UNIT 2: NETWORK SECURITY – COMPREHENSIVE STUDY NOTES
I. CRYPTOGRAPHIC FOUNDATIONS
A. Symmetric Encryption
-
Definition: Same cryptographic key for both encryption and decryption.
-
Strengths: Fast, efficient for large data volumes.
-
Weaknesses: Key distribution problem; requires secure channel for key exchange.
-
Classical Cipher – Caesar Cipher:
-
Process: Each plaintext character shifted by fixed number
kpositions in alphabet. -
Encryption: $$\displaystyle E(x) = (x + k) \mod 26 $$
-
Decryption: $$\displaystyle D(x) = (x - k) \mod 26 $$
-
Example (Dec 2024): Ciphertext
ZICVTWQNGRZGVTWAVZHCQYGLMGJ, shift $$\displaystyle k=17 $$.-
Convert letters to numbers (A=0, B=1, ..., Z=25).
-
For each ciphertext number $c$, compute $$\displaystyle p = (c - 17) \mod 26 $$.
-
Resulting plaintext:
THEQUICKBROWNFOXJUMPSOVERTHELAZYDOG.
-
-
-
Block vs. Stream Ciphers:
-
Block Ciphers: Encrypt fixed-size blocks (e.g., 64-bit, 128-bit). Examples: AES, DES. Modes of operation required for repeated use.
-
Stream Ciphers: Encrypt bit/byte stream on-the-fly. Example: RC4.
-
-
Modes of Operation (for Block Ciphers):
| Mode | Description | Merits | Demerits | |------|-------------|--------|----------| | ECB (Electronic Codebook) | Each block encrypted independently | Simple, parallelizable | Identical plaintext blocks → identical ciphertext; no diffusion | | CBC (Cipher Block Chaining) | XOR each plaintext block with previous ciphertext block | Hides patterns, requires IV | Sequential encryption, error propagation | | CFB (Cipher Feedback) | Turns block cipher into stream; feedback from ciphertext | Handles streaming data, no padding | Error propagation, sequential | | OFB (Output Feedback) | Generates keystream independent of plaintext/ciphertext | No error propagation, synchronous stream | Keystream reuse if IV reused | | CTR (Counter) | Encrypts counter value to produce keystream | Parallelizable, random access, no padding | Counter reuse catastrophic |
-
Modern Algorithm – AES (Advanced Encryption Standard):
-
Block Size: 128 bits; Key Sizes: 128, 192, 256 bits.
-
Round Structure (per round except last):
-
SubBytes: Non-linear substitution using S-box.
-
ShiftRows: Cyclic shift of rows in state matrix.
-
MixColumns: Mixing columns for diffusion.
-
AddRoundKey: XOR with round key.
-
-
Final round omits MixColumns.
-
-
Stream Cipher – RC4:
-
Keystream Generation: Uses a pseudo-random generation algorithm (PRGA) on an S-box (256 bytes) initialized by key-scheduling algorithm (KSA).
-
KSA: Initialize S-box with identity, then permute based on key.
-
PRGA: Generate keystream byte by byte by swapping S-box entries and outputting $S[S[i] + S[j]] \mod 256$.
-
Security Considerations: Vulnerable to biases in early output; weak if key has repetitions (e.g., WEP).
-
Example Task (5-bit key): For key
K = [1,0,1,0,1](binary, 5 bits = 21 decimal? But RC4 uses bytes; simplified example often uses small key for illustration). Typically, key is byte array. For exam, show KSA with key bytes.[!TIP] In exams, use a small integer key (e.g., key = [1,2,3]) and demonstrate KSA steps briefly.
-
B. Asymmetric (Public-Key) Encryption
-
Core Principles:
-
Public/Private Key Pairs: Public key shared; private key kept secret.
-
Mathematical Trapdoor: Easy to compute in one direction (e.g., multiplication), hard to reverse (e.g., factoring).
-
-
RSA Algorithm:
-
Key Generation:
-
Choose large primes $p, q$.
-
Compute $$\displaystyle n = p \cdot q $$, $$\displaystyle \phi(n) = (p-1)(q-1) $$.
-
Choose $e$ such that $$\displaystyle 1 < e < \phi(n) $$ and $$\displaystyle \gcd(e, \phi(n)) = 1 $$.
-
Compute $$\displaystyle d = e^{-1} \mod \phi(n) $$.
- Public Key: $(e, n)$; Private Key: $(d, n)$.
-
-
Encryption: $$\displaystyle c = m^e \mod n $$
-
Decryption: $$\displaystyle m = c^d \mod n $$
-
Example (Nov 2023): $$\displaystyle p=3, q=11 $$.
-
$$\displaystyle n = 33 $$, $$\displaystyle \phi(n) = 20 $$.
-
Choose $$\displaystyle e=7 $$ (co-prime with 20).
-
$$\displaystyle d = 7^{-1} \mod 20 = 3 $$ (since $$\displaystyle 7 \cdot 3 = 21 \equiv 1 \mod 20 $$).
-
Encrypt $$\displaystyle m=2 $$: $$\displaystyle c = 2^7 \mod 33 = 128 \mod 33 = 29 $$.
-
Decrypt: $$\displaystyle m = 29^3 \mod 33 = 24389 \mod 33 = 2 $$.
-
-
Applications:
-
Confidentiality: Encrypt with recipient’s public key.
-
Digital Signatures: Sign with sender’s private key.
-
Key Exchange: Securely exchange symmetric keys.
-
-
C. Cryptographic Hash Functions & Message Authentication
-
Hash Function Properties:
-
Pre-image Resistance: Given hash $h$, hard to find $m$ such that $$\displaystyle H(m)=h $$.
-
Second Pre-image Resistance: Given $$\displaystyle m_1 $$, hard to find $$\displaystyle m_2 \neq m_1 $$ with $$\displaystyle H(m_1)=H(m_2) $$.
-
Collision Resistance: Hard to find any $$\displaystyle m_1, m_2 $$ such that $$\displaystyle H(m_1)=H(m_2) $$.
-
-
SHA-512 (Secure Hash Algorithm 512-bit):
-
Steps:
-
Padding: Append '1' bit, then '0's, then length (128-bit) to make total length multiple of 1024 bits.
-
Parsing: Divide into 1024-bit blocks $$\displaystyle M^{(1)}, ..., M^{(N)} $$.
-
Hash Computation: Initialize eight 64-bit buffers (initial values). For each block, expand to 80 words, then 80 rounds of operations using constants and functions.
-
-
Output is 512-bit digest.
-
-
Message Authentication Codes (MACs):
-
Definition: Short tag generated from message and secret key, providing integrity and authentication.
-
Purpose: Detect message modification and verify sender identity (symmetric key).
-
-
HMAC (Hash-based MAC):
-
Construction: $$\displaystyle HMAC(K, m) = H((K \oplus opad) \parallel H((K \oplus ipad) \parallel m)) $$
-
$K$: secret key (padded to block size).
-
$ipad$: 0x36 repeated; $opad$: 0x5C repeated.
-
$H$: underlying hash (e.g., SHA-256).
-
-
Security: Based on strength of underlying hash; resistant to length extension attacks.
-
-
Digital Signatures:
-
Process:
-
Sender hashes message: $$\displaystyle h = H(m) $$.
-
Sender encrypts hash with private key: $$\displaystyle s = h^d \mod n $$ (RSA) or uses DSA/ECDSA.
-
Sender sends $(m, s)$.
-
-
Verification:
-
Receiver hashes received message: $$\displaystyle h' = H(m) $$.
-
Receiver decrypts signature with public key: $$\displaystyle h'' = s^e \mod n $$.
-
If $$\displaystyle h' = h'' $$, signature valid.
-
-
Crucial Aspects:
-
Non-repudiation: Sender cannot deny sending.
-
Authentication: Receiver sure of sender identity.
-
Integrity: Any change in message invalidates signature.
-
-
II. SECURE COMMUNICATION PROTOCOLS & APPLICATIONS
A. Email Security: PGP (Pretty Good Privacy)
-
Working Principle: Hybrid cryptosystem.
-
Symmetric Encryption: Message encrypted with random session key (e.g., AES).
-
Asymmetric Encryption: Session key encrypted with recipient’s public key.
-
Hashing: Message digest computed (e.g., SHA-256) and signed with sender’s private key.
-
Compression: Applied before encryption (optional).
-
Email Compatibility: Radix-64 encoding for ASCII transmission.
-
-
PGP Message Format:
-
Structure:
[Signature] [Session Key] [Encrypted Data] [Radix-64] -
DiagramSEARCH: PGP message format diagram
-
-
Services Provided:
-
Confidentiality (via symmetric encryption).
-
Authentication & Integrity (via digital signatures).
-
Compression (reduces size).
-
Email Compatibility (ASCII armor).
-
B. Transport & Web Layer Security: SSL/TLS
-
SSL Record Protocol Services:
-
Confidentiality: Using symmetric encryption (session key).
-
Integrity: Using MAC (e.g., HMAC).
-
Authentication: Optional, via certificates.
-
-
SSL Handshake Protocol (Detailed Steps):
-
ClientHello: Client sends supported cipher suites, protocol version, random number $$\displaystyle R_C $$.
-
ServerHello: Server selects cipher suite, sends server random $$\displaystyle R_S $$, server certificate (with public key).
-
ServerKeyExchange (if needed): For ephemeral keys (DHE/ECDHE).
-
ServerHelloDone: Server signals end of hello messages.
-
ClientKeyExchange: Client generates pre-master secret $PMS$, encrypts with server’s public key, sends.
-
ChangeCipherSpec (Client): Client switches to negotiated cipher suite.
-
Finished (Client): Encrypted hash of handshake messages.
-
ChangeCipherSpec (Server) & Finished (Server): Server switches and sends finished.
- Both compute master secret from $PMS$, $$\displaystyle R_C $$, $$\displaystyle R_S $$. Then derive session keys.
-
-
SSL Session vs. SSL Connection:
-
SSL Session: Negotiated security parameters (cipher suite, master secret) between client and server. Can be reused for multiple connections (session resumption).
-
SSL Connection: Specific instance of communication using a session. Each connection has its own read/write keys.
-
Role: Sessions improve efficiency (avoid full handshake); connections provide ephemeral keys for forward secrecy (if using DHE/ECDHE).
-
C. Electronic Payment Security: SET (Secure Electronic Transaction)
-
Main Security Concerns:
-
Payment card data exposure (to merchant).
-
Consumer privacy (order details visible to merchant/bank).
-
Merchant authentication.
-
-
How SET Addresses Concerns:
-
Dual Signatures: Customer signs order info and payment info separately; merchant sees order, bank sees payment without linking.
-
Separation of Order & Payment Info: Prevents merchant from learning card details.
-
Use of Certificates: All participants (cardholder, merchant, bank, gateway) have X.509 certificates.
-
-
Participants & Transaction Flow:
-
Cardholder: Has card & certificate.
-
Merchant: Has merchant certificate.
-
Acquiring Bank: Processes payments.
-
Payment Gateway: Interfaces with bank.
-
Flow: Request → Initiation (dual signatures) → Payment Authorization → Capture.
-
D. Network Layer Security: IPSec
-
Modes:
-
Transport Mode: Protects payload (TCP/UDP/ICMP) of original IP packet. Original IP header intact (except optional fields). Used for end-to-end (host-to-host).
-
Tunnel Mode: Protects entire original IP packet (header + payload). New IP header added. Used for gateway-to-gateway (site-to-site VPN).
-
-
Protocols:
-
AH (Authentication Header): Provides integrity, authentication, anti-replay (sequence number). No confidentiality. Covers immutable parts of IP header + payload.
-
ESP (Encapsulating Security Payload): Provides confidentiality (encryption), integrity, authentication. Can be used in both modes. Encrypts payload (and optionally ESP trailer).
-
-
Security Associations (SA): Unidirectional logical connection defined by:
-
SPI (Security Parameter Index): 32-bit identifier in AH/ESP header.
-
IP Destination Address.
-
Security Protocol (AH/ESP).
-
-
Key Management: IKE (Internet Key Exchange) – two phases: Phase 1 (authenticate peers, establish IKE SA), Phase 2 (negotiate IPSec SAs).
III. NETWORK SECURITY MECHANISMS & ARCHITECTURES
A. Firewalls
-
Classification & Operational Differences:
-
Packet Filtering Firewall (Stateless):
-
Inspects individual packets based on rules (IP, port, protocol).
-
No memory of connections; vulnerable to spoofing.
-
-
Circuit-Level Gateway Firewall (Stateful):
-
Monitors TCP handshakes (SYN, SYN-ACK, ACK) to track connection state.
-
Allows packets belonging to established connections.
-
-
Application-Level Gateway (Proxy Firewall):
-
Acts as intermediary; inspects application-layer data (e.g., HTTP commands).
-
Protocol-aware; can filter specific commands (e.g., FTP
PORT).
-
-
Stateful Multilayer Inspection (SMI) Firewall:
- Combines stateful inspection with deep packet inspection at multiple layers.
-
-
Merits and Demerits (General):
-
Merits: Control access, hide internal network, logging/auditing.
-
Demerits: Cannot prevent all attacks (e.g., insider, social engineering), performance overhead, complex configuration.
-
-
Proxy vs. Personal Firewalls:
-
Proxy Firewall: Network-based; sits between internal and external networks; protects entire network.
-
Personal Firewall: Host-based; installed on individual machines; controls inbound/outbound traffic for that host.
-
B. Intrusion Detection & Prevention Systems (IDS/IPS)
-
Host-based IDS (HIDS):
-
Monitors individual host: log files, system calls, file integrity.
-
Example: OSSEC, Tripwire.
-
-
Network-based IDS (NIDS):
-
Monitors network traffic via sensors/sniffers.
-
Example: Snort, Suricata.
-
-
Detection Techniques:
-
Signature-based (Misuse Detection): Matches known attack patterns (signatures).
-
Anomaly-based: Detects deviations from normal baseline (statistical, machine learning).
-
-
Parameter Pattern Matching (Signature-based):
-
Matches specific packet parameters: source/dest IP, port, protocol flags, packet size, payload patterns.
-
Example: Snort rule:
alert tcp any any -> 192.168.1.1 80 (content:"GET /admin";)
-
C. Virtual Private Networks (VPN)
-
Definition: Secure encrypted tunnel over public network (e.g., Internet) connecting remote sites/users.
-
Types of VPNs:
-
Remote Access VPN: Individual users connect to corporate network (e.g., employee from home). Uses protocols like PPTP, L2TP/IPsec, SSL/TLS.
-
Site-to-Site (Router-to-Router) VPN: Connects entire networks (e.g., branch offices). Often uses IPsec in tunnel mode.
-
-
Comparison: VPN vs. Trusted Operating Systems
| Aspect | VPN | Trusted OS | |--------|-----|------------| | Security Level | Network-level (layer 3) | Host-level (OS kernel) | | Primary Goal | Secure communication over untrusted networks | Enforce mandatory access control (MAC) on a single system | | Mechanism | Encryption, tunneling, authentication | Security kernel, formal verification, reference monitor | | Application | Remote access, inter-site connectivity | High-assurance systems (military, government) | | Scope | Protects data in transit | Protects data at rest and processes |
D. Trusted Operating Systems
-
Concept: OS designed with security as primary goal.
-
Mandatory Access Control (MAC): Central authority defines access policies (e.g., Bell-LaPadula, Biba).
-
Security Kernels: Minimal, verified kernel enforcing security policy.
-
Formal Verification: Mathematical proofs of correctness.
-
-
Comparison with VPNs: See table above.
IV. WIRELESS & MOBILE SECURITY
A. Wireless LAN (WLAN) Security Challenges
-
Inherent Vulnerabilities of Radio Transmission:
-
Eavesdropping (wireless signals travel beyond physical boundaries).
-
Jamming (noise on channel).
-
Interception/modification (no physical control).
-
-
Threats:
-
Rogue Access Points (unauthorized APs inside network).
-
Evil Twin (malicious AP mimicking legitimate one).
-
Denial-of-Service (deauthentication attacks, jamming).
-
Session Hijacking (stealing session keys).
-
B. WLAN Protocol Stack & Security
-
IEEE 802.11i Standard (Robust Security Network - RSN):
-
Defines CCMP (Counter Mode with Cipher Block Chaining Message Authentication Code Protocol) using AES.
-
Uses 802.1X for authentication (EAP framework).
-
-
MPDU Frame Format (MAC Header):
-
Key fields: Frame Control, Duration, Addr1 (Receiver), Addr2 (Transmitter), Addr3 (BSSID), Sequence Control, QoS, HT Control, Payload, FCS.
-
Security-related: Frame Control bits (To DS, From DS, Protected Frame), Addr4 (for WDS), payload encrypted in CCMP.
-
-
Access Point Security in Public Network Environments:
-
Captive Portals: Web-based login before granting access.
-
WPA2-Enterprise: Uses 802.1X with RADIUS server; each user has unique credentials/certificates.
-
Risks: Evil Twin attacks, man-in-the-middle on captive portals, weak EAP methods.
-
C. Wireless Application Protocol (WAP) Security
-
WAP Architecture Overview:
-
Client: Mobile device with WAP browser.
-
Gateway (WAP Proxy): Translates WAP requests to HTTP/HTTPS; sits between client and server.
-
Server: Web server hosting content.
-
-
WTLS (Wireless Transport Layer Security):
-
Role: Provides security for wireless transport (like TLS for wired).
-
Adaptations for constrained devices: Smaller packet sizes, optimized handshake, support for unreliable datagrams.
-
Secures Wireless Comms: Confidentiality (encryption), integrity (MAC), authentication (certificates).
-
-
Security Issues in WTLS:
-
Gateway as Point of Trust: Gateway can decrypt/read all traffic (trusted by both sides).
-
Protocol Gaps: Early versions had weak crypto (export restrictions), vulnerable to man-in-the-middle if certificate validation skipped.
-
End-to-End Missing: Security ends at gateway; from gateway to server may be plain HTTP.
-
V. THREATS & COUNTERMEASURES
A. Malicious Software (Malware)
-
Types:
-
Virus: Attaches to executable files; requires user action.
-
Worm: Self-replicating, spreads via network (e.g., SQL Slammer).
-
Trojan Horse: Disguised as legitimate software; opens backdoor.
-
Ransomware: Encrypts files, demands ransom.
-
Spyware: Monitors user activity, steals data.
-
Adware: Displays unwanted ads.
-
Rootkit: Hides existence of other malware, deep OS integration.
-
-
Infiltration Methods:
-
Email attachments (macro viruses).
-
Drive-by downloads (malicious websites).
-
Removable media (USB autorun).
-
Network shares (exploiting weak shares).
-
B. Role of Security Devices Against Malware
-
Firewalls:
-
Block ports/protocols used by malware (e.g., block SMB for worm propagation).
-
Application controls (allow only approved apps).
-
Limitations: Cannot inspect encrypted traffic; application-layer attacks may pass.
-
-
IDS/IPS:
-
Signature-based: Detect known malware traffic patterns (e.g., specific exploit strings).
-
Anomaly-based: Detect unusual traffic spikes (worm propagation) or beaconing (C2 communication).
-
IPS: Can block malicious packets in real-time.
-
VI. ADVANCED AUTHENTICATION & EMERGING TOPICS
A. Authentication Mechanisms
-
Biometric Authentication:
-
Types: Fingerprint, Iris, Facial recognition, Voice, Vein patterns.
-
Process: Capture → Feature Extraction → Template Storage → Matching (1:1 verification or 1:N identification).
-
Advantages: Hard to forge/lose; convenient.
-
Limitations: False Reject Rate (FRR), False Accept Rate (FAR), cost, privacy concerns, template theft.
-
-
Smart Cards: "Something you have." Store cryptographic keys or certificates; require PIN (something you know) for access.
B. Web Traffic Security Approaches
-
Primary: SSL/TLS (HTTPS) – encrypts entire HTTP session.
-
VPNs: Used for remote access to internal web applications (SSL VPN or IPsec).
-
IPsec: Less common for web; used for securing backend server communications.
C. Parameter Pattern Matching
- Reiterated as signature-based IDS technique matching specific packet parameters (IP, port, flags, size, payload patterns).
VII. SHORT NOTES SYLLABUS (Dec 2024 Q15)
A. Message Authentication Codes (MACs)
-
Symmetric key-based tag for integrity and authentication.
-
Generated by combining message with secret key via algorithm (e.g., HMAC, CBC-MAC).
-
Receiver recomputes MAC with shared key; match ensures message not altered and sender knows key.
-
Example: HMAC-SHA256.
B. Parameter Pattern Matching
-
Signature-based IDS method.
-
Matches predefined patterns in packet headers/payloads.
-
Patterns include: IP addresses, port numbers, protocol flags (SYN, ACK), payload strings, packet size.
-
Example: Snort rule detecting
"GET /phpMyAdmin"in HTTP traffic.
C. IPSec
-
Modes:
-
Transport Mode: Protects transport layer payload; original IP header intact.
-
Tunnel Mode: Protects entire original IP packet; new IP header added.
-
-
Protocols:
-
AH: Integrity & authentication only; covers immutable header fields.
-
ESP: Confidentiality (encryption), integrity, authentication; covers payload (and optionally header in tunnel mode).
-
-
Security Association (SA): Unidirectional; identified by SPI, destination IP, protocol.
-
Key Management: IKE (Phase 1: IKE SA; Phase 2: IPSec SAs).
D. Access Point Security in a Public Network Environment
-
Challenges: Rogue APs, evil twins, eavesdropping, session hijacking.
-
Solutions:
-
Captive Portals: Force authentication via web page; often used with WPA2-Personal (pre-shared key) but weak.
-
WPA2-Enterprise with 802.1X: Each user has unique credentials (EAP-TLS, PEAP); RADIUS server authenticates.
-
Best Practices: Disable WPS, use strong passwords, monitor for rogue APs, segment guest network.
-
-
Risks: Evil twin mimicking SSID; man-in-the-middle if certificate validation bypassed.
E. Types of VPN
-
Remote Access VPN:
-
Individual users connect to private network over Internet.
-
Protocols: SSL/TLS (e.g., OpenVPN), IPsec (L2TP/IPsec), PPTP (insecure).
-
Use case: Employees working from home.
-
-
Site-to-Site (Router-to-Router) VPN:
-
Connects entire networks (e.g., branch offices).
-
Typically uses IPsec in tunnel mode.
-
Gateway devices (routers/firewalls) terminate tunnels.
-
Use case: Connecting geographically dispersed offices.
-
[!TIP] Exam Focus Areas (Based on Past Papers):
- Always show step-by-step calculations for RSA, RC4 keystream, Caesar cipher.
- Memorize SSL Handshake steps in order; know difference between session and connection.
- Draw and label diagrams for PGP message format, WAP architecture, IPSec modes.
- Compare and contrast (e.g., AH vs ESP, HIDS vs NIDS, VPN vs Trusted OS, block vs stream ciphers).
- Understand security implications of each protocol/mode (e.g., ECB pattern leakage, RC4 biases, WTLS gateway trust).
- Short notes from Dec 2024 Q15 are very likely to reappear.