Chapter 1
Introduction
Yawai Tint 1.1
Chapter 1
Learning Outcomes
To define three security goals
To define security attacks that threaten security goals
To define security services and how they are related to the three
security goals
To define security mechanisms to provide security services
To introduce two techniques, cryptography and steganography,
to implement security mechanisms.
Yawai Tint 1.2
SECURITY GOALS
This section defines three security goals.
Yawai Tint 1.3
Cont’d
Taxonomy of security goals
Yawai Tint 1.4
Confidentiality
Confidentiality is probably the most common aspect of information
security. We need to protect our confidential information. An
organization needs to guard against those malicious actions that
endanger the confidentiality of its information.
Yawai Tint 1.5
Integrity
Information needs to be changed constantly. Integrity means that
changes need to be done only by authorized entities and through
authorized mechanisms.
Yawai Tint 1.6
Availability
The information created and stored by an organization needs to be
available to authorized entities. Information needs to be constantly
changed, which means it must be accessible to authorized entities.
Yawai Tint 1.7
Attacks
The three goals of securityconfidentiality, integrity, and
availabilitycan be threatened by security attacks.
Topics discussed in this section:
Yawai Tint 1.8
Cont’d
Taxonomy of attacks with relation to security goals
Yawai Tint 1.9
Attacks Threatening Confidentiality
Snooping refers to unauthorized access to or interception of data.
Traffic analysis refers to obtaining some other type of information
by monitoring online traffic.
Yawai Tint 1.10
Attacks Threatening Integrity
Modification means that the attacker intercepts the message and
changes it.
Masquerading or spoofing happens when the attacker impersonates
somebody else.
Replaying means the attacker obtains a copy
of a message sent by a user and later tries to replay it.
Repudiation means that sender of the message might later deny
that she has sent the message; the receiver of the message might
later deny that he has received the message.
Yawai Tint 1.11
Attacks Threatening Availability
Denial of service (DoS) is a very common attack. It may slow
down or totally interrupt the service of a system.
Yawai Tint 1.12
Passive Versus Active Attacks
Categorization of passive and active attacks
Attacks Passive/Active Threatening
Snooping Passive Confidentiality
Traffic Analysis
Modification Active Integrity
Masquerading
Replaying
Repudiation
Denial of service Active Availability
Yawai Tint 1.13
Services and Mechanisms
ITU-T provides some security services and some mechanisms
to implement those services. Security services and
mechanisms are closely related because a mechanism or
combination of mechanisms are used to provide a service.
Topics discussed in this section:
Yawai Tint 1.14
Security Services
Security services
Yawai Tint 1.15
Security Mechanism
Yawai Tint
Security mechanisms 1.16
Relation between Services and Mechanisms
Relation between security services and mechanisms
Security Service Security Mechanism
Data confidentiality Encipherment and routing control
Data integrity Encipherment, digital signature, data integrity
Authentication Encipherment, digital signature, authentication
exchanges
Nonrepudiation Digital signature, data integrity, and notarization
Access control Access control mechanism
Yawai Tint 1.17
Techniques
Mechanisms discussed in the previous sections are only
theoretical recipes to implement security. The actual
implementation of security goals needs some techniques. Two
techniques are prevalent today: cryptography and steganography.
Topics discussed in this section:
Yawai Tint 1.18
Cryptography
Cryptography, a word with Greek origins, means “secret writing.”
However, we use the term to refer to the science and art of transforming
messages to make them secure and immune to attacks.
Yawai Tint 1.19
Steganography
The word steganography, with origin in Greek, means “covered
writing,” in contrast with cryptography, which means “secret writing.”
Example: covering data with text
Yawai Tint 1.20
Cont’d
Example: using dictionary
Example: covering data under color image
Yawai Tint 1.21
The Rest of this Book
The rest of this book is divided into four parts.
Part One: Symmetric-Key Enciphermen
Part Two: Asymmetric-Key Encipherment
Part Three: Integrity, Authentication, and Key Management
Part Four: Network Security
Yawai Tint 1.22