Important Questions

CSC327 · Exam intelligence

Cryptography important questions

From 6 past TU papers: which questions keep coming back, how much they carry, and what is most likely to show up next. Every question links to a model answer.

Most likely in the next examStatistical

Ranked by how often a topic is asked, its marks weight, and whether it is due after skipping the 2082 paper. No guarantees; study the whole syllabus.

1asked 8xavg 4 marks · Substitution Techniques
Answer

Given the key "HELLOWORLD", encrypt the plaintext "TURINGTEST" using Play fair cipher. [5]

Playfair Cipher: Encrypting "TURINGTEST" with Key "HELLOWORLD"

STEP 1 - EXTRACT (Given data)

  • Key: HELLOWORLD
  • Plaintext: TURINGTEST
  • Cipher: Playfair (5x5 matrix, I/J combined)

STEP 2 - SOLVE

Build the 5x5 Matrix

Key letters, removing duplicates (keep first occurrence): H, E, L, O, W, R, D
(HELLOWORLD → H, E, L, [L dup], O, W, [O dup], R, [L dup], D)

Fill remaining alphabet (I/J together): A, B, C, F, G, I/J, K, M, N, P, Q, S, T, U, V, X, Y, Z

C1C2C3C4C5
R1HELOW
R2RDABC
R3FGI/JKM
R4NPQST
R5UVXYZ

Split into digrams

TURINGTEST → TU | RI | NG | TE | ST

No double letters within a pair, length is even, so no padding needed.

Apply rules

TU: T(R4,C5), U(R5,C1) → rectangle
T → (R4, C1) = N; U → (R5, C5) = Z → NZ

RI: R(R2,C1), I(R3,C3) → rectangle
R → (R2, C3) = A; I → (R3, C1) = F → AF

NG: N(R4,C1), G(R3,C2) → rectangle
N → (R4, C2) = P; G → (R3, C1) = F → PF

TE: T(R4,C5), E(R1,C2) → rectangle
T → (R4, C2) = P; E → (R1, C5) = W → PW

ST: S(R4,C4), T(R4,C5) → same row (shift right, wrap)
S → C5 = T; T → C1 (wrap) = N → TN

Final Ciphertext

Plain pairCipher pair
TUNZ
RIAF
NGPF
TEPW
STTN

$$\boxed{\text{Ciphertext} = \text{NZAFPFPWTN}}$$

2asked 4xavg 6 marks · due (skipped 2082) · Finite Fields
Answer

Find the multiplicative inverse of polynomial (95) using extended euclidean Algorithm. [5]

Multiplicative Inverse in GF(2⁸) using the Extended Euclidean Algorithm

Step 1 - EXTRACT (Given data)

  • Element to invert: 95 (hexadecimal), interpreted as an element of $GF(2^8)$.
  • $95_{16} = 1001,0101_2$, giving polynomial

$$b(x) = x^7 + x^4 + x^2 + 1$$

  • AES irreducible (reduction) polynomial:

$$m(x) = x^8 + x^4 + x^3 + x + 1$$

Note: The question only states "95" and "extended Euclidean algorithm". The irreducible polynomial is not explicitly given; the AES standard modulus is assumed since this is the standard BIT/cryptography context.

Goal: find $b(x)^{-1} \bmod m(x)$.


Step 2 - SOLVE

All arithmetic is in $GF(2)$ (addition = XOR).

Initialize:

  • $r_0 = m(x)=x^8+x^4+x^3+x+1$, $; t_0=0$
  • $r_1 = b(x)=x^7+x^4+x^2+1$, $; t_1=1$

Recurrence: $r_{i+1}=r_{i-1}-q_i r_i$, $;t_{i+1}=t_{i-1}-q_i t_i$.

Division 1: $r_0 \div r_1$

$$x^8+x^4+x^3+x+1 ;=; x\cdot(x^7+x^4+x^2+1) + r_2$$

$x\cdot b = x^8+x^5+x^3+x$. XOR:

$$r_2 = (x^8+x^4+x^3+x+1)\oplus(x^8+x^5+x^3+x)=x^5+x^4+1$$

  • $q_1=x$
  • $t_2=t_0-q_1t_1 = 0 - x\cdot1 = x$

Division 2: $r_1 \div r_2$

Divide $x^7+x^4+x^2+1$ by $x^5+x^4+1$:

