Paper (movie-Gattaca)

profileOeyZ
INFOI101LectureWeek11-Security1.pdf

3/25/2019

1

INFO I101 Introduction to Informatics and Computing

Security

INDIANA UNIVERSITY BLOOMINGTON

INFO I101

Communication

Course Instructors [email protected]

Lab Instructors [email protected]

Always include your Lab Section Number in the subject line! Write professionally.

Do not email our personal emails! Do not use Canvas Messenger!

3/25/2019

2

INFO I101

Office Hours

Checkout the course website for information on office hours with the course instructors.

Logan: IW 307A Nina: Undergrad Annex

No appointments necessary!

INFO I101

Study Sessions

MTWR, 7-8 PM

Informatics West Lobby

No appointments necessary!

3/25/2019

3

INFO I101

Lab Checks (Exams)

Lab Check 1 (HTML/CSS) Week 04 Lab 02

Lab Check 2 (Python) Week 07 Lab 02

Lab Check 3 (JavaScript) Week 10 Lab 02

Lab Check 4 (Database) Week 13 Lab 02

INFO I101

Duo

Not being able to login via Duo is not a reason for a makeup exam. Make sure your phone is charged or you have an alternative method for authentication.

3/25/2019

4

INFO I101

Makeup Exams

• See announcement.

• You have one week from the date of your exam to request a makeup via the form. No requests after this.

• Makeups are only offered at certain dates and times. (See announcement.)

• You must have documentation.

INFO I101

Major Papers & Projects

All on Course Schedule & in Canvas.

• Foundations Paper

• Dimensions Paper

• Final Paper & Final Reflection

• Individual Midterm Project

Check Course Schedule for complete list.

3/25/2019

5

INFO I101

Pre-Lecture Prep

Due before your lecture begins.

Short quiz or writing assignment.

• Only one attempt! No exceptions.

• Exempt from late policy/tech buffer.

Foundations will be released later in the semester.

INFO I101

Accommodations

DSS Memos or Religious Observance paperwork due in the first two weeks.

Bring to instructor office hours.

These accommodations are not retro-active.

3/25/2019

6

INFO I101

ICE Sheets

• Form a group of 4-5. (Not 3, not 6.)

• Send one representative up to get an ICE Sheet.

• Each member should fill in their own name, username, and initials.

• Select the Lecture Day/Time and write in the Lecture Title.

Low (or no) effort on ICE activities can result in no attendance.

INFO I101 Introduction to Informatics and Computing

Security

INDIANA UNIVERSITY BLOOMINGTON

3/25/2019

7

DIMENSIONS OF INFORMATICS & COMPUTING: CYBER-SECURITY Matt Hottell

• Three principles underline Information Security: • Confidentiality • Integrity • Availability

SECURITY: THE CIA

3/25/2019

8

• Achieving this goal means that only appropriately authorized entities can get access to resources.

• Applies to communications as well as computer resources • Techniques:

• Authentication (CAS) • Encryption • Access controls and classification levels

CONFIDENTIALITY

• This goal is the prevention of unauthorized alteration of data, regardless of accidental or malicious intent.

• If a change occurs, we should be able to recognize that it has happened and hopefully have a backup.

• Techniques: • Algorithmic validation (checksums, hashing) • Access logs

INTEGRITY

3/25/2019

9

• Authorized users should be allowed to access resources when needed. • To do this, we need to make sure that attacks or other scenarios are not

preventing access. • Denial of service or server overload • Hacking • Accidents/disasters/outages

AVAILABILITY

• Which of the CIA principles do each of the following violate:

• A virus attack deletes most of the documents on a computer. • A virus attack bogs down a computer so that is is running too slowly to service

requests. • An attacker uses a logged-in computer of someone who has gone off to a

meeting to change grades on Oncourse. • A distributed denial of service attack shuts down Amazon.com for 4 hours. • An attacker calls a worker and pretends to be from the IT Helpdesk and

convinces that worker to give the attacker his password.

PICK THE PRINCIPLE

3/25/2019

10

• Managing risk is the way we make decisions about each of the CIA principles

• Risk = Threat x Vulnerability x Cost • Threat is the frequency of a particular adverse event happening • Vulnerability is the likelihood of a particular threat being effective against a

particular organization. • i.e. a weakness that can be exploited

• Cost is the potential impact of a threat acting on a vulnerable organization.

MANAGING RISK

• The threat of a virus attack is approximately 88 per 1,000 users per day.

