Skip to content
CY-503 (B) · Network Security/Quick Revision Short Notes

Network Security (CY-503 (B)) - Unit 5 Short Notes

UNIT 5: Network Security – Short Notes

0. Introduction to Network Security

Security Goals (CIA Triad + Extensions):

  • Confidentiality: Ensuring data is accessible only to authorized entities.

  • Integrity: Maintaining the accuracy and completeness of data; preventing unauthorized modification.

  • Availability: Ensuring systems and data are reliably accessible to authorized users when needed.

  • Authentication: Verifying the identity of a user, system, or entity.

  • Non-repudiation: Preventing a party from denying an action (e.g., sending a message).

Threat Landscape & Attack Vectors:

  • Passive Attacks: Eavesdropping, traffic analysis (confidentiality breach).

  • Active Attacks: Masquerade, replay, modification, DoS/DDoS (integrity/availability breach).

  • Common Vectors: Malware, phishing, man-in-the-middle, SQL injection, zero-day exploits.

[!TIP] Exam Focus: Be prepared to map specific attacks (e.g., DoS) to the security goal they violate (Availability).


1. Cryptographic Foundations

Symmetric vs. Asymmetric Encryption:

Feature Symmetric Encryption Asymmetric Encryption
Key Same secret key for encryption & decryption. Public key (encrypt) & Private key (decrypt) pair.
Speed Fast, suitable for bulk data. Slow, computationally intensive.
Key Distribution Major challenge (secure channel needed). Easier (public key can be shared openly).
Primary Use Confidentiality of data. Key exchange, digital signatures, confidentiality.
Examples AES, DES, RC4, Caesar Cipher. RSA, ECC, Diffie-Hellman.

Hash Functions: One-way functions producing a fixed-size message digest.

  • Properties: Deterministic, Quick to compute, Pre-image resistant, Second pre-image resistant, Collision resistant.

  • Role: Ensure data integrity (any change alters digest).

Digital Signatures: Provide authentication, integrity, and non-repudiation.

  1. Sender hashes the message.

  2. Sender encrypts the hash with their private key → Signature.

  3. Receiver decrypts signature with sender's public key to get hash1.

  4. Receiver hashes received message to get hash2.

  5. If hash1 == hash2, signature is valid.

Public Key Infrastructure (PKI) Basics:

  • Core: Uses digital certificates (X.509) binding a public key to an entity.

  • Components: Certificate Authority (CA), Registration Authority (RA), Certificate Repository, Certificate Revocation List (CRL).

  • Purpose: Solves the key distribution and trust problem in asymmetric crypto.


2. Symmetric Encryption Algorithms

Block Ciphers: AES (Advanced Encryption Standard)

  • Block Size: 128 bits. Key Sizes: 128, 192, 256 bits.

  • Structure: Substitution-Permutation Network (SPN). Operates on a 4x4 byte state array.

  • Rounds: 10 (128-bit key), 12 (192-bit), 14 (256-bit).

  • Core Steps per Round (except last):

    1. SubBytes: Non-linear substitution using S-box.

    2. ShiftRows: Cyclically shifts rows of state.

    3. MixColumns: Mixing columns using Galois Field arithmetic.

    4. AddRoundKey: XOR state with round key.

  • Final Round: Omits MixColumns.

Stream Ciphers: RC4

  • Principle: Generates a pseudo-random keystream from a secret key, which is XORed with plaintext.

  • Key Scheduling (KSA): Initializes a 256-byte S array with key.

  • Pseudo-Random Generation (PRGA): Generates keystream byte-by-byte.

  • Example (5-bit key K = [1,2,3,4,5]):

    • KSA initializes S with 0-255, then swaps based on key bytes.

    • PRGA: i = (i+1) mod 256, j = (j + S[i]) mod 256, swap S[i], S[j], output t = (S[i] + S[j]) mod 256, keystream byte = S[t].

    • First 3 bytes depend on initial S permutation after KSA.

Cipher Block Modes of Operation:

Mode How it Works Merits Demerits
ECB (Electronic Codebook) Each plaintext block encrypted independently. Simple, parallelizable. Identical plaintext blocks → identical ciphertext. Insecure; reveals data patterns.
CBC (Cipher Block Chaining) C_i = E_K(P_i ⊕ C_{i-1}), C_0 = IV. Hides patterns; widely used. Sequential (not parallel); requires IV (must be unpredictable).
CFB (Cipher Feedback) C_i = P_i ⊕ E_K(C_{i-1}). Operates on segments (e.g., 1 byte). No padding needed; stream-like. Error propagation; sequential.
OFB (Output Feedback) O_i = E_K(O_{i-1}), C_i = P_i ⊕ O_i. O_0 = IV. Independent of plaintext/ciphertext; no error propagation. IV must be unique; weak if keystream repeats.
CTR (Counter) C_i = P_i ⊕ E_K(IV + i). Highly parallelizable (encrypt/decrypt same); random access. Requires unique IV/counter for each message.

Classical Cipher: Caesar Cipher

  • Principle: Monoalphabetic substitution. C = (P + shift) mod 26.

  • Decryption (Shift 17): P = (C - 17) mod 26 or P = (C + 9) mod 26 (since 26-17=9).

  • Example: Ciphertext 'ZICVTWQNGRZGVTWAVZHCQYGLMGJ' → Plaintext 'THE QUICK BROWN FOX JUMPS OVER THE LAZY DOG' (classic pangram test).

[!TIP] Exam Focus: Caesar decryption and RC4 keystream generation are frequently asked with small numerical examples. Know CTR vs CBC differences clearly.


3. Asymmetric Encryption and Digital Signatures

RSA Algorithm (with example p=3, q=11):

  1. Key Generation:

    • n = p * q = 3 * 11 = 33

    • φ(n) = (p-1)*(q-1) = 2 * 10 = 20

    • Choose e such that 1 < e < φ(n) and gcd(e, φ(n)) = 1. Let e = 7 (coprime with 20).

    • Compute d such that (d * e) mod φ(n) = 1. Using Extended Euclid: d = 3 because (3*7) mod 20 = 1.

    • Public Key: (e=7, n=33). Private Key: (d=3, n=33).

  2. Encryption: C = P^e mod n. For P=2: C = 2^7 mod 33 = 128 mod 33 = 29.

  3. Decryption: P = C^d mod n. P = 29^3 mod 33 = 24389 mod 33 = 2. ✓

Digital Signature Process (using RSA):

  1. Sender computes H = Hash(Message).

  2. Sender computes S = H^d mod n (signs with private key).

  3. Sends (Message, S).

  4. Receiver computes H' = Hash(Message).

  5. Receiver computes H'' = S^e mod n (verifies with sender's public key).

  6. If H' == H'', signature is authentic.

Importance: Provides non-repudiation (sender cannot deny sending) and integrity (message not altered).


4. Hash Functions and Message Authentication

SHA-512 (Simplified Steps):

  1. Pre-processing:

    • Append a '1' bit, then k '0' bits, then 128-bit message length (in bits) to make total length ≡ 896 mod 1024.
  2. Parsing: Break padded message into 1024-bit blocks M^1, M^2, ....

  3. Initialization: Set eight 64-bit working variables (a..h) to initial hash values H0..H7.

  4. Compression Function (for each block):

    • Prepare 64-word message schedule W[0..79] from block.

    • Initialize working variables with current hash value.

    • Perform 80 rounds of operations involving logical functions (Ch, Maj, Σ0, Σ1) and constants K[t].

    • Add the compressed chunk to the current hash value.

  5. Output: Concatenate final a..h to produce 512-bit digest.

HMAC (Hash-based Message Authentication Code):

  • Purpose: MAC using a cryptographic hash function + secret key.

  • Algorithm (RFC 2104):

    
    HMAC(K, text) = Hash( (K' ⊕ opad) || Hash( (K' ⊕ ipad) || text ) )
    
    
    • K' = key padded/truncated to hash block size.

    • ipad = 0x36 repeated, opad = 0x5C repeated.

    • || = concatenation.

  • Security: Relies on strength of underlying hash (e.g., SHA-256).

Message Authentication Codes (MACs):

  • Types: HMAC (hash-based), CMAC (block cipher-based), UMAC (universal hash-based).

  • Use: Verify integrity and authenticity of a message between parties sharing a secret key. Shorter than digital signatures.


