PCS

Principles of Cyber Security: Symmetric and Asymmetric Encryption

Symmetric Encryption

  • Definition: Symmetric encryption refers to the encryption method where the same key is used for both encryption and decryption.

  • Explanation of Shared Key Usage: Both the sender and recipient share a secret key, which must be kept confidential to prevent unauthorized access.

  • Example: Data Encryption Standard (DES) is a common algorithm that illustrates symmetric encryption.

  • Real-World Application: Netflix utilizes DES in their encryption protocols to protect user data and content.

  • Year of Reference: 2024

Asymmetric Encryption

  • Example: RSA (Rivest-Shamir-Adleman) is a well-known asymmetric encryption method.

  • Key Pairs: It utilizes a pair of keys, a public key (which anyone can access) and a private key (which remains confidential to the owner).

  • Applications in Secure Communications: Asymmetric encryption is widely used in secure communications, including SSL/TLS protocols, to establish secure channels.

  • Year of Reference: 2024

AES Algorithm

  • Definition: Advanced Encryption Standard (AES) is a widely adopted symmetric encryption standard.

  • Block Sizes: AES supports block sizes of 128, 192, or 256 bits.

  • Rounds: The encryption process employs 10, 12, or 14 rounds depending on the key size, wherein each round involves multiple transformations.

  • Substitution-Permutation Network: AES uses a substitution-permutation network to achieve strong encryption efficacy.

  • Real-World Application: Tata Consultancy Services (TCS) uses AES for secure data transmission.

  • Year of Reference: 2025

RSA Encryption

  • Definition: RSA encryption is based on the mathematical concept of prime factorization.

  • Key Exchange Role: It is often used for secure key exchange, particularly for establishing shared keys between parties for further symmetric encryption.

  • Real-World Application: Infosys utilizes RSA for secure communication implementation.

  • Year of Reference: 2024

Hashing Functions

  • Common Hashing Functions: Notable hashing functions include MD5, SHA-1, and SHA-256.

  • Bit Lengths:

    • MD5: 128 bits

    • SHA-1: 160 bits

    • SHA-256: 256 bits

  • Collision Resistance: Each of these functions possesses varying degrees of collision resistance, with SHA-256 being the most secure and least susceptible to collisions.

  • Real-World Application: Wipro implements these hashing functions to verify data integrity and manage digital signatures.

  • Year of Reference: 2024

Digital Signatures

  • Definition: Digital signatures are cryptographic equivalents of handwritten signatures to verify authenticity and integrity.

  • Process:

    • Hashing: The data is hashed.

    • Private Key Signing: The hash is then signed using the signer's private key.

    • Public Key Verification: Recipients can verify the authenticity using the corresponding public key.

  • Real-World Application: Amazon utilizes digital signatures to secure transactions and communications.

  • Year of Reference: 2025

Public Key Infrastructure (PKI)

  • Definition: PKI systems involve a framework for managing digital keys and certificates.

  • Components:

    • Certificate Authorities (CAs): Trusted entities that issue digital certificates.

    • Revocation Lists: Lists used to indicate certificates that are no longer valid.

    • Trust Chains: The hierarchy of trust established through CAs and certificates.

  • Real-World Application: Microsoft integrates PKI in their product offerings to secure users and services.

  • Year of Reference: 2024

Key Exchange Methods

  • Common Methods: Key exchange techniques like Diffie-Hellman and Elliptic Curve Diffie-Hellman (ECDH) allow parties to securely establish a shared secret over an insecure channel.

  • Importance: These methods ensure the exchange of keys in a secure and confidential manner.

  • Real-World Application: Oracle employs these techniques in their secure communications technology.

  • Year of Reference: 2025

Non-Repudiation

  • Definition: Non-repudiation in cryptography ensures that a sender cannot deny the authenticity of their message.

  • Mechanisms: It is facilitated through digital signatures and timestamps.

  • Real-World Application: Google uses non-repudiation strategies to enhance accountability in communications.

  • Year of Reference: 2024

Integrity in Cryptography

  • Definition: Integrity in cryptography refers to the assurance that data has not been altered in unauthorized ways.

  • Techniques: Integrity is maintained using hashing functions and Message Authentication Codes (MACs) to detect changes.

  • Real-World Application: Meta employs integrity checks to maintain data consistency in their systems.

  • Year of Reference: 2024

Cryptographic Goals

  • Main Goals: The primary goals of cryptography include:

    • Confidentiality: Protecting data from unauthorized access.

    • Integrity: Ensuring data remains unaltered.

    • Authentication: Verifying identities of entities involved in communication.

    • Non-repudiation: Preventing denial of actions through reliable evidence.

  • Year of Reference: 2025

Confidentiality in Encryption

  • Definition: Confidentiality ensures that sensitive data is protected from unauthorized access.

  • Methods: This is achieved using various encryption techniques and algorithms, often based on ciphers that obscure data.

  • Real-World Application: Apple emphasizes confidentiality in their data protection policies.

  • Year of Reference: 2024

Common Cryptographic Threats

  • Types of Threats:

    • Side-Channel Attacks: Attacks that exploit physical implementations of a cryptographic system.

    • Key Compromise: The risk of the encryption keys being revealed or stolen.

    • Cryptanalysis Techniques: Various techniques aimed at breaking encryption algorithms.

  • Real-World Application: TCS analyzes these threats constantly to protect their communications.

  • Year of Reference: 2024

Authentication in Cryptography

  • Definition: Authentication validates the identity of users or systems involved in particular communications.

  • Methods: Common authentication approaches include challenge-response protocols and certificate-based verifications.

  • Real-World Application: Infosys implements authentication measures to secure their client transactions.

  • Year of Reference: 2024

OWASP Top 10 Vulnerabilities

  • Definition: A list of ten of the most critical security risks to web applications as outlined by the Open Web Application Security Project (OWASP).

  • Key Risks:

    • Injection: Attacks where an attacker sends untrusted data to the interpreter.

    • Broken Authentication: Issues that allow attackers to compromise user accounts.

  • Real-World Application: Wipro utilizes this framework to guide their security assessments and enhance security posture.

  • Year of Reference: 2024

Symmetric vs Asymmetric Encryption Trade-offs

  • Analysis of Trade-offs:

    • Symmetric encryption is typically faster and more efficient for bulk data encryption.

    • Asymmetric encryption, though slower, provides secure key distribution essential for establishing secure communications.

  • Real-World Application: Netflix assesses these trade-offs when configuring their security measures.

  • Year of Reference: 2024

Evaluation of RSA Algorithm for Key Generation

  • Aspects to Assess:

    • Prime Selection: Importance of selecting sufficiently large and random primes for security.

    • Modulus Computation: The process of calculating the modulus used in keys.

    • Security Against Modern Attacks: The algorithm's resilience against contemporary methods of cryptographic attacks.

  • Real-World Application: Apple reviews these aspects consistently during their security audits.

  • Year of Reference: 2025

Application of Hashing (SHA-256) Integrity in File Transfer

  • Scenario: Utilization of SHA-256 hashing to verify the integrity of data during file transfers.

  • Process:

    • Compute hash on the sender's side before transmission.

    • Compare computed hashes on the receiver's side to detect any alterations in the file.

  • Real-World Application: TCS employs these measures to secure their file transfer processes.

  • Year of Reference: 2024

PKI Components in Certificate Management

  • Analysis of Components:

    • CA Hierarchies: How CAs structure their trust relationships and digital certificates.

    • Certificate Revocation Lists (CRLs): Efforts to maintain up-to-date status reports about valid and invalid certificates.

    • Online Certificate Status Protocol (OCSP): The protocol used to query the current status of a digital certificate in real-time.

  • Real-World Application: Infosys manages PKI components to ensure secure communications and transactions.

  • Year of Reference: 2024

Digital Signatures and Their Effectiveness

Evaluation of Digital Signatures for Non-Repudiation

  • Algorithms: Digital Signature Algorithm (DSA) is an example of an algorithm used for creating secure digital signatures.

  • Legal Validity: Discussion of how digital signatures are recognized in various jurisdictions as legally binding for electronic transactions.

  • Real-World Application: Wipro employs digital signatures for securing contractual obligations.

  • Year of Reference: 2025

Application of Key Exchange (Diffie-Hellman)

  • Scenario: Implementation of Diffie-Hellman in establishing a secure communication line.

  • Illustration: The process involves parameter agreement between both parties, where each party generates a secret key, which is then shared via public channels.

  • Vulnerabilities: Potential weaknesses that can occur, particularly if participants do not ensure the integrity of their key exchange process.

  • Real-World Application: Amazon employs this method in various secure communications.

  • Year of Reference: 2024

Analysis of Cryptography in Secure Protocols (TLS)

  • Examination of TLS: Overview of its vital role in providing security for communications over networks.

  • Components:

    • Handshake Process: Establishing a secure connection through the initial communications.

    • Encryption: Protecting data during transmission via symmetric encryption.

    • Certificate Usage: Validating the server's identity using digital certificates.

  • Real-World Application: Microsoft uses TLS protocols to secure client communications.

  • Year of Reference: 2024

Encryption Strength Against Brute-Force Attacks

  • Factors to Consider:

    • Key Lengths: Longer keys generally provide stronger protection.

    • Computational Resources: The amount of processing power available to potential attackers often dictates the feasibility of breaks.

    • Future-Proofing: Assessing algorithms against anticipated advancements in computational capabilities.

  • Real-World Application: Oracle evaluates encryption methods to defend against potential brute-force attacks.

  • Year of Reference: 2025

Hybrid Encryption Model

  • Definition: A combination of both symmetric and asymmetric encryption mechanisms for enhanced security during data transmission.

  • Explanation: Symmetric methods provide speed and efficiency, while asymmetric techniques ensure safe key exchange.

  • Example: Google illustrates this through their email encryption services.

  • Year of Reference: 2024

Threats to Cryptographic Systems

  • Common Threats:

    • Quantum Computing Risks: The potential for quantum computing to break current encryption methods.

    • Implementation Flaws: Issues like padding oracles can expose weaknesses in cryptographic systems that can be exploited.

  • Real-World Application: Meta actively investigates these threats to develop stronger systems.

  • Year of Reference: 2024

Quantum-Resistant Cryptography Approaches

  • Definition: Cryptographic techniques designed to withstand the computational power of quantum computers.

  • Example: Lattice-based algorithms are being explored as viable post-quantum cryptographic solutions.

  • Real-World Application: Netflix develops plans for transitioning to quantum-resistant systems.

  • Year of Reference: 2025

HTTPS Implementation with Certificates

  • Role of SSL/TLS: Utilizes certificates for establishing secure connections over HTTP for web traffic.

  • Process:

    • Validation: Verifying the authenticity of the certificate issued by a trusted CA.

    • Protection: Against man-in-the-middle (MITM) attacks through encrypted communications.

  • Real-World Application: Apple leverages HTTPS to protect user data in their applications.

  • Year of Reference: 2024

Evaluation of Crypto Failures

  • Common Failures:

    • Weak Keys: Insufficiently strong keys can be easily brute-forced.

    • Improper Random Number Generation: Predictable random numbers can undermine cryptographic security.

  • Prevention Strategies: Importance of utilizing strong key generation techniques and ensuring random numbers are generated from a secure entropy source.

  • Real-World Application: TCS reviews past crypto failures to inform their security standards.

  • Year of Reference: 2024

Application of OWASP Guidelines to Mitigate SQL Injection

  • Approach: Implementing parameterized queries as a defense against SQL injection.

  • Additional Strategies: Utilizing input validation to prevent malicious data from executing harmful SQL commands.

  • Real-World Application: Infosys incorporates these strategies into their development lifecycle to enhance security.

  • Year of Reference: 2024

Case Studies

Designing PKI for Digital Signatures in Banking

  • Objective: Create a systems structure for certificate issuance and revocation in a banking context.

  • Evaluation Against Replay Attacks: Measures to ensure that signatures cannot be reused or exploited by attackers.

  • Real-World Application: Oracle proposes frameworks for advanced PKI implementations.

  • Year of Reference: 2024

Evaluating Hashing Algorithms

  • Comparison: Analyzing SHA-256 against MD5 regarding performance metrics and security features.

  • Key Points:

    • Collision Resistance: SHA-256 is significantly stronger in avoiding collisions than MD5.

    • Speed: MD5 is faster but less secure; SHA-256 is slower but highly recommended.

    • Deprecation Reasons: MD5's known vulnerabilities have led to its reduced use in secure applications.

  • Real-World Application: Google evaluates these hashing functions for enhanced data integrity.

  • Year of Reference: 2025

Creating a Hybrid Encryption Protocol for File Sharing

  • Design: Protocol integrates AES for robust data encryption and RSA for secure key management.

  • Security Analysis: Consideration of potential vulnerabilities and defenses ensuring data integrity and confidentiality.

  • Real-World Application: Meta develops solutions for secure file sharing in their ecosystem.

  • Year of Reference: 2024

Analyzing Quantum Threats to Cryptography

  • Discussion Points:

    • Shor's Algorithm: Impact on RSA and its capabilities to efficiently factor large integers.

    • Migration Considerations: The shift toward post-quantum cryptographic solutions necessitated by advancements in quantum computing.

  • Real-World Application: Netflix continually assesses current cryptographic practices against quantum threats.

  • Year of Reference: 2024

Evaluating Diffie-Hellman in Man-in-the-Middle Attack Scenarios

  • Case Study Analysis: Weaknesses identified in key exchange processes that make it susceptible to MITM attacks.

  • Suggested Enhancements: Implementation of authentication strategies to mitigate these vulnerabilities in future use.

  • Real-World Application: Apple reviews their key exchange protocols against modern attack vectors.

  • Year of Reference: 2025

Mitigation Strategies for OWASP Top 10 in Web Applications

  • Analysis: Concentrating on injection flaws, cross-site scripting (XSS), and misconfigurations.

  • Suggested Practices: Code examples for implementing secure coding practices, input validation, and secure configurations.

  • Real-World Application: TCS develops secure applications reflecting these benchmarks.

  • Year of Reference: 2024

Examining the Codecov CI/CD Supply-Chain Breach

  • Investigation: Analyzing Jenkins pipelines, GitHub Actions workflows, and assessing exposure to vulnerabilities.

  • Impacts: Evaluation of how misconfigured triggers led to exploitation.

  • Real-World Application: Amazon reviews case studies to enhance CI/CD security protocols.

  • Year of Reference: 2022

Analyzing SQL Injection in Login Systems

  • Exploitation Techniques: Explanation of methods attackers might use to exploit SQL injection vulnerabilities during login processes.

  • Secure Practices: Importance of prepared statements and input sanitation to secure input handling in SQL queries.

  • Real-World Application: Infosys implements stringent security measures against SQL injection attacks.

  • Year of Reference: 2025

Malware Types and Vulnerabilities

Types of Malware

  • Common Malware Types:

    • Viruses: Self-replicating programs that attach themselves to clean files and spread to other clean files.

    • Worms: Similar to viruses but spread across networks without needing to attach to a host file.

    • Trojans: Malicious software disguised as legitimate applications.

    • Ransomware: Malware that threatens to publish a victim’s data unless a ransom is paid.

  • Year of Reference: 2024

SQL Injection Attacks

  • Definition: A type of attack that occurs when an attacker uses malicious SQL code to manipulate a database.

  • Mechanism: Malicious input is designed to modify database queries, which can lead to unauthorized access to sensitive data.

  • Prevention: Input sanitization and parameterized queries help mitigate SQL injection risks.

  • Year of Reference: 2025

Cross-Site Scripting (XSS)

  • Definition: A vulnerability allowing attackers to inject malicious scripts into web pages viewed by other users.

  • Impact: The malicious script can capture sensitive information like login credentials or session tokens.

  • Year of Reference: 2024

Cross-Site Request Forgery (CSRF)

  • Definition: An attack that tricks a user into executing unwanted actions on a web application in which they are authenticated.

  • Mechanism: An attacker sends a forged request to the web application on behalf of the victim.

  • Year of Reference: 2024

Indicators of Compromise (IoCs)

  • Definition: Observable events that indicate a breach may have occurred in a system.

  • Common Examples: Unusual traffic patterns, unexpected file changes, or known malicious file hashes.

  • Year of Reference: 2025

Security Information and Event Management (SIEM)

  • Definition: Tools that provide real-time analysis of security alerts generated by hardware and applications.

  • Functions: Log aggregation, correlation of events, and alerting functionalities allow for proactive threat detection.

  • Year of Reference: 2024

Incident Response Lifecycle

  • Phases:

    • Preparation: Establishing response capabilities and developing an incident response plan.

    • Identification: Detecting and analyzing incidents based on established indicators.

    • Containment: Containing the incident to prevent further damage.

    • Eradication: Eliminating the root cause of the incident.

    • Recovery: Restoring affected systems and processes.

    • Lessons Learned: Discussing the incident and improving future response strategies.

  • Year of Reference: 2025

Server-Side Request Forgery (SSRF)

  • Definition: A vulnerability allowing an attacker to send crafted HTTP requests from a vulnerable server.

  • Exploitation: Attackers exploit this to access internal resources (like databases or APIs) from external sources.

  • Year of Reference: 2024

Secure Coding Practices

  • List of Practices:

    • Input Validation: Ensuring data being input meets specifications before processing.

    • Error Handling: Properly managing errors and preventing leakage of sensitive information.

    • Least Privilege Principle: Limiting user access rights based on necessity.

  • Year of Reference: 2024

API Security Measures

  • Security Practices Include:

    • Authentication: Verifying the identity of users or systems accessing an API.

    • Rate Limiting: Control the number of requests a user can make in a given time frame.

    • Input Validation: Sanitary protocols to prevent unwanted data from entering the API.

  • Year of Reference: 2025

Malware Analysis Techniques

  • Definition: The process of dissecting and examining malware to understand its operation and impact.

  • Methods:

    • Static Analysis: Evaluating the code without executing the program to identify potential threats.

    • Dynamic Analysis: Running the malware in a controlled environment (sandbox) to observe its behavior.

  • Year of Reference: 2024

Phases of Incident Response

  • Summary: Similar to the incident response lifecycle, detailing crucial steps in responding to security incidents.

  • Key Focuses: Ensuring efficient coordination and documentation during the phases of incident response.

  • Year of Reference: 2025

OWASP Contribution to Web Security

  • Overview: OWASP provides resources, guides, tools, and a community dedicated to improving web security.

  • Importance: Its guidelines help developers follow best security practices.

  • Year of Reference: 2024

Evaluation of SIEM Tools for Threat Detection

  • Assessment Parameters:

    • Integration: The ability of SIEM tools to work with various data sources.

    • Real-Time Analysis: Capability to analyze incoming data in real-time for quick response.

    • False Positive Reduction: Strategies to limit false positives improving efficiency.

  • Year of Reference: 2025

Applying Incident Response to XSS Attacks

  • Scenario: Responding to a detected XSS attack.

  • Phases Involved:

    • Containment: Immediately isolating affected areas.

    • Eradication: Removing compromised scripts and patches.

    • Preventive Coding Updates: Implementing best practices to prevent similar future occurrences.

  • Year of Reference: 2024

OWASP Top 10 Evaluation

Prioritizing Risks in Web Applications

  • Major Risks Identified:

    • Injection: Including SQL injection as a prevalent vulnerability open to exploitation.

    • Authentication Failures: Addressing the security implications of poorly managed user credentials.

  • Real-World Application: Oracle reviews these risks to strengthen web application security.

  • Year of Reference: 2024

Additional Malware and Cybersecurity Strategies

Case Study: Migration of XSS/CSRF Defense in Social Media Breach

  • Overview: Analysis of exploits during a social media breach and the subsequent implementation of defenses such as Content Security Policies (CSP) and token strategies.

  • Year of Reference: 2024

Creating an Incident Response Plan for API Vulnerabilities

  • Outline includes:

    • Detection protocols for observing anomalous activity related to API requests.

    • Isolation measures to contain affected services.

    • Forensic analyses to understand the breach occurrences and improve future defenses.

    • Communication strategies to inform affected parties.

  • Year of Reference: 2025

Analyzing SSRF Risks in Web Services

  • Exploration of SSRF vulnerabilities and the impact of improper input validation leading to exploitation.

  • Security Fix Proposals: Recommendations including URL validation and network restrictions to mitigate SSRF risks.

  • Year of Reference: 2024

Evaluating OWASP Guidelines for Cloud Web Apps

  • Adaptations: Analysis of OWASP Top 10 security risks tailored for cloud-based architectures.

  • Considerations: Security protocols in serverless architectures and hybrid cloud environments.

  • Year of Reference: 2025

Case Study: Design IAM (Identity and Access Management) for IaaS in AWS

  • Objective: Define IAM policies and roles while reviewing a 2025 misconfiguration incident to derive lessons learned.

  • Year of Reference: 2024

Case Study: Evaluation of the Equifax Data Breach

  • Examination of SQL Injection vulnerabilities that contributed to the breach.

  • Analysis of Observed Indicators of Compromise (IoCs) and delayed incident response reflecting on improvement opportunities.

  • Year of Reference: 2020

Kubernetes Container Security Best Practices

  • Key Strategies:

    • Pod Isolation: Supporting separation of workloads to limit the blast radius.

    • Secrets Management: Secure storage and access control for sensitive credentials.

    • Runtime Scanning: Continuous monitoring of containers for vulnerabilities in active deployment.

  • Year of Reference: 2024