Syllabus

BIT · Semester V

Information Security syllabus

Official TU syllabus for Information Security (BIT303): 10 units, 59 topics. Every unit links to its notes and solved questions.

1

Fundamentals of Information Security

8 Q
  • Security concepts and terminology
  • Threats, attacks and assets
  • Security risk and risk assessment
  • Security policy and implementation
  • Security auditing architecture
  • Attack trees and threat modeling
2

Cryptographic Foundations

6 Q
  • Number theory basics
  • Euler totient function
  • Extended Euclidean algorithm
  • Primality testing algorithms
  • Finite fields and polynomial operations
  • Substitution and transposition ciphers
3

Symmetric Encryption

4 Q
  • Symmetric cryptography principles
  • DES algorithm and round operations
  • DES sub-key generation
  • S-box operations in DES
  • DES encryption and decryption
  • Hill cipher and matrix operations
4

Asymmetric Encryption

5 Q
  • RSA algorithm and key generation
  • RSA encryption and decryption
  • RSA numerical examples
  • Diffie-Hellman key exchange protocol
  • Public key cryptography principles
5

Hash Functions and Message Authentication

7 Q
  • Hash function properties and design
  • MD5 algorithm and hash value generation
  • SHA-1 algorithm and padding
  • SHA-2 hash function
  • Message authentication purposes
  • Digital signatures for authentication
6

Authentication and Access Control

13 Q
  • Authentication systems and components
  • Challenge-response authentication
  • Password-based authentication
  • Biometric authentication
  • Two-factor authentication
  • Dictionary attacks and authentication issues
  • Access control principles and models
  • Role-based access control
  • Attribute-based access control
  • Subjects, objects and access rights
7

Malware and Cyber Threats

6 Q
  • Malicious software definition and types
  • Viruses, worms and Trojan horses
  • Zombies, bots and rootkits
  • Phishing attacks
  • Countermeasures for malware
  • Audit trail analysis
8

Trust Frameworks and Identity Management

3 Q
  • Trust frameworks overview
  • Identity providers and relying parties
  • Attribute providers
  • Open Identity Trust Framework
  • Interception, repudiation and incapacitation
9

Security Risk Management

3 Q
  • Risk definition and analysis
  • Security risk assessment aspects
  • Risk treatment methods
  • Logging function implementation
10

Legal and Ethical Issues

5 Q
  • Cybercrime and computer crime
  • Intellectual property and copyright
  • Patents and intellectual property protection
  • Ethical issues in computing
  • Cyber law status in Nepal

Study BIT303 the smart way

Solved questions, flashcards & practice