Wednesday, October 21, 2009

Lab 4 Symmetric and Asymmetric Cryptography

In this lab we are focusing on understanding symmetric and asymmetric cryptography, as well as implementing Caesar Cipher, Vigenere Cipher and the RSA algorithm. 

As we all know that there are two types of encipherment in cryptosystems namely symmetric and asymmetric encipherment. Symmetric encipherment can be in the form of substitution, transposition or both. In substitution encipherment, alphabets in the plain text is replaced with another alphabetic character. There are two types of substitution namely monoalphabetic(eg. Caesar cipher) and polyalphabetic(eg. Vigenere cipher) substitution. The transposition encipherment changes the location of characters. Transposition can be either keyed or unkeyed. The asymmetric encipherment uses two keys, which are public key and private key, to encrypt and decrypt.

The Caesar Cipher is formed by shifting the letters of the original alphabet. The example of shift 3 Caesar Cipher is shown below:


plaintext alphabet A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

ciphertext key D E F G H I J K L M N O P Q R S T U V W X Y Z A B C


Cracking the Caesar ciphertext is easy by using brute-force cryptanalysis. The reasons of using the brute-force cryptanalysis are as follows:

  • The encryption and decryption algorithms are known

  • There are only 26 keys to try

  • The language of the plaintext is known and easily recognizable. The pattern is obvious.

Considering that the Caesar ciphertext is easily broken by using the brute-force attack, the Vigenere cipher is introduced in order to improve the deciphering process. The Vigenere cipher is a method of encrypting alphabetic text by using a series of different Caesar ciphers based on the letters of a keyword. Generally, a key is needed to encrypt a plaintext using Vigenere cipher, either using a word or a phrase. 


Vigenere Cipher


Asymmetric encipherment uses keypairs namely the public and private key for encryption and decryption. The public key is known to all but the private key is kept secret. The asymmetric keys are usually generated using the RSA algorithm. The following steps involving calculations are required:

  1. Choose two distinct prime numbers, p and q

  2. Compute n=pq

  3. Compute totient(n) = (p-1)(q-1)
  4. Choose an integer e such that  1
  5. Determine d (using modular arithmetic) which satisfies the congruence relation  

    Regarding encryption, if a person A transmits a public key of (c,e) to person B and keeps the private key secret, person B send a message M to person A. To encrypt message M, it is turned into an integer 0

    For decryption however, person A can recover m from c by using the calculation below:

    m=c^d (mod n)




Lecture 4 Operating System Security

In this lecture session, we were introduced on the operating system security. In OS security, there are six aspects that protection is necessary to be implemented on: 
  • memory

  • sharable I/O devices

  • serially reusable I/O devices, such as printers and tape drives

  • sharable programs and subprocedures

  • networks

  • sharable data

Separation is the basis of protection, which means to keep one user's objects separate from each other users. There are four types of separation process:

  • Physical separation – different processes use different physical objects.

  • Temporal separation – processes have different security requirements executed at different times.

  • Logical separation – users operate under the illusion that no other processes exist, as when an OS constrains a program's accesses so that the program cannot access objects outside permitted domain.

  • Cryptographic separation – processes conceal their data and computations in a way that they are unintelligible to outside processes.


A security mechanism can offer different levels of protection, such as:

  • No protection at all

  • Isolation

  • Share all or share nothing

  • Share via access limitation

  • Share by capabilities

  • Limit use of an object

The main concern of multiprogramming is preventing a program from affecting data and programs in other users' memory space. Aside from using system software to do all that, protection can also be built using hardware which controls efficient use of memory. Thus, solid protection can be provided at essentially no additional cost.

Methods used for memory protection include:

  • fence

  • relocation

  • base/bound registers

  • tagged architecture

  • segmentation

  • paging

  • paging + segmentation


The fence is the simplest form of memory protection introduced in single-user operating systems to prevent a faulty user program from destroying part of the resident portion of the operating system. Two implementations of fence are the fixed fence which its memory address was predefined, and the fence register which uses a hardware register.

Relocation is the process of taking a program written as if it began at address 0 and changing all addresses to reflect the actual address at which the program is located in memory.

The variable fence register has the ability to relocate. This fence register has two kinds of registers namely base register which has the addresses offset from the base address in a program (the lower address limit), and the bound register is the upper address limit. With a pair of base/bound registers, a user is perfectly protected from outside users, or you should say that outside users are protected from errors in any other user's programs. However this is not quite effective because erronous addresses inside a user's address space can still affect a program. This problem is solved by adding another pair of base/bounds registers, one for instructions the second for the data space.

