Skip to main content
SECURITY PROTOCOLS
SSL ( Secure Socket layer)
• Most computers and browsers already can
exchange secure transactions across Internet,
making it difficult for unauthorized people to
intercept data such as credit card numbers.
Even if a transmission is intercepted, the
encrypted message cannot be read.
• The two key protocols for secure WWW
transactions are: SSL and S-HTTP (Secure
Hypertext Transfer Protocol).
• Originally developed by Netscape, SSL is the most
widely used standard for encrypting data on Internet.
• Provides three basic services:
a) Server authentication- uses public key cryptography
to validate server’s digital certificate and public key on
client’s machine.
b) Client authentication- SSL allows client and server
machines to jointly select an encryption algorithm to
be used for secure connection. The key to this
algorithm is transmitted using public key
cryptography, after which client and server may
communicate using secret key.
c) Encrypted SSL connection- to authenticate transaction
between client and server by above mentioned
method.
S-HTTP
• Hyper Text Transfer Protocol (HTTP) is a
“request response” type language spoken
between web browser (client software) and a
web server (server software) on Internet to
allow communication with each other and to
exchange files.
• The function of Secure- HTTP is to secure web
transactions only. It ensures transaction
confidentiality and authenticity and it ensures
non repudiation of origin.
VPN (Virtual Private Network)
• It is a private communications network often
used within a company, or by several
companies or organizations, to communicate
confidentially over a publicly accessible
network.
• VPN message traffic can be carried over a
public networking infrastructure (Internet) on
top of standard protocols, or over a service
provider’s private network with a defined
Service Level Agreement (SLA) between VPN
customer and the VPN service provider.
FIREWALL
• They are the software and hardware tools that
define, control and limit access to networks
and computers linked to the network of the
organization.
• It shields an organization’s networks from
exposure when connecting to the Internet or
to untrusted network & prevent hackers from
gaining access to corporate data.
• It must ensure a) data integrity, b)
authentication & c) confidentiality.
• Most firewalls are configured to protect against
unauthenticated log ins from the outside world,
preventing unauthorized users from logging into
machines on the company’s network.
• They can also be employed to block all unsecured
access to the internal network, while also limiting
users inside the company to connect only to
acceptable external sites.
• A firewall can be designed to separate groups within
an organization. For ex: HR dept might place their
network behind a firewall to safeguard confidential
payroll and personnel information from other
employees.
• A firewall appliance is generally one piece of
hardware that is no longer than a small desktop PC
plugged between a firm’s Internet access device
(DSL, router, modem) and the form’s first hub/switch.
• The software version of Firewall is known as
“Cyberwall”, which is all in one software package.
Developed with an aim to improve security for entire
private network.
• It can protect applications, networks and systems on
the whole LAN. It does this by residing at the
interconnection of the internal networks, the
application and database servers, the client
machines and the perimeter.