Network Security Library
Security Vulnerabilities
ATM Network Security: Vulnerabilities and Risks
Broadband Access Security: Cable Access and xDSL Lines
Communication Security at the Application Layer
Computer
Virus and Antivirus Technologies
Denial of Service (DoS) and Distributed Denial of Service (DDoS)
Ethernet LAN Security
Frame Relay Network Security: Vulnerabilities and Mitigations
ICMP Attacks
IP Spoofing
Land Attack
Network Security at the Data Link Layer (Layer 2) of LAN
Network Security at the Network Layer (Layer 3: IP)
Network Security at the Transport Layer (Layer 4: TCP and UDP)
Network Security of WAN: ATM, Frame Relay an Broadband Access
Pharming and Anti-pharming
Mitigations and Technologies
Phishing and Anti-phishing
Mitigations and Technologies
Port Scan Attack
Public-Key or Asymmetric Cryptography
RIP Routing Attacks
SPAM and Anti-Spam Technologies
Spyware and Anti-Spyware Mitigations and Technologies
Smurf Attack and Fraggle Attack
TCP Connecting Hijacking: MAN-In-The-Middle Attack
TCP "SYN" Attack
TCP/IP Network Vulnerability and Security
UDP Flood Attack Security Technologies
Biometric Technology and Its Application to Information Security
Cryptography, Data Encryption and Decryption Algorithms
Deep Inspection
IPsec Virtual Private Network (IPsec VPN)
L2TP / PPTP Virtual Private Network (VPN)
Layer 2/3 MPLS VPN based on BGP/MPLS
Packet Filtering
PKI: Public-Key Infrastructure
Secret-Key or Symmetric-Key Cryptography
SSL VPN: Secure Socket Layer Virtual Private Network
Stateful Inspection
Policies and Operations
DMZ: DeMilitarized Zone in Networks
Products and Solutions
ATM Network Security: Solutions, Technologies and Specifications
Firewall
IDS: Intrusion Detection System
IPS: Intrusion Protection/Prevention System
Network security related organizations
Information, Computer and Network Security Terms, Glossaries Dictionary
Numbers A B C D E F G H I J K L M N
O P Q R S T U V W X Y Z
0-day
128-bit encryption
128-bit keys
3DES: Triple DES
3-way handshake
40-bit encryption
56-bit encryption
64-bit encryption
64-bit keys
802.11i
802.11x
AAA server
AAA: Access control, Authorization, and Auditing
AAA: Authentication, Authorization, and Accounting
Access Control Service
Access Management
Access Point
Access Point Mapping
Access Token
Account Harvesting
ACF2: Access Control Facility 2
ACK Piggybacking
ACL: Access Control List
Active Attacks
Active Content
ActiveX
Activity Monitors
Add-on Security
Adware
AE: Authenticated Encryption
AES: Advanced Encryption Standard
AFIS: Automated Fingerprint Identification System
AH: Authentication Header
AirSnort
ALBB: Application-Level Behavior Blocking
Alias / Handle
Anna or Anna Kournikova virus
Anomaly Detection
Anonymous FTP
Anti-Adware
AntiGen
Anti-Phishing
AntiSniff
Anti-Spam
Anti-Spyware
Anti-Virus (Antivirus) Software
Anti-X
Applet
Application Filtering
Application Hardening
Application Level Gateway
Application Proxy
ARP Poisoning
ARP Spoofing
ARP: Address Resolution Protocol
ARPANET: Advanced Research Projects Agency Network
Asymmetric Algorithm
Asymmetric Cryptography
Asymmetric Warfare
ATM Security
Attack Vector
AUC: Authentication Centre
Audit Trail
Audit/Auditing
Authentication
Authentication Protocol
Authentication Server
Authentication Spoofing
Authentication Ticket
Authenticator
Authenticity
Authenticode
Authorization
Autonomous System
Availability
Back Orifice
Backdoor
Bandwidth
Banner
Basic Authentication
Bastion Host
Bayesian Analysis
Bayesian Filter
Bayesian Logic
BCP: Business Continuity Plan
Behavior Blocking
Bell-LaPadula Security Model
BGP/MPLS VPN
BIA: Business Impact Analysis
Biba Model
Bifurcation
BIND: Berkeley Internet Name Domain
BinHex
Biometric Verification
Biometrics
Birthday Attack
Birthday Paradox
Black Hat
Blacklist
Blended Attack
Blended Exploit
Blended Threat
Blind Spoofing Attack
Block Cipher
Blowfish
Blue Bomb
Bluejacking
Bluesnarf (Bluesnarfing)
Bluetooth
BO2K: Back Orifice 2000
Boot Record Infector
BOOTP (Bootstrap)
Botnet
Bounce Attack
BPCP: Business Process Contingency Plan
Brain Fingerprinting
Brain Scanning
Brainwave Detector
Brand Spoof or Brand Spoofing
British Standard 7799
Broadcast
Broadcast Address
Browser Hijacker
Brute Force
Brute Force Attack
Brute Force Cracking
Bucket Brigade
Buffer Overflow
Bugbear
BugTraq
C2: Class C2
CA: Certification Authority
CA-ACF2: Computer Associates Access Control Facility
Cache
Cache Cramming
Cache Poisoning
California Security Breach Information Act
Caller ID Spoofing
CAN-SPAM: Controlling the Assault of Non-Solicited Pornography and Marketing Act
Capture
Carding
Carnivore
CBC: Cipher Block Chaining
Cell Phone Spam
CER: Crossover Error Rate
CERT: Computer Emergency Response Team
Certificate-Based Authentication
Certification Request Syntax Standard
CFB: Ciphertext Feedback
CGI: Common Gateway Interface
cgi-bin
Chaffing
Chaffing and Winnowing
Chain of Custody
Challenge-Response
CHAP: Challenge-Handshake Authentication Protocol
Checksum
Chernobyl Virus
Chinese Wall Model
Chosen-Ciphertext Attack
Chosen-Plaintext Attack
CIAC: Computer Incident Advisory Capability
Cipher
Ciphertext
Ciphertext-Only Attack
Circuit Level Gateway/Firewall
CISO: Chief Information Security Officer
CISP: Cardholder Information Security Program
CISSP: Certified Information System Security Professional
CITU: Central Information Technology Unit
Clark-Wilson Model
Clipper
Clipper Chip
Cloud Cover
Cocooning
Cold Site
Collision
Computer Fraud
Confidentiality
Configuration Management
Connection Hijacking
Content Filtering
Content Security
Cookie
Cookie Poisoning
COPPA: Children's Online Privacy Protection Act
Corruption
Covert Channels
CPRM: Content Protection for Removable Media
CPS: Certification Practice Statement
Cracker
Cracking
CRAM: Challenge-Response Authentication Mechanism
CRAMM: CCTA Risk Analysis and Management Method
CRC: Cyclic Redundancy Check
CRL: Certificate Revocation List
Cron
Cryptanalysis
Cryptographic Algorithm
Cryptographic Checksum
Cryptographic Coprocessor
Cryptographic Message Syntax Standard
Cryptographic Token Interface Standard
Cryptography
Cryptoperiod
Cryptosystem: Cryptographic System
CSO: Chief Security Officer
CSS: Content Scrambling System
CSS: Cross Site Scripting (or XSS, cross-site malicious content)
CTCPEC: Canadian Trusted Computer Product Evaluation Criteria
Cyberslacker
Cyberterrorism or Cyberwarfare
Cyberwoozle
DAC: Discretionary Access Control
Daemon
Data Aggregation
Data Custodian
Data Integrity
Data Key
Data Mining
Data Protection Act 1984/1998
Data Retention
Data Splitting
Data Warehousing
Datagram
DDoS: Distributed Denial-of-Service Attack
Decapsulation
Decipher
Decode
Decrypt
Decryption
Deep Inspection
Defacement
Defamation Act, 1997 (UK)
Default ID or Default Password
Defense In-Depth
Deniable Encryption
Deperimeterization
Depository
DERA: Defence Evaluation and Research Agency
DES: Data Encryption Standard
DESX or DES-X
DHA: Directory Harvest Attack
DHCP Starvation
Dictionary Attack
Differential Cryptanalysis
Diffie-Hellman
Diffie-Hellman Key Agreement Standard
Digest Authentication
Digital Certificate
Digital Envelope
Digital Fingerprint
Digital Signature
Digital Silhouettes
DISA: Defense Information Systems Agency
Disassembly
Disaster Recovery
Disruption
Distributed Scans
DLL: Dynamic Link Library
DMCA: Digital Millennium Copyright Act
DMS: Defense Message System
DMZ: DeMilitarized Zone
DNS Attack
DNS Poisoning or DNS Cache Poisoning
DNS Spoofing
DNS: Domain Name System
Domain Hijacking
Domain Name
DomainKeys
Dongle
DoS Attack: Denial-of-Service Attack
DoS: Denial of Service
Drive-by Hacking
Drive-by Spamming
DRM: Digital Rights Management
DRP: Disaster Recovery Plan
DSA: Digital Signature Algorithm
DSO Exploit: Data Source Object Exploit
DSS: Digital Signature Standard
Dual Control
Dual-Homed Gateway
Due Care
Dumb Network
DumpSec
Dumpster Diving
Duress Feature
Dynamic Key Derivation
Dynamic Packet Filter
Dynamic Routing Protocol
E-911
EAP: Extensible Authentication Protocol
EAPoL: Extensible Authentication Protocol over LAN
EAPoW: Extensible Authentication Protocol over Wireless
EAR: Export Administration Regulations
Eavesdropping
ECB: Electronic Code Book
ECC: Elliptical Curve Cryptography
Echelon
Echo Reply
Echo Request
ECSS: Extended-Certificate Syntax Standard
EES: Escrowed Encryption Standard
EFS: Encrypting File System
Egress Filtering
Electrohippies Collective
Elk Cloner
EMAIL Attack
EMAIL Authentication
EMAIL Forgery
EMAIL Spoofing
Emanation Monitoring
Emanations Analysis
Encapsulation
Encryption
Ephemeral Port
Escrow Passwords
E-Signature
Ethical Hacker
Ethical Hacking
Ethical Worm
Evil Twin
Exploit
Exponential Backoff Algorithm
Exposure
False Acceptance
False Negative
False Positive
False Rejection
FAR: False Acceptance Rate
Faraday Cage
Fast File System
Fault Line Attacks
FH-CDMA: Frequency Hopping - Code Division Multiple Access
Filter
Filtering Router
Finger
Finger Image
Fingerprint Scanning
Firewall
Firewall Appliance
Fishing
Flooding Attack
Fluhrer, Martin and Shamir Attack
Footbath
Footprinting
Forensic Analysis
Forensics
Forest
Fork Bomb
Format String Attack
Form-Based Authentication
Forward Lookup
Forward Proxy
Forward Secrecy
Fragment Offset
Fragment Overlap Attack
Fragmentation
Frequency-Hopping Spread Spectrum
FRR: False Rejection Rate
FTP: File Transfer Protocol
Full Disclosure
Fully-Qualified Domain Name
Gethostbyaddr
Gethostbyname
GLBA: Gramm-Leach-Bliley Act
Glitch Attack
Global Spy Network
GNU
Gnutella
Goat
Good Worm
GPO: Group Policy Object
Graphical Password
Graphical User Authentication
Gray Hat
Group Policy Object
GSI: Government Secure Intranet
GTAC: Government Technical Assistance Centre
GUA: Graphic User Authentication
Hacker
Hacktivism
Hacktivist
Half-Open Scanning
Hardening
Harrison-Ruzzo-Ullman Model
Hash
Hash Function
Hashing
Heuristics
Hijack Attack
Hijacking
Hijackware
HIPAA: Health Insurance Portability & Accountability Act
HMAC: Keyed-Hash Message Authentication Code
Hoax Virus
Homeland Security Act
Honey Pot or Honeypot
Honeynet Project
Hops
Host-Based IDS
Hot Site
Hot Site and Cold Site
Hotfixes
HTTP Attack
HTTP Over SSL
HTTP Proxy
HTTPS
Hybrid Attack
Hybrid Encryption
Hybrid Virus
Hyperlink
Hyperlink Spoofing
IceNewk
ICMP Attack
ICMP Bug
ICMP Flood
ICMP Sweep
ICMP: Internet Control Message Protocol
ICV: Integrity Check Value
IDEA: International Data Encryption Algorithm
Identity
Identity Card
Identity Chaos
Identity Theft
IDS: Intrusion detection System
IETF: Internet Engineering Task Force
IKE: Internet Key Exchange
IM Spam
IM Worm
IMAP: Internet Message Access Protocol
Incident Handling
Incremental Backups
Inetd: Internet Daemon
Inference Attack
Information Signature
Information Sniffing
Information Warfare
Infranet Initiative
Ingress Filtering
Input Validation Attacks
Instant Spam
Integrity
Integrity Checker
Integrity Star Property
Internet Trail
Intrusion
Intrusion Detection
|
Intrusion Prevention
Inverse Mapping
IP Address
IP Flood
IP Forwarding
IP Fragmentation Attack
IP Sequence Prediction Attack
IP Spoofing
IP: Internet Protocol
IPS: Intrusion Prevension System
IPsec VPN
IPsec: Internet Protocol Security
ISA Server
ISAKMP: Internet Security Association and Key Management Protocol
ISAPI: Internet Server Application Programming Interface
Issue-Specific Policy
IT-ISAC: Information Technology Information Sharing and Analysis Center
ITSEC: Information Technology Security Evaluation Criteria
IV: Initialization Vector
Java
Java Beans
Java Stripping
JavaScript
Jitter
Joe-Job
Jump Bag
JVM: Java Virtual Machine KDC: Key Distribution Center
KDF: Key Derivation Function
Kerberos
Kernel
Key
Key Distribution
Key Escrow
Key Exchange Protocol
Key File
Key Fob
Key Logger
Key Management
Key Pair
Key Retrieval
Keyed Hash
Keyspace
keystroke Logger
Kilgetty
Klez Virus
KRI: Key Recovery Information
Kriz Virus
KSA: Key Scheduling Algorithm L0phtcrack
L2F: Layer 2 Forward Protocol
L2TP: Layer 2 Tunneling Protocol
Lamb
Land Attack
Layered Security
LDAP Attack
LDAP: Lightweight Directory Access Protocol
Leapfrog Attack
Least Privilege
Legion
Letterbomb
Lexical Analysis
Lifestyle Polygraph
Link Encryption
List Based Access Control
Live Capture
LKM: Loadable Kernel Modules
Location Poisoning
Log Clipping
Logic Bomb
Long ICMP
Loopback Address
Lucifer Algorithm
Luhn Check Digit Algorithm
LUHN Formula
Lunchtime Attack MAC Address
MAC Address Spoofing
MAC: Mandatory Access Control
MAC: Message Authentication Code
Macro Virus
Mail Bomb
Malicious Code
Malware
Masquerade
Masquerade Attack
MD2: Message-Digest Algorithm 2
MD4: Message-Digest Algorithm 4
MD5: Message-Digest Algorithm 5
Melissa Virus
Message Digest
Message Integrity Code
MICR: Magnetic Ink Character Recognition
Minutiae
MITM: Man in the Middle Attack
MMC: Microsoft Management Console
Mobile Phone Spam
Modification Detection Code
Modulus 10
Monoculture
Morris Worm
MPLS VPN
MPLS: Multiprotocol Label Switching
MPPE: Microsoft Point-to-Point Encryption
MS-CHAP: Microsoft Challenge Handshake Authentication Protocol
MSSP: Managed Security Service Provider
Multicast
Multi-Factor Authentication
Multi-Homed
Multi-Part Virus or Multipartite Virus
Multiple Key Pairs
Multizone Network NAPT: Network Address Port Translation
NAT: Network Address Translation
National Identity Card
NCSC: National Computer Security Center
Netmask
NetStumbler
Network Encryption
Network Forensics
Network Hardening
Network Mapping
Network Perimeter
Network Scanning
Network Sniffing
Network Taps
Network-Based IDS
NFC: Near Field Communication
NFS and NIS Attacks
Nimda
NIST: National Institute of Standards and Technolog
NMAP: Network Mapper
Node Spoofing
Nonce
Non-Repudiation
NSAKEY
Nuke Attack or Nuking
Null Session OATH: Open Authentication
OCSP: Online Certificate Status Protocol
OFB: Output Feedback
One-Time Pad
One-Way Encryption
One-Way Function
One-Way Hash
OpenSSL
OS Hardening
OTP: One Time Password
Overlapping Fragment Attack
Ownership Tag P equals NP
P versus NP
P3P: Platform for Privacy Preferences Project