Due to the contiguous nature and the all-for-nothing sharing solution of base/bounds registers, the tagged architecture serves as an alternative, where in every word of machine memory has one or more access rights to that word. Operating system instructions has the privilege to set these access bits.

Another protection method is the segmentation, which involves the simple notion of dividing a program into separate parts that has logical unity – exhibits a relationship among all of its code. Segments can be separately relocated, allowing any segment to be placed in any available memoy locations. The security benefits of segmentation are:

  • each address reference is checkec for protection

  • many different classes of data items can be assigned different levels of protection

  • two or more users can share access to a segment, with potentially different access rights

  • a user cannot generate an address or access to an unpermitted segment

The paging method of protection divides programs into equal-sized "pages", and memory divided into equal-sized units called "page frames". In paging, all pages in the paging approach are of the same size, which makes fragmentation an ease, but the pages have no logical unity. A certain change to a program pushes all subsequent instructions to lower addresses andd moves a few bytes from the end of each page to the start of the next.

We see the benefits of paging and segmentation. By combining the two approaches, desirable features are utilized. This approach retains the logical unity of a segment and permitted differentiated protection for the segments, but it adds an additional layer of translation for each address. Plus, additional hardware improves the efficiency of the implementation.

In multiprogramming environments, there are a number of general objects that are necessary to be protected:

  • memory

  • a file or dataset on an auxiliary storage device

  • a directory of files

  • a hardware device

  • a data structure, such as a stack

  • a table of the operating system

  • instructions, especially privileged instructions

  • passwords and the user authentication mechanism

  • the protection mechanism itself

Several goals in protecting objects would be:

  • to check every user access to an object

  • to enforce least privilege, meaning that a subject should have access to the least number of objects necessary to perform tasks.

  • Verify acceptable usage, meaning that it is necessary to check that activities performed on objects are appropriate.

The simplest method of protecting objects is to use the file directory mechanism. With that, no user can be allowed to write in other user's file directory. Access rights for users can be set in file directories, such as allowing or restricting the read, write and execute command of users. This method is easy to implement because it uses one list per user. However the drawback of this method is that the list can become too large, eg many shared objects are accessible to all users.

Another method that can be used to protect objects is using the access control matrix, which uses a table where each row represents a subject, each column represents an object, and each entry is the set of access rights for the particular subject to the object. The example of access control matrix is shown below:

Access Control Matrix

Another protection method is using the access control list, in which there is one access control list assigned to the object.

                             Object1: {{A: OWR}, {B: R}, {C: R}, {D: R}}

                             Object2: {{A: R}, {B: OWR}, {C: R}, {E: R}}

                             Object3: {{A: OWR}}

                             Object4: {{B: OWR}, {*: WR}}

                             Object5: {{B: OWR}, {E: R}}

Access Control List

Basic forms of file protection mechanism are as follows:

  • Allnone protection which assumes that all users can be trusted

  • Group protection which separate all users into groups

We did see the drawbacks of the above file protection mechanisms, individual permissions can be set, such as passwords to protect individual files, shortfalls, and temporary acquired permission.

The authentication method of protection can take many forms, such as using passwords, identity badges, and the biometrics.




Lab 3 Authentication and Basic Cryptography

In this lab session, we were being explained about what is meant by authentication and cryptography. We are required to implement Data Encryption and Local Password Policy on Windows 2003 Server Edition. Aside from the operating system, we are required to implement asymmetric cryptography by using an encryption software called Pretty Good Privacy (PGP).

The basic idea of authentication is that when a subject claims that something or an identity is true, verification is necessary. So, authentication enables verifiers to gain confidence that claims are legitimate.

Cryptography is the science of hiding information in such a way that its meaning is not unintelliglble to an unauthorized person. Encryption is the process of encoding a message so that its meaning is not obvious while decryption is the reverse process. The common terms for encrypting and decrypting are encoding and decoding.

Cryptosystems use cryptography algorithms, which can be classififed into two categories being the symmetric and asymmetric encipherment. The sole difference that can distinguish symmetric and asymmetric algorithms is the number of keys used in the encryption and decryption process.


Data encryption can also be done using the NTFS. This encryption method is convenient for laptop users because their data stored in the hard drive is encrypted and secure, which makes their data secure and unreadble just in case their laptops are stolen and hacked.

Windows 2003 has a utility which makes it easy to encrypt files to an NTFS partition.

