UNIT 5: Network Security – Short Notes
0. Introduction to Network Security
Security Goals (CIA Triad + Extensions):
-
Confidentiality: Ensuring data is accessible only to authorized entities.
-
Integrity: Maintaining the accuracy and completeness of data; preventing unauthorized modification.
-
Availability: Ensuring systems and data are reliably accessible to authorized users when needed.
-
Authentication: Verifying the identity of a user, system, or entity.
-
Non-repudiation: Preventing a party from denying an action (e.g., sending a message).
Threat Landscape & Attack Vectors:
-
Passive Attacks: Eavesdropping, traffic analysis (confidentiality breach).
-
Active Attacks: Masquerade, replay, modification, DoS/DDoS (integrity/availability breach).
-
Common Vectors: Malware, phishing, man-in-the-middle, SQL injection, zero-day exploits.
[!TIP] Exam Focus: Be prepared to map specific attacks (e.g., DoS) to the security goal they violate (Availability).
1. Cryptographic Foundations
Symmetric vs. Asymmetric Encryption:
| Feature | Symmetric Encryption | Asymmetric Encryption |
|---|---|---|
| Key | Same secret key for encryption & decryption. | Public key (encrypt) & Private key (decrypt) pair. |
| Speed | Fast, suitable for bulk data. | Slow, computationally intensive. |
| Key Distribution | Major challenge (secure channel needed). | Easier (public key can be shared openly). |
| Primary Use | Confidentiality of data. | Key exchange, digital signatures, confidentiality. |
| Examples | AES, DES, RC4, Caesar Cipher. | RSA, ECC, Diffie-Hellman. |
Hash Functions: One-way functions producing a fixed-size message digest.
-
Properties: Deterministic, Quick to compute, Pre-image resistant, Second pre-image resistant, Collision resistant.
-
Role: Ensure data integrity (any change alters digest).
Digital Signatures: Provide authentication, integrity, and non-repudiation.
-
Sender hashes the message.
-
Sender encrypts the hash with their private key → Signature.
-
Receiver decrypts signature with sender's public key to get hash1.
-
Receiver hashes received message to get hash2.
-
If
hash1 == hash2, signature is valid.
Public Key Infrastructure (PKI) Basics:
-
Core: Uses digital certificates (X.509) binding a public key to an entity.
-
Components: Certificate Authority (CA), Registration Authority (RA), Certificate Repository, Certificate Revocation List (CRL).
-
Purpose: Solves the key distribution and trust problem in asymmetric crypto.
2. Symmetric Encryption Algorithms
Block Ciphers: AES (Advanced Encryption Standard)
-
Block Size: 128 bits. Key Sizes: 128, 192, 256 bits.
-
Structure: Substitution-Permutation Network (SPN). Operates on a 4x4 byte state array.
-
Rounds: 10 (128-bit key), 12 (192-bit), 14 (256-bit).
-
Core Steps per Round (except last):
-
SubBytes: Non-linear substitution using S-box.
-
ShiftRows: Cyclically shifts rows of state.
-
MixColumns: Mixing columns using Galois Field arithmetic.
-
AddRoundKey: XOR state with round key.
-
-
Final Round: Omits MixColumns.
Stream Ciphers: RC4
-
Principle: Generates a pseudo-random keystream from a secret key, which is XORed with plaintext.
-
Key Scheduling (KSA): Initializes a 256-byte
Sarray with key. -
Pseudo-Random Generation (PRGA): Generates keystream byte-by-byte.
-
Example (5-bit key
K = [1,2,3,4,5]):-
KSA initializes
Swith 0-255, then swaps based on key bytes. -
PRGA:
i = (i+1) mod 256,j = (j + S[i]) mod 256, swapS[i], S[j], outputt = (S[i] + S[j]) mod 256, keystream byte =S[t]. -
First 3 bytes depend on initial
Spermutation after KSA.
