1.1 What is the OSI security architecture?
1.1 什麽是OSI安全體系結構?
The OSI Security Architecture is a framework that provides a systematic way of definingthe requirements for security and characterizing the approaches to satisfying thoserequirements. The document defines security attacks, mechanisms, and services, and therelationships among these categories.
1.2 What is the difference between passive and active security threats?
1.2 被動安全威脅和主動安全威脅之間的差別是什麽?
Passive attacks have to do with eavesdropping on, or monitoring, transmissions. Electronic mail, file transfers, and client/server exchanges are examples of transmissions that can be monitored. Active attacks include the modification of transmitted data and attempts to gain unauthorized access to computer systems.
1.3 List and briefly define categories of passive and active security attacks.
Passive attacks: release of message contents and traffic analysis. Active attacks: masquerade, replay, modification of messages, and denial of service.
1.3 列出和簡要定義被動安全攻擊和主動安全攻擊的範疇。
1、 What is called secret key?
1 密鑰是什麽?
The secret key is also input to the algorithm. The exact substitutions and transformations performed by the algorithm depend on the key.
2、(page.56) What is the key distribution center?
The key distribution center determines which systems are allowed to communicate with each other. When permission is granted for two systems to establish a connection, the key distribution center provides a one-time session key for that connection.
3、What services are provided by IPSec?
3. IPSec提供些什麽服務?
1.Access control
1 訪問控制
2.Connectionless integrity
3.Data origin authentication
3 數據源認證
4.Rejection of replayed packets(a form of partial sequence integrity)
4 拒絕重放數據包(部分序列完整性的壹種形式)
5.Confidentiality(encryption) 6.Limited traffic flow confidentiality
5 置信度(加密)
6 有限業務流的置信度
4、What is a replay attack?
4. 什麽事重放攻擊?
A replay attack is one in which an attacker obtains a copy of an authenticated packet and later transmits it to the intended destination.The receipt of duplicate, authenticated IP packets may disrupt service in some way or may have some other undesired consequence.The Sequence Number field is designed to thwart such attacks.First,we discus sequence numbergeneration by the sender,and then we look at how it is processed by the recipient.