2079

BIT303 · TU past paper

Information Security 2079 question paper

The complete TU 2079 exam paper for Information Security (BIT303), all 12 questions with solved model answers written to the mark scheme.

Past Papers2082208120802079

Tap a question to open its answer.

  1. 110 marksMD5 algorithm and hash value generationAnswer

    What is hash function? Describe how 128-bit of hash value is generated by taking an input message of variable size using MD5 algorithm?[10]

    A hash function is a mathematical function that takes a variable-length input message and produces a fixed-length output called the hash value or message digest, which acts as a digital fingerprint of the original message. Property Descr...

  2. 210 marksNumericalEthical issues in computingAnswer

    Explain different ethical issues in computing? Explain RSA algorithm with suitable numerical example.[10]

    Computing ethics is the branch of applied ethics dealing with the moral responsibilities of individuals and organizations in the use of information technology. Major issues include: 1. Privacy and Data Protection - Collection, storage, a...

  3. 310 marksDES algorithm and round operationsAnswer

    What is symmetric cryptography? Explain round operation of DES algorithm. Describe Sub-Key generation process for DES rounds.[10]

    Note: No curriculum notes were found for this topic. The answer below is based on standard, well-established cryptography curriculum content as taught in BSc CSIT programs. --- Symmetric cryptography (also called secret-key or convention...

  4. 45 marksAttribute-based access controlAnswer

    What is access control? Explain attribute based access control with example. [5]

    --- Access control is a security mechanism that regulates who or what can view, use, or perform operations on resources in a computing environment. It ensures that only authorized users can access specific resources and perform permitted...

  5. 55 marksNumericalHill cipher and matrix operationsAnswer

    Decrypt the cipher text "CRHG" using the Hill cipher with the key matrix $$\begin{bmatrix} 3 & 4 \ 3 & 5 \end{bmatrix}$$. [5]

    • Ciphertext: CRHG - Key matrix: $K = \begin{bmatrix} 3 & 4 \ 3 & 5 \end{bmatrix}$ - Alphabet mapping: A = 0, B = 1, ..., Z = 25 - Modulus: 26 C R H G ------------ 2 17 7 6 Column vectors: $\begin{bmatrix}2\17\end{bmatrix}$,
  6. 65 marksNumericalPrimality testing algorithmsAnswer

    Define Euler Totient function. Determine whether 37 is Composite or not using Miller Rabin Primality testing. [5]

    Euler Totient Function & Miller-Rabin Primality Test


    Part 1: Euler Totient Function

    The Euler Totient Function, denoted $\phi(n)$, is defined as the number of positive integers less than or equal to $n$ that are relatively prime (coprime) to $n$.

    $$\phi(n) = |{ k : 1 \le k \le n,\ \gcd(k, n) = 1 }|$$

    Key properties:

    • If $p$ is prime: $\phi(p) = p - 1$
    • For a prime power: $\phi(p^k) = p^k - p^{k-1}$
    • Multiplicative: $\phi(mn) = \phi(m)\cdot\phi(n)$ when $\gcd(m,n) = 1$

    Example: $\phi(37) = 36$ since 37 is prime.


    Part 2: Miller-Rabin Test on $n = 37$

    Algorithm

    To test $n$ with a chosen witness $a$:

    1. Write $n - 1 = 2^s \cdot d$ with $d$ odd.
    2. Compute $x = a^d \bmod n$.
    3. If $x \equiv 1$ or $x \equiv -1 \pmod n$ → probably prime.
    4. Otherwise square $x$ repeatedly (for $r = 1, \dots, s-1$); if any gives $-1 \pmod n$ → probably prime.
    5. If none hold → composite.

    Step 1: Express $n - 1 = 2^s \cdot d$

    $$n - 1 = 36 = 2^2 \cdot 9$$

    So $s = 2$, $d = 9$.


    Step 2: Choose witness $a = 2$, compute $a^d \bmod n$

    $$2^9 \bmod 37$$

    • $2^1 = 2$
    • $2^2 = 4$
    • $2^4 = 16$
    • $2^8 = 256 = 6\times 37 + 34 \equiv 34 \pmod{37}$
    • $2^9 = 2^8 \cdot 2 = 34 \times 2 = 68 \equiv 68 - 37 = 31 \pmod{37}$

    $$x = 2^9 \equiv 31 \pmod{37}$$


    Step 3: Check conditions

    Initial check: Is $x \equiv 1$ or $x \equiv 36\ (\equiv -1)$? $$31 \ne 1, \quad 31 \ne 36 \quad \Rightarrow \text{ not yet passed}$$

    Square once ($r = 1$): compute $2^{18} = x^2 \bmod 37$ $$31^2 = 961, \quad 961 = 25\times 37 + 36 = 925 + 36$$ $$2^{18} \equiv 36 \equiv -1 \pmod{37} \quad \checkmark$$

    Condition satisfied.


    Conclusion

    Since $2^{18} \equiv -1 \pmod{37}$, the test passes for witness $a = 2$.

    $$\boxed{37 \text{ is PROBABLY PRIME (not composite)}}$$

    37 is in fact a prime number, so Miller-Rabin correctly reports it as not composite.

  7. 75 marksTwo-factor authenticationAnswer

    Write Short Notes on: a. Phishing Attack b. Two Factor Authentication [5]

    Definition: A phishing attack is a type of social engineering attack in which an attacker disguises themselves as a trustworthy entity to trick users into revealing sensitive information such as usernames, passwords, credit card numbers,...

  8. 85 marksBiometric authenticationAnswer

    Define authentication. How Biometric information can be used for authentication? [5]

    Authentication is the process of verifying the identity of a user, system, or entity attempting to gain access to a resource. It is the mechanism by which a system confirms that someone is who they claim to be, typically before granting ...

  9. 95 marksSecurity risk assessment aspectsAnswer

    What is security risk assessment? What are different aspects of a successful security risk assessment? [5]

    Security Risk Assessment

    Definition

    Security Risk Assessment is a systematic process of identifying, analyzing, and evaluating potential security threats and vulnerabilities within an information system or organization. It helps determine the likelihood and impact of security incidents and guides decision-making for implementing appropriate security controls and countermeasures.

    Note: The reference notes did not contain material on this topic; the following answer is based on standard information security curriculum content.


    Aspects of a Successful Security Risk Assessment

    A successful security risk assessment involves the following key aspects:

    1. Asset Identification

    • Identify all valuable assets within the organization (hardware, software, data, personnel, processes).
    • Determine the value and criticality of each asset to the organization.

    2. Threat Identification

    • Identify potential threats that could harm the identified assets.
    • Threats may be natural (floods, fire), human (hackers, insiders), or environmental (power failure).

    3. Vulnerability Assessment

    • Identify weaknesses or gaps in existing security controls.
    • Vulnerabilities can exist in software, hardware, policies, or procedures.

    4. Risk Analysis

    • Evaluate the likelihood of a threat exploiting a vulnerability.
    • Estimate the potential impact or damage if the risk materializes.
    • Risk is commonly expressed as:

    $$\text{Risk} = \text{Likelihood} \times \text{Impact}$$

    5. Risk Evaluation and Prioritization

    • Compare analyzed risks against acceptable risk criteria.
    • Prioritize risks based on their severity to focus resources effectively.

    6. Risk Treatment / Mitigation

    • Select appropriate controls to:
      • Avoid the risk
      • Reduce the risk (mitigation)
      • Transfer the risk (e.g., insurance)
      • Accept the risk (if within tolerance)

    7. Documentation and Reporting

    • Document all findings, risk levels, and recommended controls.
    • Provide a clear report to management for informed decision-making.

    8. Monitoring and Review

    • Continuously monitor the risk environment.
    • Reassess risks periodically as systems, threats, and business needs change.

    Summary Table

    AspectPurpose
    Asset IdentificationKnow what to protect
    Threat IdentificationKnow what can cause harm
    Vulnerability AssessmentKnow existing weaknesses
    Risk AnalysisMeasure likelihood and impact
    Risk PrioritizationFocus on critical risks first
    Risk TreatmentApply appropriate controls
    DocumentationRecord and communicate findings
    Monitoring & ReviewEnsure ongoing security

    A well-conducted security risk assessment forms the foundation of an effective information security management system (ISMS) and helps organizations protect their assets proactively.

  10. 105 marksViruses, worms and Trojan horsesAnswer

    Differentiate between virus, worm and Trojan horse. [5]

    Note: Standard computer security concepts are used here as no specific curriculum notes were provided. --- Feature Virus Worm Trojan Horse ------------ Definition A malicious program that attaches itself to a legitimate file/program and ...

  11. 115 marksThreats, attacks and assetsAnswer

    What is Security threat and attack? Describe different types of attacks in brief. [5]

    A security threat is any potential danger or circumstance that has the possibility of exploiting a vulnerability in a system to cause harm, loss, or unauthorized access to information or resources. It represents a possible violation of s...

  12. 125 marksNumericalDiffie-Hellman key exchange protocolAnswer

    Explain Diffie Hellman Key Exchange Protocol with suitable example. [5]

    The question is descriptive. The only numeric inputs come from the standard example: - Prime $p = 23$ - Generator (primitive root) $g = 5$ - Alice's private key $a = 6$ - Bob's private key $b = 15$ --- The Diffie-Hellman (DH) Key Exchang...