General Concepts
Alice, Bob and Trudy.
Trudy can't understand or modify
and Bob is assured that
The attacker eavesdrops and read/record messages in transit.
The attacker may transmit
new messages, replay old messages,
modify/delete messages on transit.
Who are you?
Should you be doing that?
ACL (access
control list) & Groups.
Malicious code written by bad guys.
unclassified < confidential < secret < top secret
No read-up (read higher rating object).
No write-down (write an
object with lower rating).
Very low bandwidth (e.g., 1 bit every 10 seconds),
but can be used to steal
cryptographic keys.
E.g., a Trojan horse may use timing channel or storage channel
Loops 1 minute if a bit is 1 and waits 1 minute if a bit is 0.
Creates a file for 1 minute if a bit is 1 and deletes the file for 2 minute if a bit is 0.
Hide secret messages in other messages.
E.g., hide messages in images by
replacing the least significant bit of each byte of the image with the bits of
the message.
DEMO: /home/cs772/public_html/demos/steganography
Rates computer systems (D, C1,C2, B1,B2,B3 and A1). E.g.,
Luckily most patents have expired (e.g. RSA
and recently most export
control has been lifted.
The US considered encryption as
danger as the weapons of mass destruction, like
nuclear and biological technology.