Formulas & shortcuts
Cybersecurity · 26
Every formula in this course and the easiest ways to remember them, on one page.
1Security foundationsBeginner
The CIA triad, threats and risk
Open lesson- Rrisk score (1–25)
- Llikelihood, 1 = very unlikely … 5 = almost certain
- Iimpact, 1 = negligible … 5 = catastrophic
A simple qualitative model: many organisations use a 5×5 risk matrix.
Personal security: passwords, MFA and phishing
Open lesson- Hentropy, in bits
- Lpassword length (number of characters)
- Aalphabet size: lowercase 26, uppercase 26, digits 10, symbols 33
2Cryptography and network securityIntermediate
Hashing and salting: how passwords are stored
Open lesson- Nroughly how many hashes are needed to find a collision (the “birthday paradox”)
- nhash length, in bits
This is the limit for an ideal hash; MD5's weak design lets researchers find collisions in seconds.
Encryption, TLS and certificates
Open lesson- p, gpublic parameters: a large prime and a generator
- a, bthe parties' secret numbers (never sent)
- A, Bvalues sent openly: A = gᵃ mod p, B = gᵇ mod p
- Kthe shared key both parties obtain
Network security: ports, firewalls, VPNs and Wi-Fi
Open lesson3Application securityAdvanced
Web security: the OWASP Top 10
Open lessonSecure coding
Open lesson4Security operations and careersAdvanced
Incident response and digital forensics
Open lessonCareers and certifications in cybersecurity
Open lesson5Security engineering, ethics and lawUniversity
Threat modelling with STRIDE
Open lesson- SLEsingle loss expectancy, in manat
- AVasset value, in manat
- EFexposure factor: the share lost in one event, from 0 to 1
- ALEannualised loss expectancy, manat per year
- AROannualised rate of occurrence: 0.5 = once every two years, 2 = twice a year
- NBannual net benefit of the control, manat per year
- ALE₀, ALE₁annualised loss expectancy before and after the control
- Cannual cost of the control, manat per year
If NB > 0, the control pays for itself.
Security architecture and zero trust
Open lesson- Pprobability that an attack gets through every layer
- pᵢprobability that layer i misses the attack (from 0 to 1)
- nnumber of layers
Derivation: if A and B are independent, P(A and B) = P(A) · P(B); by induction the rule extends to n layers.
- Aseqavailability of the series system
- Aᵢprobability that component i is up
- Aparavailability of the parallel system
- 1 − Aᵢprobability that component i is down
Derivation: a parallel system is down only when every component is down; that event's probability is the product of the failure probabilities, and availability is its complement. Yearly downtime: D = (1 − A) · 8760 hours.
Ethics and law in cybersecurity
Open lesson- Fmaxthe GDPR fine cap for the most serious infringements
- Tthe company's worldwide annual turnover for the previous financial year, in euros
Whichever is higher applies. For other infringements: max(€10,000,000; 0.02 · T). This is a cap; the actual fine is set case by case.