Skip to content
CY-702 (B) · Block Chain & Crypto-Currencies/Quick Revision Short Notes

Block Chain & Crypto-Currencies (CY-702 (B)) - Unit 4 Short Notes

I. PENETRATION TESTING FUNDAMENTALS

Penetration Testing (Pen-Test) is a authorized simulated cyber-attack on a system to evaluate its security. Key aspects include:

  • Legal & Ethical Considerations:

    • Authorization: Written consent (Rules of Engagement) is mandatory to avoid legal violations (e.g., CFAA, GDPR).

    • Scope Definition: Clear boundaries (systems, methods, timing) prevent unintended disruption.

    • Confidentiality: Test results must be protected; disclosure only to stakeholders.

    • Liability: Contractual clauses shield testers from damages during authorized tests.

  • Reconnaissance Phase:

    • DNS Reconnaissance: Enumerating DNS records (A, MX, TXT) via tools (dig, nslookup) or zone transfers to map attack surface.

    • External Information Gathering: OSINT techniques (search engines, social media, Shodan) to collect employee names, tech stack, and infrastructure details pre-engagement.

  • Target Architecture Analysis:

    • Understanding system architecture (network topology, OS, applications, dependencies) is critical to identify vulnerabilities and avoid unintended failures (e.g., crashing legacy systems).
  • Methodologies & Frameworks:

    • PTES (Penetration Testing Execution Standard): Phases—pre-engagement, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, reporting.

    • NIST SP 800-115: Technical guide for security testing.

    • OWASP Testing Guide: Focus on web applications.

  • Vulnerability Scanning Tools:

    • Network: Nmap (port scanning), Nessus, OpenVAS.

    • Application: Burp Suite, OWASP ZAP.

    • Role: Automated identification of known vulnerabilities; must be validated to avoid false positives.

  • Capture The Flag (CTF):

    • Simulates real-world scenarios with challenges (binary exploitation, web hacking, crypto).

    • Develops practical skills under time pressure; mirrors incident response and adversarial thinking.

[!TIP]

Common Pitfall: Skipping architecture analysis leads to ineffective exploits or system damage. Always map the environment first.


II. WEB APPLICATION SECURITY

  • HTTP Strict Transport Security (HSTS):

    • Purpose: Forces browsers to use HTTPS only, preventing SSL-stripping and protocol downgrade attacks.

    • Implementation: Server sends header Strict-Transport-Security: max-age=31536000; includeSubDomains.

    • Impact: Once a browser receives HSTS, all future requests to the domain use HTTPS automatically.

  • SQL Injection:

    • Primary Risk: Unauthorized access to, modification, or deletion of database contents. Can lead to data breaches, authentication bypass, or full system compromise.

    • Impact: Confidentiality, integrity, and availability loss; regulatory fines (GDPR, PCI-DSS).

    • Mitigation: Prepared statements, parameterized queries, input validation, ORM frameworks.

  • Web Application Penetration Testing Methodologies:

    • OWASP-based: Follow OWASP Top 10 (2021) as a checklist—Injection, Broken Authentication, Sensitive Data Exposure, etc.

    • Phases: Mapping (spidering), Analysis (vulnerability scanning), Exploitation (manual testing), Post-Exploitation, Reporting.

[!TIP]

Exam Focus: HSTS prevents man-in-the-middle attacks; SQL injection exploits unsanitized user input in database queries.


III. WIRELESS AND SOCIAL ENGINEERING SECURITY

  • Packet Sniffing in Wireless Pen-Testing:

    • Significance: Captures wireless traffic to analyze protocols (WEP, WPA2), detect rogue access points, and extract credentials.

    • Techniques: Monitor mode (airmon-ng), capturing with Wireshark/tcpdump, deauthentication attacks to force handshakes for WPA2 cracking.

  • Social Engineering Tactics Targeting Wireless:

    1. Rogue Access Points: Evil twin attacks mimicking legitimate Wi-Fi.

    2. Phishing via Wi-Fi: Fake captive portals stealing credentials.

    3. Physical Tailgating: Following employees into secure areas to plug in wireless devices.

  • Employee Training Programs:

    • Role: Build security awareness to recognize phishing, suspicious Wi-Fi networks, and social manipulation.

    • Mitigation: Regular simulated phishing tests, workshops on secure Wi-Fi usage, and reporting procedures.

[!TIP]

Key Point: Wireless pen-testing often combines technical sniffing with social engineering (e.g., tricking staff into connecting to a fake AP).


IV. CRYPTOGRAPHY AND SECURE COMMUNICATION

  • RSA Algorithm for Secure Communication:

    • Key Generation:

      1. Choose large primes $p$, $q$.

      2. Compute $$\displaystyle n = p \times q $$, $$\displaystyle \phi(n) = (p-1)(q-1) $$.

      3. Select public exponent $e$ such that $$\displaystyle 1 < e < \phi(n) $$ and $$\displaystyle \gcd(e, \phi(n)) = 1 $$.

      4. Compute private exponent $$\displaystyle d \equiv e^{-1} \pmod{\phi(n)} $$.

      \n\n

      Public Key: $(e, n)$; Private Key: $(d, n)$.

    • Encryption: $$\displaystyle c = m^e \mod n $$ (using public key).

    • Decryption: $$\displaystyle m = c^d \mod n $$ (using private key).

    • Digital Signatures: $$\displaystyle s = m^d \mod n $$ (sign with private); verify $$\displaystyle m' = s^e \mod n $$ (public).

    \n\n

    \boxed{c = m^e \mod n \quad ; \quad m = c^d \mod n \quad ; \quad s = m^d \mod n}

  • Decryption Considerations:

    • Private key security (hardware security modules, secure storage).

    • Padding Schemes (PKCS#1 v2.2/OAEP) to prevent chosen-ciphertext attacks.

    • Performance: RSA is slow; often used to encrypt symmetric keys (hybrid encryption).

  • Cryptography Audit Documentation:

    • Scope and objectives.

    • Algorithms and key lengths used.

    • Key management lifecycle (generation, storage, rotation, destruction).

    • Compliance with standards (FIPS 140-2, PCI-DSS).

    • Findings and risk assessment.

  • Stakeholder Engagement:

    • Ensures cryptographic measures align with business goals, compliance requirements, and user experience.

    • Involves management (budget), IT (implementation), legal (regulatory), and end-users (training).

[!TIP]

RSA Security: Relies on difficulty of factoring large $n$. Always use OAEP padding for encryption; PSS for signatures.


V. CLOUD SECURITY

  • Challenges:

    • Shared Responsibility Model: Misunderstandings between provider and user security duties.

    • Data Breaches: Multi-tenancy risks, misconfigured storage (S3 buckets).

    • APTs & Insider Threats: Difficulty in monitoring distributed environments.

    • Compliance: Meeting GDPR, HIPAA across jurisdictions.

    • Account Hijacking: Weak credentials, lack of MFA.

  • Security Models:

    • IaaS: User secures OS, apps, data; provider secures physical infrastructure.

    • PaaS: Provider manages runtime, middleware; user secures apps and data.

    • SaaS: Provider secures everything except user data and access.

  • Best Practices:

    • Encryption: Data-at-rest (AES-256) and in-transit (TLS 1.3).

    • Identity & Access Management (IAM): Least privilege, MFA, role-based access.

    • Zero Trust: "Never trust, always verify" across network segments.

    • Monitoring & Logging: Cloud-native tools (AWS CloudTrail, Azure Monitor) for anomaly detection.

    • Regular Audits: Configuration scans (CIS Benchmarks), penetration testing.

[!TIP]

Key Concept: In cloud, security is a shared responsibility—users often overestimate provider security.


VI. MULTIMEDIA SECURITY

  • Compression & DCT:

    • Discrete Cosine Transform (DCT): Converts spatial image data to frequency domain. High-frequency components (details) are quantized aggressively.

    • Lossy Compression: Discards perceptually less important data (e.g., JPEG, MP3). Trade-off: smaller size vs. quality loss; irreversible.

  • Quality of Service (QoS) in Delivery:

    • Resource Management Strategies:

      • Bandwidth Allocation: Prioritize real-time streams (VoIP, video).

      • Buffering & Jitter Control: Smooth playback, reduce delay variation.

      • Adaptive Bitrate Streaming: Adjust quality based on network (DASH, HLS).

    • Factors Affecting QoS:

      | Factor | Impact | |--------|--------| | Bandwidth | Insufficient bandwidth causes buffering, low resolution. | | Latency | Delay in data arrival; critical for live interaction. | | Jitter | Variation in packet arrival; causes audio/video glitches. | | Packet Loss | Missing data; visible as artifacts or audio dropouts. |

  • OS Layers for Hardware Resource Management:

    • Kernel: Schedules CPU time for multimedia processes.

    • Device Drivers: Interface with sound cards, GPUs for low-latency access.

    • Middleware: Provides APIs (DirectShow, GStreamer) for application-level resource handling.

  • Security Attacks:

    • Passive: Eavesdropping on streams, traffic analysis.

    • Active: Tampering (content alteration), injection (malicious streams), DoS (flooding).

  • Multimedia Authentication & Integrity:

    • Mechanisms: Digital signatures (hash of content + private key), watermarking, robust hashing (perceptual hashes for images/audio).

    • Importance: Verifies source, detects tampering, ensures content hasn’t been altered (e.g., deepfakes, forged videos).

  • Watermarking Strategies:

    • Visible: Overlaid logo/text; deters casual theft but reduces aesthetic value.

    • Invisible: Embedded in data; robust (survives compression) or fragile (breaks on edit).

    • Use-Case Decisions:

      | Scenario | Watermark Type | Reasoning | |----------|----------------|------------| | Professional Portfolio | Visible | Promotes brand; acceptable aesthetic trade-off. | | Stock Photography | Invisible Robust | Protects copyright without impairing salability; survives format changes. | | Client Previews | Invisible Fragile | Detects unauthorized use; breaks if edited, proving tampering. |

[!TIP]

QoS Focus: For live video, latency and jitter are more critical than bandwidth. Use RTP/RTCP for real-time monitoring.


VII. DIGITAL FORENSICS

  • Digital Evidence Extraction:

    • Process Steps:

      1. Identification: Recognize potential evidence sources (devices, files).

      2. Preservation: Create bit-for-bit forensic image (e.g., using dd, FTK Imager); hash (SHA-256) to verify integrity.

      3. Collection: Seize media with chain of custody documentation.

      4. Examination: Analyze image with tools (Autopsy, EnCase) for artifacts.

      5. Analysis: Interpret data (timeline, user activity).

      6. Presentation: Report findings for legal/adjudicative purposes.

    • Tools: Volatility (memory), Wireshark (network), ExifTool (metadata).

  • Metadata Significance:

    • Authentication: EXIF data (camera model, timestamps), IPTC (copyright), file system metadata (creation/modification times).

    • Analysis: Reveals editing history (software used), geolocation, device fingerprints. Critical for establishing provenance and detecting tampering.

  • Printer & Scanner Forensics:

    • Role: Identifies specific devices from output artifacts (e.g., printer steganography—dot patterns, banding, toner distribution).

    • Case Study: Check-21 Act (U.S.)—examines check fraud by linking printed checks to specific printers via printer identification codes (microscopic dots encoding serial numbers).

  • Audio Recording Authentication:

    • Techniques:

      • Spectrogram Analysis: Visual inspection for edits, noise inconsistencies.

      • Noise Floor Examination: Background noise should be continuous; abrupt changes indicate splicing.

      • Metadata Check: Verify recording device, timestamps.

      • Chain of Custody: Document handling from seizure to analysis.

      • Expert Witness Testimony: Explain methods in court.

  • Need for Computer Forensics in Incident Response:

    • Determines scope of breach, attribution (attack vectors, malware), evidence for legal action, and recovery steps. Essential for post-incident analysis and improving defenses.
  • Forensic Protocols & Standards:

    • ACPO Guidelines (UK): Principles—no alteration, competency, audit trail, integrity.

    • ISO/IEC 27037: Guidelines for identification, collection, acquisition of digital evidence.

    • Chain of Custody: Continuous documentation of evidence handlers, timestamps, and storage conditions to prevent tampering claims.

  • Multimedia Content Forensics:

    • Tamper Detection:

      • Error Level Analysis (ELA): JPEG compression inconsistencies reveal edits.

      • JPEG Ghosts: Double compression artifacts.

      • Noise Inconsistency: Different noise patterns in regions.

    • Source Identification: Camera model fingerprint (sensor pattern noise), device calibration artifacts.

[!TIP]

Critical Rule: Always hash evidence before and after acquisition. Metadata can be easily altered; corroborate with content-level analysis.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in