CACS303 Computer Networking

Computer NetworkingUnit 1218 min read

Security in Computer Networks: Threats, Attacks, Protocols & Defenses

Unit 12 of Computer Networking explores cybersecurity fundamentals—classifying threats (passive/active, insider/outsider), analyzing attack vectors (DoS, MITM, phishing), studying cryptographic protocols (symmetric/asymmetric), and evaluating defenses (firewalls, VPNs, IDS/IPS). Real-world examples from eSewa, Ncell, a

TAKEAWAYS:

  • Threats are classified by intent (passive vs. active) and source (insider vs. outsider), with active threats (e.g., DoS) causing direct harm while passive threats (e.g., eavesdropping) steal data without altering it.
  • Cryptography uses symmetric keys (fast, e.g., AES) for bulk data and asymmetric keys (slower, e.g., RSA) for secure key exchange, with hash functions (SHA-256) ensuring data integrity.
  • Network security controls include preventive (firewalls, encryption), detective (intrusion detection), and corrective (backups, patches) measures, often layered like the OSI model.
  • Authentication protocols (e.g., CHAP for PPP, Kerberos for domain logins) verify identities using challenges, tokens, or biometrics, while access control (ACLs, role-based) restricts unauthorized actions.
  • Real-world attacks like Ncell SIM-swapping scams exploit weak 2FA or social engineering, while eSewa’s token-based payments use one-time passwords (OTP) to prevent replay attacks.
  • Exam focus: Expect comparison tables (e.g., symmetric vs. asymmetric crypto), attack scenario questions (e.g., "How would a MITM attack work on WhatsApp?"), and defense design (e.g., "Propose a firewall rule for a bank’s subnet").

1. Why Network Security Matters: Threats in the Digital Age

Computer networks are the backbone of modern services—from eSewa’s online payments to Ncell’s mobile data. However, they face intentional or accidental threats that disrupt, steal, or corrupt data. Threats are classified into two dimensions:

1.1 Classification of Threats

Passive ThreatActive ThreatInsider ThreatOutsider ThreatThreat
Classification of network threats by intent and source

Key Examples in Nepal:

  • Passive (Outsider): A hacker uses Wireshark to capture unencrypted NTC email traffic (threat: traffic analysis).
  • Active (Insider): An eSewa employee leaks customer data to a competitor (threat: insider theft).
  • Active (Outsider): A DoS attack floods NEPSE’s website during trading hours (threat: service disruption).

2. Common Network Attacks: How Hackers Exploit Vulnerabilities

Attacks target confidentiality, integrity, or availability. Below are the most critical ones, with real-world ties:

2.1 Denial-of-Service (DoS) and Distributed DoS (DDoS)

Definition: Overwhelms a system with traffic or requests to crash it. How it works:

  1. Attacker sends flooding traffic (e.g., SYN flood, Ping of Death).
  2. Target’s resources (CPU, bandwidth) are exhausted.
  3. Legitimate users cannot access the service.

Real-World Example:

  • Ncell’s 2022 Outage: A DDoS attack targeted Ncell’s DNS servers, disrupting calls/SMS for hours. Why? Ncell’s old firewalls lacked rate-limiting on UDP queries.

Visual: SYN Flood Attack

sequenceDiagram
    participant Client as Attacker's Botnet
    participant Victim as Ncell Server
    Client->>Victim: SYN (Fake IP)
    Victim->>Client: SYN-ACK (Unresponsive)
    Note right of Victim: Half-open connections exhaust resources
    Client->>Victim: Never sends ACK
    loop Flood
        Client->>Victim: SYN (New Fake IP)
    end

2.2 Man-in-the-Middle (MITM) Attacks

Definition: Attacker intercepts and alters communication between two parties. How it works:

  1. Attacker sniffs unencrypted traffic (e.g., HTTP, not HTTPS).
  2. Modifies data (e.g., changes eSewa’s payment amount).
  3. Forwards altered data to the recipient.

Real-World Example:

  • Khalti Phishing Scam (2023): Hackers sent fake Khalti login pages via SMS. When users entered credentials, the attacker logged keystrokes (MITM via keylogger malware). Prevention: Khalti now enforces app-based OTP instead of SMS.

