Was the tjx break-in due to a single security weakness

Assignment Help Computer Network Security
Reference no: EM13336743

Answer the following questions :

1. The total processing speed of microprocessors (based on clock rate and number of circuits) is doubling roughly every year. Today, a symmetric session key needs to be 100 bits long to be considered strong. How long will a symmetric session key have to be in 30 years to be considered strong?

2. How do NIST criteria for selection of DES and AES relate to Shanon's original standards of a good cryptographic system? What are the significant differences? How do these standards reflect a changed environment many years after Shannon wrote his standards?

3. A program is written to compute the sum of the integers from 1 to 10. The programmer, well trained in reusability and maintainability, writes the program so that it computes the sum of the numbers from k to n. However, a team of security specialists scrutinizes the code. The team certifies that this program properly sets k to 1 and n to 10; therefore, the program is certified as being properly restricted in that it always operates on precisely the range 1 to 10.

(a) Explain different ways that this program can be sabotaged so that during execution it computes a different sum, for example, 3 to 20.

(b) One means of limiting the effect of an untrusted program is confinement: controlling what processes have access to the untrusted program and what access the program has to other processes and data. Explain how confinement would apply to the above example.

4. The distinction between a covert storage channel and a covert timing channel is not clear-cut. Every timing can be transformed into an equivalent storage channel. Explain how this transformation could be done.

Part B :

1. Research the TJX data breach caseon the web and answer the following questions.
a. Was the TJX break-in due to a single security weakness or multiple security weaknesses? Explain.
b. Suggest a set of measures which probably would have prevented the TJX data breach. Justify your answer.
c. Which of the CIA goals did TJX fail to achieve in this attack?

Reference no: EM13336743

Questions Cloud

Find the mass flow rate : Refrigerant-22 enters a turbine at 300 psi, 280°F, 2000 ft3/hr. The exit is at 15 psi, 10°F. Find the mass flow rate
Explain place drying tube filled with cacl2 on condenser : Place drying tube filled with CaCl2 on condenser. Heat to reflux at 190 C for 25 minutes then cool. Add 0.5mL tolulene and petroleum ether 0.5-0.75 mL until slight cloudiness remains. Reheat until clear and cool in ice bath. Collect product and wa..
Determine the moment of inertia of the pulley : Two blocks, one of 50 g and the other of 46 g, are connected by a string and hung over a frictionless pulley which has a radius of 5 cm. What is the moment of inertia of the pulley
Evaluate the value of ksp for pbf2 : One liter of water will dissolve 2.15* 10^-3 mol of PbF2 at 25 degrees c. Calculate the value of ksp for PbF2.
Was the tjx break-in due to a single security weakness : Explain different ways that this program can be sabotaged so that during execution it computes a different sum, for example, 3 to 20.
What is its angular velocity and its total kintetic energy : A 20 kg piece of steel pipe that is 20 cm in diameter, 80 cm long, What is its angular velocity and its total kintetic energy
Define the heat capacity of the bomb : Its volume has been accurately determine to be 3226.7kj/m. 2.5127 gm benzoic acid are burned in a carorimter the temperatuer rises from 20.84 to 25.67degree. What is the heat capacity of the bomb.
Explain the hybridization of the central atom : Predict the electron-domain geometry, the molecular geometry, and the hybridization of the central atom. For each non ionic species, state whether it will be polar or nonpolar. a) SeO2 b) XeF4 c) PCL5 d) BrF2-
Calculate thickness of layer between 1000 and 500mb : Calculate the thickness of the layer between the 1000- and 500mb pressure surfaces (a) at a point in the tropics where the mean virtual temp of the layer is 9C and (b) at a point in the polar regions

Reviews

Write a Review

Computer Network Security Questions & Answers

  Application to input a character string

Output the string rotated to the right by a user-defined number of characters (0 or more). For example, Hello world!rotated by two characters would be: Hello world.

  Denial of service and distributed denial of service attacks

US cryptography export restrictions: past, present, and future and biometrics for authentication: security and privacy implications.

  Network security

SLE, ARO, and ALE, behavioural biometric technology, Enterprise Information Security Policy, Issue Specific Security Policy, System Specific Security Policy, firewalls protect network, creating a DMZ during firewall implementation, use of SSL to se..

  Analyse potential attacks and give a method of prevention

Write a key exchange protocol for A and B to share a symmetric key. Analyse potential attacks and give a method of prevention and write a key exchange protocol for A and B to share a session key. Must consider mutual authentication, freshness, inte..

  What if ipsec provides security at the network layer

If IPSec provides security at the network layer, why is it that security mechanisms are still needed at layers above IP?

  Develop paper where you address digital forensics tools

Develop a paper where you address three digital forensics tools in the following categories: availability, pricing, platforms supported, technical strengths and weaknesses, etc

  Academic method to project management

Sunnyville Corporation is in the business of selling home appliances. Sunnyville Corporation  has over 50 sales agents across the country. The management at Sunnyville Corporation has decided to implement an online sales program.

  Defects of gsm networks

Security mechanism, threat, GSM networks, DDoS attacks, IPv4, IPv6, IPsec integrity, authentication and privacy, IPsec AH,  ‘single sign-on' in the context of access control, Secure Electronic Transaction (SET) protoco,  Encryption

  Turtle shell architecture

Turtle Shell Architecture, zero-byte representation, Access Control List, DNS Cache Poisoning attack, 16-pass iterative and 9-pass recursive PHP function

  Which of risks gci faces are most significant to company

What measures would you propose to senior management to try to prevent a breach of data held by GCI? Your response should include recommendations for mitigating vulnerabilities identified in part (a).

  Developing a simple biometric authentication model

Developing an encryption/decryption demo (mainly for learning and teaching purposes)

  A virus is a program that attaches itself to other programs

A virus is a program that attaches itself to other programs. An infected user must take some sort of action to spread a virus to others. A worm functions as an independent program

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd