6th SEMESTER
BACHELOR OF COMPUTER APPLICATIONS (BCA)
COMPUTER
NETWORKING-II
Course Code: BCA/6/EC/32(b)
HIGHER AND TECHNICAL INSTITUTE, MIZORAM (HATIM)
Department of Computer Science
Kawmzawl: Pukpui, Lunglei – 796691, Mizoram
Affiliated to Mizoram University
UGC recognized 2(f) and 12(B) Institution
Website: [Link]
TABLE OF CONTENT
UNIT PAGES
UNIT -1
INTRODUCTION ……………..………………………………..………………………….. 1 – 20
UNIT -2
CRYPTOGRAPHY ……………………………………………………………………….. 21 – 34
UNIT -3
NETWORK SECURITY ……………………………….……………………………….. 35 – 46
UNIT -4
IP SECURITY ……………………………………………………………………………….. 47 – 64
UNIT -5
SECURITY TECHNOLOGY ……….………………………………………..……….. 65 - 78
Sixth Semester
Course No.: BCA/6/EC/32 (b)
COMPUTER NETWORKING –II
Marks Scale: 100 marks (End Sem. Exam: 75 + Int.: 25) Credit: 5
(4- 1- 0)
UNIT-1 (INTRODUCTION): (10 L)
Attacks (Virus, Worms, Trojan Horses, Hoaxes, Dictionary attack, Brute Force, DOS,
DDOS, Phishing, Spoofing, Man-in-the-middle, Mail bombing, Sniffers, Social
Engineering), Services and Mechanism, Model for Internetwork Security.
UNIT-2 (CRYPTOGRAPHY): (10 L)
1) Cryptography, Plain Text, Ciphertext, Key,
2) Symmetric key cryptography (Traditional ciphers, DES, AES),
3) Asymetric -Key Cryptography (RSA, Diffie-Hellman),
UNIT-3 (NETWORK SECURITY): (10 L)
1) Message Confidentiality
2) Message Integrity (Message Digest, SHA-1),
3) Message Authentication (MAC, HMAC),
4) Digital signature,
5) Entity authentication.
6) Key management.
UNIT-4 (SECURITY IN THE INTERNET): (10 L)
1. IP Security: AH, ESP, services, Security association, IKE, VPN.
2. SSL/TLS: SSL(Services, security parameters, sessions & connections, protocols, TLS.
3. PGP (Security parameters, services, Key rings, Certificates).
4. Firewalls (Packet-filter and Proxy firewalls).
UNIT-5 (SECURITY TECHNOLOGY): (10 L)
1) Intrusion detection and prevention system (IDPS),
2) Port scanners,
3) Firewall analysis tools,
4) Operating system detection tools,
5) Vulnerability scanners,
6) Packet sniffers,
7) Wireless security tools.
8) Antivirus Software,
9) Malicious virus remover,
10) Worm remover.
Recommended Books:
1. Behrouz A Forouzan: Data Communication and Networking, 4th Edition Tata
McGraw Hill Publication (2003).
2. Andrew S. Tanenbaum: Computer Networks, 5th Edition, Prentice Hall Publication
(2010).
3. Michael E. Whitman and Herbert J. Mattort: Principles of Information Security, 4th
Edition, Cengage Learning (2011).
3. W. Stallings: Networks Security Essentials: Application & Standards, Pearson
Education (2000).
4. W. Stallings: Cryptography and Network Security, Principles and Practice, Pearson
Education (2000).
UNIT – 1
INTRODUCTION
UNIT-1 (INTRODUCTION): (10 L)
Attacks (Virus, Worms, Trojan Horses, Hoaxes, Dictionary attack, Brute Force, DOS,
DDOS, Phishing, Spoofing, Man-in-the-middle, Mail bombing, Sniffers, Social
Engineering), Services and Mechanism, Model for Internetwork Security.
What is MALWARE?
The term "malware" is an amalgamation of malicious and software. Malware is an
umbrella term that is used to cover all types of malicious software. Malware is any
software intentionally designed to cause damage to a computer, server, client, or
computer network. Malware can infect personal computers, smartphones, tablets,
servers and even equipment — basically any device with computing capabilities.
Here are some common types of malware you might have heard about:
Virus: A harmful computer program that can copy itself and infect a computer.
Worm: A malicious computer program that sends copies of itself to other
computers via a network.
Spyware: Malware that collects information from people without their
knowledge.
Adware: Software that automatically plays, displays, or downloads
advertisements on a computer.
Trojan horse: A destructive program that pretends to be a useful application,
but harms your computer or steals your information after it's installed.
How to prevent malware:
1. Keep your computer and software updated.
2. Use a non-administrator account whenever possible.
3. Think twice before clicking links or downloading anything.
4. Be careful about opening email attachments or images.
5. Don't trust pop-up windows that ask you to download software.
6. Limit your file-sharing.
7. Use Antivirus software.
UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION 1
1. VIRUS:
A computer virus is a type of computer program that, when executed, replicates
itself by modifying other computer programs and inserting its own code. This code
infects a file or program and if it spreads massively, it may ultimately result in
crashing of the device. Viruses are always man-made.
Some of the effects of computer virus are:
1) It can steal data or passwords, log keystrokes,
2) Spam your email contacts,
3) Corrupt files,
4) Erase data,
5) It can cause permanent damage to the hard disk.
6) It can even take control over your device/computer system.
TYPES OF COMPUTER VIRUS:
1) Boot Sector Virus – It is a type of virus that infects the boot sector of floppy
disks or the Master Boot Record (MBR) of hard disks.
2) Direct Action Virus – When a virus attaches itself directly to a .exe or .com
file. If it gets installed in the memory, it keeps itself hidden. It is also known as
Non-Resident Virus.
3) Resident Virus – A virus which saves itself in the memory of the computer
and then infects other files and programs. It is hard to be removed from the
system.
4) Multipartite Virus – A virus which can attack both, the boot sector and the
executable files.
5) Overwrite Virus –can completely remove the existing program and replace it
with the malicious code by overwriting it.
6) Polymorphic Virus – Spread through spam and infected websites.
7) File Infector Virus – As the name suggests, it first infects a single file and then
later spreads itself to other executable files and programs.
8) Spacefiller Virus – It is a rare type of virus which fills in the empty spaces of a
file with viruses. It is known as cavity virus.
9) Macro Virus – A virus written in the same macro language as used in the
software program and infects the computer if a word processor file is opened.
Mainly the source of such viruses is via emails.
2 UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION
What is an Anti-Virus?
An Anti-virus is software that can detect and remove all the harmful and malicious
software from your device. Some of the major antivirus softwares commonly used are
listed below:
1) Norton Antivirus
2) Kaspersky Antivirus
3) AVAST Antivirus
4) Comodo Antivirus
5) McAfee Antivirus
10-WORST COMPUTER VIRUSES IN HISTORY:
1) Mydoom: $38 billion in 2004. - (estimated damage)
2) Sobig – $30 billion
3) Klez – $19.8 billion
4) ILOVEYOU – $15 billion
5) WannaCry – $4 billion
6) Zeus – $3 billion
7) Code Red – $2.4 billion
8) Slammer – $1.2 billion
9) CryptoLocker – $665 million
10) Sasser – $500 million
(Source: [Link]
OTHER FAMOUS COMPUTER VIRUSES:
1) CREEPER: It was the first-ever computer virus, self-replicating virus released
in the year 1971. Its creator was Bob Thomas.
2) BRAIN: In January of 1986, the first virus written for Windows based PCs
was “Brain,” began infecting 5.2" floppy disks it was written by two brothers,
Basit and Amjad Farooq Alvi, who ran a computer store in Pakistan. They
were only 17 and 24 years old at the time.
UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION 3
2. WORM:
A computer worm is a type of malware that spreads copies of itself from computer
to computer. A worm can replicate itself without any human interaction, and it
does not need to attach itself to a software program in order to cause damage. It
often uses a computer network by exploiting vulnerabilities, moving quickly from one
computer to another. Because of this, worms can propagate themselves and spread
very quickly – not only locally, but have the potential to disrupt systems worldwide.
Types of worms are as follows:
1) Email Worms: spread through malicious email as an attachment or a link of a
malicious website.
2) Instant Messaging Worms: spread by sending links to the contact list of
instant messaging applications such as Messenger, WhatsApp, Skype, etc.
Worms cause damage similar to viruses, exploiting holes in security software and
potentially stealing sensitive information, corrupting files and installing a back door
for remote access to the system, among other issues.
PRIMARY DIFFERENCE
S.N
VIRUS WORM
Virus needs another program to Worms are stand-alone malicious
1 make it work, like a word processor programs that can self-replicate and
or web browser. propagate independently.
The main objective of viruses is to The main objective of worms is to eat
2
modify the information. the system resources.
3 It is less harmful. It is more harmful as compared.
Antivirus software is used for Worms can be detected and removed
4
protection against viruses. by the Antivirus and firewall.
It does not need human action to
5 It needs human action to replicate.
replicate.
4 UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION
3. TROJAN HORSE:
A Trojan horse is a type of malicious code or software that looks legitimate but can
take control of your computer. A Trojan is sometimes called a Trojan virus or a Trojan
horse virus, A Trojan is designed to damage, disrupt, steal, or in general inflict
some other harmful action on your data or network. Viruses can execute and
replicate themselves. A Trojan cannot. The term is derived from the Ancient Greek
story of the deceptive Trojan horse that led to the fall of the city of Troy.
Here is one example of how a Trojan horse infects a personal computer: The victim
receives an official-looking email with an attachment. The attachment contains
malicious code that is executed as soon as the victim clicks on the attachment.
You can remove some Trojans by disabling startup items on your computer which
don't come from trusted sources. For the best results, first reboot your device into
safe mode so that the virus can't stop you from removing it.
SIGNS OF A TROJAN VIRUS:
1) Slow computer.
2) Blue screen of death.
3) Strange pop-ups.
4) Unfamiliar add-ons and plugins.
5) Applications acting strange.
6) Disabled security application such as UAC.
7) Insufficient memory.
8) Changed desktop.
9) Being redirected to unfamiliar websites.
10) Weird icons on the taskbar.
11) Missing files.
12) Receiving spam.
UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION 5
4. HOAXES:
A virus hoax is a false warning about a computer virus. Typically, the warning
arrives in an e-mail note or is distributed through a note in a company's internal
network. These notes are usually forwarded using distribution lists and they will
typically suggest that the recipient forward the note to other distribution lists.
If you get a message about a new virus, you can check it out by going to one of the
leading Web sites that keep up with viruses and virus hoaxes. If someone sends you a
note about a virus that you learn is a virus hoax, reply to the sender that the virus
warning is a hoax.
This is often a chain message telling recipients to forward the mail to all their
contacts. The aim is simply to cause alarm and confusion among users.
What should you do with hoaxes?
If you receive a hoax, it is advisable to simply ignore it and not forward it to anyone.
The main characteristics that help to identify these fake virus alerts are:
1) To make the messages look real, they normally include the header of a reputable
news or media agency. Similarly, the messages rarely include a date, so that they
will always appear recent, even if they have been in circulation for a long time.
2) They are always sent via email, in order to spread these rumours across the Web.
3) The messages are normally alarmist and encourage users to take immediate
action to resolve the infection. You should never follow these instructions, as they
can often be damaging to your computer.
4) As a general rule, they claim that the supposed virus goes undetected by antivirus
programs, in order to explain why users' security software has not detected the
infection.
6 UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION
5. DICTIONARY ATTACK:
A dictionary attack is a method of breaking into a password-protected computer
or server by systematically entering every word in a dictionary as a form of
password. Dictionary attacks work because many computer users and businesses
insist on using ordinary words as passwords.
