CryptographyUnit 98 min read
Authentication Systems & Intrusion Detection: Protocols, Attacks & Firewalls
Unit 9 of Cryptography explores authentication mechanisms (one-way vs. mutual), challenge-response systems (Kerberos, Needham-Schroeder), intrusion detection (signature/behavior-based), firewalls (types and rules), and real-world attacks (MITM, replay). Includes protocol traces, attack simulations, and Nepalese case st
Core Concepts: Authentication Systems
Authentication verifies a user’s identity or data integrity. It ensures who you claim to be (identity) or whether data was altered (data origin).
1. Definitions & Types
- One-Way Authentication: Server verifies client (e.g., password login). Example: Logging into eSewa with username/password.
- Mutual Authentication: Both parties verify each other (e.g., VPN handshake). Example: Ncell authenticating your SIM and your phone before allowing 5G access.
Why Mutual?
- Prevents MITM (Man-in-the-Middle) attacks where an attacker impersonates the server.
- Real Case: Khalti uses mutual auth to confirm both the merchant and the bank before processing payments.
Challenge-Response Systems
A protocol where the server sends a challenge (random data), and the client proves knowledge of a secret (e.g., password hash) without transmitting it.
How It Works
- Server sends
Challenge = R(random number). - Client computes
Response = f(R, Secret)(e.g., HMAC-SHA256). - Server verifies
f(R, StoredSecret) == Response.
Example: eSewa Login
sequenceDiagram
participant User
participant eSewaServer
User->>eSewaServer: Login Request
eSewaServer->>User: Challenge (R = "abc123")
User->>eSewaServer: Response = HMAC(R, "user_password")
eSewaServer->>User: Access GrantedAdvantages:
- No password transmitted over the network.
- Resistant to replay attacks (challenge is one-time).
Disadvantages:
- Computationally heavy for weak devices.
- Requires secure storage of secrets.
Kerberos: The Gold Standard
Kerberos uses symmetric encryption (AES) and time-stamped tickets to authenticate clients in a network (e.g., university LANs, corporate intranets).
Key Components
| Term | Description |
|---|---|
| KDC (Key Dist.) | Issues Ticket Granting Tickets (TGTs) encrypted with client’s secret. |
| TGT | Proof of identity to request service tickets. |
| Service Ticket | Grants access to a specific server (e.g., database). |
| Session Key | Temporary key for client-server communication. |
Worked Example: NTC Employee Login
- Alice (employee) requests TGT from KDC using her password hash.
- KDC replies with
TGT = {Alice, NTC-Server, SessionKey}_KDC_PrivateKey. - Alice sends
TGT + Authenticatorto NTC Server. - Server decrypts TGT with KDC’s key, then verifies Alice’s authenticator.
Why Kerberos?
- No password over the wire.
- Single sign-on (SSO) for multiple services.
- Used by Microsoft Active Directory and Linux MIT Kerberos.
Needham-Schroeder Protocol
A mutual authentication protocol using symmetric keys to prevent MITM.
Protocol Steps
sequenceDiagram
participant Alice
participant Bob
participant Server
Server->>Alice: {N1, {Alice, N2, K_AB}_KAS}
Alice->>Bob: {N2, {Alice, N1, N2, K_AB}_K_AB}
Bob->>Alice: {N3, {N2, N3}_K_AB}
Alice->>Bob: {N3}_K_ABNotation:
N1, N2, N3: Nonces (random numbers).K_AB: Shared session key.{M}_K: Message encrypted with keyK.
Attack Vulnerability:
- Original version had a replay attack flaw (fixed in Needham-Schroeder with timestamps).
Real-World Use:
- WhatsApp uses a similar double-ratchet protocol for mutual auth.
Intrusion Detection Systems (IDS)
Detects unauthorized access or attacks. Two main types:
1. Signature-Based IDS
- Matches attack patterns (e.g., SQL injection strings).
- Example: Snort detects
DROP TABLE users;in SQL queries.
2. Anomaly-Based IDS
- Learns normal behavior (e.g., traffic patterns) and flags deviations.
- Example: Ncell detects unusual login attempts from a new country.
Comparison Table
| Feature | Signature-Based | Anomaly-Based |
|---|---|---|
| Detection Method | Rule/match-based | Statistical/ML-based |
| False Positives | Low | High |
| Adaptability | Needs updates | Learns over time |
| Use Case | Known attacks (e.g., malware) | Zero-day threats |
Firewalls: First Line of Defense
Firewalls filter traffic based on rules (e.g., IP, port, protocol).
Types of Firewalls
Example Rules for a Bank (e.g., NMB Bank):
- Block: Port 22 (SSH) from external IPs.
- Allow: HTTPS (443) only to
*.nmb.com. - Log: All traffic from
192.168.1.0/24(internal network).
Real Case: Daraz Fraud Prevention
- Web Application Firewall (WAF) blocks SQLi/XSS attacks on checkout pages.
- Rate Limiting: Prevents brute-force attacks on login.
Man-in-the-Middle (MITM) Attacks
An attacker intercepts and alters communication between two parties.
MITM in Diffie-Hellman (DH)
Assumption: Prime p = 19, primitive root g = 10.
- Alice’s private key:
a = 5→ Public keyA = g^a mod p = 10^5 mod 19 = 4. - Bob’s private key:
b = 4→ Public keyB = g^b mod p = 10^4 mod 19 = 17. - Eve (attacker) sends her own public key
E = 15to both. - Shared key becomes:
K_Eve = g^(a*e) mod p(not Alice’s intended key).
Prevention:
- Digital Signatures (e.g., RSA) to verify keys.
- Perfect Forward Secrecy (PFS) in TLS (used by Google).
Message Authentication Code (MAC)
Ensures data integrity and authenticity using a shared secret key.
How MD4 Computes Digest (Simplified)
Example: Khalti uses HMAC-SHA256 to verify payment requests.
In the Real World
eSewa Login
- Uses challenge-response (HMAC) to verify users without transmitting passwords.
- Attack prevented: Brute-force (server locks after 3 failed attempts).
Ncell Fraud Detection
- Anomaly-based IDS flags calls from unusual locations (e.g., India → Nepal SIM).
- Firewall rule: Blocks port 53 (DNS) from known malicious IPs.
Nepal Rastra Bank (NRB) Payments
- Kerberos-like SSO for interbank transactions.
- MITM prevention: TLS 1.3 with ephemeral keys.
Pathao Driver Verification
- Mutual auth: App verifies driver’s license and GPS location before allowing rides.
Exam Tip
Authentication Systems
- Always compare one-way vs. mutual with a real example (e.g., eSewa vs. VPN).
- For Kerberos/Needham-Schroeder, draw the sequence diagram and label nonces/keys.
Intrusion Detection
- Signature-based: "Matches known patterns (e.g., SQLi strings)."
- Anomaly-based: "Uses ML to detect deviations (e.g., sudden traffic spikes)."
- Firewalls: List 4 types + one rule (e.g., "Block port 22 from external IPs").
Attacks
- MITM in DH: Show the fake public key exchange and how Eve computes the wrong shared key.
- Replay attacks: Explain why timestamps/nonces are needed.
MACs & Hashes
- For MD4/MD5, describe the 3-pass structure (but note MD5 is broken—use SHA-256 in practice).
- HMAC = Hash + secret key (e.g.,
HMAC-SHA256(key, message)).
Common Pitfalls:
- Forgetting mutual authentication requires both parties to verify each other.
- Confusing firewall types (e.g., calling a proxy firewall "stateful").
- Not showing nonces in challenge-response diagrams.
Based on the TU BSc CSIT syllabus for Cryptography (CSC316), unit 9.
Discussion
Loading…