Cybersecurity & Cryptography
Encryption, digital signatures, authentication, key management and the security principles behind protecting modern applications and communications.
Cybersecurity is one of the areas I most enjoyed revisiting because it sits at the intersection of mathematics, software engineering, networks and distributed systems.
Many security mechanisms are part of everyday engineering work: TLS protects APIs, hashes verify data integrity, digital signatures authenticate software and tokens carry identity information between services. Yet it is surprisingly easy to use these mechanisms without fully understanding the assumptions behind them.
Why is AES fundamentally different from RSA? How can two parties establish a shared secret over an insecure network? What exactly does a digital signature prove? Why can a secure cryptographic primitive still be used in an insecure system? How does an attacker move from a small web vulnerability to a complete application compromise?
This section combines two perspectives: the cryptographic primitives that provide confidentiality, integrity and authenticity, and the application-security mindset needed to understand how those guarantees can fail when systems are designed or implemented incorrectly.
Topics in This Section
Symmetric Cryptography · AES · Block Ciphers · Public-Key Cryptography · RSA · Diffie–Hellman · Discrete Logarithms · Elliptic-Curve Cryptography · Digital Signatures · Hash Functions · MACs · Key Management · Post-Quantum Cryptography · Authentication · Authorization · Session Security · Access Control · Injection · SQL Injection · XSS · CSRF · Application Logic · Secure Coding · Web Application Security
Understanding Cryptography
Christof Paar, Jan Pelzl & Tim Güneysu
2nd Edition — Springer
Level
Foundation → Advanced
Best for
Understanding modern applied cryptography from symmetric encryption to public-key systems, digital signatures and post-quantum algorithms.
Understanding Cryptography is the book I use when I want to understand the mechanisms behind cryptographic systems rather than simply learn which algorithm to choose.
The book progressively moves from symmetric cryptography to public-key algorithms, elliptic curves, digital signatures, hash functions, post-quantum cryptography and key management.
What I particularly value is its engineering perspective. The mathematics is important, but the algorithms are consistently connected to the security properties they provide and to the problems that appear when those algorithms are implemented in real systems.
What I Use It For
- understanding confidentiality, integrity and authenticity;
- symmetric versus asymmetric cryptography;
- stream and block ciphers;
- AES;
- block-cipher modes of operation;
- public-key cryptography;
- RSA;
- Diffie–Hellman key exchange;
- discrete-logarithm cryptosystems;
- elliptic-curve cryptography;
- digital signatures;
- hash functions;
- Message Authentication Codes;
- post-quantum cryptography;
- key establishment and key management;
- connecting cryptographic primitives to secure protocols.
Chapters Worth Reading
Cryptography Foundations
Chapter 1 — Introduction to Cryptography and Data Security
The security goals, terminology and basic principles needed to understand the rest of the book.
- confidentiality;
- integrity;
- authentication;
- cryptographic primitives;
- basic cryptanalysis;
- security assumptions.
Symmetric Cryptography
Chapter 2 — Stream Ciphers
Encryption based on pseudorandom keystreams and the security requirements of stream-cipher systems.
Chapter 3 — The Data Encryption Standard and Alternatives
DES as an important historical example for understanding block-cipher design and cryptanalysis.
Chapter 4 — The Advanced Encryption Standard
The structure and operation of AES, one of the central symmetric cryptographic primitives used in modern systems.
Chapter 5 — More About Block Ciphers
How block ciphers are turned into practical encryption schemes through different modes of operation.
Public-Key Cryptography
Chapter 6 — Introduction to Public-Key Cryptography
The mathematical and conceptual transition from shared-secret cryptography to asymmetric systems.
Chapter 7 — The RSA Cryptosystem
RSA encryption, the mathematics behind it and the security assumptions on which it depends.
Diffie–Hellman & Discrete Logarithms
Chapter 8 — Cryptosystems Based on the Discrete Logarithm Problem
Cryptographic systems whose security is based on the difficulty of solving discrete logarithms.
- Diffie–Hellman key exchange;
- discrete logarithms;
- ElGamal-style cryptography;
- security assumptions behind key establishment.
Elliptic-Curve Cryptography
Chapter 9 — Elliptic Curve Cryptosystems
How elliptic curves provide public-key cryptography with much smaller key sizes than traditional finite-field systems for comparable security levels.
- elliptic curves over finite fields;
- elliptic-curve groups;
- Elliptic Curve Discrete Logarithm Problem;
- ECC-based cryptosystems.
