Skip to content
IT-801 ยท Information Security/Quick Revision Short Notes

Information Security (IT-801) - Unit 2 Short Notes

UNIT 2: Information Security - Comprehensive Short Notes


I. FOUNDATIONAL CONCEPTS & SECURITY PRINCIPLES

Core Security Concepts

  • Threat: Potential negative action or event enabled by a vulnerability that causes harm.

  • Attack: Active assault on system integrity, availability, or confidentiality.

  • Vulnerability: Weakness in a system that can be exploited by a threat.

  • Risk: Likelihood of a threat exploiting a vulnerability and the impact.

    Relationship: A threat exploits a vulnerability to launch an attack, resulting in risk realization.

  • Security vs. Protection (Dec 2024)

    • Security: Broader concept encompassing policies, procedures, and controls to protect assets from all threats (including external, internal, accidental). Focus on assurance.

    • Protection: Subset of security. Focuses on mechanisms (like access controls, encryption) to enforce security policies and guard against unauthorized access.

  • Critical Characteristics of Information (CIA Triad +)

    | Characteristic | Definition | Example | | :--- | :--- | :--- | | Confidentiality | Ensuring information is not disclosed to unauthorized entities. | Encryption, access controls. | | Integrity | safeguarding accuracy/completeness from unauthorized alteration. | Hash functions, MACs, digital signatures. | | Availability | Ensuring information/services are accessible when needed. | Redundancy, backups, DDoS mitigation. | | Authentication | Verifying identity of user/process/origin. | Passwords, digital certificates. | | Non-Repudiation | Preventing sender/receiver from denying participation. | Digital signatures, logging. |

  • Fabrication, Interception, Modification, Repudiation (FIMR) (May 2024)

    • Fabrication: Creating false data/objects (e.g., fake credentials).

    • Interception: Eavesdropping on communication (confidentiality breach).

    • Modification: Altering data (integrity breach).

    • Repudiation: Denying an action (non-repudiation breach).

Security Policy & Management

  • Security Policy: Formal statement of management's intent to protect assets. Purpose: Sets direction, assigns responsibility, defines acceptable use.

  • Key Components (Dec 2024):

    1. Purpose & Scope: Why policy exists, what it covers.

    2. Roles & Responsibilities: Who is accountable.

    3. Risk Assessment: Identified threats/vulnerabilities.

    4. Access Control Policy: Rules for authorization.

    5. Incident Response: Procedures for breaches.

    6. Compliance & Enforcement: Consequences for violations.

  • Enterprise Security Specifications: Detailed technical standards and procedures derived from the high-level policy (e.g., "All laptops must use AES-256 encryption").

  • Security Life Cycle (Dec 2024):

    1. Policy: Define requirements.

    2. Implementation: Deploy controls (tech, procedures).

    3. Evaluation/Audit: Test effectiveness, check compliance.

    4. Maintenance: Update for new threats, patch systems.

  • Trust and Assumptions: Security systems rely on assumptions (e.g., "kernel is trusted"). Trust is placed in specific components (Trusted Computing Base - TCB). Compromise of TCB breaks entire system security.

System Security Principles & Models

  • Principle of Least Privilege: Grant users/programs only the minimum privileges needed. Reduces attack surface.

  • Information Flow Control: Policies that control how information moves between subjects/objects with different security levels (e.g., in MAC systems). Prevents unauthorized flows (e.g., from high to low).

  • Confinement Problem: Ensuring a program cannot leak data outside its execution environment (e.g., via covert channels). Mitigation: Sandboxing, capability systems, rigorous code review.

  • Malicious Logic: Software designed to perform unauthorized functions (viruses, trojans, logic bombs). Impact: Data theft, corruption, service disruption.


II. CRYPTOGRAPHY: CLASSICAL & MATHEMATICAL FOUNDATIONS

Classical Encryption Techniques

  • Substitution Cipher: Replaces plaintext elements with ciphertext elements.

    • Caesar Cipher: Shift each letter by fixed k positions (mod 26).

      • Encryption: $$\displaystyle C = (P + k) \bmod 26 $$

      • Decryption: $$\displaystyle P = (C - k) \bmod 26 $$

      • Example (key=1): Plaintext L โ†’ Ciphertext M.

    • Playfair Cipher (Jun 2025):

      1. Construct 5x5 matrix with keyword (I/J combined).

      2. Rules: Same row โ†’ shift right; same column โ†’ shift down; rectangle โ†’ swap corners.

      3. Example: Plaintext BALLOON โ†’ digraphs BA LX LO ON โ†’ Ciphertext IB YQ MQ....

  • Transposition Cipher: Rearranges plaintext elements without substitution (e.g., columnar transposition).

Steganography vs. Cryptography

Feature Steganography Cryptography
Goal Hide existence of message. Hide meaning of message.
Method Embed message in cover medium (image, audio). Transform message via algorithm & key.
Security Secrecy depends on obscurity of hiding method. Security depends on key secrecy & algorithm strength.
Use Case Covert communication where encryption itself is suspicious. General-purpose confidentiality.
Strength No secret key required for basic hiding. Provable security based on math problems.
Weakness If hiding method discovered, message revealed. Ciphertext is obvious, attracts cryptanalysis.

Cryptographic Mathematics

  • Modular Arithmetic: $a \bmod n$ = remainder of $a/n$.

    • Example (May 2024): $$\displaystyle 75 \bmod 119 = 75 $$, $$\displaystyle 89 \bmod 119 = 89 $$.
  • Euler's Totient Function ฯ†(n) (May 2023): Counts integers โ‰ค n coprime to n.

    • For prime $p$: $$\displaystyle \phi(p) = p-1 $$.

    • For $$\displaystyle n = p \times q $$ (primes): $$\displaystyle \phi(n) = (p-1)(q-1) $$.

  • Primitive Root (mod p) (May 2024): Number $\alpha$ whose powers generate all residues 1 to p-1.

    • For p=5: $$\displaystyle \alpha=2 $$ (powers: 2,4,3,1). $$\displaystyle \alpha=3 $$ also works.

    • For p=11: $$\displaystyle \alpha=2 $$ (powers: 2,4,8,5,10,9,7,3,6,1).

  • RSA Mathematical Foundation (May 2023):

    • Based on factoring problem: Given $$\displaystyle n = p \times q $$, hard to find $p,q$.

    • Euler's Theorem: $$\displaystyle m^{\phi(n)} \equiv 1 \pmod{n} $$ if $$\displaystyle \gcd(m,n)=1 $$.

    • Key Generation:

      1. Choose primes $p,q$. Compute $$\displaystyle n=pq $$, $$\displaystyle \phi(n)=(p-1)(q-1) $$.

      2. Choose $e$ such that $$\displaystyle 1 < e < \phi(n) $$, $$\displaystyle \gcd(e,\phi(n))=1 $$.

      3. Compute $$\displaystyle d \equiv e^{-1} \pmod{\phi(n)} $$.

      4. Public Key: $(e,n)$, Private Key: $(d,n)$.


III. SYMMETRIC KEY CRYPTOGRAPHY

Block Ciphers

  • Definition: Encrypts fixed-size blocks of plaintext (e.g., 128 bits) into ciphertext blocks using a key.

  • Design Principles (Jun 2025):

    • Confusion: Makes relationship between ciphertext and key complex (via S-boxes/substitution).

    • Diffusion: Spreads plaintext influence over many ciphertext bits (via permutations/transpositions).

    Goal: Each ciphertext bit depends on many key bits (confusion) and many plaintext bits (diffusion).

Modes of Operation (May 2024)

Mode How it Works IV Needed? Main Use Case
ECB Encrypt each block independently. No Rarely used (pattern leakage).
CBC XOR plaintext block with previous ciphertext block before encrypting. Yes General-purpose, storage.
CFB Encrypt previous ciphertext, XOR with plaintext to get new ciphertext. Yes Stream data (e.g., network).
OFB Generate keystream by repeatedly encrypting IV. XOR keystream with plaintext. Yes Stream data, error resilience.
CTR Encrypt counter value, XOR with plaintext. Counter increments. Yes High-speed, parallelizable.

Why ECB is rarely used (Jun 2025): Identical plaintext blocks produce identical ciphertext blocks. Reveals data patterns in ciphertext (e.g., visible structure in encrypted image).

Data Encryption Standard (DES)

  • Overview: 16-round Feistel network. 64-bit block, 56-bit key (+8 parity bits).

  • S-Boxes Purpose (Jun 2025): Provide confusion. 8 substitution boxes take 6-bit input, output 4-bit. Non-linear mapping resists differential cryptanalysis.

  • Avalanche Effect (Jun 2025): Small change in plaintext/key causes drastic (~50%) change in ciphertext. Demonstrated in DES by differing outputs after one S-box input change.

Advanced Encryption Standard (AES)

  • Steps (per round except last) (Jun 2025):

    1. Byte Substitution (SubBytes): Non-linear substitution via S-box (confusion).

    2. Shift Rows: Cyclically shift rows of state matrix (diffusion).

    3. Mix Columns: Linear mixing of columns (diffusion).

    4. Add Round Key: XOR state with round key.

    • Final Round: Omits Mix Columns.
  • Key Expansion/Key Schedule (May 2024):

    • Expands 128/192/256-bit key into array of 44/52/60 32-bit words.

    • Uses RotWord (rotate word), SubWord (S-box), and Rcon (round constant) operations.

    • Each round key is derived from previous words.


IV. ASYMMETRIC KEY CRYPTOGRAPHY & KEY MANAGEMENT

Core Concepts & Comparison

Feature Symmetric (Private Key) Asymmetric (Public Key)
Key Same secret key for encryption/decryption. Public key (encrypt/sign), Private key (decrypt/verify).
Key Management Difficult (n users โ†’ n(n-1)/2 keys). Easy (n users โ†’ 2n keys).
Speed Fast (hardware efficient). Slow (math intensive).
Primary Use Bulk data encryption. Key exchange, digital signatures, small data.
Algorithms AES, DES, 3DES, Blowfish. RSA, ECC, ElGamal, Diffie-Hellman (KE).

RSA Algorithm

  • Encryption: $$\displaystyle C = P^e \bmod n $$

  • Decryption: $$\displaystyle P = C^d \bmod n $$

  • Example (Jun 2025, May 2024): Given $$\displaystyle e=3, d=11, n=15 $$. Plaintext $$\displaystyle P=2 $$ โ†’ $$\displaystyle C=2^3 \bmod 15 = 8 $$. Decrypt: $$\displaystyle 8^{11} \bmod 15 = 2 $$.

  • Attacks (Jun 2025):

    • Factoring Attack: Factor $n$ to get $\phi(n)$, then $d$.

    • Chosen Ciphertext Attack (e.g., Bleichenbacher): Attacker decrypts chosen ciphertexts.

    • Timing Attack: Measures decryption time to infer $d$.

Key Exchange Protocols

  • Diffie-Hellman Key Exchange (Jun 2025, May 2024):

    1. Agree on prime $q$ and primitive root $\alpha$.

    2. A chooses private $$\displaystyle X_A $$, sends $$\displaystyle Y_A = \alpha^{X_A} \bmod q $$.

    3. B chooses private $$\displaystyle X_B $$, sends $$\displaystyle Y_B = \alpha^{X_B} \bmod q $$.

    4. Shared key: $$\displaystyle K = Y_B^{X_A} \bmod q = Y_A^{X_B} \bmod q $$.

    • Example (q=11, ฮฑ=7, X_A=3, X_B=6):

      • $$\displaystyle Y_A = 7^3 \bmod 11 = 343 \bmod 11 = 2 $$.

      • $$\displaystyle Y_B = 7^6 \bmod 11 = 117649 \bmod 11 = 4 $$.

      • $$\displaystyle K = 4^3 \bmod 11 = 64 \bmod 11 = 9 $$ (or $$\displaystyle 2^6 \bmod 11 = 64 \bmod 11 = 9 $$).

    • Vulnerability: Man-in-the-Middle (MitM). Attacker intercepts $$\displaystyle Y_A, Y_B $$, establishes separate keys with each party.

  • Kerberos (Jun 2025):

    • Purpose: Network authentication protocol using symmetric keys and a trusted third party (KDC).

    • Need for Double Encryption:

      1. Ticket: Encrypted with server's key. Contains client ID & session key.

      2. Authenticator: Encrypted with session key. Contains client ID & timestamp.

      • Why? Ticket proves client's identity to KDC; Authenticator proves client's current presence to server (prevents replay).
    • Versions: v4 (uses DES, IP addresses), v5 (improved, supports multiple encryption types, realms).

Pretty Good Privacy (PGP) (May 2024)

  • Provides Confidentiality & Authentication:

    1. Confidentiality: Generate random session key. Encrypt message with session key (symmetric, e.g., AES). Encrypt session key with recipient's public key (RSA). Send both.

