Crypto
Crypto
1. Confidentiality
2. Integrity
3. Availability
Security Trends
Cloud Security
Blockchain Security
Malware
Ransomware
Phishing
1
DDoS Attacks
Insider Threats
Objectives
Examples
In India:
Ethical Behavior
✔ Respect privacy
Unethical Behavior
✘ Data theft
✘ Software piracy
✘ Identity theft
2
Professional Aspects of Security
Maintain confidentiality
1. Physical Security
Protects hardware.
Examples:
CCTV
Security guards
Biometric access
2. Network Security
Examples:
Firewall
VPN
IDS
3. Application Security
Examples:
Authentication
Secure coding
3
4. Data Security
Examples:
Encryption
Backup
5. User Security
Examples:
Strong passwords
Cybersecurity training
Security Policies
Objectives
Components
1. Purpose
2. Scope
Types
4
Model of Network Security
A network security model explains secure communication between sender and receiver.
Components
1. Sender
2. Message
3. Encryption Algorithm
4. Secret Key
5. Network
6. Decryption Algorithm
7. Receiver
Working
Benefits
Confidentiality
Integrity
Authentication
Security Attack
Types of Attacks
1. Passive Attack
Examples:
Eavesdropping
Traffic Analysis
5
Characteristics
Difficult to detect
No modification of data
2. Active Attack
Examples:
Masquerade
Replay Attack
Modification Attack
Characteristics
Easier to detect
Difficult to prevent
Security Services
Types
1. Authentication
Verifies identity.
2. Access Control
3. Data Confidentiality
4. Data Integrity
5. Non-Repudiation
6
Security Mechanisms
Examples:
Encryption
Digital Signature
Access Control
Authentication Exchange
Traffic Padding
Components
Security Attacks
Security Services
Protection functions.
Security Mechanisms
Importance
7
1. Substitution Techniques
Caesar Cipher
Example:
Plaintext:
HELLO
Shift = 3
Ciphertext:
KHOOR
Formula
𝐶 = (𝑃 + 𝐾) 𝑚𝑜𝑑 26
Where:
C = Ciphertext
P = Plaintext
K = Key
Advantages
Easy to implement
Disadvantages
Easily broken
Monoalphabetic Cipher
Example:
A→D
B→E
C→F
2. Transposition Techniques
8
Characters remain unchanged but positions change.
Message:
HELLO
Ciphertext:
HLOEL
Advantages
Simple
Disadvantages
Steganography
Examples:
Images
Audio files
Videos
Encryption Steganography
Applications
Secret communication
Digital watermarking
9
Foundations of Modern Cryptography
Objectives:
Confidentiality
Integrity
Authentication
Non-repudiation
Perfect Security
Example
Conditions
Information Theory
It studies:
Information measurement
Data transmission
Communication efficiency
Importance
Product Cryptosystem
10
A product cryptosystem combines multiple encryption techniques.
Example:
Substitution + Transposition
Advantages
More secure
Harder to break
Example
Modern algorithms like AES use multiple rounds of substitution and permutation.
Cryptanalysis
Objectives
Recover plaintext
Analyze weaknesses
Types
1. Ciphertext-Only Attack
Answer
11
The OSI Security Architecture classifies security into three categories: Security Attacks,
Security Services, and Security Mechanisms.
1. Security Attacks
A. Passive Attacks
The attacker only monitors data and does not modify it.
Examples:
Eavesdropping
Traffic Analysis
Characteristics:
Difficult to detect
No alteration of data
B. Active Attacks
Examples:
Replay Attack
Masquerade Attack
Characteristics:
Easier to detect
Harder to prevent
2. Security Services
Types:
Authentication
Access Control
12
Confidentiality
Integrity
Non-Repudiation
3. Security Mechanisms
Examples:
Encryption
Digital Signature
Authentication Exchange
Access Control
Conclusion
Security attacks threaten systems, security services provide protection, and security
mechanisms implement those protections.
