1.0 FOUNDATIONAL SECURITY CONCEPTS & PRINCIPLES
1.1 Core Terminology & Characteristics
-
Threat: Potential cause of an incident that may result in harm.
-
Attack: Attempt to compromise security (confidentiality, integrity, availability).
-
Vulnerability: Weakness that can be exploited.
-
Risk: Likelihood of threat exploiting vulnerability and impact.
Security Attacks:
-
Passive: Eavesdropping, Traffic Analysis (no alteration).
-
Active: Masquerade, Replay, Modification, Denial-of-Service (alteration/disruption).
Critical Characteristics of Information:
| Characteristic | Definition |
|---|---|
| Confidentiality | Prevent unauthorized access. |
| Integrity | Ensure accuracy and completeness. |
| Availability | Accessible when needed. |
| Authentication | Verify identity. |
| Non-Repudiation | Prevent denial of actions. |
| Accountability | Trace actions to individuals. |
[!TIP] Exams often ask to differentiate passive vs active attacks with examples.
1.2 Security Policy & Management
-
Security Policy: Document defining rules, procedures, and guidelines for protecting assets.
-
Key Components:
-
Purpose and scope
-
Roles and responsibilities
-
Acceptable use
-
Access control policy
-
Incident response
-
Compliance requirements
-
-
Security Life Cycle:
-
Planning: Identify assets, risks, define policy.
-
Implementation: Deploy controls, train users.
-
Operation: Monitor, maintain, update.
-
Review/Disposal: Audit, assess, decommission securely.
-
-
Enterprise Security Specifications: Aligns policy with business goals, risk management, and compliance.
1.3 Trust & Assumptions
-
Trust: Confidence that a system operates as intended despite adversarial conditions.
-
Fundamental Security Assumptions: E.g., "The kernel is trusted," "Physical security is in place."
-
Confinement Problem: Preventing unauthorized information flow from trusted to untrusted contexts.
- Mitigation: Sandboxing, capability systems, information flow control.
-
Principle of Least Privilege: Grant minimal permissions necessary. In information flow control, restrict data access to prevent leakage.
[!TIP] Common exam question: Explain confinement problem with example (e.g., Trojan horse leaking data).
2.0 CRYPTOGRAPHY (SYMMETRIC & ASYMMETRIC)
2.1 Symmetric Cipher Fundamentals
Model:
Plaintext $\xrightarrow{\text{Encryption (Algo + Key)}}$ Ciphertext $\xrightarrow{\text{Decryption (Algo + Key)}}$ Plaintext.
Substitution Techniques:
-
Caesar Cipher: Shift each letter by fixed key (e.g., key=3: A→D).
-
Playfair Cipher:
-
Matrix Construction: 5x5 grid with keyword (I/J combined). Fill remaining letters.
-
Encryption Steps:
-
Split plaintext into digraphs (pad with X if needed).
-
For each pair:
-
Same row: Replace with next in row (wrap).
-
Same column: Replace with below (wrap).
-
Rectangle: Swap columns.
-
-
-
Example: Keyword "MONARCHY", plaintext "BALLOON" → pairs: BA, LX, LO, ON. Encrypt using matrix.
-
Transposition Techniques: Rearrange plaintext letters (e.g., rail fence, columnar).
Steganography vs Encryption:
| Feature | Steganography | Encryption |
|---|---|---|
| Purpose | Hide existence of message | Hide content of message |
| Method | Embed in cover medium | Transform using algorithm/key |
| Strength | Security through obscurity | Mathematical strength |
2.2 Block Ciphers & Modes of Operation
-
Block Cipher: Processes fixed-size blocks (e.g., 128 bits).
-
Stream Cipher: Processes continuous bits.
-
Design Principles:
-
Diffusion: Spread plaintext influence over many ciphertext bits (e.g., AES MixColumns).
-
Confusion: Make relationship between key and ciphertext complex (e.g., AES SubBytes).
-
Data Encryption Standard (DES):
-
S-Boxes: Provide non-linearity, resist differential cryptanalysis.
-
Avalanche Effect: Small change in plaintext/key causes significant change in ciphertext.
Advanced Encryption Standard (AES):
-
Steps per Round (except last):
-
SubBytes: Byte substitution via S-box.
-
ShiftRows: Shift rows cyclically.
-
MixColumns: Mix columns using matrix multiplication.
-
AddRoundKey: XOR with round key.
-
-
Key Expansion: Generate round keys from cipher key using Rijndael key schedule.
Modes of Operation:
-
ECB (Electronic Codebook):
-
Each block encrypted independently.
-
Why rarely used? Identical plaintext blocks → identical ciphertext blocks → pattern leakage.
-
-
CBC (Cipher Block Chaining):
-
Each plaintext block XORed with previous ciphertext block before encryption.
-
Requires Initialization Vector (IV).
-
Provides diffusion.
-
[!TIP] ECB is insecure for large data; always use CBC or CTR for better security.
2.3 Public-Key Cryptography (Asymmetric)
Comparison:
| Feature | Symmetric | Asymmetric |
|---|---|---|
| Keys | Same key for enc/dec | Public key for enc, private for dec |
| Speed | Faster | Slower |
| Key Distribution | Problem | Solved |
| Algorithms | AES, 3DES | RSA, ECC, Diffie-Hellman |
RSA Algorithm:
-
Key Generation:
-
Choose primes $p$, $q$.
-
Compute $$\displaystyle n = p \cdot q $$, $$\displaystyle \phi(n) = (p-1)(q-1) $$.
-
Choose $e$ such that $$\displaystyle 1 < e < \phi(n) $$, $$\displaystyle \gcd(e, \phi(n)) = 1 $$.
-
Compute $d$ such that $d \cdot e \equiv 1 \pmod{\phi(n)}$.
-
-
Encryption: $$\displaystyle C = M^e \bmod n $$.
-
Decryption: $$\displaystyle M = C^d \bmod n $$.
\boxed{C = M^e \bmod n}
\boxed{M = C^d \bmod n}
Attacks on RSA:
-
Brute force (try all $d$).
-
Mathematical (factor $n$ to get $p,q$).
-
Timing attacks (measure decryption time).
-
Chosen ciphertext (adaptive chosen ciphertext attack).
Euler's Totient Function $\phi(n)$: Count numbers $\le n$ coprime to $n$. For $$\displaystyle n = pq $$, $$\displaystyle \phi(n) = (p-1)(q-1) $$.
Factoring Problem: Hard to factor large $n$; basis of RSA security.
2.4 Key Exchange & Management
Primitive Root: For prime $q$, $\alpha$ is primitive root if its powers generate all $1$ to $q-1$.
Diffie-Hellman Key Exchange:
-
Agree on prime $q$ and primitive root $\alpha$.
-
A chooses private $$\displaystyle X_A $$, computes $$\displaystyle Y_A = \alpha^{X_A} \bmod q $$.
-
B chooses private $$\displaystyle X_B $$, computes $$\displaystyle Y_B = \alpha^{X_B} \bmod q $$.
-
Exchange public keys.
-
Shared key: $$\displaystyle K = Y_B^{X_A} \bmod q = Y_A^{X_B} \bmod q $$.
Example (from past paper): $$\displaystyle q=11 $$, $$\displaystyle \alpha=7 $$, $$\displaystyle X_A=3 $$, $$\displaystyle X_B=6 $$.
-
$$\displaystyle Y_A = 7^3 \bmod 11 = 343 \bmod 11 = 2 $$.
-
$$\displaystyle Y_B = 7^6 \bmod 11 = 117649 \bmod 11 = 4 $$.
-
$$\displaystyle K = 4^3 \bmod 11 = 64 \bmod 11 = 9 $$ (or $$\displaystyle 2^6 \bmod 11 = 64 \bmod 11 = 9 $$).
\boxed{K = Y_B^{X_A} \bmod q = Y_A^{X_B} \bmod q}
Kerberos:
-
Requirements: Authentication, scalability, transparency, reasonable security.
-
Double Encryption: First encrypts ticket with server's key (confidentiality), then encrypts whole message with session key (authentication of client).
-
Versions: v4 uses DES; v5 supports multiple encryption types, longer ticket lifetimes.
2.5 Cryptographic Hash Functions & Message Authentication
Hash Function Properties:
-
Pre-image resistance: Given $h$, hard to find $m$ such that $$\displaystyle \text{hash}(m)=h $$.
-
Second pre-image resistance: Given $$\displaystyle m_1 $$, hard to find $$\displaystyle m_2 \ne m_1 $$ with same hash.
-
Collision resistance: Hard to find any two messages with same hash.
"Hashing does not ensure integrity in network communication":
-
Justification: Hash sent with message can be altered by attacker.
Example: Attacker intercepts $M$ and $H(M)$, replaces with $M'$ and $H(M')$. Receiver cannot detect change without authentication.
-
Solution: Use MAC or digital signature.
Message Authentication Code (MAC):
-
Generated using symmetric key and message.
-
Provides authentication (only parties with key can generate valid MAC) and integrity.
-
Confidentiality: Use MAC with encryption, e.g., encrypt-then-MAC: Encrypt message, then compute MAC on ciphertext.
Attacks addressed by MAC: Modification, masquerade, replay (with sequence numbers).
2.6 Cryptographic Applications & Protocols
Pretty Good Privacy (PGP):
-
Confidentiality: Symmetric session key encrypts message; session key encrypted with recipient's public key.
-
Authentication: Digital signature using sender's private key on hash of message.
-
Block Diagram:
Message → Compression → Symmetric Encryption (session key) → Public-Key Encryption (session key) → Send. For signature: Hash → Sign with private key → Attach. -
Components: Session key, public-key, one-way hash, compression.
Secure Electronic Transaction (SET):
-
Dual signature: Customer signs order and payment info separately, then combines to protect privacy.
-
Uses certificates for all parties (cardholder, merchant, bank).
SSL/TLS:
-
Purpose: Secure communication over networks (e.g., HTTPS).
-
High-level Operation: Handshake protocol negotiates keys, authenticates server (and optionally client), then symmetric encryption for data.
IPSec:
-
Components:
-
AH (Authentication Header): Integrity and authentication (no encryption).
-
ESP (Encapsulating Security Payload): Confidentiality, integrity, authentication.
-
Security Associations (SA): One-way connection with security parameters (SPI, IP destination, protocol).
-
3.0 ACCESS CONTROL & SYSTEM SECURITY
3.1 Access Control Models
Discretionary Access Control (DAC):
-
Definition: Access based on user identity and permissions granted by resource owner.
-
Mechanism: Access Control Lists (ACLs) specifying users/groups and permissions.
-
Example: Unix file permissions (rwx for owner, group, others).
Mandatory Access Control (MAC):
-
Definition: Access based on security labels (e.g., classification levels) enforced by system.
-
Mechanism: Security labels on subjects and objects; access allowed if subject's clearance ≥ object's classification.
-
Example: Military systems (Top Secret, Secret, Confidential).
Comparison: DAC vs MAC:
| Feature | DAC | MAC |
|---|---|---|
| Control | Owner discretion | System-enforced policy |
| Flexibility | High | Low |
| Security | Less secure (Trojan risk) | More secure (prevents info flow) |
| Example | Unix permissions | SELinux enforcing mode |
Role-Based Access Control (RBAC):
-
Definition: Access based on roles; users assigned roles, roles have permissions.
-
Components: Users, Roles, Permissions, Sessions.
-
Enhances security in large organizations: Simplifies management (assign role instead of individual permissions), enforces least privilege, supports separation of duties.
Task-Based Access Control (TBAC):
-
Definition: Access granted based on tasks/activities within a workflow.
-
Useful scenarios: Dynamic environments like healthcare (access based on patient treatment task), collaborative systems.
3.2 Operating System Security
Linux Security Architecture:
-
User/Group Permissions: rwx for owner, group, others.
-
SELinux/AppArmor: Mandatory Access Control frameworks enforcing policies.
-
chroot jails: Restrict process to directory subtree.
-
Capabilities: Fine-grained privileges (e.g., CAP_NET_BIND_SERVICE) instead of full root.
Windows OS Security Architecture:
-
User Account Control (UAC): Prevent unauthorized changes.
-
Security Identifiers (SIDs): Unique IDs for users/groups.
-
Access Tokens: Contain SID, privileges, integrity level for process.
-
Integrity Levels: Low, Medium, High, System; mandatory integrity control prevents lower integrity processes from writing to higher.
-
Mandatory Integrity Control (MIC): Enforces integrity levels.
Trusted Systems: Designed to enforce security policies reliably. Principles: Least privilege, secure by default, complete mediation, fail-safe defaults, economy of mechanism, open design, separation of privilege, least common mechanism, psychological acceptability.
3.3 Malicious Logic & Software Security
Malicious Logic: Software designed to perform unauthorized functions.
-
Trojan Horses, Logic Bombs, Backdoors, etc.
-
Impact: Data theft, corruption, system damage, privacy violation.
Virus vs Worms:
| Feature | Virus | Worm |
|---|---|---|
| Propagation | Needs host file/program | Self-replicates over network |
| Host Dependency | Yes | No |
| Payload | Often destructive | Often used for botnets, DDoS |
| Example | File infector | Code Red, SQL Slammer |
Virus-Related Threats:
-
Types: Boot sector, File infector, Macro, Polymorphic (changes code to avoid detection).
-
Countermeasures: Antivirus (signature/heuristic), security hygiene (don't open attachments), patching, least privilege.
3.4 Password Management & Authentication
Password Management Techniques:
-
Storage: Hash with salt (random value) to prevent rainbow table attacks.
-
Policies: Minimum length, complexity (mix of chars), no dictionary words.
-
Aging: Force periodic change.
-
Lockout: After failed attempts.
Authentication Systems:
-
Something you know: Password, PIN.
-
Something you have: Token, smart card.
-
Something you are: Biometrics.
-
Factors: Single-factor (one type), two-factor (two types), multi-factor.
[!TIP] Salting prevents precomputed hash attacks; always use unique salt per password.
4.0 NETWORK & PERIMETER SECURITY
4.1 Firewalls
Definition: Network security device that monitors and controls incoming/outgoing traffic based on predetermined security rules.
Primary Purpose: Establish barrier between trusted internal network and untrusted external network.
Three Common Types:
-
Packet-Filtering Firewall:
-
Operates at network layer (IP, port).
-
Stateless: Each packet inspected independently.
-
Rule set: Allow/deny based on source/dest IP, port, protocol.
-
DiagramPacket filtering firewall showing rule check
-
-
Stateful Inspection Firewall:
-
Tracks connection state (TCP handshake, etc.).
-
Maintains state table; allows only packets belonging to established connections.
-
More secure than packet-filtering.
-
-
Application-Level Gateway (Proxy Firewall):
-
Acts as intermediary; terminates connection from client, initiates new connection to server.
-
Inspects application-layer data (e.g., HTTP commands).
-
Can filter based on content.
-
DiagramProxy firewall with dual connections
-
How Firewall Works: Rule set applied to each packet; filtering criteria: source/dest IP, port, protocol, state, application data.
4.2 Intrusion Detection Systems (IDS)
Definition: Monitors network or system for malicious activity or policy violations.
Purpose: Detect attacks, provide response, deter attackers (accounting).
Three Benefits:
-
Detection: Identify attacks in progress.
-
Response: Trigger alerts or automated responses.
-
Deterrence/Accounting: Record evidence for forensic analysis.
Types:
-
Network-based (NIDS): Monitors network traffic (e.g., Snort).
-
Host-based (HIDS): Monitors single host (e.g., file integrity, log analysis).
Detection Techniques:
-
Signature-based: Compare traffic to known attack patterns.
-
Anomaly-based: Detect deviations from normal behavior (requires baseline).
[!TIP] IDS is passive (detects/alert); IPS is active (prevents).
4.3 Denial-of-Service (DoS) & Distributed DoS (DDoS)
Definition: Attack that makes a service unavailable by overwhelming it with traffic or exploiting vulnerabilities.
Objective: Disrupt service, cause financial loss, distract from other attacks.
Common Attack Vectors:
-
Volumetric: Flood with traffic (e.g., UDP flood, ICMP flood).
-
Protocol: Exploit protocol weaknesses (e.g., SYN flood, Ping of Death).
-
Application Layer: Target specific applications (e.g., HTTP flood, Slowloris).
5.0 APPLICATION & WEB SECURITY
5.1 Web Application Vulnerabilities
SQL Injection (SQLi):
-
How it works: Inject malicious SQL code into input fields, altering query logic.
-
Impact: Data theft, modification, deletion, authentication bypass.
-
Prevention:
-
Input validation (whitelist).
-
Parameterized queries (prepared statements).
-
Principle of least privilege (DB user with minimal rights).
-
Cross-Site Scripting (XSS):
-
How it works: Inject malicious scripts into web pages viewed by users.
-
Stored: Script stored on server (e.g., comment field).
-
Reflected: Script reflected in response (e.g., search results).
-
DOM-based: Client-side script modifies DOM.
-
-
Impact: Session hijacking, defacement, phishing.
-
Prevention:
-
Output encoding (escape user input).
-
Input validation.
-
Content Security Policy (CSP) to restrict script sources.
-
5.2 Web Technologies & Security
URL vs URI:
-
URI (Uniform Resource Identifier): String identifying a resource (e.g.,
mailto:[email protected]). -
URL (Uniform Resource Locator): Subset of URI that specifies location and access method (e.g.,
https://example.com/page). -
Difference: All URLs are URIs, but not all URIs are URLs.
HTTP:
-
Role: Application-layer protocol for web communication.
-
Basic Security Weaknesses:
-
Lack of encryption: Data in plaintext.
-
Statelessness: No inherent session management (cookies used).
-
Vulnerable to MITM, injection.
-
Cookies:
-
Purpose: Maintain session state, store user preferences.
-
Security Risks:
-
Session hijacking (steal cookie).
-
XSS (steal via injected script).
-
-
Secure Attributes:
-
HttpOnly: Prevents JavaScript access.
-
Secure: Only over HTTPS.
-
SameSite: Restricts cross-site sending.
-
5.3 Database Security
Purpose of Database Auditing: Monitor and record database activities to ensure compliance, detect anomalies, and investigate incidents.
How Auditing Helps:
-
Tracks access (who accessed what, when).
-
Detects unauthorized queries or privilege misuse.
-
Provides evidence for forensic analysis.
-
Supports compliance (e.g., GDPR, HIPAA).
5.4 Public Key Infrastructure (PKI)
Six Components:
-
Certificate Authority (CA): Issues and signs digital certificates.
-
Registration Authority (RA): Verifies identity before certificate issuance.
-
Certificate Repository: Stores certificates and CRLs.
-
Certificate Revocation List (CRL): List of revoked certificates.
-
Online Certificate Status Protocol (OCSP): Real-time certificate status checking.
-
End Entities: Users/systems that use certificates.
6.0 SECURITY AUDITING, ANALYSIS & FORENSICS
6.1 Vulnerability Analysis & Security Auditing
Vulnerability Analysis: Process of identifying, quantifying, and prioritizing security weaknesses.
Importance in Security Auditing: Proactive assessment to reduce risk, ensure compliance, and prioritize remediation.
Forensic Analysis on Compromised Server:
-
Preservation: Secure evidence (imaging disks, memory).
-
Identification: Determine scope and impact.
-
Collection: Gather logs, files, network data.
-
Analysis: Examine for attack vectors, malware, indicators of compromise.
-
Reporting: Document findings, recommendations.
[!TIP] Chain of custody critical for legal admissibility.