π Authentication verifies who a user is, authorization determines what an authenticated user may do, and accountability tracks actions performed by users.
CIA: Confidentiality, Integrity, Availability
β Must-know
If a buffer has a capacity of 10 bytes and receives 20 bytes, the extra data may overwrite adjacent memory.
A stack-based buffer overflow can overwrite nearby stack data, including a return address, so that function return transfers execution to an unintended location.
Further detail
Unsafe memory write β corrupted control data β unintended execution
β Must-know
An unsigned 8-bit integer represents values from 0 to 255, so 255 plus 1 wraps around to 0.
An integer overflow can produce an unexpectedly small size, cause insufficient memory allocation, and lead to a potential buffer overflow.
Further detail
Arithmetic overflow β incorrect size β insufficient allocation β memory corruption
β Must-know
π Sandboxing limits damage from compromised software but does not guarantee security because a sandbox escape vulnerability can let an attacker break outside the restricted environment.
Further detail
Sandboxing restricts actions, whereas isolation separates components
β Must-know
π The principle of least privilege requires each user, process, or application to have only the minimum privileges needed to perform its task.
Further detail
Validate β encode β handle errors β minimize privileges β test
β Must-know
π Static analysis examines software without executing it, dynamic analysis examines it during execution, and concolic analysis combines concrete execution with symbolic reasoning.
Dynamic analysis can detect memory violations, crashes, invalid memory accesses, and resource problems, but it only explores executed paths.
Concolic execution runs concrete inputs while maintaining symbolic constraints, derives path constraints, and generates new inputs to explore alternative paths.
Further detail
Static analysis can detect:
The main limitation of concolic analysis is path explosion, in which the number of execution paths grows extremely quickly.
SDC: Static, Dynamic, Concolic
π Vertical privilege escalation moves from a low-privileged account to a high-privileged account, whereas horizontal privilege escalation moves to another account with a similar privilege level.
π Authentication answers who a user is, whereas authorization answers what that authenticated user is allowed to do.
Authentication asks who you are, whereas authorization asks what you may do
β Must-know
π Process isolation gives each process a protected address space so that one process should not directly access another process's memory.
Further detail
Vulnerability β analysis β trigger β unintended behavior β impact
A fuzzing campaign generates test input, runs the application, monitors for crashes or interesting behavior, saves useful inputs, and analyzes the results.
Fuzzing types include:
Generate β execute β monitor β save β analyze
π A vulnerability is a weakness in a system, an exploit is a technique, code, or input that takes advantage of the weakness, and an attack is broader malicious activity using vulnerabilities or exploits to achieve a goal.
Weakness β exploit β attack β impact
| Feature | Static | Dynamic | Concolic |
|---|---|---|---|
| Program execution | No | Yes | Yes |
| Actual input | Not necessarily | Yes | Yes |
| Symbolic constraints | Usually no | Usually no | Yes |
| Main limitation | False positives | Missed paths | Path explosion |
| Model | Decision basis | Typical role |
|---|---|---|
| DAC | Resource-owner choice | Owner grants access |
| MAC | Central policies and labels | Highly controlled environments |
| RBAC | Assigned roles | Permissions follow roles |
| ABAC | User, device, location, time, and other attributes | Context-dependent access |
Test your knowledge on System Security Fundamentals with 11 multiple-choice questions with detailed corrections.
1. Which security objective ensures that information is accessible to authorized users when it is needed?
2. A user successfully proves their identity and is then allowed to view but not alter a file. Which security functions are illustrated by these two steps?
Memorize the key concepts of System Security Fundamentals with 11 interactive flashcards.
What is system security?
Protection of computer systems and data from unauthorized access and threats.
What are the three components of the CIA triad?
Confidentiality, integrity, and availability.
What is a control hijacking attack?
It manipulates program flow to execute unintended or attacker-controlled code.
Import your course and AI generates sheets, quizzes and flashcards in 30 seconds.
Sheet generator