Shared Flashcard Set

Details

SEC110_CH04
Vulnerability Assessment and Mitigating Attacks
24
Computer Networking
Undergraduate 3
09/05/2013

Additional Computer Networking Flashcards

 


 

Cards

Term
Annualized Loss Expectancy (ALE)
Definition
The expected monetary loss that can be expected for an asset due to a risk over a one-year period.
Term
Annualized Rate of Occurrence (ARO)
Definition
The probability that a risk will occur in a particular year.
Term
architectural design
Definition
The process of defining a collection of hardware and software components along with their interfaces in order to create the framework for software development.
Term
attack surface
Definition
The code that can be executed by unauthorized users in a software program.
Term
baseline reporting
Definition
A comparison of the present state of a system compared to its baseline.
Term
black boxinfrastructure
Definition
A test in which the tester has no prior knowledge of the network that is being tested.
Term
code review
Definition
Presenting the code to multiple reviewers in order to reach agreement about its security.
Term
design review
Definition
An analysis of the design of a software program by key personnel from different levels of the project.
Term
Exposure Factor (EF)
Definition
The proportion of an asset's value that is likely to be destroyed by a particular risk (expressed as a percentage).
Term
fail-open
Definition
A control that errs on the side of permissiveness in the event of a failure.
Term
fail-safe (fail-secure)
Definition
A control that errs on the side of security in the event of a failure.
Term
gray box
Definition
A test where some limited information has been provided to the tester.
Term
hardening
Definition
The process of eliminating as many security risks as possible and making the system more secure.
Term
honeynet
Definition
A network set up with intentional vulnerabilities.
Term
honeypot
Definition
A computer typically located in an area with limited security and loaded with software and data files that appear to be authentic, yet they are actually imitations of real data files, to trick attackers into revealing their attack techniques.
Term
penetration testing
Definition
A test by an outsider to actually exploit any weaknesses in systems that are vulnerable.
Term
port scanner
Definition
Software to search a system for any port vulnerabilities.
Term
protocol analyzer (sniffer)
Definition
Hardware or software that captures packets to decode and analyze the contents.
Term
Single Loss Expectancy (SLE)
Definition
The expected monetary loss every time a risk occurs.
Term
vulnerability assessment
Definition
A systematic and methodical evaluation of the exposure of assets to attackers, forces of nature, or any other entity that is a potential harm.
Term
vulnerability scan
Definition
An automated software search through a system for any known security weaknesses that then creates a report of those potential exposures.
Term
vulnerability scanner
Definition
Generic term for a range of products that look for vulnerabilities in networks or systems.
Term
white box
Definition
A test where the tester has an in-depth knowledge of the network and systems being tested, including network diagrams, IP addresses, and even the source code of custom applications.
Term
Xmas Tree port scan
Definition
Sending a packet with every option set on for whatever protocol is in use to observe how a host responds.
Supporting users have an ad free experience!