What does system security protect against?
Unauthorized access, modification, destruction, data theft, malware, vulnerability exploitation, and denial of service.
What are the three components of the CIA Triad?
Confidentiality, integrity, and availability.
What does confidentiality limit in the CIA Triad?
Information access to authorized users.
What does integrity prevent in the CIA Triad?
Unauthorized modification or corruption.
What does availability ensure in the CIA Triad?
Systems and resources remain accessible when required.
What does authentication verify?
Who a user is.
What does authorization determine?
What an authenticated user may do.
What does accountability track?
Actions performed by users.
What is a control hijacking attack?
It manipulates a program's execution flow to run unintended or attacker-controlled code.
Which program elements are commonly targeted in control hijacking?
Return addresses, function pointers, jump addresses, exception handlers, and stack control information.
What causes a buffer overflow?
Writing more data into a fixed-size buffer than it can hold, overwriting adjacent memory.
What happens in a stack-based buffer overflow?
Data beyond a local buffer overwrites nearby stack data, including the return address.
What can happen when a function returns after a stack-based buffer overflow?
Execution may transfer to an unintended location.
Name common causes of buffer overflow.
Lack of bounds checking, unsafe string operations, incorrect memory management, improper input validation, and programming errors.
Which C functions are historically unsafe and can cause buffer overflows?
gets(), strcpy(), strcat(), and sprintf().
What value range does an unsigned 8-bit integer represent?
From 0 to 255.
What happens when you add 1 to 255 in an unsigned 8-bit integer?
It wraps around to 0.
What is the range of a 32-bit signed integer?
From to .
How can integer overflow cause buffer overflow vulnerabilities?
By turning large sizes into small values causing insufficient memory allocation.
Which programming aspects can integer overflow affect?
Memory allocation, array sizes, buffer sizes, loop conditions, file sizes, and length calculations.
Name some browser protections against attacks.
Sandboxing, ASLR, DEP/NX, site isolation, process isolation, and the Same-Origin Policy.
Can attackers bypass browser protections?
Yes, by exploiting additional vulnerabilities.
What is sandboxing in software execution?
Executing a program inside a restricted environment with limited access.
How does sandboxing restrict an application?
By enforcing policies and limited permissions on its actions.
What is the purpose of isolation in computing?
To separate processes or resources to prevent unwanted interaction.
What defines robust software behavior?
Continuing to behave safely and correctly under unexpected input or abnormal conditions.
Name one key technique to improve software robustness.
Input validation.
Name another key technique to improve software robustness.
Least privilege.
Name a third key technique to improve software robustness.
Secure memory management.
What does static analysis examine in program analysis?
A program without executing it.
What does dynamic analysis examine in program analysis?
A program during execution.
What does concolic analysis combine in program analysis?
Concrete execution with symbolic reasoning.
What vulnerabilities can static analysis detect?
Possible buffer overflows, uninitialized variables, dead code, memory problems, dangerous functions, some injection vulnerabilities, and incorrect data flows.
What are the limitations of static analysis?
It may produce false positives and miss runtime-dependent vulnerabilities.
What issues can dynamic analysis detect?
Memory violations, crashes, invalid memory accesses, runtime behavior, and resource problems.
What is the limitation of dynamic analysis?
It only explores executed paths.
What is the main limitation of concolic execution?
Path explosion.
What is a privilege in computer security?
Permission to perform a specific operation by a user, process, or program.
What does vertical privilege escalation involve?
Moving from a low-privileged user to a high-privileged user.
What does horizontal privilege escalation involve?
Accessing another user at a similar privilege level.
What is the purpose of access control?
To determine which subjects can access which resources and operations.
What question does authentication answer?
Who are you?
What question does authorization answer?
What are you allowed to do?
What does DAC allow in access control?
Resource owners decide access permissions.
On what basis does ABAC make access decisions?
Attributes like user, role, device, location, resource, time, and environment.
What does operating system security protect?
Processes, memory, files, users, devices, system calls, the kernel, and network resources.
What is process isolation in operating systems?
Each process has its own protected address space preventing direct memory access by others.
Which permissions can memory pages have in an OS?
Read, write, and execute permissions represented by R, W, and X.
What does an R-X memory page allow?
It is readable and executable but not writable.
Name some major operating-system security mechanisms.
Authentication, authorization, access control, process isolation, memory protection, privilege separation, secure boot, file permissions, auditing and logging, and security updates.
What is exploitation in software security?
It is the process of taking advantage of a software or system vulnerability to cause unintended behavior.
What happens during code injection attacks?
An attacker causes unintended code or commands to be executed.
What is a use-after-free vulnerability?
It occurs when a program uses memory after it has been released.
What risks can use-after-free vulnerabilities cause?
They can cause crashes, data corruption, unexpected behavior, or code-execution vulnerabilities.
What does return-oriented programming use to perform actions?
It uses existing instruction sequences called gadgets.
How does return-oriented programming achieve desired behavior?
By chaining gadgets without injecting a new program.
What is fuzzing in software testing?
An automated testing technique supplying unexpected or malformed inputs to a program.
What are the main steps in a basic fuzzing process?
Generate input, submit to application, monitor behavior, save notable inputs, analyze results.
What types of bugs can fuzzing discover?
Crashes, buffer overflows, integer bugs, memory corruption, parser vulnerabilities, and input-validation errors.
How does mutation-based fuzzing generate inputs?
By modifying valid inputs.
How does generation-based fuzzing create inputs?
From a specification or grammar.
What characterizes black-box fuzzing?
It has little internal knowledge of the program.
What distinguishes white-box fuzzing?
It uses the internal structure of the program.
What feedback does grey-box fuzzing use?
Limited feedback such as code coverage.
What does ASLR do in security defenses?
ASLR randomizes memory locations.
What is the difference between a vulnerability and an exploit?
A vulnerability is a system weakness; an exploit takes advantage of it.
What are the main program-analysis approaches?
Static, dynamic, and concolic analysis.
How does fuzzing differ from penetration testing?
Fuzzing tests inputs automatically; penetration testing assesses full attack paths.
What security defense prevents execution from data regions?
DEP/NX prevents execution from designated data regions.
What is the role of stack canaries in security?
Stack canaries detect certain stack overflows.
What does Control-Flow Integrity (CFI) enforce?
CFI restricts execution to valid control-flow paths.
What does sandboxing do in application security?
Sandboxing restricts compromised applications.
Test your knowledge with 29 questions on System Security Fundamentals.
1. Which statement best describes the overall purpose of system security?
2. A security policy prevents an unauthorized employee from viewing confidential files but permits authorized employees to read them. Which CIA Triad property does this policy primarily protect?
Review the complete course in the study sheet for System Security Fundamentals.
See study sheet →Import your course and AI generates flashcards in 30 seconds.
Flashcard generator