UNIT 5: Advanced Security Mechanisms (including Biometrics)
I. Cryptographic Foundations
Symmetric vs Asymmetric Encryption
| Feature | Symmetric Encryption | Asymmetric Encryption |
|---|---|---|
| Key Usage | Same secret key for encryption & decryption | Public key (encrypt) & Private key (decrypt) |
| Speed | Fast (Hardware efficient) | Slow (Computationally intensive) |
| Key Distribution | Major challenge (Secure channel needed) | Easy (Public key can be shared openly) |
| Purpose | Confidentiality | Confidentiality, Authentication, Non-repudiation |
| Examples | AES, DES, RC4, 3DES | RSA, ECC, Diffie-Hellman |
| Key Length | 128, 256 bits | 1024, 2048, 3072 bits (RSA) |
[!TIP] Exam often asks for a comparison table. Remember: Symmetric solves speed, Asymmetric solves key distribution.
Block Ciphers (AES) & Stream Ciphers (RC4)
-
Block Cipher (AES):
-
Operates on fixed-size blocks (128 bits).
-
Uses multiple rounds (10/12/14 for 128/192/256-bit keys) of substitution, permutation, mixing.
-
Modes of Operation (see next section) are required to encrypt data longer than one block.
-
-
Stream Cipher (RC4):
-
Generates a pseudo-random keystream from a secret key.
-
Encrypts by XORing plaintext with keystream byte-by-byte.
-
Vulnerable if keystream reused (e.g., WEP).
-
RC4 Pseudo-Random Generation (KSA & PRGA):
-
KSA (Key-Scheduling Algorithm): Initialize S-box (0-255), permute using key.
-
PRGA (Pseudo-Random Generation Algorithm): For each byte
i:j = (j + S[i]) mod 256; swapS[i]&S[j]; outputK = S[(S[i] + S[j]) mod 256].
Example (5-bit key, e.g.,
10101= 21): First 3 bytes depend on KSA output. Initial S = [0,1,...,255]. After KSA with key, run PRGA first 3 iterations to get keystream bytes. -
-
Modes of Operation for Block Ciphers
| Mode | How it Works | Merits | Demerits |
|---|---|---|---|
| ECB<br>(Electronic Codebook) | Each plaintext block encrypted independently. | Simple, parallelizable. | Identical plaintext blocks → identical ciphertext (pattern leakage). Insecure. |
| CBC<br>(Cipher Block Chaining) | C_i = E_K(P_i ⊕ C_{i-1}), C_0 = IV. |
Hides patterns, widely used (TLS, IPSec). | Sequential (not parallelizable), error propagation, IV must be unpredictable. |
| CFB<br>(Cipher Feedback) | Turns block cipher into stream cipher. C_i = P_i ⊕ E_K(C_{i-1}). |
No padding needed, works on smaller units (bits/bytes). | Error propagates for s bits, sequential. |
| OFB<br>(Output Feedback) | Generates keystream independent of plaintext/ciphertext. O_i = E_K(O_{i-1}), C_i = P_i ⊕ O_i. |
Error doesn't propagate, keystream can be precomputed. | If keystream reused → catastrophic break. |
| CTR<br>(Counter) | `C_i = P_i ⊕ E_K(IV | counter_i)`. |
Public Key Cryptography: RSA Algorithm (Example)
Steps:
-
Key Generation:
-
Choose primes
p, q. Computen = p*q,φ(n) = (p-1)(q-1). -
Choose
esuch that1 < e < φ(n)andgcd(e, φ(n)) = 1. -
Compute
dsuch thatd*e ≡ 1 mod φ(n). -
Public Key:
(e, n), Private Key:(d, n).
-
-
Encryption:
C = M^e mod n -
Decryption:
M = C^d mod n
Example (p=3, q=11):
n = 33,φ(n) = 20. Choosee=7(gcd(7,20)=1). Findd:7d ≡ 1 mod 20→d=3(since 21 mod 20 = 1).
Encrypt
M=2:C = 2^7 mod 33 = 128 mod 33 = 29.
Decrypt
C=29:M = 29^3 mod 33 = 24389 mod 33 = 2. ✔️
Hash Functions & SHA-512
-
Purpose: Produce fixed-size message digest (hash) from arbitrary input. Properties: Deterministic, Fast, Pre-image resistant, Second pre-image resistant, Collision resistant.
-
SHA-512 Steps (Simplified):
-
Pre-processing: Pad message to multiple of 1024 bits (append
1, zeros, 128-bit length). -
Initialize Hash Values (H0-H7): Eight 64-bit constants from fractional parts of sqrt(primes).
-
Process Message in 1024-bit Blocks:
-
Break block into 16 × 64-bit words (
W[0..15]). -
Extend to 80 words (
W[t] = σ1(W[t-2]) + W[t-7] + σ0(W[t-15]) + W[t-16]for t=16..79). -
Initialize working variables
a..h = H0..H7. -
80 rounds of compression:
T1 = h + Σ1(e) + Ch(e,f,g) + K[t] + W[t];T2 = Σ0(a) + Maj(a,b,c); updateh=g, g=f, f=e, e=d+T1, d=c, c=b, b=a, a=T1+T2. -
Update hash:
H_i = H_i + variable_i.
-
-
Output: Concatenate final
H0..H7→ 512-bit digest.
-
-
Collision Resistance: Finding any two different inputs
M1 ≠ M2such thatHash(M1) = Hash(M2)should be computationally infeasible. Brute-force requires ~2^(n/2) operations (Birthday Paradox).
Message Authentication Codes (MACs) & HMAC
-
MAC: Short tag generated from message + secret key. Provides integrity and authentication.
-
HMAC (Hash-based MAC):
-
HMAC(K, M) = Hash((K ⊕ opad) || Hash((K ⊕ ipad) || M)) -
ipad = 0x36repeated,opad = 0x5Crepeated. -
Why secure? Inner/outer hash prevents extension attacks if underlying hash is weak.
-
Steps:
-
Pad key
Kto block size (e.g., 64 bytes for SHA-256) with zeros. -
Compute
K ⊕ ipad, append messageM, hash →inner. -
Compute
K ⊕ opad, appendinner, hash → final HMAC.
-
-
II. Authentication Mechanisms
Digital Signatures
-
Process:
-
Signing: Sender computes
Sig = Hash(Message)^d_S mod n_Susing their private key. -
Verification: Receiver computes
Hash(Message)andSig^e_S mod n_S. If equal → valid.
-
-
Crucial Role:
-
Authentication: Proves sender's identity.
-
Non-repudiation: Sender cannot deny sending (only they have private key).
-
Integrity: Any change in message invalidates signature.
-
Used in code signing, contracts, SSL/TLS certificates.
-
Biometric Authentication
-
Types:
-
Physiological: Fingerprint, Iris, Face, DNA, Retina.
-
Behavioral: Voice, Keystroke dynamics, Gait, Signature.
-
-
Working Principle (Generalized):
-
Enrollment: Capture raw biometric → Feature Extraction (unique template) → Template Storage (database or smart card).
-
Verification/Identification:
-
Verification (1:1): "Are you X?" Compare live sample with stored template of claimed identity.
-
Identification (1:N): "Who are you?" Compare live sample against all templates in database.
-
-
Matching: Compute similarity score between live & stored template. If score > threshold → accept.
-
-
Challenges:
-
False Accept Rate (FAR) & False Reject Rate (FRR) trade-off.
-
Non-revocability: Biometric cannot be changed if compromised.
-
Spoofing/Attacks: Fake fingerprint, voice recording.
-
Noise & Variability: Sensor noise, physiological changes (cut finger, aging).
-
Template Security: Protect stored templates (use cancellable biometrics, encryption).
-
Smart Cards & Multi-Factor Authentication
-
Smart Cards: Physical tokens with embedded chip (stores private keys, certificates). "Something you have". Often combined with PIN ("something you know") for 2FA.
-
Biometric + Smart Card: Card stores encrypted biometric template. Live biometric unlocks/decrypts template on-card → enhances security over standalone biometrics.
-
Multi-Factor Authentication (MFA): Combines ≥2 independent factors:
-
Knowledge (password, PIN)
-
Possession (smart card, OTP token, phone)
-
Inherence (biometric)
Example: ATM card (possession) + PIN (knowledge). Future: Phone (possession) + Fingerprint (inherence).
-
III. Secure Communication Protocols
Pretty Good Privacy (PGP)
-
Components & Working:
-
Key Management: Uses Web of Trust (users sign each other's keys) instead of centralized CA. Each user has:
-
Public Key Ring: Others' public keys.
-
Private Key Ring: Own private key (encrypted with symmetric passphrase).
-
Public/Private Key Pair: RSA/DSA/ECC.
-
-
Encryption for Confidentiality:
-
Generate random session key (symmetric, e.g., IDEA, AES).
-
Encrypt message with session key.
-
Encrypt session key with recipient's public key.
-
Send both encrypted session key & encrypted message.
-
-
Signing for Authentication:
-
Compute hash (SHA-256) of message.
-
Encrypt hash with sender's private key → signature.
-
Attach signature to message.
-
-
Signing + Encryption: Sign first, then encrypt both message & signature.
-
-
General PGP Message Format:
[Packet: Session Key (encrypted with recipient's PK)] [Packet: Signature (optional)] [Packet: Compressed Data (optional)] [Packet: Literal Data (actual message)]Each "packet" has a header tag, length, and body.
Secure Sockets Layer (SSL/TLS)
-
SSL Record Protocol Services:
-
Confidentiality: Using symmetric encryption (after handshake).
-
Integrity: Using MAC (HMAC) on data.
-
Encapsulation: Fragments, compresses, adds MAC, encrypts application data.
-
-
SSL Handshake Protocol (Step-by-Step):
-
ClientHello: Client sends supported cipher suites, TLS version, random
R_C. -
ServerHello: Server selects cipher suite, sends SSL/TLS version, random
R_S, Server Certificate (contains server's public key & identity). -
ServerHelloDone.
-
Client Certificate (optional): If server requests client auth.
-
ClientKeyExchange: Client generates premaster secret, encrypts with server's public key (from cert), sends to server.
-
Both compute Master Secret:
Master Secret = PRF(premaster secret, "master secret", R_C + R_S). -
Key Derivation: From Master Secret, derive session keys (client write MAC key, server write MAC key, client write encryption key, server write encryption key).
-
ChangeCipherSpec (Client & Server): Subsequent messages use derived session keys.
-
Finished (Client & Server): Send HMAC of all previous handshake messages. Verifies handshake integrity.
-
-
SSL Connection vs SSL Session:
-
Session: Established via handshake. Stores Master Secret, cipher specs, session ID. Can be resumed later (avoids full handshake).
-
Connection: Specific association between client & server for data transfer. Uses session keys derived from a session. Multiple connections can reuse one session.
-
Contribution to Web Security: Sessions enable efficient secure reconnections (e.g., browser revisits HTTPS site). Connections provide ephemeral encryption for each TCP connection.
-
IP Security (IPSec)
-
Authentication Header (AH): Provides data origin authentication & integrity (no confidentiality).
-
Transport Mode: AH protects payload of original IP packet. New IP header (from original) + AH. Used for end-to-end (host-to-host).
-
Tunnel Mode: AH protects entire original IP packet. New IP header + AH + original IP packet. Used for network-to-network (gateway-to-gateway, e.g., VPN).
-
-
Encapsulating Security Payload (ESP): Provides confidentiality, authentication, integrity.
-
Transport Mode: ESP trailer after original payload, ESP auth after trailer. Original IP header unchanged. Used for host-to-host.
-
Tunnel Mode: Entire original IP packet is ESP payload. New outer IP header + ESP (SPI, Seq#, Payload, Pad, Pad Len, Next Header, Auth). Used for gateway-to-gateway VPNs.
Key Difference: AH authenticates immutable IP header fields (except mutable ones like TTL). ESP in tunnel mode hides original IP addresses.
-
Secure Electronic Transaction (SET)
-
Security Concerns in Online Transactions:
-
Confidentiality: Cardholder data (credit card number) must be secret.
-
Integrity: Order info, payment info must not be altered.
-
Authentication: Cardholder, merchant, bank must be genuine.
-
Non-repudiation: Cardholder cannot deny order; merchant cannot deny receiving payment.
-
-
SET Protocol - How It Addresses Concerns:
-
Uses dual signatures: Cardholder signs order info + payment info together, but separates them. Merchant sees order, bank sees payment, neither sees full link.
-
Entities: Cardholder, Merchant, Issuer (cardholder's bank), Acquirer (merchant's bank), Payment Gateway, Certification Authority (CA).
-
Example Flow (Simplified):
-
Cardholder gets dual signature on
Order + Payment. -
Sends
Order+Dual Signatureto Merchant. -
Sends
Payment+Dual Signature(encrypted for bank) via Payment Gateway to Acquirer/Issuer. -
Merchant verifies signature on order. Bank verifies signature on payment using cardholder's public key (from cert).
-
-
Addresses Concerns: Confidentiality (encryption), Integrity (digital signatures), Authentication (certificates), Non-repudiation (dual signatures bind parties).
-
IV. Network Security Infrastructure
Virtual Private Networks (VPNs) vs Trusted Operating Systems
| Aspect | VPN | Trusted Operating System (TOS) |
|---|---|---|
| Core Idea | Create secure "tunnel" over untrusted network (Internet). | OS itself enforces mandatory security policies (e.g., Bell-LaPadula, Biba) via formal verification. |
| Security Mechanism | Cryptography (IPSec, SSL/TLS). | Mandatory Access Control (MAC) labels (e.g., sensitivity levels). |
| Architecture | Often gateway-based (site-to-site) or client-based (remote access). | Secure kernel, reference monitor, security policy engine. |
| Primary Goal | Confidentiality & Integrity of data in transit. | Confidentiality & Integrity of data at rest & in use on the host. |
| Application | Connect remote offices/users securely over Internet. | High-assurance systems (military, government, critical infrastructure). |
| Example | IPSec tunnel between two corporate routers. | SELinux, Trusted Solaris, MULTOS. |
Intrusion Detection Systems (IDS)
-
Host-based IDS (HIDS):
-
Working: Monitors a single host (OS, file system, logs, processes).
-
Components: Sensors (collect audit logs), Analyzer (detect anomalies/signatures), Manager (alert).
-
Detection: File integrity checks (Tripwire), log analysis, rootkit detection.
-
Diagram:
[Host OS] → [HIDS Agent] → [Local DB/Alert]
-
-
Network-based IDS (NIDS):
-
Working: Monitors network traffic (sensors on network segments).
-
Components: Sensors (packet capture), Analyzer (pattern/signature match), Console.
-
Detection: Signature-based (known attack patterns), Anomaly-based (baseline deviation).
-
Diagram:
[Network Segment] → [NIDS Sensor] → [Central Analyzer] → [Console]
-
-
Parameter Pattern Matching (IDS Technique):
-
Signature-based Detection: Compare network/host activity against a database of known attack signatures (patterns).
-
How: Predefined patterns (e.g., specific byte sequence in packet, log message). Efficient for known attacks but fails against zero-day.
-
Example: Snort rule:
alert tcp any any -> any 80 (content:"/etc/passwd";)
-
Firewalls
-
Classification & Operational Differences:
| Type | Layer | How it Works | Example/Use Case | | :--- | :--- | :--- | :--- | | Packet Filtering | Network/Transport (IP, Port) | Stateless. Checks source/dest IP, port, protocol against ACL. | Simple router ACL. Fast but can't inspect payload. | | Circuit-Level Gateway | Session (TCP/UDP) | Monitors TCP handshake. Creates virtual circuit. Hides internal IPs. | SOCKS proxy. Stateful, but no payload inspection. | | Application-Level Gateway<br>(Proxy) | Application (HTTP, FTP) | Intercepts & inspects application layer commands. Acts as intermediary. | HTTP proxy (Squid). Can filter URLs, commands. Slow. | | Stateful Inspection | Network/Transport | Tracks state of connections (SYN, ESTABLISHED, FIN). Context-aware. | Most modern firewalls (iptables state module). | | Personal Firewall | All (Host-based) | Software on endpoint. Controls inbound/outbound per-app. | Windows Defender Firewall. |
-
Merits: Access control, traffic logging, network segmentation, hide internal structure.
-
Demerits: Cannot stop internal threats, encrypted traffic bypass, complex rule management, single point of failure, cannot stop malware in allowed traffic (e.g., HTTP download).
Malicious Software (Malware)
-
Types:
-
Virus: Attaches to executable, requires user action to spread.
-
Worm: Self-replicating, spreads over network (no host file).
-
Trojan: Disguised as legitimate software. Provides backdoor.
-
Ransomware: Encrypts files, demands ransom.
-
Rootkit: Hides existence/activities (OS/kernel level).
-
Spyware/Adware: Steals data/shows ads.
-
Bot: Compromised host in botnet (DDoS, spam).
-
-
How IDS & Firewalls Help:
-
Firewalls: Block known malicious IPs/ports, prevent worm propagation by filtering traffic. Limitation: Cannot inspect allowed application traffic (e.g., HTTP).
