Добавил:
ivanov666
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз:
Предмет:
Файл:English for Information Security. Учебник
.pdf
41
In a ciphertext only attack the cryptanalyst has only the encoded message
9. Complete the text. Translate the resulted text into Russian
with a random 56-bit possible key, do the following:
other keys obtained by inverting one bit of that key.
In those of the 56 cases where the flipped bit results in the ciphertext
original trial key, invert that bit of the trial key to obtain the next trial key.
which a trial encipherment differs from the actual ciphertext is a measure of
one's (lack of) altitude.
10. Translate into English the following passage.
полным раскрытием

42
Reading Section
11. Read the text. Make its mindmap
Text B. More Facts about Cryptanalysis
Types of cryptanalysis attacks
These cryptanalysis attacks depend on how much information is known
about the ciphertext.
Here are some of the cryptanalytic methods and techniques:
Known-plaintext Analysis (KPA) is an attack about ciphertext
decryption with known partial plaintext.
Chosen-plaintext Analysis (CPA) an attack that makes use of
ciphertext that matches arbitrarily selected plaintext through the same algorithm
technique.
Ciphertext-only Analysis (COA) this attack involves the use of
known ciphertext collections.
Man-in-the-Middle Attack occurs when two parties use the
message or key shared via a communication channel that has been compromised.
Adaptive Chosen-plaintext Attack (ACPA) involves the use of
chosen plaintext and ciphertext based on data learned from past encryptions.
Differential cryptanalysis attack involves analyzing pairs of
plaintext to determine how the algorithm under scrutiny works when different
types of data are used.
Integral cryptanalysis it uses sets of plaintexts in which part of the
plaintext is kept constant but the rest of the plaintext is modified.
Side-channel attack depends on the information collected from a
physical system used to encrypt or decrypt data. Such information includes the
time a system takes to respond to queries, power consumption used by the
encryption system, and the electromagnetic radiation emitted by the system.

43
Dictionary attack this technique is used against password files
based on natural words and known sequences of letters or numbers.
Cryptanalysis examples
Cryptographic ciphers can be broken in many ways. Modern
cryptographic algorithms are harder to break compared to classical ciphers.
While Caesar cipher may be solved by hand, others like ADFGVX cipher
require the use of a computer.
Here are a few cryptanalysis examples and techniques on classical
ciphers:
Cryptanalysis of the Playfair cipher.
Cryptanalysis of the Vigenere cipher.
Cryptanalysis of Hill cipher.
Text Characterisation
Text characterization is an automatic determination of how close a piece
of text is to natural language.
Here are methods a cryptanalyst can use to find the key in order to solve
a certain text:
Counting frequency of the text.
Identifying patterns.
Cryptanalysis tool kit.
Index of the coincidence to estimate the distribution of letter
frequency in a given language.
Unicity distance.
Quadgram statistics, which involve adding up all likelihoods of
ciphertext appearing in a length of four blocks to determine how close the code
is to a given language (English).
Modern cryptanalysis

44
Most of the modern techniques are about differential power analysis and
timing.
Here are a few modern cryptanalysis techniques:
Measurement of differences in electricity consumption when the
system is encrypting.
Social engineering, tricking individuals into giving them passwords
and keys.
Exploiting a weakness known with a specific cryptosystem.
Using Trojan horse viruses to steal private keys from personal
computers.
Cryptanalysis tools
Here are tools and resourses that you can use to learn more about
cryptanalysis:
CrypTool this has e-learning programs and also a web portal for
learning cryptanalysis and cryptographic algorithms.
is an open source cryptanalysis tool used for classical
polyalphabetic and monoalphabetic ciphers.
Cryptol helps users monitor how algorithms operate in software
programs that use specific algorithms and ciphers.
CryptoBench this is a program used to do cryptanalysis of
ciphertext generated with most common algorithms.
Cryptanalysts goals
Here are goals an attacker/cryptanalyst maybe after when trying to break
into a system:
Total break to find the secret key.
Global deduction to find a functionally equivalent algorithm for
encryption and decryption that does not need the secret key.

45
Information deduction to gain some information about plaintexts
or ciphertexts that were not known before.
Distinguishing algorithm to distinguish the output of the
encryption or ciphertext from a random permutation of bits.
Speaking Section.
12. Prepare a presentation on one of the aspects of modern cryptanalysis that is
interesting for you
Video Section
13. Watch the video and summarize the advantages of the job presented
there
https://www.youtube.com/watch?v=UxE5oWGlH7w

46
UNIT 4. INFORMATION PROTECTION IN AN ORGANIZATION.
RISK ASSESSMENT
LEAD-IN:
Equifax’s Data Breaches
Former Equifax CEO Richard Smith testifies during a Senate Banking
Committee hearing in Washington, D.C. on Wednesday, Oct. 4, 2017.
Credit rating firm Equifax makes its profits from selling personal, often
sensitive information to financial institutions and lenders.
But in September, it revealed that it had been at the center of one of the
worst data breaches in history, with the information of some 145 million
people, about half of the U.S. population, compromised.
In the aftermath, CEO Richard Smith stepped down, as well as its chief
information officer and chief security officer, amid revelations that Equifax was
aware of the system flaw that the hackers took advantage of since March. Then,
when the hack did happen, the firm waited a full two months before disclosing it.
Meanwhile, the Justice Department is reportedly looking into whether top
Equifax executives committed insider trading when selling some $1.8 billion in
shares just before the breach was disclosed.
Is the situation described in the Lead-in text far from being
unique?
Can you remember any other cases of information leakage at an
enterprise or in an organization?
Pronunciation
1. Make sure you pronounce the following words correctly
via
qualitative [kwlttv]
audit [t]
employee [mpl]
cyber [sb]
objective [ktv]
threat [t]
malicious [mls]
assignment [snm()nt]
breach []
assess [ss]
compliance [kns]
malware [(r)]
access [akss]
quantitative [kwntttv]

47
Word Study
2. Study the following definitions and memorize the terms
Aftermath the period that follows an unpleasant event or accident,
and the effects that it causes. Synonyms: consequence, outcome. E.g. Many
more people were injured in the aftermath of the explosion.
crippling lawsuit court case that results in serious financial loss or
other undesirable effects. Synonyms: disastrous, destructive. E.g. The insurance
can prevent crippling lawsuits.
data exfiltration - the unauthorized copying, transfer or retrieval
of data from a computer or server. Synonyms: data extrusion
or data exportation. E.g. After a successful asset discovery adversaries try
to exfiltrate data from the compromised network.
data leakage - The unauthorized transfer of classified information
from a computer or datacenter to the outside world. Synonyms: data loss,
disclosure of data. E.g. Thus, we can infer that the trends occurring in publicly
disclosed data leakage incidents accurately reflect the trends in data loss in
general.
disgruntled employee unhappy and annoyed specialist. Synonyms:
dissatisfied, disappointed. E.g. You could become a disgruntled employee if your
boss swipes all your best ideas without giving you credit (or a raise).
evaluate to form an idea of the amount, number, or value of.
Synonyms: assess, estimate. E.g. It can be difficult to evaluate the effectiveness
of different techniques.
fraudulent acting with or having the intent to deceive; relating to
or proceeding from fraud or dishonest action. Synonyms: deceitful, dishonest,
illegal. E.g. Fraudulent actions led to corruption of the security system.
granular having a high level of detail. Synonyms: detailed,
thorough. E.g. They presented a granular report on security policy.

48
ill-intentioned employee malicious specialist. Synonyms:
malicious, harmful, adverse. E.g. Desjardins Group, the largest financial co-
operative in North America, said an “ill-intentioned” employee illegally exposed
the personal information of some 2.9 million credit union members in one of
Canada‟s largest data leaks.
Phishing attack - a type of social engineering attack often used to
steal user data, including login credentials and credit card numbers. It occurs
when an attacker, masquerading as a trusted entity, dupes a victim into opening
an email, instant message, or text message. E.g. Phishing attacks involved
tricking a victim into taking some action that benefits the attacker.
spoof A spoofing attack is when a malicious party impersonates
another device or user on a network in order to launch attacks against network
hosts, steal data, spread malware or bypass access controls. Synonyms: cheating,
deceit, hoax, trick. E.g. This type of spoofing is done by telemarketers to hide
their true identity and by hackers to gain access to unprotected phone voicemail
messages.
unwittingly - without being aware; in a way that is not conscious or
deliberate. Synonyms: accidentally, unintentionally, spontaneously, mindlessly.
E.g. I apologize for any problems which I may, unwittingly, have caused.
3. Match the words with their synonyms. Give the Russian equivalents
assessment
discolour, stain
watch
handle
wise, shrewd
goal, target
make certain;
protect
reduce
regulate, manage
massive;
powerful; large
estimation,
evaluation
ensure
mitigate
breach
far seeing
objective
keep an eye
hefty
tarnish
violation, break

49
4. Match the words in A and B. Translate the word combinations
A
B
ill-intentioned
control
crippling
receivable
Phishing
exfiltration
granular
an objective
hefty
lawsuit
data
an eye
accounts
attack
set
employee
keep
payout
Grammar Section
Modal Verbs
5. Rewrite the following sentences using have to, should, must, can, might,
be able to, shall or their negative forms or questions
1. Perhaps they will buy this IT product.
2. -off.
3.
4. What do you think of buying this computer?
5.
6. This program is free.

50
7. Perhaps I will
8.
9. We wear a kind of uniform. This is the rule at our work.
10. He is very good at programming.
11.
12. I want to help you. Tell me what to do.
13. She is a successful team leader.
14. I need your advice in this situation.
15. Is it possible for you to do it tomorrow?
6. Rewrite the following sentences using have to, should, must, can, might
or their negative forms or questions. Mind different types of infinitives
1. Perhaps you made a mistake in this task.
2. I am sure Alice is working now.
3. I think it was unwise of you to do that.
4. I am sure it was not him!
5.
6. It was necessary for the security officer to estimate the risk.
7. You look like Paul! You are like twins!
8.
9. You were very careless with your password.
10.
11. I am sure they have been working over this problem for 2 years.
12. We were made to reload the program.
13. Are you still here? It was not necessary to wait for me.
14. It was necessary for the security officer to estimate the risk. But he
15.
Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]
