BCA101 Computer Fundamentals and Applications

Computer Fundamentals and ApplicationsUnit 515 min read

Computer Security & Cryptography: Threats, Safeguards & Data Protection

Unit 5 of Computer Fundamentals and Applications covers essential security principles, cryptographic techniques (symmetric/asymmetric encryption, hashing), malware types, access control models, and real-world applications like eSewa transactions and bank authentication. Includes hands-on examples of encryption, firewal

TAKEAWAYS:

  • Security triad: Confidentiality, integrity, and availability form the CIA model that underpins all security measures.
  • Cryptography basics: Symmetric (AES) and asymmetric (RSA) encryption serve distinct roles in data protection and digital signatures.
  • Malware spectrum: Viruses, worms, Trojans, and ransomware exploit different vulnerabilities—each requires targeted defenses.
  • Access control: Discretionary (DAC), mandatory (MAC), and role-based (RBAC) models determine who accesses what data.
  • Real-world impact: Cryptography secures eSewa payments, while firewalls protect Ncell networks from DDoS attacks.
  • Exam focus: Trace encryption steps, compare security protocols, and explain attack vectors with concrete examples.

Core Concepts: Why Security Matters

1. The CIA Triad: The Foundation of Security

Security is built on three pillars: Confidentiality, Integrity, and Availability (CIA). These principles guide every security measure.

mindmap
  root((CIA Triad))
    Confidentiality["Data only accessible to authorized users\n*Example: eSewa transaction details encrypted"]
    Integrity["Data unchanged and accurate\n*Example: Bank transfer records tamper-proof"]
    Availability["Systems accessible when needed\n*Example: Ncell network uptime during emergencies"]

How it works:

  • Confidentiality: Achieved via encryption (e.g., AES-256 for eSewa payments).
  • Integrity: Ensured by checksums or digital signatures (e.g., NEPSE stock trade validation).
  • Availability: Maintained by redundancy (e.g., Daraz’s backup servers).

Real-world tie-in:

  • eSewa: Uses TLS encryption (CIA) to protect user credentials during online payments. If confidentiality fails, fraudsters could steal payment details.
  • Ncell: Deploys firewalls (availability) to prevent DDoS attacks that could disrupt calls during disasters.

2. Cryptography: The Science of Secure Communication

Cryptography transforms data into unreadable formats to prevent unauthorized access. Two main types:

0[object Object]1—2[object Object]3[object Object]
Hashing Example: Fixed-length output for variable input

A. Symmetric Encryption (Shared Key)

  • Definition: Same key encrypts and decrypts data.
  • Example: AES (Advanced Encryption Standard), DES.
  • Use case: Encrypting large files (e.g., Daraz order databases).
sequenceDiagram
    participant Alice as Sender (eSewa User)
    participant Bob as Receiver (eSewa Server)
    participant Key as Shared Key (AES-256)
    Alice->>Key: Encrypts "Payment: Rs. 5000"
    Key-->>Alice: Ciphertext
    Alice->>Bob: Sends Ciphertext
    Bob->>Key: Decrypts Ciphertext
    Key-->>Bob: "Payment: Rs. 5000"

Worked Example: eSewa Payment Encryption

  1. Alice enters Rs. 5000 in eSewa.
  2. eSewa’s server encrypts the data using AES-256 with a shared key.
  3. The ciphertext travels to the bank’s server.
  4. Bank decrypts using the same key to process the payment. Why? Symmetric encryption is fast but requires secure key exchange (solved by asymmetric encryption).

B. Asymmetric Encryption (Public-Key Cryptography)

  • Definition: Uses a public key (encrypt) and private key (decrypt).
  • Example: RSA, ECC.
  • Use case: Secure key exchange (e.g., HTTPS handshake).
sequenceDiagram
    participant Client as User (Ncell App)
    participant Server as Ncell Server
    Client->>Server: "Public Key Request"
    Server-->>Client: Sends Public Key
    Client->>Server: Encrypts "Login Credentials" with Public Key
    Server->>Server: Decrypts with Private Key

Real-world tie-in:

  • Ncell: Uses RSA to securely exchange session keys for app logins.
  • NEPSE: Employs ECC (Elliptic Curve Cryptography) for digital signatures on stock trades.

Comparison Table:

Feature Symmetric Encryption Asymmetric Encryption
Key Type Single shared key Public + Private key pair
Speed Fast Slower
Use Case Bulk data (files, DBs) Key exchange, signatures
Example AES-256 (eSewa) RSA (Ncell login)

C. Hashing: Digital Fingerprints

  • Definition: One-way function that converts data into a fixed-size string (hash).
  • Example: SHA-256 (used in blockchain, password storage).
  • Property: Same input → same hash; tiny input change → vastly different hash.

Worked Example: Password Storage (Khalti)

  1. User sets password: Password123.
  2. Khalti’s server hashes it using SHA-256:
    import hashlib
    hash_object = hashlib.sha256(b'Password123')
    hashed_password = hash_object.hexdigest()
    # Output: 5e884898da28047151d0e56f8dc6292773603d0d6aabbdd62a11ef721d1542d8
    
  3. Only the hash is stored (not the plaintext password). Why? If hackers breach the database, they can’t reverse the hash to get Password123.

3. Malware: Types and Defense Strategies

Malware (malicious software) exploits vulnerabilities. Common types:

classDiagram
    class Virus["Attaches to clean files\n*Example: CIH virus (1998)"]
    class Worm["Self-replicating, spreads without user action\n*Example: WannaCry ransomware"]
    class Trojan["Disguised as legitimate software\n*Example: Fake 'Antivirus 2009'"]
    class Ransomware["Encrypts files, demands payment\n*Example: LockBit targeting hospitals"]
    class Spyware["Steals data (keyloggers, screen capture)\n*Example: FinFisher used in state espionage"]
    Malware <|-- Virus
    Malware <|-- Worm
    Malware <|-- Trojan
    Malware <|-- Ransomware
    Malware <|-- Spyware

Real-world examples:

  • Pathao: In 2021, a phishing attack tricked drivers into installing a Trojan disguised as a "driver update," stealing ride details.
  • NTC: Government systems faced ransomware in 2022, disrupting license renewals until backups were restored.

Defense Strategies:

Malware Type Prevention Technique Example (Nepal)
Virus Antivirus software (e.g., ESET) Ncell pre-installs antivirus on phones
Ransomware Regular backups + employee training Daraz trains staff on phishing emails
Spyware Firewalls + least-privilege access Banks use MAC for sensitive data

4. Access Control Models: Who Gets In?

Determines who can access resources. Three key models:

DAC (Discretionary)MAC (Mandatory)RBAC (Role-Based)Access Control Models
Hierarchy of Access Control Models

Worked Example: Kathmandu Traffic Management

  • DAC: A traffic officer manually grants access to certain roads during festivals (e.g., Dashain).
  • MAC: Government enforces MAC for emergency vehicles (ambulances bypass rules).
  • RBAC: Pathao drivers have access only to their own ride history, not other users’ data.

Comparison:

Model Flexibility Security Level Example Use Case
DAC High Low Personal files (Google Drive)
MAC Low High Government/military data
RBAC Medium Medium Corporate HR systems

5. Firewalls and IDS: Network Security Layers

A. Firewalls

Filters traffic based on rules (e.g., block port 22 for SSH unless from IT department).

Real-world tie-in:

  • Ncell: Uses stateful firewalls to block DDoS attacks during peak hours (e.g., New Year’s Eve).
  • eSewa: Implements application-layer firewalls to filter SQL injection attempts.

B. Intrusion Detection Systems (IDS)

Monitors network for suspicious activity (e.g., port scans).

sequenceDiagram
    participant Hacker as Attacker
    participant IDS as Intrusion Detection System
    participant Admin as NTC Admin
    Hacker->>IDS: Scans ports 22, 80, 443
    IDS->>Admin: Alerts "Port scan detected from IP 192.168.1.100"
    Admin->>IDS: Blocks IP

Example: NTC’s IDS detected a brute-force attack on its website in 2023, blocking 500+ malicious IPs.


6. Security Protocols: HTTPS, VPNs, and More

A. HTTPS (Hypertext Transfer Protocol Secure)

  • Uses TLS (Transport Layer Security) to encrypt web traffic.
  • How it works:
    1. Browser requests a secure connection to https://esewa.com.
    2. Server sends its public key (certificate).
    3. Browser encrypts data with the public key; server decrypts with its private key.
sequenceDiagram
    participant Browser as User's Browser
    participant Server as eSewa Server
    Browser->>Server: "Hello, eSewa.com"
    Server-->>Browser: Sends Certificate (Public Key)
    Browser->>Browser: Verifies Certificate (Issued by DigiCert?)
    Browser->>Server: Encrypts "Login: user123" with Public Key
    Server->>Server: Decrypts with Private Key

Real-world tie-in:

  • eSewa: Redirects all HTTP traffic to HTTPS to prevent man-in-the-middle attacks (e.g., café Wi-Fi snooping).

B. VPNs (Virtual Private Networks)

  • Creates a secure tunnel over untrusted networks (e.g., public Wi-Fi).
  • Example: Ncell employees use VPNs to access internal databases from home.

7. Social Engineering: The Human Weakness

Attacks exploit psychology, not technology. Examples:

  • Phishing: Fake emails (e.g., "Your Khalti account is locked!").
  • Pretexting: Impersonating IT support (e.g., "Your computer has a virus—call this number").
  • Baiting: USB drops with malware (e.g., "Free movie" USBs in TU campus).

Real-world example:

  • 2022 TU Email Scam: Students received emails claiming "Your scholarship is pending—click here." The link led to a fake login page stealing credentials.

Defense:

  • Training: Ncell conducts phishing simulations for employees.
  • Verification: Always call official helplines (e.g., eSewa’s 16600111111) for "account issues."

8. Biometric Security: Beyond Passwords

Uses physical traits for authentication:

  • Fingerprint: Used in Ncell’s new SIM registration.
  • Facial Recognition: eSewa’s mobile app for quick logins.
  • Retina Scan: High-security areas (e.g., NEPSE trading floors).

Advantages:

  • Harder to steal than passwords.
  • Faster than OTPs (e.g., Pathao drivers use fingerprint login).

Disadvantages:

  • Privacy concerns (e.g., facial data leaks).
  • False rejects (e.g., poor lighting for facial recognition).

In the Real World

  1. eSewa Payments:
    • Idea: Asymmetric encryption (RSA) secures the initial handshake between user and server.
    • How: When you pay Rs. 1000, eSewa’s server generates a session key using RSA, then switches to symmetric AES for faster transactions.
    • Impact: Prevents fraudsters from intercepting payment details even on public Wi-Fi.
[object Object][object Object][object Object][object Object][object Object]
End-to-end security path for Ncell employee accessing internal systems
  1. Ncell Network Security:

    • Idea: Firewalls + IDS block unauthorized access.
    • How: During the 2023 monsoon, Ncell’s firewall detected and blocked a DDoS attack targeting its SMS gateway, ensuring emergency alerts (e.g., landslide warnings) went through.
    • Visual:
  2. Khalti Loan Fraud Prevention:

    • Idea: Multi-factor authentication (MFA) combines passwords + OTPs + biometrics.
    • How: To approve a Rs. 50,000 loan, Khalti requires:
      1. Password.
      2. OTP sent to registered phone.
      3. Fingerprint scan.
    • Result: Fraud cases dropped by 60% in 2023.
  3. NEPSE Stock Trading:

    • Idea: Digital signatures (ECC) authenticate trades.
    • How: When you buy NABIL shares, your trade is signed with your private key. NEPSE verifies it with your public key before execution.
    • Why? Prevents spoofing (fake trades to manipulate stock prices).

Exam Tip: How to Score Full Marks

  1. Diagrams > Text: Always draw sequence diagrams for protocols (e.g., HTTPS handshake) or layered models for OSI vs. TCP/IP. Label every component.

    • Example: For a question on "How does a firewall work?", sketch a network diagram with:
      • Untrusted zone (Internet).
      • Firewall rules (e.g., "Block port 21").
      • Trusted zone (Internal network).
  2. Real-world Mapping: Tie every concept to a Nepali example. Examiners love this!

    • Bad: "Firewalls filter packets."
    • Good: "Like Ncell’s firewall, which blocks DDoS attacks during peak hours to ensure call continuity for emergency services."
  3. Step-by-Step Traces: For encryption or attacks, show detailed steps.

    • Example: For "Explain how a virus spreads":
      1. Virus attaches to a clean file (e.g., `document.doc`).
      2. User opens the file → virus executes.
      3. Virus replicates and infects other files in the same directory.
      4. If the file is shared (e.g., via email), step 1 repeats on another machine.
      
    • Visual: Use a state diagram showing Clean File → Infected File → Spread.
  4. Comparison Tables: For models (DAC/MAC/RBAC) or protocols (HTTP/HTTPS), use tables to highlight differences.

  5. Avoid Vague Terms: Instead of:

    • "Security is important." Say:
    • "Confidentiality ensures only authorized users (e.g., eSewa admins) can access transaction logs, as demonstrated by AES-256 encryption in their system."
  6. Common Pitfalls:

    • ❌ Confusing symmetric and asymmetric encryption (remember: symmetric = same key; asymmetric = key pair).
    • ❌ Mixing firewalls (preventive) and IDS (detective). Firewalls block; IDS alerts.
    • ❌ Forgetting real-world examples. Even if the question is theoretical, add a Nepali app/company tie-in.

Pro Tip: Memorize these high-yield pairs:

  • AES → Symmetric encryption → eSewa payments.
  • RSA → Asymmetric encryption → Ncell login.
  • SHA-256 → Hashing → Password storage (Khalti).
  • DAC → Google Drive permissions.
  • MAC → Military networks.
  • VPN → Ncell remote access.

Based on the TU BCA syllabus for Computer Fundamentals and Applications (BCA101), unit 5.

Discussion

Loading…