0% found this document useful (0 votes)
34 views21 pages

Information Systems and Security Essentials

(1) The document discusses various concepts related to information security including information systems, information security, threats, risks, biometrics, authentication vs authorization, physical access control, security vs privacy, firewalls, and cryptography. (2) It provides definitions and explanations of each concept. For example, it defines an information system as a collection of technical and human resources that provide storage, computing, distribution and communication of information required by an organization. (3) The key difference discussed is that authentication confirms identity while authorization determines permissions. Physical access control limits physical access to assets while logical access controls digital access. Security protects information through controls while privacy is an individual's right to choose what information to share.

Uploaded by

chattan
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
34 views21 pages

Information Systems and Security Essentials

(1) The document discusses various concepts related to information security including information systems, information security, threats, risks, biometrics, authentication vs authorization, physical access control, security vs privacy, firewalls, and cryptography. (2) It provides definitions and explanations of each concept. For example, it defines an information system as a collection of technical and human resources that provide storage, computing, distribution and communication of information required by an organization. (3) The key difference discussed is that authentication confirms identity while authorization determines permissions. Physical access control limits physical access to assets while logical access controls digital access. Security protects information through controls while privacy is an individual's right to choose what information to share.

Uploaded by

chattan
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

(a) What is meant by Information System?

Information system is the collection of technical and human resources that provide the
storage,computing,distributing and communication of the information required by all or some part
of an enterprise that facilates planning control coordination and decision making in an organization.

(b) What is meant by information Security?


information security is a term designed to protect the confidentiality, integrity and availability of
computer system data from those with malicious intentions.

(c) Define Threat.


A threat is anything that has the potential to cause serious harm to a computer system.
Threats are potentials for vulnerabilities to turn into attacks on computer systems, networks and can
put computer system at risk.

(d) Define Risk.


A risk is anything that can virtually threaten or limit the productivity. Risk can be defined as those
vulnerabilities that can cause severe impact
on organization in term of its productivity , effciency and decision making.

(e) What is the meaning of biometric?


Biometric usually refers to devices that can sense, record and then process data based on
some natural and sufficiently unique characteristic of the human body (or other aspect)
such as the finger print, iris, face, voice, etc. This is generally with the purpose of providing
secure and hard to falsify authentication of an individual's identity.

(f) What is the difference between authorization and authentication?


Authentication is the process of confirming you identity. Authorization is the process of
determining if you have the required permissions
John is able to write new topics in Quora and Sasmita can edits them to correct their
grammar.
Authentication process always proceeds to Authorization process.
Authorization helps you to control access rights by granting or
denying specific permissions to an authenticated user.
(g) What is meant by physical access control?
Access control is any mechanism or system that manages access through the
authorization or revocation of rights to physical or logical assets within an organization.
physical and logical. Physical access control limits access to campuses, buildings, rooms
and physical IT assets.
he action of enforcing access control rules is called authorization

(h) What is the difference between security and privacy?


privacy is a right and security is a policy.
By privacy we mean the right of the individual to choose which kind of information
involving himself he wants to share and with whom and when he wants to share it.

By security we generally mean the level of protection we provide to control access to


certain information. In some cases, that might mean complete isolation of information (no-
one can access it), while in others there might be specific criteria allowing certain entities
access, at particular times, etc
(i) What is the use of firewall?
A Firewall can be a Hardware component or software program that is designed to monitor
& filter the network traffic that is coming into or going out of network.

A firewall is a layer of security that designates what traffic is and isn't allowed to enter
your computer on a network. Generally, they let good traffic through, while keeping
hackers, malware, and other unsavory traffic out
A firewall also prevents confidential information being sent out from your computer
without your permission
(j) What is cryptography?
It is the art ans science (mostly science currently) creating secret writing (almost anything
that a computer to do is also "writing") via making them unreadable by scrambling
the Symbols of the message in such a way that only the intended receiver can read it with
knowing nothing then method used to scramble the message can descrambled it if they
know some secret (like a password) between them.

Q2. What is meant by Risk Analysis? Explain different techniques of risk analysis with suitable
examples.

Risk analysis is a component of risk managemennt which is the review of the risks associated with a
particular event or action. It is applied to projects, information technology, security issues and any
action where risks may be analyzed on a quantitative and qualitative basis. Risk analysis is a
component of risk management.
the following are the techniques of risk analysis:
Sensitivity Analysis

[Link] analysis is simply the method for determining how sensitive our NPV(NET Present
Value) analysis is to changes in our variable assumptions. To begin a sensitivity analysis, we must
first come up with a base-case scenario. This is typically the NPV using assumptions we believe are
most accurate. From there, we can change various assumptions we had initially made based on
other potential assumptions. NPV is then recalculated, and the sensitivity of the NPV based on the
change in assumptions is determined. Depending on our confidence in our assumptions, we can
determine how potentially risky a project can be.

2. Scenario Analysis
Scenario analysis takes sensitivity analysis a step further. Rather than just looking at the sensitivity
of our NPV analysis to changes in our variable assumptions, scenario analysis also looks at the
probability distribution of the variables. Like sensitivity analysis, scenario analysis starts with the
construction of a base case scenario. From there, other scenarios are considered, known as the
"best-case scenario" and the "worst-case scenario". Probabilities are assigned to the scenarios and
computed to arrive at an expected value. Given its simplicity, scenario analysis is one the most
frequently used risk-analysis techniques.

3. Monte Carlo Simulation


Monte Carlo simulation is considered to be the "best" method of sensitivity analysis. It comes up
with infinite calculations (expected values) given a number of constraints. Constraints are added
and the system generates random variables of inputs. From there, NPV is calculated. Rather than
generating just a few iterations, the simulation repeats the process numerous times. From the
numerous results, the expected value is then calculated.

Q3. What is meant by physical security? Why is it necessary for information security and privacy?
Explain different types of physical security measures with suitable examples.
Physical security are the measures designed and deployed to ensure the physical protection of
tangible assets specially IT assets like facilities, equipment, personnel, resources and other
properties against damage and unauthorized physical access. Physical security measures are taken
in order to protect these assets from physical threats including theft, vandalism, fire and natural
disasters.

Q4 Biometric devices no doubt provide very strong verification and identification have their own
advantages and limitations. What is your point of view about this statement? Use suitable example
to justify your answer.

Biometric security is the strongest and most foolproof physical security technique used for identity
verification as biometric devices evaluates an individuals bodily elements or biological
data,Biometric security-based systems or engines store human body characteristics that do not
change over an individual's lifetime such as fingerprints, eye texture, voice, hand patterns and facial
recognition etc.. .
An individual's body characteristics are pre-stored in a biometric security system or scanner, which
may be accessed by authorized personnel. When an individual walks into a facility or tries to gain
access to a system, the biometric scanner evaluates his/her physical characteristics, which are
matched with stored records. the individual is granted access only If a match is located,
The benefits offered by biometric system are:

Accurate Identification
While traditional security systems are reliant on passwords, personal identification numbers (PINs)
or smart cards, you can achieve a high level of accuracy with biometrics systems. We can use
biological characteristics like fingerprints and iris scans, which offer unique and accurate
identification methods. These features cannot be easily duplicated, which means only the authorized
person gets access and you get high level of security.

Easy and Safe for Use


Biometrics technology gives you accurate results with minimal invasiveness as a simple scan or a
photograph is usually all thats required. Moreover the software and hardware can be easily used
and you can have them installed without the need for excessive training.

Time Saving

Biometric identification is extremely quick, which is another advantage it has over other traditional
security methods. A person can be identified or rejected in a matter of seconds. For those business
owners that understand the value of time management the use of this technology can only be
beneficial to your office revenue by increasing productivity and reducing costs by eliminating fraud
and waste.
.
Security

Another advantage these systems have is that they cant be guessed or stolen; hence they will be a
long term security solution for your company. The problem with efficient password systems is that
there is often a sequence of numbers, letters, and symbols, which makes them difficult to remember
on a regular basis and can be stolen or lost and also involve the risk of things being shared. As a
result you cant ever be really sure as to who the real user is. However that wont be the case with
biometric characteristics, and you wont have to deal with the problem of sharing, duplication, or
fraud.
Along with these there are some limitations as well which cannot be [Link] of the limitation
of these biometric system are:

1. Biometrics is not a secret: Unlike passwords and cryptographic keys that are known only to the
user, biometrics such as face and fingerprints can easily be recorded and potentially misused by
biometrics experts without the users consent. There have been several instances where artificial
fingerprints have been used to circumvent biometrics security systems. Face and voice biometrics
are similarly vulnerable to being captured without the users explicit knowledge.

2. Biometrics cannot be cancelled: Passwords, PINs, etc., can be reset if [Link],


biometrics are permanently associated with the user and cannot be replaced if compromised.

3. Compromised biometrics: Biometrics provides usability advantages since it obviates the need to
remember and manage multiple passwords. However, this also means that if a biometric is
compromised in one application, essentially all applications where the particular biometric is used
are compromised.

4. Tracking: It is likely that the same biometric might be used for various applications and locations,
the user can potentially be tracked if organisations collude and share their respective biometric
databases while traditional authentication schemes requires the user to maintain different identities
to prevent tracking. The fact that a biometric remains the same presents a privacy concern.

Q5. RIFD is good but at the same time some bad also. Do you agree with this statement? Use
suitable example to justify your answer.

Q6. Explain that how cryptography is used for information security? Explain different types of
cryptography techniques.

It refers to the design of mechanisms based on mathematical algorithms that provide fundamental
information security services.

* One-way cryptographic functions are used to store passwords in a manner that cannot be
retrieved
* Cryptography permits secure delivery of authenticating data in one direction, then
secure delivery of the authentication token
* One-way cryptographic functions are used to detect unauthorized tampering with
software
* As no security is perfect, cryptography prevents unauthorized users from reading data or
making undetectable alterations
* As intruders are looking for something in a specific form, on a computer or network,
cryptography makes sniffing such data impractical
* Cryptography ensures that the source and destination are who they claim to be, at all
points in a transaction
* One-way cryptographic functions are used to both digitally sign content and validate it
was unchanged in transit
* Digital signature schemes are the only effective way to officially sign off on an instruction
to a computer
* Encryption ensures multi-path routing does not impact data integrity or sequencing
* Encryption makes it harder for viruses, worms, trojans and logic bombs to find the
necessary hooks

Information security uses cryptography on several levels. The information cannot be read without a
key to decrypt it. The information maintains its integrity during transit and while being stored.
Cryptography also aids in non-repudiation. This means that neither the creator nor the receiver of
the information may claim they did not create or receive it.
[Link] Key Cryptography (Secret Key Cryptography)

[Link] Key Cryptography (Public Key Cryptography)

3. HASH FUNCTION

[Link] Key Cryptography (Secret Key Cryptography)

a).Same Key is used by both parties


b). Simpler and Faster

[Link] Key Cryptography (Public Key Cryptography)

a).Two different keys are used Users get the Key from an Certificate Authority.
b). Authentication in asymmetric cryptography is more secured but the process is relatively
more complex as the certificate has to be obtained from certification authority.

3. HASH FUNCTION:

a).Uses mathematical transformation to irreversibly encrypt information.


b).It is a one-way encryption
c).uses no key for encryption and decryption

Q7. Web technologies have made our life easy but we should not forget about how vulnerable it
has
made us from privacy point of view. What is your point of view about this statement? Use suitable
example.

Q8. What is meant by CIA? Explain each with suitable examples.

CIA refers to Confidentiality of information, integrity of information and availability of


information.

Confidentiality

When we talk about confidentiality of information, we are talking about protecting the information
from disclosure to unauthorized parties.
Information has value, especially in todays [Link] one has information they wish to keep a
secret. Protecting such information is a very major part of information security.
ts.
A very key component of protecting information confidentiality would be encryption. Encryption
ensures that only the right people (people who knows the key) can read the information. Encryption
is VERY widespread in todays environment and can be found in almost every major protocol in
use. A very prominent example will be SSL/TLS, a security protocol for communications over the
internet that has been used in conjunction with a large number of internet protocols to ensure
[Link] ways to ensure information confidentiality include enforcing file permissions and
access control list to restrict access to sensitive information.
Integrity

Integrity of information refers to protecting information from being modified by unauthorized


parties.
Information only has value if it is correct. Information that has been tampered could prove costly.
For example, if you were sending an online money transfer for $100, but the information was
tampered in such a way that you actually sent $10,000, it could prove to be very costly for you.
As with data confidentiality, cryptography plays a very major role in ensuring data integrity.
Commonly used methods to protect data integrity includes hashing the data you receive and
comparing it with the hash of the original message,other methods use of existing schemes such as
GPG to digitally sign the data.

Availability

Availability of information refers to ensuring that authorized parties are able to access the
information when [Link] only has value if the right people can access it at the right
times. Denying access to information has become a very common attack nowadays such as DOS
attack and some physical damage like fire, power outage flood [Link] is a major way to ensure
data [Link] doing off-site backups can limit the damage caused to hard drives by
natural disasters. For information services that is highly critical, redundancy might be appropriate.
Having a off-site location ready to restore services in case anything happens to your primary data
centers will heavily reduce the downtime in case of anything happens.

Q9. What is meant by information classification? How do we do it? Also explain its advantages
with
suitable examples.
Data Classification Program is an extremely important first step to building a
secure organization. Classifying data is the process of categorizing data assets
based on nominal values according to its sensitivity (e.g., impact of applicable
laws and regulations). For example, data might be classified as: public, internal,
confidential (or highly confidential), restricted, regulatory, or top secret.
Data and information assets are classified respective of the risk of unauthorized
disclosure (e.g., lost or stolen inadvertently or nefariously). High risk data,
typically classified Confidential, requires a greater level of protection, while
lower risk data, possibly labeled internal requires proportionately less
protection.
Consequently, the classification of the most sensitive element in a data
collection will determine the data classification of the entire collection.
Public Information that may or must be open to the general public. It is
defined as information with no existing local, national, or international legal
restrictions on access or usage. Public data, while subject to SecureState
disclosure rules, is available to all SecureState employees and all individuals or
entities external to the corporation. Examples include:

Publicly posted press release


Publicly available marketing materials
Publicly posted job announcements
Internal Information that must be guarded due to proprietary, ethical, or
privacy considerations and must be protected from unauthorized access,
modification, transmission, storage or other use. This classification applies
even though there may not be a civil statute requiring this protection. Internal
Data is information that is restricted to personnel who have a legitimate reason
to access it. Examples include:

General employment data (e.g., excluded SSN, salary)


Business partner information where no more restrictive confidentiality
agreement exist
Contracts
Confidential Highly sensitive data intended for limited, specific use by a
workgroup, department, or group of individuals with a legitimate need-to-know.
Explicit authorization by the Data Steward is required for access because of
legal, contractual, privacy, or other constraints. Confidential data have a very
high level of sensitivity. Examples include:

Payment Card Industry (PCI)


SarbanesOxley Act (SOX)
Privacy

Q10. Explain different threat types to information security and privacy with suitable examples.

a) What do you understand by ssecurity matrix?


b) What do you mean by Worm?
A computer worm is a self-replicating computer program that penetrates an operating
system with the intent of spreading malicious code. Worms utilize networks to send copies
of the original code to other computers, causing harm by consuming bandwidth or
possibly deleting files or sending documents via email. Worms can also install backdoors
on computers.
c) What do you mean by Database security?
It is basically the protective measures that is implemented
Databases can hold scores of information about clients, running systems, and more
depending on what the database is for. This information is likely not something you want
to lose or worse have stolen. Loss or theft of this kind of sensitive data could lead to
lawsuits, loss of credibility, and most certainly more trouble in the future.
d) How user authentication is different from user authorisation?

e) Discuss the purpose of risk management for security?

f) What do you mean by cryptography?

g) Give examples of 5 different biometrics?


Biometric security is a security mechanism used to authenticate and provide access to a facility or
system based on the automatic and instant verification of an individual's physical characteristics.
h) What is the function of Firewall?

i) What do you mean by information level threat?

j) What are threats?


Threat - potential event, phenomenon or activity, which when it occurs can cause harm or
damage to other entity (data, server, data centre, human, organization, company, nation,
mankind).

Q.2 Explain the Classification of information and also explain three pillars of information security?
[definition]
Confidentiality

When we talk about confidentiality of information, we are talking about protecting the information
from disclosure to unauthorized parties.
Information has value, especially in todays [Link] one has information they wish to keep a
secret. Protecting such information is a very major part of information security.
ts.
A very key component of protecting information confidentiality would be encryption. Encryption
ensures that only the right people (people who knows the key) can read the information. Encryption
is VERY widespread in todays environment and can be found in almost every major protocol in
use. A very prominent example will be SSL/TLS, a security protocol for communications over the
internet that has been used in conjunction with a large number of internet protocols to ensure
[Link] ways to ensure information confidentiality include enforcing file permissions and
access control list to restrict access to sensitive information.

Integrity

Integrity of information refers to protecting information from being modified by unauthorized


parties.
Information only has value if it is correct. Information that has been tampered could prove costly.
For example, if you were sending an online money transfer for $100, but the information was
tampered in such a way that you actually sent $10,000, it could prove to be very costly for you.
As with data confidentiality, cryptography plays a very major role in ensuring data integrity.
Commonly used methods to protect data integrity includes hashing the data you receive and
comparing it with the hash of the original message,other methods use of existing schemes such as
GPG to digitally sign the data.

