802.1x *** The IEEE standard that defines port-based security for wireless network access
control.
Acceptable Use Policy (AUP)/Rules of behavior *** Agreed-upon principles set forth by a
company to govern how the employees of that company may use the resources such as
computers and internet access.
Access Control List (ACL) *** A table or data file that specifies whether a user or group has
access to a specific resource on a computer or network.
ACL *** Access Control List
AUP *** Acceptable Use Policy
Access point (AP) *** The point at which access to a network is accomplished. This term is
often used in relation to a wireless access point.
AP *** Access Point
Active response *** A response generated in real time.
Address Resolution Protocol (ARP) *** Protocol used to map known IP addresses to unknown
physical addresses.
ARP *** Address Resolution Protocol
,Address Resolution Protocol (ARP) Poisoning *** an attack that convinces the network that
the attacker's MAC address is the one associated with an allowed address so that traffic is
wrongly sent to the attacker's machine
Administrative Control *** a control implemented through administrative policies or
procedures
Advanced Persistent Threat (APT) *** a sophisticated, possibly long-running computer hack
that is perpetrated by large, well-funded organizations such as governments
APT *** Advanced Persistent Threat
Adware *** software that gathers information to pass on to marketers or that intercepts
personal data such as credit card numbers and makes them available to third parties
Agile Development *** A method of software development meant to be rapid.
Alarm *** a notification that an unusual condition exists an should be investigated
alert *** an indication that an unusual condition could exist and should be investigated
all-in-one appliance *** an appliance that performs multiple functions
analyzer *** The component or process that analyzes the data collected by the sensor.
Annual Loss Expectancy (ALE) *** A calculation used to identify risks and calculate the
expected loss each year.
ALE *** Annual Loss Expectancy
, Annualized Rate of Occurrence (ARO) *** A calculation of how often a threat will occur. For
example, a threat that occurs once every five years has an annualized rate of occurrence of 1/5,
or 0.2.
ARO *** Annualized Rate of Occurrence
Anomaly Detection IDS (AD-IDS) *** An anomaly-detection intrusion detection system
works by looking for deviations from a pattern of normal network traffic.
AD-IDS *** Anomaly Detection IDS
IDS *** Intrusion Detection System
antivirus software *** Software that identifies the presence of a virus and is capable of
removing or quarantining the virus.
appliance *** a freestanding device that operates in a largely self-contained manner
application-level proxy *** a device or software that recognizes application-specific
commands and offers granular control over them
armored virus *** a virus that is protected in a way that makes disassembling it difficult - it is
'armored' against antivirus programs trying to understand or analyze its code
ARP spoofing *** More commonly known as ARP poisoning, this involves the MAC (Media
Access Control) address of the data being faked.
Asset Value (AV) *** The assessed value of an item (server, property, and so on) associated
with cash flow.