~/ learn/ comp-400/ cards/ Intruder classes, the attack methodology, and what an IDS is
1 of 7

An attacker reaches root on a file server, stops the audit daemon, and rewrites the access-control configuration so that nothing done afterwards is recorded anywhere. Which class of the classical taxonomy is that?

An attacker reaches root on a file server, stops the audit daemon, and rewrites the access-control configuration so that nothing done afterwards is recorded anywhere. Which class of the classical taxonomy is that?

Answer

Clandestine user

Options - A. Clandestine user - B. Masquerader - C. Misfeasor - D. Mole Why - A. Correct — the defining act is turning the supervisory level against the monitoring, and this is the one class that may be an insider or an outsider. - B. A masquerader is not authorised to use the computer at all; they penetrate the access controls and run somebody else’s account. This attacker holds supervisory power and hides behind that, not behind a borrowed identity. - C. A misfeasor is a legitimate user exceeding or misusing their authority. They have standing on the system already, and they do not need to defeat the auditing to do what they do. - D. Not a member of this taxonomy at all. If it looked plausible, that is the recognition trap: three real terms and one that merely sounds like one. Ask what standing the intruder had before the intrusion: none (masquerader), legitimate (misfeasor), or supervisory (clandestine user).

J. P. Anderson, Computer Security Threat Monitoring and Surveillance (1980), carried by earlier editions of Stallings & Brown — NOT in the 5th edition

space flip · ← → navigate · esc to exit
NORMAL ~/memra/library/888979ea-0170-4764-90da-ec68ce4c8512/flashcard utf-8 LF