Discretionary and mandatory access control

Assignment Help Computer Network Security
Reference no: EM133322

QUESTION 1

(a) Sort out each of the following as a violation of privacy, integrity, and ease of use, authenticity or some grouping of these:

I. Paul copies Sam's homework

II. Simon crashes Rita's system

III. Wayne changes the amount of Lee's cheque from $100 to $1000

(b) (i) Describe the following:

A. Logic bombs

B. War dialing?

(ii) Express how war dialling is executed.

(c) (i) What are buffer overflows?

(ii) Elucidate how ‘Ping of death' attack is achieved.

(d) (I) Talk about three methods by which passwords based systems can be attacked

(II) Present at least one system of defense against each of the method you have identified at (I) above.

(e) Distinguish between Discretionary and Mandatory Access Control.

(f) Give three causes why Biometrics is not as popular as passwords based system.

(g) What is steganography?

List two drawbacks of steganography.

QUESTION 2

(a) (I) In the RSA scheme of public key cryptography what should conclude the length of key and the maximum length of a message block?

(II) If a key length of 512 bits is chosen and the message is 400 bits long. What will be the length of the resulting cipher text block?

(b)(I)Elucidate why the number 3 is a popular choice of public key exponent in RSA algorithm.

(II) In what circumstances it would be impossible to use 3 as RSA public key exponent?

(III) Elucidate why RSA digital signatures are used to sign a Message Digest instead of the message itself.

(IV) What advantages does a digital signature created by a public cryptographic system have over a MAC created by a secretkey algorithm and a shared key?

(c) In a simple demonstration of the impression of RSA digital signatures, it was decided to use either the pair of small primes 23 and 29 or 19 and 23 as p and q where the public key modulus is n = p x q. Show that if a public key exponent of 3 is to be used in the demonstration, then 23 and 29 must be used for p and q.

(d) In a public key infrastructure explain what is meant by the subsequent:

(I) A chain of certificates.

(II) A certificate revocation list.

(III) A trust anchor.

(e) Two parties wish to converse by email from time to time and intend to keep the content of their communication and the fact that communication are taking place , a total secret. Illustrate how they might achieve their aim.

QUESTION 3:

(a) A firewall is placed at the gateway between a corporate LAN and the internet. Clarify in outline how the firewall could be arranged to provide the following functions.

(I) To bar all communications to or from a particular external address on the internet.

(II) To bar all incoming TELNET sessions

(III) To bar any external machines on the internet from initiating a association to a machine on the corporate LAN.

(b)(I) Assailant is intent on disrupting secure communications by inserting bogus packets (with correct TCP checksum) into the communications. Thrash out how such an attack would impact on systems protected by IPsec and SSL.

(II) What does S/MIME stand for?

(c) Explain with the help of a considered sketch how SSL works.

(d) Give one example of a symmetric and one asymmetric algorithm used by PGP.

(e) In the context of IPSec protocol explicates the terms:

I. Tunnel

II. Transport mode.

(f) Which IPSec mode would be appropriate for the next?

(i) Firewall to firewall communication

(ii) IP virtual Private Networks.

(g)List four services offered by PGP.

Reference no: EM133322

Questions Cloud

Why might a best fit approach be more helpful : What are the severe limitations of the best practice approach What is meant by the best fit approach to the design and development of a human resource strategy Why might a best fit approach be more helpful
Define service recovery : Define service recovery Discuss the impact of the service recovery efforts on customer loyalty
Turtle shell architecture : Turtle Shell Architecture, zero-byte representation, Access Control List, DNS Cache Poisoning attack, 16-pass iterative and 9-pass recursive PHP function
Symmetric encryption algorithms : block cipher and a stream cipher, Caesar cipher, cryptanalytic attacks, mono alphabetic cipher and a poly alphabetic cipher, Mix Columns, Add Round key, PGP services, traffic padding, contrast link and end-to-end encryption
Discretionary and mandatory access control : Logic bombs, War dialing, Ping of death attack, steganography, RSA scheme, digital signature, A chain of certificates, A certificate revocation list, A trust anchor, asymmetric algorithm used by PGP, IPSec mode, IP virtual Private Networks
Network security : SLE, ARO, and ALE, behavioural biometric technology, Enterprise Information Security Policy, Issue Specific Security Policy, System Specific Security Policy, firewalls protect network, creating a DMZ during firewall implementation, use of SSL to se..
Digital forensic investigation : computer security incident, Trojan Defence, anti-forensics technique, chain of custody, FAT file system, SQLOracleHacks.txt, SQLOracleAttacks.txt, SQLInjection.html
Computer security incident : Locard's Exchange Principle, electronic crime scene, modules or DLLs a process, router forensics, Configuration and user, Local logs process and memory, Network Information, File system, Portray the NTP vulnerability of some Cisco IOS routers
Security vulnerabilities of vc : single access point (AP), wireless network, CSMA/CA, goals of information security, Wireless LANs, wireless hacking process, Wired Equivalent Privacy (WEP), Open System Authentication and Shared Key Authentication, Initialisation Vector (IV), RADIU..

Reviews

Write a Review

Computer Network Security Questions & Answers

  An overview of wireless lan security - term paper

Computer Science or Information Technology deals with Wireless LAN Security. Wireless LAN Security is gaining importance in the recent times. This report talks about how vulnerable are wireless LAN networks without any security measures and also talk..

  Computer networks and security against hackers

This case study about a company named Magna International, a Canada based global supplier of automotive components, modules and systems. Along with the company analysis have been made in this assignment.

  New attack models

The Internet evolution is and is very fast and the Internet exposes the connected computers to attacks and the subsequent losses are in rise.

  Islamic Calligraphy

Islamic calligraphy or Arabic calligraphy is a primary form of art for Islamic visual expression and creativity.

  A comprehensive study about web-based email implementation

Conduct a comprehensive study about web-based email implementation in gmail. Optionally, you may use sniffer like wireshark or your choice to analyze the communication traffic.

  Retention policy and litigation hold notices

The purpose of this project is to provide you with an opportunity to create a document retention policy. You will also learn how to serve a litigation hold notice for an educational institute.

  Tools to enhance password protection

A report on Tools to enhance Password Protection.

  Analyse security procedures

Analyse security procedures

  Write a report on denial of service

Write a report on DENIAL OF SERVICE (DoS).

  Phising email

Phising email It is multipart, what are the two parts? The HTML part, is it inviting the recepient to click somewhere? What is the email proporting to do when the link is clicked?

  Express the shannon-hartley capacity theorem

Express the Shannon-Hartley capacity theorem in terms of where is the Energy/bit and is the psd of white noise.

  Modern symmetric encryption schemes

Pseudo-random generators, pseudo-random functions and pseudo-random permutations

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd