Link copied to clipboard

Cyber Security Body of Knowledge (CyBOK) Version 1.1.0

draft Competency Framework · v1.1.0

CyBOK Version 1.1.0 (31 July 2021): 5 broad categories, 21 Knowledge Areas (including Applied Cryptography and Formal Methods for Security added in v1.1), and the official knowledge-tree topic nodes from CyBOK_Knowledge_trees_topic_list_1.1.0.csv. competencyText values are competency-style statements; official KA descriptions and topic labels are preserved in comments/descriptions. CyBOK Version 1.1.0 © Crown Copyright, The National Cyber Security Centre 2021, licensed under the Open Government Licence: https://www.nationalarchives.gov.uk/doc/open-government-licence/. Generated for TLA Toolbox import 2026-08-27. Source: https://www.cybok.org/.

Competencies2021
View CTDL-ASN JSON-LD View IEEE SCD JSON-LD Download Markdown Docs Log in to browse full details

Competencies (2021)

Human, Organisational and Regulatory AspectsCyBOK Category
Human FactorsHuman, Organisational and Regulatory Aspects
usable securityHuman Factors
assessment criteriaHuman Factors
effectivenessHuman Factors
efficiencyHuman Factors
satsifactionHuman Factors
fitting the task to the humanHuman Factors
human capabilities and limitationsHuman Factors
ethicsLaw & Regulation
alarm fatigueHuman Factors
short term memoryHuman Factors
one-time passwordsHuman Factors
improving memoryHuman Factors
long term memoryHuman Factors
passwordsHuman Factors
human biasesHuman Factors
needs of specific groupsHuman Factors
childrenHuman Factors
CAPTCHAsHuman Factors
older citizensHuman Factors
cultural needsHuman Factors
disabilityHuman Factors
goals and tasksHuman Factors
production and enabling tasksHuman Factors
workarounds to security mechanismsHuman Factors
workloadHuman Factors
workload measurementHuman Factors
compliance budgetHuman Factors
security fatigueHuman Factors
compliance fatigueHuman Factors
interaction contextHuman Factors
contextual inquiryHuman Factors
physical characteristicsHuman Factors
lightHuman Factors
noiseHuman Factors
temperatureHuman Factors
pollutionHuman Factors
social contextHuman Factors
device capabilities and limitationsHuman Factors
human errorHuman Factors
latent usability failures in systems-of-systemsHuman Factors
thinking, fast and slowHuman Factors
mixed-mode thinkingHuman Factors
shadow securityHuman Factors
security hygieneHuman Factors
awareness and educationHuman Factors
termsHuman Factors
awarenessHuman Factors
only the first stepHuman Factors
educationHuman Factors
trainingHuman Factors
new approachesHuman Factors
security awareness gamesHuman Factors
mental models of cyber risks and defencesHuman Factors
positive securityHuman Factors
fear uncertainty and doubtHuman Factors
people are not the weakest linkHuman Factors
stakeholder engagementHuman Factors
employeesHuman Factors
projective techniquesHuman Factors
creative security engagementsHuman Factors
physical modelsHuman Factors
software developersHuman Factors
developers and password securityHuman Factors
app development and vulnerabilitiesHuman Factors
StackOverflowHuman Factors
API usabailityHuman Factors
disconnects between developers and usersHuman Factors
Law & RegulationHuman, Organisational and Regulatory Aspects
introductory principles of legal researchLaw & Regulation
nature of law and legal analysisLaw & Regulation
legal terminologyLaw & Regulation
applying law to cyberspace and information technologiesLaw & Regulation
criminal lawLaw & Regulation
civil lawLaw & Regulation
liability and courtsLaw & Regulation
evidence and proofLaw & Regulation
holistic approaches to legal risk analysisLaw & Regulation
jurisdictionLaw & Regulation
prescriptive jurisdictionLaw & Regulation
prescriptive jurisdiction over online contentLaw & Regulation
prescriptive jurisdiction over computer crimeLaw & Regulation
prescriptive jurisdiction and data protectionLaw & Regulation
GDPRLaw & Regulation
enforcement jurisdictionLaw & Regulation
asset seizure and forfeitureLaw & Regulation
seizure and forfeiture of servers domain names and registriesLaw & Regulation
territorial location of the right to demand repayment of bank depositsLaw & Regulation
foreing recognition and enforcement of civil judgmentsLaw & Regulation
arrest of natural persons in state territoryLaw & Regulation
extradition of natural personsLaw & Regulation
technological content filteringLaw & Regulation
orders to in-state persons directing production of data under their control whether held on domestic or foreign IT systemsLaw & Regulation
international legal assistanceLaw & Regulation
data sovereigntyLaw & Regulation
privacy laws in general and electronic interceptionLaw & Regulation
international normsLaw & Regulation
metadataLaw & Regulation
human rightsLaw & Regulation
interception by a stateLaw & Regulation
interception by persons other than statesLaw & Regulation
enforcement of privacy lawsLaw & Regulation
data protectionLaw & Regulation
subject matter and regulatory focusLaw & Regulation
data subject, personal data (and PII)Law & Regulation
definitionsLaw & Regulation
de-anonymisationLaw & Regulation
processingLaw & Regulation
controller and processorLaw & Regulation
core regulatory principlesLaw & Regulation
investigation and prevention of crimeLaw & Regulation
transfers pursuant to international mutual legal assistance treatyLaw & Regulation
derogations allowing transfersLaw & Regulation
personal data breach notificationLaw & Regulation
enforcement and penaltiesLaw & Regulation
computer crimeLaw & Regulation
crimes against information systemsLaw & Regulation
improper access to a systemLaw & Regulation
improper interference with dataLaw & Regulation
improper interference with systemsLaw & Regulation
improper interception of communicationLaw & Regulation
de minimis exceptions to crimes against information systemsLaw & Regulation
the enforcement of and penalties for crimes against information systemsLaw & Regulation
warranted state activityLaw & Regulation
research and development activities conducted by non-state personsLaw & Regulation
self-help disfavoured: software locks and hack-backLaw & Regulation
undisclosed software locksLaw & Regulation
hack-backLaw & Regulation
contractLaw & Regulation
online contractsLaw & Regulation
time of contract and receipt of contractual communicationLaw & Regulation
encouraging security standards via contractLaw & Regulation
supply chainLaw & Regulation
closed trading and payment systemsLaw & Regulation
freedom of contract and its limitationsLaw & Regulation
wanarties and their exclusionLaw & Regulation
limitations of liability and exclusions of liabilityLaw & Regulation
breach of contract and remediesLaw & Regulation
effects of contract on non-contracting partiesLaw & Regulation
conflict of law -- contractsLaw & Regulation
intellectual propertyLaw & Regulation
understanding intellectual propertyLaw & Regulation
catalogue of intellectual property rightsLaw & Regulation
copyrightLaw & Regulation
patentsLaw & Regulation
trademarksLaw & Regulation
trade secretsLaw & Regulation
enforcement -- remediesLaw & Regulation
criminal liabilityLaw & Regulation
civil liabilityLaw & Regulation
reverse engineeringLaw & Regulation
circumventing copyright technological protection measuresLaw & Regulation
testing a proprietary cryptographic algorithmLaw & Regulation
international treatment and conflict of lawLaw & Regulation
internet intermediariesLaw & Regulation
shields from liabilityLaw & Regulation
take-down proceduresLaw & Regulation
dematerialisation of documents and electronic trust servicesLaw & Regulation
admission into evidence of electronic documentsLaw & Regulation
requirements of form and the threat of unenforceabilityLaw & Regulation
electronic signatures and indentity trust servicesLaw & Regulation
the law of armed conflictLaw & Regulation
conflict of law -- electronic signatures and trust servicesLaw & Regulation
other regulatory mattersLaw & Regulation
industry-specific regulationsLaw & Regulation
NIS directiveLaw & Regulation
restrictions on exporting security technologiesLaw & Regulation
matters classified as secret by a stateLaw & Regulation
public international lawLaw & Regulation
attributing action to a state under international lawLaw & Regulation
state cyber operations in generalLaw & Regulation
cyber espionage in peacetimeLaw & Regulation
cross-border criminal investigationLaw & Regulation
obligations owed to a clientLaw & Regulation
codes of conductLaw & Regulation
vulnerability testingLaw & Regulation
vulnerability disclosureLaw & Regulation
facilitating and acting on vulnerability disclosureLaw & Regulation
Privacy & Online RightsHuman, Organisational and Regulatory Aspects
confidentialityPrivacy & Online Rights
data confidentialityPrivacy & Online Rights
cryptography-based access controlPrivacy & Online Rights
protecting data in transitPrivacy & Online Rights
E2EEPrivacy & Online Rights
OTRPrivacy & Online Rights
protecting data during processingPrivacy & Online Rights
outsourcingPrivacy & Online Rights
private information retrievalPrivacy & Online Rights
oblivious transferPrivacy & Online Rights
homomorphic encryptionPrivacy & Online Rights
efficiency concernsPrivacy & Online Rights
collaborative computationPrivacy & Online Rights
verification in the encrypted domainPrivacy & Online Rights
private computation - input verificationPrivacy & Online Rights
zero-knowledge proofsPrivacy & Online Rights
ZK-SNARKPrivacy & Online Rights
private authenticationPrivacy & Online Rights
attribute based credentialsPrivacy & Online Rights
private paymentsPrivacy & Online Rights
blind signaturesPrivacy & Online Rights
obfuscation-based inference controlPrivacy & Online Rights
anonymisationPrivacy & Online Rights
k-anonymityPrivacy & Online Rights
l-diversityPrivacy & Online Rights
generalisationPrivacy & Online Rights
suppressionPrivacy & Online Rights
dummy additionPrivacy & Online Rights
perturbationPrivacy & Online Rights
differential privacyPrivacy & Online Rights
metadata confidentialityPrivacy & Online Rights
traffic metadataPrivacy & Online Rights
anonymous communications networksPrivacy & Online Rights
TorPrivacy & Online Rights
mix networksPrivacy & Online Rights
VPNsPrivacy & Online Rights
device metadataPrivacy & Online Rights
attacksPrivacy & Online Rights
dificulty of defencePrivacy & Online Rights
cookie-based techniquesPrivacy & Online Rights
location metadataPrivacy & Online Rights
clustering techniquesPrivacy & Online Rights
controlPrivacy & Online Rights
privacy settings configurationPrivacy & Online Rights
machine learning based techniquesPrivacy & Online Rights
privacy policy negotiationPrivacy & Online Rights
P3PPrivacy & Online Rights
purpose-based access controlPrivacy & Online Rights
sticky policiesPrivacy & Online Rights
privacy policy interpretabilityPrivacy & Online Rights
transparencyPrivacy & Online Rights
feedback-based transparencyPrivacy & Online Rights
privacy mirrorsPrivacy & Online Rights
privacy nudgesPrivacy & Online Rights
audit-based transparencyPrivacy & Online Rights
auditing specificationsPrivacy & Online Rights
formal methods-based approachesPrivacy & Online Rights
distributed ledgersPrivacy & Online Rights
privacy technologies and democratic valuesPrivacy & Online Rights
privacy technologies as support fo democratic political systemsPrivacy & Online Rights
electronic votingPrivacy & Online Rights
property of electronic voting systemsPrivacy & Online Rights
ballot secrecyPrivacy & Online Rights
universal verifiabilityPrivacy & Online Rights
eligibility verifiabilityPrivacy & Online Rights
voting mix networksPrivacy & Online Rights
verifiable shufflesPrivacy & Online Rights
blind-signature-based schemesPrivacy & Online Rights
homomorphic encryption-based schemesPrivacy & Online Rights
anonymous petitionsPrivacy & Online Rights
censorship resistance and freedom of speechPrivacy & Online Rights
data publishing censorship resistancePrivacy & Online Rights
Eternity ServicePrivacy & Online Rights
FreenetPrivacy & Online Rights
TanglerPrivacy & Online Rights
data access censorship resistancePrivacy & Online Rights
mimickingPrivacy & Online Rights
