Shared Flashcard Set

Details

1 - Computer Forensics || Email
1 - Computer Forensics || Email
50
Computer Science
Undergraduate 4
11/13/2018

Additional Computer Science Flashcards

 


 

Cards

Term
Email System Architecture
Definition
Client

MSA

Transmitter

Internet

Receiver

MDA <> Mailstore

Client (POP, IMAP) or Browser (HTTP)
Term
What is MSA?
Definition
Mail Submission Agent
Term
What is MDA?
Definition
Mail Storage and Delivery Agent
Term
What is a computer program for reading and sending e-mails?
Definition
Client
Term
What is a MUA?
Definition
Mail User Agent
Term
What is POP3?
Definition
Post Office Protocol Server
Term
What is the Post Office Protocol Sever?
Definition
Popular email protocol used to deliver message from a mail server.
Term
What is IMAP?
Definition
Internet Message Access Protocol Server
Term
What is the difference between POP3 and IMAP?
Definition
POP3 by default the message in server is deleted.

IMAP messages stay in the server even after access and users can arrange emails into folders.
Term
What is SMTP?
Definition
Simple Mail Transfer Protocol Server
Term
What is a Simple Mail Transfer Protocol Server?
Definition
An outgoing email server with a push protocol that first consults DNS to find IP address of the recipient's SMTP server before sending an email.
Term
What is an e-mail address?
Definition
Globally unique ID and used to receive email.
Term
What is a global reference to an Internet resource like a host, network or service which maps to IP address(es)?
Definition
Domain
Term
Describe the structure of a Domain
Definition
Has a hierarchical sequence of labels, separated by dots.
Term
What is the top of the hierarchy of a Domain?
Definition
On the right end of the sequence.
Term
What is used for threading and aiding identification for duplications?
Definition
Message-ID
Term
What is used for the purpose of message tracking?
Definition
ENVelope Identifier (ENVID)
Term
What are the two parts of an Email Message?
Definition
Body and Header
Term
What can the body of an e-mail contain?
Definition
Text, multimedia elements in Hyper Text Markup Language (HTML) and attachments encoded in Multi-Purpose Internet Mail Extensions (MIME).
Term
What can include headers in a message?
Definition
The sender or by a component of the e-mail system.
Term
The header of an email is a structured set of fields that include what?
Definition
‘From’, ‘To’, ‘Subject’, ‘Date’, ‘CC’, ‘BCC’, ‘Return-To’, etc.
Term
The header of an email can also include what kind of information?
Definition
Transit-handling trace
Term
What refers to the study of source and content of e-mail message to find evidence?
Definition
Email Forensics
Term
What kind of evidence is searched for using email forensics?
Definition
–identification of the actual sender, recipient, date and time when it was sent, etc.

–Finding the history of a message and identity of all involved entities.

–A forensic investigation of e-mail can examine both email header and body.
Term
Email Forensics also includes the investigation of what?
Definition
Some client or server computer suspected of being used or misused for e-mail forgery.
Term
What is Header Analysis?
Definition
The investigation of meta data in the e-mail message in the form of control information contain information about the sender and/or the path along which the message has traversed.
Term
What is Server Investigation?
Definition
Copies of delivered emails and server logs are investigated to identify the source of an e-mail message.
Term
What is Network Device Investigation?
Definition
To investigate the source of an email message by investigating logs maintained by the network devices.
Term
What Are Software Embedded Identifiers?
Definition
Information about the creator of e-mail, attached files or documents may be included with the message by the e-mail software used by the sender for composing e-mail.
Term
What Are Sender Mailer Fingerprints?
Definition
Identification of software handling e-mail at server can be revealed from the Received header field and identification of software handling e-mail at client can be ascertained by using different set of headers like “X-Mailer” or equivalent.
Term
What does the X-Mailer Line Do In The Email Header?
Definition
Tells you what program was used to draft and send the original email.
Term
What is SPF?
Definition
Sender Policy Framework
Term
What is Sender Policy Framework?
Definition
A simple email-validation system designed to detect email spoofing.
Term
Where is the list of authorized sending hosts for a domain published?
Definition
Domain Name System (DNS) records for that domain in the form of a specially formatted TXT record.
Term
Email spam and phishing often use what kind of forged addresses?
Definition
From Addresses
Term
What is DKIM?
Definition
DomainKeys Identified Mail
Term
What is DomainKeys Identified Mail?
Definition
Another email authentication method designed to detect email spoofing.
Term
One can verify a DKIMs authenticity and the content integrity using what?
Definition
Signer's public key published in the DNS.
Term
DKIM Tag: v
Definition
Version
Term
DKIM Tag: a
Definition
Signing Algorithm
Term
DKIM Tag: b
Definition
Signatures of Heading and Body
Term
DKIM Tag: bh
Definition
Body Hash
Term
DKIM Tag: d
Definition
Domain
Term
DKIM Tag: s
Definition
Selector
Term
DKIM Tag: c
Definition
Canonicalization algorithm(s) for header and body
Term
DKIM Tag: q
Definition
Default query method
Term
DKIM Tag: l
Definition
Length of the canonicalized part of the body that has been signed.
Term
DKIM Tag: t
Definition
Signature timestamp
Term
DKIM Tag: x
Definition
Expire time
Term
DKIM Tag: h
Definition
List of signed header fields, repeated for fields that occur multiple times.
Supporting users have an ad free experience!