1/59
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is Information security
The protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability.
What are the Three key security concepts
CIA (confidentiality, integrity, availability)
Confidentiality
Assures that confidential information is not disclosed to unauthorized individuals.
Integrity
Assures that information and programs are changed only in a specified and authorized manner. Involves maintaining the consistency, accuracy, and trustworthiness of data.
Availability
Assures that systems work promptly, and service is not denied to authorized users.
Cryptography
the practice of encoding and decoding information so that only the intended recipient can read and process it.
Symmetric Encryption
Encryption and Decryption use the same key
Asymmetric Encryption
Encryption uses a public key, Decryption uses a secret key
Symmetric Encryption components
Plaintext
Encryption algorithm
Secret key
Ciphertext
Decryption algorithm
Requirements for secure use of symmetric encription
Strong encryption algorithm
Sender and receiver must obtain copies of the secret key in a secure manor
Cryptanalysis attack
decrypt ciphertext or discover the key while in possession of several ciphertexts with plaintext
Common symmetric encryption algorithms
Des
Triple Des
Aes
Des
Data encryption standard - uses 64-bit plaintext blocks and 56 bit key
Triple-DES
Repeats basic DES algorithm three times using either 2 or 3 unique keys for a key size of 112 or 168 bits
Aes
uses 128-bit data or 128/192/256-bit keys
block cipher
processes plaintext input into fixed-size blocks and produces a block of cipher text
stream cipher
processes the input elements continuously, producing output one element at a time
Brute Force attack
Try all possible keys on some ciphertext until an intelligible translation into plaintext is obtained
ECB
Electronic codebook - The message is divided into fixed-size blocks each block is encrypted separately using the same encryption key.
CBC
Cipher Block Chaining - Each ciphertext block depends on all plaintext blocks processed up to that point To make each message unique, an initialization vector must be used in the first block.
Replay Attack
a form of network attack where an attacker intercepts a valid data transmission and maliciously repeats or delays it.
Message Authentication Code (MAC)
Ensures integrity and authenticity by generating the number with the secret key and message.
Hash Function
accepts a variable-size message M as input and produces a fixed-size message digest as output
Hash Function Properties
Applied to any size data
H produces fixed-length output
H(x) is relatively easy to compute for any given x, making both hardware and software implementations practical.
One-way resistant
Weak collision resistance
Strong collision resistance
Digital signature
Used in Asymmetric encryption/secure hash to verify the integrity of the message. Done by encrypting with private key and the hash of the message, if the other user has the same hash function they can analyze the signature using the senders public key and compare.
RSA
still the only widely accepted public-key encryption algorithm but needs a 1024-bit keys or larger
congruent of modulo n
a - b = k * n
Euler's theorem
a^φ (n) ≡ 1 (mod n)
Euler's totient φ(n)
φ(p) = p − 1 for a prim p
φ(p × q) = (p − 1)(q − 1)
RSA algo key generation
Select 2 primes (p, q where p ≠ q)
Compute the modules (p x q)
Compute totient φ(p × q) = (p − 1)(q − 1)
Choose public exponent e with gcd(φ(n), e) = 1, 1 < e < φ(n)
Compute the private exponent d · e mod φ(n) = 1
RSA public key
KU = {e, n}
RSA Private Key
KR = {d, n}
User Authentication
The process of verifying an identity claimed by or for a system entity.
Steps of user auth.
Identification
Verification
Means of user auth.
knows, possesses, is, does
password authentication
widely used user auth method, users provide a name/login and password and system compares the info for a specified login
Storing Passwords
Store the passwords using a hash you only know and add salt value (a random value)
Multi-Factor Authentication
A method of confirming users' claimed identities by using a combination of two or more different factors
Client Attacks
Adversary attempts to achieve user authentication without access to the remote host or the intervening communications path
Host Attacks
Directed at the user file at the host where passwords, token passcodes, or biometric templates are stored
Eavesdropping, theft, copying
Adversary attempts to learn the password by some sort of attack that involves the physical proximity of user and adversary
Trojan Horse
An application or physical device masquerades as an authentic application or device for the purpose of capturing a user password
Denial of service
attacker attempts to disable a user authentication service
Access control
Constrains what a user can do directly, as well as what programs executing on behalf of the users are allowed to do
What are the goals of access control
Prevent activity that could lead to breach of security
Protect against accidental and malicious threats by regulating the reading, writing, and execution of data and programs
Access control elements - subject
Owner, Group, World/others
Access control elements - access rights
read, write, execute, delete, create, search, copy, print, modify, add, etc.
Discretionary Access Control (DAC)
• User-oriented security policy (based on identity of requestor)
• Entity has rights to enable another entity to access a resource
Mandatory Access Control (MAC)
• Access permissions are defined by a system itself
• Based on comparing security labels of system resources (e.g., top security, low security) with security clearances of entities accessing the resources
• Cleared entity cannot pass on access rights to another entity

Role-Based Access Control (RBAC)
Based on roles that users have within system and on rules stating what accesses are allowed to users in given roles
Attribute-Based Access Control (ABAC)
Controls access based on attributes of the user, the resource to be accessed, and current environmental conditions
Access Control Principles
least privilege
separation of duty
fail-safe defaults

Access Control Lists (ACL)
Access rights are stored with objects, requires the subjects to be authenticated before access to a particular object.

Capability Lists
Linked list of each row of access control matrix is stored with the correspondent subject

Authorization Table
Tables contain one row for one access right of one subject to one resource

UNIX File Access Control
administered using inodes (index nodes)
an active inode is associated with exactly one file
MAC Bell-LaPadula model
No read up, No write down
ABAC Elements
Attributes, Policy model, Architecture model
ABAC Pros
• Dynamic and fine-grained access control
• Scalable
• Consider environmental conditions
• Can be mapped to MAC, DAC and RBAC models
• Easy administration
ABAC Cons
• Attribute needs provisioning and maintenance
• Possibility of attribute explosion
• Complex to analyze