Skip to content
Artwork for CyBOK — The Cybersecurity Body of Knowledge
Education

CyBOK — The Cybersecurity Body of Knowledge

University of Bristol and the CyberWire

A comprehensive Body of Knowledge to inform and underpin education and professional training for the cyber security sector.

  • 20 episodes
  • Updated June 18

Episodes20

  • June 18 · 22 min

    CyBOK - Secure Software Lifecycle with Laurie Williams

    From secure coding practices to managing third-party components and responding to vulnerabilities in production, building secure software requires more than just finding bugs. It demands a comprehensive approach that spans the entire software lifecycle. This episode explores the Secure Software Lifecycle, or SSDL, the processes and practices that help organizations develop, deploy, and maintain software that upholds the core principles of confidentiality, integrity, and availability. We speak with CyBOK Secure Software Lifecycle Topic Guide author Laurie Williams for insighits into the topic.

  • June 8 · 21 min

    CyBOK - Security Informed Safety with Victor Lough

    In this topic guide we set out the present state of thinking on how to combine the perpectives of cyber security and safety and reliability cultures. In particular, we focus on a structured approach to defending safety critical systems, with mechanisms already in place for safety and reliability. In other words, we do not start with the assumption of greenfield sites and recognise that security cultures must work in concert with existing, well-embedded, safety and reliability cultures. We speak with CyBOK Security Informed Safety Topic Guide author Victor Lough for a view into the topic.

  • March 31 · 22 min

    CyBOK - Cloud Security with Mark Buckwell

    Adoption of cloud computing has accelerated the digital transformation of organisations globally, supported by a corresponding transformation in cybersecurity. With the migration of applications from on-premise data centres to the public cloud and their integration with edge environments, the threats to processing sensitive data have changed. The cloud platform's built-in security has mitigated the broader threat landscape for businesses, but it has also brought additional complexity and skill demands. As a result, organisations must manage multiple cloud providers with many new cybersecurity solutions that are hosted on different technology platforms. We speak with CyBOK Cloud Security Topic Guide author Mark Buckwell for a view into the topic.

  • Nov 1, 2023 · 16 min

    CyBOK - AI for Security with Matilda Rhode

    Cybersecurity, like other industries, has seen an explosion in the use of artificial intelligence (AI) and machine learning (ML) technologies in recent years. AI and ML can help to automate tasks. Data-driven approaches in general can draw patterns from vast volumes of data far quicker than humans are can. This episode summarises the state of AI for security at the time of writing and highlights some of the considerations to guide whether it is an appropriate approach for a given problem, common pitfalls to avoid, and human-AI ecosystems.AI is challenged by several open research areas including lack of transparency, robustness to concept drift, and the security of AI systems themselves. This topic guide is for those looking to build and/or procure AI solutions to use for cybersecurity applications. Some sections are more relevant for those building and others to those procuring solutions. We speak with CyBOK AI for Security author Matilda Rhode for an overview of the topic.

  • Nov 1, 2023 · 21 min

    CyBOK - Security Economics with Tyler Moore

    The Security Economics Knowledge Guide introduces some of the most impactful ways economics has helped to shed light on cybersecurity problems and frame solutions that blend private and public action. The guide focuses on the organizational, rather than individual, perspective, which is where the majority of scholarly activity has focused. The author of this knowledge guides shares canonical security failures from an economic perspective, describes key measurement challenges, reviews firm-level approaches to improving cybersecurity, and discusses available public-policy options. We speak with CyBOK Security Economics author Tyler Moore for an overview of the topic.

  • Sep 25, 2023 · 21 min

    CyBOK - Security and Privacy of AI with Lorenzo Cavallaro and Emiliano De Cristofaro

    Machine Learning (ML) has rapidly become a fundamental technology that underpins count- less applications, from natural language processing and computer vision to fraud detection and personalized recommendations. In recent years, there has been a growing understanding of how to use ML in security contexts, leading to the development of advanced tools and techniques for detecting and preventing malicious activities. However, the security and privacy aspects of ML itself remain less understood, posing new challenges and opportunities for researchers and practitioners. This Cybersecurity Body of Knowledge (CyBoK) Knowledge Guide (KG) aims to define the scope of adversarial machine learning and privacy in ML and provide an overview of the state- of-the-art in these rapidly evolving fields. Our focus is on the key challenges, open problems, and promising solutions that have emerged in the context of securing and preserving the privacy of ML systems. We speak with CyBOK Security and Privacy of AI authors Lorenzo Cavallaro and Emiliano De Cristofaro for an overview of the topic.

  • Sep 21, 2021 · 20 min

    CyBOK - Network Security 2.0 with Christian Rossow

    The ubiquity of networking allows us to connect all sorts of devices and gain unprecedented access to a whole range of applications and services anytime, anywhere. However, our heavy reliance on networking technology also makes it an attractive target for malicious users who are willing to compromise the security of our communications and/or cause disruption to services that are critical for our day-to-day survival in a connected world. The Network Security 2.0 knowledge area explains the challenges associated with securing a network under a variety of attacks for a number of networking technologies and widely used security protocols, along with emerging security challenges and solutions. We speak with CyBOK Network Security 2.0 author Christian Rossow for an overview of the topic.

  • Sep 21, 2021 · 31 min

    CyBOK - Formal Methods with David Basin

    The Formal Methods knowledge area surveys the most relevant topics in formal methods for security. As a discipline, formal methods address foundations, methods and tools, based on mathematics and logic, for rigourously developing and reasoning about computer systems, whether they be software, hardware, or a combination of the two. The application of formal methods to security has emerged over recent decades as a well-established research area focused on the specification and proof of security properties of systems, their components, and protocols. We speak with CyBOK Formal Methods author David Basin for an overview of the topic.

  • Sep 21, 2021 · 31 min

    CyBOK - Applied Cryptography with Kenny Paterson

    The Applied Cryptography knowledge area This document provides a broad introduction to the field of cryptography, focusing on applied aspects of the subject. It complements the CyBoK document [1] which focuses on formal aspects of cryptography (including definitions and proofs) and on describing the core cryptographic primitives. That said, formal aspects are highly relevant when considering applied cryptography. As we shall see, they are increasingly important when it comes to providing security assurance for real-world deployments of cryptography. We speak with CyBOK Applied Cryptography author Kenny Paterson for an overview of the topic.

  • May 1, 2021 · 22 min

    CyBOK - Web and Mobile Security with Sascha Fahl

    The purpose of the Web and Mobile Security chapter is to provide an overview of security mechanisms, attacks and defences in modern web and mobile ecosystems. Web and mobile security have become the primary means through which many users interact with the Internet and computing systems. Hence, their impact on overall information security is significant due to the sheer prevalence of web and mobile applications (apps). Covering both web and mobile security, this Knowledge Area emphasises the intersection of their security mechanisms, vulnerabilities and mitigations. We speak with CyBOK Web and Mobile Security author Sascha Fahl for an introductory overview of the topic.

  • Sep 1, 2020 · 37 min

    CyBOK - Law and Regulation with Robert Carolina

    The purpose of the Law and Regulation chapter is to provide a snapshot of legal and regulatory topics that merit consideration when conducting various activities in the field of cyber security such as: security management, risk assessment, security testing, forensic investigation, research, product and service development, and cyber operations (defensive and offensive). The hope is to provide a framework that shows the cyber security practitioner the most common categories of legal and regulatory risk that apply to these activities, and to highlight (where possible) some sources of legal authority and scholarship.. We speak with CyBOK Law and Regulation author Robert Carolina for an introductory overview of the topic.

  • Sep 1, 2020 · 17 min

    CyBOK - Adversarial Behaviours with Gianluca Stringhini

    The purpose of the Adversarial Behaviours chapter is to provide an overview of the malicious operations that are happening on the Internet today. The chapter discusses how these frameworks can be used by researchers and practitioners to develop effective mitigations against malicious online operations. We speak with CyBOK Distributed Systems Security author Gianluca Stringhini for an introductory overview of the topic.

