Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

English for Information Security. Учебник

.pdf
Скачиваний:
0
Добавлен:
07.09.2026
Размер:
2 Мб
Скачать
31
cryptography and a protocol governing incentivization) that made bitcoin creator Satoshi Nakamoto's idea so useful.
Blockchains are built from 3 technologies
Private Key
Cryptography
P2P Network
Program (the

Identiy
System of record
Platform
The result is a system for digital interactions that does not need a trusted third party. The work of securing digital relationships is implicit supplied by the elegant, simple, yet robust network architecture of blockchain technology itself.
Defining digital trust
Trust is a risk judgement between different parties, and in the digital world, determining trust often boils down to proving identity (authentication) and proving permissions (authorization).
Put more simply, we want to know, 'Are you who you say you are?' and 'Should you be able to do what you are trying to do?'
In the case of blockchain technology, private key cryptography provides a powerful ownership tool that fulfills authentication requirements. Possession of a private key is ownership. It also spares a person from having to share more personal information than they would need to for an exchange, leaving them exposed to hackers.
Authentication is not enough. Authorization having enough money, broadcasting the correct transaction type, etc needs a distributed, peer-to-peer network as a starting point. A distributed network reduces the risk of centralized corruption or failure.
This distributed network must also be committed to the transaction network's recordkeeping and security. Authorizing transactions is a result of the
32
entire network applying the rules upon which it was designed (the blockchain's protocol).
Authentication and authorization supplied in this way allow for interactions in the digital world without relying on (expensive) trust. Today, entrepreneurs in industries around the world have woken up to the implications of this development unimagined, new and powerful digital relationships are possible. Blockchain technology is often described as the backbone for a transaction layer for the Internet, the foundation of the Internet of Value.
In fact, the idea that cryptographic keys and shared ledgers can incentivize users to secure and formalize digital relationships has imaginations running wild. Everyone from governments to IT firms to banks is seeking to build this transaction layer.
Authentication and authorization, vital to digital transactions, are established as a result of the configuration of blockchain technology.
The idea can be applied to any need for a trustworthy system of record [4].
Speaking Section
16. Work in groups. Make a presentation on the way blockchain technology is used in the modern world
Video Section
17. Watch the video. Make notes on its main points. Present them to the group
https: //www.coursera.org/lecture/information-security-data/an-introduction-to­knowledge-areas-in-information-security-7mqjI
33
UNIT 3. CRYPTANALYSIS LEAD-IN
What knowledge and skills are important for a cryptanalyst?
Pronunciation
1. Make sure you pronounce the following words correctly
subterfuge [sbt]
inquisitiveness [ztvns]
coincidence [knsd()ns]
susceptibility [ssptblti]
signature [snt]
frequency [)nsi]
unicity [sti]
supposedly [spzdli]
Trojan [trd()n ]
scrutiny [ni]
threat [t]
measurement [mm()nt]
perseverance [pvr()ns]
partial [pl]
precaution [prk()n]
Word Study
2. Study the following definitions and memorize the terms
Access (noun) the means or opportunity to approach or enter a
place. E.g. "the staircase gives access to the top floor. Synonyms: entrance, entry, way in, means of entry. (verb) approach or enter (a place); obtain or retrieve (computer data or a file). E.g. Information can be accessed from several files and displayed at the same time. Synonyms: approach or enter (a place); obtain or retrieve (computer data or a file).
Derive -
receive or obtain from a source or origin (usually followed by  trace from a source or origin. Synonyms: gain, attain, glean, gather, reap, net. E.g. English words derived from German.
Digital signature - a digital code (generated and authenticated by
public key encryption) which is attached to an electronically transmitted
34
document to verify its contents and the sender's identity. A digital signature guarantees the authenticity of an electronic document or message in digital communication and uses encryption techniques to provide proof of original and unmodified documentation. Synonyms: electronic signature. E.g. Digital
signatures are used in e-commerce, software distribution, financial transactions and other situations that rely on forgery or tampering detection techniques.
