19-Soft-B3 Security · December 2018
Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)
National Exams, December 2018 — 04-Soft-B3, Security/Safety (closed book, 3 hours, no calculator). FIVE of the seven questions constitute a complete paper (the first five as answered in the answer book are marked, each of equal value); this solution answers all seven as a full study resource. Most questions call for essay-format answers; clarity and organisation of the answer are important. Question 6 asks for a security analysis of a short C program.
Reference texts. Stallings & Brown, Computer Security: Principles and Practice, 4th ed., Ch. 2–3 (Cryptographic Tools, One-Time Pad, Stream/Block Ciphers, Modes of Operation), Ch. 21 (Public-Key Infrastructure, Certificate Authorities), Ch. 10 (Key Management, Diffie–Hellman, RSA), Ch. 3 (Hash Functions, MAC), Ch. 23 (Digital Signatures), Ch. 3 & 24 (User Authentication, Two-Factor, SSO, Password Storage), Ch. 9 (Firewalls, DMZ), Ch. 8 (Intrusion Detection, Honeypots), Ch. 10 (Buffer Overflow), Ch. 1 (Security Concepts — CIA Triad); Anderson, Security Engineering, 3rd ed., Ch. 4 (Access Control), Ch. 1 (Security Concepts).
Question text not reproduced: the examination questions are © Engineers and Geoscientists BC. Open the official past paper (linked at the top of this page) to read the question, then follow the worked solution below.
Part a) — the network firewall. A network firewall is a security device (hardware appliance or software) placed at the boundary between two networks of different trust levels (e.g. an organisation's internal network and the public internet) that inspects traffic crossing that boundary and enforces an access-control policy — permitting traffic that matches an allowed rule (source/destination IP, port, protocol, and for a stateful firewall, connection state) and dropping everything else. Its purpose is to reduce the network's exposed attack surface, ensuring only traffic the organisation has explicitly decided to allow reaches its internal hosts, without relying on every individual host to defend itself.
Part b) — the DMZ. A demilitarized zone (DMZ) is a separate network segment positioned between the fully trusted internal network and the fully untrusted internet, used to host systems that must be reachable from the outside (a public web server, a mail relay, a DNS server) without placing them directly on the internal network. It is implemented with two firewalls (or one firewall with three interfaces): an outer firewall between the internet and the DMZ, permitting only the specific traffic the public-facing service needs, and an inner firewall between the DMZ and the internal network, permitting only the narrow traffic the DMZ service legitimately needs to exchange internally. If the DMZ host is compromised, the inner firewall still blocks the attacker from freely reaching the internal network.
Part c) — intrusion detection systems and honeypots. A network intrusion detection system (NIDS) monitors network traffic and raises an alert when it observes behaviour matching known attack signatures or deviating from an established normal-behaviour baseline — unlike a firewall, it typically does not block traffic itself (an intrusion prevention system does), it detects and reports so an analyst or automated response can act. A honeypot is a decoy system deliberately made to look like a real, valuable, and vulnerable target, deployed with no legitimate production purpose so that any interaction with it is inherently suspicious; it is used to detect attackers early, divert them from real assets, and study their tools and techniques. Similarity: both are fundamentally detective (not preventive) controls — neither stops an attack outright the way a firewall's access-control rules do; both work by observing activity and surfacing it as intelligence about an ongoing or attempted attack, and a honeypot's traffic is in fact one of the highest-confidence data sources an IDS can monitor, since any interaction with it is by definition unauthorized.