Skip to content

Lesson pack 2 · Foundation · 90 minutes

Classical ciphers and frequency analysis

Break Caesar, Vigenere, and arbitrary substitution using letter statistics - and learn why statistics beat guessing.

Print this page for a paper plan - the navigation and links drop out.Student-facing version

Before the session

  • Nothing to install. Students need a browser and https://ctfpal.com. Confirm the room can reach it once; after that it works offline.
  • Read the lesson yourself first - about 7 minutes.
  • Have one worked example ready to paste. The classroom link builder on the instructor page turns it into a URL that opens preloaded.

Objectives

Written as things a student can do afterwards, so they can be assessed rather than asserted.

  1. Break a Caesar shift with chi-squared scoring rather than by reading 26 candidates
  2. Recover a Vigenere key length using the index of coincidence, then the key itself per column
  3. Distinguish a transposition from a substitution by looking at letter frequencies
  4. Recognise a polygraphic or fractionating cipher - Playfair, Hill, ADFGVX - from what single-letter statistics fail to say
  5. Explain why short ciphertexts defeat statistical attacks

Running order (90 min)

TimeWhat happens
0:00-0:09Frame the problemWhat the category looks like when you meet it cold, and why the naive approach fails.
0:09-0:27Teach the methodThe technique itself, on the board or from the lesson. No tools open yet.
0:27-0:50Demonstrate liveSame technique, in the workspace, on your worked example. Narrate every choice.
0:50-1:21Practice setStudents work the challenges. Circulate rather than present.
1:21-1:30Checkpoint and wrapCollect the artefact, name what comes next.

Tools used

  • Cipher identifier and automatic decoder - Paste anything and find out what it is. ctfpal runs every decoder and rotation, including multi-pass cascades, and ranks results by English-likeness and flag patterns.https://ctfpal.com/?tool=cipher-identifier
  • Caesar cipher decoder with automatic shift detection - Break a Caesar shift without guessing. ctfpal scores all 26 rotations by chi-squared letter frequency and puts the English one first.https://ctfpal.com/?tool=caesar-cipher
  • ROT13 decoder - Apply ROT13 (and ROT47) instantly. ROT13 is its own inverse, so the same operation encodes and decodes.https://ctfpal.com/?tool=rot13
  • Atbash cipher decoder - Decode Atbash, the keyless substitution that maps A to Z, B to Y, and so on. Its own inverse.https://ctfpal.com/?tool=atbash-cipher
  • Affine cipher solver - Brute-force every valid affine key pair and rank the 312 candidate decryptions by English-likeness.https://ctfpal.com/?tool=affine-cipher
  • Vigenere cipher solver with automatic key recovery - Decrypt Vigenere with a known key, or recover the key from ciphertext alone using index-of-coincidence period detection and per-column chi-squared.https://ctfpal.com/?tool=vigenere-cipher
  • Monoalphabetic substitution cipher solver - Break an arbitrary substitution cipher automatically by hill-climbing on quadgram statistics - no key, no guessing.https://ctfpal.com/?tool=substitution-cipher-solver
  • Rail fence cipher solver - Brute-force rail fence transposition across 2-8 rails and every starting offset, ranked by English-likeness.https://ctfpal.com/?tool=rail-fence-cipher
  • Playfair cipher decoder - Decrypt Playfair with a known keyword, using the 5x5 digraph square. Recognisable by its even length and total absence of doubled letters.https://ctfpal.com/?tool=playfair-cipher
  • Hill cipher solver - Encrypt and decrypt with matrix keys over mod 26, including matrix inversion and known-plaintext key recovery.https://ctfpal.com/?tool=hill-cipher
  • Bacon cipher decoder - Decode Baconian ciphers, including the versions hidden in letter case, font changes, or two repeated symbols.https://ctfpal.com/?tool=bacon-cipher
  • ADFGVX cipher decoder - Decrypt ADFGX and ADFGVX - a Polybius substitution followed by a columnar transposition, and unmistakable from its six-letter alphabet.https://ctfpal.com/?tool=adfgvx-cipher
  • Enigma machine simulator and cracker - Run Enigma I, M3 and the four-rotor M4 in the browser, and recover the rotor order and start positions of an unplugged machine by brute force.https://ctfpal.com/?tool=enigma

Reading

  • Chi-squared, index of coincidence, and why classical ciphers fall - 7 min. Caesar, Vigenère, and substitution ciphers do not need guesswork - they need two statistics. How chi-squared scores a candidate plaintext, how the index of coincidence recovers a key length, and how to combine them into an attack that runs in milliseconds.

Practice set

Real picoCTF challenges tagged with this module’s techniques, easiest first. Assign the first three in class and the rest as homework.

  1. 13 - picoCTF 2019, easy
  2. interencdec - picoCTF 2024, easy
  3. Mod 26 - picoCTF 2021, easy
  4. The Numbers - picoCTF 2019, easy
  5. caesar - picoCTF 2019, medium
  6. credstuff - picoCTF 2022, medium
  7. Easy1 - picoCTF 2019, medium
  8. Guess My Cheese (Part 1) - picoCTF 2025, medium
  9. Hidden Cipher 1 - picoCTF 2026, medium
  10. Hidden Cipher 2 - picoCTF 2026, medium
  11. la cifra de - picoCTF 2019, medium
  12. New Vignere - picoCTF 2021, hard

Checkpoint (gradeable)

Recover a Vigenere key from ciphertext alone and report the index of coincidence at each candidate period.

Deliberately a produced artefact rather than a quiz question: it is either there or it is not, which makes it fast to mark and hard to bluff. Every tool in ctfpal is deterministic, so two students who did the work correctly hand in the same value.

Where the room gets stuck

This is the first module where the tool's output is a ranked list rather than an answer. Students need to be told explicitly that reading the ranking - and noticing when the top two candidates score similarly - is the skill being taught.

  • Reading a flat frequency profile as 'not a substitution cipher' when unchanged English frequencies in a scrambled text are the signature of a transposition.
  • Scoring a 20-character ciphertext statistically. Below roughly 100 characters the second-best key often outscores the right one, and the answer has to come from a crib instead.
  • Assuming English. A challenge whose plaintext is a flag format, a base64 blob, or another language breaks every frequency table the tool ships with.
  • Stripping spacing and punctuation before analysis. Word boundaries survive most classical ciphers untouched, and on a short ciphertext the pattern of word lengths is a stronger crib than any frequency table.
  • Accepting the solver's top-ranked mapping and fixing the spelling by hand until it reads. That converts a hypothesis into an answer without ever testing it; the confirmation has to be a crib that had to fit.

If a student wants the subject, not the answer

Chapter-level references, so a student can be pointed at twenty pages rather than at a book. Nothing here is required to complete the module.

  • Black Hat Go, Tom Steele, Chris Patten, and Dan Kottmann. Chapter 11, Implementing and Attacking Cryptography. Implementing a cipher and then attacking your own implementation is the fastest cure for treating ciphers as black boxes.
  • Designing Secure Software, Loren Kohnfelder. Chapter 5, Cryptography. Explains why these ciphers are historical curiosities rather than options, in the vocabulary modern designs use.

If you finish early

  • Hand out a challenge from the cross-CTF index in this category - each one has published solutions to compare afterwards.
  • Run the same input through Identify and let the class argue with the ranking. Disagreeing with a confidence score is where the technique actually lands.
  • Ask a student to break their own example - construct an input that defeats the tool, and explain why.

Take this into a room

Markdown files, built here in your browser. They print, they open in anything, and they carry the challenge text - so the session works with no network in the room.