret, private, sensitive, or confidential information about an organization.
Espionage
Often with the intent of disclosing or selling the information to a competitor or other interested organization (such as a foreign government). Attackers can be dissatisfied employees, and in some cases, employees who are being blackmailed from someone outside the organization. Countermeasures are to strictly control access to all nonpublic data, thoroughly screen new employee candidates, and efficiently track all employee activities.
Must be preserved and identifiable
Evidence
Sufficient –persuasive enough to convince one of its validity
Reliable –consistent with fact, evidence has not been tampered with or modified
Relevant –relationship to the findings must be reasonable and sensible, Proof of crime, documentation of events, proof of acts and methods used, motive proof, identification of acts
Permissible – lawful obtaining of evidence, avoid: unlawful search and seizure, secret recording, privacy violations, forced confessions, unlawful obtaining of evidence
Preserved and identifiable – collection, reconstruction
Identification labeling, recording serial number etc.
Evidence must be preserved and identifiable
1. Discovery
2. Protection
3. Recording
4. Collection and identification
5. Analysis
6. Storage, preservation, transportation
7. Present in court
8. Return to owner
Evidence Lifecycle
Allows officials to seize evidence before it’s destroyed (police team fall in)
Exigent Circumstances
Most conservative from a security perspective
Fail Closed/Secure
Program execution is terminated and system protected from hardware or software compromise occurs DOORS usually
Fail safe system
Or resilient system: reboot, selected, non-critical processing is terminated
Fail soft
Switches to hot backup
Failover
Backup critical information thus enabling data recovery
Failure Preparation
The event signaling an IDS to produce an alarm when no attack has taken place
False attack stimulus
A failure of an IDS to detect an actual attack
False negative
An alert or alarm that is triggered when no actual attack has taken place
False positive
Mitigation of system or component loss or interruption through use of backup capability.
Fault tolerance
Carried out to unlawfully obtain money or services.
Financial Attacks
All files, archive bit and modify bit are cleared. Advantage: only previous day needed for full restore, disadvantage: time consuming
Full Backup
System can restore functional processes automatically
Function Recovery
Carried out to damage an organization or a person. The damage could be in the loss of information or information processing capabilities or harm to the organization or a person’s reputation.
Grudge Attacks
Want to verify their skills as intruders
Hackers and Crackers
Often combine political motivations with the thrill of hacking.
Hacktivists
Review the contents. This may include a review of Personal computers & Smartphones
Hardware/ Embedded Device Analysis
Second-hand data not admissible in court
Hearsay
Something a witness hears another one say.
Business records and all that’s printed or displayed. Exception: audit trails and business records when the documents are created in the normal course of business.
Hearsay Evidence
Information that, if made public or even shared around the organization, could seriously impede the organization’s operations
Highly Confidential
Monitors activity on a single computer, including process calls and information recorded in firewall logs. Often examines events in more detail than NIDS, can pinpoint specific files compromised in an attack. Can track processes employed by the attacker. A benefit over NIDSs is that it can detect anomalies on the host system.
Host-based IDS (HIDS)
Redundant component that provides failover capability in the event of failure or interruption of a primary component.
Hot Spares
Software component that manages the virtual components. Adds an additional attack surface, so it’s important to ensure it is deployed in a secure state and kept up-to-date with patches, controls access to physical resources
Hypervisor
Event or series of events that adversely impact the ability of an organization to do business; suspected attack
Incident
A documented battle plan for coordinating response to incidents.
Incident handling
Incident response process
Detect
Respond
Report
Recover
Remediate
Review
Only modified files, archive bit cleared, Advantage: least time and space, Disadvantage: first restore full then all incremental backups, thus less reliable because it depends on more components
Incremental Backup
loss would inconvenience the organization but disclosure is unlikely to result in financial loss or serious damage to credibility.
Internal Use only
Evidence retrieval method, ultimately obtain a confession
Interrogation
Gather facts and determine the substance of the case.
Interviewing
Occurs when an attacker is able to bypass or thwart security mechanisms and gain access to an organization’s resources.
Intrusion
Monitors recorded information and real-time events to detect abnormal activity indicating a potential incident. Automates the inspection of logs and real-time events to find attempts and failures. An effective method of detecting many DoS and DDoS attacks. Can recognize attacks that come from external connections, such as from the Internet, and attacks that spread internally such as a malicious worm. Responds by sending alerts or raising alarms. In some cases can modify the environment to stop an attack.
A primary goal is to provide a means for a timely and accurate response to attacks. Intended as part of a defense-in-depth security plan. It will work with and compliment other security mechanisms but does not replace them.
