• Embed Doc
  • Readcast
  • Collections
  • CommentGo Back
 
CSC4430 –Data Communication and Computer Networks1
Lecture 23 (Network Security) Outline
Network Security
Basic requirements.
Meeting these requirements:
Privacy.Digital Signature.
Specific security standards in practice:
Privacy standards: DES, RSA.Standard at application layer: PGP.Standard at transport layer: SSL.
 
CSC4430 –Data Communication and Computer Networks2
23.1. Internet Security Threats
Friends: Bob, Alice want to communicate
securely
.
Enemies: Trudy, the
intruder 
may intercept, add,delete or modify messages.
securesendersecurereceiverchannel
data, controlmessages
datadataAliceBobTrudy
 
CSC4430 –Data Communication and Computer Networks3
23.1. Internet Security Threats
Q:What can a
bad guy
do?A:a lot!
eavesdrop:
intercept messages.
actively
insert 
messages into connection.
impersonation:
can fake (spoof) source address inpacket (or any field in packet).
denial of service
: prevent service from being usedby others (e.g., by overloading resources).
hijacking:
take over 
ongoing connection byremoving sender or receiver, inserting himself inplace.
of 00

Leave a Comment

You must be to leave a comment.
Submit
Characters: ...
You must be to leave a comment.
Submit
Characters: ...