Operating SystemUnit 1214 min read
OS Security & Authentication: Threats, Controls, and Real-World Systems
Unit 12 of Operating System explores security threats (viruses, worms, DoS), authentication mechanisms (passwords, biometrics, OTP), authorization models, and system hardening techniques—with Nepalese and global examples like eSewa’s 2FA and Ncell’s SIM-based authentication.
TAKEAWAYS:
- Security threats (malware, DoS, MITM) exploit OS vulnerabilities, requiring layered defenses like firewalls, encryption, and access controls.
- Authentication verifies identity (passwords, biometrics, OTP), while authorization grants permissions based on roles or policies.
- Distributed systems rely on clock synchronization (e.g., Kerberos) to prevent replay attacks and ensure transaction consistency.
- Biometric systems (fingerprint, retina) balance convenience and security but face challenges like spoofing and privacy concerns.
- System hardening (disabling services, patching, least privilege) reduces attack surfaces in real-world deployments like bank servers.
- Security policies (e.g., NTC’s network segmentation) and auditing (logs, SIEM) are critical for compliance and incident response.
Core Concepts: Security Threats and OS Vulnerabilities
Operating systems are the first line of defense for computer systems. They must protect against internal threats (malicious users, misconfigurations) and external threats (hackers, malware). Below are the key threats categorized by their origin and impact:
1. Malware: Viruses, Worms, and Trojans
Malware exploits OS vulnerabilities to gain unauthorized access or damage systems.
How They Work:
- Viruses (e.g., CIH virus) attach to executable files and require user interaction (e.g., opening an infected email attachment). They often corrupt data or degrade system performance. Example: In Nepal, a USB-based virus spread via pirated software, encrypting files until a ransom was paid (similar to global ransomware like WannaCry).
- Worms (e.g., Morris Worm) self-replicate and spread across networks without user action, consuming bandwidth and resources. Example: The 2020 Ncell network outage was partly caused by a worm exploiting unpatched routers in the ISP’s backbone.
- Trojans (e.g., Emotet) disguise themselves as legitimate software (e.g., a "free game crack") but install backdoors for remote control. Example: Fake eSewa payment apps on Android (available on third-party stores) were Trojans stealing login credentials.
Real-World Impact:
- Nepal Rastra Bank (NRB) reported a $1.2M cyberheist in 2021 where Trojans hijacked SWIFT transactions via compromised credentials.
- Daraz’s payment gateway faced credit card skimming attacks where malware injected code into checkout pages to steal card details.
2. Denial-of-Service (DoS) and Distributed DoS (DDoS) Attacks
DoS attacks overwhelm a system’s resources (CPU, bandwidth, memory), making it unavailable to legitimate users.
Types of DoS Attacks:
| Attack Type | Mechanism | Example in Nepal |
|---|---|---|
| SYN Flood | Exploits TCP handshake to consume connections | NTC’s 2019 outage: Attackers sent 10M SYN packets to routers, crippling internet for hours. |
| Ping of Death | Sends malformed ICMP packets >65,536 bytes | Used to crash old Ncell modems in the 2000s. |
| DDoS (Botnet) | Zombie devices (e.g., hacked CCTV cameras) flood targets | 2022 Pathao driver app DDoS: Attackers used a botnet to spike API calls, delaying ride assignments. |
Mitigation:
- Rate limiting (e.g., eSewa’s login attempts: 5 tries → temporary block).
- Firewalls (e.g., NTC’s border routers filter malicious traffic).
- Anycast routing (e.g., Google’s DNS (8.8.8.8) distributes load across servers).
3. Man-in-the-Middle (MITM) and Replay Attacks
MITM attacks intercept communications between two parties, while replay attacks reuse valid data to gain unauthorized access.
sequenceDiagram
participant A as Alice (User)
participant M as Malicious Hacker
participant B as Bob (Server)
A->>M: Sends "Login: user123" (unencrypted)
M->>B: Forwards "Login: user123" (stolen credentials)
B-->>M: Returns "Access Granted"
M-->>A: Shows fake "Access Granted" pageReal-World Example: Unsecured Wi-Fi in Kathmandu
- Cafés and hotels often use WEP/WPA (weak encryption), allowing attackers to sniff passwords.
