Skip to content
IT-801 · Information Security/Quick Revision Short Notes

Information Security (IT-801) - Unit 4 Short Notes

1.0 FOUNDATIONAL SECURITY CONCEPTS & PRINCIPLES

1.1 Core Terminology & Characteristics

  • Threat: Potential cause of an incident that may result in harm.

  • Attack: Attempt to compromise security (confidentiality, integrity, availability).

  • Vulnerability: Weakness that can be exploited.

  • Risk: Likelihood of threat exploiting vulnerability and impact.

Security Attacks:

  • Passive: Eavesdropping, Traffic Analysis (no alteration).

  • Active: Masquerade, Replay, Modification, Denial-of-Service (alteration/disruption).

Critical Characteristics of Information:

Characteristic Definition
Confidentiality Prevent unauthorized access.
Integrity Ensure accuracy and completeness.
Availability Accessible when needed.
Authentication Verify identity.
Non-Repudiation Prevent denial of actions.
Accountability Trace actions to individuals.

[!TIP] Exams often ask to differentiate passive vs active attacks with examples.

1.2 Security Policy & Management

  • Security Policy: Document defining rules, procedures, and guidelines for protecting assets.

  • Key Components:

    • Purpose and scope

    • Roles and responsibilities

    • Acceptable use

    • Access control policy

    • Incident response

    • Compliance requirements

  • Security Life Cycle:

    1. Planning: Identify assets, risks, define policy.

    2. Implementation: Deploy controls, train users.

    3. Operation: Monitor, maintain, update.

    4. Review/Disposal: Audit, assess, decommission securely.

  • Enterprise Security Specifications: Aligns policy with business goals, risk management, and compliance.

1.3 Trust & Assumptions

  • Trust: Confidence that a system operates as intended despite adversarial conditions.

  • Fundamental Security Assumptions: E.g., "The kernel is trusted," "Physical security is in place."

  • Confinement Problem: Preventing unauthorized information flow from trusted to untrusted contexts.

    • Mitigation: Sandboxing, capability systems, information flow control.
  • Principle of Least Privilege: Grant minimal permissions necessary. In information flow control, restrict data access to prevent leakage.

[!TIP] Common exam question: Explain confinement problem with example (e.g., Trojan horse leaking data).

2.0 CRYPTOGRAPHY (SYMMETRIC & ASYMMETRIC)

2.1 Symmetric Cipher Fundamentals

Model:

Plaintext $\xrightarrow{\text{Encryption (Algo + Key)}}$ Ciphertext $\xrightarrow{\text{Decryption (Algo + Key)}}$ Plaintext.

Substitution Techniques:

  • Caesar Cipher: Shift each letter by fixed key (e.g., key=3: A→D).

  • Playfair Cipher:

    • Matrix Construction: 5x5 grid with keyword (I/J combined). Fill remaining letters.

    • Encryption Steps:

      1. Split plaintext into digraphs (pad with X if needed).

      2. For each pair:

        • Same row: Replace with next in row (wrap).

        • Same column: Replace with below (wrap).

        • Rectangle: Swap columns.

    • Example: Keyword "MONARCHY", plaintext "BALLOON" → pairs: BA, LX, LO, ON. Encrypt using matrix.

Transposition Techniques: Rearrange plaintext letters (e.g., rail fence, columnar).

Steganography vs Encryption:

Feature Steganography Encryption
Purpose Hide existence of message Hide content of message
Method Embed in cover medium Transform using algorithm/key
Strength Security through obscurity Mathematical strength

2.2 Block Ciphers & Modes of Operation

  • Block Cipher: Processes fixed-size blocks (e.g., 128 bits).

  • Stream Cipher: Processes continuous bits.

  • Design Principles:

    • Diffusion: Spread plaintext influence over many ciphertext bits (e.g., AES MixColumns).

    • Confusion: Make relationship between key and ciphertext complex (e.g., AES SubBytes).

Data Encryption Standard (DES):

  • S-Boxes: Provide non-linearity, resist differential cryptanalysis.