-
Cipher Block Modes of Operation:
| Mode | How it Works | Merits | Demerits |
|---|---|---|---|
| ECB (Electronic Codebook) | Each plaintext block encrypted independently. | Simple, parallelizable. | Identical plaintext blocks → identical ciphertext. Insecure; reveals data patterns. |
| CBC (Cipher Block Chaining) | C_i = E_K(P_i ⊕ C_{i-1}), C_0 = IV. |
Hides patterns; widely used. | Sequential (not parallel); requires IV (must be unpredictable). |
| CFB (Cipher Feedback) | C_i = P_i ⊕ E_K(C_{i-1}). Operates on segments (e.g., 1 byte). |
No padding needed; stream-like. | Error propagation; sequential. |
| OFB (Output Feedback) | O_i = E_K(O_{i-1}), C_i = P_i ⊕ O_i. O_0 = IV. |
Independent of plaintext/ciphertext; no error propagation. | IV must be unique; weak if keystream repeats. |
| CTR (Counter) | C_i = P_i ⊕ E_K(IV + i). |
Highly parallelizable (encrypt/decrypt same); random access. | Requires unique IV/counter for each message. |
Classical Cipher: Caesar Cipher
-
Principle: Monoalphabetic substitution.
C = (P + shift) mod 26. -
Decryption (Shift 17):
P = (C - 17) mod 26orP = (C + 9) mod 26(since 26-17=9). -
Example: Ciphertext
'ZICVTWQNGRZGVTWAVZHCQYGLMGJ'→ Plaintext'THE QUICK BROWN FOX JUMPS OVER THE LAZY DOG'(classic pangram test).
[!TIP] Exam Focus: Caesar decryption and RC4 keystream generation are frequently asked with small numerical examples. Know CTR vs CBC differences clearly.
3. Asymmetric Encryption and Digital Signatures
RSA Algorithm (with example p=3, q=11):
-
Key Generation:
-
n = p * q = 3 * 11 = 33 -
φ(n) = (p-1)*(q-1) = 2 * 10 = 20 -
Choose
esuch that1 < e < φ(n)andgcd(e, φ(n)) = 1. Lete = 7(coprime with 20). -
Compute
dsuch that(d * e) mod φ(n) = 1. Using Extended Euclid:d = 3because(3*7) mod 20 = 1. -
Public Key:
(e=7, n=33). Private Key:(d=3, n=33).
-
-
Encryption:
C = P^e mod n. ForP=2:C = 2^7 mod 33 = 128 mod 33 = 29. -
Decryption:
P = C^d mod n.P = 29^3 mod 33 = 24389 mod 33 = 2. ✓
Digital Signature Process (using RSA):
-
Sender computes
H = Hash(Message). -
Sender computes
S = H^d mod n(signs with private key). -
Sends
(Message, S). -
Receiver computes
H' = Hash(Message). -
Receiver computes
H'' = S^e mod n(verifies with sender's public key). -
If
H' == H'', signature is authentic.
Importance: Provides non-repudiation (sender cannot deny sending) and integrity (message not altered).
4. Hash Functions and Message Authentication
SHA-512 (Simplified Steps):
-
Pre-processing:
- Append a '1' bit, then
k'0' bits, then 128-bit message length (in bits) to make total length ≡ 896 mod 1024.
- Append a '1' bit, then
-
Parsing: Break padded message into 1024-bit blocks
M^1, M^2, .... -
Initialization: Set eight 64-bit working variables
(a..h)to initial hash valuesH0..H7. -
Compression Function (for each block):
-
Prepare 64-word message schedule
W[0..79]from block. -
Initialize working variables with current hash value.
-
Perform 80 rounds of operations involving logical functions (
Ch,Maj,Σ0,Σ1) and constantsK[t]. -
Add the compressed chunk to the current hash value.
-
-
Output: Concatenate final
a..hto produce 512-bit digest.
HMAC (Hash-based Message Authentication Code):
-
Purpose: MAC using a cryptographic hash function + secret key.
-
Algorithm (RFC 2104):
HMAC(K, text) = Hash( (K' ⊕ opad) || Hash( (K' ⊕ ipad) || text ) )-
K'= key padded/truncated to hash block size. -
ipad= 0x36 repeated,opad= 0x5C repeated. -
||= concatenation.
-
-
Security: Relies on strength of underlying hash (e.g., SHA-256).
Message Authentication Codes (MACs):
-
Types: HMAC (hash-based), CMAC (block cipher-based), UMAC (universal hash-based).
-
Use: Verify integrity and authenticity of a message between parties sharing a secret key. Shorter than digital signatures.
5. Secure Communication Protocols
SSL/TLS Handshake Protocol (High-Level Steps):
-
ClientHello: Client sends supported TLS version, cipher suites, random
R_C. -
ServerHello: Server selects version/cipher, sends random
R_S, its certificate (with public key). -
Key Exchange: Client generates premaster secret, encrypts with server's public key (from cert), sends to server.
-
Key Derivation: Both compute master secret
= PRF(premaster, "master secret", R_C + R_S). Then derive session keys (write MAC key, write encryption key). -
Finished: Both exchange
VerifyData(hash of all handshake messages) encrypted with session keys to confirm key derivation success. -
Secure Data Transfer: Application data encrypted with symmetric session keys.
SSL Record Protocol Services:
-
Confidentiality: Symmetric encryption (e.g., AES) of data.
-
Integrity: HMAC for message authentication.
-
Encapsulation: Fragments data, compresses (optional), adds MAC, encrypts, adds SSL header.
SSL Connection vs. Session:
-
Session: Negotiated security parameters (keys, cipher suite) between client/server. Can be resumed for new connections to avoid full handshake.
-
Connection: A specific communication channel using a session's parameters. One session can have multiple connections.
PGP (Pretty Good Privacy) for Email:
-
Working Principle (Hybrid Crypto):
-
Authentication/Signature: Sender signs message hash with private key.
-
Confidentiality: Sender generates random session key, encrypts message with symmetric cipher (e.g., CAST-128), encrypts session key with recipient's public key.
-
Both encrypted components + signature sent together.
-
-
PGP Message Format:
[Signature] [Encrypted Session Key] [Encrypted Data]. Each part has its own header. -
Authentication & Confidentiality: Achieved via digital signature (private key) and session key encryption (recipient's public key).
IPSec:
-
AH (Authentication Header): Provides data origin authentication, integrity, and anti-replay (sequence number). Does NOT provide confidentiality. Can be used in Transport (protects payload of IP packet) or Tunnel (protects entire inner IP packet) mode.
-
ESP (Encapsulating Security Payload): Provides confidentiality (encryption), authentication, integrity, anti-replay.
-
Transport Mode: Encrypts &/or authenticates payload of original IP packet. Original IP header visible.
-
Tunnel Mode: Encrypts &/or authenticates the entire original IP packet, which is then encapsulated into a new IP packet with outer header. Used for VPNs.
-
WAP & WTLS:
-
WAP Architecture: Application → WAE → WSP → WTP → WTLS → WDP → Bearer Network (GSM, CDMA).
-
WTLS (Wireless TLS): Security layer for WAP. Based on TLS but optimized for constrained wireless devices (smaller certificates, optimized handshake).
-
Security Issues: Gateway Translation Problem – WTLS between mobile & WAP gateway, but often plaintext HTTP between gateway & web server, creating a security gap. WTLS termination at gateway.
SET (Secure Electronic Transaction):
-
Participants: Cardholder, Merchant, Issuer (Bank), Acquirer (Merchant's Bank), Payment Gateway, Certification Authority.
-
Protocol Overview:
-
Cardholder obtains dual signature (links order info & payment info without revealing each to other parties).
-
Uses public key certificates for all parties.
-
Confidentiality: Payment info encrypted with merchant's public key (for bank), order info encrypted with merchant's public key.
-
Integrity/Authentication: Digital signatures on messages.
-
-
Addresses Concerns: Protects cardholder data, ensures merchant authenticity, provides non-repudiation for all parties.
-
Business Application: Secure credit card transactions over the internet.
6. Network Security Devices
Firewalls:
-
Classification & Operational Differences:
| Type | Layer | Operation | Example/Use | | :--- | :--- | :--- | :--- | | Packet Filtering | Network/Transport (IP, Port) | Stateless/Stateful inspection of packet headers. Rules based on IP, port, protocol. | Simple, fast, but can't inspect payload. | | Circuit-Level Gateway | Session (TCP) | Monitors TCP handshake; sets up temporary circuit. Hides internal network structure. | No payload inspection. | | Application-Level Gateway (Proxy) | Application (HTTP, FTP) | Intercepts & inspects entire application layer traffic. Enforces protocol rules. | High security, performance hit. | | Personal Firewall | Host-based | Software on individual host. Controls inbound/outbound traffic for that machine. | Protects endpoints. |
-
Merits: Access control, logging, defense-in-depth.
-
Demerits: Cannot stop internal attacks, complex rule management, may be bypassed (encrypted tunnels), single point of failure.
Intrusion Detection Systems (IDS):
-
HIDS vs NIDS:
| Feature | HIDS (Host-based) | NIDS (Network-based) | | :--- | :--- | :--- | | Location | Installed on individual host/ server. | Sensors placed at strategic network points (e.g., DMZ). |
Monitoring | Host logs, file integrity, system calls. | Network traffic (packets, flows). |
Visibility | Sees internal host activity. | Sees network-wide traffic. |
Scope | Detects attacks on the host. | Detects attacks through the network. |
Example | OSSEC, Wazuh. | Snort, Suricata. |
-
Detection Techniques:
-
Signature/Pattern Matching: Compares activity to known attack signatures. High detection rate for known attacks, zero-day blind.
-
Anomaly Detection: Establishes baseline "normal" behavior; flags deviations. Can detect novel attacks, higher false positives.
-
-
Role Against Malware: Can detect malware communication (C&C callbacks), propagation scans, or exploit attempts by analyzing traffic patterns/signatures.
7. Wireless and Mobile Security
WLAN Security Challenges:
-
Open Medium: Radio signals propagate beyond physical boundaries.
-
Weak/Missing Initial Security: Early WEP was cryptographically broken.
-
Rogue Access Points: Unauthorized APs inside corporate network.
-
Evil Twin: Malicious AP with same SSID as legitimate one.
-
Client Misconfiguration: Weak encryption, ad-hoc networking.
-
Denial-of-Service: Jamming, deauthentication attacks.
Access Point (AP) Security in Public Networks:
-
Captive Portals: Web-based authentication before granting access.
-
WPA2/WPA3-Enterprise: Uses 802.1X/EAP for individual user authentication against a RADIUS server. Most secure for public hotspots.
-
Isolation (Client Isolation): Prevents clients from communicating directly with each other.
-
Strong Encryption: Mandatory use of WPA2/WPA3-Personal (PSK) at minimum.
WLAN Protocol Stack & MPDU:
-
Stack: 802.11 (MAC/PHY) → LLC → Network Layer (IP) → Transport (TCP/UDP) → Application.
-
MPDU (MAC Protocol Data Unit): Frame format at 802.11 MAC layer.
-
Fields: Frame Control, Duration, Addr1 (Receiver), Addr2 (Transmitter), Addr3 (BSSID), Sequence Control, Addr4 (optional), Frame Body (payload), FCS (CRC).
-
Key Point: Address fields allow for distribution system (DS) bridging between APs.
-
8. Authentication Mechanisms
Biometric Authentication:
-
Methods: Fingerprint, Iris/Retina, Face recognition, Voice, Vein pattern, Keystroke dynamics.
-
Implementation: Enrolment (capture template, store in database) → Verification/Identification (capture sample, compare to template using matching algorithm).
-
Metrics: FAR (False Accept Rate), FRR (False Reject Rate), EER (Equal Error Rate). Trade-off between security (low FAR) and convenience (low FRR).
-
Challenges: Spoofing (fake fingerprint), non-universality, template security, cost.
Smart Cards:
-
Technology: Plastic card with embedded microcontroller or memory chip.
-
Types: Contact (requires reader), Contactless (RFID/NFC).
-
Use in Authentication: Stores cryptographic keys, certificates, or performs cryptographic operations on-card (private key never leaves card). Used for two-factor (card + PIN) or one-factor (cryptographic challenge-response).
-
Advantages: Portable, tamper-resistant, supports strong crypto.
9. Virtual Private Networks (VPNs)
Types of VPNs:
-
Remote Access VPN: Individual user connects to corporate network over internet (e.g., SSL VPN, IPsec client).
-
Site-to-Site (Gateway-to-Gateway) VPN: Connects entire networks (e.g., branch offices) via secure tunnel between gateways/routers.
-
Mobile VPN: Designed for users with changing IP addresses (e.g., law enforcement).
