Search This Blog

Monday, 5 October 2026

Multiple Choice Questions on IS

0 comments

 MCQs on Information Security


1.  Which of the following term indicates that the data is not modified by unauthorised users? 
  • Confidentiality
  • Integrity
  • Availability
  • Flexibility
2.  Authentication is used for which of the following? 
  • Provide access rights
  • Verify identify of the user
  • Monitor systems connected to a network
  • Encrypt data at rest
3.  Which device connects multiple networks? 
  • Hub
  • Router
  • Switch
  • Repeater

4.  Information Security is for protecting which of the following? 
  • Hardware
  • Software
  • Data
  • Data Center

5.  Reconnaissance means ________________. 
  • Gaining access
  • Collecting information
  • Exploiting system
  • Clearing logs

    6.  Which security service ensures that data is protected from unauthorised disclosure. 
    • Confidentiality
    • Authenticity
    • Availability
    • Integrity

    Continue reading →
    Thursday, 1 October 2026

    Block Chain Technology

    0 comments

    Introduction to Block-Chain Technology


    Block-chain is a shared, immutable digital ledger, enabling the recording of transactions and the tracking of assets within a business network and providing a single source of truth. 

    • In block-chain technology, each transaction is stored in a block structure, which is  linked with other blocks, forming a secure and transparent chain. 
    • This structure guarantees data integrity and provides a tamper-proof record, making block-chain ideal for applications like cryptocurrencies and supply chain management.

    Decentralised Database Storage
    • Block-chain technology is an advanced database mechanism that allows transparent information sharing within a business network. 
    • Block chain operates as a decentralised distributed database, with data stored across multiple computers, making it resistant to tampering.
    • A block-chain database stores data in blocks that are linked together in a chain. 
    • Transactions on block-chain are validated through a consensus mechanism, ensuring agreement across the network.

    Advantages of using Block Chain
    • The key benefit of block chain lies in its ability to provide security, transparency and trust without relying on traditional intermediaries, such as banks or other third parties. 
    • Its design reduces the risk of fraud and errors, making it especially valuable in industries where secure transactions are critical, including finance and healthcare. 

    Key Components of Block-chain Technology

    Block-chain architecture has the following main components:

    A distributed ledger:
    • A distributed ledger is the shared database in the block-chain network that stores the transactions, such as a shared file that everyone in the team can edit. 
    • In most shared text editors, anyone with editing rights can delete the entire file. 
    • However, distributed ledger technologies have strict rules about who can edit and how to edit. 
    • Users cannot delete entries once they have been recorded.

    Smart contracts:
    • Companies use smart contracts to self-manage business contracts without the need for an assisting third party. 
    • They are programs stored on the block-chain system that run automatically when predetermined conditions are met. 
    • They run if-then checks so that transactions can be completed confidently. 
      • For example, a logistics company can have a smart contract that automatically makes payment once goods have arrived at the port.

    Public key cryptography
    • Public key cryptography is a security feature to uniquely identify participants in the block-chain network. 
    • This mechanism generates two sets of keys for network members. 
    • One key is a public key that is common to everyone in the network and the other is the private key that is unique to every member. 
    • The private and public keys work together to unlock the data in the ledger. 
      • For example, John and Jill are two members of the network. John records a transaction that is encrypted with his private key. 
      • Jill can decrypt it with her public key. This way, Jill is confident that John made the transaction. 
      • Jill's public key wouldn't have worked if John's private key had been tampered with.
    Continue reading →
    Tuesday, 29 September 2026

    Firewalls and Intrusion Detection

    0 comments

    Introduction to Firewalls

    • A firewall is a computer or group of computers that stand between  trusted networks (such as LAN) and untrusted networks (such as the Internet), inspecting all traffic passing between them.
    • A firewall can be a router, a personal computer, or a collection of hosts, that is set up specifically to shield a private network from security attacks that comes from an external entity.
    • The basic function of a firewall is to screen network traffic for the purpose of preventing unauthorised access between computer networks.
    • To be effective in their operation, firewalls must have the following attributes:
      • All communications must pass through the firewall
      • The firewall permits only traffic that is authorized
      • The firewalls can withstand attacks upon itself

     
    Continue reading →
    Monday, 28 September 2026

    Transport Layer Security for Web Applications

    0 comments

    Web Security

    • Virtually all businesses including government agencies as well as individuals have web sites now-a-days.  
    • The number of users of web sites and web applications increase rapidly day by day.  
    • Web browsers are easy to use, web servers are relatively easy to configure and manage, and web content is increasingly easy to develop.
    • But, Internet and World Wide Web (WWW) are vulnerable to compromises of various security threats that may challenge the web traffic security of an organisation or an individual.


    • The World Wide Web (WWW) provides the platform for client/server applications to run over the Internet and TCP/IP intranets.
    • Casual and untrained (in security matters) users are common clients for web based services.  Such users are not necessarily aware of the security risks that exist and do not have the tools or knowledge to take effective countermeasures

    Web Security Threats:
    • One way of classifying attacks on Web can be in terms of their impact on the web: passive attack and active attack
      • Passive attacks include eavesdropping on network traffic between browser and server and gaining access to information on a Web site that is supposed to be restricted
      • Active attacks include impersonating another user, altering message in transit between client and server, and altering information on a web site.

    Table: A Comparison of Threats on the Web
    • Another way of classifying the attack on the Web can be done in terms of the location of its occurrence on the web: web server, web browser, and network traffic between browser and the server.
    Web Traffic Security Approaches:
    • One way of providing web security is to use IP Security (IPSec) protocol as shown in Figure (a).  IPSec is a general-purpose solution for providing security on the internet, which is transparent to end users and applications.

    • Another way of implementing web security is to implement security just above TCP (Figure b).  In this approach, the protocols such as Secure Socket Layer (SSL) and Transport Layer Security (TLS) could be used on top of the Transport Layer.
    • The third approach is providing security at the application layer.  In this approach, the application-specific security service such as Kerberos is embedded within the particular application for securing its data transmission on the web.

    Transport Layer Security (TLS)

    • One of the most widely used security services for web security is Transport Layer Security (TCL) 
    • TCL is an Internet standard that evolved from a commercial protocol known as Secure Socket Layer (SSL)
    • TLS is a general-purpose service implemented as a set of protocols that rely on TCP
    • TLS can be used for web security in two ways:
      • TLS could be provided as part of the underlying protocol suit and therefore transparent to applications running above it
      • TLS can be embedded in specific application packages, such as web browsers on which web clients are running
    • TLS is designed to make use of TCP to provide a reliable end-to-end secure service for the applications running on the application layer

    Fig. TLS Protocol Stack








    Continue reading →
    Wednesday, 16 September 2026

    Hash Functions and Digital Signatures

    0 comments

    Introduction to Hash Functions

    A hash function H is a mathematical algorithm that accepts a variable-length block of data or message as input and produces a fixed-size output known as checksum,  hash value, hash code, or message digest (h =H(M)).
    • The primary objective of a hash function is to verify data integrity, as any alteration to even a single bit in the input message will, with high probability, produce a different hash code. 


    Applications of Hash Functions:

    • The purpose of a hash function is to produce a "fingerprint" of a file, message, or a block of data.
    • Hash functions are widely used across various domains due to their efficiency and versatility:
      • Hash Tables: The most common use of hash functions in DSA is in hash tables, which provide an efficient way to store and retrieve data.
      • Message Authentication: Message authentication is a mechanism or service used to verify the integrity of a message. When a hash function is used to provide message authentication, the hash value generated by the hash function is often referred to as message digest.
      • Digital Signatures: In digital signatures, the hash value of the message is encrypted with the user's private key.  Anyone who knows the sender's public key can verify the integrity of the message that is associated with the digital signature.


    Hash Function Requirements:

    To be useful for message authentication, a hash function H must have the following properties.

    1. Variable Input Size: A has function can be applied to a data block or message of any arbitrary size. i.e., H can be applied to a block of data of any size.
    2. Fixed Output Size: The output of a hash function should have a fixed size, regardless of the size of the input, i.e., the function H produces a fixed-length output regardless of how large or small the input message is.
    3. Efficiency: The hash function should be able to process the input quickly.  H(x) is relatively easy and fast to compute for any given input x, making both software and hardware implementations practical.
    4. Pre-image Resistance: It should be computationally infeasible to reverse the hash function.
      • For any given hash value h, it is computationally infeasible to find x (input message) such that H(x) = h.  
      • This property is also known as one-way property.
    5. Collision Resistance: It should be difficult to find two different inputs that produce the same hash value.  
      • For any given message x, it is computationally infeasible to find a different message y ≠ × such that H(y) = H(x). 
      • This property prevents an attacker from forging an alternative message that yields the same hash code as that of the original message.
      • This property is sometimes referred to as weak collision resistance.
    6. Avalanche Effect: A small change in the input should produce a significantly different hash value.
      • It is computationally infeasible to find any pair (x,y) such that H(x) = H(y).
      • This property is sometimes referred to as strong collision resistance.
    • The first three properties are requirements for the practical applications of a hash function to message authentication.
    • A hash function that satisfies only the first five properties of hash functions is referred to as a weak hash function. 
    • If all the six properties of hash functions are inherited by a hash function, then it is referred to as a strong hash function.


    A Simple Hash Function
    • All hash functions operate using the following general principles:
      • The input (message, file, etc.) is viewed as a sequence of n-bit blocks.
      • The input is processed one block at a time in an iterative fashion to produce a set of n-bit hash values (say 128 bits in length).

    • One of the simplest hash functions is the bit-by-bit exclusive-OR (XOR) or every block.  This can be expressed as follows:

    • This hash function produces a simple parity for each bit position and is known as a longitudinal redundancy check.  
    • It is reasonably effective for random data as a data integrity check.
    • A simple approach to improve the simple hash function is to perform a one-bit circular shift, or rotation, on the hash value after each block is processed.
    • The procedure can be summarised as follows:
      • Initially set the n-bit hash value to zero.
      • Process each successive n-bit block of data as follows:
        • Rotate the current hash value to the left by one bit.
        • XOR the block into the hash value.


    Cryptographic Cash Function

    • A cryptographic hash function is an hash function specifically designed for security applications and Internet protocols.
    • These hash functions are designed for security rather than speed. They are used in applications where data protection is critical.
    • All cryptographic hash functions involve the iterative use of a compression function.
    • The compression function used in secure hash algorithms falls into one of two categories: 
      • a function specifically designed for the hash function 
      • an algorithm based on a symmetric block cipher. SHA and Whirlpool are examples of these two approaches, respectively.
    • For a hash function to be cryptographically secure and effective in practice, it must satisfy the following two properties:
      • The function is one-way, i.e, the function creates the checksum from the information, but the checksum can't be used for creating the information.  This property is known as pre-image resistant.
      • It should not be possible to find two pieces of information that provide the same checksum when run through the function.  This property of the has function is known as collision resistance.
    • Two secure hash functions that are commonly used are MD5, which produces a 128-bit checksum, and SHA, which produces a 160-bit checksum.  
      • Among these two, SHA, which was developed by the government of USA and is believed to be more secure than MD5

    Message Authentication:
    • Message authentication assures that the data received by the recipient are exactly the same as it was sent (with out insertion or deletion of some portion). 
    • In message authentication, the sender computes the hash value (called message digest) of the message by applying a hash function on it and transmits both the message digest and the message. 
    • The receiver performs the same hash calculation on the message and compares the  calculated message digest with that of the message digest received from the sender.
    • If there is a mismatch, the receiver knows that the message (or possibly the message digest) has been altered.


    Digital Signatures

    • Digital signature is an encrypted form of a message that can be utilised for enforcing integrity and authentication of the message during transmission from sender to the receiver.
    • It can be used for ensuring the authentication of a message using cryptographic hash function. 
    • President Clinton signed a law to allow digital signatures to be used as a legal signature.  

    Use of Cryptography in Digital Signatures:
    • Proper use of cryptography can provide confidentiality, authentication and integrity of information during transmission.
    • Symmetric cryptography uses only one key for both encryption and decryption.  Whereas, asymmetric cryptography (also called public key cryptography) uses a key pair - one key to encrypt the data and another key to decrypt the data
    • In public key encryption , the private key is kept secret by the owner; the public key is published identifying who the owner is;  one key can't be used for creating another.

    Steps involved in using Digital Signatures:
        1. The information (message) to be secured is first put through a hash function.  The hash function creates a checksum of the information.
        2. The checksum is then encrypted with the help of sender's private key.  The encrypted checksum is known as the digital signature, because it needs the sender's public key for decrypting the checksum.
        3. The information (message) and the digital signature are sent to the receiver of the information.  If confidentiality of the information is also desired, then the message as well as digital signature can be encrypted using a symmetric key cryptography.
        4. At the receiving side, the receiver gets the information and puts it through the same hash function to derive the checksum of the message being sent.
        5. The encrypted checksum (digital signature) came along the message is decrypted and the two checksums (original and calculated) are compared.
        6. If the received checksum and the calculated checksum do match with each other, it ensures that the information has not been modified during transmission, i.e., integrity of the message is secured.


      The security and usefulness of a digital signature depends upon two critical elements:
      • Protection of the sender's private key
      • A secure hash function that creates a checksum of at least 128 bits.

      Continue reading →
      Wednesday, 9 September 2026

      Question Bank on Cryptography & Network Security

      0 comments

      Frequently Asked Questions (FAQ)


      UNIT-1

      Multiple Choice Questions:

      1.  The _______________ attack is related to confidentiality.
      • Fabrication
      • Interception
      • Interruption
      • Modification
      2.  If the recipient of the message has to be satisfied with the identity of the sender, the principle of ________________ comes into picture.
      • Authentication
      • Confidentiality
      • Integrity
      • Access control
      3.  The ______________ attack is related to availability. 
      • Fabrication
      • Interception
      • Interruption
      • Modification

      4.  If we want to ensure the principle of __________________, the content of a message must not be modified while in transit.
      • Authentication
      • Access control
      • Confidentiality
      • Integrity

      5.  Interruption attacks are also called as ______________ attack. 
      • Alteration
      • Denial of Service (DoS)
      • Masquerade
      • Replay attacks


        Descriptive Questions (2 Marks):

        1. Define Cryptography.
        2. What is steganography? How is it different from cryptography?
        3. What is masquerade?  Which principle of security is breached because of that?
        4. What are replay attacks?  Give an example of a replay attack.
        5. What are the two basic functions used in encryption algorithms?
        6. Writ the differences between Symmetric and Asymmetric ciphers.
        7. What is the main difference between a stream cipher and a block cipher?
        8. Briefly define the monoalphabetic cipher.
        9. What is the difference between a monoalphabetic cipher and a polyalphabetic cipher?
        10. Differentiate between substitution and transposition techniques in classical cryptography.


        Descriptive Questions (5 Marks):

        1. Explain the importance of cryptography in the evolution of secure communication with suitable historical examples.
        2. Discuss any one of the passive attacks in detail.
        3. Discuss any two Substitution Technique and list their merits and demerits.
        4. Explain the working principle of the Caesar cipher. Encrypt the text "NETWORK" using a key value of 3.
        5. Explain the Play Fair cipher algorithm? Encrypt the message ‘MY BALLOON’ using the key ‘MONACHRY’
        6. Compare and Contrast stream ciphers and block ciphers.
        7. Explain the followings: (a) Playfair cipher. (b) Vernam cipher
        8. Describe the working of a Columnar Transposition Cipher by encrypting the message “CRYPTOGRAPHY IS FUN” using the keyword “NETWORK.” Show column arrangement, transposition steps, and final ciphertext.
        9. Explain the basic principle of rotor machine.
        10. Explain the work of a Rotor Machine with a simple example. Show how a single plaintext letter is transformed through multiple rotors into ciphertext.
        Continue reading →
        Tuesday, 8 September 2026

        Question Bank on Information Security

        0 comments

        Frequently Asked Questions (FAQ)

        Unit-1 Questions

        Topics Covered: 
        • Security Attacks (Interruption, Interception, Modification and Fabrication)
        • Security Services (Confidentiality, Integrity, Authentication, Non-repudiation, Access Contol)
        • Security Mecahanisms
          • A model for inter-network security
        • Classical Encryption Techniques
        • DES, Strength of DES
        • Differential and Linear Cryptanalysis
        • Design principles and Modes of Operation of Block ciphers
        • Blowfish
        • Placement of Encryption Function
        • Traffic Confidentiality
        • Key Distribution
        • Random Number Generation


        Descriptive Questions (2 Marks):
        1. What does the CIA Triad stand for?
        2. What do you mean by Security Service?
        3. Define data confidentiality.
        4. What is Cryptanalysis?
        5. What are the ingredients of Symmetric Cipher model?
        6. List the security services available for securing a system from various attacks.
        7. Define stream ciphers.
        8. Differentiate Symmetric and Asymmetric cryptography.
        9. How many modes of operations are there for implementing a Block Cipher?  What are they?
        10. Give example for mono alphabetic and poly alphabetic ciphers.
        11. What is known as security attack?


        Descriptive Questions (5 Marks):
        1. With the help of a neat diagram, explain the model for network security.
        2. Differentiate active and passive security attack.
        3. Write short notes on Data Confidentiality.
        4. Explain symmetric cipher model with diagram.
        5. Make a comparison between Symmetric and Asymmetric cipher models.
        6. For each of the following assets, assign a low, moderate or high impact level for the loss of confidentiality, availability and integrity respectively.  Justify your answer:
          • Financial organisation managing routine administrative information
          • Organisation managing public information on its web server
          • Law enforcement organisation managing extremely sensitive information.
        7. Draw a matrix that shows the relationship between security mechanisms and attacks.
        8. State the difference between block cipher and stream cipher.
        9. Compare and contrast linear and differential cryptanalysis.
        10. List and explain the strength of DES.
        11. Explain in detail about Blowfish Algorithm.



        Unit-2 Questions

        Topics Covered: 
        • Principles of Public Key Cryptography
          • RSA Algorithm
        • Key Management
          • Diffie-Hellman Key Exchange
        • Elliptic Curve Cryptography
        • Message Authentication and Hash Functions
          • Authentication Requirements
          • Message authentication
          • Hash Functions and MACs
          • Hash and MAC Algorithms
          • SHA-512
          • HMAC


        Descriptive Questions (2 Marks):
        1. Describe the use of Public Key cryptography.
        2. Draw the diagram for Public-Key distribution scenario.
        3. What is one-way authentication.
        4. Draw the general structure of Secure Hash Code.
        5. What are the requirements of MAC function?



        Descriptive Questions (5 Marks):
        1. Briefly explain the working principle of Public Key Cryptography.
        2. In RSA, Given n=12091 and e=13, encrypt the message "THIS IS TOUGH" using the 00 to 26 encoding scheme.  Also decrypt the ciphertext to find the original message.
        3. Explain simple secret key distribution with diagram.
        4. Explain the Diffie-Helmen key exchange algorithm.
        5. Discuss about authentication requirement.
        6. Discuss about message authentication and Hash functions.
        7. Explain the SHA-512 algorithm.  Illustrate with an example.
        8. Explain message digest generation using SHA-512 algorithm.  
        9. What is the order of finding two messages having the same message digest using SHA-512?
        10. Define HMAC.  Write short notes on Security of HMAC.



        Unit-3 Questions

        Topics Covered: 
        • Digital Signatures
        • Authentication Protocols
        • Digital Signature Standard (DSS)
        • Authentication Applications
        • Kerberos
        • X.509 Directory Authentication Service (DAS)
        • E-Mail Security
          • Pretty Good Privacy (PGP)
          • S/MIME


        Descriptive Questions (2 Marks):
        1. What is Digital Signature?
        2. Differentiate RSA and DES approach for digital signature.
        3. Why Kerberos is needed?


        Descriptive Questions (5 Marks):
        1. State the properties and requirements of digital signatures.
        2. Mention three variations of digital signatures and state the purpose of each.
        3. Explain in detail about Kerberos.
        4. Assume client C wants to communicate with a server S using Kerberos protocol.  How can it be achieved?
        5. Explain the X.509 certificate formats.
        6. Explain the X.509v3 certificate format.
        7. What do you mean by PGP?  Explain the working principle of PGP.
        8. Why does PGP compress the message?  What are the reasons for compressing the signature before encryption.
        9. List and explain the services provided by PGP and show how message generation is done using PGP with a neat diagram.
        10. In PGP, what is the probability that a user with N Public Keys will have at least one, duplicate key ID?




        Unit-4 Questions

        Topics Covered: 
        • IP Security
          • Overview
          • IP Security Architecture
          • Authentication Header (AH)
          • Encapsulating Security Payload (ESP) 
          • Combining Security Associations (SAs)
          • Key Management
        • Web Security
          • Web Security Requirements
          • Secure Socket Layer (SSL)
          • Transport Layer Security (TLS)
          • Secure Electronic Transaction (SET)


        Descriptive Questions (2 Marks):
        1. Define the term IP Security (IPSec).
        2. What is TLS?
        3. Write about Security Association (SA).


        Descriptive Questions (5 Marks):
        1. What is IP Security?  Discuss in detail about IPSec Architecture.
        2. Explain IP Security architecture with supporting diagrams.
        3. Explain the need for combining Security Associations (SAs) for network security.
        4. Explain in detail Secure Electronic Transaction (SET).
        5. Discuss the steps involved in Secure Electronic Transaction (SET).




        Unit-5 Questions

        Topics Covered: 
        • Intruders
          • Viruses and Worms
          • Viruses and related threats
        • Firewall
          • Firewall Design Principles
          • Trusted Systems
          • Intrusion Detection System (IDS)


        Descriptive Questions (2 Marks):
        1. What do you mean by Worms?
        2. Write any two design goals of firewall.
        3. List the three types of firewall.
        4. What is the role of firewall in Information Security (IS)?


        Descriptive Questions (5 Marks):
        1. Discuss about:
          • Intruders
          • Trusted System
        2. Differentiate worms and viruses.
        3. Select any antivirus of your choice and explain it in detail.
        4. Write and explain the four phases that a typical virus goes through.
        5. Explain in detail Intrusion Detection System (IDS) with diagram.
        6. Where would you place a web server in an organisation assuming that you can use a network firewall and why?
        7. Define firewall.  Explain its characteristics, types, services and limitations.

          Continue reading →