0% found this document useful (0 votes)
22 views24 pages

Cryptography & Network Security Course

Uploaded by

veweta7491
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
22 views24 pages

Cryptography & Network Security Course

Uploaded by

veweta7491
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Duration: 60 min VI semester ISE Dept 21ISE161

Cryptography & Network


Security
Prof: Dr Saritha Chakrasali
Lesson overview

• Introduction
• Course Objectives & Outcomes
• Textbooks
• Modules
Learning objectives
• Assessments & Assignments
Learning objectives

1 To understand Cryptography Theories, Algorithms and Systems.


2 To understand necessary Approaches and Techniques to build protection mechanisms in order to secure computer networks.
3 To study Information Security Models, threats, and attacks.
4 To know the legal, ethical and professional issues in Information Security
5 To know the technological aspects of Information Security

Learning outcomes

After completing the course, the students will be able to


CO 1: Understand the basic concepts of classical encryption techniques, block ciphers, stream ciphers, cryptographic functions, key
management, and IP security.
CO 2: Explain the structure of various block ciphers and stream ciphers.
CO 3: Apply public key cryptosystems, hash functions and key distribution techniques in real time applications.
CO 4: Understanding the critical characteristics, approaches and need for Information Security.
CO 5: Infer the aspects of risk management and security technologies.
Reference Books

• Cryptography and Network Security – Principles and Practice by William Stallings, Person, 7th Edition, 2017.

• Principles of Information Security, 6th edition, Michael E Whittman, Herbert J Mattord, CENGAGE Learning, 2018

• Network Security Essentials Applications and Standards, William Stallings, Pearson, 4 th Edition, 2012.

• Network Security Private Communication in a Public world, Charlie Kaufman, Radia Perlman and Mike Speciner, 2nd Edition, PHI, 2013.

• Network Security and Management, Brijendra Singh, 3rd Edition, PHI, 2013.
Modules
ASSESSMENT PROCESS

ASSIGNMENTS
ASSIGNMENT : Report on Network security tools
ATT : Quiz, Presentations
Module 1 overview

• Introduction:
• Computer Security Concepts,
• The OSI Security Architecture, Security Attacks, Security Services, Security Mechanisms,
• A Model for Network Security.
Learning objectives
Learning objectives

• Describe the key security requirements of confidentiality, integrity, and availability.

• Describe the X.800 security architecture for OSI.

• Discuss the types of security threats and attacks that must be dealt with and give examples of the types of threats and attacks

that apply to different categories of computer and network assets.

• Explain the fundamental security design principles.

• Discuss the use of attack surfaces and attack trees.

• List and briefly describe key organizations involved in cryptography standards


EXPLAIN 10
min

Cryptographic algorithms and protocols

Network and Internet security


■ Symmetric encryption:
■ Asymmetric encryption
■ Data integrity algorithms:
■ Authentication protocols:
EXPLAIN 10
min

Computer Security:

The protection afforded to an automated information system in order to attain the applicable objectives of
preserving the integrity, availability, and confidentiality of information system resources (includes hardware,
software, firmware, information/data, and telecommunications)

Confidentiality: This term covers two related concepts:


Data1 confidentiality:

Privacy: CIA triad


Integrity: This term covers two related concepts:

Data integrity:

System integrity:

Availability:
ENGAGE 5
min

[Link]

EXPLORE
EXPLAIN
CIA triad
■ Confidentiality: Preserving authorized restrictions on information access and disclosure,
including means for protecting personal privacy and proprietary information.
A loss of confidentiality is the unauthorized disclosure of information.

■ Integrity: Guarding against improper information modification or destruction, including


ensuring information nonrepudiation and authenticity.
A loss of integrity is the unauthorized modification or destruction of information.

■ Availability: Ensuring timely and reliable access to and use of information.


A loss of availability is the disruption of access to or use of information or an information
system.

■ Authenticity: The property of being genuine and being able to be verified and trusted;
confidence in the validity of a transmission, a message, or message originator. This means
verifying that users are who they say they are and that each input arriving at the system came
from a trusted source.

■ Accountability: The security goal that generates the requirement for actions of an entity to be
traced uniquely to that entity. This supports nonrepudiation, deterrence, fault isolation,
intrusion detection and prevention, and after action recovery and legal action. Because truly
secure systems are not yet an achievable goal, we must be able to trace a security breach to a
responsible party. Systems must keep records of their activities to permit later forensic analysis
to trace security breaches or to aid in transaction disputes
ENGAGE 10
min

Three levels of impact on organizations or individuals should there be a breach of security (i.e., a loss of confidentiality, integrity, or
availability)

EXPLORE
EXPLAIN
OSI Security Architecture

■ Security attack: Any action that compromises the security of information owned by an organization.

■ Security mechanism: A process (or a device incorporating such a process) that is designed to detect, prevent, or recover from
a security attack.

■ Security service: A processing or communication service that enhances the security of the data processing systems and the
information transfers of an organization. The services are intended to counter security attacks, and they make use of one or
more security mechanisms to provide the service.
EXPLAIN

Passive Attacks
• Release of message contents
• Traffic Analysis
EXPLAIN Active Attacks
EXPLAIN Active Attacks
•X.800 defines a security service as a
service that is provided by a protocol
layer of communicating open systems
and that ensures adequate security of
the systems or of data transfers.
EXPLAIN Security Mechanisms
EXPLAIN
ENGAGE 10
min

Attack Tree

EXPLORE
EXPLAIN Model for Network Security

This general model shows that there are four


basic tasks in designing a particular security
service:
1. Design an algorithm for performing the
security-related transformation. The
algorithm should be such that an
opponent cannot defeat its purpose.
2. 2. Generate the secret information to be
used with the algorithm.
3. 3. Develop methods for the distribution
and sharing of the secret information.
4. 4. Specify a protocol to be used by the
two principals that makes use of the
security algorithm and the secret
information to achieve a particular
security service.
ENGAGE 10
min

Consider an automated cash deposit machine in which


users provide a card or an account number to deposit
cash. Give examples of confidentiality, integrity, and
avail ability requirements associated with the system,
and, in each case, indicate the degree of importance of
the requirement.

EXPLORE
ENGAGE 10
min

For each of the following assets, assign a low, moderate, or high impact level for the loss of
confidentiality, availability, and integrity, respectively. Justify your answers.
a. A student maintaining a blog to post public information.
b. An examination section of a university that is managing sensitive information about exam
papers.
c. An information system in a pathological laboratory maintaining the patient’s data.
d. A student information system used for maintaining student data in a university that
contains both personal, academic information and routine administrative in formation (not
privacy related). Assess the impact for the two data sets separately and the information
system as a whole.
e. A University library contains a library management system which controls the distribution
of books amongst the students of various departments. The library management system
contains both the student data and the book data. Assess the impact for the two data sets
separately and the information system as a whole.

EXPLORE

You might also like