Attack Strategy: is the process of gathering information about an organization, including: System hardware information Network configuration Individual user information, is the process of manipulating others into providing sensitive information. Social engineering tactics include: Intimidation Sympathy, approach to obtaining information includes using software or utilities to find vulnerabilities in a system. Methods often used by hackers are: Port scan Ping sweep, is the penetration of system defenses. It is often achieved by using information gathered by through reconnaissance., is a primary objective of an attacker. Once an attacker has breached the system, obtaining higher privileges allows the attacker to access more information and gain greater control within the system., is an alternative method of accessing an application or operating system for troubleshooting. Hackers often create backdoors to exploit a system without being detected., a computer involves preparing it to perform additional tasks in the attack, such as installing software designed to attack other systems. This is an optional step., takes advantage of known vulnerabilities in software and systems. Once a vulnerability has been exploited, an attacker can often: Steal information Deny services Crash systems Modify/alter information, Defense Methodology: involves implementing multiple security strategies to protect the same asset. Defense in depth or security in depth is based on the premise that no single layer is completely effective in securing assets. The most secure system/network has many layers of security and eliminates single points of failure., states that users or groups are given only the access they need to do their jobs and nothing more. When assigning privileges, be aware that it is often easier to give a user more access when it is needed than to take away privileges that have already been granted., should incorporate a variety of methods. Implementing multiple layers of the same defense does not provide adequate protection against attacks., in security is the constant change in personal habits and passwords to prevent predictable behavior., security measures should provide protection, but not be so complex that it is difficult to understand and use them.,
0%
2.1 Attack & Defense
共享
共享
共享
由
Mrspendrak
G11
CTE
CS
编辑内容
打印
嵌入
更多
作业
排行榜
显示更多
显示更少
此排行榜当前是私人享有。单击
,共享
使其公开。
资源所有者已禁用此排行榜。
此排行榜被禁用,因为您的选择与资源所有者不同。
还原选项
按组分配
是一个开放式模板。它不会为排行榜生成分数。
需要登录
视觉风格
字体
需要订阅
选项
切换模板
显示所有
播放活动时将显示更多格式。
打开成绩
复制链接
QR 代码
删除
恢复自动保存:
?