Vulnerability Analysis (2020)
The intent of the Vulnerability Analysis Knowledge Unit is to provide students with a thorough understanding of system vulnerabilities, to include what they are, how they can be found/identified, the different types of vulnerabilities, how to determine the root cause of a vulnerability, and how to mitigate their effect on an operational system.
- 1 Outcomes
- 2 Topics
- 3 Skills
- 4 NICE Framework Categories
- 5 CSEC 2017 Categories
- 6 Specialization Areas
- 7 See also
- 8 Further reading
- 9 Sample knowledge test
- 10 Sample skills test
- 11 Sample abilities test
- 12 Additional notes or materials
- 13 Contacts
- 14 Reference ID
To complete this KU, students should be able to:
- Apply tools and techniques for identifying vulnerabilities.
- Create and apply a vulnerability map of a system.
- Apply techniques to trace a vulnerability to its root cause.
- Propose and analyze countermeasures to mitigate vulnerabilities.
- Explain the circumstances under which a vulnerability must be disclosed.
- Definition of “vulnerability”
- System modeling techniques
- Vulnerability mapping.
- Vulnerability characteristics and classification.
- Buffer overflows, privilege escalation, rootkits
- Return oriented programming
- Social Engineering Vulnerabilities
- Administrative Privileges and Their Effect on Vulnerabilities
- Root causes of vulnerabilities
- Mitigation strategies
- Analyze the expected and actual effectiveness of proposed countermeasures.
- Explain when vulnerabilities must be disclosed.
- Tools and Techniques for Identifying Vulnerabilities
NICE Framework Categories
CSEC 2017 Categories
- Digital Forensics, Specialization Area
- Industrial Control Systems-SCADA Security
- Network Security Administration, Specialization Area
- Network Security Engineering
- Secure Cloud Computing
- Secure Software Development
- Security Incident Analysis and Response
- System Security Administration
Related Knowledge Units
- Life-Cycle Security
- Software Assurance
- Security Risk Analysis
- Secure Programming Practices
- Software Security Analysis
- QA/Functional Testing
Original Knowledge Unit
Suggested academic readings
Sample knowledge test
Sample skills test
Sample abilities test
Additional notes or materials