Comum · Saberes
Attack vector
Method which malicious code utilizes to infect a computer or propagates itself
In computer security, an attack vector is a specific path, method, or scenario that can be exploited to break into an IT system, thus compromising its security. The term was derived from the corresponding notion of vector in biology.
Na Wikipédia
Texto em inglês Ainda não há artigo no seu idioma: trecho em inglês.
In computer security, an attack vector is a specific path, method, or scenario that can be exploited to break into an IT system, thus compromising its security. The term was derived from the corresponding notion of vector in biology. An attack vector may be exploited manually, automatically, or through a combination of manual and automatic activity. Often, this is a multi-step process. For instance, malicious code (code that the user did not consent to being run and that performs actions the user would not consent to) often operates by being added to a harmless seeming document made available to an end user. When the unsuspecting end user opens the document, the malicious code in question (known as the payload) is executed and performs the abusive tasks it was programmed to execute, which may include things such as spreading itself further, opening up unauthorized access to the IT system, stealing or encrypting the user's documents, etc. In order to limit the chance of discovery once installed, the code in question is often obfuscated by layers of seemingly harmless code. Some common attack vectors: exploiting buffer overflows; this is how the Blaster worm was able to propagate. exploiting webpages and email supporting the loading and subsequent execution of JavaScript or other types of scripts without properly limiting their powers. exploiting networking protocol flaws to perform unauthorized actions at the other end of a network connection. phishing: sending deceptive messages to end users to entice them to reveal confidential information, such as passwords.
Texto: Wikipédia em inglês, CC BY-SA 4.0. ·
Cartas próximas
-
★★
Juice jacking
-
P★★
Processo (informática)
-
★★★★
Segurança da informação
Proteger as informações mitigando os riscos das informações
-
★★
Capture the flag (cybersecurity)
Computer security exercise in which "flags" are hidden in purposefully vulnerable programs or websites
-
B★
BlueBorne (security vulnerability)
Bluetooth vulnerability, an attack vector
-
C★★
Circuit (computer science)
Model of computation
-
V★★
Validator
Computer program used to check the validity or syntactical correctness of a fragment of code or document
-
F★★
Fraude eletrônica
Uso tecnologia da informação para cometer fraude
-
P★
Programação automática
-
q★★
quantidade vetorial
Quantidade física que é um vetor
-
★★★
Controle de acesso
-
★★★
Ransomware
Um tipo de software nocivo que restringe o acesso ao sistema infectado e cobra um resgate para que o acesso possa ser restabelecido
-
O★★★
Ofuscação (software)
-
A★
Active defense
-
B★★
Blowback (intelligence)
Unintended consequences of a covert operation that are suffered by the aggressor
-
★
Ciphertext
Encrypted information
-
★★★★
Infecção
Entrada, desenvolvimento e multiplicação de um patógeno no corpo de um organismo vivo
-
P★
Pharming