Availability

Availability of information refers to ensuring that authorized parties are able to access the
information when [Link] only has value if the right people can access it at the right
times. Denying access to information has become a very common attack nowadays such as DOS
attack and some physical damage like fire, power outage flood [Link] is a major way to ensure
data [Link] doing off-site backups can limit the damage caused to hard drives by
natural disasters. For information services that is highly critical, redundancy might be appropriate.
Having a off-site location ready to restore services in case anything happens to your primary data
centers will heavily reduce the downtime in case of anything happens.
Q.3 Discuss about biometrics technique and also explain key success factors and benefits of
biometrics?
[10]
6.4.1 Face Recognition
The biometric system can robotically identify a person by the face. This technology functions by
analyzing particular traits in the face such as - the distance between the eyes, width of the nose,
position of cheekbones, jaw line, chin ,unique shape, pattern etc. These systems include
dimensions of the eyes, nose, mouth, and other facial features for identification. To rise accuracy
these systems also may measure mouth and lip movement. Face recognition captures traits of a
face either from video or still image and converts unique traits of a face into a set of numbers.
These data gathered from the face are mixtured in a single unit that uniquely recognizes identifies
each person. Sometime the traits of the face are examined like the ongoing modifications in the
face while smiling or crying or reacting to dissimilar situation, etc. The whole face of the person
is taken into consideration or the other part of the face is taken into consideration for the
recognition of a person. It is very complicated technology. The data capture by means of video
or thermal imaging. The user identity is assured by looking at the screen. The primary advantage
to using facial recognition as a biometric authenticator is that people are adapted to presenting
their faces for identification and rather than ID card or photo identity card this method will be
beneficial in recognizing a person.
!
Caution As the person faces alters by the age or person goes for plastic surgery, in this case
the facial recognition algorithm should gauge the relative position of ears, noses, eyes
and other facial traits.
LOVELY PROFESSIONAL UNIVERSITY 77
Unit 6: Biometric Controls for Security
6.4.2 Hand Geometry Notes
Hand geometry is a method that captures the physical traits of a users hand and fingers.
It examines finger image ridge endings, branches made by ridges. These systems gauge and
record the length, width, thickness, and surface area of an individuals hand. It is accessed in
applications like access control and time and attendance etc. It is easy to use, relatively not costly
and broadly accepted. A camera captures a three dimensional image of the hand. A verification
template is formed and accumulated in the database and is compared to the template at the time
of confirmation of a person. Fingerprint identification. Presently fingerprint readers are being
constructed into computer memory cards for use with laptops or PCs and also in cellular
telephones, and personal digital assistants. It is successfully executed in the area of physical
access control.
6.4.3 Eye Recognition
This method includes scanning of retina and iris in eye. Retina scan method maps the capillary
pattern of the retina, a thin nerve on the back of the eye. A retina scan gauges patterns at over 400
points. It examines the iris of the eye, which is the colored ring of tissue that surrounds the pupil
of the eye. This is a very mature technology with a proven track record in a number of application
areas. Retina scanning captures individual pattern of blood vessels where the iris scanning
captures the iris. The user must focus on a point and when it is in that position the system
accesses a beam of light to capture the unique retina traits. It is broadly secure and accurate and
used heavily in controlled environment. However, it is expensive, secure and needs perfect
alignment and generally the user must look in to the device with proper focus. Iris recognition
is one of the most reliable biometric recognition and verification methods. It is accessed in
airports for travellers. Retina scan is used in military and government organization. Organizations
use retina scans initially for authentication in high-end security applications to control access.
Example: Government buildings, military operations or other limited quarters, to
authorized personnel only.
The unique pattern and traits in the human iris remain unchanged during ones lifetime and no
two persons in the world can have the same iris outline.
6.4.4 Voice Biometrics
Voice biometrics, accesses the persons voice to verify or recognize the person. It confirms as
well as identifies the speaker. A microphone on a standard PC with software is needed to
examine the unique traits of the person. It is mainly used in telephone-based applications. Voice
verification is simple to use and does not need a great deal of user education. To enroll, the user
speaks a provided pass phrase into a microphone or telephone handset. The system then forms
a template based on various traits, including pitch, tone, and shape of larynx. Generally, the
enrollment procedure takes less than a minute for the user to accomplish. Voice verification is
one of the least intrusive of all biometric methods. Moreover, voice verification is simple to use
and does not need a great deal of user education.
Task Discuss the functioning of voice biometrics.
78 LOVELY PROFESSIONAL UNIVERSITY
Information Security and Privacy
Notes 6.4.5 Signature Verification
Signature verification technology is the examination of an individuals written signature, involving
the speed, acceleration rate, stroke length and pressure applied during the signature. There are
diverse methods to capture data for analysis i.e. a special pen can be used to identify and examine
analyze various movements when writing a signature, the data will then be obtained within the
pen. Information can also be captured among a special tablet that gauges time, pressure,
acceleration
and the duration the pen touches it. As the user writes on the tablet, the movement of the pen
produces sound against paper an is used for verification. An individuals signature can modify
over time, though, which can effect in the system not identifying authorized users. Signature
systems depend on the device such as special tablet, a special pen etc. When the user signs his name
on an electronic pad, instead of merely comparing signatures, the device instead compares the
direction, speed and pressure of the writing instrument as it moves across the pad.
Task Explain the process of signature verification.
6.4.6 Keystroke
This technique depends on the fact that each person has her/his own keyboard-melody, which
is examined when the user types. It gauges the time taken by a user in pressing a specific key or
looking for a particular key.
6.5 Key Success Factors Notes
For any effectual biometrics system, there are a some significant factors related with it: accuracy,
speed and throughput rate, acceptance by users, exclusiveness of biometrics organ and action,
reliability, data storage needs, enrolment time, intrusiveness of data collection, etc.
Effective performance of biometrics system would rely on these factors as discussed below.
6.5.1 Accuracy
It is the most important trait of a biometric identification verification system. If the system
cannot correctly separate an authentic person from an imposter, it should not be considered a
biometrics identification system. There are two concerns that occurs-false rejection rate (FRR)
and false acceptance rate (FAR):
1. FRR: This rate is usually articulated as a percentage. It is the rate at which authentic,
enrolled persons are discarded as anonymous persons by a biometrics system. It is also
called Type 1 error. When FRR increase, it may be fine if it is a tight security area such as
defense or medical foundation but not fine if it is a retail business. FAR is a reverse
condition. This is the rate at which unenrolled persons are established as authentic, enrolled
persons by a biometrics system. FAR is also called Type II error.
2. Crossover Error Rate (CER): It is the rate at which FAR and FRR compares. It is also called
EER and is specified as a percentage. This is the most significant measure of biometrics
system accuracy. ERR or CER displays the accuracy level at which the probability of a false
non-match.
Did u know? Full form of ERR
Equal Error Rate.
6.5.2 Speed and Throughput Rate
For biometrics system classification, speed and throughput are imperative. Data-processing
ability of the biometrics system decides the speed; it is declared as how fast the accept or reject
decision is articulated. It associates to the authentication procedure; the system setup, card input
or PIN; inputting the physical data by inserting the hand or finger, aligning the eye speaking
access words or signing a name processing and matching of data files, etc. A system speed of 5s
of start up via decision enunciation is good as per usually accepted standards. Another standard
is a portal throughput rate of 6-10 per min, which is equal to 6-10 s per person through the door.
!
Caution Regardless of great strides in the biometrics research, it is not simple for most
biometrics systems to meet these standards.
6.5.3 Acceptability by Users
User acceptability to-date is a big confront for enveloping deployment of biometrics systems,
this is mainly owing to the social sigma linked to the biometrics system provided their nature
and lack of adequate responsiveness on biometrics identification system. Biometric system
acceptance appears when those who must access the system, that is, management and unions
80 LOVELY PROFESSIONAL UNIVERSITY
Information Security and Privacy
Notes concerned in the organizations, need to come to an agreement that biometrics should be
deployed
for the protection of organizational assets. Also consider the social sigma factor mentioned as
well as the lack of awareness; fingerprinting is a chiefly sensitive topic, given that it is linked
with criminals. Eye retina scanning requires users to trust that the system will not harm their
eyes, a feeling they carry perhaps owing to rumors and insufficient information concerning
how the retinal scanning technology functions.
6.5.4 Uniqueness of Biometrics Organ and Action
The intention of biometrics system is positive identification of the personnel- specified this, it is
significant that the systems are based on unique traits of the employees. So when the base is
exclusive trait, a file match is a positive identification instead of a statement of high probability
that it is the right person. Out of the many physical traits that can be used, only three can actually
be considered unique enough for recognition: the fingerprint, the retina of the eye and the iris
of the eye.
6.5.5 Reliability of Biometrics
When using biometrics verification systems, it is significant that they function in an accurate
fashion. The notion of systems reliability is connected to its selectivity. Reliability is a prospect
that a matcher system will properly identify the mate when the mate is present in the system
repository, while selectivity is the number of incorrect mates determined for a specified search.
Only authorized persons must be permissible to access and it must prevent the others without
breakdown in performance correctness or speed.
Did u know? The tradeoff between reliability and selectivity provides the greatest system
design challenge as these parameters are interdependent.
6.5.6 Data Storage Requirements in Biometrics System
Earlier computer systems had primary and secondary memory size constraints, that are restricted
RAM and disk size. This is less of an concern today as computer technology has advanced in both
hardware and software. Even then, the size of biometrics data files is still a factor of interest.
Provided the large size of biometrics match templates, even with the current ultra-high speed
processors, large data files take longer than small files to process. This is particularly so in
biometrics systems that performs full identification. Typically, biometrics file size varies between
9 and 10,000 bytes, mostly falling in the 256-1,000 byte range.
6.5.7 Enrolment Time in Biometrics
We have discussed matching and enrolment; enrolment time is also so much of a concern these
days. In the previous days, biometrics system sometimes had enrolment process requiring
many repetitions and numerous minutes to completes.
Q.4 Discuss the various Information System Security & Threats also explain Global information
system? [10]
In simple words, global information system is an expansion of an information system that operates
across geographical and time boundaries. It can be defined as a computerized system which
supports the business strategies of a multinationnal organization and deals with components of the
international market as a single market .

