PCS
Principles of Cyber Security: Symmetric and Asymmetric Encryption
Symmetric Encryption
Definition: Symmetric encryption refers to the encryption method where the same key is used for both encryption and decryption.
Explanation of Shared Key Usage: Both the sender and recipient share a secret key, which must be kept confidential to prevent unauthorized access.
Example: Data Encryption Standard (DES) is a common algorithm that illustrates symmetric encryption.
Real-World Application: Netflix utilizes DES in their encryption protocols to protect user data and content.
Year of Reference: 2024
Asymmetric Encryption
Example: RSA (Rivest-Shamir-Adleman) is a well-known asymmetric encryption method.
Key Pairs: It utilizes a pair of keys, a public key (which anyone can access) and a private key (which remains confidential to the owner).
Applications in Secure Communications: Asymmetric encryption is widely used in secure communications, including SSL/TLS protocols, to establish secure channels.
Year of Reference: 2024
AES Algorithm
Definition: Advanced Encryption Standard (AES) is a widely adopted symmetric encryption standard.
Block Sizes: AES supports block sizes of 128, 192, or 256 bits.
Rounds: The encryption process employs 10, 12, or 14 rounds depending on the key size, wherein each round involves multiple transformations.
Substitution-Permutation Network: AES uses a substitution-permutation network to achieve strong encryption efficacy.
Real-World Application: Tata Consultancy Services (TCS) uses AES for secure data transmission.
Year of Reference: 2025
RSA Encryption
Definition: RSA encryption is based on the mathematical concept of prime factorization.
Key Exchange Role: It is often used for secure key exchange, particularly for establishing shared keys between parties for further symmetric encryption.
Real-World Application: Infosys utilizes RSA for secure communication implementation.
Year of Reference: 2024
Hashing Functions
Common Hashing Functions: Notable hashing functions include MD5, SHA-1, and SHA-256.
Bit Lengths:
MD5: 128 bits
SHA-1: 160 bits
SHA-256: 256 bits
Collision Resistance: Each of these functions possesses varying degrees of collision resistance, with SHA-256 being the most secure and least susceptible to collisions.
Real-World Application: Wipro implements these hashing functions to verify data integrity and manage digital signatures.
Year of Reference: 2024
Digital Signatures
Definition: Digital signatures are cryptographic equivalents of handwritten signatures to verify authenticity and integrity.
Process:
Hashing: The data is hashed.
Private Key Signing: The hash is then signed using the signer's private key.
Public Key Verification: Recipients can verify the authenticity using the corresponding public key.
Real-World Application: Amazon utilizes digital signatures to secure transactions and communications.
Year of Reference: 2025
Public Key Infrastructure (PKI)
Definition: PKI systems involve a framework for managing digital keys and certificates.
Components:
Certificate Authorities (CAs): Trusted entities that issue digital certificates.
Revocation Lists: Lists used to indicate certificates that are no longer valid.
Trust Chains: The hierarchy of trust established through CAs and certificates.
Real-World Application: Microsoft integrates PKI in their product offerings to secure users and services.
Year of Reference: 2024
Key Exchange Methods
Common Methods: Key exchange techniques like Diffie-Hellman and Elliptic Curve Diffie-Hellman (ECDH) allow parties to securely establish a shared secret over an insecure channel.
Importance: These methods ensure the exchange of keys in a secure and confidential manner.
Real-World Application: Oracle employs these techniques in their secure communications technology.
Year of Reference: 2025
Non-Repudiation
Definition: Non-repudiation in cryptography ensures that a sender cannot deny the authenticity of their message.
Mechanisms: It is facilitated through digital signatures and timestamps.
Real-World Application: Google uses non-repudiation strategies to enhance accountability in communications.
Year of Reference: 2024
Integrity in Cryptography
Definition: Integrity in cryptography refers to the assurance that data has not been altered in unauthorized ways.
Techniques: Integrity is maintained using hashing functions and Message Authentication Codes (MACs) to detect changes.
Real-World Application: Meta employs integrity checks to maintain data consistency in their systems.
Year of Reference: 2024
Cryptographic Goals
Main Goals: The primary goals of cryptography include:
Confidentiality: Protecting data from unauthorized access.
