1/23
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Why would we want to use IP Security ? (Regarding IEEE 802.11i)
Previously, we discussed of security between hosts directly connected (over a wireless network), but many security concerns are shared across layers
Give examples of security concerns shared across layers.
Disallowing links to untrusted sites
Authenticating all incoming traffic from a site
Encrypting all outgoing traffic from a site
What can provide IPSec ?
IPSec can provide application-independent and technology-independent security services such as Authentication, Confidentiality and Key management
What are the different applications of IPSec ?
Secure branch connectivity over the Internet
Secure Remote Access over the Internet
Secure Communication Channels across Organizations
Additional Layer of Security to app-layer security
What are IPSEC documents ?
Authentication Header : IP message authentication but is today replaced by ESP
Encapsulating Security Payload : combined encryption and authentication of IP packets
Internet Key Exchange : defines key management schemes for IPsec
Cryptographic algorithms : recommended cipher suites
What are the IPSec services ?
Access control
Connection-less integrity
Data origin authentication
Rejection of replayed packets
Confidentiality
Limited traffic flow confidentiality
What services do ESP protocol provide ?
Connection-less Integrity
Data Origin Authentication
Anti-replay service
Confidentiality
Traffic Flow Confidentiality
What do ESP packets contain ?
Payload Data
Next Header
Padding
Integrity Check Value which provides integrity
IV value
What does IKE add comparing to DH ?
It uses cookies to counter clogging attacks
It enables the two parties to negotiate a modular group specifying the global parameters of the DH key exchange
It uses nonces to protect against replay attacks
It enables the exchange of DH public key values
It authenticates the DH exchange to counter MiTM attacks
What are SAs in IPSec ?
Security Associations are one-way logical connections between a sender and a receiver and it defines the parameters of security services to be used for protecting traffic
How are SAs uniquely identified ?
Security Parameters Index : to identify the related security parameters at the receiver of the packet
IP Destination Address : IP of the destination end point
Security Protocol Identifier : specify whether it is AH or ESP
What is the Transport Mode ?
Only traffic from transport-layer is encrypted and authenticated so traffic analysis is possible
What is the Tunnel Mode ?
Packets from IP-layer are entirely encrypted (both header and payload) and authenticated so no routers on the path can see the original IP header
Why is Tunnel Mode preferable to Transport Mode when configuring a VPN tunnel between two gateways?
Tunnel Mode is preferable because it protects the entire original IP packet
What are the main functions of the Security Policy Database (SPD) ?
SPD defines what to do on the traffic based on criteria like IP addresses and ports. It decides if traffic should be Bypassed (no protection), Discarded or Protected (IPSec) and map it to a particular SA
What are the main functions of the Security Association Database (SAD) ?
It is a database defining the parameters associated with each SA used to process the packets that the SPD has decided to protect
Explain how the anti-replay mechanism in ESP works. What does the receiver do when it receives a duplicate or old packet?
This mechanism is based on last valid received Sequence Number and we advance the window if a valid packet is received
If a packet’s sequence number goes out of the sliding window or if it matches a bit already marked as received within the window then the packet is dropped
What is the main difference in protection offered by AH and ESP?
Both AH and ESP provide data integrity, authentication and anti-replay but only ESP provides confidentiality through encryption
True or False: In Transport Mode, the IP header is encrypted. Justify your answer.
False : in Transport Mode only the IP payload is encrypted so routers can read the IP header to deliver the packet
Which of the following is not a service provided by IPSec ESP? (A. Confidentiality, B. Authentication, C. Replay protection, D. Traffic routing)
D. Traffic routing
What role does the PRF play in key derivation in IPSec?
In IPSec, the Pseudo Random Function is a cryptographic tool that generates key materials and authentication hashes from a single shared secret
What are the advantages of implementing security at the network layer compared to the application or transport layer ?
It is application-independent so applications do not need to be reconfigured to be secure
Security policies can be enforced for all host traffic at a single choke point
Key Management in IPSec ?
4 keys are required : transmit and receive pairs. Two types of key management defined in IPSec :
Manual : manual configuration of the keys by system administrator
Automatic : on-demand creation of keys via an automated system. Today, standard is Internet Key Exchange protocol based on DH
What are the disadvantages of implementing security at the network layer compared to the application or transport layer ?
It lacks context about users and applications (uses only addresses and ports)
Encapsulating and encrypting every network packet can cause significant latency