Q.5 Elaborate the various applications of RFID and also explain the impact of it on privacy?
[10]

RFID, or Radio Frequency IDentification, is a technology where information stored on a microchip


can be read remotely, without physical contact using energy in the RF spectrum. An RFID system
consists of a reader, or interrogator, which emits an RF signal via an antenna. The microchip
receives the energy via an attached antenna (termed an RFID tag) and varies the electromagnetic
response its antenna in such a way that information can be transferred to the reader.
Various application of RFID are:
1. Smart Shopping Experience: Putting RFID tags on products which are sitting on the isle in a
brick and mortar store. People can scan the product and directly add to the cart where the product is
billed in real time.

2. Smart Poster: RFiD tags can allow you to make static posters talk to the person scanning the
poster and get more detail about it.

3. Smart Supply Chain Mgmt: From in sourcing of raw material to shipping and tracking a product
once it is delivered can be tracked with cheap RFiD readers and tags to get more real time inventory
update.

4. Express Toll Lanes: To reduce the congestion at toll collection points and to create fast express
toll collection lane - RFiD tag on the cars windshield with the RFiD reader installed on the boom
barrier can play a important role to automate toll collection.

5. Catching Violators of Traffic rules: If there a particular traffic rule such as odd and even recently
launched in Delhi, India or other cities - RFiD readers installed on traffic lights with a mandate of a
RFiD tag on every car (car registration no is stored in the tag) can be used to effectively an cheaply
catch the violators.
[how does RFID helps in security]
An RFID tag is more powerful than the conventional bar code. It is basically a
microchip and an antenna from which readers are able to communicate with the
tag. Using it, an authorized party can follow a tagged item from place to place
and tune in on the condition of the item and place it geographically. The RFID
tag readers can be placed anywhere within a facility like a warehouse or a store
and are able to read, as of today, up to 30 feet with a good deal of reliability.

