Outline for October 11, 2006
Reading
: §23.1–23.2
Greetings and felicitations!
Puzzle of the day
System Analysis
Learn everything you can about the system
Learn everything you can about operational procedures
Compare to other systems
Hypothesis Generation
Study the system, look for inconsistencies in interfaces
Compare to other systems' flaws
Compare to vulnerabilities models
Hypothesis testing
Look at system code, see if it would work (live experiment may be unneeded)
If live experiment needed, observe usual protocols
Generalization
See if other programs, interfaces, or subjects/objects suffer from the same problem
See if this suggests a more generic type of flaw
Elimination
Examples
MTS terminal system
Burroughs system
You can also obtain a PDF version of this.
Version of October 10, 2006 at 8:05 PM