Sécurité informatique

116 documents à télécharger gratuitement

Cours, examens, TD, TP et exercices de sécurité informatique. Thèmes couverts : cybersécurité, cryptographie, chiffrement, pentest, vulnérabilités.

Outils de sécurité et de maintenance informatique - TP4

This document provides a detailed explanation of essential system maintenance tools available in Windows XP, such as disk defragmenter, disk cleanup, system restoration, and file backup utilities. It also explores file compression techniques and software along with their use cases in archiving and email transfers. Additionally, it introduces fundamental concepts of cybersecurity, such as antivirus mechanisms (dictionary, behavior-based, and heuristic detection methods) and firewall activation to protect against viruses, worms, trojans, and unauthorized intrusions. An emphasis is placed on p...

disk defragmentation
WinRAR
system restoration
3p0
Sécurité applicative avec focus sur OWASP TOP 10 et CSRF attack prevention

This document provides an instructional assignment on cybersecurity, focusing on practical exercises such as reproducing a CSRF attack and securing code with CSRF Tokens. It emphasizes secure session management and secure storage of passwords using PBKDF2 with SALT. Additionally, students are required to configure secure cookies, modify PHP session parameters, and attempt password cracking using tools like John the Ripper to reinforce their understanding of security measures and vulnerabilities in application development.

CSRF attack
PBKDF2
OWASP TOP 10
3p0
SQL Injection and XSS Vulnerability Assessment and Mitigation

The document outlines tasks focused on identifying and mitigating common web application vulnerabilities, specifically blind and union-based SQL injection as well as reflected Cross-Site Scripting (XSS). The methodology involves utilizing specially designed authentication and PHP pages, traffic analysis with Wireshark, and secure coding practices such as input filtering, prepared statements, output encoding, and sanitization. Findings emphasize the importance of adhering to OWASP guidelines and employing robust defenses in web application development. The assignment underscores practical im...

SQL injection
blind injection
reflected XSS
1p0
Sécurité applicative – Lab2 SSDLC

This document is a detailed lab report guiding students through the implementation and testing of various security tools and concepts. It involves using tools like FlawFinder to analyze C/C++ code for vulnerabilities, setting up intentionally insecure web applications like OWASP WebGoat and DVWA within Docker, and performing SQL injection attacks for pentesting. The exercises also cover static code analysis and manual pentesting techniques, promoting hands-on learning of security best practices and the exploitation of common vulnerabilities.

FlawFinder
SQL Injection
OWASP WebGoat
15p0
Lab1- SSDLC

This document provides a framework for addressing sensitive data protection in compliance with OWASP ASVS standards, detailing the corresponding CWE references for each requirement. It involves researching existing threat modeling methodologies (e.g., VAST, DREAD, STRIDE) and utilizing tools like Microsoft TMT or pyTMT to analyze threats in a user-proposed architecture, explaining at least three detected threats. Additionally, it highlights best practices for database and communication security as outlined by the OWASP SCP guide.

OWASP ASVS
CWE
Threat Modeling
3p0
Sécurité Informatique - Chapitre 3 : Cryptographie

This document introduces cryptography, emphasizing its role in ensuring confidentiality, authenticity, and integrity of information. It details cryptographic concepts like encryption, decryption, symmetric and asymmetric key systems, hashing functions, and digital signatures. Methodologies for achieving security objectives such as confidentiality, integrity, and authenticity are elaborated with examples of key algorithms like DES, AES, RSA, and hashing-based methods. The document also highlights the benefits and trade-offs of symmetric versus asymmetric algorithms and stresses the importanc...

cryptography
DES
RSA
7p0
Sécurité Informatique - Chapitre 2 B : Les logiciels malveillants

Chapter 2 B offers an in-depth analysis of malicious software, categorizing and reviewing their functions and propagation methods, including viruses, worms, Trojans, backdoors, spyware, adware, rootkits, and cryptoviruses. Methods to detect and protect against these cyber threats include signature-based detection, behavioral analysis, firewalls, antivirus systems, and secure network architectures. Polymorphism and advanced obfuscation techniques are highlighted as mechanisms to evade detection. The document emphasizes preventive measures at various levels (individual systems, servers, and n...

malicious software
signature-based detection
polymorphism
4p0
Sécurité Informatique : Les Attaques Réseau

This document introduces key concepts in network security, detailing vulnerabilities and advanced attack methodologies. It covers fundamental network protocols such as TCP, UDP, IP, Ethernet, and ARP, explaining their role in communication and packet handling. Various network attack techniques are explained, including identity spoofing (MAC and IP), session hijacking, and Denial of Service (DoS/DDoS). Practical examples illustrate methods such as ARP cache poisoning, DNS spoofing, and SYN flooding, providing insight into the mechanisms attackers use to compromise network integrity and avail...

TCP/IP
SYN flooding
ARP spoofing
8p0
Sécurité Informatique

This document introduces the foundational principles of information security, emphasizing the transition from physical to digital protection tools and the importance of securing distributed systems and networks. It defines key concepts such as vulnerabilities, threats, and countermeasures, and outlines fundamental objectives including confidentiality, integrity, and availability. It further delves into core security principles like defense in depth, least privilege, and the avoidance of security through obscurity, and concludes with the importance of standardized practices and policies for...

vulnerability
ISO 27002
CIA (Confidentiality
8p0
Activité 6.1: Les moyens de cyberdéfense

Cette activité permet une introduction à la sécurité des datawarehouses à travers une approche collective. Les participants travailleront en groupes pour analyser un article scientifique et produire un document synthétisant leurs findings. L'activité exige un document PDF à soumettre avec des critères d'évaluation basés sur la qualité, la pertinence et l'exactitude des informations.

activite
groupe
cette
1p0
Activité 1.1: Dans la peau d’un expert en cybersécurité

This document explores various aspects of cybersecurity, comparing the roles and missions of ANSII Tunisia and ANSII France, with a focus on strategies for prevention and reaction against cyberattacks. It emphasizes the role of data as the core asset of enterprises and highlights significant security threats, such as the Wannacry virus and major global cybercrime contributors. It also outlines career paths in cybersecurity, discusses the tasks of a security officer (RSSI), and highlights the importance of education and awareness to foster a culture of secure practices.

Cybersecurity
Wannacry
ANSII
3p0
Cryptography in Information Technology

This document focuses on cryptographic methodologies, primarily using symmetric encryption (e.g., DES in ECB mode). It contrasts symmetric with asymmetric algorithms, emphasizing the latter’s use of dual keys for encryption and decryption processes. It further explains hashing as a data transformation method to produce fixed-length outputs, highlighting its applications in encrypted communication, sensitive data protection, and message authentication. The document explores practical cases and provides encrypted inputs and outputs for demonstration.

symmetric encryption
DES
hash function
2p0
Chiffrement symétrique et asymétrique : Comparaison, DES/ECB

This document contains an exam on cryptography covering symmetric and asymmetric encryption methods. It also discusses hash functions and their applications in securing data. The student, Yousssef Trabelsi, provides various examples and explanations related to these topics.

donne
fonction
utilise
2p0
Étude technique sur la cryptographie à clé publique

Ce document traite des principes de la cryptographie à clé publique et de la signature numérique. Il explore le fonctionnement des mécanismes sous-jacents et souligne l'importance de la compréhension technologique pour les conseillers. En outre, il propose une introduction à l'infrastructure à clé publique et aux normes en matière de cryptographie.

message
signature
chiffrement
16p0
Activité 1.1: Dans la peau d’un expert en cybersécurité

The document outlines an individual educational activity introducing cybersecurity through research and practical exercises. Learners analyze the missions of ANSII in France and Tunisia, comparing their cybersecurity strategies. Focus is placed on the importance of data, cybersecurity roles, threats like WannaCry, and preventive versus reactive measures. Raising awareness is highlighted as a pivotal step in advancing cybersecurity maturity and reducing attack risks.

cybersecurity expert
WannaCry
cybercrime prevention
3p0
Dans la peau d’un expert en cybersécurité

Cette activité vise à initier les apprenants aux concepts fondamentaux de la cybersécurité. Ils devront visionner une vidéo sur les missions d'experts en cybersécurité et utiliser ces informations pour répondre à un ensemble de questions. L'évaluation sera réalisée par le tuteur, et le travail doit être soumis sous format Word ou PDF.

curit
donn
cyber
3p0
Activité 1.1: Dans la peau d’un expert en cybersécurité

This document outlines an individual exercise designed to introduce learners to cybersecurity concepts. Participants are required to watch a video discussing the role of cybersecurity experts, with a focus on ANSII, the French cybersecurity agency, and its strategic goals in fostering trust and security in the digital space. The exercise asks students to research ANSII Tunisia for a comparative analysis and answer several cybersecurity-related questions, including the importance of data, threats like WannaCry, and the significance of prevention and sensitivity training. The assignment also...

cybersecurity
WannaCry virus
policy of security
3p0
Introduction au cyber sécurité

Un syst me d'information (SI) est un ensemble organis de ressources qui permet de collecter, stocker, traiter et distribuer de l'information 1 Il s'agit d'un syst me sociotechnique compos de deux sous-syst mes, l'un social et l'autre technique.

Informatique
exam
curit
1p0
Sécurité des systèmes - DS 1 2020-2021

The document discusses the mechanisms and principles of securing systems, emphasizing tools like the syslogd daemon for system activity logging and IDS for intrusion detection. It highlights protective measures such as firewalls, proxies, and backdoors, detailing their operational frameworks. The document outlines strategies for addressing system vulnerabilities, ensuring data integrity, confidentiality, and availability through various cybersecurity best practices. It concludes with specific actions like patch management, anti-malware tools, and proper access controls for optimizing system...

syslogd
IDS: Intrusion Detection System
firewall
2p0
Les Attaques Réseau

This document delves into various types of network attacks, categorizing them based on methodologies and impact levels. It discusses the motivations behind such actions, the subsequent effects on system confidentiality, integrity, and availability, and explores both passive attacks (eavesdropping) and active attacks (modifications and disruptions). Further elaboration is provided on attack types like denial of service (DoS), spoofing, and phishing, with clear discussion of stages in executing an attack. Examples include ARP spoofing, TCP SYN flooding, and DHCP starvation, emphasizing preven...

network attacks
ARP spoofing
denial of service (DoS)
102p0
Sécurité des Réseaux Informatiques

This document extensively explores network security attacks, categorizing them into passive and active types. It highlights major attack classes like sniffing, spoofing, denial of service (DoS), and buffer overflow, explaining their methods and implications. A key focus is on demonstrating examples such as ARP spoofing, packet sniffing, brute force password cracking, and SYN flooding. The document emphasizes preventive measures and practices for minimizing risks associated with these attacks.

network security
ARP Spoofing
denial of service (DoS)
16p0
Principles of Cryptography

This document provides an in-depth overview of cryptographic principles and their application for secure communication. It explains key concepts such as encryption, cryptanalysis, and cryptology, discussing the roles of algorithms like symmetric and asymmetric ciphers along with hash functions. The document analyzes modern cryptographic tools (e.g., AES, RSA) and mechanisms for encryption, digital signatures, and mutual authentication. Notable frameworks like Public Key Infrastructure (PKI) and components like digital certificates and certificate authorities are covered comprehensively.

cryptography
RC4
Kerkhoff's principle
21p0
Principes de cryptographie

This document provides an overview of cryptography, including definitions, principles of security, and mechanisms. It covers both symmetric and asymmetric encryption algorithms, highlighting their advantages and disadvantages.

chiffrement
message
algorithmes
21p0
Sensibilisation et initiation à la cybersécurité

This document, created by a cybersecurity-focused consortium under ANSSI governance, provides a comprehensive introduction to organizational cybersecurity. It addresses integrating security into an organization, adapting ISO 27000 standards, risk management approaches, and human resource security protocols. The framework emphasizes continual risk assessment and iterative improvements through ISO compliance, while also detailing practical measures such as information classification, access control, and project lifecycle security design.

cybersecurity
ISO 27001
risk management
62p0

Autres ressources en sécurité informatique