s11

CIA Triad
The CIA Triad is a basic security model used to protect information and computer systems. CIA stands for Confidentiality, Integrity, and Availability.
1. Confidentiality
Confidentiality means protecting information from unauthorized access.
Example: A student's personal information should only be accessible to authorized college staff.
Methods:
- Passwords
- Encryption
- Access control
- Authentication
2. Integrity
Integrity means ensuring that data is accurate and has not been changed without authorization.
Example: Marks stored in a college database should not be modified by an unauthorized person.
Methods:
- Hashing
- Digital signatures
- File permissions
3. Availability
Availability means that authorized users can access information and services whenever required.
Example: A college website should remain available when students are checking examination results.
Methods:
- Backup
- Disaster recovery
- Network protection



s21


1. Virus
A virus is a type of malware that attaches itself to a legitimate file or program. It becomes active when the infected file is executed. A virus can modify, delete, or corrupt files and may spread to other files or computers through user actions.
Points:
- Requires a host file or program to spread.
- Usually spreads when the user runs an infected file.
- Can modify, corrupt, or delete data.
- May slow down or damage the computer.
- Example: Melissa virus.
2. Worm
A worm is malware that can replicate itself automatically without attaching to another file. It usually spreads through computer networks by exploiting security weaknesses.
Points:
- Does not require a host file.
- Can spread automatically from one computer to another.
- Mainly spreads through networks and security vulnerabilities.
- Can consume large amounts of network bandwidth.
- Example: WannaCry.
3. Trojan Horse
A Trojan Horse is malware that disguises itself as a legitimate or useful program to trick users into installing or running it. Unlike a virus or worm, a Trojan generally does not reproduce itself.
Points:
- Disguises itself as legitimate software.
- Requires the user to download or execute it.
- Does not normally self-replicate.
- Can steal information, install other malware, or provide unauthorized access.
- Example: A fake free software installer containing malware.



S31


Phishing
Phishing is a cyber attack in which an attacker tries to trick a user into providing sensitive information such as passwords, banking details, or personal information.
Steps to Identify a Phishing Email
1. Check the sender's address
Look for unusual or fake email addresses.
2. Check the subject line
Urgent or threatening subjects such as "Your account will be blocked" may indicate phishing.
3. Check the links
Move the cursor over links and check their actual URL.
4. Look for spelling mistakes
Phishing emails may contain grammatical and spelling errors.
5. Check for urgent requests
Be careful if the email asks for immediate action.
6. Check attachments
Avoid opening suspicious or unexpected attachments.
7. Verify the sender
Contact the organization through its official website or phone number.
8. Do not share sensitive information
Never provide passwords, PINs, or banking information through suspicious emails.
Conclusion



S41



Brute Force Attack
A Brute Force Attack is a method in which an attacker tries different password combinations until the correct password is found.
1. Simple Brute Force
In a simple brute force attack, the attacker tries combinations of characters systematically.
Example:
Trying:
aaa → aab → aac → ...
until the correct password is found.
2. Dictionary Attack
A Dictionary Attack uses a predefined list of commonly used passwords.
Example:
password
123456
admin
welcome
qwerty

The attacker checks these passwords against the target.
3. Hybrid Attack
A Hybrid Attack combines dictionary words with additional characters or numbers.
Example:
password123
admin123
welcome@123

Prevention
- Use long passwords.
- Use complex passwords.
- Enable multi-factor authentication.
- Implement account lockout.
- Avoid common passwords.



S51



Introduction
Network security threats are attacks that can compromise communication, data, or network resources. Two important threats are Man-In-The-Middle (MITM) and Packet Sniffing.
1. Man-In-The-Middle Attack
A MITM attack occurs when an attacker secretly places themselves between two communicating parties.
Example:
A user communicates with a website, but an attacker intercepts the communication.
Risks:
- Theft of sensitive information
- Password theft
- Modification of messages
- Session hijacking
2. Packet Sniffing
Packet sniffing is the process of capturing and examining network packets travelling through a network.
Attackers may use sniffing to obtain sensitive information from unencrypted communication.
Prevention
- Use HTTPS.
- Use encrypted communication.
- Use secure Wi-Fi.
- Use VPN when appropriate.
- Avoid unknown networks.



S61



Cyber Stalking
Cyber stalking is the repeated use of digital technologies to harass, threaten, monitor, or intimidate another person.
Key Behaviors
1. Repeated unwanted messages — Sending continuous messages to a victim.
2. Online monitoring — Constantly checking someone's online activity.
3. Threats — Sending threatening or intimidating messages.
4. Fake accounts — Creating fake profiles to contact or monitor victims.
5. Sharing private information — Publishing personal information without permission.
6. Online harassment — Posting abusive or harmful content.
Misuse of Social Networking Features
Social networking platforms can be misused through:
- Fake profiles
- Location sharing
- Private-message harassment
- Unauthorized sharing of photos
- Impersonation
- Cyberbullying
Prevention
- Use strong privacy settings.
- Avoid sharing unnecessary personal information.
- Block and report abusive accounts.
- Keep evidence such as screenshots.
- Use strong passwords and MFA.



S71


DoS Attack
A Denial of Service (DoS) attack attempts to make a computer system, website, or network service unavailable to legitimate users.
Working Principle
The attacker sends a large number of requests or packets to the target. The target uses its resources to process these requests and may become slow or unavailable.
1. SYN Flood
A SYN flood abuses the TCP connection process by sending many SYN requests.
The server waits for connection completion and consumes resources.
2. HTTP Flood
An HTTP flood sends a large number of HTTP requests to a web server.
The server spends resources processing these requests, which can reduce availability.
Effects
- Slow service
- Network congestion
- Server resource exhaustion
- Service unavailability
Prevention
- Firewalls
- Traffic filtering
- Rate limiting
- Intrusion detection systems
- DDoS protection services
Conclusion



S81



Steganography
Steganography is the technique of hiding a secret message inside another file such as an image, audio, video, or text file.
The purpose is to hide the existence of the message.
Cryptography
Cryptography converts readable information into an unreadable form called ciphertext using an encryption algorithm.
Difference
Steganography	Cryptography
Hides the existence of data	Hides the meaning of data
Secret data is hidden inside another file	Data is converted into ciphertext
Uses a cover file	Uses encryption algorithms
Example: hiding text inside an image	Example: AES encryption


Example
If "HELLO" is hidden inside an image, the image may look normal. This is steganography.
If "HELLO" is converted into ciphertext using AES, it is cryptography.




S91



RSA
RSA (Rivest-Shamir-Adleman) is a public-key cryptographic algorithm that uses a public key and private key.
1. Key Generation
Choose two prime numbers:
p and q
Calculate:
n = p × q
Calculate Euler's totient:
φ(n) = (p − 1)(q − 1)
Choose a public exponent e such that it is relatively prime to φ(n).
Calculate private key d such that:
d × e ≡ 1 mod φ(n)
2. Public and Private Keys
Public Key = (e, n)
Private Key = (d, n)
3. Encryption
If M is the message:
C = Mᵉ mod n
where C is the ciphertext.
4. Decryption
M = Cᵈ mod n
The original message is obtained using the private key.




S101



AES vs RSA
Feature	AES	RSA
Type	Symmetric	Asymmetric
Keys	Same secret key	Public and private keys
Speed	Fast	Slower
Key sizes	128, 192, 256 bits	Commonly larger key sizes
Main use	Data encryption	Key exchange, digital signatures
Suitable for large data	Yes	Not normally used directly


AES
AES (Advanced Encryption Standard) is a symmetric encryption algorithm. It uses the same secret key for encryption and decryption.
Applications of AES
1. File encryption
2. Disk encryption
3. Secure communication
4. Database protection
5. Wi-Fi security
6. Protection of confidential information
Security
AES is considered a strong encryption algorithm when used with appropriate key sizes and secure modes.



S111


Cover Object
A Cover Object is the original file used to hide secret information.
It can be:
- Image
- Audio
- Video
- Text
Example: An original image before hiding a message is called the cover object.
Stego-Object
A Stego-Object is the cover object after the secret information has been embedded into it.
Example: If a secret message is hidden inside an image, the resulting image is called the stego-object.
Process
Secret Message + Cover Object
              ↓
        Steganography
              ↓
         Stego-Object

Difference
Cover Object	Stego-Object
Original file	Modified file
Does not contain hidden message	Contains hidden message
Used as input	Produced as output



S121


Browser History Analysis
Browser history analysis is the examination of browser-related information during a digital forensic investigation.
Evidence That Can Be Obtained
1. Visited websites — URLs of websites accessed by the user.
2. Date and time — Shows when websites were visited.
3. Downloaded files — Information about files downloaded from websites.
4. Download location — Location where downloaded files were stored.
5. Search history — Search terms entered by the user.
6. Bookmarks — Saved websites and pages.
7. Cookies — Information stored by websites.
8. Cache — Stored web content and resources.
9. Browsing sessions — Information related to browsing activity.
Importance
Browser artifacts can help investigators understand a user's online activities and timeline.


S141


MITM Attack
A Man-In-The-Middle attack occurs when an attacker secretly intercepts communication between two parties.
Common Effects
- Stealing sensitive information
- Modifying communication
- Session hijacking
- Password theft
Packet Sniffing
Packet sniffing is the process of capturing network packets travelling through a network.
If communication is not encrypted, sensitive information may be exposed.
Preventive Measures
1. Use HTTPS websites.
2. Use encrypted communication.
3. Use secure Wi-Fi networks.
4. Avoid unknown public networks.
5. Use VPN when appropriate.
6. Use strong authentication.
7. Keep systems and security software updated.


S151


1. Salami Attack
A Salami Attack involves stealing very small amounts of data or money repeatedly so that the individual losses may go unnoticed.
Example: Taking a very small amount from many transactions.
2. Data Diddling
Data Diddling means changing data before or during processing without authorization.
Example: Modifying an employee's salary information in a database.
3. Web Jacking
Web Jacking involves gaining unauthorized control over or redirecting users from a legitimate website.
It may be used to redirect users to a fake or malicious website.
4. Email Bombing
Email Bombing involves sending a very large number of emails to an email account or server, potentially causing service disruption.
Prevention
- Access control
- Data validation
- Monitoring
- Security software
- Email filtering
- Regular auditing



S161


DDoS Attack
A Distributed Denial of Service (DDoS) attack uses multiple systems to send large amounts of traffic toward a target in order to make its service unavailable.
Types of Flooding Attacks
1. Volume-Based Attacks
These attacks generate a large volume of traffic to consume the target's bandwidth.
Example: UDP flood.
2. Protocol Attacks
These target network or protocol resources.
Example: SYN flood.
3. Application-Layer Attacks
These target applications or web servers by sending large numbers of application requests.
Example: HTTP flood.
Effects
- Slow network
- Server overload
- Service unavailability
- Resource exhaustion
Prevention
- Firewalls
- Traffic filtering
- Rate limiting
- Intrusion detection
- DDoS protection services



S171



MITM Attack
A Man-In-The-Middle attack occurs when an attacker intercepts communication between two parties without their knowledge.
Packet Sniffing
Packet sniffing involves capturing network packets travelling through a network.
Risks
- Password theft
- Data interception
- Session hijacking
- Privacy loss
Prevention
- HTTPS
- Encryption
- Secure Wi-Fi
- VPN
- Strong authentication
- Updated security software



S181


Steganography
Steganography is the technique of hiding a secret message inside another file such as an image, audio, video, or text file.
The purpose is to hide the existence of the message.
Cryptography
Cryptography converts readable information into an unreadable form called ciphertext using an encryption algorithm.
Difference
Steganography	Cryptography
Hides the existence of data	Hides the meaning of data
Secret data is hidden inside another file	Data is converted into ciphertext
Uses a cover file	Uses encryption algorithms
Example: hiding text inside an image	Example: AES encryption


Example
If "HELLO" is hidden inside an image, the image may look normal. This is steganography.
If "HELLO" is converted into ciphertext using AES, it is cryptography.



S191



Digital Evidence
Digital evidence is information stored or transmitted in digital form that can be useful in an investigation.
Examples include:
- Files
- Emails
- Images
- Browser history
- Logs
- Metadata
Write Blocker
A write blocker prevents data from being modified on the original storage device during forensic acquisition.
Its purpose is to preserve the original evidence.
FTK Imager
FTK Imager is a forensic acquisition and imaging tool used to:
- Create forensic images
- Preview evidence
- Calculate hashes
- Examine files
EnCase Imager
EnCase Imager is used to acquire and examine forensic evidence while maintaining evidence integrity.




S201



DDoS
A Distributed Denial of Service attack uses multiple systems to send traffic toward a target and make its service unavailable.
Types
1. Volume-Based Attack
Generates large amounts of traffic to consume bandwidth.
2. Protocol Attack
Targets network protocol resources.
3. Application-Layer Attack
Targets applications or web servers with large numbers of requests.
Effects
- Network congestion
- Server overload
- Slow service
- Service unavailability
Prevention
- Firewall
- Traffic filtering
- Rate limiting
- DDoS protection
- Intrusion detection systems



S211



Forensic Image Integrity
Forensic image integrity verification ensures that a forensic copy of digital evidence has not been changed or corrupted.
Hash
A hash is a fixed-length value generated from digital data. Even a small change in the data generally produces a different hash.
MD5
MD5 generates a 128-bit hash value.
It can be used for integrity checking, although it is not considered suitable for modern security-sensitive applications.
SHA-1
SHA-1 generates a 160-bit hash value.
Like MD5, SHA-1 has known security weaknesses, so stronger modern hash functions are preferred for new security applications.
Verification Process
1. Create forensic image.
2. Calculate its hash.
3. Record the hash value.
4. Perform forensic analysis.
5. Calculate the hash again.
6. Compare both values.
7. Matching values indicate that the image has remained unchanged.



S221



Steganography
Steganography is the process of hiding secret information inside another file called a cover file.
Three Carrier Files
1. Image Files
Images are commonly used as carriers.
Examples: PNG, BMP, JPEG
A secret message can be hidden within image data.
2. Audio Files
Audio files can also carry hidden information.
Examples: WAV, MP3
Data can be hidden within audio information.
3. Video Files
Video provides a large amount of data in which information can be hidden.
Examples: MP4, AVI
Advantages
- Hides the existence of the message
- Can use common multimedia files
- Useful for information hiding



S231


RSA
RSA is an asymmetric cryptographic algorithm that uses a public key and private key.
Applications of RSA
1. Secure Communication
RSA can be used in secure communication systems for public-key operations.
2. Key Exchange
RSA can be used to help establish or protect secret keys used for symmetric encryption.
3. Digital Signatures
RSA can be used to create and verify digital signatures.
A sender uses the private key to create a signature, and the public key can be used to verify it.
4. Authentication
Digital signatures can help verify the identity of the sender.
5. Data Integrity
Digital signatures can help detect whether signed data has been modified.
Benefits
- Public-key cryptography
- Authentication
- Integrity verification
- Non-repudiation support through digital signatures



S241


Man-In-The-Middle Attack
A Man-In-The-Middle (MITM) attack occurs when an attacker secretly intercepts communication between two parties.
The attacker may monitor or modify the communication.
Common Techniques
1. Fake Wi-Fi Network
An attacker creates a network that appears legitimate and tricks users into connecting.
2. ARP Spoofing
An attacker sends false ARP information to redirect network traffic.
3. DNS Spoofing
An attacker provides false DNS information and redirects users to an unintended website.
4. Session Hijacking
An attacker attempts to take control of an existing communication session.
Prevention
- Use HTTPS.
- Use secure Wi-Fi.
- Avoid unknown networks.
- Use encryption.
- Use VPN when appropriate.
- Use strong authentication.



S251



Phishing
Phishing is a cyber attack in which attackers use fake emails or messages to trick users into revealing sensitive information.
Steps to Identify
1. Check the sender's email address.
2. Examine the subject line.
3. Check suspicious links.
4. Look for spelling and grammar mistakes.
5. Be careful with urgent requests.
6. Avoid unexpected attachments.
7. Verify the sender through an official source.
8. Never provide passwords, PINs, or banking information through suspicious messages.



S261


Caesar Cipher Decryption
Caesar Cipher is a substitution cipher where each alphabet is shifted by a fixed number of positions.
For decryption, the encrypted letters are shifted backward by the selected shift value.
Example
Suppose the encrypted message is:
KHOOR

and the shift is 3.
Shift each character 3 positions backward:
K → H
H → E
O → L
O → L
R → O

Therefore:
KHOOR → HELLO

Decryption Formula
P = (C − shift) mod 26
Where:
- P = Plaintext
- C = Ciphertext
- shift = Number of positions shifted
Steps
1. Take the encrypted message.
2. Choose the shift value.
3. Shift each alphabet backward.
4. Keep spaces and special characters unchanged.
5. Obtain the original plaintext.
