Skip to content
CY-503 (C) · Data Security/Quick Revision Short Notes

Data Security (CY-503 (C)) - Unit 3 Short Notes

UNIT 3: DATA SECURITY - EXAM-FOCUSED SHORT NOTES


1.0 CRYPTOGRAPHY FUNDAMENTALS

1.1 Symmetric vs. Asymmetric Encryption

Feature Symmetric Encryption Asymmetric Encryption
Key Single shared secret key Public/Private key pair
Primary Goal Confidentiality Confidentiality, Authentication, Non-Repudiation
Speed Fast (hardware efficient) Slow (computationally intensive)
Key Distribution Major challenge (secure channel needed) Solves via public key infrastructure (PKI)
Example Algorithms AES, DES, RC4 RSA, ECC, Diffie-Hellman
Use Case Bulk data encryption (e.g., disk, file) Key exchange, digital signatures, small data

[!TIP] Exam Focus: Be prepared to contrast security (asymmetric solves key distribution), speed (symmetric is 1000x faster), and typical applications.

1.2 Classic Ciphers: Caesar Cipher

  • Principle: Substitution cipher where each plaintext letter is shifted a fixed number (k) positions down the alphabet.

  • Encryption: $$\displaystyle C = (P + k) \mod 26 $$

  • Decryption: $$\displaystyle P = (C - k) \mod 26 $$

  • Example (Shift k=17): Decrypt ZICVTWQNGRZGVTWAVZHCQYGLMGJ

    • For 'Z' (25): $$\displaystyle P = (25 - 17) \mod 26 = 8 $$ → I

    • For 'I' (8): $$\displaystyle P = (8 - 17) \mod 26 = 17 $$ → R

    • Continue... Result: IRETURNTOYOURCOUNTRYPLEASE

1.3 Block Ciphers vs. Stream Ciphers

Block Cipher Stream Cipher
Encrypts fixed-size blocks (e.g., 128 bits) Encrypts bits/bytes one at a time
Uses confusion & diffusion across block Uses keystream XORed with plaintext
Requires padding for last block No padding needed (streaming)
Examples: AES, DES, 3DES Examples: RC4, Salsa20, ChaCha20
Merit: Stronger security guarantees Merit: Faster, low latency, suitable for real-time
Demerit: Slower, propagation of errors Demerit: Weak if keystream reused

1.4 Modes of Operation for Block Ciphers

  • Need for Modes: To securely encrypt data longer than one block, avoid pattern leakage.

  • ECB (Electronic Codebook):

    • Each block encrypted independently.

    • Merit: Simple, parallelizable.

    • Demerit: Identical plaintext blocks → identical ciphertext blocks (pattern leakage). Insecure for most uses.

  • CBC (Cipher Block Chaining):

    • $$\displaystyle C_i = E_K(P_i \oplus C_{i-1}) $$, with $$\displaystyle C_0 = IV $$.

    • Merit: Hides patterns, widely used (e.g., TLS).

    • Demerit: Sequential (not parallelizable), IV must be unpredictable.

  • CFB (Cipher Feedback): Turns block cipher into stream cipher. $$\displaystyle C_i = P_i \oplus E_K(C_{i-1}) $$.

  • OFB (Output Feedback): Generates keystream independent of plaintext/ciphertext. $$\displaystyle O_i = E_K(O_{i-1}) $$, $$\displaystyle C_i = P_i \oplus O_i $$.

  • CTR (Counter): $$\displaystyle C_i = P_i \oplus E_K(IV + i) $$. Merit: Parallelizable, random access. Demerit: Counter must never repeat.

[!TIP] Exam Focus: Know why ECB is bad (pattern leakage), and be able to draw/explain CBC operation with IV.


2.0 SYMMETRIC ENCRYPTION ALGORITHMS (MODERN)

2.1 Advanced Encryption Standard (AES)

  • Structure: Iterated Substitution-Permutation Network (not Feistel).

  • Block Size: 128 bits. Key Sizes: 128, 192, 256 bits → 10, 12, 14 rounds.

  • Round Operations (per round except last):

    1. SubBytes: Non-linear substitution using S-box.

    2. ShiftRows: Cyclic shift of rows (diffusion).

    3. MixColumns: Mixes columns using matrix multiplication.

    4. AddRoundKey: XOR with round key.

  • Final Round: SubBytes, ShiftRows, AddRoundKey (no MixColumns).

  • Key Schedule: Expands key into round keys using RotWord, SubWord, Rcon.

  • Example (Simplified 128-bit key, 1 round):

    • Plaintext: 00112233445566778899aabbccddeeff

    • After SubBytes, ShiftRows, MixColumns, AddRoundKey... (detailed step-by-step not typically required for short notes).

2.2 RC4 Stream Cipher

  • Two Phases:

    1. Key Scheduling Algorithm (KSA): Initializes S-box (0-255) and permutes using key K[].

      
      for i=0 to 255: S[i]=i, j=0
      
      for i=0 to 255: j = (j + S[i] + K[i mod keylen]) mod 256; swap(S[i], S[j])
      
      
    2. Pseudo-Random Generation Algorithm (PRGA): Generates keystream byte K.

      
      i = (i+1) mod 256; j = (j + S[i]) mod 256; swap(S[i], S[j]); t = (S[i]+S[j]) mod 256; K = S[t]
      
      
  • Encryption: Ciphertext = Plaintext XOR Keystream.

  • Worked Example (5-bit key K = [1,2,3]):

    • KSA: S = [0,1,2,3,4] initially. For i=0: j=(0+0+1)%5=1, swap S[0]↔S[1] → S=[1,0,2,3,4]. Continue...

    • PRGA: First byte: i=1, j=(0+S[1])%5=0, swap S[1]↔S[0] → S=[0,1,2,3,4], t=(0+1)%5=1, K=S[1]=1.

    • Generate first 3 bytes: 1, 3, 2 (depends on exact KSA steps).

  • Security: Vulnerable if key reused. Weak in WEP (FMS attack). Avoid in new systems.


3.0 ASYMMETRIC ENCRYPTION & DIGITAL SIGNATURES

3.1 RSA Algorithm

  • Math Foundation: Based on difficulty of factoring large integers. Uses Euler's Theorem: $$\displaystyle m^{\phi(n)} \equiv 1 \mod n $$ if gcd(m,n)=1.

  • Key Generation:

    1. Choose primes p, q. Compute $$\displaystyle n = p \times q $$, $$\displaystyle \phi(n) = (p-1)(q-1) $$.

    2. Choose public exponent e such that $$\displaystyle 1 < e < \phi(n) $$ and gcd(e, φ(n)) = 1.

    3. Compute private exponent d such that $d \times e \equiv 1 \mod \phi(n)$.

  • Encryption: $$\displaystyle C = M^e \mod n $$

  • Decryption: $$\displaystyle M = C^d \mod n $$

  • Numerical Example (p=3, q=11):

    • $$\displaystyle n=33 $$, $$\displaystyle \phi(n)=20 $$.

    • Choose $$\displaystyle e=7 $$ (gcd(7,20)=1).

    • Find $d$: $7d \equiv 1 \mod 20$ → $$\displaystyle d=3 $$ (since 21 mod 20 = 1).

    • Encrypt $$\displaystyle M=2 $$: $$\displaystyle C = 2^7 \mod 33 = 128 \mod 33 = 29 $$.

    • Decrypt $$\displaystyle C=29 $$: $$\displaystyle M = 29^3 \mod 33 = 24389 \mod 33 = 2 $$.

  • Security: Relies on integer factorization problem. Breaking requires factoring n.

3.2 Public-Key Cryptography for Digital Signatures

  • Process:

    1. Signing: Sender computes hash of message, encrypts hash with own private key → signature.

    2. Verification: Receiver decrypts signature with sender's public key, compares with freshly computed hash.

  • Provides:

    • Authentication: Proves sender's identity.

    • Non-Repudiation: Sender cannot deny sending (only they have private key).

    • Integrity: Any change in message changes hash → verification fails.

  • Crucial Aspect: Never sign raw message; always sign a hash digest (efficient, standardized).

3.3 Digital Signatures: Crucial Aspects

  • Solves Repudiation: Provides undeniable proof of origin.

  • Hash Function Role: Ensures efficiency (sign fixed-size digest) and security (collision resistance prevents forgery).

  • Applications: Software updates (code signing), financial transactions (e.g., SET), legal documents.


4.0 HASH FUNCTIONS & MESSAGE AUTHENTICATION

4.1 Cryptographic Hash Functions

  • Properties:

    • Deterministic: Same input → same output.

    • Pre-image Resistance: Given hash h, hard to find m such that hash(m)=h.

    • Second Pre-image Resistance: Given m1, hard to find m2 ≠ m1 with same hash.

    • Collision Resistance: Hard to find any two messages m1, m2 with same hash.

    • Avalanche Effect: Small change in input → ~50% change in output bits.

  • SHA-512 (Example):

    1. Padding: Append '1', zeros, and 128-bit message length (big-endian) to make length ≡ 896 mod 1024.

    2. Parsing: Split into 1024-bit blocks.

    3. Compression: For each block, update 512-bit state (8 words) using 80 rounds of operations (Ch, Maj, Σ functions) with constants.

    4. Output: Final state concatenated → 512-bit digest.

  • Finding Collisions: Brute-force requires ~$$\displaystyle 2^{256} $$ operations (birthday paradox). Theoretical order: $$\displaystyle O(2^{n/2}) $$ for n-bit hash.

4.2 Message Authentication Codes (MACs)

  • Purpose: Provide integrity and authentication between parties sharing a secret key.

  • Types:

    • Hash-based (HMAC): $$\displaystyle HMAC(K, m) = H((K \oplus opad) \| H((K \oplus ipad) \| m)) $$

      • ipad = 0x36 repeated, opad = 0x5C repeated.

      • Security Rationale: Inner hash protects against length extension attacks; outer hash acts as "signature".

    • Block Cipher-based (CMAC): Uses CBC mode with final block special processing.

  • Difference from Hash: MAC uses secret key; hash is public.

4.3 Parameter Pattern Matching (IDS Technique)

  • Definition: Anomaly-based detection that monitors statistical profiles of network/header parameters (e.g., packet size, inter-arrival time, port numbers).

  • How it Works: Establishes baseline "normal" profile. Flags deviations (e.g., sudden spike in SYN packets → SYN flood).

  • Use in IDS: Detects unknown/zero-day attacks by spotting abnormal behavior, unlike signature-based (known patterns).


5.0 AUTHENTICATION MECHANISMS (BEYOND CRYPTOGRAPHY)

5.1 Biometric Authentication

  • Types: Fingerprint, Iris, Facial, Voice, Vein pattern.

  • Working Phases:

    1. Enrollment: Capture biometric, extract feature vector, store template (often encrypted).

    2. Verification: Capture live sample, extract features, compare with stored template using matching algorithm (threshold-based).

  • Advantages: Something you are → hard to steal/lose; user-friendly.

  • Challenges:

    • False Positive (FP): Unauthorized accepted.

    • False Negative (FN): Authorized rejected.

    • Spoofing: Fake fingerprint/photo.

    • Non-revocability: Cannot "change" biometric if compromised.

5.2 Smart Cards

  • Components:

    • Physical: Plastic card with embedded microcontroller or memory chip.

    • Logical: Stores credentials (certificates, keys), performs cryptographic operations.

  • How it Works: Card inserted into reader → provides two-factor (something you have + PIN). Card can perform private key operations internally (private key never leaves card).

  • Comparison with Biometrics:

    | Smart Card | Biometric | | :--- | :--- | | Something you have | Something you are | | Can be lost/stolen | Cannot be lost (but can be spoofed) | | Revocable (issue new card) | Generally not revocable | | PIN can be guessed | Template theft permanent |


6.0 NETWORK SECURITY DEVICES: FIREWALLS & IDS

6.1 Firewalls

  • Classification & Types:

    | Type | OSI Layer | Inspection | Example | Merits | Demerits | | :--- | :--- | :--- | :--- | :--- | :--- | | Packet Filter | Network (L3) | Header (IP, Port) | Stateless rules | Fast, transparent | No context, easy to spoof | | Stateful Inspection | Transport (L4) | Connection state | Tracks TCP flags | Better security, state table | Resource intensive | | Circuit-Level Gateway | Session (L5) | TCP handshake | SOCKS proxy | Hides internal IP | No payload inspection | | Application-Level Gateway (Proxy) | Application (L7) | Full payload | Web proxy, email filter | Deep inspection, protocol aware | Slow, single point of failure | | Personal Firewall | Host-based | All traffic to/from host | Windows Defender Firewall | Protects individual host | Management overhead |

  • Role in Malware Defense: Can block known malicious ports/IPs, filter exploit traffic (proxy), but cannot detect file-based malware inside allowed connections.

