escription should include
- understanding that a large number of vulnerabilities historically have been through flaws in software
- describing elements that make a system vulnerable
- a system susceptibility or flaw
- attacker access to the flaw
- attacker capability to exploit the flaw
- explaining the effect of a vulnerability on a system (i.e., compromised confidentiality, integrity, or availability of resources)
- discussing flaws in software that can lead to vulnerabilities, such as
- buffer overflow or broken authentication and session management
- injection vulnerabilities
- input validation
- privilege confusion.
Teacher Resources: