What are the possible flaws in this protocol

Assignment Help Computer Network Security
Reference no: EM13683419

1. General Security Concepts

Identify which security requirement was violated in the following cases:

a. Eve peeks at Alice's password when she logs in.

b. Eve logs into Alice's account and stops the web server that was running.

c. There is a process running in Alice's machine, which is updating a database from a remote machine. Eve interrupts the process, resulting in inconsistent database.

2. Symmetric Encryption

Padding may not always be appropriate. For example, one might wish to store the encrypted data in the same memory buffer that originally contained the plaintext. In that case, the ciphertext must be the same length as the original plaintext. A mode for that purpose is the ciphertext stealing (CTS) mode. Figure (a) below shows an implementation of this mode.

780_General Security Concepts.png

a. Explain how it works.
b. Describe how to decrypt Cn _i and Cn.

3. Public-Key Cryptography and Message Authentication

1. Suppose Bob uses the RSA cryptosystem with a very large modulus n for which the factorization cannot be found in a reasonable amount of time. Suppose Alice sends a message to Bob by representing each alphabetic character as an integer between 0 and 25 (A ^ 0, . . ., Z ^ 25), and then encrypting each number separately using RSA with large e and large n. Is this method secure? If not, describe the most efficient attack against this encryption method.

Consider the following PKI system: An arrow from A to B (A ^ B) means that A issued a certificate for B's public key. Assume further that everybody in the system trusts A and has A's certificate:

A SI *
B C
G

In order for B to send a confidential message to G, B must acquire G's public key. Assume anyone knows only its own public/private keys. What is the chain of certificates that B needs to acquire and verify?

4. Key Distribution and User Authentication

The following is a proposed mutual authentication protocol:

Alice
Hi, I'm Alice

Hash(KAiice.Bob, Random + 1)

What are the possible flaws in this protocol? Propose how to fix the possible flaws with minimal modifications to the protocol.

5. Transport-Level Security/IP Level Security

Make some recommendations about how you would implement transport-level security and/or IP level Security for the following use cases:

a. Your company has an e-commerce website that accepts credit card payments. Your clients could use any browser to access your website, and they might not have any prior relationship with your company. You want to make sure that they "feel" safe when they access your website. You do not want any third party to eavesdrop on the communications between your clients and your website, as they could steal credit card numbers from your clients. You do not want any third party to be able to modify, inject or replay any traffic during the session.

b. Your company has a back office servers that need to be accessed by mobile/remote employees through the Internet. Those servers are critical to the operation of your business: You do not want unauthorized users to be able to access the back office servers. You do not want any third party to eavesdrop on the communications to/from your back office servers. You do not want your remote employees to connect to a 'rogue' back office server. Finally, you want to be protected against injection and replay attacks.

For each use case, please indicate how you would configure the servers and the clients, i.e., how should SSL, SSH or IPSec be parameterized on you servers/clients (You do not need to provide the exact commands or directives, but you should give details, such as the protocols versions/types to be used, ...). Also indicate which key materials are needed and how they are distributed/acquired.

 

Reference no: EM13683419

Questions Cloud

Find what the time rate of change of the electric field : The circular plates of a parallel plate capacitor have a radius of 27 centimeter. Find the time rate of change of the electric field between the plates
Determine what the displacement current : A 3.27 µF parallel plate capacitor is subjected to a changing potential difference between its plates. determine what the displacement current
Estimate the maximum speed it will reach : A proud deep-sea fishermen hangs an 61 kilogram fish from an ideal spring having negligible mass. The fish stretches the spring 0.130 meter. Estimate the maximum speed it will reach
Find how far is the object from the equilibrium position : An object is undergoing SHM with period 1.200 second and amplitude 0.530 meter. At t = 0 the object is at x = 0. Find how far is the object from the equilibrium position when t = 0.540 s
What are the possible flaws in this protocol : Identify which security requirement was violated in the cases and what are the possible flaws in this protocol? Propose how to fix the possible flaws with minimal modifications to the protocol.
Obtain what the speed of the water leaving end of the hose : Water flowing through a garden hose of diameter 2.71 centimeter fills a 25.0 L bucket in 1.50 minute. Obtain the speed of the water leaving end of the hose
Find what the amplitude at a point on the string : A series of pulses of amplitude 0.22 meter is sent down a string that is attached to a post at one end. Find the amplitude at a point on the string where two pulses are crossing, if the string is rigidly attached to the post
Obtain what the magnitude of the net gravitational force : A 160 kilogram object and a 460 kilogram object are separated by 4.70 meter. Obtain the magnitude of the net gravitational force exerted by these objects on a 30 kilogram object located midway between them
Find the current in the circuit : A series circuit consisting of an unchanged 2.0 µF capacitor and a 10-Mega ohms resistor is connected across a 100 Volt power source. Find the current in the circuit and the charge on the capacitor

Reviews

Write a Review

Computer Network Security Questions & Answers

  Use private key to decrypt the cipher text

Using blocks of 4 encrypt the message I AM AN MSC STUDENT MAJORING IN SECURITY using the public key above. Similarly use the private key above to decrypt the cipher text.

  What is the actual running environment of tool

What is the functionality of the tool and what is the actual running environment (software and hardware) of the tool?

  Why one-time password system more secure authentication

Why is one-time password system considered more secure than the basic authentication system? Give at least two reasons.

  Why is a firewall a good place to implement a vpn

Security decision making should be based on rational thinking and sound judgement. In this context critique five security design principles with suitable examples.

  What is the encrypted message entropy

Consider the following plaintext message: FAIN 460 9043 IS A GRADUATE COURSE.

  Dos attackers use zombies to attack victims

Why do you think DoS attackers use zombies to attack victims instead of sending attack packets directly to victims? Come up with two reasons.

  How many bits is the encrypted message

Based on the understanding of Q4 of Bart B, use the generated keys of Q2 - Part C to encrypt the message of Q1 - Part C using the Simplified DES algorithm.

  Analyze the header files of spams

Analyze the header files of spams. The file 199803.zip is a collection of spams received by someone during 1998 March (http://untroubled.org/spam/, other spam archives could be found at:http://spamlinks.net/filter-archives.htm, etc.).

  Find one example of password protocols in microsoft product

Find one example of password protocols in Microsoft product and discuss its security or insecurity with your colleagues. If possible, install one of the available cracking tools to see whether you could crack this system and share your experience ..

  Question about substitution ciphers

Think about two substitution ciphers. One adds a value of i to the ASCII code of the plain text character. The other adds a price of j to the plaintext character. All additions are modulo 256.

  Which will encrypt each users data in a file

Acme Inc. is developing the next generation financial tracking program, and Alice has been given the task of writing the encryption component, which will encrypt each user's data in a file on the hard drive.

  Explain the meaning the terms granularity

In reference to access control explain the meaning the terms "granularity". Discuss the trade-off between granularity and efficiency.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd