Shared Flashcard Set

Details

Additional content
AC
25
Computer Science
Undergraduate 4
04/23/2012

Additional Computer Science Flashcards

 


 

Cards

Term
STRIDE stands for
Definition
Spoofing
Tampering
Repudiation
information disclosure
DOS
Elevation if priviliege
Term
DREAD
Definition
Damage potential
Reproducibility
Exploitability
Affected Users
Discoverabiity
Term
SET stands for
Definition
Secure electronic transaction
Term
Spoofing identity is what?
Definition
Impersonating a valid user, resource or system
Term
What is spoofing a threat to?
Definition
Confidentiality, integrity, availability
Term
What is tampering with data?
Definition
Inappropriately modifying system or user data
Term
What tampering with data is a threat to?
Definition
Integrity
Term
What is repudiation?
Definition
The inability to ID an attacker
Term
What is repudiation a threat to?
Definition
integrity
Term
What is information disclosure?
Definition
A breach of privacy
Term
What is denial of... never mind
Definition
If you don't know this, you should probably just go home
Term
Elevation of priviledge is?
Definition
Gaining privileges he or she should not have
Term
Elevation of privilege is a threat that affects?
Definition
Confidentiality, integrity, availability
Term
Damage potential is what?
Definition
How much damage will ocurr if an exploit occurs
Term
Reproducability is what?
Definition
How easy is it to reproduce the athreat exploit?
Term
Exploitability is what?
Definition
What is needed to exploit this threat
Term
Affected users is what?
Definition
How many users will be affected
Term
Discoverability is what?
Definition
How easy is it to discover this threat
Term
What, on the scale of 0-10 is discoverability 0, 5,9, 10
Definition
0= Very hard
5 = Can figure it out by guessing or by monitoring network traces

9= Details of faults like this are already in the public domain

10 = Info available in the web browser address bar / form
Term
Risk is what?
Definition
(DAMAGE + REPRODUCIBILITY + EXPLOITABILITY + AFFECTED USERS + DISCOVERABILITY) / 5
Term
What does SET stand for?
Definition
Secure Electronic Transactions
Term
What is SET?
Definition
An open encryption and security specification
Term
What are the three SET services?
Definition
Secure comminication channel

X.509v3

Ensure privacy
Term
What are the 4 key features of SET?
Definition
Confidentiality of information
Integrity of data
Careholder account auth
Merchant auth
Term
What are the key disadvantages of SET?
Definition
Need to install client software
Cost and complexity
Certificate distribution
Supporting users have an ad free experience!