UNIT 3: DATA SECURITY - EXAM-FOCUSED SHORT NOTES
1.0 CRYPTOGRAPHY FUNDAMENTALS
1.1 Symmetric vs. Asymmetric Encryption
| Feature | Symmetric Encryption | Asymmetric Encryption |
|---|---|---|
| Key | Single shared secret key | Public/Private key pair |
| Primary Goal | Confidentiality | Confidentiality, Authentication, Non-Repudiation |
| Speed | Fast (hardware efficient) | Slow (computationally intensive) |
| Key Distribution | Major challenge (secure channel needed) | Solves via public key infrastructure (PKI) |
| Example Algorithms | AES, DES, RC4 | RSA, ECC, Diffie-Hellman |
| Use Case | Bulk data encryption (e.g., disk, file) | Key exchange, digital signatures, small data |
[!TIP] Exam Focus: Be prepared to contrast security (asymmetric solves key distribution), speed (symmetric is 1000x faster), and typical applications.
1.2 Classic Ciphers: Caesar Cipher
-
Principle: Substitution cipher where each plaintext letter is shifted a fixed number (
k) positions down the alphabet. -
Encryption: $$\displaystyle C = (P + k) \mod 26 $$
-
Decryption: $$\displaystyle P = (C - k) \mod 26 $$
-
Example (Shift k=17): Decrypt
ZICVTWQNGRZGVTWAVZHCQYGLMGJ-
For 'Z' (25): $$\displaystyle P = (25 - 17) \mod 26 = 8 $$ → I
-
For 'I' (8): $$\displaystyle P = (8 - 17) \mod 26 = 17 $$ → R
-
Continue... Result:
IRETURNTOYOURCOUNTRYPLEASE
-
1.3 Block Ciphers vs. Stream Ciphers
| Block Cipher | Stream Cipher |
|---|---|
| Encrypts fixed-size blocks (e.g., 128 bits) | Encrypts bits/bytes one at a time |
| Uses confusion & diffusion across block | Uses keystream XORed with plaintext |
| Requires padding for last block | No padding needed (streaming) |
| Examples: AES, DES, 3DES | Examples: RC4, Salsa20, ChaCha20 |
| Merit: Stronger security guarantees | Merit: Faster, low latency, suitable for real-time |
| Demerit: Slower, propagation of errors | Demerit: Weak if keystream reused |
1.4 Modes of Operation for Block Ciphers
-
Need for Modes: To securely encrypt data longer than one block, avoid pattern leakage.
-
ECB (Electronic Codebook):
-
Each block encrypted independently.
-
Merit: Simple, parallelizable.
-
Demerit: Identical plaintext blocks → identical ciphertext blocks (pattern leakage). Insecure for most uses.
-
-
CBC (Cipher Block Chaining):
-
$$\displaystyle C_i = E_K(P_i \oplus C_{i-1}) $$, with $$\displaystyle C_0 = IV $$.
-
Merit: Hides patterns, widely used (e.g., TLS).
-
Demerit: Sequential (not parallelizable), IV must be unpredictable.
-
-
CFB (Cipher Feedback): Turns block cipher into stream cipher. $$\displaystyle C_i = P_i \oplus E_K(C_{i-1}) $$.
-
OFB (Output Feedback): Generates keystream independent of plaintext/ciphertext. $$\displaystyle O_i = E_K(O_{i-1}) $$, $$\displaystyle C_i = P_i \oplus O_i $$.
-
CTR (Counter): $$\displaystyle C_i = P_i \oplus E_K(IV + i) $$. Merit: Parallelizable, random access. Demerit: Counter must never repeat.
[!TIP] Exam Focus: Know why ECB is bad (pattern leakage), and be able to draw/explain CBC operation with IV.
2.0 SYMMETRIC ENCRYPTION ALGORITHMS (MODERN)
2.1 Advanced Encryption Standard (AES)
-
Structure: Iterated Substitution-Permutation Network (not Feistel).
-
Block Size: 128 bits. Key Sizes: 128, 192, 256 bits → 10, 12, 14 rounds.
-
Round Operations (per round except last):
-
SubBytes: Non-linear substitution using S-box.
-
ShiftRows: Cyclic shift of rows (diffusion).
-
MixColumns: Mixes columns using matrix multiplication.
-
AddRoundKey: XOR with round key.
-
-
Final Round: SubBytes, ShiftRows, AddRoundKey (no MixColumns).
