Skip to content
IT-801 · Information Security/Quick Revision Short Notes

Information Security (IT-801) - Unit 1 Short Notes

UNIT 1: INFORMATION SECURITY FOUNDATIONS AND CRYPTOGRAPHY


1. Introduction to Information Security

Threat and Attack:

  • Threat: A potential violation of security. It is any circumstance or event with the potential to cause harm to a system or organization (e.g., a hacker, a flood, a software bug).

  • Attack: An intentional act that attempts to violate security. It is the realization of a threat.

  • Categories of Security Attacks (Based on Goals):

    • Passive Attack: Goal is to learn/use information without affecting system resources (e.g., Traffic Analysis, Release of Message Contents). Hard to detect.

    • Active Attack: Goal is to alter system resources or affect their operation (e.g., Masquerade, Replay, Modification of Messages, Denial-of-Service). Hard to prevent.

Security vs. Protection:

  • Security: Broader concept. Concerned with safeguarding assets (data, systems, reputation) from any threat (accidental or intentional, human or natural). Involves policies, risk management, and a lifecycle approach.

  • Protection: Subset of security. Specifically focuses on mechanisms to enforce security policies and control access to system resources (e.g., access controls, authentication). It's the technical implementation layer.

Exam Tip: Security is the strategy (what to protect and why); Protection is the tactics (how to enforce it technically).

Fundamental Security Concepts (The Four Horsemen):

  1. Fabrication: Creating false data or objects (e.g., fake logs, spoofed packets).

  2. Interception: Eavesdropping on communications or accessing data without authorization.

  3. Modification: Altering data or system state (e.g., tampering with files, man-in-the-middle).

  4. Repudiation: Denying an action (e.g., sender denies sending a message, receiver denies receiving it).

Critical Characteristics of Information (CIA Triad + 2):

Characteristic Definition Example
Confidentiality Preventing unauthorized disclosure of information. Encryption, access controls.
Integrity Guarding against improper modification or destruction. Hash functions, digital signatures, checksums.
Availability Ensuring information/system is accessible when needed. Redundancy, backups, DoS mitigation.
Authenticity Verifying the identity of users/systems and the origin of data. Passwords, digital certificates, MACs.
Non-Repudiation Preventing a party from denying an action (proof of origin/delivery). Digital signatures, trusted third parties (e.g., Kerberos).

Security Policy:

  • Definition: A formal document that outlines an organization's rules, procedures, and guidelines for protecting its information assets.

  • Key Components: Scope, responsibilities, risk assessment methodology, acceptable use, access control policy, incident response plan, compliance requirements.

  • Importance: Provides management direction, ensures consistency, meets legal/regulatory requirements, forms basis for technical controls.

Trust and Assumptions:

  • Security systems are built on a Trusted Computing Base (TCB) – the hardware, software, and procedures that are critical to enforcing the security policy.

  • Assumptions: We must explicitly state what is trusted (e.g., the OS kernel, the CA in PKI) and what is untrusted (e.g., user applications, network links). The security of the whole system fails if the TCB is compromised.

Security Life Cycle (PDR Model & Phases):

A continuous cycle: Plan → Do → Check → Act.

  1. Identify & Assess: Identify assets, threats, vulnerabilities. Perform risk assessment.

  2. Develop Policy: Create security policies and procedures.

  3. Implement: Deploy technical controls (firewalls, encryption), administrative controls (training, policies).

  4. Monitor & Detect: Use tools like IDS, logs, audits to monitor for violations.

  5. Respond & Recover: Incident response, disaster recovery, lessons learned.

  6. Update & Maintain: Patch systems, update policies based on new threats.


2. Cryptographic Foundations

Steganography vs. Encryption:

Feature Steganography Encryption
Goal Hide the existence of a message. Hide the content of a message.
Output Message appears as something else (image, audio). Ciphertext looks random/unintelligible.
Key Often no key needed (or a shared secret for embedding). Requires a key for encryption/decryption.
Security Security through obscurity. Broken if method discovered. Security through mathematical strength.
Use Case Covert channels, watermarking. General data confidentiality.

Classical Ciphers:

  • Caesar Cipher: Monoalphabetic substitution. Shift each letter by a fixed key k (mod 26).

    • Encryption: $$\displaystyle C = (P + k) \bmod 26 $$

    • Decryption: $$\displaystyle P = (C - k) \bmod 26 $$

    • Example: key=1, Plaintext "LUCK" → Ciphertext "MVLD".

  • Playfair Cipher: Digraph substitution. Uses a 5x5 matrix (I/J merged). Rules for same-row, same-column, rectangle.

    • Algorithm Steps:

      1. Construct matrix with keyword (remove duplicates, fill with rest of alphabet).

      2. Prepare plaintext: split into digraphs, insert 'X' for double letters or odd length.

      3. Encrypt each digraph using matrix rules.

      4. Decryption is reverse process.

Block Ciphers vs. Stream Ciphers:

Feature Block Cipher Stream Cipher
Unit Encrypts fixed-size block (e.g., 64, 128 bits). Encrypts bits/bytes one at a time.
Memory Needs to hold a full block. Very little memory, fast.
Error Propagation A bit error in ciphertext corrupts entire block upon decryption. A bit error affects only that bit.
Use Case General-purpose encryption (files, databases). Real-time, streaming data (voice, video).
Examples AES, DES, 3DES. RC4, A5/1 (GSM).

Diffusion and Confusion (Shannon's Principles):

  • Diffusion: Spreads the influence of each plaintext bit over many ciphertext bits. Goal: Hide statistical structure of plaintext. Achieved by Permutation/P-boxes and multiple rounds.

  • Confusion: Makes the relationship between ciphertext and key as complex as possible. Goal: Hide key's relationship to ciphertext. Achieved by Substitution/S-boxes.

Exam Tip: DES uses both: S-boxes (confusion), P-box & multiple rounds (diffusion). AES uses SubBytes (confusion) and ShiftRows/MixColumns (diffusion).

Modes of Operation for Block Ciphers:

  • Electronic Codebook (ECB): Each plaintext block encrypted independently. Disadvantage: Identical plaintext blocks → identical ciphertext blocks. Never use for more than one block of data. Leaks data patterns (e.g., famous penguin image).

  • Cipher Block Chaining (CBC): $$\displaystyle C_i = E_K(P_i \oplus C_{i-1}) $$, $$\displaystyle C_0 = IV $$. Each ciphertext block depends on all previous blocks. Hides patterns. Requires IV (must be unpredictable). Most common.

  • Cipher Feedback (CFB): Turns block cipher into stream cipher. $$\displaystyle C_i = P_i \oplus E_K(C_{i-1}) $$. Can handle data in smaller units (bits/bytes). Self-synchronizing.

  • Output Feedback (OFB): Turns block cipher into stream cipher. $$\displaystyle O_i = E_K(O_{i-1}) $$, $$\displaystyle C_i = P_i \oplus O_i $$. Keystream independent of plaintext/ciphertext. Error does not propagate.

  • Counter (CTR): $$\displaystyle C_i = P_i \oplus E_K(IV + i) $$. Parallelizable, random access. Keystream depends on counter.


3. Symmetric Key Cryptography

Data Encryption Standard (DES):

  • Structure: 16-round Feistel network. Block size = 64 bits, Key size = 56 bits (plus 8 parity bits).

  • Function (Round):

    1. Expansion Permutation (E-box): 32-bit half-block → 48 bits.

    2. Key Mixing: XOR with 48-bit round key.

    3. Substitution (S-boxes): 8 S-boxes, each 6-in → 4-out. Core of confusion.

    4. Permutation (P-box): 32-bit output permuted (diffusion).

  • Avalanche Effect: A small change in plaintext or key (e.g., 1 bit) results in a significant change (approx. 50%) in ciphertext. DES exhibits a strong avalanche effect.

  • Weaknesses:

    • Small Key Space (2⁵⁶): Vulnerable to brute-force (1998: EFF's Deep Crack broke key in 56 hours).

    • Weak Keys: 4 keys where encryption = decryption (K, K').

    • Semi-weak Keys: Pairs (K1, K2) where encrypting with K1 then K2 returns original.

    • Design Secrecy: S-boxes were designed by NSA with secret criteria (led to suspicion of backdoor).

Advanced Encryption Standard (AES):

  • Overview: Successor to DES. Block size = 128 bits. Key sizes = 128, 192, 256 bits (10, 12, 14 rounds respectively).

  • Rounds (for 128-bit key): Each round (except last) consists of:

    1. SubBytes: Non-linear substitution using S-box (confusion).

    2. ShiftRows: Cyclically shift rows of state matrix (diffusion).

    3. MixColumns: Linear mixing of columns (diffusion). Omitted in last round.

    4. AddRoundKey: XOR with round key.

  • Key Expansion: The 128/192/256-bit key is expanded into an array of 44/52/60 32-bit words (for 10/12/14 rounds + initial). Each new word is XOR'd with previous, with a non-linear transformation (SubWord + RotWord + RCon) every 4th word.


4. Asymmetric Key Cryptography

Public Key vs. Private Key Cryptography:

Feature Symmetric (Private Key) Asymmetric (Public Key)
Keys Single shared secret key. Key pair: Public (distribute) & Private (secret).
Key Management Difficult (O(n²) keys for n users). Simple (O(n) public keys).
Speed Very Fast (hardware/software optimized). Slow (math-intensive, orders of magnitude slower).
Primary Use Bulk data encryption/decryption. Key exchange, digital signatures, small data encryption.
Algorithms AES, DES, 3DES, Blowfish. RSA, ECC, Diffie-Hellman, ElGamal.
Confidentiality Yes (with shared key). Yes (encrypt with receiver's public key).
Authentication/Non-Rep Limited (shared secret implies origin). Yes (via digital signatures).

RSA Algorithm (Rivest-Shamir-Adleman):

  • Mathematical Basis: Difficulty of integer factorization problem. Based on Euler's theorem: $$\displaystyle m^{\phi(n)} \equiv 1 \pmod{n} $$.

  • Key Generation:

    1. Choose two large primes $p, q$.

    2. Compute $$\displaystyle n = p \times q $$, $$\displaystyle \phi(n) = (p-1)(q-1) $$.

    3. Choose public exponent $e$ such that $$\displaystyle 1 < e < \phi(n) $$ and $$\displaystyle gcd(e, \phi(n)) = 1 $$.

    4. Compute private exponent $d$ such that $$\displaystyle d \equiv e^{-1} \pmod{\phi(n)} $$ (using Extended Euclidean Algorithm).

    5. Public Key: $(e, n)$. Private Key: $(d, n)$.

  • Encryption: $$\displaystyle C = M^e \bmod n $$

  • Decryption: $$\displaystyle M = C^d \bmod n $$

  • Security: Relies on hardness of factoring large $n$. Attacks:

    • Brute-force: Try all $d$.

    • Mathematical: Factor $n$ to get $\phi(n)$ and compute $d$.

    • Timing Attacks: Exploit variations in decryption time.

    • Chosen Ciphertext: (Bleichenbacher's attack on PKCS#1 v1.5).

Euler's Totient Function $\phi(n)$:

  • Definition: Counts positive integers $\leq n$ that are coprime to $n$ (gcd=1).

  • Calculation:

    • If $n$ is prime: $$\displaystyle \phi(n) = n-1 $$.

    • If $$\displaystyle n = p \times q $$ (p, q distinct primes): $$\displaystyle \phi(n) = (p-1)(q-1) $$.

    • General: For $$\displaystyle n = p_1^{a_1} p_2^{a_2}... $$, $$\displaystyle \phi(n) = n \left(1 - \frac{1}{p_1}\right)\left(1 - \frac{1}{p_2}\right)... $$

Diffie-Hellman Key Exchange (DH):

  • Goal: Establish a shared secret key over an insecure channel.

  • Primitive Root (α) modulo q: A number α such that its powers modulo q generate all numbers 1 to q-1. For prime q, α is a generator of $$\displaystyle \mathbb{Z}_q^* $$.

  • Protocol Steps:

    1. Public Parameters: Agree on large prime $q$ and primitive root $\alpha \bmod q$.

    2. Private Keys: User A chooses random $$\displaystyle X_A $$, User B chooses random $$\displaystyle X_B $$.

    3. Public Keys: $$\displaystyle Y_A = \alpha^{X_A} \bmod q $$, $$\displaystyle Y_B = \alpha^{X_B} \bmod q $$. Exchange these.

    4. Shared Secret: A computes $$\displaystyle K = (Y_B)^{X_A} \bmod q = \alpha^{X_B X_A} \bmod q $$. B computes $$\displaystyle K = (Y_A)^{X_B} \bmod q = \alpha^{X_A X_B} \bmod q $$.

  • Security Issue: Man-in-the-Middle (MITM) attack. No authentication of parties. Vulnerable to active interception.

