CSC327 · Exam intelligence
Cryptography important questions
From 6 past TU papers: which questions keep coming back, how much they carry, and what is most likely to show up next. Every question links to a model answer.
Most likely in the next examStatistical
Ranked by how often a topic is asked, its marks weight, and whether it is due after skipping the 2082 paper. No guarantees; study the whole syllabus.
1asked 8xavg 4 marks · Substitution TechniquesAnswerHideGiven the key "HELLOWORLD", encrypt the plaintext "TURINGTEST" using Play fair cipher. [5]
Given the key "HELLOWORLD", encrypt the plaintext "TURINGTEST" using Play fair cipher. [5]
Playfair Cipher: Encrypting "TURINGTEST" with Key "HELLOWORLD"
STEP 1 - EXTRACT (Given data)
- Key: HELLOWORLD
- Plaintext: TURINGTEST
- Cipher: Playfair (5x5 matrix, I/J combined)
STEP 2 - SOLVE
Build the 5x5 Matrix
Key letters, removing duplicates (keep first occurrence):
H, E, L, O, W, R, D
(HELLOWORLD → H, E, L, [L dup], O, W, [O dup], R, [L dup], D)
Fill remaining alphabet (I/J together): A, B, C, F, G, I/J, K, M, N, P, Q, S, T, U, V, X, Y, Z
| C1 | C2 | C3 | C4 | C5 | |
|---|---|---|---|---|---|
| R1 | H | E | L | O | W |
| R2 | R | D | A | B | C |
| R3 | F | G | I/J | K | M |
| R4 | N | P | Q | S | T |
| R5 | U | V | X | Y | Z |
Split into digrams
TURINGTEST → TU | RI | NG | TE | ST
No double letters within a pair, length is even, so no padding needed.
Apply rules
TU: T(R4,C5), U(R5,C1) → rectangle
T → (R4, C1) = N; U → (R5, C5) = Z → NZ
RI: R(R2,C1), I(R3,C3) → rectangle
R → (R2, C3) = A; I → (R3, C1) = F → AF
NG: N(R4,C1), G(R3,C2) → rectangle
N → (R4, C2) = P; G → (R3, C1) = F → PF
TE: T(R4,C5), E(R1,C2) → rectangle
T → (R4, C2) = P; E → (R1, C5) = W → PW
ST: S(R4,C4), T(R4,C5) → same row (shift right, wrap)
S → C5 = T; T → C1 (wrap) = N → TN
Final Ciphertext
| Plain pair | Cipher pair |
|---|---|
| TU | NZ |
| RI | AF |
| NG | PF |
| TE | PW |
| ST | TN |
$$\boxed{\text{Ciphertext} = \text{NZAFPFPWTN}}$$
2asked 4xavg 6 marks · due (skipped 2082) · Finite FieldsAnswerHideFind the multiplicative inverse of polynomial (95) using extended euclidean Algorithm. [5]
Find the multiplicative inverse of polynomial (95) using extended euclidean Algorithm. [5]
Multiplicative Inverse in GF(2⁸) using the Extended Euclidean Algorithm
Step 1 - EXTRACT (Given data)
- Element to invert: 95 (hexadecimal), interpreted as an element of $GF(2^8)$.
- $95_{16} = 1001,0101_2$, giving polynomial
$$b(x) = x^7 + x^4 + x^2 + 1$$
- AES irreducible (reduction) polynomial:
$$m(x) = x^8 + x^4 + x^3 + x + 1$$
Note: The question only states "95" and "extended Euclidean algorithm". The irreducible polynomial is not explicitly given; the AES standard modulus is assumed since this is the standard BIT/cryptography context.
Goal: find $b(x)^{-1} \bmod m(x)$.
Step 2 - SOLVE
All arithmetic is in $GF(2)$ (addition = XOR).
Initialize:
- $r_0 = m(x)=x^8+x^4+x^3+x+1$, $; t_0=0$
- $r_1 = b(x)=x^7+x^4+x^2+1$, $; t_1=1$
Recurrence: $r_{i+1}=r_{i-1}-q_i r_i$, $;t_{i+1}=t_{i-1}-q_i t_i$.
Division 1: $r_0 \div r_1$
$$x^8+x^4+x^3+x+1 ;=; x\cdot(x^7+x^4+x^2+1) + r_2$$
$x\cdot b = x^8+x^5+x^3+x$. XOR:
$$r_2 = (x^8+x^4+x^3+x+1)\oplus(x^8+x^5+x^3+x)=x^5+x^4+1$$
- $q_1=x$
- $t_2=t_0-q_1t_1 = 0 - x\cdot1 = x$
Division 2: $r_1 \div r_2$
Divide $x^7+x^4+x^2+1$ by $x^5+x^4+1$:
- $x^2$: $x^2(x^5+x^4+1)=x^7+x^6+x^2$; XOR → $x^6+x^4+1$
- $x$: $x(x^5+x^4+1)=x^6+x^5+x$; XOR → $x^5+x^4+x+1$
- $1$: $x^5+x^4+1$; XOR → $x$
So:
- $q_2=x^2+x+1$, $; r_3=x$
- $t_3=t_1-q_2t_2 = 1 - (x^2+x+1)(x) = 1+(x^3+x^2+x)=x^3+x^2+x+1$
Division 3: $r_2 \div r_3$
Divide $x^5+x^4+1$ by $x$:
$$x^5+x^4+1 = x\cdot(x^4+x^3)+1$$
So:
- $q_3=x^4+x^3$, $; r_4=1$
- $t_4=t_2-q_3t_3 = x - (x^4+x^3)(x^3+x^2+x+1)$
Compute $(x^4+x^3)(x^3+x^2+x+1)$:
$x^4\cdot(x^3+x^2+x+1)=x^7+x^6+x^5+x^4$ $x^3\cdot(x^3+x^2+x+1)=x^6+x^5+x^4+x^3$
XOR (add): $x^6\oplus x^6=0$, $x^5\oplus x^5=0$, $x^4\oplus x^4=0$:
$$=x^7+x^3$$
Then:
$$t_4 = x \oplus (x^7+x^3) = x^7+x^3+x$$
Since $r_4 = 1 = \gcd$, the inverse of $b(x)$ modulo $m(x)$ is $t_4$.
Verification
$$b(x)^{-1} = x^7 + x^3 + x$$
Check $b(x)\cdot t_4 \bmod m(x)$:
$b = x^7+x^4+x^2+1$, $t_4=x^7+x^3+x$.
Product:
- $x^7\cdot t_4 = x^{14}+x^{10}+x^8$
- $x^4\cdot t_4 = x^{11}+x^7+x^5$
- $x^2\cdot t_4 = x^9+x^5+x^3$
- $1\cdot t_4 = x^7+x^3+x$
XOR all: $x^5\oplus x^5=0$, $x^7\oplus x^7=0$, $x^3\oplus x^3=0$:
$$= x^{14}+x^{11}+x^{10}+x^9+x^8+x$$
Reduce mod $m(x)=x^8+x^4+x^3+x+1$ (i.e. $x^8\equiv x^4+x^3+x+1$):
-
$x^8\equiv x^4+x^3+x+1$
-
$x^9\equiv x^5+x^4+x^2+x$
-
$x^{10}\equiv x^6+x^5+x^3+x^2$
-
$x^{11}\equiv x^7+x^6+x^4+x^3$
-
$x^{14}=x^6\cdot x^8\equiv x^6(x^4+x^3+x+1)=x^{10}+x^9+x^7+x^6$
reduce: $x^{10}\to x^6+x^5+x^3+x^2$, $x^9\to x^5+x^4+x^2+x$ $x^{14}\equiv (x^6+x^5+x^3+x^2)+(x^5+x^4+x^2+x)+x^7+x^6$ $= x^7+x^4+x^3+x$
Sum all reduced terms (XOR):
| term | reduced |
|---|---|
| $x^{14}$ | $x^7+x^4+x^3+x$ |
| $x^{11}$ | $x^7+x^6+x^4+x^3$ |
| $x^{10}$ | $x^6+x^5+x^3+x^2$ |
| $x^9$ | $x^5+x^4+x^2+x$ |
| $x^8$ | $x^4+x^3+x+1$ |
| $x$ | $x$ |
XOR column by column:
- $x^7$: $1+1=0$
- $x^6$: $1+1=0$
- $x^5$: $1+1=0$
- $x^4$: $1+1+1+1=0$
- $x^3$: $1+1+1+1=0$
- $x^2$: $1+1=0$
- $x^1$: $1+1+1+1=0$
- $x^0$: $1$
$$= 1 \checkmark$$
Final Answer
$$\boxed{b(x)^{-1} = x^7 + x^3 + x}$$
In binary: $1000,1010$, i.e. hexadecimal 8A.
Completing the computation through $t_4$ gives the inverse $x^7+x^3+x$, which multiplies back to $1$.
3asked 5xavg 5 marks · Number TheoryAnswerHideState Fermat's theorem with example. What is the implication of discrete logarithm? [5]
State Fermat's theorem with example. What is the implication of discrete logarithm? [5]
Statement: If p is a prime number and a is a positive integer such that gcd(a, p) = 1 (i.e., a is not divisible by p), then: $$a^{p-1} \equiv 1 \pmod{p}$$ An alternative (and equally important) form of Fermat's theorem is: $$a^p \equiv a...
4asked 3xavg 7 marks · due (skipped 2082) · Diffie-Helman Key ExchangeAnswerHideWhy do we need discrete logarithm? Illustrate with an example. Consider a Diffie-Hellman scheme with a common prime p = 13 between user A and user B. Suppose public key of A is 10 and public key of B is 8. Now determine their private keys and shared secret key. Select any valid primitive root of 13.[10]
Why do we need discrete logarithm? Illustrate with an example. Consider a Diffie-Hellman scheme with a common prime p = 13 between user A and user B. Suppose public key of A is 10 and public key of B is 8. Now determine their private keys and shared secret key. Select any valid primitive root of 13.[10]
- Common prime: $p = 13$ - Public key of A: $YA = 10$ - Public key of B: $YB = 8$ - Task: find private keys $XA, XB$ and shared secret $K$, using any valid primitive root of 13. --- Definition. Given a prime $p$, a primitive root $g$, an...
5asked 3xavg 5 marks · due (skipped 2082) · International Data Encryption StandardAnswerHideTracing the First Full Round of IDEA Algorithm
IDEA (International Data Encryption Algorithm) is a symmetric block cipher that operates on 64-bit plaintext blocks using a 128-bit key, performing 8 identical rounds with operations: multiplication modulo $2^{16}+1$, addition modulo $2^{16}$, and XOR.
Tracing the First Full Round of IDEA Algorithm
IDEA (International Data Encryption Algorithm) is a symmetric block cipher that operates on 64-bit plaintext blocks using a 128-bit key, performing 8 identical rounds with operations: multiplication modulo $2^{16}+1$, addition modulo $2^{16}$, and XOR.
Subkeys (4-bit each): - $K1 = 1100 = 12$ - $K2 = 1010 = 10$ - $K3 = 0000 = 0$ - $K4 = 1111 = 15$ - $K5 = 0101 = 5$ - $K6 = 1001 = 9$ Input plaintext blocks (4-bit each): - $X1 = 1011 = 11$ - $X2 = 1110 = 14$ - $X3 = 1011 = 11$ - $X4 = 10...
Most repeated questions
Topics asked at least twice, most-asked first.
asked 8xavg 4 marks · 2082, 2081, 2080, 2079, 2078AnswerHideGiven the key "HELLOWORLD", encrypt the plaintext "TURINGTEST" using Play fair cipher. [5]
Given the key "HELLOWORLD", encrypt the plaintext "TURINGTEST" using Play fair cipher. [5]
Playfair Cipher: Encrypting "TURINGTEST" with Key "HELLOWORLD"
STEP 1 - EXTRACT (Given data)
- Key: HELLOWORLD
- Plaintext: TURINGTEST
- Cipher: Playfair (5x5 matrix, I/J combined)
STEP 2 - SOLVE
Build the 5x5 Matrix
Key letters, removing duplicates (keep first occurrence):
H, E, L, O, W, R, D
(HELLOWORLD → H, E, L, [L dup], O, W, [O dup], R, [L dup], D)
Fill remaining alphabet (I/J together): A, B, C, F, G, I/J, K, M, N, P, Q, S, T, U, V, X, Y, Z
| C1 | C2 | C3 | C4 | C5 | |
|---|---|---|---|---|---|
| R1 | H | E | L | O | W |
| R2 | R | D | A | B | C |
| R3 | F | G | I/J | K | M |
| R4 | N | P | Q | S | T |
| R5 | U | V | X | Y | Z |
Split into digrams
TURINGTEST → TU | RI | NG | TE | ST
No double letters within a pair, length is even, so no padding needed.
