{"id":5,"date":"2018-07-11T08:43:16","date_gmt":"2018-07-11T08:43:16","guid":{"rendered":"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/2018\/07\/11\/chapter-1\/"},"modified":"2022-01-06T10:36:58","modified_gmt":"2022-01-06T10:36:58","slug":"chapter-1","status":"publish","type":"chapter","link":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/chapter\/chapter-1\/","title":{"rendered":"Cryptography"},"content":{"raw":"<div><span style=\"float: right;\"><a href=\"https:\/\/youtu.be\/YOwkywM5fwY\" target=\"_blank\" rel=\"noopener noreferrer\"><img src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"epgp books\" width=\"75px\" height=\"75px;\" \/><\/a>\r\n<\/span><\/div>\r\nModule 1: Introduction to cryptography, key principles of security, security mechanisms, security services, threat, attack, the information systems security engineering process.\r\n\r\n<strong>Types of security :<\/strong>\r\n<table class=\"aligncenter\" border=\"1\">\r\n<tbody>\r\n<tr>\r\n<td style=\"width: 88.0625px;\">Information<\/td>\r\n<td style=\"width: 572.063px;\">Protecting\u00a0 information\u00a0 (physical\u00a0 or\u00a0 digital)\u00a0 from<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 88.0625px;\">Security<\/td>\r\n<td style=\"width: 572.063px;\">unauthorized\u00a0 access,\u00a0 use,\u00a0 disclosure,\u00a0 disruption,<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 88.0625px;\"><\/td>\r\n<td style=\"width: 572.063px;\">modification or destruction.<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 88.0625px;\">Computer<\/td>\r\n<td style=\"width: 572.063px;\">To protect files and other information stored on the computer. Computer may<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 88.0625px;\">Security<\/td>\r\n<td style=\"width: 572.063px;\">be time shared or part of public telephone network, data network or the<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 88.0625px;\"><\/td>\r\n<td style=\"width: 572.063px;\">internet.<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 88.0625px;\"><\/td>\r\n<td style=\"width: 572.063px;\"><\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 88.0625px;\">Network<\/td>\r\n<td style=\"width: 572.063px;\">To protect data, when data is transmitted between computer to computer.<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 88.0625px;\">Security<\/td>\r\n<td style=\"width: 572.063px;\"><\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 88.0625px;\"><\/td>\r\n<td style=\"width: 572.063px;\"><\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\nSecurity Violation :\r\n\r\n<img class=\" wp-image-22 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-1-300x147.png\" alt=\"\" width=\"657\" height=\"322\" \/>\r\n\r\n<img class=\" wp-image-23 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-2-300x136.png\" alt=\"\" width=\"618\" height=\"280\" \/>\r\n\r\n&nbsp;\r\n\r\n<img class=\" wp-image-24 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-3-300x133.png\" alt=\"\" width=\"562\" height=\"249\" \/>\r\n\r\n<img class=\"wp-image-25 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-4-300x139.png\" alt=\"\" width=\"803\" height=\"372\" \/>\r\n\r\n<strong>The OSI Security Architecture:<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify;\">The International Telecommunication Union(ITU) Telecommunication Standardization Sector(ITU-T) develops standards relating to open systems interconnection(OSI). OSI security architecture was developed in the context of the OSI protocol architecture.<\/p>\r\n&nbsp;\r\n\r\n<strong>The OSI Security Architecture:<\/strong>\r\n\r\n&nbsp;\r\n<ol start=\"3\">\r\n \t<li><strong>Security attack: <\/strong>If information owned by an organization is compromised by any action, it is called security attack.<\/li>\r\n \t<li><strong>Security mechanism: <\/strong>Security mechanism is a process that is designed to detect, prevent or recover from a security attack.<\/li>\r\n \t<li><strong>Security service: <\/strong>Security service is used to mitigate security attack by using one or more security mechanism.<\/li>\r\n<\/ol>\r\n<strong>Security Policy<\/strong>: An Information Technology (IT) Security Policy identifies the rules and procedures for all who are accessing and using an organization's IT assets and resources.\r\n\r\n&nbsp;\r\n\r\n<strong>Vulnerabilities, Threats, Attacks(RFC 2828):<\/strong>\r\n\r\n&nbsp;\r\n<ul>\r\n \t<li>A vulnerability is a weakness in the security system.<\/li>\r\n \t<li>A threat is a potential cause of an incident, that may result in harm of systems and organization.<\/li>\r\n \t<li>An attack is an assault on system security that derives from an intelligent threat, i.e., an intelligent act that is a deliberate attempt (especially in the sense of a method or technique) to evade security services and violate the security policy of a system.