🔐 Cryptography Unit 4

Information Security, Network Security, Firewalls, IDS, Email Security, IPSec, SSL/TLS and SET

Unit 4

🎯 Unit 4 Overview

Unit 4 focuses on information security and network security. It covers network threats, security controls, wireless security, honeypots, firewalls, IDS, email security, IP security and web security protocols.

Exam Tip: Firewalls, IDS, PGP, S-MIME, IPSec and SSL/TLS are highly important for RGPV exam.

🛡️ Information Security

Information Security means protecting information from unauthorized access, misuse, modification, destruction or disclosure.

Main Goals of Information Security

⚠️ Threats in Networks

Network threats are attacks or risks that can damage computer networks, steal data or interrupt services.

Threat Description
Malware Malicious software like virus, worm, trojan and ransomware.
Phishing Fake messages or websites used to steal sensitive information.
Denial of Service Attack that makes a network or service unavailable.
Spoofing Attacker pretends to be a trusted user or system.
Man-in-the-Middle Attacker secretly intercepts communication between two parties.
Password Attack Attack to guess, steal or crack passwords.

🏗️ Network Security Controls – Architecture

Network security architecture includes different security layers and mechanisms used to protect network resources.

Important Security Controls

📡 Wireless Security

Wireless security protects wireless networks from unauthorized access and attacks.

Common Wireless Threats

Wireless Security Methods

🍯 Honeypots

A honeypot is a security mechanism that acts like a fake system to attract attackers. It helps security experts study attack methods.

Uses of Honeypots

Honeypot real production system nahi hota, ye attacker ko trap karne ke liye fake system hota hai.

🚦 Traffic Flow Security

Traffic flow security protects information related to communication patterns such as who is communicating, when communication is happening and how much data is transferred.

Methods

🔥 Firewalls

A firewall is a network security device or software that monitors and controls incoming and outgoing network traffic based on security rules.

Functions of Firewall

🧱 Types of Firewalls

Firewall Type Description
Packet Filtering Firewall Filters packets based on IP address, port number and protocol.
Stateful Inspection Firewall Tracks active connections and checks packet state.
Proxy Firewall Acts as an intermediate system between user and internet.
Application Level Firewall Filters traffic at application layer.
Next Generation Firewall Includes deep packet inspection, application control and intrusion prevention.
Personal Firewall Installed on individual computers to protect them.

🚨 Intrusion Detection System

IDS monitors network or system activities and detects suspicious or malicious behavior. It alerts the administrator when an attack is detected.

Types of IDS

📧 Email Security

Email security protects email communication from unauthorized access, phishing, spam, malware and data leakage.

Email Security Threats

🔏 Pretty Good Privacy (PGP)

PGP is an email security system used for encryption, decryption and digital signatures. It provides confidentiality, authentication and integrity.

Services Provided by PGP

📨 S-MIME

S-MIME stands for Secure/Multipurpose Internet Mail Extensions. It is used to secure email communication using encryption and digital signatures.

Features

🌐 IP Security

IP Security protects data communication at the IP layer. It provides secure communication over public networks.

Important IP Security Topics

🔐 IPSec

IPSec is a set of protocols used to secure IP communication through authentication and encryption.

Services of IPSec

Modes of IPSec

📦 Encapsulation Security Payload

ESP is a component of IPSec that provides confidentiality, authentication and integrity by encrypting the payload.

Functions

🔑 Internet Key Exchange

IKE is used in IPSec to establish secure keys between two communicating parties.

Functions of IKE

🌍 Web Security

Web security protects websites, web applications and online transactions from cyber attacks.

Common Web Threats

🔒 SSL/TLS

SSL/TLS is used to secure communication between web browser and web server. HTTPS uses TLS for secure communication.

Services

SSL is older, TLS is newer and more secure. Modern websites use TLS.

💳 Secure Electronic Transaction

SET is a security protocol designed for secure credit card transactions over the internet.

Goals of SET

⚖️ Firewall vs IDS

Firewall IDS
Controls incoming and outgoing traffic. Monitors traffic and detects attacks.
Can block unauthorized traffic. Mainly generates alerts.
Works as first line of defense. Works as monitoring and detection system.
Uses security rules. Uses signatures or anomaly detection.

⭐ Important Questions

  1. Explain information security and its goals.
  2. Explain threats in networks.
  3. Explain network security controls and architecture.
  4. What is firewall? Explain types of firewalls.
  5. Explain Intrusion Detection System and its types.
  6. Explain email security threats and controls.
  7. Explain PGP and its services.
  8. Explain S-MIME.
  9. Explain IPSec and its modes.
  10. Explain SSL/TLS and SET.

🔥 Last Minute Revision

🔗 Related Links