Study sheet: System Security Fundamentals

Course Outline

  1. Security Objectives and Properties
  2. Control Hijacking and Buffer Overflows
  3. Integer Overflow and Memory Safety
  4. Browser Defenses and Isolation
  5. Robust Software Development
  6. Program Analysis Methods
  7. Privileges and Access Control
  8. Operating System Protection
  9. Exploitation Techniques and Defenses
  10. Fuzzing and Vulnerability Detection
  11. Vulnerability Exploit and Attack

1. Security Objectives and Properties

Key Concepts & Definitions

  • System Security : the protection of computer systems, operating systems, applications, networks, and data from unauthorized access, modification, destruction, data theft, malware, vulnerability exploitation, and denial of service

Essential Points

  • The CIA triad consists of:
    • confidentiality
    • integrity
    • availability

πŸ“Œ Authentication verifies who a user is, authorization determines what an authenticated user may do, and accountability tracks actions performed by users.

Memory Hook

CIA: Confidentiality, Integrity, Availability

2. Control Hijacking and Buffer Overflows

Key Concepts & Definitions

  • Control Hijacking : an attack that manipulates a program's execution flow so that it executes unintended instructions or attacker-controlled code
  • Buffer Overflow : a condition in which a program writes more data into a fixed-size memory buffer than the buffer can hold

β˜… Must-know

  • If a buffer has a capacity of 10 bytes and receives 20 bytes, the extra data may overwrite adjacent memory.

  • A stack-based buffer overflow can overwrite nearby stack data, including a return address, so that function return transfers execution to an unintended location.

Further detail

  • Common causes include:
    • lack of bounds checking
    • unsafe string operations
    • incorrect memory management
    • improper input validation
    • programming errors

Memory Hook

Unsafe memory write β†’ corrupted control data β†’ unintended execution

3. Integer Overflow and Memory Safety

Key Concepts & Definitions

  • Integer Overflow : a condition in which an arithmetic operation produces a value outside the range representable by the integer data type

β˜… Must-know

  • An unsigned 8-bit integer represents values from 0 to 255, so 255 plus 1 wraps around to 0.

  • An integer overflow can produce an unexpectedly small size, cause insufficient memory allocation, and lead to a potential buffer overflow.

Further detail

  • The representable range of a 32-bit signed integer is βˆ’231-2^{31} to 231βˆ’12^{31}-1.

Memory Hook

Arithmetic overflow β†’ incorrect size β†’ insufficient allocation β†’ memory corruption

4. Browser Defenses and Isolation

Key Concepts & Definitions

  • Sandboxing : a security mechanism that executes a program inside a restricted environment with limited access to files, networks, hardware, processes, system calls, and sensitive data
  • Isolation : the separation of processes, users, applications, or resources so that compromising one component does not automatically compromise the others

β˜… Must-know

πŸ“Œ Sandboxing limits damage from compromised software but does not guarantee security because a sandbox escape vulnerability can let an attacker break outside the restricted environment.

Further detail

  • Browser protections include:
    • sandboxing
    • ASLR
    • DEP/NX
    • site isolation
    • process isolation
    • the Same-Origin Policy

Memory Hook

Sandboxing restricts actions, whereas isolation separates components

5. Robust Software Development

Key Concepts & Definitions

  • Robust Software : software that continues to behave safely and correctly when it receives unexpected input or encounters abnormal conditions

β˜… Must-know

  • Input validation should check:
    • type
    • length
    • range
    • format
    • encoding

πŸ“Œ The principle of least privilege requires each user, process, or application to have only the minimum privileges needed to perform its task.

Further detail

  • Secure software practices include:
    • safe error handling
    • secure defaults
    • code review
    • unit testing
    • integration testing
    • security testing
    • fuzz testing
    • penetration testing

Memory Hook

Validate β†’ encode β†’ handle errors β†’ minimize privileges β†’ test

6. Program Analysis Methods

β˜… Must-know

πŸ“Œ Static analysis examines software without executing it, dynamic analysis examines it during execution, and concolic analysis combines concrete execution with symbolic reasoning.

  • Dynamic analysis can detect memory violations, crashes, invalid memory accesses, and resource problems, but it only explores executed paths.

  • Concolic execution runs concrete inputs while maintaining symbolic constraints, derives path constraints, and generates new inputs to explore alternative paths.

Further detail

  • Static analysis can detect:

    • possible buffer overflows
    • uninitialized variables
    • dead code
    • memory problems
    • dangerous function usage
    • injection vulnerabilities
    • incorrect data flows
  • The main limitation of concolic analysis is path explosion, in which the number of execution paths grows extremely quickly.

Memory Hook

SDC: Static, Dynamic, Concolic

7. Privileges and Access Control

Key Concepts & Definitions

  • Privilege : permission granted to a user, process, or program to perform a particular operation
  • Access Control : the determination of which subjects may access which resources and which operations they are allowed to perform

Essential Points

πŸ“Œ Vertical privilege escalation moves from a low-privileged account to a high-privileged account, whereas horizontal privilege escalation moves to another account with a similar privilege level.

πŸ“Œ Authentication answers who a user is, whereas authorization answers what that authenticated user is allowed to do.

  • DAC lets resource owners determine access, MAC applies centrally enforced policies and labels, RBAC assigns permissions to roles, and ABAC bases decisions on attributes such as user, role, device, location, resource, time, and environment.

Memory Hook

Authentication asks who you are, whereas authorization asks what you may do

8. Operating System Protection

β˜… Must-know

  • Operating-system security protects:
    • processes
    • memory
    • files
    • users
    • devices
    • system calls
    • the kernel
    • network resources

πŸ“Œ Process isolation gives each process a protected address space so that one process should not directly access another process's memory.

  • Memory pages may have read, write, and execute permissions, represented by R, W, and X; an R-X page is readable and executable but not writable.

Further detail

  • Major operating-system security mechanisms include authentication, authorization, access control, process isolation, memory protection, privilege separation, secure boot, file permissions, auditing, logging, and security updates.

9. Exploitation Techniques and Defenses

Key Concepts & Definitions

  • Exploitation : the process of taking advantage of a software or system vulnerability to cause unintended behavior
  • Code Injection : Code injection occurs when an attacker causes unintended code or commands to be interpreted or executed, as in SQL injection, command injection, or script injection.
  • Use-After-Free : a vulnerability in which a program uses memory after that memory has already been released
  • Return-Oriented Programming : an exploitation technique that uses existing instruction sequences called gadgets to produce desired behavior without injecting an entire new program

Essential Points

  • Important defenses include:
    • ASLR
    • DEP/NX
    • stack canaries
    • CFI
    • sandboxing
    • least privilege

Memory Hook

Vulnerability β†’ analysis β†’ trigger β†’ unintended behavior β†’ impact

10. Fuzzing and Vulnerability Detection

Key Concepts & Definitions

  • Fuzzing : an automated testing technique that supplies large amounts of unexpected, malformed, random, or specially generated input to a program and monitors its behavior
  • Coverage-Guided Fuzzing : fuzzing that monitors which program regions are executed and mutates inputs to explore new execution paths

Essential Points

  • A fuzzing campaign generates test input, runs the application, monitors for crashes or interesting behavior, saves useful inputs, and analyzes the results.

  • Fuzzing types include:

    • mutation-based fuzzing
    • generation-based fuzzing
    • black-box fuzzing
    • white-box fuzzing
    • grey-box fuzzing

Memory Hook

Generate β†’ execute β†’ monitor β†’ save β†’ analyze

11. Vulnerability Exploit and Attack

Essential Points

πŸ“Œ A vulnerability is a weakness in a system, an exploit is a technique, code, or input that takes advantage of the weakness, and an attack is broader malicious activity using vulnerabilities or exploits to achieve a goal.

  • The relationship among these concepts is vulnerability, exploit, attack, and impact.

Memory Hook

Weakness β†’ exploit β†’ attack β†’ impact

Synthesis Tables

Program Analysis Comparison

FeatureStaticDynamicConcolic
Program executionNoYesYes
Actual inputNot necessarilyYesYes
Symbolic constraintsUsually noUsually noYes
Main limitationFalse positivesMissed pathsPath explosion

Access Control Models

ModelDecision basisTypical role
DACResource-owner choiceOwner grants access
MACCentral policies and labelsHighly controlled environments
RBACAssigned rolesPermissions follow roles
ABACUser, device, location, time, and other attributesContext-dependent access

Test your knowledge

Test your knowledge on System Security Fundamentals with 11 multiple-choice questions with detailed corrections.

1. Which security objective ensures that information is accessible to authorized users when it is needed?

2. A user successfully proves their identity and is then allowed to view but not alter a file. Which security functions are illustrated by these two steps?

Take the quiz β†’

Review with flashcards

Memorize the key concepts of System Security Fundamentals with 11 interactive flashcards.

What is system security?

Protection of computer systems and data from unauthorized access and threats.

What are the three components of the CIA triad?

Confidentiality, integrity, and availability.

What is a control hijacking attack?

It manipulates program flow to execute unintended or attacker-controlled code.

See flashcards β†’

Similar courses

Create your own study sheets

Import your course and AI generates sheets, quizzes and flashcards in 30 seconds.

Sheet generator