Invitation to Cybersecurity

Glossary 315 OpenSSL: a free command line utility that performs a large variety of cryptographic operations (9) OpenVAS: a vulnerability scanner that identifies weaknesses in computer systems and networks (3) operating system (OS): the program that runs continuously and underlies all of the other computer programs that run on the computer (2) packet: data sent over the Internet (2) packet capture (PCAP): a file that records network packets (8) packet filter firewall: a type of firewall that focuses only on metadata in the TCP and IP headers of individual packets (8) packet sniffer: an application that logs the network traffic processed by a computer’s NIC (2) packet switching: the process of directing packets one link at a time towards their destination (2) padding: extra bits added to round out a group of bits to the block size (7) passing the hash: an attack that takes advantage of trust relationships of a network to pivot to other machines (4) password: a secret string used as an authentication token based on the assumption that only the user knows it (8) password cracking: an attack against password hashes to reveal user passwords (4) password guessing: an attack where a hacker attempts to login as a user by guessing his password (4) password hash: the hash of a user’s password (4) password manager: a software solution that stores user credentials in an encrypted file (a.k.a. vault) (9) password spraying: an attack where a hacker attempts to login as any user by using the same few password guesses for many different usernames (4) patch Tuesday: the second Tuesday of every month when Microsoft and other software companies release their security bulletins (9) path: a set of links that leads from one node to another (2) patriotic hackers: hacking motivated by national pride (3) payload: the data portion of a packet (2) pen register: a device that records the metadata of electronic communications (10) Pen Register Act: a United States law that restricts the government’s access to telephone and Internet traffic metadata (10)

RkJQdWJsaXNoZXIy MTM4ODY=