5. Secure Communication Protocols

SSL/TLS Handshake Protocol (High-Level Steps):

  1. ClientHello: Client sends supported TLS version, cipher suites, random R_C.

  2. ServerHello: Server selects version/cipher, sends random R_S, its certificate (with public key).

  3. Key Exchange: Client generates premaster secret, encrypts with server's public key (from cert), sends to server.

  4. Key Derivation: Both compute master secret = PRF(premaster, "master secret", R_C + R_S). Then derive session keys (write MAC key, write encryption key).

  5. Finished: Both exchange VerifyData (hash of all handshake messages) encrypted with session keys to confirm key derivation success.

  6. Secure Data Transfer: Application data encrypted with symmetric session keys.

SSL Record Protocol Services:

  • Confidentiality: Symmetric encryption (e.g., AES) of data.

  • Integrity: HMAC for message authentication.

  • Encapsulation: Fragments data, compresses (optional), adds MAC, encrypts, adds SSL header.

SSL Connection vs. Session:

  • Session: Negotiated security parameters (keys, cipher suite) between client/server. Can be resumed for new connections to avoid full handshake.

  • Connection: A specific communication channel using a session's parameters. One session can have multiple connections.

PGP (Pretty Good Privacy) for Email:

  • Working Principle (Hybrid Crypto):

    1. Authentication/Signature: Sender signs message hash with private key.

    2. Confidentiality: Sender generates random session key, encrypts message with symmetric cipher (e.g., CAST-128), encrypts session key with recipient's public key.

    3. Both encrypted components + signature sent together.

  • PGP Message Format: [Signature] [Encrypted Session Key] [Encrypted Data]. Each part has its own header.

  • Authentication & Confidentiality: Achieved via digital signature (private key) and session key encryption (recipient's public key).

IPSec:

  • AH (Authentication Header): Provides data origin authentication, integrity, and anti-replay (sequence number). Does NOT provide confidentiality. Can be used in Transport (protects payload of IP packet) or Tunnel (protects entire inner IP packet) mode.

  • ESP (Encapsulating Security Payload): Provides confidentiality (encryption), authentication, integrity, anti-replay.

    • Transport Mode: Encrypts &/or authenticates payload of original IP packet. Original IP header visible.

    • Tunnel Mode: Encrypts &/or authenticates the entire original IP packet, which is then encapsulated into a new IP packet with outer header. Used for VPNs.

WAP & WTLS:

  • WAP Architecture: Application → WAE → WSP → WTP → WTLS → WDP → Bearer Network (GSM, CDMA).

  • WTLS (Wireless TLS): Security layer for WAP. Based on TLS but optimized for constrained wireless devices (smaller certificates, optimized handshake).

  • Security Issues: Gateway Translation Problem – WTLS between mobile & WAP gateway, but often plaintext HTTP between gateway & web server, creating a security gap. WTLS termination at gateway.

SET (Secure Electronic Transaction):

  • Participants: Cardholder, Merchant, Issuer (Bank), Acquirer (Merchant's Bank), Payment Gateway, Certification Authority.

  • Protocol Overview:

    1. Cardholder obtains dual signature (links order info & payment info without revealing each to other parties).

    2. Uses public key certificates for all parties.

    3. Confidentiality: Payment info encrypted with merchant's public key (for bank), order info encrypted with merchant's public key.

    4. Integrity/Authentication: Digital signatures on messages.

  • Addresses Concerns: Protects cardholder data, ensures merchant authenticity, provides non-repudiation for all parties.

  • Business Application: Secure credit card transactions over the internet.


6. Network Security Devices

Firewalls:

  • Classification & Operational Differences:

    | Type | Layer | Operation | Example/Use | | :--- | :--- | :--- | :--- | | Packet Filtering | Network/Transport (IP, Port) | Stateless/Stateful inspection of packet headers. Rules based on IP, port, protocol. | Simple, fast, but can't inspect payload. | | Circuit-Level Gateway | Session (TCP) | Monitors TCP handshake; sets up temporary circuit. Hides internal network structure. | No payload inspection. | | Application-Level Gateway (Proxy) | Application (HTTP, FTP) | Intercepts & inspects entire application layer traffic. Enforces protocol rules. | High security, performance hit. | | Personal Firewall | Host-based | Software on individual host. Controls inbound/outbound traffic for that machine. | Protects endpoints. |

  • Merits: Access control, logging, defense-in-depth.

