***Welcome to ashrafedu.blogspot.com * * * This website is maintained by ASHRAF***

Posts

    Latest Updates

    Friday, April 29, 2022

    The Indian Cyberspace

    Indian cyberspace was born in 1975 with the establishment of National Informatics Centre (NIC) with an aim to provide government with IT solutions.

    Three networks (NWs) were set up between 1986 and 1988 to connect various agencies of govt.

     i. INDONET which connected the IBM mainframe installations that made up India’s computer infrastructure,

    ii. NICNET (the NIC NW) a nationwide very small aperture terminal (VSAT) network for public sector organisations as well as to connect the central government with the state government and district administrations, and

    iii. ERNET (the Education and Research Network), to serve the academic and research communities.

    New Internet Policy of 1998 paved the way for services from multiple Internet service providers (ISPs) and gave boost to the Internet user base grow from 1.4 million in 1999 to over 150 million by Dec 2012.

    Even though the Indian government took a while to convert to computerisation, there has been an increasing thrust on e-governance. The govts e-governance plan is seen as a cost-effective way of taking public services to the masses across the country. Critical sectors such as Finance, Energy, Space, Telecommunications, Defence, Transport, Land Records, Public Essential Services and Utilities, Law Enforcement and Security all increasingly depend on NWs to relay data for both communication purpose and commercial transactions.

    The National e-governance Program (NeGP) is one of the most ambitious in the world and seeks to provide more than 1200 govt services online.

    Indian govt has taken many initiatives to protect the critical infrastructure driven by IT within Indian cyberspace domain. Some of the initiatives are as follows:-

    (a) Legal Framework to include enactment of IT Act (Amendment) 2008.

    (b) Policy Initiatives.

    (c) Cyber Security Initiatives.

    Information Technology Act (IT Act) was enacted in year 2000 to provide legal recognition for transactions carried out by means of electronic data interchange and other means of electronic communication. To establish a robust cyber security and data protection regime in the country, the IT Act was amended in year 2008. It provides a comprehensive definition of the computer system & tries to ascertain liability based on the type of cyber crime committed ( Hacking, spamming, tampering, identity theft, impersonation, cyber terrorism, pornography, child pornography). The act introduces the concept of ‘sensitive personal information’ and fixes liability of the ‘body corporate’ to protect the same through implementation of ‘reasonable security practices’.

    The rules issued under the Act, also require corporates to follow privacy principles such as notice, choice & consent, access & correction, disclosure to third party, etc.

    The amended Act provides provision for legal action against a person for the breach of confidentiality and privacy, under lawful contract. Critical systems can be declared as ‘protected systems’ under the Act. Security breaches of such systems attract higher prison sentences.

    The amended Act also enables setting up of a nodal agency for critical infrastructure protection and strengthens the role of CERT-In (Indian Computer Emergency Response Team). This Act creates provision for the central government to define encryption policy for strengthening security of electronic communications.

    Presently, encryption of upto 40 bits is allowed under the telecom policy.

    Cyber Appellate Tribunal, which is now operational, is expected to expedite legal proceeding of cyber crime cases. Overall, the IT (Amendment) Act, 2008 is an omnibus and comprehensive legislation which includes provisions for digital signatures, e-governance, e-commerce, data protection, cyber offences, critical information infrastructure, interception & monitoring, blocking of websites and cyber terrorism.

    Security Standards

    To make cybersecurity measures explicit, the written norms are required. These norms are known as cybersecurity standards. The standards may involve methods, guidelines, reference frameworks, etc.

    Security standards ensures efficiency of security, facilitates integration and interoperability, enables meaningful comparison of measures, reduces complexity, and provide the structure for new developments.

    A security standard is "a published specification that establishes a common language, and contains a technical specification or other precise criteria and is designed to be used consistently, as a rule, a guideline, or a definition." The goal of security standards is to improve the security of information technology (IT) systems, networks, and critical infrastructures. The Well-Written cybersecurity standards enable consistency among product developers and serve as a reliable standard for purchasing security products.

    Security standards are generally provided for all organizations regardless of their size or the industry and sector in which they operate. This section includes information about each standard that is usually recognized as an essential component of any cybersecurity strategy.

    1. ISO

    ISO stands for International Organization for Standardization. International Standards make things to work. These standards provide a world-class specification for products, services and computers, to ensure quality, safety and efficiency. They are instrumental in facilitating international trade.

