up

2020-01-27 -

STRIDE Security Properties

Name Threat Definition
Authentication Spoofing impersonating something/one else
Integrity Tampering Modifying data/code
Non-repudiation Repudiation Claiming to have not performed an action
Confidentiality Information Disclosure Exposing info to someone not authorized to see it
Availability Denial of Service Deny or degrade service
Authorization Elevation of Privilege Gain capabilities without proper authorization

Freshness is not in the framework, but it is important.

HB, what’s Freshness?

Read about: Pakistan attempting to block youtube

A switch is considered a dumb device that nobody cares about. But lots of things can go wrong here.

CAM Floods

Filling a switch table such that it broadcasts all traffic.

DHCP

A router can become a relay station, and forward DHCP DISCOVER messages. This allows a single server to serve multiple networks.

An attacker can eat all the addresses.