2081

BIT303 · TU past paper

Information Security 2081 question paper

The complete TU 2081 exam paper for Information Security (BIT303), all 12 questions with solved model answers written to the mark scheme.

Past Papers2082208120802079

Tap a question to open its answer.

  1. 110 marksNumericalRSA algorithm and key generationAnswer

    RSA Cryptosystem with p=11 and q=7

    Consider p=11 and q=7 in a RSA cryptosystem.

    i. What is a public key pair (e, n)?

    ii. What is a private key pair (d, n)?

    iii. What is ciphertext for M=6? [10]

    RSA Cryptosystem: p = 11, q = 7

    Given Data

    • $p = 11$ (prime)
    • $q = 7$ (prime)
    • Message $M = 6$

    Step A: Compute n and φ(n)

    $$n = p \times q = 11 \times 7 = 77$$

    $$\phi(n) = (p-1)(q-1) = 10 \times 6 = 60$$


    Part (i): Public Key Pair (e, n)

    Choose $e$ with $1 < e < \phi(n)$ and $\gcd(e, \phi(n)) = 1$.

    Try $e = 7$: $$\gcd(7, 60) = 1 \quad \checkmark$$

    $$\boxed{\text{Public Key} = (e, n) = (7, 77)}$$

    Note: $e$ is not unique; other valid choices include 11, 13 and 17. We use $e = 7$ here.


    Part (ii): Private Key Pair (d, n)

    Find $d$ such that $d \times 7 \equiv 1 \pmod{60}$.

    Extended Euclidean Algorithm:

    $$60 = 8 \times 7 + 4$$ $$7 = 1 \times 4 + 3$$ $$4 = 1 \times 3 + 1$$ $$3 = 3 \times 1 + 0$$

    Back substitution:

    $$1 = 4 - 1 \times 3$$ $$1 = 4 - 1 \times (7 - 1 \times 4) = 2 \times 4 - 1 \times 7$$ $$1 = 2 \times (60 - 8 \times 7) - 1 \times 7 = 2 \times 60 - 17 \times 7$$

    So $d = -17 \equiv 60 - 17 = 43 \pmod{60}$.

    Verification: $43 \times 7 = 301 = 5 \times 60 + 1 \equiv 1 \pmod{60}$ ✓

    $$\boxed{\text{Private Key} = (d, n) = (43, 77)}$$


    Part (iii): Ciphertext for M = 6

    $$C = M^e \bmod n = 6^7 \bmod 77$$

    Using repeated squaring:

    $$6^1 = 6$$ $$6^2 = 36$$ $$6^4 = 36^2 = 1296 = 16 \times 77 + 64 \equiv 64 \pmod{77}$$

    $$6^7 = 6^4 \times 6^2 \times 6^1 = 64 \times 36 \times 6$$

    $$64 \times 36 = 2304 = 29 \times 77 + 71 \equiv 71 \pmod{77}$$ $$71 \times 6 = 426 = 5 \times 77 + 41 \equiv 41 \pmod{77}$$

    $$\boxed{C = 41}$$


    Summary Table

    ParameterValue
    $n$77
    $\phi(n)$60
    Public Key $(e, n)$(7, 77)
    Private Key $(d, n)$(43, 77)
    Plaintext $M$6
    Ciphertext $C$41
  2. 210 marksDES encryption and decryptionAnswer

    Discuss how encryption and decryption is done in the DES algorithm.[10]

    DES (Data Encryption Standard) is a symmetric-key block cipher developed by IBM and adopted as a federal standard by NIST in 1977. It encrypts data in 64-bit blocks using a 56-bit key and performs 16 rounds of substitution and permutatio...

  3. 310 marksSubjects, objects and access rightsAnswer

    Define subjects, objects and access rights in access control with suitable examples. How role based access control is different from attribute based access control?[10]

    Access Control: Subjects, Objects, Access Rights, RBAC vs ABAC

    Note: No specific curriculum notes were found for this topic. The following answer is based on standard, correct Computer Science / Information Security principles as taught in BSc CSIT Operating Systems and Information Security courses.


    Part 1: Subjects, Objects, and Access Rights in Access Control

    1.1 Access Control - Brief Introduction

    Access control is a security mechanism that regulates who can use resources in a computing environment. It determines which users (or processes) are allowed to perform which operations on which resources. The three fundamental components of any access control model are: Subjects, Objects, and Access Rights.


    1.2 Subjects

    A subject is an active entity that requests access to resources or data. Subjects initiate actions and can cause information to flow among objects or change the system state.

