A Taxonomy of UNIX and Network Security Vulnerabilities

Ambrose Bierce defined 'history' as 'a record of mistakes made in the past, so we shall know when we make them again.' Although sardonic, his definition describes the state of affairs of computer system vulnerabilities. A 'vulnerable state' is 'any state which enables a user to read information without authorization, modify information without authorization, or grant or deny an entity access to a resource without authorization.' 'Exploiting a vulnerability' means that a system is in a vulnerable state and a user (called an attacker) reads or writes the information without authorization, or grants or denies service to another without authorization. In both these definitions, 'without authorization' means 'in violation of the system's security policy.' A 'vulnerability' (also called a 'flaw' or a 'hole') is the property of the system, its attendant software and/or hardware, or its administrative procedures, that cause it to enter a vulnerable state.

Click Here to download this article

Share this article

Receive all the latest articles by email!

Get all articles delivered directly to your mailbox as and when they are released on WindowSecurity.com! Choose between receiving instant updates with the Real-Time Article Update, or a monthly summary with the Monthly Article Update.



Receive all the latest articles by email!

Receive Real-Time & Monthly WindowSecurity.com article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become a WindowSecurity.com member!

Discuss your security issues with thousands of other network security experts. Click here to join!

Community Area

Log in | Register

Solution Center

Readers' Choice

Which is your preferred VPN solution?