<\/li>\r\n<\/ul>\r\n<strong>Example of Attack( Password Guessing ):<\/strong>\r\n\r\n&nbsp;\r\n\r\nPassword :\r\n\r\nThe attacker tries to guess the password.\r\n\r\n&nbsp;\r\n\r\n<strong>Security Attacks:<\/strong>\r\n<ul>\r\n \t<li><strong>Passive attack: <\/strong>The attacker collects the information or make use of collected information but do not modify any resources so system resources are not affected.<\/li>\r\n \t<li><strong>Active attack: <\/strong>The attacker changes or actions are altered.<\/li>\r\n<\/ul>\r\n<strong>Types of Passive Attacks:<\/strong>\r\n<ul>\r\n \t<li>Release of message content.<\/li>\r\n \t<li>Traffic analysis.<\/li>\r\n<\/ul>\r\n&nbsp;\r\n\r\n<strong>Types of Active Attacks:<\/strong>\r\n<ul>\r\n \t<li>Masquerade<\/li>\r\n \t<li>Replay<\/li>\r\n \t<li>Modification of messages<\/li>\r\n \t<li>Denial of service<\/li>\r\n<\/ul>\r\n<strong>Security Services(X.800):<\/strong>\r\n<ul>\r\n \t<li><strong>Authentication<\/strong><\/li>\r\n<\/ul>\r\nThe parties exchanging information are truly the same parties that they claim to be.\r\n<ul>\r\n \t<li><strong>Access control<\/strong><\/li>\r\n<\/ul>\r\nUnauthorized persons can not use the resources.\r\n<ul>\r\n \t<li><strong>Confidentiality<\/strong><\/li>\r\n<\/ul>\r\nUnauthorized disclosure of data is not done.\r\n<ul>\r\n \t<li><strong>Integrity<\/strong><\/li>\r\n<\/ul>\r\nData received is same as sent by an authorized person. No modification done.\r\n\r\n&nbsp;\r\n\r\n<strong>Nonrepudiation<\/strong>\r\n\r\nSender or receiver cannot deny that the message was sent and was received.\r\n\r\n&nbsp;\r\n\r\n<strong>Security Mechanisms<\/strong>:\r\n\r\n&nbsp;\r\n<table class=\"aligncenter\" style=\"height: 619px;\" border=\"1\">\r\n<tbody>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\">Encipherment<\/td>\r\n<td style=\"width: 531.063px; height: 28px;\">Use mathematical algorithm . The data is transformed from one<\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\r\n<td style=\"width: 531.063px; height: 28px;\">form to another by using algorithm and key, which is difficult to<\/td>\r\n<\/tr>\r\n<tr style=\"height: 31px;\">\r\n<td style=\"width: 129.063px; height: 31px;\"><\/td>\r\n<td style=\"width: 531.063px; height: 31px;\">understand.<\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\r\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\">Digital<\/td>\r\n<td style=\"width: 531.063px; height: 28px;\">Appended data so that the receiver can identify and<\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\">signature<\/td>\r\n<td style=\"width: 531.063px; height: 28px;\">verify the source.<\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\r\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\">Access control<\/td>\r\n<td style=\"width: 531.063px; height: 28px;\">Mechanisms that enforce access rights to resources.<\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\r\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\">Data Integrity<\/td>\r\n<td style=\"width: 531.063px; height: 28px;\">Mechanisms to assure the integrity of data.<\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\r\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\">Authentication<\/td>\r\n<td style=\"width: 531.063px; height: 28px;\">Mechanism to ensure identity by exchanging information.<\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\">Exchange<\/td>\r\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\r\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\">Traffic padding<\/td>\r\n<td style=\"width: 531.063px; height: 28px;\">To get rid of traffic analysis, some bits are inserted into<\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\r\n<td style=\"width: 531.063px; height: 28px;\">data.<\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\r\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\">Routing<\/td>\r\n<td style=\"width: 531.063px; height: 28px;\">In case of security threat, secure routing path is selected.<\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\">Control<\/td>\r\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\r\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\">Notarization<\/td>\r\n<td style=\"width: 531.063px; height: 28px;\">For data exchange, trusted third party is used.<\/td>\r\n<\/tr>\r\n<tr style=\"height: 28px;\">\r\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\r\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<strong>Cryptography :<\/strong>\r\n<ul>\r\n \t<li>Original message is called plaintext.<\/li>\r\n \t<li>Coded message is called ciphertext.<\/li>\r\n \t<li>Process of converting plaintext to ciphertext is known as enciphering or encryption.<\/li>\r\n \t<li>Retrieving plaintext from the ciphertext is deciphering or decryption.<\/li>\r\n \t<li>Schemes used for encryption \u2013 decryption is called cryptography.<\/li>\r\n \t<li>Cryptanalysis is about breaking the code.<\/li>\r\n<\/ul>\r\n<strong>Encryption algorithms \u2013 Symmetric Encryption:<\/strong>\r\n\r\n&nbsp;\r\n<ul>\r\n \t<li>C=E(K,P) Where C is the ciphertext, P is the plaintext, E is Encryption algorithm and K is the key.<\/li>\r\n \t<li>P=D(K,C) Where P is plaintext, C is ciphertext, D is decryption algorithm and K is the key.<\/li>\r\n \t<li>Encryption and Decryption keys are same. So this form is called symmetric encryption.<\/li>\r\n<\/ul>\r\n<strong>Encryption algorithms \u2013 Asymmetric Encryption:<\/strong>\r\n<ul>\r\n \t<li>C=E(KE,P) Where C is the ciphertext, P is the plaintext, E is Encryption algorithm and KE is the encryption key.<\/li>\r\n \t<li>P=D(KD,C) Where P is plaintext, C is ciphertext, D is decryption algorithm and KD is the decryption key.<\/li>\r\n \t<li>Encryption and Decryption keys are different. So this form is called Asymmetric encryption.<\/li>\r\n<\/ul>\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n<strong>Characteristics of cryptographic systems:<\/strong>\r\n\r\n&nbsp;\r\n<ol>\r\n \t<li>The type of operations used for transforming plaintext to ciphertext. Substitution<\/li>\r\n<\/ol>\r\ntransposition\r\n<ol start=\"2\">\r\n \t<li>The number of keys used.<\/li>\r\n \t<li>The method in which processing of plaintext is done.<\/li>\r\n<\/ol>\r\nBlock cipher\r\n\r\nStream cipher\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n<strong>Cryptanalysis:<\/strong>\r\n\r\n&nbsp;\r\n\r\nCryptanalysis is to recover the key by attacking the encryption system instead of recovering the plaintext or ciphertext.\r\n\r\n&nbsp;\r\n\r\n<img class=\"size-full wp-image-26 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-5.png\" alt=\"\" width=\"803\" height=\"345\" \/>\r\n\r\n<strong>Cryptanalytic attack<\/strong>: These types of attacks depend on amount of information known.\r\n<ul>\r\n \t<li>[1] Cryptography and Network Security Principles and Practices \u2013 William Stallings.<\/li>\r\n<\/ul>\r\n&nbsp;\r\n<table class=\"aligncenter\" style=\"width: 951px;\" border=\"1\">\r\n<tbody>\r\n<tr>\r\n<td style=\"width: 117.063px;\">Type of Attack<\/td>\r\n<td style=\"width: 435.063px;\"><\/td>\r\n<td style=\"width: 356.063px;\">Known to cryptanalyst<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\">Ciphertext only<\/td>\r\n<td style=\"width: 435.063px;\">\u2022<\/td>\r\n<td style=\"width: 356.063px;\">Encryption algorithm<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\"><\/td>\r\n<td style=\"width: 435.063px;\">\u2022<\/td>\r\n<td style=\"width: 356.063px;\">Ciphertext<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\">Known plaintext<\/td>\r\n<td style=\"width: 435.063px;\">\u2022<\/td>\r\n<td style=\"width: 356.063px;\">Encryption algorithm<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\"><\/td>\r\n<td style=\"width: 435.063px;\">\u2022<\/td>\r\n<td style=\"width: 356.063px;\">Ciphertext<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\"><\/td>\r\n<td style=\"width: 435.063px;\">\u2022\u00a0\u00a0 One or more plaintext-ciphertext pairs formed with the secret key.<\/td>\r\n<td style=\"width: 356.063px;\"><\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\">Chosen plaintext<\/td>\r\n<td style=\"width: 435.063px;\">\u2022<\/td>\r\n<td style=\"width: 356.063px;\">Encryption algorithm<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\"><\/td>\r\n<td style=\"width: 435.063px;\">\u2022<\/td>\r\n<td style=\"width: 356.063px;\">Ciphertext<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\"><\/td>\r\n<td style=\"width: 435.063px;\">\u2022\u00a0\u00a0 Plaintext<\/td>\r\n<td style=\"width: 356.063px;\">message\u00a0 chosen\u00a0 by\u00a0 cryptanalyst,\u00a0 together\u00a0 with\u00a0 its<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\"><\/td>\r\n<td style=\"width: 435.063px;\"><\/td>\r\n<td style=\"width: 356.063px;\">corresponding ciphertext generated with the secret key.<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\">Chosen ciphertext<\/td>\r\n<td style=\"width: 435.063px;\">\u2022<\/td>\r\n<td style=\"width: 356.063px;\">Encryption algorithm<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\"><\/td>\r\n<td style=\"width: 435.063px;\">\u2022<\/td>\r\n<td style=\"width: 356.063px;\">Ciphertext<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\"><\/td>\r\n<td style=\"width: 435.063px;\">\u2022<\/td>\r\n<td style=\"width: 356.063px;\">Ciphertext<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\"><\/td>\r\n<td style=\"width: 435.063px;\"><\/td>\r\n<td style=\"width: 356.063px;\">decrypted plaintext generated with the secret key.<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\"><\/td>\r\n<td style=\"width: 435.063px;\"><\/td>\r\n<td style=\"width: 356.063px;\"><\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\">Chosen text<\/td>\r\n<td style=\"width: 435.063px;\">\u2022<\/td>\r\n<td style=\"width: 356.063px;\">Encryption algorithm<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\"><\/td>\r\n<td style=\"width: 435.063px;\">\u2022<\/td>\r\n<td style=\"width: 356.063px;\">Ciphertext<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\"><\/td>\r\n<td style=\"width: 435.063px;\">\u2022<\/td>\r\n<td style=\"width: 356.063px;\">Ciphertext<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\"><\/td>\r\n<td style=\"width: 435.063px;\"><\/td>\r\n<td style=\"width: 356.063px;\">decrypted plaintext generated with the secret key.<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\"><\/td>\r\n<td style=\"width: 435.063px;\">\u2022<\/td>\r\n<td style=\"width: 356.063px;\">Plaintext<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\"><\/td>\r\n<td style=\"width: 435.063px;\"><\/td>\r\n<td style=\"width: 356.063px;\">corresponding ciphertext generated with the secret key.<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 117.063px;\"><\/td>\r\n<td style=\"width: 435.063px;\"><\/td>\r\n<td style=\"width: 356.063px;\"><\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<strong>Probable word attack:<\/strong>\r\n\r\n&nbsp;\r\n<ul>\r\n \t<li>An electronic funds transfer message has a standardized header or banner. This is an example of known plaintext.<\/li>\r\n \t<li>If an attacker is after some specific information, parts of the message is known. This is called probable word attack.<\/li>\r\n \t<li>Source code developed by Company Z includes copyright statement in some standardized position.<\/li>\r\n<\/ul>\r\nAn Encryption scheme is called <strong>unconditionally secure<\/strong>, if the ciphertext generated by the scheme does not have enough information so that it can uniquely determine the corresponding plaintext, even though much of the ciphertext is available.\r\n\r\nAn Encryption scheme is <strong>computationally secure<\/strong>, if one of the following criteria is met.\r\n<ol>\r\n \t<li>The cost of breaking the cipher exceeds the value of the encrypted information.<\/li>\r\n \t<li>The time required to break the cipher exceeds the useful lifetime of the information.<\/li>\r\n<\/ol>\r\n<strong>Brute force attack: <\/strong>This attack includes trying all possible keys to obtain plaintext from the ciphertext such that plaintext is modifiable\r\n\r\n&nbsp;\r\n<table>\r\n<tbody>\r\n<tr>\r\n<td><strong>you can view video on cryptography<\/strong><\/td>\r\n<td><a href=\"https:\/\/youtu.be\/YOwkywM5fwY\" target=\"_blank\" rel=\"noopener noreferrer\"><img class=\"alignnone wp-image-120\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"\" width=\"36\" height=\"36\" \/><\/a><\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n&nbsp;\r\n\r\n<strong>Suggested Reading:<\/strong>\r\n\r\n&nbsp;\r\n<ol>\r\n \t<li>Cryptography and Network Security Principles and Practice by William Stallings, sixth Edition, PEARSON.<\/li>\r\n \t<li>Security in Computing by Charles Pfleeger &amp; Shari Lawrence Pfleeger, fourth Edition, PEARSON.<\/li>\r\n \t<li>Network Security by Charlie Kaufman, Radia Perlman, Mike Speciner, second Edition, PHI.<\/li>\r\n \t<li>The Complete Reference \u2013 Network Security by Roberta Bragg, Mark Rhodes-Ousley &amp; Keith Strassberg, Tata McGraw Hill<\/li>\r\n \t<li>Network Security Bible by Eric Cole, Ronald Krutz, James Conley, Wiley<\/li>\r\n \t<li>Hacking 6 Exposed by Stuart McClure, Joel Scambray &amp; George Kurtz , Tata McGraw Hill .<\/li>\r\n \t<li><a href=\"http:\/\/www.snort.org\/\">www.snort.org<\/a><\/li>\r\n \t<li><a href=\"https:\/\/nmap.org\/\">https:\/\/nmap.org<\/a><\/li>\r\n<\/ol>\r\n&nbsp;","rendered":"<div><span style=\"float: right;\"><a href=\"https:\/\/youtu.be\/YOwkywM5fwY\" target=\"_blank\" rel=\"noopener noreferrer\"><img decoding=\"async\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"epgp books\" width=\"75px\" height=\"75px;\" \/><\/a><br \/>\n<\/span><\/div>\n<p>Module 1: Introduction to cryptography, key principles of security, security mechanisms, security services, threat, attack, the information systems security engineering process.<\/p>\n<p><strong>Types of security :<\/strong><\/p>\n<table class=\"aligncenter\">\n<tbody>\n<tr>\n<td style=\"width: 88.0625px;\">Information<\/td>\n<td style=\"width: 572.063px;\">Protecting\u00a0 information\u00a0 (physical\u00a0 or\u00a0 digital)\u00a0 from<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 88.0625px;\">Security<\/td>\n<td style=\"width: 572.063px;\">unauthorized\u00a0 access,\u00a0 use,\u00a0 disclosure,\u00a0 disruption,<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 88.0625px;\"><\/td>\n<td style=\"width: 572.063px;\">modification or destruction.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 88.0625px;\">Computer<\/td>\n<td style=\"width: 572.063px;\">To protect files and other information stored on the computer. Computer may<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 88.0625px;\">Security<\/td>\n<td style=\"width: 572.063px;\">be time shared or part of public telephone network, data network or the<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 88.0625px;\"><\/td>\n<td style=\"width: 572.063px;\">internet.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 88.0625px;\"><\/td>\n<td style=\"width: 572.063px;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 88.0625px;\">Network<\/td>\n<td style=\"width: 572.063px;\">To protect data, when data is transmitted between computer to computer.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 88.0625px;\">Security<\/td>\n<td style=\"width: 572.063px;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 88.0625px;\"><\/td>\n<td style=\"width: 572.063px;\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Security Violation :<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-22 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-1-300x147.png\" alt=\"\" width=\"657\" height=\"322\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-1-300x147.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-1-768x376.png 768w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-1-65x32.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-1-225x110.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-1-350x171.png 350w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-1.png 817w\" sizes=\"auto, (max-width: 657px) 100vw, 657px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-23 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-2-300x136.png\" alt=\"\" width=\"618\" height=\"280\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-2-300x136.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-2-65x30.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-2-225x102.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-2-350x159.png 350w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-2.png 762w\" sizes=\"auto, (max-width: 618px) 100vw, 618px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-24 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-3-300x133.png\" alt=\"\" width=\"562\" height=\"249\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-3-300x133.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-3-768x340.png 768w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-3-65x29.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-3-225x100.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-3-350x155.png 350w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-3.png 799w\" sizes=\"auto, (max-width: 562px) 100vw, 562px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-25 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-4-300x139.png\" alt=\"\" width=\"803\" height=\"372\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-4-300x139.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-4-768x355.png 768w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-4-65x30.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-4-225x104.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-4-350x162.png 350w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-4.png 847w\" sizes=\"auto, (max-width: 803px) 100vw, 803px\" \/><\/p>\n<p><strong>The OSI Security Architecture:<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">The International Telecommunication Union(ITU) Telecommunication Standardization Sector(ITU-T) develops standards relating to open systems interconnection(OSI). OSI security architecture was developed in the context of the OSI protocol architecture.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>The OSI Security Architecture:<\/strong><\/p>\n<p>&nbsp;<\/p>\n<ol start=\"3\">\n<li><strong>Security attack: <\/strong>If information owned by an organization is compromised by any action, it is called security attack.<\/li>\n<li><strong>Security mechanism: <\/strong>Security mechanism is a process that is designed to detect, prevent or recover from a security attack.<\/li>\n<li><strong>Security service: <\/strong>Security service is used to mitigate security attack by using one or more security mechanism.<\/li>\n<\/ol>\n<p><strong>Security Policy<\/strong>: An Information Technology (IT) Security Policy identifies the rules and procedures for all who are accessing and using an organization&#8217;s IT assets and resources.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Vulnerabilities, Threats, Attacks(RFC 2828):<\/strong><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>A vulnerability is a weakness in the security system.<\/li>\n<li>A threat is a potential cause of an incident, that may result in harm of systems and organization.<\/li>\n<li>An attack is an assault on system security that derives from an intelligent threat, i.e., an intelligent act that is a deliberate attempt (especially in the sense of a method or technique) to evade security services and violate the security policy of a system.<\/li>\n<\/ul>\n<p><strong>Example of Attack( Password Guessing ):<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>Password :<\/p>\n<p>The attacker tries to guess the password.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Security Attacks:<\/strong><\/p>\n<ul>\n<li><strong>Passive attack: <\/strong>The attacker collects the information or make use of collected information but do not modify any resources so system resources are not affected.<\/li>\n<li><strong>Active attack: <\/strong>The attacker changes or actions are altered.<\/li>\n<\/ul>\n<p><strong>Types of Passive Attacks:<\/strong><\/p>\n<ul>\n<li>Release of message content.<\/li>\n<li>Traffic analysis.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>Types of Active Attacks:<\/strong><\/p>\n<ul>\n<li>Masquerade<\/li>\n<li>Replay<\/li>\n<li>Modification of messages<\/li>\n<li>Denial of service<\/li>\n<\/ul>\n<p><strong>Security Services(X.800):<\/strong><\/p>\n<ul>\n<li><strong>Authentication<\/strong><\/li>\n<\/ul>\n<p>The parties exchanging information are truly the same parties that they claim to be.<\/p>\n<ul>\n<li><strong>Access control<\/strong><\/li>\n<\/ul>\n<p>Unauthorized persons can not use the resources.<\/p>\n<ul>\n<li><strong>Confidentiality<\/strong><\/li>\n<\/ul>\n<p>Unauthorized disclosure of data is not done.<\/p>\n<ul>\n<li><strong>Integrity<\/strong><\/li>\n<\/ul>\n<p>Data received is same as sent by an authorized person. No modification done.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Nonrepudiation<\/strong><\/p>\n<p>Sender or receiver cannot deny that the message was sent and was received.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Security Mechanisms<\/strong>:<\/p>\n<p>&nbsp;<\/p>\n<table class=\"aligncenter\" style=\"height: 619px;\">\n<tbody>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\">Encipherment<\/td>\n<td style=\"width: 531.063px; height: 28px;\">Use mathematical algorithm . The data is transformed from one<\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\n<td style=\"width: 531.063px; height: 28px;\">form to another by using algorithm and key, which is difficult to<\/td>\n<\/tr>\n<tr style=\"height: 31px;\">\n<td style=\"width: 129.063px; height: 31px;\"><\/td>\n<td style=\"width: 531.063px; height: 31px;\">understand.<\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\">Digital<\/td>\n<td style=\"width: 531.063px; height: 28px;\">Appended data so that the receiver can identify and<\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\">signature<\/td>\n<td style=\"width: 531.063px; height: 28px;\">verify the source.<\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\">Access control<\/td>\n<td style=\"width: 531.063px; height: 28px;\">Mechanisms that enforce access rights to resources.<\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\">Data Integrity<\/td>\n<td style=\"width: 531.063px; height: 28px;\">Mechanisms to assure the integrity of data.<\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\">Authentication<\/td>\n<td style=\"width: 531.063px; height: 28px;\">Mechanism to ensure identity by exchanging information.<\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\">Exchange<\/td>\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\">Traffic padding<\/td>\n<td style=\"width: 531.063px; height: 28px;\">To get rid of traffic analysis, some bits are inserted into<\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\n<td style=\"width: 531.063px; height: 28px;\">data.<\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\">Routing<\/td>\n<td style=\"width: 531.063px; height: 28px;\">In case of security threat, secure routing path is selected.<\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\">Control<\/td>\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\">Notarization<\/td>\n<td style=\"width: 531.063px; height: 28px;\">For data exchange, trusted third party is used.<\/td>\n<\/tr>\n<tr style=\"height: 28px;\">\n<td style=\"width: 129.063px; height: 28px;\"><\/td>\n<td style=\"width: 531.063px; height: 28px;\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Cryptography :<\/strong><\/p>\n<ul>\n<li>Original message is called plaintext.<\/li>\n<li>Coded message is called ciphertext.<\/li>\n<li>Process of converting plaintext to ciphertext is known as enciphering or encryption.<\/li>\n<li>Retrieving plaintext from the ciphertext is deciphering or decryption.<\/li>\n<li>Schemes used for encryption \u2013 decryption is called cryptography.<\/li>\n<li>Cryptanalysis is about breaking the code.<\/li>\n<\/ul>\n<p><strong>Encryption algorithms \u2013 Symmetric Encryption:<\/strong><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>C=E(K,P) Where C is the ciphertext, P is the plaintext, E is Encryption algorithm and K is the key.