Skip to content
CY-503 (A) · Biometric Techniques for Security/Quick Revision Short Notes

Biometric Techniques for Security (CY-503 (A)) - Unit 1 Short Notes

UNIT 1: Security Fundamentals and Biometric Authentication

1. Introduction to Security Principles

1.1 Security Objectives (CIA Triad + 2)

Objective Definition Example
Confidentiality Ensuring information is not disclosed to unauthorized entities. Encryption of data in transit.
Integrity Maintaining the accuracy and completeness of data; preventing unauthorized modification. Using Hash functions (SHA-256) to verify file integrity.
Availability Ensuring systems and data are accessible to authorized users when needed. Implementing redundant servers and DDoS mitigation.
Authentication Verifying the identity of a user, system, or entity. Password, biometric scan, or digital certificate.
Non-repudiation Preventing a party from denying an action or transaction. Digital signatures provide non-repudiation.

[!TIP] Exam Focus: CIA is foundational. Always relate security mechanisms (e.g., encryption for Confidentiality, hash for Integrity) back to these objectives.

1.2 Threat Models and Attack Vectors

  • Malware: Viruses, Worms, Trojans, Ransomware.

  • Intrusion: Unauthorized access to systems/networks (e.g., exploiting vulnerabilities).

  • Eavesdropping/Sniffing: Intercepting network traffic.

  • Spoofing: Faking identity (IP, MAC, biometric).

  • Denial-of-Service (DoS/DDoS): Overwhelming a service to make it unavailable.

  • Man-in-the-Middle (MitM): Intercepting and potentially altering communication.


2. Cryptographic Foundations

2.1 Symmetric Key Cryptography

Principle: Sender and receiver share a single, secret key for both encryption and decryption. Characteristic: Fast, efficient for bulk data encryption. Key distribution is the primary challenge.

Classical Cipher: Caesar Cipher

  • Principle: Substitution cipher where each plaintext letter is shifted a fixed number (k) positions down the alphabet.

  • Encryption: $$\displaystyle C = (P + k) \mod 26 $$

  • Decryption: $$\displaystyle P = (C - k) \mod 26 $$

  • Example (Shift 3): Plaintext: HELLO -> Ciphertext: KHOOR.

Block Ciphers: AES (Advanced Encryption Standard)

  • Block Size: 128 bits. Key Sizes: 128, 192, 256 bits.

  • Structure: Iterative Substitution-Permutation Network (SPN). Rounds: 10 (128-bit key), 12 (192-bit), 14 (256-bit).

  • Core Operations per Round:

    1. SubBytes: Non-linear substitution using S-Box.

    2. ShiftRows: Cyclic shift of rows in state matrix.

    3. MixColumns: Mixing columns (linear transformation).

    4. AddRoundKey: XOR with round key.

  • Final Round: Omits MixColumns.

Cipher Block Modes of Operation

Mode Operation Merits Demerits
ECB (Electronic Codebook) Each plaintext block encrypted independently. Simple, allows random access. Identical plaintext blocks → identical ciphertext blocks (pattern leakage). Insecure.
CBC (Cipher Block Chaining) $$\displaystyle C_i = E_K(P_i \oplus C_{i-1}) $$, $$\displaystyle C_0 = IV $$. Hides patterns, widely used. Requires IV (must be unpredictable), sequential encryption (no parallel).
CFB (Cipher Feedback) Turns block cipher into stream cipher. $$\displaystyle C_i = P_i \oplus E_K(C_{i-1}) $$. No padding needed, can handle small data units. Error propagation (corrupts next s bits).
OFB (Output Feedback) Generates keystream independent of plaintext/ciphertext. $$\displaystyle O_i = E_K(O_{i-1}) $$, $$\displaystyle C_i = P_i \oplus O_i $$. Error does not propagate, synchronous stream cipher. If keystream reused, catastrophic failure.
CTR (Counter) Encrypts counter value to generate keystream. $$\displaystyle C_i = P_i \oplus E_K(IV + i) $$. Parallel encryption/decryption, random access. Requires unique counter/IV for each message.

Stream Ciphers: RC4 (Rivest Cipher 4)

  • Principle: Variable-length key (1-256 bytes) generates a pseudo-random keystream. XOR with plaintext for encryption/decryption.

  • Key Scheduling (KSA): Initialize S array (0-255) and permute using key K.

    
    for i=0 to 255: S[i] = i; j=0;
    
    for i=0 to 255: j = (j + S[i] + K[i mod keylen]) mod 256; swap(S[i], S[j]);
    
    
  • Pseudo-random Generation (PRGA): Generate keystream byte-by-byte.

    
    i = (i + 1) mod 256;
    
    j = (j + S[i]) mod 256;
    
    swap(S[i], S[j]);
    
    t = (S[i] + S[j]) mod 256;
    
    K_stream = S[t];
    
    
  • Example (5-bit key 10101 = 21 decimal, first 3 bytes):

    1. Key array K = [1,0,1,0,1] (repeated as needed).

    2. Run KSA to get initial S permutation.

    3. Run PRGA three times to get first 3 keystream bytes (e.g., 0x3A, 0x5F, 0x1C).

[!TIP] Common Pitfall: ECB mode is insecure for repeated data patterns. Always use CBC, CTR, or GCM for new designs. RC4 has known biases; avoid in new systems.

2.2 Asymmetric Key Cryptography

Principle: Uses key pair: Public Key (shared) & Private Key (secret). Mathematically linked but infeasible to derive private from public. PKI (Public Key Infrastructure): Framework for managing digital certificates (X.509) binding public keys to entities via Certificate Authorities (CAs).

RSA Algorithm (Rivest-Shamir-Adleman)

  1. Key Generation:

    • Choose large primes $p, q$.

    • Compute $$\displaystyle n = p \times q $$, $$\displaystyle \phi(n) = (p-1)(q-1) $$.

    • Choose $e$ such that $$\displaystyle 1 < e < \phi(n) $$ and $$\displaystyle \gcd(e, \phi(n)) = 1 $$.

    • Compute $$\displaystyle d = e^{-1} \mod \phi(n) $$.

    • Public Key: $(e, n)$. Private Key: $(d, n)$.

  2. Encryption: $$\displaystyle C = P^e \mod n $$

  3. Decryption: $$\displaystyle P = C^d \mod n $$

Numerical Example (p=3, q=11):

  • $$\displaystyle n = 3 \times 11 = 33 $$, $$\displaystyle \phi(n) = 2 \times 10 = 20 $$.

  • Choose $$\displaystyle e=7 $$ (gcd(7,20)=1).

  • $$\displaystyle d = 7^{-1} \mod 20 = 3 $$ (since $$\displaystyle 7 \times 3 = 21 \equiv 1 \mod 20 $$).

  • Public Key: (7, 33). Private Key: (3, 33).

  • Encrypt $$\displaystyle P=2 $$: $$\displaystyle C = 2^7 \mod 33 = 128 \mod 33 = 29 $$.

  • Decrypt $$\displaystyle C=29 $$: $$\displaystyle P = 29^3 \mod 33 = 24389 \mod 33 = 2 $$.

[!TIP] Exam Tip: Always show key generation steps clearly. Small prime examples are common in exams.

2.3 Hash Functions and Message Authentication

Properties of Cryptographic Hash Functions

  1. Deterministic: Same input → same output.

  2. Fast Computation: Efficient for any input size.

  3. Pre-image Resistance: Given hash $h$, hard to find $M$ such that $$\displaystyle H(M)=h $$.

  4. Second Pre-image Resistance: Given $$\displaystyle M_1 $$, hard to find $$\displaystyle M_2 \neq M_1 $$ with $$\displaystyle H(M_1)=H(M_2) $$.

  5. Collision Resistance: Hard to find any $$\displaystyle M_1, M_2 $$ with $$\displaystyle H(M_1)=H(M_2) $$.

  6. Avalanche Effect: Small change in input → drastic change in output (~50% bits flip).

SHA-512 (Secure Hash Algorithm 512-bit)

Process (Simplified):

  1. Pre-processing:

    • Append 1 bit, then 0s, then 128-bit length of original message (big-endian).

    • Pad to multiple of 1024 bits.

  2. Initialize Hash Values (H0..H7): First 64 bits of fractional parts of sqrt(primes 2..9).

  3. Process Each 1024-bit Block:

    • Break block into 16 × 64-bit words $W[0..15]$.

    • Extend to 80 words: $$\displaystyle W[t] = \sigma_1(W[t-2]) + W[t-7] + \sigma_0(W[t-15]) + W[t-16] $$, $$\displaystyle t=16..79 $$.

    • Initialize working variables $$\displaystyle a..h = H0..H7 $$.