    2. Authentication (Digital Signature): Hash message. Sign hash with sender's private key. Attach signature.

  • Block Diagram Components:

    
    [Plaintext] โ†’ [Hash] โ†’ [Sign with Priv Key] โ†’ [Signature]
    
                โ†“
    
    [Session Key] โ†’ [Encrypt Msg] โ†’ [Encrypted Msg]
    
                โ†“
    
    [Encrypt Session Key with Recipient Pub Key]
    
                โ†“
    
    [Send: Encrypted Msg + Encrypted Session Key + Signature]
    
    

V. HASH FUNCTIONS, MESSAGE AUTHENTICATION & DIGITAL SIGNATURES

Hash Functions

  • Properties:

    • Pre-image Resistance: Given hash $h$, hard to find $m$ such that $$\displaystyle hash(m)=h $$.

    • Second Pre-image Resistance: Given $$\displaystyle m_1 $$, hard to find $$\displaystyle m_2 \neq m_1 $$ with same hash.

    • Collision Resistance: Hard to find any two messages $$\displaystyle m_1, m_2 $$ with same hash.

  • Common Algorithms: SHA-256, SHA-3 (secure); MD5, SHA-1 (broken, collisions found).

  • Why Hashing Alone Does NOT Ensure Integrity in Network Comms? (Jun 2025)

    Attacker can intercept message, compute hash, modify message, compute new hash, and send both. Receiver has no way to know if hash came from original sender. Need a secret key (MAC) or digital signature to authenticate the hash.

Message Authentication Code (MAC)

  • Definition: Short tag generated from message + secret key. Provides authentication (proof of origin) and integrity.

  • How MAC Achieves Authentication & Confidentiality? (Jun 2025):

    • Authentication: Only parties with secret key can generate valid MAC.

    • Confidentiality: Not provided by MAC alone. Achieved by combining with encryption.

      • Standard Approach: Encrypt-then-MAC.

        1. Encrypt plaintext โ†’ ciphertext.

        2. Compute MAC over ciphertext using shared key.

        3. Send ciphertext + MAC.

      • Receiver verifies MAC first (authenticity), then decrypts (confidentiality).

Digital Signatures

  • Process:

    1. Sender hashes message: $$\displaystyle h = H(m) $$.

    2. Sender encrypts hash with own private key: $$\displaystyle S = h^d \bmod n $$ (RSA).

    3. Sends $(m, S)$.

  • Receiver:

    1. Hashes received $m$: $$\displaystyle h' = H(m) $$.

    2. Decrypts signature with sender's public key: $$\displaystyle h'' = S^e \bmod n $$.

    3. If $$\displaystyle h' = h'' $$, signature is valid.

  • Role: Provides authentication (only sender has priv key), integrity (hash changes if msg altered), non-repudiation (sender cannot deny signature).


VI. ACCESS CONTROL MODELS & SYSTEM SECURITY

Access Control Models

Model Control Based On Key Mechanism Example
DAC Owner's discretion. Subject passes access rights to others. Permission bits (rwx), ACLs. Unix file permissions (chmod).
MAC System-enforced policy. Security labels (e.g., Top Secret). Mandatory labels, no override by user. Military systems, SELinux enforcing mode.
RBAC (Dec 2024) Roles (job functions). Users assigned roles, roles assigned permissions. Role hierarchy, sessions. Enterprise: Manager, Clerk roles.
TBAC (Dec 2024) Tasks/Workflows. Permissions dynamic, based on current task. Task activation/deactivation. Workflow systems (e.g., loan approval: VerifyDocs โ†’ Approve).

RBAC Enhancement in Large Orgs: Simplifies administration (assign roles, not per-user permissions). Supports least privilege and separation of duties.

Operating System Security

  • Linux Security Architecture (Dec 2024):

    • Trusted Path: Secure channel between user & OS (e.g., login prompt).

    • Capabilities: Fine-grained privileges (e.g., CAP_NET_ADMIN) vs. all-or-nothing root.

    • SELinux/AppArmor: Mandatory Access Control frameworks. Enforce security policies (type enforcement/SELinux, path-based/AppArmor) beyond DAC.

    • User/Group Permissions: Traditional DAC (UID/GID, rwx bits).

  • Windows OS Security Features (Dec 2024):

    • User Account Control (UAC): Requires consent/elevation for privileged actions.

    • Security Identifiers (SIDs): Unique IDs for users/groups.

    • Integrity Levels & MIC: Mandatory Integrity Control. Low/Medium/High integrity labels prevent lower-integrity processes from modifying higher-integrity objects (e.g., browser can't modify system files).

Database Security

  • Database Auditing (Dec 2024):

    • Purpose: Track who accessed/changed what data and when. For compliance, breach investigation, detecting anomalies.

    • How it Secures: Provides accountability (deterrence), detects policy violations, supports forensic analysis. Logs SQL statements, user IDs, timestamps.


VII. NETWORK SECURITY DEFENSES

Firewalls (May 2024)

  • Definition: Device/software that filters network traffic based on rule set (ACL).

  • Three Common Types:

    1. Packet-Filtering Firewall:

      • Operates at Network/Transport layer.

      • Checks source/dest IP, port, protocol.

      • Diagram: Simple rule check on each packet.

    2. Stateful Inspection Firewall:

      • Tracks connection state (e.g., TCP handshake).

      • Allows return traffic for established connections.

      • Diagram: State table tracking connections.

    3. Application-Level Gateway (Proxy):

      • Operates at Application layer.

      • Intercepts & evaluates application-specific commands (e.g., HTTP GET/POST).

      • Diagram: Client โ†” Proxy โ†” Server; Proxy terminates connections.

  • How Firewall Works: Applies rule set (e.g., ALLOW TCP from ANY to WEB_SERVER port 80) to each packet/connection.

Intrusion Detection Systems (IDS) (May 2024, Jun 2025)

  • Purpose: Monitor network/host for malicious activity/policy violations. Detects, does not prevent (that's IPS).

  • Three Benefits (May 2024):

    1. Detection: Identify attacks in progress.

    2. Deterrence: Knowledge of IDS may discourage attackers.

    3. Information Gathering: Provide data for forensic analysis, improve defenses.

  • Types:

    • NIDS (Network-based): Monitors network traffic (e.g., Snort).

    • HIDS (Host-based): Monitors system logs, file integrity on a host.

    • Signature-based: Looks for known attack patterns.

    • Anomaly-based: Detects deviations from normal baseline.

Trusted Systems (Jun 2025 - Short Note)

  • Definition: System evaluated against security criteria (e.g., TCSEC/Orange Book) to ensure it enforces security policy.

  • TCSEC Security Levels (A1 (highest) to D (lowest)):

    • A1/A2/B1/B2/B3/C1/C2/D: Increasing assurance, formal verification, access control, auditing requirements.
  • Trusted Computing Base (TCB): All hardware, software, firmware responsible for enforcing security policy. Minimal TCB is desirable.


VIII. MALWARE, ATTACKS & WEB APPLICATION SECURITY

Malware

  • Virus vs. Worm (Dec 2024, May 2023):

    | Feature | Virus | Worm | | :--- | :--- | :--- | | Propagation | Needs host file/program to spread (user action). | Self-replicating, spreads via network/email without user action. | | Primary Goal | Infect, modify, corrupt files. | Consume resources, create botnets, deliver payloads. | | Example | File infector, macro virus. | Code Red, SQL Slammer. |

  • Virus-Related Threats & Countermeasures (May 2024):

    • Threats: File corruption, data theft, boot sector damage, macro exploits.

    • Countermeasures: Antivirus (signature/heuristic), patching OS/apps, user awareness, disable macros, least privilege.

  • DoS & DDoS Attacks (Dec 2024, May 2024):

    • DoS: Deny service to single target (e.g., SYN flood, Ping of Death).

    • DDoS: Coordinated attack from multiple compromised hosts (botnet). Overwhelms target with traffic.

Web Application Vulnerabilities

  • SQL Injection (SQLi) (May 2023):

    • How it works: Attacker injects malicious SQL code via input fields. Executed by database.

      • Example: Input ' OR '1'='1 bypasses login.
    • Prevention:

      1. Prepared Statements (parameterized queries).

      2. Input Validation (whitelisting).

      3. Least Privilege (DB user has minimal permissions).

      4. Escaping/encoding user input.

  • Cross-Site Scripting (XSS) (May 2023):

    • How it works: Inject malicious scripts (JS) into web pages viewed by others.

    • Types:

      • Reflected: Script in URL, reflected by server (phishing).

      • Stored: Script stored on server (comments, DB) - affects all visitors.

      • DOM-based: Script manipulates DOM via client-side JS.

