Computer Security (Chapter-4)
Computer Security (Chapter-4)
Network Security
Internet View of Networking
PC Millions of connected computing Mobile Network
Server devices: hosts (end systems) running National or
Wireless network applications Global ISP
laptop
Cell phone
Institutional Network
Destination Hn Ht M Network
M Hd Hn Ht M Data link
Application
Ht M Transport Physical
Hn Ht M Network
Hd Hn Ht M Data link Router
Physical
+ Internet - KS
Transport mode
o Used when both endpoints support IPSec to provide security services for upper
layer protocols such as TCP or UDP segments or an ICMP packet
o The IP header is not protected
AH in Transport Mode
Original TCP/UDP
AH Data
IP Header Header
SSL consists of two layers of protocols: SSL Record Protocol Layer and Upper Layer
Protocols (SSL Handshake, SSL Change Cipher Spec, SSL Alert)
Compressed Length (16 bit): The length in bytes of the plain text fragment
(compressed fragment) if compressed
MAC (0 bytes if no authentication, 16 bytes for MD5 or 20 bytes for SHA)
Dual signature