-
IDS (NIDS): Detect worm propagation patterns (scanning), known virus signatures in network traffic.
-
IDS (HIDS): Detect file modifications (virus), unexpected processes (trojan), registry changes (rootkit).
-
Combined: Firewall reduces attack surface; IDS detects what gets through. Both are insufficient alone against sophisticated/encrypted malware; need endpoint protection (AV/EDR).
-
V. Wireless Security
Wireless LAN (WLAN) Security Challenges
-
Broadcast Medium: Signals propagate beyond physical boundaries → easy eavesdropping.
-
No Physical Control: Attacker can be anywhere within range.
-
Weak/No Encryption: Legacy protocols (WEP) are broken.
-
Rogue Access Points: Unauthorized APs inside corporate network.
-
Evil Twin: Fake AP with same SSID to steal credentials.
-
Denial-of-Service: Jamming wireless frequencies.
-
Client Misconfiguration: Open networks, weak passwords.
Wireless Application Protocol (WAP)
-
Architecture (with Diagram):
[Mobile Device] --(Wireless)--> [WAP Gateway] --(Internet)--> [Web Server] | | [WAE ( microbrowser)] [HTTP Server] [WTLS (Security)] [HTML Content]-
WAP Stack: WAE (Application), WTLS (Security), WTP (Transport), WDP (Datagram).
-
Gateway: Translates WAP requests (WSP/WTP) to HTTP/HTTPS. Terminates WTLS, may start TLS to server.
-
-
Security Mechanisms Overview:
-
WTLS: Wireless TLS (optimized for wireless: smaller packets, faster handshake).
-
End-to-End Security: Can use WTLS between device & gateway, and TLS between gateway & server.
-
Identity: Uses certificates (WTLS) or user/password.
-
Wireless Transport Layer Security (WTLS)
-
Role: Provides confidentiality, integrity, authentication for WAP applications. Analogous to TLS but designed for constrained wireless networks (low bandwidth, high latency).
-
Optimizations: Smaller record sizes, faster handshake (optional client cert), supports datagram (WDP).
-
Security Issues in WTLS:
-
Gateway Termination: WTLS often terminates at WAP gateway → gap in end-to-end security. Traffic between gateway & server may be plain HTTP.
-
Weak Ciphers: Early WTLS allowed weak encryption (export restrictions).
-
Certificate Handling: Limited device storage for certs.
-
Man-in-the-Middle: If gateway is compromised, end-to-end security fails.
-
WLAN Protocol Stack & MPDU Format
-
Protocol Stack (IEEE 802.11):
Application LLC (Logical Link Control) MAC (Medium Access Control) ← CSMA/CA PHY (Physical) ← OFDM/DSSS -
MPDU (MAC Protocol Data Unit) Format:
[Frame Control (2B)] [Duration (2B)] [Addr1 (6B)] [Addr2 (6B)] [Addr3 (6B)] [Sequence Control (2B)] [Addr4 (6B, if To DS=1 & From DS=1)] [Frame Body (0-2312B)] [FCS (4B)]-
Frame Control: Type (Mgmt, Ctrl, Data), Subtype, To/From DS flags.
-
Addresses: Depends on
To DS/From DSbits (e.g., AP to client, client to AP, WDS). -
FCS: CRC-32 for error detection.
-
Access Point Security in Public Networks
-
Threats: Evil Twin, session hijacking, man-in-the-middle, packet sniffing.
-
Security Measures:
-
WPA3-Personal: SAE (Simultaneous Authentication of Equals) replaces PSK. Resists offline dictionary attacks.
-
WPA3-Enterprise: 192-bit security suite (AES-GCM-256, HMAC-SHA384). Requires 802.1X/EAP.
-
Captive Portal: Forces HTTP redirect to authentication page (but traffic still unencrypted until HTTPS).
-
Client Isolation (AP Setting): Prevents clients from talking to each other.
-
Use of VPN: Essential on public Wi-Fi. Encrypts all traffic from device to VPN server, bypassing local network threats.
Best Practice: Always use personal VPN on public Wi-Fi, even if using HTTPS.
-
VI. Additional Security Considerations
Trusted Operating Systems
-
Concept: OS designed from ground up to enforce security policy with high assurance. Based on formal security models (Bell-LaPadula for confidentiality, Biba for integrity).
-
Security Architecture:
-
Reference Monitor: Mediates all subject-object accesses. Must be: Tamper-proof, Always invoked, Verifiable.
-
Security Kernel: Minimal, verified part of OS implementing reference monitor.
-
Mandatory Access Control (MAC): Labels (e.g., Top Secret, Secret) assigned to subjects/objects. Access based on label comparison (no user discretion).
-
Process Isolation: Each process has separate address space.
-
Audit: Complete, secure logging of security-relevant events.
-
-
Applications: Military systems, government databases, critical infrastructure control systems.
Web Traffic Security Approaches
-
SSL/TLS (HTTPS): End-to-end encryption between browser & server. Provides confidentiality, integrity, server authentication (and optionally client auth).
-
IPSec (VPN): Secures all IP traffic between gateways or hosts. Can protect non-web traffic too.
-
Application Layer Gateways/Proxies: Inspect and filter HTTP/HTTPS (HTTPS inspection via MITM with installed CA cert).
-
Content Security Policy (CSP): Mitigates XSS by defining allowed sources for scripts, styles, etc.
-
HTTP Strict Transport Security (HSTS): Forces browser to use HTTPS only.
Practical Cipher Examples & Calculations
-
Caesar Cipher Decryption (Shift 17):
-
Ciphertext:
ZICVTWQNGRZGVTWAVZHCQYGLMGJ -
Decryption:
P_i = (C_i - 17) mod 26 -
Z(25) → (25-17)=8 → I,I(8) → (8-17)=-9≡17 → R,C(2) → (2-17)=-15≡11 → L... -
Plaintext:
IRE**_**_**_**_**_**_**_**(Complete:IRELAND WAS CONQUERED BY THE ROMANS- verify exact shift).
Step: Convert letters to numbers (A=0), subtract shift, mod 26, convert back.
-
-
RC4 First 3 Bytes (5-bit key
10101= 21):-
KSA: Key
K = [21,21,21,21,21](5 bytes). InitializeS = [0,1,2,...,255]. -
For
i=0 to 255:j = (j + S[i] + K[i mod keylen]) mod 256; swapS[i]&S[j]. -
PRGA:
i=j=0initially.-
i=0:j = (0 + S[0] + K[0]) mod 256 = (0 + 0 + 21) = 21; swapS[0]&S[21]; outputK_0 = S[(S[0]+S[21]) mod 256]. -
i=1:j = (21 + S[1] + K[1]) mod 256; swap; outputK_1. -
i=2: similarly.
-
-
Result: First 3 keystream bytes depend on full KSA output. Must compute KSA completely first.
-
Parameter Pattern Matching (Detailed)
-
Definition: Technique where IDS/IPS compares network/host activity against a database of signatures (patterns) of known attacks.
-
Process:
-
Signature Creation: Analyze attack (e.g., buffer overflow exploit) → identify unique byte sequence, packet header anomaly, log message pattern.
-
Storage: Signatures stored in database (e.g., Snort rules).
-
Detection: Real-time traffic/logs scanned for exact or approximate pattern match.
-
-
Types:
-
Exact String Matching: Fast (Boyer-Moore, Aho-Corasick algorithms). Used in NIDS for payload inspection.
-
Regular Expression Matching: More flexible but slower. Used for complex patterns.
-
-
Merits: High accuracy for known attacks, low false positives.
-
Demerits: Zero-day attacks (no signature) missed. Signature updates required. Can be evaded by polymorphism/metamorphism (malware changes code each infection).
Cipher Block Modes of Operation (Recap/Comparison)
-
Purpose: Allow block ciphers to securely encrypt data larger than block size.
-
Key Comparison Points:
-
Parallelization: ECB, CTR (enc/dec). CBC, CFB, OFB (dec only for CBC/CFB).
-
Padding Required: ECB, CBC (yes). CFB, OFB, CTR (no).
-
Error Propagation: ECB (none per block), CBC (1 block), CFB (s bits), OFB/CTR (none).
-
Random Access/Seek: CTR (yes), OFB (partial), others (no).
-
IV/Nonce Requirement: All except ECB need unique IV/nonce. Reuse in CTR/OFB → keystream reuse → break.
-
-
Modern Preference: CTR (parallel, random access, no padding) or GCM (Galois Counter Mode, provides authentication). CBC still common but requires careful IV management (random, unpredictable). ECB is always insecure.