What is the Difference between Brute Force and Dictionary Attack?
S.N BRUTE FORCE DICTIONARY ATTACK
1 large number of key combination Limited to certain common keys
Time is depending on the password Time is depending on the length
2
strong and length of dictionary.
it aims at trying all possible The attacker tries a list of known or
3 combinations in the password commonly used passwords, which
space. are likely to work
A brute force attack is primarily
A dictionary attack is primarily used
4 used against the encryption
against passwords.
algorithm itself
dictionary attacks succeed because
many people have a tendency to
5
choose passwords which are short
and easy to remember
Dictionary attacks are
more efficient – they usually don't
6 Less efficient
need to try as many combinations to
succeed.
UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION 7
6. BRUTE-FORCE ATTACK:
A brute-force attack is a popular cracking method. The cracker/attacker
systematically checks all possible passwords and passphrases until the correct one is
found. The longer the password, the more combinations that will need to be tested.
Brute force is a simple attack method and has a high success rate.
Suppose, Nine-character passwords take 5-days to break, 10-character words take 4-
months, and 11-character passwords take 10-years. A brute-force attack tries
every possible combination of letters, special symbols, and numbers. It can guess a
six-character password in one-hour. If your password is long and complex, it
will take days or even years to crack it.
TYPES OF BRUTE FORCE ATTACKS:
1) Simple brute force attack—uses a systematic approach to „guess‟ that doesn’t
rely on outside logic.
2) Hybrid brute force attacks—starts from external logic to determine which
password variation may be most likely to succeed, and then continues with
the simple approach to try many possible variations.
3) Dictionary attacks—guesses usernames or passwords using a dictionary of
possible strings or phrases.
4) Rainbow table attacks—a rainbow table is a precomputed table for reversing
cryptographic hash functions. It can be used to guess a function up to a
certain length consisting of a limited set of characters.
5) Reverse brute force attack—uses a common password or collection of
passwords against many possible usernames.
6) Credential stuffing—uses previously-known password-username pairs, trying
them against multiple websites.
How to Defend Against Brute Force Attacks:
1) Increase password length: More characters equal more time to brute force
crack
2) Increase password complexity: More options for each character also
increase the time to brute force crack
8 UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION
3) Limit login attempts: A good defense against brute force attacks is to lock
out users after a few failed attempts, thus nullifying a brute force attack in
progress
4) Implement Captcha: Captcha is a common system to verify a human is a
human on websites and can stop brute force attacks in progress
5) Use multi-factor authentication: Multi-factor authentication adds a second
layer of security to each login attempt that requires human intervention which
can stop a brute force attack from success
7. DOS ATTACK:
A Denial-of-service attack (DoS attack) is an attempt to make a computer or
network resource unavailable to its intended users. The primary goal of a DoS
attack is not to steal information but to slow or take down a web site. Denial
of Service attacks (DOS attacks) involves flooding a computer or a server with
more requests than it can handle. This causes the computer (e.g. a web server)
to crash and the authorized users could not access the service offered by the
computer. Denial-of-service (DoS) attacks typically flood servers, systems or
networks with traffic in order to overwhelm the victim resources and make it
difficult or impossible for legitimate users to use them.
How do you detect DoS attacks?
The best way to detect and identify a DoS attack would be via network traffic
monitoring and analysis. Network traffic can be monitored via a firewall or
intrusion detection system. The United States Computer Emergency Readiness
Team (US-CERT) provides some guidelines for determining when a DoS attack,
the following may indicate such an attack:
1) Degradation in network performance, especially when attempting to open
files stored on the network or accessing websites;
2) Inability to reach a particular website;
3) Difficulty in accessing any website; and
4) A higher than usual volume of spam email.
UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION 9
Difference between DOS and DDOS attack:
S.N DOS ATTACK DDOS ATTACK
It stands for Denial of service It stands for Distributed Denial of
1
attack. service attack.
Single system targets the victims Multiple system attacks the victims
2
system. system.
Victim PC is loaded from the packet Victim PC is loaded from the packet of
3
of data sent from a single location. data sent from Multiple locations.
4 It is slower as compared to DDos. It is faster than Dos Attack.
It is difficult to block this attack as
Can be blocked easily as only one
5 multiple devices are sending packets
system is used.
and attacking from multiple locations.
Only single device is used with Bots are used to attack at the same
6
DOS Attack tools. time.
7 DOS Attcaks are Easy to trace. DDOS Attacks are Difficult to trace.
It allows the attacker to send massive
Volume of traffic is less as
8 volumes of traffic to the victim
compared to DDos.
network.
Types of DOS Attacks are: Types of DDOS Attacks are:
1. Buffer overflow attacks 1. Volumetric Attacks
9
2. Ping of Death or ICMP flood 2. Fragmentation Attacks
3. Teardrop Attack 3. Application Layer Attacks
10 UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION
8. DDOS ATTACK:
Distributed Denial of Service (DDoS) is a type of DOS attack where multiple
systems, which are trojan infected, target a particular system which causes a DoS
attack. A DDoS attack uses multiple servers and Internet connections to flood the
targeted resource. A DDoS attack is one of the most powerful weapons on the
cyber platform. When you come to know about a website being brought down, it
generally means it has become a victim of a DDoS attack. This means that the
hackers have attacked your website or PC by imposing these with heavy traffic. Thus,
crashing the website or computer due to overloading.
Examples of DDoS attacks:
In 2000, Michael Calce, a 15-year-old boy who used the online name “Mafiaboy”,
was behind one of the first DDoS attacks. He hacked into the computer networks of
various different universities. He used their servers to operate a DDoS attack that
brought down several websites such as eBay and Yahoo.
In 2016, Dyn was hit with a massive DDoS attack that took down major websites and
services such as Netflix, PayPal, Amazon and GitHub.
UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION 11
9. PHISHING:
Phishing is a type of social engineering. The term Phishing refers to the sending of
fraudulent message (usually email) that appears to come from a trusted source
such as banks, company or organization, etc. designed to trick the recipient
into revealing confidential information. That's why it is always advisable to access
Web pages by writing the address directly in the browser.
How does phishing work?
Most phishing attacks begin when the victim receives an email or message in which
the sender acting like a bank or another real company or organization in order to
trick the recipient. The email contains links to websites prepared by the criminals
and with the appearance of a legitimate website which asks the victim to enter
personal data.
Even though email is still the most common method used by cybercriminals for this
type of fraud, phishing can take advantage of other means of communication,
including: SMS (sometimes called 'smishing'), VoIP ('vishing') or instant
messaging on social networks.
Cybercriminals also use certain social engineering tricks to alarm recipients, with
warnings and emergency alerts to spur victims into action. The idea is to get users to
act immediately without considering the potential risks.
How to identify a phishing message:
1) It is unusual for companies -whether they are banks or utilities- to ask for
personal data via email. The simple fact that a message like this appears
should raise your suspicions.
2) It is not always easy to recognize phishing messages by their appearance.
However, producing a good replica of a company's format requires time and
effort that criminals are often not prepared to invest. Errors, typos and spelling
mistakes are frequently a giveaway. Also, check the address of the sender.
3) Take care with the operations you carry out from your smartphone. Criminals
know this and try to take advantage of the lesser visibility of small screens and
weaker general security.
12 UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION
How to protect against phishing:
1) After reading the email don't click on any links. Always access directly by
entering the address in your browser.
2) Improve the security of your computer. You should always have the latest
updates to your operating system and browser.
3) Ideally, you should also have a professional antivirus.
4) Only enter confidential information in secure websites like the address begins
with "[Link] meaning that the transfer protocol is secure
5) Check your accounts frequently. It's always worth checking bills and bank
accounts from time to time to see if there are any strange transactions.
10. SPOOFING:
Spoofing is when an attacker impersonates an authorized device or user to steal
data, spread malware, or bypass access control systems.
There are many different types of spoofing, with three of the most common being:
1) IP address spoofing: Attacker sends packets over the network from a false
IP address
2) ARP spoofing: Attacker links their MAC address to an authorized IP
address already on the network
3) DNS spoofing: Attacker initiates a threat such as cache poisoning to
reroute traffic intended for a specific domain name traffic to a different IP
address
For example, when a caller on the other end falsely introduces themselves as a
representative of your bank and asks for your account or credit card info, you are a
victim of phone spoofing.
Email spoofing is the forgery of the sender's email address so that the message
appears to have originated from the sender, but in reality the sender is not the source
of the email. It’s similar to faking the return address on an envelope. Email spoofing
is a computer crime since it is considered as fraud.
UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION 13
11. MAN-IN-THE-MIDDLE:
A man-in-the-middle attack is a type of eavesdropping attack, where attackers
interrupt an existing conversation or data transfer. After inserting themselves in the
"middle" of the transfer, the attackers pretend to be legitimate participants. This
enables an attacker to intercept information and data from either party while also
sending malicious links or other information to both legitimate participants in a way
that might not be detected until it is too late.
You can think of this type of attack as similar to the game of telephone where one
person's words are carried along from participant to participant until it has changed
by the time it reaches the final person. In a man-in-the-middle attack, the middle
participant manipulates the conversation unknown to either of the two legitimate
participants, to retrieve confidential information and otherwise cause damage.
Key Concepts of a Man-in-the-Middle Attack:
1) It is a type of session hijacking
2) Involve attackers inserting themselves as proxies in an on-going, legitimate
conversation or data transfer
3) Exploit the real-time nature of conversations and data transfers to go
undetected.
4) Allow attackers to intercept confidential data.
5) Allow attackers to insert malicious data and links in a way indistinguishable
from legitimate data
14 UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION
12. E-MAIL BOMBING:
The term “e-mail bombing” can also refer to flooding an E-mail Server with too
many e-mails in an attempt to overwhelm the email server and bring it down or
mail servers crashing. But it would be challenging to bring down modern email
accounts that use Google or Microsoft’s email servers, anyway.
Email bombing is characterized by an abuser sending huge volumes of email to a
target e-mail address resulting in victim’s email account or mail servers crashing. The
message is meaningless and excessively long in order to consume network
resources. If multiple accounts of a mail server are targeted, it may have a denial-of-
service impact. Such mail arriving frequently in your inbox can be easily detected by
spam filters. Email bombing is commonly carried out using botnets (private internet
connected computers whose security has been compromised by malware and under
the attacker’s control) as a DDoS attack. This type of attack is more difficult to control
due to multiple source addresses and the bots which are programmed to send
different messages to defeat spam filters.
“Spamming” is a variant of email bombing. Here unsolicited bulk messages are sent
to a large number of users, indiscriminately. Opening links given in spam mails may
lead you to phishing web sites hosting malware. Spam mail may also have infected
files as attachments. Email spamming worsens when the recipient replies to the email
causing all the original addressees to receive the reply. Spammers collect email
addresses from customer lists, newsgroups, chat-rooms, web sites and viruses which
harvest users’ address books, and sell them to other spammers as well. A large
amount of spam is sent to invalid email addresses.
Sending spam violates the acceptable use policy (AUP) of almost all internet service
providers. If your system suddenly becomes sluggish (email loads slowly or doesn’t
appear to be sent or received), the reason may be that your mailer is processing a
large number of messages. Unfortunately, at this time, there’s no way to completely
prevent email bombing and spam mails as it’s impossible to predict the origin of the
next attack. However, what you can do is identify the source of the spam mails and
have your router configured to block any incoming packets from that address.
UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION 15
13. SNIFFERS:
Sniffing is the process of monitoring and capturing all data packets that are passing
through a computer network using packet sniffers. Packet Sniffers are used by
network administrators to keep track of data traffic passing through their network.
These are called Network Protocol Analyzers. In the same way, malicious attackers
employ the use of these packet sniffing tools to capture data packets in a
network. Data packets captured from a network are used to extract and steal
sensitive information such as passwords, usernames, credit card information, etc.
Attackers install these sniffers in the system in the form of software or hardware.
There are different types of sniffing tools like Wireshark, Ettercap, BetterCAP,
Tcpdump, Windump, etc.
Types of Sniffing:
There are two types of sniffing attacks, active sniffing and passive sniffing.
1) Active sniffing: this is sniffing that is conducted on a switched network. A
switch is a device that connects two network devices together. Switches use
the media access control (MAC) address to forward information to their
intended destination ports. Attackers take advantage of this by injecting
traffic into the LAN to enable sniffing.
2) Passive sniffing: passive sniffing uses hubs instead of switches. Hubs
perform the same way as switches only that they do use MAC address to
read the destination ports of data. All an attacker needs to do is to simply
connect to LAN and they are able to sniff data traffic in that network.
The Difference between Sniffing and Spoofing:
In sniffing, the attacker listens into a networks’ data traffic and captures
data packets using packet sniffers.
In spoofing, the attacker steals the credentials of a user and uses them in a
system as a legitimate user. Spoofing attacks are also referred to as “man-in-the–
middle attacks” since the attacker gets in the middle of a user and a system.
16 UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION
14. SOCIAL ENGINEERING:
Social engineering is the art of exploiting human psychology, rather than
technical hacking techniques, to gain access to buildings, systems or data.
Phishing is the most common type of social engineering attack. Social engineering is
malicious activities accomplished through human interactions. It uses psychological
manipulation to trick users into making security mistakes or giving away sensitive
information.
Social engineering attacks happen in one or more steps. A perpetrator/attacker first
investigates the intended victim to gather necessary background information, such
as potential points of entry and weak security protocols, needed to proceed with the
attack. Then, the attacker moves to gain the victim’s trust and provide stimuli for
subsequent actions that break security practices, such as revealing sensitive
information or granting access to critical resources.
For example, instead of trying to find software vulnerability, a social engineer
might call an employee and pose as an IT support person, trying to trick the
employee into divulging his password.
Social engineering has proven to be a very successful way for a criminal to "get
inside" your organization. Once a social engineer has a trusted employee's
password, he can simply log in and snoop around for sensitive data. With an
access card or code in order to physically get inside a facility, the criminal can
access data, steal assets or even harm people.
Social engineering attack techniques:
Social engineering attacks come in many different forms and can be performed
anywhere where human interaction is involved. The following are the most common
forms of digital social engineering assaults.
1) Baiting: As its name implies, baiting attacks use a false promise to the
victim’s greed or curiosity. They put users into a trap that steals their personal
information or inflicts their systems with malware.
UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION 17
2) Scareware: Scareware involves victims being bombarded with false alarms
and threats. Users are deceived to think their system is infected with malware,
prompting them to install software that has no real benefit (other than for the
perpetrator) or is malware itself. Scareware is also referred to as deception
software, rogue scanner software and fraud ware.
A common scareware example is while surfing the web, displaying such text
such as, “Your computer may be infected with harmful spyware programs.” It
either offers to install the tool (often malware-infected) for you, or will direct
you to a malicious site where your computer becomes infected.
3) Phishing: As one of the most popular social engineering attack
types, phishing scams are email and text message campaigns aimed at
creating a sense of urgency, curiosity or fear in victims. It then prods them into
revealing sensitive information, clicking on links to malicious websites, or
opening attachments that contain malware.
18 UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION
A MODEL FOR NETWORK SECURITY:
The goal of network security is to keep the network running and safe for all
legitimate users. When we send our data from source to destination we have to
use some transfer method like the internet or any other communication channel
by which we are able to send our message. The two parties, who are the principals
in this transaction, must cooperate for the exchange to take place. When the
transfer of data happened from one source to another source some logical
information channel is established between them by defining a route through the
internet from source to destination. When we use the protocol for this logical
information channel the main aspect security has come. The technique for
providing security have two components:
1) A security-related transformation on the information to be sent.
2) Some secret information shared by the two principals and, it is hoped,
unknown to the opponent.
A trusted third party may be needed to achieve secure transmission. For example,
a third party may be responsible for distributing the secret information to the two
principals while keeping it from any opponent. Or a third party may be needed to
arbitrate disputes between the two principals concerning the authenticity of a
message transmission.
This model shows that there are four basic tasks in designing a particular security
service:
1) Design an algorithm for performing the security-related transformation.
2) Generate the secret information to be used with the algorithm.
3) Develop methods for the distribution and sharing of secret information.
4) Specify a protocol to be used by the two principals that make use of the
security algorithm and the secret information to achieve a particular security
service.
UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION 19
20 UNIT-1 | COMPUTER NETWORKING-II | INTRODUCTION
UNIT – 2
CRYPTOGRAPHY
UNIT-2 (CRYPTOGRAPHY): (10 L)
1) Cryptography, Plain Text, Ciphertext, Key
2) Symmetric key cryptography (Traditional ciphers, DES, AES)
3) Asymmetric -Key Cryptography (RSA, Diffie-Hellman)
What is CRYPTOGRAPHY?
The term cryptography comes from Greek words, means “secret writing”. It is the
science and art of transforming messages to make them secure and immune to
attacks. Network security is mostly achieved through the use of cryptography.
Cryptography can provide confidentiality, integrity, authentication, non-repudiations
of messages and entity authentication.
Cryptography is divided into two categories:
1) Symmetric Key Cryptography: The same key (secret key) is used by both
parties. The sender uses this key to encrypt the data; the receiver also uses the
same key to decrypt the data. The Key is shared.
2) Asymmetric Key Cryptography: There are two keys such as Private Key and
Public Key. Private Key is kept by the receiver. The public key is announced to
the public. Public key is used to encrypt the message. The private key is used
to decrypt the message.
N.B:
1. Software Product Key can be an example of Secret Key.
2. E-mail ID/Bank A/c No. can be a Public Key, Password/MPIN/TPIN can
be a Private Key.
UNIT-2 | COMPUTER NETWORKING-II | CRYPTOGRAPHY 21
PLAINTEXT and CIPHERTEXT
The original message, before being transformed, is called plaintext. It is a message
in a form that is easily readable by humans. After the message is transformed, it is
called ciphertext. An Encryption Algorithm transforms the plaintext into ciphertext;
a Decryption Algorithm transforms the ciphertext back into plaintext. The sender
uses an encryption algorithm, and the receiver uses a decryption algorithm.
What is KEY?
A key is a number (or a set of numbers) that the cipher, as an algorithm, operates on.
It locks (encrypts) data so that only someone with the right key can unlock (decrypt)
it. To encrypt a message, we need
1) Encryption Algorithm
2) Encryption Key
3) Plaintext. These create the ciphertext.
To decrypt a message, we need
1) Decryption Algorithm
2) Decryption Key
3) Ciphertext. These create the original plaintext.
Three types of Keys in Cryptography:
1) Secret Key: used in Symmetric Cryptography.
2) Public Key: used in Asymmetric Cryptography.
3) Private Key: used in Asymmetric Cryptography.
22 UNIT-2 | COMPUTER NETWORKING-II | CRYPTOGRAPHY
I. SYMMETRIC KEY CRYPTOGRAPHY:
The same key (secret key) is used by both parties. The sender uses this key to
encrypt the data; the receiver also uses the same key to decrypt the data. The Key is
shared.
There are different types of Symmetric Key Cryptography:
1) Traditional ciphers
2) Data encryption standard (DES)
3) Advanced Encryption Standard (AES)
4) IDEA (International Data Encryption Algorithm)
5) Blowfish (Drop-in replacement for DES or IDEA)
6) RC5 (Rivest Cipher 5)
1. TRADITIONAL CIPHERS:
Traditional Ciphers are character-oriented. They are broadly divided into two
categories:
1) SUBSTITUTION CIPHERS: It replaces one symbol with another. For
example, we can replace character A with D, and character T with Z. If the
symbols are digits, we can replace 3 with 7, and 2 with 6. Substitution ciphers
can be categorized into two:
i. Monoalphabetic cipher: A character/symbol is always changed to the
same character/symbol. For example, if the character L is changed to O,
every character L is changed to character O.
Plaintext : HELLO
Ciphertext : KHOOR
UNIT-2 | COMPUTER NETWORKING-II | CRYPTOGRAPHY 23
ii. Polyalphabetic cipher: Each occurrence of a character can have a
different substitute. For example, Character L could be changed to N in
the beginning of the text, but it could be changed to Z at the middle.
Plaintext : HELLO
Ciphertext : ABNZF
SHIFT CIPHER:
The simplest Monoalphabetic cipher is probably the SHIFHT CIPHER, Where
the encryption algorithm is “shift key character down”; the decryption
algorithm is “shift key character up”. The shift cipher is sometimes referred
to as the Caesar Cipher.
Example: Shift Cipher with key=15 to encrypt the message “HELLO”
Each character is shifted 15 characters down. H is encrypted to W, E is
encrypted to T, and so on.
Plaintext : HELLO
Ciphertext : WTAAD
2) TRANSPOSITION CIPHERS: There is no substitution of characters;
instead, their locations change. A character in the 1st position may appear in
the 10th position of the ciphertext. A transposition ciphers re-orders
(permutes) symbols in a block of symbols.
Plaintext : 2 4 1 3
Ciphertext : 1 2 3 4
Example: Encrypt the message “HELLO MY DEAR” using the above key.
Solution: we first remove the spaces in the message. Divide the text into
block of 4 characters. We add a bogus (filler) character Z at the end of the
third block. The result is HELL OMYD EARZ. The ciphertext is
ELHLMDOYAZER.
HELL OMYD EARZ
1234 1234 1234
2413 2413 2413
ELHL MDOY AZER - Ciphertext
24 UNIT-2 | COMPUTER NETWORKING-II | CRYPTOGRAPHY
Some of the Examples:
UNIT-2 | COMPUTER NETWORKING-II | CRYPTOGRAPHY 25
Two Modern Symmetric ciphers: They are referred to as „Block Ciphers‟.
i. Data encryption Standard (DES) – De facto Standard
ii. Advanced encryption Standard (AES) - Formal Standard.
2. DATA ENCRYPTION STANDARD (DES):
It was designed by IBM and adopted by the US government as the standard of
encryption method. The algorithm Data encryption Standard (DES) encrypts a 64-bit
plaintext block using a 64-bit key. These ciphers are referred to as block ciphers
because they divide the plaintext into blocks and use the same key for encryption
and decryption of the block.
64 bits
(56 bits + 8 parity bits)
DES has two transposition blocks (P-boxes) and 16 complex round ciphers. The
initial and final permutations are keyless straight permutations that are the inverse
to each other. Each round of DES is a complex round ciphers. The structure of the
encryption round ciphers is different from that of the decryption one.
26 UNIT-2 | COMPUTER NETWORKING-II | CRYPTOGRAPHY
3. ADVANCED ENCRYPTION STANDARD (AES):
It was designed because DES’s key was too small. AES is a very complex round cipher.
It is designed with three key sizes: 128, 192, or 256 bits. AES has three different
configurations with respect to the number of rounds and Key size.
Size of Data Block Number of Rounds Key Size
10 128 bits
128 bits 12 192 bits
14 256 bits
(Figure: AES configuration)
The structure and operations of the other configurations are similar. The difference
lies in the Key generation. There is an initial XOR operations followed by 10 round
ciphers.
UNIT-2 | COMPUTER NETWORKING-II | CRYPTOGRAPHY 27
II. ASYMMETRIC-KEY CRYPTOGRAPHY:
It uses two keys: Private Key and Public Key. There are two algorithms
1) Rivest, Shamir & Adleman (RSA) Algorithm
2) Diffie-Hellman Algorithm
1. RSA:
1) The most common public-key algorithm is RSA, named for its inventors
Rivest, Shamir, and Adleman (RSA).
2) Although RSA can be used to encrypt and decrypt actual messages, it is very
slow if the message is long. Therefore, RSA is useful for short messages.
3) RSA is used in digital signature and other cryptosystem that often need to
encrypt a small message.
4) RSA is also used for authentication.
(Figure: RSA Algorithm - Structure)
28 UNIT-2 | COMPUTER NETWORKING-II | CRYPTOGRAPHY
RSA stands for Rivest, Shamir, Adleman. These are the creators of the RSA
Algorithm. It is a public-key encryption technique used for secure data transmission
especially over the internet. Transmitting confidential and sensitive data over the
internet through this technology is safe due to its standard encryption method. It
was developed by scientist Rivest, Shamir, and Adleman at RSA Data Security Inc. in
1978. In this algorithm, a code is added to the normal message for security
purposes. The algorithm is based on the factorization of large number. Large
numbers cannot be easily factorized, so breaking into the message for intruders is
difficult.
Advantages of RSA
1) It is very easy to implement RSA algorithm.
2) RSA algorithm is safe and secure for transmitting confidential data.
3) Cracking RSA algorithm is very difficult as it involves complex mathematics.
4) Sharing public key to users is easy.
Disadvantages of RSA
1) It may fail sometimes because for complete encryption both symmetric and
asymmetric encryption is required and RSA uses symmetric encryption only.
2) It has slow data transfer rate due to large numbers involved.
3) It requires third party to verify the reliability of public keys sometimes.
4) High processing is required at receiver’s end for decryption.
UNIT-2 | COMPUTER NETWORKING-II | CRYPTOGRAPHY 29
Key Generation in RSA Algorithm:
Encryption & Decryption in RSA:
30 UNIT-2 | COMPUTER NETWORKING-II | CRYPTOGRAPHY
Example 1:
BOB chooses prime number 3 and 11 as p and q. Calculate the value of n and ɸ,
Solution:
p=3 and q=11 …………..(given)
n = p * q = 3*11 = 33
ɸ(n) = (p-1) (q-1) = (3-1) (11-1) = 2*10 = 20
Therefore, n=33 and q=20.
Example 2:
BOB chooses prime number 7 and 11 as p and q.
i) Calculate the value of n and ɸ,
ii) If he chooses e to be 13, then find the value of d.
iii) The plainttext is 5. Find the Ciphertext?
Solution:
i) n = p * q = 7*11 = 77
ɸ = (p-1) (q-1) = (7-1) (11-1) = 6*10 = 60
ii) d = e-1 mod ɸ = 13-1 (mod 60) = 37
iii) c= me (mod n) = 513 (mod 77) = 26
UNIT-2 | COMPUTER NETWORKING-II | CRYPTOGRAPHY 31
2. DIFFIE-HELLMAN:
It was originally designed for key exchange; two parties create symmetric session
key to exchange data without having to remember or store the key for future use.
They do not have to meet to agree on the key; it can be done through the Internet.
Before establishing a symmetric key, the two parties needs to choose two numbers p
and g. The first number p is a large prime number. The second number g is a
random number. These two numbers need not be confidential. They can be public.
Step-1: Alice Choose random number x, and calculates R1=gx mod p
Step-2: Alice sends R1 to Bob
Step-3: Bob chooses another random number y, and calculate R2=gy mod p
Step-4: Bob sends R2 to Alice
Step-5: Alice calculates K=(R2)x mod p.
Step-6: Bob calculates K=(R1)y mod p.
The symmetric key for the session is K=gxy mod p
32 UNIT-2 | COMPUTER NETWORKING-II | CRYPTOGRAPHY
Example of Diffie-Hellman:
p = prime Number, g= generator
a= Alice’s private key, b=Bob’s private key
x=Alice’s public key, y=Bob’s pubic key
K=Symmetric Key
Step 1: Alice and Bob get public/random numbers p=23, g=9
Step 2: Alice selected a private key a = 4 and
Bob selected a private key b = 3
Step 3: Alice and Bob compute public key
Alice: x = (9^4 mod 23) = (6561 mod 23) = 6
Bob: y = (9^3 mod 23) = (729 mod 23) = 16
Step 4: Alice and Bob exchange public keys.
Step 5: Alice receives public key y =16 and
Bob receives public key x = 6
Step 6: Alice and Bob compute symmetric keys
Alice: Ka = y^a mod p = 16^4 mod 23 = 65536 mod 23 = 9
Bob: Kb = x^b mod p = 6^3 mod 23 = 216 mod 23 = 9
Step 7: The shared secret key is 9
UNIT-2 | COMPUTER NETWORKING-II | CRYPTOGRAPHY 33
34 UNIT-2 | COMPUTER NETWORKING-II | CRYPTOGRAPHY
UNIT – 3
NETWORK SECURITY
UNIT-3 (NETWORK SECURITY): (10 L)
1) Message Confidentiality,
2) Message Integrity (Message Digest, SHA-1),
3) Message Authentication (MAC, HMAC),
4) Digital signature,
5) Entity authentication.
6) Key management.
What is Network Security?
Network Security can provide the following services related to a message and entity:
1) Message confidentiality
2) Message Integrity
3) Message Authentication
4) Message Nonrepudiation
5) Entity Authentication.
(Figure: Security Services related to the message or entity)
UNIT-3 | COMPUTER NETWORKING-II | NETWORK SECURITY 35
1. MESSAGE CONFIDENTIALITY:
The transmitted message must make sense to only the intended/expected
receiver. The message must be garbage to all others. To achieve such privacy, the
sender must encrypt/ encode the message and the only receiver should decrypt/
decode it. This can be done using either Symmetric-key Cryptography or
Asymmetric-key Cryptography.
1) CONFIDENTIALITY WITH SYMMETRIC-KEY CRYPTOGRAPHY: A sender and
receiver need to share a secret key. This can be done using a session key. A
session key is one that is used only for the duration of one session. The reason
Symmetric-key Cryptography is still the dominant method for confidentiality
of the message is its efficiency. For a long message, it is much more efficient
than Asymmetric-key Cryptography.
2) CONFIDENTIALITY WITH ASYMMETRIC-KEY CRYPTOGRAPHY: A secret
key can be divided into two parts, a public key and a private key. The public
key is used only for encryption; the private key is used only for decryption. The
public key locks the message; the private key unlocks it. It is very inefficient
for long messages.
PUBLIC KEY PRIVATE KEY
36 UNIT-3 | COMPUTER NETWORKING-II | NETWORK SECURITY
2. MESSAGE INTEGRITY:
Encryption and Decryption provide secrecy or confidentiality, but not integrity.
Message integrity means that a message has not been tampered with or altered.
The most common approach is to use a hash function that combines all the bytes in
the message with a secret key and produces a message digest that is difficult to
reverse.
DOCUMENT AND FINGERPRINT:
One way to preserve the integrity of a document is through the use of a fingerprint.
Alice needs to be sure that the contents of her document will not be changed; she
can put her fingerprint at the bottom of the document. Eve cannot modify the
contents of this document because Eve cannot forge Alice’s fingerprint. To preserve
the integrity of a document both the document and the fingerprint are needed.
MESSAGE AND MESSAGE DIGEST:
The electronic equivalent of the document and fingerprint pair is the message and
message digest pair. To preserve the integrity of a message, the message is passed
through an algorithm called a hash function. The hash function creates a
compressed image of the message called digest that can be used as a fingerprint.
(Figure: Message and Message digest)
SN DOCUMENT AND FINGERPRINT MESSAGE AND MESSAGE DIGEST
The document and fingerprint are The message and message digest
1
physically linked together. can be un-linked separately.
Message digests needs to be kept
2 No need to be kept secret.
secret.
UNIT-3 | COMPUTER NETWORKING-II | NETWORK SECURITY 37
CREATING AND CHECKING THE DIGEST:
The message digest is created at the sender site and is sent with the message to the
receiver. To check the integrity of the message/document, the receiver creates the
hash function again and compares the new message digest with the one received. If
both are the same, the receiver is sure that the original message has not been
changed.
(Figure: Checking integrity)
Hash Function needs to meet three criteria:
1. One-Wayness: cannot recover message from the digest.
2. Weak collision resistance: message cannot easily be forged.(ensure integrity)
3. Strong collision resistance: ensure non-repudiation.(sender cannot deny
sending a message that he sent).
38 UNIT-3 | COMPUTER NETWORKING-II | NETWORK SECURITY
SECURE HASH ALGORITHM (SHA-1):
1) Secure Hash Algorithm 1 (SHA-1) is a cryptographic hash function which
takes an input and produces a 160-bit (20-byte) hash value out of 512-bit
blocks. This hash value is known as a “message digest”. This message digest
is usually then rendered as a hexadecimal number which is 40 digits long.
2) SHA-1 is a revised version of SHA designed by the National Institute of
Standard and Technology (NIST).
3) SHA-1 generates smaller hash than SHA-256 or SHA-512.
4) SHA-1 is also less secure than SHA-256 or SHA-512. It is now considered
insecure since 2005. Major tech giants’ browsers like Microsoft, Google, Apple
and Mozilla have stopped accepting SHA-1 SSL certificates by 2017.
5) Example:
Input : hello world
Output : 2aae6c35c94fcfb415dbe95f408b9ce91ee846ed
(Figure: Message digest creation)
## Modification Detection Code (MDC) can detect any modification in the
message. It is a keyless hash function.
UNIT-3 | COMPUTER NETWORKING-II | NETWORK SECURITY 39
3. MESSAGE AUTHENTICATION:
Message authentication means that the receiver is ensured that the message is
coming from the intended sender, not an imposter.
A hash function guarantees the integrity of a message. It guarantees that the
message has not been changed. It does not authenticate the sender of the message.
When Alice sends a message to Bob, Bob needs to know if the message is coming from
Alice or Eve. To provide message authentication, Alice needs to provide that it is Alice
sending the message and not Eve.
MAC:
To provide message authentication, we need to change a Modification Detection
Code (MDC) to Message Authentication Code (MAC). An MDC uses a keyless hash
function; a MAC uses a keyed hash function. A keyed hash function includes the
symmetric key between the sender and the receiver when creating the digest.
(Figure: Message Authentication Code (MAC))
The sender used the symmetric key with the receiver, and keyed hash function
generates a MAC. The sender concatenates the original message and MAC, and send
to the receiver. The receiver separates the message from MAC. The receiver applies
the same keyed hash function to the message, to get another fresh MAC. It
compares the two MACs. If they are identical, the message has not been modified and
the message is authentic.
40 UNIT-3 | COMPUTER NETWORKING-II | NETWORK SECURITY
HMAC:
Hash-based Message Authentication Code (HMAC) is a type of a message
authentication code (MAC) that is acquired by executing a cryptographic hash
function on the data (that is) to be authenticated and a secret shared key. Like any
of the MAC, it is used for both data integrity and authentication. Checking data
integrity is necessary for the parties involved in communication. HTTPS, SFTP, FTPS,
and other transfer protocols use HMAC. Digital signatures are nearly similar to
HMACs i.e. they both employ a hash function and a shared key. The difference lies in
the keys i.e. HMACs use symmetric key (same key) while Signatures use
Asymmetri
c key (two
different
keys).
(Figure: HMAC)
From the above figure, HMAC creates a nested MAC by applying a keyless hash
function to the concatenation of the message and a symmetric key.
Applications of HMAC:
1) Verification of e-mail address during activation or creation of an account.
2) Authentication of form data that is sent to the client browser and then
submitted back.
3) HMACs can be used for Internet of things (IoT) due to less cost.
4) Whenever there is a need to reset the password, a link that can be used once
is sent without adding a server state.
UNIT-3 | COMPUTER NETWORKING-II | NETWORK SECURITY 41
4. DIGITAL SIGNATURE:
MAC can provide message integrity and message authentication, it has drawback. It
needs a symmetric key that must be established between the sender and the
receiver. A digital Signature can use a pair of Asymmetric keys (public key and
private key).
The Digital Signature is a technique which is used to validate the authenticity and
integrity of the message. It cannot provide confidentiality for the message. If
confidentiality is needed, a cryptosystem must be applied over the scheme.
Key CONVENTIONAL DIGITAL
SN
Differences SIGNATURE SIGNATURE
A conventional signature is But when we sign a document
1 Inclusion included in the document; it digitally, we send the signature
is part of the document. as a separate document.
For a digital signature, the
For a conventional signature, recipient receives the message
when the recipient receives a and the signature. The recipient
Verification document, she compares needs to apply a verification
2
Method the signature on the technique to the combination
document with the signature of the message and the
on file. signature to verify the
authenticity.
For a conventional signature, For a digital signature, there is a
there is normally a one-to- one-to-one relationship
3 Relationship
many relationship between between a signature and a
a signature and documents. message.
A duplicate copy of signed In Digital Signature, there is no
document can be such distinction unless there is
4 Duplicity
distinguished from the a factor of time on the
original one. document.
42 UNIT-3 | COMPUTER NETWORKING-II | NETWORK SECURITY
5. ENTITY AUTHENTICATION:
It is a technique designed to let one party prove the identity of another party.
An entity can be a person, a process, a client or a server. The entity whose identity
needs to be proved is called the claimant; the party that tries to prove the identity
of the claimant is called the verifier. The differences between Message
Authentication and Entity Authentication are as follows:
S.N Message Authentication Entity Authentication
1 It may not happen in real time It happens in real time
It simply authenticates one message;
It authenticates the claimant for the
2 the process needs to be repeated for
entire duration of a session.
each new message.
In entity Authentication, the claimant must identify herself to the verifier. This can be
done with one of the three kinds of witnesses:
1) Something known: Examples: Password, ATM PIN, private/secret key, etc.
2) Something possessed: Examples: Passport, Driving licence, ID card,
Credit/debit Card, Smart card, etc.
3) Something inherent: Examples: Fingerprint, Voice, Facial characteristics,
retinal patterns, handwriting, signature, etc.
PASSWORDS: The simplest and the oldest method of entity authentication is the
password. We can divide this authentication scheme into two groups:
1) FIXED PASSWORD: The Password is fixed; the same password is used over
and over again. This approach is subject to several attacks.
i. Eavesdropping: Eavesdroppers can listen to the line and then intercept
the message, thereby capturing the password for their own use.
ii. Stealing a Password: Physically stealing someone’s password happens
when they write down their password in notebooks or other materials.
iii. Accessing a file: Eve can hack into the system and get access to the
file where the passwords are stored.
iv. Guessing: Eve can login into someone’s system by guessing their
password with different combinations of characters.
2) ONE-TIME PASSWORD (OTP): Password is used only once. It makes
eavesdropping and stealing of password useless. This approach is very
complex.
UNIT-3 | COMPUTER NETWORKING-II | NETWORK SECURITY 43
6. KEY MANAGEMENT:
1. SYMMETRIC-KEY DISTRIBUTION: If Alice needs to exchange
confidential messages with N people, she needs N different keys. What if N
people needs to communicate with one another? A total of N(N-1)/2 keys is
needed. Each person needs to have N-1 keys to communicate with each other,
but because of the keys are shared, we need only N(N-1)2. This means that if
1 million people need to communicate with one another, each person has
almost 0.5 million different keys; in total almost 1 billion keys are needed. This
is normally referred to as N2 Problem because the number of required keys
for N entities is close to N2.
The number of keys is not the only problem; the distribution of keys is another
problem. If Alice wants to communicate with 1 million people, how can she
exchange 1 million keys with 1 million people? It is obvious that we need an
efficient way of maintaining and distributing secret keys:
i. KEY DISTRIBUTION CENTER (KDC):
KDC is a trusted third party that assigns a symmetric key to two
parties.
KDC creates a secret key for each member. This secret key can
be used only between a member and the KDC, not between two
members.
The secret key between members needs to be created as a
session key (temporary key) when two members contact KDC.
ii. KERBEROS:
It is a popular session key creator protocol that requires an
authentication server and a ticket-granting server.
Windows 2000 use Kerberos.
Three servers are involved in the Kerberos protocol:
Authentication Server, Ticket-granting Server and Real Server.
44 UNIT-3 | COMPUTER NETWORKING-II | NETWORK SECURITY
2. ASYMMETRIC-KEY DISTRIBUTION (Public-Key Distribution): In
this method, everyone has access to everyone’s public key; public keys are
available to the public. Public key can be distributed as follows:
i. Public Announcement: One can put his public key on his website or
newspaper. This approach is not secure; it is subject to forgery.
ii. Trusted Center: A more secure approach is to have a trusted center
having a directory of public keys.
iii. Controlled Trusted Center: higher level of security can be achieved
through this method.
iv. Certification Authority (CA): It is a federal or state organization that
binds the public key to an entity and issues a certificate.
v. X.509: Although the use of CA has solved the problem of public key
fraud, it has created a side effect. Each certificate may have a different
format. To remove this side effect, ITU has designed a protocol called
X.509, which has been accepted by the Internet with some changes.
vi. Public-Key Infrastructures (PKI): It is a hierarchical system to answer
queries about key certification.
UNIT-3 | COMPUTER NETWORKING-II | NETWORK SECURITY 45
46 UNIT-3 | COMPUTER NETWORKING-II | NETWORK SECURITY
UNIT – 4
SECURITY IN THE INTERNET
UNIT-4 (SECURITY IN THE INTERNET): (10 L)
1. IP Security: (AH, ESP, services, Security Association, IKE, VPN)
2. SSL/TLS: (Services, security parameters, sessions and connections, protocols, TLS).
3. PGP: (Security parameters, services, Key rings, Certificates).
4. Firewalls: (Packet-filter and Proxy firewalls).
IP SECURITY (IPSec):
IPSec is a collection of protocols designed by Internet Engineering Task Force (IETF)
to provide security for a packet at the Network level. IPSec helps to create
authenticated and confidential packets for the IP Layer.
IPSec operates in one of the two modes:
(Figure: Transport Mode and Tunnel Modes of IPSec Protocol)
1) TRANSPORT MODE: It does not protect the IP header; it only protects the
information/packet coming from the transport layer (IP payload). IP header
is added later.
UNIT-4 | COMPUTER NETWORKING-II | SECURITY IN THE INTERNET 47
The transport mode is normally used when we need host-to-host (end-to-
end) protection of data. The sending host uses IPSec to authenticate and
encrypt the payload delivered from the transport layer. The receiving host
uses IPSec to check the authentication and decrypt the IP packet, and deliver
it to the transport layer.
2) TUNNEL MODE: It protects the original IP header. It takes an IP packet,
including the header, applies IPSec security methods to the entire packet, and
then adds a new IP header. The new IP header has different information from
the original IP header.
The tunnel mode is normally used between two routers (node-to-node),
between a host and a router, or between a router and a host.
48 UNIT-4 | COMPUTER NETWORKING-II | SECURITY IN THE INTERNET
IPSec defines two protocols:
1) AUTHENTICATION HEADER (AH) PROTOCOL:
It provides source authentication and data integrity, but not privacy. The
protocol uses a hash function and a symmetric key to create a message digest;
the digest is inserted in the authentication header.
AH does not provide confidentiality, which means that the data is not
encrypted. Without data encryption, unauthorized people could use a sniffer-
type program on your network to capture and read the packets, but they
could not modify the data. AH works by using keyed hash algorithms, which
are used to sign the packet for integrity verification.
Here is the process by which AH works:
1) Computer A sends data to Computer B.
2) The IP header, the AH header, and the data are signed to provide
integrity.
3) The recipient at Computer B can be assured that the data was sent
from Computer A and that the data arrived at the destination
unmodified.
(Figure: Authentication Header (AH) Protocol in transport mode)
UNIT-4 | COMPUTER NETWORKING-II | SECURITY IN THE INTERNET 49
The AH header is placed between the IP header and IP payload to ensure
integrity and authentication. AH can be used alone or combined with ESP. The
AH header contains the following fields:
Next Header: Used to identify the IP payload via the IP protocol ID.
Payload Length: Used to indicate the length of the AH header.
Security Parameter Index (SPI): A combination field that contains the
destination address and the security protocol. This field is used to
identify the correct SA for communication.
Sequence Number: Used to provide the packet with anti-replay
protection. The sequence number starts at 1 and then increases in
increments. The value in this field is a 32-bit number. For the life of the
quick mode SA, the sequence number cannot repeat itself. If the
receiver does a check on this field and finds that an SA with this
number has been received in the past, the packet is denied.
Authentication Data: Used to verify message integrity and
authentication using the ICV. The ICV value is checked and calculated
by the receiver over the IP header, the AH header, and the IP payload.
2) ENCAPSULATING SECURITY PAYLOAD (ESP) PROTOCOL:
It provides source authentication, data integrity and privacy. ESP adds a
header and trailer. ESP’s authentication data is added at the end of the packet
which makes its calculation easier.
(Figure: Encapsulating Security Payload (ESP) Protocol in Transport mode)
50 UNIT-4 | COMPUTER NETWORKING-II | SECURITY IN THE INTERNET
The ESP header is placed before the IP payload, and an ESP trailer and ESP
authentication trailer are placed after the IP payload. The ESP header contains
the following fields:
Security Parameters Index (SPI): Used to identify which SA is used in
conjunction with the security protocol and destination address. This
value is used by the receiver to determine the packet identification.
Sequence Number: Provides anti-replay protection for the packet. The
sequence number starts at 1 and increases in 32-bit increments. It is
used to indicate the packet number sent over the quick mode SA for
the communication. This number cannot be repeated. If a recipient gets
a number that has been repeated, it will not accept the packet.
The ESP trailer contains the following fields:
Padding: Validates that byte boundaries are present on encrypted
payloads. This process is required by the encryption algorithm.
Padding Length: Used to show the length, in bytes, of the Padding
field.
Next Header: Used to identify whether the payload data is TCP or
UDP.
The ESP authentication trailer contains the Authentication Data field, which
holds the message authentication code, also known as the Integrity Check
Value (ICV). The ICV is used for message verification and authenticity. The ICV
is calculated by the packet receiver and checked against the sender’s value for
integrity verification.
UNIT-4 | COMPUTER NETWORKING-II | SECURITY IN THE INTERNET 51
IPSec SERVICES:
Services provided by IPSec are as follows:
1) Access Control: IPsec provides access control indirectly by using a
Security Association Database (SADB).
2) Message Authentication: The integrity of the message is preserved by
using authentication data.
3) Entity Authentication: IPSec authenticates the sender of data.
4) Confidentiality: Message confidentiality is provided by ESP, not AH.
5) Replay Attack Protection: In both protocols (AH and ESP), the replay
attack is prevented by using sequence number.
SECURITY ASSOCIATION:
1. IPSec requires a logical relationship between two hosts called a
Security Association (SA).
2. Security Association (SA) is very important aspect of IPSec. Using SA,
IPSec changes a connectionless protocol (i.e. IP) to a connection-
oriented protocol.
3. A set of Security Association (SA) are collected into a database, called
the Security Association Database (SADB).
4. IPSec creates Security Parameters:
a. Security Parameter Index (SPI)
b. Source IP Address (inbound) or Destination IP Address
(outbound)
c. Protocols (AH or ESP)
52 UNIT-4 | COMPUTER NETWORKING-II | SECURITY IN THE INTERNET
INTERNET KEY EXCHANGE (IKE):
1) It is a protocol designed to create both inbound and outbound security
associations in Security Association Database (SADB).
2) Internet Key Exchange (IKE) is the protocol used to set up a secure,
authenticated communications channel between two parties. IKE typically
uses X. 509 PKI certificates for authentication and the Diffie–Hellman key
exchange protocol to set up a shared session secret.
3) IKE is part of the Internet Security Protocol (IPSec) which is responsible for
negotiating security associations (SAs), which are a set of mutually agreed-
upon keys and algorithms to be used by both parties trying to establish a VPN
connection/tunnel.
4) IKE is comprised of two phases. In phase 1, IKE creates an authenticated,
secure channel between the two IKE peers. This is done using the Diffie-
Hellman key agreement protocol. In phase 2, IKE negotiates the IPSec security
associations and generates the required key material for IPSec.
5) IKE is a complex protocol based on three other protocols:
a) OAKLEY: It a key creation protocol based on Diffie-Hellman key-exchange
method. It does not define the format of the message to be exchanged.
b) SKEME: It is another protocol for key-exchange.
c) ISAKMP: Internet security Association and Key Management Protocol
defines several packets, protocols and parameters that allow IKE to be
exchanged.
UNIT-4 | COMPUTER NETWORKING-II | SECURITY IN THE INTERNET 53
VIRTUAL PRIVATE NETWORK (VPN):
It stands for Virtual Private Network. It is a technology that creates a safe and
encrypted connection over a less secure network, such as the internet. VPN masks
your internet protocol address so your online actions are virtually untraceable.
VPN creates a virtual tunnel to transfer data. Moreover, the privacy and security
provided by VPN are far better than Wi-Fi hotspots.
Virtual Private Network (VPN) is basically of 2 types:
1) Remote Access VPN:
Remote Access VPN permits a user to connect to a private network and
access all its services and resources remotely. The connection between the
user and the private network occurs through the Internet and the connection
is secure and private. Remote Access VPN is useful for home users and
business users both. An employee of a company, while he/she is out of
station, uses a VPN to connect to his/her company’s private network and
remotely access files and resources on the private network. Private users or
home users of VPN primarily use VPN services to bypass regional
restrictions on the Internet and access blocked websites. Users aware of
Internet security also use VPN services to enhance their Internet security and
privacy.
54 UNIT-4 | COMPUTER NETWORKING-II | SECURITY IN THE INTERNET
2) Site-to-Site VPN:
A Site-to-Site VPN is also called as Router-to-Router VPN and is commonly
used in the large companies. Companies or organizations, with branch
offices in different locations, use Site-to-site VPN to connect the network of
one office location to the network at another office location.
Intranet based VPN: When several offices of the same company are
connected using Site-to-Site VPN type, it is called as Intranet based VPN.
Extranet based VPN: When companies use Site-to-site VPN type to
connect to the office of another company, it is called as Extranet based
VPN.
Basically, Site-to-site VPN creates an imaginary bridge between the networks at
geographically distant offices and connects them through the Internet and sustains a
secure and private communication between the networks. In Site-to-site VPN one
router acts as a VPN Client and another router as a VPN Server as it is based on
Router-to-Router communication. When the authentication is validated between the
two routers only then the communication starts.
Types of Virtual Private Network (VPN) Protocols:
1. Internet Protocol Security (IPSec):
Internet Protocol Security, known as IPSec, is used to secure Internet
communication across an IP network. IPSec runs in 2 modes:
a) Transport mode: to encrypt the message in the data packet
b) Tunneling mode: encrypts the whole data packet.
2. Layer 2 Tunneling Protocol (L2TP):
L2TP or Layer 2 Tunneling Protocol is a tunneling protocol that is often
combined with another VPN security protocol like IPSec to establish a
highly secure VPN connection.
3. Point–to–Point Tunneling Protocol (PPTP):
Point-to-Point Protocol (PPP) is used to encrypt the data between the
connections. PPTP is one of the most widely used VPN protocol.
4. SSL and TLS:
UNIT-4 | COMPUTER NETWORKING-II | SECURITY IN THE INTERNET 55
SSL (Secure Sockets Layer) and TLS (Transport Layer Security) generate a VPN
connection where the web browser acts as the client. Online shopping
websites commonly uses SSL and TLS protocol. It is easy to switch to SSL by
web browsers and with almost no action required from the user as web
browsers come integrated with SSL and TLS. SSL connections have “https” in
the initial of the URL instead of “http”.
5. OpenVPN:
OpenVPN is an open source VPN that is commonly used for creating Point-to-
Point and Site-to-Site connections. It uses a traditional security protocol
based on SSL and TLS protocol.
6. Secure Shell (SSH):
Secure Shell or SSH generates the VPN tunnel through which the data
transfer occurs and also ensures that the tunnel is encrypted.
Advantages of VPN: VPN provides two benefits
1. ANONYMITY (ANONYMOUS): hiding your identity like IP Address, from
which location you are accessing, etc.
2. PRIVACY: hiding your activities, what sites you are visiting, what kind of work
you are doing.
Points to remember:
1. Always use paid version of VPN (not free version)
2. Use only VPN with “No Logs Policy”
3. Some of the good VPN are Express VPN, NordVPN, etc.
56 UNIT-4 | COMPUTER NETWORKING-II | SECURITY IN THE INTERNET
SSL/TLS:
Two protocols are dominant today for providing security at the Transport layer are
Secure Sockets Layer (SSL) Protocol and Transport Layer Security (TLS) Protocol.
1. They are protocols for establishing authenticated and encrypted links
between networked computers.
2. Typically, SSL is used to secure credit card transactions, data transfer and
logins, and more recently is becoming the norm when securing browsing of
social media sites.
3. One common example is when SSL is used to secure communication between
a web browser and a web server. This turns a website's address from HTTP to
HTTPS, the 'S' stands for 'secure'.
4. SSL protects website from phishing scams, data breaches, and many other
threats. Ultimately, it builds a secure environment for both visitors and site
owners.
SSL SERVICES:
It is designed to provide security and compression services to data generated
form the Application layer. SSL provides the following services:
1) Fragmentation: SSL divides the data into blocks of 214 bytes or less.
2) Compression: Data is compressed by using one of the lossless
compression methods between the client and server.
3) Message Integrity: SSL preserved the integrity of data by using keyed-
hash function to create a MAC.
4) Confidentiality: To provide confidentiality, the original data and the
MAC are encrypted using symmetric key cryptography.
5) Framing: A header is added to the encrypted payload. The payload is
then passed to a reliable transport layer protocol.
UNIT-4 | COMPUTER NETWORKING-II | SECURITY IN THE INTERNET 57
SECURITY PARAMETERS:
The security Parameters of SSL are:
1) Cipher Suite: The combination of key exchange, hash and encryption
algorithms defines a cipher suite for each SSL session.
2) Cryptographic Secret: To achieve message integrity and confidentiality,
SSL needs six cryptographic secrets, 4-keys and 2-Intiation Vectors (IVs).
SESSIONS AND CONNECTIONS:
The nature of IP and TCP protocols is different. IP is connectionless protocol; TCP
is connection-oriented protocol. An association in IPSec transforms the
connectionless IP to connection-oriented secured protocol. TCP is already
connection-oriented. However, the designer of SSL decided that they needed two
levels of connectivity: Session and Connection.
1) Session: A session between two systems is an association that can last for
a long time;
2) Connection: A connection can be established and broken several times
during a session.
PROTOCOLS:
SSL defines four protocols in two layers (i.e. Application and Transport layer):
1) Handshake Protocol: It provides security parameters for Record Protocol.
2) ChangeCipherSpec Protocol: It is used for signaling the readiness of the
cryptographic secrets.
3) Alert Protocol: It used for reporting errors and abnormal conditions.
4) Record Protocol: It is the carrier. It carries messages from other three
protocols.
58 UNIT-4 | COMPUTER NETWORKING-II | SECURITY IN THE INTERNET
TLS:
Transport Layer Security (TLS) is the Internet engineering Task Force (IETF)
standard version of SSL. They are very similar, with slight differences:
S.N SSL TLS
SSL stands for Secure Socket TLS stands for Transport Layer
1.
Layer. Security.
2. SSLv3.0 Compatible with TLSv1.0
TLS does not
3. SSL supports Fortezza algorithm.
support Fortezza algorithm.
In SSL, Message digest is used to In TLS, Pseudo-random function is
3.
create master secret. used to create master secret.
4. SSL uses MAC in Record Protocol. TLS uses HMAC in Record Protocol.
SSL is less secured as compared to
5. TLS provides high security.
TLS.
UNIT-4 | COMPUTER NETWORKING-II | SECURITY IN THE INTERNET 59
PGP:
(Introduction: In 2013, when the NSA (United States National Security Agency) scandal was
leaked to the public, people started to opt for the services which can provide them a strong
privacy for their data, most particularly for Emails. Interestingly, among the various plug-ins
and extensions that people started to use, there were two main programs that were solely
responsible for the complete email security that the people needed. One was S/MIME
which we will see later and the other was PGP.)
1) Pretty Good Privacy (PGP) is one of the protocols to provide security at
the Application Layer.
2) PGP is used to provide confidentiality and authentication services for
electronic mail and file storage.
3) It was designed by Phil Zimmermann way back in 1991. He designed it in
such a way, that the best cryptographic algorithms such as RSA, Diffie-
Hellman key exchange, DSS are used for the Asymmetric encryption.
4) CAST-128, 3DES, IDEA are used for symmetric encryption.
5) SHA-1 is used for hashing purposes.
6) PGP software is an open source one and is not dependent on either of the OS
(Operating System) or the processor. The application is based on a few
commands which are very easy to use.
SECURITY PARAMETERS:
If e-mail is a one-time activity, how can the sender and receiver agree on the security
parameters to use for email security? How can the receiver know the values of the keys
used for encryption and authentication?
Phil Zimmerman, the designer and creator of PGP, has found a very elegant solution
to the above questions. The security parameters need to be sent with the
message.
60 UNIT-4 | COMPUTER NETWORKING-II | SECURITY IN THE INTERNET
SERVICES:
PGP provides the following services:
1) Plaintext: the simplest case is to send the e-mail message in plaintext.
2) Message Authentication: The next improvement is to let the sender sign the
message
3) Compression: A further improvement is to compress the message to make
the packet more compact.
4) Confidentiality with One-Time Session Key: Confidentiality in e-mail system
can be achieved by using encryption with a One-time Session Key.
5) Code conversion: PGP uses Radix 64 conversion.
6) Segmentation: PGP allows segmentation of the message in uniform size.
KEY RINGS:
1) Each PGP user has a pair of key rings: Public-Key Ring and Private-Key Ring.
Public Key Ring contains all the public keys of other PGP users. Private Key
ring contains public/private key pairs for this user.
2) To exchange email messages, a user needs a ring of public keys; one public
key is needed for each e-mail correspondent.
3) PGP allows user to change a pair of keys from time-to-time. It also allows each
user to have different user IDs (e-mail addresses) for different groups of
people.
PGP CERTIFICATES:
1) PGP Certificate is different from X509. In X509, there is a single path from the
fully trusted authority to any certificate. In PGP, there can be multiple paths
from fully or partially trusted authorities.
2) PGP uses the idea of Certificate Trust Levels.
3) When a user receives a certificate from the introducer, it stored the certificate
under the name of the subject (certified entity). It assigns a level of trust to
this certificate.
