DAMISETTY SRINIVASA NAIDUs
DBS INSTITUTE OF TECHNOLOGY Aalayam of studies
The art of protecting information by
transforming it...
1
P.CHANDRA 118T1A0502 PH.NO:9700901132 E-mail:chandrakanthlovely@gmail.com Y.RAM KUMAR 118T1A0509 PH.NO:9494567332
Cryptography AND COMPUTER SECURITY
Contents: Abstract Introduction Computer Security Problems Key process Techniques Advanced cryptographic technique Steganography Cryptographic technologies Based on layers Based on algorithms Applications of cryptography Application of computer security Conclusion
CRYPTOGRPAHY COMPUTER SECURITY
CRYPTOGRAPHY AND COMPUTERSECURITY ABSTRACT: SECURITY in this contemporary scenarios has become a more sensible issue either it may be in the REAL WORLD or in the CYBER WORLD. In the real world as opposed to the cyber world an attack is often
preceded by information gathering. Movie gangsters case the joint, soldiers scout the area. This is also true in the cyber world. Here the bad guys are referred to as intruders, eavesdroppers, hackers, hijackers, etc. The intruders would first have a panoramic view of the victims network and then start digging the holes.
Today the illicit activities of the hackers are growing by leaps and bounds, viz., THE RECENT ATTACK ON THE DNS SERVERS HAS CAUSED A LOT OF HULLABALOO ALL OVER THE WORLD. However, fortunately, the antagonists reacted promptly and resurrected the Internet world from the brink of prostration. Since the inception of conglomerating computers with networks the consequence of which shrunk the communication world, hitherto, umpteen ilks of security breaches took their origin. Tersely quoting some security ditherersEavesdropping, hacking, hijacking, mapping, packet sniffing, 1Spoofing, DoS & DDoS attacks, etc. Newtons law says Every action has got an equal but opposite reaction. So is the case with this. Nevertheless the security Introduction: Computer security deals with the problems of legitimate messages being captured and replayed. Network security is the effort to create a secure computing platform. The action in question can be reduced to operations of access, modification and deletion. Many people pay great amounts of lip service to security but do not want to be bothered
breaches and eavesdroppers, the technological prowess has been stupendously developed to defy against each of the assaults. Our paper covers the ADVANCED technical combats that have been devised all through the way, thus giving birth to the notion of COMPUTERSECURITY. Various antidotes that are in fact inextricable with security issues are Cryptography, Authentication, Integrity and Non Repudiation, Key distribution and certification, Access control by implementing Firewalls etc. To satiate the flaws in the network security more and more advanced security notions are being devised day by day. Our paper covers a wide perspective of such arenas where the contemporary cyber world is revolving around viz. with it when it gets in their way. Its important to build systems and networks in such a way that the user is not constantly reminded of the security system. Users who find security policies and systems to restrictive will find ways around them. Its important to get their feed back to understand what can be improved, the sorts of risks that are deemed unacceptable, and what has been
done to minimize the organizations exposure to them. Network security problems can be divided roughly into four intertwined areas: Secrecy, Authentication, Nonrepudiation, and Integrity control. Secrecy has to do with keeping information out of the hands of unauthorized users. Authentication deals with whom you are talking to before revealing sensitive information or entering into a business deal. Nonrepudiation deals with signatures. Integrity control deals with long enterprises like banking, online networking. These problems can be handled by using cryptography, which provides means and methods of converting data into unreadable from, so that valid User can access Information at the Destination. Cryptography is the science of using mathematics to encrypt and decrypt data. Cryptography enables you to store sensitive information or transmit it across insecure networks (like the internet).
So that it cannot be read by anyone expect the intended recipient. While cryptography is the science of securing data, cryptanalysts are also called attackers. Cryptology embraces both cryptography and cryptanalysis.
KEY PROCESS TECHNIQUES: There are three key process techniques. They are: Symmetric-key encryption A symmetric-key encryption Hash functions
Symmetric-key encryption (one key): There is only one key in this encryption. That is private key. This key is only used for both encryption and decryption. This is also called as private-key encryption. In this
method the sender encrypt the data through private key and receiver decrypt that data through that key only. Private Key method Asymmetric-key keys): There are two keys in this encryption. They are: Public key Private key encryption (two
only the receiver has the related private key used to decrypt the message.
Public key method Hash functions: An improvement on the public key scheme is the addition of a one-way hash function in the process. A oneway hash function takes variable length input. In this case, a message of any length, even thousands or millions of bits and produces a fixedlength output; say, 160-bits. The function ensures that, if the information is changed in any way even by just one bit an entirely different output value is produced. As long as a secure hash function is used, there is no way to take someones signature from one documents and attach it to another, or to alter a signed message in any way. The slightest change in signed documents will cause the digital signature verification process to fail.
Two keys A public key and a private key, which are mathematically related, are used in public-key encryption. To contrast it with symmetric-key encryption, public-key encryption is also some times called public-key encryption. In public key can be passed openly between the parties or published in a public repository, but the related private key remains private. Data encrypted with the public key can be decrypted only using the private key. Data encrypted with the private key can be decrypted only using the public key. In the below figure, a sender has the receivers public key and uses it to encrypt a message, but
additional information to further conceal a message. There are many reasons why Steganography is used and is often used in significant fields. It can be used to communicate with complete freedom even under conditions that are censured or monitored. The Steganography is an effective ADVANCED TECHNIQUE STEGANOGRAPHY INTRODUCTION: Over the past couple of years Steganography has been the source of a lot of discussion. Steganography is one of the fundamental ways by which data can be kept confidential. Steganography hides the existence of a message bsy transmitting information through various carriers. Its goal is to prevent the detection of secret message. Steganography uses techniques to communicate information in a way that is a hidden. The most common use of Steganography is hiding information image or sound within the information of another file by using a stegokey such as password is WHAT IS STEGANOGRAPHY? The word steganography comes from the Greek name stegnos (hidden or secret) and graphy (writing or drawing) and literally means hidden writing. Stegenography uses CRYPTOGRAPHIC means of hiding data, there by protecting the data from unauthorized or unwanted viewing. But stego is simply one of many ways to protect confidentiality of data. Digital image steganography is growing in use and application. In areas strong outlawed, where cryptography are are people and being using encryption
steganography to avoid these policies and to send these messages secretly. Although steganography is become very popular in the near future.
techniques The image stegokey most or
to
communicate use of
Application layer PEM Mail) PGP (Pretty Good Privacy) SHTTP process can be (Privacy Enhanced
information in a way that is hidden. common sound such as Steganography is hiding information within password the is information of another file by using a additional information to further conceal a message. WHAT IS STEGANOGRAPHY USED FOR? Like many security tools, steganography can be used for variety of reasons, some good, some not so good. Steganography can also be used as a way to make a substitute for a one-way hash value. Further, Steganography can be used to tag notes to online images. CRYPTOGRAPHIC TECHNOLOGIES Based on layers: Link layer encryption Network layer encryption IPSEC, VPN, SKIP Transport layer SSL, PCT (private
Cryptographic starting from
implemented at various at various layers the link layer all the way up to the application layer. The most popular encryption scheme is SSL and it is implemented at the transport layer. If the encryption is done at the transport layer. If the encryption is done at the transport layer, any application that is running on the top of the transport layer can be protected. Based on algorithms: Secret-key algorithms algorithms) DES Encryption Standard) 56bitkey Triple 112bitkey IDEA (International DES (Data encryption (symmetric
Communication Technology) 9
Data Encryption Algorithm) 128bitkey Public-key algorithms) Diffie-Hellman (DH): Exponentiation is easy but computing discrete algorithms from the resulting value is practically impossible. RSA: Multiplication of two large prime numbers is easy but factoring the resulting product is APPLICATIONS OF CRYPTOGRAPHY Defense service Secure Data Manipulation E-Commerce Business Transactions Internet Payment Systems Pass Phrasing Secure practically impossible. encryption
User Systems
Identification
Access control Computational Security Secure access to Corp Data
algorithms (Asymmetric
SECURITY
Data Security
APPLICATIONS OF COMPUTER
Computer
networks
were
primarily used by university researchers for sending email, and by corporate employees for sharing printers. Under these conditions, security did not get a lot of attention. But now, as millions of ordinary citizens are using networks for: Banking Shopping Filling their returns. tax
Internet Comm.
CONCLUSION:
10
Network security is a very difficult topic. Every one has a different idea of what security is, and what levels of risks are acceptable. The key for building a secure network is to define what security means to your organization. Once that has been defined, everything that goes on with. The network can be evaluated with respect to the policy. Projects and systems can then be broken down into their components, and it becomes much simpler to decide your whether security is and what is and proposed will be conflict with policies practices. Security business, everyones intelligent achievable. Cryptography protects users by providing functionality for the encryption This of data lets and the authentication of other users. technology of an receiver electronic everybodys only with and cooperation, policy,
messages verify the sender, ensures that a message can be read only by the intended person, and assures the recipient that a message has not be altered in transmit. The Cryptography attacking techniques like Cryptanalysis and Brute Force Attack. This paper provides information of Advance Techniques Cryptography
THANK YOU. .
consistent practices, will it be
11