EXAMPLE RISK: VIRUS ATTACK ON A PC

3/25/2019

11

SECURITY: THE BROAD PICTURE

SECURITY APPLICATION: ENCRYPTION

3/25/2019

12

CRYPTOGRAPHY The Science of Secret Messages

• The classic problem in terms of computing is how do we send confidential data securely between two computers that have never communicated with each other before?

• Buying a book from amazon • Getting bank account details

WHY CRYPTO?

3/25/2019

13

• Plaintext – the message

• Ciphertext – the encrypted message

• Encryption – process of converting plaintext into ciphertext

• Decryption – process of converting ciphertext into plaintext

DEFINITIONS

3/25/2019

14

• Transposition • Switching the symbols within the plaintext

• Substitution • Substituting different symbols for the symbols in the plaintext

METHODS OF ENCRYPTION

• Rail fence cipher: one if by land two if by sea - plaintext

o e f y a d w i b s a n i b l n t o f y e

oefyadwibsaniblntofye - ciphertext

TRANSPOSITION EXAMPLE

3/25/2019

15

• Decrypt the following 3-rail fence cipher: FROASEESOOSRNENAAUCEDVYRG

TRANSPOSITION EXAMPLE

ICE 1

When the ephors send out an admiral or a general, they make two round pieces of wood exactly alike in length and thickness, so that each corresponds to the other in its dimensions, and keep one themselves, while they give the other to their envoy. These pieces of wood they call scytalae. Whenever, then, they wish to send some secret and important message, they make a scroll of parchment long and narrow, like a leathern strap, and wind it round their scytale, leaving no vacant space thereon, but covering its surface all round with the parchment. After doing this, they write what they wish on the parchment, just as it lies wrapped about the scytale; and when they have written their message, they take the parchment off and send it, without the piece of wood, to the commander. He, when he has received it, cannot otherwise get any meaning out of it,-- since the letters have no connection, but are disarranged,--unless he takes his own scytale and winds the strip of parchment about it, so that, when its spiral course is restored perfectly, and that which follows is joined to that which precedes, he reads around the staff, and so discovers the continuity of the message. And the parchment, like the staff, is called scytale, as the thing measured bears the name of the measure. -Plutarch, Lives

3/25/2019

16

• Julius Caesar Cipher • Substitute each letter in the plaintext by the letter that is 3 down from it.

• Encode(letter)=(letter+3) mod 26 • Decode(letter)=(letter -3) mod 26

SUBSTITUTION EXAMPLE

• Plaintext: One if by land two if by sea

• Ciphertext: Rqh li eb odqg wzr li eb vhd

CAESAR CIPHER EXAMPLE

3/25/2019

17

• Decode the following message: vhqg pruh slccd

CAESAR CIPHER EXAMPLE

ICE 2

• There are 4.0x1026 possible arrangements of the 26 letters. • At one arrangement per sec it would take a billion people the lifetime of the

universe to check all possibilities. • Yet they are surprisingly easy to break…

SUBSTITUTION CIPHERS

3/25/2019

18

• Check frequency of symbols in the ciphertext and compare them to “normal” frequency of letters in that language.

• Issues…

FREQUENCY ANALYSIS

• Knowledge of the same key provides the ability to both encode and decode.

• Traditional forms of encryption

SYMMETRIC KEY ENCRYPTION

3/25/2019

19

• Proposed the first asymmetric encryption scheme. • Alice and Bob each have a private key that only they know and a public

key that anyone can know. • The private key cannot be calculated using the public key

WHIT DIFFIE IN 1975

• Messages encrypted with Bob’s public key can only be decrypted using his private key

• Messages encrypted using Bob’s private key can only be decrypted using Bob’s public key.

• This is also known as Public Key Encryption

WHIT DIFFIE IN 1975

3/25/2019

20

• In April, 1977 a group of 3 MIT professors figured out mathematically how to implement Whit Diffie’s concept of asymmetric key encryption

• They formed RSA, named for the last names of the 3 researchers (Rivest, Shamir, and Adleman)

RSA

3/25/2019

21

• So how is crypto used in web browsers today?

CRYPTOGRAPHY

ICE 3

What is ONE thing that you found to be interesting during today’s lecture? Why was it interesting to you? Discuss in your group and record your thoughts.

(You MUST complete this activity to receive attendance, a blank page with only your name and username will NOT count towards attendance)

ICE 3

3/25/2019

22

Any questions? INFO I101

1. Bring your ICE Sheet to the front and set it on the pile.

2. Scan your CrimsonCard for attendance.

On your way out…