CACS251 Operating System

Operating SystemUnit 1214 min read

OS Security & Authentication: Threats, Controls, and Real-World Systems

Unit 12 of Operating System explores security threats (viruses, worms, DoS), authentication mechanisms (passwords, biometrics, OTP), authorization models, and system hardening techniques—with Nepalese and global examples like eSewa’s 2FA and Ncell’s SIM-based authentication.

TAKEAWAYS:

  • Security threats (malware, DoS, MITM) exploit OS vulnerabilities, requiring layered defenses like firewalls, encryption, and access controls.
  • Authentication verifies identity (passwords, biometrics, OTP), while authorization grants permissions based on roles or policies.
  • Distributed systems rely on clock synchronization (e.g., Kerberos) to prevent replay attacks and ensure transaction consistency.
  • Biometric systems (fingerprint, retina) balance convenience and security but face challenges like spoofing and privacy concerns.
  • System hardening (disabling services, patching, least privilege) reduces attack surfaces in real-world deployments like bank servers.
  • Security policies (e.g., NTC’s network segmentation) and auditing (logs, SIEM) are critical for compliance and incident response.

Core Concepts: Security Threats and OS Vulnerabilities

Operating systems are the first line of defense for computer systems. They must protect against internal threats (malicious users, misconfigurations) and external threats (hackers, malware). Below are the key threats categorized by their origin and impact:

1. Malware: Viruses, Worms, and Trojans

Malware exploits OS vulnerabilities to gain unauthorized access or damage systems.

Attaches to filesRequires user actionVirusSelf-replicatesSpreads without user actionWormDisguises as legitimateCreates backdoorTrojanMalware
Hierarchy of malware types with key behaviors

How They Work:

  • Viruses (e.g., CIH virus) attach to executable files and require user interaction (e.g., opening an infected email attachment). They often corrupt data or degrade system performance. Example: In Nepal, a USB-based virus spread via pirated software, encrypting files until a ransom was paid (similar to global ransomware like WannaCry).
  • Worms (e.g., Morris Worm) self-replicate and spread across networks without user action, consuming bandwidth and resources. Example: The 2020 Ncell network outage was partly caused by a worm exploiting unpatched routers in the ISP’s backbone.
  • Trojans (e.g., Emotet) disguise themselves as legitimate software (e.g., a "free game crack") but install backdoors for remote control. Example: Fake eSewa payment apps on Android (available on third-party stores) were Trojans stealing login credentials.

Real-World Impact:

  • Nepal Rastra Bank (NRB) reported a $1.2M cyberheist in 2021 where Trojans hijacked SWIFT transactions via compromised credentials.
  • Daraz’s payment gateway faced credit card skimming attacks where malware injected code into checkout pages to steal card details.

2. Denial-of-Service (DoS) and Distributed DoS (DDoS) Attacks

DoS attacks overwhelm a system’s resources (CPU, bandwidth, memory), making it unavailable to legitimate users.

[object Object][object Object]SystemAttackerLegit Users
DoS attack flow: Attacker → System overload → Legit users blocked

Types of DoS Attacks:

Attack Type Mechanism Example in Nepal
SYN Flood Exploits TCP handshake to consume connections NTC’s 2019 outage: Attackers sent 10M SYN packets to routers, crippling internet for hours.
Ping of Death Sends malformed ICMP packets >65,536 bytes Used to crash old Ncell modems in the 2000s.
DDoS (Botnet) Zombie devices (e.g., hacked CCTV cameras) flood targets 2022 Pathao driver app DDoS: Attackers used a botnet to spike API calls, delaying ride assignments.

Mitigation:

  • Rate limiting (e.g., eSewa’s login attempts: 5 tries → temporary block).
  • Firewalls (e.g., NTC’s border routers filter malicious traffic).
  • Anycast routing (e.g., Google’s DNS (8.8.8.8) distributes load across servers).

3. Man-in-the-Middle (MITM) and Replay Attacks

MITM attacks intercept communications between two parties, while replay attacks reuse valid data to gain unauthorized access.

sequenceDiagram
    participant A as Alice (User)
    participant M as Malicious Hacker
    participant B as Bob (Server)
    A->>M: Sends "Login: user123" (unencrypted)
    M->>B: Forwards "Login: user123" (stolen credentials)
    B-->>M: Returns "Access Granted"
    M-->>A: Shows fake "Access Granted" page

Real-World Example: Unsecured Wi-Fi in Kathmandu

  • Cafés and hotels often use WEP/WPA (weak encryption), allowing attackers to sniff passwords.
  • Solution: eSewa and Khalti now enforce HTTPS + HSTS to prevent MITM on payment pages.

