Important Questions

BIT303 · Exam intelligence

Information Security important questions

From 5 past TU papers: which questions keep coming back, how much they carry, and what is most likely to show up next. Every question links to a model answer.

Most likely in the next examStatistical

Ranked by how often a topic is asked, its marks weight, and whether it is due after skipping the 2082 paper. No guarantees; study the whole syllabus.

1asked 2xavg 10 marks · due (skipped 2082) · SHA-1 algorithm and padding
Answer

Describe the role of hash functions in authenticating message? How SHA-1 algorithm is used to produce hash value of a message? Explain.[10]

A hash function H is a mathematical function that maps a variable-length input message M to a fixed-length output called the message digest or hash value. The basic authentication process works as follows: At the Sender Side: 1. Sender c...

2asked 2xavg 8 marks · due (skipped 2082) · RSA algorithm and key generation
Answer

RSA Cryptosystem with p=11 and q=7

Consider p=11 and q=7 in a RSA cryptosystem.

i. What is a public key pair (e, n)?

ii. What is a private key pair (d, n)?

iii. What is ciphertext for M=6? [10]

RSA Cryptosystem: p = 11, q = 7

Given Data

  • $p = 11$ (prime)
  • $q = 7$ (prime)
  • Message $M = 6$

Step A: Compute n and φ(n)

$$n = p \times q = 11 \times 7 = 77$$

$$\phi(n) = (p-1)(q-1) = 10 \times 6 = 60$$


Part (i): Public Key Pair (e, n)

Choose $e$ with $1 < e < \phi(n)$ and $\gcd(e, \phi(n)) = 1$.

Try $e = 7$: $$\gcd(7, 60) = 1 \quad \checkmark$$

$$\boxed{\text{Public Key} = (e, n) = (7, 77)}$$

Note: $e$ is not unique; other valid choices include 11, 13 and 17. We use $e = 7$ here.


Part (ii): Private Key Pair (d, n)

Find $d$ such that $d \times 7 \equiv 1 \pmod{60}$.

Extended Euclidean Algorithm:

$$60 = 8 \times 7 + 4$$ $$7 = 1 \times 4 + 3$$ $$4 = 1 \times 3 + 1$$ $$3 = 3 \times 1 + 0$$

Back substitution:

$$1 = 4 - 1 \times 3$$ $$1 = 4 - 1 \times (7 - 1 \times 4) = 2 \times 4 - 1 \times 7$$ $$1 = 2 \times (60 - 8 \times 7) - 1 \times 7 = 2 \times 60 - 17 \times 7$$

So $d = -17 \equiv 60 - 17 = 43 \pmod{60}$.

Verification: $43 \times 7 = 301 = 5 \times 60 + 1 \equiv 1 \pmod{60}$ ✓

$$\boxed{\text{Private Key} = (d, n) = (43, 77)}$$


Part (iii): Ciphertext for M = 6

$$C = M^e \bmod n = 6^7 \bmod 77$$

Using repeated squaring:

$$6^1 = 6$$ $$6^2 = 36$$ $$6^4 = 36^2 = 1296 = 16 \times 77 + 64 \equiv 64 \pmod{77}$$

$$6^7 = 6^4 \times 6^2 \times 6^1 = 64 \times 36 \times 6$$

$$64 \times 36 = 2304 = 29 \times 77 + 71 \equiv 71 \pmod{77}$$ $$71 \times 6 = 426 = 5 \times 77 + 41 \equiv 41 \pmod{77}$$

$$\boxed{C = 41}$$


Summary Table

ParameterValue
$n$77
$\phi(n)$60
Public Key $(e, n)$(7, 77)
Private Key $(d, n)$(43, 77)
Plaintext $M$6
Ciphertext $C$41
3asked 2xavg 8 marks · due (skipped 2082) · Diffie-Hellman key exchange protocol
Answer

Distinguish between threats and attack. Discuss some computer security strategy. Assume a prime number 23 and 9 as its primitive root. Alice select a private key 5 and Bob select the private key 6. Now find the secret key value that Alice and Bob shared using Diffie - Hellman protocol.[10]

Parameter Value ------ Prime number $p$ 23 Primitive root $g$ 9 Alice's private key $a$ 5 Bob's private key $b$ 6 All required data is present. --- Aspect Threat Attack --------- Definition A potential danger that could exploit a vulnera...