    • Prevention: Input validation, output encoding (e.g., htmlspecialchars), CSP headers.

Related Web Concepts

  • Cookies (May 2023):

    • Purpose: Session management (store session ID), personalization, tracking.

    • Security Concerns: Theft (XSS, sniffing), Manipulation (tampering with values). Use HttpOnly, Secure, SameSite flags.

  • URL vs. URI (May 2023):

    • URI (Uniform Resource Identifier): Generic identifier for a resource (can be name or locator).

    • URL (Uniform Resource Locator): Subset of URI that specifies how/where to retrieve a resource (locator).

      • Example: https://example.com/page.html (includes protocol, host, path).
    • Key Difference: All URLs are URIs, but not all URIs are URLs.

  • HTTP (May 2023): Application-layer request-response protocol. Stateless. Forms basis of web communication. Insecure by default (no encryption, integrity).


IX. SECURITY AUDITING, FORENSICS & PROTOCOLS

Vulnerability Analysis & Forensics

  • Vulnerability Analysis (Dec 2024):

    • Definition: Process of identifying, quantifying, and prioritizing security weaknesses in systems.

    • Importance in Security Auditing: Provides evidence of security gaps, assesses risk, drives remediation, ensures compliance.

  • Forensic Analysis on Compromised Server (Dec 2024):

    1. Preservation: Secure evidence (disk images, memory dumps, logs) - maintain chain of custody.

    2. Identification: Determine scope of compromise (what systems, data affected).

    3. Collection: Gather relevant logs, files, network captures.

    4. Analysis: Timeline reconstruction, malware analysis, root cause determination.

    5. Reporting: Document findings, impact, recommendations.

Security Protocols & Standards

  • SSL/TLS (May 2024):

    • Purpose: Provide confidentiality (encryption), authentication (certificates), integrity (MAC) for web traffic (HTTPS).

    • Basic Operation: Handshake (negotiate cipher, authenticate server via cert, generate session key) โ†’ Record protocol (encrypt/decrypt data).

  • Secure Electronic Transaction (SET) (May 2024):

    • Purpose: Secure credit card transactions over internet.

    • How Achieved:

      1. Dual Signatures: Customer signs order & payment info separately, links them. Merchant sees order, bank sees payment - neither sees full details.

      2. Certificates: All parties (customer, merchant, bank) have X.509 certificates.

      3. Confidentiality: Payment info encrypted for bank only.

  • IP Security (IPSec) (May 2023):

    • Basic Components:

      • AH (Authentication Header): Provides integrity/authentication for IP payload (but not confidentiality). Protects against replay.

      • ESP (Encapsulating Security Payload): Provides confidentiality (encryption), integrity, authentication.

      • IKE (Internet Key Exchange): Negotiates SA (Security Association) parameters and keys.


X. FREQUENTLY ASKED COMPARISONS & JUSTIFICATIONS

  • Steganography vs. Encryption: Steganography hides existence; encryption hides meaning. Stego relies on obscurity; crypto relies on key secrecy.

  • Security vs. Protection: Security is the overall discipline (policy, risk, controls). Protection is the implementation of specific technical controls.

  • Public Key vs. Private Key Cryptography: Public key uses key pairs, solves key distribution, is slow. Private key uses shared secret, is fast, has key management issues.

  • DAC vs. MAC: DAC is discretionary (owner-controlled, e.g., Unix perms). MAC is mandatory (system-enforced labels, e.g., military).

  • Virus vs. Worm: Virus needs host/user action; worm self-replicates via network.

  • URL vs. URI: URL is a locator (how to get resource); URI is any identifier (name or locator).

  • Justification: "Hashing does not ensure integrity in network comms" (Jun 2025): Hashing alone provides no authentication. Attacker can modify message and recompute hash. Integrity requires MAC (shared secret) or digital signature (asymmetric) to authenticate the hash.

  • Justification: "Why ECB is rarely used" (Jun 2025): ECB is deterministic - same plaintext block โ†’ same ciphertext block. Reveals data patterns (e.g., in images, repeated fields), violating semantic security.

  • Justification: "Why double encryption in Kerberos?" (Jun 2025):

    1. First Encryption (Ticket): Protects session key & client ID from server (only server can decrypt with its key). Authenticates client to KDC.

    2. Second Encryption (Authenticator): Proves client's liveness to server (timestamp) and binds session key to current session. Prevents replay attacks.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in