Question

Answer the following questions in no more than six lines each. (3 x12 = 36) 1....

Answer the following questions in no more than six lines each. (3 x12 = 36)

1. Explain how a Smurf attack works.

2. Can the public key parameters be n = 15 and b = 6 in RSA? Why? (Of course the numbers are small and this is a toy example).

3. If you see several TCP SYN segments sent to a web server, but no ACK segments in the three-way handshake, what do you suspect may be happening? Explain.

4. Consider the network shown below.

Clients from the outside can only connect to the web server and mail server in the DMZ. Most hosts from the inside can connect only to the web server and mail server in the DMZ. Only the host 136.142.117.1 can connect to any web server on the outside. Design rules for packets entering only interface p for stateful packet filter A for the above security policy. You can use a mix of standard and extended ACLs or you can write your rules as sentences. Include details and add explanations as necessary. (24)

5. Alice and Bob are communicating using a shift cipher with the capital letters in English, but with a twist. They use two keys instead of one, and the keys alternate. So the first letter would be encrypted using the key k1 = 9, the second using the key k2 = 14, the third with k1, the fourth with k2 and so on as needed. Their hope is that this will prevent frequency analysis by Oscar.

a. Do you think this approach is secure? Why? Explain using Kerckhoff’s principle and the effort that it may take Oscar to use brute force. (15)

b. Decrypt the following ciphertext exchanged by Alice and Bob (show steps): JWAVXDYSA (25)

6. The decrypted message in Problem 3(b) corresponds to an article that was assigned for your reading. Summarize the main idea of that article in no more than 6 lines. (10)

0 0
Add a comment Improve this question Transcribed image text
Answer #1

Acc. to HomeworkLib policy,i can answer only atmost 4 questions. :)

1)  A smurf attack is an exploitation of the Internet Protocol (IP) broadcast addressing to create a denial of service. The attacker uses a program called Smurf to cause the attacked part of a network to become inoperable. The exploit of smurfing, as it has come to be known, takes advantage of certain known characteristics of the Internet Protocol (IP) and the Internet Control Message Protocol (ICMP).

b) basically you need two prime numbers for generating a RSA key pair. If you are able to factorize the public key and find these prime numbers, you will then be able to find the private key. The whole security of RSA is based on the fact that it is not easy to factorize large composite numbers, that's why the length of the key highly change the robustness of the RSA algorithm.

2) Basically, you need two prime numbers for generating a RSA key pair. If you are able to factorize the public key and find these prime numbers, you will then be able to find the private key. The whole security of RSA is based on the fact that it is not easy to factorize large composite numbers, that's why the length of the key highly change the robustness of the RSA algorithm.

3) Even if that ACK was lost, there will be no resending for a very simple reason. Directly after the ACK, the host that opened the TCP protocol is likely to start sending data. That data will, as all TCP packets, have an ACK number, so the recipient would get an ACK that way. Hence, the sender of the SYN-ACK should reasonably not care that it didn't get the ACK, because it gets an "implicit" ACK in the following package.

5a)
Kerckhoff's algorithm stated that, a cryptosystem should be secure even if everything about the system,except the key,is public knowledge
Although third party doesn't know about the key,but the third party can easily judge a pattern by looking at the encrypted text.

5b)
Encrypted Text-JWAVXDYSA
J-10
W-23
A-1
V-22
X-24
D-4
Y-25
S-19
A-1

First letter is encrypted with K1=9 and second key is encrypted with K2=14 and so is third and fourth.
Assuming, we take letters no subtracting by 9 and 14.

so,

J 10-9 = 1 A
W 23-14 = 9 I
A 1-9 = -8 mod 26 = 16 P
V 22 -14 =8 H
X 24-9 = 15 O
D 4-14 =-10 mod26 = 10 J
Y 25-9 = 16 P
S 19-14 = 5 E
A 1-9 = -8 mod 26 = 16 P

6) It doesn't make sense,as there is nothing as 3b mentioned above in the question.

Add a comment
Know the answer?
Add Answer to:
Answer the following questions in no more than six lines each. (3 x12 = 36) 1....
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
  • Can anyone answer and explain the following questions from Into to Computer Networking course? 1) PTSN...

    Can anyone answer and explain the following questions from Into to Computer Networking course? 1) PTSN networks are: a) Packet-switching networks offering connection-oriented services b) Packet-switching networks offering connectionless services c) Circuit-switching networks offering connection-oriented services d) Circuit-switching networks offering connectionless serive 2) Connection setup and temination, if performed, takes places in this layer of the internet model a) Presentation layer b) Session layer c) Network layer d) Physical layer 3) UDP sockets are identified by: a) Client program port...

  • Your answer should be short and not exceed more than 10 lines in each section. 1.  TCP/IP:...

    Your answer should be short and not exceed more than 10 lines in each section. 1.  TCP/IP: Unlike IP fragmentation (which can be done by intermediate devices), IP reassembly can be done only at the final destination. What could be the major problem if IP reassembly is done in intermediate devices like routers? Can you think of one major problem? 2. ARP: Describe or propose way to detect ARP spoofing attack. 3. Remote Access: Suppose you have a computer with Internet...

  • Read the Janes' Electronics, Inc. case at the end of the exam and answer the following...

    Read the Janes' Electronics, Inc. case at the end of the exam and answer the following questions. Assume that you are preparing to bid on the audit and are working on your client acceptance issues. Develop a checklist of five areas or issues that you would want to research before you accepted this firm as an audit client. For each area or issue, explain why you would want to research it and give an example of where you might go...

  • Read the Article posted below, then answer the following questions: 1. As a junior member of...

    Read the Article posted below, then answer the following questions: 1. As a junior member of your company’s committee to explore new markets, you have received a memo from the chairperson telling you to be prepared at the next meeting to discuss key questions that need to be addressed if the company decides to look further into the possibility of marketing to the BOP segment. The ultimate goal of this meeting will be to establish a set of general guidelines...

  • Q.3\ How could IT/e-banking assist an organization/ a bank to achieve a competitive advantage in the...

    Q.3\ How could IT/e-banking assist an organization/ a bank to achieve a competitive advantage in the marketplace? Explain through the case of Citibank. please make sure you give a unique answer (not copied one) ,Please no hand writing, and need references. This question is from ECOM 421 e-Business Strategies and Business Models course e-Business Strategy and Models in Banks : Case of Citibank E-business strategy in Citibank: Banks today are up-to-date with both the pros and cons of the internet....

  • Discussion questions 1. What is the link between internal marketing and service quality in the ai...

    Discussion questions 1. What is the link between internal marketing and service quality in the airline industry? 2. What internal marketing programmes could British Airways put into place to avoid further internal unrest? What potential is there to extend auch programmes to external partners? 3. What challenges may BA face in implementing an internal marketing programme to deliver value to its customers? (1981)ǐn the context ofbank marketing ths theme has bon pururd by other, nashri oriented towards the identification of...

  • Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around...

    Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around risk and threat management, fostering an environment in which objectives seem clear: manage risk, manage threat, stop attacks, identify attackers. These objectives aren't wrong, but they are fundamentally misleading.In this session we'll examine the state of the information security industry in order to understand how the current climate fails to address the true needs of the business. We'll use those lessons as a foundation...

  • The discussion: 150 -200 words. Auditing We know that computer security audits are important in business....

    The discussion: 150 -200 words. Auditing We know that computer security audits are important in business. However, let’s think about the types of audits that need to be performed and the frequency of these audits. Create a timeline that occurs during the fiscal year of audits that should occur and “who” should conduct the audits? Are they internal individuals, system administrators, internal accountants, external accountants, or others? Let me start you: (my timeline is wrong but you should use some...

  • First, read the article on "The Delphi Method for Graduate Research." ------ Article is posted below...

    First, read the article on "The Delphi Method for Graduate Research." ------ Article is posted below Include each of the following in your answer (if applicable – explain in a paragraph) Research problem: what do you want to solve using Delphi? Sample: who will participate and why? (answer in 5 -10 sentences) Round one questionnaire: include 5 hypothetical questions you would like to ask Discuss: what are possible outcomes of the findings from your study? Hint: this is the conclusion....

  • CASE 8 Unlocking the Secrets of the Apple iPhone in the Name of access the male...

    CASE 8 Unlocking the Secrets of the Apple iPhone in the Name of access the male San Bernardino suspect's iPhone 5c. Cook stated: Antiterrorism We are challenging the FBI's demands with the deepes respect for American democracy and a love of our country. We believe it would be in the best interest of everyone to step back and consider the implications While we believe the FBI's intentions are good, if would be wrong for the w e nt to force...

ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT