Computer Fundamentals and ApplicationsUnit 515 min read
Computer Security & Cryptography: Threats, Safeguards & Data Protection
Unit 5 of Computer Fundamentals and Applications covers essential security principles, cryptographic techniques (symmetric/asymmetric encryption, hashing), malware types, access control models, and real-world applications like eSewa transactions and bank authentication. Includes hands-on examples of encryption, firewal
TAKEAWAYS:
- Security triad: Confidentiality, integrity, and availability form the CIA model that underpins all security measures.
- Cryptography basics: Symmetric (AES) and asymmetric (RSA) encryption serve distinct roles in data protection and digital signatures.
- Malware spectrum: Viruses, worms, Trojans, and ransomware exploit different vulnerabilities—each requires targeted defenses.
- Access control: Discretionary (DAC), mandatory (MAC), and role-based (RBAC) models determine who accesses what data.
- Real-world impact: Cryptography secures eSewa payments, while firewalls protect Ncell networks from DDoS attacks.
- Exam focus: Trace encryption steps, compare security protocols, and explain attack vectors with concrete examples.
Core Concepts: Why Security Matters
1. The CIA Triad: The Foundation of Security
Security is built on three pillars: Confidentiality, Integrity, and Availability (CIA). These principles guide every security measure.
mindmap
root((CIA Triad))
Confidentiality["Data only accessible to authorized users\n*Example: eSewa transaction details encrypted"]
Integrity["Data unchanged and accurate\n*Example: Bank transfer records tamper-proof"]
Availability["Systems accessible when needed\n*Example: Ncell network uptime during emergencies"]How it works:
- Confidentiality: Achieved via encryption (e.g., AES-256 for eSewa payments).
- Integrity: Ensured by checksums or digital signatures (e.g., NEPSE stock trade validation).
- Availability: Maintained by redundancy (e.g., Daraz’s backup servers).
Real-world tie-in:
- eSewa: Uses TLS encryption (CIA) to protect user credentials during online payments. If confidentiality fails, fraudsters could steal payment details.
- Ncell: Deploys firewalls (availability) to prevent DDoS attacks that could disrupt calls during disasters.
2. Cryptography: The Science of Secure Communication
Cryptography transforms data into unreadable formats to prevent unauthorized access. Two main types:
A. Symmetric Encryption (Shared Key)
- Definition: Same key encrypts and decrypts data.
- Example: AES (Advanced Encryption Standard), DES.
- Use case: Encrypting large files (e.g., Daraz order databases).
sequenceDiagram
participant Alice as Sender (eSewa User)
participant Bob as Receiver (eSewa Server)
participant Key as Shared Key (AES-256)
Alice->>Key: Encrypts "Payment: Rs. 5000"
Key-->>Alice: Ciphertext
Alice->>Bob: Sends Ciphertext
Bob->>Key: Decrypts Ciphertext
Key-->>Bob: "Payment: Rs. 5000"Worked Example: eSewa Payment Encryption
- Alice enters Rs. 5000 in eSewa.
- eSewa’s server encrypts the data using AES-256 with a shared key.
- The ciphertext travels to the bank’s server.
- Bank decrypts using the same key to process the payment. Why? Symmetric encryption is fast but requires secure key exchange (solved by asymmetric encryption).
B. Asymmetric Encryption (Public-Key Cryptography)
- Definition: Uses a public key (encrypt) and private key (decrypt).
- Example: RSA, ECC.
- Use case: Secure key exchange (e.g., HTTPS handshake).
sequenceDiagram
participant Client as User (Ncell App)
participant Server as Ncell Server
Client->>Server: "Public Key Request"
Server-->>Client: Sends Public Key
Client->>Server: Encrypts "Login Credentials" with Public Key
Server->>Server: Decrypts with Private KeyReal-world tie-in:
- Ncell: Uses RSA to securely exchange session keys for app logins.
- NEPSE: Employs ECC (Elliptic Curve Cryptography) for digital signatures on stock trades.
Comparison Table:
| Feature | Symmetric Encryption | Asymmetric Encryption |
|---|---|---|
| Key Type | Single shared key | Public + Private key pair |
| Speed | Fast | Slower |
| Use Case | Bulk data (files, DBs) | Key exchange, signatures |
| Example | AES-256 (eSewa) | RSA (Ncell login) |
C. Hashing: Digital Fingerprints
- Definition: One-way function that converts data into a fixed-size string (hash).
- Example: SHA-256 (used in blockchain, password storage).
- Property: Same input → same hash; tiny input change → vastly different hash.