6.2 Intrusion Detection Systems (IDS)

  • HIDS vs NIDS Comparison:

    | Aspect | HIDS | NIDS | | :--- | :--- | :--- | | Scope | Single host/endpoint | Entire network segment | | Data Source | System logs, audit trails, file integrity | Network packets (sniffed) | | Placement | On critical hosts | At network choke points (DMZ, perimeter) | | Evasion | Harder (attacker must compromise host) | Easier (encryption, fragmentation) | | Example | OSSEC, Wazuh | Snort, Suricata |

  • Detection Methods:

    • Signature-based: Matches known attack patterns (e.g., specific byte sequence). Low false positives, misses zero-days.

    • Anomaly-based: Establishes baseline "normal" traffic. Parameter Pattern Matching is a subtype that monitors statistical parameters (packet size, rate). Detects zero-days, higher false positives.

  • Role in Malware Defense: Detects command-and-control (C2) traffic, propagation scans (NIDS), or local malware activity (HIDS file changes).


7.0 SECURE NETWORK TUNNELS: VPNs & IPSec

7.1 Virtual Private Networks (VPNs)

  • Definition: Creates encrypted tunnel over untrusted network (Internet) for secure communication.

  • Types:

    • Remote Access VPN: Individual user → corporate network (e.g., employee from home). Protocols: SSL/TLS, IPsec.

    • Site-to-Site VPN: Connects entire networks (e.g., branch offices). Intranet (same org), Extranet (with partners).

  • Security Architecture: Tunneling protocol + encryption (AES) + authentication (certificates, pre-shared keys).

  • Common Protocols: PPTP (weak), L2TP/IPsec, IPsec, SSL/TLS (most common for remote access).

7.2 IP Security (IPSec)

  • Protocols:

    • AH (Authentication Header): Provides integrity & authentication (no confidentiality). Protects IP header & payload. Rarely used alone.

    • ESP (Encapsulating Security Payload): Provides confidentiality, integrity, authentication. Encrypts payload (and optionally header).

  • Modes:

    • Transport Mode: Protects payload of original IP packet. Original IP header exposed. Used for end-to-end (host-to-host).

      
      [Original IP Hdr | ESP Trailer | ESP Auth | ESP Payload (encrypted)]
      
      
    • Tunnel Mode: Protects entire original IP packet. Entire original packet encrypted + new IP header added. Used for network-to-network (gateway-to-gateway).

      
      [New IP Hdr | ESP Trailer | ESP Auth | ESP Payload (Original IP Hdr + Data)]
      
      
  • Detailed for ESP Tunnel Mode (Most Common):

    1. Original IP packet (with payload) is encapsulated.

    2. ESP trailer (padding, pad length, next header) appended.

    3. ESP payload (original packet) encrypted with symmetric key (e.g., AES).

    4. ESP auth data (HMAC) computed over ESP header, payload, trailer.

    5. New outer IP header added.

7.3 VPN vs. Trusted Operating Systems

Aspect VPN Trusted OS
Security Layer Network/Transport (L3/L4) Host OS (mandatory access control)
Mechanism Encryption tunnel Reference Monitor enforces MAC policies
Scope Protects data in transit Protects data at rest & in use on host
Architecture Endpoints or gateways Secure kernel, security policy database
Example IPSec tunnel, SSL-VPN SELinux, Trusted Solaris
Application Secure connectivity over Internet High-security hosts (military, govt), multi-level security

[!TIP] Exam Focus: Be able to draw ESP tunnel mode vs transport mode. VPN secures communication channel; Trusted OS secures the host itself.


8.0 APPLICATION-LAYER SECURITY PROTOCOLS

8.1 Pretty Good Privacy (PGP) for Email

  • Working (Hybrid Cryptosystem):

    1. Generate random symmetric session key.

    2. Encrypt message with session key (fast, e.g., AES).

    3. Encrypt session key with recipient's public key (RSA/ECC).

    4. Optionally sign message digest (SHA) with sender's private key.

  • Services: Confidentiality (symmetric encryption), Authentication & Non-Repudiation (digital signature), Compression (ZIP).

  • PGP Message Format:

    
    [Signature (optional)] [Session Key (encrypted with recipient's pubkey)] [Encrypted Message (with session key)]
    
    
    DiagramCANVAS: A block diagram showing three sequential blocks: 1) "Signature" (signed hash), 2) "Encrypted Session Key" (RSA-encrypted), 3) "Encrypted Data" (AES ciphertext). Arrows show flow from sender to receiver.

