Cybersecurity is increasingly gaining greater relevance, especially within companies, which are inevitably custodians of sensitive data. The number of cyber attacks is growing day by day and it is essential to prepare in advance by looking for a solution to prevent such an eventuality.

Ensuring constant, multi-layered total coverage when it comes to cybersecurity is nearly impossible. However, there are expedients that allow us to prevent and find solutions to this great problem; encryption is one of them.

If we imagine cybersecurity as a chain, we can say that encryption represents one of its fundamental links.

In history, since the time of Julius Caesar, cryptography has played an extremely important role in decryption, bringing a certain advantage.

Just think of the Second World War, the Enigma machine or the Lorenz machine; the latter have over time constituted an important springboard for the development of cryptography.

What exactly is encryption?

Cryptography, or ciphering, is a technique that allows us to encrypt a message, disguising it and making it incomprehensible to everyone except its recipient. Such messages where no type of decoding is required, also called "plaintexts", undergo two processes: encryption and coding. An encryption algorithm and the respective key help to create a crypto-system.

Encryption is subject to external threats

Four main sources of encryption threats can be identified:

  • Interception: i.e. the reading of the content of the message by observers in possession of the appropriate tools to be able to decrypt it. It can also happen legally, for example in the case of a magistrate whose aim is to track down a criminal organisation;
  • modification of the message: involves the modification of the content by third parties without the knowledge of both interlocutors, thus conveying the message according to their intentions;
  • sending under a false name: i.e. interception, modification of the message and creation of a new message by impersonating another sender, taking possession of authority and credentials;
  • repudiation of podestà: in other words the refusal to send a message, which represents the simplest threat to untangle as to date the sending of a message leaves clear and traceable electronic evidence.

The role of cryptanalysis

If the task of cryptography is to try to safeguard data, cryptanalysis deals with analyzing the encrypted texts in order to attack secure communication. Cryptography and cryptanalysis go hand in hand: the more complex the encryption systems used, the more complex the cryptanalysis systems adopted must be.

Develop greater security in cryptography

Some functional solutions may be the following:

  • Pay attention to the length of the key; in fact, a key that is too short could be easily reassembled
  • Include a large number of keys: this allows for poor success on the part of the attacker despite resorting to a "brute force" approach, i.e. an exhaustive search of all possible combinations
  • Make the work factor needed to break the encryption system barrier much higher; in a cost-benefit balance, if the benefit that the attacker can have from decoding the message is lower than the effort he has to make to decode it, he will most likely give up.

The Master in Cybersecurity Culture & Governance offers the opportunity to delve deeper into this topic and prevent the most frequent and harmful cyber incidents. Thanks to practical attack and defense simulation sessions for ethical purposes, you will acquire expertise in the main techniques and procedures for responding to cyber attacks. The master's degree, starting in mid-June 2022, is aimed at professionals, undergraduates and graduates from the Faculties of Computer Science, Engineering, Law and Economics, and will be delivered in live mode streaming.