Common · Knowledge
Attack vector
Method which malicious code utilizes to infect a computer or propagates itself
In computer security, an attack vector is a specific path, method, or scenario that can be exploited to break into an IT system, thus compromising its security. The term was derived from the corresponding notion of vector in biology.
From Wikipedia
In computer security, an attack vector is a specific path, method, or scenario that can be exploited to break into an IT system, thus compromising its security. The term was derived from the corresponding notion of vector in biology. An attack vector may be exploited manually, automatically, or through a combination of manual and automatic activity. Often, this is a multi-step process. For instance, malicious code (code that the user did not consent to being run and that performs actions the user would not consent to) often operates by being added to a harmless seeming document made available to an end user. When the unsuspecting end user opens the document, the malicious code in question (known as the payload) is executed and performs the abusive tasks it was programmed to execute, which may include things such as spreading itself further, opening up unauthorized access to the IT system, stealing or encrypting the user's documents, etc. In order to limit the chance of discovery once installed, the code in question is often obfuscated by layers of seemingly harmless code. Some common attack vectors: exploiting buffer overflows; this is how the Blaster worm was able to propagate. exploiting webpages and email supporting the loading and subsequent execution of JavaScript or other types of scripts without properly limiting their powers. exploiting networking protocol flaws to perform unauthorized actions at the other end of a network connection. phishing: sending deceptive messages to end users to entice them to reveal confidential information, such as passwords.
Text: Wikipédia, CC BY-SA 4.0. ·
Related cards
-
★★
Graphics software
Software intended to manipulate visual images on a computer
-
D★
Dictionary attack
Technique for defeating a cipher or authentication mechanism by trying to determine its decryption key or passphrase by trying hundreds or sometimes millions of likely possibilities, such as words in a dictionary
-
R★★
Remote access trojan
Type of malware capable of controlling a system through a remote network connection
-
F★
Flame (malware)
Modular computer malware
-
C★★★
Cracker (computing)
Someone who cracks digital security
-
★★
Intrusion detection system
A device or software application that monitors a network or systems for malicious activity
-
★★★
Semaphore (programming)
Variable that is changed (e.g., incremented, decremented, toggled) depending on programmer-defined conditions, used to control access to a common resource by multiple processes in a concurrent system
-
★★★
attack
Action to injure another organism
-
★★
Spectre (security vulnerability)
Security vulnerability in microprocessors performing branch prediction
-
C★★★★
Cross-site request forgery
Type of malicious exploit of a website where unauthorized commands are transmitted from a user trusted by the web app, using image tags, hidden forms, XMLHttpRequest etc.
-
★★
LockBit
Criminal hacking organization
-
★★
Vehicle-ramming attack
Terrorism tactic of ramming a vehicle into people or structures
-
S★★★★
Spyware
Malware designed to secretly monitor activity and collect information from digital devices without the user's knowledge
-
V★★★
Vectorious
Medical technology company
-
★
Vectorworks
CAD software
-
★★
Juice jacking
Mobile security risk
-
★★
Process (computing)
Particular execution of a computer program
-
★★★★
Information security
Practice of protecting information and systems by mitigating information risks