Back
ExamFull examExam paper only

04 07 14 1

Full exam for Computer Security in the Computer Engineering degree programme at Politecnico di Milano. The document covers: Computer Security Exam July 4, 2014 First name: ________________________ Last name: ________________________ Matricola: ________________________ Signature: ________________________ Homeworks? [ ] (Y) [ ] (N) Total points: ___ / 30 Instructions ● The exam is composed of 8 pages.

Computer SecurityFull exam

Document information

What's included in this study material

Full exam for Computer Security in the Computer Engineering degree programme at Politecnico di Milano. The document covers: Computer Security Exam July 4, 2014 First name: ________________________ Last name: ________________________ Matricola: ________________________ Signature: ________________________ Homeworks? [ ] (Y) [ ] (N) Total points: ___ / 30 Instructions ● The exam is composed of 8 pages.

Import quality: text was extracted directly from the original document.

Extracted content from the document

Representative passages recognised in different parts of the material. The full extracted text remains available to search, while this compact preview makes the page easier to read.

Page 1

Computer Security Exam July 4, 2014 First name: ________________________ Last name: ________________________ Matricola: ________________________ Signature: ________________________ Homeworks? [ ] (Y) [ ] (N) Total points: ___ / 30 Instructions ● The exam is composed of 8 pages. ● Just as a cross check, tell us whether you have completed the homeworks, by putting an "X" mark appropriately. ● The exam is "closed books". Please put away in a non­suspicious place (i.e. not below the desk) any note, book, or similar. You will be expelled if, at any time, if you do not follow this rule. ● You are not allowed to communicate with other students, and you will be expelled from the exam if you do. ● Shut down and store electronic devices. They will be subject to inspection if found and you may be expelled if you are found using one. ● Please answer within the allowed space. Schemes are good, short answers are recommended. ● You can write in pen or pencil, any color, but avoid writing in red. ● No extra paper is allowed. ● The answers should be written exclusively in the space provided below the questions. SOLUTION 1 of 8 Question 1 (2 points) Among the attacks against WEP, consider the one made possible by the fact that CRC32 is distributive with respect to the XOR operation. A. Does such an attack allow an observer to decrypt the ciphertext? If yes, explain how. If not, explain why. No, it only allows an attacker to change random bits in an intercepted payload and modify the CRC32 checksum to account for the changes. B. Describe with at most 2 phrases the solution to this specific attack that was adopted in 802.11i, focusing on why it made the attack unfeasible. The MIC is not distributive w.r.t. XOR anymore, and is function of payload, source/destination address, and random…

Preview

First page of the document.

First page: 04 07 14 1