4asked 2xavg 5 marks · due (skipped 2082) · Zombies, bots and rootkits
Answer

Define zombies, rootkits and Trojans. [5]

Zombies, Rootkits, and Trojans

Note: No specific reference notes were found for this topic. The following answer is based on standard cybersecurity concepts as taught in BSc CSIT curriculum.


1. Zombies

A zombie (also called a bot) is a compromised computer that has been infected by malware and is secretly controlled by a remote attacker (called a botmaster or bot herder) without the knowledge of the legitimate owner.

Key characteristics:

  • The infected machine responds to commands from a Command and Control (C&C) server
  • Multiple zombies form a botnet
  • Used to carry out DDoS attacks, send spam emails, steal data, or mine cryptocurrency
  • The owner of the zombie machine is usually unaware of the malicious activity

2. Rootkits

A rootkit is a collection of malicious software tools designed to gain unauthorized root/administrator-level access to a computer system while hiding its presence from users, administrators, and security software.

Key characteristics:

  • Operates at a deep level (kernel level or user level)
  • Hides files, processes, registry entries, and network connections
  • Very difficult to detect and remove
  • Often installed after an attacker has already gained initial access
  • Can persist even after system reboots (in some cases)

Types: Kernel-level rootkits, User-level rootkits, Bootloader rootkits


3. Trojans (Trojan Horse)

A Trojan or Trojan Horse is a type of malware that disguises itself as a legitimate or useful program to trick users into installing it, but performs malicious actions in the background.

Key characteristics:

  • Named after the Greek mythological Trojan Horse
  • Does not self-replicate (unlike viruses or worms)
  • Relies on social engineering to deceive users
  • Once installed, it can create backdoors, steal passwords, download other malware, or give remote access to attackers
  • Common examples: Remote Access Trojans (RATs), banking Trojans

Summary Table

FeatureZombieRootkitTrojan
Primary purposeRemote control for attacksHide attacker's presenceDisguise as legitimate software
Self-replicatesNoNoNo
Controlled remotelyYes (by botmaster)SometimesSometimes
Detection difficultyModerateVery HighModerate
5asked 2xavg 5 marks · due (skipped 2082) · Primality testing algorithms
Answer

Write Rabin Miller Algorithm for primality testing. Test whether 341 is prime or not using the algorithm. [5]

  • Number to test: $n = 341$ - Witness base (standard choice): $a = 2$ --- If $n$ is an odd prime, write $n - 1 = 2^s \cdot d$ with $d$ odd. Then for any witness $a$ coprime to $n$, either: $$a^d \equiv 1 \pmod{n} \quad\text{OR}\quad a^{2...

Most repeated questions

Topics asked at least twice, most-asked first.

asked 3xavg 8 marks · 2082, 2081, 0
Answer

What do you mean by subjects, objects and access rights? Discuss about ethical issues in cyber security. [2.5+2.5]

Subjects, Objects, and Access Rights + Ethical Issues in Cyber Security


(a) Subjects, Objects, and Access Rights

Subject

A subject is an active entity that requests access to resources or objects in a system. Subjects are typically users, processes, or programs that initiate actions.

Examples:

  • A logged-in user requesting a file
  • A running process trying to read memory
  • An application accessing a database

Object

An object is a passive entity that contains or receives information, and to which access is controlled.

Examples:

  • Files, directories, databases
  • Memory segments, printers, network ports
  • Records in a database

Access Rights

Access rights (also called permissions or privileges) define the operations that a subject is allowed to perform on an object. They form the basis of access control policies.

Common Access Rights include:

Access RightDescription
Read (R)Subject can read/view the object
Write (W)Subject can modify the object
Execute (X)Subject can run the object as a program
Delete (D)Subject can remove the object
Create (C)Subject can create new objects
Append (A)Subject can add data to the object

Relationship

The relationship among subjects, objects, and access rights is often represented using an Access Control Matrix, where:

  • Rows represent subjects
  • Columns represent objects
  • Cells contain the access rights

Example:

File AFile BPrinter
User1R, WRExecute
User2RR, W-

(b) Ethical Issues in Cyber Security

Ethics in cyber security refers to the moral principles and standards that guide the behavior of individuals and organizations in the digital environment.

1. Privacy and Surveillance

  • Collecting, monitoring, or tracking user data without consent raises serious ethical concerns.
  • Organizations must balance security monitoring with the right to individual privacy.
  • Example: Employers monitoring employee emails without disclosure.

2. Unauthorized Access (Hacking)

  • Accessing systems without permission is both illegal and unethical, even if done with "good intentions" (e.g., grey-hat hacking).
  • Ethical hacking (penetration testing) must be done only with explicit authorization.

3. Intellectual Property and Software Piracy

  • Copying, distributing, or using software without proper licensing is unethical and illegal.
  • Respecting copyrights and licenses is a fundamental ethical obligation.

4. Data Integrity and Honesty

  • Manipulating, falsifying, or destroying data is unethical.
  • Security professionals must ensure data accuracy and report vulnerabilities honestly.

5. Responsible Disclosure

  • When a security researcher discovers a vulnerability, there is an ethical obligation to report it responsibly to the vendor before making it public, giving time for a fix.
  • Selling vulnerabilities to malicious actors is highly unethical.

6. Cybercrime and Malware Development

  • Creating and distributing malware, ransomware, or viruses to harm others is deeply unethical and criminal.

7. Social Engineering and Deception

  • Using deception to manipulate people into revealing confidential information (phishing, pretexting) is unethical.

8. Professional Responsibility

  • Security professionals have an ethical duty to protect user data, maintain confidentiality, and act in the public interest.
  • Organizations must follow ethical guidelines such as those provided by ACM Code of Ethics or (ISC)2 Code of Ethics.

9. Equity and Access

  • Denying access to digital resources based on discrimination is unethical.
  • Cyber security measures should not be used to suppress free speech or target marginalized groups.

Summary Table

Ethical IssueCore Concern
PrivacyRight to personal data protection
Unauthorized AccessConsent and legality
Intellectual PropertyRespect for ownership
Responsible DisclosureDuty to protect the public
MalwareHarm prevention
Professional ResponsibilityTrust and accountability
asked 3xavg 5 marks · 2082, 2080, 2079
Answer

Why do we need two factor authentication? Discuss about security issues for user authentication. [5]

Single-factor authentication (typically a password) has several weaknesses that make it insufficient for secure systems. Two-factor authentication addresses these by requiring two independent forms of verification before granting access....

asked 2xavg 10 marks · 2080, 0
Answer

Describe the role of hash functions in authenticating message? How SHA-1 algorithm is used to produce hash value of a message? Explain.[10]

A hash function H is a mathematical function that maps a variable-length input message M to a fixed-length output called the message digest or hash value. The basic authentication process works as follows: At the Sender Side: 1. Sender c...

asked 2xavg 8 marks · 2081, 2080
Answer

RSA Cryptosystem with p=11 and q=7

Consider p=11 and q=7 in a RSA cryptosystem.

i. What is a public key pair (e, n)?

ii. What is a private key pair (d, n)?

iii. What is ciphertext for M=6? [10]

RSA Cryptosystem: p = 11, q = 7

Given Data

  • $p = 11$ (prime)
  • $q = 7$ (prime)
  • Message $M = 6$

Step A: Compute n and φ(n)

$$n = p \times q = 11 \times 7 = 77$$

$$\phi(n) = (p-1)(q-1) = 10 \times 6 = 60$$


Part (i): Public Key Pair (e, n)

Choose $e$ with $1 < e < \phi(n)$ and $\gcd(e, \phi(n)) = 1$.