tunnelingPrivacy & Online Rights
bridgingPrivacy & Online Rights
refraction networkingPrivacy & Online Rights
privacy engineeringPrivacy & Online Rights
goalsPrivacy & Online Rights
minimize trustPrivacy & Online Rights
minimize riskPrivacy & Online Rights
strategiesPrivacy & Online Rights
minimise collectionPrivacy & Online Rights
minimise disclosurePrivacy & Online Rights
minimise replicationPrivacy & Online Rights
minimise centralizationPrivacy & Online Rights
minimise linkabilityPrivacy & Online Rights
privacy evaluationPrivacy & Online Rights
Risk Management & GovernanceHuman, Organisational and Regulatory Aspects
risk definitionRisk Management & Governance
risk assessmentRisk Management & Governance
risk managementRisk Management & Governance
levels of perceived riskRisk Management & Governance
risk governanceRisk Management & Governance
governance modelsRisk Management & Governance
technocraticRisk Management & Governance
decisionisticRisk Management & Governance
transparentRisk Management & Governance
risk perception factorsRisk Management & Governance
human factors and risk communicationRisk Management & Governance
educationRisk Management & Governance
training and inducement of behaviour changeRisk Management & Governance
creation of confidenceRisk Management & Governance
involvementRisk Management & Governance
security cultureRisk Management & Governance
just cultureRisk Management & Governance
awarenessRisk Management & Governance
awareness metricsRisk Management & Governance
enacting security policyRisk Management & Governance
presentation of risk assessment informationRisk Management & Governance
risk communication principlesRisk Management & Governance
risk assessment and management principlesRisk Management & Governance
component vs systems perspectivesRisk Management & Governance
elements of riskRisk Management & Governance
vulnerabilityRisk Management & Governance
threatRisk Management & Governance
likelihoodRisk Management & Governance
impactRisk Management & Governance
risk assessment and management methodsRisk Management & Governance
NIST guidelinesRisk Management & Governance
prepareRisk Management & Governance
conductRisk Management & Governance
communicateRisk Management & Governance
maintainRisk Management & Governance
ISO/IEC 27005Risk Management & Governance
FAIRRisk Management & Governance
Octave AllegroRisk Management & Governance
STRIDERisk Management & Governance
attack treesRisk Management & Governance
STAMPRisk Management & Governance
TOGAFRisk Management & Governance
dependency modellingRisk Management & Governance
SABSARisk Management & Governance
risk assessment and management in cyber-physical systemsRisk Management & Governance
OTRisk Management & Governance
ICS and CNIRisk Management & Governance
SCADARisk Management & Governance
NISRisk Management & Governance
security metricsRisk Management & Governance
characteristics of good metricsRisk Management & Governance
regulatory complianceRisk Management & Governance
actor-oriented approachesRisk Management & Governance
quantitative vs qualitative approachesRisk Management & Governance
business continuity: incident response and recovery planningRisk Management & Governance
ISO/IEC 27035Risk Management & Governance
plan and prepareRisk Management & Governance
detection and reportingRisk Management & Governance
assessment and decisionRisk Management & Governance
responseRisk Management & Governance
learningRisk Management & Governance
NCSC guidanceRisk Management & Governance
establish incident response capabilityRisk Management & Governance
trainingRisk Management & Governance
rolesRisk Management & Governance
recoveryRisk Management & Governance
testRisk Management & Governance
reportRisk Management & Governance
gather evidenceRisk Management & Governance
developRisk Management & Governance
reportRisk Management & Governance
Attacks and DefencesCyBOK Category
Adversarial BehavioursAttacks and Defences
Characterisation of AdversariesAdversarial Behaviours
Cyber-enabled crime vs Cyber-dependent crimeAdversarial Behaviours
Interpersonal crimesAdversarial Behaviours
CyberbullyingAdversarial Behaviours
DoxingAdversarial Behaviours
CyberstalkingAdversarial Behaviours
SextortionAdversarial Behaviours
Child predationAdversarial Behaviours
Cyber-enabled organized crimeAdversarial Behaviours
Advance fee fraudAdversarial Behaviours
Drug dealingAdversarial Behaviours
Cyber-dependent organized crimeAdversarial Behaviours
Email spamAdversarial Behaviours
Email RegulationAdversarial Behaviours
Directive on Privacy and Electronic CommunicationsAdversarial Behaviours
Privacy and Electronic Communications RegulationsAdversarial Behaviours
CAN-SPAMAdversarial Behaviours
MitigationsAdversarial Behaviours
PhishingAdversarial Behaviours
Financial MalwareAdversarial Behaviours
Botnet as a ServiceAdversarial Behaviours
Underground forumsAdversarial Behaviours
DumpzAdversarial Behaviours
FullzAdversarial Behaviours
Card skimmingAdversarial Behaviours
Insider threatsAdversarial Behaviours
Click fraudAdversarial Behaviours
Click fraud botnetsAdversarial Behaviours
Unauthorized cryptocurrency miningAdversarial Behaviours
Montization ratesAdversarial Behaviours
CryptojackingAdversarial Behaviours
RansomwareAdversarial Behaviours
Denial of ServiceAdversarial Behaviours
Low Orbit Ion CannonAdversarial Behaviours
HacktivistsAdversarial Behaviours
Data leaksAdversarial Behaviours
Web defacementsAdversarial Behaviours
State actorsAdversarial Behaviours
Differences from financially motivated attacksAdversarial Behaviours
SabotageAdversarial Behaviours
EspionageAdversarial Behaviours
DisinformationAdversarial Behaviours
Elements of a malicious operationsAdversarial Behaviours
Affiliate programmesAdversarial Behaviours
Infection vectorsAdversarial Behaviours
Malicious attachmentsAdversarial Behaviours
Black hat search engine optimisationAdversarial Behaviours
Drive-by download attacksAdversarial Behaviours
Compromising Interent-connected devicesAdversarial Behaviours
InfrastructureAdversarial Behaviours
Bulletproof hostingAdversarial Behaviours
Command and Control infrastructureAdversarial Behaviours
Takedown resilient architecturesAdversarial Behaviours
Multi-tier botnetsAdversarial Behaviours
Fast fluxAdversarial Behaviours
Domain fluxAdversarial Behaviours
Specialised servicesAdversarial Behaviours
Exploit kitsAdversarial Behaviours
Pay-per-install servicesAdversarial Behaviours
Human servicesAdversarial Behaviours
CAPTCHA solving servicesAdversarial Behaviours
Fake accountsAdversarial Behaviours
Content generationAdversarial Behaviours
Money mulesAdversarial Behaviours
Reshipping mulesAdversarial Behaviours
Payment methodsAdversarial Behaviours
Credit card processorsAdversarial Behaviours
PaypalAdversarial Behaviours
Western Union and untraceable paymentsAdversarial Behaviours
CryptocurrenciesAdversarial Behaviours
ModelsAdversarial Behaviours
Attack treesAdversarial Behaviours
Attack graphsAdversarial Behaviours
Kill chainsAdversarial Behaviours
ReconnaissanceAdversarial Behaviours
WeaponisationAdversarial Behaviours
DeliveryAdversarial Behaviours
ExploitationAdversarial Behaviours
InstallationAdversarial Behaviours
Command and ControlAdversarial Behaviours
Actions on objectivesAdversarial Behaviours
Other modelsAdversarial Behaviours
Environmental criminologyAdversarial Behaviours
Routine activity theoryAdversarial Behaviours
Rational choice theoryAdversarial Behaviours
Pattern theory of crimeAdversarial Behaviours
Sitiuational crime preventionAdversarial Behaviours
Hot spotsAdversarial Behaviours
Hot productsAdversarial Behaviours
Repeat victimsAdversarial Behaviours
MitigationsAdversarial Behaviours
AdaptationAdversarial Behaviours
DisplacementAdversarial Behaviours
Crime scriptingAdversarial Behaviours
Flow of capitalAdversarial Behaviours
AttributionAdversarial Behaviours
ForensicsAttacks and Defences
definitions and conceptual modelsForensics
forensic scienceForensics
cyber domainForensics
digital (forensic) traceForensics
legal concerns and the Daubert StandardForensics
computer misuse actForensics
cyber crimeForensics
standards for the presentation of scientific evidence in legal proceedingsForensics
ACPO good practice guide for digital evidenceForensics
BS EN ISO/IEC 17020:2012Forensics
BS EN ISO/IEC 17025:2005Forensics
definitionsForensics
digital forensicsForensics
DFRWSForensics
NISTForensics
WorkingForensics
relevenceForensics
conceptual modelsForensics
state-centricForensics
history-centricForensics
cognitive task modelForensics
differential analysisForensics
external data sourcesForensics
schemaForensics
sense-making loopForensics
bottom-up processesForensics
search and filterForensics
read and extractForensics
schematizeForensics
build caseForensics
tell storyForensics
top-down processesForensics
re-evaluateForensics
search for suportForensics
search for evidenceForensics
search for relationsForensics
search for informationForensics
the foraging loopForensics
exploreForensics
enrichForensics
exploitForensics
the sense making loopForensics
operating system analysisForensics
storage forensicsForensics
data abstraction layersForensics
physical mediaForensics
block deviceForensics
file systemForensics
application artifactsForensics
benefits of independent forensic reconstructionForensics
data acquisitionForensics
physical data acquisitionForensics
mobile,phone data acquisitionForensics
chip-off techniquesForensics
RAID data recoveryForensics
logical data acquisitionForensics
approaches to API based recoveryForensics
block-level acquisitionForensics
cryptographic hashesForensics
encryption concernsForensics
technical challengesForensics
legal challengesForensics
filesystem analysisForensics
blocksForensics
filesForensics
file systemsForensics
block device analysisForensics
partitionsForensics
logical volumesForensics
data recovery & file content carvingForensics
carving techniquesForensics
fragmentationForensics
slack spaceForensics
main memory forensicsForensics
process informationForensics
file informationForensics
network connectionsForensics
artifacts and fragmentsForensics
challenges of live forensicsForensics
application forensicsForensics
web browsersForensics
URL historyForensics
form dataForensics
temporary filesForensics
downloaded filesForensics
HTML5 local storageForensics
cookiesForensics
cloud forensicsForensics
servicesForensics
SaaSForensics
PaaSForensics
IaaSForensics
forensic challengesForensics
SaaS forensicsForensics
partial replicationForensics
revision acquisitionForensics
cloud-native artifactsForensics
artifact analysisForensics
cryptographic hashingForensics
block-level analysisForensics
approximate analysisForensics
bytewise matchingForensics
syntactic matchingForensics
semantic matchingForensics
bytewise approximate matchingForensics
cload-native artifactsForensics
Malware & Attack TechnologiesAttacks and Defences
malware taxonomyMalware & Attack Technologies
dimensionsMalware & Attack Technologies
standalone or host-programMalware & Attack Technologies
persistent or transientMalware & Attack Technologies
layers of system stackMalware & Attack Technologies
auto-spreadingMalware & Attack Technologies
dynamically updatableMalware & Attack Technologies
coordinatedMalware & Attack Technologies
kindsMalware & Attack Technologies
virusesMalware & Attack Technologies
malicious browser extensionsMalware & Attack Technologies
botnet malwareMalware & Attack Technologies
memory-resident malwareMalware & Attack Technologies
advanced persistent threatsMalware & Attack Technologies
potentially unwanted programsMalware & Attack Technologies
malicious activities by malwareMalware & Attack Technologies
attacks onMalware & Attack Technologies
confidentialityMalware & Attack Technologies
integrityMalware & Attack Technologies
availabilityMalware & Attack Technologies
cyber kill chainMalware & Attack Technologies
reconnaissanceMalware & Attack Technologies
weaponisationMalware & Attack Technologies
deliveryMalware & Attack Technologies
exploitationMalware & Attack Technologies
installationMalware & Attack Technologies
command and controlMalware & Attack Technologies
actions on objectivesMalware & Attack Technologies
underground eco-systemMalware & Attack Technologies
malware analysisMalware & Attack Technologies
analysis techniquesMalware & Attack Technologies
static analysisMalware & Attack Technologies
dynamic analysisMalware & Attack Technologies
fuzzingMalware & Attack Technologies
symbolic executionMalware & Attack Technologies
concolic executionMalware & Attack Technologies
offline concolic executionMalware & Attack Technologies
online concolic executionMalware & Attack Technologies
hybrid executionMalware & Attack Technologies
path explorationMalware & Attack Technologies
analysis environmentsMalware & Attack Technologies
environmentsMalware & Attack Technologies
machine emulatorMalware & Attack Technologies
type 2 hypervisorMalware & Attack Technologies
type 1 hypervisorMalware & Attack Technologies
bare-metal machineMalware & Attack Technologies
safety and live-environment requirementsMalware & Attack Technologies
virtualised network environmentsMalware & Attack Technologies
anti-analysis and evasion techniquesMalware & Attack Technologies
obfuscationMalware & Attack Technologies
packingMalware & Attack Technologies
code emulationMalware & Attack Technologies
basic blocksMalware & Attack Technologies
tracingMalware & Attack Technologies
fingerprintingMalware & Attack Technologies
multi-path analysisMalware & Attack Technologies
indentifying the analysis environmentMalware & Attack Technologies
red pill techniquesMalware & Attack Technologies
mitigationsMalware & Attack Technologies
malware detectionMalware & Attack Technologies
identifying the presence of malwareMalware & Attack Technologies
malware distribution methodsMalware & Attack Technologies
malware infection sitesMalware & Attack Technologies
runtime detectionMalware & Attack Technologies
evasion and countermeasuresMalware & Attack Technologies
heuristicsMalware & Attack Technologies
polymorphismMalware & Attack Technologies
update routinesMalware & Attack Technologies
attack detectionMalware & Attack Technologies
network monitoringMalware & Attack Technologies
host-basedMalware & Attack Technologies
network-basedMalware & Attack Technologies
spam detectionMalware & Attack Technologies
DDoS detectionMalware & Attack Technologies
ransomware detectionMalware & Attack Technologies
botnet detectionMalware & Attack Technologies
machine learning-based security analyticsMalware & Attack Technologies
limitationsMalware & Attack Technologies
machine learning countermeasuresMalware & Attack Technologies
malware responseMalware & Attack Technologies
disrupting malware operationsMalware & Attack Technologies
DNS fast-fluxMalware & Attack Technologies
domain-name generation algorithmsMalware & Attack Technologies
command and control takedownMalware & Attack Technologies
P2P takedownMalware & Attack Technologies
attributionMalware & Attack Technologies
historical signaturesMalware & Attack Technologies
WHOISMalware & Attack Technologies
Security Operations & Incident ManagementAttacks and Defences
fundamental conceptsSecurity Operations & Incident Management
TLSCryptography
workflows and vocabularySecurity Operations & Incident Management
intrusion detectionSecurity Operations & Incident Management
security information and event management (SIEM)Security Operations & Incident Management
security orchestration, automation and response (SOAR)Security Operations & Incident Management
MAPE-KSecurity Operations & Incident Management
architectural principlesSecurity Operations & Incident Management
demilitarised zone (DMZ)Security Operations & Incident Management
intrusion prevention systemsSecurity Operations & Incident Management
CISOs and analystsSecurity Operations & Incident Management
cyber-threat intelligence (CTI)Security Operations & Incident Management
information sharing and analysis center (ISAC)Security Operations & Incident Management
monitor: data sourcesSecurity Operations & Incident Management
network trafficSecurity Operations & Incident Management
pcapSecurity Operations & Incident Management
volumeSecurity Operations & Incident Management
packet sizeSecurity Operations & Incident Management
segmentation and fragmentationSecurity Operations & Incident Management
timestampsSecurity Operations & Incident Management
MAC layer interpretationSecurity Operations & Incident Management
application layer interpretationSecurity Operations & Incident Management
encryptionSecurity Operations & Incident Management
new protocolsSecurity Operations & Incident Management
IoTSecurity Operations & Incident Management
LoRaSecurity Operations & Incident Management
Profinet IRTSecurity Operations & Incident Management
network aggregates: netflowSecurity Operations & Incident Management
netflow / IPFixSecurity Operations & Incident Management
network infrastructure informationSecurity Operations & Incident Management
namingSecurity Operations & Incident Management
DNSSecurity Operations & Incident Management
DNSSECSecurity Operations & Incident Management
DNS as DDoS amplifierSecurity Operations & Incident Management
detecting botnets by DNSSecurity Operations & Incident Management
routingSecurity Operations & Incident Management
BGP hijacksSecurity Operations & Incident Management
application logs: web server logs and filesSecurity Operations & Incident Management
web server logsSecurity Operations & Incident Management
common log formatSecurity Operations & Incident Management
extended common log formatSecurity Operations & Incident Management
files and documentsSecurity Operations & Incident Management
system and kernel logsSecurity Operations & Incident Management
audit trailsSecurity Operations & Incident Management
orange bookSecurity Operations & Incident Management
STIDESecurity Operations & Incident Management
eXpert-BSMSecurity Operations & Incident Management
SyslogSecurity Operations & Incident Management
formatSecurity Operations & Incident Management
protocolSecurity Operations & Incident Management
analyse: analysis methodsSecurity Operations & Incident Management
misuse detectionSecurity Operations & Incident Management
symmetric cryptographyCryptography
CVESecurity Operations & Incident Management
antivirus enginesSecurity Operations & Incident Management
haystack and NIDESSecurity Operations & Incident Management
snortSecurity Operations & Incident Management
YARASecurity Operations & Incident Management
anomaly detectionSecurity Operations & Incident Management
modelsSecurity Operations & Incident Management
unsupervised techniquesSecurity Operations & Incident Management
support vector machinesSecurity Operations & Incident Management
C4.5Security Operations & Incident Management
OFBCryptography
graph-based modelsSecurity Operations & Incident Management
anomaly modelsSecurity Operations & Incident Management
specification vs learningSecurity Operations & Incident Management
adherence to use casesSecurity Operations & Incident Management
blended misuse and anomaly detectionSecurity Operations & Incident Management
machine learningSecurity Operations & Incident Management
datasetsSecurity Operations & Incident Management
machine learning for malware detectionSecurity Operations & Incident Management
testing and validating intrusion detection systemSecurity Operations & Incident Management
the base-rate falacySecurity Operations & Incident Management
contribution of SIEM to analysis and detectionSecurity Operations & Incident Management
plan: security information and event managementSecurity Operations & Incident Management
data collectionSecurity Operations & Incident Management
alert message layersSecurity Operations & Incident Management
schemaSecurity Operations & Incident Management
encodingSecurity Operations & Incident Management
transport protocolSecurity Operations & Incident Management
schemasSecurity Operations & Incident Management
SyslogSecurity Operations & Incident Management
CEFSecurity Operations & Incident Management
LEEFSecurity Operations & Incident Management
CIMSecurity Operations & Incident Management
XDAS[CADFSecurity Operations & Incident Management
CEESecurity Operations & Incident Management
IDMEFSecurity Operations & Incident Management
alert correlationSecurity Operations & Incident Management
correlation between alertsSecurity Operations & Incident Management
correlation between alerts and the environmentSecurity Operations & Incident Management
correlation between alerts and external servicesSecurity Operations & Incident Management
incident and information exchangeSecurity Operations & Incident Management
security operations and benchmarkingSecurity Operations & Incident Management
execute: mitigation and countermeasuresSecurity Operations & Incident Management
intrusion prevention systemsSecurity Operations & Incident Management
specialised examplesSecurity Operations & Incident Management
session border controllersSecurity Operations & Incident Management
web application firewallsSecurity Operations & Incident Management
denial of serviceSecurity Operations & Incident Management
software defined networking (SDN)Security Operations & Incident Management
SIEM platforms and countermeasuresSecurity Operations & Incident Management
SOAR: impact and risk assessmentSecurity Operations & Incident Management
cyber insurance modelsSecurity Operations & Incident Management
site reliability engineeringSecurity Operations & Incident Management
knowledge: intelligence and analyticsSecurity Operations & Incident Management
cyber security knowledge managementSecurity Operations & Incident Management
CVESecurity Operations & Incident Management
CVSSSecurity Operations & Incident Management
CWESecurity Operations & Incident Management
CAPECSecurity Operations & Incident Management
honeypots and honeynetsSecurity Operations & Incident Management
cyber-threat intelligenceSecurity Operations & Incident Management
indicators of compromiseSecurity Operations & Incident Management
signaturesSecurity Operations & Incident Management
information sharing and analysis centresSecurity Operations & Incident Management
situational awarenessSecurity Operations & Incident Management
human factors: incident managementSecurity Operations & Incident Management
prepare: incident management planningSecurity Operations & Incident Management
TF-CSIRTSecurity Operations & Incident Management
FIRSTSecurity Operations & Incident Management
ENISASecurity Operations & Incident Management
handle: actual incident responseSecurity Operations & Incident Management
mitigationSecurity Operations & Incident Management
gathering evidenceSecurity Operations & Incident Management
follow up: post incident activitiesSecurity Operations & Incident Management
performance metricsSecurity Operations & Incident Management
communicationSecurity Operations & Incident Management
attack attributionSecurity Operations & Incident Management
Systems SecurityCyBOK Category
Authentication, Authorisation & AccountabilitySystems Security
authorisationAuthentication, Authorisation & Accountability
access controlAuthentication, Authorisation & Accountability
core conceptsAuthentication, Authorisation & Accountability
principalAuthentication, Authorisation & Accountability
subjectAuthentication, Authorisation & Accountability
objectAuthentication, Authorisation & Accountability
identity based access controlAuthentication, Authorisation & Accountability
attribute based access controlAuthentication, Authorisation & Accountability
access rightsAuthentication, Authorisation & Accountability
security policiesAuthentication, Authorisation & Accountability
access control matrixAuthentication, Authorisation & Accountability
access control listAuthentication, Authorisation & Accountability
discretionary access controls (DAC)Authentication, Authorisation & Accountability
mandatory access controls (MAC)Authentication, Authorisation & Accountability
latticesAuthentication, Authorisation & Accountability
SELinuxAuthentication, Authorisation & Accountability
multi-level security policiesAuthentication, Authorisation & Accountability
role-based access control (RBAC)Authentication, Authorisation & Accountability
flat RBACAuthentication, Authorisation & Accountability
hierarchical RBACAuthentication, Authorisation & Accountability
constrained RBACAuthentication, Authorisation & Accountability
symmetric RBACAuthentication, Authorisation & Accountability
attribute-based access control (ABAC)Authentication, Authorisation & Accountability
code-based access cotrolAuthentication, Authorisation & Accountability
Java security modelAuthentication, Authorisation & Accountability
.NET architectureAuthentication, Authorisation & Accountability
mobile securityAuthentication, Authorisation & Accountability
permissionsAuthentication, Authorisation & Accountability
digital rights management (DRM)Authentication, Authorisation & Accountability
tamper resistanceAuthentication, Authorisation & Accountability
attestationAuthentication, Authorisation & Accountability
superdistributionAuthentication, Authorisation & Accountability
FIDO UAFAuthentication, Authorisation & Accountability
usage controlAuthentication, Authorisation & Accountability
XACML 3.0Authentication, Authorisation & Accountability
enforcing access controlAuthentication, Authorisation & Accountability
pointsAuthentication, Authorisation & Accountability
policy administration pointsAuthentication, Authorisation & Accountability
policy decision pointsAuthentication, Authorisation & Accountability
policy information pointsAuthentication, Authorisation & Accountability
policy enforcement pointsAuthentication, Authorisation & Accountability
delegation and revocationAuthentication, Authorisation & Accountability
online certificate status protocol (OCSP)Authentication, Authorisation & Accountability
reference monitorAuthentication, Authorisation & Accountability
trusted computing base (TCB)Authentication, Authorisation & Accountability
authorisationAuthentication, Authorisation & Accountability
decision algorithmsAuthentication, Authorisation & Accountability
rule combining algorithmsAuthentication, Authorisation & Accountability
execution monitorsAuthentication, Authorisation & Accountability
in-line reference monitorsAuthentication, Authorisation & Accountability
theoryAuthentication, Authorisation & Accountability
Bell-LaPadula (BLP)Authentication, Authorisation & Accountability
*-propertyAuthentication, Authorisation & Accountability
polyinstantiationAuthentication, Authorisation & Accountability
BibaAuthentication, Authorisation & Accountability
Clark-WilsonAuthentication, Authorisation & Accountability
Harrison, Ruzo and Ullman modelAuthentication, Authorisation & Accountability
enforceable policiesAuthentication, Authorisation & Accountability
access control logicsAuthentication, Authorisation & Accountability
access control in distributed systemsAuthentication, Authorisation & Accountability
core conceptsAuthentication, Authorisation & Accountability
certificateAuthentication, Authorisation & Accountability
credentialAuthentication, Authorisation & Accountability
tokenAuthentication, Authorisation & Accountability
origin-based policiesAuthentication, Authorisation & Accountability
sender policy framework (SPF)Authentication, Authorisation & Accountability
cross-site scriptingAuthentication, Authorisation & Accountability
cross-site resource sharingAuthentication, Authorisation & Accountability
federated access controlAuthentication, Authorisation & Accountability
cryptography and access controlAuthentication, Authorisation & Accountability
attribute-based encryptionAuthentication, Authorisation & Accountability
key-policy attribute-based encryptionAuthentication, Authorisation & Accountability
ciphertext-policy attribute-based encryptionAuthentication, Authorisation & Accountability
key-centric access controlAuthentication, Authorisation & Accountability
SPKI/SDSIAuthentication, Authorisation & Accountability
constrained delegationAuthentication, Authorisation & Accountability
authenticationAuthentication, Authorisation & Accountability
identity managementAuthentication, Authorisation & Accountability
privacy by designAuthentication, Authorisation & Accountability
user authenticationAuthentication, Authorisation & Accountability
risk-based authenticationAuthentication, Authorisation & Accountability
passwordsAuthentication, Authorisation & Accountability
recommendationsAuthentication, Authorisation & Accountability
biometricsAuthentication, Authorisation & Accountability
liveness detectionAuthentication, Authorisation & Accountability
verificationAuthentication, Authorisation & Accountability
failure to captureAuthentication, Authorisation & Accountability
false rejectsAuthentication, Authorisation & Accountability
false acceptsAuthentication, Authorisation & Accountability
spoofingAuthentication, Authorisation & Accountability
border control gatesAuthentication, Authorisation & Accountability
authentication tokensAuthentication, Authorisation & Accountability
behavioural authenticationAuthentication, Authorisation & Accountability
two-factor authentication (2FA)Authentication, Authorisation & Accountability
authentication in distributed systemsAuthentication, Authorisation & Accountability
Needhame-Schroeder ProtocolAuthentication, Authorisation & Accountability
KerberosAuthentication, Authorisation & Accountability
ticket granting serverAuthentication, Authorisation & Accountability
SAMLAuthentication, Authorisation & Accountability
OAuth 2Authentication, Authorisation & Accountability
facets of authenticationAuthentication, Authorisation & Accountability
patterns for entity authenticationAuthentication, Authorisation & Accountability
correspondence propertiesAuthentication, Authorisation & Accountability
alivenessAuthentication, Authorisation & Accountability
weak agreementAuthentication, Authorisation & Accountability
non-injective agreementAuthentication, Authorisation & Accountability
agreementAuthentication, Authorisation & Accountability
authentication vs verified associationAuthentication, Authorisation & Accountability
authentication for credit or responsibilityAuthentication, Authorisation & Accountability
accountabilityAuthentication, Authorisation & Accountability
technical aspectsAuthentication, Authorisation & Accountability
audit policiesAuthentication, Authorisation & Accountability
preserving the evidenceAuthentication, Authorisation & Accountability
tamper resistanceAuthentication, Authorisation & Accountability
write-once, read-manyAuthentication, Authorisation & Accountability
hash-chainAuthentication, Authorisation & Accountability
audit policiesAuthentication, Authorisation & Accountability
analysing the evidenceAuthentication, Authorisation & Accountability
assessing the evidenceAuthentication, Authorisation & Accountability
privacy and accountabilityAuthentication, Authorisation & Accountability
certificate transparencyAuthentication, Authorisation & Accountability
private subdomainsAuthentication, Authorisation & Accountability
distributed logsAuthentication, Authorisation & Accountability
consensusAuthentication, Authorisation & Accountability
blockchainsAuthentication, Authorisation & Accountability
CryptographySystems Security
schemesCryptography
AESCryptography
RSACryptography
DESCryptography
PKCSCryptography
DSACryptography
KerberosCryptography
symmetric primitivesCryptography
block ciphersCryptography
Feistel networksCryptography
stream ciphersCryptography
hash functionsCryptography
Merkel-Damgård constructionCryptography
sponge constructionsCryptography
symmetric encryption and authenticationCryptography
modes of operationCryptography
ECBCryptography
CBCCryptography
CFBCryptography
CTRCryptography
AEADCryptography
message authentication codesCryptography
extendable output functionCryptography
key derivation functionsCryptography
public key cryptographyCryptography
public key encryptionCryptography
key encapsulation mechanismsCryptography
constructions based on RSACryptography
RSA-OAEPCryptography
RSA-KEMCryptography
data encryption mechanismsCryptography
constructions based on elliptic curvesCryptography
ECIESCryptography
lattice-based constructionsCryptography
public key signaturesCryptography
full domain hashCryptography
probabilistic signature schemesCryptography
Schnorr signaturesCryptography
cryptographic security modelsCryptography
basic security definitionsCryptography
security gamesCryptography
random oracle modelCryptography
one-wayCryptography
passive attackCryptography
indistinguishabilityCryptography
chosen plaintext attacksCryptography
chosen ciphertext attackCryptography
universal forgeryCryptography
chosen message attackCryptography
hard problemsCryptography
pseudo-random functionsCryptography
pseudo-random permutationsCryptography
discrete logarithm problemCryptography
Diffie-Hellman problemCryptography
shortest vector problemCryptography
post-quantum cryptographyCryptography
closest vector problemCryptography
setup assumptionsCryptography
PKICryptography
common reference stringsCryptography
good random number generationCryptography
simulation of cryptographic operationsCryptography
universal composabilityCryptography
information-theoretically secure constructionsCryptography
one-time padCryptography
secret sharingCryptography
standard protocolsCryptography
authentication protocolsCryptography
encryption-based protocolsCryptography
message authentication-based protocolsCryptography
zero-knowledge-based protocolsCryptography
key agreement protocolsCryptography
key confirmationCryptography
forward secrecyCryptography
unknown key share securityCryptography
key transportCryptography
Diffie-Hellman key agreementCryptography
station-to-station protocolCryptography
advanced protocolsCryptography
oblivious transferCryptography
zero-knowledgeCryptography
Σ-protocolsCryptography
secure multi-party computationCryptography
public-key schemes with special propertiesCryptography
group signaturesCryptography
ring signaturesCryptography
blind signaturesCryptography
identity-based encryptionCryptography
linearly homomorphic encryptionCryptography
fully homomorphic encryptionCryptography
Distributed Systems SecuritySystems Security
classes of distributed systemsDistributed Systems Security
decentralised point-to-point interactions across distributed entities without a centralised coordination serviceDistributed Systems Security
P2PDistributed Systems Security
KademliaDistributed Systems Security
NapsterDistributed Systems Security
GnutellaDistributed Systems Security
wireless sensor networksDistributed Systems Security
online gaming systemsDistributed Systems Security
coordinated clustering across distributed resources and servicesDistributed Systems Security
coordination of resources vs coordination of resourcesDistributed Systems Security
client-server modelsDistributed Systems Security
n-tier multi tenancy modelsDistributed Systems Security
cloudsDistributed Systems Security
publicDistributed Systems Security
privateDistributed Systems Security
hybridDistributed Systems Security
multi-cloudDistributed Systems Security
big data servicesDistributed Systems Security
high performance computingDistributed Systems Security
databasesDistributed Systems Security
ledgersDistributed Systems Security
storage systemsDistributed Systems Security
classes of vulnerabilities & threatsDistributed Systems Security
access/admission control & ID managementDistributed Systems Security
data transportationDistributed Systems Security
resource management and coordination servicesDistributed Systems Security
data securityDistributed Systems Security
confidentiality integrity and availabilityDistributed Systems Security
side channel attacksDistributed Systems Security
data consistencyDistributed Systems Security
decentralised P2P modelsDistributed Systems Security
principlesDistributed Systems Security
symmetry of interfacesDistributed Systems Security
resilience to perturbationsDistributed Systems Security
survivability through replicationDistributed Systems Security
peer resources at the network's edgeDistributed Systems Security
address varianceDistributed Systems Security
unstructured P2P protocolsDistributed Systems Security
message passingDistributed Systems Security
structured P2P protocolsDistributed Systems Security
