Paper (movie-Gattaca)
3/25/2019
1
INFO I101 Introduction to Informatics and Computing
Security
INDIANA UNIVERSITY BLOOMINGTON
INFO I101
Communication
Course Instructors [email protected]
Lab Instructors [email protected]
Always include your Lab Section Number in the subject line! Write professionally.
Do not email our personal emails! Do not use Canvas Messenger!
3/25/2019
2
INFO I101
Office Hours
Checkout the course website for information on office hours with the course instructors.
Logan: IW 307A Nina: Undergrad Annex
No appointments necessary!
INFO I101
Study Sessions
MTWR, 7-8 PM
Informatics West Lobby
No appointments necessary!
3/25/2019
3
INFO I101
Lab Checks (Exams)
Lab Check 1 (HTML/CSS) Week 04 Lab 02
Lab Check 2 (Python) Week 07 Lab 02
Lab Check 3 (JavaScript) Week 10 Lab 02
Lab Check 4 (Database) Week 13 Lab 02
INFO I101
Duo
Not being able to login via Duo is not a reason for a makeup exam. Make sure your phone is charged or you have an alternative method for authentication.
3/25/2019
4
INFO I101
Makeup Exams
• See announcement.
• You have one week from the date of your exam to request a makeup via the form. No requests after this.
• Makeups are only offered at certain dates and times. (See announcement.)
• You must have documentation.
INFO I101
Major Papers & Projects
All on Course Schedule & in Canvas.
• Foundations Paper
• Dimensions Paper
• Final Paper & Final Reflection
• Individual Midterm Project
Check Course Schedule for complete list.
3/25/2019
5
INFO I101
Pre-Lecture Prep
Due before your lecture begins.
Short quiz or writing assignment.
• Only one attempt! No exceptions.
• Exempt from late policy/tech buffer.
Foundations will be released later in the semester.
INFO I101
Accommodations
DSS Memos or Religious Observance paperwork due in the first two weeks.
Bring to instructor office hours.
These accommodations are not retro-active.
3/25/2019
6
INFO I101
ICE Sheets
• Form a group of 4-5. (Not 3, not 6.)
• Send one representative up to get an ICE Sheet.
• Each member should fill in their own name, username, and initials.
• Select the Lecture Day/Time and write in the Lecture Title.
Low (or no) effort on ICE activities can result in no attendance.
INFO I101 Introduction to Informatics and Computing
Security
INDIANA UNIVERSITY BLOOMINGTON
3/25/2019
7
DIMENSIONS OF INFORMATICS & COMPUTING: CYBER-SECURITY Matt Hottell
• Three principles underline Information Security: • Confidentiality • Integrity • Availability
SECURITY: THE CIA
3/25/2019
8
• Achieving this goal means that only appropriately authorized entities can get access to resources.
• Applies to communications as well as computer resources • Techniques:
• Authentication (CAS) • Encryption • Access controls and classification levels
CONFIDENTIALITY
• This goal is the prevention of unauthorized alteration of data, regardless of accidental or malicious intent.
• If a change occurs, we should be able to recognize that it has happened and hopefully have a backup.
• Techniques: • Algorithmic validation (checksums, hashing) • Access logs
INTEGRITY
3/25/2019
9
• Authorized users should be allowed to access resources when needed. • To do this, we need to make sure that attacks or other scenarios are not
preventing access. • Denial of service or server overload • Hacking • Accidents/disasters/outages
AVAILABILITY
• Which of the CIA principles do each of the following violate:
• A virus attack deletes most of the documents on a computer. • A virus attack bogs down a computer so that is is running too slowly to service
requests. • An attacker uses a logged-in computer of someone who has gone off to a
meeting to change grades on Oncourse. • A distributed denial of service attack shuts down Amazon.com for 4 hours. • An attacker calls a worker and pretends to be from the IT Helpdesk and
convinces that worker to give the attacker his password.
PICK THE PRINCIPLE
3/25/2019
10
• Managing risk is the way we make decisions about each of the CIA principles
• Risk = Threat x Vulnerability x Cost • Threat is the frequency of a particular adverse event happening • Vulnerability is the likelihood of a particular threat being effective against a
particular organization. • i.e. a weakness that can be exploited
• Cost is the potential impact of a threat acting on a vulnerable organization.
MANAGING RISK
• The threat of a virus attack is approximately 88 per 1,000 users per day.
EXAMPLE RISK: VIRUS ATTACK ON A PC
3/25/2019
11
SECURITY: THE BROAD PICTURE
SECURITY APPLICATION: ENCRYPTION
3/25/2019
12
CRYPTOGRAPHY The Science of Secret Messages
• The classic problem in terms of computing is how do we send confidential data securely between two computers that have never communicated with each other before?
• Buying a book from amazon • Getting bank account details
WHY CRYPTO?
3/25/2019
13
• Plaintext – the message
• Ciphertext – the encrypted message
• Encryption – process of converting plaintext into ciphertext
• Decryption – process of converting ciphertext into plaintext
DEFINITIONS
3/25/2019
14
• Transposition • Switching the symbols within the plaintext
• Substitution • Substituting different symbols for the symbols in the plaintext
METHODS OF ENCRYPTION
• Rail fence cipher: one if by land two if by sea - plaintext
o e f y a d w i b s a n i b l n t o f y e
oefyadwibsaniblntofye - ciphertext
TRANSPOSITION EXAMPLE
3/25/2019
15
• Decrypt the following 3-rail fence cipher: FROASEESOOSRNENAAUCEDVYRG
TRANSPOSITION EXAMPLE
ICE 1
When the ephors send out an admiral or a general, they make two round pieces of wood exactly alike in length and thickness, so that each corresponds to the other in its dimensions, and keep one themselves, while they give the other to their envoy. These pieces of wood they call scytalae. Whenever, then, they wish to send some secret and important message, they make a scroll of parchment long and narrow, like a leathern strap, and wind it round their scytale, leaving no vacant space thereon, but covering its surface all round with the parchment. After doing this, they write what they wish on the parchment, just as it lies wrapped about the scytale; and when they have written their message, they take the parchment off and send it, without the piece of wood, to the commander. He, when he has received it, cannot otherwise get any meaning out of it,-- since the letters have no connection, but are disarranged,--unless he takes his own scytale and winds the strip of parchment about it, so that, when its spiral course is restored perfectly, and that which follows is joined to that which precedes, he reads around the staff, and so discovers the continuity of the message. And the parchment, like the staff, is called scytale, as the thing measured bears the name of the measure. -Plutarch, Lives
3/25/2019
16
• Julius Caesar Cipher • Substitute each letter in the plaintext by the letter that is 3 down from it.
• Encode(letter)=(letter+3) mod 26 • Decode(letter)=(letter -3) mod 26
SUBSTITUTION EXAMPLE
• Plaintext: One if by land two if by sea
• Ciphertext: Rqh li eb odqg wzr li eb vhd
CAESAR CIPHER EXAMPLE
3/25/2019
17
• Decode the following message: vhqg pruh slccd
CAESAR CIPHER EXAMPLE
ICE 2
• There are 4.0x1026 possible arrangements of the 26 letters. • At one arrangement per sec it would take a billion people the lifetime of the
universe to check all possibilities. • Yet they are surprisingly easy to break…
SUBSTITUTION CIPHERS
3/25/2019
18
• Check frequency of symbols in the ciphertext and compare them to “normal” frequency of letters in that language.
• Issues…
FREQUENCY ANALYSIS
• Knowledge of the same key provides the ability to both encode and decode.
• Traditional forms of encryption
SYMMETRIC KEY ENCRYPTION
3/25/2019
19
• Proposed the first asymmetric encryption scheme. • Alice and Bob each have a private key that only they know and a public
key that anyone can know. • The private key cannot be calculated using the public key
WHIT DIFFIE IN 1975
• Messages encrypted with Bob’s public key can only be decrypted using his private key
• Messages encrypted using Bob’s private key can only be decrypted using Bob’s public key.
• This is also known as Public Key Encryption
WHIT DIFFIE IN 1975
3/25/2019
20
• In April, 1977 a group of 3 MIT professors figured out mathematically how to implement Whit Diffie’s concept of asymmetric key encryption
• They formed RSA, named for the last names of the 3 researchers (Rivest, Shamir, and Adleman)
RSA
3/25/2019
21
• So how is crypto used in web browsers today?
CRYPTOGRAPHY
ICE 3
What is ONE thing that you found to be interesting during today’s lecture? Why was it interesting to you? Discuss in your group and record your thoughts.
(You MUST complete this activity to receive attendance, a blank page with only your name and username will NOT count towards attendance)
ICE 3
3/25/2019
22
Any questions? INFO I101
1. Bring your ICE Sheet to the front and set it on the pile.
2. Scan your CrimsonCard for attendance.
On your way out…