Daily current affairs on DailyCA
DailyCA NotesStudy notes for competitive exams My revisionsRevisions

Security Controls, Encryption and Authentication

Basic 5 min read Updated

Saved in this browser only. See all revisions due

Key points

  • A firewall filters traffic; an antivirus removes malware
  • Symmetric encryption uses one key, asymmetric uses a public and private pair
  • Sign with the private key, verify with the public key
  • A digital signature gives authenticity, integrity and non-repudiation
  • Authentication is who you are; authorisation is what you may do
  • An OTP is a possession factor, not knowledge
  • 2FA needs two factors from different categories
  • Combinations = choices to the power length
On this page
  1. Security controls
  2. Encryption
  3. Digital signatures
  4. Authentication
  5. Strong passwords

Security controls

ControlWhat it does
FirewallAllows or blocks network traffic according to rules; may be hardware or software
AntivirusScans files, detects and removes malware; its signature database must be updated
Patch managementKeeps the OS and software updated so known flaws are closed
VPNCreates an encrypted tunnel over a public network
SandboxRuns a suspicious program in an isolated environment
HoneypotA decoy system that attracts attackers so they can be studied

Key point

A firewall filters traffic; it does not remove a virus. An antivirus removes malware but does not filter network traffic. Interchanging the two is a standard trap.

Encryption

Encryption converts readable plaintext into unreadable ciphertext.

  • Symmetric: the same key encrypts and decrypts, as in AES.
  • Asymmetric: a public key and private key pair, as in RSA.
  • HTTPS uses TLS encryption. The padlock in the browser shows only that the connection is encrypted; it is no guarantee that the site itself is genuine.

Digital signatures

The sender signs using the private key and the receiver verifies using the public key. A digital signature provides authenticity, integrity and non-repudiation, meaning the sender cannot later deny having sent it.

In India a Digital Signature Certificate is issued by Certifying Authorities licensed by the Controller of Certifying Authorities. E-tendering normally requires a Class 3 DSC. Verify this against the latest official instructions before relying on it.

Authentication

Authentication answers who you are. Authorisation answers what you may do. Authentication comes first.

FactorMeaningExamples
KnowledgeSomething you knowPassword, PIN, security question
PossessionSomething you haveOTP on the registered mobile, hardware token, smart card
InherenceSomething you areFingerprint, face, iris

Two-factor authentication requires factors from two different categories. A password plus a security question is not 2FA, because both are knowledge factors.

Strong passwords

Use length above all, mix upper and lower case, numbers and symbols, keep a different password for every account, never share it, and prefer a password manager.

Formula

Total combinations = c to the power n, where c is the number of choices per position and n is the length, when repetition is allowed.

Example

A 4-digit numeric PIN has 10 to the power 4, that is 10,000 possible values from 0000 to 9999. Adding length increases the count exponentially, which is why long passwords are safer.

Exam tip

An OTP is a possession factor, not a knowledge factor. This single distinction decides most 2FA questions.

Practice questions

Answer all, then check. Explanations appear after checking.

1Which security tool monitors and filters incoming and outgoing network traffic according to predefined rules?
2Which of the following is an example of the possession factor of authentication?
3In a digital signature, the sender signs the message using which key?
4An office locker uses a 4-digit numeric PIN in which digits may repeat. How many different PINs are possible?
5The padlock symbol and HTTPS in a browser confirm that:

Finished this topic? Tick it off.

Saved in this browser only. See all revisions due