  • Demerits: Cannot stop internal attacks, complex rule management, may be bypassed (encrypted tunnels), single point of failure.

Intrusion Detection Systems (IDS):

  • HIDS vs NIDS:

    | Feature | HIDS (Host-based) | NIDS (Network-based) | | :--- | :--- | :--- | | Location | Installed on individual host/ server. | Sensors placed at strategic network points (e.g., DMZ). |

    Monitoring | Host logs, file integrity, system calls. | Network traffic (packets, flows). |

    Visibility | Sees internal host activity. | Sees network-wide traffic. |

    Scope | Detects attacks on the host. | Detects attacks through the network. |

    Example | OSSEC, Wazuh. | Snort, Suricata. |

  • Detection Techniques:

    • Signature/Pattern Matching: Compares activity to known attack signatures. High detection rate for known attacks, zero-day blind.

    • Anomaly Detection: Establishes baseline "normal" behavior; flags deviations. Can detect novel attacks, higher false positives.

  • Role Against Malware: Can detect malware communication (C&C callbacks), propagation scans, or exploit attempts by analyzing traffic patterns/signatures.


7. Wireless and Mobile Security

WLAN Security Challenges:

  • Open Medium: Radio signals propagate beyond physical boundaries.

  • Weak/Missing Initial Security: Early WEP was cryptographically broken.

  • Rogue Access Points: Unauthorized APs inside corporate network.

  • Evil Twin: Malicious AP with same SSID as legitimate one.

  • Client Misconfiguration: Weak encryption, ad-hoc networking.

  • Denial-of-Service: Jamming, deauthentication attacks.

Access Point (AP) Security in Public Networks:

  • Captive Portals: Web-based authentication before granting access.

  • WPA2/WPA3-Enterprise: Uses 802.1X/EAP for individual user authentication against a RADIUS server. Most secure for public hotspots.

  • Isolation (Client Isolation): Prevents clients from communicating directly with each other.

  • Strong Encryption: Mandatory use of WPA2/WPA3-Personal (PSK) at minimum.

WLAN Protocol Stack & MPDU:

  • Stack: 802.11 (MAC/PHY) → LLC → Network Layer (IP) → Transport (TCP/UDP) → Application.

  • MPDU (MAC Protocol Data Unit): Frame format at 802.11 MAC layer.

    • Fields: Frame Control, Duration, Addr1 (Receiver), Addr2 (Transmitter), Addr3 (BSSID), Sequence Control, Addr4 (optional), Frame Body (payload), FCS (CRC).

    • Key Point: Address fields allow for distribution system (DS) bridging between APs.


8. Authentication Mechanisms

Biometric Authentication:

  • Methods: Fingerprint, Iris/Retina, Face recognition, Voice, Vein pattern, Keystroke dynamics.

  • Implementation: Enrolment (capture template, store in database) → Verification/Identification (capture sample, compare to template using matching algorithm).

  • Metrics: FAR (False Accept Rate), FRR (False Reject Rate), EER (Equal Error Rate). Trade-off between security (low FAR) and convenience (low FRR).

  • Challenges: Spoofing (fake fingerprint), non-universality, template security, cost.

Smart Cards:

  • Technology: Plastic card with embedded microcontroller or memory chip.

  • Types: Contact (requires reader), Contactless (RFID/NFC).

  • Use in Authentication: Stores cryptographic keys, certificates, or performs cryptographic operations on-card (private key never leaves card). Used for two-factor (card + PIN) or one-factor (cryptographic challenge-response).

  • Advantages: Portable, tamper-resistant, supports strong crypto.


9. Virtual Private Networks (VPNs)

Types of VPNs:

  • Remote Access VPN: Individual user connects to corporate network over internet (e.g., SSL VPN, IPsec client).

  • Site-to-Site (Gateway-to-Gateway) VPN: Connects entire networks (e.g., branch offices) via secure tunnel between gateways/routers.

  • Mobile VPN: Designed for users with changing IP addresses (e.g., law enforcement).

