Skip to content

Network Security Vulnerabilities & Trust

← Back to Domain-Specific Families

Abstractions about how networked systems establish trust and where it fails — web and API vulnerabilities (cross-site scripting, mass assignment, server-side request forgery), identity and verification mechanisms (federated identity, message authentication codes, proof-carrying code, zero trust), and network communication and architecture (protocols, link-state routing, peer-to-peer systems).

26 abstractions in this family — domain-specific abstractions that sit near one another in structural-signature space (k-means over structural-signature embeddings). Each is shown with its short description.

  • Access URL — Reach a resource through a published, dereferenceable handle that names a route rather than the bytes — so location, storage, and hosting stay hidden behind a routing layer and identity can outlive the link.
  • Authentication Failure — The breakdown of a system's identity-verification, in which a claim is accepted when it should not be — because the procedure checked too little, the wrong evidence, or evidence an impostor could produce — yielding a session that inherits the real actor's privileges and corrupts every control conditioned on 'who is this?'
  • Block Storage over a Network — Present remote storage to a host as a block device by carrying block I/O requests, data, and completion status across a network.
  • Cross-Site Scripting — Insert attacker-supplied bytes into a server's output so the victim's browser executes them under the trusted site's origin, arising when content is written into a sink without encoding for the context it lands in.
  • Digital Watermarking — Embedding an identifiable signal in controlled features of a digital artifact so a specified detector can later test for that signal under stated conditions.
  • Excessive Data Exposure — An API endpoint returns more fields than the caller's role requires, trusting a client-side filter to hide the surplus — but the unfiltered payload is already on the wire, so the surplus must be stripped at the producer via role-scoped projection.
  • Fallacy of the Secure Network — The mistake of deriving trust in a distributed system from network position — inside the VPN, behind the firewall — rather than from cryptographic verification, treating a known routing path as if it were a verified identity.
  • Federated Identity — Let a service recognize a subject through an identity-provider assertion accepted under governed trust.
  • Instant messaging — Synchronous or near-real-time networked communication in which identified users exchange text and often presence, multimedia, files, voice, or video through persistent applications or services.
  • Internet Blocking — An Internet intervention that prevents a selected user, endpoint, route, protocol, domain, or content object from reaching or acting on a network resource within a declared scope and duration.
  • Link-state Routing — Distribute local connectivity state so network nodes can calculate routes from a topology view.
  • Mass Assignment — The web-application vulnerability in which a request-binding layer writes all client-supplied fields directly to a domain object with no allow-list, letting a caller set server-managed attributes like role or owner_id simply by naming them.
  • Message Authentication Code — A secret-key-dependent tag and verification test that binds a specified message to a key-holding group for integrity and origin assurance, without itself supplying secrecy or freshness.
  • Network Protocol — A shared specification of roles, messages, states, timing, error handling, and semantic effects governing interoperable communication among networked participants.
  • Page Fault — A memory-access exception that lets the operating system resolve an absent or disallowed virtual-memory mapping.
  • Peer-to-Peer Architecture — A peer-to-peer architecture lets participating endpoints supply service data or work to one another instead of relying solely on a dedicated server.
  • Pooling Equilibrium — Sustain a signaling-game equilibrium in which every hidden sender type chooses the same on-path action and the receiver's posterior remains its prior.
  • Proof-Carrying Code — A code-admission method in which an untrusted producer supplies executable code with a formal proof that the consumer checks against its policy for that received code.
  • Rate-Limit Absence — Diagnose a whole family of endpoint abuses as one defect — a callable action left uncapped whose per-invocation cost to the service far exceeds the attacker's, so no enforced per-source budget separates legitimate demand from adversarial demand driven at machine speed.
  • Server-Side Request Forgery — Diagnose the web attack in which an attacker-supplied URL makes a server issue a request under its own credentials and network position, by asking whether the issuer of the intent and the carrier of the authority are the same principal.
  • Smart Contract — Executable protocol rules can return information or conditionally change shared state without necessarily constituting a legal contract.
  • Social VPN — A peer-to-peer virtual private network whose authenticated membership and public-key discovery are derived automatically from declared social-network relationships, while encrypted IP traffic is carried through an overlay.
  • Source Protection — The layered practice by which a journalist shields a vulnerable upstream provider's identity from any party who would harm them — protecting not just the present source but the future channel, since a single breach collapses the protection promise across every source not yet contacted.
  • Technology Provisioning — Technology provisioning maps an approved service or identity request into configured target-system state and manages that state as the request changes.
  • Zero-trust architecture — Zero-trust architecture requires every access request to be explicitly authenticated, authorized, and continually evaluated from identity, device, resource, and context signals without granting implicit trust from network location or prior admission.
  • Zooko's Triangle — A contested network-naming design triangle weighs human-readable names, secure binding, and decentralized control under explicit trust and namespace assumptions.