Skip to content
CY-702 (B) · Block Chain & Crypto-Currencies/Quick Revision Short Notes

Block Chain & Crypto-Currencies (CY-702 (B)) - Unit 3 Short Notes

UNIT 3: BLOCKCHAIN SECURITY, CRYPTOGRAPHY & FORENSICS

I. FOUNDATIONS OF SECURITY ASSESSMENT & ETHICS

Legal and Ethical Considerations in Penetration Testing

  • Definition: The framework governing authorized simulated attacks on systems to identify vulnerabilities.

  • Impact on Organizational Decision-Making:

    • Risk vs. Reward: Legal/ethical constraints define test scope, balancing security improvement against potential business disruption, reputational damage, or contractual breaches.

    • Authorization: Formal, written consent (Get Out of Jail Free card) is mandatory. Unauthorized testing is illegal.

    • Liability: Clear agreements on data handling, downtime, and incident response during testing protect both tester and organization.

  • Compliance & Regulatory Frameworks:

    • Standards: PCI-DSS, HIPAA, GDPR, ISO 27001 often mandate regular security testing.

    • Reporting: Findings must be documented to demonstrate due diligence and compliance.

[!TIP] Exam Focus: Always link legal/ethical considerations to organizational risk management. Unethical testing destroys trust and incurs legal penalties, negating any security benefit.

Types of Penetration Testing

Type Primary Use Case Key Considerations
Network Penetration Testing Assessing external/internal network infrastructure (firewalls, routers, servers). Focus on network segmentation, firewall rules, service misconfigurations, and lateral movement.
Application Penetration Testing Assessing web/mobile apps for flaws (logic, code, data handling). Deep dive into OWASP Top 10 (e.g., SQLi, XSS), API security, session management, and business logic flaws.

Penetration Testing Methodologies

  • Structured Approach for Web Apps (e.g., OWASP Testing Guide):

    1. Information Gathering (Reconnaissance)

    2. Configuration & Deployment Management Testing

    3. Identity Management Testing

    4. Authentication Testing

    5. Authorization Testing

    6. Session Management Testing

    7. Input Validation Testing (SQLi, XSS, etc.)

    8. Business Logic Testing

    9. Client-Side Testing

    10. Reporting

Vulnerability Scanning Tools

  • Categories & Applications:

    • Network Scanners: Nmap – Port/service discovery, OS fingerprinting.

    • Web App Scanners: Burp Suite, OWASP ZAP – Automated crawling, vulnerability detection (SQLi, XSS).

    • Configuration Scanners: Nessus, OpenVAS – Comprehensive vulnerability assessment across systems.

  • Limitations:

    • False Positives/Negatives: Automated tools require manual verification.

    • Context Blind: Cannot understand business logic flaws.

    • Coverage: May miss custom or complex vulnerabilities.

Capture the Flag (CTF) Competitions

  • Purpose: Simulate real-world cybersecurity scenarios in a controlled, competitive environment.

  • How They Simulate Reality:

    • Diverse Challenges: Reverse engineering, forensics, web exploitation, crypto, steganography.

    • Time Pressure: Mimics incident response constraints.

    • Skill Application: Forces use of multiple tools and creative thinking, similar to red teaming.

    • Learning Platform: Safe environment to practice offensive/defensive techniques.

[!TIP] Common Pitfall: CTFs are skill-building exercises, not direct replacements for professional, scoped penetration tests. They often lack the business context and legal boundaries of real engagements.

II. RECONNAISSANCE & INFORMATION GATHERING

DNS Reconnaissance

  • Purpose: To map an organization's external digital footprint, identify target systems, and enumerate potential attack surfaces.

  • Techniques for Mapping External Presence:

    • Zone Transfer (AXFR): Attempt to retrieve entire DNS zone file (misconfiguration).

    • DNS Enumeration: dig, nslookup, dnsrecon to find subdomains, MX records, TXT records.

    • Reverse DNS Lookups: Map IP addresses to hostnames.

    • Search Engine Discovery (Google Dorking): site:target.com, intitle:"index of".

    • Certificate Transparency Logs: Find subdomains via SSL/TLS certificates.

Target System Architecture Analysis

  • Importance Before Exploitation: Prevents wasted effort, identifies high-value targets, and helps chain vulnerabilities. Understanding layers (network, OS, app, data) is crucial for effective attack planning.

  • Components & Layers to Evaluate:

    • Network Topology: Firewalls, DMZs, segmentation.

    • Operating System: Version, patch level, running services, configuration.

    • Application Stack: Frameworks, languages, libraries, versions.

    • Data Flow: How data moves between components; where is it validated/stored?

    • Authentication & Authorization Mechanisms: SSO, RBAC, session handling.

[!TIP] Exam Answer Hook: "Thorough architecture analysis allows a penetration tester to identify the critical path to sensitive data, prioritize attacks on high-impact components, and avoid triggering unnecessary alerts on low-value systems."

III. EXPLOITATION & VULNERABILITY MANAGEMENT

Web Application Vulnerabilities

SQL Injection (SQLi)

  • Primary Risk: Unauthorized access to, modification of, or deletion of backend database contents.

  • Impact:

    • Data Breach: Theft of sensitive data (PII, credentials, financial records).

    • Data Loss/Corruption: DROP TABLE, DELETE commands.

    • Authentication Bypass: Log in as admin without password.

    • Remote Code Execution (in some DBs): Execute OS commands.

HTTP Strict Transport Security (HSTS)

  • Importance: Forces browsers to interact with a website only over HTTPS, preventing Man-in-the-Middle (MitM) protocol downgrade attacks.

  • Implementation: Server sends header Strict-Transport-Security: max-age=<seconds>; includeSubDomains.

  • Why Crucial: Stops attackers from stripping HTTPS or using SSL-stripping tools to intercept traffic.

System and Network Exploitation Principles

  • Role of Architecture Understanding: The architecture reveals trust boundaries, data validation points, and privilege escalation paths. Exploitation success depends on finding a weakness in one layer (e.g., a vulnerable service) that can be leveraged to compromise the next layer (e.g., OS, then database).

IV. WIRELESS & SOCIAL ENGINEERING SECURITY

Wireless Penetration Testing

Packet Sniffing

  • Importance: Fundamental for passive reconnaissance and active attack execution.

  • Techniques:

    • Monitor Mode: Capture all wireless traffic in range (e.g., airodump-ng).

    • Analysis: Identify SSIDs, client MACs, encryption types (WEP/WPA2), and capture handshakes for offline cracking.

    • Active Attacks: Inject packets, deauthenticate clients to force handshake capture.

Social Engineering Attacks (Targeting Wireless)

  1. Evil Twin Attack: Rogue AP mimicking legitimate SSID to steal credentials.

  2. Wi-Fi Phishing: "Captive Portal" mimics corporate login page to harvest credentials.

  3. Physical Tailgating/Piggybacking: Gaining physical access to deploy malicious devices or observe network credentials.

Human Factor Mitigation

  • Employee Training Programs:

    • Awareness: Teach recognition of phishing, pretexting, and baiting.

    • Simulated Attacks: Regular, authorized phishing campaigns to test and train staff.

    • Policy & Procedure: Clear guidelines for verifying identities, reporting suspicious activity, and secure wireless usage (e.g., "never connect to unknown Wi-Fi").

    • Culture: Foster a security-first mindset where employees feel responsible and empowered to question anomalies.

V. CRYPTOGRAPHY & SECURE COMMUNICATION

RSA Algorithm (for Secure Communication)

Goal: Asymmetric encryption for confidentiality (encryption) and digital signatures (authenticity/integrity).

1. Key Generation:

  • Choose two large primes: $p, q$.

  • Compute modulus: $$\displaystyle n = p \times q $$.

  • Compute totient: $$\displaystyle \phi(n) = (p-1)(q-1) $$.

  • Choose public exponent $e$ such that $$\displaystyle 1 < e < \phi(n) $$ and $$\displaystyle gcd(e, \phi(n)) = 1 $$.

  • Compute private exponent $d$ such that $$\displaystyle d \equiv e^{-1} \pmod{\phi(n)} $$.

  • Public Key: $(e, n)$. Private Key: $(d, n)$.

2. Encryption (Confidentiality):

  • Sender obtains receiver's public key $(e, n)$.

  • Plaintext message $M$ is converted to integer $$\displaystyle m < n $$.

  • Ciphertext: $$\displaystyle c = m^e \bmod n $$.

3. Decryption:

  • Receiver uses private key $(d, n)$.

  • Recover message: $$\displaystyle m = c^d \bmod n $$.

  • Convert $m$ back to plaintext $M$.

4. Digital Signature (Authentication & Integrity):

  • Sender hashes message: $H(M)$.

  • Sender encrypts hash with their private key: $$\displaystyle S = H(M)^d \bmod n $$ (signature).

  • Receiver decrypts signature with sender's public key: $$\displaystyle H' = S^e \bmod n $$.

  • Receiver hashes received message independently. If $$\displaystyle H' = H(M) $$, signature is valid.

[!TIP] Critical Formula: The core relationship is $$\displaystyle m^{ed} \equiv m \pmod{n} $$. This underpins both encryption/decryption and signature verification.

Decryption Concepts

  • Principle: The process of converting ciphertext back into readable plaintext using a secret key (symmetric) or private key (asymmetric).

  • Scenarios:

    • Secure Communication: Recipient decrypts received encrypted message.

    • Data at Rest: Decrypting a stored encrypted file or database field.

    • Digital Signatures: Verifying a signature by "decrypting" it with the signer's public key to reveal the hash.

    • Blockchain Context: Decrypting a transaction payload intended for a specific recipient (e.g., in private/confidential transactions).

Cryptography Audit

Key Elements for Documentation Report

  1. Scope & Objectives: What systems, algorithms, and key management processes were audited?

  2. Algorithm & Protocol Assessment: Strength of ciphers (AES-256 vs. DES), key lengths, protocol versions (TLS 1.2 vs. 1.3).

  3. Key Management Lifecycle: Generation, storage, distribution, rotation, and destruction procedures. Security of Hardware Security Modules (HSMs).

  4. Implementation Review: Code review for side-channel vulnerabilities, proper use of cryptographic libraries (avoid "roll-your-own").

  5. Compliance Check: Alignment with standards (FIPS 140-2/3, NIST guidelines).

  6. Findings & Risk Rating: Clear list of weaknesses (e.g., weak keys, improper IV usage) with CVSS scores.

  7. Remediation Roadmap: Prioritized, actionable recommendations.

Stakeholder Engagement in Implementation

  • Why Crucial: Cryptography is a business enabler, not just a technical control.

  • Engagement Points:

    • Management: Explain risk reduction, compliance benefits, and cost of failure (data breach).

    • Developers/Engineers: Provide clear, implementable specifications and training on secure crypto libraries.

    • Legal/Compliance: Ensure chosen algorithms meet regulatory requirements for data protection.

    • End-Users: Communicate changes (e.g., longer key rotation periods) that might affect usability.

  • Outcome: Ensures cryptographic measures are adopted correctly, maintained, and aligned with business goals, preventing a perfect technical solution that fails in practice.

Cryptographic Measures in Broader Systems (Integration)

  • Considerations:

    • Performance Overhead: Encryption/decryption adds latency; balance security with performance (e.g., in high-frequency trading blockchains).

    • Key Distribution Problem: How are public keys exchanged and verified? (PKI, Web of Trust, blockchain-based DIDs).

    • Interoperability: Systems must agree on algorithms, formats (e.g., PEM, DER), and protocols.

    • Legacy System Compatibility: Integrating modern crypto with old systems can force weak cipher suites.

    • Cryptographic Agility: Design systems to easily upgrade/swap algorithms if one is broken (e.g., quantum threat to RSA/ECC).

VI. CLOUD & SPECIALIZED SECURITY CONTEXTS

Cloud Security (Penetration Testing & Cryptography)

  • Unique Considerations for Pen Testing:

    • Shared Responsibility Model: Tester must know what is provider's vs. tenant's responsibility (e.g., AWS secures hypervisor, tenant secures S3 buckets).

    • Authorization: Mandatory written permission from both cloud provider and tenant. Providers have strict "acceptable use" policies.

    • Tooling: Cloud-native tools (AWS Inspector, Azure Security Center) and traditional tools adapted for virtual environments.

    • Targets: Misconfigured storage buckets (S3), insecure IAM policies, exposed management consoles, cloud service APIs.

  • Cryptography Considerations:

    • Provider-Managed Keys vs. Customer-Managed Keys (CMK): Who controls the keys? (e.g., AWS KMS).

    • Data Residency & Sovereignty: Where is encrypted data stored/processed?

    • Encryption in Transit/At Rest: Default encryption offered, but tenant must configure correctly.

    • Key Management Complexity: Centralized vs. distributed key management across multi-cloud.

Case Study Analysis: Defining Objectives for rgpvonline.com

  • Primary Objectives (Example):

    1. Identify Critical Vulnerabilities: Find SQLi, XSS, RCE in web application that could compromise student/faculty data.

    2. Assess Authentication Mechanisms: Test for credential stuffing, session fixation, MFA bypass.

    3. Evaluate Information Disclosure: Check for server banners, directory listings, error messages revealing system details.

    4. Test for Misconfigurations: Insecure direct object references (IDOR), backup files exposed, administrative interfaces.

    5. Review API Security (if applicable): Test endpoints for lack of rate limiting, improper authentication.

    6. Social Engineering Simulation (Phishing): Test staff/student awareness targeting the university domain.

    7. Compliance Check: Assess alignment with educational data protection norms (potentially similar to FERPA concepts).

  • Scope Definition: Must explicitly state in-scope URLs (*.rgpvonline.com), excluded systems (e.g., third-party payment gateways), and testing constraints (no DoS, no data alteration beyond proof-of-concept).

VII. MULTIMEDIA SECURITY & DIGITAL FORENSICS

A. Multimedia Systems & Compression

Discrete Cosine Transform (DCT)

  • Role in Compression: Core mathematical transform in JPEG (image) and MPEG (video). Converts spatial pixel data into frequency domain.

  • Why Lossy? Human vision is less sensitive to high-frequency details. DCT allows:

    1. Quantization: Rounding high-frequency coefficients to zero (discarding "less important" info).

    2. Efficient entropy coding (Huffman) of the quantized coefficients.

    • Result: Significant size reduction with perceptually minimal quality loss.

Quality of Service (QoS) in Multimedia

  • Resource Management Factors:

    • Bandwidth: Available network throughput.

    • Latency/Jitter: Delay and variation in packet arrival (critical for real-time audio/video).

    • Packet Loss: Lost packets cause glitches/artifacts.

    • CPU/Memory: For encoding/decoding on client/server.

  • Delivery Challenges & Solutions:

    • Challenge: Network congestion → Solution: Adaptive Bitrate Streaming (DASH, HLS), buffering.

    • Challenge: Variable device capabilities → Solution: Transcoding to multiple resolutions/bitrates.

    • Challenge: Unreliable protocols (UDP) → Solution: Forward Error Correction (FEC), retransmission strategies.

Interdisciplinary Industry Mergers

  • Examples & Implications:

    • Telecom + Media: Telecom companies (AT&T, Verizon) acquiring content providers (Time Warner) → Convergence of network delivery and content creation. Security Implication: Larger attack surface (network + content).

    • Hardware + Software + Content: Apple (hardware/OS) + Beats (audio hardware/content) + Apple TV+ → End-to-end ecosystem. Implication: Security must be integrated across all layers.

    • Gaming + Social Media + Streaming: Platforms like Twitch (gaming + live streaming + chat). Implication: Complex user-generated content moderation and real-time interaction security.

B. Security Attacks & Authentication

Active vs. Passive Security Attacks (Multimedia Systems)

Feature Passive Attack Active Attack
Goal Eavesdrop, monitor, analyze traffic. Modify, inject, delete, or disrupt data/streams.
Detection Very difficult; no trace in data stream. Easier to detect; corrupts data or causes DoS.
Examples Packet sniffing of unencrypted video stream. Replay attack on VoIP, video injection, DoS on streaming server.
Countermeasures Encryption (TLS, SRTP). Authentication, integrity checks (HMAC), timestamps, sequence numbers.

Multimedia Authentication

  • Mechanisms for Integrity Verification:

    • Digital Watermarking (Robust/Fragile): Embed data to prove origin/tamper.

    • Digital Signatures: Sign hash of multimedia file with private key.

    • Perceptual Hashing: Generate a fingerprint (hash) of the content; similar content yields similar hashes (used for copyright detection).

  • Importance: Proves content authenticity (not fake), provenance (source), and integrity (not altered). Critical for news footage, legal evidence, digital rights management.

C. Watermarking Techniques

  • Visible Watermark: Overlay (logo, text) directly visible on image/video.

  • Invisible (Robust/Fragile) Watermark: Data embedded imperceptibly within the media's data (e.g., in DCT coefficients, pixel LSBs).

Scenario-Based Decision Factors:

Scenario Recommended Type Reasoning & Influencing Factors
Professional Portfolio Website Visible Primary Goal: Protect copyright while showcasing work. Visible watermark deters direct theft, asserts ownership, and can be a branding element. Factor: Deterrence & Branding outweighs aesthetic purity.
Stock Photography Platform (for sale) Invisible (Robust) Primary Goal: Track unauthorized use, prove ownership in court. Must survive cropping, compression, format conversion. Factor: Forensic traceability & legal admissibility are paramount. Visible watermark would degrade salability.
Client Preview Images (low-res) Visible Primary Goal: Prevent client from using preview as final product. Visible watermark clearly marks as "PROOF" or "PREVIEW". Factor: Clear communication & immediate deterrence for low-value, low-resolution deliverables.