    • Main Loop (t=0..79):

      • $$\displaystyle T_1 = h + \Sigma_1(e) + Ch(e,f,g) + K[t] + W[t] $$

      • $$\displaystyle T_2 = \Sigma_0(a) + Maj(a,b,c) $$

      • $$\displaystyle h = g; g = f; f = e; e = d + T_1; d = c; c = b; b = a; a = T_1 + T_2 $$

    • Update hash: $$\displaystyle H_i = H_i + \text{corresponding working var} $$.

  4. Output: Concatenate $H0..H7$ → 512-bit digest.

HMAC (Hash-based Message Authentication Code)

Principle: Uses a cryptographic hash function with a secret key $K$ to provide data origin authentication and integrity. Algorithm:

  1. If $$\displaystyle |K| > \text{block size} $$, hash $K$ to get key of block size. If shorter, pad with zeros.

  2. Compute: $$\displaystyle \text{HMAC}(K, \text{text}) = H((K \oplus \text{opad}) \| H((K \oplus \text{ipad}) \| \text{text})) $$

    • ipad = 0x36 repeated block_size times.

    • opad = 0x5C repeated block_size times.

    • \|\ denotes concatenation.

  3. Security: Relies on strength of underlying hash (e.g., HMAC-SHA256).

Message Authentication Codes (MACs)

  • Principle: Short tag generated from message + secret key. Receiver verifies tag using same key.

  • Types: HMAC (hash-based), CMAC (block cipher-based), UMAC (universal hash-based).

  • Usage: Ensure message integrity and authentication between parties sharing a key. Does not provide non-repudiation.

[!TIP] Key Distinction: Hash = one-way, no key. MAC = uses secret key for authentication. Digital Signature = uses private key for non-repudiation.

2.4 Digital Signatures

Principle: Asymmetric technique where sender uses private key to sign; receiver uses sender's public key to verify. Process:

  1. Sender computes hash $$\displaystyle h = H(\text{message}) $$.

  2. Sender encrypts hash with private key: $$\displaystyle \text{Signature} = h^d \mod n $$ (RSA).

  3. Sender sends message + signature.

  4. Receiver decrypts signature with sender's public key: $$\displaystyle h' = \text{Signature}^e \mod n $$.

  5. Receiver computes $$\displaystyle h'' = H(\text{received message}) $$.

  6. If $$\displaystyle h' = h'' $$, signature is valid. Importance:

  • Authentication: Confirms sender identity.

  • Integrity: Any change in message invalidates signature.

  • Non-repudiation: Sender cannot deny having signed (only they have private key).


3. Authentication Mechanisms

3.1 Traditional Authentication

  • Password-based: "Something you know."

  • Vulnerabilities: Brute-force, dictionary attacks, shoulder surfing, reuse.

  • Mitigations: Salted hashing (bcrypt, scrypt), password policies, multi-factor.

3.2 Token-based Authentication

  • Smart Cards: Plastic card with embedded integrated circuit (chip).

  • Technology: Contact (ISO 7816) or Contactless (RFID/NFC, ISO 14443).

  • Applications: Storing digital certificates, cryptographic keys, performing computations (e.g., RSA). Used in e-passports, payment cards, corporate ID.

3.3 Biometric Authentication

Fundamentals: "Something you are." Uses unique physiological or behavioral characteristics. Common Traits:

  • Physiological: Fingerprint, Iris, Retina, Face, DNA.

  • Behavioral: Voice, Keystroke dynamics, Gait, Signature.

Biometric System Architecture:


Sensor → Feature Extraction → Template Creation → Template Storage → Matching Engine → Decision

  1. Sensor: Captures raw biometric data (e.g., fingerprint scanner, camera).

  2. Feature Extraction: Processes raw data to extract distinctive, compact features (minutiae points, iris code, face embeddings).

  3. Template Storage: Stores feature template (not raw image). Can be on-device or central database (encrypted!).

  4. Matching: Compares input template with stored template(s). Computes similarity score.

  5. Decision: Compares score to threshold. If score > threshold → accept; else reject.

Performance Metrics:

  • False Rejection Rate (FRR) / Type I Error: Genuine user rejected.

  • False Acceptance Rate (FAR) / Type II Error: Impostor accepted.

  • Equal Error Rate (EER): Point where FRR = FAR. Lower EER = better system.

  • Receiver Operating Characteristic (ROC) Curve: Plots FAR vs. FRR at varying thresholds.

Advantages:

  • Hard to lose, forget, or share.

  • Strong link to individual.

  • Convenient (no memorization).

Limitations & Security Concerns:

  • Accuracy: Noisy data (dirty finger, lighting), intra-class variations.

  • Privacy: Biometric data is sensitive PII. Theft is irreversible (unlike password reset).

