19-Soft-B3 Security · May 2014
Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)
National Exams, May 2014 — 04-Soft-B3, Security/Safety (closed book, 3 hours, no calculator). FIVE of the seven questions constitute a complete paper (the first five as answered in the answer book are marked, each of equal value); this solution answers all seven as a full study resource. Most questions call for essay-format answers; clarity and organisation of the answer are important. Question 6 asks for a security analysis of a short C program.
Reference texts. Stallings & Brown, Computer Security: Principles and Practice, 4th ed., Ch. 2–3 (Cryptographic Tools, One-Time Pad, Block Ciphers), Ch. 21 (Public-Key Infrastructure, Certificate Authorities), Ch. 3 (Hash Functions, MAC), Ch. 23 (Digital Signatures), Ch. 3 & 24 (User Authentication, Two-Factor, SSO), Ch. 9 (Firewalls, DMZ), Ch. 8 (Intrusion Detection, Honeypots), Ch. 10 (Buffer Overflow); Anderson, Security Engineering, 3rd ed., Ch. 4 (Access Control, Least Privilege), Ch. 1 & 9 (Defense in Depth, Separation of Duty).
Question text not reproduced: the examination questions are © Engineers and Geoscientists BC. Open the official past paper (linked at the top of this page) to read the question, then follow the worked solution below.
Part a) — the network firewall. A network firewall is a security device (hardware appliance or software) placed at the boundary between two networks of different trust levels (e.g. an organisation's internal network and the public internet) that inspects traffic crossing that boundary and enforces an access-control policy — a set of rules based on attributes such as source/destination IP address, port, protocol, and (for a stateful firewall) connection state — permitting traffic that matches an allowed rule and dropping/rejecting everything else. Its purpose is to reduce the network's exposed attack surface by ensuring that only traffic the organisation has explicitly decided to allow can reach its internal hosts, without relying on every individual host to defend itself.
Part b) — the DMZ. A demilitarized zone (DMZ) is a separate network segment positioned between the fully trusted internal network and the fully untrusted external network (the internet), used to host systems that must be reachable from the outside — a public web server, a mail relay, a DNS server — without placing them directly on the internal network. It is implemented with two firewalls (or one firewall with three network interfaces): an outer firewall between the internet and the DMZ, permitting only the specific traffic the public-facing service needs (e.g. HTTP/HTTPS), and an inner firewall between the DMZ and the internal network, permitting only the narrow, specific traffic the DMZ service legitimately needs to exchange with internal systems (e.g. a web server querying a back-end database on one specific port). If the DMZ host is compromised, the inner firewall still blocks the attacker from freely reaching the internal network.
Part c) — intrusion detection systems and honeypots. An intrusion detection system (IDS) monitors network traffic or host activity and raises an alert when it observes behaviour matching known attack signatures or deviating from an established normal-behaviour baseline (anomaly detection) — unlike a firewall, it typically does not block traffic itself (an intrusion prevention system does), it detects and reports so an analyst or automated response can act. A honeypot is a decoy system deliberately made to look like a real, valuable, and vulnerable target, deployed with no legitimate production purpose so that any interaction with it is inherently suspicious; it is used to detect attackers early, divert them away from real assets, and study their tools and techniques. Similarity: both are fundamentally detective (not preventive) controls — neither one stops an attack outright the way a firewall's access-control rules do; both work by observing activity (network traffic for an IDS, any interaction at all for a honeypot) and surfacing it as intelligence about an ongoing or attempted attack.