Digital Signatures
Chapter 10 — Digital Signatures
How asymmetric cryptography can provide origin authentication, integrity and non-repudiation properties.
- signature principles;
- RSA signatures;
- discrete-logarithm signatures;
- elliptic-curve signatures;
- signature security.
Hash Functions
Chapter 11 — Hash Functions
One-way functions used throughout modern security protocols for integrity, signatures and authentication.
- preimage resistance;
- second-preimage resistance;
- collision resistance;
- SHA-family functions;
- SHA-3;
- applications of cryptographic hashes.
Post-Quantum Cryptography
Chapter 12 — Post-Quantum Cryptography
Cryptographic approaches designed to remain secure against attacks from sufficiently capable quantum computers.
- the quantum threat to public-key cryptography;
- Shor’s algorithm;
- Grover’s algorithm;
- lattice-based cryptography;
- code-based cryptography;
- hash-based signatures;
- post-quantum key establishment and signatures.
Message Authentication Codes
Chapter 13 — Message Authentication Codes
How symmetric keys can be used to provide integrity and message authenticity.
- MAC security;
- hash-based MACs;
- HMAC;
- block-cipher-based MACs.
Key Management
Chapter 14 — Key Management
The practical problem that appears after choosing secure cryptographic algorithms: how keys are generated, distributed, protected and replaced.
- key establishment;
- key distribution;
- public-key infrastructures;
- certificates;
- key lifecycle;
- trust relationships.
My Suggested Learning Path
Security Foundations
Chapter 1
Symmetric Cryptography
Chapters 2–5
Public-Key Cryptography
Chapters 6–9
Signatures & Hashes
Chapters 10–11
Post-Quantum Cryptography
Chapter 12
Authentication
Chapter 13
Key Management
Chapter 14
The Web Application Hacker’s Handbook
Dafydd Stuttard & Marcus Pinto
2nd Edition — Wiley
Level
Intermediate → Advanced
Best for
Understanding how web-application vulnerabilities emerge and developing a systematic security-testing mindset.
The Web Application Hacker’s Handbook approaches security from the opposite direction: instead of beginning with cryptographic primitives, it begins with the application and asks how its assumptions can be broken.
The book is older than many of the technologies used in today’s web stacks, so I treat it primarily as a source of enduring application-security principles rather than as a catalogue of current tools or frameworks.
Its greatest value for me is the methodology: understand the application, identify where trust changes, inspect how data crosses those boundaries and systematically challenge the assumptions made by authentication, authorization, session management and input processing.
What I Use It For
- thinking like an attacker;
- understanding web-application attack surfaces;
- authentication weaknesses;
- session-management vulnerabilities;
- authorization and access-control failures;
- SQL and other injection vulnerabilities;
- backend-component attacks;
- business-logic vulnerabilities;
- Cross-Site Scripting;
- Cross-Site Request Forgery and client-side attacks;
- information disclosure;
- application-server weaknesses;
- source-code security review;
- systematic vulnerability assessment.
Chapters Worth Reading
Web Security Foundations
Chapter 1 — Web Application (In)security
Why web applications present such a large attack surface and how application vulnerabilities emerge.
Chapter 2 — Core Defense Mechanisms
The main mechanisms applications use to defend themselves and the assumptions attackers try to break.
- authentication;
- session management;
- access control;
- input handling;
- attack surfaces.
Web Application Technologies
Chapter 3 — Web Application Technologies
The protocols, browser technologies and server-side mechanisms on which web applications are built.
Mapping the Attack Surface
Chapter 4 — Mapping the Application
Systematically discovering application functionality, entry points and potential trust boundaries before attempting to identify vulnerabilities.
Client-Side Trust
Chapter 5 — Bypassing Client-Side Controls
Why security decisions cannot safely depend on controls enforced only by the client.
Authentication & Sessions
Chapter 6 — Attacking Authentication
Weaknesses in login systems, credential handling and account-recovery mechanisms.
Chapter 7 — Attacking Session Management
How weaknesses in session identifiers and lifecycle management can allow attackers to impersonate legitimate users.
Authorization & Access Control
Chapter 8 — Attacking Access Controls
How applications fail when they authenticate users correctly but do not consistently enforce what those users are allowed to do.
Injection & Backend Systems
Chapter 9 — Attacking Data Stores
Injection vulnerabilities involving databases and other data-processing systems.
Chapter 10 — Attacking Back-End Components
Attacks that exploit unsafe interaction between the application and underlying operating-system or infrastructure components.
Business Logic
Chapter 11 — Attacking Application Logic
Security failures that arise not from an unsafe programming primitive but from incorrect assumptions about how users will interact with a business process.