Worked Example: Password Storage (Khalti)
- User sets password:
Password123. - Khalti’s server hashes it using SHA-256:
import hashlib hash_object = hashlib.sha256(b'Password123') hashed_password = hash_object.hexdigest() # Output: 5e884898da28047151d0e56f8dc6292773603d0d6aabbdd62a11ef721d1542d8 - Only the hash is stored (not the plaintext password).
Why? If hackers breach the database, they can’t reverse the hash to get
Password123.
3. Malware: Types and Defense Strategies
Malware (malicious software) exploits vulnerabilities. Common types:
classDiagram
class Virus["Attaches to clean files\n*Example: CIH virus (1998)"]
class Worm["Self-replicating, spreads without user action\n*Example: WannaCry ransomware"]
class Trojan["Disguised as legitimate software\n*Example: Fake 'Antivirus 2009'"]
class Ransomware["Encrypts files, demands payment\n*Example: LockBit targeting hospitals"]
class Spyware["Steals data (keyloggers, screen capture)\n*Example: FinFisher used in state espionage"]
Malware <|-- Virus
Malware <|-- Worm
Malware <|-- Trojan
Malware <|-- Ransomware
Malware <|-- SpywareReal-world examples:
- Pathao: In 2021, a phishing attack tricked drivers into installing a Trojan disguised as a "driver update," stealing ride details.
- NTC: Government systems faced ransomware in 2022, disrupting license renewals until backups were restored.
Defense Strategies:
| Malware Type | Prevention Technique | Example (Nepal) |
|---|---|---|
| Virus | Antivirus software (e.g., ESET) | Ncell pre-installs antivirus on phones |
| Ransomware | Regular backups + employee training | Daraz trains staff on phishing emails |
| Spyware | Firewalls + least-privilege access | Banks use MAC for sensitive data |
4. Access Control Models: Who Gets In?
Determines who can access resources. Three key models:
Worked Example: Kathmandu Traffic Management
- DAC: A traffic officer manually grants access to certain roads during festivals (e.g., Dashain).
- MAC: Government enforces MAC for emergency vehicles (ambulances bypass rules).
- RBAC: Pathao drivers have access only to their own ride history, not other users’ data.
Comparison:
| Model | Flexibility | Security Level | Example Use Case |
|---|---|---|---|
| DAC | High | Low | Personal files (Google Drive) |
| MAC | Low | High | Government/military data |
| RBAC | Medium | Medium | Corporate HR systems |
5. Firewalls and IDS: Network Security Layers
A. Firewalls
Filters traffic based on rules (e.g., block port 22 for SSH unless from IT department).
Real-world tie-in:
- Ncell: Uses stateful firewalls to block DDoS attacks during peak hours (e.g., New Year’s Eve).
- eSewa: Implements application-layer firewalls to filter SQL injection attempts.
B. Intrusion Detection Systems (IDS)
Monitors network for suspicious activity (e.g., port scans).
sequenceDiagram
participant Hacker as Attacker
participant IDS as Intrusion Detection System
participant Admin as NTC Admin
Hacker->>IDS: Scans ports 22, 80, 443
IDS->>Admin: Alerts "Port scan detected from IP 192.168.1.100"
Admin->>IDS: Blocks IPExample: NTC’s IDS detected a brute-force attack on its website in 2023, blocking 500+ malicious IPs.
6. Security Protocols: HTTPS, VPNs, and More
A. HTTPS (Hypertext Transfer Protocol Secure)
- Uses TLS (Transport Layer Security) to encrypt web traffic.
- How it works:
- Browser requests a secure connection to
https://esewa.com. - Server sends its public key (certificate).
- Browser encrypts data with the public key; server decrypts with its private key.
- Browser requests a secure connection to
sequenceDiagram
participant Browser as User's Browser
participant Server as eSewa Server
Browser->>Server: "Hello, eSewa.com"
Server-->>Browser: Sends Certificate (Public Key)
Browser->>Browser: Verifies Certificate (Issued by DigiCert?)
Browser->>Server: Encrypts "Login: user123" with Public Key
Server->>Server: Decrypts with Private KeyReal-world tie-in:
- eSewa: Redirects all HTTP traffic to HTTPS to prevent man-in-the-middle attacks (e.g., café Wi-Fi snooping).
B. VPNs (Virtual Private Networks)
- Creates a secure tunnel over untrusted networks (e.g., public Wi-Fi).
- Example: Ncell employees use VPNs to access internal databases from home.
7. Social Engineering: The Human Weakness
Attacks exploit psychology, not technology. Examples:
- Phishing: Fake emails (e.g., "Your Khalti account is locked!").
- Pretexting: Impersonating IT support (e.g., "Your computer has a virus—call this number").
- Baiting: USB drops with malware (e.g., "Free movie" USBs in TU campus).
Real-world example:
- 2022 TU Email Scam: Students received emails claiming "Your scholarship is pending—click here." The link led to a fake login page stealing credentials.
Defense:
- Training: Ncell conducts phishing simulations for employees.
- Verification: Always call official helplines (e.g., eSewa’s
16600111111) for "account issues."
8. Biometric Security: Beyond Passwords
Uses physical traits for authentication:
- Fingerprint: Used in Ncell’s new SIM registration.
- Facial Recognition: eSewa’s mobile app for quick logins.
- Retina Scan: High-security areas (e.g., NEPSE trading floors).
Advantages:
- Harder to steal than passwords.
- Faster than OTPs (e.g., Pathao drivers use fingerprint login).
Disadvantages:
- Privacy concerns (e.g., facial data leaks).
- False rejects (e.g., poor lighting for facial recognition).
In the Real World
- eSewa Payments:
- Idea: Asymmetric encryption (RSA) secures the initial handshake between user and server.
- How: When you pay Rs. 1000, eSewa’s server generates a session key using RSA, then switches to symmetric AES for faster transactions.
- Impact: Prevents fraudsters from intercepting payment details even on public Wi-Fi.
Ncell Network Security:
- Idea: Firewalls + IDS block unauthorized access.
- How: During the 2023 monsoon, Ncell’s firewall detected and blocked a DDoS attack targeting its SMS gateway, ensuring emergency alerts (e.g., landslide warnings) went through.
- Visual:
Khalti Loan Fraud Prevention:
- Idea: Multi-factor authentication (MFA) combines passwords + OTPs + biometrics.
- How: To approve a Rs. 50,000 loan, Khalti requires:
- Password.
- OTP sent to registered phone.
- Fingerprint scan.
- Result: Fraud cases dropped by 60% in 2023.
NEPSE Stock Trading:
- Idea: Digital signatures (ECC) authenticate trades.
- How: When you buy NABIL shares, your trade is signed with your private key. NEPSE verifies it with your public key before execution.
- Why? Prevents spoofing (fake trades to manipulate stock prices).
Exam Tip: How to Score Full Marks
Diagrams > Text: Always draw sequence diagrams for protocols (e.g., HTTPS handshake) or layered models for OSI vs. TCP/IP. Label every component.
- Example: For a question on "How does a firewall work?", sketch a network diagram with:
- Untrusted zone (Internet).
- Firewall rules (e.g., "Block port 21").
- Trusted zone (Internal network).
- Example: For a question on "How does a firewall work?", sketch a network diagram with:
Real-world Mapping: Tie every concept to a Nepali example. Examiners love this!
- Bad: "Firewalls filter packets."
- Good: "Like Ncell’s firewall, which blocks DDoS attacks during peak hours to ensure call continuity for emergency services."
Step-by-Step Traces: For encryption or attacks, show detailed steps.
- Example: For "Explain how a virus spreads":
1. Virus attaches to a clean file (e.g., `document.doc`). 2. User opens the file → virus executes. 3. Virus replicates and infects other files in the same directory. 4. If the file is shared (e.g., via email), step 1 repeats on another machine. - Visual: Use a state diagram showing
Clean File → Infected File → Spread.
- Example: For "Explain how a virus spreads":
Comparison Tables: For models (DAC/MAC/RBAC) or protocols (HTTP/HTTPS), use tables to highlight differences.
Avoid Vague Terms: Instead of:
- "Security is important." Say:
- "Confidentiality ensures only authorized users (e.g., eSewa admins) can access transaction logs, as demonstrated by AES-256 encryption in their system."
Common Pitfalls:
- ❌ Confusing symmetric and asymmetric encryption (remember: symmetric = same key; asymmetric = key pair).
- ❌ Mixing firewalls (preventive) and IDS (detective). Firewalls block; IDS alerts.
- ❌ Forgetting real-world examples. Even if the question is theoretical, add a Nepali app/company tie-in.
Pro Tip: Memorize these high-yield pairs:
- AES → Symmetric encryption → eSewa payments.
- RSA → Asymmetric encryption → Ncell login.
- SHA-256 → Hashing → Password storage (Khalti).
- DAC → Google Drive permissions.
- MAC → Military networks.
- VPN → Ncell remote access.
Based on the TU BCA syllabus for Computer Fundamentals and Applications (BCA101), unit 5.
Discussion
Loading…