Skip to content
CS-703 (A) · Cryptography & Information Security/Quick Revision Short Notes

Cryptography & Information Security (CS-703 (A)) - Unit 5 Short Notes

How unit 5 is examined

This unit covers attack-side and defence-side security tools; the marks sit in steganography (definition, types, versus cryptography, tools), steganalysis, spoofing tools and DoS tools.

Spoofing tools: like Arping etc.

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">High weight</span>

Definition. <mark>Spoofing is forging the identity of a sender, such as its IP address, MAC address, ARP reply or DNS answer, so that a victim trusts a packet that really came from an attacker.</mark>

Key points.

  1. IP spoofing puts a fake source address in the IP header, and it is used to hide the attacker, to bypass address-based filters and to reflect flood traffic at a victim.
  2. ARP spoofing sends forged ARP replies that bind the attacker's MAC address to the gateway's IP address, so the victim's traffic passes through the attacker (a man-in-the-middle).
  3. DNS spoofing (cache poisoning) plants a false IP for a domain name, which sends users to a fake site.
  4. MAC spoofing changes the network card's MAC address to imitate an authorised device, and it defeats MAC filtering.
  5. Arping sends ARP requests to a given IP on the local network and prints the MAC address that answers, so it is used to find live hosts and to detect duplicate IPs or a spoofed reply.
  6. Other tools are arpspoof and dnsspoof (dsniff suite), Ettercap and Cain and Abel for ARP poisoning, hping for crafted spoofed-source packets, and macchanger or SMAC for MAC spoofing.
  7. Attackers use these tools for sniffing, session hijacking and redirection, while the defences are static ARP entries, dynamic ARP inspection on switches, DNSSEC, ingress and egress filtering, and encrypted protocols such as HTTPS.

<figure class="ds-fig" style="margin:1.4rem 0;overflow-x:auto"><svg xmlns="http://www.w3.org/2000/svg" id="dsfig-u5-01" viewBox="0 0 338 166" width="338" height="166" role="img" aria-label="ARP spoofing: victim V sends traffic to attacker A, who relays it to gateway G (man-in-the-middle)"><style>#dsfig-u5-01 .e{stroke:#454C5A;stroke-width:1.4;fill:none}#dsfig-u5-01 .e.hi{stroke:#2340B8;stroke-width:2.6}#dsfig-u5-01 .n{fill:#FFFFFF;stroke:#16181D;stroke-width:1.4}#dsfig-u5-01 .n.hi{fill:#E3E9FC;stroke:#2340B8;stroke-width:2.2}#dsfig-u5-01 .n.rb-b{fill:#16181D;stroke:#16181D}#dsfig-u5-01 .n.rb-r{fill:#BD3227;stroke:#BD3227}#dsfig-u5-01 text{font-family:"JetBrains Mono",ui-monospace,Menlo,Consolas,monospace;font-size:13px}#dsfig-u5-01 .t{fill:#16181D;font-weight:500}#dsfig-u5-01 .t.inv{fill:#FFFFFF;font-weight:700}#dsfig-u5-01 .kd{stroke:#16181D;stroke-width:1.2}#dsfig-u5-01 .dot{fill:#16181D}#dsfig-u5-01 .ann{fill:#2340B8;font-size:11px;font-weight:700}#dsfig-u5-01 .lbl{fill:#6F7787;font-family:system-ui,-apple-system,sans-serif;font-size:12px;font-weight:700}#dsfig-u5-01 .ptr{fill:#2340B8;font-size:12px;font-weight:700}#dsfig-u5-01 .ah{fill:#454C5A}#dsfig-u5-01 .ah.hi{fill:#2340B8}#dsfig-u5-01 .wl rect{fill:#FFFFFF;stroke:#DCE0E7}#dsfig-u5-01 .wl .t{font-size:12px;font-weight:700}#dsfig-u5-01 .wl.hi rect{fill:#2340B8;stroke:#2340B8}#dsfig-u5-01 .wl.hi .t{fill:#FFFFFF}html.dark #dsfig-u5-01 .e{stroke:#B1B7C3}html.dark #dsfig-u5-01 .e.hi{stroke:#8FA3FF}html.dark #dsfig-u5-01 .n{fill:#161920;stroke:#E6E8ED}html.dark #dsfig-u5-01 .n.hi{fill:#1E2748;stroke:#8FA3FF}html.dark #dsfig-u5-01 .n.rb-b{fill:#E6E8ED;stroke:#E6E8ED}html.dark #dsfig-u5-01 .n.rb-r{fill:#FF7E71;stroke:#FF7E71}html.dark #dsfig-u5-01 .t{fill:#E6E8ED}html.dark #dsfig-u5-01 .t.inv{fill:#0F1115}html.dark #dsfig-u5-01 .kd{stroke:#E6E8ED}html.dark #dsfig-u5-01 .dot{fill:#E6E8ED}html.dark #dsfig-u5-01 .ann{fill:#8FA3FF}html.dark #dsfig-u5-01 .lbl{fill:#858D9C}html.dark #dsfig-u5-01 .ptr{fill:#8FA3FF}html.dark #dsfig-u5-01 .ah{fill:#B1B7C3}html.dark #dsfig-u5-01 .ah.hi{fill:#8FA3FF}html.dark #dsfig-u5-01 .wl rect{fill:#161920;stroke:#2A2E37}html.dark #dsfig-u5-01 .wl.hi rect{fill:#8FA3FF;stroke:#8FA3FF}html.dark #dsfig-u5-01 .wl.hi .t{fill:#0F1115}</style><defs><marker id="ah13" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah" d="M0,1 L9,5 L0,9 z"/></marker><marker id="ahh13" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah hi" d="M0,1 L9,5 L0,9 z"/></marker></defs><path class="e" d="M55.8,115.5 L151.5,51.6" marker-end="url(#ah13)"/><path class="e" d="M184.8,50.5 L280.5,114.4" marker-end="url(#ah13)"/><path class="e" d="M279,126 L61,126" marker-end="url(#ah13)"/><g class="wl"><rect x="73.8" y="74" width="61.5" height="18" rx="9"/><text class="t" x="104.5" y="83" dy=".35em" text-anchor="middle">fakeARP</text></g><g class="wl"><rect x="210" y="74" width="47.1" height="18" rx="9"/><text class="t" x="233.5" y="83" dy=".35em" text-anchor="middle">relay</text></g><circle class="n" cx="40" cy="126" r="18"/><text class="t" x="40" y="126" dy=".35em" text-anchor="middle">V</text><circle class="n" cx="169" cy="40" r="18"/><text class="t" x="169" y="40" dy=".35em" text-anchor="middle">A</text><circle class="n" cx="298" cy="126" r="18"/><text class="t" x="298" y="126" dy=".35em" text-anchor="middle">G</text></svg><figcaption style="font-size:.82em;opacity:.72;margin-top:.45rem">ARP spoofing: victim V sends traffic to attacker A, who relays it to gateway G (man-in-the-middle)</figcaption></figure>

Answer frame. Open with the definition and the four kinds of spoofing; draw the ARP spoofing figure; develop points 1-6 as one line per tool with its use; close with the countermeasures of point 7 and that spoofing tools are dual-use.

Pitfall: Do not call Arping an attack tool only; it is a diagnostic that becomes a spoofing aid.

Asked: [14 marks] (Jun 2025) Write short notes (any three): i) Spoofing tools ii) ECC iii) Firewalls iv) Cryptanalysis Asked: [7 marks] (Dec 2020) Discuss various spoofing and foot printing tools.

Footprinting tools

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Footprinting is the first step of an attack, collecting public information about a target such as domains, IP ranges, name servers and owners.

Key points.

  1. nslookup queries a DNS server for records of a name, for example nslookup example.com.
  2. dig is the more detailed Linux DNS tool, for example dig example.com MX returns the mail servers.
  3. Whois returns the registrar, registrant, contact details, name servers and registration dates of a domain.
  4. traceroute shows the routers on the path to the target, and Nmap adds open ports and services.
  5. The defence is to hide registrant data with privacy protection and to limit DNS zone transfers.

