How do nist criteria for selection of des and aes

Assignment Help Computer Network Security
Reference no: EM13336618

Part A :

Answer the following questions :

1. The total processing speed of microprocessors (based on clock rate and number of circuits) is doubling roughly every year. Today, a symmetric session key needs to be 100 bits long to be considered strong. How long will a symmetric session key have to be in 30 years to be considered strong?

2. How do NIST criteria for selection of DES and AES relate to Shanon's original standards of a good cryptographic system? What are the significant differences? How do these standards reflect a changed environment many years after Shannon wrote his standards?

3. A program is written to compute the sum of the integers from 1 to 10. The programmer, well trained in reusability and maintainability, writes the program so that it computes the sum of the numbers from k to n. However, a team of security specialists scrutinizes the code. The team certifies that this program properly sets k to 1 and n to 10; therefore, the program is certified as being properly restricted in that it always operates on precisely the range 1 to 10.

(a) Explain different ways that this program can be sabotaged so that during execution it computes a different sum, for example, 3 to 20.

(b) One means of limiting the effect of an untrusted program is confinement: controlling what processes have access to the untrusted program and what access the program has to other processes and data. Explain how confinement would apply to the above example.

4. The distinction between a covert storage channel and a covert timing channel is not clear-cut. Every timing can be transformed into an equivalent storage channel. Explain how this transformation could be done.

Part B :

1. Research the TJX data breach case on the web and answer the following questions.

a. Was the TJX break-in due to a single security weakness or multiple security weaknesses? Explain.
b. Suggest a set of measures which probably would have prevented the TJX data breach. Justify your answer.
c. Which of the CIA goals did TJX fail to achieve in this attack?

Rationale
This assessment task is based on the following topics discussed in the subject: the overview of Information security fundamentals, security threats, cryptography, malicious software and its countermeasures, operating system security and software security .

The assessment task is aligned with the following learning outcomes of the subject:

On successful completion of this subject, students will

be able to justify security goals and the importance of maintaining the secure computing environment against digital threats;
be able to explain the fundamental concepts of cryptographic algorithms;
be able to examine malicious activities that may affect the security of a computer program and justify the choice of various controls to mitigate threats.

Reference no: EM13336618

Questions Cloud

How do these standards reflect a changed environment : Explain different ways that this program can be sabotaged so that during execution it computes a different sum, for example, 3 to 20.
Explain bacteria to inactivate the antibiotic penicillin : Penicillase is an enzyme secreted by bacteria to inactivate the antibiotic penicillin. The enzyme has a molar mass of 30,000 and a single active site. The catalytic rate constant is 2000 s-1 and the Michaelis constant is KM = 5 x 10-5 M.
What is the magnetic moment of the loop : The plane of a 6.0 cm × 8.0 cm rectangular loop of wire is parallel to a 0.16-T magnetic field. The loop carries a current of 6.8 A. What is the magnetic moment of the loop
Explain the molar mass of a protein is from a measurement : The molar mass of a protein is determined from a measurement of the osmotic pressure. If 0.01 grams of the protein is dissolved in 1 ml. and osmotic pressure of 5 x 10-3 atm develops at a temperature of 310 K, what is the molar mass of the protein..
How do nist criteria for selection of des and aes : How do NIST criteria for selection of DES and AES relate to Shanon's original standards of a good cryptographic system? What are the significant differences? How do these standards reflect a changed environment many years after Shannon wrote his s..
What is the discharging current : A parallel-plate capacitor with circular plates of radius R is being discharged. What is the discharging current
Find the net downward force on the tanks flat bottom : The pressure at the surface of the water will be 140kPa , and the depth of the water will be 13.8m . The pressure of the air in the building outside the tank will be 87.0kPa
How much displacement current is encircled by the loop : A capacitor with parallel circular plates of radius R = 1.65 cm is discharging via a current of 16.5 A. How much displacement current is encircled by the loop
Explain the maximum age of a sample : What is the maximum age of a sample that can be measured by 14C dating if the error of measurement is 0.5%

Reviews

Write a Review

Computer Network Security Questions & Answers

  Is there any way that eve can read encrypted communications

Suppose that Eve runs a key server. Alice downloads a key from the key server which Eve claims is Bob's public key. Bob downloads a key from the key server which Eve claims is Alice's public key.

  Strong ciphers produced by the enigma machine

Concur with, dispute, or qualify following statement: "The strong ciphers produced by Enigma machine are  result of complex mathematical trapdoor functions used to encrypt messages."

  Explaining wan links for point-to-point home office address

Servers, administrative and support users 2 subnets with 50 hosts for faculty & student labs 10 or more WAN links for point-to-point home office address. Design the subnet?

  What is the value of shared secret key

You have secretly picked the value SA = 17. You begin the session by sending Bob your calculated value of TA. Bob responds by sending you the value TB = 291. What is the value of your shared secret key?

  Explain the various strategies to prevent such cyber warfare

Need a 1000 word paper on the various recent/news on the United States (particular the group known as Anonymous and Lulzsec).

  What is the difference between inference and aggregation

What is the difference between inference and aggregation? Give an example of each, and describe at least one way to mitigate each type of vulnerability.

  Develop paper where you address digital forensics tools

Develop a paper where you address three digital forensics tools in the following categories: availability, pricing, platforms supported, technical strengths and weaknesses, etc

  Discuss the risks of having a single root user

Originally Linux/UNIX systems had one all-powerful user called root that managed systems. Discuss the risks of having a single root user and how more limited management abilities can be given to others users on Linux/UNIX systems.

  How clark -wilson model is implemented on computer system

Assume that the Clark -Wilson model is implemented on a computer system. Could a computer virus that scrambled constrained data items be introduced into the system?

  Define the repository usernames and passwords

Install the distributed revision control system subversion from the Debian package of the same name. After installation you will need to configure subversion to be usable.

  Analyse potential attacks and give a method of prevention

Write a key exchange protocol for A and B to share a symmetric key. Analyse potential attacks and give a method of prevention and write a key exchange protocol for A and B to share a session key. Must consider mutual authentication, freshness, inte..

  Perspective of current hot topics in information security

Build an understanding and perspective of current hot topics in Information Security and build generic skills including

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd