[Link] Hacking.
Explain different types of Hackers: obscene content without consent, and is punishable
Hacking is the unauthorized access or control over under cyber laws.
computer network security systems.
Types of hackers:White Hat – Ethical hackers.
Black Hat – Malicious hackers.
[Link] between Firewall and IDS:
Grey Hat – Mix of both; hack
without permission but without harmful intent. Intrusion Detection
Firewall
Script Kiddies – Inexperienced System (IDS)
hackers using existing tools.
Controls and filters Monitors network/system
Hacktivists – Hack for political or
incoming/outgoing traffic for suspicious activity
social messages.
2. PGP (Pretty Good Privacy) is a data encryption and Acts as a barrier to prevent Detects but does not block
decryption program that provides secure communication unauthorized access attacks
by ensuring confidentiality, authentication, and data
integrity. It combines symmetric-key encryption for fast Uses signatures or
data encryption and public-key encryption for secure key Works on predefined rules
anomaly detection
exchange. PGP is commonly used to secure emails and and policies
methods
files.
3. List two protocols in IP Sec. State its function: Operates at network and Can operate at all layers
transport layers depending on type
• AH (Authentication Header): Ensures data
integrity and authenticity. 8. Explain AH & ESP with respect to IP security?
AH (Authentication Header) and ESP (Encapsulating
• ESP (Encapsulating Security Payload): Provides
Security Payload) are two main protocols in IPsec:
confidentiality, integrity, and authenticity.
[Link] is the technique of hiding secret • AH provides authentication and integrity for IP
information within an ordinary file or message to avoid packets, ensuring that the data has not been
detection. Unlike encryption, which scrambles the altered and is from a legitimate source. It does
content, steganography hides the fact that communication not provide encryption.
is taking place—commonly by embedding hidden data in
images, audio, video, or text files. • ESP provides encryption, authentication, and
5. What is IP Security? Describe authentication header integrity, ensuring confidentiality of data along
mode of IP security: with source verification and protection against
tampering.
IP Security (IPSec) is a protocol suite used to secure IP
communications by authenticating and encrypting each 9 Define Cyber Terrorism?
IP packet in a communication session. It ensures Cyber terrorism refers to the use of internet or computer
confidentiality, integrity, and authentication. systems to conduct violent acts that threaten or cause
Authentication Header (AH) Mode in IPSec provides data fear for political, religious, or ideological objectives. It
integrity, origin authentication, and protection against includes attacks on critical infrastructure like power grids,
replay attacks, but it does not encrypt the data. It adds government networks, or communication systems to
an AH header to the packet to verify that the data has not disrupt services and create panic among the public.
been tampered with.
12 Differentiate between host
6. List any four types of cybercrimes and explain one Network-
based & network based IDS. Host-Based
1. Identity Theft Based IDS
Point IDS (HIDS)
(NIDS)
2. Cyberstalking
Installed on Placed at
3. Phishing
individual strategic
1. Location
4. Hacking devices or points in the
hosts network
Explanation – Phishing:
Phishing is a cybercrime where attackers trick users into Monitors OS
Monitors
revealing sensitive information like passwords or credit logs,
network traffic
card details by pretending to be a trusted entity, usually 2. Data Monitored application
and packet
through fake emails or websites. activity, and
data
[Link] pornography refers to the distribution, sharing, file integrity
or access of pornographic material through the internet,
digital platforms, or electronic devices. It may involve 3. Visibility Has deep Has a broader
illegal content such as child pornography or sharing insight into view of
infrastructure, or government organizations. It includes
12 Differentiate between host hacking government websites, spreading propaganda, or
based & network based IDS. Network-
Host-Based initiating digital attacks to create panic or fear.
Based IDS
Point IDS (HIDS)
(NIDS) (ii) Cyber Stalking
Classification: Cyber Crime Against Individuals
the internal network-wide Explanation: Cyber stalking involves using electronic
behavior of activities communication to harass or threaten someone
the system persistently. It may include sending repeated emails,
messages, or social media harassment, causing mental
Runs distress to the victim.
Uses host
independently,
system [Link] between Substitution Cipher and
doesn’t
4. Resource Usage resources, Transposition Cipher:
burden
may impact
individual
performance Substitution
hosts Aspect Transposition Cipher
Cipher
Replaces each Rearranges the
13. Explain e-mail security techniques: character in the position of characters
Definition
plaintext with without changing the
• Encryption (e.g., PGP, S/MIME): Protects email another character. characters themselves.
content from unauthorized access.
Changes the Changes the
Encryption
• Digital Signatures: Verifies sender identity and identity of the position/order of
Method
ensures message integrity. characters. characters.
• Spam Filters & Antivirus: Detect and block ‘HELLO’ →
malicious or junk emails. ‘HELLO’ → ‘LOHEL’
Example ‘IFMMP’ (each
(letters rearranged)
letter shifted by 1)
• Two-Factor Authentication (2FA): Adds a
security layer to access email accounts. Easier to break Harder to detect due to
14. Explain limitations of Firewall: Security using frequency unchanged letter
analysis. frequency.
• Cannot detect or stop insider attacks.
• Cannot inspect encrypted traffic for threats.
• Limited protection against malware or 19 Advantages of Host Based IDS.
advanced persistent threats (APTs). 1. Monitors Internal Activity:
It can detect suspicious behavior on the specific
• May block legitimate traffic due to strict rules. host, including unauthorized file access or
[Link]-Based Intrusion Detection System (NIDS): privilege escalation.
It is a security system that monitors and analyzes network 2. Detailed Logging and Analysis:
traffic for suspicious activities or policy violations. NIDS Provides in-depth analysis of system logs,
operates at the network level and detects threats in real- application activity, and user actions for precise
time without affecting individual host performance. threat detection.
16. (i) Circuit Gateway:
3. File Integrity Monitoring:
A Circuit Gateway is a type of firewall that works at the
Can track changes to critical system files and
transport layer. It creates a virtual connection between
configurations, helping detect tampering or
the internal user and the remote host, allowing traffic
malware installation.
only after verifying the session.
4. Customizable Security Rules:
(ii) Honey Pots:
Rules and alerts can be tailored for each host
Honey Pots are decoy systems set up to lure attackers.
based on its specific role, improving accuracy
They help in monitoring, detecting, and analyzing
and reducing false positives.
unauthorized access attempts without risking real
systems. 20. Classify the following cybercrimes:
Q17. Classify the following cyber crimes: (i) Copyright Infringement
Classification: Intellectual Property Crime
(i) Cyber Terrorism against a Government Organization
Explanation: This involves unauthorized use,
Classification: Cyber Terrorism
reproduction, or distribution of copyrighted material
Explanation: This refers to the use of internet-based
(such as software, music, movies, or digital content)
attacks to threaten or cause harm to national security,
without the owner's permission. It violates copyright laws • Broad Coverage:
and affects creators' rights and revenues. NIDS monitors all inbound and outbound traffic
across the network, providing a centralized
(ii) Cyber-Stalking view of the entire network’s security.
Classification: Cyber Harassment Crime
Explanation: Cyber-stalking is the use of electronic • Real-Time Detection:
communication (emails, social media, messaging apps) to It analyzes traffic in real time, enabling quick
harass, threaten, or stalk an individual persistently. It can detection and response to potential threats or
lead to emotional distress and fear in victims and is intrusions.
punishable under cyber laws.
21 Define Host Based IDS. • No Impact on Hosts:
A Host-Based Intrusion Detection System (HIDS) is a Since NIDS runs independently of individual
security system installed on an individual host (like a systems, it does not affect the performance of
computer or server) to monitor and analyze activities on any host or device on the network.
that specific system. It checks for suspicious behavior
such as unauthorized access, file changes, or system log • Detection of Wide Range of Attacks:
anomalies. It can detect attacks like port scanning, DoS
attacks, unauthorized access attempts, and
Key Features: suspicious patterns across the network.
• Detects internal threats. 25. Define Email Security. Explain SMTP (4 Marks)
• Provides detailed audit trails. Email Security:
Email security refers to the measures and techniques
• Can trigger alerts for suspicious behavior like used to protect email communication from unauthorized
privilege escalation or file tampering. access, threats, or data breaches. It involves securing the
content, sender/receiver identity, and the transmission
[Link] PEM- Privacy Enhanced Mail. path.
PEM (Privacy Enhanced Mail) is a protocol developed to
secure email communication over the internet using Common techniques include:
cryptographic techniques. It ensures confidentiality,
authentication, message integrity, and non-repudiation. • Encryption (e.g., PGP, S/MIME)
Working: • Digital Signatures
• The message is first encrypted using a • Spam Filters
symmetric key.
• Two-Factor Authentication (2FA)
• The symmetric key is then encrypted using the
recipient’s public key. SMTP (Simple Mail Transfer Protocol):
SMTP is a protocol used to send emails from a client to a
• A digital signature is created using the sender’s server or between servers. It operates on port 25 and
private key. follows a push model. It does not support receiving
[Link] Limitations of Firewall ? emails; protocols like POP3 or IMAP are used for that.
• Cannot Detect Internal Threats:
Working of SMTP:
Firewalls mainly monitor incoming and
outgoing traffic; they cannot detect attacks • User composes email and hits "send".
from insiders or compromised internal systems.
• SMTP client connects to SMTP server.
• Ineffective Against Encrypted Traffic:
Firewalls cannot analyze encrypted packets, • Email is sent to recipient's mail server.
making it hard to detect threats hidden in
encrypted communication. • Recipient retrieves the email using POP3/IMAP.
• Limited Protection Against Malware: 26. List types of firewall. Explain packet filter with
Firewalls cannot detect or remove malware like diagram (4 Marks)
viruses or Trojans once they enter through
allowed traffic. Types of Firewalls:
• No User Authentication or Content Filtering: • Packet Filtering Firewall
Basic firewalls don’t offer user-level control or
detailed content filtering (e.g., detecting
• Stateful Inspection Firewall
malicious attachments in emails). • Proxy Firewall
24. Advantages of network based IDS.
• Next-Generation Firewall (NGFW) 28. Explain Need of Cyber Security (4 marks)
Packet Filtering Firewall: Definition:
Cyber security is the practice of protecting
• Works at Network Layer (Layer 3). systems, networks, and data from digital attacks,
unauthorized access, damage, or theft.
• Filters traffic based on IP address, protocol, and
port number.
Need for Cyber Security:
• Does not inspect payload, only headers.
1. Protect Data Privacy: Prevent unauthorized
Example Rules: access to sensitive personal or organizational
data.
• Allow: TCP from [Link] to [Link] on 2. Prevent Financial Loss: Cyber attacks like
port 80 ransomware and fraud can cause major financial
damage.
• Deny: All traffic from IP [Link] 3. Maintain Business Continuity: Ensures
systems stay secure and operational, avoiding
27. Describe ‘Kerberos’ protocol with suitable downtime.
diagram. 4. Guard Against Threats: Stops malware,
phishing, hacking, and other malicious
activities.
Definition:
Kerberos is a network authentication protocol that uses
secret-key cryptography and a trusted third party to
verify users and services over an insecure network.
Working Steps:
1. User → AS: Sends username to AS.
2. AS → User: Sends encrypted TGT and session
key.
3. User → TGS: Sends TGT and request for
service.
4. TGS → User: Sends service ticket.
5. User → Service Server: Sends service ticket to
access the service.