Information System Security
CMIS 422
The Security Toolbox
Module 2
Karan Sharma
1
Session Learning Outcomes
At the end of this unit you will be able to:
• Survey authentication mechanisms
• List available access control implementation options
• Explain the problems encryption is designed to solve
• Understand the various categories of encryption tools as well as the
strengths, weaknesses, and applications of each
• Learn about certificates and certificate authorities
2
Session Overview
• Authentication mechanisms
• Available access control implementation options
• Various categories of encryption tools
• Strengths, weaknesses, and applications of each encryption
techniques
• Certificates
• Certificate authorities
3
Rules of the Class
1. Use the emoticons to provide feedback to the instructor
2. Raise your hand if you have a question about the class
content or wish to speak
– To talk, click the microphone icon
– Click the icon again to mute it when you are finished speaking
– Always mute your microphone when someone else is speaking
3. Use the chat or Technical support button from the myCourses
Course Home page if you have technical problems – e.g.
cannot see, cannot speak etc.
4
Q What is authentication?
A The act of proving that a user is who she says she is
Methods:
Something the user knows
Something the user is
Something user has
5
Something You Know
• Passwords
• Security questions
• Attacks on “something you know”:
• Dictionary attacks
• Inferring likely passwords/answers
• Guessing
• Defeating concealment
• Exhaustive or brute-force attack
• Rainbow tables
6
Something You Know
• Passwords
• Security questions
• Attacks on “something you know”:
• Dictionary attacks
• Inferring likely passwords/answers
• Guessing
• Defeating concealment
• Exhaustive or brute-force attack
• Rainbow tables
7
Something You Know
• Passwords
• Security questions
• Attacks on “something you know”:
• Dictionary attacks
• Inferring likely passwords/answers
• Guessing
• Defeating concealment
• Exhaustive or brute-force attack
• Rainbow tables
8
Distribution of Password Types
9
Something You Know
• Passwords
• Security questions
• Attacks on “something you know”:
• Dictionary attacks
• Inferring likely passwords/answers
• Guessing
• Defeating concealment
• Exhaustive or brute-force attack
• Rainbow tables
10
Something You Know
• Passwords
• Security questions
• Attacks on “something you know”:
• Dictionary attacks
• Inferring likely passwords/answers
• Guessing
• Defeating concealment
• Exhaustive or brute-force attack
• Rainbow tables
11
Password Storage
Plaintext Concealed
12
Something You Know
• Passwords
• Security questions
• Attacks on “something you know”:
• Dictionary attacks
• Inferring likely passwords/answers
• Guessing
• Defeating concealment
• Exhaustive or brute-force attack
• Rainbow tables
13
Something You Know
• Passwords
• Security questions
• Attacks on “something you know”:
• Dictionary attacks
• Inferring likely passwords/answers
• Guessing
• Defeating concealment
• Exhaustive or brute-force attack
• Rainbow tables
14
Password Storage
15
Something You Know
• Passwords
• Security questions
• Attacks on “something you know”:
• Dictionary attacks
• Inferring likely passwords/answers
• Guessing
• Defeating concealment
• Exhaustive or brute-force attack
• Rainbow tables
16
Access Control
Policy:
Who+What+How = Yes/No
Object
Mode of Access (What)
Subject (How)
(Who)
17
Access Policies
Goals
• Check every access
• Enforce least privilege
• Verify acceptable usage
Track users’ access
Enforce at appropriate granularity
Use audit logging to track accesses
18
Implementing Access Control
• Reference monitor
• Access control directory
• Access control matrix
• Access control list
• Privilege list
• Capability
• Procedure-oriented access control
• Role-based access control
19
Reference Monitor
20
Access Control Directory
21
Access Control Matrix
Objects
File A Printer System Clock
Read
User W Write Write Read
Own
Subjects
Admin Write Control Control
22
Access Control Matrix
23
Access Control List
24
Privilege list
File A Printer System Clock
Read
User W Write Write Read
Own
Admin Write Control Control
25
Capability
• A capability is an unforgeable token that gives the possessor
certain rights to an object.
• Single- or multi-use ticket to access an object or service
26
Role-based access control
• Role-based access control lets us associate privileges with
groups, such as all administrators can have significant
privileges, and others such as regular users or guests to have
lower privileges.
• Administering security is easier if we can control access by job
demands, not by person.
27
Implementing Access Control
• Reference monitor
• Access control directory
• Access control matrix
• Access control list
• Privilege list
• Capability
• Role-based access control
28
Break
29
Symmetric vs. Asymmetric
30
DES: The Data Encryption Standard
• Symmetric block cipher
• Developed in 1976 by IBM for the US National
Institute of Standards and Technology (NIST)
31
AES: Advanced Encryption System
• Symmetric block
cipher
• Developed in 1999
by independent
Dutch
cryptographers
• Still in common use
32
DES vs. AES
33
Discussion
Q How do you share a secret with your friend?
34
Public Key to Exchange Secret Keys
35
Key Exchange Man in the Middle
36
Error Detecting Codes
Demonstrates that a block of data has been modified
Simple error detecting codes:
• Parity checks
Cryptographic error detecting codes:
• One-way hash functions
• Cryptographic checksums
• Digital signatures
37
Parity Check
• The simplest error detection code is a parity check.
• An extra bit, which we call a fingerprint, is added to an existing
group of data bits, depending on their sum.
• The two kinds of parity are called even and odd.
• With even parity the fingerprint is 0 if the sum of the data bits
is even, and 1 if the sum is odd; that is, the parity bit is set so
that the sum of all data bits plus the parity bit is even.
• Odd parity is the same except the overall sum is odd.
38
Parity Check
39
Hash Codes
• In most files, the elements or components of the file are not bound
together in any way.
• That is, each byte or bit or character is independent of every other
one in the file.
• This lack of binding means that changing one value affects the
integrity of the file but that one change can easily go undetected.
• One technique for providing the seal is to compute a function,
sometimes called a hash or checksum or message digest of the file.
40
One-Way Hash Function
41
Digital Signature
The most powerful technique to demonstrate authenticity is a
digital signature.
A digital signature must meet two primary conditions:
• It must be unforgeable. If person S signs message M with signature
Sig(S,M), no one else can produce the pair [M,Sig(S,M)].
• It must be authentic. If a person R receives the pair [M, Sig(S,M)]
supposedly from S, R can check that the signature is really from S.
• Only S could have created this signature, and the signature is firmly attached
to M.
42
Digital Signature
43
Digital Signatures
Digital signatures must meet two requirements and, ideally, satisfy
two more:
• Not alterable (desirable): No signer, receiver, or any interceptor can
modify the signature without the tampering being evident
• Not reusable (desirable): Any attempt to reuse a previous signature will
be detected by receiver
The general way of computing digital signatures is with public key
encryption:
• The signer computes a signature value by using a private key
• Others can use the public key to verify that the signature came from
the corresponding private key
44
Digital Signatures
45
Certificates: Trustable Identities and Public Keys
• A certificate is a public key and an identity bound
together and signed by a certificate authority.
• A certificate authority is an authority that users trust
to accurately verify identities before generating
certificates that bind those identities to keys.
46
Certificate Signing and Hierarchy
47
Certificate Signing and Hierarchy
48
Cryptographic Tool Summary
49
Session Summary
• Users can authenticate using something they know, something
they are, or something they have
• Systems may use a variety of mechanisms to implement access
control
• Encryption helps prevent attackers from revealing, modifying,
or fabricating messages
• Symmetric and asymmetric encryption have complementary
strengths and weaknesses
• Certificates bind identities to digital signatures
50
Information System Security
CMIS 422
The Security Toolbox
Module 2
Karan Sharma
51