UNIT-4 | COMPUTER NETWORKING-II | SECURITY IN THE INTERNET 61
FIREWALLS:
A Firewall is a network security device that monitors and filters incoming and
outgoing network traffic based on a set of security rules. Its purpose is to establish a
barrier between your internal network and incoming traffic from external sources
(such as the internet) in order to block malicious traffic like viruses and hackers.
A firewall is usually classified into two:
1) PACKET-FILTER FIREWALL: It can forward and block packets based on
the information in the Network Layer and Transport Layer headers:
a. Source and destination IP addresses,
b. Source and destination Port Addresses, and
c. Type of protocol (TCP or UDP).
A packet-filter firewall is a router that uses a filtering table to decide which
packets must be discarded (not forwarded).
62 UNIT-4 | COMPUTER NETWORKING-II | SECURITY IN THE INTERNET
From the above figure, the following packets are filtered:
a) Incoming packets from network [Link] are blocked.
b) Incoming packets destined for any Telnet server (port 23) are blocked.
c) Incoming packets destined for internal host [Link] are blocked.
d) Outgoing packets destined for an HTTP server (port 80) are blocked.
2) PROXY FIREWALL: Sometimes we need to filter a message based on the
information available in the message itself.
As an example, an organization wants to implement the following policies
regarding their websites: Only those Internet users who have previously
established business relations with the company can have access; access
to other users must be blocked. In this case, a packet-filter firewall is not
feasible because it cannot distinguish between different packets arriving at
TCP port 80 (HTTP). Testing must be done at the Application Layer.
One solution is to install a proxy computer, which stands between the
customer (user client) computer and the corporation computer.
When a client sends a message, the proxy firewall runs a server process to
receive the request. The server opens the packets at the Application level and
finds out if the request is legitimate. If it is legitimate/ authorize, it will send
the message to the real server. If it is not, the message is dropped and error
message is sent to the external user. In this way, the requests of the external
users are filtered based on the contents at the application layer.
UNIT-4 | COMPUTER NETWORKING-II | SECURITY IN THE INTERNET 63
Difference between Firewall and Proxy Server:
S.N Firewall Proxy Firewall (Proxy Server)
Firewall can monitor and filter all Proxy server connects an external
1 the incoming and outgoing traffic client with a server to
on a given local network. communicate with each other.
It blocks connections from It facilitates connections over
2
unauthorised network. network.
It filters the client-side requests
It filters data by monitoring IP
3 that are made to connect to the
packets that are traversed.
network.
It works on Network and Transport
4 It works on Application Layer.
layer.
It exists as an interface between a It can exist with public networks
5
public and private network. on both sides.
It is used to protect an internal It is used for anonymity and to
6
network against attacks. bypass restrictions.
The overhead generated is more as The overhead generated is less as
7
compared to a proxy server. compared to a firewall.
64 UNIT-4 | COMPUTER NETWORKING-II | SECURITY IN THE INTERNET
UNIT – 5
SECURITY TECHNOLOGY
UNIT-5 (SECURITY TECHNOLOGY): (10 L)
1 Intrusion detection and prevention system (IDPS) 6 Packet sniffers
2 Port scanners 7 Wireless security tools
3 Firewall analysis tools 8 Antivirus Software
4 Operating system detection tools 9 Malicious virus remover
5 Vulnerability scanners 10 Worm remover
INTRUSION DETECTION AND PREVENTION SYSTEM (IDPS):
An Intrusion Detection and Prevention System (IDPS) monitors network traffic for
indications of an attack, alerting administrators to possible attacks. Typically, an
intrusion detection and prevention system accomplishes this by using a device or
software to gather, log, detect, and prevent suspicious activity. These tools detect
malware, socially engineered attacks, and other web-based threats. IDPS also provide
preemptive intrusion prevention capabilities for internal threats and potentially
compromised systems.
Intrusion detection and prevention systems monitor systems for abnormal behavior
and potential vulnerabilities that can leave a business susceptible to cyber-attacks.
Companies choose to adopt these to protect their sensitive business information and
ensure their computing infrastructure performs as needed.
Some next-generation firewall software offer intrusion detection and prevention
capabilities. But the main functionality of firewall tools will be controlling network
access, rather than monitoring network behavior.
To qualify for inclusion in the Intrusion Detection and Prevention Systems (IDPS)
category, a product must:
1) Monitor IT systems for abnormal behavior and misuse
2) Inform administrators of abnormal protocol activity
3) Monitor the performance of IT hardware and security components
4) Provide blocking mechanisms for web-based threats
UNIT-5 | COMPUTER NETWORKING-II | SECURITY TECHNOLOGY 65
The four common types of IDPS, as defined by NIST, include the following:
1) Network-Based IDPS: This type of IDPS monitors network traffic for specific
network segments and devices. It analyzes the network and application
protocol activity to identify suspicious and abnormal activity.
2) Wireless IDPS: This IDPS is a sub-type of network-based IDPS. It monitors
wireless network traffic and analyzes it to identify suspicious activity involving
networking protocols.
3) Network Behavior Analysis (NBA) System: This IDPS is a sub-type of
network-based IDPS. It is used to examine network traffic in order to identify
threats that generate unusual traffic flows (i.e. malware, DDoS attacks, and
policy violations).
4) Host-Based IDPS: This IDPS is used to monitor the characteristics of a single
host and the events occurring within that host for suspicious activity.
66 UNIT-5 | COMPUTER NETWORKING-II | SECURITY TECHNOLOGY
PORT SCANNERS:
A port scanner is a computer program that checks network ports for one of three
possible statuses – open, closed, or filtered.
Port scanners are valuable tools in diagnosing network and connectivity issues.
However, attackers use port scanners to detect possible access points for infiltration
and to identify what kinds of devices you are running on the network, like firewalls,
proxy servers or VPN servers. As ports on a computer are the place where
information is sent and received, port scanning is analogous to knocking on doors to
see if someone is home.
A port scanner sends a TCP or UDP network packet and asks the port about their
current status. The three types of responses are below:
1) Open, Accepted: The computer responds and asks if there is anything it can
do for you.
2) Closed, Not Listening: The computer responds that ―This port is currently in
use and unavailable at this time.‖
3) Filtered, Dropped, Blocked: The computer doesn’t even bother to respond.
The simplest port scans are ping scans. A ping is an Internet Control Message
Protocol (ICMP) echo request – you are looking for any ICMP replies, which
indicate that the target is alive.
Some of the popular Port Scanners:
Nmap stands for "Network Mapper", it is the most popular network
discovery and port scanner in the history.
Unicornscan is the second most popular free port scanner after Nmap.
Some other popular port scanners are
Angry IP Scan,
Netcat,
Zenmap, etc.
UNIT-5 | COMPUTER NETWORKING-II | SECURITY TECHNOLOGY 67
FIREWALL ANALYSIS TOOLS:
Firewall Analysis can be split broadly in to two categories:
1) The operation of the Firewall captured in security and event logs.
2) The administration of Firewall captured in configurations, policies and
rules files.
Firewall log analysis provides insight in to the security threats and traffic behavior.
In depth analysis of the firewall security logs provides critical network intelligence
about attempts to breach security and attacks like virus, Trojan, denial of service, etc.
These network security threats pose a grave risk to the critical resources in the
network. From the firewall security log reports security administrators can perform
security log analysis, visualize network threat scenario and plan their strategy to
protect from those threats.
Analysis of traffic logs provides valuable information about bandwidth usage,
employee internet usage, bandwidth guzzling web sites, and interface wise traffic. From
the traffic log reports of firewall analysis, network/security administrators will be to
monitor fair usage of the bandwidth for business purposes and plan for the future
requirements of bandwidth capacity.
Firewall Analyzer acts as an extensive firewall log analyzer collects sys-log
generated by firewalls and generates reports which enable security admininstrators
to perform firewall logs analysis.
Firewall configuration analysis provides information to optimize the performance
of firewalls. Deeper analysis of the policies/rules provides information about the
frequency of usage or non-usage of the rules. This information can be used by the
security / network administrators to find out the adequacy of the rules, requirement
of a particular rule, rule usage resulting in security policy implementation. From the
rules / policy reports of firewall analysis, the administrator can decide whether to
delete unused rules, modify the moderately used rules and add new rules to meet
the security policy requirements.
Analysis of firewall configuration provides information about wrong
configurations, sub-optimal configurations, etc. With this information, the
68 UNIT-5 | COMPUTER NETWORKING-II | SECURITY TECHNOLOGY
administrator will be able to correct / fine tune the configurations for optimum
firewall performance.
OPERATING SYSTEM DETECTION TOOLS:
Operating System Detection (OSD) tools are designed to scan a network and
identify each machine's OS. In order construct a complete image of the entire
network, an OSD tool must be able to scan a large network quickly enough to
identify users that may only connect for a brief time.
The two most popular OS detection tools are nmap and p0f.
1. NMAP: ACTIVE SCANNING
Nmap is one of the most popular and accurate tools for mapping a network and
performing OSD. It works by sending specially crafted packets to a target machine
and then deduces its OS based on the response. Nmap is known to be an accurate
OSD tool, and it has the ability to differentiate between minor OS releases. Using it to
scan an entire network will normally yield an accurate result for each machine on the
network that responds to the nmap probes, but the scanning process can take a
long time to complete for a large network. The additional traffic generated by
nmap or any other active scanner also uses up bandwidth that would otherwise be
consumed by regular network users, so frequent scans can be inconvenient.
Although nmap is accurate, there are several cases where nmap cannot detect a
machine's OS.
a) Nmap needs at least one open and one closed port to perform OSD
accurately. In the case where a machine on the network does not accept
incoming connections, nmap will not be able to determine the machine's OS.
b) Network Address Translation (NAT) devices also prevent nmap from working
correctly. If there is no way to address a machine behind a NAT device, then
nmap cannot scan the device.
c) The active nature of nmap also means that firewalls and IDS can detect the
packets that nmap sends and block it from working. There is active research in
making active scans like those performed by nmap stealthier, but since nmap
is an active scanner, it must send and receive packets in order to work.
2. P0F: PASSIVE OBSERVATION
UNIT-5 | COMPUTER NETWORKING-II | SECURITY TECHNOLOGY 69
Passive OSD solves many of the problems associated with active scanning tools. The
biggest advantage of passive OSD is that it can work in cases where active scanners
such as nmap fail. Since passive observation does not generate any new traffic, it
cannot be blocked by firewalls, closed ports, or NAT devices. The scope for a passive
scanner is all of the traffic that is observable; it does not have to rely on responses to
specially crafted packets.
POF is a passive OSD tool that can also determine hypertext transfer protocol (HTTP)
clients, physical link types, and whether a machine is behind a NAT device. Its OSD
mechanism works by observing all of the transmission control protocol (TCP)
handshakes on a network. As long as a machine makes a TCP connection while p0f
is running, it can attempt to identify the machine's OS. Like all passive scanners, p0f
can read traffic that was sent behind NAT devices or firewalls, but it can only use TCP
traffic. In the case that a machine communicates without using TCP or where
transport layer traffic is encrypted, p0f will not work.
As an example, a group of 10 personal computers using a wireless router would be
entirely undetectable to an nmap scan. Since the router does not forward ports, an
nmap OSD scan of the IP address would only return a result for the router. However,
p0f could detect the OS of all 10 computers as long as each one is sending
traffic while the scanner is running. Even if the machines are running advanced
antivirus and firewall software, a passive scanner will not be impeded. p0f also covers
the case of machines that are only temporarily connected to the network. As long as
p0f can keep up with the bandwidth that it observes, it can attempt to detect the OS
of every machine communicating on the network.
