Cybersecurity Web Security & OWASP Top 10

Network Security, Cryptography, and Secure Access Controls

⏱ 15 min read • Level: Intermediate • Updated: Sep 30, 2026

Introduction: Securing Data in Transit and Access Perimeters

Protecting modern distributed applications requires securing communication channels across untrusted networks and enforcing strict identity verification. As infrastructure shifts from monolithic on-premises data centers to multi-cloud architectures, traditional network perimeter security has been replaced by Zero Trust Architecture—a model based on the principle of “never trust, always verify.”

Core Concepts: Cryptography Fundamentals

Modern cryptography provides confidentiality, integrity, and non-repudiation through two primary mathematical paradigms:

  • Symmetric Key Cryptography: The same shared secret key is used for both encryption and decryption. Algorithms like AES-256-GCM provide high computational throughput and authenticated encryption.
  • Asymmetric Key Cryptography (Public-Key): Uses a mathematically linked key pair: a public key for encryption/signature verification and a private key for decryption/signing. Algorithms include RSA-4096 and elliptic curve cryptography (ECDSA, Ed25519).
  • Cryptographic Hash Functions: One-way deterministic functions mapping arbitrary input to fixed-size digests (e.g. SHA-256, SHA-3). Password hashing requires slow, memory-hard algorithms with work factors (e.g. bcrypt, Argon2id, PBKDF2).

Transport Layer Security (TLS 1.3)

TLS secures communication between clients and servers. TLS 1.3 optimizes the handshake process into a single round-trip (1-RTT) while eliminating outdated cipher suites (such as RC4, DES, and CBC-mode ciphers). During the handshake:

  1. The client sends supported cipher suites and key share parameters (ClientHello).
  2. The server selects the cipher suite, provides its digital certificate (issued by a trusted Certificate Authority), and provides its key share (ServerHello).
  3. Both parties independently derive symmetric session keys using Diffie-Hellman key exchange (Forward Secrecy).
  4. All subsequent traffic is encrypted using high-speed symmetric encryption.

Modern Access Control & Identity Architecture

Access control determines what authenticated users can do within an application:

  • Role-Based Access Control (RBAC): Assigns permissions to roles (e.g. Admin, Editor, Viewer), and users to roles.
  • Attribute-Based Access Control (ABAC): Dynamically evaluates policies based on user attributes, resource attributes, and environmental context (e.g. time of day, IP subnet).
  • JSON Web Tokens (JWT): Stateless authentication tokens containing a header, payload (claims), and cryptographic signature. Tokens must be signed with strong algorithms (e.g. RS256) and verified on every request.

Deep Dive: Modern Transport Layer Security (TLS 1.3)

Transport Layer Security (TLS) forms the foundational cryptographic backbone of modern internet communication. TLS 1.3, finalized in RFC 8446, introduced major performance and security enhancements over TLS 1.2 by fundamentally redesigning the cryptographic handshake. In TLS 1.2, establishing an encrypted session required two complete network round-trips (2-RTT) between the client and server before application data could be transmitted. TLS 1.3 reduced this handshake to a single round-trip (1-RTT), and introduced 0-RTT resumption for returning clients.

More critically, TLS 1.3 completely excised legacy cryptographic algorithms that had proven vulnerable to cryptanalytic attacks. Deprecated algorithms include:

  • Static RSA Key Exchange: In static RSA key exchange, if an adversary records encrypted network traffic and subsequently compromises the server’s private key years later, they can decrypt all historical traffic retroactively. TLS 1.3 mandates Ephemeral Diffie-Hellman (DHE/ECDHE), guaranteeing Perfect Forward Secrecy (PFS): every session generates ephemeral keys that are destroyed immediately after session teardown, ensuring past sessions cannot be decrypted even if long-term certificates are compromised.
  • CBC Mode Ciphers and Legacy Hashes: CBC (Cipher Block Chaining) mode ciphers—frequently susceptible to padding oracle attacks (e.g., POODLE)—along with SHA-1 and MD5 hashing algorithms were completely removed. TLS 1.3 exclusively permits Authenticated Encryption with Associated Data (AEAD) ciphers, primarily AES-GCM and ChaCha20-Poly1305.

Enterprise Identity Federation: OAuth 2.0 and OpenID Connect (OIDC)

Modern access control delegates identity management to dedicated identity providers (IdPs) using open standards. A frequent point of confusion among engineers is the distinction between authentication and authorization:

  1. OAuth 2.0 (Authorization Framework): OAuth 2.0 is designed strictly for delegated access authorization. It allows a third-party application to obtain limited access to a user’s HTTP resources on an API server without exposing user passwords. OAuth issues an Access Token (often a cryptographically signed JSON Web Token or opaque string) that API gateways validate to grant resource access. Crucially, OAuth 2.0 does not specify a mechanism for communicating user identity.
  2. OpenID Connect (Authentication Layer): Built directly on top of OAuth 2.0, OIDC adds an identity layer. During the authorization handshake, the IdP issues an ID Token in addition to the access token. The ID Token is a verifiable JWT containing standard identity claims (such as sub, email, iss, and exp), allowing client applications to verify who the user is and establish local user sessions securely.

Common Mistakes & Practical Pitfalls

  • Using Fast Hash Functions for Passwords: Hashing passwords with MD5, SHA-1, or plain SHA-256 allows attackers to compute billions of guesses per second on modern GPUs. Always use memory-hard functions like bcrypt or Argon2id with a unique cryptographic salt.
  • JWT alg: "none" Attack: Misconfigured JWT libraries that accept unsigned tokens with the algorithm header set to "none" permit attackers to forge arbitrary administrative claims. Always enforce expected algorithms explicitly.
  • Hardcoding Secrets in Code Repositories: Storing private keys, API credentials, or database passwords in source code exposes entire infrastructures to leakages during code commits. Always inject secrets via environment variables or secret management services.

Exam Connection: Certification Blueprint Alignment

This module aligns directly with network and cryptographic concepts on the Cybersecurity Fundamentals Assessment:

  • Distinguishing between symmetric (AES) and asymmetric (RSA/ECC) encryption use cases.
  • Explaining the mechanics of Certificate Authorities (CAs) and public key infrastructure (PKI).
  • Understanding password hashing best practices (salting, stretching with bcrypt/Argon2).
  • Recognizing principles of Zero Trust and least privilege access controls.

Key Takeaways

  • Symmetric encryption provides high-speed bulk data encryption; asymmetric encryption enables key exchange and digital signatures.
  • TLS 1.3 establishes encrypted transport tunnels using forward secrecy to protect against retroactive decryption.
  • Passwords must always be hashed using slow, memory-hard algorithms (bcrypt/Argon2) with unique salts.

Knowledge Check

  1. Why is symmetric encryption preferred over asymmetric encryption for bulk data transfer?
    Answer: Symmetric encryption algorithms (like AES) are orders of magnitude faster and require far less computational overhead than asymmetric algorithms (like RSA).
  2. What is the role of a cryptographic salt in password storage?
    Answer: A salt ensures that identical passwords produce completely different hash digests, neutralizing precomputed rainbow table attacks.
  3. What does “Forward Secrecy” guarantee in TLS communication?
    Answer: Even if a server’s long-term private key is compromised in the future, past encrypted sessions cannot be decrypted because session keys were generated ephemerally and discarded.

Next Step

Congratulations on completing the Cybersecurity learning path! Test your knowledge on the Cybersecurity Fundamentals Assessment or explore the Cybersecurity Skill Hub.

Visual Learning

Watch & Learn

Curated video tutorials and deep-dives illustrating these concepts in practice.

Primary Specifications

Official Documentation

Authoritative references and documentation directly from language and standard maintainers.

Curated Articles

Recommended Reading

Hand-picked engineering articles, tutorials, and practical perspectives on this topic.

Formative Practice

Test Your Understanding of Web Security & OWASP Top 10

Apply what you just learned with curated practice questions and in-depth explanations.

Practice Questions →
Advertisement