Skip to content
CY-503 (B) · Network Security/Quick Revision Short Notes

Network Security (CY-503 (B)) - Unit 1 Short Notes

UNIT 1: NETWORK SECURITY – SHORT NOTES


I. CRYPTOGRAPHIC FOUNDATIONS

Symmetric Encryption

  • Principle: Uses the same secret key for both encryption and decryption. Provides confidentiality.

  • Process:

    1. Sender & Receiver agree on a secret key K via a secure channel.

    2. Sender: C = E(K, P) (Ciphertext = Encryption of Plaintext with Key).

    3. Receiver: P = D(K, C) (Plaintext = Decryption of Ciphertext with Key).

  • Challenge: Secure key distribution and management.

Block Ciphers: AES (Advanced Encryption Standard)

  • Structure: Iterative Substitution-Permutation Network. Operates on fixed-size blocks (128 bits). Key sizes: 128, 192, 256 bits.

  • Core Rounds (per block):

    1. SubBytes: Non-linear substitution using S-box.

    2. ShiftRows: Permutation (row shifting).

    3. MixColumns: Mixing columns (linear transformation).

    4. AddRoundKey: XOR with round key.

  • Example (Simplified 128-bit key, 1 round):

    • Plaintext Block: P = 00112233445566778899aabbccddeeff

    • Round Key: RK = 000102030405060708090a0b0c0d0e0f

    • AddRoundKey(P, RK) → Intermediate state → (SubBytes, ShiftRows, MixColumns) → Final ciphertext block.

Stream Ciphers: RC4

  • Algorithm: Generates a pseudo-random keystream from a secret key, which is XORed with plaintext.

  • Keystream Generation (KSA & PRGA):

    1. KSA (Key Scheduling Algorithm): Initialize S-box (0-255), permute using secret key.

    2. PRGA (Pseudo-Random Generation Algorithm): Continuously generate keystream bytes by swapping S[i] and S[j], output S[(S[i]+S[j]) % 256].

  • Example (5-bit key K=10101):

    • Key length l=5. S-box init S=[0,1,2,3,4].

    • KSA: For i=0 to 4, j = (j + S[i] + K[i mod l]) mod 5, swap S[i] and S[j].

    • PRGA: i=0, j=0, i=(i+1) mod 5, j=(j+S[i]) mod 5, swap, output S[(S[i]+S[j]) mod 5]. Repeat.

    • Keystream bytes generated are XORed with plaintext bits.

Classical Cipher: Caesar Cipher

  • Principle: Substitution cipher shifting each letter by a fixed number k (shift).

  • Encryption: C = (P + k) mod 26 (P, C are letter positions 0-25).

  • Decryption: P = (C - k) mod 26 or P = (C + (26-k)) mod 26.

  • Example: Decrypt ZICVTWQNGRZGVTWAVZHCQYGLMGJ with shift k=17.

    • k' = 26 - 17 = 9 (reverse shift).

    • Z(25) -> (25+9) mod 26 = 8 -> I, I(8) -> (8+9) mod 26 = 17 -> R, etc.

    • Plaintext: RETURNHOMEATONCE.

[!TIP] Exam Focus: RSA example (p=3,q=11) and RC4 5-bit keystream generation are highly frequent.


Modes of Operation for Block Ciphers

Mode How it Works Merits Demerits
ECB<br>(Electronic Codebook) Each block encrypted independently. Simple, parallelizable. Identical plaintext blocks → identical ciphertext. Insecure for repetitive data.
CBC<br>(Cipher Block Chaining) C_i = E(K, P_i ⊕ C_{i-1}), C_0 = IV. Hides patterns, widely used (TLS, IPsec). Sequential encryption, error propagation. IV must be unpredictable.
CFB<br>(Cipher Feedback) Generates keystream: O_i = E(K, C_{i-1}), C_i = P_i ⊕ O_i. Turns block cipher into stream cipher, no padding. Sequential, error propagates for s bits.
OFB<br>(Output Feedback) Keystream independent of plaintext: O_i = E(K, O_{i-1}), C_i = P_i ⊕ O_i. No error propagation, can precompute keystream. If keystream repeats, catastrophic.
CTR<br>(Counter) Keystream: `O_i = E(K, Nonce Counter_i), C_i = P_i ⊕ O_i`.

Block vs. Stream Ciphers

Feature Block Ciphers Stream Ciphers
Unit Fixed-size block (e.g., 128 bits). Bit/byte-by-byte.
Structure Complex rounds (substitution, permutation). Simple state update & output function.
Speed Generally slower (complex rounds). Very fast (simple XOR).
Error Propagation Affects entire block. Limited to corrupted bits.
Use Case Bulk data encryption, disk encryption. Real-time comms (TLS record, WEP/WPA).
Example AES, DES, 3DES. RC4, A5/1, ChaCha20.

II. HASH FUNCTIONS & MESSAGE AUTHENTICATION

Cryptographic Hash Functions (e.g., SHA-512)

  • Properties:

    1. Pre-image resistance: Given h, hard to find M such that hash(M)=h.

    2. Second pre-image resistance: Given M1, hard to find M2≠M1 with hash(M1)=hash(M2).

    3. Collision resistance: Hard to find any M1, M2 with same hash.

  • SHA-512 Process:

    1. Padding: Append 1 bit, then 0s, then 128-bit message length. Total bits ≡ 896 mod 1024.

    2. Parse: Split padded message into 1024-bit blocks M^1 ... M^N.

    3. Initialize Hash: 8 initial 64-bit constants (H0^0 ... H7^0).

    4. Process Each Block: For each block, 80 rounds of message schedule & compression function updating the hash state.

    5. Output: Final hash = H0^N || H1^N || ... || H7^N (512 bits).

Message Authentication Codes (MACs)

  • Purpose: Provide integrity + authenticity (not confidentiality). Detects message modification.

  • HMAC (Hash-based MAC):

    • HMAC(K, M) = Hash((K ⊕ opad) || Hash((K ⊕ ipad) || M))

    • ipad = 0x36, opad = 0x5C (fixed padding).

    • Uses underlying hash (SHA-256, SHA-512). Resistant to length extension attacks.

  • CBC-MAC:

    • Encrypt message in CBC mode with a secret key K.

    • MAC = last ciphertext block.

    • Vulnerable if message length not fixed (needs length prepending or CMAC variant).

Collision Resistance & Birthday Attack

  • Birthday Paradox: In a set of ~√N random items, probability of a collision is ~50% (N = hash output space size).

  • Implication: For an n-bit hash, collision attack complexity is ~2^(n/2), not 2^n.

  • Example: SHA-1 (160-bit) theoretically breakable in ~2^80 operations (theoretical), SHA-256 secure against this (~2^128).


III. DIGITAL SIGNATURES

  • Mechanism:

    1. Signing: Sender computes Sig = D(Private_Key, Hash(Message)) (or uses specific algorithm like RSA-PSS, ECDSA).

    2. Verification: Receiver computes Hash(Message) and V = E(Public_Key, Sig). Valid if V == Hash(Message).

  • Workflow:

    
    Sender: Message → Hash → Sign with Private Key → (Message + Signature)
    
    Receiver: (Message + Signature) → Hash(Message) → Verify Signature with Sender's Public Key → Valid/Invalid
    
    
  • Importance:

    • Non-repudiation: Sender cannot deny sending.

    • Integrity: Message not altered.

    • Authentication: Confirms sender identity.

  • Applications: Software distribution (code signing), financial transactions (digital cheques), legal documents.


IV. EMAIL SECURITY: PRETTY GOOD PRIVACY (PGP)

  • Working Principle: Hybrid cryptosystem.

    1. Confidentiality: Message encrypted with fast symmetric session key.

    2. Session Key encrypted with recipient's public key.

    3. Authentication/Integrity: Digital signature created using sender's private key on message hash.

  • PGP Message Format (Layered):

    
    [Session Key Encrypted with Recipient's Public Key]
    
    [Signature (if present): Sender's Key ID, Signature Packet]
    
    [Compressed (optional) & Encrypted Data Packet]
    
    [Literal Data Packet: actual message]
    
    

    *

    DiagramCANVAS: A block diagram showing: "Original Message" → "Compress" → "Sign" (using Sender's Private Key) → "Encrypt" (using Session Key) → "Encrypt Session Key" (with Recipient's Pub Key) → Final PGP Message Packet containing Encrypted Session Key, Signature, and Encrypted Data.

  • Authentication & Confidentiality Process:

    1. Alice wants to send confidential, signed email to Bob.

    2. Alice generates random session key K_s.

    3. Alice: Compress(M) → Sign(Compress(M), Alice_Priv) → Encrypt(Compressed+Signature, K_s).

    4. Alice: Encrypt(K_s, Bob_Pub).

    5. Sends: [Enc_Ks] || [Encrypted_Data].

    6. Bob: Decrypts K_s with Bob_Priv. Decrypts data with K_s. Decompresses. Verifies signature with Alice_Pub.


V. NETWORK LAYER SECURITY: IPSEC

IPSec Protocols

  • AH (Authentication Header):

    • Provides data origin authentication, integrity, anti-replay.

    • Does NOT provide confidentiality.

    • Transport Mode: AH protects IP payload (TCP/UDP), IP header partially protected (mutable fields excluded).

    • Tunnel Mode: AH protects entire original IP packet (header + payload). New IP header added.

  • ESP (Encapsulating Security Payload):

    • Provides confidentiality (encryption), authentication, integrity, anti-replay.

    • Transport Mode: ESP encrypts & authenticates IP payload. Original IP header unprotected.

    • Tunnel Mode: ESP encrypts & authenticates entire original IP packet. New IP header added.

Security Associations (SA)

  • Concept: A unidirectional logical connection between two IPsec endpoints providing security services.

  • Parameters (SAD - Security Association Database):

    • SPI (Security Parameter Index): 32-bit unique identifier for SA.

    • IP Destination Address.

    • Security Protocol (AH/ESP).

    • Mode (Transport/Tunnel).

    • Cryptographic algorithms & keys (encryption, authentication).

    • Lifetime (time/bytes).

  • Management: Manual configuration or via IKE (Internet Key Exchange) protocol (IKEv1/v2).


VI. TRANSPORT LAYER SECURITY: SSL/TLS

SSL Handshake Protocol (Simplified TLS 1.2)

  1. ClientHello: Client sends supported TLS version, cipher suites, random R_C.

  2. ServerHello: Server chooses TLS version, cipher suite, random R_S. Sends Server Certificate (contains PubKey).

  3. ServerHelloDone: Server signals end of hello messages.

  4. ClientKeyExchange: Client generates premaster secret, encrypts with Server's PubKey (from cert), sends.

  5. ChangeCipherSpec (Client): Client signals subsequent messages will be encrypted.

  6. Finished (Client): Encrypted hash of all handshake messages so far.

  7. ChangeCipherSpec (Server) & Finished (Server): Server does same.

  8. Secure Channel Established: Both derive master secret from premaster secret, R_C, R_S. Then derive session keys for encryption/MAC.

SSL Record Protocol Services

  • Confidentiality: Using symmetric encryption (session key).

  • Integrity: Using MAC (HMAC) on record.

  • Anti-replay: Sequence numbers.

  • Fragmentation & Reassembly: of application data.

SSL Connection vs. SSL Session

SSL Session SSL Connection
Established by Handshake. Established by Application Data transfer.
Defines cryptographic parameters (master secret, cipher suite). Uses session's parameters to create fresh encryption/MAC keys.
Can be resumed (abbreviated handshake) to avoid full handshake. Ephemeral, exists for duration of data transfer.
One session can support multiple connections. Each connection has its own read/write keys.

VII. NETWORK SECURITY DEVICES

Firewalls

Type Operational Principle Example Merits Demerits
Packet Filtering Stateless. Inspects IP/Transport headers (IP, port, protocol). Rule-based (ACL). iptables (stateless). Fast, transparent, low cost. No app-layer inspection, IP spoofing possible, complex rule management.
Circuit-Level Gateway Monitors TCP handshaking (SYN, SYN-ACK, ACK). Creates virtual circuit. SOCKS proxy. Hides internal network, validates session. No content inspection, per-connection state.
Application-Level Gateway (Proxy) Deep packet inspection. Interprets application protocol (HTTP, FTP). Acts as intermediary. Web proxy, mail gateway. Granular control, user authentication, content filtering. Performance bottleneck, protocol-specific, expensive.
Personal Firewall Host-based. Controls inbound/outbound traffic for a single system. Windows Defender Firewall. Protects mobile/remote hosts. Host management overhead.

Intrusion Detection Systems (IDS)

  • HIDS (Host-based IDS):

    • Components: Audit/log monitor, signature database, detection engine.

    • Monitoring: System calls, file integrity (Tripwire), log files on specific host.

    • Deployment: On critical servers/workstations.

  • NIDS (Network-based IDS):

    • Components: Network sensors (promiscuous mode), analysis engine, management console.

    • Monitoring: Network traffic (packet headers/payloads) at strategic points (DMZ, network perimeter).

    • Deployment:

      DiagramSEARCH: NIDS deployment diagram showing sensors at network segments sending data to central analysis console

    • Detection: Parameter Pattern Matching (Signature-based):

      • Compare traffic against database of known attack signatures (byte patterns, sequence of packets).

      • Pros: Low false positives for known attacks.

      • Cons: Cannot detect zero-day/novel attacks. Signature maintenance critical.

[!TIP] IDS vs Firewall: Firewall prevents attacks (proactive, access control). IDS detects attacks (reactive, monitoring).


VIII. VIRTUAL PRIVATE NETWORKS (VPN)

Types of VPN

  • Site-to-Site VPN (Gateway-to-Gateway):

    • Connects entire networks (e.g., branch office to HQ).

    • Uses tunnel mode IPSec/SSL.

    • Gateways handle encryption/decryption.

  • Remote Access VPN:

    • Connects individual remote users to corporate network.

    • Uses transport mode (often SSL/TLS) or tunnel mode.

    • Client software (Cisco AnyConnect, OpenVPN) on user's device.

VPN vs Trusted Operating Systems

Aspect VPN Trusted OS
Principle Encryption & tunneling over untrusted network (Internet). Creates "private" pipe. Mandatory Access Control (MAC). Enforces security policy via reference monitor (security kernel).
Security Model Confidentiality & integrity of data in transit. Confidentiality, integrity, availability of data at rest & in use on the system.
Application Secure remote access, inter-site connectivity. High-assurance systems (military, government), multi-level security (MLS).
Example IPsec, SSL-VPN, WireGuard. SELinux, Trusted Solaris, MULTICS.
Focus Network layer security. OS kernel & resource security.

IX. WIRELESS SECURITY

WLAN Security Challenges & Threats

  • Eavesdropping: Wireless medium is broadcast.

  • Rogue Access Points: Unauthorized APs inside network.

  • Denial-of-Service (DoS): Jamming, deauthentication attacks.

  • 802.11 Protocol Issues:

    • WEP (Wired Equivalent Privacy): Broken (RC4 weak IVs, no key management).

    • WPA/WPA2 (Wi-Fi Protected Access): Uses TKIP (WPA) or CCMP/AES (WPA2). PSK (Pre-Shared Key) vulnerable to offline dictionary attacks.

    • WPA3: SAE (Simultaneous Authentication of Equals) resists offline dictionary. Forward secrecy.

Wireless Application Protocol (WAP) Security

  • Architecture:

    
    Mobile Device → WAP Browser → WAP Stack → **WAP Gateway** (protocol conversion) → Internet/Web Server
    
    

    *

    DiagramSEARCH: WAP architecture diagram showing mobile phone, WAP stack layers (WAE, WSP, WTP, WTLS), WAP Gateway, and Web Server.

  • WTLS (Wireless Transport Layer Security):

    • Purpose: Provide security (like TLS) in wireless, constrained environments (low bandwidth, high latency).

    • Mechanisms: Optimized TLS variant. Supports datagram (WDP), short certificates, message fragmentation.

    • Security Issues: Gateway Decryption Model: WTLS terminates at WAP Gateway, which decrypts and re-encrypts with TLS to server. Gateway is a trusted point—if compromised, all wireless traffic exposed. End-to-end security lost.

Access Point Security in Public Networks

  • Risks:

    • Evil Twin: Rogue AP with same SSID as legitimate one. Captures credentials.

    • Packet Sniffing: Unencrypted traffic easily captured.

    • Man-in-the-Middle (MitM): Rogue AP intercepts/alters traffic.

  • Mitigation:

    • WPA2/WPA3-Personal (PSK): Minimum for user encryption.

    • Captive Portals: Force authentication via web page (but traffic still unencrypted until HTTPS).

    • VPN: Always use corporate VPN over public Wi-Fi.

    • 802.1X (Enterprise): Individual user authentication (EAP-TLS, PEAP).

WLAN Technical Details

  • Protocol Stack: IEEE 802.11 (PHY + MAC) → LLC → Network Layer (IP).

  • MPDU (MAC Protocol Data Unit) Format:

    
    [Frame Control (2)] [Duration (2)] [Addr1 (6)] [Addr2 (6)] [Addr3 (6)] [Seq Ctrl (2)] [Addr4 (6, optional)] [Frame Body (0-2312)] [FCS (4)]
    
    
    • Frame Control: Type/Subtype, flags (To/From DS, More Fragments).

    • Addresses: Addr1=Receiver, Addr2=Transmitter, Addr3=Filtering (BSSID), Addr4=WDS.

    • FCS: CRC-32 for error detection.


X. SECURE ELECTRONIC TRANSACTION (SET)

  • Security Concerns in Online Transactions:

    • Confidentiality: Cardholder data (PAN) must be secret.

    • Integrity: Transaction data must not be altered.

    • Authentication: Cardholder, merchant, bank must authenticate each other.

    • Non-repudiation: Parties cannot deny transaction.

  • SET Participants:

    • Cardholder, Merchant, Issuing Bank, Acquiring Bank, Certificate Authority (CA).
  • Key Mechanism: Dual Signature

    • Cardholder creates two hashes: H1 = Hash(Order Info), H2 = Hash(Payment Info).

    • Cardholder computes H = Hash(H1 || H2) and signs H with private key → Dual Signature.

    • Merchant receives Order Info & Dual Signature. Can verify H1 matches Order Info and H is valid (using cardholder's cert). Cannot see Payment Info.

    • Bank receives Payment Info & Dual Signature. Can verify H2 matches Payment Info and H is valid. Cannot see Order Info.

    • Privacy: Merchant sees order, bank sees payment, neither sees both.

  • Transaction Flow (Simplified):

    1. Cardholder & Merchant exchange certificates.

    2. Cardholder sends dual-signed order/payment to merchant.

    3. Merchant forwards payment info + dual signature to acquiring bank.

    4. Bank validates with issuer, sends authorization to merchant.

    5. Merchant completes order, sends confirmation to cardholder.

  • Business Apps & Adoption: Designed for credit card transactions over open networks. Not widely adopted due to complexity, cost, need for all parties to implement, competition from simpler SSL-based solutions.


XI. MALWARE AND SECURITY THREATS

Types of Malicious Software

Type Propagation Impact
Virus Requires host program & user action (execute infected file). Corrupts/deletes files, spreads to other files.
Worm Self-replicating, exploits network/vulnerabilities (no host). Consumes bandwidth, creates botnets.
Trojan Horse Disguised as legitimate software. User installs. Backdoors, data theft, ransomware drop.
Ransomware Often via trojan/phishing. Encrypts files, demands ransom. Data loss, financial extortion.
Spyware Secretly monitors activity (keyloggers, screenscrapers). Privacy violation, credential theft.
Rootkit Hides existence/processes at OS kernel level. Persistent stealth, difficult to detect.
Botnet Network of compromised hosts (zombies) controlled by C&C. DDoS attacks, spam, crypto-mining.

General Security Considerations & Threats

  • Attack Vectors: Phishing, drive-by downloads, malicious attachments, unpatched vulnerabilities, social engineering.

  • Defense-in-Depth:

    • Prevention: Firewalls, patching, user training, least privilege.

    • Detection: IDS/IPS, antivirus/EDR, log monitoring.

    • Response: Incident response plan, backups, isolation.


XII. AUTHENTICATION MECHANISMS

Biometric Authentication

  • Types: Fingerprint, Iris, Facial recognition, Voice, Vein pattern.

  • Advantages:

    • Hard to lose/forge (unique to individual).

    • Convenient (no token/password to remember).

  • Challenges:

    • False Rejection Rate (FRR): Legitimate user rejected.

    • False Acceptance Rate (FAR): Impostor accepted.

    • Privacy: Storage of biometric templates (must be encrypted, not raw image).

    • Spoofing: Fake fingerprints, photos, voice recordings. Liveness detection needed.

    • Irrevocability: Cannot "change" biometric if compromised.

Smart Cards

  • Types:

    • Contact: Requires insertion into reader (chip & pins).

    • Contactless (RFID/NFC): Proximity-based (e.g., access cards, payment cards).

  • How They Enhance Security (Two-Factor):

    1. Something you have: The physical card.

    2. Something you know: PIN/password.

    • Card contains secure microprocessor storing cryptographic keys, performing operations internally. Private keys never leave card.

    • Resistant to replay, key extraction (if tamper-resistant).


XIII. ADDITIONAL TOPICS

Web Traffic Security Approaches

  • SSL/TLS (HTTPS): De facto standard. Secures HTTP at transport layer (TCP). Provides server authentication (certificates), optional client auth, encryption, integrity.

  • S-HTTP (Secure HTTP): Obsolete. Secured message-level (application layer). Could mix secured/unsecured pages on same server. Never widely adopted.

  • IPsec: Can secure web traffic at network layer (tunnel mode). Used for site-to-site or remote access VPNs carrying web traffic. Transparent to applications.

Trusted Operating Systems

  • Concept: OS designed to meet high security requirements (e.g., Orange Book B1/A1).

  • Reference Monitor: Abstract machine mediating all subject-object accesses. Must be:

    1. Tamper-proof.

    2. Always invoked (unbypassable).

    3. Small enough to be verifiable.

  • Security Kernel: Minimal implementation of reference monitor.

  • Examples: SELinux (Flask architecture, Type Enforcement), Trusted Solaris (multilevel security), Multics (early reference monitor).

  • Features: Mandatory Access Control (MAC), formal verification, secure boot, auditing.

Parameter Pattern Matching

  • As used in IDS/IPS: Signature-based detection.

  • Process: Compare network packet headers/payloads or system audit logs against a database of known attack patterns (signatures).

  • Signature: Byte sequence, pattern of system calls, specific packet flag combinations.

  • Role: Effective for known malware, exploits, attack tools. Cannot detect novel (zero-day) attacks or polymorphic malware that changes signature.

  • Used in: Snort (NIDS), OSSEC (HIDS), antivirus software.

Cipher Block Modes of Operation (Detailed)

  • ECB: Insecure for patterns. Only for single block encryption (e.g., encrypting a key).

  • CBC: Most common for bulk encryption (disk encryption, TLS pre-1.3). Requires random, unique IV (not secret). Sequential.

  • CTR: Turns block cipher into stream cipher. Parallelizable (encrypt/decrypt). Requires unique nonce/counter per key. Used in IPSec, TLS 1.3.

  • OFB/CFB: Stream cipher modes. Error propagation limited. OFB keystream independent of plaintext; CFB keystream depends on previous ciphertext.

  • XTS (XEX-based Tweaked CodeBook mode): For disk encryption (IEEE 1619). Tweaks based on sector number. No authentication.

[!TIP] Exam Focus: Be prepared to draw/explain PGP format, SSL handshake, NIDS deployment, WAP architecture, MPDU format, and compare VPN/Trusted OS, Block/Stream ciphers, Firewall types, AH/ESP modes. Always include examples where specified (RSA p=3,q=11; RC4 5-bit; Caesar shift=17).

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in