VPN vs. Trusted Operating Systems:

Aspect VPN Trusted Operating System
Security Architecture Cryptographic (tunneling, encryption). Security at network/transport layer. Relies on end-point security. Mandatory Access Control (MAC) enforced by security kernel. Label-based (e.g., Bell-LaPadula, Biba). Security at OS/kernel layer.
Primary Goal Secure communication channel over untrusted network (confidentiality, integrity). Secure information flow within a single system (prevent unauthorized data access/leakage).
Application Domain Connecting remote users/sites, securing traffic over internet. High-assurance military/government systems, multilevel security (MLS) environments where users process data at different classification levels on same machine.
Trust Base Trust in cryptographic algorithms, VPN endpoints, and configuration. Trust in formally verified security kernel and reference monitor.

10. Malware and Threats

Types of Malicious Software:

  • Virus: Requires host program to replicate; attaches to executable.

  • Worm: Standalone; self-replicates over network (e.g., SQL Slammer).

  • Trojan Horse: Disguised as legitimate software; provides backdoor.

  • Ransomware: Encrypts files, demands ransom.

  • Spyware/Adware: Secretly monitors/collects data or displays ads.

  • Rootkit: Hides existence/activity of other malware at OS/kernel level.

  • Bot/Botnet: Compromised host controlled by C&C server; used for DDoS, spam.

  • Logic Bomb: Code that triggers malicious action on a condition (date, event).

Infiltration Vectors: Phishing emails, malicious downloads, drive-by downloads, infected USB, software vulnerabilities, weak passwords.

Mitigation with IDS & Firewalls:

  • Firewalls: Block known malicious IPs/ports (outbound C&C traffic), prevent worm propagation by filtering scan traffic, enforce application-layer rules (proxy).

  • IDS:

    • NIDS: Detect worm propagation (scanning patterns), C&C communication, exploit attempts.

    • HIDS: Detect file modifications (ransomware), process creation (trojan execution), registry changes (persistence).

    • Signature-based: Detect known malware traffic/behavior.

    • Anomaly-based: Detect unusual outbound traffic (bot C&C), data exfiltration spikes.


11. Trusted Operating Systems

Security Architecture:

  • Reference Monitor: Abstract machine enforcing security policy. Must be: Tamper-proof, Always invoked, Verifiable small.

  • Security Kernel: Minimal part of OS implementing reference monitor (scheduler, I/O manager, memory manager).

  • Mandatory Access Control (MAC): System-enforced, based on security labels (e.g., Top Secret, Secret). Rules like Bell-LaPadula ("no read up, no write down" - confidentiality) and Biba ("no write up, no read down" - integrity).

  • Process Isolation: Hardware-enforced memory protection (rings, MMU).

  • Trusted Path: Guaranteed communication channel between user and security kernel (e.g., secure login prompt).

Applications: Military systems (multilevel secure workstations), government systems handling classified data, financial transaction processing systems requiring high integrity.


12. Application and Web Security

Web Traffic Security Approaches:

  1. SSL/TLS (HTTPS): De facto standard. Provides end-to-end encryption, server authentication (certificates), optional client auth. Secures HTTP at transport layer.

  2. VPNs: Creates secure tunnel for all traffic (including web) from remote client to corporate network. Can use IPsec or SSL.

  3. Application Layer Gateways (Proxy Firewalls): Inspects and filters HTTP/HTTPS content. Can enforce URL filtering, data leakage prevention (DLP), and deep packet inspection (DPI) for web traffic.

  4. Other Mechanisms:

    • Secure Cookies: Secure and HttpOnly flags.

    • Input Validation/Output Encoding: Prevent XSS, SQLi.

    • Web Application Firewalls (WAF): Specialized for HTTP/HTTPS, blocks OWASP Top 10 attacks.

    • HSTS: Forces HTTPS.

SET in E-commerce (Detailed - see Section 5.5):

  • Application: Enables secure credit card transactions between customer, merchant, and banks.

  • How it Addresses Concerns:

    • Confidentiality: Cardholder's account details encrypted for bank only.

    • Merchant Authentication: Merchant's certificate verifies legitimacy.

    • Cardholder Authentication: Dual signature & certificate.

    • Order/Price Integrity: Order information signed by customer.

    • Non-repudiation: All parties have digital signatures on transactions.

  • Business Environment: Used in B2C/B2B e-commerce where parties may not have pre-existing relationships. Requires all participants to have certificates from a CA.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in