Lecture Notes: Security Challenges, OSI Security Architecture, and Cryptography
Security Challenges: Attacker vs Defender
- Security is not as simple as it seems; attackers and defenders think differently.
- If a system has 10 vulnerabilities and you fix 9, the remaining one may still be exploitable; attackers may rely on that single weakness.
- Defender mindset often focuses on software and functionality, not necessarily on network security; attackers can exploit network methods (e.g., packet capture) that bypass software-level defenses.
- Example: you implement user authentication with username/password, but an attacker can silently capture network traffic to obtain credentials via packet sniffing; this is a reminder that software security plus network security are both essential.
- The term "packet sniffing" (the transcript sometimes says packet splitting) highlights hidden monitoring of network traffic; tools like Wireshark enable traffic analysis.
- Security is often seen as an afterthought and not necessary until a failure occurs; e.g., phasing password changes every 2 months is a security practice to complicate attacker patterns.
- Security requires constant monitoring (e.g., antivirus with daily updates to detect new threats and corrupted files).
- Security should be integrated from the start (not as an afterthought); IoT devices (e.g., cameras) illustrate the risk when security is ignored during design.
- Botnets: compromised devices (often IoT) can be used to generate traffic and overwhelm services, causing legitimate users to lose access; botnets illustrate the risk of insecure devices.
- Security vs usability: a trade-off exists; increasing usability may reduce security, and vice versa; developers must balance security needs with user experience and practicality.
- Questions and class discussion encouraged for clarification and deeper understanding.
OSI Security Architecture: Key Terms and Concepts
- OSI stands for Open Systems Interconnection; it provides a network model and security framework.
- Distinctions:
- Attack: the actual action performed to exploit a vulnerability (the active event of breaking protections).
- Security mechanism: the process designed to detect, prevent, or recover from a security attack (e.g., encryption, authentication).
- Security service: goals achieved by applying security mechanisms (the outcomes after protection is applied).
- Examples of security services include:
- Confidentiality: preventing unauthorized access to information.
- Integrity: preventing unauthorized modification of data.
- Authenticity: verifying the identity of users or data sources.
- Accountability: traceability of actions to responsible entities.
- Availability: ensuring services are accessible when needed.
- The terms Attack vs Threat vs Vulnerability:
- Vulnerability (threat that can be exploited): a weakness in a system that could be exploited by an attacker.
- Attack: the actual action that exploits a vulnerability to achieve unauthorized goals.
- Interpreting the difference helps in designing defenses (mitigate vulnerabilities, detect attacks, and enforce services).
- Examples of terms in practice (from lecture):
- Encryption as a security mechanism to support confidentiality and integrity.
- Digital signatures to support nonrepudiation and authenticity.
- Authentication mechanisms to verify user identity.
- Access control to restrict resource access to legitimate users.
- Availability as a service goal ensuring the system remains operational.
- Quick recap of terms:
- Attack is an action that exploits a vulnerability.
- Security mechanism is a defensive measure (e.g., encryption, MAC, authentication).
- Security service is the outcome (confidentiality, integrity, etc.).
Attacks, Mechanisms, and Security Services: Definitions and Examples
- Attacks: actual actions to exploit vulnerabilities (e.g., eavesdropping, modification, impersonation).
- Security mechanisms: defenses designed to detect, prevent, or recover from attacks (e.g., encryption, MAC, authentication protocols).
- Security services: goals achieved by applying mechanisms (e.g., confidentiality, integrity, authenticity, nonrepudiation, availability).
- Example relationships:
- Encryption mechanism provides confidentiality and integrity;
- Digital signatures provide authenticity and nonrepudiation;
- MAC provides integrity and authenticity for a message with a shared key.
- Typical questions you might be asked:
- What is the goal of a particular security service?
- Which mechanism provides a given service?
- How do you differentiate an attack from a vulnerability?
Types of Attacks: Passive vs Active
- Passive attacks:
- The attacker observes communications without altering them.
- They exploit information leakage and metadata (e.g., traffic analysis).
- Example tools and concepts: packet sniffing with Wireshark; observing source/destination addresses.
- Often harder to detect because no obvious alteration occurs.
- Active attacks:
- The attacker takes actions to modify or disrupt communications.
- Common types include:
- Denial of Service (DoS): flooding a service with requests so legitimate users cannot access it.
- Replay attack: capturing and retransmitting valid data to trick a system.
- Data modification: altering the content of messages in transit.
- Man-in-the-middle (MITM): attacker impersonates both client and server to intercept and alter communication.
- The transcript mentions a specific example of replay-like behavior and data manipulation as active attacks.
- The importance of recognizing both types for defense planning (e.g., encryption for confidentiality, integrity checks, anti-replay measures, and strong authentication).
Attacks, Services, and Mechanisms: Concrete Examples
- Services (goals in security):
- Authentication: verifying identity (e.g., login with password).
- Access control: enforcing who can access what resources (role-based access, Canvas example).
- Confidentiality: protecting information from unauthorized access (encrypted data).
- Integrity: ensuring data is not altered in an unauthorized way (digital signatures, MAC).
- Authenticity: confirming data origins or identities.
- Nonrepudiation: preventing a party from denying an action (e.g., digital signatures).
- Availability: ensuring services are reachable (e.g., Canvas available to students).
- Mechanisms to achieve these services:
- Encryption (cryptography): protects confidentiality and can support integrity.
- Authentication protocols: verify identities (e.g., multi-factor authentication).
- Keystream generation and message authentication: MAC for integrity and authenticity with a shared key.
- Notarization and digital timestamps: trusted third-party verification of data existence at a point in time.
- Routing control: choosing secure network paths when delivering data.
- Key exchange protocols: securely distribute cryptographic keys between parties.
- Practical examples:
- Notarization: digital timestamps verify that a document existed at a certain time, useful for assignments or legal documents.
- Botnets illustrate the consequence of poor device security, enabling attackers to generate large volumes of traffic or requests to legitimate services.
Cryptography: Core Concepts and Terminology
- Core terms:
- Cryptography: the science of designing secure communication to protect data; aims include confidentiality, integrity, availability, authenticity, and accountability.
- Cryptanalysis: attempting to break or analyze cryptographic systems to reveal information.
- Cryptology: the umbrella field covering both cryptography and cryptanalysis.
- Cryptographer: a person who designs encryption algorithms and secure protocols.
- Core goals of modern cryptography (as covered in the lecture):
- Confidentiality, Integrity, Nonrepudiation, Authentication (and sometimes Availability and Accountability).
- Key concepts:
- Plaintext: the original message to be sent.
- Ciphertext: the encrypted form of the message.
- Encryption algorithm: transforms plaintext into ciphertext using a key.
- Decryption algorithm: recovers plaintext from ciphertext using a key.
- Encryption key: used to encrypt plaintext.
- Decryption key: used to decrypt ciphertext.
- Some algorithms use the same key for encryption and decryption (symmetric); others use different keys (asymmetric).
- Important caveat from lecture: AES and RSA were mentioned as examples of encryption mechanisms; note academically that AES is a symmetric (single-key) algorithm, while RSA is an asymmetric (two-key) algorithm.
- Cryptographic objects and processes:
- Cryptosystem: a complete design including algorithms, keys, and protocols to satisfy security objectives (confidentiality, integrity, availability, etc.).
- Interceptor: an attacker trying to read or alter protected data.
- Components of a cryptosystem typically include plaintext, ciphertext, encryption/decryption algorithms, and keys.
- Keyless cryptographic primitives:
- Cryptographic hash function: maps input to a fixed-length digest; same input always yields same output; designed to be collision-resistant and preimage-resistant.
- Pseudo-random number generator (PRNG): generates sequences that appear random for cryptographic use (e.g., password generation).
- Symmetric (single-key) vs. asymmetric (two-key) cryptography:
- Symmetric (single-key): one secret key for both encryption and decryption (e.g., AES).