- Solution: eSewa and Khalti now enforce HTTPS + HSTS to prevent MITM on payment pages.
Clock Synchronization in Distributed Systems In distributed systems (e.g., Nepal Stock Exchange (NEPSE) trading platform), clock desynchronization can cause:
- Replay attacks: An attacker records a valid transaction (e.g., stock buy) and replays it later.
- Inconsistent logs: Servers may disagree on the order of events.
Solution: Network Time Protocol (NTP)
- How it works: Servers sync clocks with time.nist.gov (or local NTP servers like ntp.ntc.net.np).
- Example: NEPSE’s trading system uses NTP to timestamp trades, preventing fraudulent replays.
Authentication: Proving You Are Who You Claim
Authentication verifies identity before granting access. Common methods:
1. Password-Based Authentication
- Static passwords: Easy to crack (e.g., brute force, dictionary attacks).
- Improvements:
- Password policies: Enforce complexity (e.g., Ncell SIM PIN: 4-8 digits + letters).
- Salting and hashing: Stores hashed passwords (e.g., SHA-256) with random salts to prevent rainbow table attacks.
Weaknesses:
- Phishing: Fake eSewa login pages trick users into entering credentials.
- Keyloggers: Malware records keystrokes (e.g., 2020 NABIL bank breach).
2. One-Time Passwords (OTP)
OTPs generate a single-use code, reducing replay attack risks.
sequenceDiagram
participant U as User
participant S as Server
participant D as Device (e.g., Authy)
U->>S: Requests OTP
S->>D: Sends OTP via TOTP/HOTP
D-->>U: Displays "123456" (valid for 30s)
U->>S: Submits "123456"
S-->>U: Grants accessTypes of OTPs:
| Type | Mechanism | Example in Nepal |
|---|---|---|
| TOTP | Time-based (e.g., Google Authenticator) | Khalti’s 2FA: Sends a 6-digit code via app. |
| SMS OTP | Sent via text message | eSewa’s login: "Your code is 789012". |
| HOTP | Counter-based (e.g., hardware tokens) | Nepal Rastra Bank’s ATM pins. |
Security Note:
- SMS OTPs are vulnerable to SIM swapping (e.g., attacker calls Ncell to port your number).
- Solution: eSewa now supports app-based OTPs (TOTP) for higher security.
3. Biometric Authentication
Uses unique physical traits for authentication.
Advantages/Disadvantages:
| Biometric | Pros | Cons | Example |
|---|---|---|---|
| Fingerprint | Fast, cheap | Spoofable (silicon fingerprints) | Ncell’s face unlock (vulnerable to photos). |
| Retina | Highly unique | Expensive, invasive | Used in high-security labs. |
| Voice | Non-intrusive | Affected by colds, noise | Siri/Google Assistant. |
Real-World Use in Nepal:
- Nepal Police’s biometric database uses fingerprints for criminal records.
- Khalti’s face authentication (for small transactions) is less secure than OTPs.
4. Multi-Factor Authentication (MFA)
Combines two or more authentication methods for stronger security.
Example: Logging into eSewa
- Factor 1: Password (something you know).
- Factor 2: OTP from Authy app (something you have).
- Factor 3: Fingerprint scan (something you are).
Why MFA?
- Reduces breach impact: Even if passwords are stolen, OTPs prevent access.
- NIST guidelines recommend MFA for all critical systems (e.g., banking, government portals).
Authorization: What You Can Do After Authenticating
Authorization determines permissions after authentication. Models include:
1. Role-Based Access Control (RBAC)
Assigns permissions based on roles (e.g., admin, user).
Example: NTC Network Access
| Role | Permissions |
|---|---|
| Network Admin | Full access to routers, firewalls |
| Technician | Read-only config, limited changes |
| Guest User | Access to Wi-Fi only (no admin panels) |
2. Access Control Lists (ACL)
Granular permissions for specific users/resources.
Example: File Permissions in Linux
ls -l important.txt
# Output: -rw-r--r-- 1 user group 0 Jan 1 10:00 important.txt
# Meaning: Owner (user) can read/write; group/others can read only.
System Hardening: Reducing Attack Surfaces
Hardening minimizes vulnerabilities in OS configurations.