Key Management:

  • Symmetric (n users): Each pair needs a unique key. Total keys = $$\displaystyle \frac{n(n-1)}{2} $$.

  • Asymmetric (n users): Each user has one public/private key pair. Total public keys = $n$, private keys = $n$.


5. Hash Functions and Message Authentication

Hash Functions:

  • Properties:

    • Input: Arbitrary length.

    • Output: Fixed length (e.g., 160 bits for SHA-1, 256 for SHA-256).

    • Efficiency: Easy to compute $$\displaystyle h = H(x) $$.

    • Pre-image Resistance: Given $h$, hard to find any $x$ such that $$\displaystyle H(x)=h $$.

    • Second Pre-image Resistance: Given $$\displaystyle x_1 $$, hard to find $$\displaystyle x_2 \neq x_1 $$ such that $$\displaystyle H(x_1)=H(x_2) $$.

    • Collision Resistance: Hard to find any pair $$\displaystyle x_1, x_2 $$ such that $$\displaystyle H(x_1)=H(x_2) $$.

  • Common Algorithms: MD5 (broken), SHA-1 (weak), SHA-2 family (SHA-256, SHA-512), SHA-3 (Keccak).

  • Role in Integrity: Compute hash of file/message. Send hash securely (or sign it). Receiver recomputes hash and compares. Any change alters hash.

Exam Justification: "Hashing does not ensure integrity in network communication." Why? An attacker can intercept message, modify it, compute new hash, and send both. Receiver has no way to know if hash came from original sender. Solution: Use a Message Authentication Code (MAC) or Digital Signature (keyed hash).

Message Authentication Codes (MACs):

  • Definition: A short tag generated from a message and a secret key. Provides authentication and integrity.

  • Construction: $$\displaystyle MAC = C_K(M) $$ where $C$ is a MAC algorithm (e.g., HMAC, CMAC).

    • HMAC: Hash-based (e.g., HMAC-SHA256). $$\displaystyle HMAC(K, M) = H((K \oplus opad) \| H((K \oplus ipad) \| M)) $$.

    • CMAC: Cipher-based (block cipher in CBC mode with special final step).

  • Achieving Authentication & Confidentiality:

    1. MAC-then-Encrypt: Compute MAC on plaintext, then encrypt both. (Used in SSL/TLS historically).

    2. Encrypt-then-MAC: Encrypt plaintext, then compute MAC on ciphertext. Most secure (provides integrity for ciphertext). (Used in IPsec).

    3. Encrypt-and-MAC: Compute MAC on plaintext and encrypt plaintext separately. Send both.

Exam Tip: For both authentication and confidentiality, typically use: Encrypt (with symmetric key) + MAC (with same or different key). Order matters (Encrypt-then-MAC preferred).

Message Authentication vs. Digital Signatures:

  • MAC: Uses symmetric key. Provides source authentication (only parties sharing key know who sent it). Does not provide non-repudiation (sender can claim receiver forged MAC).

  • Digital Signature: Uses asymmetric key (private key to sign, public key to verify). Provides source authentication and non-repudiation (only sender has private key).


6. Authentication and Access Control

Authentication Factors:

  1. Something you know: Password, PIN, secret question.

  2. Something you have: Smart card, token, phone (for OTP).

  3. Something you are: Biometrics (fingerprint, iris, face).

  4. Somewhere you are: Location (GPS, IP address).

  5. Something you do: Behavioral biometrics (keystroke dynamics, gait).

Multi-Factor Authentication (MFA): Combining ≥2 factors from different categories (e.g., password + OTP). Much stronger than single-factor.

Access Control Models:

Model Discretionary Access Control (DAC) Mandatory Access Control (MAC) Role-Based Access Control (RBAC) Task-Based Access Control (TBAC)
Control Basis Owner's discretion. User can grant permissions to others. System-enforced policy. Labels (classification) on subjects & objects. Organizational roles. Permissions assigned to roles, users assigned to roles. Dynamic tasks/workflows. Permissions granted for specific tasks/sessions.
Flexibility High (user-centric). Low (central policy, rigid). Medium-High (admin manages roles). High (context-aware, dynamic).
Example Unix file permissions (rwx for owner/group/others). Military security levels (Top Secret, Secret). Employee → "Manager" role → can "Approve_Expense". Hospital: Doctor gets access to patient records only during active treatment session.
Key Strength Ease of use, delegation. Strong, prevents data leaks. Scalable, easy admin (role hierarchy). Fine-grained, least privilege for dynamic environments.

Principle of Least Privilege:

  • Definition: Each subject (user, process) should be granted only the minimum privileges necessary to perform its intended function.

  • Application: In access control (RBAC roles with minimal permissions), in OS (user accounts without admin rights), in applications (features disabled by default). Reduces attack surface and damage from compromised accounts.

Confinement Problem:

  • Definition: The challenge of preventing a process from accessing or disseminating information beyond its authorized boundaries, especially when it receives data from a more trusted source.

  • Mitigation Techniques:

    • Secure Capabilities: unforgeable tokens that grant specific access.

    • Sandboxing: Running untrusted code in isolated environment (e.g., Java VM, containers).

    • Information Flow Control: Tracking and controlling how data moves through a system (e.g., taint analysis).

    • Trusted Path: Ensuring communication with security-critical components (e.g., login) cannot be intercepted.

Password Management:

  • Best Practices:

    • Length over complexity: Minimum 12-15 characters.

    • Passphrases: Use multiple random words (e.g., correct-horse-battery-staple).

    • No reuse across sites.

    • Regular change only if breach suspected (NIST guidelines now advise against forced frequent changes).

    • Use password manager to generate/store unique, strong passwords.

  • Secure Storage: Never store plaintext. Store only salted cryptographic hash (e.g., bcrypt, scrypt, Argon2). Salt is a random value unique per password, concatenated before hashing to defeat rainbow tables.

    • Stored record: username | salt | hash(salt + password).

7. System and Software Security

Operating System Security:

  • Linux Architecture:

    • Kernel Mode (Privileged): Core OS, drivers, system calls.

    • User Mode (Unprivileged): Applications, shells.

    • Security Features: Discretionary Access Control (DAC) via file permissions (rwx), Mandatory Access Control (MAC) via SELinux/AppArmor (enforces type enforcement), user/group IDs, capabilities (fine-grained privileges), chroot jails, namespaces/containers (isolation).

  • Windows Security Features:

    • Security Accounts Manager (SAM): Local user database.

    • Access Tokens: Created at logon, contains user SID, group SIDs, privileges.

    • Integrity Levels: Low, Medium, High, System (UAC).

    • User Account Control (UAC): Prompts for consent/elevation for admin tasks.

    • Windows Defender: Antivirus/antimalware.

    • BitLocker: Full-disk encryption.

Malicious Logic:

  • Definition: Software (or firmware) intentionally included or inserted into a system to perform an unauthorized function.

  • Types & Impact:

    • Virus: Requires host program to replicate. Attaches to executable. Impact: Corrupts files, steals data.

    • Worm: Standalone, self-replicating, spreads over network. Impact: Consumes bandwidth, creates botnets.

    • Trojan Horse: Disguised as legitimate software. Impact: Provides backdoor, steals credentials.

    • Logic Bomb: Code that triggers on a specific condition (date, event). Impact: Data deletion, system crash.

    • Rootkit: Hides existence/activity of other malware. Impact: Stealth, persistent access.

    • Ransomware: Encrypts files, demands ransom. Impact: Data loss, financial extortion.

Vulnerability Analysis:

  • Process:

    1. Identification: Use scanners (Nessus, OpenVAS), manual review, fuzzing to find potential vulnerabilities.

    2. Assessment: Classify severity (CVSS score), determine exploitability, potential impact.

    3. Remediation: Patch, configure, or mitigate (e.g., firewall rule).

    4. Verification: Rescan to confirm fix.

  • Importance in Auditing: Proactive identification of weaknesses before attackers exploit them. Essential for compliance (PCI-DSS, ISO 27001) and risk management.

Forensic Analysis on Compromised Server:

  1. Preparation: Have incident response plan, tools ready (write-blockers, forensic distros like CAINE).

  2. Identification: Detect breach (IDS alert, anomaly).

  3. Containment: Isolate server from network (unplug cable), document physical state.

  4. Preservation: Create bit-for-bit forensic image of disks, memory (RAM dump). Use hash (SHA-256) to verify integrity.

  5. Analysis: Examine logs, processes, network connections, file system (deleted files, timestamps), memory (malware, keys). Timeline reconstruction.