  • Avalanche Effect: Small change in plaintext/key causes significant change in ciphertext.

Advanced Encryption Standard (AES):

  • Steps per Round (except last):

    1. SubBytes: Byte substitution via S-box.

    2. ShiftRows: Shift rows cyclically.

    3. MixColumns: Mix columns using matrix multiplication.

    4. AddRoundKey: XOR with round key.

  • Key Expansion: Generate round keys from cipher key using Rijndael key schedule.

Modes of Operation:

  • ECB (Electronic Codebook):

    • Each block encrypted independently.

    • Why rarely used? Identical plaintext blocks → identical ciphertext blocks → pattern leakage.

  • CBC (Cipher Block Chaining):

    • Each plaintext block XORed with previous ciphertext block before encryption.

    • Requires Initialization Vector (IV).

    • Provides diffusion.

[!TIP] ECB is insecure for large data; always use CBC or CTR for better security.

2.3 Public-Key Cryptography (Asymmetric)

Comparison:

Feature Symmetric Asymmetric
Keys Same key for enc/dec Public key for enc, private for dec
Speed Faster Slower
Key Distribution Problem Solved
Algorithms AES, 3DES RSA, ECC, Diffie-Hellman

RSA Algorithm:

  • Key Generation:

    1. Choose primes $p$, $q$.

    2. Compute $$\displaystyle n = p \cdot q $$, $$\displaystyle \phi(n) = (p-1)(q-1) $$.

    3. Choose $e$ such that $$\displaystyle 1 < e < \phi(n) $$, $$\displaystyle \gcd(e, \phi(n)) = 1 $$.

    4. Compute $d$ such that $d \cdot e \equiv 1 \pmod{\phi(n)}$.

  • Encryption: $$\displaystyle C = M^e \bmod n $$.

  • Decryption: $$\displaystyle M = C^d \bmod n $$.

\boxed{C = M^e \bmod n}

\boxed{M = C^d \bmod n}

Attacks on RSA:

  • Brute force (try all $d$).

  • Mathematical (factor $n$ to get $p,q$).

  • Timing attacks (measure decryption time).

  • Chosen ciphertext (adaptive chosen ciphertext attack).

Euler's Totient Function $\phi(n)$: Count numbers $\le n$ coprime to $n$. For $$\displaystyle n = pq $$, $$\displaystyle \phi(n) = (p-1)(q-1) $$.

Factoring Problem: Hard to factor large $n$; basis of RSA security.

2.4 Key Exchange & Management

Primitive Root: For prime $q$, $\alpha$ is primitive root if its powers generate all $1$ to $q-1$.

Diffie-Hellman Key Exchange:

  1. Agree on prime $q$ and primitive root $\alpha$.

  2. A chooses private $$\displaystyle X_A $$, computes $$\displaystyle Y_A = \alpha^{X_A} \bmod q $$.

  3. B chooses private $$\displaystyle X_B $$, computes $$\displaystyle Y_B = \alpha^{X_B} \bmod q $$.

  4. Exchange public keys.

  5. Shared key: $$\displaystyle K = Y_B^{X_A} \bmod q = Y_A^{X_B} \bmod q $$.

Example (from past paper): $$\displaystyle q=11 $$, $$\displaystyle \alpha=7 $$, $$\displaystyle X_A=3 $$, $$\displaystyle X_B=6 $$.

  • $$\displaystyle Y_A = 7^3 \bmod 11 = 343 \bmod 11 = 2 $$.

  • $$\displaystyle Y_B = 7^6 \bmod 11 = 117649 \bmod 11 = 4 $$.

  • $$\displaystyle K = 4^3 \bmod 11 = 64 \bmod 11 = 9 $$ (or $$\displaystyle 2^6 \bmod 11 = 64 \bmod 11 = 9 $$).

\boxed{K = Y_B^{X_A} \bmod q = Y_A^{X_B} \bmod q}

Kerberos:

  • Requirements: Authentication, scalability, transparency, reasonable security.

