← NotedeckAll engines · 网络安全

网络安全

12 engines
TLS handshake · the 1-RTT message flow of TLS 1.3
TLS 1.3 单往返 · ClientHello/ServerHello/Finished · ECDHE · vs 1.2
HMAC · inner/outer double hashing and the avalanche effect
H((K⊕opad)‖H((K⊕ipad)‖m)) · ipad/opad · 标签雪崩 · 验证
Digital signatures · sign with the private key, verify with the public key, detect tampering
sign=Enc_priv(hash) · verify=Dec_pub(sig)==hash · 篡改检测
Kerberos ticket flow · AS / TGS exchanges
AS→TGT+会话密钥 · TGS→服务票据 · 三方流 · 各 blob 密钥
Access-control matrix · matrix / ACL / capability views
主体×客体 r/w/x/own · ACL 列 vs 能力表行 · 同数据三视图
The CIA triad · attacks & controls mapped to pillars
机密性/完整性/可用性 · 攻击↔支柱 · 控制映射
Buffer overflow · stack-smashing concept
栈帧[缓冲区|保存FP|返回地址] · 越界覆盖RIP · 金丝雀缓解
SQL injection · concatenation vs parameterized query
WHERE name='<输入>' · ' OR '1'='1 恒真 · 参数化绑定中和
Reflected XSS · innerHTML vs escaped text
innerHTML 执行 vs textContent 转义 · 模拟是否会执行 · 结构解析
Symmetric vs asymmetric encryption
共享密钥 vs 公私钥对 · 玩具密码往返 · 密钥分发问题
Password entropy
H=L·log2(N) 位 · 字符集/长度 · 破解时间 · 长度胜复杂度
Hash avalanche effect
翻一位输入约翻一半输出位 · 确定性混合哈希 · 汉明距离