  • Sep 1, 2020 · 20 min

    CyBOK - Hardware Security with Ingrid Verbauwhede

    The purpose of the Distributed Systems Security chapter covers a broad range of topics from trusted computing to Trojan circuits. To classify these topics we follow the different hardware abstraction layers as introduced by the Y-chart of Gajski & Kuhn. We speak with CyBOK Hardware Security author Ingrid Verbauwhede for an introductory overview of the topic.

  • Sep 1, 2020 · 20 min

    CyBOK - Distributed Systems Security with Neeraj Suri

    The purpose of the Distributed Systems Security chapter is to introduce the different classes of distributed systems categorising them into two broad categories of decentralised distributed systems (without central coordination) and the coordinated resource/services type of distributed systems. Subsequently, each of these distributed system categories is expounded for the conceptual mechanisms providing their characteristic functionalities prior to discussing the security issues pertinent to these systems. We speak with CyBOK Distributed Systems Security author Neeraj Suri for an introductory overview of the topic.

  • Jul 17, 2020 · 18 min

    CyBOK - Privacy and Online Rights with Carmela Troncoso

    The purpose of the Privacy and Online Rights chapter is to introduce system designers to the concepts and technologies that are used to engineer systems that inherently protect users’ privacy. We aim to provide designers with the ability to identify privacy problems, to describe them from a technical perspective, and to select adequate technologies to eliminate, or at least, mitigate these problems. We speak with CyBOK Privacy and Online Rights Knowledge Area author Carmela Troncoso for an introductory overview of the topic.

  • Jul 17, 2020 · 22 min

    CyBOK - Network Security with Sanjay Jha

    The purpose of the Network Security chapter is to explain the challenges associated with securing a network under a variety of attacks for a number of networking technologies and widely used security protocols, along with emerging security challenges and solutions. This chapter aims to provide the necessary background in order to understand other knowledge areas. An understanding of basic networking protocol stack and TCP/IP suite is assumed. We speak with CyBOK Network Security Knowledge Area author Sanjay Jha for an introductory overview of the topic.

  • Jul 17, 2020 · 17 min

    CyBOK - Operating Systems & Virtualisation Security with Herbert Bos

    The purpose of the Operating Systems & Virtualisation Security chapter is to introduce the principles, primitives and practices for ensuring security at the operating system and hypervisor levels. We see that the challenges related to operating system security have evolved over the past few decades, even if the principles have stayed mostly the same. We speak with CyBOK Operating Systems & Virtualisation Security author Herbert Bos for an introductory overview of the topic.

  • Jul 17, 2020 · 21 min

    CyBOK - Human Factors with Awais Rashid

    The Human Factors chapter presents a foundational understanding of the role of human factors in cyber security. One key aspect of this is how to design security that is usable and acceptable to a range of human actors, for instance, end-users, administrators and developers. This knowledge area also introduces a broader organisational and societal perspective on security that has emerged over the past decade. We speak with CyBOK Human Factors co-author Awais Rashid for an introductory overview of the topic.

  • Jul 17, 2020 · 20 min

    CyBOK - AAA with Dieter Gollmann

    The Authentication, Authorisation & Accountability (AAA) chapter presents the general foundations of access control and some significant instantiations that have emerged as IT kept spreading into new application areas. It will survey modes of user authentication and the way they are currently deployed, authentication protocols for the web, noting how new use cases have led to a shift from authentication to authorisation protocols, and the formalisation of authentication properties as used in today’s protocol analysis tools. On accountability, the focus is on the management and protection of audit logs. We speak with CyBOK Authentication, Authorisation & Accountability (AAA) author Dieter Gollmann for an introductory overview of the topic.

  • Jul 17, 2020 · 18 min

    CyBOK - Risk Management and Governance with Pete Burnap

    The Risk Management and Governance chapter explains the fundamental principles of cyber risk assessment and management and their role in risk governance, expanding on these to cover the knowledge required to gain a working understanding of the topic and its sub-areas. We speak with CyBOK Risk Management and Governance author Pete Burnap for an introductory overview of the topic.