📌 Authentication verifies who a user is, authorization determines what an authenticated user may do, and accountability tracks actions performed by users.
CIA: Confidentiality, Integrity, Availability
★ Must-know
Further detail
Control hijacking commonly targets:
Common causes and historically unsafe functions include:
Overflow → corrupted control data → unintended execution
★ Must-know
📐 Formula — An unsigned 8-bit integer represents values from 0 to 255, so through wraparound; a 32-bit signed integer ranges from to .
Integer overflow can turn a large calculated size into an unexpectedly small value, causing insufficient memory allocation and potentially enabling a buffer overflow.
Browser protections include:
Further detail
Input → arithmetic overflow → incorrect size → memory corruption
📌 Sandboxing restricts what an application can do through policies and limited permissions, whereas isolation separates processes, users, applications, or resources to prevent unwanted interaction.
Sandboxing restricts actions, whereas isolation separates components
★ Must-know
📌 Static analysis examines a program without executing it, dynamic analysis examines it during execution, and concolic analysis combines concrete execution with symbolic reasoning.
Further detail
Static analysis can detect:
Dynamic analysis can detect memory violations, crashes, invalid memory accesses, runtime behavior, and resource problems, but it only explores executed paths.
Static sees, dynamic does, concolic combines
📌 Vertical privilege escalation moves from a low-privileged user to a high-privileged user, whereas horizontal privilege escalation gives one user access to another user at a similar privilege level.
📌 Authentication answers “Who are you?”, whereas authorization answers “What are you allowed to do?” after authentication.
Authentication asks who, authorization asks what
★ Must-know
Operating system security protects:
Memory pages can have read, write, and execute permissions, represented by R, W, and X; an R-X page is readable and executable but not writable.
Further detail
Vulnerability → analysis → trigger → unintended behavior → impact
★ Must-know
📌 Mutation-based fuzzing modifies valid inputs, generation-based fuzzing creates inputs from a specification or grammar, black-box fuzzing has little internal knowledge, white-box fuzzing uses internal structure, and grey-box fuzzing uses limited feedback such as code coverage.
Further detail
Generate → execute → monitor → save → analyze
★ Must-know
📌 A vulnerability is a weakness in a system, an exploit is a technique, code, or input that takes advantage of the weakness, and an attack is broader malicious activity using vulnerabilities or exploits to achieve a goal.
Further detail
📌 Fuzzing is automated input testing focused on unexpected behavior, whereas penetration testing is a broader, usually scoped security assessment that investigates complete attack paths.
Vulnerability → exploit → attack → impact
| Feature | Static | Dynamic | Concolic |
|---|---|---|---|
| Program execution | No | Yes | Yes |
| Actual input | Not necessarily | Yes | Yes |
| Symbolic constraints | Usually no | Usually no | Yes |
| Main limitation | False positives | Missed paths | Path explosion |
| Model | Decision basis | Typical characteristic |
|---|---|---|
| DAC | Resource owner | Owner grants access |
| MAC | Central policy and labels | Strictly controlled environments |
| RBAC | Roles | Permissions assigned to roles |
| ABAC | Attributes and context | Uses user, device, location, time, and environment |
Test your knowledge on System Security Fundamentals with 29 multiple-choice questions with detailed corrections.
1. Which statement best describes the overall purpose of system security?
2. A security policy prevents an unauthorized employee from viewing confidential files but permits authorized employees to read them. Which CIA Triad property does this policy primarily protect?
Memorize the key concepts of System Security Fundamentals with 72 interactive flashcards.
What does system security protect against?
Unauthorized access, modification, destruction, data theft, malware, vulnerability exploitation, and denial of service.
What are the three components of the CIA Triad?
Confidentiality, integrity, and availability.
What does confidentiality limit in the CIA Triad?
Information access to authorized users.
Import your course and AI generates sheets, quizzes and flashcards in 30 seconds.
Sheet generator