Monash University · FACULTY OF CYBERSECURITY

FIT1093 Chap.1 Security Goals, Threats and Attack Types

- one subject, every graph, every model, every mark
6 Chapters4-page Bible
Our own words - no uploaded lecturer files
Updated for this semester
Chapter 1 of 10 · FIT1093

Security Goals, Threats and Attack Types

The opening week of the unit sets up the vocabulary that every later topic reuses. Cybersecurity is presented as a problem of several parties who own different assets and still have to interact, where some parties misbehave. The goal is to design systems, meaning technologies, processes and practices together, that keep protecting data, networks, computers and programs even while an adversary is active.

Four security goals organise the whole semester: confidentiality keeps secret data secret, integrity keeps data unchanged, authentication confirms that data or a person is genuine, and availability keeps a service usable when it is needed.

Week 1 then separates four terms that students often blur.

A threat is a set of circumstances with the potential to cause harm, a vulnerability is a weakness that could be exploited, an attack is the action that exploits it, and a control is the measure that removes or reduces the weakness.

Attacks are grouped by the goal they break: interception, exposure, inference and intrusion against confidentiality; modification and fabrication against integrity; impersonation and repudiation against authentication; and interruption or denial of service against availability.

Two further ideas shape how defences are chosen.

Passive attacks such as eavesdropping and traffic analysis are hard to detect, so the realistic plan is to prevent them from revealing anything. Active attacks such as replay, masquerade and modification are hard to prevent on a channel you do not control, so the plan is to detect them and recover.

Finally, three principles guide design: the weakest link, timeliness, which says protection is only needed while the asset has value, and effectiveness, which asks for mechanisms that are correct, efficient, easy to use and no more expensive than what they protect.

In this chapter

What this chapter covers

  • 01

    The security problem and the four security goals

  • 02

    Threat, vulnerability, attack and control

  • 03

    Attack families mapped to the goal each one breaks

  • 04

    Passive and active attacks with their defensive plans

  • 05

    Prevent, detect and recover as general approaches

  • 06

    The weakest link, timeliness and effectiveness principles

Worked example · free

Classify a three-step attack on a library loan app

Q [6 marks]. The mark allocation on this example is our own practice weighting, not an official university scheme. A library app sends loan requests over campus Wi-Fi. An attacker (1) watches which titles a student borrows each week, (2) alters a captured request so a different book is reserved, and (3) floods the reservation server in the first week of semester so nobody can reserve. Classify each step as passive or active and name the goal it breaks.
  • 2Step 1 only observes traffic, so it is passive. Learning a person's reading pattern breaks confidentiality, through inference from observed behaviour.
  • 2Step 2 changes a genuine message in transit, which is an active modification attack on integrity.
  • 2Step 3 overwhelms the server, an active interruption, also called denial of service, against availability.
Step 1 is a passive attack on confidentiality, step 2 an active attack on integrity, and step 3 an active attack on availability. Encrypting and authenticating each request addresses the first two; rate limiting addresses the third.
Sia tip — Ask whether the attacker changed anything. If nothing changed, the attack is passive and almost always targets confidentiality.
Glossary

Key terms

Integrity
The security goal that received or stored data has not been modified by an unauthorised party.
Availability
The security goal that a system or service remains usable by legitimate users when they need it.
Vulnerability
A weakness in a system that a threat agent could exploit to cause loss or harm.
Traffic Analysis
A passive attack that learns who is communicating, how often and for how long, without reading message content.
Weakest Link Principle
The idea that a system is only as secure as its least protected component, which is where attackers concentrate.
FAQ

Security Goals, Threats and Attack Types FAQ

What are the four security goals in this unit?

Confidentiality, integrity, authentication and availability, abbreviated on the Week 1 slides as C, I, A and A. Each later week introduces tools aimed at one or more of them, so naming the goal is the first step in most scenario answers.

What is the difference between a threat and a vulnerability?

A threat is a set of circumstances that could cause harm, while a vulnerability is a specific weakness that might be exploited. The attack is the action that exploits the weakness, and a control is the measure that reduces it.

Why are passive attacks prevented rather than detected?

Passive attacks such as eavesdropping leave no trace in the data, so a defender usually cannot notice them. The practical response is prevention: making intercepted traffic useless to the attacker, typically through encryption or access control.

Is fabrication an attack on integrity or on authentication?

Sources in the unit differ. The Week 1 slides list fabrication under integrity, while the Workshop 1 solution calls it an attack on authenticity. A forged message damages both, so state which reading you use and justify it.

Which principle says security should be easy to use?

The effectiveness principle. It asks for mechanisms that are correct, efficient, easy to use and appropriate, and that do not cost more than the asset they protect, which balances security against cost and performance.

Study strategy

Assessment move

Build a single table for this chapter with the four goals as columns and fill in, for each one, the attacks against it, an everyday example, and the defensive approach that fits. Then practise classification on small invented incidents: for each step, decide whether the attacker changed anything, which goal suffered, and which weakness made it possible.

Learn the four terms threat, vulnerability, attack and control as a sequence you can apply to any story, because the sample in-class test asked students to categorise attacks and justify the choice. Finally, attach a real situation to each of the three principles so that you can explain them rather than recite them, and check whether an answer of yours names a principle without saying why it applies.

Working through Security Goals, Threats and Attack Types in FIT1093? Sia is AskSia’s AI Cybersecurity tutor — ask any FIT1093 Security Goals, Threats and Attack Types question and get a clear, step-by-step explanation grounded in how FIT1093 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.

A+Everything unlocked
Unlocks this Bible + all 111 of your Monash University subjects - and 1,000+ Bibles across every Australian university.
Sia - your FIT1093 tutor, unlimited, worked the way the exam marks it
The full 4-page Bible + practice bank with worked solutions
Chrome extension - sync your LMS so Sia knows your deadlines
Bilingual EN / Chinese on every Bible and every Sia answer
$0.99 Trial
30-day money-back · cancel in one tap · how it works
FIT1093 · Cybersecurity Tools and Techniques - independent study guide on the AskSia Library. More Monash University subjects · Microeconomics across all universities