IT231 IT And Applications

IT And ApplicationsUnit 911 min read

Cybersecurity & Info Security: Threats, Controls & Best Practices

Unit 9 of IT And Applications explores cybersecurity fundamentals—threats (malware, phishing, DDoS), defense mechanisms (firewalls, encryption, authentication), and real-world applications in Nepalese tech (eSewa, banks) and global platforms (Google, WhatsApp). Includes case studies, attack simulations, and compliance

TAKEAWAYS:

  • Cybersecurity protects digital assets from unauthorized access/modification via confidentiality, integrity, and availability (CIA triad).
  • Threats range from active attacks (phishing, ransomware) to passive threats (eavesdropping, data leaks).
  • Defense layers include preventive (firewalls, encryption), detective (intrusion detection), and corrective (backups, incident response).
  • Authentication factors (something you know/have/are) and access controls (role-based, mandatory) enforce least-privilege principles.
  • Compliance (GDPR, PCI-DSS) and ethical hacking (penetration testing) are critical for secure systems.
  • Real-world examples show how eSewa uses 2FA, banks encrypt transactions, and WhatsApp secures messages with end-to-end encryption.

Core Concepts: What is Cybersecurity?

Cybersecurity is the practice of protecting digital systems, networks, and data from theft, damage, or unauthorized access. It encompasses technologies, processes, and practices designed to safeguard:

  • Confidentiality: Ensuring data is accessible only to authorized users (e.g., bank passwords).
  • Integrity: Guaranteeing data is accurate and unaltered (e.g., tamper-proof medical records).
  • Availability: Ensuring systems operate when needed (e.g., NTC’s network uptime).

Why is it critical? In 2023, Nepal’s eSewa faced a phishing attack stealing user credentials, while Ncell reported SIM-swapping frauds costing millions. Globally, WhatsApp’s end-to-end encryption prevents hackers from reading messages, even if servers are compromised.


1. Cyber Threats: The Attackers’ Toolkit

Threats can be active (malicious intent) or passive (unauthorized access). Classify them using this table:

Threat Type Examples Impact Real-World Case
Malware Viruses, worms, Trojans Corrupts data, steals info Khalti’s 2022 malware attack (fake payment links)
Phishing Fake emails, spoofed websites Credential theft, financial loss Nepal Police’s fake "COVID vaccine" scam
DDoS Attacks Overloading servers with traffic Downtime, service disruption Daraz’s Black Friday 2023 outage
Insider Threats Employees leaking data Data breaches, reputational damage Nepal Rastra Bank’s insider trading leaks
Social Engineering Tricking users into revealing secrets Unauthorized access Pathao drivers’ fake "app update" scams

2. Defense Mechanisms: Building Layers of Security

Cybersecurity relies on defense-in-depth: multiple overlapping layers. Use this mermaid diagram to visualize the CIA Triad + Security Controls:

EncryptionAccess ControlsConfidentialityHashingDigital SignaturesIntegrityRedundancyDDoS ProtectionAvailabilityCIA Triad
Hierarchical breakdown of CIA Triad principles with corresponding controls

Key Controls Explained

  1. Preventive Controls

    • Firewalls: Filters traffic between trusted/untrusted networks (e.g., NTC’s ISP firewalls block malicious IPs).

    • Encryption: Converts data into unreadable ciphertext (e.g., WhatsApp’s Signal Protocol).

  2. Detective Controls

    • Intrusion Detection Systems (IDS): Monitors network for suspicious activity (e.g., Google’s Chronicle).
    • Audit Logs: Tracks user actions (e.g., bank transaction logs).
  3. Corrective Controls

    • Backups: Restores data after ransomware (e.g., Nepal’s Central Database’s daily backups).
    • Incident Response Plans: Steps to contain breaches (e.g., Ncell’s cybersecurity team’s 2023 breach response).

3. Authentication & Access Control: Who Gets In?

Authentication verifies identity; authorization grants permissions. Use multi-factor authentication (MFA) for stronger security.

Authentication Factor Example Used By
Something You Know Password, PIN eSewa, Gmail
Something You Have OTP, Smart Card Khalti, Ncell
Something You Are Fingerprint, Retina Scan Nepal Police ID systems

Worked Example: eSewa’s 2FA Process

  1. User logs in with password (Factor 1).
  2. eSewa sends an OTP to their phone (Factor 2).
  3. Hackers can’t proceed without the OTP, even if they steal the password.

4. Cybersecurity in Nepal: Case Studies

Case 1: Ncell’s SIM-Swapping Fraud (2023)

  • Threat: Attackers tricked Ncell staff to transfer a user’s number to a new SIM.
  • Impact: ₹500,000 stolen via unauthorized transactions.
  • Solution: Ncell now requires biometric verification for SIM changes.
2023 BSSIM-swappingattack reported (Ncell2023 BSTwo-factorauthentication (2FA) b2023 BSVictims lostaccess to accounts; fi2023 BSNcell implementedstricter SIM registrat
Chronology of Ncell’s SIM-swapping incident and response

Case 2: Daraz’s Payment Gateway Breach

  • Threat: SQL injection attack exposed customer credit card data.
  • Solution: Daraz implemented WAF (Web Application Firewall) and PCI-DSS compliance.

SQL injection attack labelled diagram**Shows malicious input (`' OR '1'='1`) bypassing login checks. (Image: Batka savemazaalai, CC BY-SA 4.0, via Wikimedia Commons)


5. Compliance & Ethical Hacking

Compliance Frameworks

Framework Purpose Applies To
GDPR Protects EU citizen data Nepalese apps handling EU users
PCI-DSS Secures credit card transactions Daraz, Khalti
ISO 27001 Manages information security risks Banks, NTC
01.252.53.755PCI-DSS4ISO 270013GDPR5Nepal’s Data Privacy Act 20752
Global compliance frameworks ranked by relevance to Nepalese IT sectors (2024)

Ethical Hacking: Penetration Testing

  • Goal: Find vulnerabilities before attackers do.
  • Tools: Metasploit, Burp Suite, Nmap.
  • Example: Nepal’s Cyber Security Center conducts pen tests for government websites.

Threat Description Mitigation
AI-Powered Attacks Deepfake phishing, automated hacking AI-driven threat detection (e.g., Darktrace)
IoT Vulnerabilities Hacked smart devices (e.g., CCTV cameras) Segment IoT networks, strong passwords
Quantum Computing Breaks current encryption Post-quantum cryptography (e.g., lattice-based encryption)

In the Real World

  1. eSewa’s 2FA System

    • Idea Used: Multi-factor authentication (MFA).
    • How: After entering a password, users receive an OTP via SMS or app. This prevents credential stuffing attacks where hackers use leaked passwords.
  2. Khalti’s Encrypted Transactions

    • Idea Used: End-to-end encryption (E2EE) and PCI-DSS compliance.
    • How: When you transfer money, Khalti encrypts the transaction data so even their servers can’t read it. This protects against man-in-the-middle attacks.
  3. Ncell’s Biometric SIM Verification

    • Idea Used: Something You Are (biometric) authentication.
    • How: To activate a new SIM, users must scan their fingerprint. This stops SIM-swapping fraud, where attackers trick providers into transferring a user’s number to a new SIM.
  4. WhatsApp’s End-to-End Encryption

    • Idea Used: Signal Protocol (E2EE).
    • How: Messages are encrypted on your phone and only decrypted on the recipient’s phone. Even WhatsApp can’t read them, protecting against government surveillance (e.g., in Nepal’s 2022 data leaks).
  5. Nepal Rastra Bank’s Cybersecurity Audits

    • Idea Used: ISO 27001 compliance and penetration testing.
    • How: The central bank conducts annual security audits and red team exercises to simulate real attacks, ensuring financial system integrity.

Exam Tip

  1. Define Key Terms Precisely

    • Cybersecurity ≠ IT Security: IT security focuses on hardware/software; cybersecurity includes human factors (e.g., phishing).
    • CIA Triad: Always explain confidentiality, integrity, and availability with real examples (e.g., "Bank transactions need integrity to prevent fraud").
  2. Compare Threats & Controls

    • Exam Question: "Differentiate between preventive and detective controls."
    • Answer:
      Preventive Detective
      Stops attacks before they happen Detects attacks after they occur
      Example: Firewall blocking malicious IPs Example: IDS alerting on unusual login attempts
      Weakness: Can’t stop zero-day exploits Weakness: Only works if attack occurs
  3. Use Nepalese Examples

    • eSewa, Khalti, Ncell, NTC, and banks are high-probability exam topics. Relate every concept to them:
      • "How does Ncell prevent SIM-swapping?" → Biometric authentication + OTP verification.
      • "Why is Daraz’s PCI-DSS compliance important?" → Protects customer credit card data from breaches.
  4. Diagrams = Extra Marks

    • Draw CIA Triad, firewall layers, or MFA workflow in exams. Label every component.
    • Example:
      [User] → [Password] → [Firewall] → [IDS] → [Server]
                   ↑               ↑
              (Preventive)    (Detective)
      
  5. Case Study Questions

    • If asked "How would you secure eSewa from phishing?", answer:
      1. Educate users on spotting fake links.
      2. Implement DMARC to prevent email spoofing.
      3. Use behavioral analytics to detect unusual logins.

Quick Revision Table

Topic Key Points Exam Focus
CIA Triad Confidentiality, Integrity, Availability Define + give Nepalese examples
Threats Malware, Phishing, DDoS, Insider Threats Match threats to real cases (eSewa, Ncell)
Controls Preventive (Firewall), Detective (IDS), Corrective (Backups) Compare with table/diagram
Authentication MFA (Password + OTP + Biometrics) Explain eSewa/Khalti’s MFA
Compliance GDPR, PCI-DSS, ISO 27001 Link to banks/Daraz
Ethical Hacking Penetration testing, vulnerability assessment Describe Nepal’s Cyber Security Center

Based on the TU BBA syllabus for IT And Applications (IT231), unit 9.

Discussion

Loading…