  6. Eradication & Recovery: Remove malware, patch vulnerabilities, restore from clean backup.

  7. Lessons Learned: Document findings, update policies.

Database Auditing:

  • Purpose: Monitor, record, and analyze database activity to ensure security, compliance, and detect anomalies.

  • Methods:

    • Native DB Logs: Audit trails (login attempts, DML operations).

    • Change Data Capture (CDC): Track row-level changes.

    • Database Activity Monitoring (DAM): Real-time monitoring of SQL queries.

    • File Integrity Monitoring (FIM): Watch for changes to database files.

    • Log Analysis: Correlate logs with application/OS logs.

Trusted Systems (TCSEC - Orange Book):

  • Evaluation Criteria: Defines levels of trust (from D - Minimal to A1 - Verified Design).

  • Key Levels:

    • C2: Controlled Access Protection. Discretionary Access Control (DAC), audit of security-relevant events. (e.g., Windows NT 4.0, SELinux in C2 mode).

    • B1: Labeled Security. Mandatory Access Control (MAC) with security labels.

    • B3: Security Domains. Highly resistant to penetration, trusted recovery.

  • Modern Equivalent: Common Criteria (CC/ISO 15408) with Evaluation Assurance Levels (EAL1-EAL7).


8. Network Security

Firewalls:

  • Definition: A network security device (hardware/software) that monitors and controls incoming/outgoing network traffic based on predetermined security rules.

  • Working Mechanism: Acts as a gatekeeper at network boundary. Enforces access control policy by inspecting packet headers (and sometimes payload) against rule set (ACL).

  • Types with Diagrams:

    • Packet Filtering Firewall:

      DiagramCANVAS: Simple router with ACL list checking source/dest IP, port, protocol. Stateless. Fast but limited.

    • Stateful Inspection Firewall:

      DiagramCANVAS: Tracks connection state (SYN, ESTABLISHED, FIN). Maintains state table. More secure than stateless.

    • Proxy Firewall (Application-Level Gateway):

      DiagramCANVAS: Client connects to proxy, proxy connects to server. Proxy inspects application-layer data (HTTP, FTP). Hides internal network. Can be slow.

    • Next-Generation Firewall (NGFW):

      DiagramCANVAS: Combines stateful inspection with deep packet inspection (DPI), intrusion prevention (IPS), application awareness/control, and threat intelligence feeds.

Intrusion Detection Systems (IDS):

  • Definition: A device or software that monitors network or system activity for malicious actions or policy violations and reports/acts upon them.

  • Types:

    • NIDS (Network-based): Monitors network traffic (e.g., Snort).

    • HIDS (Host-based): Monitors a single host (logs, file integrity - Tripwire).

  • Detection Methods:

    • Signature-based: Looks for known attack patterns (signatures). High accuracy, low false positives, but zero-day blind.

    • Anomaly-based: Establishes baseline of "normal" activity, flags deviations. Can detect new attacks, but high false positives.

  • Benefits:

    1. Detection: Identifies attacks that bypass firewalls.

    2. Deterrence: Knowledge of IDS may deter attackers.

    3. Information: Provides data for forensic analysis and improving defenses.

Denial-of-Service (DoS) & Distributed DoS (DDoS):

  • Mechanisms:

    • Volumetric: Flood network with traffic (UDP flood, ICMP flood) to consume bandwidth.

    • Protocol: Exploit protocol weaknesses (SYN flood, Ping of Death) to consume server resources (connection tables).

    • Application Layer: Target specific application (HTTP flood, Slowloris) to exhaust CPU/memory.

  • DDoS: Attack originates from many compromised hosts (botnet) simultaneously. Much harder to block.

  • Mitigation:

    • Rate limiting at network edge.

    • SYN cookies for SYN flood.

    • Blackholing / Sinkholing traffic.

    • Anycast networks to distribute load.

    • Cloud-based DDoS protection services (scrubbing centers).

Secure Tunnels and VPNs:

  • Concept: An encrypted "pipe" through an untrusted network (like the internet) that provides confidentiality, integrity, and sometimes authentication for the traffic inside.

  • Protocols:

    • IPsec (Layer 3): Secures IP packets. Operates in Transport (payload only) or Tunnel (entire packet) mode. Uses AH (authentication) or ESP (confidentiality+auth).

