Info Sec Exam 1 Review

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/59

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 7:43 PM on 10/6/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

60 Terms

1
New cards

What is Information security

The protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability.

2
New cards

What are the Three key security concepts

CIA (confidentiality, integrity, availability)

3
New cards

Confidentiality

Assures that confidential information is not disclosed to unauthorized individuals.

4
New cards

Integrity

Assures that information and programs are changed only in a specified and authorized manner. Involves maintaining the consistency, accuracy, and trustworthiness of data.

5
New cards

Availability

Assures that systems work promptly, and service is not denied to authorized users.

6
New cards

Cryptography

the practice of encoding and decoding information so that only the intended recipient can read and process it.

7
New cards

Symmetric Encryption

Encryption and Decryption use the same key

8
New cards

Asymmetric Encryption

Encryption uses a public key, Decryption uses a secret key

9
New cards

Symmetric Encryption components

  • Plaintext

  • Encryption algorithm

  • Secret key

  • Ciphertext

  • Decryption algorithm


10
New cards

Requirements for secure use of symmetric encription

  • Strong encryption algorithm

  • Sender and receiver must obtain copies of the secret key in a secure manor


11
New cards

Cryptanalysis attack

decrypt ciphertext or discover the key while in possession of several ciphertexts with plaintext

12
New cards

Common symmetric encryption algorithms

  • Des

  • Triple Des

  • Aes


13
New cards

Des

Data encryption standard - uses 64-bit plaintext blocks and 56 bit key

14
New cards

Triple-DES

Repeats basic DES algorithm three times using either 2 or 3 unique keys for a key size of 112 or 168 bits

15
New cards

Aes

uses 128-bit data or 128/192/256-bit keys

16
New cards

block cipher

processes plaintext input into fixed-size blocks and produces a block of cipher text

17
New cards

stream cipher

processes the input elements continuously, producing output one element at a time

18
New cards

Brute Force attack

Try all possible keys on some ciphertext until an intelligible translation into plaintext is obtained


19
New cards

ECB

Electronic codebook - The message is divided into fixed-size blocks each block is encrypted separately using the same encryption key.

20
New cards

CBC

Cipher Block Chaining - Each ciphertext block depends on all plaintext blocks processed up to that point To make each message unique, an initialization vector must be used in the first block.

21
New cards

Replay Attack

a form of network attack where an attacker intercepts a valid data transmission and maliciously repeats or delays it.

22
New cards

Message Authentication Code (MAC)

Ensures integrity and authenticity by generating the number with the secret key and message.

23
New cards

Hash Function

accepts a variable-size message M as input and produces a fixed-size message digest as output

24
New cards

Hash Function Properties

  • Applied to any size data

  • H produces fixed-length output

  • H(x) is relatively easy to compute for any given x, making both hardware and software implementations practical.

  • One-way resistant

  • Weak collision resistance

  • Strong collision resistance


25
New cards

Digital signature

Used in Asymmetric encryption/secure hash to verify the integrity of the message. Done by encrypting with private key and the hash of the message, if the other user has the same hash function they can analyze the signature using the senders public key and compare.

26
New cards

RSA

still the only widely accepted public-key encryption algorithm but needs a 1024-bit keys or larger

27
New cards

congruent of modulo n

a - b = k * n

28
New cards

Euler's theorem

a^φ (n) ≡ 1 (mod n)

29
New cards

Euler's totient φ(n)

φ(p) = p − 1 for a prim p

φ(p × q) = (p − 1)(q − 1)

30
New cards

RSA algo key generation

  1. Select 2 primes (p, q where p ≠ q)

  2. Compute the modules (p x q)

  3. Compute totient φ(p × q) = (p − 1)(q − 1)

  4. Choose public exponent e with gcd(φ(n), e) = 1, 1 < e < φ(n)

  5. Compute the private exponent d · e mod φ(n) = 1


31
New cards

RSA public key

KU = {e, n}

32
New cards

RSA Private Key

KR = {d, n}

33
New cards

User Authentication

The process of verifying an identity claimed by or for a system entity.

34
New cards

Steps of user auth.

  1. Identification

  2. Verification


35
New cards

Means of user auth.

knows, possesses, is, does

36
New cards

password authentication

widely used user auth method, users provide a name/login and password and system compares the info for a specified login

37
New cards

Storing Passwords

Store the passwords using a hash you only know and add salt value (a random value)

38
New cards

Multi-Factor Authentication

A method of confirming users' claimed identities by using a combination of two or more different factors

39
New cards

Client Attacks

Adversary attempts to achieve user authentication without access to the remote host or the intervening communications path

40
New cards

Host Attacks

Directed at the user file at the host where passwords, token passcodes, or biometric templates are stored

41
New cards

Eavesdropping, theft, copying

Adversary attempts to learn the password by some sort of attack that involves the physical proximity of user and adversary

42
New cards

Trojan Horse

An application or physical device masquerades as an authentic application or device for the purpose of capturing a user password

43
New cards

Denial of service

attacker attempts to disable a user authentication service

44
New cards

Access control

Constrains what a user can do directly, as well as what programs executing on behalf of the users are allowed to do

45
New cards

What are the goals of access control

  • Prevent activity that could lead to breach of security

  • Protect against accidental and malicious threats by regulating the reading, writing, and execution of data and programs


46
New cards

Access control elements - subject

Owner, Group, World/others

47
New cards

Access control elements - access rights

read, write, execute, delete, create, search, copy, print, modify, add, etc.

48
New cards

Discretionary Access Control (DAC)

• User-oriented security policy (based on identity of requestor)

• Entity has rights to enable another entity to access a resource

49
New cards

Mandatory Access Control (MAC)

• Access permissions are defined by a system itself

• Based on comparing security labels of system resources (e.g., top security, low security) with security clearances of entities accessing the resources

• Cleared entity cannot pass on access rights to another entity

50
New cards
<p>Role-Based Access Control (RBAC)</p>

Role-Based Access Control (RBAC)

Based on roles that users have within system and on rules stating what accesses are allowed to users in given roles

51
New cards

Attribute-Based Access Control (ABAC)

Controls access based on attributes of the user, the resource to be accessed, and current environmental conditions

52
New cards

Access Control Principles

  • least privilege

  • separation of duty

  • fail-safe defaults


53
New cards
<p>Access Control Lists (ACL)</p>

Access Control Lists (ACL)

Access rights are stored with objects, requires the subjects to be authenticated before access to a particular object.

54
New cards
<p>Capability Lists</p>

Capability Lists

Linked list of each row of access control matrix is stored with the correspondent subject

55
New cards
<p>Authorization Table</p>

Authorization Table

Tables contain one row for one access right of one subject to one resource

56
New cards
<p>UNIX File Access Control</p>

UNIX File Access Control

administered using inodes (index nodes)

an active inode is associated with exactly one file

57
New cards

MAC Bell-LaPadula model

No read up, No write down

58
New cards

ABAC Elements

Attributes, Policy model, Architecture model

59
New cards

ABAC Pros

• Dynamic and fine-grained access control

• Scalable

• Consider environmental conditions

• Can be mapped to MAC, DAC and RBAC models

• Easy administration

60
New cards

ABAC Cons

• Attribute needs provisioning and maintenance

• Possibility of attribute explosion

• Complex to analyze