BIT303 · TU past paper
Information Security 2081 question paper
The complete TU 2081 exam paper for Information Security (BIT303), all 12 questions with solved model answers written to the mark scheme.
Tap a question to open its answer.
- 110 marksNumericalRSA algorithm and key generationHideAnswer
RSA Cryptosystem with p=11 and q=7
Consider p=11 and q=7 in a RSA cryptosystem.
i. What is a public key pair (e, n)?
ii. What is a private key pair (d, n)?
iii. What is ciphertext for M=6? [10]
RSA Cryptosystem: p = 11, q = 7
Given Data
- $p = 11$ (prime)
- $q = 7$ (prime)
- Message $M = 6$
Step A: Compute n and φ(n)
$$n = p \times q = 11 \times 7 = 77$$
$$\phi(n) = (p-1)(q-1) = 10 \times 6 = 60$$
Part (i): Public Key Pair (e, n)
Choose $e$ with $1 < e < \phi(n)$ and $\gcd(e, \phi(n)) = 1$.
Try $e = 7$: $$\gcd(7, 60) = 1 \quad \checkmark$$
$$\boxed{\text{Public Key} = (e, n) = (7, 77)}$$
Note: $e$ is not unique; other valid choices include 11, 13 and 17. We use $e = 7$ here.
Part (ii): Private Key Pair (d, n)
Find $d$ such that $d \times 7 \equiv 1 \pmod{60}$.
Extended Euclidean Algorithm:
$$60 = 8 \times 7 + 4$$ $$7 = 1 \times 4 + 3$$ $$4 = 1 \times 3 + 1$$ $$3 = 3 \times 1 + 0$$
Back substitution:
$$1 = 4 - 1 \times 3$$ $$1 = 4 - 1 \times (7 - 1 \times 4) = 2 \times 4 - 1 \times 7$$ $$1 = 2 \times (60 - 8 \times 7) - 1 \times 7 = 2 \times 60 - 17 \times 7$$
So $d = -17 \equiv 60 - 17 = 43 \pmod{60}$.
Verification: $43 \times 7 = 301 = 5 \times 60 + 1 \equiv 1 \pmod{60}$ ✓
$$\boxed{\text{Private Key} = (d, n) = (43, 77)}$$
Part (iii): Ciphertext for M = 6
$$C = M^e \bmod n = 6^7 \bmod 77$$
Using repeated squaring:
$$6^1 = 6$$ $$6^2 = 36$$ $$6^4 = 36^2 = 1296 = 16 \times 77 + 64 \equiv 64 \pmod{77}$$
$$6^7 = 6^4 \times 6^2 \times 6^1 = 64 \times 36 \times 6$$
$$64 \times 36 = 2304 = 29 \times 77 + 71 \equiv 71 \pmod{77}$$ $$71 \times 6 = 426 = 5 \times 77 + 41 \equiv 41 \pmod{77}$$
$$\boxed{C = 41}$$
Summary Table
Parameter Value $n$ 77 $\phi(n)$ 60 Public Key $(e, n)$ (7, 77) Private Key $(d, n)$ (43, 77) Plaintext $M$ 6 Ciphertext $C$ 41 - 210 marksDES encryption and decryptionHideAnswer
Discuss how encryption and decryption is done in the DES algorithm.[10]
DES (Data Encryption Standard) is a symmetric-key block cipher developed by IBM and adopted as a federal standard by NIST in 1977. It encrypts data in 64-bit blocks using a 56-bit key and performs 16 rounds of substitution and permutatio...
- 310 marksSubjects, objects and access rightsHideAnswer
Define subjects, objects and access rights in access control with suitable examples. How role based access control is different from attribute based access control?[10]
Access Control: Subjects, Objects, Access Rights, RBAC vs ABAC
Note: No specific curriculum notes were found for this topic. The following answer is based on standard, correct Computer Science / Information Security principles as taught in BSc CSIT Operating Systems and Information Security courses.
Part 1: Subjects, Objects, and Access Rights in Access Control
1.1 Access Control - Brief Introduction
Access control is a security mechanism that regulates who can use resources in a computing environment. It determines which users (or processes) are allowed to perform which operations on which resources. The three fundamental components of any access control model are: Subjects, Objects, and Access Rights.
1.2 Subjects
A subject is an active entity that requests access to resources or data. Subjects initiate actions and can cause information to flow among objects or change the system state.
Characteristics:
- Subjects are always the initiators of an access request.
- A subject can be a user, a process, or a program acting on behalf of a user.
Examples:
Subject Description A logged-in user (e.g., alice)Requests to read a file A running process (e.g., a web server process) Requests to open a socket An application program Requests to write to a database An OS daemon Requests to access hardware resources Example: When a student logs into a university portal and tries to view their marks, the student (user) is the subject.
1.3 Objects
An object is a passive entity that contains or receives information. Objects are the resources that subjects want to access.
Characteristics:
- Objects do not initiate actions; they are acted upon.
- Objects can be data containers, devices, or services.
Examples:
Object Description Files and directories A text file, a folder Database records A row in a student table Hardware devices Printer, disk drive Memory segments A shared memory block Network resources A socket, a port Programs/executables A compiled binary Example: In the same university portal scenario, the marks database record is the object being accessed.
1.4 Access Rights
Access rights (also called permissions or privileges) define the type of operations a subject is allowed to perform on an object. They form the link between subjects and objects.
Common Access Rights:
Access Right Meaning Read (R) Subject can view/read the object Write (W) Subject can modify the object Execute (X) Subject can run the object as a program Delete (D) Subject can remove the object Create (C) Subject can create new objects Append (A) Subject can add data without modifying existing data Own Subject has full control and can grant rights to others Access Control Matrix Example:
File1.txt Database Printer Alice (Admin) Read, Write, Delete Read, Write Print Bob (Student) Read Read -- Process P1 Read, Execute -- Print Example: Alice has Read and Write rights on
File1.txt, meaning she can open and modify it. Bob has only Read right, so he can view but not change the file.
Part 2: Role-Based Access Control (RBAC) vs Attribute-Based Access Control (ABAC)
2.1 Role-Based Access Control (RBAC)
In RBAC, access decisions are based on the roles assigned to users. A role is a collection of permissions associated with a job function. Users are assigned roles, and roles are assigned permissions.
Key Concepts:
- User --> Role --> Permission (three-tier model)
- Roles represent job functions (e.g., Doctor, Nurse, Manager)
- A user can have multiple roles
- Permissions are attached to roles, not directly to users
Example:
Role: "Doctor" Permissions: Read patient records, Write prescriptions, View lab results Role: "Receptionist" Permissions: Read patient name, Schedule appointments User: Dr. Smith --> Assigned Role: Doctor User: Mary --> Assigned Role: ReceptionistDr. Smith can read patient records because the Doctor role has that permission, not because of any personal attribute.
2.2 Attribute-Based Access Control (ABAC)
In ABAC, access decisions are based on attributes of the subject, object, environment, and the action being performed. It uses policies that evaluate combinations of attributes.
Key Concepts:
- Uses attributes (key-value pairs) of:
- Subject attributes: role, department, clearance level, age
- Object attributes: classification, owner, sensitivity
- Environment attributes: time of day, location, IP address
- Action attributes: read, write, delete
- Policies are written as logical rules combining these attributes
Example:
Policy: "Allow access IF subject.department == 'Cardiology' AND object.type == 'PatientRecord' AND object.ward == 'Cardiology' AND environment.time BETWEEN 08:00 AND 20:00"A doctor in Cardiology can access Cardiology patient records only during working hours.
2.3 Key Differences: RBAC vs ABAC
Feature RBAC ABAC Basis of Decision User's assigned role Combination of attributes (subject, object, environment) Granularity Coarse-grained (role level) Fine-grained (attribute level) Flexibility Less flexible; roles must be predefined Highly flexible; policies can be dynamic Scalability Can suffer from "role explosion" in large systems Scales well without creating many roles Policy Expression Simple (user has role, role has permission) Complex (boolean rules over many attributes) Administration Easy once roles are defined, adding a user means assigning a role Harder, policies must be written, tested and maintained Context Awareness None, a role holds the same permissions at all times and places Full, time, location, device and risk level can all be used Performance Fast, the check is a simple lookup Slower, every request evaluates a policy Standard NIST RBAC model XACML, ABAC policy languages Best Suited For Organisations with stable, well defined job functions Dynamic environments needing fine grained, situation dependent control
Conclusion
Access control rests on three elements: the subject is the active entity that requests access (a user, a process or a device acting on a user's behalf), the object is the passive resource being protected (a file, a table, a printer or a record), and the access right is the operation the subject is permitted to perform on that object (read, write, execute, delete or own). The reference monitor consults the access control policy on every request and permits it only if the triple (subject, object, right) is authorised.
RBAC and ABAC then differ in how that triple is decided. RBAC inserts a role between the user and the permission, so a user is granted a role and the role carries the permissions, which is simple to administer and audit but static. ABAC makes the decision at request time by evaluating a rule over the attributes of the subject, the object, the action and the environment, which gives fine grained and context aware control at the cost of more complex policy management. Many real systems combine the two, using roles as one of the attributes that an ABAC policy tests.
- 45 marksDictionary attacks and authentication issuHideAnswer
How online and offline dictionary attacks are done in password based authentication systems? [5]
Dictionary attacks exploit the fact that users tend to choose weak, predictable passwords. An attacker uses a pre-compiled list of likely passwords (a "dictionary") and systematically tries each one. --- - The attacker directly interacts...
- 55 marksOpen Identity Trust FrameworkHideAnswer
Describe the roles of relying parties, attribute providers and identity providers in Open Identity Trust Framework. [5]
Note: The reference notes did not contain material on this topic. The following answer is based on standard, correct knowledge of the Open Identity Trust Framework (OITF), as used in identity management and federated identity systems. --...
- 65 marksZombies, bots and rootkitsHideAnswer
Define zombies, rootkits and Trojans. [5]
Zombies, Rootkits, and Trojans
Note: No specific reference notes were found for this topic. The following answer is based on standard cybersecurity concepts as taught in BSc CSIT curriculum.
1. Zombies
A zombie (also called a bot) is a compromised computer that has been infected by malware and is secretly controlled by a remote attacker (called a botmaster or bot herder) without the knowledge of the legitimate owner.
Key characteristics:
- The infected machine responds to commands from a Command and Control (C&C) server
- Multiple zombies form a botnet
- Used to carry out DDoS attacks, send spam emails, steal data, or mine cryptocurrency
- The owner of the zombie machine is usually unaware of the malicious activity
2. Rootkits
A rootkit is a collection of malicious software tools designed to gain unauthorized root/administrator-level access to a computer system while hiding its presence from users, administrators, and security software.
Key characteristics:
- Operates at a deep level (kernel level or user level)
- Hides files, processes, registry entries, and network connections
- Very difficult to detect and remove
- Often installed after an attacker has already gained initial access
- Can persist even after system reboots (in some cases)
Types: Kernel-level rootkits, User-level rootkits, Bootloader rootkits
3. Trojans (Trojan Horse)
A Trojan or Trojan Horse is a type of malware that disguises itself as a legitimate or useful program to trick users into installing it, but performs malicious actions in the background.
Key characteristics:
- Named after the Greek mythological Trojan Horse
- Does not self-replicate (unlike viruses or worms)
- Relies on social engineering to deceive users
- Once installed, it can create backdoors, steal passwords, download other malware, or give remote access to attackers
- Common examples: Remote Access Trojans (RATs), banking Trojans
Summary Table
Feature Zombie Rootkit Trojan Primary purpose Remote control for attacks Hide attacker's presence Disguise as legitimate software Self-replicates No No No Controlled remotely Yes (by botmaster) Sometimes Sometimes Detection difficulty Moderate Very High Moderate - 75 marksCyber law status in NepalHideAnswer
Briefly describe the status of cyber law in Nepal. [5]
Note: The reference notes did not contain material on this topic. The following answer is based on standard, publicly known information about cyber law in Nepal, appropriate for a BSc CSIT exam. --- Cyber law refers to the legal framewor...
- 85 marksRisk treatment methodsHideAnswer
Discuss various methods of risk treatment during security risk analysis. [5]
Risk treatment refers to the process of selecting and implementing measures to modify risk. After risks have been identified and assessed, an organization must decide how to handle each risk. There are four main methods of risk treatment...
- 95 marksNumericalS-box operations in DESHideAnswer
What is the use of S-box in DES? Illustrate S-box operation with an example. [5]
S-Box in DES (Data Encryption Standard)
STEP 1 - EXTRACT: Given Data
This is a conceptual/illustrative question. The only numeric data needed comes from the standard DES S-box specification (the S1 table) and a chosen example input. No numeric data is supplied in the question itself, so I use the standard DES S1 table and the classic textbook example input
011011.Standard S1 table (from DES specification):
Row\Col 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 0 14 4 13 1 2 15 11 8 3 10 6 12 5 9 0 7 1 0 15 7 4 14 2 13 1 10 6 12 11 9 5 3 8 2 4 1 14 8 13 6 2 11 15 12 9 7 3 10 5 0 3 15 12 8 2 4 9 1 7 5 11 3 14 10 0 6 13 Example input:
011011
STEP 2 - SOLVE
Use of S-Box in DES
An S-Box (Substitution Box) is the heart of the DES round function and is its only non-linear component. Its purposes are:
- Confusion: It hides the statistical relationship between plaintext, key, and ciphertext (Shannon's confusion principle).
- Non-linearity: Since XOR, permutation, and expansion in DES are all linear, the S-boxes are what make DES resistant to linear and differential cryptanalysis.
- Compression: Each S-box maps a 6-bit input to a 4-bit output, so the 8 S-boxes together reduce 48 bits → 32 bits in each round.
- Avalanche effect: A single-bit change at the input propagates to many output bits, giving DES its cryptographic strength.
DES uses 8 S-boxes (S1-S8), each with its own $4 \times 16$ lookup table.
S-Box Operation Rule
For a 6-bit input $b_1 b_2 b_3 b_4 b_5 b_6$:
- Row = decimal value of the outer bits $b_1 b_6$ (range 0-3)
- Column = decimal value of the middle 4 bits $b_2 b_3 b_4 b_5$ (range 0-15)
- Output = 4-bit binary of the table entry at (row, column)
Worked Example (using S1, input
011011)Bits:
$$b_1 b_2 b_3 b_4 b_5 b_6 = 0;1;1;0;1;1$$
Row = $b_1 b_6 = 01_2 = 1$
Column = $b_2 b_3 b_4 b_5 = 1101_2 = 13$
Lookup:
$$S1[\text{row}=1][\text{col}=13] = 5$$
Output (4-bit):
$$5_{10} = 0101_2$$
Result
$$\boxed{\text{Input } 011011 ;\rightarrow; \text{Output } 0101}$$
Thus a 6-bit block is substituted and compressed into a 4-bit block, providing the essential non-linear confusion in DES.
- 105 marksSHA-2 hash functionHideAnswer
How hash value is generated by the SHA-2 hash function. [5]
Note: No specific reference notes were found for this topic. The following answer is based on standard cryptography curriculum content appropriate for BSc CSIT. --- SHA-2 (Secure Hash Algorithm 2) is a family of cryptographic hash functi...
- 115 marksNumericalPrimality testing algorithmsHideAnswer
Write Rabin Miller Algorithm for primality testing. Test whether 341 is prime or not using the algorithm. [5]
- Number to test: $n = 341$ - Witness base (standard choice): $a = 2$ --- If $n$ is an odd prime, write $n - 1 = 2^s \cdot d$ with $d$ odd. Then for any witness $a$ coprime to $n$, either: $$a^d \equiv 1 \pmod{n} \quad\text{OR}\quad a^{2...
- 125 marksInterception, repudiation and incapacitatiHideAnswer
Define interception, repudiation and incapacitation with examples. [5]
Interception, Repudiation, and Incapacitation
Note: No specific reference notes were found for this topic. The following answer is based on standard Information Security / Computer Security curriculum as taught in BSc CSIT.
1. Interception
Definition: Interception is a security attack in which an unauthorized party gains access to an asset (data, communication, or resource) without the knowledge of the legitimate parties. It is an attack on confidentiality.
Example:
- An attacker uses a packet sniffer on a network to capture and read emails or passwords being transmitted between two users.
- Wiretapping a telephone line to listen to private conversations.
2. Repudiation
Definition: Repudiation is a threat in which a user or entity denies having performed an action or transaction that actually took place. It is an attack on non-repudiation (the inability to deny an action). It can be either:
- Sender repudiation: The sender denies sending a message.
- Receiver repudiation: The receiver denies receiving a message.
Example:
- A customer places an online order and later denies having placed it to avoid payment.
- A user sends a malicious message and later claims they never sent it.
3. Incapacitation
Definition: Incapacitation is an attack that destroys or disables a system component or resource, making it unavailable to legitimate users. It is an attack on availability.
Example:
- A Denial of Service (DoS) attack that floods a web server with excessive requests, causing it to crash and become unavailable to genuine users.
- Physically destroying a hard disk or deleting critical system files so that the system cannot function.
Summary Table
Attack Security Property Violated Nature Interception Confidentiality Passive / Active Repudiation Non-repudiation Active Incapacitation Availability Active