Common · Knowledge
Attack vector
Method which malicious code utilizes to infect a computer or propagates itself
In computer security, an attack vector is a specific path, method, or scenario that can be exploited to break into an IT system, thus compromising its security. The term was derived from the corresponding notion of vector in biology.
From Wikipedia
In computer security, an attack vector is a specific path, method, or scenario that can be exploited to break into an IT system, thus compromising its security. The term was derived from the corresponding notion of vector in biology. An attack vector may be exploited manually, automatically, or through a combination of manual and automatic activity. Often, this is a multi-step process. For instance, malicious code (code that the user did not consent to being run and that performs actions the user would not consent to) often operates by being added to a harmless seeming document made available to an end user. When the unsuspecting end user opens the document, the malicious code in question (known as the payload) is executed and performs the abusive tasks it was programmed to execute, which may include things such as spreading itself further, opening up unauthorized access to the IT system, stealing or encrypting the user's documents, etc. In order to limit the chance of discovery once installed, the code in question is often obfuscated by layers of seemingly harmless code. Some common attack vectors: exploiting buffer overflows; this is how the Blaster worm was able to propagate. exploiting webpages and email supporting the loading and subsequent execution of JavaScript or other types of scripts without properly limiting their powers. exploiting networking protocol flaws to perform unauthorized actions at the other end of a network connection. phishing: sending deceptive messages to end users to entice them to reveal confidential information, such as passwords.
Text: Wikipédia, CC BY-SA 4.0. ·
Related cards
-
★★
Juice jacking
Mobile security risk
-
★★
Process (computing)
Particular execution of a computer program
-
★★★★
Information security
Practice of protecting information and systems by mitigating information risks
-
★★
Capture the flag (cybersecurity)
Computer security exercise in which "flags" are hidden in purposefully vulnerable programs or websites
-
B★
BlueBorne (security vulnerability)
Bluetooth vulnerability, an attack vector
-
C★★
Circuit (computer science)
Model of computation
-
V★★
Validator
Computer program used to check the validity or syntactical correctness of a fragment of code or document
-
C★★
Computer fraud
The act of using a computer to take or alter electronic data, or to gain unlawful use of a computer or system
-
A★
Automatic programming
Type of computer programming where some mechanism generates a computer program allowing programmers to write code at higher abstraction levels
-
V★★
Vector quantity
Physical quantity that is a vector
-
★★★
Access control
Selective restriction of access to a place or other resource, allowing only authorized users
-
★★★
Ransomware
Program that locks files until a sum of money is paid
-
O★★★
Obfuscation (software)
Creating difficult-to-understand computer code
-
A★
Active defense
-
B★★
Blowback (intelligence)
Unintended consequences of a covert operation that are suffered by the aggressor
-
★
Ciphertext
Encrypted information
-
★★★★
Infection
Invasion of and multiplication in a host by disease-causing pathogens or organisms, and the reaction of host tissues
-
P★
Pharming
Cyberattack intended to redirect a website's traffic to another, fake site