Skip to content

Cyberattack

Conduct a deliberate hostile action through or against digital systems to gain unauthorized access, steal or manipulate information, disrupt availability, or maliciously control computing resources.

Version
v2 · 2026-09-06 · History
Domain-specific #
1608
Origin domain
computer science
Subdomain
cybersecurity
Aliases
Cyber attack, Computer attack, Computer network attack

Core Idea

A cyberattack is a deliberate hostile attempt conducted through or against digital systems, networks, software, services, identities, or data. Its objectives include unauthorized access, collection, disclosure, manipulation, destruction, denial, degradation, or malicious control. The NIST glossary captures both the broad malicious-activity sense and the narrower “via cyberspace” sense directed at an enterprise's computing environment or information.

An attack is an action or campaign, not merely a possibility. It may fail and still be an attack. When it succeeds or imminently jeopardizes protected information or systems, it may become a security incident under the applicable operational or legal definition.

Scope of Application

The abstraction covers credential attacks, exploitation of software flaws, malware delivery, ransomware, distributed denial of service, destructive wipers, data theft, supply-chain compromise, and adversarial manipulation of digital processes. NIST risk assessment separates threat sources, threat events, vulnerabilities, likelihood, and impact, preventing the attack action from absorbing the entire risk model.

Clarity

Name the adversary, target, objective, access vector, technique, exploited condition, attempted effect, observed evidence, and success criteria. Distinguish a single action from a multi-stage campaign. State whether social engineering counts only when it drives a cyber-mediated effect. Do not infer attribution or success solely from an alert.

Manages Complexity

Cyberattack organizes heterogeneous technical events into an adversarial path. Analysts can map initial access, execution, persistence, privilege, movement, collection, command, and impact without treating every log line as an independent incident. The path model also exposes control opportunities before, during, and after compromise.

Abstract Reasoning

  1. Declare the protected system and security properties.
  2. Identify plausible adversarial principals and objectives.
  3. Reconstruct the action sequence from evidence and dependencies.
  4. Separate access path, exploited condition, technique, and payload.
  5. Determine which steps were attempted and which succeeded.
  6. Trace effects on confidentiality, integrity, availability, authenticity, and control.
  7. Bound the campaign in time, identity, infrastructure, and objective.
  8. Map preventive, detective, containment, recovery, and attribution controls.
  9. Preserve uncertainty and alternative hypotheses.

Knowledge Transfer

The portable pattern is an intentional hazard follows a constructed path through reachable interfaces and dependencies to change a protected state; analyze the path stepwise and keep possibility, attempt, success, and consequence distinct. The proposed immediate parent is Exposure Pathway.

Relationships to Other Abstractions

Local relationship map for CyberattackParents appear above the current abstraction, mutual partners to the right, and children below. Node labels state whether each abstraction is prime or domain-specific; colors identify relation types.CyberattackDOMAINPrime abstraction: Exposure Pathway — is a kind ofExposure PathwayPRIME

Current abstraction Cyberattack Domain-specific

Parents (1) — more general patterns this builds on

  • Cyberattack is a kind of Exposure Pathway Prime

    Exposure Pathway is the proposed immediate parent.

Hierarchy paths (3) — routes to 3 parentless roots

Neighborhood in Abstraction Space

Cyberattack sits in a sparse region of the domain-specific corpus (98th percentile for distinctiveness): few abstractions share its structure, so a faithful description tends to retrieve it precisely.

Family — Unclustered & Miscellaneous (1565 abstractions)

Nearest neighbors

Computed from structural-signature embeddings · 2026-09-08