Presentation is loading. Please wait.

Presentation is loading. Please wait.

ECE509 Cyber Security : Concept, Theory, and Practice Cryptography Spring 2014.

Similar presentations


Presentation on theme: "ECE509 Cyber Security : Concept, Theory, and Practice Cryptography Spring 2014."— Presentation transcript:

1 ECE509 Cyber Security : Concept, Theory, and Practice Cryptography Spring 2014

2 Attack Types Passive attack: observe communications and/or data Active attack: modify communications and/or data

3 What are the security services in the OSI model?

4 Security Services in OSI Model Physical Layer: Data-Link Layer: Network Layer: Transport Layer: Session Layer: Presentation Layer: Application Layer:

5 Security Services in OSI Model Confidentiality Integrity Authentication Access Control Non-repudiation

6 Security Mechanisms to provide the needed security services Checksums/hash algorithms: Authorization and Integrity Encryption: Confidentiality, Integrity, Authentication Digital signatures: Integrity, Authentication, Non- repudiation

7 Secure Sockets Layer (SSL) Mechanisms: –Hashing SHA: Secure Hash Algorithm MD5: Message-Digest algorithm –Encryptions DES: Data Encryption Standard RSA: Ron Rivest, Adi Shamir, and Leonard Adleman –Signatures DSA: Digital Signature Algorithm RSA: Ron Rivest, Adi Shamir, and Leonard Adleman

8 Hash Function Data Channel Hashing Message Hash Message Hash Data

9 MAC (Message Authentication Code) Data Channel MAC Data Channel Message MAC Message MAC

10 Traditional Encryption (Symmetric Encryption) Common Key Insecure Channel Data

11 Key Agreement Insecure Channel Data

12 Public Key Encryption Insecure Channel Data

13 Digital Signature Data Channel Hashing Message Hash Message Hash Data Encrypt Signature Channel Signature

14 Digital Signature Data Signature Hashing Decrypt Compare Message Hash

15 Message/Data Encryption Data Encrypted Session Key Encrypted Session Key Encrypted Session Key Encrypted Session Key Channel

16 Reading “Understanding Security Using the OSI Model”, SANS Institute InfoSec Reading Room, [ https://www.sans.org/reading- room/whitepapers/protocols/understanding -security-osi-model-377 ]https://www.sans.org/reading- room/whitepapers/protocols/understanding -security-osi-model-377


Download ppt "ECE509 Cyber Security : Concept, Theory, and Practice Cryptography Spring 2014."

Similar presentations


Ads by Google