    • SSL/TLS VPN (Layer 4/5): Uses SSL/TLS to secure application traffic. Often clientless (browser-based). Easier to deploy through firewalls.

    • SSH Tunnel: Port forwarding over SSH connection.

IP Security (IPsec):

  • Components:

    • AH (Authentication Header): Provides data origin authentication, integrity, and anti-replay. No confidentiality.

    • ESP (Encapsulating Security Payload): Provides confidentiality (encryption), data origin authentication, integrity, and anti-replay.

    • IKE (Internet Key Exchange): Protocol for negotiating Security Associations (SAs) and keys. IKEv1/v2.

    • SA (Security Association): A one-way logical connection specifying security protocols, keys, and SPI (Security Parameter Index).

  • Modes:

    • Transport Mode: Protects payload of original IP packet. Used for end-to-end (host-to-host).

    • Tunnel Mode: Encapsulates entire original IP packet in new IP header. Used for site-to-site VPNs (gateway-to-gateway).

SSL/TLS Overview:

  • Purpose: Provide secure communication over TCP/IP (primarily for web - HTTPS).

  • Handshake (Simplified):

    1. ClientHello: Client sends supported cipher suites, TLS version, random.

    2. ServerHello: Server chooses cipher suite, sends its certificate (with public key), random.

    3. Key Exchange: Client verifies cert, generates pre-master secret, encrypts with server's public key, sends.

    4. Session Keys: Both derive master secret from pre-master + randoms. Then derive symmetric session keys for encryption/MAC.

    5. Finished: Exchange encrypted "Finished" messages to verify handshake integrity.

  • Provides: Server authentication (via certificate), optional client authentication, confidentiality (symmetric encryption), integrity (MAC).


9. Application and Web Security

Web Application Vulnerabilities (OWASP Top 10):

  • SQL Injection (SQLi):

    • Mechanism: Attacker inserts malicious SQL code into input fields that are concatenated into backend queries. ' OR '1'='1 bypasses login.

    • Prevention:

      • Use Prepared Statements (Parameterized Queries). Most effective.

      • Stored Procedures (if not concatenating).

      • Input Validation (whitelist, not blacklist).

      • Principle of Least Privilege for DB accounts.

      • Escaping user input (last resort).

  • Cross-Site Scripting (XSS):

    • Mechanism: Attacker injects malicious scripts (usually JavaScript) into web pages viewed by others. Types: Stored (DB), Reflected (URL), DOM-based.

    • Prevention:

      • Output Encoding: Encode user-supplied data before rendering in HTML/JS context (e.g., < → &lt;). Context-aware encoding is critical.

      • Content Security Policy (CSP): Whitelist sources for scripts, styles, etc.

      • Input Validation (as defense-in-depth).

      • HttpOnly flag on cookies to prevent theft via XSS.

Malware: Viruses vs. Worms:

Feature Virus Worm
Replication Requires host program (executable file, boot sector). Standalone program. Self-replicating.
Propagation Needs human action (run infected program, share file). Automatic over network (exploiting vulnerabilities, email).
Primary Goal Corrupt, modify, delete files; display messages. Spread rapidly, create botnets, launch DDoS, deliver payloads.
Example File infector, macro virus (Word), boot sector. Code Red, SQL Slammer, WannaCry (had worm component).

Virus Types:

  • File Infector: Attaches to .exe, .com files.

  • Macro Virus: Infects macro-enabled documents (Word, Excel).

  • Boot Sector Virus: Infects master boot record (MBR).

  • Polymorphic Virus: Changes its code (encryption/mutation) to avoid signature detection.

  • Metamorphic Virus: Rewrites its entire code each generation.

  • Stealth Virus: Hides its presence from AV (intercepts system calls).

Malware Countermeasures:

  • Prevention: User education, least privilege, patch management, disable macros, email filtering, web filtering, application whitelisting.

  • Detection: Antivirus/Antimalware (signature + heuristic/behavioral), HIDS.

  • Response: Isolate infected machine, analyze, remove malware, restore from backup, patch vulnerability.

Secure Electronic Transaction (SET):

  • Goal: Secure credit card transactions over the internet.

  • Protocol & Security:

    • Uses dual signature: Customer signs once for merchant, once for bank, links them.

    • Parties: Customer, Merchant, Bank (Acquirer), Certification Authority (CA).

    • Process:

      1. Customer gets certificates from CA (bank & merchant certs).

      2. Order & Payment sent separately: Order Info (merchant) + Payment Info (bank), linked by dual signature.

      3. Merchant verifies order, gets authorization from bank.

      4. Merchant fulfills order, bank settles.

    • Security: Confidentiality (payment info only for bank), Integrity, Authentication (all parties), Non-repudiation.

Pretty Good Privacy (PGP):

  • Components & Services (Email Security):

    • Cryptographic Key Management: Uses Web of Trust (decentralized) instead of PKI hierarchy.

    • Digital Signatures: For authentication & non-repudiation (RSA/DSA + SHA).

    • Confidentiality: Symmetric session key (IDEA/Cast5) encrypted with receiver's public key (RSA/ElGamal).

    • Compression: Applied before encryption (ZIP).

    • Radix-64 Conversion (ASCII Armor): Encodes binary data to text for email.

  • How it Works (Sending):

    1. Sign message with private key.

    2. Compress.

    3. Generate random session key.

    4. Encrypt compressed message with session key.

    5. Encrypt session key with receiver's public key.

    6. Prepend receiver's key ID, sender's key ID, timestamp.

    7. Radix-64 encode entire block.

Diagram Requested: Block diagram showing: [Plaintext] → [Sign] → [Compress] → [Encrypt with Session Key] → [Encrypt Session Key with Receiver Pub Key] → [Combine + Key IDs] → [Radix-64] → [Email].


10. Enterprise Security and Protocols

Kerberos:

  • Requirements: Secure authentication over insecure network; mutual authentication; limited trust in third party; scalability.

  • Versions: Kerberos v4 (uses DES, no realm concept), Kerberos v5 (standard, uses AES, supports realms, cross-realm, renewable tickets).

  • Why Double Encryption? In the Authenticator (encrypted with session key) and the Ticket (encrypted with server's key). The ticket contains the session key and client ID. The authenticator contains client ID and timestamp. The server decrypts ticket first to get session key, then uses that to decrypt authenticator. This provides:

    1. Confidentiality of session key (only server can get it from ticket).

    2. Integrity & Timeliness of authenticator (prevent replay).

    3. Mutual Authentication (server can reply with an authenticator encrypted with session key).

Public Key Infrastructure (PKI): Six Components:

  1. Certificate Authority (CA): Trusted entity that issues and revokes digital certificates.

  2. Registration Authority (RA): Verifies identity of certificate applicants before CA issues cert. Front-end for CA.

  3. Certificate Repository: Directory (e.g., LDAP) where certificates and CRLs are stored/retrieved.

  4. Certificate Revocation List (CRL): List of certificates revoked before expiry (signed by CA).

  5. Online Certificate Status Protocol (OCSP): Real-time protocol to query certificate status (revoked/valid/unknown). More timely than CRL.

  6. PKI Clients/Applications: Software that uses certificates (browsers, email clients).

Web Security Basics:

  • Cookies: Small pieces of data stored by browser. Types: Session (in-memory, deleted on close), Persistent (saved to disk, has expiry). Security Flags: Secure (HTTPS only), HttpOnly (not accessible to JS), SameSite (CSRF mitigation).

  • HTTP vs HTTPS: HTTP = plaintext (port 80). HTTPS = HTTP over TLS/SSL (port 443). Provides encryption, server authentication, integrity.

  • URL vs URI:

    • URI (Uniform Resource Identifier): Generic identifier for a resource (e.g., mailto:[email protected], urn:isbn:0451450523).

    • URL (Uniform Resource Locator): Subset of URI that specifies how and where to retrieve a resource (protocol + location). e.g., https://www.example.com/index.html.

Enterprise Security Specifications (Key Elements):

  1. Security Policy Framework: Overall governance.

  2. Risk Management Process: Identify, assess, treat risks.

  3. Access Control Policy: DAC/MAC/RBAC definitions.

  4. Network Security Architecture: Firewalls, IDS/IPS, segmentation.

  5. Cryptography Policy: Algorithms, key lengths, certificate usage.

  6. Incident Response Plan: Roles, procedures, communication.

  7. Business Continuity/Disaster Recovery: Backup, recovery strategies.

  8. Compliance & Auditing: Meet regulations (GDPR, HIPAA), regular audits.

  9. Security Awareness Training: For all employees.

  10. Physical Security: Controls for facilities, hardware.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in