Try $e = 7$: $$\gcd(7, 60) = 1 \quad \checkmark$$

$$\boxed{\text{Public Key} = (e, n) = (7, 77)}$$

Note: $e$ is not unique; other valid choices include 11, 13 and 17. We use $e = 7$ here.


Part (ii): Private Key Pair (d, n)

Find $d$ such that $d \times 7 \equiv 1 \pmod{60}$.

Extended Euclidean Algorithm:

$$60 = 8 \times 7 + 4$$ $$7 = 1 \times 4 + 3$$ $$4 = 1 \times 3 + 1$$ $$3 = 3 \times 1 + 0$$

Back substitution:

$$1 = 4 - 1 \times 3$$ $$1 = 4 - 1 \times (7 - 1 \times 4) = 2 \times 4 - 1 \times 7$$ $$1 = 2 \times (60 - 8 \times 7) - 1 \times 7 = 2 \times 60 - 17 \times 7$$

So $d = -17 \equiv 60 - 17 = 43 \pmod{60}$.

Verification: $43 \times 7 = 301 = 5 \times 60 + 1 \equiv 1 \pmod{60}$ ✓

$$\boxed{\text{Private Key} = (d, n) = (43, 77)}$$


Part (iii): Ciphertext for M = 6

$$C = M^e \bmod n = 6^7 \bmod 77$$

Using repeated squaring:

$$6^1 = 6$$ $$6^2 = 36$$ $$6^4 = 36^2 = 1296 = 16 \times 77 + 64 \equiv 64 \pmod{77}$$

$$6^7 = 6^4 \times 6^2 \times 6^1 = 64 \times 36 \times 6$$

$$64 \times 36 = 2304 = 29 \times 77 + 71 \equiv 71 \pmod{77}$$ $$71 \times 6 = 426 = 5 \times 77 + 41 \equiv 41 \pmod{77}$$

$$\boxed{C = 41}$$


Summary Table

ParameterValue
$n$77
$\phi(n)$60
Public Key $(e, n)$(7, 77)
Private Key $(d, n)$(43, 77)
Plaintext $M$6
Ciphertext $C$41
asked 2xavg 8 marks · 2080, 2079
Answer

Distinguish between threats and attack. Discuss some computer security strategy. Assume a prime number 23 and 9 as its primitive root. Alice select a private key 5 and Bob select the private key 6. Now find the secret key value that Alice and Bob shared using Diffie - Hellman protocol.[10]

Parameter Value ------ Prime number $p$ 23 Primitive root $g$ 9 Alice's private key $a$ 5 Bob's private key $b$ 6 All required data is present. --- Aspect Threat Attack --------- Definition A potential danger that could exploit a vulnera...

asked 2xavg 5 marks · 2081, 0
Answer

Define zombies, rootkits and Trojans. [5]

Zombies, Rootkits, and Trojans

Note: No specific reference notes were found for this topic. The following answer is based on standard cybersecurity concepts as taught in BSc CSIT curriculum.


1. Zombies

A zombie (also called a bot) is a compromised computer that has been infected by malware and is secretly controlled by a remote attacker (called a botmaster or bot herder) without the knowledge of the legitimate owner.

Key characteristics:

  • The infected machine responds to commands from a Command and Control (C&C) server
  • Multiple zombies form a botnet
  • Used to carry out DDoS attacks, send spam emails, steal data, or mine cryptocurrency
  • The owner of the zombie machine is usually unaware of the malicious activity

2. Rootkits

A rootkit is a collection of malicious software tools designed to gain unauthorized root/administrator-level access to a computer system while hiding its presence from users, administrators, and security software.

