Network security topics via analysing

Assignment Help Computer Networking
Reference no: EM133021266

SENG2250 System and Network Security - The University of Newcastle

Aims
This assignment aims to establish a basic familiarity with network security topics via analysing, designing, and implementing solutions.

Questions

1. Network Security
A bank system, including the internal and external sub-systems, is used by different users. Based on the security requirements, these accesses should be protected in different ways depending on access methods. We will focus on network security for internal and external access to the bank system in this task.
• There are two types of users: bank customers and bank employees.
• The bank system provides a range of services, such as personal savings, bank statements, money transfer, internal message management, and account management.
• As a customer, it is allowed to use web browsers to access the bank website and make transactions.
• A customer can also use the mobile app to access the services. In this case, the customer is likely to use a mobile network or WiFi connection.
• As a bank employee, it is allowed to access the bank system via the website or desktop application.
• When an employee is travelling for business, it may need to connect the bank servers via a secure connection.

Your task.

a. Consider the security of the above system, discuss two potential security issues and provide countermeasures.
For each of the issues, specify the related security service(s), attack(s) and mechanism(s). The demonstrated issues must not relate to the same security service(s).

b. Consider that a bank employee requests to modify a bank customer's daily cash transfer limit. Briefly describe the essential security-related step(s) that demonstrate the security checks for the operation. For each step, specify the aimed security service(s).

c. An employee accesses the internal system with proper authentication and authorisation. Consider Kerberos, SAML, and OAuth, which one is better for internal system authentication and authorisation? Justify your answer.

d. To provide secure connection services for the travelling employees, which of IPSec, SSL/TLS, and SSH, would be a better option? Justify your answer.

2. Programming Task
A client and a server are planning to do data exchange. They decide to use a simplified SSL handshake (see Figure 1) to establish a secure channel (session key) then exchange data. The simplified SSL handshake removes the messages for alert, change cipher spec, certificate, etc.

1016_figure.jpg

Figure 1. Secure data exchange.

IDC: client ID; IDS: server ID; SID: session ID;
Your task: implement the above mechanism in Java (alternatively C++/Python). The following components are mandatory for implementation.
• Fast modular exponentiation
• RSA signature scheme.
o RSA key generation: randomly generate two primes ??, ?? (for 2048-bit RSA). Set the public key as the fixed ?? = 65537. Server's RSA public key will be sent to the client in the Steup message. Assume this message can be securely delivered, no security protection is needed. Note that a client DOES NOT have its RSA keys.
o RSA signature generation: using SHA256 for message digest computation.
o RSA signature verification: using SHA256 for message digest computation.
o The underlying hash function is SHA256. You can use it from the Java library.
o Key generation needs to be implemented using (Java) BigInteger.
o RSA signature generation and verification need to be implemented using your own fast modular exponentiation method.

• Diffie-Hellman key exchange
o Use the parameters ??, ?? from the System Parameters section.
• The DH key exchange should be secure against man-in-the-middle attacks.
• HMAC
o Use SHA256 as the underlying hash function.
o Use the DH key (e.g., k = g!") to generate the authentication key k′, such that k# = H(k), where H() is the SHA256 hash function.
o HMAC is calculated as (refer to lecture 2)
H(k#, m) = H((k# ⊕ opad)||H((k# ⊕ ipad)||m))
• CTR mode
o Assume a message is always a multiple of 16-byte, i.e. no padding needed.
• Data exchange
o When a shared session key is created, they use 256-bit AES encryption with
CTR and HMAC to protect data confidentiality and integrity, respectively.
o Demonstrate at least two message exchanges, where each message is exactly 64 bytes.

Attachment:- System and Network Security.rar

Reference no: EM133021266

Questions Cloud

Calculate the amount of the firm gross profit : Evening Story Corporation has sales of $4,432,837; income tax of $374,116; and interest expense of $142,142. Calculate the amount of the firm's gross profit
Why do people cheat in education and business : What are some of the harms that come from these acts? In your answer explain why you feel the actions are unethical using ethical theory and/or reasoning.
Citibank e-business strategy for global corporate banking : 1. What are the impacts of the internet on the competitive landscape of corporate banking? (Hint: use Porters 5 forces)
What are the financial risks of the host country : Take Canadian Home Hardware company to Finland and Analyze the company's risk of entering into a foreign market. What are the financial risks of host country
Network security topics via analysing : Assignment aims to establish a basic familiarity with network security topics via analysing, designing, and implementing solutions
Compute xbar and sigma : Hudson Realty is considering a boost in advertising in order to reduce a large inventory of unsold houses.
Prepare a flexible budget performance report for the selling : Given that the actual sales for January 2021 are $507,000, prepare a flexible budget performance report for the selling expenses
How much revenue is needed to earn their target net income : The restaurant serves full meals and beverages including specialty coffees and cocktails. How much revenue is needed to earn their target net income of $288,750
How do you manage credible elections : How do you manage credible elections?

Reviews

Write a Review

Computer Networking Questions & Answers

  What are major concerning factors of data loss and data thef

What are major concerning factors of data loss and data theft

  What command should be entered from the router prompt

Modify the command for Problem so that the access list is applied to outbound data packets.

  Build an application about an online furniture shopping

Need to build an application in Just in mind about an online furniture shopping based on 3 scenario described attachment

  What is the name of the archived running config file

ITNE 2005 Victorian Institute of Technology Australia-Configure a clock rate of 128000 for routers with a DCE serial cable attached to their serial interface.

  Assignment on domain design for security worksheet

Assignment on Domain Design for Security Worksheet, Research and examine a domain model for security that is different from the one you previously developed for this course. Assume that recent compromises of sensitive information require security e..

  How each layer of suite represents the communication flow

describe how each layer of the Model/Suite represents the communication flow between organizational levels and across departments/division of an actual hierarch

  What is the main disadvantage of a cut through switch

What is the main disadvantage of a cut through switch? Is there a way to solve the disadvantage of a cut-through switch without losing its advantages?

  Vertical cabling to connect

How would you use Vertical Cabling to connect 2 networks on 2 different floors?

  Define network diagram data for a small project

Consider Table 6-2, Network Diagram Data for a Small Project. All duration estimates or estimates times are in days, and the network proceeds from Node 1 to Node 9.(Please answer the questions for Chapter 6, number 2 under Exercises, pp 246.)

  Which of the given is a cisco ios feature which can collect

question which of the following is a cisco ios feature that can collect timestamps of traffic sent between a particular

  What rfc describes the gopher protocol

What RFC describes the Gopher protocol? Print and read the first two pages of the RFC and list and illustrate 5 RFCs that describe the IMAP protocol. Print and read the first two pages of one of these RFCs.

  Plan for how a vlan could be implemented

Explain in a 350- to 700-word plan for how a VLAN could be implemented so that bandwidth is not consumed. Your plan must ensure that the network is not flooded with packets, and that members of the same VLAN can be located in different buildings o..

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd