FIT1093 Chap.1 Security Goals, Threats and Attack Types
Security Goals, Threats and Attack Types
The opening week of the unit sets up the vocabulary that every later topic reuses. Cybersecurity is presented as a problem of several parties who own different assets and still have to interact, where some parties misbehave. The goal is to design systems, meaning technologies, processes and practices together, that keep protecting data, networks, computers and programs even while an adversary is active.
Four security goals organise the whole semester: confidentiality keeps secret data secret, integrity keeps data unchanged, authentication confirms that data or a person is genuine, and availability keeps a service usable when it is needed.
Week 1 then separates four terms that students often blur.
A threat is a set of circumstances with the potential to cause harm, a vulnerability is a weakness that could be exploited, an attack is the action that exploits it, and a control is the measure that removes or reduces the weakness.
Attacks are grouped by the goal they break: interception, exposure, inference and intrusion against confidentiality; modification and fabrication against integrity; impersonation and repudiation against authentication; and interruption or denial of service against availability.
Two further ideas shape how defences are chosen.
Passive attacks such as eavesdropping and traffic analysis are hard to detect, so the realistic plan is to prevent them from revealing anything. Active attacks such as replay, masquerade and modification are hard to prevent on a channel you do not control, so the plan is to detect them and recover.
Finally, three principles guide design: the weakest link, timeliness, which says protection is only needed while the asset has value, and effectiveness, which asks for mechanisms that are correct, efficient, easy to use and no more expensive than what they protect.
What this chapter covers
- 01
The security problem and the four security goals
- 02
Threat, vulnerability, attack and control
- 03
Attack families mapped to the goal each one breaks
- 04
Passive and active attacks with their defensive plans
- 05
Prevent, detect and recover as general approaches
- 06
The weakest link, timeliness and effectiveness principles
Worked example · free
Classify a three-step attack on a library loan app
- 2Step 1 only observes traffic, so it is passive. Learning a person's reading pattern breaks confidentiality, through inference from observed behaviour.
- 2Step 2 changes a genuine message in transit, which is an active modification attack on integrity.
- 2Step 3 overwhelms the server, an active interruption, also called denial of service, against availability.
Key terms
- Integrity
- The security goal that received or stored data has not been modified by an unauthorised party.
- Availability
- The security goal that a system or service remains usable by legitimate users when they need it.
- Vulnerability
- A weakness in a system that a threat agent could exploit to cause loss or harm.
- Traffic Analysis
- A passive attack that learns who is communicating, how often and for how long, without reading message content.
- Weakest Link Principle
- The idea that a system is only as secure as its least protected component, which is where attackers concentrate.
Security Goals, Threats and Attack Types FAQ
What are the four security goals in this unit?
Confidentiality, integrity, authentication and availability, abbreviated on the Week 1 slides as C, I, A and A. Each later week introduces tools aimed at one or more of them, so naming the goal is the first step in most scenario answers.
What is the difference between a threat and a vulnerability?
A threat is a set of circumstances that could cause harm, while a vulnerability is a specific weakness that might be exploited. The attack is the action that exploits the weakness, and a control is the measure that reduces it.
Why are passive attacks prevented rather than detected?
Passive attacks such as eavesdropping leave no trace in the data, so a defender usually cannot notice them. The practical response is prevention: making intercepted traffic useless to the attacker, typically through encryption or access control.
Is fabrication an attack on integrity or on authentication?
Sources in the unit differ. The Week 1 slides list fabrication under integrity, while the Workshop 1 solution calls it an attack on authenticity. A forged message damages both, so state which reading you use and justify it.
Which principle says security should be easy to use?
The effectiveness principle. It asks for mechanisms that are correct, efficient, easy to use and appropriate, and that do not cost more than the asset they protect, which balances security against cost and performance.
Assessment move
Build a single table for this chapter with the four goals as columns and fill in, for each one, the attacks against it, an everyday example, and the defensive approach that fits. Then practise classification on small invented incidents: for each step, decide whether the attacker changed anything, which goal suffered, and which weakness made it possible.
Learn the four terms threat, vulnerability, attack and control as a sequence you can apply to any story, because the sample in-class test asked students to categorise attacks and justify the choice. Finally, attach a real situation to each of the three principles so that you can explain them rather than recite them, and check whether an answer of yours names a principle without saying why it applies.
Working through Security Goals, Threats and Attack Types in FIT1093? Sia is AskSia’s AI Cybersecurity tutor — ask any FIT1093 Security Goals, Threats and Attack Types question and get a clear, step-by-step explanation grounded in how FIT1093 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.