BIT303 · TU past paper
Information Security 2079 question paper
The complete TU 2079 exam paper for Information Security (BIT303), all 12 questions with solved model answers written to the mark scheme.
Tap a question to open its answer.
- 110 marksMD5 algorithm and hash value generationHideAnswer
What is hash function? Describe how 128-bit of hash value is generated by taking an input message of variable size using MD5 algorithm?[10]
A hash function is a mathematical function that takes a variable-length input message and produces a fixed-length output called the hash value or message digest, which acts as a digital fingerprint of the original message. Property Descr...
- 210 marksNumericalEthical issues in computingHideAnswer
Explain different ethical issues in computing? Explain RSA algorithm with suitable numerical example.[10]
Computing ethics is the branch of applied ethics dealing with the moral responsibilities of individuals and organizations in the use of information technology. Major issues include: 1. Privacy and Data Protection - Collection, storage, a...
- 310 marksDES algorithm and round operationsHideAnswer
What is symmetric cryptography? Explain round operation of DES algorithm. Describe Sub-Key generation process for DES rounds.[10]
Note: No curriculum notes were found for this topic. The answer below is based on standard, well-established cryptography curriculum content as taught in BSc CSIT programs. --- Symmetric cryptography (also called secret-key or convention...
- 45 marksAttribute-based access controlHideAnswer
What is access control? Explain attribute based access control with example. [5]
--- Access control is a security mechanism that regulates who or what can view, use, or perform operations on resources in a computing environment. It ensures that only authorized users can access specific resources and perform permitted...
- 55 marksNumericalHill cipher and matrix operationsHideAnswer
Decrypt the cipher text "CRHG" using the Hill cipher with the key matrix $$\begin{bmatrix} 3 & 4 \ 3 & 5 \end{bmatrix}$$. [5]
- Ciphertext: CRHG - Key matrix: $K = \begin{bmatrix} 3 & 4 \ 3 & 5 \end{bmatrix}$ - Alphabet mapping: A = 0, B = 1, ..., Z = 25 - Modulus: 26 C R H G ------------ 2 17 7 6 Column vectors: $\begin{bmatrix}2\17\end{bmatrix}$,
- 65 marksNumericalPrimality testing algorithmsHideAnswer
Define Euler Totient function. Determine whether 37 is Composite or not using Miller Rabin Primality testing. [5]
Euler Totient Function & Miller-Rabin Primality Test
Part 1: Euler Totient Function
The Euler Totient Function, denoted $\phi(n)$, is defined as the number of positive integers less than or equal to $n$ that are relatively prime (coprime) to $n$.
$$\phi(n) = |{ k : 1 \le k \le n,\ \gcd(k, n) = 1 }|$$
Key properties:
- If $p$ is prime: $\phi(p) = p - 1$
- For a prime power: $\phi(p^k) = p^k - p^{k-1}$
- Multiplicative: $\phi(mn) = \phi(m)\cdot\phi(n)$ when $\gcd(m,n) = 1$
Example: $\phi(37) = 36$ since 37 is prime.
Part 2: Miller-Rabin Test on $n = 37$
Algorithm
To test $n$ with a chosen witness $a$:
- Write $n - 1 = 2^s \cdot d$ with $d$ odd.
- Compute $x = a^d \bmod n$.
- If $x \equiv 1$ or $x \equiv -1 \pmod n$ → probably prime.
- Otherwise square $x$ repeatedly (for $r = 1, \dots, s-1$); if any gives $-1 \pmod n$ → probably prime.
- If none hold → composite.
Step 1: Express $n - 1 = 2^s \cdot d$
$$n - 1 = 36 = 2^2 \cdot 9$$
So $s = 2$, $d = 9$.
Step 2: Choose witness $a = 2$, compute $a^d \bmod n$
$$2^9 \bmod 37$$
- $2^1 = 2$
- $2^2 = 4$
- $2^4 = 16$
- $2^8 = 256 = 6\times 37 + 34 \equiv 34 \pmod{37}$
- $2^9 = 2^8 \cdot 2 = 34 \times 2 = 68 \equiv 68 - 37 = 31 \pmod{37}$
$$x = 2^9 \equiv 31 \pmod{37}$$
Step 3: Check conditions
Initial check: Is $x \equiv 1$ or $x \equiv 36\ (\equiv -1)$? $$31 \ne 1, \quad 31 \ne 36 \quad \Rightarrow \text{ not yet passed}$$
Square once ($r = 1$): compute $2^{18} = x^2 \bmod 37$ $$31^2 = 961, \quad 961 = 25\times 37 + 36 = 925 + 36$$ $$2^{18} \equiv 36 \equiv -1 \pmod{37} \quad \checkmark$$
Condition satisfied.
Conclusion
Since $2^{18} \equiv -1 \pmod{37}$, the test passes for witness $a = 2$.
$$\boxed{37 \text{ is PROBABLY PRIME (not composite)}}$$
37 is in fact a prime number, so Miller-Rabin correctly reports it as not composite.
- 75 marksTwo-factor authenticationHideAnswer
Write Short Notes on: a. Phishing Attack b. Two Factor Authentication [5]
Definition: A phishing attack is a type of social engineering attack in which an attacker disguises themselves as a trustworthy entity to trick users into revealing sensitive information such as usernames, passwords, credit card numbers,...
- 85 marksBiometric authenticationHideAnswer
Define authentication. How Biometric information can be used for authentication? [5]
Authentication is the process of verifying the identity of a user, system, or entity attempting to gain access to a resource. It is the mechanism by which a system confirms that someone is who they claim to be, typically before granting ...
- 95 marksSecurity risk assessment aspectsHideAnswer
What is security risk assessment? What are different aspects of a successful security risk assessment? [5]
Security Risk Assessment
Definition
Security Risk Assessment is a systematic process of identifying, analyzing, and evaluating potential security threats and vulnerabilities within an information system or organization. It helps determine the likelihood and impact of security incidents and guides decision-making for implementing appropriate security controls and countermeasures.
Note: The reference notes did not contain material on this topic; the following answer is based on standard information security curriculum content.
Aspects of a Successful Security Risk Assessment
A successful security risk assessment involves the following key aspects:
1. Asset Identification
- Identify all valuable assets within the organization (hardware, software, data, personnel, processes).
- Determine the value and criticality of each asset to the organization.
2. Threat Identification
- Identify potential threats that could harm the identified assets.
- Threats may be natural (floods, fire), human (hackers, insiders), or environmental (power failure).
3. Vulnerability Assessment
- Identify weaknesses or gaps in existing security controls.
- Vulnerabilities can exist in software, hardware, policies, or procedures.
4. Risk Analysis
- Evaluate the likelihood of a threat exploiting a vulnerability.
- Estimate the potential impact or damage if the risk materializes.
- Risk is commonly expressed as:
$$\text{Risk} = \text{Likelihood} \times \text{Impact}$$
5. Risk Evaluation and Prioritization
- Compare analyzed risks against acceptable risk criteria.
- Prioritize risks based on their severity to focus resources effectively.
6. Risk Treatment / Mitigation
- Select appropriate controls to:
- Avoid the risk
- Reduce the risk (mitigation)
- Transfer the risk (e.g., insurance)
- Accept the risk (if within tolerance)
7. Documentation and Reporting
- Document all findings, risk levels, and recommended controls.
- Provide a clear report to management for informed decision-making.
8. Monitoring and Review
- Continuously monitor the risk environment.
- Reassess risks periodically as systems, threats, and business needs change.
Summary Table
Aspect Purpose Asset Identification Know what to protect Threat Identification Know what can cause harm Vulnerability Assessment Know existing weaknesses Risk Analysis Measure likelihood and impact Risk Prioritization Focus on critical risks first Risk Treatment Apply appropriate controls Documentation Record and communicate findings Monitoring & Review Ensure ongoing security
A well-conducted security risk assessment forms the foundation of an effective information security management system (ISMS) and helps organizations protect their assets proactively.
- 105 marksViruses, worms and Trojan horsesHideAnswer
Differentiate between virus, worm and Trojan horse. [5]
Note: Standard computer security concepts are used here as no specific curriculum notes were provided. --- Feature Virus Worm Trojan Horse ------------ Definition A malicious program that attaches itself to a legitimate file/program and ...
- 115 marksThreats, attacks and assetsHideAnswer
What is Security threat and attack? Describe different types of attacks in brief. [5]
A security threat is any potential danger or circumstance that has the possibility of exploiting a vulnerability in a system to cause harm, loss, or unauthorized access to information or resources. It represents a possible violation of s...
- 125 marksNumericalDiffie-Hellman key exchange protocolHideAnswer
Explain Diffie Hellman Key Exchange Protocol with suitable example. [5]
The question is descriptive. The only numeric inputs come from the standard example: - Prime $p = 23$ - Generator (primitive root) $g = 5$ - Alice's private key $a = 6$ - Bob's private key $b = 15$ --- The Diffie-Hellman (DH) Key Exchang...