Apply rules
TU: T(R4,C5), U(R5,C1) → rectangle
T → (R4, C1) = N; U → (R5, C5) = Z → NZ
RI: R(R2,C1), I(R3,C3) → rectangle
R → (R2, C3) = A; I → (R3, C1) = F → AF
NG: N(R4,C1), G(R3,C2) → rectangle
N → (R4, C2) = P; G → (R3, C1) = F → PF
TE: T(R4,C5), E(R1,C2) → rectangle
T → (R4, C2) = P; E → (R1, C5) = W → PW
ST: S(R4,C4), T(R4,C5) → same row (shift right, wrap)
S → C5 = T; T → C1 (wrap) = N → TN
Final Ciphertext
| Plain pair | Cipher pair |
|---|---|
| TU | NZ |
| RI | AF |
| NG | PF |
| TE | PW |
| ST | TN |
$$\boxed{\text{Ciphertext} = \text{NZAFPFPWTN}}$$
asked 5xavg 5 marks · 2082, 2080, 2079, 2078, 2076AnswerHideState Fermat's theorem with example. What is the implication of discrete logarithm? [5]
State Fermat's theorem with example. What is the implication of discrete logarithm? [5]
Statement: If p is a prime number and a is a positive integer such that gcd(a, p) = 1 (i.e., a is not divisible by p), then: $$a^{p-1} \equiv 1 \pmod{p}$$ An alternative (and equally important) form of Fermat's theorem is: $$a^p \equiv a...
asked 4xavg 6 marks · 2081, 2080, 2078AnswerHideFind the multiplicative inverse of polynomial (95) using extended euclidean Algorithm. [5]
Find the multiplicative inverse of polynomial (95) using extended euclidean Algorithm. [5]
Multiplicative Inverse in GF(2⁸) using the Extended Euclidean Algorithm
Step 1 - EXTRACT (Given data)
- Element to invert: 95 (hexadecimal), interpreted as an element of $GF(2^8)$.
- $95_{16} = 1001,0101_2$, giving polynomial
$$b(x) = x^7 + x^4 + x^2 + 1$$
- AES irreducible (reduction) polynomial:
$$m(x) = x^8 + x^4 + x^3 + x + 1$$
Note: The question only states "95" and "extended Euclidean algorithm". The irreducible polynomial is not explicitly given; the AES standard modulus is assumed since this is the standard BIT/cryptography context.
Goal: find $b(x)^{-1} \bmod m(x)$.
Step 2 - SOLVE
All arithmetic is in $GF(2)$ (addition = XOR).
Initialize:
- $r_0 = m(x)=x^8+x^4+x^3+x+1$, $; t_0=0$
- $r_1 = b(x)=x^7+x^4+x^2+1$, $; t_1=1$
Recurrence: $r_{i+1}=r_{i-1}-q_i r_i$, $;t_{i+1}=t_{i-1}-q_i t_i$.
Division 1: $r_0 \div r_1$
$$x^8+x^4+x^3+x+1 ;=; x\cdot(x^7+x^4+x^2+1) + r_2$$
$x\cdot b = x^8+x^5+x^3+x$. XOR:
$$r_2 = (x^8+x^4+x^3+x+1)\oplus(x^8+x^5+x^3+x)=x^5+x^4+1$$
- $q_1=x$
- $t_2=t_0-q_1t_1 = 0 - x\cdot1 = x$
Division 2: $r_1 \div r_2$
Divide $x^7+x^4+x^2+1$ by $x^5+x^4+1$:
- $x^2$: $x^2(x^5+x^4+1)=x^7+x^6+x^2$; XOR → $x^6+x^4+1$
- $x$: $x(x^5+x^4+1)=x^6+x^5+x$; XOR → $x^5+x^4+x+1$
- $1$: $x^5+x^4+1$; XOR → $x$
So:
- $q_2=x^2+x+1$, $; r_3=x$
- $t_3=t_1-q_2t_2 = 1 - (x^2+x+1)(x) = 1+(x^3+x^2+x)=x^3+x^2+x+1$
Division 3: $r_2 \div r_3$
Divide $x^5+x^4+1$ by $x$:
$$x^5+x^4+1 = x\cdot(x^4+x^3)+1$$
So:
- $q_3=x^4+x^3$, $; r_4=1$
- $t_4=t_2-q_3t_3 = x - (x^4+x^3)(x^3+x^2+x+1)$
Compute $(x^4+x^3)(x^3+x^2+x+1)$:
$x^4\cdot(x^3+x^2+x+1)=x^7+x^6+x^5+x^4$ $x^3\cdot(x^3+x^2+x+1)=x^6+x^5+x^4+x^3$
XOR (add): $x^6\oplus x^6=0$, $x^5\oplus x^5=0$, $x^4\oplus x^4=0$:
$$=x^7+x^3$$
Then:
$$t_4 = x \oplus (x^7+x^3) = x^7+x^3+x$$
Since $r_4 = 1 = \gcd$, the inverse of $b(x)$ modulo $m(x)$ is $t_4$.
Verification
$$b(x)^{-1} = x^7 + x^3 + x$$
Check $b(x)\cdot t_4 \bmod m(x)$:
$b = x^7+x^4+x^2+1$, $t_4=x^7+x^3+x$.
Product:
- $x^7\cdot t_4 = x^{14}+x^{10}+x^8$
- $x^4\cdot t_4 = x^{11}+x^7+x^5$
- $x^2\cdot t_4 = x^9+x^5+x^3$
- $1\cdot t_4 = x^7+x^3+x$
XOR all: $x^5\oplus x^5=0$, $x^7\oplus x^7=0$, $x^3\oplus x^3=0$:
$$= x^{14}+x^{11}+x^{10}+x^9+x^8+x$$
Reduce mod $m(x)=x^8+x^4+x^3+x+1$ (i.e. $x^8\equiv x^4+x^3+x+1$):
-
$x^8\equiv x^4+x^3+x+1$
-
$x^9\equiv x^5+x^4+x^2+x$
-
$x^{10}\equiv x^6+x^5+x^3+x^2$
-
$x^{11}\equiv x^7+x^6+x^4+x^3$
-
$x^{14}=x^6\cdot x^8\equiv x^6(x^4+x^3+x+1)=x^{10}+x^9+x^7+x^6$
reduce: $x^{10}\to x^6+x^5+x^3+x^2$, $x^9\to x^5+x^4+x^2+x$ $x^{14}\equiv (x^6+x^5+x^3+x^2)+(x^5+x^4+x^2+x)+x^7+x^6$ $= x^7+x^4+x^3+x$
Sum all reduced terms (XOR):
| term | reduced |
|---|---|
| $x^{14}$ | $x^7+x^4+x^3+x$ |
| $x^{11}$ | $x^7+x^6+x^4+x^3$ |
| $x^{10}$ | $x^6+x^5+x^3+x^2$ |
| $x^9$ | $x^5+x^4+x^2+x$ |
| $x^8$ | $x^4+x^3+x+1$ |
| $x$ | $x$ |
XOR column by column:
- $x^7$: $1+1=0$
- $x^6$: $1+1=0$
- $x^5$: $1+1=0$
- $x^4$: $1+1+1+1=0$
- $x^3$: $1+1+1+1=0$
- $x^2$: $1+1=0$
- $x^1$: $1+1+1+1=0$
- $x^0$: $1$
$$= 1 \checkmark$$
Final Answer
$$\boxed{b(x)^{-1} = x^7 + x^3 + x}$$
In binary: $1000,1010$, i.e. hexadecimal 8A.
Completing the computation through $t_4$ gives the inverse $x^7+x^3+x$, which multiplies back to $1$.
asked 4xavg 8 marks · 2082, 2081, 2079, 2078AnswerHideDescribe the properties of hash functions. Discuss how hash value is generated using SHA-1 algorithm.[10]
Describe the properties of hash functions. Discuss how hash value is generated using SHA-1 algorithm.[10]
A hash function is a function that maps a message of any length into a fixed-length hash value, which serves as the authenticator. Cryptographic hash functions play a fundamental role in efficient and secure information processing. Prope...
asked 3xavg 7 marks · 2081, 2080, 2076AnswerHideWhy do we need discrete logarithm? Illustrate with an example. Consider a Diffie-Hellman scheme with a common prime p = 13 between user A and user B. Suppose public key of A is 10 and public key of B is 8. Now determine their private keys and shared secret key. Select any valid primitive root of 13.[10]
Why do we need discrete logarithm? Illustrate with an example. Consider a Diffie-Hellman scheme with a common prime p = 13 between user A and user B. Suppose public key of A is 10 and public key of B is 8. Now determine their private keys and shared secret key. Select any valid primitive root of 13.[10]
- Common prime: $p = 13$ - Public key of A: $YA = 10$ - Public key of B: $YB = 8$ - Task: find private keys $XA, XB$ and shared secret $K$, using any valid primitive root of 13. --- Definition. Given a prime $p$, a primitive root $g$, an...
asked 3xavg 5 marks · 2081, 2079, 2076AnswerHideTracing the First Full Round of IDEA Algorithm
IDEA (International Data Encryption Algorithm) is a symmetric block cipher that operates on 64-bit plaintext blocks using a 128-bit key, performing 8 identical rounds with operations: multiplication modulo $2^{16}+1$, addition modulo $2^{16}$, and XOR.
Tracing the First Full Round of IDEA Algorithm
IDEA (International Data Encryption Algorithm) is a symmetric block cipher that operates on 64-bit plaintext blocks using a 128-bit key, performing 8 identical rounds with operations: multiplication modulo $2^{16}+1$, addition modulo $2^{16}$, and XOR.
Subkeys (4-bit each): - $K1 = 1100 = 12$ - $K2 = 1010 = 10$ - $K3 = 0000 = 0$ - $K4 = 1111 = 15$ - $K5 = 0101 = 5$ - $K6 = 1001 = 9$ Input plaintext blocks (4-bit each): - $X1 = 1011 = 11$ - $X2 = 1110 = 14$ - $X3 = 1011 = 11$ - $X4 = 10...
asked 3xavg 5 marks · 2080, 2079, 2076AnswerHideHow substitution ciphers are different from transposition ciphers? Given a message M="CSIT PROGRAM IS A HOT CAKE", encrypt M using Rail Fence cipher with rail size 3. [5]
How substitution ciphers are different from transposition ciphers? Given a message M="CSIT PROGRAM IS A HOT CAKE", encrypt M using Rail Fence cipher with rail size 3. [5]
Feature Substitution Cipher Transposition Cipher --------- Basic idea Each plaintext character is replaced by another character/symbol Character identity is retained but its position is changed Operation Maps letters to other letters via...
asked 3xavg 5 marks · 2082, 2079, 2076AnswerHideDescribe any three types of malicious logic. [5]
Describe any three types of malicious logic. [5]
Malicious Logic
Malicious Logic (Malicious Code / Rogue Programs)
Malicious logic refers to a set of instructions or programs that are intentionally designed to cause harm, unauthorized access, or disruption to a computer system or network.
1. Trojan Horse
A Trojan Horse is a program that appears to perform a legitimate or useful function but secretly contains hidden code that performs unauthorized or harmful actions when executed.
- It does not replicate itself (unlike a virus).
- It tricks the user into running it by disguising itself as a legitimate program.
- Example: A user downloads what appears to be a free game, but the program secretly installs a backdoor, allowing an attacker to gain remote access to the system.
- Damage: Data theft, unauthorized access, system damage.
2. Virus
A virus is a piece of malicious code that attaches itself to a legitimate program or file and replicates when that program is executed. It requires a host program to spread.
- It can spread from one computer to another through infected files, email attachments, or removable media.
- A virus typically has two phases:
- Infection phase: It attaches itself to other programs.
- Attack phase: It performs its malicious activity (deleting files, corrupting data, etc.).
- Example: A virus attached to a
.exefile that corrupts system files when executed. - Damage: File corruption, system crashes, data loss.
3. Worm
A worm is a self-contained, self-replicating program that spreads across networks without needing to attach itself to a host program. Unlike a virus, it does not require user interaction to propagate.
- It exploits vulnerabilities in operating systems or network services to spread automatically.
- Worms consume network bandwidth and system resources, causing slowdowns or crashes.
- Example: The Morris Worm (1988) spread across the Internet by exploiting UNIX vulnerabilities, causing widespread system slowdowns.
- Damage: Network congestion, system resource exhaustion, data theft.
Summary Table
| Type | Replicates? | Needs Host? | Spreads Via |
|---|---|---|---|
| Trojan Horse | No | Yes (disguise) | User deception |
| Virus | Yes | Yes (host file) | Infected files/media |
| Worm | Yes | No | Network/vulnerabilities |
Other types of malicious logic include Logic Bombs (code that triggers under specific conditions) and Trapdoors/Backdoors (hidden entry points left by developers for unauthorized access).
asked 3xavg 5 marks · 2082, 2081, 2076AnswerHideList and explain the types of firewall. [5]
List and explain the types of firewall. [5]
Types of Firewall
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules. It establishes a barrier between a trusted internal network and untrusted external networks.
Types of Firewall
1. Packet Filtering Firewall
- Operates at the Network Layer (Layer 3) of the OSI model.
- Inspects each packet passing through the network and filters them based on rules such as source IP, destination IP, port numbers, and protocols.
- It does not examine the content of the packet.
- Advantage: Fast and efficient.
- Disadvantage: Cannot detect application-level attacks; stateless (does not track connection state).
2. Stateful Inspection Firewall (Dynamic Packet Filtering)
- Operates at the Network and Transport Layer.
- Tracks the state of active connections and makes filtering decisions based on the context of traffic (e.g., whether a packet is part of an established connection).
- Maintains a state table to monitor ongoing sessions.
- Advantage: More secure than simple packet filtering.
- Disadvantage: Slower than packet filtering; cannot inspect application-layer data.
3. Application Layer Firewall (Proxy Firewall)
- Operates at the Application Layer (Layer 7).
- Acts as an intermediary (proxy) between the client and the server; it intercepts all messages entering and leaving the network.
- Can inspect the full content of network traffic including HTTP, FTP, DNS, etc.
- Advantage: Provides deep packet inspection; hides internal network details.
- Disadvantage: Slower performance due to deep inspection; requires more resources.
4. Circuit-Level Gateway
- Operates at the Session Layer (Layer 5).
- Monitors TCP handshaking and session establishment to determine whether a requested session is legitimate.
- Does not inspect the actual content of the packets.
- Advantage: Faster than application-layer firewalls; hides internal network information.
- Disadvantage: Cannot filter individual packets after the session is established.
5. Next-Generation Firewall (NGFW)
- Combines the features of traditional firewalls with advanced capabilities such as:
- Deep Packet Inspection (DPI)
- Intrusion Prevention System (IPS)
- Application awareness and control
- SSL/TLS inspection
- Can identify and block sophisticated attacks including malware and application-layer threats.
- Advantage: Comprehensive security; highly effective against modern threats.
- Disadvantage: Expensive and complex to configure.
Summary Table
| Type | OSI Layer | Key Feature |
|---|---|---|
| Packet Filtering | Network (L3) | Filters by IP/port rules |
| Stateful Inspection | Network/Transport | Tracks connection state |
| Application Layer (Proxy) | Application (L7) | Deep content inspection |
| Circuit-Level Gateway | Session (L5) | Monitors TCP handshake |
| Next-Generation Firewall | Multiple Layers | DPI + IPS + App control |
asked 2xavg 8 marks · 2081, 2076AnswerHideWhat is Message Authentication Code? List the operation of computing digest value in different passes of MD4. Describe about Needhom-Schroeder protocol.[10]
What is Message Authentication Code? List the operation of computing digest value in different passes of MD4. Describe about Needhom-Schroeder protocol.[10]
--- Definition: A Message Authentication Code (MAC) is a function of the message and a secret key that produces a fixed-length value that serves as the authenticator. Working Principle: - This technique assumes that the sender and receiv...
asked 2xavg 5 marks · 2081, 2078AnswerHideWhat is intrusion? Explain any two types of intrusion detection system. [5]
What is intrusion? Explain any two types of intrusion detection system. [5]
Intrusion and Intrusion Detection Systems
What is Intrusion?
Intrusion detection is the process of identifying and responding to malicious activity targeted at a resource. An intrusion refers to any unauthorized attempt to access, manipulate, or compromise a system's resources, data, or services.
An Intrusion Detection System (IDS) is a system designed to test/analyze network system traffic/events against a given set of parameters and alert/capture data when these thresholds are met. IDS uses collected information and pre-defined knowledge-based systems to reason about the possibility of an intrusion. It also provides services to cope with intrusion such as giving alarms and activating programs to deal with intrusion.
Two Types (Approaches) of Intrusion Detection System
1. Statistical Anomaly Detection
Statistical anomaly detection involves the collection of data relating to the behaviours of legitimate users over a period of time. Then statistical tests are applied to observed behaviour to determine with a high level of confidence whether the behaviour is that of a legitimate user or not.
It falls into two broad categories:
-
Threshold Detection:
- Involves counting the number of occurrences of a specified event type over an interval of time.
- If the count exceeds a reasonable number, an intrusion is assumed.
- Example: Too many failed login attempts within a short time.
-
Profile-Based Anomaly Detection:
- Focuses on characterizing the past behaviour of individual users or related groups of users.
- Significant deviations from the established profile are flagged as potential intrusions.
2. Rule-Based Detection
Rule-based detection involves an attempt to define a set of rules that can be used to decide whether a given behaviour is that of an intruder.
It falls into two broad categories:
-
Rule-Based Anomaly Detection:
- Historical audit records are analyzed to identify usage patterns.
- Rules are generated automatically to describe those patterns.
- Any behaviour that deviates from these rules is flagged as suspicious.
-
Rule-Based Penetration Identification:
- Uses rules for identifying known penetrations or penetrations that would exploit known weaknesses.
- Rules are typically defined by security experts based on known attack signatures.
- Example: A rule that detects a specific sequence of commands known to exploit a vulnerability.
Summary Table:
| Approach | Basis | Method |
|---|---|---|
| Statistical Anomaly Detection | Behaviour deviation from normal | Threshold / Profile-based |
| Rule-Based Detection | Predefined rules | Anomaly rules / Penetration rules |
asked 2xavg 5 marks · 2080, 2078AnswerHideWrite down the encryption and decryption process at 2-DES and 3-DES. Explain the Fiestal cipher structure. Divide $5x^2 + 4x + 6$ by $2x + 1$ over GF(7). [10]
Write down the encryption and decryption process at 2-DES and 3-DES. Explain the Fiestal cipher structure. Divide $5x^2 + 4x + 6$ by $2x + 1$ over GF(7). [10]
--- 2-DES applies the DES algorithm twice with two independent keys $K1$ and $K2$ (each 56 bits, giving 112-bit effective key length). Encryption: $$C = E{K2}(E{K1}(P))$$ Plaintext $P$ is first encrypted with $K1$ to give an intermediate...
asked 2xavg 10 marks · 2079, 2076AnswerHideShow that Z 5 is a field. John publishes the ElGamal public key (q, α, YA) =(101, 2, 14). Jane desired to send the secret message CSIT to John. Using the equivalence A = 0, B=1, ..., Z=25, encrypt the message using John’s public key. Use a random number k = 4.[10]
Show that Z 5 is a field. John publishes the ElGamal public key (q, α, YA) =(101, 2, 14). Jane desired to send the secret message CSIT to John. Using the equivalence A = 0, B=1, ..., Z=25, encrypt the message using John’s public key. Use a random number k = 4.[10]
--- Field problem: - Set: $\mathbb{Z}5 = {0,1,2,3,4}$ under addition and multiplication mod 5. ElGamal problem: - Public key: $(q, \alpha, YA) = (101, 2, 14)$ - Message: "CSIT" - Encoding: $A=0, B=1, \dots, Z=25$ - Random number: $k = ...
asked 2xavg 3 marks · 2080, 2078AnswerHideGive the formal definition of authentication system. Describe about one way and mutual authentication system. [3257]
Give the formal definition of authentication system. Describe about one way and mutual authentication system. [3257]
An Authentication System is a security measure put in place to secure data and systems by requiring additional input beyond username and password for users to access a system. Formally, an authentication system is defined as a 5-tuple: $...
asked 2xavg 8 marks · 2079, 2078AnswerHideHow direct digital signature different from arbitrated digital signature? How digital signature generation and verification is done using RSA. [5]
How direct digital signature different from arbitrated digital signature? How digital signature generation and verification is done using RSA. [5]
--- - Involves only two parties: the sender and the receiver. - The sender signs the message using their private key. - The receiver verifies the signature using the sender's public key. - No third party is involved in the process. - Wea...
Study every one of these with model answers, flashcards, and MCQs.
Open CSC327 study modes