1answer.
Ask question
Login Signup
Ask question
All categories
  • English
  • Mathematics
  • Social Studies
  • Business
  • History
  • Health
  • Geography
  • Biology
  • Physics
  • Chemistry
  • Computers and Technology
  • Arts
  • World Languages
  • Spanish
  • French
  • German
  • Advanced Placement (AP)
  • SAT
  • Medicine
  • Law
  • Engineering
saul85 [17]
4 years ago
14

Information flow is a useful mechanism that can enforce a variety of security policies that are hard to describe in simple acces

s control lists. Describe how you can use information flow as a building block to catch the following attacks or vulnerabilities. Please specify the information sources and sinks that one should track (1 point * 3): 1. A buffer overflow attack that overwrites a function pointer. 2. Link following attack where a victim process reads a file from an attacker-controlled directory. 3. Skype app on Android accidentally stores the password in plaintext in a file that's accessible to everyone.
English
1 answer:
I am Lyosha [343]4 years ago
3 0

Answer / Explanation

For proper clarity, we redefine information flow as the navigation of data between humans and systems.

A proper and well secured mode of movement of information or data flow information flow is a critical factor when considering the performance of a process, decision making and in communications. The following are common types of information flow.

It should also be noted that the advantages of an information flow process can not be over emphasized.

Referring back to the question where we are being asked to describe how information flow serve as a building block to curb attacks can also point back to some of its advantages.

(1) Buffer Overflow attack: This can be described as an abnormal behaviour where a program while writing data or transferring data to a buffer exceeds the buffer's boundary and overwrites to adjacent memory locations which may result in abnormal program behavior including memory access errors, incorrect results, and crashes.  We should also understand that buffers are allotted areas of memory set aside to hold data, often while moving it from one section of a program to another, or between programs. Thus, information flow helps to curb the buffer overflow attach by setting a boundary limit in the process of transfer of communication between the program and the buffer therefor casing a stoppage in the overwrite process of a buffer overflow.

(2)  This can be likened to the page catch attack or Directory Traversal Attacks  where an attacker is are able to traverse out of the current directory into parent directories usually by supplying a series of “../” (dot dot slashes). Sometimes it is possible to back out of the root directory of the Web server and traverse into other directories on the file system. Typically, directory traversal attacks allow the attacker to access or overwrite files that are not intended to be accessible. Now to link the attack, it should be noted that the attacker tries to overwrite the buffer therefore intentionally creating a loophole in the program. Thus, by implementing the information flow, we can also curb this.

(3) This can be likened to the aforementioned process. If passwords are accidentally stored in a location where it is accessible to everyone, then it posses a risk of it being hacked or the password being changed. However, to prevent this, we can simply make use of the clear catch or clear buffer catch process, this way, we are sure of the security of the transfer of data which also streamlines it down to one of the functionality of the information flow process.

You might be interested in
Any ten points for or against telling ghost stories to children​
alukav5142 [94]

Answer:

i'd say it's okay to tell ghost stories to children as long as they aren't too graphic.  Ghost stories can be fun to tell around the campfire and stuff.

5 0
3 years ago
So.. Is the `Inciting Incident` another meaning for `Rising Action` in a story?
yaroslaw [1]

Answer:

The inciting incident is an episode, plot point or event that hooks the reader into the story. This particular moment is when an event thrusts the protagonist into the main action of the story.

Explanation:

Inciting Incident: The character reacts to something that has happened, and it starts a chain reaction of events. Rising Action: The story builds. There is often a complication, which means the problem the character tried to solve gets more complex.

5 0
3 years ago
Help me please……………………
antiseptic1488 [7]

Answer:

entertain people (c)

Explanation:

the various forms of media are to entertain people

7 0
3 years ago
Read 2 more answers
Give examples of how land resources are used in a city setting.
Ierofanga [76]

Answer: An example of how land resources are used in a city setting: land resources such as gravel and bedrock are used to construct buildings, roads, and sidewalks.

(Vote me brainliest please )

4 0
4 years ago
Read 2 more answers
Which rights were guaranteed in the Declaration of Independence?
Minchanka [31]
C. life, liberty and the pursuit of happiness
5 0
3 years ago
Read 2 more answers
Other questions:
  • Write a thesis explaining the importance of having a good friend.
    12·1 answer
  • What is most likely the purpose of "A Voyage to the Country of the Houyhnhnms" in Jonathan Swift's Gulliver's Travels?
    14·2 answers
  • Once the dye had been applied to the shirt, all that remained was to -steep- it. - dry(my answer) - freeze - rinse - soak
    6·1 answer
  • The Classical model of argument consists of five components. Which of the following is NOT one of those components? A.) a strong
    13·1 answer
  • Audiences are impressed favorably with speakers who speak in a monotone. true or false
    6·2 answers
  • Read the provided document and then answer the questions.
    10·1 answer
  • Which statement makes the best counterclaim for this claim?
    14·1 answer
  • Which appeal is John Dickinson using in his letter rejecting British taxes?
    5·1 answer
  • R8 me hows everyone doing....
    10·2 answers
  • Read the excerpt from Votes for Women:
    11·1 answer
Add answer
Login
Not registered? Fast signup
Signup
Login Signup
Ask question!