0% found this document useful (0 votes)
8 views22 pages

Overview of Security Mechanisms

Chapter 1 introduces key concepts in information security, focusing on three primary goals: confidentiality, integrity, and availability. It discusses various security attacks that threaten these goals, categorizing them into passive and active attacks, and outlines the relationship between security services and mechanisms. The chapter also introduces cryptography and steganography as techniques to implement security mechanisms.

Uploaded by

ymoo683
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views22 pages

Overview of Security Mechanisms

Chapter 1 introduces key concepts in information security, focusing on three primary goals: confidentiality, integrity, and availability. It discusses various security attacks that threaten these goals, categorizing them into passive and active attacks, and outlines the relationship between security services and mechanisms. The chapter also introduces cryptography and steganography as techniques to implement security mechanisms.

Uploaded by

ymoo683
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPT, PDF, TXT or read online on Scribd

Chapter 1

Introduction

Yawai Tint 1.1


Chapter 1
Learning Outcomes
 To define three security goals
 To define security attacks that threaten security goals
 To define security services and how they are related to the three
security goals
 To define security mechanisms to provide security services
 To introduce two techniques, cryptography and steganography,
to implement security mechanisms.

Yawai Tint 1.2


SECURITY GOALS

This section defines three security goals.

Yawai Tint 1.3


Cont’d

Taxonomy of security goals

Yawai Tint 1.4


Confidentiality

 Confidentiality is probably the most common aspect of information


security. We need to protect our confidential information. An
organization needs to guard against those malicious actions that
endanger the confidentiality of its information.

Yawai Tint 1.5


Integrity

 Information needs to be changed constantly. Integrity means that


changes need to be done only by authorized entities and through
authorized mechanisms.

Yawai Tint 1.6


Availability

 The information created and stored by an organization needs to be


available to authorized entities. Information needs to be constantly
changed, which means it must be accessible to authorized entities.

Yawai Tint 1.7


Attacks

The three goals of securityconfidentiality, integrity, and


availabilitycan be threatened by security attacks.

Topics discussed in this section:

Yawai Tint 1.8


Cont’d

Taxonomy of attacks with relation to security goals


Yawai Tint 1.9
Attacks Threatening Confidentiality

 Snooping refers to unauthorized access to or interception of data.


 Traffic analysis refers to obtaining some other type of information
by monitoring online traffic.

Yawai Tint 1.10


Attacks Threatening Integrity

 Modification means that the attacker intercepts the message and


changes it.
 Masquerading or spoofing happens when the attacker impersonates
somebody else.
 Replaying means the attacker obtains a copy
of a message sent by a user and later tries to replay it.
 Repudiation means that sender of the message might later deny
that she has sent the message; the receiver of the message might
later deny that he has received the message.
Yawai Tint 1.11
Attacks Threatening Availability

 Denial of service (DoS) is a very common attack. It may slow


down or totally interrupt the service of a system.

Yawai Tint 1.12


Passive Versus Active Attacks

Categorization of passive and active attacks

Attacks Passive/Active Threatening


Snooping Passive Confidentiality
Traffic Analysis
Modification Active Integrity
Masquerading
Replaying
Repudiation
Denial of service Active Availability

Yawai Tint 1.13


Services and Mechanisms

 ITU-T provides some security services and some mechanisms


to implement those services. Security services and
mechanisms are closely related because a mechanism or
combination of mechanisms are used to provide a service.

Topics discussed in this section:

Yawai Tint 1.14


Security Services

Security services

Yawai Tint 1.15


Security Mechanism

Yawai Tint
Security mechanisms 1.16
Relation between Services and Mechanisms

Relation between security services and mechanisms

Security Service Security Mechanism


Data confidentiality Encipherment and routing control
Data integrity Encipherment, digital signature, data integrity
Authentication Encipherment, digital signature, authentication
exchanges
Nonrepudiation Digital signature, data integrity, and notarization
Access control Access control mechanism

Yawai Tint 1.17


Techniques

Mechanisms discussed in the previous sections are only


theoretical recipes to implement security. The actual
implementation of security goals needs some techniques. Two
techniques are prevalent today: cryptography and steganography.

Topics discussed in this section:

Yawai Tint 1.18


Cryptography

Cryptography, a word with Greek origins, means “secret writing.”


However, we use the term to refer to the science and art of transforming
messages to make them secure and immune to attacks.

Yawai Tint 1.19


Steganography

The word steganography, with origin in Greek, means “covered


writing,” in contrast with cryptography, which means “secret writing.”

Example: covering data with text

Yawai Tint 1.20


Cont’d

Example: using dictionary

Example: covering data under color image

Yawai Tint 1.21


The Rest of this Book

The rest of this book is divided into four parts.

Part One: Symmetric-Key Enciphermen

Part Two: Asymmetric-Key Encipherment

Part Three: Integrity, Authentication, and Key Management

Part Four: Network Security

Yawai Tint 1.22

You might also like