Your answer should be short and not exceed more than 10 lines in each section.
1. TCP/IP: Unlike IP fragmentation (which can be done by intermediate devices), IP reassembly can be done only at the final destination. What could be the major problem if IP reassembly is done in intermediate devices like routers? Can you think of one major problem?
2. ARP: Describe or propose way to detect ARP spoofing attack.
3. Remote Access: Suppose you have a computer with Internet connection at home. Files with sensitive information are stored on that computer and you often read and retrieve those files remotely. For security reason, describe one technology that you can use to access that computer and ensure the data transmission is encrypted.
1)
Intermediate routers can fragment an IP datagram or perform additional fragmentation on a fragmented IP datagram but cannot perform IP reassembly (UMUC, 2012). There are a number of reasons for this. Firstly, if router or any other intermediate device were to perform IP reassembly, this would heighten its complexity. Routers, for instance, are dedicated devices that are designed to process a high volume of packets rapidly and since they do not perform reassembly, they can instantly pass on all fragments to their final destination. Attempting to perform IP reassembly in an intermediate device such as a router would require more processing and increase the complexity of the device’s responsibilities. It would also require the device to have to wait for all fragments to be reassembled before the reassembled message can be sent on. This would slow down the device and could lead to a traffic jam. This means that these devices would need more processing resources and storage space in order to handle the fragmentation and reassembly of IP datagrams.
2)
The Address Resolution Protocol is one of the most essential protocols for LAN communication n and is used to resolve a MAC address for a host given its IP address. Because ARP doesn’t use authentication and is stateless, it is easy to spoof ARP packets by impersonating another host on the network. ARP spoofing detection can be accomplished by monitoring ARP Request/Responses on the network and constructing a MAC address to IP address database. If an unauthorized change occurs in the database, an alarm should trigger alerting administrators that an ARP spoofing attack may be underway. ARPWATCH and WireShark are popular tools that can detect ARP spoofing. This passive method of ARP spoofing detection has weaknesses. The time lag between address mappings and subsequent attack detection is a major drawback. If an ARP spoofing attack occurs before the tools starts detecting, the mapping tool will learn the spoofed MAC/IP in the table. The only way to remove a spoofed entry is manually undo it in the MAC/IP database. While effective, this method relies heavily on manual intervention by the network administrator which becomes unreasonable wen talking about thousands of systems, thus impossible to use for large networks.
NOTE: As per Chegg policy, I am allowed to answer only 2 questions (including sub-parts) on a single post. Kindly post the remaining questions separately and I will try to answer them. Sorry for the inconvenience caused.
Your answer should be short and not exceed more than 10 lines in each section. 1. TCP/IP:...
3. Remote Access: Suppose you have a computer with Internet connection at home. Files with sensitive information are stored on that computer and you often read and retrieve those files remotely. For security reason, describe one technology that you can use to access that computer and ensure the data transmission is encrypted What is the name of the technology? What is the server port number? a. What is the encrypting method or algorithm used in that technology? b. 177 wordsP...
3. Remote Access: Suppose you have a computer with Internet connection at home. Files with sensitive information are stored on that computer and you often read and retrieve those files remotely. For security reason, describe one technology that you can use to access that computer and ensure the data transmission is encrypted. What is the name of the technology? What is the server port number? What is the encrypting method or algorithm used in that technology? Answer it within 10lines....
Six Which of the following options can be used to configure TCP/IP? (Choose all that apply.) APIPA DHCP DNS Static IP addressing You need to install a new Windows 10 machine into Site A with a subnet mask of 255.255.255.224. Which TCP/IP address can you assign to the new Windows 10 machine as a valid host address? 192.168.2.63 Which subnet mask would you utilize if you had a class C network and you wanted to connect 23 branch offices back...
In this assignment, you design a simple chat room in the form of a network application which uses the services of a TCP/IP computer network. Your design should have a clientserver architecture in which the server is multi-threaded. Then, you need to implement the server-side of the chat-room application in Java (implementing the client-side is optional). The server maintains a list (an ArrayList will work well) of all the active connections. It will listen on a port for a new...
Answer the following questions in no more than six lines each. (3 x12 = 36) 1. Explain how a Smurf attack works. 2. Can the public key parameters be n = 15 and b = 6 in RSA? Why? (Of course the numbers are small and this is a toy example). 3. If you see several TCP SYN segments sent to a web server, but no ACK segments in the three-way handshake, what do you suspect may be happening? Explain....
PART A 21 MARKS
SHORT ANSWER QUESTIONS Answer ALL questions from this part. Write
your answers in the Examination Answer Booklet. Each question is
worth 1.5 marks (14 x 1.5 = 21 marks).
Question 1
An organisation has been granted a block of addresses with the mask
/22. If the organisation creates 8 equal-sized subnets, how many
addresses (including the special addresses) are available in each
subnet? Show your calculations.
Question 2
Give an example of a valid classful address...
TRUE/FALSE QUESTIONS: Foundations of Information Security and Assurance 1. There is a problem anticipating and testing for all potential types of non-standard inputs that might be exploited by an attacker to subvert a program. 2. Without suitable synchronization of accesses it is possible that values may be corrupted, or changes lost, due to over-lapping access, use, and replacement of shared values. 3. The biggest change of the nature in Windows XP SP2 was to change all anonymous remote procedure call (RPC)...
Question 6 After a problem and its symptoms have been identified, a theory regarding a probable cause should be established. True False 1.25 points Question 7 An open electrical circuit as a result of a failed circuit breaker is considered to be what type of failure system? a. fail-tolerant b. fail-close c. fail-open d. fail-dynamic 1.25 points Question 8 At what layer of the OSI model do the IP, ICMP, and ARP protocols operate? a. Application b. Session c. Transport...
CASE 8 Unlocking the Secrets of the Apple iPhone in the Name of access the male San Bernardino suspect's iPhone 5c. Cook stated: Antiterrorism We are challenging the FBI's demands with the deepes respect for American democracy and a love of our country. We believe it would be in the best interest of everyone to step back and consider the implications While we believe the FBI's intentions are good, if would be wrong for the w e nt to force...
Explain what enterprise resource planning (ERP) systems. Outline several of their key characteristics. Describe in reasonable detail how a company leverages an ERP system and how its operations are improved after installing an ERP system like SAP. Explain how a supply chain management system helps an organization make its operations more efficient What is Upstream and Downstream management of the supply chain? Explain the concept of “Supply Network”, its benefits, and how technology made this concept available Explain the difference...