Security Controls, Encryption and Authentication
Saved in this browser only. See all revisions due
Key points
- A firewall filters traffic; an antivirus removes malware
- Symmetric encryption uses one key, asymmetric uses a public and private pair
- Sign with the private key, verify with the public key
- A digital signature gives authenticity, integrity and non-repudiation
- Authentication is who you are; authorisation is what you may do
- An OTP is a possession factor, not knowledge
- 2FA needs two factors from different categories
- Combinations = choices to the power length
Security controls
| Control | What it does |
|---|---|
| Firewall | Allows or blocks network traffic according to rules; may be hardware or software |
| Antivirus | Scans files, detects and removes malware; its signature database must be updated |
| Patch management | Keeps the OS and software updated so known flaws are closed |
| VPN | Creates an encrypted tunnel over a public network |
| Sandbox | Runs a suspicious program in an isolated environment |
| Honeypot | A decoy system that attracts attackers so they can be studied |
Key point
A firewall filters traffic; it does not remove a virus. An antivirus removes malware but does not filter network traffic. Interchanging the two is a standard trap.
Encryption
Encryption converts readable plaintext into unreadable ciphertext.
- Symmetric: the same key encrypts and decrypts, as in AES.
- Asymmetric: a public key and private key pair, as in RSA.
- HTTPS uses TLS encryption. The padlock in the browser shows only that the connection is encrypted; it is no guarantee that the site itself is genuine.
Digital signatures
The sender signs using the private key and the receiver verifies using the public key. A digital signature provides authenticity, integrity and non-repudiation, meaning the sender cannot later deny having sent it.
In India a Digital Signature Certificate is issued by Certifying Authorities licensed by the Controller of Certifying Authorities. E-tendering normally requires a Class 3 DSC. Verify this against the latest official instructions before relying on it.
Authentication
Authentication answers who you are. Authorisation answers what you may do. Authentication comes first.
| Factor | Meaning | Examples |
|---|---|---|
| Knowledge | Something you know | Password, PIN, security question |
| Possession | Something you have | OTP on the registered mobile, hardware token, smart card |
| Inherence | Something you are | Fingerprint, face, iris |
Two-factor authentication requires factors from two different categories. A password plus a security question is not 2FA, because both are knowledge factors.
Strong passwords
Use length above all, mix upper and lower case, numbers and symbols, keep a different password for every account, never share it, and prefer a password manager.
Formula
Total combinations = c to the power n, where c is the number of choices per position and n is the length, when repetition is allowed.
Example
A 4-digit numeric PIN has 10 to the power 4, that is 10,000 possible values from 0000 to 9999. Adding length increases the count exponentially, which is why long passwords are safer.
Exam tip
An OTP is a possession factor, not a knowledge factor. This single distinction decides most 2FA questions.
Practice questions
Answer all, then check. Explanations appear after checking.
Finished this topic? Tick it off.
Saved in this browser only. See all revisions due