Computer Science · Ch 12 — Security Aspects
Summary
Summary
- Threats are potential dangers to a system; vulnerabilities are weaknesses that threats exploit. A risk is the chance of loss when a threat meets a vulnerability.
- Confidentiality keeps data secret from unauthorised users; integrity ensures data is not altered; availability means data and services are accessible when needed. Together these form the CIA triad.
- Authentication verifies who you are (passwords, biometrics, OTPs); authorisation decides what you may do after authentication. Non-repudiation prevents a user from denying an action they performed.
- Passwords should be long, mixed-case with digits and symbols, and never shared or reused. Two-factor authentication (2FA) adds a second check (e.g., OTP) beyond the password.
- Malware includes viruses (attach to files), worms (self-replicate over networks), Trojan horses (disguised as useful software), spyware (secretly monitors), and ransomware (locks data for payment).
- Phishing tricks users into revealing credentials via fake emails/sites; social engineering manipulates people directly. Denial of Service (DoS) floods a server to make it unavailable; DDoS does this from many machines.
- Firewalls filter incoming/outgoing traffic based on rules, acting as a barrier between a trusted internal network and untrusted outside networks.
- Encryption converts plaintext to ciphertext using a key. Symmetric encryption uses one shared key; asymmetric (public-key) uses a public key to encrypt and a private key to decrypt.
- Digital signatures use the sender's private key to sign a message; the receiver verifies it with the sender's public key, ensuring authenticity and integrity.
- Cookies store small data on the client; HTTP is unencrypted, while HTTPS uses SSL/TLS to encrypt communication between browser and server. …