POF is able to determine the OS of a remote machine because of implementation
differences in how each OS constructs TCP synchronize (SYN) or synchronize and
acknowledge (SYN+ACK) packets. Although the format of the header fields is
standardized, the values within the fields and are not fixed. The TCP options are
particularly variable, since they can appear in any order. In total, p0f extracts 9 values
from each SYN or SYN+ACK packet: The IP version, the initial time to live, the length
of the IP options, the max segment size, the window size, the window scaling factor,
the ordering of the TCP options, a set of implementation quirks, and whether there is
TCP payload data. These nine values differ enough between each OS to determine
which OS sent them. The corresponding values for each known OS are stored in p0f's
signature list.
70 UNIT-5 | COMPUTER NETWORKING-II | SECURITY TECHNOLOGY
VULNERABILITY SCANNERS:
Vulnerability scanners are automated tools that allow organizations to check if
their networks, systems and applications have security weaknesses that could
expose them to attacks. For example, some vulnerability scans are able to identify
over 50,000 unique external and/or internal weaknesses (i.e., different ways or
methods that hackers can exploit your network).
Vulnerability scanners can be categorized into 5 types:
1. Network-based scanners:
Network based vulnerability scanners identify possible network security attacks
and vulnerable systems on wired or wireless networks. Network-based scanners
discover unknown or unauthorized devices and systems on a network help
determine if there are unknown perimeter points on the network, such as
unauthorized remote access servers, or connections to insecure networks of
business partners.
2. Host-based scanners:
Host based vulnerability scanners are used to locate and identify vulnerabilities
in servers, workstations, or other network hosts, and provide greater visibility
into the configuration settings and patch history of scanned systems. Host-
based vulnerability assessment tools can also provide an insight into the
potential damage that can be done by insiders and outsiders once some level
of access is granted or taken on a system.
3. Wireless scanners:
Wireless vulnerability scanners are used to identify rogue access points and also
validate that a company’s network is securely configured.
4. Application scanners:
Applications vulnerability scanners test websites in order to detect known
software vulnerabilities and erroneous configurations in network or web
applications.
5. Database scanners:
UNIT-5 | COMPUTER NETWORKING-II | SECURITY TECHNOLOGY 71
Database vulnerability scanners identify the weak points in a database so as to
prevent malicious attacks
6. PACKET SNIFFERS:
When any data has to be transmitted over the computer network, it is broken down
into smaller units at the sender’s node called data packets and reassembled at
receiver’s node in original format. It is the smallest unit of communication over a
computer network. It is also called a block, a segment, a datagram or a cell. The
act of capturing data packet across the computer network is called packet sniffing.
It is similar to as wiretapping to a telephone network. It is mostly used by crackers
and hackers to collect information illegally about network. It is also used by ISPs,
advertisers and governments.
Packet sniffing is done by using tools called packet sniffer. A packet sniffer — also
known as a packet analyzer, protocol analyzer or network analyzer — is a piece
of hardware or software used to monitor network traffic. Sniffers work by examining
streams of data packets that flow between computers on a network as well as
between networked computers and the larger Internet. It can be either filtered or
unfiltered. Filtered is used when only specific data packets have to be captured and
Unfiltered is used when all the packets have to be captured. WireShark, SmartSniff
are examples of packet sniffing tools.
Packet sniffers do have legitimate purposes, such as helping administrators at
companies keep track of employees’ network use and protecting end users from
malicious files, communications, and processes. However, they can also be used
maliciously. For example, if an employee at a company mistakenly downloads a
malware-laden file that contains a packet sniffer, the sniffer could record data
transmitted on the corporate network and send reports to the cybercriminals behind
it. The criminals could then use that data to launch further attacks, extort money
from the company or its employees, and more.
How to avoid packet sniffing
1) Use a VPN service.
2) Avoid unreliable public Wi-Fi networks. Hackers can set up their own
routers and monitor all the traffic that passes through them;
3) Use a secure HTTPS protocol where possible.
4) Always update your security software;
72 UNIT-5 | COMPUTER NETWORKING-II | SECURITY TECHNOLOGY
7. WIRELESS SECURITY TOOLS:
Wireless security is the prevention of unauthorized users from accessing your
wireless network and stealing the data using your Wi-Fi network. To be precise,
wireless security ensures protection to a Wi-Fi network from unauthorized access.
To secure the wireless connection, we should focus on the following areas –
1) Identify endpoint of wireless network and end-users i.e., Authentication.
2) Protecting wireless data packets from middleman i.e., Privacy.
3) Keeping the wireless data packets intact i.e., Integrity.
Wireless security is ensured by following methods- Authentication, Privacy and
Integrity.
There are broadly two types of Authentication process:
i. Wired Equivalent Privacy (WEP): For wireless data transmitting over the air,
open authentication provides no security. WEP uses the RC4 cipher algorithm
for making every frame encrypted. The RC4 cipher also encrypts data at the
sender side and decrypt data at the receiving site, using a string of bits as key
called WEP key. WEP key can be used as an authentication method or
encryption tool.
UNIT-5 | COMPUTER NETWORKING-II | SECURITY TECHNOLOGY 73
ii. Extensible Authentication Protocol (802.1x/EAP): In WEP authentication,
authentication of the wireless clients takes place locally at AP. But Scenario
gets changed with 802.1x. A dedicated authentication server is added to the
infrastructure. There is the participation of three devices –
a. Supplicant – Device requesting access.
b. Authenticator – Device that provides access to network usually a
WLAN controller (WLC).
c. Authentication Server – Device that takes client credentials and
denies or grants access.
8. ANTIVIRUS SOFTWARE:
Antivirus software is a program(s) that is created to search, detect, prevent and
remove software viruses from your system that can harm your system. Other
harmful software such as worms, adware, and other threats can also be detected and
removed via antivirus. This software is designed to be used as a proactive approach
to cyber security, preventing threats from entering your computer and causing
issues. Most antivirus software operates in the background once installed, providing
real-time protection against virus attacks.
While you may believe that your computer is safe as long as you don’t visit
questionable websites, hackers have far more sophisticated methods of infecting
your computer that is why you need a powerful antivirus to stay to secure your data
and system.
Examples of Antivirus:
The antivirus software is available in 2 types:
(i) Free: Free anti-virus software provides basic virus protection
(ii) Paid: commercial anti-virus software provides more extensive protection.
74 UNIT-5 | COMPUTER NETWORKING-II | SECURITY TECHNOLOGY
The following are some commonly used antivirus software:
1. Bitdefender: This user-friendly antivirus software is compatible with all four
major operating systems and smart homes, and it also includes a free VPN
with a daily limit of 200MB, parental controls, camera protection, a password
manager, etc. This security suite is reasonably priced and will protect up to five
devices 24 hours a day, seven days a week.
2. AVAST: This is a free antivirus available. All you have to do to obtain top-
notch protection on your computer, emails, downloads, and instant messages
in the free version is register (for free) once a year. It includes a sophisticated
heuristics engine that enables it to detect viruses.
3. Panda: It can detect viruses, trojans, spyware, adware, worms, and malware at
the same level as other antiviruses do. It is different from others because using
this software, when you scan your computer, it doesn’t consume any of your
computer’s resources; instead, it runs in the cloud, allowing your machine to
continue to function normally.
Advantages of Antivirus:
1) Spam and advertisements are blocked: Viruses exploit pop-up advertising
and spam websites as one of the most common ways to infect your computer
and destroy your files. Antivirus acts against harmful virus-infected adverts
and websites by denying them direct access to your computer network.
2) Virus protection and transmission prevention: It identifies any possible
infection and then attempts to eliminate it.
3) Hackers and data thieves are thwarted: Antivirus do regular checks to see if
there are any hackers or hacking-related apps on the network. As a result,
antivirus offers complete security against hackers.
4) Protected against devices that can be detached: Antivirus scans all
removable devices for potential viruses, ensuring that no viruses are
transferred.
5) To improve security from web, restrict website access: Antivirus restricts
your online access in order to prevent you from accessing unauthorized
networks. This is done to ensure that you only visit websites that are safe and
non-harmful to your computer.
6) Password Protection: Using antivirus, you should consider using a password
manager for added security.
UNIT-5 | COMPUTER NETWORKING-II | SECURITY TECHNOLOGY 75
Disadvantages of Antivirus:
1) Slows down system’s speed: When you use antivirus programs, you’re using
a lot of resources like your RAM and hard drive. As a result, the computer’s
overall speed may be significantly slowed.
2) Popping up of Advertisements: Apart from commercial antivirus
applications, free antivirus must make money in some way. One approach to
attaining these is through advertising. Many times these advertisements
degrade the user experience by popping up every time.
3) Security Holes: When security flaws exist in the operating system or
networking software, the virus will be able to defeat antivirus protection. The
antivirus software will be ineffective unless the user takes steps to keep it
updated.
4) No customer care service: There will be no customer service provided unless
you pay for the premium version. If an issue arises, the only method to solve it
is to use forums and knowledge resources.
9. MALICIOUS VIRUS REMOVER:
The term "malware" is an amalgamation of malicious and software. Malware is an
umbrella term that is used to cover all types of malicious software. Malware is a
software that gets into the system without user consent with an intention to steal
private and confidential data of the user that includes bank details and password. They
also generates annoying pop up ads and makes changes in system settings
Anti-malware is a type of software program created to protect information
technology (IT) systems and individual computers from malicious software, or
malware. Antimalware programs scan a computer system to prevent, detect and
remove malware.
Malwarebytes is an anti-malware software for Microsoft
Windows, macOS, Chrome OS, Android, and iOS that finds
and removes malware. Made by Malwarebytes
Corporation, it was first released in January 2006. It is
available in a free version, which scans for and removes
malware when started manually, and a paid version, which
additionally provides scheduled scans, real-time
protection and a flash-memory scanner.
76 UNIT-5 | COMPUTER NETWORKING-II | SECURITY TECHNOLOGY
They get into the system through various means:
Along with free downloads.
Clicking on suspicious link.
Opening mails from malicious source.
Visiting malicious websites.
Not installing an updated version of antivirus in the system.
Types of Malware:
Virus
Worm
Logic Bomb
Trojan/Backdoor
Rootkit
Advanced Persistent Threat
Spyware and Adware
Malware Detection:
Here are some of the situations that one can use to identify whether the computer
system has been affected by malware or not:
Increased CPU usage
Slow computer or web browser speeds
Frequent freezing or crashing
Appearance of strange files, programs, or desktop icons
Programs running, turning off, or reconfiguring themselves
System not booting up
Emails/messages being sent automatically and without user’s knowledge
UNIT-5 | COMPUTER NETWORKING-II | SECURITY TECHNOLOGY 77
10. WORM REMOVER:
Any self-propagating program that will call any sort of damage to the system is a
kind of worm that will get activated it does not need a host program like a
message that is been sent by someone, users are required to be very careful and
aware before clicking any e-mail or message sent by the third party even various
websites can also become a means for spreading worms and viruses.
Worm Watcher:
1. For limiting the size of the worm a special program is required which can
automatically take steps to limit the size for shutting it down if it grows beyond
a certain limit. In the state of the individual segment, the watcher also maintains
are running log recording changes.
2. For visualizing what might have on wrong with the worm this type of
information can be used to analyse.
Antidotes:
1. This has seen that generally to COM or EXE files the most of the viruses attach
themselves and instructions are given to all users not to copy out COM or EXE
files.
2. All the original COM or EXE files are kept on a write-protected floppy as a
backup. Whenever these files are required to be copied they should be copied
from this write-protected floppy.
3. A program is called antidote which is available to check the infected files that are
COM or EXE. The boot virus is not located in this and this program only checked
the J virus, so we can conclude that it is required to run both the programs for a
complete checkup.
78 UNIT-5 | COMPUTER NETWORKING-II | SECURITY TECHNOLOGY