Sécurité informatique

116 documents à télécharger gratuitement

Cours, examens, TD, TP et exercices de sécurité informatique. Thèmes couverts : cybersécurité, cryptographie, chiffrement, pentest, vulnérabilités.

ASR4 Networks: Firewall and Security Structures

This document introduces fundamental concepts related to network security, specifically focusing on firewalls and address translation mechanisms. It outlines various firewall components such as packet filtering, NAT (Network Address Translation), and their implementation using Linux tools like iptables. Different architectures are explored, including internal networks, demilitarized zones (DMZ), and external networks, emphasizing structured security policies. Additionally, the document explains the functionality of proxy servers for optimizing network resources, caching, and enhancing secur...

Firewall
iptables
Network Address Translation (NAT)
10p0
Concepts cryptographiques de base

This document introduces the foundational concepts of cryptology, encompassing cryptography and cryptanalysis, with a focus on their roles in secure communications. It outlines cryptographic functions and terminologies such as encryption and decryption methods, including symmetric and asymmetric algorithms. It also discusses the importance and mechanics of public-key infrastructures (PKIs) and digital certificates for authenticating encrypted exchanges. Notable algorithms like RSA, El Gamal, and ECC, along with digital signature techniques such as DSA and ECDSA, are explained in relation to...

cryptography
RSA algorithm
public-key infrastructure
4p0
TD0 – Introduction Sécurité Informatique

This document is an examination on the basics of computer security. It includes multiple-choice questions focusing on different types of cyber attacks and security concepts. Students are required to select the correct answers for various scenarios related to information security.

attaque
informations
seau
5p0
Systèmes de détections des intrusions

The document discusses Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) in network security. IDS monitors traffic and raises alerts based on abnormal patterns, with methods such as signature-based or anomaly-based detection, while IPS actively prevents intrusions by analyzing and blocking malicious traffic in real-time. IDS includes Network IDS (NIDS) for passive monitoring of network traffic and Host IDS (HIDS) for analyzing local host activities. Key issues include false positives and the need for improved algorithms to correlate alerts and detect complex attacks.

IDS
IPS
anomaly-based detection
29p0
Panorama des menaces recensées par le CERT-RENATER

Le CERT-RENATER présente un aperçu des menaces informatiques et de la sécurité sur ses réseaux. Il a pour mission de coordonner et détecter les incidents de sécurité, et de fournir des informations à son réseau de correspondants. Les incidents et malwares les plus courants observés en 2011-2012 sont détaillés, soulignant l'importance de la veille et de la prévention des menaces.

nombre
jours
renater
22p0
Sécurité Informatique - Examen Principal 2017/2018

This document describes a comprehensive exam on computer security that assesses knowledge across multiple topics including cryptographic techniques, system vulnerabilities, and intrusion detection systems. Questions span from theoretical concepts like steganography and encryption key usage to practical applications like breaking encryption algorithms using techniques such as linear cryptanalysis. The methodology includes question-based assessments as well as problem-solving exercises like algorithm analysis and risk evaluation. Findings help gauge the student’s ability to understand and app...

confidentiality
cryptanalysis
symmetric encryption
6p0
Sécurité Informatique

This document provides an in-depth overview of information security covering topics such as threats, vulnerabilities, encryption, and defensive strategies. It highlights key objectives like confidentiality, integrity, and availability, while exploring evolving risks due to technological advancements and diverse attacker motivations. Strategies and tools such as firewalls, honeypots, ISO standards, and anti-malware are analyzed for securing systems, networks, and applications. Real-world examples such as botnets, virus propagation, and social engineering attacks demonstrate the practical rel...

security
ISO 27000
botnets
283p0
SYN cookie - Wikipédia

SYN cookies are specially crafted initial sequence numbers used in server-side TCP connections to mitigate SYN flood attacks. They function by leveraging the network to temporarily store connection information instead of maintaining it locally, thus minimizing resource allocation until verification. While effective against flooding, syncookies limit TCP option functionality, potentially reducing network efficiency, and introduce vulnerabilities if the authentication mechanism is guessed by attackers. On Linux, their configuration is managed via the 'tcp_syncookies' parameter in the sysctl.c...

SYN cookies
TCP packet format
SYN flooding
3p0
Les principales attaques

This document outlines major cyber attack types and preventive measures. It discusses viruses, their propagation methods, and antivirus solutions. It highlights attacks like denial of service (DoS), network sniffing, system intrusion, and trojans, alongside their respective countermeasures like firewalls, switches, and secure access policies. Moreover, it introduces social engineering as an attack vector and emphasizes employee training to mitigate these threats.

cyber attack
DoS
sniffer
2p0
Cryptographie et sécurité informatique

Ce document traite des concepts fondamentaux de la cryptographie, en se concentrant sur l'algorithme de Hill et la méthode RSA. Il présente des exercices pratiques pour coder et décoder des messages, ainsi qu'une analyse de fréquence pour déchiffrer les textes cryptés. Les étudiants apprennent à appliquer des méthodes mathématiques pour renforcer la sécurité des communications.

chiffrement
lettres
quot
2p0
Examen de Sécurité Informatique

Cet examen évalue la compréhension des concepts de sécurité informatique, y compris le chiffrement symétrique et asymétrique. Les étudiants doivent résoudre des exercices basés sur le système RSA et les pratiques de sécurité réseau. Un audit de sécurité est également demandé pour une clinique fictive.

clinique
nmap
assurer
3p0
La sécurité des machines

Cette formation aborde la législation en matière de sécurité des machines et les règles de conduite à suivre. Elle comprend des évaluations continues et un examen final pour certifier les connaissances acquises. Les participants doivent respecter un taux de présence de 90% minimum.

machines
risque
curit
46p0
Atelier 6 : Système d’authentification

This document outlines the development of a basic authentication system using PHP and MySQL. It details the creation of a database, a 'users' table, and the implementation of an object-oriented PHP 'USER' class with methods for user registration, login, session management, and logout. A database connection is established through PDO, and security measures include password hashing with `password_hash()` and `password_verify()`. Additionally, step-by-step instructions are provided to create `index.php` (login page), `sign-up.php` (registration page), and `home.php` (user dashboard), ensuring...

authentication system
password_hash
object-oriented programming
Institut Supérieur des Études Technologiques14p0
Cours Sécurité Informatique – Chapitre 2: Notions de la Cryptologie

This document explores foundational concepts in cryptology, specifically cryptography and cryptanalysis. It defines cryptographic functions and systems, such as symmetric and asymmetric encryption methods, and examines their principles, algorithms, and security implications. It also discusses key management practices, including the generation, storage, and maintenance of keys, along with the role of Public Key Infrastructure (PKI) and certification authorities. Finally, it highlights the importance of cryptographic robustness against attacks and the distribution of secure keys.

Cryptology
AES
Cryptanalysis
20p0
Description détaillée de la fonction de hachage MD5

Ce document fournit une description détaillée de l'algorithme de hachage MD5, en expliquant le fonctionnement des registres et des étapes de calcul. Les opérations de hachage sont réalisées à travers quatre tours, chacun impliquant des opérations spécifiques sur les registres. La méthode inclut des initialisations, des sauvegardes et les détails des opérations mathématiques impliquées.

abcd
bcda
cdab
2p0
GnuPG Guide

This document provides a comprehensive guide on using GnuPG for secure communication. It covers the generation of key pairs, creation of revocation certificates, and the process of publishing public keys. Additional topics include verifying identities through fingerprinting and signing keys to establish trust.

publique
gnupg
peut
7p0
Introduction to Computer Security

This document presents an introduction to computer security, covering the fundamental concepts, threats, and defenses in information systems. It outlines the objectives of the course as well as the critical components of confidentiality, integrity, and availability (CIA). Additionally, it describes various cryptographic techniques and the importance of securing operating systems and networks.

risque
introduction
2014
50p0
Sécurité informatique

Ce document aborde les concepts fondamentaux de la cryptographie et de l'authentification. Il détaille les techniques d'identification, les méthodes de cryptage ainsi que les bonnes pratiques en matière de gestion des mots de passe. La mise en place d'une authentification forte est également discutée.

cryptographie
2014
laabidi
139p0
TD1: Cryptographie

This document comprises exercises focused on cryptography, including the Hill cipher and RSA encryption techniques. It explores encoding texts using mathematical algorithms and the implications of frequency analysis in breaking encoded messages. Additionally, it provides practical exercises to calculate key values using examples.

chiffrement
lettres
quot
1p0
II3-Sécurité Informatique

This document presents exercises on cryptography, including the Hill cipher and RSA algorithms. It covers encoding methods, frequency analysis, and the decryption process. Students are tasked with both theoretical questions and practical exercises to apply their understanding of cryptographic methods.

chiffrement
lettres
quot
4p0
Attaques MITM avec ARP Spoofing

This document details techniques for performing Man in the Middle (MITM) attacks using arp-scan and arpspoof. It explains how to manipulate ARP replies to deceive devices on a network. Additionally, it covers SSL stripping methods and the significance of certificate validation.

certificat
faire
https
4p0
GnuPG: Utilisation et Fonctionnalités

Ce document explique comment utiliser GnuPG pour la communication sécurisée en utilisant la cryptographie asymétrique. Il couvre la génération de clés, la création de certificats de révocation, et l'importation et exportation des clés publiques. Des commandes et étapes précises sont fournies pour aider l'utilisateur à maîtriser GnuPG.

publique
gnupg
peut
7p0
Crypto et sécurité de l’information

This document discusses the importance of information security and the evolution of threats associated with internet usage. It introduces the basic principles of security, including authentication, access control, and data integrity, and emphasizes the role of cryptography in ensuring privacy and non-repudiation. The document also highlights various types of cryptosystems and the emerging challenges posed by advancements in technology.

tatouage
images
cryptosyste
ENIT76p0
Crypto et sécurité de l’information

This document covers the fundamentals of symmetric cryptography, focusing on various algorithms such as substitution and transposition. It provides an overview of classic ciphers and their improvements in modern cryptography. Real-world examples, including the DES and AES algorithms, are discussed in detail.

cryptage
algorithmes
bloc
79p0

Autres ressources en sécurité informatique