0% found this document useful (0 votes)
6 views51 pages

Information System Security Overview

The document outlines the learning outcomes and content of a module on Information System Security, focusing on authentication mechanisms, access control options, and encryption tools. It discusses various methods of authentication, the implementation of access control policies, and the importance of encryption in securing data. Additionally, it covers digital signatures and certificates, emphasizing their role in establishing trust and identity in digital communications.

Uploaded by

janani.22
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views51 pages

Information System Security Overview

The document outlines the learning outcomes and content of a module on Information System Security, focusing on authentication mechanisms, access control options, and encryption tools. It discusses various methods of authentication, the implementation of access control policies, and the importance of encryption in securing data. Additionally, it covers digital signatures and certificates, emphasizing their role in establishing trust and identity in digital communications.

Uploaded by

janani.22
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Information System Security

CMIS 422
The Security Toolbox
Module 2

Karan Sharma

1
Session Learning Outcomes

At the end of this unit you will be able to:


• Survey authentication mechanisms
• List available access control implementation options
• Explain the problems encryption is designed to solve
• Understand the various categories of encryption tools as well as the
strengths, weaknesses, and applications of each
• Learn about certificates and certificate authorities

2
Session Overview
• Authentication mechanisms
• Available access control implementation options
• Various categories of encryption tools
• Strengths, weaknesses, and applications of each encryption
techniques
• Certificates
• Certificate authorities

3
Rules of the Class

1. Use the emoticons to provide feedback to the instructor


2. Raise your hand if you have a question about the class
content or wish to speak
– To talk, click the microphone icon
– Click the icon again to mute it when you are finished speaking
– Always mute your microphone when someone else is speaking
3. Use the chat or Technical support button from the myCourses
Course Home page if you have technical problems – e.g.
cannot see, cannot speak etc.

4
Q What is authentication?

A The act of proving that a user is who she says she is


Methods:
Something the user knows
Something the user is
Something user has

5
Something You Know
• Passwords
• Security questions
• Attacks on “something you know”:
• Dictionary attacks
• Inferring likely passwords/answers
• Guessing
• Defeating concealment
• Exhaustive or brute-force attack
• Rainbow tables

6
Something You Know
• Passwords
• Security questions
• Attacks on “something you know”:
• Dictionary attacks
• Inferring likely passwords/answers
• Guessing
• Defeating concealment
• Exhaustive or brute-force attack
• Rainbow tables

7
Something You Know
• Passwords
• Security questions
• Attacks on “something you know”:
• Dictionary attacks
• Inferring likely passwords/answers
• Guessing
• Defeating concealment
• Exhaustive or brute-force attack
• Rainbow tables

8
Distribution of Password Types

9
Something You Know
• Passwords
• Security questions
• Attacks on “something you know”:
• Dictionary attacks
• Inferring likely passwords/answers
• Guessing
• Defeating concealment
• Exhaustive or brute-force attack
• Rainbow tables

10
Something You Know
• Passwords
• Security questions
• Attacks on “something you know”:
• Dictionary attacks
• Inferring likely passwords/answers
• Guessing
• Defeating concealment
• Exhaustive or brute-force attack
• Rainbow tables

11
Password Storage

Plaintext Concealed

12
Something You Know
• Passwords
• Security questions
• Attacks on “something you know”:
• Dictionary attacks
• Inferring likely passwords/answers
• Guessing
• Defeating concealment
• Exhaustive or brute-force attack
• Rainbow tables

13
Something You Know
• Passwords
• Security questions
• Attacks on “something you know”:
• Dictionary attacks
• Inferring likely passwords/answers
• Guessing
• Defeating concealment
• Exhaustive or brute-force attack
• Rainbow tables

14
Password Storage

15
Something You Know
• Passwords
• Security questions
• Attacks on “something you know”:
• Dictionary attacks
• Inferring likely passwords/answers
• Guessing
• Defeating concealment
• Exhaustive or brute-force attack
• Rainbow tables

16
Access Control

Policy:
Who+What+How = Yes/No

Object
Mode of Access (What)
Subject (How)
(Who)

17
Access Policies
Goals
• Check every access
• Enforce least privilege
• Verify acceptable usage

Track users’ access


Enforce at appropriate granularity
Use audit logging to track accesses

18
Implementing Access Control
• Reference monitor
• Access control directory
• Access control matrix
• Access control list
• Privilege list
• Capability
• Procedure-oriented access control
• Role-based access control

19
Reference Monitor

20
Access Control Directory

21
Access Control Matrix

Objects

File A Printer System Clock

Read
User W Write Write Read
Own
Subjects

Admin Write Control Control

22
Access Control Matrix

23
Access Control List

24
Privilege list

File A Printer System Clock

Read
User W Write Write Read
Own

Admin Write Control Control

25
Capability

• A capability is an unforgeable token that gives the possessor


certain rights to an object.

• Single- or multi-use ticket to access an object or service

26
Role-based access control

• Role-based access control lets us associate privileges with


groups, such as all administrators can have significant
privileges, and others such as regular users or guests to have
lower privileges.

• Administering security is easier if we can control access by job


demands, not by person.

27
Implementing Access Control
• Reference monitor
• Access control directory
• Access control matrix
• Access control list
• Privilege list
• Capability
• Role-based access control

28
Break

29
Symmetric vs. Asymmetric

30
DES: The Data Encryption Standard
• Symmetric block cipher
• Developed in 1976 by IBM for the US National
Institute of Standards and Technology (NIST)

31
AES: Advanced Encryption System

• Symmetric block
cipher
• Developed in 1999
by independent
Dutch
cryptographers
• Still in common use

32
DES vs. AES

33
Discussion

Q How do you share a secret with your friend?

34
Public Key to Exchange Secret Keys

35
Key Exchange Man in the Middle

36
Error Detecting Codes

Demonstrates that a block of data has been modified

Simple error detecting codes:


• Parity checks

Cryptographic error detecting codes:


• One-way hash functions
• Cryptographic checksums
• Digital signatures

37
Parity Check
• The simplest error detection code is a parity check.
• An extra bit, which we call a fingerprint, is added to an existing
group of data bits, depending on their sum.
• The two kinds of parity are called even and odd.
• With even parity the fingerprint is 0 if the sum of the data bits
is even, and 1 if the sum is odd; that is, the parity bit is set so
that the sum of all data bits plus the parity bit is even.
• Odd parity is the same except the overall sum is odd.

38
Parity Check

39
Hash Codes
• In most files, the elements or components of the file are not bound
together in any way.
• That is, each byte or bit or character is independent of every other
one in the file.
• This lack of binding means that changing one value affects the
integrity of the file but that one change can easily go undetected.
• One technique for providing the seal is to compute a function,
sometimes called a hash or checksum or message digest of the file.

40
One-Way Hash Function

41
Digital Signature

The most powerful technique to demonstrate authenticity is a


digital signature.

A digital signature must meet two primary conditions:


• It must be unforgeable. If person S signs message M with signature
Sig(S,M), no one else can produce the pair [M,Sig(S,M)].
• It must be authentic. If a person R receives the pair [M, Sig(S,M)]
supposedly from S, R can check that the signature is really from S.
• Only S could have created this signature, and the signature is firmly attached
to M.

42
Digital Signature

43
Digital Signatures
Digital signatures must meet two requirements and, ideally, satisfy
two more:
• Not alterable (desirable): No signer, receiver, or any interceptor can
modify the signature without the tampering being evident
• Not reusable (desirable): Any attempt to reuse a previous signature will
be detected by receiver
The general way of computing digital signatures is with public key
encryption:
• The signer computes a signature value by using a private key
• Others can use the public key to verify that the signature came from
the corresponding private key
44
Digital Signatures

45
Certificates: Trustable Identities and Public Keys

• A certificate is a public key and an identity bound


together and signed by a certificate authority.

• A certificate authority is an authority that users trust


to accurately verify identities before generating
certificates that bind those identities to keys.

46
Certificate Signing and Hierarchy

47
Certificate Signing and Hierarchy

48
Cryptographic Tool Summary

49
Session Summary
• Users can authenticate using something they know, something
they are, or something they have
• Systems may use a variety of mechanisms to implement access
control
• Encryption helps prevent attackers from revealing, modifying,
or fabricating messages
• Symmetric and asymmetric encryption have complementary
strengths and weaknesses
• Certificates bind identities to digital signatures

50
Information System Security
CMIS 422
The Security Toolbox
Module 2

Karan Sharma

51

You might also like