    Characteristics:

    • Subjects are always the initiators of an access request.
    • A subject can be a user, a process, or a program acting on behalf of a user.

    Examples:

    SubjectDescription
    A logged-in user (e.g., alice)Requests to read a file
    A running process (e.g., a web server process)Requests to open a socket
    An application programRequests to write to a database
    An OS daemonRequests to access hardware resources

    Example: When a student logs into a university portal and tries to view their marks, the student (user) is the subject.


    1.3 Objects

    An object is a passive entity that contains or receives information. Objects are the resources that subjects want to access.

    Characteristics:

    • Objects do not initiate actions; they are acted upon.
    • Objects can be data containers, devices, or services.

    Examples:

    ObjectDescription
    Files and directoriesA text file, a folder
    Database recordsA row in a student table
    Hardware devicesPrinter, disk drive
    Memory segmentsA shared memory block
    Network resourcesA socket, a port
    Programs/executablesA compiled binary

    Example: In the same university portal scenario, the marks database record is the object being accessed.


    1.4 Access Rights

    Access rights (also called permissions or privileges) define the type of operations a subject is allowed to perform on an object. They form the link between subjects and objects.

    Common Access Rights:

    Access RightMeaning
    Read (R)Subject can view/read the object
    Write (W)Subject can modify the object
    Execute (X)Subject can run the object as a program
    Delete (D)Subject can remove the object
    Create (C)Subject can create new objects
    Append (A)Subject can add data without modifying existing data
    OwnSubject has full control and can grant rights to others

    Access Control Matrix Example:

    File1.txtDatabasePrinter
    Alice (Admin)Read, Write, DeleteRead, WritePrint
    Bob (Student)ReadRead--
    Process P1Read, Execute--Print

    Example: Alice has Read and Write rights on File1.txt, meaning she can open and modify it. Bob has only Read right, so he can view but not change the file.


    Part 2: Role-Based Access Control (RBAC) vs Attribute-Based Access Control (ABAC)

    2.1 Role-Based Access Control (RBAC)

    In RBAC, access decisions are based on the roles assigned to users. A role is a collection of permissions associated with a job function. Users are assigned roles, and roles are assigned permissions.

    Key Concepts:

    • User --> Role --> Permission (three-tier model)
    • Roles represent job functions (e.g., Doctor, Nurse, Manager)
    • A user can have multiple roles
    • Permissions are attached to roles, not directly to users

    Example:

    Role: "Doctor"
      Permissions: Read patient records, Write prescriptions, View lab results
    
    Role: "Receptionist"
      Permissions: Read patient name, Schedule appointments
    
    User: Dr. Smith  --> Assigned Role: Doctor
    User: Mary       --> Assigned Role: Receptionist
    

    Dr. Smith can read patient records because the Doctor role has that permission, not because of any personal attribute.


    2.2 Attribute-Based Access Control (ABAC)

    In ABAC, access decisions are based on attributes of the subject, object, environment, and the action being performed. It uses policies that evaluate combinations of attributes.

    Key Concepts:

    • Uses attributes (key-value pairs) of:
      • Subject attributes: role, department, clearance level, age
      • Object attributes: classification, owner, sensitivity
      • Environment attributes: time of day, location, IP address
      • Action attributes: read, write, delete
    • Policies are written as logical rules combining these attributes

    Example:

    Policy: "Allow access IF
      subject.department == 'Cardiology'
      AND object.type == 'PatientRecord'
      AND object.ward == 'Cardiology'
      AND environment.time BETWEEN 08:00 AND 20:00"
    

    A doctor in Cardiology can access Cardiology patient records only during working hours.


    2.3 Key Differences: RBAC vs ABAC

    FeatureRBACABAC
    Basis of DecisionUser's assigned roleCombination of attributes (subject, object, environment)
    GranularityCoarse-grained (role level)Fine-grained (attribute level)
    FlexibilityLess flexible; roles must be predefinedHighly flexible; policies can be dynamic
    ScalabilityCan suffer from "role explosion" in large systemsScales well without creating many roles
    Policy ExpressionSimple (user has role, role has permission)Complex (boolean rules over many attributes)
    AdministrationEasy once roles are defined, adding a user means assigning a roleHarder, policies must be written, tested and maintained
    Context AwarenessNone, a role holds the same permissions at all times and placesFull, time, location, device and risk level can all be used
    PerformanceFast, the check is a simple lookupSlower, every request evaluates a policy
    StandardNIST RBAC modelXACML, ABAC policy languages
    Best Suited ForOrganisations with stable, well defined job functionsDynamic environments needing fine grained, situation dependent control

    Conclusion

    Access control rests on three elements: the subject is the active entity that requests access (a user, a process or a device acting on a user's behalf), the object is the passive resource being protected (a file, a table, a printer or a record), and the access right is the operation the subject is permitted to perform on that object (read, write, execute, delete or own). The reference monitor consults the access control policy on every request and permits it only if the triple (subject, object, right) is authorised.

    RBAC and ABAC then differ in how that triple is decided. RBAC inserts a role between the user and the permission, so a user is granted a role and the role carries the permissions, which is simple to administer and audit but static. ABAC makes the decision at request time by evaluating a rule over the attributes of the subject, the object, the action and the environment, which gives fine grained and context aware control at the cost of more complex policy management. Many real systems combine the two, using roles as one of the attributes that an ABAC policy tests.

  4. 45 marksDictionary attacks and authentication issuAnswer

    How online and offline dictionary attacks are done in password based authentication systems? [5]

    Dictionary attacks exploit the fact that users tend to choose weak, predictable passwords. An attacker uses a pre-compiled list of likely passwords (a "dictionary") and systematically tries each one. --- - The attacker directly interacts...

  5. 55 marksOpen Identity Trust FrameworkAnswer

    Describe the roles of relying parties, attribute providers and identity providers in Open Identity Trust Framework. [5]

    Note: The reference notes did not contain material on this topic. The following answer is based on standard, correct knowledge of the Open Identity Trust Framework (OITF), as used in identity management and federated identity systems. --...

  6. 65 marksZombies, bots and rootkitsAnswer

    Define zombies, rootkits and Trojans. [5]

    Zombies, Rootkits, and Trojans

    Note: No specific reference notes were found for this topic. The following answer is based on standard cybersecurity concepts as taught in BSc CSIT curriculum.


    1. Zombies

    A zombie (also called a bot) is a compromised computer that has been infected by malware and is secretly controlled by a remote attacker (called a botmaster or bot herder) without the knowledge of the legitimate owner.

    Key characteristics:

    • The infected machine responds to commands from a Command and Control (C&C) server
    • Multiple zombies form a botnet
    • Used to carry out DDoS attacks, send spam emails, steal data, or mine cryptocurrency
    • The owner of the zombie machine is usually unaware of the malicious activity

    2. Rootkits

    A rootkit is a collection of malicious software tools designed to gain unauthorized root/administrator-level access to a computer system while hiding its presence from users, administrators, and security software.

    Key characteristics:

    • Operates at a deep level (kernel level or user level)
    • Hides files, processes, registry entries, and network connections
    • Very difficult to detect and remove
    • Often installed after an attacker has already gained initial access
    • Can persist even after system reboots (in some cases)

    Types: Kernel-level rootkits, User-level rootkits, Bootloader rootkits


    3. Trojans (Trojan Horse)

    A Trojan or Trojan Horse is a type of malware that disguises itself as a legitimate or useful program to trick users into installing it, but performs malicious actions in the background.

    Key characteristics:

    • Named after the Greek mythological Trojan Horse
    • Does not self-replicate (unlike viruses or worms)
    • Relies on social engineering to deceive users
    • Once installed, it can create backdoors, steal passwords, download other malware, or give remote access to attackers
    • Common examples: Remote Access Trojans (RATs), banking Trojans

    Summary Table

    FeatureZombieRootkitTrojan
    Primary purposeRemote control for attacksHide attacker's presenceDisguise as legitimate software
    Self-replicatesNoNoNo
    Controlled remotelyYes (by botmaster)SometimesSometimes
    Detection difficultyModerateVery HighModerate
  7. 75 marksCyber law status in NepalAnswer

    Briefly describe the status of cyber law in Nepal. [5]

    Note: The reference notes did not contain material on this topic. The following answer is based on standard, publicly known information about cyber law in Nepal, appropriate for a BSc CSIT exam. --- Cyber law refers to the legal framewor...

  8. 85 marksRisk treatment methodsAnswer

    Discuss various methods of risk treatment during security risk analysis. [5]

    Risk treatment refers to the process of selecting and implementing measures to modify risk. After risks have been identified and assessed, an organization must decide how to handle each risk. There are four main methods of risk treatment...

  9. 95 marksNumericalS-box operations in DESAnswer

    What is the use of S-box in DES? Illustrate S-box operation with an example. [5]

    S-Box in DES (Data Encryption Standard)

    STEP 1 - EXTRACT: Given Data

    This is a conceptual/illustrative question. The only numeric data needed comes from the standard DES S-box specification (the S1 table) and a chosen example input. No numeric data is supplied in the question itself, so I use the standard DES S1 table and the classic textbook example input 011011.

    Standard S1 table (from DES specification):

    Row\Col0123456789101112131415
    01441312151183106125907
    10157414213110612119538
    24114813621115129731050
    31512824917511314100613

    Example input: 011011


    STEP 2 - SOLVE

    Use of S-Box in DES

    An S-Box (Substitution Box) is the heart of the DES round function and is its only non-linear component. Its purposes are:

    1. Confusion: It hides the statistical relationship between plaintext, key, and ciphertext (Shannon's confusion principle).
    2. Non-linearity: Since XOR, permutation, and expansion in DES are all linear, the S-boxes are what make DES resistant to linear and differential cryptanalysis.
    3. Compression: Each S-box maps a 6-bit input to a 4-bit output, so the 8 S-boxes together reduce 48 bits → 32 bits in each round.
    4. Avalanche effect: A single-bit change at the input propagates to many output bits, giving DES its cryptographic strength.

    DES uses 8 S-boxes (S1-S8), each with its own $4 \times 16$ lookup table.

    S-Box Operation Rule

    For a 6-bit input $b_1 b_2 b_3 b_4 b_5 b_6$:

    • Row = decimal value of the outer bits $b_1 b_6$ (range 0-3)
    • Column = decimal value of the middle 4 bits $b_2 b_3 b_4 b_5$ (range 0-15)
    • Output = 4-bit binary of the table entry at (row, column)

    Worked Example (using S1, input 011011)

    Bits:

    $$b_1 b_2 b_3 b_4 b_5 b_6 = 0;1;1;0;1;1$$

    Row = $b_1 b_6 = 01_2 = 1$

    Column = $b_2 b_3 b_4 b_5 = 1101_2 = 13$

    Lookup:

    $$S1[\text{row}=1][\text{col}=13] = 5$$

    Output (4-bit):

    $$5_{10} = 0101_2$$

    Result

    $$\boxed{\text{Input } 011011 ;\rightarrow; \text{Output } 0101}$$

    Thus a 6-bit block is substituted and compressed into a 4-bit block, providing the essential non-linear confusion in DES.

  10. 105 marksSHA-2 hash functionAnswer

    How hash value is generated by the SHA-2 hash function. [5]

    Note: No specific reference notes were found for this topic. The following answer is based on standard cryptography curriculum content appropriate for BSc CSIT. --- SHA-2 (Secure Hash Algorithm 2) is a family of cryptographic hash functi...

  11. 115 marksNumericalPrimality testing algorithmsAnswer

    Write Rabin Miller Algorithm for primality testing. Test whether 341 is prime or not using the algorithm. [5]

    • Number to test: $n = 341$ - Witness base (standard choice): $a = 2$ --- If $n$ is an odd prime, write $n - 1 = 2^s \cdot d$ with $d$ odd. Then for any witness $a$ coprime to $n$, either: $$a^d \equiv 1 \pmod{n} \quad\text{OR}\quad a^{2...
  12. 125 marksInterception, repudiation and incapacitatiAnswer

    Define interception, repudiation and incapacitation with examples. [5]

    Interception, Repudiation, and Incapacitation

    Note: No specific reference notes were found for this topic. The following answer is based on standard Information Security / Computer Security curriculum as taught in BSc CSIT.


    1. Interception

    Definition: Interception is a security attack in which an unauthorized party gains access to an asset (data, communication, or resource) without the knowledge of the legitimate parties. It is an attack on confidentiality.

    Example:

    • An attacker uses a packet sniffer on a network to capture and read emails or passwords being transmitted between two users.
    • Wiretapping a telephone line to listen to private conversations.

    2. Repudiation

    Definition: Repudiation is a threat in which a user or entity denies having performed an action or transaction that actually took place. It is an attack on non-repudiation (the inability to deny an action). It can be either:

    • Sender repudiation: The sender denies sending a message.
    • Receiver repudiation: The receiver denies receiving a message.

    Example:

    • A customer places an online order and later denies having placed it to avoid payment.
    • A user sends a malicious message and later claims they never sent it.

    3. Incapacitation

    Definition: Incapacitation is an attack that destroys or disables a system component or resource, making it unavailable to legitimate users. It is an attack on availability.

    Example:

    • A Denial of Service (DoS) attack that floods a web server with excessive requests, causing it to crash and become unavailable to genuine users.
    • Physically destroying a hard disk or deleting critical system files so that the system cannot function.

    Summary Table

    AttackSecurity Property ViolatedNature
    InterceptionConfidentialityPassive / Active
    RepudiationNon-repudiationActive
    IncapacitationAvailabilityActive