module 8
attack - intentional or unintentional act that can damage
exploit - p a technique used to compress a system
vulnerability - a potential weakness in an asset or its diverse control system
sun tzu wu - the art of war
threat
common attack pattern enumeration and classification (capec)
the 12 categories of threats
1. software piracy
2. hacker skills and abilities
[Link] protection in user registration
[Link] in quality of service
[Link] service issues
[Link] and other service provider [Link]
[Link] irregularities
[Link] or trespass
[Link] of privileges
[Link] variants
[Link] attacks
*brute force
*dictionary
*rainbow tables
*social engineering
module 9
april 1997 - internet disaster
human error or failure
acronyms
1. P E B K A C (problem exists between keyboard and chair)
2. P I C N I C (PROBLEM IN CHAIR NOT IN THE COMPUTER)
3. ID-10-T error (idiot)
[Link] free fraud
[Link]
*url and html
[Link] texting
[Link] engineering
[Link] extortion
[Link] computer software
SOFTWARE ATTACKS
1. malware
2. virus
3. worms
4. trojan horses
5. polymorphic threats
module 11
1. due care
2. due diligence
3. jurisdiction
4. liability
5. long arm jurisdiction
6. restitution
GENERAL COMPUTER CRIME LAW
the computer fraud and abuse act of 1986
PRIVACY
1. aggregate information
2. information aggregation
3. privacy
4. identity theft
5. personally identifiable information
6. us copyright law
7. freedom of information act of 1966
8. digital millennium copyright act
module 12
ASSOCIATION OF COMPUTING MACHINERY (ACM)
ISC- international information system security certification consortium, inc.
SANS- SYSTEM ADMINISTRATION NETWORKING AND SECURITY INSTITUTE
ISACA- INTERMISSION SYSTEM AUDIT AND CONTROL ASSOCIATION
ISSA- INFORMATION SYSTEM SECURITY ASSOCIATION
information assurance
signals intelligence