Integrity: Ensuring data remains unaltered.
Authentication: Verifying identities of entities involved in communication.
Non-repudiation: Preventing denial of actions through reliable evidence.
Year of Reference: 2025
Confidentiality in Encryption
Definition: Confidentiality ensures that sensitive data is protected from unauthorized access.
Methods: This is achieved using various encryption techniques and algorithms, often based on ciphers that obscure data.
Real-World Application: Apple emphasizes confidentiality in their data protection policies.
Year of Reference: 2024
Common Cryptographic Threats
Types of Threats:
Side-Channel Attacks: Attacks that exploit physical implementations of a cryptographic system.
Key Compromise: The risk of the encryption keys being revealed or stolen.
Cryptanalysis Techniques: Various techniques aimed at breaking encryption algorithms.
Real-World Application: TCS analyzes these threats constantly to protect their communications.
Year of Reference: 2024
Authentication in Cryptography
Definition: Authentication validates the identity of users or systems involved in particular communications.
Methods: Common authentication approaches include challenge-response protocols and certificate-based verifications.
Real-World Application: Infosys implements authentication measures to secure their client transactions.
Year of Reference: 2024
OWASP Top 10 Vulnerabilities
Definition: A list of ten of the most critical security risks to web applications as outlined by the Open Web Application Security Project (OWASP).
Key Risks:
Injection: Attacks where an attacker sends untrusted data to the interpreter.
Broken Authentication: Issues that allow attackers to compromise user accounts.
Real-World Application: Wipro utilizes this framework to guide their security assessments and enhance security posture.
Year of Reference: 2024
Symmetric vs Asymmetric Encryption Trade-offs
Analysis of Trade-offs:
Symmetric encryption is typically faster and more efficient for bulk data encryption.
Asymmetric encryption, though slower, provides secure key distribution essential for establishing secure communications.
Real-World Application: Netflix assesses these trade-offs when configuring their security measures.
Year of Reference: 2024
Evaluation of RSA Algorithm for Key Generation
Aspects to Assess:
Prime Selection: Importance of selecting sufficiently large and random primes for security.
Modulus Computation: The process of calculating the modulus used in keys.
Security Against Modern Attacks: The algorithm's resilience against contemporary methods of cryptographic attacks.
Real-World Application: Apple reviews these aspects consistently during their security audits.
Year of Reference: 2025
Application of Hashing (SHA-256) Integrity in File Transfer
Scenario: Utilization of SHA-256 hashing to verify the integrity of data during file transfers.
Process:
Compute hash on the sender's side before transmission.
Compare computed hashes on the receiver's side to detect any alterations in the file.
Real-World Application: TCS employs these measures to secure their file transfer processes.
Year of Reference: 2024
PKI Components in Certificate Management
Analysis of Components:
CA Hierarchies: How CAs structure their trust relationships and digital certificates.
Certificate Revocation Lists (CRLs): Efforts to maintain up-to-date status reports about valid and invalid certificates.
Online Certificate Status Protocol (OCSP): The protocol used to query the current status of a digital certificate in real-time.
Real-World Application: Infosys manages PKI components to ensure secure communications and transactions.
Year of Reference: 2024
Digital Signatures and Their Effectiveness
Evaluation of Digital Signatures for Non-Repudiation
Algorithms: Digital Signature Algorithm (DSA) is an example of an algorithm used for creating secure digital signatures.
Legal Validity: Discussion of how digital signatures are recognized in various jurisdictions as legally binding for electronic transactions.
Real-World Application: Wipro employs digital signatures for securing contractual obligations.
Year of Reference: 2025
Application of Key Exchange (Diffie-Hellman)
Scenario: Implementation of Diffie-Hellman in establishing a secure communication line.
Illustration: The process involves parameter agreement between both parties, where each party generates a secret key, which is then shared via public channels.
Vulnerabilities: Potential weaknesses that can occur, particularly if participants do not ensure the integrity of their key exchange process.
Real-World Application: Amazon employs this method in various secure communications.
Year of Reference: 2024
Analysis of Cryptography in Secure Protocols (TLS)
Examination of TLS: Overview of its vital role in providing security for communications over networks.
Components:
Handshake Process: Establishing a secure connection through the initial communications.
Encryption: Protecting data during transmission via symmetric encryption.
Certificate Usage: Validating the server's identity using digital certificates.
Real-World Application: Microsoft uses TLS protocols to secure client communications.
Year of Reference: 2024
Encryption Strength Against Brute-Force Attacks
Factors to Consider:
Key Lengths: Longer keys generally provide stronger protection.
Computational Resources: The amount of processing power available to potential attackers often dictates the feasibility of breaks.
Future-Proofing: Assessing algorithms against anticipated advancements in computational capabilities.
Real-World Application: Oracle evaluates encryption methods to defend against potential brute-force attacks.
Year of Reference: 2025
Hybrid Encryption Model
Definition: A combination of both symmetric and asymmetric encryption mechanisms for enhanced security during data transmission.
Explanation: Symmetric methods provide speed and efficiency, while asymmetric techniques ensure safe key exchange.
Example: Google illustrates this through their email encryption services.
Year of Reference: 2024
Threats to Cryptographic Systems
Common Threats:
Quantum Computing Risks: The potential for quantum computing to break current encryption methods.
Implementation Flaws: Issues like padding oracles can expose weaknesses in cryptographic systems that can be exploited.
Real-World Application: Meta actively investigates these threats to develop stronger systems.
Year of Reference: 2024
Quantum-Resistant Cryptography Approaches
Definition: Cryptographic techniques designed to withstand the computational power of quantum computers.
Example: Lattice-based algorithms are being explored as viable post-quantum cryptographic solutions.
Real-World Application: Netflix develops plans for transitioning to quantum-resistant systems.
Year of Reference: 2025
HTTPS Implementation with Certificates
Role of SSL/TLS: Utilizes certificates for establishing secure connections over HTTP for web traffic.
Process:
Validation: Verifying the authenticity of the certificate issued by a trusted CA.
Protection: Against man-in-the-middle (MITM) attacks through encrypted communications.
Real-World Application: Apple leverages HTTPS to protect user data in their applications.
Year of Reference: 2024
Evaluation of Crypto Failures
Common Failures:
Weak Keys: Insufficiently strong keys can be easily brute-forced.
Improper Random Number Generation: Predictable random numbers can undermine cryptographic security.
Prevention Strategies: Importance of utilizing strong key generation techniques and ensuring random numbers are generated from a secure entropy source.
Real-World Application: TCS reviews past crypto failures to inform their security standards.
Year of Reference: 2024
Application of OWASP Guidelines to Mitigate SQL Injection
Approach: Implementing parameterized queries as a defense against SQL injection.
Additional Strategies: Utilizing input validation to prevent malicious data from executing harmful SQL commands.
Real-World Application: Infosys incorporates these strategies into their development lifecycle to enhance security.
Year of Reference: 2024
Case Studies
Designing PKI for Digital Signatures in Banking
Objective: Create a systems structure for certificate issuance and revocation in a banking context.
Evaluation Against Replay Attacks: Measures to ensure that signatures cannot be reused or exploited by attackers.
Real-World Application: Oracle proposes frameworks for advanced PKI implementations.
Year of Reference: 2024
Evaluating Hashing Algorithms
Comparison: Analyzing SHA-256 against MD5 regarding performance metrics and security features.
Key Points:
Collision Resistance: SHA-256 is significantly stronger in avoiding collisions than MD5.
Speed: MD5 is faster but less secure; SHA-256 is slower but highly recommended.
Deprecation Reasons: MD5's known vulnerabilities have led to its reduced use in secure applications.
Real-World Application: Google evaluates these hashing functions for enhanced data integrity.
Year of Reference: 2025
Creating a Hybrid Encryption Protocol for File Sharing
Design: Protocol integrates AES for robust data encryption and RSA for secure key management.
Security Analysis: Consideration of potential vulnerabilities and defenses ensuring data integrity and confidentiality.
Real-World Application: Meta develops solutions for secure file sharing in their ecosystem.
Year of Reference: 2024
Analyzing Quantum Threats to Cryptography
Discussion Points:
Shor's Algorithm: Impact on RSA and its capabilities to efficiently factor large integers.
Migration Considerations: The shift toward post-quantum cryptographic solutions necessitated by advancements in quantum computing.
Real-World Application: Netflix continually assesses current cryptographic practices against quantum threats.
Year of Reference: 2024
Evaluating Diffie-Hellman in Man-in-the-Middle Attack Scenarios
Case Study Analysis: Weaknesses identified in key exchange processes that make it susceptible to MITM attacks.
Suggested Enhancements: Implementation of authentication strategies to mitigate these vulnerabilities in future use.
Real-World Application: Apple reviews their key exchange protocols against modern attack vectors.
Year of Reference: 2025
Mitigation Strategies for OWASP Top 10 in Web Applications
Analysis: Concentrating on injection flaws, cross-site scripting (XSS), and misconfigurations.
Suggested Practices: Code examples for implementing secure coding practices, input validation, and secure configurations.
Real-World Application: TCS develops secure applications reflecting these benchmarks.
Year of Reference: 2024
Examining the Codecov CI/CD Supply-Chain Breach
Investigation: Analyzing Jenkins pipelines, GitHub Actions workflows, and assessing exposure to vulnerabilities.
Impacts: Evaluation of how misconfigured triggers led to exploitation.
Real-World Application: Amazon reviews case studies to enhance CI/CD security protocols.
Year of Reference: 2022
Analyzing SQL Injection in Login Systems
Exploitation Techniques: Explanation of methods attackers might use to exploit SQL injection vulnerabilities during login processes.
Secure Practices: Importance of prepared statements and input sanitation to secure input handling in SQL queries.
Real-World Application: Infosys implements stringent security measures against SQL injection attacks.
Year of Reference: 2025
Malware Types and Vulnerabilities
Types of Malware
Common Malware Types:
Viruses: Self-replicating programs that attach themselves to clean files and spread to other clean files.
Worms: Similar to viruses but spread across networks without needing to attach to a host file.
Trojans: Malicious software disguised as legitimate applications.
Ransomware: Malware that threatens to publish a victim’s data unless a ransom is paid.
Year of Reference: 2024
SQL Injection Attacks
Definition: A type of attack that occurs when an attacker uses malicious SQL code to manipulate a database.
Mechanism: Malicious input is designed to modify database queries, which can lead to unauthorized access to sensitive data.
Prevention: Input sanitization and parameterized queries help mitigate SQL injection risks.
Year of Reference: 2025
Cross-Site Scripting (XSS)
Definition: A vulnerability allowing attackers to inject malicious scripts into web pages viewed by other users.
Impact: The malicious script can capture sensitive information like login credentials or session tokens.
Year of Reference: 2024
Cross-Site Request Forgery (CSRF)
Definition: An attack that tricks a user into executing unwanted actions on a web application in which they are authenticated.
Mechanism: An attacker sends a forged request to the web application on behalf of the victim.
Year of Reference: 2024
Indicators of Compromise (IoCs)
Definition: Observable events that indicate a breach may have occurred in a system.
Common Examples: Unusual traffic patterns, unexpected file changes, or known malicious file hashes.
Year of Reference: 2025
Security Information and Event Management (SIEM)
Definition: Tools that provide real-time analysis of security alerts generated by hardware and applications.
Functions: Log aggregation, correlation of events, and alerting functionalities allow for proactive threat detection.
Year of Reference: 2024
Incident Response Lifecycle
Phases:
Preparation: Establishing response capabilities and developing an incident response plan.
Identification: Detecting and analyzing incidents based on established indicators.
Containment: Containing the incident to prevent further damage.
Eradication: Eliminating the root cause of the incident.
Recovery: Restoring affected systems and processes.
Lessons Learned: Discussing the incident and improving future response strategies.
Year of Reference: 2025
Server-Side Request Forgery (SSRF)
Definition: A vulnerability allowing an attacker to send crafted HTTP requests from a vulnerable server.
Exploitation: Attackers exploit this to access internal resources (like databases or APIs) from external sources.
Year of Reference: 2024
Secure Coding Practices
List of Practices:
Input Validation: Ensuring data being input meets specifications before processing.
Error Handling: Properly managing errors and preventing leakage of sensitive information.
Least Privilege Principle: Limiting user access rights based on necessity.
Year of Reference: 2024
API Security Measures
Security Practices Include:
Authentication: Verifying the identity of users or systems accessing an API.
Rate Limiting: Control the number of requests a user can make in a given time frame.
Input Validation: Sanitary protocols to prevent unwanted data from entering the API.
Year of Reference: 2025
Malware Analysis Techniques
Definition: The process of dissecting and examining malware to understand its operation and impact.
Methods:
Static Analysis: Evaluating the code without executing the program to identify potential threats.
Dynamic Analysis: Running the malware in a controlled environment (sandbox) to observe its behavior.
Year of Reference: 2024
Phases of Incident Response
Summary: Similar to the incident response lifecycle, detailing crucial steps in responding to security incidents.
Key Focuses: Ensuring efficient coordination and documentation during the phases of incident response.
Year of Reference: 2025
OWASP Contribution to Web Security
Overview: OWASP provides resources, guides, tools, and a community dedicated to improving web security.
Importance: Its guidelines help developers follow best security practices.
Year of Reference: 2024
Evaluation of SIEM Tools for Threat Detection
Assessment Parameters:
Integration: The ability of SIEM tools to work with various data sources.
Real-Time Analysis: Capability to analyze incoming data in real-time for quick response.
False Positive Reduction: Strategies to limit false positives improving efficiency.
Year of Reference: 2025
Applying Incident Response to XSS Attacks
Scenario: Responding to a detected XSS attack.
Phases Involved:
Containment: Immediately isolating affected areas.
Eradication: Removing compromised scripts and patches.
Preventive Coding Updates: Implementing best practices to prevent similar future occurrences.
Year of Reference: 2024
OWASP Top 10 Evaluation
Prioritizing Risks in Web Applications
Major Risks Identified:
Injection: Including SQL injection as a prevalent vulnerability open to exploitation.
Authentication Failures: Addressing the security implications of poorly managed user credentials.
Real-World Application: Oracle reviews these risks to strengthen web application security.
Year of Reference: 2024
Additional Malware and Cybersecurity Strategies
Case Study: Migration of XSS/CSRF Defense in Social Media Breach
Overview: Analysis of exploits during a social media breach and the subsequent implementation of defenses such as Content Security Policies (CSP) and token strategies.
Year of Reference: 2024
Creating an Incident Response Plan for API Vulnerabilities
Outline includes:
Detection protocols for observing anomalous activity related to API requests.
Isolation measures to contain affected services.
Forensic analyses to understand the breach occurrences and improve future defenses.
Communication strategies to inform affected parties.
Year of Reference: 2025
Analyzing SSRF Risks in Web Services
Exploration of SSRF vulnerabilities and the impact of improper input validation leading to exploitation.
Security Fix Proposals: Recommendations including URL validation and network restrictions to mitigate SSRF risks.
Year of Reference: 2024
Evaluating OWASP Guidelines for Cloud Web Apps
Adaptations: Analysis of OWASP Top 10 security risks tailored for cloud-based architectures.
Considerations: Security protocols in serverless architectures and hybrid cloud environments.
Year of Reference: 2025
Case Study: Design IAM (Identity and Access Management) for IaaS in AWS
Objective: Define IAM policies and roles while reviewing a 2025 misconfiguration incident to derive lessons learned.
Year of Reference: 2024
Case Study: Evaluation of the Equifax Data Breach
Examination of SQL Injection vulnerabilities that contributed to the breach.
Analysis of Observed Indicators of Compromise (IoCs) and delayed incident response reflecting on improvement opportunities.
Year of Reference: 2020
Kubernetes Container Security Best Practices
Key Strategies:
Pod Isolation: Supporting separation of workloads to limit the blast radius.
Secrets Management: Secure storage and access control for sensitive credentials.
Runtime Scanning: Continuous monitoring of containers for vulnerabilities in active deployment.
Year of Reference: 2024