Common · Knowledge
Attack vector
Method which malicious code utilizes to infect a computer or propagates itself
In computer security, an attack vector is a specific path, method, or scenario that can be exploited to break into an IT system, thus compromising its security. The term was derived from the corresponding notion of vector in biology.
From Wikipedia
In computer security, an attack vector is a specific path, method, or scenario that can be exploited to break into an IT system, thus compromising its security. The term was derived from the corresponding notion of vector in biology. An attack vector may be exploited manually, automatically, or through a combination of manual and automatic activity. Often, this is a multi-step process. For instance, malicious code (code that the user did not consent to being run and that performs actions the user would not consent to) often operates by being added to a harmless seeming document made available to an end user. When the unsuspecting end user opens the document, the malicious code in question (known as the payload) is executed and performs the abusive tasks it was programmed to execute, which may include things such as spreading itself further, opening up unauthorized access to the IT system, stealing or encrypting the user's documents, etc. In order to limit the chance of discovery once installed, the code in question is often obfuscated by layers of seemingly harmless code. Some common attack vectors: exploiting buffer overflows; this is how the Blaster worm was able to propagate. exploiting webpages and email supporting the loading and subsequent execution of JavaScript or other types of scripts without properly limiting their powers. exploiting networking protocol flaws to perform unauthorized actions at the other end of a network connection. phishing: sending deceptive messages to end users to entice them to reveal confidential information, such as passwords.
Text: Wikipédia, CC BY-SA 4.0. ·
Related cards
-
★★
Clickjacking
Malicious technique of tricking a Web user
-
★★★★
Malware
Software that is intentionally hostile, intrusive, or damaging to a computer or network
-
W★
Web shell
Malicious web-based shell-like interface
-
★★★
Patch (computing)
Piece of software designed to update a computer program to fix or improve it
-
★★★
Man-in-the-middle attack
Form of active eavesdropping in which the attacker makes connections with the victims and relays messages between them
-
★★★★
Hacker
Person who uses technical knowledge to achieve a goal within a computerized system by non-standard means
-
C★★
Cyberterrorism
Using attacks based on the Internet or other computer and telecommunications networks for terrorist purposes
-
★★★
Cybercrime
Any crime that involves a computer and a network
-
★
Antisec Movement
Hacking (computer security)
-
P★★★
Penetration test
Method of evaluating computer and network security by simulating a cyber attack
-
★★
Vector graphics editor
Computer program to make and change vector graphics images
-
C★
Collision attack
Cryptographic attack
-
★★
Vector-06C
Home computer model
-
S★
Secure coding
Practice of avoiding accidental introduction of security vulnerabilities while developing software
-
★★★★
Computer virus
Type of computer program that, when executed, replicates itself by modifying other computer programs and inserting its own code
-
★★★★
Euclidean vector
Geometric object that has magnitude (or length) and direction
-
★
security system
Integrated technologies and processes used to protect people, property, and assets from threats
-
★★
Thrust vectoring
Ability of an aircraft or other craft to manipulate the direction of an engine thrust (e.g. jet or rocket engine)