Terminologies Lecture 3d: Compsci 726 Network Defence and Countermeasures
Terminologies Lecture 3d: Compsci 726 Network Defence and Countermeasures
Terminologies Lecture 3d: Compsci 726 Network Defence and Countermeasures
Lecture 3d
COMPSCI 726
Network Defence and Countermeasures
Source: SANS
2
THE OSI SECURITY ARCHITECTURE
▪ Security attack
– An action that compromises security of the system and
exchanged information
▪ Security service
– A service that enhances security of the system and
exchanged information
▪ Security mechanism
– A mechanism that is designed to detect, prevent, or recover
from a security attack
3
TYPES OF SECURITY ATTACKS
▪ Passive
– Release of message content (disclosure)
– Traffic analysis
▪ Active
– Masquerade
– Replay
– Message modification
– Denial of Service (DoS)
4
RELEASE OF MESSAGE CONTENT
5
TRAFFIC ANALYSIS
6
MASQUERADE
7
REPLAY
8
MESSAGE MODIFICATION
9
DENIAL OF SERVICE (DOS)
10
SECURITY SERVICES
▪ Authentication
– A process of identifying whether the communicating entity is the one it
claims to be
▪ Confidentiality
– Protection of the data
▪ Data integrity
– Ensuring received data is not tampered by unauthorised entities
▪ Non-repudiation
– Protection against denial by communicating entities
▪ Availability
– The property of a system being accessible and usable upon demand
11
RELATIONSHIP BETWEEN SECURITY
SERVICES AND ATTACKS
Release of
Traffic Message Denial of
Message Masquerade Replay
Analysis Modification Service
Services Content
Authentication ✓
Access
✓
Control
Confidentiality
✓
(Message)
Confidentiality
✓
(Header)
Data Integrity ✓* ✓
Non-
repudiation
Availability ✓
* Using freshness
12
TO BE CONTINUED
13
Questions?
14