Intrusion Detection System (IDS)
Includes all the capabilities of an IDS but can also take additional steps to stop or prevent intrusions. If desired, administrators can disable these extra features, essentially causing it to function as an IDS.
Intrusion Prevention System (IPS)
ME, Africa, Indonesia
Islamite and other Religious Laws
Most basic type of storage
When two drives or disks have a logical joining without redundacy
JBOD
Evenly distributed
Lighting Continuous
No bleeding over no blinding
Lighting Controlled
Against blinding
Lighting Glare Protection
IDS detects activities and turns on lightning
Lighting Responsive Areas Illumination
Timers
Lighting Standby
If no tampering is done with the alarm wires
Line Supervision Check
Audible at least 4000 feet
Local Alarms
every time you make contact with another it results in an exchange of materials for both physical and digital evidence.
Locard’s principle
Record of system activity, which provides for monitoring and detection.
Log
System administrator intervention is required to return the system to a secure state
Manual Recovery
A branch of computer forensic analysis. Involves the identification and extraction of information from storage. This may include the following: Magnetic (e.g., hard disks, tapes) Optical (e.g., CDs, DVDs, Blu-ray discs) Memory (e.g., RAM, solid state storage)
Techniques used may include the recovery of deleted files from unallocated sectors of the physical disk, the live connection to a computer system (especially useful when examining encrypted), and the static examination of forensic images of storage.
Media Analysis
Designed to extract secret information.
Military or Intelligence Attack
MOM
Means, Opportunity and Motive
Used in determining suspects
Continuous surveillance, to provide for detection and response of any failure in preventive controls.
Monitor
wave pattern movement sensors
Motion Detector
MTBF
Mean Time Between Failures (Useful Life) = MTTF + MTTR
Mean Time To Failure
Mean Time To Recover
Often depends on either prior knowledge that an incident is underway or the use of preexisting security controls that log activity. These include: Intrusion detection and prevention system logs, data captured by a flow monitoring system, Packet captures deliberately collected during an incident. Logs from firewalls and other security devices. Collect and correlate information from these disparate sources and produce as comprehensive a picture of activity as possible.
Network Analysis
Server optimized for providing file-based data storage to the network. Unlike a File Server, a ? unit has no input or output devices, and the OS is dedicated for providing storage services.
Network Attached Storage (NAS)
Scans all outgoing looking for specific variables. If a user sends out a restricted file, the system will detect it and prevent it from leaving the organization. Sends an alert, such as an email to an administrator.
Network-based DLP
Monitors and evaluates network activity to detect attacks or event anomalies. Cannot monitor content of encrypted traffic but can monitor other packet details. Just one can monitor a large network by using remote sensors to collect data at key network locations that send data to a central management console.
Network-based IDS (NIDS)
Data or interference that can trigger a false positive
Noise
Most preferred in the legal investigation; pages are attached to a binding.
Notebook
Communication of a security incident to stakeholders and data owners.
Notification
Utilization after initial use
Object Reuse
Requires witnesses to testify only about the facts of the case; cannot be used as evidence in the case.
Opinion Rule
Involve relocating personnel to the alternate site and commencing operations there. Critical systems are run at an alternate site, main site open also
Parallel Tests
Through sensing changes in temperature
Passive Infrared Detection
Light beams interrupted (as in an store entrance)
Photoelectric Detector
A very cold site.
Prefabricated Building
Comes with door
Preset Lock
Controls deployed to avert unauthorized and/or undesired actions.
Prevention
Combination or electrical lock
Programmable Lock
Define the way in which the organization operates.
Proprietary
Owned and operated by the customer.
System provides many of the features in-house
Proprietary Systems
Customer view taken into account
Prototyping
Magnetic field shows presence around an object
Proximity or Capacitance Detector
False vulnerability in a system that may attract an attacker
Pseudo Flaw
Degaussing or overwriting to be removed
Purging
RAID Levels
RAID 0 Striped, one large disk out of several. Improved performance but no fault tolerance
RAID 1 Mirrored drives: fault tolerance from disk errors and single disk failure, expensive; redundancy only, not speed
RAID 2 not used commercially. Hammering Code Parity/error
RAID 3 Striped on byte level with extra parity drive. Improved performance and fault tolerance, but parity drive is a single point of failure and write intensive. 3 or more drives
RAID 4 Same as Raid 3 but striped on block level; 3 or more drives
RAID 5 Striped on block level, parity distributed over all drives. Requires all drives but one to be present to operate hot. Swappable. Interleave parity, recovery control; 3 or more drives
RAID 6 Dual Parity; parity distributed over all drives. Requires all drives but two to be present to operate hot. Swappable.