Q.6 Write and explain Meaning, Applications of Cryptography with respect to cryptographic
algorithms? [10]
Cryptography is the process of converting recognizable data into an encrypted code for transmitting
it over a network (either trusted or untrusted). Data is encrypted at the source, i.e. sender's end and
decrypted at the destination, i.e. receiver's end.
In all cases, the initial unencrypted data is referred to as plain text. It is encrypted into cipher text,
which will in turn (usually) be decrypted into usable plaintext using different encryption algorithms.
Plaintext =>Ciphertext=> Plaintext=>Encryption=> Decryption

The Purpose :-
* Authentication : The process of proving one's identity.
* Privacy/confidentiality : Ensuring that no one can read the message except the intended receiver.
* Integrity : Assuring the receiver that the received message has not been altered in any way from
the original.
* Non-repudiation : A mechanism to prove that the sender really sent this message.

In general cryptographic algorithms are classified into three categories as follows :


Secret Key Cryptography :-
With secret key cryptography, a single key is used for both encryption and decryption. Because a
single key is used for both functions, secret key cryptography is also called symmetric encryption.

Public-Key Cryptography :-
PKC employs two keys that are mathematically related although knowledge of one key does not
allow someone to easily determine the other key. One key is used to encrypt the plaintext and the
other key is used to decrypt the ciphertext. No matter which key is applied first, but both the keys
are required for the process to work. Because a pair of keys are required, this approach is also called
asymmetric cryptography.
In PKC, one of the keys is designated the public key and may be advertised as widely as the owner
wants. The other key is designated the private key and is never revealed to another party.

Hash Functions :-
Hash functions, also called message digests and one-way encryption, are algorithms that, in some
sense, use no key. Instead, a fixed-length hash value is computed based upon the plaintext that
makes it impossible for either the contents or length of the plaintext to be recovered. Hash
algorithms are typically used to provide a digital fingerprint of a file's contents, often used to ensure
that the file has not been altered by an intruder or virus. Hash functions are also commonly
employed by many operating systems to encrypt passwords. Hash functions, then, provide a
measure of the integrity of a file.

Q.7 Write a short note on the following:


[10]
a) Proxy Servers
A proxy server is a service that takes a request and performs it on behalf of the user or another
service. In some cases, this proxy server may cache the results in order to speed up the same
requests from either the same and/or other users/services. The idea of proxies in computing have
been around for awhile, but really seemed to have hit their peak with the advent of the World Wide
Web. Here, most proxies did act as Caching servers in order to speed up requests for larger
organizations. Additionally, Content Filtering capabilities prevented access to illegal and/or illicit
content as well as providing network-wide Ad Blocking. In the case of HTTP, proxies basically
work by rewriting the request header to show that the proxy is actually doing the request.

b) Packet Filtering
Packet Filtering is a simple firewall technique in apache, it lets users to restrict or block some
packets that are coming from the internet into safe ports. This technique is implemented using the
internet router. It can block following services as finger, exec, TFTP.
Here,
Finger informs the number of logged-in users
Exec It allows Bad Guy to run programs remotely.
TFTP It is a security free file-transferprotocol. The possibilities are horrendous!
Packet filtering will only check for the port number and IP address and it will discard packets
whereas proxy opens every packet and examines the data for content that is not allowed.
With time there has been improvement of filtering of packets which has made them more efficient
Earlier a packet filter might have seen a request for web traffic and allowed the packet not knowing
it was a malicious packet, whereas a proxy would have detected the data payload as malicious and
denied it ever coming into your network.

c) Screening Routers

Screening routers can look at information related to the hard-wired address of a


computer, its IP address (Network layer), and even the types of connections
(Transport layer) and then provide filtering based on that information. A screening
router may be a stand-alone routing device or a computer that contains two network
interface cards (dual-homed system). The router connects two networks and performs
packet filtering to control traffic between the networks. Administrators program the
device with a set of rules that define how packet filtering is done. Ports can also be
blocked; for example, you can block all applications except HTTP (Web) services.
However, the rules that you can define for routers may not be sufficient to protect
your network resources, especially if the Internet is connected to one side of the
router. Those rules may also be difficult to implement and error-prone, which could
potentially open up holes in your defenses.
d) Hardware Level Firewall
"Hardware" firewalls are usually optimized to run with very little underlying operating
system (perhaps entirely in firmware) to maximize throughput.
A firewall is a protective system that lies, in essence, between your computer network and the Internet. When used
correctly, a firewallprevents unauthorized use and access to your network
A hardware firewall uses packet filtering to examine the header of a packet to determine its source and destination. This
information is compared to a set of predefined or user-created rules that determine whether the packet is to be forwarded
or dropped.
A hardware firewall uses a PC-like appliance to run software that blocks unwanted outside traffic. A firewall appliance
may allow the firewall administrator to simply drag and drop various rules into place. For example, if your business
wishes to block all incoming traffic from particular top level domains (TLDs), such as particular country codes, a few
clicks will give the option of blocking incoming, outgoing or both types of traffic to/from those TLDs. Likewise, if a given
user group perhaps your tech support operation needs to run Microsoft Remote Desktop Connection (RDC) to assist
users on another network, that entire group can be dragged and dropped into an authorized users category while the
RDC application can be dropped into an authorized application category.

Hardware firewalls offer other advantages. Updating a firewall appliance with new
rules to prevent evolving threats, hacks and malware is straightforward: a single
update protects all machines connected on the network. Further, many firewall
appliances are delivered with additional security features that may include VPN
services, intrusion detection and others that would normally have to be purchased and
configured separately.

Q.8 Explain the Methodologies for Information System Security?


[10]

Q9. The purpose of a risk assessment is to help management create appropriate strategies and
controls for stewardship of information assets. Justify the statement.

Q10. Explain biometric controls for security. Give proper examples also.
biometric security is mainly implemented in environments with critical physical security
requirements or that are highly prone to identity theft.

.(a) Give the importance of information systems?


-information system improves operational excellence
by constantly having the correct amount of stock in store so consumers can always get what they
want.
-information system help managers to use real time data while making a decision, therefore better
decision are made without wasting time to look for information.
-information system provides recordkeeping in a technical way with easy upgrade which enhance
information [Link] improves efficiency and productivity.
-Because of recordkeeping in a technical and modern way,vital information are safeguarded and
protected by the use of different techniques and security measures
-Better recordkeeping and efficient decision making eventually leads to better service to consumer
and more the number of happy customers,the more profit a company ears.

(b) Explain the concept of global information system.


In simple words, global information system is an expansion of an information system that operates
across geographical and time boundaries. It can be defined as a computerized system which
supports the business strategies of a multinationnal organization and deals with components of the
international market as a single market .

(c) Name the various principles of information security.


confidentiality, possessionmeans the information is always under the control of an
authenticated person
, integrity, authenticity, availability, and utility
(d) What is the need for physical security?
The objective of physical security is to safeguard personnel, information, equipment, IT
infrastructure, facilities and all other company assets.
Physical security must be implemented correctly to prevent attackers from gaining physical access
and take what they want. All the firewalls, cryptography and other security measures would be
useless if that were to occur.

(e) Name few natural disasters and their controls.

(f) What is difference between VIRUS & WORMS?


A computer virus is a type of malware that propagates by inserting a copy of itself into and becoming part of another
program. It spreads from one computer to another, leaving infections as it travels. Viruses can range in severity from
causing mildly annoying effects to damaging data or software and causing denial-of-service (DoS) conditions
Computer worms are similar to viruses in that they replicate functional copies of themselves and can cause the same
type of damage. In contrast to viruses, which require the spreading of an infected host file, worms are standalone
software and do not require a host program or human help to propagate. To spread, worms either exploit a vulnerability
on the target system or use some kind of social engineering to trick users into executing them.
(g) What is cryptography?
It is the art ans science (mostly science currently) creating secret writing (almost anything
that a computer to do is also "writing") via making them unreadable by scrambling
the Symbols of the message in such a way that only the intended receiver can read it with
knowing nothing then method used to scramble the message can descrambled it if they
know some secret (like a password) between them.
(h) Differentiate between information level threats and network level threats.

(i) What do you mean by electronic signature?

(j) What is the significance of internet privacy?

Q2. Explain various Malicious Threats with their accessing damages respectively.

Q3. Explain the need of physical security. Also explain various methods for physical entry
control.
Physical Security can be defined as the protection of tangible property from direct access. this
should be contrasted with the concept of network security. Examples of physical security include
human guards, realestate security systems, and pad locks.
Physical security depicts efforts to establish safety like bug detectors that are intended to deny
unapproved access to offices, hardware and assets and to shield staff and property from harm or
mischief.

Q4. Explain the various biometric techniques and their key success factors and benefits.

Q5. Explain the various applications of Cryptography in detail.

Secure Communication
Secure communication is the most straightforward use of cryptography. Two people may
communicate securely by encrypting the messages sent between them. This can be done
in such a way that a third party eavesdropping may never be able to decipher the
messages. While secure communication has existed for centuries, the key management
problem has prevented it from becoming commonplace. Thanks to the development of
public-key cryptography, the tools exist to create a large-scale network of people who can
communicate securely with one another even if they had never communicated before.

Identification and Authentication


Identification and authentication are two widely used applications of cryptography.
Identification is the process of verifying someone's or some thing's identity. For example,
when withdrawing money from a bank, a teller asks to see identification (for example, a
driver's license) to verify the identity of the owner of the account. This same process can
be done electronically using cryptography. Every automatic teller machine (ATM) card is
associated with a ``secret'' personal identification number (PIN), which binds the owner to
the card and thus to the [Link] the card is inserted into the ATM, the machine
prompts the card holder for the PIN. If the correct PIN is entered, the machine identifies
that person as the rightful owner and grants access. Another important application of
cryptography is authentication. Authentication is similar to identification, in that both allow
an entity access to resources (such as an Internet account), but authentication is broader
because it does not necessarily involve identifying a person or entity. Authentication
merely determines whether that person or entity is authorized for whatever is in question.

Secret Sharing
Another application of cryptography, called secret sharing, allows the trust of a secret to
be distributed among a group of people. For example, in a (k ,n)-threshold scheme,
information about a secret is distributed in such away that any k out of the n
people (k en) have enough information to determine the secret, but any set of
k -1people do not. In any secret sharing scheme, there are designated sets of people
whose cumulative informationsuffices to determine the secret. In some implementations
of secret sharing schemes, each participant receivesthe secret after it has been
generated. In other implementations, the actual secret is never made visible to
theparticipants, although the purpose for which they sought the secret (for example,
access to a building or permission to execute a process) is allowed. See Question2.1.9for
more information on secret sharing.
Electronic Commerce
Over the past few years there has been a growing amount of business conducted over the
Internet - this form of business is called electronic commerce or e-commerce.
E -commerce is comprised of online banking, onlinebrokerage accounts, and Internet
shopping, to name a few of the many applications.
One can book plane tickets,make hotel reservations, rent a car, transfer money from one
account to another, buy compact disks (CDs),clothes, books and so on all while sitting in
front of a computer. However, simply entering a credit card number onthe Internet leaves
one open to fraud.
One cryptographic solution to this problem is to encrypt the credit cardnumber (or other
private information) when it is entered online, another is to secure the entire session
,When a computer encrypts this information and sends it out on the Internet, it
isincomprehensible to a third party viewer. The web server ("Internet shopping center")
receives the encryptedinformation, decrypts it, and proceeds with the sale without fear
that the credit card number or other personal data would be stolen.

Q6. Explain the concept of securing mobile databases. Also elaborate various database
security policies.

Q7. What do you mean by a security model? Explain. Also explain various methodologies for
Information System Security.

Q8. Explain the working of RFID. Also elaborate the usage and effectiveness of RFID.