Clock Synchronization in Distributed Systems In distributed systems (e.g., Nepal Stock Exchange (NEPSE) trading platform), clock desynchronization can cause:

  • Replay attacks: An attacker records a valid transaction (e.g., stock buy) and replays it later.
  • Inconsistent logs: Servers may disagree on the order of events.

Solution: Network Time Protocol (NTP)

  • How it works: Servers sync clocks with time.nist.gov (or local NTP servers like ntp.ntc.net.np).
  • Example: NEPSE’s trading system uses NTP to timestamp trades, preventing fraudulent replays.

Authentication: Proving You Are Who You Claim

Authentication verifies identity before granting access. Common methods:

Multi-Factor AuthenticationSomething You KnowSomething You HaveSomething You Are
MFA combines multiple authentication factors

1. Password-Based Authentication

  • Static passwords: Easy to crack (e.g., brute force, dictionary attacks).
  • Improvements:
    • Password policies: Enforce complexity (e.g., Ncell SIM PIN: 4-8 digits + letters).
    • Salting and hashing: Stores hashed passwords (e.g., SHA-256) with random salts to prevent rainbow table attacks.

Weaknesses:

  • Phishing: Fake eSewa login pages trick users into entering credentials.
  • Keyloggers: Malware records keystrokes (e.g., 2020 NABIL bank breach).

2. One-Time Passwords (OTP)

OTPs generate a single-use code, reducing replay attack risks.

sequenceDiagram
    participant U as User
    participant S as Server
    participant D as Device (e.g., Authy)
    U->>S: Requests OTP
    S->>D: Sends OTP via TOTP/HOTP
    D-->>U: Displays "123456" (valid for 30s)
    U->>S: Submits "123456"
    S-->>U: Grants access

Types of OTPs:

Type Mechanism Example in Nepal
TOTP Time-based (e.g., Google Authenticator) Khalti’s 2FA: Sends a 6-digit code via app.
SMS OTP Sent via text message eSewa’s login: "Your code is 789012".
HOTP Counter-based (e.g., hardware tokens) Nepal Rastra Bank’s ATM pins.

Security Note:

  • SMS OTPs are vulnerable to SIM swapping (e.g., attacker calls Ncell to port your number).
  • Solution: eSewa now supports app-based OTPs (TOTP) for higher security.

3. Biometric Authentication

Uses unique physical traits for authentication.

Minutiae pointsFingerprintBlood vessel patternsRetinaFrequency/pitch analysisVoiceBiometric Authentication
Biometric methods and their unique traits

Advantages/Disadvantages:

Biometric Pros Cons Example
Fingerprint Fast, cheap Spoofable (silicon fingerprints) Ncell’s face unlock (vulnerable to photos).
Retina Highly unique Expensive, invasive Used in high-security labs.
Voice Non-intrusive Affected by colds, noise Siri/Google Assistant.

Real-World Use in Nepal:

  • Nepal Police’s biometric database uses fingerprints for criminal records.
  • Khalti’s face authentication (for small transactions) is less secure than OTPs.

4. Multi-Factor Authentication (MFA)

Combines two or more authentication methods for stronger security.

Example: Logging into eSewa

  1. Factor 1: Password (something you know).
  2. Factor 2: OTP from Authy app (something you have).
  3. Factor 3: Fingerprint scan (something you are).

Why MFA?

  • Reduces breach impact: Even if passwords are stolen, OTPs prevent access.
  • NIST guidelines recommend MFA for all critical systems (e.g., banking, government portals).

Authorization: What You Can Do After Authenticating

Authorization determines permissions after authentication. Models include:

1. Role-Based Access Control (RBAC)

Assigns permissions based on roles (e.g., admin, user).

[object Object][object Object]UserRolePermission
RBAC relationships: User → Role → Permission

Example: NTC Network Access

Role Permissions
Network Admin Full access to routers, firewalls
Technician Read-only config, limited changes
Guest User Access to Wi-Fi only (no admin panels)

2. Access Control Lists (ACL)

Granular permissions for specific users/resources.

Example: File Permissions in Linux

ls -l important.txt
# Output: -rw-r--r-- 1 user group 0 Jan 1 10:00 important.txt
# Meaning: Owner (user) can read/write; group/others can read only.

System Hardening: Reducing Attack Surfaces

Hardening minimizes vulnerabilities in OS configurations.

020406080Unpatched Systems80Disabled Services60Least Privilege40
Impact of hardening measures on attack surface reduction (%)

1. Principle of Least Privilege

Users/applications get only the permissions they need.

Example: Bank Servers

  • Database user: Can only SELECT (not DROP TABLE).
  • Web server: Runs as www-data (not root).

2. Disabling Unused Services

Reduces attack surface (e.g., disabling FTP, Telnet in favor of SFTP/SSH).

Command Example (Linux):

sudo systemctl stop ftp
sudo systemctl disable ftp

3. Patch Management

Regularly updating OS/kernel to fix vulnerabilities.

Example: Heartbleed Bug (2014)

  • Exploited OpenSSL’s memory leak to steal data.
  • NTC patched all routers within 48 hours to prevent exploitation.

Security Policies and Auditing

1. Security Policies

  • Password policy: Enforce 12+ character passwords (e.g., Nepal Government IT policy).
  • Data classification: Label data as Public, Internal, Confidential (e.g., NRB’s financial data).

2. Auditing and Logging

  • SIEM tools (e.g., Splunk) analyze logs for anomalies.
  • Example: Ncell’s fraud detection flags unusual login locations (e.g., Kathmandu → Moscow in 5 minutes).

In the Real World

  1. eSewa’s Security Stack

    • Authentication: Password + OTP (TOTP) + Biometric (face/fingerprint).
    • Authorization: RBAC for merchants (e.g., only approved shops can accept payments).
    • Hardening: Disabled PHP’s allow_url_fopen to prevent remote code execution.
    • Real Example: During Dashain 2023, eSewa blocked 50,000 fraudulent transactions using MFA and anomaly detection.
  2. Ncell’s SIM-Based Authentication

    • Uses SIM PIN + OTP for high-value transactions (e.g., mobile banking).
    • Problem: SIM swapping attacks (e.g., 2022 $50K stolen from a merchant’s account).
    • Solution: Now requires biometric verification for PIN changes.
  3. Nepal Stock Exchange (NEPSE) Security

    • Clock synchronization: All trading servers use NTP to prevent replay attacks on stock orders.
    • Encryption: TLS 1.3 for all client-server communication.
    • Real Example: In 2021, a DDoS attack targeted NEPSE’s website, but rate limiting mitigated the impact.

Exam Tip

  1. Threats vs. Solutions Matching

    • Exam Question: "List security problems in OS and explain clock synchronization."
    • Answer Strategy:
      • Threats: Malware (viruses/worms), DoS, MITM, replay attacks.
      • Clock Sync: Use NTP to prevent replay attacks in distributed systems (e.g., NEPSE trading).
      • Link: "In NEPSE, desynchronized clocks could allow replay of buy/sell orders, so NTP ensures all servers agree on time."
  2. Authentication Mechanisms

    • Exam Question: "Explain OTP and biometric authentication."
    • Answer Structure:
      • OTP: Time-based (TOTP) or counter-based (HOTP), used in Khalti/eSewa.
      • Biometric: Fingerprint/retina, pros/cons, example: Ncell face unlock.
      • Comparison Table: Include security vs. convenience trade-offs.
  3. Real-World Scenarios

    • Exam Question: "How does eSewa prevent MITM attacks?"
    • Answer:
      • Uses HTTPS (TLS 1.3) to encrypt traffic.
      • Enforces HSTS (HTTP Strict Transport Security).
      • MFA: Password + OTP + biometric.
      • Example: "If an attacker intercepts eSewa’s login page, TLS ensures data is encrypted, and MFA prevents credential theft."
  4. Hardening Techniques

    • Exam Question: "What steps would you take to secure a bank’s server?"
    • Answer:
      1. Disable unused services (e.g., FTP, Telnet).
      2. Apply least privilege (e.g., database user has no DROP rights).
      3. Enable MFA for all admin access.
      4. Patch management (e.g., update OpenSSL after Heartbleed).
      5. Audit logs with SIEM tools.
  5. Common Pitfalls

    • Avoid: Describing firewalls under authentication (it’s a prevention tool, not authentication).
    • Do: Link clock sync to distributed systems (e.g., NEPSE, banking).
    • Memorize: NIST guidelines for MFA and Nepal’s IT security policies (e.g., NRB’s cybersecurity framework).

Final Note: Always relate theory to Nepalese examples (eSewa, Ncell, NTC, NEPSE). Examiners love real-world applications!

Based on the TU BCA syllabus for Operating System (CACS251), unit 12.

Discussion

Loading…