CompTIA SecurityX (CAS-005)Security EngineeringMedium
A critical infrastructure organization is implementing a new Industrial Control System (ICS) for its power grid. Due to the high-stakes nature of the environment, the security architect must ensure that all communications between field devices (PLCs, RTUs) and the central control system are not only encrypted but also protected against replay attacks and unauthorized modifications. Which cryptographic primitive, when properly implemented, would provide the BEST assurance of both data integrity and authenticity for these communications?
- ASymmetric Encryption (e.g., AES-256)
- BMessage Authentication Code (MAC)
- CHash Function (e.g., SHA-256)
- DDigital Signature
Show answer & explanationAnswer & explanation
Correct answer: B. Message Authentication Code (MAC)
A Message Authentication Code (MAC) provides both data integrity (ensuring the message hasn't been altered) and authenticity (verifying the sender's identity through a shared secret key). This protects against replay attacks when combined with sequence numbers or timestamps.
Why the other options are wrong
- A. Symmetric encryption provides confidentiality but does not inherently guarantee data integrity or authenticity against active attackers without additional mechanisms.
- C. A hash function provides data integrity (detecting accidental changes) but does not provide authenticity or protection against intentional tampering unless combined with a secret key (which then becomes a MAC).
- D. A digital signature provides authenticity and integrity, but typically relies on asymmetric cryptography, which can be computationally intensive for constrained ICS devices and does not natively protect against replay attacks without additional mechanisms like sequence numbers.
Message Authentication Code (MAC)
A short piece of information used to authenticate a message and provide integrity and authenticity assurances. It is generated using a secret key and a cryptographic hash function.
- Requires a shared secret key between sender and receiver.
- Provides both data integrity and message authenticity.
- Protects against replay attacks when combined with nonces/timestamps.
Memory trick: MACs Authenticate Critical Systems.