Brute force attack - a trial-and-error method used to obtain information such as a user password or personal identification number (PIN). In a brute force attack, automated software is used to generate a large number of consecutive guesses as to the value of the desired data.
Intercept to stop, catch or take control of someone or something before they can get to the place they are going to. Synonyms: hold back, obstruct. E.g. We intercepted a message sent from a business firm in Paris to the
Hague.
Inquisitiveness asking a lot of questions and wanting to know things. Synonyms: curiosity. E.g. His inquisitiveness led him to the career in
journalism.
Man-in-the-middle attack - an attack where the attacker secretly relays and possibly alters the communication between two parties who believe they are directly communicating with each other. One example of a MITM is active eavesdropping, in which the attacker makes independent connections with the victims and relays messages between them to make them believe they are talking directly to each other over a private connection, when in fact the entire conversation is controlled by the attacker. The attacker must be able to intercept all relevant messages passing between the two victims and inject new ones.
Precaution - something done to protect people or things against possible harm or trouble. Synonyms: safeguard, preventive measure,
35
safety measure, insurance. E.g. Residents along the coast were evacuated as a precaution.
Subterfuge the use of lies and tricks. Synonyms: lie, invention,
falsehood, hoax. E.g. Subterfuge led by the deceitful media caused everyday
people to be confused.
Susceptibility - the tendency to be easily affected or influenced by
something. Synonyms: vulnerability, sensitivity, openness. E.g.
the gene that controls susceptibility to nicotine addiction.
Scrutiny critical observation or examination. Synonyms:
inspection, survey, study, analysis. E.g.
Council services are subject to close scrutiny to ensure their efficiency.
Unicity - the condition of being united; quality of the unique;
unification. Synonyms: singularity, uniqueness. E.g. The unicity of the new
principle allows to reproduce a sound in the real quality.
3. Match the words with their synonyms. Give the Russian equivalents
hinder
crack
individual, group
permutation
quit
provide
include
perseverance
endurance
involve
flaw
give up
party
fault
shift
encode
encrypt
ensure
prevent
break
Grammar Section Future intentions, Active and Passive Future Forms
4. Choose the correct form
1. will/is going to be unique.
2. We will/are going to buy new equipment.
3. This laboratory will/is going to work over a speech synthesizer.
36
4.  I will/am going to help you.
5. Big credit card companies will develop/will be developed/are going to develop more secure ways to use credit cards.
6. In this case unauthorized physical access will prevent/will be prevented/will
prevented.
7. Knowing about the risk, one is prepares/will prepared/will be prepared to
mitigate it.
8. The underlined secure network services will be installed/will have been
installed/is installed in accordance with the operational documentation.
9. A two-dimensional slice through an object will produce/will be
produced/will produced by the summation of many one-dimensional scans in computer-assisted tomography.
10. The project will launch/will be launched/will have been launched by the
end of the month.
5. Put the verbs in the correct forms, Active Voice
1. What you (do) tomorrow? We (have) a workshop in cryptanalysis.
2. Hurry up! No use. When we come to the lecture, it already (start).
3. I (finish) the report tomorrow. I think I (complete) it by 10 a.m.
4. Where you (go) in summer? We (meet) our colleagues from Moscow office.
5. Tomorrow this time he (fly) to Rome.
Put the verbs in the correct forms, Passive Voice
1. This work (finish) next month as we have completed 90 % of it.
2. The papers of the conference (translate) into 12 languages.
3. The system (develop) by 2010.
4. It is essential that the process of analyzing and assessing risk (understand) by all sides.
5. By the end of the year all the problems (settle).
37
6. You (inform) about the decision of the consumers in a week.
6. Put the verbs in the correct forms, Active or Passive
1. Could you meet our colleagues at the airport? OK. I (do) it.
2. I (launch) this program tomorrow.
3. Where you (stay) in London?
4. I think biometrics (use) for identification and authentication
everywhere.
5. I (present) our research at the conference in Moscow in June
6. At this time next year we (discuss) the details of the experiment.
7. Our scientists (develop) modern equipment by next month. All
arrangements have been made.
8. In June we (develop) the new device for three years.
9. 8.00 and 14.00. We (make) a presentation.
10. By the time he (arrive) at the office the work already (start).
11. According to the timetable the bus (arrive) at 8. Chris (come) an hour