distributed hash tableDistributed Systems Security
hybrid P2P protocolsDistributed Systems Security
hierarchical P2P protocolsDistributed Systems Security
attacking P2P systemsDistributed Systems Security
functional elementsDistributed Systems Security
P2P operationsDistributed Systems Security
mitigationsDistributed Systems Security
P2P data structuresDistributed Systems Security
attack typesDistributed Systems Security
denial of service (DoS)Distributed Systems Security
collusion attacksDistributed Systems Security
pollution attacksDistributed Systems Security
white washingDistributed Systems Security
routing attacksDistributed Systems Security
routing table poisoningDistributed Systems Security
buffer map cheating attacksDistributed Systems Security
sybil attacksDistributed Systems Security
eclipse attacksDistributed Systems Security
localised eclipse attacksDistributed Systems Security
topology aware localised eclipse attacksDistributed Systems Security
outgoing eclipse attacksDistributed Systems Security
coordinated resources clusteringDistributed Systems Security
systems coordination stylesDistributed Systems Security
synchronousDistributed Systems Security
asynchronousDistributed Systems Security
partially synchronousDistributed Systems Security
reliable and secure group communicationDistributed Systems Security
coordination principlesDistributed Systems Security
consensusDistributed Systems Security
agreementDistributed Systems Security
validityDistributed Systems Security
terminationDistributed Systems Security
group membership and consistencyDistributed Systems Security
strong consistency modelsDistributed Systems Security
strict consistencyDistributed Systems Security
linearisabilityDistributed Systems Security
weak consistency modelsDistributed Systems Security
sequential consistencyDistributed Systems Security
causal consistencyDistributed Systems Security
eventual consistencyDistributed Systems Security
replication management and coordination schemaDistributed Systems Security
CAPDistributed Systems Security
consistencyDistributed Systems Security
availabilityDistributed Systems Security
partitionDistributed Systems Security
replication and coordinationDistributed Systems Security
PaxosDistributed Systems Security
Byzantine Fault ToleranceDistributed Systems Security
commit protocolsDistributed Systems Security
coordination classes and attackabilityDistributed Systems Security
classes of disruptionsDistributed Systems Security
timing basedDistributed Systems Security
value basedDistributed Systems Security
resource coordination classDistributed Systems Security
characteristicsDistributed Systems Security
cloud modelDistributed Systems Security
IaaSDistributed Systems Security
PaaSDistributed Systems Security
operational attributesDistributed Systems Security
client-server modelDistributed Systems Security
attackability implicationsDistributed Systems Security
compromise of resourcesDistributed Systems Security
compromise of access/admission controlDistributed Systems Security
compromise of VMDistributed Systems Security
compromise of schedulerDistributed Systems Security
compromise of brokerDistributed Systems Security
compromise of communicationDistributed Systems Security
compromise on monitoring and accountingDistributed Systems Security
services coordination classDistributed Systems Security
characteristic examplesDistributed Systems Security
web servicesDistributed Systems Security
key distributionDistributed Systems Security
storageDistributed Systems Security
transactional services, databasesDistributed Systems Security
blockchains/cryptocurrenciesDistributed Systems Security
propertiesDistributed Systems Security
proof of workDistributed Systems Security
attackability implicationsDistributed Systems Security
short transactionsDistributed Systems Security
large transactionsDistributed Systems Security
mixed transactionsDistributed Systems Security
e-commerce supporting transactionsDistributed Systems Security
informational systemsDistributed Systems Security
Formal Methods for SecuritySystems Security
MotivationFormal Methods for Security
Inadequacy of Traditional Development MethodsFormal Methods for Security
System designFormal Methods for Security
Code levelFormal Methods for Security
Configuration levelFormal Methods for Security
Towards More Scientific Development MethodsFormal Methods for Security
LimitationsFormal Methods for Security
Foundations, Methods and ToolsFormal Methods for Security
Properties of Systems and Their ExecutionsFormal Methods for Security
Trace PropertiesFormal Methods for Security
HyperpropertiesFormal Methods for Security
Relations on SystemsFormal Methods for Security
Logics and Specification LanguagesFormal Methods for Security
Property CheckingFormal Methods for Security
Interactive Theorem ProvingFormal Methods for Security
Decision ProceduresFormal Methods for Security
Static AnalysisFormal Methods for Security
Dynamic AnalysisFormal Methods for Security
HardwareFormal Methods for Security
Hardware VerificationFormal Methods for Security
Side-ChannelsFormal Methods for Security
API Attacks on Security HardwareFormal Methods for Security
Cryptographic ProtocolsFormal Methods for Security
Symbolic MethodsFormal Methods for Security
Theorem ProvingFormal Methods for Security
Model Checking Trace PropertiesFormal Methods for Security
Model Checking Non-trace PropertiesFormal Methods for Security
Stochastic MethodsFormal Methods for Security
Computational MethodsFormal Methods for Security
Game-based ProofsFormal Methods for Security
Simulation-based ProofsFormal Methods for Security
Software and Large-Scale SystemsFormal Methods for Security
Information Flow ControlFormal Methods for Security
Static Analysis and TypingFormal Methods for Security
Self-composition and Product ProgramsFormal Methods for Security
Cryptographic LibrariesFormal Methods for Security
Freedom from side-channel attacksFormal Methods for Security
Memory safetyFormal Methods for Security
Cryptographic securityFormal Methods for Security
Low-level CodeFormal Methods for Security
Operating SystemsFormal Methods for Security
Functional Correctness of Kernel ComponentsFormal Methods for Security
Absence of Bug ClassesFormal Methods for Security
Web-based ApplicationsFormal Methods for Security
Web ProgrammingFormal Methods for Security
Web ComponentsFormal Methods for Security
Component InteractionFormal Methods for Security
Full-stack VerificationFormal Methods for Security
ConfigurationFormal Methods for Security
Policy AnalysisFormal Methods for Security
Specification-based SynthesisFormal Methods for Security
Operating Systems & Virtualisation SecuritySystems Security
attacker modelOperating Systems & Virtualisation Security
threats to security for modern OSsOperating Systems & Virtualisation Security
malicious extensionsOperating Systems & Virtualisation Security
DMZNetwork Security
bootkitOperating Systems & Virtualisation Security
memory errors (software)Operating Systems & Virtualisation Security
memory corruption (hardware)Operating Systems & Virtualisation Security
uninitialised data leakageOperating Systems & Virtualisation Security
concurrency bugs and double fetchOperating Systems & Virtualisation Security
side channels (hardware)Operating Systems & Virtualisation Security
side channels (speculative)Operating Systems & Virtualisation Security
side channels (software)Operating Systems & Virtualisation Security
resource depletion (DoS)Operating Systems & Virtualisation Security
deadlocks (DoS)Operating Systems & Virtualisation Security
attack surfaceOperating Systems & Virtualisation Security
role of operating systemsOperating Systems & Virtualisation Security
isolationOperating Systems & Virtualisation Security
mediationOperating Systems & Virtualisation Security
design choicesOperating Systems & Virtualisation Security
single domainOperating Systems & Virtualisation Security
monolithic OSOperating Systems & Virtualisation Security
microkernel based multi-serverOperating Systems & Virtualisation Security
unikernelOperating Systems & Virtualisation Security
virtual machinesOperating Systems & Virtualisation Security
hypervisorsOperating Systems & Virtualisation Security
QubesOSOperating Systems & Virtualisation Security
drawbacksOperating Systems & Virtualisation Security
containersOperating Systems & Virtualisation Security
IoTOperating Systems & Virtualisation Security
security domainsOperating Systems & Virtualisation Security
OS security principlesOperating Systems & Virtualisation Security
Saltzer and Schroeder's principlesOperating Systems & Virtualisation Security
principle of economy of mechanismOperating Systems & Virtualisation Security
principle of fail-safe defaultsOperating Systems & Virtualisation Security
principle of complete mediationOperating Systems & Virtualisation Security
principle of open designOperating Systems & Virtualisation Security
principle of separation of privilegeOperating Systems & Virtualisation Security
principle of least authorityOperating Systems & Virtualisation Security
principle of least commmon mechanismOperating Systems & Virtualisation Security
principle of psychological acceptabilityOperating Systems & Virtualisation Security
security modelsOperating Systems & Virtualisation Security
Bell-LaPadula modelOperating Systems & Virtualisation Security
Biba modelOperating Systems & Virtualisation Security
newer principlesOperating Systems & Virtualisation Security
principle of minimizing the trusted computing baseOperating Systems & Virtualisation Security
principle of intentional useOperating Systems & Virtualisation Security
primitives for isolation and mediationOperating Systems & Virtualisation Security
MulticsOperating Systems & Virtualisation Security
ringsOperating Systems & Virtualisation Security
virtual memoryOperating Systems & Virtualisation Security
segment-based protectionOperating Systems & Virtualisation Security
segmentationOperating Systems & Virtualisation Security
hierarchical filesystemsOperating Systems & Virtualisation Security
mandatory access controlsOperating Systems & Virtualisation Security
discretionary access controlsOperating Systems & Virtualisation Security
trusted computer system evaluation criteriaOperating Systems & Virtualisation Security
authentication and identificationOperating Systems & Virtualisation Security
access control listsOperating Systems & Virtualisation Security
SELinuxOperating Systems & Virtualisation Security
capabilitiesOperating Systems & Virtualisation Security
physical access and secure deletionOperating Systems & Virtualisation Security
memory protection and address spacesOperating Systems & Virtualisation Security
pagingOperating Systems & Virtualisation Security
modern hardware extensions for memory protectionOperating Systems & Virtualisation Security
Intel MPXOperating Systems & Virtualisation Security
Intel MPKOperating Systems & Virtualisation Security
memory tagging extensionsOperating Systems & Virtualisation Security
memory protection unitOperating Systems & Virtualisation Security
Intel SGXOperating Systems & Virtualisation Security
ARM TrustZoneOperating Systems & Virtualisation Security
DMAOperating Systems & Virtualisation Security
protection ringsOperating Systems & Virtualisation Security
ring 0Operating Systems & Virtualisation Security
ring -1Operating Systems & Virtualisation Security
safe languagesSoftware Security
ring -2Operating Systems & Virtualisation Security
ring -3 / Intel MEOperating Systems & Virtualisation Security
low-end devices and IoTOperating Systems & Virtualisation Security
operating system hardeningOperating Systems & Virtualisation Security
formal verificationOperating Systems & Virtualisation Security
information hidingOperating Systems & Virtualisation Security
ASLROperating Systems & Virtualisation Security
KASLROperating Systems & Virtualisation Security
fine-grained randomisationOperating Systems & Virtualisation Security
control-flow restrictionsOperating Systems & Virtualisation Security
control-flow integrityOperating Systems & Virtualisation Security
