Checking input against expected rules.

Restricting operation frequency.

Entity that can be authenticated or authorized.

Encoding output to prevent interpretation as code.

Deliberately limiting resource usage.

Boundary separating different security assumptions.

Injecting malicious SQL through application input.

Challenge designed to distinguish humans from bots.

Authorization framework for delegated access.

Analysis of potential security threats.