later.
12. Our consumers (hope) the results of the risk assessment (obtain) soon.
Reading Section
7. These phrases and sentences have been removed from the text. Read the text
and complete it. There are two sentences that you don‟t need
…algorithm the larger its key space…
…knowing that their supposedly confidential communication has been intercepted…
…a demanding task and they should not quit failing…
…the system administrators or users,…
… mathematical formulas to look for algorithm weaknesses and break into information security systems…
38
…trying all possible keys until hitting on the one that results in plaintext…
…how they work and to identify flaws that could be there…
Text A. Cryptanalysis
Cryptanalysis is the decryption and analysis of codes, ciphers or encrypted text. It goes with other names like (code-breaking and cracking the code).
Basically, cryptanalysis uses ___________________________ built with cryptography.
Cryptanalysis generally involves studying cryptographic systems in order to understand ___________________________ so as to break into, with or without the key.
The main aim of a cryptanalyst is to be able to decode ciphertexts without knowing:
The source of the plaintext.
The encryption key used.
The algorithm that was used to encode information.
In order to discover the hidden aspects of a system and solve codes, the following traits are common among cryptanalysts:
Patience, since it takes a lot of time to crack a given code.
Perseverance, since this is ___________________________to break
codes.
Cryptanalyst needs to be good at mathematics.
A high-performance computer is needed.
High level of intuition.
Inquisitiveness.
39
Cryptanalysis is a battle between code makers (cryptographers) vs code breakers (cryptanalysts). With all the efforts being made, the field of cryptology has continued to grow and become better day after day.
The major categories of cryptanalysis include ciphertext only, known plaintext, chosen plaintext, and chosen ciphertext. These involve deriving the key from analysis of the pieces provided.
In a man-in-the-middle attack, the attacker intercepts the key exchange between the parties. This allows him to decrypt a message from one party, read it, then re-encrypt it with the sender's key before transmitting it on to the intended recipient. The sender and recipient have no way of________________________.
To prevent this, both sides can compute a cryptographic hash function of the key exchange, sign it using a digital signature algorithm, and send the signature to the other side. The recipient then verifies that the hash matches the locally computed hash and the signature came from the desired other party.
A brute force attack involves____________________________________. The defense is to make the attack too time consuming or expensive. The larger the key length that is supported by an _______________________________. Therefore, the more unique keys available, the longer it would take for a successful brute force attack.
Other types of attacks look for weaknesses in the algorithm, in the implementation. But the most successful attacks on systems are attacks on _____________________where attackers gain access through subterfuge, susceptibility to greed, or through physical violence or threat of violence.
Here controls and precautions to take to prevent cryptanalytic attacks:
Instead of designing your own personal algorithm, use the proven
existing ones already.
40
Use cryptographic algorithms with the best-recommended key sizes. Ensure correct use of any given algorithm. Generate key material using good sources of randomness and avoid
known weak keys.
Use the already proven protocols and their correct implementations. Choose initialization vectors with good random numbers. Use the most appropriate cryptographic algorithm depending on the
data [8].
Vocabulary Section
8. Complete the text using the terms and word combinations given below Running through, a strong encryption algorithm, maps, in parallel, the
cryptanalyst, the actual message, computing power
There are several distinct types of cryptoanalytic attack. The type used

Types of cryptoanalytic attacks. A standard cryptoanalytic is to determine
   
be known because it is standard or because it is guessed. If the plaintext segment is guessed it is unlikelely that its exact position is known however a message is
     
some systems a known ciphertext-plaintext pair will compromise the entire

 
of time to run. It consists of trying all possibilities in a logical manner until the correct one is found. Another type of brute force attack is a dictionary attack.
   
the plaintext) is one of them. This type of attack is often used to determine passwords since people usually use easy to remember words.
Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]