VPN vs. Trusted Operating Systems:
| Aspect | VPN | Trusted Operating System |
|---|---|---|
| Security Architecture | Cryptographic (tunneling, encryption). Security at network/transport layer. Relies on end-point security. | Mandatory Access Control (MAC) enforced by security kernel. Label-based (e.g., Bell-LaPadula, Biba). Security at OS/kernel layer. |
| Primary Goal | Secure communication channel over untrusted network (confidentiality, integrity). | Secure information flow within a single system (prevent unauthorized data access/leakage). |
| Application Domain | Connecting remote users/sites, securing traffic over internet. | High-assurance military/government systems, multilevel security (MLS) environments where users process data at different classification levels on same machine. |
| Trust Base | Trust in cryptographic algorithms, VPN endpoints, and configuration. | Trust in formally verified security kernel and reference monitor. |
10. Malware and Threats
Types of Malicious Software:
-
Virus: Requires host program to replicate; attaches to executable.
-
Worm: Standalone; self-replicates over network (e.g., SQL Slammer).
-
Trojan Horse: Disguised as legitimate software; provides backdoor.
-
Ransomware: Encrypts files, demands ransom.
-
Spyware/Adware: Secretly monitors/collects data or displays ads.
-
Rootkit: Hides existence/activity of other malware at OS/kernel level.
-
Bot/Botnet: Compromised host controlled by C&C server; used for DDoS, spam.
-
Logic Bomb: Code that triggers malicious action on a condition (date, event).
Infiltration Vectors: Phishing emails, malicious downloads, drive-by downloads, infected USB, software vulnerabilities, weak passwords.
Mitigation with IDS & Firewalls:
-
Firewalls: Block known malicious IPs/ports (outbound C&C traffic), prevent worm propagation by filtering scan traffic, enforce application-layer rules (proxy).
-
IDS:
-
NIDS: Detect worm propagation (scanning patterns), C&C communication, exploit attempts.
-
HIDS: Detect file modifications (ransomware), process creation (trojan execution), registry changes (persistence).
-
Signature-based: Detect known malware traffic/behavior.
-
Anomaly-based: Detect unusual outbound traffic (bot C&C), data exfiltration spikes.
-
11. Trusted Operating Systems
Security Architecture:
-
Reference Monitor: Abstract machine enforcing security policy. Must be: Tamper-proof, Always invoked, Verifiable small.
-
Security Kernel: Minimal part of OS implementing reference monitor (scheduler, I/O manager, memory manager).
-
Mandatory Access Control (MAC): System-enforced, based on security labels (e.g., Top Secret, Secret). Rules like Bell-LaPadula ("no read up, no write down" - confidentiality) and Biba ("no write up, no read down" - integrity).
-
Process Isolation: Hardware-enforced memory protection (rings, MMU).
-
Trusted Path: Guaranteed communication channel between user and security kernel (e.g., secure login prompt).
Applications: Military systems (multilevel secure workstations), government systems handling classified data, financial transaction processing systems requiring high integrity.
12. Application and Web Security
Web Traffic Security Approaches:
-
SSL/TLS (HTTPS): De facto standard. Provides end-to-end encryption, server authentication (certificates), optional client auth. Secures HTTP at transport layer.
-
VPNs: Creates secure tunnel for all traffic (including web) from remote client to corporate network. Can use IPsec or SSL.
-
Application Layer Gateways (Proxy Firewalls): Inspects and filters HTTP/HTTPS content. Can enforce URL filtering, data leakage prevention (DLP), and deep packet inspection (DPI) for web traffic.
-
Other Mechanisms:
-
Secure Cookies:
SecureandHttpOnlyflags. -
Input Validation/Output Encoding: Prevent XSS, SQLi.
-
Web Application Firewalls (WAF): Specialized for HTTP/HTTPS, blocks OWASP Top 10 attacks.
-
HSTS: Forces HTTPS.
-
SET in E-commerce (Detailed - see Section 5.5):
-
Application: Enables secure credit card transactions between customer, merchant, and banks.
-
How it Addresses Concerns:
-
Confidentiality: Cardholder's account details encrypted for bank only.
-
Merchant Authentication: Merchant's certificate verifies legitimacy.
-
Cardholder Authentication: Dual signature & certificate.
-
Order/Price Integrity: Order information signed by customer.
-
Non-repudiation: All parties have digital signatures on transactions.
-
-
Business Environment: Used in B2C/B2B e-commerce where parties may not have pre-existing relationships. Requires all participants to have certificates from a CA.