Network threats

Assignment Help Computer Network Security
Reference no: EM133476

QUESTION 1:

(a) Differentiate between confidentiality, integrity and availability. Demonstrate your answer using an example.

(b) What is the dissimilarity amid between a virus, a worm and a trojan horse?

(c) Why are commercial employees especially dangerous? What sorts of attacks do they perpetrate?

(d) Does using passwords with salts make attacking a specific account more difficult than using passwords without salts? Give explanation why or why not.

(e) Illustrate the principle of least privilege. Why is it significant?

(f) Data compression is frequently used in data storage or transmission. Presume you want to use data compression in conjunction with encryption.

Does it make added sense to

I. Compress the data and then encrypt the result, or

II. Encrypt the data and then compress the result.

Give good reason for your answer.

QUESTION 2

(a) Decrypt the subsequent, which has been encrypted with a Caesar cipher: G AYKC, G QYU, G AMLOSCPCB

(b) Why is it significant for a cipher to have a large number of potential keys?

(c) Converse the algorithm of the rail fence cipher. You may use an instance to illustrate your answer.

(d) Thrash out the need to perform a threat assessment to implement a physical security program?

(e) Teardrop attacks and Ping of death attacks are methods of launching a Denial of Service attack. Make clear the terms in bold.

(f) Portray five services in PGP operation.

(g) Give explanation the need for web security. Describe briefly the three different approaches to provide web security.

QUESTION 3

(a) Illustrate three network threats that a firewall does not protect against.

(b) Clarify the strengths and weaknesses of each of the following firewall deployment scenarios in defending servers, desktop machines, and laptops against network threats.

I. A firewall at the network perimeter.

II. Firewalls on every end host machine.

III. A network perimeter firewall and firewalls on every end host machine.

(c) Amy desires to send a cellphone text message to Bill securely, over an insecure communication network.
Amy's cellphone has a RSA public key KA and co petitioning private key vA; likewise, Bill's cellphone has KB and vB.
Let's design or intend a cryptographic protocol for doing this, assuming both know each other's public keys.

Here is what Amy's cellphone will do to post the text message m:

1. Amy's phone arbitrarily picks a new AES session key k and computes c = RSA-Encrypt(KB; k), c' = AES-CBC-Encrypt(k;m), and t = RSA-Sign(vA; (c; c')).

2. Amy's phone sends (c; c'; t) to Bill's phone.
And at this time is what Bill's cellphone will do, upon receiving (c; c'; t):

1. Bill's phone ensures that t is a valid RSA signature on (c; c') under public key KA. If not, terminate.

2. Bill's phone computes k' = RSA-Decrypt(vB; c) and m' = AES-CBCDecrypt( k'; c').

3. Bill's phone updates Bill that Amy sent message m'.

I. Does this protocol guarantee the confidentiality of Amy's messages? Why or why not?

II. Does this protocol guarantee authentication and data integrity for every text message Bill receives? Explain Why or why not?

III. Presume that Bill is Amy's stockbroker. Bill hooks up the output of this protocol to an automatic stocktrading service, so if Amy sends a text message "Sell 100 shares MSFT" using the above protocol, then this trade will be straight away and automatically executed from Amy's account.

Recommend one reason why this might be a bad idea from a security point of view.

(d) Presume that an algorithm is found that can efficiently factorise a large number. Describe how a cryptanalyst could use this algorithm to break RSA cryptosystem.

Reference no: EM133476

Questions Cloud

Information flow complexity : Cyclomatic complexity, monitoring devices, wireless dial-out device with controller, Request for Proposals (RFPs), Weighted IFC
Project management for engineering : economic feasibility of the projec, restrictions are the economics of the project based,  technical feasibility for the project
Ip spoofing : honeypot or a firewall, error handling, Denial-Of-Service, Public Key Infrastructure, WLAN Administrator, WEP Protocol, RSA Algorithm, Network Engineer
Protocol stack for wap2 : WAP protocol, cellular network infrastructure, SSL protect against eavesdropping, network datagrams (packets) be protected at the network layer, pin and fingerprint, Certificate Revocation, Public Key Infrastructure, modern symmetric algorithm bl..
Network threats : confidentiality, integrity and availability, trojan horse, Compress the data, Caesar cipher, rail fence cipher, PGP operation, network perimeter, MSFT, RSA cryptosystem
Ssl for http traffic : SSL Record protocol of the SSL protocol stack, RADIUS, networks for access control, DNS poisoning, Spear Phishing attacks, centralised or decentralised access control, encrypt email data
Security by obscurity : Defacement, Infiltration, Phishing, Pharming, Insider Threats, Click Fraud, Denial of Service, Data Theft/Loss, IP Whitelisting and IP Spoofing, recursive PHP functio, worm and a virus, hash on a string using MD5
Concept of subletting in v6 : small package routing is more efficient in IPV6 than in IPV4, increase the hacking factor, network security model (NSM), ACL, VLAN, war dialing
Mc gregor theory : action of a modern HR department, Personnel Management and Human Resources Management, Maslow's Theory to managing people, Maslow's hierarchy of needs Theory, Apprenticeship, job description, interviewing

Reviews

Write a Review

Computer Network Security Questions & Answers

  Analyze security requirements and prepare a security policy

Analyze security requirements and prepare a security policy.

  Discuss two drawbacks of steganography

Discuss two drawbacks of steganography Describe the operation of a Trojan Horse program. How can we protect our computer from such a program

  Dos and ddos attack

Denial of Service attack (DoS) and Distributed Denial of service (DDoS) attack, two-factor authentication system, password ageing, biometric devic,  cryptographic attack made Double DES (2DES), Demilitarized Zone (DMZ), SSL protocols

  Dissect an email

Dissect an email you have received. First, get the original, ASCII text of the email, including the headers, and the blank line separating the headers and the body of the email.

  Retention policy and litigation hold notices

The purpose of this project is to provide you with an opportunity to create a document retention policy. You will also learn how to serve a litigation hold notice for an educational institute.

  Access control list

DNS Cache Poisoning attack, Turtle Shell Architecture,

  A comprehensive study about web-based email implementation

Conduct a comprehensive study about web-based email implementation in gmail. Optionally, you may use sniffer like wireshark or your choice to analyze the communication traffic.

  Analyse security procedures

Analyse security procedures

  Compute the entry in the rijndaels-box

Compute the entry in the RijndaelS-box

  Mitigating dos attacks against broadcast authentication

Mitigating DOS Attacks against Broadcast Authentication in Wireless Sensor Networks

  Cyber terrorism

competitive intelligenc, information safekeeping governance, administration, ISO/IEC 27002, Conceptual Framework

  An overview of wireless lan security - term paper

Computer Science or Information Technology deals with Wireless LAN Security. Wireless LAN Security is gaining importance in the recent times. This report talks about how vulnerable are wireless LAN networks without any security measures and also talk..

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd