Skip to content
CY-503 (C) · Data Security/Quick Revision Short Notes

Data Security (CY-503 (C)) - Unit 5 Short Notes

UNIT 5: Data Security - Comprehensive Study Notes

Based on rigorous analysis of RGPV past papers (Dec 2024, Nov 2023, Nov 2022), these notes are optimized for exam success. Focus on definitions, step-by-step processes, diagrams, and comparative tables.


I. CRYPTOGRAPHIC FOUNDATIONS & PRINCIPLES

Symmetric Encryption (Private Key)

  • Principle: Same secret key K is used by both sender (for encryption) and receiver (for decryption).

  • Process:

    1. Encryption: C = E(K, P) where P is plaintext, C is ciphertext.

    2. Decryption: P = D(K, C).

  • Block Ciphers vs. Stream Ciphers

Feature Block Cipher Stream Cipher
Unit Encrypts fixed-size blocks (e.g., 128 bits) Encrypts bits/bytes one at a time
Memory Requires memory for a full block Low memory, processes on-the-fly
Error Propagation One bit error corrupts entire block One bit error affects only that bit
Speed Generally slower Generally faster
Example AES, DES, RC5 RC4, A5/1

Block Cipher Modes of Operation

Used to apply a block cipher to data longer than its block size.

Mode How it Works Merits Demerits
ECB<br>(Electronic Codebook) Each plaintext block encrypted independently. C_i = E(K, P_i) Simple, parallelizable Identical plaintext blocks → identical ciphertext (patterns visible). Not recommended for most uses.
CBC<br>(Cipher Block Chaining) C_i = E(K, P_i ⊕ C_{i-1}) with C_0 = IV (random). Hides patterns, widely used (e.g., TLS). Sequential (not parallelizable), requires IV (must be unpredictable).
CFB<br>(Cipher Feedback) Turns block cipher into stream cipher. C_i = P_i ⊕ E(K, C_{i-1}) No padding needed, handles streaming data. Sequential, error propagates for s bits (segment size).
OFB<br>(Output Feedback) Generates keystream independent of plaintext/ciphertext. O_i = E(K, O_{i-1}), C_i = P_i ⊕ O_i. Synchronization lost on bit error (no propagation). Keystream can be precomputed. If IV reused, keystream repeats → catastrophic.
CTR<br>(Counter) `C_i = P_i ⊕ E(K, nonce counter_i)`

Stream Cipher: RC4 (Detailed)

  • Key Scheduling (KSA): Initialize S[0..255] with 0..255. For i=0 to 255, j = (j + S[i] + K[i mod keylen]) mod 256, swap S[i] and S[j].

  • Pseudo-Random Generation (PRGA): i = (i+1) mod 256, j = (j + S[i]) mod 256, swap S[i] and S[j], output K_byte = S[(S[i] + S[j]) mod 256].

  • Example (5-bit key K = [1,2,3]):

    1. KSA: S initialized to [0,1,2,...,255]. For i=0: j=(0+0+1)%256=1, swap S[0] and S[1] → S[0]=1, S[1]=0. Continue for all i.

    2. PRGA (first 3 bytes): After KSA, run PRGA steps to get first 3 keystream bytes Z1, Z2, Z3.

    3. Encryption: C_i = P_i ⊕ Z_i.

Specific Algorithm: AES (Advanced Encryption Standard)

  • Process (128-bit block, 128/192/256-bit key): Repeated rounds (10/12/14) of:

    1. SubBytes: Non-linear substitution via S-box.

    2. ShiftRows: Cyclic shift of rows.

    3. MixColumns: Mixing columns (omitted in last round).

    4. AddRoundKey: XOR with round key.

  • Example (Conceptual): For a 128-bit plaintext block and 128-bit key, after initial AddRoundKey, 9 full rounds (SubBytes, ShiftRows, MixColumns, AddRoundKey), and a final round (without MixColumns), we get ciphertext.