-
Key Schedule: Expands key into round keys using RotWord, SubWord, Rcon.
-
Example (Simplified 128-bit key, 1 round):
-
Plaintext:
00112233445566778899aabbccddeeff -
After SubBytes, ShiftRows, MixColumns, AddRoundKey... (detailed step-by-step not typically required for short notes).
-
2.2 RC4 Stream Cipher
-
Two Phases:
-
Key Scheduling Algorithm (KSA): Initializes S-box (0-255) and permutes using key
K[].for i=0 to 255: S[i]=i, j=0 for i=0 to 255: j = (j + S[i] + K[i mod keylen]) mod 256; swap(S[i], S[j]) -
Pseudo-Random Generation Algorithm (PRGA): Generates keystream byte
K.i = (i+1) mod 256; j = (j + S[i]) mod 256; swap(S[i], S[j]); t = (S[i]+S[j]) mod 256; K = S[t]
-
-
Encryption:
Ciphertext = Plaintext XOR Keystream. -
Worked Example (5-bit key
K = [1,2,3]):-
KSA: S = [0,1,2,3,4] initially. For i=0: j=(0+0+1)%5=1, swap S[0]↔S[1] → S=[1,0,2,3,4]. Continue...
-
PRGA: First byte: i=1, j=(0+S[1])%5=0, swap S[1]↔S[0] → S=[0,1,2,3,4], t=(0+1)%5=1, K=S[1]=1.
-
Generate first 3 bytes: 1, 3, 2 (depends on exact KSA steps).
-
-
Security: Vulnerable if key reused. Weak in WEP (FMS attack). Avoid in new systems.
3.0 ASYMMETRIC ENCRYPTION & DIGITAL SIGNATURES
3.1 RSA Algorithm
-
Math Foundation: Based on difficulty of factoring large integers. Uses Euler's Theorem: $$\displaystyle m^{\phi(n)} \equiv 1 \mod n $$ if gcd(m,n)=1.
-
Key Generation:
-
Choose primes
p,q. Compute $$\displaystyle n = p \times q $$, $$\displaystyle \phi(n) = (p-1)(q-1) $$. -
Choose public exponent
esuch that $$\displaystyle 1 < e < \phi(n) $$ and gcd(e, φ(n)) = 1. -
Compute private exponent
dsuch that $d \times e \equiv 1 \mod \phi(n)$.
-
-
Encryption: $$\displaystyle C = M^e \mod n $$
-
Decryption: $$\displaystyle M = C^d \mod n $$
-
Numerical Example (p=3, q=11):
-
$$\displaystyle n=33 $$, $$\displaystyle \phi(n)=20 $$.
-
Choose $$\displaystyle e=7 $$ (gcd(7,20)=1).
-
Find $d$: $7d \equiv 1 \mod 20$ → $$\displaystyle d=3 $$ (since 21 mod 20 = 1).
-
Encrypt $$\displaystyle M=2 $$: $$\displaystyle C = 2^7 \mod 33 = 128 \mod 33 = 29 $$.
-
Decrypt $$\displaystyle C=29 $$: $$\displaystyle M = 29^3 \mod 33 = 24389 \mod 33 = 2 $$.
-
-
Security: Relies on integer factorization problem. Breaking requires factoring
n.
3.2 Public-Key Cryptography for Digital Signatures
-
Process:
-
Signing: Sender computes hash of message, encrypts hash with own private key → signature.
-
Verification: Receiver decrypts signature with sender's public key, compares with freshly computed hash.
-
-
Provides:
-
Authentication: Proves sender's identity.
-
Non-Repudiation: Sender cannot deny sending (only they have private key).
-
Integrity: Any change in message changes hash → verification fails.
-
-
Crucial Aspect: Never sign raw message; always sign a hash digest (efficient, standardized).
3.3 Digital Signatures: Crucial Aspects
-
Solves Repudiation: Provides undeniable proof of origin.
-
Hash Function Role: Ensures efficiency (sign fixed-size digest) and security (collision resistance prevents forgery).
-
Applications: Software updates (code signing), financial transactions (e.g., SET), legal documents.
4.0 HASH FUNCTIONS & MESSAGE AUTHENTICATION
4.1 Cryptographic Hash Functions
-
Properties:
-
Deterministic: Same input → same output.
-
Pre-image Resistance: Given hash
h, hard to findmsuch thathash(m)=h. -
Second Pre-image Resistance: Given
m1, hard to findm2 ≠ m1with same hash. -
Collision Resistance: Hard to find any two messages
m1, m2with same hash. -
Avalanche Effect: Small change in input → ~50% change in output bits.
-
-
SHA-512 (Example):
-
Padding: Append '1', zeros, and 128-bit message length (big-endian) to make length ≡ 896 mod 1024.
-
Parsing: Split into 1024-bit blocks.
-
Compression: For each block, update 512-bit state (8 words) using 80 rounds of operations (Ch, Maj, Σ functions) with constants.
-
Output: Final state concatenated → 512-bit digest.
-
-
Finding Collisions: Brute-force requires ~$$\displaystyle 2^{256} $$ operations (birthday paradox). Theoretical order: $$\displaystyle O(2^{n/2}) $$ for n-bit hash.
4.2 Message Authentication Codes (MACs)
-
Purpose: Provide integrity and authentication between parties sharing a secret key.
-
Types:
-
Hash-based (HMAC): $$\displaystyle HMAC(K, m) = H((K \oplus opad) \| H((K \oplus ipad) \| m)) $$
-
ipad= 0x36 repeated,opad= 0x5C repeated. -
Security Rationale: Inner hash protects against length extension attacks; outer hash acts as "signature".
-
-
Block Cipher-based (CMAC): Uses CBC mode with final block special processing.
-
-
Difference from Hash: MAC uses secret key; hash is public.
4.3 Parameter Pattern Matching (IDS Technique)
-
Definition: Anomaly-based detection that monitors statistical profiles of network/header parameters (e.g., packet size, inter-arrival time, port numbers).
-
How it Works: Establishes baseline "normal" profile. Flags deviations (e.g., sudden spike in SYN packets → SYN flood).
-
Use in IDS: Detects unknown/zero-day attacks by spotting abnormal behavior, unlike signature-based (known patterns).
5.0 AUTHENTICATION MECHANISMS (BEYOND CRYPTOGRAPHY)
5.1 Biometric Authentication
-
Types: Fingerprint, Iris, Facial, Voice, Vein pattern.
-
Working Phases:
-
Enrollment: Capture biometric, extract feature vector, store template (often encrypted).
-
Verification: Capture live sample, extract features, compare with stored template using matching algorithm (threshold-based).
-
-
Advantages: Something you are → hard to steal/lose; user-friendly.
-
Challenges:
-
False Positive (FP): Unauthorized accepted.
-
False Negative (FN): Authorized rejected.
-
Spoofing: Fake fingerprint/photo.
-
Non-revocability: Cannot "change" biometric if compromised.
-
5.2 Smart Cards
-
Components:
-
Physical: Plastic card with embedded microcontroller or memory chip.
-
Logical: Stores credentials (certificates, keys), performs cryptographic operations.
-
-
How it Works: Card inserted into reader → provides two-factor (something you have + PIN). Card can perform private key operations internally (private key never leaves card).
-
Comparison with Biometrics:
| Smart Card | Biometric | | :--- | :--- | | Something you have | Something you are | | Can be lost/stolen | Cannot be lost (but can be spoofed) | | Revocable (issue new card) | Generally not revocable | | PIN can be guessed | Template theft permanent |
6.0 NETWORK SECURITY DEVICES: FIREWALLS & IDS
6.1 Firewalls
-
Classification & Types:
| Type | OSI Layer | Inspection | Example | Merits | Demerits | | :--- | :--- | :--- | :--- | :--- | :--- | | Packet Filter | Network (L3) | Header (IP, Port) | Stateless rules | Fast, transparent | No context, easy to spoof | | Stateful Inspection | Transport (L4) | Connection state | Tracks TCP flags | Better security, state table | Resource intensive | | Circuit-Level Gateway | Session (L5) | TCP handshake | SOCKS proxy | Hides internal IP | No payload inspection | | Application-Level Gateway (Proxy) | Application (L7) | Full payload | Web proxy, email filter | Deep inspection, protocol aware | Slow, single point of failure | | Personal Firewall | Host-based | All traffic to/from host | Windows Defender Firewall | Protects individual host | Management overhead |
-
Role in Malware Defense: Can block known malicious ports/IPs, filter exploit traffic (proxy), but cannot detect file-based malware inside allowed connections.
6.2 Intrusion Detection Systems (IDS)
-
HIDS vs NIDS Comparison:
| Aspect | HIDS | NIDS | | :--- | :--- | :--- | | Scope | Single host/endpoint | Entire network segment | | Data Source | System logs, audit trails, file integrity | Network packets (sniffed) | | Placement | On critical hosts | At network choke points (DMZ, perimeter) | | Evasion | Harder (attacker must compromise host) | Easier (encryption, fragmentation) | | Example | OSSEC, Wazuh | Snort, Suricata |
-
Detection Methods:
-
Signature-based: Matches known attack patterns (e.g., specific byte sequence). Low false positives, misses zero-days.
-
Anomaly-based: Establishes baseline "normal" traffic. Parameter Pattern Matching is a subtype that monitors statistical parameters (packet size, rate). Detects zero-days, higher false positives.
-
-
Role in Malware Defense: Detects command-and-control (C2) traffic, propagation scans (NIDS), or local malware activity (HIDS file changes).
7.0 SECURE NETWORK TUNNELS: VPNs & IPSec
7.1 Virtual Private Networks (VPNs)
-
Definition: Creates encrypted tunnel over untrusted network (Internet) for secure communication.
-
Types:
-
Remote Access VPN: Individual user → corporate network (e.g., employee from home). Protocols: SSL/TLS, IPsec.
-
Site-to-Site VPN: Connects entire networks (e.g., branch offices). Intranet (same org), Extranet (with partners).
-
-
Security Architecture: Tunneling protocol + encryption (AES) + authentication (certificates, pre-shared keys).
-
Common Protocols: PPTP (weak), L2TP/IPsec, IPsec, SSL/TLS (most common for remote access).
7.2 IP Security (IPSec)
-
Protocols:
-
AH (Authentication Header): Provides integrity & authentication (no confidentiality). Protects IP header & payload. Rarely used alone.
-
ESP (Encapsulating Security Payload): Provides confidentiality, integrity, authentication. Encrypts payload (and optionally header).
-
-
Modes:
-
Transport Mode: Protects payload of original IP packet. Original IP header exposed. Used for end-to-end (host-to-host).
[Original IP Hdr | ESP Trailer | ESP Auth | ESP Payload (encrypted)] -
Tunnel Mode: Protects entire original IP packet. Entire original packet encrypted + new IP header added. Used for network-to-network (gateway-to-gateway).
[New IP Hdr | ESP Trailer | ESP Auth | ESP Payload (Original IP Hdr + Data)]
-
-
Detailed for ESP Tunnel Mode (Most Common):
-
Original IP packet (with payload) is encapsulated.
-
ESP trailer (padding, pad length, next header) appended.
-
ESP payload (original packet) encrypted with symmetric key (e.g., AES).
-
ESP auth data (HMAC) computed over ESP header, payload, trailer.
-
New outer IP header added.
-
7.3 VPN vs. Trusted Operating Systems
| Aspect | VPN | Trusted OS |
|---|---|---|
| Security Layer | Network/Transport (L3/L4) | Host OS (mandatory access control) |
| Mechanism | Encryption tunnel | Reference Monitor enforces MAC policies |
| Scope | Protects data in transit | Protects data at rest & in use on host |
| Architecture | Endpoints or gateways | Secure kernel, security policy database |
| Example | IPSec tunnel, SSL-VPN | SELinux, Trusted Solaris |
| Application | Secure connectivity over Internet | High-security hosts (military, govt), multi-level security |
[!TIP] Exam Focus: Be able to draw ESP tunnel mode vs transport mode. VPN secures communication channel; Trusted OS secures the host itself.
8.0 APPLICATION-LAYER SECURITY PROTOCOLS
8.1 Pretty Good Privacy (PGP) for Email
-
Working (Hybrid Cryptosystem):
-
Generate random symmetric session key.
-
Encrypt message with session key (fast, e.g., AES).
-
Encrypt session key with recipient's public key (RSA/ECC).
-
Optionally sign message digest (SHA) with sender's private key.
-
-
Services: Confidentiality (symmetric encryption), Authentication & Non-Repudiation (digital signature), Compression (ZIP).
-
PGP Message Format:
[Signature (optional)] [Session Key (encrypted with recipient's pubkey)] [Encrypted Message (with session key)]DiagramCANVAS: A block diagram showing three sequential blocks: 1) "Signature" (signed hash), 2) "Encrypted Session Key" (RSA-encrypted), 3) "Encrypted Data" (AES ciphertext). Arrows show flow from sender to receiver.
8.2 SSL / TLS
-
SSL Record Protocol:
-
Services: Confidentiality (encryption), Integrity (MAC), Encapsulation (fragments data into records).
-
Takes application data, fragments, compresses (optional), adds MAC, encrypts, adds header (type, version, length).
-
-
SSL Handshake Protocol (Establishing Secure Connection):
-
ClientHello: Client sends supported cipher suites, random nonce.
-
ServerHello: Server selects cipher suite, sends random nonce, certificate (with public key).
-
Key Exchange: Server may send ServerKeyExchange (if needed, e.g., DH params). ClientKeyExchange: Client sends premaster secret encrypted with server's public key (RSA) or DH public value.
-
Change Cipher Spec: Both sides compute master secret from premaster + nonces. Derive session keys. Switch to encrypted mode.
-
Finished: Encrypted "verify" messages to confirm handshake integrity.
-
-
SSL Session vs Connection:
-
Session: Established security parameters (master secret, cipher suite) that can be reused for multiple connections (faster).
-
Connection: Transient communication channel associated with a session. Each HTTP request/response may use same session but new connection.
-
-
Contribution to HTTPS: SSL/TLS provides encryption (confidentiality) and server authentication (via certificate) for web traffic.
8.3 Secure Electronic Transaction (SET)
-
Security Concerns in Online Transactions:
-
Card number theft during transmission.
-
Merchant fraud (charging wrong amount).
-
Customer anonymity vs. merchant needing payment info.
-
Disputes (did customer authorize?).
-
-
How SET Addresses Them:
-
Dual Signature: Customer signs order info and payment info separately, then combines. Merchant sees order, bank sees payment, neither sees full link.
-
Separation of Information: Order and payment messages are separate.
-
Certificates for All Parties: Cardholder, Merchant, Bank (acquirer) all have X.509 certificates.
-
-
Transaction Flow Example:
-
Customer sends Purchase Order (encrypted for merchant) + Payment Instructions (encrypted for bank) with dual signature.
-
Merchant forwards payment info to bank, gets authorization.
-
Merchant fulfills order.
-
Bank settles with merchant.
-
-
Application: B2C e-commerce with high security (though complex, superseded by simpler TLS + 3D Secure).
9.0 WIRELESS & MOBILE SECURITY
9.1 Wireless LAN (WLAN) Security Challenges
-
Open Medium: Radio signals travel beyond physical boundaries → eavesdropping easy.
-
Rogue Access Points: Unauthorized APs inside corporate network.
-
Weak Encryption: WEP (RC4 with weak IV, cracked in minutes). WPA/WPA2 (TKIP/AES) stronger, but WPA2 has KRACK attack.
-
Denial-of-Service: Jamming, deauthentication attacks.
-
Public vs Private: Public hotspots (coffee shops) have no encryption by default → man-in-the-middle risk. Private networks use WPA2/WPA3.
9.2 Wireless Application Protocol (WAP) Security
-
WAP Architecture:
[Mobile Device] <--WTLS--> [WAP Gateway] <--TLS/SSL--> [Web Server]DiagramCANVAS: Three boxes left-to-right: "Mobile Device (WAP Browser)", "WAP Gateway (Protocol Gateway)", "Web Server (HTTP/HTTPS)". Arrows: Mobile→Gateway labeled "WTLS (encrypted)", Gateway→Web Server labeled "TLS/SSL (decrypted/re-encrypted)". Gateway shown as decryption point. -
WTLS (Wireless Transport Layer Security):
-
Analogous to TLS but optimized for wireless constraints (low bandwidth, high latency).
-
Handshake similar to TLS: cipher suite negotiation, certificate exchange (optional).
-
Provides confidentiality, integrity, authentication between mobile device and gateway.
-
-
Security Issues in WTLS:
-
Gateway Decryption Point: Traffic is decrypted at gateway → internal network sees plaintext. Gateway is single point of failure/attack.
-
Weak Cipher Suites: Early WTLS allowed weak crypto (export restrictions).
-
Certificate Management: Hard on mobile devices; often bypassed.
-
9.3 Access Point (AP) Security in Public Networks
-
Risks in Hotspots:
-
Evil Twin: Rogue AP with same SSID.
-
Sniffing: Unencrypted traffic.
-
Session Hijacking.
-
-
Mitigation:
-
Use personal firewall on device.
-
Always use VPN (e.g., SSL-VPN) for any sensitive traffic.
-
Disable SSID broadcast (security through obscurity, not strong).
-
Use WPA2/WPA3 with strong passphrase (for known networks).
-
Verify network name with staff.
-
9.4 WLAN Protocol Stack & MPDU Format
-
IEEE 802.11 Stack:
Application LLC (Logical Link Control) MAC (Medium Access Control) → **MPDU** PLCP (Physical Layer Convergence Protocol) PMD (Physical Medium Dependent) -
MAC Protocol Data Unit (MPDU) Frame:
[MAC Header] | [Frame Body] | [FCS (Frame Check Sequence)]DiagramCANVAS: Horizontal block diagram: Left: "MAC Header" (with sub-labels: Frame Control, Duration, Addr1, Addr2, Addr3, Seq Ctrl). Middle: "Frame Body" (0-2312 bytes). Right: "FCS" (4 bytes, CRC).-
MAC Header Fields:
-
Addr1: Receiver MAC.
-
Addr2: Transmitter MAC.
-
Addr3: BSSID (AP MAC) or destination in ad-hoc.
-
-
FCS: 32-bit CRC for error detection.
-
10.0 MALWARE & GENERAL THREATS
10.1 Types of Malicious Software (Malware)
| Type | Definition | Propagation | Impact |
|---|---|---|---|
| Virus | Needs host program, attaches to executable | User action (run infected file) | Corrupts files, spreads |
| Worm | Standalone, self-replicating | Network exploits, email | Consumes bandwidth, creates botnets |
| Trojan | Disguised as legitimate software | Social engineering, drive-by download | Backdoor, data theft |
| Ransomware | Encrypts files, demands ransom | Phishing, exploit kits | Data loss, financial extortion |
| Spyware | Secretly monitors activity | Bundled software | Keylogging, credential theft |
| Adware | Displays unwanted ads | Bundled, malicious sites | Annoyance, privacy violation |
| Rootkit | Hides existence/processes | Exploits, social engineering | Persistent stealth access |
10.2 Security Considerations & Threats
-
Threat Landscape: Social engineering (phishing), zero-day exploits (unknown vulnerabilities), APTs (targeted, prolonged attacks).
-
Defense-in-Depth: Layered security (firewall, IDS, AV, patching, user training). No single solution is sufficient.
11.0 ADVANCED & COMPARATIVE TOPICS
11.1 Trusted Operating Systems
-
Concept: OS designed with security as primary goal, enforcing Mandatory Access Control (MAC).
-
MAC vs DAC:
-
DAC (Discretionary): Owner decides access (Unix permissions). Vulnerable toTrojan misuse.
-
MAC (Mandatory): System-wide policy enforced by security kernel (e.g., Bell-LaPadula model). Labels (e.g., Top Secret) on subjects/objects. No override by user.
-
-
Security Architecture:
-
Reference Monitor: Abstract machine mediating all accesses.
-
Security Kernel: Minimal, verified part of OS implementing reference monitor.
-
Trusted Computing Base (TCB): All hardware/software critical to security.
-
-
Examples: SELinux (Linux), Trusted Solaris, Windows with Mandatory Integrity Control.
-
Applications: Military systems, government databases, critical infrastructure.
11.2 Web Traffic Security Approaches
| Approach | Layer | Mechanism | Scope | Best For |
|---|---|---|---|---|
| SSL/TLS | Application (L7) | End-to-end encryption & auth | Host-to-host (browser↔server) | Web browsing (HTTPS), email (SMTPS) |
| IPsec | Network (L3) | AH/ESP in transport/tunnel mode | Network-to-network or host-to-host | Site-to-site VPN, securing all traffic |
| VPN (Tunneling) | Varies (L2/L3) | Tunnels + encryption (often IPsec/SSL) | Gateway-to-gateway or remote access | Connecting branch offices, remote workers |
| PGP | Application (L7) | Hybrid (symmetric + asymmetric) | End-to-end for specific app | Secure email, file encryption |
-
Selection Criteria:
-
Required services: Confidentiality only? Need authentication?
-
Deployment point: Protect entire network (IPsec) vs. specific app (SSL/TLS, PGP).
-
Performance: IPsec (kernel) vs SSL (user-space).
-
Transparency: IPsec (transparent to apps) vs SSL (app-aware).
-