Answer
Objectives
Components
1. Security Attacks
Examples:
Passive attacks
13
Active attacks
2. Security Services
Examples:
Authentication
Confidentiality
Integrity
Access Control
Non-Repudiation
3. Security Mechanisms
Examples:
Encryption
Digital Signatures
Advantages
Standardized framework
Conclusion
Answer
14
Classical encryption techniques are traditional methods used to secure information.
1. Substitution Technique
Caesar Cipher
Example:
Plaintext:
HELLO
Shift = 3
Ciphertext:
KHOOR
Formula:
𝐶 = (𝑃 + 𝐾) 𝑚𝑜𝑑 26
Advantages
Easy to implement
Disadvantages
Easily cracked
2. Transposition Technique
Plaintext:
HELLO
Ciphertext:
HLOEL
Advantages
Simple implementation
15
Disadvantages
Low security
Substitution Transposition
Conclusion
Q4. Explain Security Policies and the Need for Security at Multiple Levels.
Answer
Security Policy
A security policy is a formal document containing rules and procedures for protecting
information resources.
Objectives
Reduce risks
Define responsibilities
Components
1. Purpose
2. Scope
3. User Responsibilities
16
Security must be implemented at various levels.
Physical Security
Protects hardware.
Examples:
CCTV
Security Guards
Network Security
Examples:
Firewalls
VPN
Application Security
Examples:
Authentication
Secure Coding
Data Security
Examples:
Encryption
Backup
User Security
Examples:
Strong Passwords
Cybersecurity Education
Conclusion
17
Q5. Explain the Model of Network Security with a neat diagram.
Answer
The Network Security Model describes secure communication between a sender and
receiver.
Diagram
Sender
|
Plaintext
|
Encryption Algorithm
|
Ciphertext
|
Network
|
Ciphertext
|
Decryption Algorithm
|
Plaintext
|
Receiver
Components
Sender
Encryption Algorithm
Secret Key
Network
Communication medium.
18
Decryption Algorithm
Receiver
Advantages
Ensures confidentiality
Maintains integrity
Supports authentication
Conclusion
Answer
Perfect Security
Example
One-Time Pad
Conditions:
1. Random key
Information Theory
It deals with:
Information measurement
Data transmission
19
Entropy
Communication systems
Importance
Product Cryptosystem
Example:
Substitution + Transposition
Advantages
Stronger security
Harder to break
Example
Conclusion
Perfect security, information theory, and product cryptosystems form the theoretical basis of
modern cryptography.
Answer
Cryptanalysis is the science of breaking cryptographic systems without knowing the secret
key.
Objectives
Recover plaintext
Discover weaknesses
Types of Cryptanalysis
20
1. Ciphertext-Only Attack (COA)
Goal:
Goal:
Goal:
Goal:
Importance
Conclusion
Answer
21
Legal Aspects
Examples:
Purpose:
Protect privacy
Ethical Aspects
Ethical Activities:
Respect privacy
Protect information
Unethical Activities:
Hacking
Piracy
Data Theft
Professional Aspects
Maintain confidentiality
Follow policies
Importance
22
Reduces cyber crime
Conclusion
Legal, ethical, and professional practices are essential for maintaining a secure digital
environment.
Answer:
The CIA Triad consists of:
Answer:
Passive Attack
Monitors communication.
No data modification.
Active Attack
Passive Active
23
Passive Active
Answer:
OSI Security Architecture provides a framework for understanding security in
communication systems.
It consists of:
1. Security Attacks
2. Security Services
3. Security Mechanisms
Answer:
Substitution Technique
Transposition Technique
Answer:
Perfect security means ciphertext gives no information about plaintext.
24
One-Time Pad achieves perfect secrecy because:
Key is random.
Answer:
Cryptanalysis is the study of breaking encryption systems.
Types:
1. Ciphertext-Only Attack
Answer:
The network security model includes:
Sender
Encryption
Secret Key
Network Channel
Decryption
Receiver
The sender encrypts the message before transmission, and the receiver decrypts it using the
appropriate key. This ensures confidentiality and integrity.
Symmetric Key Cryptography is a method where the same key is used for both encryption
and decryption.
Working
Plaintext
↓
Encryption + Secret Key
↓
Ciphertext
↓
Decryption + Same Secret Key
↓
Plaintext
Examples
DES
3DES
AES
RC4
S-DES
Advantages
Fast
Easy implementation
Disadvantages
Less scalable
1. Algebraic Structures
26
An algebraic structure is a set of elements with one or more operations.
Examples:
Integers
Real Numbers
Binary Numbers
Used in:
Encryption
Decryption
Key Generation
2. Modular Arithmetic
Formula
𝑎 𝑚𝑜𝑑 𝑛
Example
17 mod 5 = 2
Because:
17 = 5 × 3 + 2
Remainder = 2
Applications
RSA
DES
AES
3. Euclid's Algorithm
Example
Find GCD(48,18)
27
48 = 18×2 + 12
18 = 12×1 + 6
12 = 6×2 + 0
GCD = 6
Importance
Key generation
4. Congruence
Two numbers are congruent if they leave the same remainder when divided by a number.
Formula
𝑎 ≡ 𝑏(mod𝑛)
Example
17 ≡ 5 (mod 12)
5. Matrices in Cryptography
Example:
|1 2|
|3 4|
Used in:
Hill Cipher
AES transformations
Advantages:
Faster encryption
28
Group
1. Closure
2. Associativity
3. Identity Element
4. Inverse Element
Example:
Ring
Addition
Multiplication
Properties:
Multiplication is associative.
Example:
Integers (Z)
Field
Examples:
Rational Numbers
Finite Fields
Importance
29
Finite Fields
Notation:
GF(n)
GF = Galois Field
Example:
GF(2)
Elements:
{0,1}
Applications
AES
Error Correction
Cryptography
Characteristics
10-bit key
8-bit plaintext
Two rounds
Components
Initial Permutation
Expansion Permutation
S-Boxes
P4 Permutation
Advantages
30
Easy to understand
Disadvantages
Developed by:
IBM and adopted by National Institute of Standards and Technology.
Features
16 rounds
DES Structure
Plaintext
↓
Initial Permutation
↓
16 Feistel Rounds
↓
Final Permutation
↓
Ciphertext
Strength of DES
Advantages
Well-tested algorithm
Weaknesses
31
Small key size (56 bits)
Differential Cryptanalysis
Idea
Steps
2. Encrypt them.
Used Against
DES
Block ciphers
Linear Cryptanalysis
Idea
Plaintext
Ciphertext
Key bits
Objective
Advantage
32
Block Cipher Design Principles
1. Confusion
Introduced by:
Claude Shannon
Example:
Substitution
2. Diffusion
Example:
Permutation
Design Goals
Resistance to attacks
Efficient implementation
P1 → C1
P2 → C2
P3 → C3
Advantage
Simple
33
Disadvantage
Pattern leakage
P1 XOR IV → Encrypt
P2 XOR C1 → Encrypt
Advantage
Better security
Applications:
Network communication
Advantages:
Advantages:
Fast
Parallel processing
34
1. Security
2. Performance
3. Flexibility
4. Simplicity
5. Efficiency
Selected by:
National Institute of Standards and Technology
Features
Property Value
Rounds 10,12,14
AES Structure
Steps:
1. SubBytes
2. ShiftRows
3. MixColumns
4. AddRoundKey
Advantages
Very secure
Fast
35
RC4
Features
Stream cipher
Fast implementation
Advantages
Simple
Fast
Disadvantages
Security weaknesses
No longer recommended
Key Distribution
Challenges
Methods
1. Physical Delivery
36
Public key cryptography used to exchange symmetric keys.
Answer:
Strengths:
Proven design
Weaknesses:
Conclusion: DES was important historically but has largely been replaced by AES.
Answer:
AES is the current encryption standard.
Features:
Operations:
1. SubBytes
2. ShiftRows
37
3. MixColumns
4. AddRoundKey
Advantages:
High security
Answer:
Modes:
1. ECB
2. CBC
3. CFB
4. OFB
5. CTR
Explain each mode, its working, advantages, and disadvantages. CBC and CTR are commonly
used because they provide better security than ECB.
Answer:
The mathematical foundations include:
Algebraic Structures
Modular Arithmetic
Euclid's Algorithm
Congruence
Matrices
Groups
Rings
Fields
38
Finite Fields
These concepts are used in DES, AES, RC4, and modern cryptographic algorithms.
Answer:
Key distribution is the secure sharing of secret keys.
Methods:
1. Physical Delivery
Answer:
Modular arithmetic is arithmetic based on remainders.
Example:
17 mod 5 = 2
22 mod 7 = 1
Applications:
DES
AES
RSA
Answer:
39
Group: Set with one operation satisfying closure, associativity, identity, and inverse.
Answer:
DES is a symmetric block cipher.
Features:
64-bit block
56-bit key
16 rounds
Structure:
1. Initial Permutation
2. Feistel Rounds
3. Final Permutation
Answer:
Differential Cryptanalysis
Linear Cryptanalysis
40
Q5. Explain AES and its advantages.
Answer:
AES is a modern encryption standard.
Features:
128/192/256-bit keys
Multiple rounds
Advantages:
High security
Fast execution
Worldwide acceptance
Public Key Cryptography (Asymmetric Cryptography) is a cryptographic system that uses two
different keys:
Working
Sender
↓
Encrypt using Receiver's Public Key
↓
Ciphertext
↓
Receiver
↓
Decrypt using Private Key
↓
Plaintext
Advantages
41
Solves key distribution problem
Better authentication
Disadvantages
Examples
RSA
Diffie-Hellman
ElGamal
1. Prime Numbers
A prime number is a number greater than 1 that has only two factors:
1
Itself
Examples
2, 3, 5, 7, 11, 13, 17
Non-prime Numbers
4, 6, 8, 9, 10
Importance
RSA
Diffie-Hellman
ElGamal
42
2. Primality Testing
Methods
1. Trial Division
2. Fermat Test
3. Miller-Rabin Test
Example
Check 17:
Factors:
1 and 17
Therefore, 17 is prime.
Applications
Cryptographic protocols
3. Factorization
Example
15 = 3 × 5
21 = 3 × 7
35 = 5 × 7
Importance
Euler's Totient Function counts the positive integers less than n that are relatively prime to n.
Notation:
φ(n)
43
Formula for Prime Number
𝜑(𝑝) = 𝑝 − 1
Example
For p = 11
φ(11)=10
𝜑(𝑝𝑞) = (𝑝 − 1)(𝑞 − 1)
Example:
p=3,q=11
φ(33)=20
Application
Used in RSA.
5. Fermat's Theorem
𝑎𝑝−1 ≡ 1(mod𝑝)
Example
2^10 mod 11 = 1
Uses
RSA
Primality Testing
6. Euler's Theorem
If gcd(a,n)=1:
𝑎𝜑(𝑛) ≡ 1(mod𝑛)
Uses
44
RSA encryption
Key generation
Example
Find x:
x ≡ 2 mod 3
x ≡ 3 mod 5
Solution:
x=8
Advantages
Faster computations
Exponentiation
Repeated multiplication.
Example:
2^5 = 32
Modular Exponentiation
2^10 mod 7
RSA
Diffie-Hellman
ElGamal
Logarithm
45
Inverse operation of exponentiation.
Example:
2^3=8
Therefore:
log₂8=3
Importance
Diffie-Hellman
ElGamal
ECC
RSA Cryptosystem
Developed by:
Ron Rivest
Adi Shamir
Leonard Adleman
Step 1
p=3
q=11
Step 2
Calculate:
n=p×q=33
46
Step 3
Calculate:
φ(n)=20
Step 4
Choose:
e=3
Step 5
Calculate:
d=7
RSA Encryption
𝐶 = 𝑀𝑒 𝑚𝑜𝑑 𝑛
RSA Decryption
𝑀 = 𝐶 𝑑 𝑚𝑜𝑑 𝑛
Advantages
High security
Digital signatures
Disadvantages
Slow
Key Distribution
Methods
47
1. Manual Distribution
Importance
Key Management
Key generation
Storage
Distribution
Revocation
Destruction
Objectives
Protect keys
Maintain confidentiality
Developed by:
Whitfield Diffie
Martin Hellman
Working
48
4. Compute same secret key independently.
Advantages
ElGamal Cryptosystem
Developed by:
Taher ElGamal
Features
Digital signatures
Advantages
High security
Flexible
Disadvantages
General equation:
𝑦 2 = 𝑥 3 + 𝑎𝑥 + 𝑏
Operations
1. Point Addition
2. Point Doubling
3. Scalar Multiplication
Importance
Foundation of ECC.
49
Elliptic Curve Cryptography (ECC)
Based on:
Advantages
Faster computation
Comparison
Answer
Euler's Totient Function φ(n) counts positive integers less than n that are relatively prime to
n.
𝜑(𝑝) = 𝑝 − 1
Example:
For p = 11
φ(11)=10
50
It is widely used in RSA key generation.
Answer
Fermat's Theorem
For prime p:
𝑎𝑝−1 ≡ 1(mod𝑝)
Euler's Theorem
If gcd(a,n)=1:
𝑎𝜑(𝑛) ≡ 1(mod𝑛)
Applications:
RSA
Primality Testing
Cryptography
Answer
Steps:
Advantages:
51
Answer
Features:
Digital signatures
Advantages:
Strong security
Disadvantages:
Larger ciphertext
Answer
Equation:
𝑦 2 = 𝑥 3 + 𝑎𝑥 + 𝑏
Advantages:
Fast execution
High security
Q1. Explain RSA Cryptosystem with key generation, encryption and decryption.
Answer
Key Generation
2. Compute n = p × q.
52
3. Compute φ(n).
4. Choose e.
5. Compute d.
Encryption
𝐶 = 𝑀𝑒 𝑚𝑜𝑑 𝑛
Decryption
𝑀 = 𝐶 𝑑 𝑚𝑜𝑑 𝑛
Advantages
Security
Digital signatures
Disadvantages
Computationally expensive
Answer
1. Prime Numbers
2. Primality Testing
3. Factorization
5. Fermat's Theorem
6. Euler's Theorem
8. Exponentiation
9. Logarithm
These concepts form the basis of RSA, Diffie-Hellman, ElGamal, and ECC.
53
Answer
Steps:
Advantages:
Disadvantages:
Q4. Explain Elliptic Curve Cryptography (ECC) and Elliptic Curve Arithmetic.
Answer
Equation:
𝑦 2 = 𝑥 3 + 𝑎𝑥 + 𝑏
Arithmetic Operations:
1. Point Addition
2. Point Doubling
3. Scalar Multiplication
Advantages:
Smaller keys
Faster computation
High security
54
Q5. Explain Key Distribution, Key Management and ElGamal Cryptosystem.
Answer
Key Distribution
Methods:
Manual
PKI
Key Management
Includes:
Key generation
Storage
Revocation
ElGamal Cryptosystem
Advantages:
Strong security
Disadvantages:
Larger ciphertext
These requirements are achieved through Message Authentication and Message Integrity.
55
Authentication Requirements
Objectives
2. Message Integrity
3. Non-Repudiation
Authentication Function
Methods
1. Message Encryption
3. Hash Function
4. Digital Signature
Message
Secret Key
Working
Message is authentic.
Advantages
Fast
Efficient
Limitation
Hash Function
A hash function converts a message of any size into a fixed-length value called a hash or
digest.
Properties
Fixed-size output
Fast computation
One-way function
Example
Message
↓
Hash Function
↓
Hash Value (Digest)
1. One-Way Property
57
2. Deterministic
4. Avalanche Effect
Preimage Resistance
Collision Resistance
Finding two different messages with the same hash should be computationally infeasible.
Security of MAC
Resist forgery.
58
SHA Family
Advantages
Strong security
Fast processing
Widely used
Applications
Digital Signatures
SSL/TLS
Password Storage
Blockchain
Digital Signature
It provides:
1. Authentication
2. Integrity
3. Non-Repudiation
59
Working
Sender
Receiver
Message is authentic.
Integrity is maintained.