Packet Filtering
Packet Monkey
Packet Sniffing
PAE: Port Access Entity
Palladium
PAP: Password Authentication Protocol
Pass Phrase or Passphrase
Passive FTP
Password
Password Aging
Password Attack
Password Chaos
Password Cracker
Password Cracking
Password Sniffing
Password Synchronization
Password-Based Crystography Standard
PASV FTP: Passive FTP
Patch
Patching
Penetration
Penetration Testing
Perl: Practical Extraction and Reporting Language
Permutation
Personal Firewalls
PFS: Perfect Forward Secrecy or Public-Key Forward Secrecy
PGP: Pretty Good Privacy
Phisher
Phishing
Phreak
PIESS: Personal Information Exchange Syntax Standard
Ping Flood
Ping of Death
Ping Scan
Ping Sweep
PING: Packet Internet Gopher
Piracy
PKCS: Public-Key Cryptography Standards
PKI: Public Key Infrastructure
PKISS: Private-Key Information Syntax Standard
PKIX: Public-Key Infrastructure X.509 Group
Plaintext
Poison Reverse
Policy-Based Management
Polyinstantiation
Polymorphic Virus
Polymorphism
Port Based Access Control
Port Mirroring
Port Scan
Port Scan Attack
Port Scanner
PPTP: Point-to-Point Tunneling Protocol
Preamble
Presence Technology
Privacy of Information or Data
Private Addressing
Private Key
Privilege of User
Program Infector
Program Policy
Promiscuous Mode
Proprietary Information
Proxy
Proxy Server
Pseudo Random Number Generator
Pseudonymous Profile
Public Key
Public Key Cryptography
Public Key Encryption
Pulsing Zombie
PUP: Potentially Unwanted Program
PWL: Password List File QAZ
Quantum Cryptography
Quarantine Area RA: Registration Authority
Race Condition
RACF: Resource Access Control Facility
Radiation Monitoring
RADIUS: Remote Authentication Dial-In User Service
Rainbow Series
Random Number
Random Number Generator
RARP: Reverse Address Resolution Protocol
RAS: Remote Access Service
RAT: Remote Administration Tool
RAT: Remote Administration Trojan
RBAC: Role Based Access Control
RC2/RC4
rDNS: Reverse DNS
Reconnaissance
Red Team
Redact
Reflexive ACLs (Cisco)
Remote Administration
Replay Attack
Residual Risk
Resource Exhaustion
Reverse Engineering
Reverse Lookup
Reverse Proxy
RID: Relative ID or Relative Identifier
Ridge
Rijndael
RIP Routing Attack
RIP: Routing Information Protocol
Risk Assessment
Rivest-Shamir-Adleman
ROKSO: Register of Known Spam Operations
Rootkit
Routing Daemon
Routing Loop
Roving Analysis Port
RPC Scans: Remote Procedure Call Scan
RSA Cryptography Standard
RSA: Rivest-Shamir-Adleman
RSBAC: Rule Set Based Access Control S/Key
Safe Architecture
Safe Harbor
Salt
SAML: Security Assertion Markup Language
SB-1386
Scavenging
SCR: Screen Saver Files
Script Kiddie (or Kiddy)
Script Vulnerability
Scunthorpe Test
Seat Management
Secret Key
Secret Key Algorithm
Secret Key Encryption
SecurID Token System
Security Audit
Security Clearance
Security Policy
Security Token
Security+ Certification
Sender ID
Sensitive Information
Separation of Duties
Server Accelerator Card
Service Packs
Session
Session Hijacking
Session Key
SET: Secure Electronic Transaction
S-FTP, or Secure FTP, S/FTP
SHA or SHA-1: Secure Hash Algorithm
Shadow Password File
Shadow Passwords
Share
Sheep
Sheep Dipping or Sheepdip
Shell
Shoulder Surfing
S-HTTP , or Secure HTTP, S/HTTP
SID: security identifier (ID)
Signals Analysis
Signature
Signature Detection
Simple Integrity Property
Simple Security Property
Skipjack
Slag Code
Smart Card
Smart Home or Building
S-MIME, or Secure MIME, S/MIME
SMS Spam
Smurf Attack or Smurfing
Snake Oil
Snarf Attack
Sn |