UNIT 1: Foundations of Security Testing, Cryptography, and Multimedia Forensics
1.0 Foundations of Security Testing and Forensics
1.1 Legal and Ethical Considerations in Security Assessments
-
Impact on Organizational Decision-Making:
-
Authorization: Formal, written consent (Rules of Engagement) is mandatory. Unauthorized testing is illegal (Computer Fraud and Abuse Act, IT Act).
-
Scope Definition: Legally binding document defining targets, methods, timing, and exclusions. Prevents "scope creep" and unintended disruption.
-
Liability & Insurance: Organizations must assess legal liability for potential service disruption or data exposure during testing. Insurance policies may require specific testing protocols.
-
Compliance Frameworks: Testing must align with regulatory requirements (GDPR, HIPAA, PCI-DSS). Findings often serve as evidence for compliance audits.
-
Ethical Boundaries: Testers must adhere to ethical codes (e.g., (ISC)² Code of Ethics). Actions must be proportional, minimize damage, and protect client data confidentiality.
-
-
[!TIP] Exam Focus: Always link legal/ethical points to organizational risk (financial, reputational, legal) and decision-making (to test or not, budget allocation, vendor selection).
1.2 Reconnaissance and Information Gathering
-
DNS Reconnaissance:
-
Purpose: To map an organization's digital footprint, identify hosts, subdomains, network ranges, and technology stack.
-
Techniques:
-
Zone Transfer (AXFR): Attempt unauthorized transfer of DNS zone file (misconfiguration).
-
Enumeration: Querying for common records (A, AAAA, MX, TXT, SRV).
-
Subdomain Enumeration: Using brute-force, wordlists, search engines, and certificate transparency logs.
-
Reverse DNS Lookups: Mapping IP addresses to hostnames.
-
-
-
External Presence Data Gathering (Pre-engagement):
-
Sources: Search engines (Google Dorks), social media (LinkedIn, Twitter), job postings (tech stack clues), public code repositories (GitHub), historical DNS records, and WHOIS databases.
-
Importance: Builds an attack surface map without touching the target network. Identifies potential entry points (exposed admin panels, outdated software versions in job ads) and social engineering targets.
-
-
[!TIP] Common Pitfall: Reconnaissance is passive (no direct interaction) initially. Active probing (e.g., port scanning) comes later and must be within scope.
1.3 System Architecture Analysis
-
Importance Pre-Exploitation:
-
Attack Surface Identification: Understand all interfaces (APIs, web apps, network services, mobile app backends) to prioritize testing.
-
Dependency Mapping: Identify third-party libraries, frameworks, and services. A vulnerability in a shared library can compromise the entire system.
-
Data Flow Analysis: Trace how data moves between components (client → server → database). Pinpoints where sensitive data is processed/stored and potential injection points.
-
Technology Stack Profiling: Server OS, web server (Apache/Nginx), database (MySQL/PostgreSQL), programming language (PHP/Java/.NET). Each has known vulnerabilities and misconfigurations.
-
Mobile-Specific: Analyze app architecture (native vs. hybrid), backend API endpoints, local storage mechanisms (SQLite, SharedPreferences), and inter-process communication.
-
-
Outcome: A comprehensive architectural diagram is created to guide systematic testing, not random exploitation.
2.0 Penetration Testing Methodologies
2.1 Testing Paradigms
| Paradigm | Primary Use Case | Key Considerations |
|---|---|---|
| Network Penetration Testing | Assessing perimeter defenses, internal network segmentation, firewall rules, and network service vulnerabilities (e.g., SMB, SSH, RDP). | Focus on infrastructure. Requires network-level access (often via VPN). Tests lateral movement. Scope often includes entire subnets. |
| Application Penetration Testing | Assessing security of specific software applications (Web, Mobile, API). | Focus on business logic and code. Deep dive into OWASP Top 10. Requires understanding of the application's workflow. Scope is the application itself and its immediate backend. |
| Mobile Penetration Testing | Assessing native/hybrid mobile apps and their backend services. | Unique aspects: local storage, OS permissions, inter-app communication, reverse engineering (APK/IPA), and mobile-specific APIs (camera, GPS). |
2.2 Web Application Security Testing
-
OWASP-Based Methodologies: Follow structured frameworks like OWASP Testing Guide (v4) or OWASP Web Security Testing Guide (WSTG). Phases: Information Gathering, Configuration & Deployment Management Testing, Identity Management Testing, Authentication Testing, Authorization Testing, Session Management Testing, Input Validation Testing (e.g., SQLi, XSS), Business Logic Testing.
-
HTTP Strict Transport Security (HSTS):
-
Purpose: To force browsers to interact with a website only over HTTPS, preventing protocol downgrade attacks and cookie hijacking.
-
Implementation: Server sends header
Strict-Transport-Security: max-age=31536000; includeSubDomains. -
Crucial: Must be initially set over a valid HTTPS connection. Once cached, browser will reject any HTTP connection to that domain.
-
-
SQL Injection (SQLi):
-
Primary Risk: Unauthorized access to, modification of, or deletion of backend database contents. This leads to data breaches (PII, credentials), data loss, and potentially complete system compromise via database file access or command execution (if DB user has high privileges).
-
Exploitation Vectors: User input fields (login forms, search bars), HTTP headers (User-Agent, Referer), Cookies, API parameters.
-
Types: In-band (Error-based, Union-based), Inferential (Blind Boolean-based, Time-based), Out-of-band.
-
2.3 Wireless Penetration Testing
-
Packet Sniffing:
-
Role: Foundational for passive reconnaissance. Captures 802.11 frames to identify SSIDs, BSSIDs (AP MACs), client MACs, and encryption protocols (WEP, WPA2, WPA3).
-
Tools: Wireshark (analysis), aircrack-ng suite (capture with
airodump-ng).
-
-
Tactics for Attacking Wireless Networks:
-
Evil Twin / Rogue AP: Fake AP mimicking a legitimate one to lure clients and capture credentials (e.g., WPA2 4-way handshake).
-
Deauthentication Attack: Sends forged deauth packets to disconnect clients from the AP, forcing them to reconnect and capture the handshake for offline cracking.
-
Jamming: RF interference to disrupt service (Denial-of-Service).
-
WPS PIN Attack: Exploiting poorly implemented WPS to recover WPA2 passphrase.
-
KRACK Attack: Exploiting WPA2 4-way handshake vulnerabilities to reinstall keys and decrypt traffic.
-
2.4 Social Engineering
-
Common Tactics (Targeting Wireless/General Users):
-
Phishing: Fake emails/SMS (smishing) directing to malicious sites or credential harvesters.
-
Pretexting: Creating a fabricated scenario (e.g., "IT support") to gain trust and extract information.
-
Baiting: Offering free software/music downloads infected with malware.
-
Tailgating/Piggybacking: Physically following an authorized person into a restricted area.
-
Quid Pro Quo: Offering a benefit (free tech support) in exchange for information.
-
-
Role of Employee Training in Mitigation:
-
Awareness: Educates on common tactics and red flags (urgent language, mismatched URLs, unexpected attachments).
-
Simulation: Regular, controlled phishing simulations to reinforce learning.
-
Policy & Procedure: Clear reporting channels for suspected attacks. Enforces principle of least privilege.
-
Culture: Fosters a security-first mindset where employees are the first line of defense, not the weakest link.
-
2.5 Simulated Environments
-
Capture The Flag (CTF) Competitions:
-
Simulation of Real-World Scenarios: Present a controlled environment with multiple, interconnected vulnerabilities (web app, network service, misconfigurations, steganography) that mimic a real corporate network.
-
Skills Tested: Reconnaissance, vulnerability scanning, exploitation, privilege escalation, lateral movement, persistence, report writing.
-
Learning Value: Hands-on practice in a legal, safe setting. Develops problem-solving under time pressure. Highlights the chain of exploits needed for a full compromise, not just a single vulnerability.
-
3.0 Vulnerability Analysis and Management
3.1 Vulnerability Scanning
-
Tools & Types:
| Type | Tools (Examples) | Purpose | | :--- | :--- | :--- | | Network Scanning | Nmap, Nessus, OpenVAS | Discover live hosts, open ports, services, and OS fingerprinting. | | Application Scanning | OWASP ZAP, Burp Suite, Nikto | Identify web app flaws (SQLi, XSS, CSRF, insecure deserialization). | | Cloud Scanning | ScoutSuite, Prowler, AWS Inspector | Check cloud configs (S3 bucket permissions, security groups, IAM policies). |
-
Interpretation: Scans produce findings with severity ratings (Critical, High, Medium, Low, Informational). Key is false positive reduction (manual validation) and risk-based prioritization (CVSS score + business impact). A "High" CVSS 9.8 on a non-critical test server may be lower priority than a "Medium" on a public-facing database.
3.2 Cloud Security Considerations
-
Unique Vulnerabilities:
-
Misconfiguration: #1 cause of cloud breaches. Public S3 buckets, overly permissive security groups, default credentials.
-
Insecure APIs: Vulnerable cloud service APIs or poorly secured custom APIs.
-
Account Hijacking: Weak authentication, lack of MFA on root/admin accounts.
-
Insider Threat: Malicious or negligent cloud service provider employee or organization's own employee with excessive permissions.
-
Shared Technology Vulnerabilities: Hypervisor escape, side-channel attacks in multi-tenant environments.
-
-
Shared Responsibility Model:
-
Provider (e.g., AWS, Azure): Security OF the cloud (physical infrastructure, hypervisor, network fabric).
-
Customer: Security IN the cloud (OS patching, application security, data encryption, IAM, network configs). Misunderstanding this boundary is a major risk.
-
3.3 Exploitation Fundamentals
-
From Identification to Proof-of-Concept (PoC):
-
Vulnerability Identification: From scan report, CVE database, or manual testing.
-
Research: Understand the flaw (read CVE, advisory, exploit-db). Identify affected versions and prerequisites.
-
Exploit Selection/Development: Use existing public exploit (Metasploit module) or develop custom PoC script (Python, Bash).
-
Testing in Lab: Validate exploit in isolated environment to understand impact and payload options.
-
Execution on Target: Run exploit against in-scope target during authorized test window. Capture evidence (screenshots, shell sessions, extracted data).
-
PoC Documentation: Clearly document steps, commands, output, and impact for the report. Never run destructive payloads (e.g.,
rm -rf) without explicit client approval.
-
4.0 Cryptography and Secure Communication
4.1 Cryptographic Principles
-
RSA Algorithm for Secure Communication:
-
Purpose: Asymmetric cryptosystem for key exchange (establishing a shared secret) and digital signatures (authentication/integrity). Not typically used for bulk data encryption due to speed.
-
Key Generation:
-
Choose large primes $p$ and $q$.
-
Compute modulus $$\displaystyle n = p \times q $$.
-
Compute totient $$\displaystyle \phi(n) = (p-1)(q-1) $$.
-
Choose public exponent $e$ such that $$\displaystyle 1 < e < \phi(n) $$ and $$\displaystyle gcd(e, \phi(n)) = 1 $$.
-
Compute private exponent $d$ such that $$\displaystyle d \equiv e^{-1} \mod \phi(n) $$.
-
Public Key: $(e, n)$
-
Private Key: $(d, n)$
-
-
Encryption (Confidentiality): $$\displaystyle C = M^e \mod n $$ (using recipient's public key).
-
Decryption: $$\displaystyle M = C^d \mod n $$ (using recipient's private key).
-
Digital Signature (Authentication/Integrity): $$\displaystyle S = H(M)^d \mod n $$ (sign with private key). Verification: $$\displaystyle H(M) \stackrel{?}{=} S^e \mod n $$.
-
-
Decryption Concepts:
-
Symmetric Decryption: Using the same secret key $K$ for encryption and decryption (e.g., AES: $$\displaystyle D_K(C) = P $$). Requires secure key exchange first.
-
Asymmetric Decryption: Using private key to decrypt data encrypted with corresponding public key (as in RSA above).
-
Hybrid Systems (e.g., TLS): Use asymmetric crypto (RSA/ECDH) to securely exchange a symmetric session key, then use fast symmetric crypto (AES) for bulk data encryption/decryption.
-
4.2 Cryptographic Implementation and Auditing
-
Key Elements of a Cryptography Audit Report:
-
Executive Summary: High-level findings and risk posture.
-
Scope & Methodology: Systems, algorithms, and protocols audited.
-
Algorithm & Key Management Assessment: Strength of algorithms (key length, mode of operation), key generation, storage, rotation, and destruction policies.
-
Protocol Configuration Review: TLS/SSL versions, cipher suite strength, certificate validity and management.
-
Implementation Flaws: Hardcoded keys, weak random number generators, improper padding (e.g., PKCS#1 v1.5), side-channel leakages.
-
Compliance Mapping: Alignment with standards (PCI-DSS, NIST SP 800-52, FIPS 140-2/3).
-
Remediation Plan: Prioritized, actionable recommendations.
-
-
Stakeholder Engagement for Successful Deployment:
-
Developers: Training on secure crypto APIs, avoiding "roll-your-own" crypto.
-
System Administrators: Proper configuration of TLS, certificate management.
-
Management: Understanding business risk of weak crypto, allocating budget for proper tools (HSMs) and audits.
-
Legal/Compliance: Ensuring chosen algorithms meet regulatory requirements for data protection.
-
4.3 Cryptographic Attacks and Defenses
-
Common Weaknesses & Attacks Overview:
| Weakness | Attack Vector | Defense | | :--- | :--- | :--- | | Weak PRNG | Predictable keys/IVs (e.g., Debian OpenSSL bug). | Use OS-provided CSPRNG (
/dev/urandom,CryptGenRandom). | | Small Key Size | Brute-force, factorization (RSA < 2048-bit). | Use recommended key lengths (RSA 3072+, AES-256). | | Protocol Downgrade | Forcing SSL 3.0/TLS 1.0. | Disable old protocols, use HSTS. | | Padding Oracle | CBC mode with improper padding validation (e.g., POODLE). | Use authenticated encryption (AES-GCM). | | Side-Channel | Timing, power analysis, cache attacks. | Constant-time implementations, hardware countermeasures (HSMs). | | Key Management | Hardcoded keys, poor storage. | Use key management systems (KMS), HSMs, environment variables. |
5.0 Multimedia Security and Forensics
5.1 Multimedia Fundamentals
-
Discrete Cosine Transform (DCT):
-
Use in Compression: Core transform in JPEG (image) and MPEG (video) codecs. Converts spatial pixel data into frequency domain.
-
Lossy Nature: After DCT, quantization step discards high-frequency components (perceptually less important details). This loss is irreversible. The more aggressive the quantization, the higher the compression but lower the quality.
-
Formula (1D):
-
$$F(u) = \alpha(u) \sum_{x=0}^{N-1} f(x) \cos\left(\frac{\pi(2x+1)u}{2N}\right)$$
where $\alpha(u)$ is a normalization factor.
-
Virtual Reality (VR) as Multimedia:
-
Immersive Experience: Combines 3D graphics, spatial audio, and head tracking to create a simulated environment.
-
Real-time Interaction: Requires extremely low latency (<20ms) to prevent motion sickness.
-
High Bandwidth: Streaming high-resolution stereoscopic video demands massive bandwidth and compression.
-
Hardware Dependency: Relies on HMDs (Head-Mounted Displays) and motion sensors.
-
5.2 Quality of Service (QoS) in Multimedia
-
Factors Affecting QoS:
-
Bandwidth: Sufficient data rate to transmit media without buffering.
-
Latency: Delay in packet delivery. Critical for real-time communication (VoIP, video conferencing).
-
Jitter: Variation in packet arrival time. Causes audio/video stuttering.
-
Packet Loss: Lost packets result in visual artifacts (pixelation) or audio dropouts.
-
Codec Efficiency: Balance between compression ratio and computational complexity.
-
-
Resource Management for QoS Assurance:
-
Types of Resources Managed:
-
Network Resources: Bandwidth allocation (DiffServ, IntServ), queue management (priority queuing).
-
CPU Resources: Scheduling for encoding/decoding, thread prioritization.
-
Memory Resources: Buffering strategies (jitter buffers), cache management.
-
Storage Resources: I/O throughput for streaming from disk.
-
-
Techniques: Traffic shaping, admission control, resource reservation (RSVP), adaptive bitrate streaming (DASH, HLS).