  • $x^2$: $x^2(x^5+x^4+1)=x^7+x^6+x^2$; XOR → $x^6+x^4+1$
  • $x$: $x(x^5+x^4+1)=x^6+x^5+x$; XOR → $x^5+x^4+x+1$
  • $1$: $x^5+x^4+1$; XOR → $x$

So:

  • $q_2=x^2+x+1$, $; r_3=x$
  • $t_3=t_1-q_2t_2 = 1 - (x^2+x+1)(x) = 1+(x^3+x^2+x)=x^3+x^2+x+1$

Division 3: $r_2 \div r_3$

Divide $x^5+x^4+1$ by $x$:

$$x^5+x^4+1 = x\cdot(x^4+x^3)+1$$

So:

  • $q_3=x^4+x^3$, $; r_4=1$
  • $t_4=t_2-q_3t_3 = x - (x^4+x^3)(x^3+x^2+x+1)$

Compute $(x^4+x^3)(x^3+x^2+x+1)$:

$x^4\cdot(x^3+x^2+x+1)=x^7+x^6+x^5+x^4$ $x^3\cdot(x^3+x^2+x+1)=x^6+x^5+x^4+x^3$

XOR (add): $x^6\oplus x^6=0$, $x^5\oplus x^5=0$, $x^4\oplus x^4=0$:

$$=x^7+x^3$$

Then:

$$t_4 = x \oplus (x^7+x^3) = x^7+x^3+x$$

Since $r_4 = 1 = \gcd$, the inverse of $b(x)$ modulo $m(x)$ is $t_4$.

Verification

$$b(x)^{-1} = x^7 + x^3 + x$$

Check $b(x)\cdot t_4 \bmod m(x)$:

$b = x^7+x^4+x^2+1$, $t_4=x^7+x^3+x$.

Product:

  • $x^7\cdot t_4 = x^{14}+x^{10}+x^8$
  • $x^4\cdot t_4 = x^{11}+x^7+x^5$
  • $x^2\cdot t_4 = x^9+x^5+x^3$
  • $1\cdot t_4 = x^7+x^3+x$

XOR all: $x^5\oplus x^5=0$, $x^7\oplus x^7=0$, $x^3\oplus x^3=0$:

$$= x^{14}+x^{11}+x^{10}+x^9+x^8+x$$

Reduce mod $m(x)=x^8+x^4+x^3+x+1$ (i.e. $x^8\equiv x^4+x^3+x+1$):

  • $x^8\equiv x^4+x^3+x+1$

  • $x^9\equiv x^5+x^4+x^2+x$

  • $x^{10}\equiv x^6+x^5+x^3+x^2$

  • $x^{11}\equiv x^7+x^6+x^4+x^3$

  • $x^{14}=x^6\cdot x^8\equiv x^6(x^4+x^3+x+1)=x^{10}+x^9+x^7+x^6$

    reduce: $x^{10}\to x^6+x^5+x^3+x^2$, $x^9\to x^5+x^4+x^2+x$ $x^{14}\equiv (x^6+x^5+x^3+x^2)+(x^5+x^4+x^2+x)+x^7+x^6$ $= x^7+x^4+x^3+x$

Sum all reduced terms (XOR):

termreduced
$x^{14}$$x^7+x^4+x^3+x$
$x^{11}$$x^7+x^6+x^4+x^3$
$x^{10}$$x^6+x^5+x^3+x^2$
$x^9$$x^5+x^4+x^2+x$
$x^8$$x^4+x^3+x+1$
$x$$x$

XOR column by column:

  • $x^7$: $1+1=0$
  • $x^6$: $1+1=0$
  • $x^5$: $1+1=0$
  • $x^4$: $1+1+1+1=0$
  • $x^3$: $1+1+1+1=0$
  • $x^2$: $1+1=0$
  • $x^1$: $1+1+1+1=0$
  • $x^0$: $1$

$$= 1 \checkmark$$

Final Answer

$$\boxed{b(x)^{-1} = x^7 + x^3 + x}$$

In binary: $1000,1010$, i.e. hexadecimal 8A.

Completing the computation through $t_4$ gives the inverse $x^7+x^3+x$, which multiplies back to $1$.

3asked 5xavg 5 marks · Number Theory
Answer

State Fermat's theorem with example. What is the implication of discrete logarithm? [5]

Statement: If p is a prime number and a is a positive integer such that gcd(a, p) = 1 (i.e., a is not divisible by p), then: $$a^{p-1} \equiv 1 \pmod{p}$$ An alternative (and equally important) form of Fermat's theorem is: $$a^p \equiv a...

4asked 3xavg 7 marks · due (skipped 2082) · Diffie-Helman Key Exchange
Answer

Why do we need discrete logarithm? Illustrate with an example. Consider a Diffie-Hellman scheme with a common prime p = 13 between user A and user B. Suppose public key of A is 10 and public key of B is 8. Now determine their private keys and shared secret key. Select any valid primitive root of 13.[10]

  • Common prime: $p = 13$ - Public key of A: $YA = 10$ - Public key of B: $YB = 8$ - Task: find private keys $XA, XB$ and shared secret $K$, using any valid primitive root of 13. --- Definition. Given a prime $p$, a primitive root $g$, an...
5asked 3xavg 5 marks · due (skipped 2082) · International Data Encryption Standard
Answer

Tracing the First Full Round of IDEA Algorithm

IDEA (International Data Encryption Algorithm) is a symmetric block cipher that operates on 64-bit plaintext blocks using a 128-bit key, performing 8 identical rounds with operations: multiplication modulo $2^{16}+1$, addition modulo $2^{16}$, and XOR.

Subkeys (4-bit each): - $K1 = 1100 = 12$ - $K2 = 1010 = 10$ - $K3 = 0000 = 0$ - $K4 = 1111 = 15$ - $K5 = 0101 = 5$ - $K6 = 1001 = 9$ Input plaintext blocks (4-bit each): - $X1 = 1011 = 11$ - $X2 = 1110 = 14$ - $X3 = 1011 = 11$ - $X4 = 10...

Most repeated questions

Topics asked at least twice, most-asked first.

asked 8xavg 4 marks · 2082, 2081, 2080, 2079, 2078
Answer

Given the key "HELLOWORLD", encrypt the plaintext "TURINGTEST" using Play fair cipher. [5]

Playfair Cipher: Encrypting "TURINGTEST" with Key "HELLOWORLD"

STEP 1 - EXTRACT (Given data)

  • Key: HELLOWORLD
  • Plaintext: TURINGTEST
  • Cipher: Playfair (5x5 matrix, I/J combined)

STEP 2 - SOLVE

Build the 5x5 Matrix

Key letters, removing duplicates (keep first occurrence): H, E, L, O, W, R, D
(HELLOWORLD → H, E, L, [L dup], O, W, [O dup], R, [L dup], D)

Fill remaining alphabet (I/J together): A, B, C, F, G, I/J, K, M, N, P, Q, S, T, U, V, X, Y, Z

C1C2C3C4C5
R1HELOW
R2RDABC
R3FGI/JKM
R4NPQST
R5UVXYZ

Split into digrams

TURINGTEST → TU | RI | NG | TE | ST

No double letters within a pair, length is even, so no padding needed.

Apply rules

TU: T(R4,C5), U(R5,C1) → rectangle
T → (R4, C1) = N; U → (R5, C5) = Z → NZ

RI: R(R2,C1), I(R3,C3) → rectangle
R → (R2, C3) = A; I → (R3, C1) = F → AF

NG: N(R4,C1), G(R3,C2) → rectangle
N → (R4, C2) = P; G → (R3, C1) = F → PF

TE: T(R4,C5), E(R1,C2) → rectangle
T → (R4, C2) = P; E → (R1, C5) = W → PW

ST: S(R4,C4), T(R4,C5) → same row (shift right, wrap)
S → C5 = T; T → C1 (wrap) = N → TN

Final Ciphertext

Plain pairCipher pair
TUNZ
RIAF
NGPF
TEPW
STTN

$$\boxed{\text{Ciphertext} = \text{NZAFPFPWTN}}$$

asked 5xavg 5 marks · 2082, 2080, 2079, 2078, 2076
Answer

State Fermat's theorem with example. What is the implication of discrete logarithm? [5]

Statement: If p is a prime number and a is a positive integer such that gcd(a, p) = 1 (i.e., a is not divisible by p), then: $$a^{p-1} \equiv 1 \pmod{p}$$ An alternative (and equally important) form of Fermat's theorem is: $$a^p \equiv a...

asked 4xavg 6 marks · 2081, 2080, 2078
Answer

Find the multiplicative inverse of polynomial (95) using extended euclidean Algorithm. [5]

Multiplicative Inverse in GF(2⁸) using the Extended Euclidean Algorithm

Step 1 - EXTRACT (Given data)

  • Element to invert: 95 (hexadecimal), interpreted as an element of $GF(2^8)$.
  • $95_{16} = 1001,0101_2$, giving polynomial

$$b(x) = x^7 + x^4 + x^2 + 1$$

  • AES irreducible (reduction) polynomial:

$$m(x) = x^8 + x^4 + x^3 + x + 1$$

Note: The question only states "95" and "extended Euclidean algorithm". The irreducible polynomial is not explicitly given; the AES standard modulus is assumed since this is the standard BIT/cryptography context.

Goal: find $b(x)^{-1} \bmod m(x)$.


Step 2 - SOLVE

All arithmetic is in $GF(2)$ (addition = XOR).

Initialize:

  • $r_0 = m(x)=x^8+x^4+x^3+x+1$, $; t_0=0$
  • $r_1 = b(x)=x^7+x^4+x^2+1$, $; t_1=1$

Recurrence: $r_{i+1}=r_{i-1}-q_i r_i$, $;t_{i+1}=t_{i-1}-q_i t_i$.

Division 1: $r_0 \div r_1$

$$x^8+x^4+x^3+x+1 ;=; x\cdot(x^7+x^4+x^2+1) + r_2$$

$x\cdot b = x^8+x^5+x^3+x$. XOR:

$$r_2 = (x^8+x^4+x^3+x+1)\oplus(x^8+x^5+x^3+x)=x^5+x^4+1$$

  • $q_1=x$
  • $t_2=t_0-q_1t_1 = 0 - x\cdot1 = x$

Division 2: $r_1 \div r_2$

Divide $x^7+x^4+x^2+1$ by $x^5+x^4+1$:

  • $x^2$: $x^2(x^5+x^4+1)=x^7+x^6+x^2$; XOR → $x^6+x^4+1$
  • $x$: $x(x^5+x^4+1)=x^6+x^5+x$; XOR → $x^5+x^4+x+1$
  • $1$: $x^5+x^4+1$; XOR → $x$

So:

  • $q_2=x^2+x+1$, $; r_3=x$
  • $t_3=t_1-q_2t_2 = 1 - (x^2+x+1)(x) = 1+(x^3+x^2+x)=x^3+x^2+x+1$

Division 3: $r_2 \div r_3$

Divide $x^5+x^4+1$ by $x$:

$$x^5+x^4+1 = x\cdot(x^4+x^3)+1$$

So:

  • $q_3=x^4+x^3$, $; r_4=1$
  • $t_4=t_2-q_3t_3 = x - (x^4+x^3)(x^3+x^2+x+1)$

Compute $(x^4+x^3)(x^3+x^2+x+1)$:

$x^4\cdot(x^3+x^2+x+1)=x^7+x^6+x^5+x^4$ $x^3\cdot(x^3+x^2+x+1)=x^6+x^5+x^4+x^3$

XOR (add): $x^6\oplus x^6=0$, $x^5\oplus x^5=0$, $x^4\oplus x^4=0$:

$$=x^7+x^3$$

Then:

$$t_4 = x \oplus (x^7+x^3) = x^7+x^3+x$$

Since $r_4 = 1 = \gcd$, the inverse of $b(x)$ modulo $m(x)$ is $t_4$.

Verification

$$b(x)^{-1} = x^7 + x^3 + x$$

Check $b(x)\cdot t_4 \bmod m(x)$:

$b = x^7+x^4+x^2+1$, $t_4=x^7+x^3+x$.

Product:

  • $x^7\cdot t_4 = x^{14}+x^{10}+x^8$
  • $x^4\cdot t_4 = x^{11}+x^7+x^5$
  • $x^2\cdot t_4 = x^9+x^5+x^3$
  • $1\cdot t_4 = x^7+x^3+x$

XOR all: $x^5\oplus x^5=0$, $x^7\oplus x^7=0$, $x^3\oplus x^3=0$:

$$= x^{14}+x^{11}+x^{10}+x^9+x^8+x$$

Reduce mod $m(x)=x^8+x^4+x^3+x+1$ (i.e. $x^8\equiv x^4+x^3+x+1$):

