Presentation is loading. Please wait.

Presentation is loading. Please wait.

CSCE 790: Computer Network Security Chin-Tser Huang University of South Carolina.

Similar presentations


Presentation on theme: "CSCE 790: Computer Network Security Chin-Tser Huang University of South Carolina."— Presentation transcript:

1 CSCE 790: Computer Network Security Chin-Tser Huang huangct@cse.sc.edu University of South Carolina

2 8/21/2003(C) 2003 Chin-Tser Huang2 About Me Chin-Tser Huang Ph.D. in Computer Sciences, 2003, University of Texas at Austin My first semester with USC Research in network security, network protocol design and verification, distributed systems My new web page is not ready, but if you want to know more about me, here is the old one: http://www.cs.utexas.edu/users/chuang http://www.cs.utexas.edu/users/chuang

3 8/21/2003(C) 2003 Chin-Tser Huang3 About the Course A grad-level seminar course focusing on basics and issues in network security First half will be lectures about elements of network security, cryptography backgrounds, and introduction to network security designs Second half will be your chance to present what you have learned from key research papers

4 8/21/2003(C) 2003 Chin-Tser Huang4 Course Information Online http://www.cse.sc.edu/~huangct/CSCE 790F03/index.htm http://www.cse.sc.edu/~huangct/CSCE 790F03/index.htm List of assigned paper and useful links will be added shortly Lecture slides will be available online too

5 8/21/2003(C) 2003 Chin-Tser Huang5 Your Best Strategy Come to every lecture to learn basic security problems and skills to counter them Keep yourself exposed to articles related to network security to collect project ideas Read each assigned paper and write good summary for each paper Do not wait till last minute to prepare for exam or work on project Enjoy the fun!

6 8/21/2003(C) 2003 Chin-Tser Huang6 What Can Go Wrong… …when your computer y receive or is waiting for a message m? m Internet x y ?

7 8/21/2003(C) 2003 Chin-Tser Huang7 Message Loss Adversary A can discard m in its transit m x y A

8 8/21/2003(C) 2003 Chin-Tser Huang8 Message Interception Adversary A can get a copy of m when m passes by m x y m m A

9 8/21/2003(C) 2003 Chin-Tser Huang9 Message Modification Adversary A can arbitrarily modify the content of m to become m’ m x y m’ A

10 8/21/2003(C) 2003 Chin-Tser Huang10 Message Insertion Adversary A can arbitrarily fabricate a message m, pretending that m was sent by x x y m src: x dst: y A

11 8/21/2003(C) 2003 Chin-Tser Huang11 Message Replay Adversary A can replay a message m that has been sent earlier by x and received by y x y m m A

12 8/21/2003(C) 2003 Chin-Tser Huang12 Denial-of-Service Attack Adversary A can send huge amount of messages to y to block m from arriving at y x y m ……………… ????? A

13 8/21/2003(C) 2003 Chin-Tser Huang13 Type of Attacks Passive attacks Traffic analysis Message interception Active attacks Message loss Message modification Message insertion Message replay Denial-of-Service attack

14 8/21/2003(C) 2003 Chin-Tser Huang14 Network Security Services Confidentiality Integrity Authentication Anti-replay … Availability Access control Non-repudiation Anonymity

15 8/21/2003(C) 2003 Chin-Tser Huang15 Confidentiality Keep message known only to the receiver and secret to anyone else Counter message interception

16 8/21/2003(C) 2003 Chin-Tser Huang16 Integrity When receiver receives message m, receiver can verify m is intact after sent by sender Counter message modification

17 8/21/2003(C) 2003 Chin-Tser Huang17 Authentication When receiver receives message m, receiver can verify m is indeed sent by the sender recorded in m Counter message insertion

18 8/21/2003(C) 2003 Chin-Tser Huang18 Anti-replay When receiver receives message m, receiver can verify m is not a message that was sent and received before Counter message replay

19 8/21/2003(C) 2003 Chin-Tser Huang19 Availability Property of a system or a resource being accessible and usable upon demand by an authorized entity Counter denial-of-service attack

20 8/21/2003(C) 2003 Chin-Tser Huang20 Access Control Mechanism to enforce access rights to resources and data Users can access resources and data to which they have access rights Users cannot access resources and data to which they don’t have access rights

21 8/21/2003(C) 2003 Chin-Tser Huang21 Non-repudiation When receiver receives message m, receiver gets proof that sender of m ever sent m Receiver of m can show proof to third- party so that sender of m cannot repudiate

22 8/21/2003(C) 2003 Chin-Tser Huang22 Anonymity Identity of sender is hidden from receiver When receiver receives message m, receiver has no clue about sender of m

23 8/21/2003(C) 2003 Chin-Tser Huang23 Network Security Is Great… Prevent messages from being attacked in their transit Detect and discard messages that are modified, inserted, or replayed Disallow unauthorized access to local system resource and sensitive data

24 8/21/2003(C) 2003 Chin-Tser Huang24 …But Hard To Achieve Many layers in network architecture Many different media of network connection Adversary’s location hard to determine New attacks keep emerging Cryptographic overhead

25 8/21/2003(C) 2003 Chin-Tser Huang25 Why Should You Take This Course Security is an increasingly important issue You want to have basic knowledge about network security You can learn latest attacks and newest skills to counter those attacks You have a chance to implement the skills learned in the class


Download ppt "CSCE 790: Computer Network Security Chin-Tser Huang University of South Carolina."

Similar presentations


Ads by Google