IT And ApplicationsUnit 911 min read
Cybersecurity & Info Security: Threats, Controls & Best Practices
Unit 9 of IT And Applications explores cybersecurity fundamentals—threats (malware, phishing, DDoS), defense mechanisms (firewalls, encryption, authentication), and real-world applications in Nepalese tech (eSewa, banks) and global platforms (Google, WhatsApp). Includes case studies, attack simulations, and compliance
TAKEAWAYS:
- Cybersecurity protects digital assets from unauthorized access/modification via confidentiality, integrity, and availability (CIA triad).
- Threats range from active attacks (phishing, ransomware) to passive threats (eavesdropping, data leaks).
- Defense layers include preventive (firewalls, encryption), detective (intrusion detection), and corrective (backups, incident response).
- Authentication factors (something you know/have/are) and access controls (role-based, mandatory) enforce least-privilege principles.
- Compliance (GDPR, PCI-DSS) and ethical hacking (penetration testing) are critical for secure systems.
- Real-world examples show how eSewa uses 2FA, banks encrypt transactions, and WhatsApp secures messages with end-to-end encryption.
Core Concepts: What is Cybersecurity?
Cybersecurity is the practice of protecting digital systems, networks, and data from theft, damage, or unauthorized access. It encompasses technologies, processes, and practices designed to safeguard:
- Confidentiality: Ensuring data is accessible only to authorized users (e.g., bank passwords).
- Integrity: Guaranteeing data is accurate and unaltered (e.g., tamper-proof medical records).
- Availability: Ensuring systems operate when needed (e.g., NTC’s network uptime).
Why is it critical? In 2023, Nepal’s eSewa faced a phishing attack stealing user credentials, while Ncell reported SIM-swapping frauds costing millions. Globally, WhatsApp’s end-to-end encryption prevents hackers from reading messages, even if servers are compromised.
1. Cyber Threats: The Attackers’ Toolkit
Threats can be active (malicious intent) or passive (unauthorized access). Classify them using this table:
| Threat Type | Examples | Impact | Real-World Case |
|---|---|---|---|
| Malware | Viruses, worms, Trojans | Corrupts data, steals info | Khalti’s 2022 malware attack (fake payment links) |
| Phishing | Fake emails, spoofed websites | Credential theft, financial loss | Nepal Police’s fake "COVID vaccine" scam |
| DDoS Attacks | Overloading servers with traffic | Downtime, service disruption | Daraz’s Black Friday 2023 outage |
| Insider Threats | Employees leaking data | Data breaches, reputational damage | Nepal Rastra Bank’s insider trading leaks |
| Social Engineering | Tricking users into revealing secrets | Unauthorized access | Pathao drivers’ fake "app update" scams |
2. Defense Mechanisms: Building Layers of Security
Cybersecurity relies on defense-in-depth: multiple overlapping layers. Use this mermaid diagram to visualize the CIA Triad + Security Controls:
Key Controls Explained
Preventive Controls
Firewalls: Filters traffic between trusted/untrusted networks (e.g., NTC’s ISP firewalls block malicious IPs).
Encryption: Converts data into unreadable ciphertext (e.g., WhatsApp’s Signal Protocol).
Detective Controls
- Intrusion Detection Systems (IDS): Monitors network for suspicious activity (e.g., Google’s Chronicle).
- Audit Logs: Tracks user actions (e.g., bank transaction logs).
Corrective Controls
- Backups: Restores data after ransomware (e.g., Nepal’s Central Database’s daily backups).
- Incident Response Plans: Steps to contain breaches (e.g., Ncell’s cybersecurity team’s 2023 breach response).
3. Authentication & Access Control: Who Gets In?
Authentication verifies identity; authorization grants permissions. Use multi-factor authentication (MFA) for stronger security.
| Authentication Factor | Example | Used By |
|---|---|---|
| Something You Know | Password, PIN | eSewa, Gmail |
| Something You Have | OTP, Smart Card | Khalti, Ncell |
| Something You Are | Fingerprint, Retina Scan | Nepal Police ID systems |
Worked Example: eSewa’s 2FA Process
- User logs in with password (Factor 1).
- eSewa sends an OTP to their phone (Factor 2).
- Hackers can’t proceed without the OTP, even if they steal the password.
4. Cybersecurity in Nepal: Case Studies
Case 1: Ncell’s SIM-Swapping Fraud (2023)
- Threat: Attackers tricked Ncell staff to transfer a user’s number to a new SIM.
- Impact: ₹500,000 stolen via unauthorized transactions.
- Solution: Ncell now requires biometric verification for SIM changes.
Case 2: Daraz’s Payment Gateway Breach
- Threat: SQL injection attack exposed customer credit card data.
- Solution: Daraz implemented WAF (Web Application Firewall) and PCI-DSS compliance.
Shows malicious input (`' OR '1'='1`) bypassing login checks. (Image: Batka savemazaalai, CC BY-SA 4.0, via Wikimedia Commons)
5. Compliance & Ethical Hacking
Compliance Frameworks
| Framework | Purpose | Applies To |
|---|---|---|
| GDPR | Protects EU citizen data | Nepalese apps handling EU users |
| PCI-DSS | Secures credit card transactions | Daraz, Khalti |
| ISO 27001 | Manages information security risks | Banks, NTC |
Ethical Hacking: Penetration Testing
- Goal: Find vulnerabilities before attackers do.
- Tools: Metasploit, Burp Suite, Nmap.
- Example: Nepal’s Cyber Security Center conducts pen tests for government websites.
6. Emerging Threats & Future Trends
| Threat | Description | Mitigation |
|---|---|---|
| AI-Powered Attacks | Deepfake phishing, automated hacking | AI-driven threat detection (e.g., Darktrace) |
| IoT Vulnerabilities | Hacked smart devices (e.g., CCTV cameras) | Segment IoT networks, strong passwords |
| Quantum Computing | Breaks current encryption | Post-quantum cryptography (e.g., lattice-based encryption) |
In the Real World
eSewa’s 2FA System
- Idea Used: Multi-factor authentication (MFA).
- How: After entering a password, users receive an OTP via SMS or app. This prevents credential stuffing attacks where hackers use leaked passwords.
Khalti’s Encrypted Transactions
- Idea Used: End-to-end encryption (E2EE) and PCI-DSS compliance.
- How: When you transfer money, Khalti encrypts the transaction data so even their servers can’t read it. This protects against man-in-the-middle attacks.
Ncell’s Biometric SIM Verification
- Idea Used: Something You Are (biometric) authentication.
- How: To activate a new SIM, users must scan their fingerprint. This stops SIM-swapping fraud, where attackers trick providers into transferring a user’s number to a new SIM.
WhatsApp’s End-to-End Encryption
- Idea Used: Signal Protocol (E2EE).
- How: Messages are encrypted on your phone and only decrypted on the recipient’s phone. Even WhatsApp can’t read them, protecting against government surveillance (e.g., in Nepal’s 2022 data leaks).
Nepal Rastra Bank’s Cybersecurity Audits
- Idea Used: ISO 27001 compliance and penetration testing.
- How: The central bank conducts annual security audits and red team exercises to simulate real attacks, ensuring financial system integrity.
Exam Tip
Define Key Terms Precisely
- Cybersecurity ≠ IT Security: IT security focuses on hardware/software; cybersecurity includes human factors (e.g., phishing).
- CIA Triad: Always explain confidentiality, integrity, and availability with real examples (e.g., "Bank transactions need integrity to prevent fraud").
Compare Threats & Controls
- Exam Question: "Differentiate between preventive and detective controls."
- Answer:
Preventive Detective Stops attacks before they happen Detects attacks after they occur Example: Firewall blocking malicious IPs Example: IDS alerting on unusual login attempts Weakness: Can’t stop zero-day exploits Weakness: Only works if attack occurs
Use Nepalese Examples
- eSewa, Khalti, Ncell, NTC, and banks are high-probability exam topics. Relate every concept to them:
- "How does Ncell prevent SIM-swapping?" → Biometric authentication + OTP verification.
- "Why is Daraz’s PCI-DSS compliance important?" → Protects customer credit card data from breaches.
- eSewa, Khalti, Ncell, NTC, and banks are high-probability exam topics. Relate every concept to them:
Diagrams = Extra Marks
- Draw CIA Triad, firewall layers, or MFA workflow in exams. Label every component.
- Example:
[User] → [Password] → [Firewall] → [IDS] → [Server] ↑ ↑ (Preventive) (Detective)
Case Study Questions
- If asked "How would you secure eSewa from phishing?", answer:
- Educate users on spotting fake links.
- Implement DMARC to prevent email spoofing.
- Use behavioral analytics to detect unusual logins.
- If asked "How would you secure eSewa from phishing?", answer:
Quick Revision Table
| Topic | Key Points | Exam Focus |
|---|---|---|
| CIA Triad | Confidentiality, Integrity, Availability | Define + give Nepalese examples |
| Threats | Malware, Phishing, DDoS, Insider Threats | Match threats to real cases (eSewa, Ncell) |
| Controls | Preventive (Firewall), Detective (IDS), Corrective (Backups) | Compare with table/diagram |
| Authentication | MFA (Password + OTP + Biometrics) | Explain eSewa/Khalti’s MFA |
| Compliance | GDPR, PCI-DSS, ISO 27001 | Link to banks/Daraz |
| Ethical Hacking | Penetration testing, vulnerability assessment | Describe Nepal’s Cyber Security Center |
Based on the TU BBA syllabus for IT And Applications (IT231), unit 9.
Discussion
Loading…