  • Spoofing/Attacks:

    • Presentation Attack: Fake biometric (gummy finger, photo, voice recording).

    • Database Attack: Steal stored templates.

    • Replay Attack: Replay intercepted digital template.

  • Revocability: If compromised, cannot "change" your fingerprint.

  • Universality & Inclusivity: Not all people have usable biometrics (e.g., manual laborers' fingerprints).

Integration with Smart Cards (Multi-factor):

  • "Something you have" (Smart Card) + "Something you are" (Biometric).

  • Biometric data is stored on the smart card (not centrally) and matched on-card. Private key for digital signature is released only upon successful biometric match.

  • Benefit: Prevents misuse of lost/stolen card. Mitigates central database breach risk.

3.4 Multi-factor Authentication (MFA)

  • Combines two or more independent factors:

    1. Knowledge (password, PIN)

    2. Possession (smart card, OTP token, phone)

    3. Inherence (biometric)

  • Goal: Increase security by requiring multiple proofs of identity. Single factor compromise does not grant access.


4. Secure Communication Protocols

4.1 Email Security: PGP (Pretty Good Privacy)

Working Principle (Hybrid Cryptography):

  1. Session Key Generation: Sender generates random symmetric session key (e.g., AES-256).

  2. Message Encryption: Encrypt email body with session key (fast).

  3. Session Key Encryption: Encrypt session key with receiver's PUBLIC KEY (RSA/ElGamal).

  4. Signing (Optional): Sender signs the message hash with sender's PRIVATE KEY.

  5. Transmission: Send: {Encrypted Session Key, Encrypted Message, Digital Signature}.

PGP Message Format (Radix-64 / ASCII Armored):

-----BEGIN PGP MESSAGE-----

Version: PGP 9.9

[Base64-encoded data block]
-----END PGP MESSAGE-----

Internal Data Structure (conceptual):


[Signature Packet] (if signed)

[Public-Key Encrypted Session Key Packet] (for each recipient)

[Symmetrically Encrypted Data Packet] (contains compressed message)

Provides:

  • Confidentiality: Via symmetric encryption of message.

  • Authentication: Via digital signature.

  • Integrity: Via signature/hash.

4.2 Transport Layer Security: SSL/TLS

SSL Record Protocol Services:

  • Confidentiality: Using symmetric encryption (AES, 3DES).

  • Integrity: Using MAC (HMAC-SHA256) or AEAD (AES-GCM).

  • Authentication: Optional, using digital certificates (X.509).

SSL Handshake Protocol (Simplified TLS 1.2):

  1. ClientHello: Client sends supported cipher suites, TLS version, random Client.random.

  2. ServerHello: Server selects cipher suite, sends TLS version, random Server.random, and Server Certificate (containing server's public key).

  3. ServerHelloDone: Server indicates hello phase done.

  4. Client Key Exchange:

    • Client verifies server certificate.

    • Client generates pre-master secret.

    • Encrypts pre-master secret with server's public key (from cert) and sends.

  5. Both Compute Master Secret: Using Client.random, Server.random, and pre-master secret via PRF.

  6. Key Derivation: Master Secret → symmetric session keys (client write MAC key, server write MAC key, client write encryption key, server write encryption key).

  7. Change Cipher Spec: Both sides send message to switch to encrypted communication.

  8. Finished: Both send encrypted "Finished" message (hash of all handshake messages) to verify handshake integrity.

SSL Connection vs SSL Session:

  • SSL Session: Established during handshake. Contains:

    • Session ID

    • Peer's certificate

    • Compression method

    • Master Secret

    • Cipher spec

    • Can be resumed later (Session Resumption) to avoid full handshake.

  • SSL Connection: Specific association between client and server providing a secure service. Uses keys derived from a session. Multiple connections can reuse one session.

[!TIP] Exam Focus: Know the handshake steps (ClientHello, ServerHello/Cert, Key Exchange, Finished). Session resumption is a key optimization.

4.3 Network Layer Security: IPsec

Two Main Protocols:

  • AH (Authentication Header): Provides data origin authentication, integrity, and anti-replay. Does NOT provide confidentiality. Protects IP payload + selected IP header fields.

  • ESP (Encapsulating Security Payload): Provides confidentiality (encryption), data origin authentication, integrity, and anti-replay. Protects IP payload (and optionally trailer). Can operate in two modes.

Modes of Operation:

Mode Operation Use Case AH/ESP Protection Scope
Transport Mode Original IP header is preserved. ESP/AH trailer inserted after payload. Host-to-Host (e.g., two servers). ESP: Encrypts & authenticates transport layer segment (TCP/UDP). AH: Authenticates payload + selected IP header fields.
Tunnel Mode Original IP packet is encapsulated inside a new IP packet. New outer header. Gateway-to-Gateway (site-to-site VPN) or Host-to-Gateway. ESP: Encrypts & authenticates the entire original IP packet. AH: Authenticates entire original IP packet + outer header (selected fields).

Example (ESP Tunnel Mode for Site-to-Site VPN):


[New Outer IP Hdr (Gateway A → Gateway B)] [ESP Hdr] [Orig IP Hdr] [Orig TCP/UDP] [ESP Trail] [ESP Auth]

The original packet is invisible to intermediate routers.

4.4 E-commerce Security: SET (Secure Electronic Transaction)

Security Issues in Online Transactions:

  • Confidentiality: Card details exposed.

  • Integrity: Order tampering.

  • Authentication: Merchant/customer/bank identity.

  • Non-repudiation: Customer denying order; merchant denying charge.

SET Protocol Overview:

  • Participants: Cardholder, Merchant, Issuer (cardholder's bank), Acquirer (merchant's bank), Payment Gateway, Certification Authorities.

  • Key Features:

    1. Dual Signature: Customer signs two separate messages (order info & payment info) with one signature. Links them without revealing payment info to merchant or order info to bank.

    2. Certificate-based: All parties have X.509 certificates.

    3. Confidentiality: Payment info (card number) encrypted with merchant's public key (for bank) and payment gateway's public key.

    4. Integrity: All messages signed.

  • Business Environment: Enables secure credit card transactions over open networks (Internet). Separates order and payment flows.

[!TIP] Comparison: SET is complex and rarely used today (replaced by simpler TLS + PCI-DSS compliance). PGP is for email; SSL/TLS is for web traffic; SET was specifically for credit card payments.

4.5 Wireless Security

WLAN Security Challenges:

  • Open Medium: Radio signals propagate beyond physical boundaries.

  • No Physical Control: Attacker can be anywhere within range.

  • Resource Constraints: Devices (IoT) have limited power/compute.

  • Legacy Protocols: WEP is broken.

WAP (Wireless Application Protocol) Architecture & Security:

  • Goal: Provide Internet access to mobile devices (phones) over wireless networks (GSM, CDMA).

  • Layered Model: WAE (Application), WSP (Session), WTP (Transaction), WTLS (Security), WDP (Transport - over UDP, SMS, etc.).

  • WTLS (Wireless Transport Layer Security): Based on TLS but optimized for wireless.

    • Optimizations: Smaller packet size, faster handshake, support for datagram (like DTLS), optional client certs.

    • Security Issues: Early WTLS had vulnerabilities (like SSL 2.0). Compression before encryption was weak. Modern systems use TLS directly.

Access Point Security in Public Networks (e.g., Coffee Shop Wi-Fi):

  • Open Authentication: No password, but traffic is unencrypted (unless application-layer encryption like HTTPS used).

  • Captive Portal: User must authenticate via web page (often just terms acceptance) before gaining Internet access. Does not encrypt traffic between client and AP.

  • Risk: Man-in-the-Middle attacks, eavesdropping on unencrypted traffic.

  • Mitigation: Always use VPN over public Wi-Fi. Use HTTPS.

WLAN Protocol Stack & MPDU Format (IEEE 802.11):

  • Stack: LLC (Logical Link Control) → MAC (802.11) → PHY (e.g., OFDM).

  • MAC Frame (MPDU) Format:

    
    [MAC Header] [Frame Body (LLC PDU)] [FCS (CRC)]
    
    
    • MAC Header Fields: Frame Control, Duration, Addr1 (Receiver), Addr2 (Transmitter), Addr3 (BSSID/Source), Sequence Control, Addr4 (for mesh), QoS Control, HT Control.

    • Frame Body: Contains LLC PDU (typically IP packet).

    • FCS: 32-bit CRC for error detection.


5. Network Security Infrastructure

5.1 Intrusion Detection Systems (IDS)

Definition: Device/software that monitors network or system activities for malicious actions or policy violations.

Type Focus Placement Example
HIDS (Host-based) Single host (OS, logs, file integrity). Agent on critical servers/workstations. OSSEC, Wazuh, Windows Event Log monitoring.
NIDS (Network-based) Network traffic (packets, flows). Strategic network points (DMZ, backbone). Snort, Suricata, Zeek (Bro).

Detection Techniques:

  • Signature-based (Parameter Pattern Matching):

    • Compare traffic/events against database of known attack signatures (patterns).

    • Pros: Low false positives, effective for known attacks.

    • Cons: Cannot detect zero-day or novel attacks. Requires constant signature updates.

  • Anomaly-based:

    • Build baseline of "normal" behavior. Flag deviations.

    • Pros: Can detect unknown attacks.

    • Cons: High false positives, difficult to define "normal".

[!TIP] Exam Distinction: IDS detects and alerts. IPS (Intrusion Prevention System) can actively block traffic. NIDS sees entire network segment; HIDS sees host internals.

5.2 Firewalls

Definition: Network security device that enforces access control policies between trusted and untrusted networks.

Classification:

Type Layer Operation Example
Packet Filtering Network/Transport (IP, Port) Stateless inspection of packet headers (src/dst IP, port, protocol). Allow/deny rules. iptables (Linux), router ACLs.
Circuit-level Gateway Session (TCP) Monitors TCP handshake (SYN, SYN-ACK, ACK). Verifies legitimate session. Hides internal IPs. SOCKS proxy.
Application-level Gateway (Proxy) Application (HTTP, FTP, SMTP) Intercepts and inspects entire application layer traffic. Acts as intermediary. Can filter content. Web proxy (Squid), mail proxy.
Stateful Inspection Network/Transport Tracks state of connections (connection table). Allows return traffic only for established connections. Modern stateful firewalls (Cisco ASA, Palo Alto).
Personal Firewall Host Software firewall on individual endpoint. Controls inbound/outbound per application. Windows Defender Firewall, Little Snitch.

Merits:

  • First line of defense.

  • Controls access based on policy.

  • Hides internal network structure (NAT).

  • Logs traffic for audit.

Demerits:

  • Cannot inspect encrypted traffic (without decryption/SSL inspection).

  • Cannot prevent attacks from inside the trusted network.

  • Complex rule management; misconfiguration creates holes.

  • Limited protection against application-layer attacks (unless proxy).

5.3 Virtual Private Networks (VPN)

Definition: Creates a secure, encrypted "tunnel" over a public network (Internet) to connect remote users or networks.

Types:

  • Remote Access VPN: Individual user → corporate network. Uses protocols like IPsec (IKEv2) or SSL/TLS (OpenVPN, AnyConnect).

  • Site-to-Site VPN: Connects two networks (e.g., branch offices). Primarily uses IPsec in tunnel mode.

Security Architecture:

  1. Tunneling: Encapsulating original IP packet in new packet.

  2. Encryption: Confidentiality (AES, 3DES).

  3. Authentication: Pre-shared keys (PSK) or digital certificates.

  4. Integrity: HMAC (SHA-1, SHA-256).

  5. Key Management: IKE (Internet Key Exchange) Phase 1 (authenticate peers, establish IKE SA) & Phase 2 (negotiate IPsec SA for data).

Comparison with Trusted Operating Systems:

Feature VPN Trusted OS (e.g., SELinux, Trusted Solaris)
Scope Network-level security (links). Host-level security (single system).
Mechanism Encryption, tunneling, authentication. Mandatory Access Control (MAC), security policies, reference monitors.
Goal Secure communication channel over untrusted network. Enforce strict security policy on a single, high-assurance system.
Use Case Remote workers, inter-office connectivity. Military, government systems requiring high assurance.

5.4 Trusted Operating Systems

  • Concept: OS designed with security as primary goal, implementing reference monitor concept (mediates all access, tamper-proof, verifiable).

  • Security Features:

    • Mandatory Access Control (MAC): Labels (e.g., Top Secret, Secret) enforced by kernel. Users cannot override.

    • Security Policy: Formal, enforceable model (e.g., Bell-LaPadula - confidentiality, Biba - integrity).

    • Trusted Path: Secure communication channel between user and Trusted Computing Base (TCB).

    • Auditing: Comprehensive, tamper-evident logs.

    • Isolation: Processes/domains strictly separated.


