Tamer Khattab: Electrical Engineering Qatar University
Tamer Khattab: Electrical Engineering Qatar University
Tamer Khattab: Electrical Engineering Qatar University
Electrical Engineering
Qatar University
Slides based on
Textbook slides by William Stallings
(author)
ELEC 441
Fundamentals of Secure Communications
Lecture 1 Objectives
Communications Security Concepts • Describe the key security requirements
of confidentiality, integrity, and
(Network & Information Security) availability.
measures to deter,
prevent, detect, and
correct security
violations that involve
the transmission of
information
• Security service
• A processing or communication service that
enhances the security of the data processing
systems and the information transfers of an
organization
• Intended to counter security attacks, and
they make use of one or more security
mechanisms to provide the service
• Security mechanism
• A process (or a device incorporating such a
process) that is designed to detect, prevent,
or recover from a security attack
Security Services
• Authentication
• Access control
• Data confidentiality
• Data integrity
• Nonrepudiation
• Availability service
Security Mechanisms
• Cryptography
• Data integrity
• Digital signatures
• Authentication exchange
• Traffic padding
• Routing control
• Notarization
• Access control
• Propensity: A tendency to be
willing to trust others across a
broad spectrum of situations and
trust targets. • Ability: (competence), relates to the
potential ability of the evaluated entity
• Risk: A measure of the extent to to do a given task or be entrusted with
which an entity is threatened by a given information.
potential circumstance or event,
and typically a function of 1) the • Benevolence: A disposition of goodwill
towards the trusting party.
adverse impacts that would arise if
the circumstance or event occurs; • Integrity: The truster’s perception that
and 2) the likelihood of occurrence. the trustee adheres to a set of
principles that the truster finds
acceptable.
© 2017 Pearson Education, Ltd., All rights reserved.
Standards
National Institute of Standards and Technology
•NIST is a U.S. federal agency that deals with measurement science, standards, and technology related to U.S.
government use and to the promotion of U.S. private-sector innovation
•Despite its national scope, NIST Federal Information Processing Standards (FIPS) and Special Publications (SP)
have a worldwide impact
Internet Society
•ISOC is a professional membership society with world-wide organizational and individual membership
•Provides leadership in addressing issues that confront the future of the Internet and is the organization home
for the groups responsible for Internet infrastructure standards
ITU-T
•The International Telecommunication Union (ITU) is an international organization within the United Nations
System in which governments and the private sector coordinate global telecom networks and services
•The ITU Telecommunication Standardization Sector (ITU-T) is one of the three sectors of the ITU and whose
mission is the development of technical standards covering all fields of telecommunications
ISO
•The International Organization for Standardization is a world-wide federation of national standards bodies
from more than 140 countries
•ISO is a nongovernmental organization that promotes the development of standardization and related
activities with a view to facilitating the international exchange of goods and services and to developing
cooperation in the spheres of intellectual, scientific, technological, and economic activity
© 2017 Pearson Education, Ltd., All rights reserved.
Summary
• Network security • Security services
concepts • Authentication
• Definition • Access control
• Examples • Data confidentiality
• Challenges • Data integrity
• Nonrepudiation
• The OSI security
• Availability service
architecture
• Security mechanisms
• Security attacks
• Passive attacks • Cryptography
• Active attacks
• Network security model
• Standards
© 2017 Pearson Education, Ltd., All rights reserved.