Key characteristics:

  • Operates at a deep level (kernel level or user level)
  • Hides files, processes, registry entries, and network connections
  • Very difficult to detect and remove
  • Often installed after an attacker has already gained initial access
  • Can persist even after system reboots (in some cases)

Types: Kernel-level rootkits, User-level rootkits, Bootloader rootkits


3. Trojans (Trojan Horse)

A Trojan or Trojan Horse is a type of malware that disguises itself as a legitimate or useful program to trick users into installing it, but performs malicious actions in the background.

Key characteristics:

  • Named after the Greek mythological Trojan Horse
  • Does not self-replicate (unlike viruses or worms)
  • Relies on social engineering to deceive users
  • Once installed, it can create backdoors, steal passwords, download other malware, or give remote access to attackers
  • Common examples: Remote Access Trojans (RATs), banking Trojans

Summary Table

FeatureZombieRootkitTrojan
Primary purposeRemote control for attacksHide attacker's presenceDisguise as legitimate software
Self-replicatesNoNoNo
Controlled remotelyYes (by botmaster)SometimesSometimes
Detection difficultyModerateVery HighModerate
asked 2xavg 5 marks · 2081, 2079
Answer

Write Rabin Miller Algorithm for primality testing. Test whether 341 is prime or not using the algorithm. [5]

  • Number to test: $n = 341$ - Witness base (standard choice): $a = 2$ --- If $n$ is an odd prime, write $n - 1 = 2^s \cdot d$ with $d$ odd. Then for any witness $a$ coprime to $n$, either: $$a^d \equiv 1 \pmod{n} \quad\text{OR}\quad a^{2...
asked 2xavg 5 marks · 2080, 0
Answer

What is the role of digital signature in message authentication? List any two natures of zombies. [5]

--- A digital signature is a cryptographic mechanism that provides a way to verify the authenticity and integrity of a digital message or document. It plays the following key roles in message authentication: A digital signature confirms ...

asked 2xavg 8 marks · 2082, 2080
Answer

Define malicious software. Explain the different types of malicious softwares.[10]

Malicious Software: Definition and Types

Definition of Malicious Software

Malicious software (Malware) is any software program that is intentionally designed to gain unauthorized access to a computer system, disrupt normal operations, steal sensitive information, or cause damage to hardware, software, or data without the knowledge or consent of the user.

Malware is created by attackers, hackers, or cybercriminals with harmful intent. It can spread through email attachments, infected websites, removable media, network connections, and software downloads.


Types of Malicious Software

1. Virus

  • A virus is a self-replicating program that attaches itself to legitimate executable files or programs.
  • It activates when the infected program is executed and spreads to other files.
  • It can corrupt or delete files, slow down the system, and cause data loss.
  • Example: File infector virus, Boot sector virus.
  • Key feature: Requires a host program to spread.

2. Worm

  • A worm is a standalone malicious program that replicates itself and spreads across networks without needing a host file.
  • Unlike viruses, worms do not need to attach to an existing program.
  • They consume network bandwidth and system resources.
  • Example: Morris Worm, ILOVEYOU worm.
  • Key feature: Self-propagating through networks.

3. Trojan Horse

  • A Trojan horse is a program that appears to be legitimate and useful software but contains hidden malicious code.
  • It does not self-replicate but tricks users into installing it.
  • Once installed, it can create backdoors, steal data, or allow remote access.
  • Example: Remote Access Trojans (RATs), Banking Trojans.
  • Key feature: Disguised as legitimate software.

4. Spyware

  • Spyware is software that secretly monitors and collects user information without their knowledge.
  • It tracks browsing habits, keystrokes, passwords, and personal data and sends it to a third party.
  • It often comes bundled with free software downloads.
  • Example: Keyloggers, adware with tracking capabilities.
  • Key feature: Operates silently in the background.

5. Adware

  • Adware is software that automatically displays or downloads unwanted advertisements on a user's computer.
  • While not always harmful, it can slow down the system and redirect browsers.
  • Some adware also acts as spyware by tracking user behavior.
  • Example: Pop-up generators, browser hijackers.
  • Key feature: Generates unwanted advertisements.

6. Ransomware

  • Ransomware is malware that encrypts the victim's files or locks the system and demands a ransom payment (usually in cryptocurrency) to restore access.
  • It is one of the most dangerous and financially damaging types of malware.
  • Example: WannaCry, CryptoLocker.
  • Key feature: Encrypts data and demands payment.

7. Rootkit

  • A rootkit is a collection of tools that allows an attacker to gain administrator-level (root) access to a computer while hiding its presence.
  • It modifies the operating system to conceal malicious activity.
  • Very difficult to detect and remove.
  • Example: NTRootkit, Azazel.
  • Key feature: Hides itself and other malware from detection.

8. Backdoor

  • A backdoor is a hidden method of bypassing normal authentication to gain unauthorized access to a system.
  • It can be installed by a Trojan or created by the software developer intentionally or unintentionally.
  • Allows attackers to remotely control the system.
  • Key feature: Provides unauthorized remote access.

9. Logic Bomb

  • A logic bomb is malicious code that remains dormant until a specific condition or trigger event occurs (e.g., a specific date, time, or user action).
  • Once triggered, it executes its payload, which may delete files or crash the system.
  • Example: A disgruntled employee planting code to activate on termination date.
  • Key feature: Triggered by a specific event or condition.

10. Keylogger

  • A keylogger records every keystroke made by a user on the keyboard.
  • It captures passwords, credit card numbers, and other sensitive information.
  • Can be software-based or hardware-based.
  • Key feature: Records keystrokes to steal credentials.

Summary Table

TypeSelf-ReplicatesNeeds HostMain Purpose
VirusYesYesCorrupt files
WormYesNoSpread via network
TrojanNoNoBackdoor/data theft
SpywareNoNoSteal information
RansomwareNoNoExtort money
RootkitNoNoHide malware
Logic BombNoYesTriggered damage
KeyloggerNoNoCapture keystrokes

Conclusion

Malicious software poses a serious threat to individuals, organizations, and governments. Understanding the different types of malware is essential for implementing effective security measures such as antivirus software, firewalls, regular updates, and user awareness training to protect computer systems and sensitive data.

asked 2xavg 5 marks · 2082, 2079
Answer

Explain about threats, attacks and assets. [5]

Assets are the valuable resources of a system or organization that need to be protected. They include: Type Examples --------------- Hardware Computers, servers, routers, storage devices Software Operating systems, application programs, ...

asked 2xavg 5 marks · 2082, 0
Answer

Explain the security auditing architecture. [5]

Note: The reference notes did not contain this topic. The following answer is based on standard, correct information from the security and operating systems domain, appropriate for BSc CSIT curriculum. --- Security auditing is the system...

asked 2xavg 5 marks · 2082, 2080
Answer

Define cybercrime and computer crime. Discuss about intellectual property. [5]

Cybercrime, Computer Crime, and Intellectual Property


Cybercrime

Cybercrime refers to any criminal activity that involves a computer, networked device, or a network as the primary tool or target. It includes crimes committed over the internet or through digital means such as hacking, phishing, identity theft, online fraud, cyberstalking, and spreading malware.

Example: Unauthorized access to someone's email account or stealing credit card information online.


Computer Crime

Computer crime (also called computer-related crime) refers to any illegal act in which a computer is used as a tool, target, or place of criminal activity. It is a broader term that includes both online and offline misuse of computers.

Example: Using a computer to forge documents, unauthorized copying of software, or destroying data stored on a computer.

Key Difference

CybercrimeComputer Crime
Primarily involves the internet/networkMay or may not involve a network
Subset of computer crimeBroader category
e.g., phishing, DDoS attackse.g., software piracy, data manipulation

Intellectual Property (IP)

Intellectual Property refers to creations of the mind -- inventions, literary and artistic works, designs, symbols, names, and images used in commerce -- that are protected by law.

Types of Intellectual Property

  1. Copyright

    • Protects original creative works such as books, music, software, films, and artwork.
    • Gives the creator exclusive rights to reproduce, distribute, and display the work.
    • Example: Source code of a software program is protected by copyright.
  2. Patent

    • Grants an inventor exclusive rights to make, use, or sell an invention for a limited period (usually 20 years).
    • Example: A new algorithm or hardware design.
  3. Trademark

    • Protects brand names, logos, and symbols that distinguish goods/services of one entity from another.
    • Example: The logo of a software company.
  4. Trade Secret

    • Confidential business information that provides a competitive edge.
    • Example: Google's search algorithm.

Intellectual Property in the Context of Computers

  • Software Piracy: Unauthorized copying or distribution of software violates copyright law.
  • Digital Piracy: Illegal downloading or sharing of music, movies, and e-books.
  • Plagiarism: Using someone else's code or content without proper attribution.

Importance of Protecting IP

  • Encourages innovation and creativity.
  • Provides economic benefits to creators and developers.
  • Ensures fair competition in the market.
  • Protects consumers from counterfeit products.
asked 2xavg 5 marks · 2082, 0
Answer

What is attack tree? Describe about password based authentication. [5]

Attack Tree and Password-Based Authentication


Attack Tree

An attack tree is a conceptual diagram that models the various ways an attacker can compromise a system or achieve a malicious goal. It provides a formal, structured methodology for describing the security of systems based on varying attacks.

Structure

  • The root node represents the goal of the attack (e.g., "Gain unauthorized access").
  • Child nodes represent sub-goals or methods to achieve the parent goal.
  • Nodes are connected using:
    • AND nodes: All child conditions must be satisfied.
    • OR nodes: Any one child condition is sufficient.

Example

Goal: Break into a system
    OR
    ├── Guess Password
    │       AND
    │       ├── Know username
    │       └── Try common passwords
    ├── Steal Password
    └── Exploit vulnerability

Benefits

  • Helps in threat modeling and risk assessment.
  • Allows security teams to prioritize defenses.
  • Provides a visual and systematic view of possible attack paths.

Password-Based Authentication

Password-based authentication is the most widely used method of verifying a user's identity. The user provides a username and a secret password, which the system verifies against stored credentials.

How It Works

  1. User enters username and password.
  2. System looks up the stored (hashed) password for that username.
  3. The entered password is hashed and compared with the stored hash.
  4. If they match, access is granted; otherwise, it is denied.

Password Storage

  • Passwords are never stored in plaintext.
  • A one-way hash function (e.g., SHA-256, bcrypt) is applied.
  • A salt (random value) is added before hashing to prevent dictionary and rainbow table attacks.

Stored value = Hash(password + salt)

Common Attacks on Passwords

AttackDescription
Dictionary AttackTries common words/passwords
Brute Force AttackTries all possible combinations
Rainbow Table AttackUses precomputed hash tables
PhishingTricks users into revealing passwords
Shoulder SurfingObserving the user while typing

Countermeasures

  • Use salted hashing (bcrypt, Argon2).
  • Enforce strong password policies (length, complexity).
  • Implement account lockout after failed attempts.
  • Use multi-factor authentication (MFA) alongside passwords.
  • Encourage use of password managers.

Limitations

  • Users tend to choose weak or reusable passwords.
  • Vulnerable to social engineering.
  • Does not provide non-repudiation on its own.

Study every one of these with model answers, flashcards, and MCQs.

Open BIT303 study modes