1- Consider password authentication : (a) Suppose an off-line dictionary attack is used, and suppose the attacker has prepared a dictionary of 10,0000 entries, the password file contains 1000 users with 50 different salt values(Salt values correlation to user accounts attackers is unknown to the attacker). If the attacker’s goal is to get as many passwords as possible, how many hash values would the attacker compute in the worst case? (b) Based on the above part, how many comparisons between hash values are needed in the worse case? 2- A Digital Certificate usually contains an identity and other fields such as certificate issuer’s name .. etc : (a) Explain the process for a service owner (i.e. web application) to get a Digital Certificate ? (b) How does the Digital Certificate issued in part(a) enable any end user to detect the man in the middle attack? (c) What is the impact on the validity of the Digital Certificate if the hash algorithm used is not weak collision resistant? Justify your answer 3- Ali is the owner and can read* and write to the file grades.xlsx, controls and can read the file salaries.xlsx, and can execute the file dean.exe. Ahmed can read, write, and execute from grades.xlsx, and can not access(no read, no write, and no execute) salaries.xlsx or dean.exe: (a) Build an access control matrix that reflects the above description? (b) After applying all the below sequence of commands, draw the final extended access control Matrix matrix:1. Ali transfer write privilege to Ahmed on grades.xlsx 2. Ali transfer read privilege to Ahmed on dean.xlsx 3. Ali delete read privilege from Ahmed on grades.xlsx 4. Ahmed destroy grades.xlsx. 5. Ali destroy salaries.xlsx.

Computer Networking: A Top-Down Approach (7th Edition)
7th Edition
ISBN:9780133594140
Author:James Kurose, Keith Ross
Publisher:James Kurose, Keith Ross
Chapter1: Computer Networks And The Internet
Section: Chapter Questions
Problem R1RQ: What is the difference between a host and an end system? List several different types of end...
icon
Related questions
Question

1- Consider password authentication :
(a) Suppose an off-line dictionary attack is used, and suppose the attacker has prepared a dictionary
of 10,0000 entries, the password file contains 1000 users with 50 different salt values(Salt values
correlation to user accounts attackers is unknown to the attacker). If the attacker’s goal is to get as
many passwords as possible, how many hash values would the attacker compute in the worst case?
(b) Based on the above part, how many comparisons between hash values are needed in the worse case?

2- A Digital Certificate usually contains an identity and other fields such as certificate issuer’s
name .. etc :
(a) Explain the process for a service owner (i.e. web application) to get a Digital Certificate ?
(b) How does the Digital Certificate issued in part(a) enable any end user to detect the man in the
middle attack?
(c) What is the impact on the validity of the Digital Certificate if the hash algorithm used is not weak
collision resistant? Justify your answer

3- Ali is the owner and can read* and write to the file grades.xlsx, controls and can read the file
salaries.xlsx, and can execute the file dean.exe. Ahmed can read, write, and execute from grades.xlsx,
and can not access(no read, no write, and no execute) salaries.xlsx or dean.exe:
(a) Build an access control matrix that reflects the above description?
(b) After applying all the below sequence of commands, draw the final extended access control Matrix
matrix:1. Ali transfer write privilege to Ahmed on grades.xlsx
2. Ali transfer read privilege to Ahmed on dean.xlsx
3. Ali delete read privilege from Ahmed on grades.xlsx
4. Ahmed destroy grades.xlsx.
5. Ali destroy salaries.xlsx.

Expert Solution
trending now

Trending now

This is a popular solution!

steps

Step by step

Solved in 6 steps with 5 images

Blurred answer
Recommended textbooks for you
Computer Networking: A Top-Down Approach (7th Edi…
Computer Networking: A Top-Down Approach (7th Edi…
Computer Engineering
ISBN:
9780133594140
Author:
James Kurose, Keith Ross
Publisher:
PEARSON
Computer Organization and Design MIPS Edition, Fi…
Computer Organization and Design MIPS Edition, Fi…
Computer Engineering
ISBN:
9780124077263
Author:
David A. Patterson, John L. Hennessy
Publisher:
Elsevier Science
Network+ Guide to Networks (MindTap Course List)
Network+ Guide to Networks (MindTap Course List)
Computer Engineering
ISBN:
9781337569330
Author:
Jill West, Tamara Dean, Jean Andrews
Publisher:
Cengage Learning
Concepts of Database Management
Concepts of Database Management
Computer Engineering
ISBN:
9781337093422
Author:
Joy L. Starks, Philip J. Pratt, Mary Z. Last
Publisher:
Cengage Learning
Prelude to Programming
Prelude to Programming
Computer Engineering
ISBN:
9780133750423
Author:
VENIT, Stewart
Publisher:
Pearson Education
Sc Business Data Communications and Networking, T…
Sc Business Data Communications and Networking, T…
Computer Engineering
ISBN:
9781119368830
Author:
FITZGERALD
Publisher:
WILEY