RFID stands for Radio Frequency identification. It is a wireless non-contact use of radio-
frequency electromagnetic fields to transfer data. Used for the purpose of automatic
identification & tracking of tags attached to assets.

RFID tags are of two types: Those that do not have a battery are called passive
tags. Those that use a battery are called active tags. The battery mostly assists in
boosting the read range of the RFID tag. Passive tags are powered by the RF signal
from the interrogator/reader itself.
An RFID tag comprises of essentially 2 parts

First: an antenna for transmitting & receiving radio frequency signals. There are several
types of antenna designs and shapes depending on the application.
Second: RFID Chip or IC (integrated circuit), which stores the tags ID and other info. This is
the heart of the RFID tag. The brain of the tag. An IC is essentially a microchip.
In an RFID tag both antenna & IC are bonded together to form an operational RFID inlay or
transponder. NOTE: not all ICs are compatible with any one antenna design. An antenna
needs to be designed around the IC and tuned according to the ICs frequency for optimal
performance.
RFID mostly operates in the frequency ranges given below.

LF Low frequency @ 125 khz: RFID tags with LF are ideal for reading metal objects or
objects with high water content such as fruit & veg/Animals with a very limited read range.

HF: High frequency @ 13.56 Mhz: RFID tags with HF work fairly well on metal objects and
objects with medium to high water content with a maximum read range of 3 feet to 1
meter
UHF: Ultra high frequency @ 860 960 [Link] tags with UHF offers better read ranges
than LF and HF tags and can transfer data much faster but the signal does not pass
through metal or objects with water content.
[success factor is in image]:

Usage:
Simultaneous reading (without visual contact) of several RFID labels
Possibility of long distance reading (UHF)
Readings High level of safety
Protection of data encoded in the chip
The impenetrable character of the microchip

Q.9 Explain Database security, Mobile Databases Security and Enterprise Database Security?

Q.10 Write and explain the steps for:

a) Implications of RFID

b) Use with Bio-Metrics


Biometric devices authenticate users to access control systems through some sort of personal
identifier such as a fingerprint, voiceprint, iris scan, retina scan, facial scan, or signature dynamics.
The nice thing about using biometrics is that end-users do not lose or misplace their personal
identifier. Its hard to leave your fingers at home. However, biometrics have not caught on as
fast as originally anticipated due to the false positives and false negatives that are common
when using biometric technologies.
Biometric authentication systems employ unique physical characteristics (or attributes) of an
individual person in order to authenticate the persons identity. Physical attributes employed in
biometric authentication systems include fingerprints, hand geometry, hand -written signatures,
retina patterns and voice patterns. Biometric authentication systems based upon these physical
attributes have been developed for computer login applications.
Biometric authentication systems generally operate in the following manner:
1. Prior to any authentication attempts, a user is enrolled by creating a reference profile
(or template) based on the desired physical attribute. The reference profile is usually
based on the combination of several measurements. The resulting template is associated
with the identity of the user and stored for later use.
LOVELY PROFESSIONAL UNIVERSITY 191
Unit 13: Privacy Technological Impacts
2. When attempting to authenticate themselves, the user enters his login name or, Notes
alternatively, the user may provide a card/token containing identification information.
The users physical attribute is then measured.
3. The previously stored reference profile of the physical attribute is then compared with the
measured profile of the attribute taken from the user. The result of the comparison is then
used to either accept or reject the user.
4. Biometric systems can provide an increased level of security for IT systems, but the
technology is still less matures than memory or smart cards. Imperfections in biometric
authentication devices arise from technical difficulties in measuring and profiling physical
attributes as well as from the somewhat variable nature of physical attributes.

c)
A smart card is a device typically the size and shape of a credit card and contains one or more
integrated chips that perform the functions of a computer with a microprocessor, memory, and
input/output. Smart cards may be used to provide increased functionality as well as an increased
level of security over memory cards when used for identification and authentication.
Smart Cards are plastic cards that have integrated circuits or storage receptacles embedded in
them. Smart cards with integrated circuits that can execute transactions and are often referred to
as active smart cards.
Cards with memory receptacles that simply store information (such as your bank ATM card) are
referred to as passive. Whether or not a memory card is a type of smart card depends on who
192 LOVELY PROFESSIONAL UNIVERSITY
Information Security and Privacy
Notes you ask and what marketing material you are reading. Used to authenticate users to domains,
systems, and networks, smart cards offer two-factor authentication something a user has, and
something a user knows. The card is what the user has, and the personal identification number
is what the person knows.
A smart card can process, as well as store, data through its microprocessor; therefore, the smart
card itself (as opposed to the reader/writer device), can control access to the information stored
on the card. This can be especially useful for applications such as user authentication in which
security of the information must be maintained. The smart card can actually perform the password
or PIN comparisons inside the card.
As an authentication method, the smart card is something the user possesses. With recent
advances, a password or PIN (something a user knows) can be added for additional security and
a fingerprint or photo (something the user is) for even further security. As contrasted with
memory cards, an important and useful feature of a smart card is that it can be manufactured to
ensure the security of its own memory, thus reducing the risk of lost or stolen cards.
The smart card can replace conventional password security with something better, a PIN, which
is verified by the card versus the computer system, which may not have as sophisticated a means
for user identification and authentication.
The card can be programmed to limit the number of login attempts as well as ask biographic
questions, or make a biometric check to ensure that only the smart cards owner can use it. In
addition, non-repeating challenges can be used to foil a scenario in which an attacker tries to
login using a password or PIN he observed from a previous login. In addition, the complexity
of smart card manufacturing makes forgery of the cards contents virtually impossible.
Use of smart devices means the added expense of the card itself, as well as the special reader
devices. Careful decisions as to what systems warrant the use of a smart card must be made. The
cost of manufacturing smart cards is higher than that of memory cards but the disparity will get
less and less as more and more manufacturers switch to this technology. On the other hand, it
should be remembered that smart cards, as opposed to memory only cards, can effectively
communicate with relatively dumb, inexpensive reader devices.

You might also like