shadow stacksOperating Systems & Virtualisation Security
indirect branch trackingOperating Systems & Virtualisation Security
pointer authenticationOperating Systems & Virtualisation Security
data-flow integrityOperating Systems & Virtualisation Security
partitioningOperating Systems & Virtualisation Security
write xor executeOperating Systems & Virtualisation Security
SMEP and SMAPOperating Systems & Virtualisation Security
speculative executionOperating Systems & Virtualisation Security
meltdownOperating Systems & Virtualisation Security
spectreOperating Systems & Virtualisation Security
RIDLOperating Systems & Virtualisation Security
partitioning micro-architectural statesOperating Systems & Virtualisation Security
page colouringOperating Systems & Virtualisation Security
code and data integrity checksOperating Systems & Virtualisation Security
driver signingOperating Systems & Virtualisation Security
boot checksOperating Systems & Virtualisation Security
UEFIOperating Systems & Virtualisation Security
TPMsOperating Systems & Virtualisation Security
PCRsOperating Systems & Virtualisation Security
hypervisor supported introspectionOperating Systems & Virtualisation Security
anomaly detectionOperating Systems & Virtualisation Security
related areasOperating Systems & Virtualisation Security
databasesOperating Systems & Virtualisation Security
querying encrypted databasesOperating Systems & Virtualisation Security
homomorphic encryptionOperating Systems & Virtualisation Security
outsourced databasesOperating Systems & Virtualisation Security
Merkle hash treesOperating Systems & Virtualisation Security
embracing securityOperating Systems & Virtualisation Security
GRSecurityOperating Systems & Virtualisation Security
PaX TeamOperating Systems & Virtualisation Security
Software and Platform SecurityCyBOK Category
Software SecuritySoftware and Platform Security
categories of vulnerabilitiesSoftware Security
CVEs and CWEsSoftware Security
memory management vulnerabilitiesSoftware Security
attacksSoftware Security
code corruption attacksSoftware Security
control-flow hijack attacksSoftware Security
information leak attackSoftware Security
data-only-attacksSoftware Security
spatial vulnerabilitiesSoftware Security
temporal vulnerabilitiesSoftware Security
structured output generation vulnerabilitiesSoftware Security
SQL injectionSoftware Security
command injection vulnerabilitiiesSoftware Security
script injection vulnerabilities (XSS)Software Security
stored injection vulnerabiliitesSoftware Security
higher-order injection vulnerabilitiesSoftware Security
race condition vulnerabilitiesSoftware Security
concurrency bugsSoftware Security
time-of-check to time-of-useSoftware Security
API vulnerabilitiesSoftware Security
correct useSoftware Security
correct implementationSoftware Security
side-channel vulnerabilitiesSoftware Security
software-based side-channelsSoftware Security
covert channelsSoftware Security
micro-architectual effectsSoftware Security
fault-injection attacksSoftware Security
physical fault-injectionSoftware Security
software fault-injectionSoftware Security
RowhammerSoftware Security
prevention of vulnerabilitiesSoftware Security
API designSoftware Security
defensive programmingSoftware Security
sandboxingSoftware Security
principle of least privilegeSoftware Security
assertionsSoftware Security
contractsSoftware Security
coding practicesSoftware Security
coding guidelinesSoftware Security
MISRASoftware Security
dangerous functionsSoftware Security
programming idiomsSoftware Security
resource acquisition is initialisationSoftware Security
move semanticsSoftware Security
smart pointersSoftware Security
checking complianceSoftware Security
erroneous executionSoftware Security
trapped errorsSoftware Security
untrapped errorsSoftware Security
language design and type systemsSoftware Security
memory management mitigationsSoftware Security
immutable stateSoftware Security
dynamic checksSoftware Security
static checksSoftware Security
structured output generations mitigationsSoftware Security
type systemsSoftware Security
query generationSoftware Security
race condition mitigationsSoftware Security
ownershipSoftware Security
aliasingSoftware Security
information flowSoftware Security
mitigating exploitationSoftware Security
runtime detection of attacksSoftware Security
stack canariesSoftware Security
non-executable memorySoftware Security
control flow integritySoftware Security
automated software diversitySoftware Security
ASLRSoftware Security
limiting privilegesSoftware Security
sandboxingSoftware Security
monitorsSoftware Security
jailsSoftware Security
compartmentalisationSoftware Security
object-capability systemsSoftware Security
detection of vulnerabilitiesSoftware Security
static detectionSoftware Security
heurisitic static detectionSoftware Security
taint analysisSoftware Security
information flow analysisSoftware Security
sound static verificationSoftware Security
program verificationSoftware Security
abstract interpretationSoftware Security
model checkingSoftware Security
soundinessSoftware Security
dynamic detectionSoftware Security
generating relevant executionsSoftware Security
black-box fuzzingSoftware Security
white-box fuzzingSoftware Security
dynamic symbolic executionSoftware Security
monitoringSoftware Security
pre/post-conditionsSoftware Security
design by contractSoftware Security
soundnessSoftware Security
completenessSoftware Security
Secure Software LifecycleSoftware and Platform Security
motivations for secure software lifecycleSecure Software Lifecycle
breaches are costlySecure Software Lifecycle
vulnerablities can be exploited without being noticedSecure Software Lifecycle
patching can introduce vulnerabilitiesSecure Software Lifecycle
customers don't apply patchesSecure Software Lifecycle
trusted computingSecure Software Lifecycle
prescriptive processesSecure Software Lifecycle
SAFECodeSecure Software Lifecycle
application security control definitionSecure Software Lifecycle
secure design principlesSecure Software Lifecycle
secure coding practicesSecure Software Lifecycle
legal and industry requirementsSecure Software Lifecycle
internal policies and standardsSecure Software Lifecycle
incidents and feedbackSecure Software Lifecycle
threats and riskSecure Software Lifecycle
designSecure Software Lifecycle
secure coding practicesSecure Software Lifecycle
manage security findingsSecure Software Lifecycle
common criteriaSecure Software Lifecycle
CVSSSecure Software Lifecycle
vulnerability response and disclosureSecure Software Lifecycle
planning the implementation and deploment of secure developmentSecure Software Lifecycle
PCI DSSSecure Software Lifecycle
manage the security risk of using third-party componentsSecure Software Lifecycle
perfrom static analysis security testingSecure Software Lifecycle
perform dynamic analysis security testingSecure Software Lifecycle
perform penetration testingSecure Software Lifecycle
Microsoft SDLSecure Software Lifecycle
provide trainingSecure Software Lifecycle
define security requirementsSecure Software Lifecycle
SQUARESecure Software Lifecycle
KAOSSecure Software Lifecycle
define metrics and compliance reportingSecure Software Lifecycle
KPIsSecure Software Lifecycle
GDPRSecure Software Lifecycle
establish design requirementsSecure Software Lifecycle
Saltzer Schroeder principlesSecure Software Lifecycle
IEEE Center for Secure Design principlesSecure Software Lifecycle
perform threat modellingSecure Software Lifecycle
STRIDESecure Software Lifecycle
games for threat modellingSecure Software Lifecycle
archtectural risk analysisSecure Software Lifecycle
attack resistance analysisSecure Software Lifecycle
ambiguity analysisSecure Software Lifecycle
weakness analysisSecure Software Lifecycle
design and use cryptography standardsSecure Software Lifecycle
use approved toolsSecure Software Lifecycle
establish a standard incident response processSecure Software Lifecycle
TouchpointsSecure Software Lifecycle
code review (tools)Secure Software Lifecycle
penetration testingSecure Software Lifecycle
abuse casesSecure Software Lifecycle
human errorSecure Software Lifecycle
risk-based security testingSecure Software Lifecycle
OWASP ASVSSecure Software Lifecycle
security requirementsSecure Software Lifecycle
security operationsSecure Software Lifecycle
adaptations of secure software lifecycleSecure Software Lifecycle
agile and DevOpsSecure Software Lifecycle
use software composition analysis and governanceSecure Software Lifecycle
use tools and automationSecure Software Lifecycle
keep credentials safeSecure Software Lifecycle
use continuous learning and monitoringSecure Software Lifecycle
mobileSecure Software Lifecycle
OWASP Mobile Application Security Verification StandardSecure Software Lifecycle
Mobile Security Testing GuideSecure Software Lifecycle
TPMSecure Software Lifecycle
mobile app security checklistSecure Software Lifecycle
moblie threat modelSecure Software Lifecycle
mobile application architectureSecure Software Lifecycle
mobile dataSecure Software Lifecycle
threat agent identificationSecure Software Lifecycle
methods of attackSecure Software Lifecycle
controlsSecure Software Lifecycle
cloud computingSecure Software Lifecycle
multitenancySecure Software Lifecycle
tokenisation of sensitive dataSecure Software Lifecycle
trusted compute poolsSecure Software Lifecycle
data encryption and key managementSecure Software Lifecycle
authentication and identity manangementSecure Software Lifecycle
SSOSecure Software Lifecycle
shared-domain issuesSecure Software Lifecycle
IoTSecure Software Lifecycle
use of RFID tagsSecure Software Lifecycle
default passwords and credentialsSecure Software Lifecycle
use the manufacturer usage descriptionSecure Software Lifecycle
develop a secure upgrade processSecure Software Lifecycle
road vehiclesSecure Software Lifecycle
US National Highway Traffic Safety AdministrationSecure Software Lifecycle
IS21434Secure Software Lifecycle
US SPY car actSecure Software Lifecycle
Intelligent and Connected Vehicles initiativeSecure Software Lifecycle
ecommerceSecure Software Lifecycle
PCI DSSSecure Software Lifecycle
assess the secure software lifecycleSecure Software Lifecycle
SAMMSecure Software Lifecycle
BSIMMSecure Software Lifecycle
Common CriteriaSecure Software Lifecycle
structural testingSecure Software Lifecycle
methodical testingSecure Software Lifecycle
methodical designSecure Software Lifecycle
semi-formal designSecure Software Lifecycle
semi-formal verified designSecure Software Lifecycle
formally verified designSecure Software Lifecycle
Web & Mobile SecuritySoftware and Platform Security
fundamental concepts and approachesWeb & Mobile Security
appificationWeb & Mobile Security
webificationWeb & Mobile Security
Uniform Resource Locators (URLs)Web & Mobile Security
Hypertext Transfer Protocol (HTTP)Web & Mobile Security
protocol formatWeb & Mobile Security
cookiesWeb & Mobile Security
Hypertext Markup Language (HTML)Web & Mobile Security
Cascading Style Sheets (CSS)Web & Mobile Security
JavaScriptWeb & Mobile Security
script processingWeb & Mobile Security
WebAssembly (Wasm)Web & Mobile Security
WebViewsWeb & Mobile Security
application storesWeb & Mobile Security
side-loadingWeb & Mobile Security
vetting procedureWeb & Mobile Security
signingWeb & Mobile Security
impact of user ratings and reviews on application securityWeb & Mobile Security
sandboxingWeb & Mobile Security
application isolationWeb & Mobile Security
content isolationWeb & Mobile Security
same origin policy (SOP)Web & Mobile Security
content security policy (CSP)Web & Mobile Security
permission dialog based access controlWeb & Mobile Security
security principlesWeb & Mobile Security
reference monitorWeb & Mobile Security
security policyWeb & Mobile Security
system applicationsWeb & Mobile Security
third-party applicationsWeb & Mobile Security
different permission approachesWeb & Mobile Security
web PKI and HTTPSWeb & Mobile Security
warning messagesWeb & Mobile Security
adoptionWeb & Mobile Security
rogues certificate authorities and certificate transparencyWeb & Mobile Security
authenticationWeb & Mobile Security
