BIT303 · TU past paper
Information Security 2082 question paper
The complete TU 2082 exam paper for Information Security (BIT303), all 12 questions with solved model answers written to the mark scheme.
Tap a question to open its answer.
- 1Substitution and transposition ciphersHideAnswer
Distinction between Substitution and Transposition Cipher, DES Sub-Key Generation, and Finite Fields
--- Feature Substitution Cipher Transposition Cipher --------- Basic Operation Replaces each plaintext character with another character Rearranges (permutes) the positions of plaintext characters Character Identity Characters change thei...
- 210 marksMessage authentication purposesHideAnswer
What are the purposes of message authentication? Explain the working mechanism of MD5.[10]
Message Authentication: Purposes and MD5 Working Mechanism
Part 1: Purposes of Message Authentication
Message authentication is a mechanism used to verify the integrity and origin of a message. The main purposes are:
1. Message Integrity
Ensures that the message has not been altered (accidentally or intentionally) during transmission. The receiver can verify that the received message is exactly what was sent.
2. Message Authentication (Source Verification)
Confirms that the message actually came from the claimed sender and not from an imposter or attacker.
3. Non-repudiation
Prevents the sender from later denying that they sent the message. This is important in legal and financial transactions.
4. Protection Against Masquerade
Prevents an unauthorized party from pretending to be a legitimate sender and injecting false messages.
5. Protection Against Replay Attack
Ensures that a previously sent valid message cannot be captured and retransmitted by an attacker to produce an unauthorized effect.
6. Protection Against Modification
Detects any unauthorized changes to the content, sequence, or timing of a message.
7. Sequence Control
Ensures messages are received in the correct order and none are missing or duplicated.
Part 2: MD5 (Message Digest 5) - Working Mechanism
MD5 was designed by Ronald Rivest in 1991. It produces a 128-bit (16-byte) message digest from an input message of arbitrary length.
Overview
Input Message (any length) | v [Padding + Length] | v [512-bit Blocks] | v [4 Rounds of Processing per Block] | v 128-bit Message Digest
Step-by-Step Working of MD5
Step 1: Append Padding Bits
- The original message is padded so that its length becomes congruent to 448 mod 512.
- Padding is always added, even if the message is already the right length.
- Padding consists of a single '1' bit followed by as many '0' bits as needed.
Padded Length ≡ 448 (mod 512)Step 2: Append Length
- A 64-bit representation of the original message length (before padding) is appended.
- This makes the total message length a multiple of 512 bits.
Total Length = Multiple of 512 bitsStep 3: Initialize MD Buffer (Initial Hash Values)
MD5 uses a 128-bit buffer divided into four 32-bit registers:
Register Initial Value (hex) A 67452301 B EFCDAB89 C 98BADCFE D 10325476 These are fixed constants (little-endian format).
Step 4: Process Message in 512-bit Blocks
Each 512-bit block is divided into sixteen 32-bit sub-blocks (M[0] to M[15]).
Each block goes through 4 rounds, and each round has 16 operations (total = 64 operations per block).
Four Auxiliary (Non-linear) Functions:
Round Function Formula 1 F(B,C,D) (B AND C) OR (NOT B AND D) 2 G(B,C,D) (B AND D) OR (C AND NOT D) 3 H(B,C,D) B XOR C XOR D 4 I(B,C,D) C XOR (B OR NOT D) Each Operation:
Each of the 64 operations follows this general form:
a = b + ((a + F(b,c,d) + M[k] + T[i]) <<< s)Where:
a, b, c, dare the four registers (rotated each step)Fis the round function (F, G, H, or I)M[k]is a 32-bit sub-block of the messageT[i]is a constant derived from|sin(i)| × 2^32(precomputed table of 64 constants)<<<denotes left circular shift bysbitssis a per-step shift amount
Step 5: Update Buffer
After processing each 512-bit block, the output of the four rounds is added to the previous buffer values:
A = A + AA B = B + BB C = C + CC D = D + DDWhere AA, BB, CC, DD are the saved values of A, B, C, D before processing the block.
Step 6: Output
After all blocks are processed, the 128-bit message digest is the concatenation of registers:
MD5 Digest = A || B || C || D (128 bits)
Summary Diagram of MD5
Message | +---> Padding (to 448 mod 512) + 64-bit length | +---> Divide into 512-bit blocks | For each block: | +----+----+----+----+ | A | B | C | D | <-- 128-bit buffer +----+----+----+----+ | Round 1 (16 ops using F) Round 2 (16 ops using G) Round 3 (16 ops using H) Round 4 (16 ops using I) | Add to previous A,B,C,D | Final Output: 128-bit Digest
Key Properties of MD5
Property Value Output size 128 bits Block size 512 bits Number of rounds - 310 marksMalicious software definition and typesHideAnswer
Define malicious software. Explain the different types of malicious softwares.[10]
Malicious Software: Definition and Types
Definition of Malicious Software
Malicious software (Malware) is any software program that is intentionally designed to gain unauthorized access to a computer system, disrupt normal operations, steal sensitive information, or cause damage to hardware, software, or data without the knowledge or consent of the user.
Malware is created by attackers, hackers, or cybercriminals with harmful intent. It can spread through email attachments, infected websites, removable media, network connections, and software downloads.
Types of Malicious Software
1. Virus
- A virus is a self-replicating program that attaches itself to legitimate executable files or programs.
- It activates when the infected program is executed and spreads to other files.
- It can corrupt or delete files, slow down the system, and cause data loss.
- Example: File infector virus, Boot sector virus.
- Key feature: Requires a host program to spread.
2. Worm
- A worm is a standalone malicious program that replicates itself and spreads across networks without needing a host file.
- Unlike viruses, worms do not need to attach to an existing program.
- They consume network bandwidth and system resources.
- Example: Morris Worm, ILOVEYOU worm.
- Key feature: Self-propagating through networks.
3. Trojan Horse
- A Trojan horse is a program that appears to be legitimate and useful software but contains hidden malicious code.
- It does not self-replicate but tricks users into installing it.
- Once installed, it can create backdoors, steal data, or allow remote access.
- Example: Remote Access Trojans (RATs), Banking Trojans.
- Key feature: Disguised as legitimate software.
4. Spyware
- Spyware is software that secretly monitors and collects user information without their knowledge.
- It tracks browsing habits, keystrokes, passwords, and personal data and sends it to a third party.
- It often comes bundled with free software downloads.
- Example: Keyloggers, adware with tracking capabilities.
- Key feature: Operates silently in the background.
5. Adware
- Adware is software that automatically displays or downloads unwanted advertisements on a user's computer.
- While not always harmful, it can slow down the system and redirect browsers.
- Some adware also acts as spyware by tracking user behavior.
- Example: Pop-up generators, browser hijackers.
- Key feature: Generates unwanted advertisements.
6. Ransomware
- Ransomware is malware that encrypts the victim's files or locks the system and demands a ransom payment (usually in cryptocurrency) to restore access.
- It is one of the most dangerous and financially damaging types of malware.
- Example: WannaCry, CryptoLocker.
- Key feature: Encrypts data and demands payment.
7. Rootkit
- A rootkit is a collection of tools that allows an attacker to gain administrator-level (root) access to a computer while hiding its presence.
- It modifies the operating system to conceal malicious activity.
- Very difficult to detect and remove.
- Example: NTRootkit, Azazel.
- Key feature: Hides itself and other malware from detection.
8. Backdoor
- A backdoor is a hidden method of bypassing normal authentication to gain unauthorized access to a system.
- It can be installed by a Trojan or created by the software developer intentionally or unintentionally.
- Allows attackers to remotely control the system.
- Key feature: Provides unauthorized remote access.
9. Logic Bomb
- A logic bomb is malicious code that remains dormant until a specific condition or trigger event occurs (e.g., a specific date, time, or user action).
- Once triggered, it executes its payload, which may delete files or crash the system.
- Example: A disgruntled employee planting code to activate on termination date.
- Key feature: Triggered by a specific event or condition.
10. Keylogger
- A keylogger records every keystroke made by a user on the keyboard.
- It captures passwords, credit card numbers, and other sensitive information.
- Can be software-based or hardware-based.
- Key feature: Records keystrokes to steal credentials.
Summary Table
Type Self-Replicates Needs Host Main Purpose Virus Yes Yes Corrupt files Worm Yes No Spread via network Trojan No No Backdoor/data theft Spyware No No Steal information Ransomware No No Extort money Rootkit No No Hide malware Logic Bomb No Yes Triggered damage Keylogger No No Capture keystrokes
Conclusion
Malicious software poses a serious threat to individuals, organizations, and governments. Understanding the different types of malware is essential for implementing effective security measures such as antivirus software, firewalls, regular updates, and user awareness training to protect computer systems and sensitive data.
- 45 marksNumericalFinite fields and polynomial operationsHideAnswer
Perform polynomial addition, subtraction and multiplication of $2x^2 + 4x + 2$ and $5x + 6$ over $GF(7)$. [5]
Polynomial Arithmetic over GF(7)
Step 1 - Extract (Given Data)
$$A(x) = 2x^2 + 4x + 2$$ $$B(x) = 5x + 6$$
Field: $GF(7)$, so all coefficients reduced $\bmod 7$.
Coefficient vectors:
- $A: [x^2, x^1, x^0] = [2, 4, 2]$
- $B: [x^2, x^1, x^0] = [0, 5, 6]$
Step 2 - Solve
1. Addition $A(x) + B(x)$
Degree A B Sum mod 7 $x^2$ 2 0 2 2 $x^1$ 4 5 9 2 $x^0$ 2 6 8 1 $$\boxed{A(x) + B(x) = 2x^2 + 2x + 1}$$
2. Subtraction $A(x) - B(x)$
Degree A B Diff mod 7 $x^2$ 2 0 2 2 $x^1$ 4 5 -1 6 $x^0$ 2 6 -4 3 $$\boxed{A(x) - B(x) = 2x^2 + 6x + 3}$$
3. Multiplication $A(x) \times B(x)$
Expand: $$(2x^2 + 4x + 2)(5x + 6)$$ $$= 10x^3 + 12x^2 + 20x^2 + 24x + 10x + 12$$
Collect: $$= 10x^3 + 32x^2 + 34x + 12$$
Reduce $\bmod 7$:
Degree Raw mod 7 $x^3$ 10 3 $x^2$ 32 4 $x^1$ 34 6 $x^0$ 12 5 $$\boxed{A(x) \times B(x) = 3x^3 + 4x^2 + 6x + 5}$$
Summary
Operation Result over $GF(7)$ $A + B$ $2x^2 + 2x + 1$ $A - B$ $2x^2 + 6x + 3$ $A \times B$ $3x^3 + 4x^2 + 6x + 5$ - 55 marksThreats, attacks and assetsHideAnswer
Explain about threats, attacks and assets. [5]
Assets are the valuable resources of a system or organization that need to be protected. They include: Type Examples --------------- Hardware Computers, servers, routers, storage devices Software Operating systems, application programs, ...
- 65 marksTwo-factor authenticationHideAnswer
Why do we need two factor authentication? Discuss about security issues for user authentication. [5]
Single-factor authentication (typically a password) has several weaknesses that make it insufficient for secure systems. Two-factor authentication addresses these by requiring two independent forms of verification before granting access....
- 75 marksRole-based access controlHideAnswer
Differentiate between role based and attribute based access controls. [5]
Note: The reference notes did not contain this topic directly. The following answer is based on standard, correct information from access control theory as taught in security and operating systems courses. --- RBAC grants or restricts ac...
- 85 marksSecurity auditing architectureHideAnswer
Explain the security auditing architecture. [5]
Note: The reference notes did not contain this topic. The following answer is based on standard, correct information from the security and operating systems domain, appropriate for BSc CSIT curriculum. --- Security auditing is the system...
- 95 marksCybercrime and computer crimeHideAnswer
Define cybercrime and computer crime. Discuss about intellectual property. [5]
Cybercrime, Computer Crime, and Intellectual Property
Cybercrime
Cybercrime refers to any criminal activity that involves a computer, networked device, or a network as the primary tool or target. It includes crimes committed over the internet or through digital means such as hacking, phishing, identity theft, online fraud, cyberstalking, and spreading malware.
Example: Unauthorized access to someone's email account or stealing credit card information online.
Computer Crime
Computer crime (also called computer-related crime) refers to any illegal act in which a computer is used as a tool, target, or place of criminal activity. It is a broader term that includes both online and offline misuse of computers.
Example: Using a computer to forge documents, unauthorized copying of software, or destroying data stored on a computer.
Key Difference
Cybercrime Computer Crime Primarily involves the internet/network May or may not involve a network Subset of computer crime Broader category e.g., phishing, DDoS attacks e.g., software piracy, data manipulation
Intellectual Property (IP)
Intellectual Property refers to creations of the mind -- inventions, literary and artistic works, designs, symbols, names, and images used in commerce -- that are protected by law.
Types of Intellectual Property
-
Copyright
- Protects original creative works such as books, music, software, films, and artwork.
- Gives the creator exclusive rights to reproduce, distribute, and display the work.
- Example: Source code of a software program is protected by copyright.
-
Patent
- Grants an inventor exclusive rights to make, use, or sell an invention for a limited period (usually 20 years).
- Example: A new algorithm or hardware design.
-
Trademark
- Protects brand names, logos, and symbols that distinguish goods/services of one entity from another.
- Example: The logo of a software company.
-
Trade Secret
- Confidential business information that provides a competitive edge.
- Example: Google's search algorithm.
Intellectual Property in the Context of Computers
- Software Piracy: Unauthorized copying or distribution of software violates copyright law.
- Digital Piracy: Illegal downloading or sharing of music, movies, and e-books.
- Plagiarism: Using someone else's code or content without proper attribution.
Importance of Protecting IP
- Encourages innovation and creativity.
- Provides economic benefits to creators and developers.
- Ensures fair competition in the market.
- Protects consumers from counterfeit products.
-
- 105 marksAttack trees and threat modelingHideAnswer
What is attack tree? Describe about password based authentication. [5]
Attack Tree and Password-Based Authentication
Attack Tree
An attack tree is a conceptual diagram that models the various ways an attacker can compromise a system or achieve a malicious goal. It provides a formal, structured methodology for describing the security of systems based on varying attacks.
Structure
- The root node represents the goal of the attack (e.g., "Gain unauthorized access").
- Child nodes represent sub-goals or methods to achieve the parent goal.
- Nodes are connected using:
- AND nodes: All child conditions must be satisfied.
- OR nodes: Any one child condition is sufficient.
Example
Goal: Break into a system OR ├── Guess Password │ AND │ ├── Know username │ └── Try common passwords ├── Steal Password └── Exploit vulnerabilityBenefits
- Helps in threat modeling and risk assessment.
- Allows security teams to prioritize defenses.
- Provides a visual and systematic view of possible attack paths.
Password-Based Authentication
Password-based authentication is the most widely used method of verifying a user's identity. The user provides a username and a secret password, which the system verifies against stored credentials.
How It Works
- User enters username and password.
- System looks up the stored (hashed) password for that username.
- The entered password is hashed and compared with the stored hash.
- If they match, access is granted; otherwise, it is denied.
Password Storage
- Passwords are never stored in plaintext.
- A one-way hash function (e.g., SHA-256, bcrypt) is applied.
- A salt (random value) is added before hashing to prevent dictionary and rainbow table attacks.
Stored value = Hash(password + salt)
Common Attacks on Passwords
Attack Description Dictionary Attack Tries common words/passwords Brute Force Attack Tries all possible combinations Rainbow Table Attack Uses precomputed hash tables Phishing Tricks users into revealing passwords Shoulder Surfing Observing the user while typing Countermeasures
- Use salted hashing (bcrypt, Argon2).
- Enforce strong password policies (length, complexity).
- Implement account lockout after failed attempts.
- Use multi-factor authentication (MFA) alongside passwords.
- Encourage use of password managers.
Limitations
- Users tend to choose weak or reusable passwords.
- Vulnerable to social engineering.
- Does not provide non-repudiation on its own.
- 115 marksSubjects, objects and access rightsHideAnswer
What do you mean by subjects, objects and access rights? Discuss about ethical issues in cyber security. [2.5+2.5]
Subjects, Objects, and Access Rights + Ethical Issues in Cyber Security
(a) Subjects, Objects, and Access Rights
Subject
A subject is an active entity that requests access to resources or objects in a system. Subjects are typically users, processes, or programs that initiate actions.
Examples:
- A logged-in user requesting a file
- A running process trying to read memory
- An application accessing a database
Object
An object is a passive entity that contains or receives information, and to which access is controlled.
Examples:
- Files, directories, databases
- Memory segments, printers, network ports
- Records in a database
Access Rights
Access rights (also called permissions or privileges) define the operations that a subject is allowed to perform on an object. They form the basis of access control policies.
Common Access Rights include:
Access Right Description Read (R) Subject can read/view the object Write (W) Subject can modify the object Execute (X) Subject can run the object as a program Delete (D) Subject can remove the object Create (C) Subject can create new objects Append (A) Subject can add data to the object Relationship
The relationship among subjects, objects, and access rights is often represented using an Access Control Matrix, where:
- Rows represent subjects
- Columns represent objects
- Cells contain the access rights
Example:
File A File B Printer User1 R, W R Execute User2 R R, W -
(b) Ethical Issues in Cyber Security
Ethics in cyber security refers to the moral principles and standards that guide the behavior of individuals and organizations in the digital environment.
1. Privacy and Surveillance
- Collecting, monitoring, or tracking user data without consent raises serious ethical concerns.
- Organizations must balance security monitoring with the right to individual privacy.
- Example: Employers monitoring employee emails without disclosure.
2. Unauthorized Access (Hacking)
- Accessing systems without permission is both illegal and unethical, even if done with "good intentions" (e.g., grey-hat hacking).
- Ethical hacking (penetration testing) must be done only with explicit authorization.
3. Intellectual Property and Software Piracy
- Copying, distributing, or using software without proper licensing is unethical and illegal.
- Respecting copyrights and licenses is a fundamental ethical obligation.
4. Data Integrity and Honesty
- Manipulating, falsifying, or destroying data is unethical.
- Security professionals must ensure data accuracy and report vulnerabilities honestly.
5. Responsible Disclosure
- When a security researcher discovers a vulnerability, there is an ethical obligation to report it responsibly to the vendor before making it public, giving time for a fix.
- Selling vulnerabilities to malicious actors is highly unethical.
6. Cybercrime and Malware Development
- Creating and distributing malware, ransomware, or viruses to harm others is deeply unethical and criminal.
7. Social Engineering and Deception
- Using deception to manipulate people into revealing confidential information (phishing, pretexting) is unethical.
8. Professional Responsibility
- Security professionals have an ethical duty to protect user data, maintain confidentiality, and act in the public interest.
- Organizations must follow ethical guidelines such as those provided by ACM Code of Ethics or (ISC)2 Code of Ethics.
9. Equity and Access
- Denying access to digital resources based on discrimination is unethical.
- Cyber security measures should not be used to suppress free speech or target marginalized groups.
Summary Table
Ethical Issue Core Concern Privacy Right to personal data protection Unauthorized Access Consent and legality Intellectual Property Respect for ownership Responsible Disclosure Duty to protect the public Malware Harm prevention Professional Responsibility Trust and accountability - 125 marksSecurity policy and implementationHideAnswer
Define security policy. How do you implement logging function? [5]
Security Policy and Logging Function Implementation
Definition of Security Policy
A security policy is a formal set of rules, guidelines, and procedures that defines how an organization manages, protects, and distributes sensitive information and resources. It specifies:
- What assets need to be protected
- Who is authorized to access those assets
- How the assets should be protected
- What actions are permitted or prohibited within a system
A security policy serves as the foundation for all security mechanisms in a system. It may include:
- Access control policies (who can access what)
- Authentication policies (how users prove their identity)
- Confidentiality policies (protecting data from unauthorized disclosure)
- Integrity policies (ensuring data is not tampered with)
- Availability policies (ensuring resources are accessible to authorized users)
Example: "Only authenticated administrators can read/write to the database; all other users have read-only access."
Implementation of Logging Function
Logging is the process of recording events, actions, and transactions that occur within a system for the purposes of auditing, monitoring, debugging, and security analysis.
Key Steps to Implement a Logging Function:
1. Define What to Log
Decide which events should be recorded:
- Login attempts (successful and failed)
- File access and modifications
- System errors and exceptions
- User actions and privilege changes
- Network connections
2. Design the Log Structure
Each log entry should contain:
Field Description Timestamp Date and time of the event User ID Who performed the action Event Type Type of event (login, access, error) Resource What was accessed or modified Status Success or failure IP Address Source of the request 3. Basic Logging Function (Pseudocode)
function logEvent(userID, eventType, resource, status): timestamp = getCurrentDateTime() logEntry = timestamp + " | " + userID + " | " + eventType + " | " + resource + " | " + status appendToLogFile(logEntry) if status == "FAILURE": triggerAlert(logEntry) end function4. Log Storage and Protection
- Store logs in a write-once or append-only file to prevent tampering
- Use encryption to protect log contents
- Maintain backup copies of logs
- Restrict access to log files (only administrators)
5. Log Management
- Implement log rotation to manage file size
- Set retention policies (e.g., keep logs for 90 days)
- Use centralized log servers (e.g., syslog) for distributed systems
6. Log Analysis and Auditing
- Regularly review logs for suspicious activity
- Use automated tools to detect anomalies
- Generate audit reports for compliance
Importance of Logging in Security
- Provides accountability by tracking user actions
- Helps in intrusion detection and incident response
- Supports forensic analysis after a security breach
- Ensures compliance with security policies and regulations