Vulnerabilities scanning tools (Angry IP, HPing2, IP Scanner, Global Network Inventory Scanner, Net Tools Suite Pack)

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>

Definition. <mark>A vulnerability scanning tool probes hosts and networks to find live systems, open ports and known weaknesses before an attacker does.</mark>

Key points.

  1. Angry IP Scanner is a fast, free scanner that pings a range of IP addresses and reports hostnames, MAC addresses and open ports.
  2. HPing2 is a command-line packet crafter that sends custom TCP, UDP or ICMP packets, for example hping2 -S -p 80 host, to test firewalls and ports.
  3. IP Scanner and Net Tools Suite Pack list the hosts, shares and services of a network range with several small utilities such as ping, port scan and trace.
  4. Global Network Inventory Scanner collects hardware, software and patch details of computers without installing an agent.
  5. Larger scanners such as Nessus and OpenVAS match services against a database of known vulnerabilities and give a report.

Asked: [7 marks] (Dec 2025) Write short notes on Vulnerability Scanning Tools and DoS Attack Understanding Tools with examples.

NetBIOS enumeration using NetView tool

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. NetBIOS enumeration extracts computer names, users, shares and services from a Windows network through NetBIOS (ports 137-139) and SMB (port 445).

Key points.

  1. The Windows command net view \\host lists the shared resources of a machine, and net view /domain lists the domains.
  2. nbtstat -A shows the NetBIOS name table of a remote IP, revealing names, groups and logged-on users.
  3. The attacker uses the shares and names for password guessing and for planning further attacks.
  4. The defence is to disable NetBIOS over TCP/IP, block ports 137-139 and 445 at the firewall, and remove unneeded shares.

Steganography (Merge Streams)

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">High weight</span>

Definition. <mark>Steganography is the art of hiding a secret message inside an ordinary cover medium such as an image, audio, video or text, so that nobody suspects the message exists.</mark>

Key points.

  1. The cover file plus the secret message, embedded by an algorithm and an optional key, gives a stego file that looks unchanged; the receiver runs extraction to recover the message.
  2. Text steganography hides bits in white space, word choice or the first letters of words.
  3. Image steganography hides bits in pixels; the commonest method is LSB (least significant bit) replacement.
  4. Audio and video steganography hide bits in sample values, silence, echoes or frame data, where human senses do not notice small changes.
  5. Network steganography hides data in unused protocol header fields, such as IP ID or TCP flags, or in packet timing.
  6. LSB example: to hide bits 0,1,0,0,0,0,0,1 (letter A) in the bytes 200 to 207, only the last bit of each byte changes, giving 200,201,202,202,204,204,206,207, a change of at most 1 in 255.
  7. Merge Streams hides data by merging one stream into another so that the carrier file still opens normally; Steghide (JPEG, BMP, WAV, AU with encryption) and S-Tools (BMP, GIF, WAV) are the usual tools, and Steganalysis is the counter-technique.

<figure class="ds-fig" style="margin:1.4rem 0;overflow-x:auto"><svg xmlns="http://www.w3.org/2000/svg" id="dsfig-u5-02" viewBox="0 0 596 252" width="596" height="252" role="img" aria-label="C cover, M secret message, E embed, S stego file, X extract, R recovered message"><style>#dsfig-u5-02 .e{stroke:#454C5A;stroke-width:1.4;fill:none}#dsfig-u5-02 .e.hi{stroke:#2340B8;stroke-width:2.6}#dsfig-u5-02 .n{fill:#FFFFFF;stroke:#16181D;stroke-width:1.4}#dsfig-u5-02 .n.hi{fill:#E3E9FC;stroke:#2340B8;stroke-width:2.2}#dsfig-u5-02 .n.rb-b{fill:#16181D;stroke:#16181D}#dsfig-u5-02 .n.rb-r{fill:#BD3227;stroke:#BD3227}#dsfig-u5-02 text{font-family:"JetBrains Mono",ui-monospace,Menlo,Consolas,monospace;font-size:13px}#dsfig-u5-02 .t{fill:#16181D;font-weight:500}#dsfig-u5-02 .t.inv{fill:#FFFFFF;font-weight:700}#dsfig-u5-02 .kd{stroke:#16181D;stroke-width:1.2}#dsfig-u5-02 .dot{fill:#16181D}#dsfig-u5-02 .ann{fill:#2340B8;font-size:11px;font-weight:700}#dsfig-u5-02 .lbl{fill:#6F7787;font-family:system-ui,-apple-system,sans-serif;font-size:12px;font-weight:700}#dsfig-u5-02 .ptr{fill:#2340B8;font-size:12px;font-weight:700}#dsfig-u5-02 .ah{fill:#454C5A}#dsfig-u5-02 .ah.hi{fill:#2340B8}#dsfig-u5-02 .wl rect{fill:#FFFFFF;stroke:#DCE0E7}#dsfig-u5-02 .wl .t{font-size:12px;font-weight:700}#dsfig-u5-02 .wl.hi rect{fill:#2340B8;stroke:#2340B8}#dsfig-u5-02 .wl.hi .t{fill:#FFFFFF}html.dark #dsfig-u5-02 .e{stroke:#B1B7C3}html.dark #dsfig-u5-02 .e.hi{stroke:#8FA3FF}html.dark #dsfig-u5-02 .n{fill:#161920;stroke:#E6E8ED}html.dark #dsfig-u5-02 .n.hi{fill:#1E2748;stroke:#8FA3FF}html.dark #dsfig-u5-02 .n.rb-b{fill:#E6E8ED;stroke:#E6E8ED}html.dark #dsfig-u5-02 .n.rb-r{fill:#FF7E71;stroke:#FF7E71}html.dark #dsfig-u5-02 .t{fill:#E6E8ED}html.dark #dsfig-u5-02 .t.inv{fill:#0F1115}html.dark #dsfig-u5-02 .kd{stroke:#E6E8ED}html.dark #dsfig-u5-02 .dot{fill:#E6E8ED}html.dark #dsfig-u5-02 .ann{fill:#8FA3FF}html.dark #dsfig-u5-02 .lbl{fill:#858D9C}html.dark #dsfig-u5-02 .ptr{fill:#8FA3FF}html.dark #dsfig-u5-02 .ah{fill:#B1B7C3}html.dark #dsfig-u5-02 .ah.hi{fill:#8FA3FF}html.dark #dsfig-u5-02 .wl rect{fill:#161920;stroke:#2A2E37}html.dark #dsfig-u5-02 .wl.hi rect{fill:#8FA3FF;stroke:#8FA3FF}html.dark #dsfig-u5-02 .wl.hi .t{fill:#0F1115}</style><defs><marker id="ah14" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah" d="M0,1 L9,5 L0,9 z"/></marker><marker id="ahh14" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah hi" d="M0,1 L9,5 L0,9 z"/></marker></defs><path class="e" d="M55.8,50.5 L151.5,114.4" marker-end="url(#ah14)"/><path class="e" d="M55.8,201.5 L151.5,137.6" marker-end="url(#ah14)"/><path class="e" d="M188,126 L277,126" marker-end="url(#ah14)"/><path class="e" d="M317,126 L406,126" marker-end="url(#ah14)"/><path class="e" d="M446,126 L535,126" marker-end="url(#ah14)"/><g class="wl"><rect x="210" y="117" width="47.1" height="18" rx="9"/><text class="t" x="233.5" y="126" dy=".35em" text-anchor="middle">stego</text></g><circle class="n" cx="40" cy="40" r="18"/><text class="t" x="40" y="40" dy=".35em" text-anchor="middle">C</text><circle class="n" cx="40" cy="212" r="18"/><text class="t" x="40" y="212" dy=".35em" text-anchor="middle">M</text><circle class="n" cx="169" cy="126" r="18"/><text class="t" x="169" y="126" dy=".35em" text-anchor="middle">E</text><circle class="n" cx="298" cy="126" r="18"/><text class="t" x="298" y="126" dy=".35em" text-anchor="middle">S</text><circle class="n" cx="427" cy="126" r="18"/><text class="t" x="427" y="126" dy=".35em" text-anchor="middle">X</text><circle class="n" cx="556" cy="126" r="18"/><text class="t" x="556" y="126" dy=".35em" text-anchor="middle">R</text></svg><figcaption style="font-size:.82em;opacity:.72;margin-top:.45rem">C cover, M secret message, E embed, S stego file, X extract, R recovered message</figcaption></figure>