HTTP authenticationWeb & Mobile Security
form-based authenticationWeb & Mobile Security
mobile device authenticationWeb & Mobile Security
biometricsWeb & Mobile Security
graphical passwordsWeb & Mobile Security
unlock patternsWeb & Mobile Security
cookiesWeb & Mobile Security
passwords and alternativesWeb & Mobile Security
password policiesWeb & Mobile Security
password strength metersWeb & Mobile Security
password managersWeb & Mobile Security
multi-factor authenticationWeb & Mobile Security
european payment services directive 2Web & Mobile Security
WebAuthnWeb & Mobile Security
OAuthWeb & Mobile Security
frequent software updatesWeb & Mobile Security
automatic updates in browsersWeb & Mobile Security
automatic updates in appsWeb & Mobile Security
outdated third party librariesWeb & Mobile Security
client side vulnerabilities and mitigationsWeb & Mobile Security
phishingWeb & Mobile Security
address bar manipulation attacksWeb & Mobile Security
internationalised domain name homographs attacksWeb & Mobile Security
anti-phishing trainingWeb & Mobile Security
drive-by-download attacksWeb & Mobile Security
clickjackingWeb & Mobile Security
confused deputy attacksWeb & Mobile Security
client side storageWeb & Mobile Security
cookiesWeb & Mobile Security
HTML5-based storageWeb & Mobile Security
storage in mobile applicationsWeb & Mobile Security
information leakis in Android applicationsWeb & Mobile Security
physical attacksWeb & Mobile Security
smudge attacksWeb & Mobile Security
shoulder surfingWeb & Mobile Security
server side vulnerabilities and mitigationsWeb & Mobile Security
injection vulnerabilitiesWeb & Mobile Security
input sanitisationWeb & Mobile Security
SQL-injectionWeb & Mobile Security
blind attacksWeb & Mobile Security
second order attacksWeb & Mobile Security
prepared statementsWeb & Mobile Security
command injectionWeb & Mobile Security
restrictive development frameworksWeb & Mobile Security
user uploaded filesWeb & Mobile Security
metadada filteringWeb & Mobile Security
same-origin policiesWeb & Mobile Security
local file inclusionWeb & Mobile Security
path sanitisationWeb & Mobile Security
cross-site scripting (XSS)Web & Mobile Security
stored XSS attacksWeb & Mobile Security
reflected XSS attacksWeb & Mobile Security
cross-site request forgery (CSRF)Web & Mobile Security
server side misconfigurations & vulnerable componentsWeb & Mobile Security
HeartBleedWeb & Mobile Security
firewallsWeb & Mobile Security
load balancersWeb & Mobile Security
HTTPS misconfigurationsWeb & Mobile Security
databasesWeb & Mobile Security
password leaksWeb & Mobile Security
Infrastructure SecurityCyBOK Category
Applied CryptographyInfrastructure Security
The Cryptographic TriumvirateApplied Cryptography
Algorithms, Schemes and ProtocolsApplied Cryptography
Hash functionsApplied Cryptography
Block ciphersApplied Cryptography
Stream ciphersApplied Cryptography
Message Authentication Code(MAC) schemesApplied Cryptography
Authenticated Encryption(AE)schemesApplied Cryptography
AE SecurityApplied Cryptography
Nonces in AEApplied Cryptography
AE VariantsApplied Cryptography
Constructing AE SchemesApplied Cryptography
Public Key Encryption Schemes and Key Encapsulation MechanismsApplied Cryptography
PKE SecurityApplied Cryptography
Key Encapsulation MechanismsApplied Cryptography
Some common PKE schemes and KEMsApplied Cryptography
Difie-Hellman Key ExchangeApplied Cryptography
From Difie-Hellman to ElGamalApplied Cryptography
Digital SignaturesApplied Cryptography
Cryptographic DiversityApplied Cryptography
The AdversaryApplied Cryptography
The Role of Formal Security Deinitions and ProofsApplied Cryptography
Key SizesApplied Cryptography
Development of Standardised CryptographyApplied Cryptography
Post-quantum CryptographyApplied Cryptography
Quantum Key DistributionApplied Cryptography
From Schemes to ProtocolsApplied Cryptography
Cryptographic ImplementationApplied Cryptography
Cryptographic LibrariesApplied Cryptography
API Design for Cryptographic LibrariesApplied Cryptography
Implementation ChallengesApplied Cryptography
Side ChannelApplied Cryptography
Length Side ChannelsApplied Cryptography
Timing Side ChannelsApplied Cryptography
Error Side ChannelsApplied Cryptography
Attacks Arising from Shared ResourcesApplied Cryptography
Implementation WeaknessesApplied Cryptography
Attacks Arising from CompositionApplied Cryptography
Hardware Side ChannelsApplied Cryptography
Fault AttacksApplied Cryptography
DefencesApplied Cryptography
Random Bit GenerationApplied Cryptography
Key ManagementApplied Cryptography
The Key Life-cycleApplied Cryptography
Key DerivationApplied Cryptography
Password-Based Key DerivationApplied Cryptography
Key GenerationApplied Cryptography
Key StorageApplied Cryptography
Key TransportationApplied Cryptography
Refreshing Keys and Forward SecurityApplied Cryptography
Managing Public Keys and Public Key InfrastructureApplied Cryptography
Binding Public Keys and Identities via CertificatesApplied Cryptography
Reliance on Naming, CA Operations and TimeApplied Cryptography
Reliance on Certificate Status InformationApplied Cryptography
Reliance on Correct Software and Unbroken CryptographyApplied Cryptography
Other Approaches to Managing Public KeysApplied Cryptography
Consuming CryptographyApplied Cryptography
The Challenges of Consuming CryptographyApplied Cryptography
Addressing the ChallengesApplied Cryptography
Making Cryptography InvisibleApplied Cryptography
Applied Cryptography in ActionApplied Cryptography
Transport Layer SecurityApplied Cryptography
Secure MessagingApplied Cryptography
Apple MessageApplied Cryptography
SignalApplied Cryptography
TelegramApplied Cryptography
Contact Tracing a la DP-3TApplied Cryptography
Future of Applied CryptographyApplied Cryptography
Cyber-Physical Systems SecurityInfrastructure Security
cyber-physical systemsCyber-Physical Systems Security
characteristicsCyber-Physical Systems Security
embedded systemsCyber-Physical Systems Security
real-time systemsCyber-Physical Systems Security
network protocolsCyber-Physical Systems Security
wirelessCyber-Physical Systems Security
sensor networksCyber-Physical Systems Security
controlCyber-Physical Systems Security
discrete-time controlCyber-Physical Systems Security
networked-controlled systemsCyber-Physical Systems Security
hybrid systemsCyber-Physical Systems Security
protections against natural events and accidentsCyber-Physical Systems Security
safetyCyber-Physical Systems Security
protectionCyber-Physical Systems Security
protection of generatorsCyber-Physical Systems Security
under frequency load shedding (UFLS)Cyber-Physical Systems Security
overcurrent protectionCyber-Physical Systems Security
ove/under voltageCyber-Physical Systems Security
reliabilityCyber-Physical Systems Security
fault toleranceCyber-Physical Systems Security
robust controlCyber-Physical Systems Security
safety vs securityCyber-Physical Systems Security
security and privacy concernsCyber-Physical Systems Security
attacks agains CPSsCyber-Physical Systems Security
architectural threatsCyber-Physical Systems Security
high-profile real-world attacksCyber-Physical Systems Security
crosscutting securityCyber-Physical Systems Security
preventing attacksCyber-Physical Systems Security
securing legacy systemsCyber-Physical Systems Security
bumb-in-the-wireCyber-Physical Systems Security
wireless shieldCyber-Physical Systems Security
lightweight securityCyber-Physical Systems Security
secure microkernelsCyber-Physical Systems Security
preventing transduction attacksCyber-Physical Systems Security
detecting attacksCyber-Physical Systems Security
remote attestationCyber-Physical Systems Security
network intrusion detectionCyber-Physical Systems Security
physics-based attack detectionCyber-Physical Systems Security
historical anomaliesCyber-Physical Systems Security
physical-law anomaliesCyber-Physical Systems Security
out-of-band detectionCyber-Physical Systems Security
active detectionCyber-Physical Systems Security
mitigating attacksCyber-Physical Systems Security
resilient control systemsCyber-Physical Systems Security
conservative controlCyber-Physical Systems Security
resilient estimationCyber-Physical Systems Security
sensor fusionCyber-Physical Systems Security
virtual sensorsCyber-Physical Systems Security
constraining actuationCyber-Physical Systems Security
inertial resetsCyber-Physical Systems Security
reactive control compensationCyber-Physical Systems Security
safe control actionsCyber-Physical Systems Security
CPS domainsCyber-Physical Systems Security
industrial control systemsCyber-Physical Systems Security
PLCsCyber-Physical Systems Security
RTUsCyber-Physical Systems Security
corporate networksCyber-Physical Systems Security
SCADACyber-Physical Systems Security
regulatory controlCyber-Physical Systems Security
OT networksCyber-Physical Systems Security
intrusion detectionCyber-Physical Systems Security
electric power gridsCyber-Physical Systems Security
bulk power systemCyber-Physical Systems Security
smart gridsCyber-Physical Systems Security
efficiencyCyber-Physical Systems Security
reliabilityCyber-Physical Systems Security
consumer choiceCyber-Physical Systems Security
load-altering attacksCyber-Physical Systems Security
transportation systems and autonomous vehiclesCyber-Physical Systems Security
traffic flow controlCyber-Physical Systems Security
demand managementCyber-Physical Systems Security
incident managementCyber-Physical Systems Security
vulnerabilitiesCyber-Physical Systems Security
ground, air, and see vehiclesCyber-Physical Systems Security
privacy concerns of dronesCyber-Physical Systems Security
transduction attacks on sensorsCyber-Physical Systems Security
robotics and advanced manufacturingCyber-Physical Systems Security
attacks on qualityCyber-Physical Systems Security
safety problemsCyber-Physical Systems Security
medical devicesCyber-Physical Systems Security
implantable medical devicesCyber-Physical Systems Security
attacksCyber-Physical Systems Security
touch-to-access principleCyber-Physical Systems Security
IoTCyber-Physical Systems Security
DDoS attacksCyber-Physical Systems Security
botnetsCyber-Physical Systems Security
privacy invasionsCyber-Physical Systems Security
attacks on digital assistantsCyber-Physical Systems Security
security hubsCyber-Physical Systems Security
policy and political aspectsCyber-Physical Systems Security
incentives and regulationCyber-Physical Systems Security
regulationCyber-Physical Systems Security
incentivesCyber-Physical Systems Security
cyber-conflictCyber-Physical Systems Security
cybercriminalsCyber-Physical Systems Security
disgruntled employeesCyber-Physical Systems Security
terrorists and activistsCyber-Physical Systems Security
nation statesCyber-Physical Systems Security
Tallinn manualCyber-Physical Systems Security
Koh speechCyber-Physical Systems Security
acts of warCyber-Physical Systems Security
industry practices and standardsCyber-Physical Systems Security
ISA 99/IEC 62443Cyber-Physical Systems Security
NIST SP 800-53Cyber-Physical Systems Security
NIST-IR 762Cyber-Physical Systems Security
NERC standardsCyber-Physical Systems Security
IEC 104Cyber-Physical Systems Security
PROFINETCyber-Physical Systems Security
IEC 62351Cyber-Physical Systems Security
ETSI TS 103 645Cyber-Physical Systems Security
Hardware SecurityInfrastructure Security
hardware design cycleHardware Security
hardware design processHardware Security
behavioural domainHardware Security
current, voltageHardware Security
logicHardware Security
register transfersHardware Security
algorithmsHardware Security
systemsHardware Security
structural domainHardware Security
transistorsHardware Security
gates, flip-flops, etcHardware Security
ALUs, RAM, etcHardware Security
processorHardware Security
physical domainHardware Security
transistor layoutHardware Security
cell layoutHardware Security
module layoutHardware Security
floorplansHardware Security
physical partitionsHardware Security
root of trustHardware Security
TPMsHardware Security
SIMsHardware Security
threat modelHardware Security
measuring hardware securityHardware Security
FIPS 140-2Hardware Security
approved cryptographic algorithmsHardware Security
tamper evidenceHardware Security
tamper resistanceHardware Security
common criteria and EMVCoHardware Security
SESIPHardware Security
secure platformsHardware Security
hardware security module (HSM)Hardware Security
secure element and smartcardHardware Security
trusted platform module (TPM)Hardware Security
root of trust for measurementHardware Security
root of trust for storageHardware Security
root of trust for reportingHardware Security
hardware support for software securityHardware Security
objectivesHardware Security
protectionHardware Security
isolationHardware Security
attestationHardware Security
sealed storageHardware Security
memory protectionHardware Security
control flow integrityHardware Security
information flow analysisHardware Security
virtual machinesHardware Security
trusted execution environmentHardware Security
IBM 4758 secure coprocessorHardware Security
ARM TrustzoneHardware Security
protected module architecturesHardware Security
small TCB implementationsHardware Security
zero TCB implementationsHardware Security
Intel Software Guard Extension (SGX)Hardware Security
light-weight solutionsHardware Security
SMARTHardware Security
hardware shadow stacksHardware Security
pointer authenticationHardware Security
QarmaHardware Security
hardware design for cryptographic algorithmsHardware Security
design processHardware Security
register transfer level (RTL)Hardware Security
application specific integrated circuit (ASIC)Hardware Security
field programmable gata array (FPGA)Hardware Security
power consumptionHardware Security
electronic design automation (EDA)Hardware Security
cryptographic algorithms at RTL levelHardware Security
secret key algorithmsHardware Security
secret key light-weight algorithmsHardware Security
hash algorithmsHardware Security
cryptocurrency miningHardware Security
public key algorithmsHardware Security
quantum resistant algorithmsHardware Security
homomorphic encryption schemesHardware Security
side-channel attacks and fault attacksHardware Security
attacksHardware Security
passive side channel attacksHardware Security
simple power analysisHardware Security
differential power analysisHardware Security
electro-magnetic radiation attacksHardware Security
timing attacksHardware Security
constant time executionHardware Security
template attacksHardware Security
micro-architectural side-channelsHardware Security
spectreHardware Security
meltdownHardware Security
foreshadowHardware Security
active fault attacksHardware Security
RowHammerHardware Security
optical-fault attacksHardware Security
sensorsHardware Security
countermeasuresHardware Security
randomisationHardware Security
maskingHardware Security
hidingHardware Security
micro-code updatesHardware Security
redundancyHardware Security
entropy generating building blocksHardware Security
random number generationHardware Security
pseudo random number generation (PRNG)Hardware Security
true random number generation (TRNG)Hardware Security
physically unclonable functions (PUFs)Hardware Security
weak PUFsHardware Security
strong PUFsHardware Security
machine learning attacksHardware Security
hardware design processHardware Security
design and fabrication of silicon integrated circuitsHardware Security
trojan circuitsHardware Security
cicuit level techniquesHardware Security
board level securityHardware Security
timeHardware Security
Network SecurityInfrastructure Security
Security Goals and Attacker ModelsNetwork Security
Security Goals in Networked SystemsNetwork Security
Attacker ModelsNetwork Security
Networking ApplicationsNetwork Security
Local Area Networks (LANs)Network Security
Connected Networks and the InternetNetwork Security
Bus NetworksNetwork Security
Wireless NetworksNetwork Security
Fully Distributed Networks: DHTs and Unstructured P2P NetworksNetwork Security
Software-Defined Networking and Network Function VirtualisationNetwork Security
Network Protocols and Their SecurityNetwork Security
Security at the Application LayerNetwork Security
Email and Messaging SecurityNetwork Security
Hyper Text Transfer Protocol Secure (HTTPS)Network Security
DNS SecurityNetwork Security
Network Time Protocol (NTP) SecurityNetwork Security
Distributed Hash Table (DHT) SecurityNetwork Security
Anonymous and Censorship-Free CommunicationNetwork Security
Security at the Transport LayerNetwork Security
TLS (Transport Layer Security)Network Security
Public Key InfrastructureNetwork Security
TCP SecurityNetwork Security
UDP SecurityNetwork Security
QUICNetwork Security
Security at the Internet LayerNetwork Security
IPv4 SecurityNetwork Security
IP SpoofingNetwork Security
Fragmentation AttacksNetwork Security
VPNs and IPsecNetwork Security
NATNetwork Security
IPv6 SecurityNetwork Security
Routing SecurityNetwork Security
Within an Autonomous System (AS)Network Security
Across ASsNetwork Security
ICMP SecurityNetwork Security
Security on Link LayerNetwork Security
Port-based Network Access Control (IEEE 802.1X)Network Security
WAN Link-Layer SecurityNetwork Security
Attacks on Ethernet SwitchesNetwork Security
Address Resolution Protocol (ARP) / Neighbor Discovery Protocol (NDP)Network Security
Network SegmentationNetwork Security
Wireless SecurityNetwork Security
Bus SecurityNetwork Security
Network Security ToolsNetwork Security
FirewallingNetwork Security
Application Gateway (AG)Network Security
Circuit-level Gateway (CG)Network Security
Intrusion Detection and Prevention SystemsNetwork Security
Intrusion Prevention System (IPS)Network Security
Network Security MonitoringNetwork Security
SDN and NFV SecurityNetwork Security
Network Access ControlNetwork Security
Zero Trust NetworkingNetwork Security
DoS CountermeasuresNetwork Security
Other Network Security TopicsNetwork Security
Cloud and Data Center SecurityNetwork Security
Delay-Tolerant Networks and Ad-hoc Sensors NetworksNetwork Security
Network Covert ChannelsNetwork Security
Payment NetworksNetwork Security
Physical-Layer SecurityNetwork Security
Networking Infrastructure SecurityNetwork Security
Cross-Border RegulationsNetwork Security
Physical Layer & Telecommunications SecurityInfrastructure Security
schemes for confidentiality, integrity and access controlPhysical Layer & Telecommunications Security
key establishment based on channel reciprocityPhysical Layer & Telecommunications Security
establishment processesPhysical Layer & Telecommunications Security
quantisationPhysical Layer & Telecommunications Security
information reconciliationPhysical Layer & Telecommunications Security
key verificationPhysical Layer & Telecommunications Security
MIMO-supported approachesPhysical Layer & Telecommunications Security
orthogonal blindingPhysical Layer & Telecommunications Security
zero-forcingPhysical Layer & Telecommunications Security
secrecy capacityPhysical Layer & Telecommunications Security
friendly jammingPhysical Layer & Telecommunications Security
protecting data integrityPhysical Layer & Telecommunications Security
integrity codesPhysical Layer & Telecommunications Security
LPI and covert communicationPhysical Layer & Telecommunications Security
frequency hoppingPhysical Layer & Telecommunications Security
direct sequency spread spectrumPhysical Layer & Telecommunications Security
chirpingPhysical Layer & Telecommunications Security
jamming and jamming-resilient communicationPhysical Layer & Telecommunications Security
classifications of jammersPhysical Layer & Telecommunications Security
constantPhysical Layer & Telecommunications Security
reactivePhysical Layer & Telecommunications Security
countermeasuresPhysical Layer & Telecommunications Security
coordinated spread spectrum techniquesPhysical Layer & Telecommunications Security
uncoordinated spread spectrum techniquesPhysical Layer & Telecommunications Security
signal anihilation and overshadowingPhysical Layer & Telecommunications Security
identificationPhysical Layer & Telecommunications Security
device under identificationPhysical Layer & Telecommunications Security
identification signalsPhysical Layer & Telecommunications Security
featuresPhysical Layer & Telecommunications Security
in-specificaitonPhysical Layer & Telecommunications Security
modulation errorsPhysical Layer & Telecommunications Security
time-related parametersPhysical Layer & Telecommunications Security
out-specificationPhysical Layer & Telecommunications Security
clock skewPhysical Layer & Telecommunications Security
turn-on transient durationPhysical Layer & Telecommunications Security
inferred characteristicsPhysical Layer & Telecommunications Security
device fingerprintsPhysical Layer & Telecommunications Security
propertiesPhysical Layer & Telecommunications Security
universalityPhysical Layer & Telecommunications Security
uniquenessPhysical Layer & Telecommunications Security
collectabilityPhysical Layer & Telecommunications Security
permenancePhysical Layer & Telecommunications Security
robustnessPhysical Layer & Telecommunications Security
data-dependencyPhysical Layer & Telecommunications Security
attacks on physical layer identificationPhysical Layer & Telecommunications Security
signal re(p)layPhysical Layer & Telecommunications Security
feature replayPhysical Layer & Telecommunications Security
distance bounding and secure positioningPhysical Layer & Telecommunications Security
distance bounding protocolsPhysical Layer & Telecommunications Security
attacksPhysical Layer & Telecommunications Security
distance fraudPhysical Layer & Telecommunications Security
mafia fraudPhysical Layer & Telecommunications Security
terrorist fraudPhysical Layer & Telecommunications Security
distance hijackingPhysical Layer & Telecommunications Security
distance measurement techniquesPhysical Layer & Telecommunications Security
physical layer attacks on secure distance measurementPhysical Layer & Telecommunications Security
RSSI-based distance estimation attacksPhysical Layer & Telecommunications Security
time of flight based ranging attacksPhysical Layer & Telecommunications Security
secure positioningPhysical Layer & Telecommunications Security
spoofing attacksPhysical Layer & Telecommunications Security
verifiable multilaterationPhysical Layer & Telecommunications Security
secure positioning based on hidden stationsPhysical Layer & Telecommunications Security
physical layer security of selected communication technologiesPhysical Layer & Telecommunications Security
NFCPhysical Layer & Telecommunications Security
wormhole attacksPhysical Layer & Telecommunications Security
shieldingPhysical Layer & Telecommunications Security
multi-factor authenticationPhysical Layer & Telecommunications Security
protocol augmentationPhysical Layer & Telecommunications Security
timing restrictionsPhysical Layer & Telecommunications Security
distance boundingPhysical Layer & Telecommunications Security
air traffic communication networksPhysical Layer & Telecommunications Security
ADS-BPhysical Layer & Telecommunications Security
multilaterationPhysical Layer & Telecommunications Security
cellular networksPhysical Layer & Telecommunications Security
GSMPhysical Layer & Telecommunications Security
3GPhysical Layer & Telecommunications Security
GPRSPhysical Layer & Telecommunications Security
4G (LTE)Physical Layer & Telecommunications Security
authentication protocolsPhysical Layer & Telecommunications Security
5GPhysical Layer & Telecommunications Security
GNSS security and spoofing attacksPhysical Layer & Telecommunications Security
galileoPhysical Layer & Telecommunications Security
signal spoofing attacksPhysical Layer & Telecommunications Security
non-coherent and modified message contentsPhysical Layer & Telecommunications Security
non-coherent but unmodified message contentsPhysical Layer & Telecommunications Security
coherent but modified message contentsPhysical Layer & Telecommunications Security
coherent and unmodified message contentsPhysical Layer & Telecommunications Security
seeamless takeover attackPhysical Layer & Telecommunications Security
countermeasuresPhysical Layer & Telecommunications Security