  • $x^8\equiv x^4+x^3+x+1$

  • $x^9\equiv x^5+x^4+x^2+x$

  • $x^{10}\equiv x^6+x^5+x^3+x^2$

  • $x^{11}\equiv x^7+x^6+x^4+x^3$

  • $x^{14}=x^6\cdot x^8\equiv x^6(x^4+x^3+x+1)=x^{10}+x^9+x^7+x^6$

    reduce: $x^{10}\to x^6+x^5+x^3+x^2$, $x^9\to x^5+x^4+x^2+x$ $x^{14}\equiv (x^6+x^5+x^3+x^2)+(x^5+x^4+x^2+x)+x^7+x^6$ $= x^7+x^4+x^3+x$

Sum all reduced terms (XOR):

termreduced
$x^{14}$$x^7+x^4+x^3+x$
$x^{11}$$x^7+x^6+x^4+x^3$
$x^{10}$$x^6+x^5+x^3+x^2$
$x^9$$x^5+x^4+x^2+x$
$x^8$$x^4+x^3+x+1$
$x$$x$

XOR column by column:

  • $x^7$: $1+1=0$
  • $x^6$: $1+1=0$
  • $x^5$: $1+1=0$
  • $x^4$: $1+1+1+1=0$
  • $x^3$: $1+1+1+1=0$
  • $x^2$: $1+1=0$
  • $x^1$: $1+1+1+1=0$
  • $x^0$: $1$

$$= 1 \checkmark$$

Final Answer

$$\boxed{b(x)^{-1} = x^7 + x^3 + x}$$

In binary: $1000,1010$, i.e. hexadecimal 8A.

Completing the computation through $t_4$ gives the inverse $x^7+x^3+x$, which multiplies back to $1$.

asked 4xavg 8 marks · 2082, 2081, 2079, 2078
Answer

Describe the properties of hash functions. Discuss how hash value is generated using SHA-1 algorithm.[10]

A hash function is a function that maps a message of any length into a fixed-length hash value, which serves as the authenticator. Cryptographic hash functions play a fundamental role in efficient and secure information processing. Prope...

asked 3xavg 7 marks · 2081, 2080, 2076
Answer

Why do we need discrete logarithm? Illustrate with an example. Consider a Diffie-Hellman scheme with a common prime p = 13 between user A and user B. Suppose public key of A is 10 and public key of B is 8. Now determine their private keys and shared secret key. Select any valid primitive root of 13.[10]

  • Common prime: $p = 13$ - Public key of A: $YA = 10$ - Public key of B: $YB = 8$ - Task: find private keys $XA, XB$ and shared secret $K$, using any valid primitive root of 13. --- Definition. Given a prime $p$, a primitive root $g$, an...
asked 3xavg 5 marks · 2081, 2079, 2076
Answer

Tracing the First Full Round of IDEA Algorithm

IDEA (International Data Encryption Algorithm) is a symmetric block cipher that operates on 64-bit plaintext blocks using a 128-bit key, performing 8 identical rounds with operations: multiplication modulo $2^{16}+1$, addition modulo $2^{16}$, and XOR.

Subkeys (4-bit each): - $K1 = 1100 = 12$ - $K2 = 1010 = 10$ - $K3 = 0000 = 0$ - $K4 = 1111 = 15$ - $K5 = 0101 = 5$ - $K6 = 1001 = 9$ Input plaintext blocks (4-bit each): - $X1 = 1011 = 11$ - $X2 = 1110 = 14$ - $X3 = 1011 = 11$ - $X4 = 10...

asked 3xavg 5 marks · 2080, 2079, 2076
Answer

How substitution ciphers are different from transposition ciphers? Given a message M="CSIT PROGRAM IS A HOT CAKE", encrypt M using Rail Fence cipher with rail size 3. [5]

Feature Substitution Cipher Transposition Cipher --------- Basic idea Each plaintext character is replaced by another character/symbol Character identity is retained but its position is changed Operation Maps letters to other letters via...

asked 3xavg 5 marks · 2082, 2079, 2076
Answer

Describe any three types of malicious logic. [5]

Malicious Logic


Malicious Logic (Malicious Code / Rogue Programs)

Malicious logic refers to a set of instructions or programs that are intentionally designed to cause harm, unauthorized access, or disruption to a computer system or network.


1. Trojan Horse

A Trojan Horse is a program that appears to perform a legitimate or useful function but secretly contains hidden code that performs unauthorized or harmful actions when executed.

  • It does not replicate itself (unlike a virus).
  • It tricks the user into running it by disguising itself as a legitimate program.
  • Example: A user downloads what appears to be a free game, but the program secretly installs a backdoor, allowing an attacker to gain remote access to the system.
  • Damage: Data theft, unauthorized access, system damage.

2. Virus

A virus is a piece of malicious code that attaches itself to a legitimate program or file and replicates when that program is executed. It requires a host program to spread.

  • It can spread from one computer to another through infected files, email attachments, or removable media.
  • A virus typically has two phases:
    • Infection phase: It attaches itself to other programs.
    • Attack phase: It performs its malicious activity (deleting files, corrupting data, etc.).
  • Example: A virus attached to a .exe file that corrupts system files when executed.
  • Damage: File corruption, system crashes, data loss.

3. Worm

A worm is a self-contained, self-replicating program that spreads across networks without needing to attach itself to a host program. Unlike a virus, it does not require user interaction to propagate.

  • It exploits vulnerabilities in operating systems or network services to spread automatically.
  • Worms consume network bandwidth and system resources, causing slowdowns or crashes.
  • Example: The Morris Worm (1988) spread across the Internet by exploiting UNIX vulnerabilities, causing widespread system slowdowns.
  • Damage: Network congestion, system resource exhaustion, data theft.

Summary Table

TypeReplicates?Needs Host?Spreads Via
Trojan HorseNoYes (disguise)User deception
VirusYesYes (host file)Infected files/media
WormYesNoNetwork/vulnerabilities

Other types of malicious logic include Logic Bombs (code that triggers under specific conditions) and Trapdoors/Backdoors (hidden entry points left by developers for unauthorized access).

asked 3xavg 5 marks · 2082, 2081, 2076
Answer

List and explain the types of firewall. [5]

Types of Firewall


Firewall

A firewall is a network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules. It establishes a barrier between a trusted internal network and untrusted external networks.


Types of Firewall

1. Packet Filtering Firewall

  • Operates at the Network Layer (Layer 3) of the OSI model.
  • Inspects each packet passing through the network and filters them based on rules such as source IP, destination IP, port numbers, and protocols.
  • It does not examine the content of the packet.
  • Advantage: Fast and efficient.
  • Disadvantage: Cannot detect application-level attacks; stateless (does not track connection state).

2. Stateful Inspection Firewall (Dynamic Packet Filtering)

  • Operates at the Network and Transport Layer.
  • Tracks the state of active connections and makes filtering decisions based on the context of traffic (e.g., whether a packet is part of an established connection).
  • Maintains a state table to monitor ongoing sessions.
  • Advantage: More secure than simple packet filtering.
  • Disadvantage: Slower than packet filtering; cannot inspect application-layer data.

3. Application Layer Firewall (Proxy Firewall)

  • Operates at the Application Layer (Layer 7).
  • Acts as an intermediary (proxy) between the client and the server; it intercepts all messages entering and leaving the network.
  • Can inspect the full content of network traffic including HTTP, FTP, DNS, etc.
  • Advantage: Provides deep packet inspection; hides internal network details.
  • Disadvantage: Slower performance due to deep inspection; requires more resources.

4. Circuit-Level Gateway

  • Operates at the Session Layer (Layer 5).
  • Monitors TCP handshaking and session establishment to determine whether a requested session is legitimate.
  • Does not inspect the actual content of the packets.
  • Advantage: Faster than application-layer firewalls; hides internal network information.
  • Disadvantage: Cannot filter individual packets after the session is established.

5. Next-Generation Firewall (NGFW)

  • Combines the features of traditional firewalls with advanced capabilities such as:
    • Deep Packet Inspection (DPI)
    • Intrusion Prevention System (IPS)
    • Application awareness and control
    • SSL/TLS inspection
  • Can identify and block sophisticated attacks including malware and application-layer threats.
  • Advantage: Comprehensive security; highly effective against modern threats.
  • Disadvantage: Expensive and complex to configure.

Summary Table

TypeOSI LayerKey Feature
Packet FilteringNetwork (L3)Filters by IP/port rules
Stateful InspectionNetwork/TransportTracks connection state
Application Layer (Proxy)Application (L7)Deep content inspection
Circuit-Level GatewaySession (L5)Monitors TCP handshake
Next-Generation FirewallMultiple LayersDPI + IPS + App control
asked 2xavg 8 marks · 2081, 2076
Answer

What is Message Authentication Code? List the operation of computing digest value in different passes of MD4. Describe about Needhom-Schroeder protocol.[10]

--- Definition: A Message Authentication Code (MAC) is a function of the message and a secret key that produces a fixed-length value that serves as the authenticator. Working Principle: - This technique assumes that the sender and receiv...

asked 2xavg 5 marks · 2081, 2078
Answer

What is intrusion? Explain any two types of intrusion detection system. [5]

Intrusion and Intrusion Detection Systems

What is Intrusion?

Intrusion detection is the process of identifying and responding to malicious activity targeted at a resource. An intrusion refers to any unauthorized attempt to access, manipulate, or compromise a system's resources, data, or services.

An Intrusion Detection System (IDS) is a system designed to test/analyze network system traffic/events against a given set of parameters and alert/capture data when these thresholds are met. IDS uses collected information and pre-defined knowledge-based systems to reason about the possibility of an intrusion. It also provides services to cope with intrusion such as giving alarms and activating programs to deal with intrusion.


Two Types (Approaches) of Intrusion Detection System

1. Statistical Anomaly Detection

Statistical anomaly detection involves the collection of data relating to the behaviours of legitimate users over a period of time. Then statistical tests are applied to observed behaviour to determine with a high level of confidence whether the behaviour is that of a legitimate user or not.

It falls into two broad categories:

  • Threshold Detection:

    • Involves counting the number of occurrences of a specified event type over an interval of time.
    • If the count exceeds a reasonable number, an intrusion is assumed.
    • Example: Too many failed login attempts within a short time.
  • Profile-Based Anomaly Detection:

    • Focuses on characterizing the past behaviour of individual users or related groups of users.
    • Significant deviations from the established profile are flagged as potential intrusions.

2. Rule-Based Detection

Rule-based detection involves an attempt to define a set of rules that can be used to decide whether a given behaviour is that of an intruder.

It falls into two broad categories:

  • Rule-Based Anomaly Detection:

    • Historical audit records are analyzed to identify usage patterns.
    • Rules are generated automatically to describe those patterns.
    • Any behaviour that deviates from these rules is flagged as suspicious.
  • Rule-Based Penetration Identification:

    • Uses rules for identifying known penetrations or penetrations that would exploit known weaknesses.
    • Rules are typically defined by security experts based on known attack signatures.
    • Example: A rule that detects a specific sequence of commands known to exploit a vulnerability.

Summary Table:

ApproachBasisMethod
Statistical Anomaly DetectionBehaviour deviation from normalThreshold / Profile-based
Rule-Based DetectionPredefined rulesAnomaly rules / Penetration rules
asked 2xavg 5 marks · 2080, 2078
Answer

Write down the encryption and decryption process at 2-DES and 3-DES. Explain the Fiestal cipher structure. Divide $5x^2 + 4x + 6$ by $2x + 1$ over GF(7). [10]

--- 2-DES applies the DES algorithm twice with two independent keys $K1$ and $K2$ (each 56 bits, giving 112-bit effective key length). Encryption: $$C = E{K2}(E{K1}(P))$$ Plaintext $P$ is first encrypted with $K1$ to give an intermediate...

asked 2xavg 10 marks · 2079, 2076
Answer

Show that Z 5 is a field. John publishes the ElGamal public key (q, α, YA) =(101, 2, 14). Jane desired to send the secret message CSIT to John. Using the equivalence A = 0, B=1, ..., Z=25, encrypt the message using John’s public key. Use a random number k = 4.[10]

--- Field problem: - Set: $\mathbb{Z}5 = {0,1,2,3,4}$ under addition and multiplication mod 5. ElGamal problem: - Public key: $(q, \alpha, YA) = (101, 2, 14)$ - Message: "CSIT" - Encoding: $A=0, B=1, \dots, Z=25$ - Random number: $k = ...

asked 2xavg 3 marks · 2080, 2078
Answer

Give the formal definition of authentication system. Describe about one way and mutual authentication system. [3257]

An Authentication System is a security measure put in place to secure data and systems by requiring additional input beyond username and password for users to access a system. Formally, an authentication system is defined as a 5-tuple: $...

asked 2xavg 8 marks · 2079, 2078
Answer

How direct digital signature different from arbitrated digital signature? How digital signature generation and verification is done using RSA. [5]

--- - Involves only two parties: the sender and the receiver. - The sender signs the message using their private key. - The receiver verifies the signature using the sender's public key. - No third party is involved in the process. - Wea...

Study every one of these with model answers, flashcards, and MCQs.

Open CSC327 study modes