Skip to content
CY-503 (B) · Network Security/Quick Revision Short Notes

Network Security (CY-503 (B)) - Unit 4 Short Notes

UNIT 4: NETWORK SECURITY - SHORT NOTES

I. CRYPTOGRAPHIC FOUNDATIONS & PRINCIPLES

A. Symmetric Encryption

  • Core Principle: Same secret key $K$ used for both encryption $$\displaystyle E_K(P) $$ and decryption $$\displaystyle D_K(C) $$. Provides confidentiality.

  • Block vs. Stream Ciphers:

    | Feature | Block Cipher | Stream Cipher | | :--- | :--- | :--- | | Unit | Fixed-size block (e.g., 128 bits) | Continuous stream of bits/bytes | | Modes | Requires (ECB, CBC, etc.) | Typically inherent (synchronous) or self-synchronizing (CFB) | | Example | AES, DES | RC4, A5/1 | | Error Propagation | Can affect entire block (CBC) | Limited to corrupted bits | | Speed | Slower, more complex | Faster, simpler hardware |

  • Modes of Operation (for Block Ciphers):

    • ECB (Electronic Codebook): Each block encrypted independently. Merit: Simple, parallelizable. Demerit: Identical plaintext blocks → identical ciphertext blocks (pattern leakage).

    • CBC (Cipher Block Chaining): $$\displaystyle C_i = E_K(P_i \oplus C_{i-1}) $$, $$\displaystyle C_0 = IV $$. Merit: Hides patterns, widely used. Demerit: Sequential encryption, IV must be unpredictable.

    • CFB (Cipher Feedback): Turns block cipher into stream. $$\displaystyle C_i = P_i \oplus E_K(C_{i-1}) $$. Merit: Handles data units < block size. Demerit: Error propagation.

    • OFB (Output Feedback): Generates keystream independent of plaintext/ciphertext. $$\displaystyle O_i = E_K(O_{i-1}) $$, $$\displaystyle C_i = P_i \oplus O_i $$. Merit: No error propagation. Demerit: If keystream repeats, catastrophic.

    • CTR (Counter): $$\displaystyle C_i = P_i \oplus E_K(IV + i) $$. Merit: Parallelizable, random access. Demerit: IV must never repeat with same key.

    [!TIP] Exam Focus: Be prepared to compare/contrast modes and identify which is suitable for a given scenario (e.g., CTR for high-speed networks, CBC for general-purpose).

  • High-Frequency Algorithm: Advanced Encryption Standard (AES)

    • Structure: Iterated Substitution-Permutation Network (SPN). 10/12/14 rounds for 128/192/256-bit keys.

    • Round Operations (except last round):

      1. SubBytes: Non-linear substitution using S-box (confusion).

      2. ShiftRows: Cyclic shift of rows (diffusion across columns).

      3. MixColumns: Linear mixing of columns (diffusion within column).

      4. AddRoundKey: XOR with round key.

    • Key Expansion: Round keys derived from cipher key via Rijndael's key schedule.

    • Decryption: Inverse operations in reverse order (InvSubBytes, InvShiftRows, InvMixColumns, AddRoundKey).

    [!TIP] Common Pitfall: MixColumns is omitted in the final decryption round. AES operates on a 4x4 byte state matrix.

  • High-Frequency Algorithm: RC4 Stream Cipher

    • Workflow: Two phases: Key Scheduling (KSA) initializes 256-byte S-box, Pseudo-Random Generation Algorithm (PRGA) generates keystream bytes.

    • KSA:

      
      for i = 0 to 255: S[i] = i
      
      j = 0
      
      for i = 0 to 255:
      
          j = (j + S[i] + key[i mod keylen]) mod 256
      
          swap(S[i], S[j])
      
      
    • PRGA:

      
      i = j = 0
      
      while generating:
      
          i = (i + 1) mod 256
      
          j = (j + S[i]) mod 256
      
          swap(S[i], S[j])
      
          t = (S[i] + S[j]) mod 256
      
          keystream_byte = S[t]
      
      
    • Worked Example (5-byte key for clarity): Let key = [0x01, 0x02, 0x03, 0x04, 0x05].

      1. KSA: Initialize S[0..255]=0..255. For i=0: j=(0+S[0]+key[0])=1 → swap S[0],S[1]. Continue for all 256 iterations.

      2. PRGA (first 3 bytes):

        • i=1, j=(0+S[1]) mod 256 → swap S[1],S[j], t=(S[1]+S[j]) mod 256, output S[t].

        • i=2, j=(prev_j + S[2]) mod 256 → swap, output.

        • i=3, j=(prev_j + S[3]) mod 256 → swap, output.

      [!TIP] Exam Alert: RC4 has weaknesses in initial keystream (e.g., biases in second byte). Never use with same key for multiple sessions.

  • Historical Cipher: Caesar Cipher

    • Encryption: $$\displaystyle C = (P + k) \mod 26 $$, where $P, C$ are letter indices (0-25), $k$ is shift.

    • Decryption: $$\displaystyle P = (C - k) \mod 26 $$.

    • Example: Ciphertext 'ZICVTWQNGRZGVTWAVZHCQYGLMGJ', shift $$\displaystyle k=17 $$.

      • Convert letters to numbers (A=0, B=1, ..., Z=25).

      • For each ciphertext number $C$, compute $$\displaystyle P = (C - 17) \mod 26 $$.

      • Result: 'THEQUICKBROWNFOXJUMPSOVERTHELAZYDOG'.

B. Asymmetric (Public-Key) Cryptography

  • Fundamental Principles:

    • Key Pair: Public key ($PK$) for encryption/verification, Private key ($SK$) for decryption/signing. Mathematically linked.

    • Key Distribution: Public keys can be shared openly; private keys kept secret. Relies on Public Key Infrastructure (PKI) and certificates for authenticity.

    • One-Way Function: Easy to compute $$\displaystyle y=f(x) $$, infeasible to compute $$\displaystyle x=f^{-1}(y) $$ without trapdoor (private key).

  • High-Frequency Algorithm: RSA

    • Mathematical Foundation: Based on difficulty of factoring large integers. Euler's Totient: $$\displaystyle \phi(n) = (p-1)(q-1) $$ for $$\displaystyle n=pq $$, $p,q$ prime.

    • Key Generation:

      1. Choose large primes $p, q$.

      2. Compute $$\displaystyle n = p \times q $$, $$\displaystyle \phi(n) = (p-1)(q-1) $$.

      3. Choose $e$ such that $$\displaystyle 1 < e < \phi(n) $$ and $$\displaystyle \gcd(e, \phi(n)) = 1 $$.

      4. Compute $$\displaystyle d = e^{-1} \mod \phi(n) $$ (using Extended Euclidean Algorithm).

      Public Key: $(e, n)$, Private Key: $(d, n)$.

    • Encryption: $$\displaystyle C = P^e \mod n $$.

    • Decryption: $$\displaystyle P = C^d \mod n $$.

    • Worked Example ($$\displaystyle p=3, q=11 $$):

      • $$\displaystyle n = 33 $$, $$\displaystyle \phi(n) = 2 \times 10 = 20 $$.

      • Choose $$\displaystyle e=7 $$ (coprime with 20).

      • $$\displaystyle d = 7^{-1} \mod 20 = 3 $$ (since $$\displaystyle 7 \times 3 = 21 \equiv 1 \mod 20 $$).

      • Encrypt $$\displaystyle P=2 $$: $$\displaystyle C = 2^7 \mod 33 = 128 \mod 33 = 29 $$.

      • Decrypt $$\displaystyle C=29 $$: $$\displaystyle P = 29^3 \mod 33 = 24389 \mod 33 = 2 $$.

    [!TIP] Critical: RSA encryption/signature padding (e.g., OAEP, PSS) is mandatory in practice to avoid deterministic attacks.

C. Cryptographic Hash Functions & Message Authentication

  • Hash Function Properties:

    • Pre-image Resistance: Given hash $h$, infeasible to find $m$ such that $$\displaystyle H(m)=h $$.

    • Second Pre-image Resistance: Given $$\displaystyle m_1 $$, infeasible to find $$\displaystyle m_2 \neq m_1 $$ with $$\displaystyle H(m_1)=H(m_2) $$.

    • Collision Resistance: Infeasible to find any $$\displaystyle m_1, m_2 $$ with $$\displaystyle H(m_1)=H(m_2) $$.

    • Deterministic, Fast Computation, Avalanche Effect.

  • High-Frequency Algorithm: SHA-512 (SHA-2 Family)

    • Input: Message $m$ of any length.

    • Steps:

      1. Padding: Append '1' bit, then '0' bits, then 128-bit length of original message (in bits). Total length $\equiv 896 \mod 1024$.

      2. Parsing: Break padded message into 1024-bit blocks $$\displaystyle M^{(1)}, ..., M^{(N)} $$.

      3. Initialize Hash Values ($$\displaystyle H_0^{(0)}..H_7^{(0)} $$): 8 constants from square roots of first 8 primes.

      4. Process Each Block: For each block, 80 rounds of operations using message schedule $$\displaystyle W_t $$, constants $$\displaystyle K_t $$, and functions $$\displaystyle Ch, Maj, \Sigma_0, \Sigma_1 $$. Update working variables.

      5. Output: Final hash = $$\displaystyle H_0^{(N)} || ... || H_7^{(N)} $$ (512 bits).

    • Message Digest: Fixed-size output (512 bits) uniquely representing input.

  • Message Authentication Codes (MACs)

    • Purpose: Provide integrity + authentication (but not non-repudiation). Both parties share secret key $K$.

    • HMAC (Hash-based MAC) Algorithm:

      
      HMAC_K(m) = H( (K ⊕ opad) || H( (K ⊕ ipad) || m ) )
      
      

      Where $H$ is hash (e.g., SHA-256), ipad = 0x36 repeated, opad = 0x5C repeated. Key $K$ padded/truncated to block size.

    • Comparison with Digital Signatures:

      | Feature | MAC (HMAC) | Digital Signature (RSA/DSA) | | :--- | :--- | :--- | | Key | Shared secret (symmetric) | Public/Private key pair | | Provides | Integrity, Authentication | Integrity, Authentication, Non-Repudiation | | Scalability | $O(n)$ keys for $n$ parties | $O(n)$ public keys, each party manages one private key | | Computation | Faster (hash only) | Slower (public-key ops) |

  • Parameter Pattern Matching

    • Definition: Technique used in Intrusion Detection Systems (IDS) and integrity checking where known attack signatures (byte patterns, sequences, or parameter values) are searched for in network traffic, log files, or file contents.

    • Process: Predefined patterns (e.g., "cmd.exe /C" for shell invocation) are matched against data streams using efficient string matching algorithms (e.g., Aho-Corasick, Boyer-Moore).

    • Use Case: Signature-based IDS detects malware, exploits; file integrity checkers (e.g., Tripwire) detect unauthorized changes by matching current hash/parameters against baseline.

II. AUTHENTICATION, INTEGRITY & NON-REPUDIATION

A. Digital Signatures

  • How it Works (using RSA):

    1. Signing: Sender computes signature $$\displaystyle S = H(m)^d \mod n $$ (using their private key $(d,n)$).

    2. Verification: Receiver computes $$\displaystyle H'(m) = S^e \mod n $$ (using sender's public key $(e,n)$) and compares with independently computed $H(m)$.

  • Importance:

    • Authentication: Confirms sender's identity.

    • Integrity: Any change in $m$ invalidates signature.

    • Non-Repudiation: Sender cannot deny sending (only they possess $d$).

  • Role in Protocols: Used in PGP (signing emails), SSL/TLS (server authentication), code signing.

B. Advanced Authentication Mechanisms

  • Biometric Authentication:

    • Principle: Uses unique physiological/behavioral traits (fingerprint, iris, face, voice).

    • Types: Physiological (fingerprint, iris) vs. Behavioral (keystroke dynamics, gait).

    • Challenges: False Rejection Rate (FRR), False Acceptance Rate (FAR), template security, cost, user acceptance.

  • Smart Cards:

    • Principle: Physical token with embedded microprocessor/memory storing credentials (certificates, keys). Requires card reader + PIN (two-factor).

    • Applications: ATM cards, SIM cards, corporate ID/access, e-passports.

III. SECURE COMMUNICATION PROTOCOLS & APPLICATIONS

A. Email Security: Pretty Good Privacy (PGP)

  • Working (Hybrid Cryptosystem):

    1. Compression: Message compressed (ZIP) to reduce size & remove patterns.

    2. Session Key: Generate random symmetric key $$\displaystyle K_s $$ (e.g., AES).

    3. Encryption: Encrypt compressed message with $$\displaystyle K_s $$.

    4. Signing (optional): Sign message digest (SHA) with sender's private RSA key.

    5. Key Encryption: Encrypt $$\displaystyle K_s $$ with recipient's public RSA key.

    6. Format: Combine signature (if any), encrypted $$\displaystyle K_s $$, encrypted message into Radix-64 (ASCII armor).

  • Services: Confidentiality (symmetric + PK), Authentication (digital signatures), Compression, Email Compatibility (Radix-64).

  • General Format of PGP Message:

    
    [Signature Packet] (optional)
    
    [Public-Key Encrypted Session Key Packet] (one per recipient)
    
    [Symmetrically Encrypted Data Packet] (compressed message)
    
    [Modification Detection Code Packet] (optional, SHA-1 hash)
    
    
    DiagramPGP message structure showing packet sequence

B. Web Security: SSL/TLS

  • High-Frequency Topic: SSL Handshake Protocol (TLS 1.2 example):

    1. ClientHello: Client sends supported TLS version, cipher suites, random nonce $$\displaystyle R_C $$.

    2. ServerHello: Server selects TLS version, cipher suite, sends random nonce $$\displaystyle R_S $$, and Server Certificate (X.509).

    3. ServerKeyExchange (if needed): E.g., for DH parameters.

    4. ServerHelloDone: Server signals end of hello messages.

    5. ClientKeyExchange: Client sends PreMasterSecret encrypted with server's public key (RSA) or its DH public value.

    6. ChangeCipherSpec (Client): Client signals subsequent messages will be encrypted.

    7. Finished (Client): Encrypted hash of all handshake messages so far.

    8. ChangeCipherSpec (Server) & Finished (Server): Server does the same.

    • Master Secret: Derived from PreMasterSecret and both nonces ($$\displaystyle R_C, R_S $$) using PRF.
  • SSL Connection vs. SSL Session:

    • Session: Established by handshake. Stores security parameters (master secret, cipher suite, peer certs). Can be resumed via Session ID or Session Ticket to avoid full handshake.

    • Connection: Actual network connection using a session's parameters. Multiple connections can reuse one session.

    • Contribution to Web Traffic: Session resumption drastically reduces latency and computational cost for frequent connections (e.g., web browsing), improving performance and scalability.

  • SSL Record Protocol Services:

    • Confidentiality: Symmetric encryption (AES, 3DES).

    • Integrity: HMAC (e.g., SHA-256).

    • Authentication: Optional via certificates.

    • Fragmentation & Reassembly.

C. Network Layer Security: IPSec

  • Architecture: Two primary protocols:

    • AH (Authentication Header): Provides data origin authentication, integrity, anti-replay. No encryption. Covers immutable parts of IP header + payload.

    • ESP (Encapsulating Security Payload): Provides confidentiality (encryption), authentication, integrity, anti-replay. Encrypts payload (and optionally trailer).

  • Modes of Operation:

    • Transport Mode: Original IP header preserved, ESP/AH inserted after header. Protects transport layer segment (TCP/UDP). Used for end-to-end (host-to-host).

    • Tunnel Mode: Entire original IP packet is encapsulated as payload in new IP packet with new header. Protects entire original IP packet. Used for gateway-to-gateway (site-to-site VPN) or host-to-gateway.

    • Comparison of AH and ESP:

      | Service | AH | ESP | | :--- | :--- | :--- | | Confidentiality | No | Yes (optional) | | Integrity | Yes | Yes (optional) | | Authentication | Yes | Yes (optional) | | Anti-Replay | Yes | Yes | | NAT Traversal | No | Yes (with UDP encapsulation) | | Covers IP Header | Immutable fields only | No (unless tunnel mode) |

D. E-Commerce Security: Secure Electronic Transaction (SET)

  • Main Security Concerns: Confidentiality (payment info), Integrity (order/payment), Authentication (cardholder, merchant, bank), Non-Repudiation.

  • How SET Addresses:

    • Dual Signatures: Cardholder signs order info and payment info separately, then combines. Merchant sees order, bank sees payment, neither sees both.

    • Certificates: All parties (Cardholder, Merchant, Bank) have X.509 certificates from Certification Authorities (CAs).

    • Key Management: Uses symmetric key (DES) for message encryption, public key (RSA) for key exchange and signatures.

  • Application in Business: Parties: Cardholder, Merchant, Acquiring Bank, Issuing Bank. Flow: Cardholder → Merchant (order+payment) → Merchant → Bank (payment) → Bank → Issuer → Merchant.

E. Virtual Private Networks (VPN)

  • Definition: Secure "tunnel" over untrusted network (Internet) using encryption and tunneling.

  • Types of VPNs:

    • Remote Access VPN: Individual user connects to corporate network via VPN client (e.g., SSL VPN, IPsec client).

    • Site-to-Site VPN: Connects entire networks (e.g., branch offices). Subtypes:

      • Intranet VPN: Connects LANs of same organization.

      • Extranet VPN: Connects LANs of different organizations (e.g., with partners).

  • Comparison: VPN vs. Trusted Operating Systems

    | Aspect | VPN | Trusted Operating System | | :--- | :--- | :--- | | Security Mechanism | Encryption & Tunneling over public networks | Mandatory Access Controls (MAC) like Bell-LaPadula, Biba on a single, physically secured system | | Primary Goal | Secure communication over untrusted infrastructure | Prevent unauthorized access/leakage within a single trusted system | | Architecture | Peer-to-peer or gateway-based tunneling | Centralized, kernel-enforced security policy | | Use Case | Connect remote users/sites over Internet | High-security environments (military, government) requiring strict data flow control on a standalone system |

IV. NETWORK SECURITY INFRASTRUCTURE & DEFENSE

A. Intrusion Detection Systems (IDS)

  • Classification:

    • Host-based IDS (HIDS): Installed on individual host. Monitors system logs, file integrity, process activity. Example: OSSEC, Wazuh.

    • Network-based IDS (NIDS): Monitors network traffic (often via SPAN/mirror port). Sensors placed at strategic points.

      DiagramNIDS placement with network tap/SPAN port

  • Detection Techniques:

    • Signature-based Detection: Compares traffic/activity against database of known attack patterns (Parameter/Pattern Matching). Low false positives, cannot detect novel attacks.

    • Anomaly-based Detection: Establishes baseline of "normal" activity (using statistics, ML). Flags deviations. Can detect zero-days, higher false positives.

B. Firewalls

  • Primary Classification & Operational Differences:

    | Type | Packet Filtering | Circuit-Level Gateway | Application-Level Gateway (Proxy) | | :--- | :--- | :--- | :--- | | Layer | Network/Transport (IP, Port) | Session (TCP/UDP) | Application (HTTP, FTP, SMTP) | | State | Stateless (per-packet) | Stateful (tracks sessions) | Stateful (per-connection) | | Inspection | Header fields (IP, port, flags) | Session validity (TCP handshake) | Deep Packet Inspection (DPI), application commands | | Example | iptables (stateful module), router ACLs | SOCKS, stateful iptables | HTTP proxy (Squid), FTP proxy | | Merits | Fast, transparent, low cost | Better security than stateless, tracks connections | Highest security, can filter content, hide internal network | | Demerits | Vulnerable to spoofing, no app awareness | Cannot inspect application data | Performance bottleneck, requires per-app proxy, may break some protocols |