1. Principle of Least Privilege
Users/applications get only the permissions they need.
Example: Bank Servers
- Database user: Can only
SELECT(notDROP TABLE). - Web server: Runs as
www-data(notroot).
2. Disabling Unused Services
Reduces attack surface (e.g., disabling FTP, Telnet in favor of SFTP/SSH).
Command Example (Linux):
sudo systemctl stop ftp
sudo systemctl disable ftp
3. Patch Management
Regularly updating OS/kernel to fix vulnerabilities.
Example: Heartbleed Bug (2014)
- Exploited OpenSSL’s memory leak to steal data.
- NTC patched all routers within 48 hours to prevent exploitation.
Security Policies and Auditing
1. Security Policies
- Password policy: Enforce 12+ character passwords (e.g., Nepal Government IT policy).
- Data classification: Label data as Public, Internal, Confidential (e.g., NRB’s financial data).
2. Auditing and Logging
- SIEM tools (e.g., Splunk) analyze logs for anomalies.
- Example: Ncell’s fraud detection flags unusual login locations (e.g., Kathmandu → Moscow in 5 minutes).
In the Real World
eSewa’s Security Stack
- Authentication: Password + OTP (TOTP) + Biometric (face/fingerprint).
- Authorization: RBAC for merchants (e.g., only approved shops can accept payments).
- Hardening: Disabled PHP’s
allow_url_fopento prevent remote code execution. - Real Example: During Dashain 2023, eSewa blocked 50,000 fraudulent transactions using MFA and anomaly detection.
Ncell’s SIM-Based Authentication
- Uses SIM PIN + OTP for high-value transactions (e.g., mobile banking).
- Problem: SIM swapping attacks (e.g., 2022 $50K stolen from a merchant’s account).
- Solution: Now requires biometric verification for PIN changes.
Nepal Stock Exchange (NEPSE) Security
- Clock synchronization: All trading servers use NTP to prevent replay attacks on stock orders.
- Encryption: TLS 1.3 for all client-server communication.
- Real Example: In 2021, a DDoS attack targeted NEPSE’s website, but rate limiting mitigated the impact.
Exam Tip
Threats vs. Solutions Matching
- Exam Question: "List security problems in OS and explain clock synchronization."
- Answer Strategy:
- Threats: Malware (viruses/worms), DoS, MITM, replay attacks.
- Clock Sync: Use NTP to prevent replay attacks in distributed systems (e.g., NEPSE trading).
- Link: "In NEPSE, desynchronized clocks could allow replay of buy/sell orders, so NTP ensures all servers agree on time."
Authentication Mechanisms
- Exam Question: "Explain OTP and biometric authentication."
- Answer Structure:
- OTP: Time-based (TOTP) or counter-based (HOTP), used in Khalti/eSewa.
- Biometric: Fingerprint/retina, pros/cons, example: Ncell face unlock.
- Comparison Table: Include security vs. convenience trade-offs.
Real-World Scenarios
- Exam Question: "How does eSewa prevent MITM attacks?"
- Answer:
- Uses HTTPS (TLS 1.3) to encrypt traffic.
- Enforces HSTS (HTTP Strict Transport Security).
- MFA: Password + OTP + biometric.
- Example: "If an attacker intercepts eSewa’s login page, TLS ensures data is encrypted, and MFA prevents credential theft."
Hardening Techniques
- Exam Question: "What steps would you take to secure a bank’s server?"
- Answer:
- Disable unused services (e.g., FTP, Telnet).
- Apply least privilege (e.g., database user has no
DROPrights). - Enable MFA for all admin access.
- Patch management (e.g., update OpenSSL after Heartbleed).
- Audit logs with SIEM tools.
Common Pitfalls
- Avoid: Describing firewalls under authentication (it’s a prevention tool, not authentication).
- Do: Link clock sync to distributed systems (e.g., NEPSE, banking).
- Memorize: NIST guidelines for MFA and Nepal’s IT security policies (e.g., NRB’s cybersecurity framework).
Final Note: Always relate theory to Nepalese examples (eSewa, Ncell, NTC, NEPSE). Examiners love real-world applications!
Based on the TU BCA syllabus for Operating System (CACS251), unit 12.
Discussion
Loading…