8.2 SSL / TLS

  • SSL Record Protocol:

    • Services: Confidentiality (encryption), Integrity (MAC), Encapsulation (fragments data into records).

    • Takes application data, fragments, compresses (optional), adds MAC, encrypts, adds header (type, version, length).

  • SSL Handshake Protocol (Establishing Secure Connection):

    1. ClientHello: Client sends supported cipher suites, random nonce.

    2. ServerHello: Server selects cipher suite, sends random nonce, certificate (with public key).

    3. Key Exchange: Server may send ServerKeyExchange (if needed, e.g., DH params). ClientKeyExchange: Client sends premaster secret encrypted with server's public key (RSA) or DH public value.

    4. Change Cipher Spec: Both sides compute master secret from premaster + nonces. Derive session keys. Switch to encrypted mode.

    5. Finished: Encrypted "verify" messages to confirm handshake integrity.

  • SSL Session vs Connection:

    • Session: Established security parameters (master secret, cipher suite) that can be reused for multiple connections (faster).

    • Connection: Transient communication channel associated with a session. Each HTTP request/response may use same session but new connection.

  • Contribution to HTTPS: SSL/TLS provides encryption (confidentiality) and server authentication (via certificate) for web traffic.

8.3 Secure Electronic Transaction (SET)

  • Security Concerns in Online Transactions:

    • Card number theft during transmission.

    • Merchant fraud (charging wrong amount).

    • Customer anonymity vs. merchant needing payment info.

    • Disputes (did customer authorize?).

  • How SET Addresses Them:

    • Dual Signature: Customer signs order info and payment info separately, then combines. Merchant sees order, bank sees payment, neither sees full link.

    • Separation of Information: Order and payment messages are separate.

    • Certificates for All Parties: Cardholder, Merchant, Bank (acquirer) all have X.509 certificates.

  • Transaction Flow Example:

    1. Customer sends Purchase Order (encrypted for merchant) + Payment Instructions (encrypted for bank) with dual signature.

    2. Merchant forwards payment info to bank, gets authorization.

    3. Merchant fulfills order.

    4. Bank settles with merchant.

  • Application: B2C e-commerce with high security (though complex, superseded by simpler TLS + 3D Secure).


9.0 WIRELESS & MOBILE SECURITY

9.1 Wireless LAN (WLAN) Security Challenges

  • Open Medium: Radio signals travel beyond physical boundaries → eavesdropping easy.

  • Rogue Access Points: Unauthorized APs inside corporate network.

  • Weak Encryption: WEP (RC4 with weak IV, cracked in minutes). WPA/WPA2 (TKIP/AES) stronger, but WPA2 has KRACK attack.

  • Denial-of-Service: Jamming, deauthentication attacks.

  • Public vs Private: Public hotspots (coffee shops) have no encryption by default → man-in-the-middle risk. Private networks use WPA2/WPA3.

9.2 Wireless Application Protocol (WAP) Security

  • WAP Architecture:

    
    [Mobile Device] <--WTLS--> [WAP Gateway] <--TLS/SSL--> [Web Server]
    
    
    DiagramCANVAS: Three boxes left-to-right: "Mobile Device (WAP Browser)", "WAP Gateway (Protocol Gateway)", "Web Server (HTTP/HTTPS)". Arrows: Mobile→Gateway labeled "WTLS (encrypted)", Gateway→Web Server labeled "TLS/SSL (decrypted/re-encrypted)". Gateway shown as decryption point.
  • WTLS (Wireless Transport Layer Security):

    • Analogous to TLS but optimized for wireless constraints (low bandwidth, high latency).

    • Handshake similar to TLS: cipher suite negotiation, certificate exchange (optional).

    • Provides confidentiality, integrity, authentication between mobile device and gateway.

  • Security Issues in WTLS:

    • Gateway Decryption Point: Traffic is decrypted at gateway → internal network sees plaintext. Gateway is single point of failure/attack.

    • Weak Cipher Suites: Early WTLS allowed weak crypto (export restrictions).

    • Certificate Management: Hard on mobile devices; often bypassed.

9.3 Access Point (AP) Security in Public Networks

  • Risks in Hotspots:

    • Evil Twin: Rogue AP with same SSID.

    • Sniffing: Unencrypted traffic.

    • Session Hijacking.

  • Mitigation:

    • Use personal firewall on device.

    • Always use VPN (e.g., SSL-VPN) for any sensitive traffic.

    • Disable SSID broadcast (security through obscurity, not strong).

    • Use WPA2/WPA3 with strong passphrase (for known networks).

    • Verify network name with staff.

9.4 WLAN Protocol Stack & MPDU Format

  • IEEE 802.11 Stack:

    
    Application
    
    LLC (Logical Link Control)
    
    MAC (Medium Access Control) → **MPDU**
    
    PLCP (Physical Layer Convergence Protocol)
    
    PMD (Physical Medium Dependent)
    
    
  • MAC Protocol Data Unit (MPDU) Frame:

    
    [MAC Header] | [Frame Body] | [FCS (Frame Check Sequence)]
    
    
    DiagramCANVAS: Horizontal block diagram: Left: "MAC Header" (with sub-labels: Frame Control, Duration, Addr1, Addr2, Addr3, Seq Ctrl). Middle: "Frame Body" (0-2312 bytes). Right: "FCS" (4 bytes, CRC).
    • MAC Header Fields:

      • Addr1: Receiver MAC.

      • Addr2: Transmitter MAC.

      • Addr3: BSSID (AP MAC) or destination in ad-hoc.

    • FCS: 32-bit CRC for error detection.


10.0 MALWARE & GENERAL THREATS

10.1 Types of Malicious Software (Malware)

Type Definition Propagation Impact
Virus Needs host program, attaches to executable User action (run infected file) Corrupts files, spreads
Worm Standalone, self-replicating Network exploits, email Consumes bandwidth, creates botnets
Trojan Disguised as legitimate software Social engineering, drive-by download Backdoor, data theft
Ransomware Encrypts files, demands ransom Phishing, exploit kits Data loss, financial extortion
Spyware Secretly monitors activity Bundled software Keylogging, credential theft
Adware Displays unwanted ads Bundled, malicious sites Annoyance, privacy violation
Rootkit Hides existence/processes Exploits, social engineering Persistent stealth access

10.2 Security Considerations & Threats

  • Threat Landscape: Social engineering (phishing), zero-day exploits (unknown vulnerabilities), APTs (targeted, prolonged attacks).

  • Defense-in-Depth: Layered security (firewall, IDS, AV, patching, user training). No single solution is sufficient.


11.0 ADVANCED & COMPARATIVE TOPICS

11.1 Trusted Operating Systems

  • Concept: OS designed with security as primary goal, enforcing Mandatory Access Control (MAC).

  • MAC vs DAC:

    • DAC (Discretionary): Owner decides access (Unix permissions). Vulnerable toTrojan misuse.

    • MAC (Mandatory): System-wide policy enforced by security kernel (e.g., Bell-LaPadula model). Labels (e.g., Top Secret) on subjects/objects. No override by user.

  • Security Architecture:

    • Reference Monitor: Abstract machine mediating all accesses.

    • Security Kernel: Minimal, verified part of OS implementing reference monitor.

    • Trusted Computing Base (TCB): All hardware/software critical to security.

  • Examples: SELinux (Linux), Trusted Solaris, Windows with Mandatory Integrity Control.

  • Applications: Military systems, government databases, critical infrastructure.

11.2 Web Traffic Security Approaches

Approach Layer Mechanism Scope Best For
SSL/TLS Application (L7) End-to-end encryption & auth Host-to-host (browser↔server) Web browsing (HTTPS), email (SMTPS)
IPsec Network (L3) AH/ESP in transport/tunnel mode Network-to-network or host-to-host Site-to-site VPN, securing all traffic
VPN (Tunneling) Varies (L2/L3) Tunnels + encryption (often IPsec/SSL) Gateway-to-gateway or remote access Connecting branch offices, remote workers
PGP Application (L7) Hybrid (symmetric + asymmetric) End-to-end for specific app Secure email, file encryption
  • Selection Criteria:

    • Required services: Confidentiality only? Need authentication?

    • Deployment point: Protect entire network (IPsec) vs. specific app (SSL/TLS, PGP).

    • Performance: IPsec (kernel) vs SSL (user-space).

    • Transparency: IPsec (transparent to apps) vs SSL (app-aware).

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in