Security & Privacy Topics
109 topics
- Security & Privacy
Physically Unclonable Function (PUF)
A hardware security primitive that extracts a semiconductor fabrication process variation as a "fingerprint" to regenerate a chip-unique Response for each Challenge, deriving the key from physical characteristics when needed rather than storing it, thereby blocking cloning and theft. Covers SRAM·Arbiter·RO implementation types and weak/strong PUFs, the fuzzy extractor·helper data that correct noise, CRP-based authentication, the uniqueness·reliability·uniformity quality metrics, modeling·side-channel attacks and defenses, complementarity with TPM·HSM, and the ISO/IEC 20897 standard with its link to PQC·Zero Trust, in essay form.
- Security & Privacy
Steganography
An information-hiding technique that conceals not the content but the very fact that "communication is taking place" by embedding a secret message in an ordinary cover medium — distinguishing it from encryption and watermarking, covering spatial-domain (LSB·BPCS) and transform-domain (DCT·DWT·spread-spectrum) techniques, the triangular trade-off of imperceptibility·capacity·robustness, the Prisoners' Problem adversary model and the stego key, chi-square·RS·deep-learning steganalysis, stegware·exfiltration cases and CDR multilayer defense, and the spear-and-shield co-evolution of the generative-AI era, in essay form.
- Security & Privacy
HSM (Hardware Security Module)
A tamper-resistant dedicated device that performs the entire key lifecycle — generation, use, destruction — and crypto operations only inside a protected hardware boundary, blocking plaintext key exposure and serving, with FIPS 140 certification, as the foundation of PKI, finance, cloud (BYOK/HYOK), and the PQC transition.
- Security & Privacy
SAML 2.0-Based Single Sign-On (SSO) and Identity Federation
A mature enterprise authentication standard that realizes cross-domain web SSO and identity federation by having the browser relay an IdP-signed XML Assertion to the SP — covering the four axes of Assertion/Protocol/Binding/Profile, the SP/IdP role split and metadata-based pre-established trust, the SP-Initiated SSO flow with signature/Audience/validity-time verification, comparison with OIDC and Kerberos, implementation vulnerabilities such as XML Signature Wrapping, and integration with zero trust and SCIM, organized in depth from a professional-engineer perspective.
- Security & Privacy
TLS (Transport Layer Security) and the TLS 1.3 Handshake
A cryptographic protocol that provides confidentiality, integrity, and authentication over a reliable transport such as TCP, and the de facto standard of Internet security — covering the layered Record/Handshake structure, the (EC)DHE·HKDF·AEAD-based TLS 1.3 1-RTT handshake and certificate verification, the PSK-resumption/0-RTT replay trade-off, comparison with TLS 1.2, attacks such as downgrade and Heartbleed, latest trends including hybrid PQC·ECH·JA3 fingerprinting, and the certificate lifecycle, decryption visibility, and quantum-transition roadmap, organized in depth from a professional-engineer perspective.
- Security & Privacy
Intrusion Detection and Prevention Systems (IDS/IPS)
A defense-in-depth layer monitoring attacks inside permitted traffic that firewalls cannot see, through a sensor->analysis->response pipeline — misuse (signature) and anomaly (behavior) detection, NIDS/HIDS, passive (IDS) vs in-line (IPS) deployment, false-positive/negative balance, and evolution into NGIPS, XDR, and UEBA.
- Security & Privacy
CVSS (Common Vulnerability Scoring System)
An open vulnerability severity assessment system maintained by FIRST — deriving a 0.0–10.0 score from Base, Threat, and Environmental metrics, complemented by risk-based prioritization combining EPSS and KEV.
- Security & Privacy
Information Security Policy, Security Activities, and Experts
The concept of information security policy (policy → guidelines → procedures), security activities by phase (deterrence, prevention, detection, response, recovery), and the roles and competencies of security experts.
- Security & Privacy
MyData Transfer Security (Sept. 2023 Guideline)
Safe-handling requirements for MyData transfers, including designating a Chief Privacy Officer (CPO), access management of processing systems, and personal data management and disaster preparedness.
- Security & Privacy
Privacy-Enhancing Technologies (PET)
A family of technologies that achieve data utilization and privacy at the same time — pseudonymization/anonymization, differential privacy, homomorphic encryption, ZKP, MPC, and federated learning.
- Security & Privacy
Symmetric and Asymmetric Encryption
Comparison of symmetric encryption with a shared secret key (fast, key-distribution challenge) and asymmetric encryption with public/private keys (key distribution, digital signatures, slow), plus the hybrid digital envelope.
- Security & Privacy
Quantitative Cyber Risk Analysis Based on FAIR
An essay-style guide to FAIR, which decomposes information-security risk into loss event frequency (LEF) and loss magnitude (LM), then models economic loss distributions including uncertainty. Covers TEF, vulnerability, primary and secondary loss, the O-RA process and Monte Carlo modeling, connections with qualitative matrices and NIST SP 800-30, a hypothetical calculation, industry cases, control cost-benefit, the O-RA 2.1/O-RT 3.1 update, and professional-engineer considerations for data quality and governance.
- Security & Privacy
Generative AI Security Guidelines
A deep-dive guide that layer-controls generative AI threats—data leakage, prompt injection, data poisoning, hallucination, misuse, and model theft—across input (DLP), model (isolation/verification), output (filter/evidence/watermarking), and governance, linked with standards and regulations such as OWASP, NIST, and the EU AI Act.
- Security & Privacy
Managing Financial Digital Operational Resilience under EU DORA
An essay-style treatment of Regulation (EU) 2022/2554 centered on business services: ICT risk management, incident classification and reporting, resilience testing and TLPT, third-party contracts and registers, and CTPP oversight. Covers the implementation architecture, comparison with ISO 27001 and BCP/DR, cloud-outage, subcontracting, and backup-recovery scenarios, and professional-engineer considerations on proportionality, concentration risk, and management accountability.
- Security & Privacy
DRM (Digital Rights Management)
An essay-style treatment of DRM as a copyright-protection framework that encrypts content and issues and binds usage rights (licenses) separately to enforce policy at each moment of consumption. Covers the content-key separation principle; packaging, license, and client layers; the license-acquisition sequence; MPEG-CENC, EME, and multi-DRM (Widevine, PlayReady, FairPlay); forensic watermarking and the analog hole; hardware DRM and HDCP; the extension to C2PA content authenticity; and balancing user experience, interoperability, and law.
- Security & Privacy
Secure Product Design and Vulnerability Response under the EU Cyber Resilience Act (CRA)
An essay-style guide to the product-lifecycle security duties in the EU Cyber Resilience Act (Regulation (EU) 2024/2847). Covers scope and exemptions; manufacturer, importer, and open-source steward roles; risk assessment, essential requirements, SBOM, support periods, and updates; 24/72-hour vulnerability and incident reporting applicable from 2026; class-based conformity assessment; and the 2027 general application date. Includes connected-camera, smart-meter, and open-source supply-chain cases, comparison with NIS2 and GDPR, and professional-engineer considerations.
- Security & Privacy
SBOM (Software Bill of Materials)
Approaches to using SBOM, a software component inventory, to make open-source vulnerability and license risks visible and manage them via SCA and CVE mapping.
- Security & Privacy
CASB (Cloud Access Security Broker)
A security control layer that enforces the four functions of visibility, compliance, data security, and threat protection via API/proxy modes at the brokering point between users and cloud services—blocking Shadow IT and SaaS data leaks while integrating and evolving into a core pillar of SSE/SASE.
- Security & Privacy
Data Safe Zone
A designated, controlled environment for analyzing and using sensitive data without leakage — its definition, functions, and designation requirements.
- Security & Privacy
Homomorphic Encryption
A cryptographic technology that enables computation on ciphertext without decryption — the PHE, SWHE, and FHE types and their working principles and applications.
- Security & Privacy
Kubernetes Workload Protection with Confidential Containers(CoCo)
An essay-style treatment of Confidential Containers(CoCo), which runs Kubernetes Pods inside hardware-backed TEEs: the Pod-centric trust boundary, Kata Containers, remote attestation, Trustee/KBS, encrypted images, conditional key release, local Pod VM and Peer Pods deployment choices, finance, manufacturing, and multi-tenant cases, and Professional Engineer considerations for the TCB, supply chain, performance, and regulation.
- Security & Privacy
Digital Envelope Creation and Opening Procedures
The creation and opening procedures of a hybrid technique that symmetrically encrypts plaintext with a session key and sends it together with the session key encrypted using the recipient's public key.
- Security & Privacy
Container Security Based on Kubernetes Pod Security Standards and Pod Security Admission
An essay-style treatment of the container security strategy that standardizes Kubernetes Pod permissions and isolation as Privileged, Baseline, and Restricted profiles and gradually applies them through Pod Security Admission enforce, audit, and warn modes with Namespace labels, version pinning, and exemptions; PSS controls, supply-chain and runtime security integration, and finance and manufacturing-edge cases.
- Security & Privacy
AI Security Threats: Adversarial Attacks and Generative AI Vulnerabilities
Four machine learning adversarial attacks (poisoning, evasion, inversion, extraction) and their defenses, plus security vulnerabilities of generative LLMs and countermeasures.
- Security & Privacy
Email Authentication Framework (SPF, DKIM, DMARC)
An essay-style treatment of how SPF (sending IP authorization), DKIM (digital-signature integrity), and DMARC (header From alignment, policy, and reporting) compensate for SMTP's lack of sender verification: their principles and complementary relationship, detailed mechanisms such as canonicalization, alignment, and ARC, a phased adoption strategy from p=none to reject, the latest trends including 2024 mandatory authentication for bulk senders and BIMI, common misconfigurations, and operational implications from a Professional Engineer's perspective.
- Security & Privacy
VEX-Based SBOM Vulnerability Impact Analysis and Software Supply Chain Response
An essay-style treatment of VEX, which applies vulnerability candidates found via the SBOM to the product, version, and execution context and conveys them as NOT AFFECTED, AFFECTED, FIXED, or UNDER INVESTIGATION statuses with justification: its data model, minimum elements, and interoperability across OpenVEX, CycloneDX, SPDX, and CSAF; automation pipelines; supplier/consumer responsibilities; application in SaaS, finance, and embedded systems; and risk-based operating strategies from a Professional Engineer's perspective.
- Security & Privacy
East-West Traffic Control and Zero Trust Implementation Based on Microsegmentation
A zero trust implementation means that divides east-west traffic among assets, workloads, and services into small logical boundaries based on business flows and identity, and enforces default-deny, least privilege, and continuous verification to reduce lateral movement and the blast radius after a breach.
- Security & Privacy
The Purdue Model for Industrial Control Systems (ICS)
A reference architecture that divides ICS into levels from the physical process (L0) to enterprise IT (L5). It blocks threat propagation by isolating domains with an IT/OT DMZ and is combined with IEC 62443 and zero trust.
- Security & Privacy
SPIFFE/SPIRE-Based Workload Identity and Secretless Service Authentication
A standard and operational framework that automatically issues SPIFFE IDs and short-lived SVIDs to dynamic services through node and workload attestation, and implements service authentication and least privilege without long-lived secrets via the Workload API, mTLS, and trust-domain federation.
- Security & Privacy
Zero Trust Security Model
Zero Trust discards perimeter-based trust and continuously verifies all access based on identity and context. Covers the four principles (explicit verification, least privilege, assume breach, micro-segmentation), the NIST SP 800-207 (PDP/PEP) architecture, and phased adoption based on a maturity model.
- Security & Privacy
Access Control Security Models (BLP, Biba, Clark-Wilson)
A comparison of BLP for confidentiality (No Read-Up, No Write-Down), Biba for integrity (No Write-Up, No Read-Down), and Clark-Wilson for commercial integrity (transactions, separation of duties) as symmetries in the direction of threat.
- Security & Privacy
ISMS and ISMS-P
The differences between the information security management system ISMS and ISMS-P, which adds personal data protection, and the criteria for ISMS mandatory subjects.
- Security & Privacy
Amendment to the Personal Information Protection Act (2023)
The 2023 amended Personal Information Protection Act: unified regulation, the right to data portability (the basis for MyData), the right to refuse and demand explanation of automated decisions, and stronger fines based on total revenue, plus data-processing actors and flows, a GDPR comparison, and corporate response strategies.
- Security & Privacy
Block Cipher Algorithms
Block ciphers (AES, DES) that repeatedly apply confusion and diffusion to plaintext in fixed block units, and operation modes ECB, CBC, CTR, and GCM.
- Security & Privacy
Digital Forensics
The forensic science of collecting, analyzing, and preserving digital evidence while maintaining integrity and chain of custody — its concept, types, procedures, techniques, and applications.
- Security & Privacy
Generative AI Red Teaming and Adversarial Security Testing
A continuous security-testing strategy that verifies generative AI models and applications from an attacker's perspective and links vulnerabilities in the model, implementation, infrastructure, and operational behavior to risk management and remediation.
- Security & Privacy
Cybersecurity Risk Management Based on the NIST Cybersecurity Framework 2.0
An essay-style overview of NIST CSF 2.0 — its six functions (GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER), the Core, Organizational Profile, and Implementation Tier structure, current-versus-target-state gap analysis, and cloud, AI, and supply-chain application strategy.
- Security & Privacy
AI Personal Data Protection Self-Assessment Checklist
A voluntary code by which operators self-check that they process personal data lawfully and safely across the entire AI lifecycle. The principles of lawfulness, safety, transparency, and rights protection.
- Security & Privacy
Standards for Safety Assurance Measures for Personal Data
Administrative, technical, and physical measures under the Personal Information Protection Act notification—covering the establishment of an internal management plan and methods for applying encryption.
- Security & Privacy
Personal Data De-identification and Privacy Protection Models (k-anonymity, l-diversity, t-closeness)
A privacy protection model and lifecycle governance that de-identifies identifiers, quasi-identifiers, and sensitive information through pseudonymization and generalization, then quantitatively verifies re-identification risk using k-anonymity (group size), l-diversity (value variety), and t-closeness (value distribution).
- Security & Privacy
Privileged Access Management (PAM)
An essay-style overview of PAM, a security control framework that identifies, vaults, least-privileges, monitors, and revokes privileged accounts and sessions — account types (human, non-human, emergency), vaulting, password rotation, session management (PSM), PEDM, JIT/ZSP, and audit (UEBA) functions and architecture, a comparison with IAM and IGA, and cloud/DevOps extension and adoption strategy.
- Security & Privacy
White-box Cryptography
An essay-style overview of a software key-protection technique that fuses and hides keys within the algorithm using lookup tables and encoding, even under a white-box model where the attacker fully controls the execution environment — black/grey/white-box attack models, the implementation principles of key fusion, encoding, and masking, DRM and HCE payment applications, DCA and DFA attacks, and the trade-offs versus a TEE and layered defense.
- Security & Privacy
Security Threats to Drones and Countermeasures
Drone threats such as GPS spoofing, communication hijacking, and firmware tampering, and countermeasures spanning communication, GPS, and firmware security, anti-drone, and regulation.
- Security & Privacy
Mirai Botnet
A botnet that mass-infected IoT devices left with default Telnet passwords via dictionary attacks and abused them for large-scale DDoS. The infection chain, security across the lifecycle, the 7 common security principles, and the variants and regulatory trends after the source code was released.
- Security & Privacy
Policy as Code and Executable Governance
An executable-governance approach that version-controls security, compliance, and operational rules as declarative code and enforces them repeatedly across CI/CD, IaC, APIs, and Kubernetes runtime via PDP/PEP.
- Security & Privacy
Secrets Management
A system that separates credentials such as passwords, API keys, certificates, and encryption keys from code and centrally stores, issues, rotates, revokes, and audits them, shifting static secrets to dynamic, short-lived secrets and infrastructure-identity-based authentication to minimize the blast radius upon leakage.
- Security & Privacy
Network Access Authentication Based on EAP-TLS (Extensible Authentication Protocol-Transport Layer Security)
The principles, procedure, comparison, and operational strategy of a method that mutually authenticates the client and authentication server with X.509 certificates and the TLS handshake, and controls network access by combining 802.1X/RADIUS policy with the PKI lifecycle.
- Security & Privacy
EMP Attack (ElectroMagnetic Pulse)
A threat that physically destroys electronic, power, and communication hardware with a powerful electromagnetic pulse. The E1/E2/E3 components of a high-altitude nuclear HEMP, layered defense through shielding, grounding, and filtering, and resilience strategies with isolated spares and redundancy.
- Security & Privacy
Identification and Authentication
The difference between identification, which claims an identity, and authentication, which verifies its authenticity (identification → authentication → authorization → audit); security requirements; the four authentication factors of knowledge, possession, biometrics, and behavior; and MFA, passkeys (FIDO2), and adaptive authentication.
- Security & Privacy
JWT (JSON Web Token)
A stateless token that carries and signs authentication information. The Header, Payload, and Signature structure, its fit for MSA and API authentication, and mitigations for payload exposure and revocation limits.
- Security & Privacy
Credential Stuffing
An attack that automatically injects leaked accounts to exploit password reuse—hard to detect as it resembles legitimate logins, with multi-layered defenses of MFA, passkeys, bot management, and risk-based authentication (RBA) as the key.
- Security & Privacy
File Carving
Recovering files from raw data by their signatures and structure without file-system metadata. The four techniques (header/footer, structure, content, defragmentation) and handling of integrity and SSD TRIM.
- Security & Privacy
Kerberos Authentication Protocol
An intranet authentication protocol that achieves mutual authentication and SSO without exposing passwords via a KDC (AS/TGS), symmetric keys, tickets (TGT), and timestamps — covering the 3-phase, 6-message procedure, cross-realm and delegation, Golden/Silver Ticket and Kerberoasting attacks and defenses, and hybrid SSO integration.
- Security & Privacy
Merkle Tree and Data Integrity Verification
A structure that hierarchically hashes data blocks, summarizes them into a single root hash, and verifies inclusion and integrity with an O(log n) Merkle path without transmitting the entire original — covering the construction and verification of a binary Merkle tree, odd-node handling, protocol-specific variants, application in blockchain, Git, and Certificate Transparency, and operational considerations.
- Security & Privacy
Post-Quantum Cryptography (PQC)
Quantum-resistant public-key cryptography based on lattices, hashes, and codes that remains hard even for quantum computers (Shor's algorithm). The urgency of migration seen through Harvest-Now-Decrypt-Later (HNDL) and Mosca's inequality, the NIST standards (ML-KEM, ML-DSA, SLH-DSA), and hybrid mode and crypto-agility.
- Security & Privacy
Smart Contract Security and Audit Strategy
Based on the deterministic execution, asset custody, immutability, and gas constraints of smart contracts, models trust boundaries from the wallet through oracles and bridges, and organizes the causes and countermeasures for reentrancy, authorization, oracle, arithmetic, signature, and upgrade vulnerabilities, along with the test/audit/deploy/monitor lifecycle.
- Security & Privacy
SOAR (Security Orchestration, Automation, and Response)
SOAR, which integrates security operations into orchestration, automation, and response: reducing response time (MTTR) through playbook automation, complementing SIEM (detection), and evolving into an AI-integrated autonomous SOC.
- Security & Privacy
CNAPP (Cloud-Native Application Protection Platform)
A cloud-native integrated security platform that consolidates and correlates fragmented cloud security functions such as CSPM, CWPP, CIEM, KSPM, and DSPM, and prioritizes risk around genuinely exploitable attack paths from code to runtime.
- Security & Privacy
Metaverse Security Threats and Social Issues
Threats arising from immersion, avatars, and the virtual economy such as biometric leakage, account/asset theft, and impersonation, alongside identity confusion, virtual violence, and addiction, with technical, institutional, and ethical measures.
- Security & Privacy
API Security Design and Operation Based on OWASP API Security Top 10 (2023)
Analyzes the top 10 risks of OWASP API Security Top 10 (2023) from the perspectives of object-, property-, and function-level authorization and resource and business-flow control, and organizes design/operational responses at the gateway, service, and data layers.
- Security & Privacy
OWASP Top 10 (Web Application Security Risks)
The awareness standard for the top 10 web application security risks, selected from real vulnerability data (CVE) and expert surveys — providing an in-depth treatment of the 2025 revision's per-item principles (A01 Access Control through A10 Improper Exception Handling), changes from 2021 (rise of supply-chain failures and misconfiguration, SSRF consolidation), Shift-Left embedding in the SDLC/DevSecOps, and alignment with ASVS, SAMM, and the API/LLM Top 10.
- Security & Privacy
Web Server Security — Reverse Proxy and DDoS Cyber Shelter
The reverse proxy that protects the front end of a web server (concealment, load balancing, SSL, WAF) and the cyber shelter for responding to large-scale DDoS (rerouting, scrubbing), with CDN-integrated multi-layered defense.
- Security & Privacy
RSA vs. DSA
Comparing factorization-based, general-purpose RSA (encryption and signing) with discrete-logarithm-based, signing-only DSA. Signature generation/verification speed, and the evolution to ECDSA and PQC.
- Security & Privacy
Network Scanning
Active probing of hosts, ports, services, and vulnerabilities, serving both as attack reconnaissance and defensive assessment. SYN, FIN, UDP and other techniques that abuse the 3-way handshake, with attack-surface minimization and IDS/IPS and SIEM/SOAR integration.
- Security & Privacy
Quantum Cryptography
The methods, technologies, and vulnerabilities of quantum cryptography (QKD), which detects eavesdropping and distributes keys using the quantum-mechanical principles of measurement disturbance and no-cloning.
- Security & Privacy
Ransomware and RaaS
Ransomware, which encrypts and steals data to demand a ransom, and RaaS, an as-a-service model with a division of labor among developers, affiliates, and IABs. Responding to the evolution into double and triple extortion with immutable backups (3-2-1), EDR/XDR, least privilege, and IR.
- Security & Privacy
Security Considerations When Adopting Cloud
Under the premise of the shared responsibility model, reviewing data encryption and key management, IAM/CIEM, configuration security (CSPM), network and visibility, regulation (CSAP) and sovereignty, continuity and exit, and supply chain (SBOM). Misconfiguration and account management are the greatest risks, integrated through CNAPP and zero trust.
- Security & Privacy
Common Criteria (CC / ISO/IEC 15408)
An international standard by which a third party evaluates and certifies the security functions (SFR) and assurance level (SAR/EAL) of security products through a standardized procedure — covering the PP/ST/TOE concepts, the evaluation/certification process, and trends including CCRA mutual recognition, cPP, and CC:2022.
- Security & Privacy
ZTNA (Zero Trust Network Access)
Organizes ZTNA, which distrusts network location and verifies user, device, context, and resource on a per-request basis to provide least-privilege, per-application access — covering its principles, PDP/PEP composition, comparison with VPN and SASE, adoption steps, and cloud-native extension.
- Security & Privacy
Characteristics and Security Vulnerabilities of NFT Marketplaces
The characteristics of NFTs (irreversibility, off-chain storage) and the security vulnerabilities of NFT marketplaces (phishing signature theft, contract flaws) and their countermeasures.
- Security & Privacy
Differential Privacy and the Privacy Budget
This essay covers the definition of differential privacy, which bounds the difference in output probability between adjacent datasets by ε and δ, along with sensitivity and the Laplace and Gaussian mechanisms, composition and privacy accounting, a comparison with de-identification, federated learning, and homomorphic encryption, and application strategies for public statistics, service analytics, and DP training.
- Security & Privacy
AI Software BOM (AI SBOM) and Artificial Intelligence Supply Chain Transparency
This essay covers, in a professional-engineer answer format, the concept, standards, and collection, verification, and operational strategy of an AI Software BOM that manages the composition and relationships of models, data, code, pipelines, infrastructure, and external services in a machine-readable form.
- Security & Privacy
CTEM (Continuous Threat Exposure Management)
This essay covers, in an answer format, the five-stage cycle of CTEM, which continuously discovers, prioritizes, validates, and remediates exposure spanning assets, misconfigurations, privileges, and attack surface from the attacker's perspective, along with its reference architecture, its differences from traditional vulnerability management and penetration testing, an adoption roadmap, and professional-engineer considerations.
- Security & Privacy
Threat Modeling
This essay covers, in an essay format, a Shift-Left security activity that structures the system with a DFD, exhaustively derives threats with STRIDE, prioritizes them with DREAD and CVSS, and proactively mitigates risk at the design stage.
- Security & Privacy
Blockchain Types (Public, Private, Hybrid)
Classifying blockchains by openness into public (open, decentralized), private (permissioned, controlled), consortium, and hybrid. Trade-offs from the perspective of consensus and the trilemma, with regulatory and interoperability considerations.
- Security & Privacy
The Three Data Acts and MyData
The amendment of the Three Data Acts, which introduced pseudonymized data and unified oversight to balance protection and utilization, and the concept of MyData based on the right to data portability and standardized APIs, including information provided by industry, cross-sector expansion, and promotion measures.
- Security & Privacy
Modification and Fabrication
Modification is the illegal alteration of an original (integrity violation), while fabrication is the false creation or impersonation of something that did not exist (integrity plus authentication violation); these are countered with hashes and MACs (modification detection) and digital signatures and PKI (fabrication prevention, authentication, non-repudiation), extending in the AI era to deepfakes and C2PA provenance proof.
- Security & Privacy
Tor vs. VPN
An anonymity network that hides identity through multi-node onion routing. Compared with the single-server trust of a VPN in terms of trust model, speed, and purpose.
- Security & Privacy
Message Authentication Code (MAC)
A symmetric-key technique that verifies integrity and origin authentication by generating a keyed authentication tag from a message and a shared secret key and comparing it upon recomputation. Covers HMAC/CMAC/GMAC types, the non-repudiation difference from digital signatures, and the evolution toward AEAD.
- Security & Privacy
PKI (Public Key Infrastructure)
This essay covers the components and certificate lifecycle of PKI, which binds a public key to an identity in an X.509 certificate via a CA's digital signature and makes it verifiable through a hierarchical chain of trust, revocation (CRL/OCSP), and repositories, along with a comparison of trust models, trends such as ACME automation, CT transparency, and the post-quantum (PQC) transition, and professional-engineer considerations.
- Security & Privacy
Post-Quantum Cryptography (PQC) and Cryptographic Transition Strategy
A strategy that counters Shor and HNDL threats by using ML-KEM, ML-DSA, and SLH-DSA and transitions PKI and the supply chain in stages through a cryptographic-asset inventory, risk prioritization, hybrid piloting, and crypto agility.
- Security & Privacy
File Slack
The space left over when a file does not fully fill a cluster. RAM and drive slack, where deleted data persists and is exploited as forensic evidence or for concealment.
- Security & Privacy
InfoStealer
Information-stealing malware that covertly exfiltrates sensitive data such as accounts, session cookies, and cryptocurrency wallets. Its attack procedure (kill chain) and the MaaS crime ecosystem, MFA bypass via session cookies, and a layered response of prevention, stronger authentication, EDR detection, and dark-web monitoring.
- Security & Privacy
Secure Coding and Software Development Security
Development-security activities that integrate security across all SDLC phases to proactively eliminate vulnerabilities at the design and implementation stages — an in-depth treatment covering secure-coding rules such as input validation and output encoding, the seven vulnerability categories, embedding threat modeling and SAST/DAST/IAST/SCA analysis into CI/CD, and extension to AI, supply chain, and DevSecOps.
- Security & Privacy
Fast-Track Verification Scheme for Information Security Products
A scheme that rapidly verifies the security of new-technology and converged security products whose adoption was blocked by the absence of evaluation criteria, thereby supporting their public-sector adoption.
- Security & Privacy
SLSA-Based Software Supply Chain Security and Build Integrity
This essay explains how to verify the integrity of the path by which software flows from source to distributed artifacts, centering on SLSA's Build and Source tracks and provenance. It describes the difference from an SBOM, attack scenarios, CI/CD implementation, and verification, policy, and operational considerations in a professional-engineer essay format.
- Security & Privacy
WAF (Web Application Firewall)
This essay covers the definition of a WAF and the background behind application-layer (L7) defense, the overall structure spanning normalization, detection, and decision along with deployment modes such as reverse proxy, transparent bridge, out-of-band, and cloud-based, the trade-offs among negative (signatures, OWASP CRS), positive (whitelist), and anomaly/bot-management detection models, defense against OWASP Top 10 threats such as SQLi and XSS along with the Log4Shell virtual-patching case, a comparison with IPS, RASP, and API gateways, evolution toward WAAP and cloud WAF, and professional-engineer considerations such as false-positive tuning, SSL decryption, SPOF, and regulatory compliance.
- Security & Privacy
Cyber Kill Chain
A defense-oriented, intelligence-driven framework that decomposes targeted cyberattacks into a seven-stage chain of reconnaissance, weaponization, delivery, exploitation, installation, command and control (C2), and actions on objectives, neutralizing a breach even when only a single stage is blocked. This essay covers the adversary behavior and defensive controls at each stage, layered-defense design through the Courses of Action matrix (detect, deny, disrupt, degrade, deceive) and gap analysis of defensive coverage, a comparison with MITRE ATT&CK, the Diamond Model, and the Unified Kill Chain along with strategies for combining them, structural limitations such as perimeter bias and linear assumptions and its evolution to address cloud and insider threats, integration with SIEM, SOAR, and XDR and its application to threat hunting, and professional-engineer considerations such as Zero Trust, blocking to the left, and campaign intelligence.
- Security & Privacy
Data Industry Act (Data Industry Promotion Act)
A framework act that promotes the data industry by facilitating the production, trading, and utilization of data. Covers data asset protection, valuation, and trade facilitation.
- Security & Privacy
XDR (eXtended Detection and Response)
A threat-response framework that collects, normalizes, and correlates telemetry from endpoints, network, email, cloud, and identity on a single platform, automatically reconstructing scattered alerts into a single attack story (incident) and unifying and automating detection, investigation, and response as one flow. This essay covers the overall architecture spanning sensors, core (data lake, correlation engine, ML/UEBA), and response, the operational flow of detect, triage, investigate, contain, and recover, the principles of ATT&CK-chain-based incident reconstruction, a comparison of Native versus Open (Hybrid) XDR and its boundaries with SIEM, SOAR, and EDR, recent trends such as generative-AI copilots, SASE/SSE extension, MDR as-a-service consumption, and OCSF standardization, and professional-engineer considerations including data quality, false-positive tuning, vendor lock-in, privacy, Zero Trust integration, and organizational maturity.
- Security & Privacy
DLP (Data Loss Prevention)
A data-centric security framework that identifies, monitors, and blocks sensitive and confidential data across its at-rest, in-motion, and in-use states using content inspection, preventing both intentional exfiltration and inadvertent exposure. This essay covers controls for the three data states (Network, Endpoint, and Storage DLP) and the overall architecture, detection techniques such as patterns, dictionaries, EDM/fingerprinting, and ML together with their combination and tuning, the operational flow of risk-based graduated responses (log, alert, encrypt, block), the relationship with adjacent technologies like DRM, CASB, and UEBA, the deployment process from classification and policy design through monitoring, enforcement, and continuous improvement, and professional-engineer considerations such as SASE/SSE extension for the cloud, remote-work, and generative-AI era and the trade-off between privacy and false positives.
- Security & Privacy
Non-Fungible Token (NFT)
The structure, standards (ERC-721/1155), and issuance/trading of NFTs, which use blockchain smart contracts to prove the uniqueness and ownership of digital and physical assets, along with RWA applications and challenges of off-chain persistence, copyright, speculation, and regulation.
- Security & Privacy
SIEM (Security Information and Event Management)
An integrated security-monitoring platform that collects, normalizes, and correlates heterogeneous logs and events from across the organization in real time to detect multi-stage threats and provide compliance evidence and a basis for incident investigation. An essay-style overview of the data pipeline from collection → normalization → storage → correlation → alerting and the principles of rule- and statistics-based (UEBA) detection, its relationship to and differences from log management, SOAR, and XDR, recent trends that overcome alert fatigue, cost, and detection-coverage limits through AI-SIEM, data lakes, cloud-native design, and XDR integration, and Professional-Engineer-level considerations such as collection-policy design, rule tuning, and combining analyst expertise.
- Security & Privacy
Decentralized Identity (DID)
A self-sovereign identity model that returns control of identity information from institutions to users—cryptographically verifying against forgery and tampering without excessive collection, through the issuer-holder-verifier trust triangle, VC/VP, and selective disclosure.
- Security & Privacy
MITRE ATT&CK (Cyber Attack Tactics and Techniques Knowledge Base)
An open knowledge base that systematizes attack behaviors observed in real-world breaches into tactics, techniques, and procedures (TTPs)—focusing on adversary behavior rather than IoCs and serving as a common language for detection-gap analysis, threat hunting, and adversary emulation.
- Security & Privacy
Zero-Knowledge Proof (ZKP)
A cryptographic protocol that proves knowledge of a secret, or the truth of a statement, without revealing the secret. Satisfying completeness, soundness, and zero-knowledge, it is implemented in interactive/non-interactive (Fiat-Shamir) forms and via zk-SNARK and zk-STARK, emerging as the core of zk-Rollup blockchain scaling and privacy-preserving identity proof (selective disclosure).
- Security & Privacy
DevSecOps
An integrated development-security-operations methodology that embeds security across the entire SDLC through automation (Security as Code) and shifts it left, achieving fast deployment and safety at the same time—covering SAST, DAST, IAST, SCA, and pipeline gates.
- Security & Privacy
Confidential Computing
A hardware-isolated data-protection paradigm that uses a CPU hardware-based trusted execution environment (TEE) and remote attestation to protect data even while it is 'in use' during computation, excluding even the hypervisor and cloud operator from the trust boundary.
- Security & Privacy
Passkeys and FIDO2/WebAuthn
Passwordless authentication based on FIDO2 (WebAuthn + CTAP) that keeps the private key in the device's secure enclave and logs in with domain-bound public-key signatures, fundamentally blocking phishing, credential stuffing, and server breaches. By eliminating shared secrets and preventing phishing through origin binding, the choice between synced and device-bound types and the design of the account-recovery path govern the security–convenience trade-off.
- Security & Privacy
OAuth 2.0 and OpenID Connect (OIDC)
OAuth 2.0 is an authorization framework that delegates limited permissions without exposing passwords; OIDC is an authentication layer atop it that proves identity with a signed ID token, including the latest security-hardening standards such as PKCE, FAPI, and OAuth 2.1.
- Security & Privacy
Access Control
Controlling a subject's access to objects through identification/authentication → authorization → auditing — DAC, MAC, RBAC, and ABAC policies, and ACL, capability, and reference-monitor implementations.
- Security & Privacy
Anti-Forensics and Countermeasures
Techniques that hide, destroy, or tamper with evidence to obstruct forensics, and compliance countermeasures based on logging, evidence collection, integrity preservation (chain of custody), and monitoring.
- Security & Privacy
APEC CBPR (Cross-Border Privacy Rules)
APEC's certification system for cross-border transfers of personal data — the nine APEC Privacy Principles and the key CBPR certification requirements.
- Security & Privacy
FIPS 140-2 (Security Requirements for Cryptographic Modules)
The standard for cryptographic module security requirements — the Level 1–4 classification and considerations for cryptosystem design, security elements, and threat-response strategies.
- Security & Privacy
ISA/IEC 62443 (Industrial Control System Security)
An international security standard for industrial control systems (OT) — the four tiers of General, Policy, System, and Component, plus Zone/Conduit, Security Levels, and the seven foundational requirements.
- Security & Privacy
Multi-Party Computation (MPC)
A technique that lets multiple parties jointly compute only the result while keeping their inputs private — types such as secret sharing and garbled circuits, and use in distributed authentication.
- Security & Privacy
PbD (Privacy by Design)
A methodology that embeds privacy proactively and by default from the design stage — its 7 foundational principles and 8 strategies, compared with Article 3 of Korea's Personal Information Protection Act.
- Security & Privacy
Qshing (QR Phishing)
Phishing that lures victims to malicious sites or apps via QR codes to steal information — attack flow and techniques, with URL verification and QR integrity countermeasures.
- Security & Privacy
TPM (Trusted Platform Module)
A hardware security chip that performs key storage, integrity measurement (PCR), sealing, and remote attestation — the root of trust for secure boot, disk encryption, and device authentication.