- Asymmetric (two-key): a public key for encryption and a private key for decryption (e.g., RSA, ECC); enables digital signatures and key exchange.
- Overview of symmetric encryption concepts:
- Block cipher: processes fixed-size blocks of data; can use chaining to produce ciphertext for successive blocks (example in lecture: previous ciphertext influences the next; CBC-like chaining).
- Stream cipher: encrypts data bit-by-bit or byte-by-byte using a keystream derived from a key.
- Examples given: Block cipher mode variants, and stream cipher basics where Ci = Pi
oplus S_i (plaintext bit/byte XORed with keystream bit/byte).
- Message authentication code (MAC): a one-key mechanism that provides data integrity and authenticity by attaching a MAC value computed with a shared secret key to the message.
- Example scenario: Alice (E) sends M with MACK(M); Bob computes MACK(M) and verifies it matches, confirming data integrity and authenticity.
- Notation: MAC_K(M) denotes the MAC computed with secret key K.
- Key exchange and authentication concepts:
- Key exchange: securely distributing keys among parties so that they can communicate securely.
- User authentication: confirming a user's identity before granting access.
- Notarization: trusted third-party verification (e.g., digital timestamping) to verify actions or data existence at a given time.
- Notable cryptographic mechanisms mentioned:
- Digital signatures: provide authenticity and nonrepudiation by signing with a private key; verifiable with a public key.
- Digital signatures and cryptographic hash functions are used to guarantee data integrity and nonrepudiation.
- Secure web browsing: TLS relies on public-key cryptography to secure online communications.
- Quick formula-style recap (where helpful for study):
- Symmetric encryption (single-key):
- Encryption: C=EK(P)
- Decryption: P=DK(C)
- Key is shared between sender and receiver.
- Asymmetric encryption (two-key):
- Encryption: C=Epub(P)
- Decryption: P=Dpriv(C)
- Public key for encryption, private key for decryption; enables digital signatures and public-key cryptography.
- Digital signature workflow:
- Signature: S=Signpriv(M)
- Verification: V=Verifypub(M,S)
- Hash function properties (keyless): digest H(M) is a fixed-length representation of M; designed to be collision-resistant and preimage-resistant.
- MAC workflow (one-key): MACK(M) provides integrity/authenticity; recipient recomputes MACK(M) and compares.
- Concrete examples and clarifications:
- Caesar cipher (historical, insecure): shift letters by a fixed number; for a 3-letter shift, the encryption of a letter P is: E(P)=(P+3)mod26. (P and C are numeric positions 0–25.)
- AES (symmetric) vs RSA (asymmetric) highlighted in class as examples; remember the conceptual difference between single-key vs two-key algorithms.
- Secure web traffic (TLS) uses public-key cryptography for initial key exchange and symmetric cryptography for data transfer, combining the strengths of both.
- Public-key cryptography enables digital signatures, key exchange, and robust authentication in distributed systems.
Cryptosystems: Components and Operation
- A cryptosystem encompasses the following core elements:
- Plaintext: the original, readable message to be sent.
- Encryption algorithm: transforms plaintext into ciphertext using a key.
- Ciphertext: the encrypted representation of the plaintext.
- Decryption algorithm: recovers plaintext from ciphertext using a (potentially different) key.
- Encryption key: key used to perform encryption.
- Decryption key: key used to perform decryption.
- How a cryptosystem works in simple terms:
- Sender takes plaintext, applies the encryption algorithm with the encryption key to generate ciphertext.
- Ciphertext is transmitted over an insecure channel.
- Receiver uses the decryption key with the decryption algorithm to recover the plaintext.
- An interceptor without the decryption key cannot easily recover the original message.
- Important nuance:
- Some algorithms use the same key for encryption and decryption (symmetric), others use a pair of keys (asymmetric).
- Block cipher vs stream cipher recap:
- Block cipher: processes data in fixed-size blocks; can chain blocks to enhance security (e.g., CBC). Example concept from lecture: C_i depends on the previous ciphertext block.