<\/li>\n<li>P=D(K,C) Where P is plaintext, C is ciphertext, D is decryption algorithm and K is the key.<\/li>\n<li>Encryption and Decryption keys are same. So this form is called symmetric encryption.<\/li>\n<\/ul>\n<p><strong>Encryption algorithms \u2013 Asymmetric Encryption:<\/strong><\/p>\n<ul>\n<li>C=E(KE,P) Where C is the ciphertext, P is the plaintext, E is Encryption algorithm and KE is the encryption key.<\/li>\n<li>P=D(KD,C) Where P is plaintext, C is ciphertext, D is decryption algorithm and KD is the decryption key.<\/li>\n<li>Encryption and Decryption keys are different. So this form is called Asymmetric encryption.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Characteristics of cryptographic systems:<\/strong><\/p>\n<p>&nbsp;<\/p>\n<ol>\n<li>The type of operations used for transforming plaintext to ciphertext. Substitution<\/li>\n<\/ol>\n<p>transposition<\/p>\n<ol start=\"2\">\n<li>The number of keys used.<\/li>\n<li>The method in which processing of plaintext is done.<\/li>\n<\/ol>\n<p>Block cipher<\/p>\n<p>Stream cipher<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Cryptanalysis:<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>Cryptanalysis is to recover the key by attacking the encryption system instead of recovering the plaintext or ciphertext.<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-26 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-5.png\" alt=\"\" width=\"803\" height=\"345\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-5.png 803w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-5-300x129.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-5-768x330.png 768w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-5-65x28.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-5-225x97.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-5-350x150.png 350w\" sizes=\"auto, (max-width: 803px) 100vw, 803px\" \/><\/p>\n<p><strong>Cryptanalytic attack<\/strong>: These types of attacks depend on amount of information known.<\/p>\n<ul>\n<li>[1] Cryptography and Network Security Principles and Practices \u2013 William Stallings.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<table class=\"aligncenter\" style=\"width: 951px;\">\n<tbody>\n<tr>\n<td style=\"width: 117.063px;\">Type of Attack<\/td>\n<td style=\"width: 435.063px;\"><\/td>\n<td style=\"width: 356.063px;\">Known to cryptanalyst<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\">Ciphertext only<\/td>\n<td style=\"width: 435.063px;\">\u2022<\/td>\n<td style=\"width: 356.063px;\">Encryption algorithm<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\"><\/td>\n<td style=\"width: 435.063px;\">\u2022<\/td>\n<td style=\"width: 356.063px;\">Ciphertext<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\">Known plaintext<\/td>\n<td style=\"width: 435.063px;\">\u2022<\/td>\n<td style=\"width: 356.063px;\">Encryption algorithm<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\"><\/td>\n<td style=\"width: 435.063px;\">\u2022<\/td>\n<td style=\"width: 356.063px;\">Ciphertext<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\"><\/td>\n<td style=\"width: 435.063px;\">\u2022\u00a0\u00a0 One or more plaintext-ciphertext pairs formed with the secret key.<\/td>\n<td style=\"width: 356.063px;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\">Chosen plaintext<\/td>\n<td style=\"width: 435.063px;\">\u2022<\/td>\n<td style=\"width: 356.063px;\">Encryption algorithm<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\"><\/td>\n<td style=\"width: 435.063px;\">\u2022<\/td>\n<td style=\"width: 356.063px;\">Ciphertext<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\"><\/td>\n<td style=\"width: 435.063px;\">\u2022\u00a0\u00a0 Plaintext<\/td>\n<td style=\"width: 356.063px;\">message\u00a0 chosen\u00a0 by\u00a0 cryptanalyst,\u00a0 together\u00a0 with\u00a0 its<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\"><\/td>\n<td style=\"width: 435.063px;\"><\/td>\n<td style=\"width: 356.063px;\">corresponding ciphertext generated with the secret key.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\">Chosen ciphertext<\/td>\n<td style=\"width: 435.063px;\">\u2022<\/td>\n<td style=\"width: 356.063px;\">Encryption algorithm<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\"><\/td>\n<td style=\"width: 435.063px;\">\u2022<\/td>\n<td style=\"width: 356.063px;\">Ciphertext<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\"><\/td>\n<td style=\"width: 435.063px;\">\u2022<\/td>\n<td style=\"width: 356.063px;\">Ciphertext<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\"><\/td>\n<td style=\"width: 435.063px;\"><\/td>\n<td style=\"width: 356.063px;\">decrypted plaintext generated with the secret key.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\"><\/td>\n<td style=\"width: 435.063px;\"><\/td>\n<td style=\"width: 356.063px;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\">Chosen text<\/td>\n<td style=\"width: 435.063px;\">\u2022<\/td>\n<td style=\"width: 356.063px;\">Encryption algorithm<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\"><\/td>\n<td style=\"width: 435.063px;\">\u2022<\/td>\n<td style=\"width: 356.063px;\">Ciphertext<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\"><\/td>\n<td style=\"width: 435.063px;\">\u2022<\/td>\n<td style=\"width: 356.063px;\">Ciphertext<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\"><\/td>\n<td style=\"width: 435.063px;\"><\/td>\n<td style=\"width: 356.063px;\">decrypted plaintext generated with the secret key.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\"><\/td>\n<td style=\"width: 435.063px;\">\u2022<\/td>\n<td style=\"width: 356.063px;\">Plaintext<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\"><\/td>\n<td style=\"width: 435.063px;\"><\/td>\n<td style=\"width: 356.063px;\">corresponding ciphertext generated with the secret key.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 117.063px;\"><\/td>\n<td style=\"width: 435.063px;\"><\/td>\n<td style=\"width: 356.063px;\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Probable word attack:<\/strong><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>An electronic funds transfer message has a standardized header or banner. This is an example of known plaintext.<\/li>\n<li>If an attacker is after some specific information, parts of the message is known. This is called probable word attack.<\/li>\n<li>Source code developed by Company Z includes copyright statement in some standardized position.<\/li>\n<\/ul>\n<p>An Encryption scheme is called <strong>unconditionally secure<\/strong>, if the ciphertext generated by the scheme does not have enough information so that it can uniquely determine the corresponding plaintext, even though much of the ciphertext is available.<\/p>\n<p>An Encryption scheme is <strong>computationally secure<\/strong>, if one of the following criteria is met.<\/p>\n<ol>\n<li>The cost of breaking the cipher exceeds the value of the encrypted information.<\/li>\n<li>The time required to break the cipher exceeds the useful lifetime of the information.<\/li>\n<\/ol>\n<p><strong>Brute force attack: <\/strong>This attack includes trying all possible keys to obtain plaintext from the ciphertext such that plaintext is modifiable<\/p>\n<p>&nbsp;<\/p>\n<table>\n<tbody>\n<tr>\n<td><strong>you can view video on cryptography<\/strong><\/td>\n<td><a href=\"https:\/\/youtu.be\/YOwkywM5fwY\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-120\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"\" width=\"36\" height=\"36\" \/><\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p><strong>Suggested Reading:<\/strong><\/p>\n<p>&nbsp;<\/p>\n<ol>\n<li>Cryptography and Network Security Principles and Practice by William Stallings, sixth Edition, PEARSON.<\/li>\n<li>Security in Computing by Charles Pfleeger &amp; Shari Lawrence Pfleeger, fourth Edition, PEARSON.<\/li>\n<li>Network Security by Charlie Kaufman, Radia Perlman, Mike Speciner, second Edition, PHI.<\/li>\n<li>The Complete Reference \u2013 Network Security by Roberta Bragg, Mark Rhodes-Ousley &amp; Keith Strassberg, Tata McGraw Hill<\/li>\n<li>Network Security Bible by Eric Cole, Ronald Krutz, James Conley, Wiley<\/li>\n<li>Hacking 6 Exposed by Stuart McClure, Joel Scambray &amp; George Kurtz , Tata McGraw Hill .<\/li>\n<li><a href=\"http:\/\/www.snort.org\/\">www.snort.org<\/a><\/li>\n<li><a href=\"https:\/\/nmap.org\/\">https:\/\/nmap.org<\/a><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n","protected":false},"author":4,"menu_order":1,"template":"","meta":{"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":["miss-hiteishi-diwanji"],"pb_section_license":""},"chapter-type":[47],"contributor":[58],"license":[],"class_list":["post-5","chapter","type-chapter","status-publish","hentry","chapter-type-standard","contributor-miss-hiteishi-diwanji"],"part":3,"_links":{"self":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/chapters\/5","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/wp\/v2\/users\/4"}],"version-history":[{"count":7,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/chapters\/5\/revisions"}],"predecessor-version":[{"id":480,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/chapters\/5\/revisions\/480"}],"part":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/parts\/3"}],"metadata":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/chapters\/5\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/wp\/v2\/media?parent=5"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/chapter-type?post=5"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/wp\/v2\/contributor?post=5"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/wp\/v2\/license?post=5"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}