-
5.3 Security Attacks on Multimedia Systems
-
Active vs. Passive Attacks:
| Passive Attack | Active Attack | | :--- | :--- | | Goal: Eavesdropping, monitoring. | Goal: Modify, disrupt, inject. | | Examples: Packet sniffing of unencrypted stream, traffic analysis. | Examples: Replay attack (resend old packets), injection (add fake video frames), DoS (flood stream), modification (alter video content). | | Detection: Very difficult. | Detection: Possible via integrity checks, sequence numbers, timestamps. | | Confidentiality Threat. | Integrity & Availability Threat. |
5.4 Multimedia Authentication and Protection
-
Watermarking:
-
Visible Watermark: Logo/text overlaid visibly on image/video.
- Use-Case Decision Factors: Deterrence (claim ownership, prevent commercial reuse), Branding (portfolio sites). Not suitable for sale previews or stock photos where aesthetics are critical.
-
Invisible (Robust/Fragile) Watermark: Data embedded imperceptibly in frequency/spatial domain.
-
Robust: Survives compression, resizing. Use for copyright protection, tracking (forensic watermarking).
-
Fragile: Breaks with any modification. Use for tamper detection, authentication.
-
-
Decision Factors for Scenario:
-
Professional Portfolio (High-Quality): Visible watermark (low opacity) or invisible robust watermark. Goal: Branding and deterrence while showcasing quality.
-
Stock Photography (For Sale): Invisible robust watermark. Goal: Track unauthorized use without degrading saleable image quality.
-
Low-Res Preview to Clients: Visible watermark (prominent) or invisible fragile watermark. Goal: Clearly mark as unreleased, prevent misuse.
-
-
-
Authentication Mechanisms for Integrity:
-
Cryptographic Hashes (MD5, SHA-1/256/3): Generate fingerprint of file. Any change alters hash. Must be computed on original file.
-
Digital Signatures: Hash of media signed with sender's private key. Provides integrity, authentication, and non-repudiation.
-
Watermarking (Fragile): Detects localized tampering.
-
5.5 Digital Forensics for Multimedia
-
Digital Evidence Extraction Process & Tools:
-
Identification: Recognize potential evidence (image, video, audio file).
-
Preservation: Create a forensic image (bit-stream copy) of the storage media using write-blockers. Hash (SHA-256) original and copy for integrity verification.
-
Examination: Analyze the copied data.
- Tools:
exiftool(metadata),strings(embedded text),binwalk(embedded files),ffmpeg(media info),Ghiro(automated image forensics),Audacity(audio waveform analysis).
- Tools:
-
Analysis: Interpret findings (timeline from metadata, hidden data, signs of manipulation).
-
Presentation: Document chain of custody, tools used, hashes, and findings in a report.
-
-
Metadata Significance:
-
Authentication: EXIF data (camera model, timestamp, GPS coordinates) can corroborate a file's claimed origin. Metadata can be easily forged or stripped.
-
Analysis: Timeline construction (DateTimeOriginal, FileModifyDate). Geolocation from GPS tags. Software used (from Producer tag). Device identification (serial number from some cameras).
-
Red Flags: Inconsistencies between metadata and claimed scenario (e.g., photo taken at night but EXIF says daytime).
-
-
Printer/Scanner Forensics:
-
Risks: Forged documents, counterfeit currency, fraudulent contracts.
-
Mechanism: Every printer/scanner leaves a unique "fingerprint" due to manufacturing variations:
-
Mechanical: Banding patterns from print head/roller imperfections.
-
Electro-optical: Noise patterns in CCD/CMOS sensors (scanner).
-
Software: Dithering patterns, halftone screens.
-
-
Case Study: "The Check Fraud Case" - Investigators linked fraudulent checks to a specific printer model and, via service records, to a suspect's purchase by matching the unique banding pattern in the MICR line (routing/account numbers).
-
-
Audio Recording Authentication in Legal Contexts:
-
Chain of Custody: Proven handling from recording to presentation.
-
Format & Header Analysis: Check for inconsistencies in container format, codec, timestamps.
-
Waveform/Spectrogram Analysis: Look for edits (clicks, abrupt changes), noise profile consistency, spectral anomalies.
-
Contextual Corroboration: Background sounds, speaker voice identification (spectral comparison), alignment with known events.
-
Device Identification: Similar to printers, microphones and ADCs have unique noise signatures (Electronic Voice Identification).
-
5.6 Multimedia Content Forensics
-
Techniques for Detecting Manipulation (Images/Video):
-
Error Level Analysis (ELA): Resave image at known quality, compare. Areas with different compression artifacts may be pasted.
-
Copy-Move Detection: Find duplicated regions within an image (using block matching or keypoint descriptors like SIFT).
-
Lighting/Shadow Inconsistency: Analyze light direction and shadow geometry using 3D models.
-
JPEG Ghosts: Detect double JPEG compression (re-saving a JPEG).
-
Video Frame Analysis: Look for inconsistencies in frame interpolation, motion vectors, or noise patterns across frames.
-
-
Protocols Relevant to Multimedia Forensics:
-
Focus on standards for evidence handling and reporting, not network protocols.
-
ISO/IEC 27037:2012: Guidelines for identification, collection, acquisition, and preservation of digital evidence.
-
NIST SP 800-101: Guidelines for mobile device forensics.
-
Scientific Working Group on Digital Evidence (SWGDE) Best Practices: For image and video authentication.
-
6.0 Professional Practices and Reporting
6.1 Documentation and Reporting
-
Structure of Penetration Test Report:
-
Executive Summary: Business impact, overall risk rating, key recommendations for C-level.
-
Scope & Methodology: Rules of Engagement, tools used, testing approach (black/grey/white box).
-
Detailed Findings: For each vulnerability:
-
Title & Severity (CVSS score).
-
Description: What is the flaw?
-
Evidence: Screenshots, curl commands, exploit output.
-
Impact: Business risk, potential data loss, financial damage.
-
Remediation: Clear, actionable steps (e.g., "Apply parameterized queries").
-
References: CVE, OWASP ID.
-
-
Architecture & Attack Path: Diagrams showing how chained vulnerabilities lead to compromise.
-
Conclusion & Recommendations: Strategic advice, prioritized roadmap.
-
-
Communicating to Stakeholders:
-
Technical Team (Devs/Admins): Detailed findings, PoC steps, specific code/config fixes.
-
Management: Focus on business risk, cost of remediation vs. cost of breach, compliance impact. Avoid jargon.
-
Legal/Compliance: Evidence of due diligence, mapping to regulatory controls.
-
6.2 Training and Awareness
-
Designing Effective Employee Security Training:
-
Role-Based Content: Tailor for developers (secure coding), IT staff (patching), general staff (phishing).
-
Interactive & Engaging: Use simulated phishing, tabletop exercises, short video modules.
-
Regular & Reinforced: Not a one-time annual event. Quarterly micro-learning, monthly phishing simulations.
-
Positive Reinforcement: Reward reporting of suspicious emails, not punish mistakes.
-
Metrics: Track click rates on phishing simulations, training completion, incident reports to measure effectiveness.
-
6.3 Operating System and Resource Management
-
OS Layering for Hardware Resource Management:
-
Concept: Abstract complex hardware behind simpler, standardized interfaces (system calls). Each layer provides services to the layer above, using services of the layer below.
-
Modern OS Layers (Example - Linux):
-
Hardware: CPU, Memory, I/O Devices.
-
Kernel: Core OS. Directly manages hardware via drivers. Provides process scheduling, memory management, file system, networking stack.
-
System Libraries (e.g., glibc): Wrap kernel syscalls into standard C library functions (
open(),read(),fork()). -
Shell/User Applications: Use library functions to perform tasks without knowing hardware details.
-
-
Benefit: Hardware independence for applications, security (kernel protects hardware), portability.
-
-
Resource Types Managed (Multimedia/QoS Context):
-
CPU: Processing cycles for encoding/decoding.
-
Memory (RAM): Buffering media streams.
-
Disk I/O: Reading/writing media files.
-
Network Bandwidth: Throughput for streaming.
-
GPU: Hardware acceleration for video rendering/transcoding.
-
Specialized Hardware: Audio DSPs, video capture cards.
-