Attack, services and mechanisms Prof. Neeraj
Description: Attack, services and mechanisms Prof. Neeraj Bhargava Pramod Singh Rathore Department of Computer Science School of Engineering System Sciences, MDS University Ajmer, Rajasthan, India Introduction To assess the security needs of an
Related Topics
Download Presentation
"Attack, services and mechanisms Prof. Neeraj" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.
Presentation Transcript
slide1. Attack, services and mechanisms
Prof. Neeraj Bhargava
Pramod Singh Rathore
Department of Computer Science
School of Engineering & System Sciences,
MDS University Ajmer, Rajasthan, India<br>
slide2. Introduction To assess the security needs of an organization effectively, the manager responsible for security, needs some systematic way of defining the requirements for security and characterization of approaches to satisfy those requirements. One approach is to consider three aspects of information security:
Security Attack: Any action that compromises the security of information.
Security Mechanism: A mechanism that is designed to detect, prevent, or recover from a security attack.
Security Service: A service that enhances the security of data processing systems and information transfers. A security service makes use of one or more security mechanisms.<br>
slide3. Security Attacks<br>
slide4. Attacks threating Confidentiality Snooping: refers to unauthorized access to or interception of data.
Traffic Analysis: refers to obtaining some other type of information by monitoring online traffic.<br>
slide5. Attacks threating Integrity Modification: means that the attacker intercepts the message and changes it.
Masquerading: happens when somebody impersonates somebody else.
Replaying: means the attacker impersonates somebody else.
Repudiation: means that the sender of the message later deny that he/she sends the message; receiver of the message might later deny that he has received the message.<br>
slide6. Attacks threating Availability Denial of service(DOS): is a very common attack. It may slow down or totally interrupt the service of a system.<br>
slide7. Security Services Authentication: assures recipient that the message is from the source that it claims to be from.Â
Access Control: controls who can have access to resource under what condition
Availability:Â available to authorized entities for 24/7.Â
Confidentiality:Â information is not made available to unauthorized individual
Integrity:Â assurance that the message is unaltered
Non-Repudiation:Â protection against denial of sending or receiving in the communication<br>
slide8. Security Mechanisms Encipherment :This security mechanism deals with hiding and covering of data which helps data to become confidential. It is achieved by applying mathematical calculations or algorithms which reconstruct information into not readable form. It is achieved by two famous techniques named Cryptography and Encipherment. Level of data encryption is dependent on the algorithm used for encipherment.
Access Control :This mechanism is used to stop unattended access to data which you are sending. It can be achieved by various techniques such as applying passwords, using firewall, or just by adding PIN to data.
Notarization :This security mechanism involves use of trusted third party in communication. It acts as mediator between sender and receiver so that if any chance of conflict is reduced. This mediator keeps record of requests made by sender to receiver for later denied.
Data Integrity :This security mechanism is used by appending value to data to which is created by data itself. It is similar to sending packet of information known to both sending and receiving parties and checked before and after data is received. When this packet or data which is appended is checked and is the same while sending and receiving data integrity is maintained.<br>
slide9. Authentication exchange :This security mechanism deals with identity to be known in communication. This is achieved at the TCP/IP layer where two-way handshaking mechanism is used to ensure data is sent or not
Bit stuffing :This security mechanism is used to add some extra bits into data which is being transmitted. It helps data to be checked at the receiving end and is achieved by Even parity or Odd Parity.
Digital Signature :This security mechanism is achieved by adding digital data that is not visible to eyes. It is form of electronic signature which is added by sender which is checked by receiver electronically. This mechanism is used to preserve data which is not more confidential but sender’s identity is to be notified.<br>
slide10. Thank you…<br>
Prof. Neeraj Bhargava
Pramod Singh Rathore
Department of Computer Science
School of Engineering & System Sciences,
MDS University Ajmer, Rajasthan, India<br>
slide2. Introduction To assess the security needs of an organization effectively, the manager responsible for security, needs some systematic way of defining the requirements for security and characterization of approaches to satisfy those requirements. One approach is to consider three aspects of information security:
Security Attack: Any action that compromises the security of information.
Security Mechanism: A mechanism that is designed to detect, prevent, or recover from a security attack.
Security Service: A service that enhances the security of data processing systems and information transfers. A security service makes use of one or more security mechanisms.<br>
slide3. Security Attacks<br>
slide4. Attacks threating Confidentiality Snooping: refers to unauthorized access to or interception of data.
Traffic Analysis: refers to obtaining some other type of information by monitoring online traffic.<br>
slide5. Attacks threating Integrity Modification: means that the attacker intercepts the message and changes it.
Masquerading: happens when somebody impersonates somebody else.
Replaying: means the attacker impersonates somebody else.
Repudiation: means that the sender of the message later deny that he/she sends the message; receiver of the message might later deny that he has received the message.<br>
slide6. Attacks threating Availability Denial of service(DOS): is a very common attack. It may slow down or totally interrupt the service of a system.<br>
slide7. Security Services Authentication: assures recipient that the message is from the source that it claims to be from.Â
Access Control: controls who can have access to resource under what condition
Availability:Â available to authorized entities for 24/7.Â
Confidentiality:Â information is not made available to unauthorized individual
Integrity:Â assurance that the message is unaltered
Non-Repudiation:Â protection against denial of sending or receiving in the communication<br>
slide8. Security Mechanisms Encipherment :This security mechanism deals with hiding and covering of data which helps data to become confidential. It is achieved by applying mathematical calculations or algorithms which reconstruct information into not readable form. It is achieved by two famous techniques named Cryptography and Encipherment. Level of data encryption is dependent on the algorithm used for encipherment.
Access Control :This mechanism is used to stop unattended access to data which you are sending. It can be achieved by various techniques such as applying passwords, using firewall, or just by adding PIN to data.
Notarization :This security mechanism involves use of trusted third party in communication. It acts as mediator between sender and receiver so that if any chance of conflict is reduced. This mediator keeps record of requests made by sender to receiver for later denied.
Data Integrity :This security mechanism is used by appending value to data to which is created by data itself. It is similar to sending packet of information known to both sending and receiving parties and checked before and after data is received. When this packet or data which is appended is checked and is the same while sending and receiving data integrity is maintained.<br>
slide9. Authentication exchange :This security mechanism deals with identity to be known in communication. This is achieved at the TCP/IP layer where two-way handshaking mechanism is used to ensure data is sent or not
Bit stuffing :This security mechanism is used to add some extra bits into data which is being transmitted. It helps data to be checked at the receiving end and is achieved by Even parity or Odd Parity.
Digital Signature :This security mechanism is achieved by adding digital data that is not visible to eyes. It is form of electronic signature which is added by sender which is checked by receiver electronically. This mechanism is used to preserve data which is not more confidential but sender’s identity is to be notified.<br>
slide10. Thank you…<br>