Security
- •
What it is
- •
The ability to trust the applications and services you use — that the parties involved really are who they claim to be, and that the systems involved are protected from tampering or compromise. In the web context, HTTPS certificates are a concrete example: they prove you're actually talking to the site you intended to, and stop attackers on the network from reading or altering the traffic.
- •
- •
Why it matters
- •
Security is a precondition for privacy, not a substitute for it. A tool can be extremely secure (well-defended against attackers) while still not being private, if the operator of that tool itself has full access to your data.
- •
- •
- •
In this collection 388
- AAA (Identification, Authentication, Authorization, Accounting)
- Access Badge
- Access Control List (ACL)
- Access Control Vestibule
- Account Lockout
- Accounting
- Active Directory
- Active Monitoring
- Adaptive Identity
- Address Space Layout Randomization (ASLR)
- Adversary
- AES
- AES CBC Bit-Flipping
- AES-GCM Forbidden Attack (Nonce Reuse Tag Forgery)
- AES-IGE Padding Oracle Attack (CBC-Equivalence)
- Agreement Type
- Alert Tuning
- Allow List - Deny List
- Anonymity
- Application Containerization
- Application Security Monitoring
- Asset (concept)
- Asset Management
- Attack Surface
- Attribute-based Access Control (ABAC)
- Audits and Assessments
- Authentication
- Authorization
- Availability
- Backup
- Benchmark (Security)
- Birthday Attack
- Bloatware
- Block Cipher Mode of Operation
- Bollards
- Bring Your Own Device (BYOD)
- Brute Force (Password Attack)
- Buffer Overflow
- Business Email Compromise
- Business Impact Analysis
- CBC Decryption via ECB Oracle
- CBC IV=Key Recovery Attack
- CBC Padding Oracle Attack (Vaudenay)
- Censorship (Online)
- Centralized vs. Decentralized Security
- Certificate Authority
- Certificate Revocation List (CRL)
- Certificate Signing Request (CSR)
- Certificate Transparency & SPKI Fingerprinting
- Chain of Custody
- Chain of Trust
- CIA Triad
- Cloud Responsibility Matrix
- Cloud-specific Vulnerability
- Code Signing
- Cold Site
- Common Vulnerabilities and Exposures (CVE)
- Common Vulnerability Scoring System (CVSS)
- Compartmentalization
- Compensating Control
- Compliance
- Confidentiality
- Configuration Enforcement
- Connectivity (Secure Infrastructure)
- Content Filtering
- Continuity of Operations Planning (COOP)
- Control Plane
- Corrective Control
- CRIME Attack (Compression Oracle Side-Channel)
- Cross-site Request Forgery (CSRF)
- Cross-site Scripting (XSS)
- Data at Rest
- Data in Transit
- Data in Use
- Data Loss Prevention (DLP)
- Data Masking
- Data Plane
- Data Roles and Responsibilities
- Data Sovereignty
- Data Subject
- Database Encryption
- DDoS Reflection and Amplification
- Deception and Disruption
- Decommissioning
- Default Credentials
- Denial of Service (DoS)
- Detective Control
- Deterrent Control
- Device Placement
- Diffie-Hellman Downgrade Attack (Export-Grade - Weak Group Negotiation)
- Diffie-Hellman Parameter-Public-Value Injection (MITM)
- Digital Certificate
- Digital Forensics
- Directive Control
- Directory Traversal
- Disaster Recovery Testing
- Discretionary Access Control (DAC)
- Distributed Denial of Service (DDoS)
- DLL Injection
- DMARC
- DNS Poisoning
- Domain Hijacking
- Domain Keys Identified Mail (DKIM)
- Downgrade Attack
- Dynamic Analysis (Fuzzing)
- E-discovery
- ECB Byte-at-a-Time Decryption Attack
- Eliciting Information
- Embedded System
- End-of-Life (EOL)
- End-of-Service-Life (EOSL)
- End-To-End Encryption (E2Ee)
- Endpoint Detection and Response (EDR)
- Environmental Attack
- Extended Detection and Response (XDR)
- Extensible Authentication Protocol (EAP)
- FactorDB (Pragmatic Factorization Lookup)
- Failover
- Failure Modes
- False Positive - False Negative
- Federation
- Fencing
- File Encryption
- File Integrity Monitoring (FIM)
- Fileless Malware
- Firewall
- Firmware
- Forensic Acquisition
- Full RELRO
- Full-Disk Encryption
- Gap Analysis
- Governance Structure
- Group Policy
- Hacktivist
- Hardening Target
- Hardware Security Module (HSM)
- Hardware Vulnerability
- Header Manipulation
- Honeyfile
- Honeynet
- Honeypot
- Honeytoken
- Host-based Firewall
- Host-based Intrusion Prevention System (HIPS)
- Hot Site
- Hybrid Cloud
- Identification
- Identity and Access Management (IAM)
- Identity Fraud
- Identity Proofing
- IEEE 802.1X
- Impersonation
- In-band Key Exchange
- Incident Response
- Indicators of Compromise
- Infrared Sensors
- Infrastructure Considerations
- Input Validation
- Insider Threat
- Integrity
- Internet of Things (IoT)
- Intrusion Prevention System (IPS)
- Jailbreaking-Rooting
- Jump Server
- Just-in-time Permissions
- Key Escrow
- Key Management
- Keylogger
- Known-Plaintext Keystream Recovery (Many-Time Pad)
- Lateral Movement
- LDAP (Lightweight Directory Access Protocol)
- Legal Hold
- Levels of Encryption
- Lighting (Security)
- Log Aggregation
- Log Data
- Logic Bomb
- Logical Segmentation (VLANs)
- Malicious Code
- Malicious Updates
- Malware
- Managerial Control
- Mandatory Access Control (MAC)
- Many-Time Pad (Multi-Message Keystream Reuse)
- Mass Surveillance
- Media Sanitization
- Memory Injection
- Metadata
- Microservices
- Microwave Sensors
- Misconfiguration Vulnerability
- Misinformation-Disinformation
- Mobile Device Management (MDM)
- Mobile Device Vulnerabilities
- Multi-cloud Systems
- Multifactor Authentication
- Nation State
- NetFlow
- Network-based Firewall
- Next-Generation Firewall (NGFW)
- NIST SP 800-61 (Incident Response Lifecycle)
- Noisy Padding Oracle Attack (Statistical Amplification)
- Non-repudiation
- NX-DEP (No-eXecute)
- OAuth
- Obfuscation
- OCSP Stapling
- OFB Mode Encryption-Decryption Symmetry
- On-path Attack
- On-path Browser Attack
- On-premises Security
- Online Certificate Status Protocol (OCSP)
- Open Service Ports
- Operating System Vulnerabilities
- Operational Control
- Organized Crime
- Out-of-band Key Exchange
- Package Monitoring
- Partition Encryption
- Pass the Hash
- Passive Attack
- Passive Monitoring
- Password Hashing
- Password Security
- Patching
- PEM & DER (ASN.1 Encoding)
- Penetration Test
- Perfect Security
- Persistence (Penetration Testing)
- Phishing
- Physical Attack (Brute Force)
- Physical Isolation
- Physical Security
- Physical Segmentation
- Piggybacking
- Plaintext Recovery via Rejection-Sampling Oracle (Process of Elimination)
- Platform Diversity
- Playbook
- Policy Enforcement Point (PEP)
- Port Security
- Posture Assessment
- Power Resiliency
- Pressure Sensors
- Pretexting
- Preventive Control
- Privacy
- Privacy Vs Secrecy
- Private Certificate Authority
- Privilege Escalation
- Proxy
- Pseudonymity
- Public Exposure
- Public Key Infrastructure (PKI)
- Race Condition
- RADIUS
- Ransomware
- RC4 Weak-IV Key Recovery (FMS Attack)
- Real-Time Operating System (RTOS)
- Record Encryption
- Replay Attack
- Resilience
- Resource Reuse
- Responsible Disclosure Program
- RF Jamming
- RFID Cloning
- Right-to-Audit Clause
- Risk
- Risk Analysis
- Risk Management
- Risk Management Strategies
- Risk Tolerance
- Risk Transference
- Role-based Access Control (RBAC)
- Root Cause Analysis
- Root of Trust
- Rootkit
- RSA Padding Schemes (PKCS-1 v1.5 vs OAEP vs Unpadded)
- RSA Sign = Decrypt When Keys Are Shared (Unrestricted Signing Oracle)
- Rule-based Access Control
- Salting
- Sandbox Testing
- Sandboxing
- SASE
- SCADA - ICS
- Screened Subnet
- Scripting and Automation
- Secure Baseline
- Secure Cookie
- Secure Enclave
- Secure Protocol
- Security Assertion Markup Language (SAML)
- Security Awareness Training
- Security Consideration (Regulatory, Legal, Industry, Geographic)
- Security Content Automation Protocol (SCAP)
- Security Control Categories
- Security Control Types
- Security Guard
- Security Information and Event Management (SIEM)
- Security Orchestration, Automation, and Response (SOAR)
- Security Policy
- Security Procedure
- Security Reduction
- Security Standard
- Security Zone
- Security-Enhanced Linux (SELinux)
- Segmentation (Data Protection)
- Segmentation (Network)
- Self-Signed Certificate
- Sender Policy Framework (SPF)
- Sensors and Alarms
- Serverless Architecture
- Session Hijacking
- Shadow IT
- Sideloading
- Simple Network Management Protocol (SNMP)
- Single Sign-On (SSO)
- Site Resiliency
- Site Survey
- Smishing
- Software Defined Networking (SDN)
- Spraying Attack
- Spyware
- SQL Injection
- SSH Public-Private Key Format
- SSL Stripping
- Stack Canary
- Static Application Security Testing (SAST)
- Static-Key Generator Substitution Attack (Diffie-Hellman)
- Steganography
- Subject Alternative Name (SAN)
- Supply Chain Attack
- Supply Chain Vulnerability
- Surveillance Capitalism
- Tabletop Exercise
- Tailgating
- Technical Control
- The Pivot
- Third-Party Certificate Authority
- Third-party Risk Assessment
- Threat
- Threat Actor
- Threat Hunting
- Threat Intelligence
- Threat Modeling
- Three States of Data
- Time-of-day Restrictions
- Time-Seeded Encryption Key Weakness (Coarse Timestamp-Derived Keys)
- Timing Side-Channel Attack (Computational Cost as an Oracle)
- Tokenization
- Transport Encryption
- Trojan Horse
- Trusted Platform Module (TPM)
- Two-Person Integrity-Control
- Two-Time Pad (XOR Key Reuse)
- Typosquatting
- Ultrasonic Sensors
- Unified Threat Management (UTM)
- Unsecure Network Vector
- Unskilled Attacker
- Unsupported Systems Vector
- URL Scanning
- USB Blocking
- User Behavior Analytics
- Video Surveillance
- Virtualization
- Virtualization Vulnerability
- Virus
- Vishing
- VM Escape
- Volume Encryption
- VPN Concentrator
- Vulnerability
- Vulnerability Classification
- Vulnerability Remediation
- Vulnerability Scanning
- Vulnerable Software Vector
- Warm Site
- Watering Hole Attack
- Web Application Firewall (WAF)
- Wildcard Certificate
- Wireless Deauthentication Attack
- Wireless Security Mode
- Worm
- X.509 Certificate
- XOR-Instead-of-Exponentiation Notation Bug (Diffie-Hellman)
- Zero Trust
- Zero-Day Vulnerability
- Zerologon (AES-CFB8 Zero-State Keystream Collision)