- Stream cipher: processes data bit-by-bit or byte-by-byte; uses a keystream Si to transform Pi to Ci via XOR: C</em>i=P<em>i⊕S</em>i.
From Theory to Practice: Algorithms, Hashes, and Signatures
- Keyless cryptographic primitives:
- Cryptographic hash function: fixed-length output for any input; used for integrity checks, digital fingerprints.
- PRNG (pseudo-random number generator): used to generate unpredictable values for keys, nonces, and other cryptographic parameters.
- Single-key (symmetric) algorithms:
- Block cipher: operates on fixed-size blocks; example concept and chaining.
- Stream cipher: bit- or byte-level encryption with a keystream.
- MAC (part of a symmetric approach): message authentication code uses a shared secret to ensure integrity and authenticity.
- Two-key (asymmetric) algorithms:
- Public-key cryptography: uses a public key for encryption and a private key for decryption.
- Includes digital signatures, key exchange, and public-key encryption.
- Key concepts for secure design:
- Public key cryptography enables secure authentication, digital signatures, and key exchange without sharing a secret key ahead of time.
- Hash functions and MACs provide integrity and, in the case of MACs, authenticity with a shared secret.
- Notarization/digital timestamps provide non-repudiation-like evidence by certifying when data existed.
Practical Scenarios and Connections
- Example: Password storage and authentication
- Passwords should be stored in hashed or encrypted form to protect against theft.
- Hashing with a salt and a strong hash function helps protect passwords from rainbow-table attacks.
- Example: Cryptocurrencies
- Digital currencies rely on cryptographic algorithms (public-key cryptography, digital signatures) to verify ownership and secure transactions.
- Example: Secure web browsing
- TLS (Transport Layer Security) uses a combination of asymmetric cryptography for key exchange and symmetric cryptography for data transfer, plus MACs and certificates for authentication and integrity.
- Important real-world considerations:
- The balance between security and usability in system design; overly strict security can hinder usability, while lax security increases risk.
- Continuous monitoring and updating to address evolving threats; security is a continuous process, not a one-off configuration.
- Caesar cipher encryption (illustrative, insecure):
- E(P)=(P+3)mod26.
- Symmetric encryption (one key):
- C=E<em>K(P); P=D</em>K(C)
- Asymmetric encryption (two keys):
- C=E<em>pub(P); P=D</em>priv(C)
- Digital signature workflow:
- S=Sign<em>priv(M); verification: V=Verify</em>pub(M,S)
- MAC (one-key):
- MAC value is computed as MACK(M) and verified with the same secret key K.
- Hash and PRNG basics:
- Hash: H(M)
ightarrow ext{digest} (fixed length, collision-resistant). - PRNG: generates pseudo-random values for cryptographic use.
- Bitwise operations in stream ciphers:
- C<em>i=P</em>i⊕S<em>i (Pi is the i-th bit/byte of plaintext; S_i is the i-th bit/byte of the keystream).
- Notarization idea:
- Time-stamping a file to verify existence at a specific time; example for assignment submission history.
Notable Takeaways for Exam Prep
- Understand the distinctions between attacker mindset and defender mindset, and why security should be integral from the start, not an afterthought.
- Be able to differentiate between attack, security mechanism, and security service, and give examples for each.
- Distinguish passive vs active attacks and give examples (eavesdropping, traffic analysis vs DoS, replay, MITM).
- Memorize major security services (confidentiality, integrity, authenticity, nonrepudiation, availability) and match them to appropriate mechanisms.
- Know the high-level difference between symmetric (single-key) and asymmetric (two-key) cryptography, and the kinds of tasks each enables (data protection vs digital signatures and key exchange).
- Be able to describe how block ciphers and stream ciphers differ in processing data and provide an example of each mechanism.
- Understand the role of MACs in ensuring data integrity and authenticity with a shared secret, and how a recipient validates the MAC.
- Recognize the function of digital signatures and notarization for nonrepudiation and time-bound verification.
- Appreciate practical security concerns like botnets, usability trade-offs, and the importance of ongoing monitoring and security-by-design in devices (e.g., IoT).