0% found this document useful (0 votes)
10 views101 pages

Cloud Security: Key Concepts & Threats

The document discusses the importance of information security, particularly in the context of cloud computing, emphasizing the need for confidentiality, integrity, and availability (CIA triad). It outlines various security threats and attacks, including phishing and malware, and highlights the tools and measures necessary for effective information security. Additionally, it covers concepts such as non-repudiation and access control, which are crucial for maintaining secure systems.

Uploaded by

sshreyasaxenaa
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
10 views101 pages

Cloud Security: Key Concepts & Threats

The document discusses the importance of information security, particularly in the context of cloud computing, emphasizing the need for confidentiality, integrity, and availability (CIA triad). It outlines various security threats and attacks, including phishing and malware, and highlights the tools and measures necessary for effective information security. Additionally, it covers concepts such as non-repudiation and access control, which are crucial for maintaining secure systems.

Uploaded by

sshreyasaxenaa
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Name of Institution

Cloud Security
Dr. Nitish Kumar Ojha
Name of Institution
Scope
▪ Definition and need of information security
(to define and uunderstand the need)

▪ Elements of information security


(to understand cconfidentiality, integrity and availability)

▪ Security threats and attacks


(to understand spams, phishing, malware, spyware….)

▪ Tools required for information security


(people. process and technology)

▪ Basic security measures for system


(awareness and updation with technology)

▪ Take home message

13
Why is it Important?

▪ Over the years, the security threats (bots, spam, phishing) become a major concern.

▪ Roughly 156 million phishing emails are sent globally every day, so even if a fraction
fall for the scam, phishers score big.

▪ Spam messages account for 48.16% of e-mail traffic world wide.


(Symantec, 2017).

▪ On average, in USA majority of the unsolicited spam e-mails account 12.08 % of global
spam volume.
(Symantec, 2017).
▪ IT threats are challenging in terms of - time and money!

12
What is Information Security in Cloud
▪ The protection of information and its critical elements, including
systems and hardware which use, store and transmit that information
in Cloud.
Necessary tools for execution
▪ Policy
▪ Awareness
▪ Education
▪ Training
▪ Technology
11
Elements of Information Security

“CIA” Triad
▪ Confidentiality
▪ Integrity
▪ Availability

10
Confidentiality
▪ Used to prevent the disclosure of information to
unauthorized individuals/systems
▪ Privacy - the owner has to decide access
Example: Password hacking in online money transactions.

Prevention: by encrypting the data and limiting the places where


it appears 9
8
9
10
11
Confidentiality:
Confidentiality: concealment from unauthorized parties –

1. Identification – unique identifiers for all users – User Name

2. Authentication - Authentication is the act of confirming the


truth of an attribute of a datum or entity.

3. Authorization - allowing users who have been identified and


authenticated to use certain resources.

4. Privacy - The right to privacy refers to having control over


this personal information.
12
Integrity
Protect the data modification whether addition or deletion.
▪ Data integrity: Assures information change in a specified and authorized
manner
▪ System integrity: Assures that a system performs its intended function in
an unimpaired manner, free from deliberate or intentional unauthorized
manipulation of the system

Prevention: message authentication & integrity codes (MAC/


MIC) and message digests such as MD5 or SHA-1 hashes 8
Data Integrity

14
Availability
▪ Ability of the infrastructure to function according to business
expectations during its specified time of operation.
▪ Assures that systems work promptly and services are not
denied to authorized users
Nobody can disturb the system to make it unusable.

Prevention: Backup systems 7


Types Of Security Threats

▪ Computer viruses
▪ Trojan horses
▪ DNS poisoning
▪ Password grabbers
▪ Network worms
▪ Logic bombs
▪ Hijacked home page
▪ Password cracker
and many more ……

6
Types Of Attacks

▪ SQL Injection
▪ Dictionary attack
▪ Phishing
▪ Cross site scripting (XSS)
▪ UI redressing
and many more …….

5
Types of Attacks on System in
detail -

18
Malware
• Programs are also considered malware if they secretly act against the interests
of the computer user.
Malware
 Can be loosely defined as “Malicious computer executable”
◦ A bit flexible definition
◦ Annoying software or program codes
 Running a code without user’s consent
◦ “If you let somebody else execute code on your computer, then it is not your own
computer”
 Not only virus or worm
◦ Sometimes known as computer contaminant
 Should not be confused with defective software which contains harmful bugs
Reasons for increase
 Growing number and connectivity of computers
◦ “Everybody” is connected and dependent on computers
◦ the number of attacks increase
◦ attacks can be launched easily (automated attacks)
 Growing system complexity
◦ unsafe programming languages
◦ hiding code is easy
◦ verification and validation is impossible
 Systems are easily extensible
◦ mobile code, dynamically loadable modules
◦ incremental evolution of systems
Top 10 Malware

 According to Sophos 86% of the reported attacks is spyware.


Computer virus examples
• Is a Trojan a virus?

• Trojans can be viruses.

A Trojan is a computer program pretending to be something it’s not for the


purposes of sneaking onto your computer and delivering some sort of
malware. To put it another way, if a virus disguises itself then it’s a Trojan.

• A Trojan could be a seemingly benign file downloaded off the web or a Word
doc attached to an email. Think that movie you downloaded from your
favorite P2P sharing site is safe? What about that “important” tax document
from your accountant? Think twice, because they could contain a virus.
• Is a worm a virus?
• Worms are not viruses, though the terms are sometimes used interchangeably.

• Even worse, the terms are sometimes used together in a strange and
contradictory word salad; i.e. a “worm virus malware.” It’s either a worm or a
virus, but it can’t be both, because worms and viruses refer to two similar but
different threats. As mentioned earlier, a virus needs a host system to replicate
and some sort of action from a user to spread from one system to the next.

• A worm, conversely, doesn’t need a host system and is capable of spreading


across a network and any systems connected to the network without user
action. Once on a system, worms are known to drop malware (often
ransomware) or open a backdoor.
• Is ransomware a virus?
• Ransomware can be a virus.

• Does the virus prevent victims from accessing their system or personal files
and demands ransom payment in order to regain access à la ransomware? If
so, then it’s a ransomware virus. In fact, the very first ransomware was a virus
(more on that later).

• Nowadays, most ransomware comes as a result of computer worm, capable of


spreading from one system to the next and across networks without user
action (e.g. WannaCry).
• Is a rootkit a virus?

• Rootkits are not viruses.

• A rootkit is a software package designed to give attackers “root” access or


admin access to a given system. Crucially, rootkits cannot self-replicate and
don’t spread across systems.
• Is a software bug a virus?

• Software bugs are not viruses.

• Even though we sometimes refer to a biological virus as a “bug” (e.g. “I caught a


stomach bug”), software bugs and viruses are not the same thing. A software bug
refers to a flaw or mistake in the computer code that a given software program is
made up of. Software bugs can cause programs to behave in ways the software
manufacturer never intended.

• The Y2K bug famously caused programs to display the wrong date, because the
programs could only manage dates through the year 1999. After 1999 the year
rolled over like the odometer on an old car to 1900. While the Y2K bug was
relatively harmless, some software bugs can pose a serious threat to consumers.
Cybercriminals can take advantage of bugs in order to gain unauthorized access to a
system for the purposes of dropping malware, stealing private information, or
opening up a backdoor. This is known as an exploit.
Do Macs get malware?
What is Non-Repudiation?
• Non-repudiation is the ability to prevent an electronic message or transaction
that someone cannot deny the validity of something.

• It is a legal concept that’s mostly used in information security and refers to a


service, which provides a reason for the origin and integrity of data.

• In other words, non-repudiation makes it very challenging to strongly deny


who/where a message comes from, as well as the authenticity and integrity of
that message.
• What is Non repudiation?

• Non-repudiation is an often used service to ensure the authenticity and source of


data and prevent a denial in an electronic message or transaction that someone
cannot deny the validity of something.

• It ensures that both the sender and the recipient of the information will receive
proof of delivery and the sender’s identity, so nobody may deny processing the
information at a later time.

• Nonrepudiation is a legal concept that is also frequently used in


communications, computing, and security-related information processing. This
also guarantees evidence of the origins, authenticity, and unaltered state of data.
• How Does it Relate to Network Security?

• Online Transactions: Digital signatures are created to join a public key with an
encrypted key, ensuring that parties cannot be challenged in the future for the
authenticity of a signature or the transmission of information.

• Data Audit Logs: A digital signature, generated through a hash algorithm, is


distributed as a checksum for log files and confirms their integrity.

• E-commerce: Non-repudiation verifies that a communication was received and


acknowledged by the recipient, which helps resolve conflicts.

• Digital Contracts and Email: Email methods of surveillance are part of the non-
repudiation process. A signed message cannot be returned or sent back without the
signature of the sender and the recipient.
• Pillars of Non-Repudiation
• Verification: Nonrepudiation is ensuring that users are genuinely who they
claim to be, using methods like passwords, usernames, digital certificates, and
security tokens.

• Reliability: Nonrepudiation encourages that information is always available


on time and performs well whenever it’s needed.

• Privacy: Limiting access to sensitive data, such as personally identifiable


information and confidential corporate data.

• Non-denial: This prohibits people from being able to retract their actions
because the system records each action they perform.
• Benefits Of Non-repudiation
• Nonrepudiation is mostly accomplished through cryptography, like digital
signatures, and consists of other services for authentication, auditing, and
logging.

• A MAC can provide integrity and authentication while preventing message


fabrication by those who do not know the shared secret key.

• Only the private key holder can access and create this signature that proves a
document was electronically signed and verified.

• In non-repudiation, Digital signatures guarantee that a third party cannot


subsequently withdraw sending information or contest the legitimacy of its
signature in online transactions.
Availability
• Availability is one of the three basic functions of security management that
are present in all systems.

• Availability is the assertion that a computer system is available or accessible


by an authorized user whenever it is needed. Systems have high order of
availability to ensures that the system operates as expected when needed.

• Availability provides building of fault tolerance system in the products. It


also ensures the backup processing by including hot and cold sites in the
disaster recovery planning.
• 1. Denial of Service:

Denial of Service specifies to actions that lock up computing services in a way
that the authorized users is unable to use the system whenever needed.

• Availability is also blocked in case, if a security office unintentionally locks up


an access control of database during the routine maintenance of the system
thus for a period of time authorized users are block to access.

• In the computer systems, internet worm overloaded about 10% of the system
on the network, causing them to be non responsive to the need of users is an
example of denial of service.
• 2. Loss of Data Processing Capabilities:

• The loss of data processing capabilities are generally caused by the natural
disasters or human actions is perhaps more common.

• Contingency planning is the measure to counter such type of losses, which


helps in minimizing the time for that a data processing capability remains
unavailable.

• Contingency planning provides an alternative means of processing which


involves business resumption planning, alternative site processing or simply
disaster recovery planning thereby ensures data availability.
• Security aspects of Availability:
Generally, three basic issues are aspects of security initiatives that are used to
address availability, they are:
[Link] issues:
The physical issues includes access controls that prevent unauthorized persons
from coming into contact with computing resources, various fire and water
control mechanisms, hot and cold sites for use in alternative site processing,
and backup storage facilities.
[Link] issues:
Technical issues includes the fault-tolerance mechanisms, electronic vaulting
(automatically backup to a secure location) and access control software to
restrict unauthorized users from disrupting services. Fault tolerance
mechanisms involves hardware redundancy, disk mirroring and application
checkpoint restart.
• Administrative issues:

• The issues comes in the administrative aspect of availability are access


control policies, operating procedures, contingency planning and user
training.

• Proper training of operators, programmers and security personnel can help


avoid many computing stages that leads to the loss of availability.
Department of Computer
Science and Engineering
Access Control
Department of Computer
Science and Engineering

➢Today we will start to cover Access Control


▪ Access Control: It is a security technique that regulates who or what can
view or use resources in a computing environment.

➢A bit theoretic concept


▪ because it is more than read, write, execute

➢But still an operating system related concept


▪ the resources are to be accessed but by whom?
▪ access control paradigms center around this question
50
A Model for Access Control
Department of Computer
Science and Engineering

access reference
subject object
request monitor

source request guard resource


(e.g. users, (e.g. files,
processes) printers)

51
Basic Terminology Department of Computer
Science and Engineering

➢Subject/Principal: active entity – user or process


➢Object: passive entity – file or resource
➢Access operations: read, write, ...
▪ Access operations vary from basic memory/file access to method calls in an
object-oriented system.
▪ Comparable systems may use different access operations.
➢Authorization:
▪ Access control decision is actually an authorization decision
▪ if o is an object, authorization answers the question “Who is trusted to access
o?”

52
Simple analogy Department of Computer
Science and Engineering

➢Consider a paper-based office in which certain documents should


only be read by certain individuals
➢We could implement access control by
▪ storing documents in filing cabinets
▪ issuing keys to the relevant individuals for the appropriate cabinets.
➢The reference monitor is the set of locked filing cabinets
▪ An access request (an attempt to open a filing cabinet) is granted if the key
fits the lock (and denied otherwise)

53
Options for Focusing Control
Department of Computer
Science and Engineering

➢Subjects and objects provide a different focus of control


▪ What is the subject allowed to do?
▪ What may be done with an object?

➢Traditionally, multi-user operating systems manage files and


resources, i.e. objects
▪ Access control takes the second approach

➢Application oriented IT systems, like DBMSs, offer services for the


user and control the actions of subjects.
54
Elementary access operations Department of Computer
Science and Engineering

➢On the most elementary level, a subject may


▪ observe an object, or
▪ alter an object.
➢We refer to observe and alter as access modes.
➢The four Bell-LaPadula (BLP) access rights:
▪ execute
▪ read
▪ append, also called blind write
▪ write

55
Department of Computer
BLP Access Rights and Modes Science and Engineering

➢Mapping between access rights and access modes.


execute append read write
observe X X
alter X X

➢Write access usually includes read access. Hence, the write right includes observe and alter
mode.
➢Few systems implement append. Allowing users to alter an object without observing its
content is rarely useful (exception: audit log).
➢A file can be used without being opened and read. Example: use of a cryptographic key.
This can be expressed by an execute right that includes neither observe nor alter mode.

56
Who Sets the Policy?
Department of Computer
Science and Engineering

Security policies specify how subjects access objects. There are two
mechanisms for deciding who is in charge of setting the policy:

➢The owner of a resource decides who is allowed access. Such


policies are called discretionary as access control is at the owner’s
discretion.
➢A system wide policy decides who is allowed access. Such policies
are called mandatory.

57
Access Control Structures
Department of Computer
Science and Engineering

➢Requirements on access control structures:


▪ The access control structure should help to express your desired access control
policy.

▪ You should be able to check that your policy has been captured correctly.

➢Access rights can be defined individually for each combination of subject


and object.

➢For large numbers of subjects and objects, such structures are


cumbersome to manage.
▪ Intermediate levels of control are preferable.
58
Access Control Matrix Department of Computer
Science and Engineering

• S … set of subjects
• O … set of objects
• A … set of access operations
• Access control matrix: M = (Mso)sS,oO,
Mso  A; Mso specifies the operations subject s may perform on object o.
• The access control matrix is
• an abstract concept
• not very suitable for direct implementation
• Management of the matrix is likely to be extremely difficult if there are ten thousands
of files and hundreds of users (resulting in millions of matrix entries)
• The matrix is likely to be extremely sparse and therefore implementation is inefficient

[Link] [Link] [Link]


Alice {} {exec} {exec,read}
Bob {read,write}
59 {exec} {exec,read,write}
Department of Computer
Science and Engineering

• What is Defense-in-depth –
• Defense-in-depth is an information assurance strategy that provides multiple,
redundant defensive measures in case a security control fails or a vulnerability
is exploited. It originates from a military strategy by the same name, which
seeks to delay the advance of an attack, rather than defeating it with one
strong line of defense.

• Defense-in-depth cybersecurity use cases include end-user security, product


design and network security.

• An opposing principle to defense in depth is known as simplicity-in-security,


which operates under the assumption that too many security measures might
introduce problems or gaps that attackers can leverage.
Department of Computer
Science and Engineering
Department of Computer
Science and Engineering

• Défense in depth, layered security architecture


• Physical controls – These controls include security measures that prevent
physical access to IT systems, such as security guards or locked doors.

• Technical controls – Technical controls include security measures that protect


network systems or resources using specialized hardware or software, such as
a firewall appliance or antivirus program.

• Administrative controls – Administrative controls are security measures


consisting of policies or procedures directed at an organization’s employees,
e.g., instructing users to label sensitive information as “confidential”.
Department of Computer
Science and Engineering

• Defense-in-depth information assurance: Use cases


• Broadly speaking, defense-in-depth use cases can be broken down into user
protection scenarios and network security scenarios.
• Website protection
• Defense-in-depth user protection involves a combination of security offerings
(e.g., WAF, antivirus, antispam software, etc.) and training to block threats and
protect critical data.
• A vendor providing software to protect end-users from cyberattacks can bundle
multiple security offerings in the same product. For example, packaging together
antivirus, firewall, anti-spam and privacy controls.
• As a result, the user’s network is secured against malware, web application
attacks (e.g., XSS, CSRF).
Department of Computer
Least Privileges - Science and Engineering

• What is Least Privilege?


• The principle of least privilege (PoLP) refers to an information security
concept in which a user is given the minimum levels of access – or
permissions – needed to perform his/her job functions. It is widely considered
to be a cybersecurity best practice and is a fundamental step in
protecting privileged access to high-value data and assets.

• Least privilege extends beyond human access. The model can be applied to
applications, systems or connected devices that require privileges or
permissions to perform a required task. Least privilege enforcement ensures
the non-human tool has the requisite access needed – and nothing more.
Department of Computer
Science and Engineering

• Why is the Principle of Least Privilege Important?


• It reduces the cyber attack surface. Most advanced attacks today rely on
the exploitation of privileged credentials. By limiting super-user and administrator
privileges (that provide IT administrators will unfettered access to target systems), least
privilege enforcement helps to reduce the overall cyber attack surface.
• It stops the spread of malware. By enforcing least privilege on endpoints, malware
attacks (such as SQL injection attacks) are unable to use elevated privileges to increase
access and move laterally in order to install or execute malware or damage the machine.
• It improves end-user productivity. Removing local administrator rights from business
users helps to reduce the risk, but enabling just-in-time privilege elevation, based on
policy, helps to keep users productive and keeps IT helpdesk calls to a minimum.
• It helps streamline compliance and audits. Many internal policies and regulatory
requirements require organizations to implement the principle of least privilege on
privileged accounts to prevent malicious or unintentional damage to critical systems. Least
privilege enforcement helps organizations demonstrate compliance with a full audit trail of
privileged activities.
Department of Computer

Importance of Security in Cloud Science and Engineering

• Cloud security is the complete set of interrelated policies, tools, processes, and
personnel for protecting cloud computing environments from harm. It applies to
every part of the cloud computing stack, from networking and storage (cloud
infrastructure) all the way up to data and applications.

• Cloud security shares some core concepts with traditional on-


premises cybersecurity, but involves unique technologies and best practices of
its own.

• The latter components help defend against certain sophisticated threats in the
cloud, protect a dissipating network perimeter, and properly distribute security
responsibilities between cloud service providers and their customers.
Department of Computer

Why is cloud security important? Science and Engineering

The high-level objectives of cloud security are to:

• Ensure cloud data, users, and underlying systems are sufficiently secured
against threats such as bot-driven distributed denial-of-service (DDoS)
attacks, API exploitation, and data corruption vulnerabilities.

• Support regulatory compliance requirements with applicable statutes, like


those governing where cloud data can be stored and what levels of user
privacy cloud providers must respect
Department of Computer
Science and Engineering

• Provide visibility across the cloud environment, so security teams know what
requests are being made via APIs and user interfaces, while also being able to view
related analytics.

• Enforce access controls and authentication for cloud users and their devices, no
matter their locations; this is often done via a zero trust security model

• Assign responsibilities to the cloud service provider and to the subscriber, as


appropriate for the cloud service and deployment model(s) in question
Department of Computer
What is a cloud security architecture? Science and Engineering

• A cloud security architecture is a structure for how security responsibilities


are shared between the cloud provider and subscriber—basically, a
determination of who secures what, and in which ways.

• In each area for which it is responsible, the provider or customer will take
care of specific technical components that either secure the cloud apps
themselves or secure access to them.
Department of Computer
Science and Engineering
• What is Cloud ?

• The term Cloud refers to a Network or Internet. In other words,


we can say that Cloud is something, which is present at remote
location. Cloud can provide services over public and private
networks, i.e., WAN, LAN or VPN.

• Applications such as e-mail, web conferencing, customer


relationship management (CRM) execute on cloud.
What is Cloud Computing?
• Cloud Computing refers to manipulating,
configuring, and accessing the hardware and software resources
remotely. It offers online data storage, infrastructure, and application.

• Cloud computing offers platform independency, as the software is


not required to be installed locally on the PC. Hence, the Cloud
Computing is making our business
applications mobile and collaborative.
• NIST says – Cloud model is composed of five essential
characteristics, three service models, and four deployment models
are!

• Five essential characteristics


[Link]-demand self-service
[Link] network access
[Link] pooling
[Link] elasticity
[Link] Service
• Three service models
[Link] Software as a Service (SaaS)
[Link] Platform as a Service (PaaS)
[Link] Infrastructure as a Service (IaaS)

• Four deployment models


[Link] cloud
[Link] cloud
[Link] cloud
[Link] cloud
• Key enabling technologies include:
[Link] wide-area networks
[Link]
[Link] server computers
[Link]-performance virtualization for commodity hardware.
• Public Cloud
• The public cloud allows systems and services to be easily accessible to
the general public. Public cloud may be less secure because of its
openness.
• Private Cloud
• The private cloud allows systems and services to be accessible within
an organization. It is more secured because of its private nature.
• Community Cloud
• The community cloud allows systems and services to be accessible by a
group of organizations.
• Hybrid Cloud
• The hybrid cloud is a mixture of public and private cloud, in which the
critical activities are performed using private cloud while the non-
critical activities are performed using public cloud.
• Service Models
• Cloud computing is based on service models. These are categorized
into three basic service models which are -
• Infrastructure-as–a-Service (IaaS)
• Platform-as-a-Service (PaaS)
• Software-as-a-Service (SaaS)
• Anything-as-a-Service (XaaS) is yet another service model, which
includes Network-as-a-Service, Business-as-a-Service, Identity-as-a-
Service, Database-as-a-Service or Strategy-as-a-Service.

• The Infrastructure-as-a-Service (IaaS) is the most basic level of


service. Each of the service models inherit the security and management
mechanism from the underlying model, as shown in the following
diagram:
• Infrastructure-as-a-Service (IaaS)
• IaaS provides access to fundamental resources
such as physical machines, virtual machines,
virtual storage, etc.
• Platform-as-a-Service (PaaS)
• PaaS provides the runtime environment for
applications, development and deployment tools,
etc.
• Software-as-a-Service (SaaS)
• SaaS model allows to use software applications
as a service to end-users.
What is Cryptography Department of Computer
Science and Engineering

➢ Cryptography refers to the science and art of transforming messages to make them
secure and immune to attacks. It is the study of
➢ Secret (crypto-) writing (-graphy)
➢ It can be described as the study of protecting information weather in transit or at
rest, by using techniques to render the information unusable to anyone who does not
possess the means to decrypt it. Encryption Decryption

Plaintext Ciphertext Plaintext

➢ It is a method of storing and transmitting data in a particular form so that only


those for whom it is intended can read and process it.
➢ Cryptography not only protects data from theft or alteration but can also be used
for user authentication.
Department of Computer
Components or Basics terms Science and Engineering

➢ Encryption
▪ Scrambling a message or data using a specialized cryptographic algorithm.
➢ Plaintext
▪ The message or data before it gets encrypted.
➢ Ciphertext
▪ The encrypted version of the message.
➢ Cipher
▪ The algorithm that does the encryption.
➢ Decryption
▪ The process of converting ciphertext back to the original plaintext.
Basics of Cryptography Department of Computer
Science and Engineering

➢ Cryptography is associated with the process of converting


ordinary plain text into unintelligible text and vice-versa.

Relationship between the plaintext and the ciphertext

86
Department of Computer
The General Goals of Cryptography Science and Engineering

➢ Confidentiality
C I
▪ Assuring that only authorized parties are able to understand the data. S
➢ Integrity
A
▪ Ensuring that when a message is sent over a network, the message that
arrives is the same as the message that was originally sent.
S = Secure
➢ Availability
▪ Can access data whenever need it?
❑ Other security components added to CIA to be complete as CIAAAN
✓ Authentication: Ensuring that whoever supplies or accesses sensitive data is an authorized party.
✓ Authorization: Ensuring the users permission to access a resource.
✓ Non-repudiation: Ensuring that the intended recipient actually received the message & ensuring that the
sender actually sent the message.
Department of Computer
Types of Ciphers Science and Engineering

➢Cipher: Cipher is a method for encrypting messages.


➢Symmetric Ciphers: same key used for encryption and decryption.
▪ Strength of algorithm is determined by the size of the key.
• The longer the key the more difficult it is to crack
▪ Key length is expressed in bits: Typical key sizes vary between 48 bits and 448 bits
➢Two Types:
▪ Block cipher: encrypts a block of plaintext at a time (typically 64 or 128 bits).
▪ Stream cipher: encrypts data one bit or one byte at a time.
➢Asymmetric Ciphers: different keys used for encryption and decryption
➢Two most popular algorithms are :
▪ RSA: Ron Rivest, Adi Shamir and Leonard Adleman.
▪ ECC: Elliptic Curve Cryptosystems.
Department of Computer
Symmetric Key Encryption Science and Engineering

➢ With this approach the sender and


the receiver use the same secret
key to encrypt and decrypt
messages.
➢ The strength of symmetric key
encryption is fast, bulk encryption.

➢ Major Challenges
▪ Key distribution- It requires a secure mechanism to deliver keys properly.
▪ Scalability- Each pair of users needs a unique pair of keys, so the number of keys grow exponentially.
➢ Examples of symmetric algorithms are as follows: (EXTENDED LEARNING)
▪ DES (Data Encryption Standard)
▪ AES (Advanced Encryption Standard)
Department of Computer
Types of Symmetric Algorithms Science and Engineering

Block Cipher Stream Cipher

➢ Operate by encrypting a fixed amount, or ➢ Treats the message as a stream of bits


“block,” (64 or 128 bit) of data or bytes and performs mathematical
➢ It is somewhat faster than stream cipher functions on them individually
each time n characters executed. ➢ The same plaintext bit or byte will be
➢ Transmission errors in one cipher text transformed into a different ciphertext
block have no affect on other blocks. bit or byte each time it is encrypted
➢ Identical blocks of plaintext produce ➢ Stream cipher is less vulnerable to
identical blocks of cipher text. insertion or deletion.
➢ Block encryption may be more ➢ Transmission error at the nth bit in the
susceptible to cryptanalysis than either stream cipher may lead to incorrect
stream mode. ciphertext thereafter.
Department of Computer
Common Symmetric Algorithms Science and Engineering

DES AES
➢ Designed by IBM in the 1970s and adopted ➢ AES was announced by National Institute of
by the National Institute for Standards and Standards and Technology on November 26,
Technology (NIST)] in 1977 for commercial 2001.
and unclassified government applications.
➢ AES is a block cipher with a block length of
➢ DES is a block-cipher employing a 56- bit
key that operates on 64-bit blocks. 128 bits.
➢ It allows for three different key lengths: 128,
➢ DES results in a permutation among the 264
possible arrangements of 64 bits, each of 192, or 256 bits.
which may be either 0 or 1 ➢ Encryption consists of 10 rounds of
➢ Triple DES (3DES) is an enhanced version processing for 128-bit keys, 12 rounds for
of DES which applies the Data Encryption 192-bit keys, and 14 rounds for 256- bit keys.
Standard (DES) cipher algorithm three
times to each data block.
Department of Computer
Asymmetric Key Encryption Science and Engineering

➢ Asymmetric encryption uses a key pair (Public key and Private key) .
➢ The two different asymmetric keys are mathematically related but cannot be derived
from each other.
➢ Each key type can be used to encrypt and decrypt. If data is encrypted with a private
key, it must be decrypted with the corresponding public key and vice versa.
➢ Better key distribution and scalability than symmetric systems.
➢ Works much slower than symmetric systems.
➢ Examples of asymmetric key algorithms:
▪ RSA
▪ Elliptic Curve Cryptosystem (ECC)
Department of Computer
Common Asymmetric Algorithms Science and Engineering

➢ RSA (Ron Rivest, Adi Shamir and Leonard Adleman)


▪ Developed in 1978 at MIT.
▪ RSA gets its security from the difficulty of factoring large numbers
▪ Best known & widely used.
▪ Each user generates a public/private key pair by applying the RSA
algorithm to two large primes at random say p and q
▪ One advantage of using RSA is that it can be used for encryption and digital
signatures
▪ RSA is used in many Web browsers with the Secure Sockets Layer (SSL)
protocol
Common Asymmetric Algorithms Department of Computer
(contd.)
Science and Engineering

➢ Elliptic Curve Cryptosystems (ECCs):


▪ ECC was introduced by Victor Miller and Neal Koblitz in 1985.
▪ For elliptic-curve-based protocols, it is assumed that finding the discrete logarithm of a
random elliptic curve element with respect to a publicly known base point is infeasible.
▪ The size of the elliptic curve determines the difficulty of the problem.
▪ ECC requires significantly smaller key size with same level of security as compared to
the key size for RSA : faster computations, need less storage space.
▪ ECC ideal for constrained environments : Pagers , PDAs , Cellular Phones and Smart
Cards.
Public Key Cryptography
Department of Computer
Science and Engineering

➢ It is a hybrid use of two different algorithms: asymmetric and symmetric.


➢ Public key cryptography uses two keys (public and private) generated by an
asymmetric algorithm for protecting encryption keys and key distribution, and a
secret key is generated by a symmetric algorithm and used for bulk encryption.
Bill sends
a message
Department of Computer
Hashing Techniques Science and Engineering

➢ Cryptographic hashing functions are used to ensure the integrity of data using an
integrity checksum.
➢ Hashing functions are one-way functions. This means that the ciphertext (i.e., the
checksum) cannot be used to reconstruct the plaintext.
➢ The checksum (the ciphertext) is much smaller than the plaintext.
➢ Hashing functions provide a kind of digital fingerprint.
➢ The security of the hashing function is related to the size of the resulting checksum
(in bits).
➢ Examples of Hashing Algorithms: (Extended Learning)
▪ MD5 (Message-Digest algorithm 5)
▪ SHA (Secure Hash Algorithm)
Hashing Algorithms
Department of Computer
Science and Engineering

SHA MD5
⚫ 128- bit hash value typically
⚫ SHA-1 produces a 160-bit hash value. expressed as a 32-digit hexadecimal
number.
⚫ SHA-256 uses 32-bit words.
⚫ MD5 processes a variable-length message
⚫ SHA-512 uses 64-bit words. into a fixed-length output of 128 bits.

⚫ The collision ratio for SHA is far less ⚫ It is easy to compute.


than the collision ratio MD5. ⚫ It is infeasible to modify a message without
changing its hash.
⚫ No two messages have the same hash.
Digital Signatures Department of Computer
Science and Engineering

➢ Goals
▪ It should be proof of authenticity and should be impossible to forge.
▪ It should be impossible to alter the signed document without detection.
▪ It should be impossible to transplant the signature to another document.
➢ Technology
▪ A hash function to help generate the digital signature, S.
▪ Symmetric (secret key) cryptography to encrypt the message, M.
▪ Public key cryptography to share the secret key used to encrypt and decrypt the message, M.
▪ Public key cryptography to encrypt and decrypt the digital signature, S.
Department of Computer
Public Key Infrastructure (PKI) Science and Engineering

➢ It consists of programs, data formats, procedures, communication protocols,


security policies, and public key cryptographic mechanisms working in a
comprehensive manner to enable a wide range of dispersed people to
communicate in a secure and predictable fashion.
➢ PKI is an ISO authentication framework that uses public key cryptography
and the X.509 standard protocols
➢ PKI provides authentication, confidentiality, nonrepudiation, and integrity of
the messages exchanged
➢ PKI is a hybrid system of symmetric and asymmetric key algorithms
➢ Each person who wants to participate in a PKI requires a digital certificate
Thanks

You might also like