Security Vulnerability Domains and Technical Analysis

Posted by Anonymous and classified in Computers

Written on in English with a size of 3.94 KB

Security Vulnerability Domains

This table outlines critical domains in security, detailing their underlying assumptions, common flaws, and defensive strategies.

DomainDefinitionPurposeRoot AssumptionTypical FlawExploited byAttacker NeedsObservable EffectConsequenceDifficultyMain DefensesExam Trigger Words
CertificationThird-party statement of complianceBuild trustRequirements well-definedWrong scopeCompliance gamingDocs, audits“Certified but insecure”False sense of securityMediumISO 17000 familyattestation, conformity
RepeatabilitySame tester, same setupReliabilityOperator consistencyHuman variancePoor testingSame labInconsistent resultsInvalid certLowCalibrationsame setup
ReproducibilityDifferent testers, same resultObjectivityMethod independenceWeak methodLab mismatchMultiple labsDivergent resultsUnusable certMediumStandardized methodsdifferent setups
MicroarchitectureISA implementation detailsPerformanceIsolation holdsShared resourcesSide-channelsLocal executionTiming/cache leaksSecret exposureHighHW+SW patchescache, OoO
SpeculationExecute before checksSpeedWrong paths invisibleSpeculative stateSpectreMispredictionCache pollutionIsolation breakVery highFencesbranch predictor
Side-ChannelPhysical leakageUnavoidable physicsNo observable diffTiming diffPrime+ProbeMeasurementKey recoveryCrypto breakHighNoise, isolationtiming
Race ConditionTiming-dependent logicParallelismAtomicityTOCTOURetry abuseTiming controlState desyncPrivilege escalationMediumLockswindow
Window of VulnerabilityGap between A and BSchedulingNo interferenceAssumption gapSymlink swapMany retriesWrong object usedRoot accessLowAtomic opsA→B
Low-Level MemoryCode & data as bytesFlexibilityCorrect addressingPointer confusionOverwriteMemory accessControl flow changeRCEMediumMemory safetypointer
Memory CorruptionInvalid memory accessUnsafe languagesBounds respectedOverflow/UAFROPBug triggerCrash or hijackFull compromiseMediumASLR, NXbuffer
Trusted ComputingVerify system integrityMalware stealthMeasurement truthfulCheating proverState forgeryControl systemFake “clean” stateUndetected malwareHighTPMroot of trust
KernelPrivileged OS coreResource controlBug-free codeNULL derefKernel exploitUser accessRing-0 executionTotal takeoverVery highSMEP/SMAPprivilege

Related entries: