Skip to content
CY-503 (B) · Network Security/Quick Revision Short Notes

Network Security (CY-503 (B)) - Unit 2 Short Notes

UNIT 2: NETWORK SECURITY – COMPREHENSIVE STUDY NOTES


I. CRYPTOGRAPHIC FOUNDATIONS

A. Symmetric Encryption

  • Definition: Same cryptographic key for both encryption and decryption.

  • Strengths: Fast, efficient for large data volumes.

  • Weaknesses: Key distribution problem; requires secure channel for key exchange.

  • Classical Cipher – Caesar Cipher:

    • Process: Each plaintext character shifted by fixed number k positions in alphabet.

    • Encryption: $$\displaystyle E(x) = (x + k) \mod 26 $$

    • Decryption: $$\displaystyle D(x) = (x - k) \mod 26 $$

    • Example (Dec 2024): Ciphertext ZICVTWQNGRZGVTWAVZHCQYGLMGJ, shift $$\displaystyle k=17 $$.

      • Convert letters to numbers (A=0, B=1, ..., Z=25).

      • For each ciphertext number $c$, compute $$\displaystyle p = (c - 17) \mod 26 $$.

      • Resulting plaintext: THEQUICKBROWNFOXJUMPSOVERTHELAZYDOG.

  • Block vs. Stream Ciphers:

    • Block Ciphers: Encrypt fixed-size blocks (e.g., 64-bit, 128-bit). Examples: AES, DES. Modes of operation required for repeated use.

    • Stream Ciphers: Encrypt bit/byte stream on-the-fly. Example: RC4.

  • Modes of Operation (for Block Ciphers):

    | Mode | Description | Merits | Demerits | |------|-------------|--------|----------| | ECB (Electronic Codebook) | Each block encrypted independently | Simple, parallelizable | Identical plaintext blocks → identical ciphertext; no diffusion | | CBC (Cipher Block Chaining) | XOR each plaintext block with previous ciphertext block | Hides patterns, requires IV | Sequential encryption, error propagation | | CFB (Cipher Feedback) | Turns block cipher into stream; feedback from ciphertext | Handles streaming data, no padding | Error propagation, sequential | | OFB (Output Feedback) | Generates keystream independent of plaintext/ciphertext | No error propagation, synchronous stream | Keystream reuse if IV reused | | CTR (Counter) | Encrypts counter value to produce keystream | Parallelizable, random access, no padding | Counter reuse catastrophic |

  • Modern Algorithm – AES (Advanced Encryption Standard):

    • Block Size: 128 bits; Key Sizes: 128, 192, 256 bits.

    • Round Structure (per round except last):

      1. SubBytes: Non-linear substitution using S-box.

      2. ShiftRows: Cyclic shift of rows in state matrix.

      3. MixColumns: Mixing columns for diffusion.

      4. AddRoundKey: XOR with round key.

    • Final round omits MixColumns.

  • Stream Cipher – RC4:

    • Keystream Generation: Uses a pseudo-random generation algorithm (PRGA) on an S-box (256 bytes) initialized by key-scheduling algorithm (KSA).

    • KSA: Initialize S-box with identity, then permute based on key.

    • PRGA: Generate keystream byte by byte by swapping S-box entries and outputting $S[S[i] + S[j]] \mod 256$.

    • Security Considerations: Vulnerable to biases in early output; weak if key has repetitions (e.g., WEP).

    • Example Task (5-bit key): For key K = [1,0,1,0,1] (binary, 5 bits = 21 decimal? But RC4 uses bytes; simplified example often uses small key for illustration). Typically, key is byte array. For exam, show KSA with key bytes.

      [!TIP] In exams, use a small integer key (e.g., key = [1,2,3]) and demonstrate KSA steps briefly.

B. Asymmetric (Public-Key) Encryption

  • Core Principles:

    • Public/Private Key Pairs: Public key shared; private key kept secret.

    • Mathematical Trapdoor: Easy to compute in one direction (e.g., multiplication), hard to reverse (e.g., factoring).

  • RSA Algorithm:

    • Key Generation:

      1. Choose large primes $p, q$.

      2. Compute $$\displaystyle n = p \cdot q $$, $$\displaystyle \phi(n) = (p-1)(q-1) $$.

      3. Choose $e$ such that $$\displaystyle 1 < e < \phi(n) $$ and $$\displaystyle \gcd(e, \phi(n)) = 1 $$.

      4. Compute $$\displaystyle d = e^{-1} \mod \phi(n) $$.

      • Public Key: $(e, n)$; Private Key: $(d, n)$.
    • Encryption: $$\displaystyle c = m^e \mod n $$

    • Decryption: $$\displaystyle m = c^d \mod n $$

    • Example (Nov 2023): $$\displaystyle p=3, q=11 $$.

      • $$\displaystyle n = 33 $$, $$\displaystyle \phi(n) = 20 $$.

      • Choose $$\displaystyle e=7 $$ (co-prime with 20).

      • $$\displaystyle d = 7^{-1} \mod 20 = 3 $$ (since $$\displaystyle 7 \cdot 3 = 21 \equiv 1 \mod 20 $$).

      • Encrypt $$\displaystyle m=2 $$: $$\displaystyle c = 2^7 \mod 33 = 128 \mod 33 = 29 $$.

      • Decrypt: $$\displaystyle m = 29^3 \mod 33 = 24389 \mod 33 = 2 $$.

    • Applications:

      • Confidentiality: Encrypt with recipient’s public key.

      • Digital Signatures: Sign with sender’s private key.

      • Key Exchange: Securely exchange symmetric keys.

C. Cryptographic Hash Functions & Message Authentication

  • Hash Function Properties:

    • Pre-image Resistance: Given hash $h$, hard to find $m$ such that $$\displaystyle H(m)=h $$.

    • Second Pre-image Resistance: Given $$\displaystyle m_1 $$, hard to find $$\displaystyle m_2 \neq m_1 $$ with $$\displaystyle H(m_1)=H(m_2) $$.

    • Collision Resistance: Hard to find any $$\displaystyle m_1, m_2 $$ such that $$\displaystyle H(m_1)=H(m_2) $$.

  • SHA-512 (Secure Hash Algorithm 512-bit):

    • Steps:

      1. Padding: Append '1' bit, then '0's, then length (128-bit) to make total length multiple of 1024 bits.

      2. Parsing: Divide into 1024-bit blocks $$\displaystyle M^{(1)}, ..., M^{(N)} $$.

      3. Hash Computation: Initialize eight 64-bit buffers (initial values). For each block, expand to 80 words, then 80 rounds of operations using constants and functions.

    • Output is 512-bit digest.

  • Message Authentication Codes (MACs):

    • Definition: Short tag generated from message and secret key, providing integrity and authentication.

    • Purpose: Detect message modification and verify sender identity (symmetric key).

  • HMAC (Hash-based MAC):

    • Construction: $$\displaystyle HMAC(K, m) = H((K \oplus opad) \parallel H((K \oplus ipad) \parallel m)) $$

      • $K$: secret key (padded to block size).

      • $ipad$: 0x36 repeated; $opad$: 0x5C repeated.

      • $H$: underlying hash (e.g., SHA-256).

    • Security: Based on strength of underlying hash; resistant to length extension attacks.

  • Digital Signatures:

    • Process:

      1. Sender hashes message: $$\displaystyle h = H(m) $$.

      2. Sender encrypts hash with private key: $$\displaystyle s = h^d \mod n $$ (RSA) or uses DSA/ECDSA.

      3. Sender sends $(m, s)$.

    • Verification:

      1. Receiver hashes received message: $$\displaystyle h' = H(m) $$.

      2. Receiver decrypts signature with public key: $$\displaystyle h'' = s^e \mod n $$.

      3. If $$\displaystyle h' = h'' $$, signature valid.

    • Crucial Aspects:

      • Non-repudiation: Sender cannot deny sending.

      • Authentication: Receiver sure of sender identity.

      • Integrity: Any change in message invalidates signature.


II. SECURE COMMUNICATION PROTOCOLS & APPLICATIONS

A. Email Security: PGP (Pretty Good Privacy)

  • Working Principle: Hybrid cryptosystem.

    1. Symmetric Encryption: Message encrypted with random session key (e.g., AES).

    2. Asymmetric Encryption: Session key encrypted with recipient’s public key.

    3. Hashing: Message digest computed (e.g., SHA-256) and signed with sender’s private key.

    4. Compression: Applied before encryption (optional).

    5. Email Compatibility: Radix-64 encoding for ASCII transmission.

  • PGP Message Format:

    • Structure: [Signature] [Session Key] [Encrypted Data] [Radix-64]

    • DiagramSEARCH: PGP message format diagram
  • Services Provided:

    • Confidentiality (via symmetric encryption).

    • Authentication & Integrity (via digital signatures).

    • Compression (reduces size).

    • Email Compatibility (ASCII armor).

B. Transport & Web Layer Security: SSL/TLS

  • SSL Record Protocol Services:

    • Confidentiality: Using symmetric encryption (session key).

    • Integrity: Using MAC (e.g., HMAC).

    • Authentication: Optional, via certificates.

  • SSL Handshake Protocol (Detailed Steps):

    1. ClientHello: Client sends supported cipher suites, protocol version, random number $$\displaystyle R_C $$.

    2. ServerHello: Server selects cipher suite, sends server random $$\displaystyle R_S $$, server certificate (with public key).

    3. ServerKeyExchange (if needed): For ephemeral keys (DHE/ECDHE).

    4. ServerHelloDone: Server signals end of hello messages.

    5. ClientKeyExchange: Client generates pre-master secret $PMS$, encrypts with server’s public key, sends.

    6. ChangeCipherSpec (Client): Client switches to negotiated cipher suite.

    7. Finished (Client): Encrypted hash of handshake messages.

    8. ChangeCipherSpec (Server) & Finished (Server): Server switches and sends finished.

    • Both compute master secret from $PMS$, $$\displaystyle R_C $$, $$\displaystyle R_S $$. Then derive session keys.
  • SSL Session vs. SSL Connection:

    • SSL Session: Negotiated security parameters (cipher suite, master secret) between client and server. Can be reused for multiple connections (session resumption).

    • SSL Connection: Specific instance of communication using a session. Each connection has its own read/write keys.

    • Role: Sessions improve efficiency (avoid full handshake); connections provide ephemeral keys for forward secrecy (if using DHE/ECDHE).

C. Electronic Payment Security: SET (Secure Electronic Transaction)

  • Main Security Concerns:

    • Payment card data exposure (to merchant).

    • Consumer privacy (order details visible to merchant/bank).

    • Merchant authentication.

  • How SET Addresses Concerns:

    • Dual Signatures: Customer signs order info and payment info separately; merchant sees order, bank sees payment without linking.

    • Separation of Order & Payment Info: Prevents merchant from learning card details.

    • Use of Certificates: All participants (cardholder, merchant, bank, gateway) have X.509 certificates.

  • Participants & Transaction Flow:

    1. Cardholder: Has card & certificate.

    2. Merchant: Has merchant certificate.

    3. Acquiring Bank: Processes payments.

    4. Payment Gateway: Interfaces with bank.

    5. Flow: Request → Initiation (dual signatures) → Payment Authorization → Capture.

D. Network Layer Security: IPSec

  • Modes:

    • Transport Mode: Protects payload (TCP/UDP/ICMP) of original IP packet. Original IP header intact (except optional fields). Used for end-to-end (host-to-host).

    • Tunnel Mode: Protects entire original IP packet (header + payload). New IP header added. Used for gateway-to-gateway (site-to-site VPN).

  • Protocols:

    • AH (Authentication Header): Provides integrity, authentication, anti-replay (sequence number). No confidentiality. Covers immutable parts of IP header + payload.

    • ESP (Encapsulating Security Payload): Provides confidentiality (encryption), integrity, authentication. Can be used in both modes. Encrypts payload (and optionally ESP trailer).

  • Security Associations (SA): Unidirectional logical connection defined by:

    • SPI (Security Parameter Index): 32-bit identifier in AH/ESP header.

    • IP Destination Address.

    • Security Protocol (AH/ESP).

  • Key Management: IKE (Internet Key Exchange) – two phases: Phase 1 (authenticate peers, establish IKE SA), Phase 2 (negotiate IPSec SAs).


III. NETWORK SECURITY MECHANISMS & ARCHITECTURES

A. Firewalls

  • Classification & Operational Differences:

    1. Packet Filtering Firewall (Stateless):

      • Inspects individual packets based on rules (IP, port, protocol).

      • No memory of connections; vulnerable to spoofing.

    2. Circuit-Level Gateway Firewall (Stateful):

      • Monitors TCP handshakes (SYN, SYN-ACK, ACK) to track connection state.

      • Allows packets belonging to established connections.

    3. Application-Level Gateway (Proxy Firewall):

      • Acts as intermediary; inspects application-layer data (e.g., HTTP commands).

      • Protocol-aware; can filter specific commands (e.g., FTP PORT).

    4. Stateful Multilayer Inspection (SMI) Firewall:

      • Combines stateful inspection with deep packet inspection at multiple layers.
  • Merits and Demerits (General):

    • Merits: Control access, hide internal network, logging/auditing.

    • Demerits: Cannot prevent all attacks (e.g., insider, social engineering), performance overhead, complex configuration.

  • Proxy vs. Personal Firewalls:

    • Proxy Firewall: Network-based; sits between internal and external networks; protects entire network.

    • Personal Firewall: Host-based; installed on individual machines; controls inbound/outbound traffic for that host.

B. Intrusion Detection & Prevention Systems (IDS/IPS)

  • Host-based IDS (HIDS):

    • Monitors individual host: log files, system calls, file integrity.

    • Example: OSSEC, Tripwire.

  • Network-based IDS (NIDS):

    • Monitors network traffic via sensors/sniffers.

    • Example: Snort, Suricata.

  • Detection Techniques:

    • Signature-based (Misuse Detection): Matches known attack patterns (signatures).

    • Anomaly-based: Detects deviations from normal baseline (statistical, machine learning).

  • Parameter Pattern Matching (Signature-based):

    • Matches specific packet parameters: source/dest IP, port, protocol flags, packet size, payload patterns.

    • Example: Snort rule: alert tcp any any -> 192.168.1.1 80 (content:"GET /admin";)

C. Virtual Private Networks (VPN)

  • Definition: Secure encrypted tunnel over public network (e.g., Internet) connecting remote sites/users.

  • Types of VPNs:

    1. Remote Access VPN: Individual users connect to corporate network (e.g., employee from home). Uses protocols like PPTP, L2TP/IPsec, SSL/TLS.

    2. Site-to-Site (Router-to-Router) VPN: Connects entire networks (e.g., branch offices). Often uses IPsec in tunnel mode.

  • Comparison: VPN vs. Trusted Operating Systems

    | Aspect | VPN | Trusted OS | |--------|-----|------------| | Security Level | Network-level (layer 3) | Host-level (OS kernel) | | Primary Goal | Secure communication over untrusted networks | Enforce mandatory access control (MAC) on a single system | | Mechanism | Encryption, tunneling, authentication | Security kernel, formal verification, reference monitor | | Application | Remote access, inter-site connectivity | High-assurance systems (military, government) | | Scope | Protects data in transit | Protects data at rest and processes |

D. Trusted Operating Systems

  • Concept: OS designed with security as primary goal.

    • Mandatory Access Control (MAC): Central authority defines access policies (e.g., Bell-LaPadula, Biba).

    • Security Kernels: Minimal, verified kernel enforcing security policy.

    • Formal Verification: Mathematical proofs of correctness.

  • Comparison with VPNs: See table above.


IV. WIRELESS & MOBILE SECURITY

A. Wireless LAN (WLAN) Security Challenges

  • Inherent Vulnerabilities of Radio Transmission:

    • Eavesdropping (wireless signals travel beyond physical boundaries).

    • Jamming (noise on channel).

    • Interception/modification (no physical control).

  • Threats:

    • Rogue Access Points (unauthorized APs inside network).

    • Evil Twin (malicious AP mimicking legitimate one).

    • Denial-of-Service (deauthentication attacks, jamming).

    • Session Hijacking (stealing session keys).

B. WLAN Protocol Stack & Security

  • IEEE 802.11i Standard (Robust Security Network - RSN):

    • Defines CCMP (Counter Mode with Cipher Block Chaining Message Authentication Code Protocol) using AES.

    • Uses 802.1X for authentication (EAP framework).

  • MPDU Frame Format (MAC Header):

    • Key fields: Frame Control, Duration, Addr1 (Receiver), Addr2 (Transmitter), Addr3 (BSSID), Sequence Control, QoS, HT Control, Payload, FCS.

    • Security-related: Frame Control bits (To DS, From DS, Protected Frame), Addr4 (for WDS), payload encrypted in CCMP.

  • Access Point Security in Public Network Environments:

    • Captive Portals: Web-based login before granting access.

    • WPA2-Enterprise: Uses 802.1X with RADIUS server; each user has unique credentials/certificates.

    • Risks: Evil Twin attacks, man-in-the-middle on captive portals, weak EAP methods.

C. Wireless Application Protocol (WAP) Security

  • WAP Architecture Overview:

    • Client: Mobile device with WAP browser.

    • Gateway (WAP Proxy): Translates WAP requests to HTTP/HTTPS; sits between client and server.

    • Server: Web server hosting content.

  • WTLS (Wireless Transport Layer Security):

    • Role: Provides security for wireless transport (like TLS for wired).

    • Adaptations for constrained devices: Smaller packet sizes, optimized handshake, support for unreliable datagrams.

    • Secures Wireless Comms: Confidentiality (encryption), integrity (MAC), authentication (certificates).

  • Security Issues in WTLS:

    • Gateway as Point of Trust: Gateway can decrypt/read all traffic (trusted by both sides).

    • Protocol Gaps: Early versions had weak crypto (export restrictions), vulnerable to man-in-the-middle if certificate validation skipped.

    • End-to-End Missing: Security ends at gateway; from gateway to server may be plain HTTP.


V. THREATS & COUNTERMEASURES

A. Malicious Software (Malware)

  • Types:

    • Virus: Attaches to executable files; requires user action.

    • Worm: Self-replicating, spreads via network (e.g., SQL Slammer).

    • Trojan Horse: Disguised as legitimate software; opens backdoor.

    • Ransomware: Encrypts files, demands ransom.

    • Spyware: Monitors user activity, steals data.

    • Adware: Displays unwanted ads.

    • Rootkit: Hides existence of other malware, deep OS integration.

  • Infiltration Methods:

    • Email attachments (macro viruses).

    • Drive-by downloads (malicious websites).

    • Removable media (USB autorun).

    • Network shares (exploiting weak shares).

B. Role of Security Devices Against Malware

  • Firewalls:

    • Block ports/protocols used by malware (e.g., block SMB for worm propagation).

    • Application controls (allow only approved apps).

    • Limitations: Cannot inspect encrypted traffic; application-layer attacks may pass.

  • IDS/IPS:

    • Signature-based: Detect known malware traffic patterns (e.g., specific exploit strings).

    • Anomaly-based: Detect unusual traffic spikes (worm propagation) or beaconing (C2 communication).

    • IPS: Can block malicious packets in real-time.


VI. ADVANCED AUTHENTICATION & EMERGING TOPICS

A. Authentication Mechanisms

  • Biometric Authentication:

    • Types: Fingerprint, Iris, Facial recognition, Voice, Vein patterns.

    • Process: Capture → Feature Extraction → Template Storage → Matching (1:1 verification or 1:N identification).

    • Advantages: Hard to forge/lose; convenient.

    • Limitations: False Reject Rate (FRR), False Accept Rate (FAR), cost, privacy concerns, template theft.

  • Smart Cards: "Something you have." Store cryptographic keys or certificates; require PIN (something you know) for access.

B. Web Traffic Security Approaches

  • Primary: SSL/TLS (HTTPS) – encrypts entire HTTP session.

  • VPNs: Used for remote access to internal web applications (SSL VPN or IPsec).

  • IPsec: Less common for web; used for securing backend server communications.

C. Parameter Pattern Matching

  • Reiterated as signature-based IDS technique matching specific packet parameters (IP, port, flags, size, payload patterns).

VII. SHORT NOTES SYLLABUS (Dec 2024 Q15)

A. Message Authentication Codes (MACs)

  • Symmetric key-based tag for integrity and authentication.

  • Generated by combining message with secret key via algorithm (e.g., HMAC, CBC-MAC).

  • Receiver recomputes MAC with shared key; match ensures message not altered and sender knows key.

  • Example: HMAC-SHA256.

B. Parameter Pattern Matching

  • Signature-based IDS method.

  • Matches predefined patterns in packet headers/payloads.

  • Patterns include: IP addresses, port numbers, protocol flags (SYN, ACK), payload strings, packet size.

  • Example: Snort rule detecting "GET /phpMyAdmin" in HTTP traffic.

C. IPSec

  • Modes:

    • Transport Mode: Protects transport layer payload; original IP header intact.

    • Tunnel Mode: Protects entire original IP packet; new IP header added.

  • Protocols:

    • AH: Integrity & authentication only; covers immutable header fields.

    • ESP: Confidentiality (encryption), integrity, authentication; covers payload (and optionally header in tunnel mode).

  • Security Association (SA): Unidirectional; identified by SPI, destination IP, protocol.

  • Key Management: IKE (Phase 1: IKE SA; Phase 2: IPSec SAs).

D. Access Point Security in a Public Network Environment

  • Challenges: Rogue APs, evil twins, eavesdropping, session hijacking.

  • Solutions:

    • Captive Portals: Force authentication via web page; often used with WPA2-Personal (pre-shared key) but weak.

    • WPA2-Enterprise with 802.1X: Each user has unique credentials (EAP-TLS, PEAP); RADIUS server authenticates.

    • Best Practices: Disable WPS, use strong passwords, monitor for rogue APs, segment guest network.

  • Risks: Evil twin mimicking SSID; man-in-the-middle if certificate validation bypassed.

E. Types of VPN

  1. Remote Access VPN:

    • Individual users connect to private network over Internet.

    • Protocols: SSL/TLS (e.g., OpenVPN), IPsec (L2TP/IPsec), PPTP (insecure).

    • Use case: Employees working from home.

  2. Site-to-Site (Router-to-Router) VPN:

    • Connects entire networks (e.g., branch offices).

    • Typically uses IPsec in tunnel mode.

    • Gateway devices (routers/firewalls) terminate tunnels.

    • Use case: Connecting geographically dispersed offices.


[!TIP] Exam Focus Areas (Based on Past Papers):

  • Always show step-by-step calculations for RSA, RC4 keystream, Caesar cipher.
  • Memorize SSL Handshake steps in order; know difference between session and connection.
  • Draw and label diagrams for PGP message format, WAP architecture, IPSec modes.
  • Compare and contrast (e.g., AH vs ESP, HIDS vs NIDS, VPN vs Trusted OS, block vs stream ciphers).
  • Understand security implications of each protocol/mode (e.g., ECB pattern leakage, RC4 biases, WTLS gateway trust).
  • Short notes from Dec 2024 Q15 are very likely to reappear.
Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in