Basis Steganography Cryptography
Goal Hides the existence of the message Hides the meaning of the message
Visibility Stego file looks normal Ciphertext looks scrambled and is obviously secret
Security principle Obscurity of the channel Secrecy of the key with a strong algorithm
Robustness Fragile: compression or cropping can destroy the message Strong against modification of a copy, but any change breaks decryption
If detected Message is usually readable Message stays unreadable without the key
Example LSB of a photo carries text Caesar shift or AES encryption

Answer frame. Open with the definition and the contrast with cryptography; draw the embed and extract figure; develop points 1-5 as the types, then the LSB example, then two tools; close that the two are best combined by encrypting first and hiding afterwards. For the comparison question, give the table and one example each.

Asked: [14 marks] (Dec 2020) Write short notes: i) Steganography ii) UDP Flood iii) Lan Scanner Tools Asked: [7 marks] (Nov 2023) What is Steganography? Explain different types of Steganography. Asked: [7 marks] (Dec 2025) What is Steganography? Explain any two tools used for hiding information in digital media. Asked: [7 marks] (Jun 2025) Describe the differences between steganography and cryptography with example in details.

Image Hide

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Image Hide is a steganography tool that hides text or files inside an image without visibly changing it.

Key points.

  1. It embeds the message in the pixel data, and the picture looks the same to the eye.
  2. The stego image is saved in a lossless format such as PNG or BMP, because JPEG compression would destroy the hidden bits.
  3. The receiver opens the image with the same tool to extract the message.

Stealth Files

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Stealth Files is a tool that hides any file inside another carrier file, such as an executable, DLL or document.

Key points.

  1. The hidden file is stored inside the carrier, which still runs or opens normally.
  2. A password protects the hidden data during extraction.
  3. It makes files invisible to casual browsing, so it is a data hiding method rather than a strong encryption.

Blindside using S-Tools

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. BlindSide and S-Tools are steganography tools that hide files in image and audio carriers.

Key points.

  1. BlindSide hides files inside bitmap images and asks for a password.
  2. S-Tools hides data in BMP, GIF and WAV files by LSB replacement, and it can encrypt the message first with ciphers such as DES, 3DES or IDEA.
  3. Both give a stego file that looks and plays like the original.

Steghide, Steganos, Stegdetect

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Steghide and Steganos hide data in cover files, and Stegdetect detects hidden data in JPEG files.

Key points.

  1. Steghide hides data in JPEG, BMP, WAV and AU files, compresses and encrypts it with a passphrase, and keeps the colour or sample statistics of the cover.
  2. Steganos is a commercial suite that hides and encrypts files inside pictures and audio.
  3. Stegdetect uses statistical tests to find data hidden in JPEG images by Jsteg, JPHide and OutGuess.

Steganalysis (Stego Watch, detection tools)

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">High weight</span>

Definition. <mark>Steganalysis is the study and practice of detecting, and if possible extracting or destroying, hidden data in a cover medium.</mark>

Key points.

  1. The analyst compares the suspect file with a clean original, or checks it for unusual size, colour palette or timestamps.
  2. Visual analysis looks for distortions, and comparing the LSB plane of an image often shows noise where data is hidden.
  3. Statistical analysis, such as the chi-square test or histogram checks, detects that hiding has made pixel values too evenly distributed.
  4. Signature analysis looks for the known patterns that each tool leaves in the file.
  5. Stego Watch (WetStone) analyses many files, scores how likely each is to hold hidden data and reports the suspects; Stego Detection tools such as Stegdetect and StegSpy do the same for specific formats.
  6. Attacks are classed by what the analyst has: stego-only, known-cover, known-message and known-stego attack.
  7. Uses are forensics, blocking data leaks and finding malware channels; a message that is hidden and also encrypted stays unreadable even when found.

<figure class="ds-fig" style="margin:1.4rem 0;overflow-x:auto"><svg xmlns="http://www.w3.org/2000/svg" id="dsfig-u5-03" viewBox="0 0 467 80" width="467" height="80" role="img" aria-label="F suspect files, A analysis (visual, statistical, signature), T Stego Watch score, R report of suspects"><style>#dsfig-u5-03 .e{stroke:#454C5A;stroke-width:1.4;fill:none}#dsfig-u5-03 .e.hi{stroke:#2340B8;stroke-width:2.6}#dsfig-u5-03 .n{fill:#FFFFFF;stroke:#16181D;stroke-width:1.4}#dsfig-u5-03 .n.hi{fill:#E3E9FC;stroke:#2340B8;stroke-width:2.2}#dsfig-u5-03 .n.rb-b{fill:#16181D;stroke:#16181D}#dsfig-u5-03 .n.rb-r{fill:#BD3227;stroke:#BD3227}#dsfig-u5-03 text{font-family:"JetBrains Mono",ui-monospace,Menlo,Consolas,monospace;font-size:13px}#dsfig-u5-03 .t{fill:#16181D;font-weight:500}#dsfig-u5-03 .t.inv{fill:#FFFFFF;font-weight:700}#dsfig-u5-03 .kd{stroke:#16181D;stroke-width:1.2}#dsfig-u5-03 .dot{fill:#16181D}#dsfig-u5-03 .ann{fill:#2340B8;font-size:11px;font-weight:700}#dsfig-u5-03 .lbl{fill:#6F7787;font-family:system-ui,-apple-system,sans-serif;font-size:12px;font-weight:700}#dsfig-u5-03 .ptr{fill:#2340B8;font-size:12px;font-weight:700}#dsfig-u5-03 .ah{fill:#454C5A}#dsfig-u5-03 .ah.hi{fill:#2340B8}#dsfig-u5-03 .wl rect{fill:#FFFFFF;stroke:#DCE0E7}#dsfig-u5-03 .wl .t{font-size:12px;font-weight:700}#dsfig-u5-03 .wl.hi rect{fill:#2340B8;stroke:#2340B8}#dsfig-u5-03 .wl.hi .t{fill:#FFFFFF}html.dark #dsfig-u5-03 .e{stroke:#B1B7C3}html.dark #dsfig-u5-03 .e.hi{stroke:#8FA3FF}html.dark #dsfig-u5-03 .n{fill:#161920;stroke:#E6E8ED}html.dark #dsfig-u5-03 .n.hi{fill:#1E2748;stroke:#8FA3FF}html.dark #dsfig-u5-03 .n.rb-b{fill:#E6E8ED;stroke:#E6E8ED}html.dark #dsfig-u5-03 .n.rb-r{fill:#FF7E71;stroke:#FF7E71}html.dark #dsfig-u5-03 .t{fill:#E6E8ED}html.dark #dsfig-u5-03 .t.inv{fill:#0F1115}html.dark #dsfig-u5-03 .kd{stroke:#E6E8ED}html.dark #dsfig-u5-03 .dot{fill:#E6E8ED}html.dark #dsfig-u5-03 .ann{fill:#8FA3FF}html.dark #dsfig-u5-03 .lbl{fill:#858D9C}html.dark #dsfig-u5-03 .ptr{fill:#8FA3FF}html.dark #dsfig-u5-03 .ah{fill:#B1B7C3}html.dark #dsfig-u5-03 .ah.hi{fill:#8FA3FF}html.dark #dsfig-u5-03 .wl rect{fill:#161920;stroke:#2A2E37}html.dark #dsfig-u5-03 .wl.hi rect{fill:#8FA3FF;stroke:#8FA3FF}html.dark #dsfig-u5-03 .wl.hi .t{fill:#0F1115}</style><defs><marker id="ah15" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah" d="M0,1 L9,5 L0,9 z"/></marker><marker id="ahh15" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah hi" d="M0,1 L9,5 L0,9 z"/></marker></defs><path class="e" d="M59,40 L148,40" marker-end="url(#ah15)"/><path class="e" d="M188,40 L277,40" marker-end="url(#ah15)"/><path class="e" d="M317,40 L406,40" marker-end="url(#ah15)"/><g class="wl"><rect x="210" y="31" width="47.1" height="18" rx="9"/><text class="t" x="233.5" y="40" dy=".35em" text-anchor="middle">stats</text></g><g class="wl"><rect x="342.1" y="31" width="40.8" height="18" rx="9"/><text class="t" x="362.5" y="40" dy=".35em" text-anchor="middle">flag</text></g><circle class="n" cx="40" cy="40" r="18"/><text class="t" x="40" y="40" dy=".35em" text-anchor="middle">F</text><circle class="n" cx="169" cy="40" r="18"/><text class="t" x="169" y="40" dy=".35em" text-anchor="middle">A</text><circle class="n" cx="298" cy="40" r="18"/><text class="t" x="298" y="40" dy=".35em" text-anchor="middle">T</text><circle class="n" cx="427" cy="40" r="18"/><text class="t" x="427" y="40" dy=".35em" text-anchor="middle">R</text></svg><figcaption style="font-size:.82em;opacity:.72;margin-top:.45rem">F suspect files, A analysis (visual, statistical, signature), T Stego Watch score, R report of suspects</figcaption></figure>

Answer frame. Open with the definition and its purpose; draw the flow figure; develop points 1-5 as the methods, then tools; close with forensic uses and that a hidden message can still be encrypted.

Asked: [14 marks] (Dec 2025) Write short notes on any two of the following: a) Steganalysis Tools b) SSL/TLS Protocols c) Differential Cryptanalysis d) Elliptic Curve Cryptography

StegSpy

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. StegSpy is a steganalysis tool that checks a file for hidden content and, if found, names the tool that hid it.

Key points.

  1. It looks for signatures of tools such as Hiderman, JPHide, Masker, JPegX and Invisible Secrets.
  2. It reports whether the file is stego, which program was used and where the hidden data begins.
  3. It supports image formats such as BMP, GIF and JPEG.

Trojans Detection Tools (i.e. Netstat, fPort, TCPView, CurrPorts Tool, Process Viewer)

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>

Definition. <mark>A Trojan is malware that appears to be useful software but secretly opens a backdoor, and Trojan detection tools find it through its open ports, processes and behaviour.</mark>

Key points.

  1. Netstat (netstat -an) lists the open ports and connections, so an unknown listening or established port is a warning.
  2. fPort shows each open port with the process and path that owns it, which reveals a Trojan behind a port.
  3. TCPView is a graphical live list of TCP and UDP endpoints with their processes, and it can close a connection.
  4. CurrPorts shows all open ports with the process details and can export the list, and Process Viewer lists the running processes, modules and threads.
  5. By type, detection is done by antivirus (signatures), behaviour monitors (unusual activity) and sandboxes (running the file in isolation).
  6. Prevention is to avoid unknown downloads, keep the antivirus and patches updated, and use a firewall.

Asked: [7 marks] (Nov 2022) Explain in short different types of Trojans detection tools.

LAN scanner tools

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. LAN scanner tools discover hosts on a local network and capture or analyse its traffic.

Key points.

  1. look@LAN is a network monitor that scans an IP range and lists the hosts, MAC addresses and open ports.
  2. Wireshark is a graphical packet analyser that captures live packets and decodes each protocol layer.
  3. tcpdump is a command-line packet capture tool, for example tcpdump -i eth0 port 80.
  4. Angry IP Scanner and Nmap are common examples for scanning; administrators use them for inventory and troubleshooting, and attackers for reconnaissance.

DoS attack understanding tools

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>

Definition. <mark>A denial of service (DoS) attack makes a system or network unavailable to its users by exhausting its bandwidth, memory or processing power; a distributed DoS (DDoS) does this from many machines at once.</mark>

Key points.

  1. Flooding attacks such as ICMP or UDP floods overload the bandwidth of the victim with useless packets.
  2. A SYN flood sends many TCP SYN requests and never completes the handshake, so the half-open connection table fills.
  3. A Smurf attack sends ICMP echo requests with the victim's spoofed address to a broadcast address, so every host replies to the victim.
  4. Jolt2 sends a stream of fragmented ICMP packets with identical fragment offsets, which drives an unpatched Windows host to 100 percent CPU.
  5. Bubonic.c sends TCP packets with random options to crash Windows 2000 machines.
  6. Land sends a SYN packet whose source and destination IP address and port are the same, so the victim replies to itself and hangs; LaTierra is an improved Land that attacks many ports in a loop.
  7. Mitigation is to patch systems, filter spoofed and broadcast traffic, rate-limit and use SYN cookies, and use intrusion prevention and DDoS protection services.

Answer frame. Open with the definition of DoS and DDoS and their impact; list the types; develop points 4-6 as named tools with the working of each; close with the mitigation of point 7.

Asked: [7 marks] (Nov 2022, Nov 2023) Explain in short different types of DoS Attack Understanding Tools.

DoS tools: Targa, Nemesy, Panther2, Crazy Pinger, UDP Flood, FSMax

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. These are tools that generate attack traffic to test or break a target's availability.

Key points.

  1. Targa combines many attacks in one program, such as teardrop, land, jolt, bonk and winnuke, and Nemesy generates random packets against a target.
  2. Panther2, Crazy Pinger and Some Trouble flood the target with packets, Crazy Pinger using ICMP echo.
  3. A UDP flood sends a large number of UDP packets to random ports, the victim answers each with an ICMP port unreachable message, and its bandwidth and CPU are exhausted; rate limiting and UDP filtering reduce it.
  4. FSMax is a stress tool that tests how much load a server can bear.

Last-minute revision

  • Steganography hides that a message exists; cryptography hides what it says.
  • Steganography model: cover + message + key gives stego; extraction reverses it.
  • LSB replacement changes only the last bit of each byte or pixel value.
  • Steganalysis detects hidden data by visual, statistical (chi-square) and signature checks.
  • Stego Watch, Stegdetect and StegSpy are detection tools; Steghide, S-Tools and Image Hide are hiding tools.
  • ARP spoofing binds the attacker's MAC to the gateway IP; Arping finds the MAC for an IP.
  • Defences for spoofing: static ARP, dynamic ARP inspection, DNSSEC, ingress and egress filtering.
  • nslookup and dig query DNS, Whois gives the owner, traceroute gives the path.
  • Netstat, fPort, TCPView and CurrPorts map open ports to processes to find Trojans.
  • Land: source equals destination SYN; Jolt2: fragmented ICMP; Bubonic.c: random TCP options.
  • UDP flood makes the victim send ICMP port unreachable replies until it is exhausted.

Memory hooks

  • Stego is "hide the box", crypto is "lock the box".
  • ARP spoof: attacker becomes the gateway's face.
  • Land attacks itself: the victim sends the reply to its own address.
  • Netstat lists ports, fPort names the owner, TCPView draws it.
  • Steganalysis: look, count, match (visual, statistics, signature).

Coverage checklist

  • Spoofing tools: like Arping etc. (Jun 2025 short note; Dec 2020 spoofing and footprinting)
  • Foot printing Tools (ex-nslookup, dig, Whois, etc..) (covered with the Dec 2020 spoofing question)
  • Vulnerabilities Scanning Tools (i.e. Angry IP, HPing2, IP Scanner, Global Network Inventory Scanner, Net Tools Suite Pack.) (Dec 2025 short note)
  • NetBIOS Enumeration Using NetView Tool
  • Steganography Merge Streams (Dec 2020, Nov 2023, Dec 2025, Jun 2025)
  • Image Hide
  • Stealth Files
  • Blindside using: STools
  • Steghide, Steganos. Stegdetect
  • Steganalysis - Stego Watch- Stego Detection Tool (Dec 2025)
  • StegSpy.
  • Trojans Detection Tools (i.e. Netstat, fPort, TCPView, CurrPorts Tool, Process Viewer) (Nov 2022)
  • Lan Scanner Tools (i.e. look@LAN, Wireshark, Tcpdump). (covered with the Dec 2020 short note)
  • DoS Attack Understanding Tools- Jolt2, Bubonic.c, Land and LaTierra (Nov 2022, Nov 2023)
  • Targa, Nemesy Blast, Panther2, Crazy Pinger, Some Trouble, UDP Flood, FSMax (UDP flood in the Dec 2020 short note)
Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in