Advantages
Authentication
Integrity
Non-repudiation
Authentication Protocols
Objectives
Prevent impersonation
Examples:
Kerberos
X.509
60
DSS (Digital Signature Standard)
Digital Signature Standard is a standard for digital signatures published by National Institute
of Standards and Technology.
Features
Provides authentication
Provides integrity
Supports non-repudiation
Applications
Electronic Documents
E-Governance
Banking Systems
ENTITY AUTHENTICATION
Biometrics Authentication
Examples
Fingerprint
Iris Scan
Face Recognition
Voice Recognition
Advantages
61
Difficult to forge
Convenient
Disadvantages
Expensive
Privacy concerns
Password Authentication
Types
1. Static Password
Long length
Difficult to guess
Challenge-Response Protocol
Working
Advantages
AUTHENTICATION APPLICATIONS
62
Kerberos
Developed at:
Massachusetts Institute of Technology
Objectives
Components
Verifies users.
Client
Service Server
Working
63
Advantages
Strong authentication
Single Sign-On
Secure communication
X.509
Used in:
SSL/TLS
HTTPS
PKI
1. Version Number
2. Serial Number
3. Subject Name
4. Issuer Name
5. Public Key
6. Validity Period
7. Digital Signature
Advantages
Strong authentication
Certificate-based security
Widely accepted
64
Q1. Explain Message Authentication Code (MAC).
Answer
Working:
Advantages:
Provides authentication.
Ensures integrity.
Limitation:
Answer
Security Requirements:
1. Preimage Resistance
3. Collision Resistance
Properties:
One-way
Deterministic
Fixed-length output
Applications:
Digital signatures
Password protection
65
Q3. Explain Digital Signature and its working.
Answer
Working:
4. Compare hashes.
Answer
Components:
Client
Service Server
Advantages:
Single Sign-On
Strong security
Answer
Contents:
66
Subject Name
Issuer Name
Public Key
Validity Period
Digital Signature
Applications:
SSL/TLS
HTTPS
Secure Email
Q1. Explain Message Authentication and Integrity. Discuss MAC and Hash Functions.
Answer
MAC
Hash Function
One-way function.
Security Requirements
Preimage Resistance
Collision Resistance
67
Both MAC and hash functions are widely used in secure communication systems.
Answer
1. Authentication
2. Integrity
3. Non-Repudiation
Working:
1. Generate hash.
DSS
Features:
Uses DSA
Supports integrity
Supports authentication
Provides non-repudiation
Applications:
Banking
E-commerce
Government systems
Answer
Biometrics
68
Examples:
Fingerprint
Iris
Face Recognition
Advantages:
Difficult to forge
Password Authentication
Types:
Static Password
OTP
Challenge-Response Protocol
Advantages:
These techniques are widely used for access control and identity verification.
Answer
Components:
1. Client
4. Service Server
Working:
2. AS issues TGT.
69
3. TGS issues service ticket.
Advantages:
Single Sign-On
Secure authentication
Password protection
Applications:
Enterprise networks
Distributed systems
Answer
Certificate Components:
Version
Serial Number
Subject Name
Issuer Name
Public Key
Validity Period
Digital Signature
Authentication Applications:
Kerberos
Ticket-based authentication
X.509
Certificate-based authentication
Advantages:
70
Supports HTTPS and SSL/TLS
Introduction
Electronic mail (E-mail) is one of the most widely used communication methods on the
Internet.
Eavesdropping
Message Modification
Spoofing
Phishing
Spam
Security Requirements
1. Confidentiality
2. Authentication
3. Integrity
4. Non-Repudiation
It provides:
Confidentiality
Authentication
Integrity
Compression
71
Working of PGP
Step 1: Authentication
Step 2: Confidentiality
Step 3: Transmission
Advantages
Strong security
Widely used
Uses:
Digital Signatures
X.509 Certificates
Services Provided
1. Authentication
2. Integrity
72
3. Confidentiality
4. Non-Repudiation
Advantages
Industry standard
Certificate-based security
Strong authentication
PGP S/MIME
Flexible Standardized
IP SECURITY (IPSec)
Objectives
1. Authentication
2. Integrity
3. Confidentiality
4. Access Control
IPSec Services
73
Data Authentication
Data Integrity
Encryption
Replay Protection
IPSec Protocols
Provides:
Authentication
Integrity
Encryption
Provides:
Confidentiality
Authentication
Integrity
Modes of IPSec
Transport Mode
Tunnel Mode
74
Applications
VPNs
Secure Communication
Remote Access
WEB SECURITY
Introduction
Web security protects websites, web applications, and users from attacks.
1. Phishing
2. SQL Injection
4. Session Hijacking
SSL/TLS
HTTPS
Advantages
75
Data Encryption
Authentication
Integrity Protection
SYSTEM SECURITY
System security protects computer systems from attacks and unauthorized access.
INTRUDERS
Definition
Types of Intruders
1. Masquerader
Example
2. Misfeasor
Example
3. Clandestine User
Example
Intrusion Detection
76
Methods used to detect intruders:
Host-Based IDS
Network-Based IDS
Definition
Types of Malware
1. Virus
2. Worm
3. Trojan Horse
4. Ransomware
5. Spyware
6. Adware
VIRUSES
Definition
A virus is a malicious program that attaches itself to a host program and spreads when the
host runs.
77
Working
1. Infection
2. Replication
3. Activation
4. Execution
Types of Viruses
File Virus
Macro Virus
Infects documents.
Polymorphic Virus
Prevention
Antivirus software
Regular updates
Safe browsing
Email filtering
FIREWALLS
Definition
A firewall is a security system that monitors and controls incoming and outgoing network
traffic.
78
Trusted Network ↔ Firewall ↔ Internet
Functions
Access Control
Traffic Filtering
Monitoring
Logging
Types of Firewalls
Advantages:
Fast
Simple
Advantages:
Better security
Example:
HTTP
FTP
4. Proxy Firewall
79
Advantages:
High security
Advantages of Firewalls
Monitor traffic
Block attacks
Answer
PGP (Pretty Good Privacy) is an email security system that provides confidentiality,
authentication, integrity, and digital signatures.
Working:
Advantages:
Strong security
Answer
S/MIME is a secure email standard that uses public key cryptography and X.509 certificates.
80
Services:
Authentication
Integrity
Confidentiality
Non-Repudiation
Advantages:
Industry standard
Certificate-based security
Answer
Protocols:
Authentication
Integrity
Confidentiality
Authentication
Integrity
Applications:
VPNs
Secure networking
Answer
Types:
81
1. Masquerader
2. Misfeasor
3. Clandestine User
Detection:
Host-Based IDS
Network-Based IDS
Answer
Types:
4. Proxy Firewall
Advantages:
Protects networks
Answer
Electronic Mail Security protects emails from unauthorized access, modification, and
spoofing.
Security Requirements
1. Confidentiality
2. Integrity
82
3. Authentication
4. Non-Repudiation
PGP
Provides:
Encryption
Authentication
Digital Signatures
Working:
Hash message
S/MIME
Uses:
X.509 Certificates
Provides:
Authentication
Integrity
Confidentiality
Comparison
Answer
Services
Authentication
83
Integrity
Confidentiality
Replay Protection
Protocols
AH
Authentication
Integrity
ESP
Confidentiality
Authentication
Integrity
Modes
Transport Mode
Tunnel Mode
Applications:
VPNs
Answer
Common Attacks
Phishing
SQL Injection
84
Cross-Site Scripting (XSS)
Session Hijacking
Protection Methods
HTTPS
TLS
Secure coding
Input validation
Authentication mechanisms
Answer
Types
1. Virus
2. Worm
3. Trojan Horse
4. Ransomware
5. Spyware
6. Adware
1. Infection
2. Replication
3. Activation
4. Execution
Types of Viruses
85
File Virus
Macro Virus
Polymorphic Virus
Prevention
Antivirus software
Updates
Safe browsing
Answer
A firewall is a network security device that controls traffic between trusted and untrusted
networks.
Functions
Traffic Filtering
Access Control
Monitoring
Logging
Types
4. Proxy Firewall
Advantages
86
87
88
89
90