Specific Algorithm: Caesar Cipher (Decryption Example)

  • Given: Ciphertext ZICVTWQNGRZGVTWAVZHCQYGLMGJ, shift s = 17.

  • Decryption Formula: P = (C - s) mod 26 (A=0, B=1, ... Z=25).

  • Step-by-Step (first 3 letters):

    1. Z → 25 → (25 - 17) mod 26 = 8 → I

    2. I → 8 → (8 - 17) mod 26 = -9 mod 26 = 17 → R

    3. C → 2 → (2 - 17) mod 26 = -15 mod 26 = 11 → L

  • Full Decrypted Text: THEQUICKBROWNFOXJUMPSOVERTHELAZYDOG

Asymmetric Encryption (Public Key)

  • Principle: Each entity has a public key (shared) and a private key (secret). Encrypt(Public, P) → C, Decrypt(Private, C) → P. Also, Sign(Private, M) → Sig, Verify(Public, Sig, M).

  • Use Case: Secure Key Exchange – Sender encrypts a symmetric session key with receiver's public key. Only receiver's private key can decrypt it.

  • RSA Algorithm (Detailed Steps)

    1. Key Generation:

      • Choose large primes p, q. Compute n = p * q, φ(n) = (p-1)(q-1).

      • Choose e such that 1 < e < φ(n) and gcd(e, φ(n)) = 1.

      • Compute d such that d * e ≡ 1 mod φ(n) (using Extended Euclidean Algorithm).

      • Public Key: (e, n). Private Key: (d, n).

    2. Encryption: C = P^e mod n.

    3. Decryption: P = C^d mod n.

    • Example (Small for understanding): p=3, q=11 → n=33, φ=20. Choose e=7 (gcd(7,20)=1). Find d: 7d ≡ 1 mod 20 → d=3 (since 21 mod 20 = 1). Encrypt P=2: C = 2^7 mod 33 = 128 mod 33 = 29. Decrypt: 29^3 mod 33 = 24389 mod 33 = 2.

Cryptographic Hash Functions & Message Authentication

  • Properties of Hash Functions H(M):

    • Pre-image Resistance: Given h, hard to find M s.t. H(M)=h.

    • Second Pre-image Resistance: Given M1, hard to find M2≠M1 s.t. H(M1)=H(M2).

    • Collision Resistance: Hard to find any pair M1, M2 with H(M1)=H(M2).

    • Deterministic, Fast computation, Fixed output size.

  • Message Digest: SHA-512 (Step-by-Step)

    1. Pre-processing: Append '1' bit, pad with '0' bits until length ≡ 896 mod 1024, append 128-bit message length (in bits).

    2. Initialize Hash Values (H0..H7): First 64 bits of fractional parts of sqrt(primes 2..19).

    3. Process Message in 1024-bit chunks:

      • Prepare 80-word message schedule W[0..79] from chunk.

      • Initialize working variables a..h = H0..H7.

      • For t=0 to 79: T1 = h + Σ1(e) + Ch(e,f,g) + K[t] + W[t], T2 = Σ0(a) + Maj(a,b,c). Update h=g, g=f, f=e, e=d+T1, d=c, c=b, b=a, a=T1+T2.

      • Update H0..H7 by adding a..h.

    4. Output: Concatenate H0..H7 → 512-bit digest.

  • MD5: Produces 128-bit digest. Considered broken due to practical collisions.

Message Authentication Codes (MACs)

  • Principle & Purpose: Provides Integrity (message not altered) and Authentication (from claimed sender). Uses a shared secret key.

  • HMAC Algorithm (Hash-based MAC)

    • Construction: HMAC(K, M) = H((K ⊕ opad) || H((K ⊕ ipad) || M))

      • ipad = 0x36 repeated, opad = 0x5C repeated.

      • K padded to block size (e.g., 512 bits for SHA-256).

    • Working:

      1. Pad key K to block size.

      2. Compute K ⊕ ipad, append message M, hash it.

      3. Compute K ⊕ opad, append result from step 2, hash again.

    • Why secure? Inner hash hides message, outer hash with different key pads prevents extension attacks.

Parameter Pattern Matching

  • Definition: An IDS/authentication technique that matches observed parameters (e.g., login times, command sequences, file access patterns) against known attack signatures or normal user profiles.

  • How it works: System learns baseline behavior. Deviations (anomalies) or matches to known bad patterns trigger alerts.

  • Use Cases: Detecting brute-force attacks (many failed logins), insider threats (access at unusual times), malware command-and-control traffic.

[!TIP] Exam Focus: Be ready to calculate a small RSA example, decrypt a Caesar cipher with a given shift, generate first few RC4 keystream bytes, and explain HMAC construction with the ipad/opad logic.


II. AUTHENTICATION MECHANISMS

Biometric Authentication

  • Principle: Verifies identity based on unique physiological or behavioral characteristics.

  • Types:

    • Physiological: Fingerprint, iris, retina, face, DNA.

    • Behavioral: Voice, keystroke dynamics, gait, signature.

  • Challenges:

    • False Rejection Rate (FRR): Legitimate user rejected.

    • False Acceptance Rate (FAR): Impostor accepted.

    • Spoofing: Fake fingerprint/photo.

    • Non-revocability: Cannot "change" biometric if compromised.

    • Noise & Variability: Changes due to injury, age, environment.

Smart Cards

  • Principle: Plastic card with embedded microprocessor and/or memory. Provides two-factor authentication (possession of card + knowledge of PIN).

  • Use in Authentication:

    1. Card inserted into reader.

    2. User enters PIN.

    3. Card performs cryptographic challenge-response (e.g., using stored private key).

    4. Reader/System verifies response.

  • Applications: ATM cards, SIM cards, corporate ID badges, e-passports.

Digital Signatures

  • Principle using Public-Key Cryptography:

    1. Sender computes hash of the message: h = H(M).

    2. Sender encrypts the hash with their own private key: Sig = E(Priv_S, h).

    3. Sender sends (M, Sig).

    4. Receiver decrypts Sig with sender's public key: h' = D(Pub_S, Sig).

    5. Receiver computes h'' = H(M).

    6. If h' == h'', signature is valid.

  • Importance in Secure Communication:

    • Authentication: Proves message came from the holder of the private key.

    • Integrity: Any change in M changes h, making Sig invalid.

    • Non-repudiation: Sender cannot deny sending M (only they could have created Sig).

[!TIP] Common Pitfall: Do not confuse digital signatures (private key for signing) with encryption (public key for confidentiality). Signature = Priv_S(H(M)). Encryption = Pub_R(M).


III. SECURE COMMUNICATION PROTOCOLS & SYSTEMS

Pretty Good Privacy (PGP)

  • Working & Components:

    • Cryptographic Tools: Uses a hybrid approach.

      • Symmetric (session key): For bulk email encryption (fast, e.g., CAST-128, IDEA, AES).

      • Asymmetric (public/private keys): For encrypting the session key and digital signatures (RSA, ElGamal).

      • Hash: For signatures (SHA-1, MD5).

    • Key Management: Web of Trust (users sign each other's keys) instead of centralized CA.

  • General Format of a PGP Message:

    
    [Session Key (encrypted with receiver's public key)]
    
    [Signature (optional, of plaintext hash with sender's private key)]
    
    [Compressed/Encrypted Data (with session key)]
    
    
    DiagramPGP message structure showing the layered encryption/signing process
  • Application in Securing Email:

    1. Confidentiality: Sender generates random session key Ks. Encrypts email body with Ks (symmetric). Encrypts Ks with receiver's public key. Sends both.

    2. Authentication/Integrity: Sender hashes plaintext, signs hash with their private key. Receiver verifies signature with sender's public key.

    • Flow: M → [H(M) → Sign(Priv_S)] and M → E(Ks, M) → [Ks → Encrypt(Pub_R, Ks)].

Secure Sockets Layer / Transport Layer Security (SSL/TLS)

  • SSL Handshake Protocol (Step-by-Step):

    1. ClientHello: Client sends supported cipher suites, protocol version, random R_C.

    2. ServerHello: Server selects cipher suite, sends SSL version, random R_S, its certificate (with public key).

    3. ServerHelloDone: Server signals end of hello messages.

    4. ClientKeyExchange: Client generates premaster secret PMS, encrypts it with server's public key from cert, sends E(Pub_S, PMS).

    5. Client computes: Master Secret = H(PMS, R_C, R_S). Derives session keys (write MAC key, write encryption key).

    6. ChangeCipherSpec: Client signals subsequent messages will be encrypted.

    7. Finished: Client sends H(prev_messages + session_keys) (encrypted).

    8. Server computes: Same master secret and session keys from PMS, R_C, R_S.

    9. Server ChangeCipherSpec & Finished: Server sends its encrypted Finished message.

    • Result: Secure symmetric channel established.
  • SSL Record Protocol Services:

    • Confidentiality: Using symmetric encryption (session keys).

    • Integrity: Using MAC (e.g., HMAC) on each record.

    • Encapsulation: Wraps higher-level protocol data (like HTTP) into records.

  • SSL Connection vs. SSL Session:

    • Session: Logical association between client & server. Created during handshake. Stores security parameters (master secret, cipher suite, IDs). Can be resumed later (avoids full handshake).

    • Connection: Actual, transient communication channel. Uses session's security parameters to generate ephemeral session keys. Multiple connections can reuse one session.

IP Security (IPSec)

  • Protocols:

    • AH (Authentication Header): Provides data origin authentication, integrity, anti-replay. No encryption. Protects IP payload and selected IP header fields.

    • ESP (Encapsulating Security Payload): Provides confidentiality (encryption), data origin authentication, integrity, anti-replay. Protects IP payload (and optionally trailer).

  • Modes of Operation:

    • Transport Mode: Original IP header is preserved. AH/ESP trailer inserted after payload. Used for end-to-end (host-to-host) communication.

      • [IP Hdr] [AH/ESP] [TCP/UDP Hdr] [Data]
    • Tunnel Mode: Original IP packet is encapsulated inside a new IP packet. New outer IP header. Used for gateway-to-gateway (site-to-site VPN) or host-to-gateway.

      • [New IP Hdr] [AH/ESP] [Original IP Hdr + TCP/UDP Hdr + Data]
    • Key Difference: AH in tunnel mode protects the entire inner packet (including original IP header). In transport mode, AH cannot protect mutable header fields (like TTL, TOS).

Secure Electronic Transaction (SET)

  • Main Security Concerns in Online Transactions:

    • Confidentiality: Cardholder data (credit card number) must be secret.

    • Integrity: Transaction data must not be altered.

    • Authentication: All parties (cardholder, merchant, bank) must be authenticated.

    • Non-repudiation: Cardholder cannot deny order; merchant cannot deny receipt.

  • How SET Addresses Concerns:

    • Participants: Cardholder, Merchant, Issuer (cardholder's bank), Acquirer (merchant's bank), Payment Gateway, Certification Authority (CA).

    • Dual Signature: Cardholder creates two separate hashes: H1 = H(Order Info), H2 = H(Payment Info). Then signs H1 ⊕ H2. This links order and payment without revealing payment info to merchant or order info to bank.

    • Certificates: All parties have X.509 certificates issued by CAs.

    • Flow: Cardholder sends dual-signed message to merchant. Merchant forwards payment info (encrypted for bank) to payment gateway. Bank verifies and authorizes.

  • Application: Used in B2C e-commerce. Ensures merchant never sees full card number, bank sees only payment data.

Wireless Application Protocol (WAP) Security

  • WAP Architecture Overview:

    
    Mobile Device (WAP Client)
    
          |
    
    [WTLS (Wireless TLS)]  <--- Security layer
    
          |
    
    [WTP (Wireless Transaction Protocol)]
    
          |
    
    [WDP (Wireless Datagram Protocol)]  <--- Adapts to underlying bearer (GSM, CDMA)
    
          |
    
    [Physical Network (e.g., Cellular)]
    
    
    DiagramWAP stack showing client, WAP gateway, and web server
  • Wireless Transport Layer Security (WTLS):

    • Role: Provides confidentiality, integrity, authentication over wireless networks. Analogous to TLS but optimized for constrained devices (low bandwidth, high latency).

    • Features: Supports datagram (connectionless) mode, optional client authentication, session resumption.

  • Security Issues in WTLS:

    • Weak Cryptography: Early implementations allowed export-grade (40-bit) keys.

    • End-to-End Gap: WAP Gateway decrypts WTLS, then re-encrypts with TLS to web server. Data is in plaintext at the gateway – a major vulnerability.

    • Certificate Handling: Complex on mobile devices.

    • Protocol Vulnerabilities: Similar to early SSL/TLS flaws.

[!TIP] Exam Focus: Be able to draw and explain the PGP message format and WAP architecture. Differentiate SSL session vs. connection. Explain the dual signature in SET. For IPSec, contrast transport vs. tunnel mode for AH/ESP.


IV. NETWORK SECURITY INFRASTRUCTURE & DEVICES

Firewalls

  • Classification & Operational Differences:
Type Operational Principle Example/Use Case Merits Demerits
Packet Filtering Examines packet headers (IP, port, protocol) against ACL rules. Stateless. DROP all TCP port 23 (block Telnet). Fast, transparent, low cost. No packet content inspection. Easy to spoof IP. State manipulation attacks.
Circuit-Level Gateway Monitors TCP handshakes (SYN, SYN-ACK, ACK). Creates virtual circuit. Filters at session layer. SOCKS proxy. Hides internal network structure. Does not inspect packet contents.
Application-Level Gateway (Proxy) Deep packet inspection. Intercepts & evaluates application-layer data (e.g., HTTP commands). Acts as intermediary. Web proxy filtering URLs, SMTP proxy scanning emails. Granular control, user authentication, content filtering. Performance bottleneck. Must understand each protocol.
Stateful Inspection Tracks connection state (TCP flags, sequence numbers). Combines packet filtering with session tracking. Modern enterprise firewalls (e.g., Cisco ASA). More secure than stateless filtering. Can detect spoofing. More resource-intensive. Complex rule sets.
Personal Firewall Software on host machine. Controls inbound/outbound traffic for that host. Windows Defender Firewall. Protects mobile/remote hosts. Can be disabled by user/malware.
  • Role Against Malware: Blocks known malicious IPs/ports, prevents inbound connections to vulnerable services, can inspect for malware signatures (UTM firewalls).

Intrusion Detection Systems (IDS)

  • Definition of Intrusion: Unauthorized attempt to access, manipulate, or disable a system or network.

  • Classification:

    • Network-based IDS (NIDS): Monitors network traffic (e.g., on a DMZ segment). Sensors placed at strategic points.

      • Working: Sniffs packets, matches against signatures or baselines.

      • Components: Sensors, Management Console, Database.

      DiagramNIDS deployment showing sensors on network segments feeding into a central console
    • Host-based IDS (HIDS): Installed on individual hosts/servers. Monitors system logs, file integrity, process activity.

      • Working: Checks for unauthorized file changes (via hashes), suspicious logins, policy violations.

      • Components: Agent on host, central manager.

  • Parameter Pattern Matching (as IDS Technique):

    • Monitors parameters like login frequency, time of day, commands executed, resource usage.

    • Anomaly Detection: Establishes baseline normal profile. Flags deviations (e.g., user logging in at 3 AM for first time).

    • Misuse Detection: Matches patterns to known attack signatures (e.g., "NT AUTHENTICATE" repeated 100 times → brute-force).

  • Role Against Malware: Detects malware communication (C&C callbacks), lateral movement (scanning), data exfiltration patterns.

Malicious Software (Malware)

  • Types & Infiltration Methods:
Type Definition Infiltration/Impact
Virus Code that attaches to legitimate program/file. Requires user execution. Email attachments, infected software downloads. Corrupts/deletes files.
Worm Self-replicating, network-propagation. No host file needed. Exploits vulnerabilities (e.g., EternalBlue). Consumes bandwidth, creates botnets.
Trojan Horse Disguised as legitimate software. Contains hidden malicious function. Downloaded from untrusted sites. Provides backdoor, steals data.
Ransomware Encrypts victim's files, demands ransom for decryption key. Phishing emails, exploit kits. Denies access to data.
Spyware Secretly monitors user activity, collects data. Bundled with freeware. Steals credentials, browsing history.
Rootkit Hides existence/activity of other malware. Modifies OS kernel. Installed via exploit or trojan. Provides persistent, stealthy admin access.
Bot/Botnet Compromised host under remote control (C&C). Used for DDoS, spam, cryptojacking.
Adware Displays unwanted ads. Often bundled. Annoyance, can track behavior.
  • How IDS/Firewalls Help:

    • Firewalls: Block known malware C&C IPs/domains, prevent inbound exploits, restrict outbound traffic from infected hosts.

    • IDS: Detect malware propagation (worm scanning), C&C communication patterns, data exfiltration, policy violations (e.g., accessing banned sites).

[!TIP] Exam Focus: Draw & label NIDS architecture. Compare all firewall types in a table. For malware, know 1-2 key examples of each type and their primary propagation method.


V. WIRELESS NETWORK SECURITY

Wireless LAN (WLAN) Security

  • Security Challenges:

    • Eavesdropping: Radio signals travel beyond physical boundaries.

    • Rogue Access Points (AP): Unauthorized AP plugged into network.

    • Evil Twin: Malicious AP with same SSID as legitimate one.

    • Wireless Denial-of-Service (W-DoS): Jamming or deauthentication attacks.

    • Misconfiguration: Weak/default encryption (WEP), open networks.

    • Client Misassociation: Client connects to wrong/evil AP.

  • WLAN Protocol Stack & MPDU Format:

    • Stack: 802.11 (MAC/PHY) → LLC → Network Layer (IP).

    • MAC Protocol Data Unit (MPDU):

      
      [MAC Header] (Addr1, Addr2, Addr3, Seq Ctrl, Frame Control)
      
      [Frame Body] (payload, up to 2304 bytes)
      
      [FCS] (Frame Check Sequence, CRC-32)
      
      
      Diagram802.11 MPDU frame structure showing header fields
  • Access Point (AP) Security in Public Networks (Risks & Mitigations):

    • Risks: Man-in-the-middle (evil twin), session hijacking, captive portal bypass, malware distribution.

    • Mitigations:

      • User: Use VPN on public Wi-Fi. Verify SSID with staff. Avoid sensitive transactions.

      • Enterprise: 802.1X/EAP authentication (not pre-shared key). Wireless Intrusion Prevention System (WIPS) to detect rogue APs. Network segmentation (guest VLAN).

WAP Security Deep Dive (See also Section III)

  • WAP Architecture Security Implications: The WAP Gateway is a trusted third party that decrypts WTLS and re-encrypts with TLS. This creates a point of vulnerability where data is in plaintext.

  • WTLS Specifics and Limitations:

    • Specifics: Optimized for wireless (smaller handshake, datagram support). Uses similar cipher suites to TLS (RC5, DES, 3DES, MD5, SHA).

    • Limitations: End-to-end security gap at gateway. Early versions had weak crypto (export restrictions). Complex certificate management on mobile devices. Largely superseded by direct HTTPS over cellular data (3G/4G/5G).


VI. SPECIALIZED SECURITY ARCHITECTURES & COMPARISONS

Virtual Private Networks (VPN)

  • Definition & Core Concept: Creates a secure, encrypted "tunnel" over a public network (Internet) to connect remote users or sites to a private network.

  • Types:

    • Remote Access VPN: Individual user (telecommuter) connects to corporate network. Uses client software (e.g., Cisco AnyConnect, OpenVPN). Protocols: SSL/TLS (common), IPsec.

    • Site-to-Site VPN: Connects entire networks (e.g., branch office to HQ). Uses VPN gateways/routers. Protocols: IPsec (dominant), GRE over IPsec.

    • DiagramVPN types showing remote user <-> corporate gateway and branch office <-> HQ gateway
  • Security Architecture:

    1. Tunneling: Encapsulates original packet (with private IP) inside new packet (with public IP).

    2. Encryption: AES, 3DES, ChaCha20.

    3. Authentication: Pre-shared keys (PSK) or digital certificates (for IKE in IPsec).

    4. Integrity: HMAC (e.g., SHA-256).

Trusted Operating Systems

  • Definition & Security Architecture: OS designed with formal security models and mandatory access control (MAC). Security policy is enforced by the kernel, not by users/owners.

  • Bell-LaPadula Model (Confidentiality):

    • Simple Security Property (ss-property): "No read up." Subject can read object only if subject's clearance ≥ object's classification.

    • *-Property (Star property): "No write down." Subject can write object only if object's classification ≥ subject's clearance.

    • Discretionary Security Property: Access permissions (read/write) based on access matrix (like DAC).

  • Example: SELinux, Trusted Solaris, historically Multics.

Comparison: VPN vs. Trusted Operating Systems

Feature Virtual Private Network (VPN) Trusted Operating System
Primary Goal Secure communication over untrusted networks (confidentiality, integrity). Secure information flow within a single system (confidentiality, mandatory control).
Security Scope Network/Transport layer. Protects data in transit between endpoints. OS/Kernel layer. Protects data at rest and processes in execution on a single host.
Architecture Tunneling & Encryption. Relies on cryptographic protocols (IPsec, SSL/TLS). Mandatory Access Control (MAC). Relies on formal security model (Bell-LaPadula, Biba) enforced by kernel.
Key Mechanism Session keys, encryption algorithms, authentication (certificates/PSK). Security labels (clearance/classification), mandatory policies, reference monitor.
Use Case Remote worker accessing corporate files; connecting branch offices. Military/intelligence systems, high-assurance servers, systems processing classified data.
Trust Anchor Cryptographic keys and CAs. The verified, secure kernel (TCB - Trusted Computing Base).

Web Traffic Security Approaches

  • Overview of Methods:

    1. SSL/TLS (HTTPS): De facto standard. Secures HTTP at transport layer. Provides server authentication (certificates), optional client auth, encryption, integrity. Used by browsers.

    2. IPsec (Tunnel Mode): Can secure all IP traffic between gateways. Transparent to applications. Used for site-to-site VPNs.

    3. PGP/S/MIME: Secures the email message itself (end-to-end), independent of transport. Provides non-repudiation.

    4. SSH (Secure Shell): Secures remote login and file transfer (SFTP). Replaces insecure Telnet/FTP.

  • Selection Criteria:

    • Need for end-to-end vs. hop-by-hop? PGP (end-to-end), TLS (hop-by-hop between client & server).

    • Application layer vs. network layer? TLS (app layer), IPsec (network layer).

    • Performance & overhead? TLS lighter than IPsec for web.

    • Non-repudiation required? Use digital signatures (PGP/S/MIME).

[!TIP] Final Exam Checklist: You must be able to:

  1. Draw & explain PGP message format, WAP architecture, NIDS, IPSec modes.
  1. Perform calculations for Caesar, RC4 (small key), RSA (small primes), AES (conceptual steps).
  1. Compare & contrast (in tables): Block vs. Stream ciphers, Firewall types, IDS types, VPN vs. Trusted OS, SSL session vs. connection, AH vs. ESP.
  1. Explain step-by-step: SSL Handshake, HMAC construction, SET dual signature, RSA key gen/enc/dec.
  1. Define & list properties: Hash functions, MACs, Biometrics challenges, Malware types.
  1. Describe working: RC4, AES rounds, SHA-512 compression, Bell-LaPadula rules.
Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in