  • Double Encryption: First encrypts ticket with server's key (confidentiality), then encrypts whole message with session key (authentication of client).

  • Versions: v4 uses DES; v5 supports multiple encryption types, longer ticket lifetimes.

2.5 Cryptographic Hash Functions & Message Authentication

Hash Function Properties:

  • Pre-image resistance: Given $h$, hard to find $m$ such that $$\displaystyle \text{hash}(m)=h $$.

  • Second pre-image resistance: Given $$\displaystyle m_1 $$, hard to find $$\displaystyle m_2 \ne m_1 $$ with same hash.

  • Collision resistance: Hard to find any two messages with same hash.

"Hashing does not ensure integrity in network communication":

  • Justification: Hash sent with message can be altered by attacker.

    Example: Attacker intercepts $M$ and $H(M)$, replaces with $M'$ and $H(M')$. Receiver cannot detect change without authentication.

  • Solution: Use MAC or digital signature.

Message Authentication Code (MAC):

  • Generated using symmetric key and message.

  • Provides authentication (only parties with key can generate valid MAC) and integrity.

  • Confidentiality: Use MAC with encryption, e.g., encrypt-then-MAC: Encrypt message, then compute MAC on ciphertext.

Attacks addressed by MAC: Modification, masquerade, replay (with sequence numbers).

2.6 Cryptographic Applications & Protocols

Pretty Good Privacy (PGP):

  • Confidentiality: Symmetric session key encrypts message; session key encrypted with recipient's public key.

  • Authentication: Digital signature using sender's private key on hash of message.

  • Block Diagram:

    
    Message → Compression → Symmetric Encryption (session key) → Public-Key Encryption (session key) → Send.
    
    For signature: Hash → Sign with private key → Attach.
    
    
  • Components: Session key, public-key, one-way hash, compression.

Secure Electronic Transaction (SET):

  • Dual signature: Customer signs order and payment info separately, then combines to protect privacy.

  • Uses certificates for all parties (cardholder, merchant, bank).

SSL/TLS:

  • Purpose: Secure communication over networks (e.g., HTTPS).

  • High-level Operation: Handshake protocol negotiates keys, authenticates server (and optionally client), then symmetric encryption for data.

IPSec:

  • Components:

    • AH (Authentication Header): Integrity and authentication (no encryption).

    • ESP (Encapsulating Security Payload): Confidentiality, integrity, authentication.

    • Security Associations (SA): One-way connection with security parameters (SPI, IP destination, protocol).

3.0 ACCESS CONTROL & SYSTEM SECURITY

3.1 Access Control Models

Discretionary Access Control (DAC):

  • Definition: Access based on user identity and permissions granted by resource owner.

  • Mechanism: Access Control Lists (ACLs) specifying users/groups and permissions.

  • Example: Unix file permissions (rwx for owner, group, others).

Mandatory Access Control (MAC):

  • Definition: Access based on security labels (e.g., classification levels) enforced by system.

  • Mechanism: Security labels on subjects and objects; access allowed if subject's clearance ≥ object's classification.

  • Example: Military systems (Top Secret, Secret, Confidential).

Comparison: DAC vs MAC:

Feature DAC MAC
Control Owner discretion System-enforced policy
Flexibility High Low
Security Less secure (Trojan risk) More secure (prevents info flow)
Example Unix permissions SELinux enforcing mode

Role-Based Access Control (RBAC):

  • Definition: Access based on roles; users assigned roles, roles have permissions.

  • Components: Users, Roles, Permissions, Sessions.

  • Enhances security in large organizations: Simplifies management (assign role instead of individual permissions), enforces least privilege, supports separation of duties.

Task-Based Access Control (TBAC):

  • Definition: Access granted based on tasks/activities within a workflow.

  • Useful scenarios: Dynamic environments like healthcare (access based on patient treatment task), collaborative systems.

3.2 Operating System Security

Linux Security Architecture:

  • User/Group Permissions: rwx for owner, group, others.

  • SELinux/AppArmor: Mandatory Access Control frameworks enforcing policies.

  • chroot jails: Restrict process to directory subtree.

  • Capabilities: Fine-grained privileges (e.g., CAP_NET_BIND_SERVICE) instead of full root.

Windows OS Security Architecture:

  • User Account Control (UAC): Prevent unauthorized changes.

  • Security Identifiers (SIDs): Unique IDs for users/groups.

  • Access Tokens: Contain SID, privileges, integrity level for process.

  • Integrity Levels: Low, Medium, High, System; mandatory integrity control prevents lower integrity processes from writing to higher.

  • Mandatory Integrity Control (MIC): Enforces integrity levels.

Trusted Systems: Designed to enforce security policies reliably. Principles: Least privilege, secure by default, complete mediation, fail-safe defaults, economy of mechanism, open design, separation of privilege, least common mechanism, psychological acceptability.

3.3 Malicious Logic & Software Security

Malicious Logic: Software designed to perform unauthorized functions.

  • Trojan Horses, Logic Bombs, Backdoors, etc.

  • Impact: Data theft, corruption, system damage, privacy violation.

Virus vs Worms:

Feature Virus Worm
Propagation Needs host file/program Self-replicates over network
Host Dependency Yes No
Payload Often destructive Often used for botnets, DDoS
Example File infector Code Red, SQL Slammer

Virus-Related Threats:

  • Types: Boot sector, File infector, Macro, Polymorphic (changes code to avoid detection).

  • Countermeasures: Antivirus (signature/heuristic), security hygiene (don't open attachments), patching, least privilege.

3.4 Password Management & Authentication

Password Management Techniques:

  • Storage: Hash with salt (random value) to prevent rainbow table attacks.

  • Policies: Minimum length, complexity (mix of chars), no dictionary words.

  • Aging: Force periodic change.

  • Lockout: After failed attempts.

Authentication Systems:

  • Something you know: Password, PIN.

  • Something you have: Token, smart card.

  • Something you are: Biometrics.

  • Factors: Single-factor (one type), two-factor (two types), multi-factor.

[!TIP] Salting prevents precomputed hash attacks; always use unique salt per password.

4.0 NETWORK & PERIMETER SECURITY

4.1 Firewalls

Definition: Network security device that monitors and controls incoming/outgoing traffic based on predetermined security rules.

Primary Purpose: Establish barrier between trusted internal network and untrusted external network.

Three Common Types:

  1. Packet-Filtering Firewall:

    • Operates at network layer (IP, port).

    • Stateless: Each packet inspected independently.

    • Rule set: Allow/deny based on source/dest IP, port, protocol.

    • DiagramPacket filtering firewall showing rule check
  2. Stateful Inspection Firewall:

    • Tracks connection state (TCP handshake, etc.).

    • Maintains state table; allows only packets belonging to established connections.

    • More secure than packet-filtering.

  3. Application-Level Gateway (Proxy Firewall):

    • Acts as intermediary; terminates connection from client, initiates new connection to server.

    • Inspects application-layer data (e.g., HTTP commands).

    • Can filter based on content.

    • DiagramProxy firewall with dual connections

How Firewall Works: Rule set applied to each packet; filtering criteria: source/dest IP, port, protocol, state, application data.

4.2 Intrusion Detection Systems (IDS)

Definition: Monitors network or system for malicious activity or policy violations.

Purpose: Detect attacks, provide response, deter attackers (accounting).

Three Benefits:

  1. Detection: Identify attacks in progress.

  2. Response: Trigger alerts or automated responses.

  3. Deterrence/Accounting: Record evidence for forensic analysis.

Types:

  • Network-based (NIDS): Monitors network traffic (e.g., Snort).

  • Host-based (HIDS): Monitors single host (e.g., file integrity, log analysis).

Detection Techniques:

  • Signature-based: Compare traffic to known attack patterns.

  • Anomaly-based: Detect deviations from normal behavior (requires baseline).

[!TIP] IDS is passive (detects/alert); IPS is active (prevents).

4.3 Denial-of-Service (DoS) & Distributed DoS (DDoS)

Definition: Attack that makes a service unavailable by overwhelming it with traffic or exploiting vulnerabilities.

Objective: Disrupt service, cause financial loss, distract from other attacks.

Common Attack Vectors:

  • Volumetric: Flood with traffic (e.g., UDP flood, ICMP flood).

  • Protocol: Exploit protocol weaknesses (e.g., SYN flood, Ping of Death).

  • Application Layer: Target specific applications (e.g., HTTP flood, Slowloris).

5.0 APPLICATION & WEB SECURITY

5.1 Web Application Vulnerabilities

SQL Injection (SQLi):

  • How it works: Inject malicious SQL code into input fields, altering query logic.

  • Impact: Data theft, modification, deletion, authentication bypass.

  • Prevention:

    • Input validation (whitelist).

    • Parameterized queries (prepared statements).

    • Principle of least privilege (DB user with minimal rights).

Cross-Site Scripting (XSS):

  • How it works: Inject malicious scripts into web pages viewed by users.

    • Stored: Script stored on server (e.g., comment field).

    • Reflected: Script reflected in response (e.g., search results).

    • DOM-based: Client-side script modifies DOM.

  • Impact: Session hijacking, defacement, phishing.

  • Prevention:

    • Output encoding (escape user input).

    • Input validation.

    • Content Security Policy (CSP) to restrict script sources.

5.2 Web Technologies & Security

URL vs URI:

  • URI (Uniform Resource Identifier): String identifying a resource (e.g., mailto:[email protected]).

  • URL (Uniform Resource Locator): Subset of URI that specifies location and access method (e.g., https://example.com/page).

  • Difference: All URLs are URIs, but not all URIs are URLs.

HTTP:

  • Role: Application-layer protocol for web communication.

  • Basic Security Weaknesses:

    • Lack of encryption: Data in plaintext.

    • Statelessness: No inherent session management (cookies used).

    • Vulnerable to MITM, injection.

Cookies:

  • Purpose: Maintain session state, store user preferences.

  • Security Risks:

    • Session hijacking (steal cookie).

    • XSS (steal via injected script).

  • Secure Attributes:

    • HttpOnly: Prevents JavaScript access.

    • Secure: Only over HTTPS.

    • SameSite: Restricts cross-site sending.

5.3 Database Security

Purpose of Database Auditing: Monitor and record database activities to ensure compliance, detect anomalies, and investigate incidents.

How Auditing Helps:

  • Tracks access (who accessed what, when).

  • Detects unauthorized queries or privilege misuse.

  • Provides evidence for forensic analysis.

  • Supports compliance (e.g., GDPR, HIPAA).

5.4 Public Key Infrastructure (PKI)

Six Components:

  1. Certificate Authority (CA): Issues and signs digital certificates.

  2. Registration Authority (RA): Verifies identity before certificate issuance.

  3. Certificate Repository: Stores certificates and CRLs.

  4. Certificate Revocation List (CRL): List of revoked certificates.

  5. Online Certificate Status Protocol (OCSP): Real-time certificate status checking.

  6. End Entities: Users/systems that use certificates.

6.0 SECURITY AUDITING, ANALYSIS & FORENSICS

6.1 Vulnerability Analysis & Security Auditing

Vulnerability Analysis: Process of identifying, quantifying, and prioritizing security weaknesses.

Importance in Security Auditing: Proactive assessment to reduce risk, ensure compliance, and prioritize remediation.

Forensic Analysis on Compromised Server:

  1. Preservation: Secure evidence (imaging disks, memory).

  2. Identification: Determine scope and impact.

  3. Collection: Gather logs, files, network data.

  4. Analysis: Examine for attack vectors, malware, indicators of compromise.

  5. Reporting: Document findings, recommendations.

[!TIP] Chain of custody critical for legal admissibility.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in