This is one of the sections I find particularly valuable because business-logic vulnerabilities often cannot be discovered simply by searching for a known technical pattern.
Cross-Site Scripting & Browser Attacks
Chapter 12 — Attacking Users: Cross-Site Scripting
How untrusted data can cross into executable browser contexts and affect other users.
Chapter 13 — Attacking Users: Other Techniques
Additional attacks that exploit browser behaviour and the trust relationship between users and applications.
Information Disclosure & Architecture
Chapter 15 — Exploiting Information Disclosure
How apparently minor information leaks can reveal implementation details useful for later attacks.
Chapter 17 — Attacking Application Architecture
Security issues created by architectural assumptions and interactions between application components.
Chapter 18 — Attacking the Application Server
Security weaknesses below the application itself in servers and deployment infrastructure.
Secure Code Review
Chapter 19 — Finding Vulnerabilities in Source Code
Moving from black-box application behaviour to the code paths responsible for security-sensitive decisions.
Security-Testing Methodology
Chapter 21 — A Web Application Hacker’s Methodology
A structured process for approaching application-security testing rather than searching randomly for individual vulnerabilities.
My Suggested Learning Path
Understand the Attack Surface
Chapters 1–4
Identity & Authorization
Chapters 6–8
Injection & Backend Attacks
Chapters 9–10
Business Logic & Browser Security
Chapters 11–13
Architecture & Code
Chapters 15, 17–19
Testing Methodology
Chapter 21
Why I Keep Both Books
Understanding Cryptography
Security primitive first.
- AES;
- RSA;
- Diffie–Hellman;
- elliptic curves;
- digital signatures;
- hash functions;
- MACs;
- post-quantum cryptography;
- key management.
The Web Application Hacker’s Handbook
System weakness first.
- authentication;
- sessions;
- authorization;
- injection;
- XSS;
- business logic;
- architecture;
- secure code review;
- testing methodology.
One book explains how security guarantees are constructed. The other shows how those guarantees can disappear when the surrounding application makes the wrong assumptions.
Topic → Book Map
Encryption
Understanding Cryptography: Chapters 2–9
Authentication & Integrity
Understanding Cryptography: Chapters 10–14
Web Application Hacker’s Handbook: Chapters 6–7 for application-level authentication and sessions
Digital Signatures
Understanding Cryptography: Chapter 10
Hash Functions & MACs
Understanding Cryptography: Chapters 11 and 13
Post-Quantum Cryptography
Understanding Cryptography: Chapter 12
Authentication & Session Security
Web Application Hacker’s Handbook: Chapters 6–7
Authorization
Web Application Hacker’s Handbook: Chapter 8
Injection
Web Application Hacker’s Handbook: Chapters 9–10
Business-Logic Security
Web Application Hacker’s Handbook: Chapter 11
Browser-Side Attacks
Web Application Hacker’s Handbook: Chapters 12–13
Secure Code Review
Web Application Hacker’s Handbook: Chapter 19
How I Use These Books
I find cybersecurity easier to reason about when I separate the security property I need from the mechanism used to provide it.
“I need to prevent anyone who intercepts this message from reading it.”
That starts with confidentiality and leads to encryption, key management and the choice between symmetric and asymmetric cryptography.
“I do not care whether the message is secret, but I must know that nobody modified it.”
That leads to integrity, cryptographic hashes and Message Authentication Codes.
“Anyone should be able to verify that this message was produced by a specific private key holder.”
That points toward asymmetric cryptography, digital signatures and public-key infrastructures.
“The login mechanism is cryptographically secure, so why can a user still access another user’s data?”
That reveals the difference between authentication and authorization and moves the problem from cryptographic security into application security.
Start from the security property, identify the mechanism that provides it, then look for every assumption around that mechanism that could invalidate the guarantee.
Related Areas
Security and cryptography connect naturally with almost every other area in this library.
Computer Networks
TLS, VPNs, authentication, firewalls and secure network communication.
Software Architecture & Microservices
Identity, authorization, Zero Trust, API security and service-to-service authentication.
Distributed Systems
Trust, Byzantine behaviour, authenticated communication and distributed consensus.
Blockchain & Smart Contracts
Hashes, digital signatures, public keys, consensus and cryptographic proofs.
Privacy-Enhancing Technologies
Zero-Knowledge Proofs, homomorphic encryption, secure computation and differential privacy.
Post-Quantum Cryptography
Quantum-resistant key establishment, digital signatures and migration away from vulnerable public-key algorithms.