  • Comparison: Proxy Firewalls vs. Personal Firewalls:

    | Feature | Proxy Firewall | Personal Firewall | | :--- | :--- | :--- | | Deployment | Network gateway (perimeter) | Individual host/endpoint | | Function | Acts as intermediary (client ↔ server), terminates connections | Filters traffic to/from the host, controls applications | | Visibility | Sees all traffic passing through gateway | Sees only host's traffic | | Primary Use | Network perimeter defense | Host hardening, insider threat, mobile devices |

C. Malware (Malicious Software)

  • Types of Malware:

    • Virus: Attaches to legitimate program/file, requires user execution.

    • Worm: Self-replicating, spreads via network/email without user action.

    • Trojan Horse: Disguised as legitimate software, provides backdoor.

    • Ransomware: Encrypts files, demands ransom.

    • Spyware: Secretly monitors user activity.

    • Rootkit: Hides existence/activities of other malware at OS/kernel level.

    • Bot/Botnet: Compromised host under attacker control (C&C).

  • How IDS and Firewalls Help:

    • IDS: Signature-based detects known malware traffic/patterns; Anomaly-based detects unusual network behavior (e.g., beaconing, data exfiltration).

    • Firewalls: Block malicious ports/protocols, restrict outbound connections (C&C), filter by IP/domain reputation, prevent worm propagation by closing vulnerabilities.

V. WIRELESS & MOBILE SECURITY

A. Wireless LAN (WLAN) Security

  • Security Challenges:

    • Open broadcast medium (anyone can listen).

    • Mobile, transient nodes (hard to physical security).

    • Lack of physical perimeter.

    • Rogue Access Points (APs), Evil Twins.

    • Client misconfiguration.

  • Security Mechanisms:

    • WEP (Wired Equivalent Privacy): Uses RC4 with 40/104-bit key + 24-bit IV. Broken due to weak IV, no key management.

    • WPA/WPA2/WPA3: Successors. WPA2 uses AES-CCMP (strong). WPA3 uses SAE (Simultaneous Authentication of Equals) for password-based key exchange, forward secrecy.

    • 802.1X/EAP: Port-based network access control. Authentication framework: Supplicant (client), Authenticator (AP), Authentication Server (RADIUS). EAP types: EAP-TLS (certificates), PEAP (tunnelled), EAP-FAST.

  • Access Point Security in Public Networks:

    • Rogue AP: Unauthorized AP connected to network (internal threat).

    • Evil Twin: Malicious AP mimicking legitimate SSID (external threat).

    • Client Isolation: Feature on APs that prevents wireless clients from communicating directly with each other (mitigates lateral movement).

    • Mitigations: Wireless IDS/IPS, 802.1X, regular site surveys, strong encryption (WPA2/WPA3), disable SSID broadcast (security through obscurity, not sufficient).

B. Wireless Application Protocol (WAP) Security

  • WAP Architecture Overview:

    
    Mobile Device (WAP Browser) → [Wireless Network (GPRS/UMTS)] → WAP Gateway (protocol translation) → Internet (WWW)
    
    
    DiagramWAP stack showing mobile, gateway, web server
  • Focus: Wireless Transport Layer Security (WTLS)

    • Role: Security layer in WAP stack, analogous to SSL/TLS but optimized for constrained wireless devices (low bandwidth, high latency, datagram-oriented). Provides confidentiality, integrity, authentication between mobile device and WAP gateway.

    • Security Issues and Limitations:

      1. Weak Cryptography: Early versions allowed export-grade (40-bit) RC4, MD5.

      2. Gateway Translation Gap: End-to-end security breaks at WAP gateway (WTLS → SSL/TLS). Gateway can read all data ("man-in-the-middle" by design).

      3. Certificate Handling: Limited device storage for certificates, user acceptance issues.

      4. Session Resumption: Less efficient than SSL/TLS.

    • Overall WAP Security: Relies on WTLS for wireless leg, but true end-to-end security requires application-layer encryption (e.g., using HTTPS directly if device supports).

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in