D. Digital Forensics & Evidence Handling

Digital Evidence Extraction

  • Steps:

    1. Identification: Recognize potential evidence (device, file, metadata).

    2. Preservation: Create forensic image (bit-for-bit copy) using write-blockers. Hash (MD5/SHA-1) original and image for integrity.

    3. Examination: Analyze image using tools ( autopsy, FTK, Wireshark). Timeline analysis, file carving, keyword search.

    4. Analysis: Interpret findings, correlate events, establish narrative.

    5. Presentation: Document chain of custody, tools used, findings in a report for court.

  • Tools: dd, FTK Imager, Autopsy, Wireshark, Volatility (memory analysis), exiftool (metadata).

Metadata in Forensics

  • Significance: "Data about data" (EXIF, IPTC, XMP for images; ID3 for audio).

  • Assists in:

    • Authentication: Camera model, software, creation/modification timestamps.

    • Analysis: GPS location (from photos), device serial number, editing history.

    • Timeline Construction: CreateDate, ModifyDate establish when an event occurred.

    • Source Identification: Link media to a specific device or software.

Printer and Scanner Forensics

  • Role in Risk Identification & Mitigation:

    • Identification: Unique printer steganography (yellow dot patterns) can identify the specific printer model and sometimes serial number that produced a document.

    • Authentication: Detect forged documents by analyzing dot patterns inconsistent with claimed printer.

    • Source Tracking: Trace leaked confidential documents back to a specific office printer.

  • Case Study Illustration:

    • Scenario: A confidential memo is leaked to the press.

    • Process: Forensic examiner uses a microscope and image analysis software to detect and decode the manufacturer's tracking dots embedded in the printed page.

    • Outcome: The pattern reveals the document was printed on a specific model of HP LaserJet in the company's Delhi office on a specific date/time (from dot pattern encoding). This narrows the suspect pool to individuals with access to that printer on that day, leading to the identification of the insider threat.

Audio Recording Authentication

  • Methods for Legal Validation:

    1. Metadata Analysis: Check creation software, device ID, timestamps for consistency.

    2. Spectrogram Analysis: Visualize audio frequencies. Look for edits (splices, cuts), noise pattern inconsistencies, or artifacts from compression.

    3. Waveform Analysis: Check for abrupt starts/ends, level mismatches indicating splicing.

    4. Contextual Corroboration: Compare audio content with known facts, witness statements, other evidence.

    5. Expert Witness Testimony: Forensic audio expert presents findings on likelihood of tampering.

E. Forensic Foundations & Protocols

The Need for Computer Forensics (in Multimedia Context)

  • Broader Context: Multimedia files (images, video, audio) are increasingly central to cybercrime (extortion videos, child exploitation material, deepfakes), intellectual property theft, and civil litigation.

  • Need: To collect, preserve, analyze, and present digital multimedia evidence in a legally admissible manner. Ensures chain of custody, integrity, and scientific validity of findings.

Protocols in Multimedia Forensics

  • Standards & Procedures:

    • ISO/IEC 27037: Guidelines for identification, collection, acquisition of digital evidence.

    • NIST SP 800-101: Guidelines for mobile device forensics.

    • SWGDE (Scientific Working Group on Digital Evidence): Best practices for digital evidence examination.

    • Chain of Custody: Documented, unbroken record of evidence handling from seizure to presentation.

    • Forensic Soundness: Use of validated tools, write-blockers, hashing to prove evidence has not been altered.

Multimedia Content Forensics

  • Techniques for Authenticity & Tamper Detection:

    • Source Identification: Identify camera/model used via sensor pattern noise (PRNU), lens distortion, color filter array (CFA) interpolation.

    • Tamper Detection:

      • Error Level Analysis (ELA): JPEG re-save artifacts reveal edited areas.

      • Copy-Move Detection: Find duplicated regions within an image (cloning).

      • Splicing Detection: Inconsistencies in lighting, shadows, perspective, noise patterns across the image.

      • Video Frame Consistency: Check for frame duplication, insertion, or dropping.

    • Deepfake Detection: Analyze facial artifacts, blinking patterns, head pose inconsistencies, or use AI-based detectors.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in