    ISO 27000 Series

    It is the family of information security standards which is developed by the International Organization for Standardization and the International Electrotechnical Commission to provide a globally recognized framework for best information security management. It helps the organization to keep their information assets secure such as employee details, financial information, and intellectual property.

    The need of ISO 27000 series arises because of the risk of cyber-attacks which the organization face. The cyber-attacks are growing day by day making hackers a constant threat to any industry that uses technology.

    The ISO 27000 series can be categorized into many types. They are-

    ISO 27001- This standard allows us to prove the clients and stakeholders of any organization to managing the best security of their confidential data and information. This standard involves a process-based approach for establishing, implementing, operating, monitoring, maintaining, and improving our ISMS.

    ISO 27000- This standard provides an explanation of terminologies used in ISO 27001.

    ISO 27002- This standard provides guidelines for organizational information security standards and information security management practices. It includes the selection, implementation, operating and management of controls taking into consideration the organization's information security risk environment(s).

    ISO 27005- This standard supports the general concepts specified in 27001. It is designed to provide the guidelines for implementation of information security based on a risk management approach. To completely understand the ISO/IEC 27005, the knowledge of the concepts, models, processes, and terminologies described in ISO/IEC 27001 and ISO/IEC 27002 is required. This standard is capable for all kind of organizations such as non-government organization, government agencies, and commercial enterprises.

    ISO 27032- It is the international Standard which focuses explicitly on cybersecurity. This Standard includes guidelines for protecting the information beyond the borders of an organization such as in collaborations, partnerships or other information sharing arrangements with clients and suppliers.

    2. IT Act

    The Information Technology Act also known as ITA-2000, or the IT Act main aims is to provide the legal infrastructure in India which deal with cybercrime and e-commerce. The IT Act is based on the United Nations Model Law on E-Commerce 1996 recommended by the General Assembly of United Nations. This act is also used to check misuse of cyber network and computer in India. It was officially passed in 2000 and amended in 2008. It has been designed to give the boost to Electronic commerce, e-transactions and related activities associated with commerce and trade. It also facilitate electronic governance by means of reliable electronic records.

    IT Act 2000 has 13 chapters, 94 sections and 4 schedules. The first 14 sections concerning digital signatures and other sections deal with the certifying authorities who are licenced to issue digital signature certificates, sections 43 to 47 provides penalties and compensation, section 48 to 64 deal with appeal to high court, sections 65 to 79 deal with offences, and the remaining section 80 to 94 deal with miscellaneous of the act.

    3. Copyright Act

    The Copyright Act 1957 amended by the Copyright Amendment Act 2012 governs the subject of copyright law in India. This Act is applicable from 21 January 1958. Copyright is a legal term which describes the ownership of control of the rights to the authors of "original works of authorship" that are fixed in a tangible form of expression.

    An original work of authorship is a distribution of certain works of creative expression including books, video, movies, music, and computer programs. The copyright law has been enacted to balance the use and reuse of creative works against the desire of the creators of art, literature, music and monetize their work by controlling who can make and sell copies of the work.

    The copyright act covers the following-

    • Rights of copyright owners
    • Works eligible for protection
    • Duration of copyright
    • Who can claim copyright

    The copyright act does not covers the following-

    • Ideas, procedures, methods, processes, concepts, systems, principles, or discoveries
    • Works that are not fixed in a tangible form (such as a choreographic work that has not been notated or recorded or an improvisational speech that has not been written down)
    • Familiar symbols or designs
    • Titles, names, short phrases, and slogans
    • Mere variations of typographic ornamentation, lettering, or coloring

    4. Patent Law

    Patent law is a law that deals with new inventions. Traditional patent law protect tangible scientific inventions, such as circuit boards, heating coils, car engines, or zippers. As time increases patent law have been used to protect a broader variety of inventions such as business practices, coding algorithms, or genetically modified organisms. It is the right to exclude others from making, using, selling, importing, inducing others to infringe, and offering a product specially adapted for practice of the patent.

    5. IPR

    Intellectual property rights is a right that allow creators, or owners of patents, trademarks or copyrighted works to benefit from their own plans, ideas, or other intangible assets or investment in a creation. These IPR rights are outlined in the Article 27 of the Universal Declaration of Human Rights. It provides for the right to benefit from the protection of moral and material interests resulting from authorship of scientific, literary or artistic productions. These property rights allow the holder to exercise a monopoly on the use of the item for a specified period.

    CYBERSPACE - ROLE OF INTERNATIONAL LAWS

    Cyberspace can be defined as an intricate environment that involves interactions between people, software, and services. It is maintained by the worldwide distribution of information and communication technology devices and networks.

    Ø  ROLE OF INTERNATIONAL LAWS

    In various countries, areas of the computing and communication industries are regulated by governmental bodies.

    There are specific rules on the uses to which computers and computer networks, in particular there are rules on unauthorized access, data privacy and spamming.

    There are also limits on the use of encryption and of equipment which may be used to defeat copy protection schemes.

    There are laws governing trade on the Internet, taxation, consumer protection, and advertising.

    There are laws on censorship versus freedom of expression, rules on public access to government information, and individual access to information held on them by private bodies.

    Some states limit access to the Internet, by law as well as by technical means.

    Cybercrime is "international" that there are ‘no cyber-borders between countries’. The complexity in types and forms of cybercrime increases the difficulty to fight back.

    Fighting cybercrime needs for international cooperation. Various organizations and governments have already made joint efforts in establishing global standards of legislation and law enforcement both on a regional and on an international scale.

    Security at Network Layer IP security (IPSec)

    The IP security (IPSec) is an Internet Engineering Task Force (IETF) standard suite of protocols between 2 communication points across the IP network that provide data authentication, integrity, and confidentiality.

    It also defines the encrypted, decrypted and authenticated packets.

    The protocols needed for secure key exchange and key management are defined in it.

    IPsec can be used to do the following things:

    • To encrypt application layer data.
    • To provide security for routers sending routing data across the public internet.
    • To provide authentication without encryption, like to authenticate that the data originates from a known sender.
    • To protect network data by setting up circuits using IPsec tunneling in which all data is being sent between the two endpoints is encrypted, as with a Virtual Private Network(VPN) connection.

    It has the following components:

    1. Encapsulating Security Payload (ESP) –
      It provides data integrity, encryption, authentication and anti replay. It also provides authentication for payload.
    2. Authentication Header (AH) –
      It also provides data integrity, authentication and anti replay and it does not provide encryption. The anti replay protection, protects against unauthorized transmission of packets. It does not protect data’s confidentiality.

    3.      Internet Key Exchange (IKE) –
    It is a network security protocol designed to dynamically exchange encryption keys and find a way over Security Association (SA) between 2 devices. The Security Association (SA) establishes shared security attributes between 2 network entities to support secure communication. The Key Management Protocol (ISAKMP) and Internet Security Association which provides a framework for authentication and key exchange. ISAKMP tells how the set up of the Security Associations (SAs) and how direct connections between two hosts that are using IPsec.

     

    Internet Key Exchange (IKE) provides message content protection and also an open frame for implementing standard algorithms such as SHA and MD5. The algorithm’s IP sec users produces a unique identifier for each packet. This identifier then allows a device to determine whether a packet has been correct or not. Packets which are not authorized are discarded and not given to receiver.

    Working of IP Security –

    1. The host checks if the packet should be transmitted using IPsec or not. These packet traffic triggers the security policy for themselves. This is done when the system sending the packet apply an appropriate encryption. The incoming packets are also checked by the host that they are encrypted properly or not.
    2. Then the IKE Phase 1 starts in which the 2 hosts( using IPsec ) authenticate themselves to each other to start a secure channel. It has 2 modes. The Main mode which provides the greater security and the Aggressive mode which enables the host to establish an IPsec circuit more quickly.
    3. The channel created in the last step is then used to securely negotiate the way the IP circuit will encrypt data across the IP circuit.
    4. Now, the IKE Phase 2 is conducted over the secure channel in which the two hosts negotiate the type of cryptographic algorithms to use on the session and agreeing on secret keying material to be used with those algorithms.
    5. Then the data is exchanged across the newly created IPsec encrypted tunnel. These packets are encrypted and decrypted by the hosts using IPsec SAs.
    6. When the communication between the hosts is completed or the session times out then the IPsec tunnel is terminated by discarding the keys by both the hosts.

    Security at transport layer – SSL and TLS

    Secure Socket Layer (SSL) provides security to the data that is transferred between web browser and server. SSL encrypts the link between a web server and a browser which ensures that all data passed between them remain private and free from attack. 

    1. Secure Socket Layer Protocols: 

    • SSL record protocol
    • Handshake protocol
    • Change-cipher spec protocol
    • Alert protocol

    SSL Record provides two services to SSL connection. 

    • Confidentiality
    • Message Integrity


    In the SSL Record Protocol application data is divided into fragments. The fragment is compressed and then encrypted MAC (Message Authentication Code) generated by algorithms like SHA (Secure Hash Protocol) and MD5 (Message Digest) is appended. After that encryption of the data is done and in last SSL header is appended to the data. 


    Handshake Protocol: 

    Handshake Protocol is used to establish sessions. This protocol allows the client and server to authenticate each other by sending a series of messages to each other. Handshake protocol uses four phases to complete its cycle. 



    • Phase-1: In Phase-1 both Client and Server send hello-packets to each other. In this IP session, cipher suite and protocol version are exchanged for security purposes. 
    • Phase-2: Server sends his certificate and Server-key-exchange. The server end phase-2 by sending the Server-hello-end packet. 
    • Phase-3: In this phase Client reply to the server by sending his certificate and Client-exchange-key. 
    • Phase-4: In Phase-4 Change-cipher suite occurred and after this Handshake Protocol ends. 

    Change-cipher Protocol: 
    This protocol uses the SSL record protocol. Unless Handshake Protocol is completed, the SSL record Output will be in a pending state. After handshake protocol, the Pending state is converted into the current state. 
    Change-cipher protocol consists of a single message which is 1 byte in length and can have only one value. This protocol’s purpose is to cause the pending state to be copied into the current state. 

    Alert Protocol: 
    This protocol is used to convey SSL-related alerts to the peer entity. Each message in this protocol contain 2 bytes(level – 1 byte, alert – 1 byte).

    The level is further classified into two parts: 
     Warning: 
    This Alert has no impact on the connection between sender and receiver. 
     Fatal Error: 
    This Alert breaks the connection between sender and receiver. 

    Silent Features of Secure Socket Layer: 
     The advantage of this approach is that the service can be tailored to the specific needs of the given application.

    Secure Socket Layer was originated by Netscape.

    SSL is designed to make use of TCP to provide reliable end-to-end secure service.

    2. Transport Layer Security (TLS)

    Transport Layer Securities (TLS) are designed to provide security at the transport layer. TLS was derived from a security protocol called Secure Socket Layer (SSL). TLS ensures that no third party may eavesdrop or tampers with any message. 

    There are several benefits of TLS: 

    • Encryption: 
      TLS/SSL can help to secure transmitted data using encryption.
    • Interoperability: 
      TLS/SSL works with most web browsers, including Microsoft Internet Explorer and on most operating systems and web servers.
    • Algorithm flexibility: 
      TLS/SSL provides operations for authentication mechanism, encryption algorithms and hashing algorithm that are used during the secure session.
    • Ease of Deployment: 
      Many applications TLS/SSL temporarily on a windows server 2003 operating systems.
    • Ease of Use: 
      Because we implement TLS/SSL beneath the application layer, most of its operations are completely invisible to client. 
    TLS consists of two basic protocols:
    1. Handshake protocol - Use public key cryptography to establish a shared secret key between client         and server


    2. Record protocol - Use the secret to protect communication between client and server.

    The client connect to server (using TCP), the client will be something. The client sends number of specification: 

    1. Version of SSL/TLS.
    2. which cipher suites, compression method it wants to use. 
       

    The server checks what the highest SSL/TLS version is that is supported by them both, picks a cipher suite from one of the clients option (if it supports one) and optionally picks a compression method. After this the basic setup is done, the server provides its certificate. This certificate must be trusted either by the client itself or a party that the client trusts. Having verified the certificate and being certain this server really is who he claims to be (and not a man in the middle), a key is exchanged. This can be a public key or simply nothing depending upon cipher suite. 

    Both the server and client can now compute the key for symmetric encryption. The handshake is finished and the two hosts can communicate securely. To close a connection by finishing. TCP connection both sides will know the connection was improperly terminated. The connection cannot be compromised by this through, merely interrupted.

    Both Secure Socket Layer and Transport Layer Security are the protocols used to provide the security between web browser and web server.

    SSL Vs TLS

    The main differences between Secure Socket Layer and Transport Layer Security is that in SSL (Secure Socket Layer), Message digest is used to create master secret and It provides the basic security services which are Authentication and confidentiality while in TLS (Transport Layer Security), Pseudo-random function is used to create master secret.

    S.NO

    SSL

    TLS

    1.

    SSL stands for Secure Socket Layer.

    TLS stands for Transport Layer Security.

    2.

    SSL (Secure Socket Layer) supports Fortezza algorithm.

    TLS (Transport Layer Security) does not supports Fortezza algorithm.

    3.

    SSL (Secure Socket Layer) is the 3.0 version.

    TLS (Transport Layer Security) is the 1.0 version.

    4.

    In SSL( Secure Socket Layer), Message digest is used to create master secret.

    In TLS(Transport Layer Security), Pseudo-random function is used to create master secret.

    5.

    In SSL( Secure Socket Layer), Message Authentication Code protocol is used.

    In TLS(Transport Layer Security), Hashed Message Authentication Code protocol is used.

    6.

    SSL (Secure Socket Layer) is complex than TLS(Transport Layer Security).

    TLS (Transport Layer Security) is simple.

    7.

    SSL (Secure Socket Layer) is less secured as compared to TLS(Transport Layer Security).

    TLS (Transport Layer Security) provides high security.


    Security at the Application layer – PGP and S/MIME

    Two schemes have been developed for e-mail security: PGP and S/MIME. Both these schemes use secret-key and public-key cryptography.

    I. Pretty Good Privacy (PGP) is an e-mail encryption scheme. It has become the de-facto standard for providing security services for e-mail communication. it uses public key cryptography, symmetric key cryptography, hash function, and digital signature. It provides −

    • Privacy
    • Sender Authentication
    • Message Integrity
    • Non-repudiation

    Along with these security services, it also provides data compression and key management support. PGP uses existing cryptographic algorithms such as RSA, IDEA, MD5, etc., rather than inventing the new ones.

    Working of PGP

    ·        Hash of the message is calculated. (MD5 algorithm)

    ·        Resultant 128 bit hash is signed using the private key of the sender (RSA Algorithm).

    ·        The digital signature is concatenated to message, and the result is compressed.

    ·        A 128-bit symmetric key, KS is generated and used to encrypt the compressed message with IDEA.

    ·        KS is encrypted using the public key of the recipient using RSA algorithm and the result is appended to the encrypted message.


    In PGP scheme, a message in signed and encrypted, and then MIME is encoded before transmission.

    II. S / MIME

    S/MIME stands for Secure Multipurpose Internet Mail Extension. S/MIME is a secure e-mail standard. It is based on an earlier non-secure e-mailing standard called MIME.

    S/MIME approach is similar to PGP. It also uses public key cryptography, symmetric key cryptography, hash functions, and digital signatures. It provides similar security services as PGP for e-mail communication.

    The most common symmetric ciphers used in S/MIME are RC2 and TripleDES. The usual public key method is RSA, and the hashing algorithm is SHA-1 or MD5.

    S/MIME specifies the additional MIME type, such as “application/pkcs7-mime”, for data enveloping after encrypting. The whole MIME entity is encrypted and packed into an object. S/MIME has standardized cryptographic message formats (different from PGP). In fact, MIME is extended with some keywords to identify the encrypted and/or signed parts in the message.

    S/MIME relies on X.509 certificates for public key distribution. It needs top-down hierarchical PKI for certification support.

    Due to the requirement of a certificate from certification authority for implementation, not all users can take advantage of S/MIME, as some may wish to encrypt a message, with a public/private key pair.

    Either PGP or S/MIME, is used depending on the environment. A secure e-email communication in a captive network can be provided by adapting to PGP. For e-mail security over Internet, where mails are exchanged with new unknown users very often, S/MIME is considered as a good option.

    Difference between PGP and S/MIME :

    S.NO

    PGP

    S/MIME

    1.

    It is designed for processing the plain texts

    While it is designed to process email as well as many multimedia files.

    2.

    PGP is less costly as compared to S/MIME.

    While S/MIME is comparatively expensive.

    3.

    PGP is good for personal as well as office use.

    While it is good for industrial use.

    4.

    PGP is less efficient than S/MIME.

    While it is more efficient than PGP.

    5.

    It depends on user key exchange.

    Whereas it relies on a hierarchically valid certificate for key exchange.

    6.

    PGP is comparatively less convenient.

    While it is more convenient than PGP due to the secure transformation of all the applications.

    7.

    PGP contains 4096 public keys.

    While it contains only 1024 public keys.

    8.

    PGP is the standard for strong encryption.

    While it is also the standard for strong encryption but has some drawbacks.

    9.

    PGP is also be used in VPNs.

    While it is not used in VPNs, it is only used in email services.

    10.

    PGP uses Diffie hellman digital signature.

    While it uses Elgamal digital signature.


    Network session analysis

    Network session analysis Network session analysis is a method of monitoring network activity and availability to identify issues, such as ...