Skip to content
CY-503 (A) · Biometric Techniques for Security/Quick Revision Short Notes

Biometric Techniques for Security (CY-503 (A)) - Unit 4 Short Notes

UNIT 4: Network Security Protocols & Infrastructure


1.0 Cryptographic Foundations & Primitives

1.1 Symmetric Encryption

  • Principle: Same secret key K is used for both encryption (E_K(P) = C) and decryption (D_K(C) = P). Requires secure key distribution.

  • Block vs. Stream Ciphers:

    | Feature | Block Cipher | Stream Cipher | | :--- | :--- | :--- | | Unit | Fixed-size block (e.g., 128 bits) | Continuous stream of bits/bytes | | Operation | Operates on whole block at once | Operates on one bit/byte at a time | | Example | AES, DES | RC4 | | Error Propagation | A bit error affects entire block | A bit error affects only that bit |

  • AES (Advanced Encryption Standard):

    • Block Size: 128 bits. Key Sizes: 128, 192, 256 bits.

    • Core Steps (per round for 128-bit key):

      1. SubBytes: Non-linear substitution using S-box.

      2. ShiftRows: Cyclic shift of rows in state matrix.

      3. MixColumns: Mixing columns using matrix multiplication in GF(2⁸).

      4. AddRoundKey: XOR state with round key.

    • Final Round: Omits MixColumns.

    • Key Expansion: Round keys derived from cipher key via Rijndael's key schedule.

  • RC4 Stream Cipher:

    • Key Scheduling (KSA): Initialize S array (0-255), permute using secret key K.

    • Pseudo-Random Generation (PRGA): For each byte:

      i = (i + 1) mod 256

      j = (j + S[i]) mod 256

      Swap(S[i], S[j])

      t = (S[i] + S[j]) mod 256

      Keystream Byte = S[t]

    • Ciphertext: C = P ⊕ Keystream.

    [!TIP] Exam Focus: Be prepared to generate first few keystream bytes for a small key (e.g., 5-bit key K = [1,2,3,4,5]). Show full KSA and first 3 PRGA steps.

1.2 Asymmetric Encryption & Digital Signatures

  • Principle: Key pair: Public key (PU) for encryption/verify, Private key (PR) for decryption/sign. E_{PU}(P) = C, D_{PR}(C) = P.

  • RSA Algorithm (Detailed Steps with p=3, q=11):

    1. Key Generation:

      • Choose primes: p=3, q=11.

      • n = p * q = 33.

      • φ(n) = (p-1)(q-1) = 2 * 10 = 20.

      • Choose e s.t. 1 < e < φ(n) and gcd(e, φ(n)) = 1. Let e=7 (coprime with 20).

      • Compute d such that (d * e) mod φ(n) = 1. (d*7) mod 20 = 1 → d=3 (since 21 mod 20 = 1).

      • Public Key: (e=7, n=33). Private Key: (d=3, n=33).

    2. Encryption: C = P^e mod n. For P=2: C = 2^7 mod 33 = 128 mod 33 = 29.

    3. Decryption: P = C^d mod n. P = 29^3 mod 33 = 24389 mod 33 = 2.

  • Digital Signatures (Using Public-Key Cryptography):

    1. Signing: Sender computes S = H(Message)^d mod n (using their private key).

    2. Verification: Receiver computes S^e mod n and compares with H(Message) (using sender's public key).

    • Crucial Importance: Provides Authentication (sender is who they claim), Integrity (message not altered), and Non-Repudiation (sender cannot deny sending).

1.3 Hash Functions & Message Authentication

  • Properties of Cryptographic Hash Functions (H):

    • Fixed Output Size: e.g., SHA-512 → 512-bit digest.

    • Efficient Computation: Easy to compute H(M).

    • Pre-image Resistance: Given h, hard to find M s.t. H(M)=h.

    • Second Pre-image Resistance: Given M1, hard to find M2≠M1 s.t. H(M1)=H(M2).

    • Collision Resistance: Hard to find any M1, M2 s.t. H(M1)=H(M2).

  • SHA-512 Algorithm (High-Level Steps):

    1. Pre-processing: Pad message to multiple of 1024 bits. Append length (128 bits).

    2. Initialize Hash Values (H0..H7): First 64 bits of fractional parts of sqrt(primes 2..19).

    3. Process Message in 1024-bit Blocks: For each block, expand to 80 words W[0..79].

    4. Compression Function: Update working variables a..h using 80 rounds of operations with constants K[0..79] (from fractional parts of sqrt(primes 2..79)).