For information on how to encrypt files to an NTFS partition, please visit:

http://technet.microsoft.com 


Windows 2003 also has the local password policy setup for the password length. For suthentication in work environments, usernames and passwords are required. What is to be focused here is the password length because short passwords are easy to crack and guessable. With Windows 2000/2003, the local password policy allows you to specify the minimum length for passwords.

For more information on how to setup local password policy for password length, please visit:

http://technet.microsoft.com/en-us/library/cc781633(WS.10).aspx


The local password policy can also be set for complexity. The main focus here is the usage of various password characters such as letters, numbers and symbols. So, the local password policy can also specify password characters to be used.

For more information on how to set the local password policy for password complexity, please visit:

http://technet.microsoft.com/en-us/library/cc781633(WS.10).aspx


Windows 2003 has the utility of setting the account lockout polisy where this policy disables an account for a specific amount of time after a certain amount of failed login attempts.

For more information on how to set an account lockup policy, please visit:

http://technet.microsoft.com/en-us/library/cc781491(WS.10).aspx


For encryption and decryption of plaintext, we use the third party software called Pretty Good Privacy. PGP is referred to as a hybrid cryptosystem because it has the best features of both conventional and public key cryptography. With PGP,

For more information on how PGP works, please visit:

http://www.pgpi.org/doc/pgpintro/


Lecture 3 Program Security

In this lecture, we learnt about what it means by a secure program, malicious codes, and the web application vulnerabilities. Besides that, we had also touched on the measures on how to counter malicious code and vulnerabilities by applying software engineering principles and practices, and the protections against program flaws during execution.

From what I’ve understand from the lecture is that a secure program is defined by different perspectives of who is going to evaluate software quality. There are also a number of approaches in judging program security. This includes fixing faults by patching software after conducting penetration tests. There is no doubt that fixes might trigger more faults later results in software failures. There are flaws in software in the software market, but flaws are not the causes of faults followed by failures.

The common flaws that we see in programs are:

  • validation error

  • domain error

  • serialization and aliasing

  • inadequate identification and authentication

  • boundary condtion violation

  • other exploitable logic errors

Non-malicious program errors occur because of unintentional mistakes made by software developers, which causes malfunction. Examples of non-malicious program errors are buffer overflows, incomplete mediation (exposed and uncontrolled data), and Time of Check to Time of Use. These non-malicious program errors may lead to exploitation of malicious programmers, or commonly known as hackers. As I've said earlier in the ealier posts, with small amount of knowledge, a commoner can easily exploit unintentional program errors.

To describe buffer overflow, it is almost similar to attempting to pour two liters of water into a one-liter bottle. Incomplete mediation has something to do with manipulating exposed data such as date and time to cause errors (Note: Usually exposed and uncontrolled data exists in URLs). The Time-to-check to time-to-use flaw is pertaining to mediation that is performed with the "bait and switch" method in the middle, or further known as a serialization or synchronization flaw. It is possible that these three flaws can be combined together as a multistep attack to cause harm to a system.

This is why malicious programmers create malicious codes in order to cause harm or exploit a particular system. Furthermore, malicious codes have the ability to cause as much harm, as well as its prolonged existence, either created by accident or intended.

Types of malicious code that existed today are as follows:


Spywares are a new type of malicious/non-malicious code. It is a term for tracking software deployed without adequate notice, consent, or control for the user. Often the tracking is done by reporting information (anything from browsing history to credit-card or personal details) to a third party.


Below are the effects of viruses and causes:


Virus Effect

Causes

Attach to executable program

Modify file directory

Write to executable program

Attach to data or control file

Modify directory

Rewrite data

Append to data

Append data to itself

Remain in memory

Intercept interrupt by modifying interrupt handler address table

Load self in non-transient memory area

Infect disks

Intercept interrupt

Intercept operating system

Conceal self

Intercept system calls that would reveal self and falsify result

classify self as "hidden" file

Spread infection

Infect boot sector

Infect systems program

Infect ordinary program

Infect data ordinary program reads to control its execution

Prevent deactivation

Activate before deactivating program and block deactivation

Store sopy to reinfect after deactivation


The above notes regarding malicious codes are anonymous codes that are not targeted to a specific system, application or a particular purpose. The main focus of the targeted malicious code are trapdoors and salami attack.

Trapdoors are undocumented entry point to a module. It is usually inserted by software developers during code development testing. Its initial purpose is to provide "hooks" by which to connect future modifications and enhancements, or basically to just allow access if the module should have future failures. Aside from its legitimate use, trapdoors allow a programmer access to a program once it is placed in production. The main causes of trapdoors includes programmer's forgetfulness of removing them, programmer's intention to leave them for testing, maintenance, and or later covert means of access.

As for the salami attack, this code merges bits of seemingly inconsequenial data to yield powerful results, for instance programs that often disregard small amounts of money in their interest computations.

The top ten web application vulnerabilities that we normally see in the world today are:

  • Cross-site scripting

  • Injection flaws

  • Malicious file execution

  • Insecure direct object reference

  • Cross site request forgery

  • Information leakage and improper error handling

  • Broken authentication and session management

  • Insecure crypto storage

  • Insecure communications

  • Failure to restrict URL access


There are a few aspects to control against program threats. We can see some signs that show that there are viruses within a system because they leave certain trails, however sometimes they can be very hard to detect because they can self-modify. A program scanner with a considerably good checksum can be used to detect changes in self-modifying codes.

Viruses may be invisible and hiding in large programs, compilers, database or file managers. The popular hiding place for viruses in within an attachment of emails or a public download file. A virus has phases to go through before it is fully activated – Dormant phase, propagation phase, triggering phase and execution phase.


For preventing virus infection, a system should have a virus detection and identification tool a.k.a. scanners. Removal tools are also essential to clean viruses. What I personally think is that a system should have an internet security package that has antivirus protection to actively protect files from infection. This protection mechanism should include real-time file system protection, document protection, email client protection and web access protection. Nevertheless, daily updates of virus definitions is necessary.

Other ways of preventing virus detection include using only well-known software, do software testing in an isolated PC, and not opening unknown email attachments. Besides that, backups are necessary too.


Lab 2 The Goals of Information Technology Security

In this lab we were taught on what are the goals of IT Security. The main focus in this lab session is for us to be able to determine NTFS and FAT32 partitions, as well as implementing confidentiality, integrity, and availability in Windows Server 2003.

The goals of information security is to achieve three aspects namely confidentiality, integrity and availability and the implementation of a secure computing network environment. However, to achieve the balance between the three elements is a difficult task. Besides that, another goal to achieved is to provide legitimate use of resources which ensures that the resources are from the original source.

Our first task is to use an NTFS partition to secure local resources. Windows Server 2003 has a feature of setting up local file security. The main concern about this part is that you have to check whether there's any corruption of a FAT32 partition on a particular hard-drive, in our case we used a virtual machine. Then, the NTFS conversion can be done with commands typed in the Command Prompt.

The most convenient thing about this lab session is that we are taught to implement data confidentiality, integrity and availability at the same time. We have created two user accounts in Windows 2003 virtual machine, then create folders, then do some settings to the folders. Basically, there's a security option in folders created. Furthermore, it's easier to set user permissions which allows or restrict access of certain users towards a folder in a particular network, which covers the three security principles. 

For further details on how to set this in detail, please visit http://technet.microsoft.com .

Thursday, August 20, 2009

Lecture 2 : Authentication and Basic Cryptography

In this lecture, our lecturer showed us on the authentication and the basic cryptography. I’ve learned on the basic ideas of authentication, passwords, cryptography concepts and algorithms, digital signature, Public Key Infrastructure a.k.a PKI, RSA algorithm, and the methods of attack in encryption systems.

Authentication is a type of security measure designed to establish the validity of a transmission, message, or originator, or a means of verifying an individual's authorization to receive specific categories of information. Basic requirements to achieve total authentication is that messages come from apparent source or author, unaltered contents, and sent at a certain time or sequence.

A password is a secret word or string of characters that is used for authentication, to prove identity or gain access to a resource. To better protect passwords, do not let anyone know about them and do not write on anywhere you can dream of. The criteria in choosing a good password are that the password is hard to guess but easy to remember, not shorter than six characters, not patterns from the keyboard, etc.

Encryption is the process of encoding a message so that its meaning is hidden while decryption is the reverse process – transforming an encrypted message back to its original form.

A system to encrypt and decrypt messages is called cryptosystem. There are two types of cryptosystems which are asymmetric and symmetric systems. The difference between these two systems is shown below:

When Symmetric algorithms are used, both parties share the same key for en- and decryption. To provide privacy, this key needs to be kept secret. Once somebody else gets to know the key, it is not safe anymore. Symmetric algorithms have the advantage of not consuming too much computing power.

Asymmetric algorithms use a pair of keys. One is used for encryption and the other one for decryption. The decryption key is typically kept secret, thus called private key, while the encryption key is spread to all who might want to send encrypted messages, therefore inherits the name public key. Those who possess the public key are able to send encrypted messages to the owner of the private key. The private key can't be reconstructed from the public key.

There are two methods of cryptography algorithms namely substitution algorithms which consists of monoalphabetic and polyalphabetic substitutions, and transposition algorithms consisting of keyed and unkeyed transposition.

One of the earliest creations of substitution ciphers is the Caesar cipher, which uses shifts of alphabets to replace with another. 1-25 shifts can be done using Caesar cipher. The second substitution cipher is the random (monoalphabetic) cipher whereby alphabet is written in a chosen order underneath the alphabet written in strict alphabetical order.

The Vigenere Cipher is a method of encrypting plaintext by using a series of different Caesar Ciphers based on the letters of a keyword, which is known as the simple form of polyalphabetic substitution.

The Vigenere Tableau

One way of decoding monoalphabetic substitution ciphers is conducting the frequency analysis and attack. There are some differences of the frequency analysis results between English language and Malay language. Breaking Vigenere Cipher isn’t easy and it was secure until after 301 years that Charles Babbage had successfully attacked the cipher. The main weakness of the Vigenere cipher is the repeating nature of the key itself.

Block and stream ciphers are two categories of ciphers used in classical cryptography. Block and stream ciphers differ in how large a piece of the message is processed in each encryption operation. Generally, block ciphers are more efficient for computers while stream ciphers are easier for humans t do by hand.

A Message Authentication Codes (MAC) algorithm is a short piece of information used to authenticate a message. A MAC algorithm, a.k.a keyed hash function, accepts as input a secret key and an arbitrary-length to be authenticated, and outputs a MAC.

The overview of the hash function is shown below:

A message sometimes can contain a digital signature which contains a cryptographic value. This is to provide data integrity and non-repudiation. Digital signatures can be generated from RSA algorithm.

Certification authority is a free body organization which issues digital certificates to websites which needs security certification in terms of user identity by assigning public and private keys. However, there are certain attacks that can be done on digital certificates by impersonating identities.

To facilitate the use of public cryptography, the Public Key Infrastructure is introduced. The following processes needs to be taken upon establishment of PKI:

  • Key pairs for CAs are generated
  • Key pairs for users are generated
  • Users requests certificates
  • Users’ identities verified
  • Users’ key pairs verified
  • Certificate produced and checked
  • Certificates removed/updated when necessary
  • Certificates revoked

Methods of attack are divided into two namely untargeted and targeted attacks. What I’m interested to know about in one of the methods of attack is the brute force attack, which is the exhaustive key search to try whatever combinations possible. Other attacks such as the replay attacks take encrypted information to be replayed at a later time period.

Monday, August 10, 2009

Lab 1 : Virtualization

In this lab tutorial, we are taught about virtualization. What I personally understand about virtualization is that you create hardware emulation as a platform/environment for an operating system to be installed on. Any kind of guest software can be installed on this so-called hardware emulation, commonly referred to as a virtual machine.

The main advantage of virtualization is that you can have a certain degree of flexibility, portability and interoperability in the sense that any kind of software can be virtually compatible with any hardware environment created by this virtualization platform.

The concept of virtualization is not limited to just virtual machines. Virtual servers can now be created with virtualization software.

The term Virtual Machine is clearly defined as an efficient and isolated duplicate of a real machine. A real machine has the characteristics of having a processor, memory, network connections and peripheral ports. A virtual machine is capable of emulating a real machine that has these characteristics.

The benefits of using a virtual machine include:

  • Hardware utilization due to the usage of multiple virtual machines inside a single hardware.
  • The decreasing of the operating cost and capital by sharing in number of virtual machines.
  • High availability of virtual machines and security.
  • Virtual machines can be used from anywhere inside the intranet.

The VMware Workstation is the commercial virtualization software that is capable of creating and running multiple virtual machines at the same time. In addition to that, VMware Workstation enables the conversion of existing physical PC into a virtual machine. VMware is also capable of running Windows or Linux-based virtual machines or others on the same PC. Virtual machines can share files with each other using drag-and-drop functionality. One organization can also speed up deployment of operating systems by just cloning virtual machines as installing operating systems and applications can be time-consuming. If one desires, one may also reduce the size of virtual machines and insert them into removable storages and take them wherever he/she wants to. The preservation of a current state of a virtual machine can also be done by taking a snapshot, just in case there are any crashes or errors happening to the particular virtual machine.