6. Malware and Threat Management

6.1 Types of Malicious Software

Type Definition Propagation Primary Goal
Virus Code that attaches to legitimate program/file. Requires user execution. Human action (run infected file). Corrupt, delete, steal data.
Worm Self-replicating, standalone program. Exploits vulnerabilities to spread autonomously. Network (SMB, email, web). Consume bandwidth, create botnets, drop payloads.
Trojan Horse Disguised as legitimate software. Does not self-replicate. Social engineering (download/install). Provide backdoor, steal data, spy.
Ransomware Encrypts victim's files/drives. Demands ransom for decryption key. Phishing, exploit kits, RDP brute-force. Financial extortion.
Spyware/Adware Secretly monitors user activity, collects data, displays ads. Bundled with software, drive-by download. Data theft, revenue from ads.
Rootkit Hides existence/activities of other malware. Modifies OS/kernel. Often installed by other malware. Maintain stealthy, persistent access.
Bot/Botnet Compromised host under remote control (C&C). Worm/virus/trojan. DDoS attacks, spam, crypto-mining.

6.2 Protection Mechanisms: Role of IDS & Firewalls

  • Firewalls:

    • Preventative: Block known malicious IPs/ports (e.g., block outbound to C&C servers).

    • Limit Propagation: Segment network (DMZ, internal VLANs) to contain outbreaks.

    • Logging: Detect unusual outbound traffic from infected hosts.

  • IDS/IPS:

    • Detection: Signature-based IDS detects known malware traffic patterns (e.g., specific worm propagation attempts).

    • Anomaly-based: Detects unusual traffic volume (worm) or beaconing (C&C communication).

    • Prevention (IPS): Can block malicious packets/connections in real-time (e.g., block exploit kit download).

  • Limitation: Primarily effective against network-based propagation and command/control. Less effective against user-executed trojans or insider threats.

6.3 General Security Considerations and Threats

  • Defense-in-Depth: Layered security (firewall, IDS, AV, patching, training).

  • Patch Management: Unpatched vulnerabilities are primary infection vector.

  • Least Privilege: Users/apps run with minimal necessary permissions.

  • User Awareness: Phishing is top infection vector. Train users.

  • Backup & Recovery: Critical for ransomware resilience.

  • Threat Intelligence: Subscribe to feeds for IOCs (Indicators of Compromise).


7. Additional Security Topics

7.1 Web Traffic Security Approaches

Protocol Layer Encryption Port Use
HTTPS Application (HTTP over TLS) TLS (SSL) 443 Secure web browsing (dominant).
SHTTP Application Symmetric key per message 443 Rare. Negotiates security per message.
SSL/TLS Transport (between app & transport) TLS N/A Underlying protocol for HTTPS, SMTPS, etc.

[!TIP] Modern Standard: TLS 1.2/1.3. SSL 2.0/3.0 are deprecated and insecure.

7.2 Parameter Pattern Matching (Detailed)

  • Definition: Technique used primarily in signature-based IDS/IPS and anti-virus.

  • Process:

    1. Signature Creation: Analyze known attack (e.g., buffer overflow exploit). Identify unique byte sequence ("pattern") in network packet or file.

    2. Pattern Storage: Store pattern in database, often with metadata (attack ID, severity).

    3. Scanning: For each packet/file, scan payload for occurrence of any stored pattern.

    4. Matching: If pattern found → alert/block.

  • Challenges:

    • Evasion: Attackers obfuscate payload (polymorphism, metamorphism, encoding, fragmentation).

    • Performance: Deep packet inspection is CPU-intensive at high speeds.

    • False Positives: Legitimate traffic matching pattern.

  • Example (Snort Rule): alert tcp any 80 -> any any (content:"|90 90 90 90|"; msg:"NOP sled detected";)

    • Looks for sequence of four No-Operation (NOP) instructions, common in buffer overflow exploits.

7.3 Smart Cards and Biometrics Integration

  • Architecture: Biometric sensor → feature extraction → on-card matching (template stored on card) → if match, card releases private key/certificate.

  • Security Benefits:

    • Two-Factor: Possession (card) + Inherence (biometric).

    • Template Privacy: Template never leaves card; no central biometric DB.

    • Replay Protection: Biometric is live; cannot reuse stolen template without liveness detection.

    • Non-repudiation: Private key is only released after biometric verification, binding user to transaction.

  • Applications: High-security physical access (data centers), national ID cards (e.g., India's Aadhaar, e-passports), corporate login.


8. Practical Examples & Problem Solving (Key Formulas)

8.1 Caesar Cipher Decryption

Given: Ciphertext ZICVTWQNGRZGVTWAVZHCQYGLMGJ, Shift k=17. Decryption: $$\displaystyle P = (C - k) \mod 26 $$

  • Convert letters to numbers (A=0, B=1, ..., Z=25).

  • Z(25) → (25-17)=8 → I

  • I(8) → (8-17)=-9 mod26=17 → R

  • Continue for all letters. Result: RETURNWITHOUTPERILALLWILLBEWELL (or similar phrase; verify).

8.2 RSA with Small Primes (p=3, q=11)

  • $$\displaystyle n = 33 $$, $$\displaystyle \phi(n)=20 $$.

  • Choose $$\displaystyle e=7 $$ (gcd(7,20)=1).

  • $$\displaystyle d = e^{-1} \mod 20 = 3 $$.

  • Encrypt $$\displaystyle P=15 $$: $$\displaystyle C = 15^7 \mod 33 = 170859375 \mod 33 = 9 $$.

  • Decrypt $$\displaystyle C=9 $$: $$\displaystyle P = 9^3 \mod 33 = 729 \mod 33 = 15 $$.

8.3 RC4 Key Stream Generation (5-bit key 10101 = 21)

  1. KSA: Initialize S=[0,1,...,255]. Key K = [21,21,21,21,21] (repeat).

    
    for i=0 to 255:
    
        j = (j + S[i] + K[i mod 5]) mod 256
    
        swap(S[i], S[j])
    
    
  2. PRGA (First 3 bytes):

    • i=0, j=S[0]=0 → j=(0+0+21)=21 → swap(S[0],S[21]). S[0]=21, S[21]=0. t=(21+0)=21 → K1=S[21]=0.

    • i=1, j=(21+S[1]=1+21)=22 → swap(S[1],S[22]). t=(S[1]+S[22]) → compute. K2=...

    • i=2, ... → K3=...

    • Example Output: First 3 bytes might be [0x3A, 0x5F, 0x1C] (actual depends on full KSA).

8.4 SHA-512 Message Digest

  • Pre-processing: Pad message to 1024-bit multiple. Append 128-bit length.

  • Initialize H: 8 constants (64-bit each) from sqrt(2..9).

  • For each 1024-bit block:

    • Prepare 80 words (64-bit) W[0..79].

    • W[t] = σ1(W[t-2]) + W[t-7] + σ0(W[t-15]) + W[t-16] for t=16..79.

    • a..h = H0..H7.

    • For t=0 to 79:

      • T1 = h + Σ1(e) + Ch(e,f,g) + K[t] + W[t]

      • T2 = Σ0(a) + Maj(a,b,c)

      • (h,g,f,e,d,c,b,a) = (g,f,e,d+T1,c,b,a,T1+T2)

    • H_i = H_i + corresponding var.

  • Output: H0 || H1 || ... || H7 (512 bits).

8.5 SSL Handshake Step-by-Step

  1. ClientHello: Client lists TLS versions, cipher suites, Client.random.

  2. ServerHello: Server picks TLS version/cipher, sends Server.random, Certificate.

  3. ServerHelloDone.

  4. Client:

    • Verify server cert (chain, validity, hostname).

    • Generate pre-master secret.

    • Encrypt with server's public key → send ClientKeyExchange.

    • Compute master secret from pre-master, Client.random, Server.random.

    • Derive session keys.

    • Send ChangeCipherSpec, then encrypted Finished (hash of handshake).

  5. Server:

    • Decrypt pre-master with private key.

    • Compute same master secret and session keys.

    • Send ChangeCipherSpec, then encrypted Finished.

  6. Secure Application Data exchanged using session keys.

8.6 PGP Operations for Email Security

  1. Signing (Optional): Sig = H(Message)^(Private_Key_Sender).

  2. Session Key: Generate random symmetric key K_s.

  3. Encrypt Message: C_msg = E_{K_s}(Message).

  4. Encrypt Session Key: C_key = E_{Public_Key_Receiver}(K_s).

  5. Send: {C_key, C_msg, Sig} (or without Sig).

  6. Receiver:

    • Decrypt C_key with Private_Key_Receiver → K_s.

    • Verify Sig with Public_Key_Sender (if present).

    • Decrypt C_msg with K_s → Message.

8.7 IPSec Modes (AH/ESP Transport vs Tunnel)

  • AH Transport: Original IP header + payload authenticated. Header fields like TTL may change → integrity check fails. Rarely used.

  • ESP Transport: Payload (TCP/UDP) encrypted & authenticated. Original IP header unprotected (can be modified).

  • AH Tunnel: Entire original IP packet authenticated + new outer header.

  • ESP Tunnel: Entire original IP packet encrypted & authenticated. New outer header. Most common for VPNs.

[!TIP] Exam Question: "Explain transport and tunnel mode for ESP." Draw diagrams showing original packet inside new packet for tunnel mode; original header + ESP trailer for transport mode. Highlight what is protected (encrypted/authenticated).

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in