    5. Add to Hash Values: H_i = H_i + a..h (mod 2^64).

  • Message Authentication Codes (MACs):

    • Concept: Short tag generated from message M and secret key K: T = MAC_K(M). Receiver verifies T' == MAC_K(M).

    • HMAC Algorithm (Detailed):

      HMAC_K(M) = H((K⁺ ⊕ opad) ∥ H((K⁺ ⊕ ipad) ∥ M))

      where K⁺ is key padded to block size, ipad=0x36, opad=0x5C, ∥ is concatenation.

      Why HMAC? Proven secure based on underlying hash function's properties.

  • Secure Message Authentication using Hash Functions (Example):

    • Simple (Insecure): T = H(M ∥ K) vulnerable to length extension.

    • Secure (HMAC): As above. Uses two hash invocations and inner/outer pads to prevent attacks.


2.0 Secure Communication Protocols

2.1 SSL/TLS

  • SSL Record Protocol Services:

    1. Confidentiality: Using symmetric encryption (e.g., AES).

    2. Integrity: Using MAC (e.g., HMAC-SHA256).

    3. Optional Compression.

  • SSL Handshake Protocol (Step-by-Step for TLS 1.2):

    1. ClientHello: Client sends supported cipher suites, protocol version, random R_C.

    2. ServerHello: Server picks cipher suite, sends version, random R_S.

    3. Certificate: Server sends its certificate (with public key).

    4. ServerHelloDone: Server signals end of hello messages.

    5. ClientKeyExchange: Client generates premaster secret, encrypts with server's public key, sends.

    6. ChangeCipherSpec (Client): Client signals subsequent messages will be encrypted.

    7. Finished (Client): Encrypted H(handshake_messages).

    8. ChangeCipherSpec (Server) & Finished (Server): Server does the same.

    • Master Secret: Both derive master_secret = H(premaster_secret ∥ R_C ∥ R_S).
  • SSL Connection vs. SSL Session:

    • Session: Established via handshake. Stores security parameters (master secret, cipher suite). Can be resumed to avoid full handshake.

    • Connection: Actual communication channel using session parameters. Multiple connections can reuse one session.

    • Contribution to Web Security: Session resumption reduces latency and computational cost for repeated connections to same server (e.g., loading multiple images).

2.2 Pretty Good Privacy (PGP)

  • Working for Email Security:

    1. Signing (Authentication): Sender computes sig = H(Message)^d_sender. Attaches to message.

    2. Encryption (Confidentiality):

      • Generate random session key K_s.

      • Encrypt message with symmetric cipher (e.g., CAST-128): C = E_{K_s}(M).

      • Encrypt K_s with recipient's public key: K_s' = E_{PU_recipient}(K_s).

      • Send (K_s' ∥ C ∥ sig).

    3. Decryption: Recipient uses PR_recipient to get K_s, decrypts C, verifies sig using sender's public key.

  • General Format of a PGP Message:

    
    [Tag: PKESK (Public-Key Encrypted Session Key)]
    
    [Tag: SKESK (Symmetric-Key Encrypted Session Key) - optional]
    
    [Tag: SIGNATURE]
    
    [Tag: LITERAL DATA (the encrypted message)]
    
    
    DiagramCANVAS: A block diagram showing PGP message structure with labeled fields: Version, Signature, Session Key Encrypted with Recipient's PK, Symmetrically Encrypted Data, and Literal Data Packet.

2.3 IP Security (IPSec)

  • Authentication Header (AH):

    • Provides data origin authentication, integrity, and anti-replay.

    • Does NOT provide confidentiality.

    • Transport Mode: AH protects payload of original IP packet. [Original IP Header (mutable fields=0) ∥ AH ∥ TCP/UDP ∥ Data].

    • Tunnel Mode: AH protects entire original IP packet. [New IP Header ∥ AH ∥ Original IP Header ∥ TCP/UDP ∥ Data]. Used for gateway-to-gateway (VPN).

  • Encapsulating Security Payload (ESP):

    • Provides confidentiality, data origin authentication, integrity, and anti-replay.

    • Transport Mode: [Original IP Header (mutable fields=0) ∥ ESP Header ∥ ESP Trailer ∥ ESP Auth ∥ TCP/UDP ∥ Data].

    • Tunnel Mode: [New IP Header ∥ ESP Header ∥ ESP Trailer ∥ ESP Auth ∥ Original IP Header ∥ TCP/UDP ∥ Data].

  • IPSec as a Framework: AH and ESP are two separate protocols. Can be used independently or together (e.g., ESP with auth only, or ESP with both encryption & auth). Security Association (SA) is a one-way connection defined by SPI, IP destination, and security protocol (AH/ESP).


3.0 Network Security Infrastructure & Mechanisms

3.1 Intrusion Detection Systems (IDS)

  • Intrusion: Any set of actions that attempt to compromise the confidentiality, integrity, or availability of a resource.

  • Classification:

    | Feature | Host-based IDS (HIDS) | Network-based IDS (NIDS) | | :--- | :--- | :--- | | Location | On individual host/endpoint | On network segments (sensors) | | Data Source | System logs, file integrity, process activity | Network packets (traffic) | | Detection | Insider threats, file changes, policy violations | External attacks, DoS, scanning | | Diagram |

    DiagramSEARCH: host-based IDS architecture agent on host sending logs to manager
    |
    DiagramSEARCH: network-based IDS sensor on network segment analyzing traffic
    | | Example | OSSEC, Wazuh | Snort, Suricata |

3.2 Firewalls

  • Classification/Types:

    1. Packet Filtering Firewall:

      • Operates at Network Layer (OSI L3).

      • Examines header fields (IP src/dst, port, protocol).

      • Uses ACL (Access Control List) rules: ALLOW/DENY [src_ip] [dst_ip] [port] [protocol].

      • Merits: Fast, transparent, low cost.

      • Demerits: No payload inspection, susceptible to IP spoofing, complex rule management.

    2. Circuit-Level Gateway:

      • Operates at Session Layer (OSI L5).

      • Monitors TCP handshake (SYN, SYN-ACK, ACK) to validate sessions.

      • Hides internal network addresses (NAT-like).

      • Merit: Simple, good for outbound control.

      • Demerit: No inspection of data within session.

    3. Application-Level Gateway (Proxy Firewall):

      • Operates at Application Layer (OSI L7).

      • Intercepts all traffic for specific application (HTTP, FTP). Acts as intermediary.

      • Performs deep packet inspection and protocol validation.

      • Merits: Highest security, detailed logging, user authentication.

      • Demerits: Performance bottleneck, must support each application, expensive.

  • Role of IDS & Firewalls Against Malware:

    • Firewall: Blocks unauthorized connections/ports (preventative). Can block known malicious IPs/domains.

    • IDS: Detects malware activity (e.g., beaconing, exploit traffic, policy violation). Does not block (unless IPS). Provides alerts and forensic data.

    • Complementary: Firewall reduces attack surface; IDS detects what gets through or originates internally.

3.3 Virtual Private Networks (VPN)

  • What is a VPN? A tunnel over a public network (Internet) that provides confidentiality, authentication, and integrity for private traffic, making it appear as if hosts are on a private network.

  • Types of VPNs:

    • Remote Access VPN: Individual user → corporate network (e.g., employee from home). Uses protocols like PPTP, L2TP/IPsec, SSL-VPN.

    • Site-to-Site (Gateway-to-Gateway) VPN: Connects entire networks (e.g., branch offices). Uses IPsec or GRE.

  • Comparison with Trusted Operating Systems:

    | Aspect | VPN | Trusted OS (e.g., SELinux, Trusted Solaris) | | :--- | :--- | :--- | | Primary Goal | Secure communication channel over untrusted network. | Secure individual host/system via mandatory access control (MAC). | | Security Scope | Network/Transport layer (tunneling). | OS/Kernel level (process, file, resource access). | | Key Mechanism | Encryption (IPsec, SSL), Tunneling. | Security policy, labels, reference monitor. | | Application | Connect remote users/sites. | Protect high-security servers, prevent insider threats. | | Example | Cisco AnyConnect, OpenVPN. | SELinux enforcing mode, Microsoft Windows Integrity Mechanism. |

3.4 Malicious Software (Malware)

  • Types & Infiltration Methods:

    | Malware Type | Core Behavior | Infiltration/Propagation | | :--- | :--- | :--- | | Virus | Attaches to legitimate program/file. Requires user execution. | Email attachments, infected USB, downloads. | | Worm | Self-replicating, spreads autonomously over network. | Exploits vulnerabilities (e.g., SMB), email, P2P. | | Trojan Horse | Disguised as legitimate software. Contains hidden malicious function. | Social engineering, fake downloads, cracked software. | | Rootkit | Hides existence/activities of other malware. Deep OS integration. | Exploits, trojans, phishing. | | Ransomware | Encrypts files, demands ransom. | Phishing, exploit kits, RDP brute-force. | | Spyware/Adware | Collects user data/displays ads. | Bundled with freeware, drive-by downloads. | | Bot/Botnet | Compromised host under remote control (C&C). | Worm/virus/trojan infection, then join botnet. |

  • IDS/Firewall Safeguarding:

    • Firewall: Blocks command-and-control (C&C) callbacks (known bad IPs/domains), prevents worm propagation by blocking exploit ports.

    • IDS: Detects anomalous traffic patterns (e.g., mass emailing from virus, worm scanning, C&C communication). Signature-based IDS can detect known malware payloads.


4.0 Wireless & Mobile Security

4.1 Wireless LAN (WLAN) Security

  • Security Challenges:

    • Open Medium: Radio signals propagate beyond physical boundaries.

    • No Physical Control: Attacker can be anywhere within range.

    • Weak/default Configurations: Often overlooked.

    • Eavesdropping: Easy to capture traffic.

    • Rogue Access Points: Unauthorized APs inside network.

    • Client Misassociation: Clients connecting to evil twin APs.

  • WLAN Security Mechanisms:

    • WEP (Wired Equivalent Privacy): Broken. Uses RC4 with static key. IV reuse → key recovery.

    • WPA/WPA2/WPA3:

      • WPA (TKIP): Temporary fix. Per-packet key mixing, MIC.

      • WPA2 (CCMP/AES): Mandatory for Wi-Fi certification. Uses AES in CCM mode (confidentiality+integrity). Still vulnerable to KRACK (key reinstallation attack).

      • WPA3 (SAE - Simultaneous Authentication of Equals): Replaces PSK with Dragonfly handshake. Provides forward secrecy and resistance to offline dictionary attacks.

    • 802.1X (Port-Based Network Access Control):

      • Framework: Supplicant (client) → Authenticator (AP) → Authentication Server (RADIUS).

      • Process: EAPOL (EAP over LAN) frames. Authenticator blocks port until supplicant authenticated.

      • Provides individual user authentication (vs. pre-shared key for all).

  • Access Point Security in Public Networks:

    • Use Enterprise WPA2/WPA3 with 802.1X. Avoid open or WPA2-Personal (PSK) hotspots.

    • Client-Side: Use VPN for all traffic. Ensure OS firewall enabled. Disable auto-connect.

    • AP Configuration: Use strong RADIUS backend, disable WPS, use separate guest VLAN.

4.2 Wireless Application Protocol (WAP) Security

  • WAP Architecture (Layered):

    
    Application Layer (WAE - Wireless Application Environment)
    
    Session Layer (WSP - Wireless Session Protocol)
    
    Transaction Layer (WTP - Wireless Transaction Protocol)
    
    Security Layer (WTLS - Wireless Transport Layer Security)
    
    Transport Layer (WDP - Wireless Datagram Protocol) → underlying bearers (SMS, GPRS, etc.)
    
    
    DiagramCANVAS: A 5-layer stack diagram from top (WAE) to bottom (WDP), with WTLS in the middle highlighted as the security layer.
  • WTLS (Wireless Transport Layer Security):

    • Purpose: Provide security (privacy, authentication, integrity) for WAP traffic over unreliable wireless bearers (high latency, low bandwidth).

    • Based on TLS 1.1 but optimized: Handles datagram (UDP-like) nature of WDP. Smaller record sizes, optional retransmission.

    • Key Features: Supports cryptographic algorithms suitable for constrained devices (e.g., RSA, DSA, HMAC, RC5, DES, 3DES, AES). Supports session resumption.

  • Role in Securing Wireless Comms: WTLS secures the wireless leg (handset to WAP gateway). However, the gateway decrypts WTLS and re-encrypts with standard TLS/TCP for the wired Internet. This creates a decryption point.

  • Security Issues/Challenges in WTLS:

    1. WTLS-to-TLS Gap: Traffic is decrypted at the WAP gateway. If gateway is compromised, end-to-end security is broken.

    2. Algorithm Limitations: Early implementations used weak crypto (e.g., 40-bit RC5) for export compliance.

    3. Implementation Flaws: Vulnerabilities in gateway software.

    4. End-to-End Problem: WTLS does not provide true end-to-end security between client and final web server; it's hop-by-hop to the gateway.


5.0 Specialized Security Applications

5.1 Secure Electronic Transaction (SET)

  • Main Security Concerns in Online Financial Transactions:

    • Confidentiality: Cardholder data (PAN) must not be exposed to merchant.

    • Integrity: Order and payment info must not be altered.

    • Authentication: Customer, merchant, and bank must authenticate each other.

    • Non-Repudiation: Customer cannot deny placing order; merchant cannot deny received payment.

  • How SET Addresses These Concerns:

    1. Dual Signature: Customer signs a hash of Order Info + Payment Info together. Merchant sees order, bank sees payment. Neither gets both.

    2. Three-Party Model: Customer, Merchant, Bank (Acquirer & Issuer via payment gateway).

    3. Certificates: All parties have X.509 v3 certificates.

    4. Key Exchange: Uses symmetric key for transaction (efficiency) encrypted with public keys.

  • Application in Business Environment (Example):

    • Customer: browses merchant site, places order. Uses SET wallet software. Generates dual signature.

    • Merchant: Receives order info, dual signature. Forwards payment info (encrypted for bank) and dual signature to payment gateway.

    • Bank (Issuer): Verifies customer's certificate and signature. Authorizes payment. Sends confirmation to merchant via gateway.

    • Merchant: Fulfills order upon receiving bank confirmation.

    • Outcome: Customer's card number never revealed to merchant. Bank authenticates customer directly.

5.2 Biometric Authentication

  • Principles: Use of unique, measurable biological or behavioral characteristics for automated recognition.

  • Process (Generic):

    1. Enrollment: Capture raw biometric → extract feature vector → store in database (often as template, not raw image).

    2. Live Capture: Capture new sample.

    3. Feature Extraction: Extract feature vector from live sample.

    4. Matching: Compare live feature vector against stored template(s). Compute similarity score.

    5. Decision: If score > threshold → accept; else → reject.

  • Types:

    • Physiological: Fingerprint, Iris, Face, DNA, Hand geometry.

    • Behavioral: Voice, Signature dynamics, Keystroke dynamics, Gait.

  • Key Metrics:

    • False Acceptance Rate (FAR): Probability of accepting impostor.

    • False Rejection Rate (FRR): Probability of rejecting genuine user.

    • Equal Error Rate (EER): Point where FAR=FRR. Lower EER = better system.

  • Context with Smart Cards: Often used in two-factor authentication: "something you have" (smart card) + "something you are" (biometric). Biometric template can be stored on smart card (personalization) or in central database.


6.0 Web & Application Layer Security Approaches

6.1 Web Traffic Security

  • General Approaches:

    1. SSL/TLS: De facto standard for securing HTTP (HTTPS). Provides end-to-end encryption between browser and web server.

    2. VPN (SSL-VPN, IPsec): Secures entire IP traffic, including web, from remote client to corporate network gateway.

    3. Application-Layer Gateways/Proxies: Reverse proxies (e.g., for DDoS protection, WAF) that terminate and re-encrypt TLS.

    4. HTTP Strict Transport Security (HSTS): Forces browser to use HTTPS only.

    5. Secure Cookies: Secure and HttpOnly flags.

6.2 Parameter Pattern Matching

  • Concept: A signature-based detection technique, often used in Web Application Firewalls (WAFs) and Intrusion Prevention Systems (IPS).

  • How it works:

    1. Define patterns (regular expressions, byte sequences) that characterize known attacks (e.g., SQL injection: ' OR 1=1--, XSS: <script>).

    2. Inspect HTTP request parameters (GET/POST data, cookies, headers) for these patterns.

    3. If a match is found → block request and log event.

  • Limitations: Easily evaded by obfuscation (e.g., UNION/**/SELECT), encoding (URL, HTML, Unicode), or zero-day attacks (no known pattern). Requires constant signature updates.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in