RAID 7 Same as raid 5 but all drives act as one single virtual disk
Circumvent a pin tumbler lock
Raking
Measures followed to restore critical functions following a security incident.
Recovery
A group of hard drives working as one storage unit for the purpose of speed and fault tolerance
Redundant Array of Independent Drives (RAID)
Use of a backup server(s) to protect information and essential processes in the event of a primary system failure.
Redundant Servers
Potentially retrievable data residue that remains following intended erasure of data.
Remanence
Real-time, automatic and transparent backup of data.
Remote Journaling
Policy, procedures, a team
Response Capability
Criminal act of destruction or disruption committed against an organization by an employee. It can become a risk if an employee is knowledgeable enough about the assets of an organization, has sufficient access to manipulate critical aspects of the environment, and has become disgruntled.
Sabotage
Goes back to the primary site to normal processing environmental conditions. Clean, repair, save what can be saved. Can declare when primary site is available again
Salvage Team
Attackers who lack the ability to devise their own attacks will often download programs that do their work for them. The main motivation behind these attacks is the “high” of successfully breaking into a system. Service interruption. An attacker may destroy data, the main motivation is to compromise a system and perhaps use it to launch an attack against another victim. Website defacements common
Script Kiddies
Copies of documents. Not as strong as best. A copy is not permitted if the original (Best) is available. Oral like Witness testimony
Secondary Evidence
Group of independent servers which are managed as a single system. All servers are online and take part in processing service requests.
All share the same OS and application software vs. grid devices that can have different OSs while still working on same problem.
Server Clustering
Guidelines within an organization that control the rules and configurations of an IDS
Site policy
The ability an IDS has to dynamically change its rules and configurations in response to changing environmental activity
Site policy awareness
Conduct forensic reviews of applications or the activity that takes place within a running application. In some cases, conduct a review of software code, looking for back doors, logic bombs, or other security vulnerabilities. In other cases, review and interpret the log files from application or database servers, seeking other signs of malicious activity, such as SQL injection attacks, privilege escalations, or other application attacks.
Software Analysis
Controlled area only accessible for approved users
Software Library
A subnetwork with storage devices servicing all servers on the attached network.
Storage Area Network (SAN)
Third party, commercial services provide alternate backups and processing facilities. Most common of implementations!
Subscription Services
When an unexpected kernel or media failure happens and the regular recovery procedure
System Cold Start Failure
System shuts itself down in a controlled manner after detecting inconsistent data structures or runs out of resources
System Reboot Failure
System Recovery
1. Rebooting system in single user mode or recovery console, so no user access is enabled
2. Recovering all file systems that were active during failure
3. Restoring missing or damaged files
4. Recovering the required security characteristic, such as file security labels
5. CheckingSystem Recovery
Purpose of a ? is to disrupt normal life and instill fear
Terrorist Attacks
Launched only for the fun of it. Pride, bragging rights
Thrill Attacks
Highly sensitive internal documents that could seriously damage the organization if such information were lost or made public
Top Secret
An event that triggers an IDS to produce an alarm and react as though a real attack were in progress
True attack stimulus
Ensures that the security is not breached when a system crash or failure occurs. Only required for a B3 and A1 level systems.
Trusted Recovery
Cylinder slot
Tumbler Lock
- Operational
- Criminal
- Civil
- eDiscovery
Types of Investigation
Legislative: writes (statutory laws)
Executive: enforces (administrative laws)
Juridical: interprets laws (makes common laws out of court decisions)
US Law: 3 Branches
Criminal: individuals in violation; punishment mostly imprisonment
Civil: wrongs against individual or organization that result in a damage or loss. Punishment can include financial penalties. AKA tort (I’ll Sue You!) Jury decides liability
Administrative/Regulatory: – how industries, organizations and officers have to act. Wrongs can be penalized with imprisonment or financial penalties
US Law: 3 Categories
Why certain people fall prey to crime and how lifestyle affects their chances
Victimology
Hanging, with a key
Warded Lock
Raid 6
Does not require a hot spare drive or disk
piracy act of copying software from top notch brands and distributing over the Internet
warez
colocation cloud
Colocation cloud combines the benefits of colocation and cloud computing to provide a comprehensive solution that addresses the limitations of traditional data management approaches.
blue team
defends from attacks
red team
attacks
white team
handles security incidents