click below
click below
Normal Size Small Size show me how
2.2
Common threat vectors and attack surfaces
| Term | Definition |
|---|---|
| Threat vector | How an attacker can gain unauthorized access to a system to do damage |
| Attack surface | Where an unauthorized user can try to enter/extract data from an environment |
| Messages (vector) | threats delivered via email or text |
| Images (vector) | embedding malicious code in an image file |
| Removeable devices (vector) | a USB, for example |
| Typosquatting (impersonation) | an attacker registers a domain name similar to a popular website but contains a typo |
| Watering hole attack (which kind of attack) | impersonation |
| Watering hole attack (definition) | attackers compromise a specific website/service that their target is known to use |
| Pretexting | attackers create a convincing fake scenario to manipulate their targets |
| Spear phishing | cybercriminals who are more tightly focused on a specific group of people or orgs |
| Whaling | spear phishing that targets high profile individuals like CEOs |
| Business email compromise (BEC) | advanced attack that leverages internal email accounts to manipulate employees into carrying out malicious actions |
| Vishing | phone based voice phishing |
| Smishing | sms text phishing |
| Fraud | being tricked into handing over personal info |
| Identity fraud | attacker takes victim's info to commit a crime; does not assume their identity |
| Influence campaign | coordinated efforts to affect public perception/behavior towards a particular cause or person/group |
| Misinformation | inaccurate info shared unintentionally |
| Disinformation | intentional spread of false info to deceive |
| Hoax | malicious deception often spread through social media, email, etc. |
| Baiting | planting a malware infected device for a victim to find and unintentionally introduce malware to their orgs. system |