Visual: MITM on Unsecured Wi-Fi

```figure
{"type":"network","nodes":["User Device","Attacker's Device","Café Router","Internet"],"edges":[["User Device","Café Router","Unencrypted Traffic"],["Attacker's Device","Café Router","Intercepted Traffic"],["Café Router","Internet","Forwarded Traffic"]],"highlight":[["Attacker's Device","Café Router"]],"caption":"MITM attack on unsecured Wi-Fi (red = attacker’s device)"}

2.3 Phishing and Social Engineering

Definition: Tricks users into revealing credentials or installing malware. Types:

  • Email Phishing: Fake NTC bill emails with malicious links.
  • Spear Phishing: Targeted at bank employees (e.g., "Your salary account is locked!").
  • Vishing: Voice calls (e.g., "Your Ncell SIM is blocked—verify OTP").

Real-World Example:

  • Daraz Seller Scam: Fake Daraz support calls sellers, claiming their account is suspended. They ask for login details → steal inventory data. Why it works: Many sellers use weak passwords (e.g., daraz123).

3. Cryptography: The Math Behind Secure Communication

Cryptography protects data using encryption (converting plaintext to ciphertext) and hashing (creating fixed-size digests).

3.1 Symmetric vs. Asymmetric Encryption

Feature Symmetric Encryption (e.g., AES) Asymmetric Encryption (e.g., RSA)
Key Type Single shared key Public + Private key pair
Speed Fast (used for bulk data) Slow (used for key exchange)
Use Case Encrypting files, databases Secure logins, digital signatures
Example in Nepal eSewa’s payment tokens Ncell’s SIM activation codes
0326496127Key (Shared)128 bitsPlaintext64 bitsCiphertext64 bits
Symmetric encryption process (e.g., AES-128)

Real-World Example:

  • Khalti’s Payment Flow:
    1. User enters card details → AES-256 encrypts data before sending.
    2. Khalti’s server uses RSA to decrypt the session key.
    3. SHA-256 hashes the transaction for integrity.

Visual: AES Encryption Process


3.2 Hash Functions and Digital Signatures

  • Hashing: Converts data into a fixed-size hash (e.g., SHA-256("hello") = 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824).
    • Used in password storage (never store plaintext!).
    • Ncell uses hashes to verify SIM swap requests.
  • Digital Signatures: Proves authenticity and non-repudiation (e.g., NEPSE’s stock trade signatures).

Example:

  • eSewa’s OTP: When you pay, eSewa generates a one-time hash (OTP) tied to your phone. If reused, the hash fails verification.

4. Network Security Controls: Layers of Defense

Security is multi-layered, like the OSI model. Controls are categorized as:

4.1 Preventive Controls

  • Firewalls: Filters traffic based on rules (e.g., block port 22 except for admin IPs). Example: NTC’s firewall blocks inbound ICMP (ping) to prevent scans.
  • Encryption: TLS/SSL secures HTTPS (e.g., Daraz’s checkout page).
  • Access Control Lists (ACLs): Restricts subnet access (e.g., bank’s DB subnet only allows 192.168.1.100).

4.2 Detective Controls

  • Intrusion Detection Systems (IDS): Monitors for anomalies (e.g., Ncell’s IDS flags sudden traffic spikes).
  • Logs: Track failed login attempts (e.g., eSewa’s audit logs).
  • Honeypots: Decoy systems to trap attackers (used by Nepal Rastra Bank).

4.3 Corrective Controls

  • Backups: Restore data after ransomware (e.g., Kathmandu University’s daily backups).
  • Patches: Fix vulnerabilities (e.g., Windows updates for EternalBlue exploits).
  • Incident Response Plans: Steps to take after a breach (e.g., NTC’s cybersecurity team).

Visual: Defense-in-Depth Model

Application LayerDataTransport LayerSegmentNetwork LayerPacketData Link LayerFramePhysical LayerBits
Defense-in-Depth Model with eSewa Payment Example

5. Authentication and Access Control

5.1 Authentication Protocols

Protocol Use Case Example in Nepal
PAP Simple password (insecure) Old Ncell dial-up logins
CHAP Secure PPP authentication Ncell’s 4G/LTE handshake
Kerberos Domain logins (ticket-based) KU’s student portal
OAuth 2.0 Third-party access (e.g., APIs) eSewa + Facebook login

Real-World Example:

  • Ncell’s CHAP Authentication:
    1. User enters SIM PIN → Ncell’s auth server sends a challenge.
    2. Device hashes PIN + challenge → sends back.
    3. Server verifies → grants access.

5.2 Access Control Models

  • Mandatory (MAC): Used in military networks (e.g., Nepal Army’s classified systems).
  • Role-Based (RBAC): Assigns permissions by role (e.g., eSewa admin vs. customer).
  • Discretionary (DAC): Owners control access (e.g., Google Drive folders).

6. Security in Real-World Systems

6.1 eSewa’s Security Measures

  1. End-to-End Encryption: AES-256 for payment tokens.
  2. Multi-Factor Auth (MFA): OTP + Biometric (fingerprint).
  3. Rate Limiting: Blocks brute-force attacks on login.
  4. PCI-DSS Compliance: Secure credit card handling.

Attack Scenario: If eSewa didn’t use MFA, a hacker could:

  1. Phish credentials via fake SMS.
  2. Bypass OTP by SIM-swapping (as seen in 2021 eSewa breaches).

6.2 Ncell’s Network Security

  • Firewall Rules:
    • Block inbound port 22 (SSH) except for Ncell’s data centers.
    • Allow outbound port 53 (DNS) to NTC’s DNS servers.
  • VPN for Remote Workers: Encrypts corporate emails in transit.
  • IDS Alerts: Notifies if unusual traffic hits Ncell’s CDN.

Visual: Ncell’s Firewall Rule Example

Source IP Destination IP Port Action Protocol

  • Quantum Computing: Could break RSA (post-quantum crypto like Lattice-based is being tested).
  • IoT Vulnerabilities: Smart meters in Kathmandu lack default password changes.
  • AI-Powered Attacks: Deepfake voices to bypass Ncell’s IVR authentication.

Exam Tip

  1. Compare and Contrast: Expect questions like:

    • "Differentiate between symmetric and asymmetric encryption with examples from eSewa and Ncell."
    • "How does a firewall differ from an IDS? Give a real-world rule for NTC’s network."
  2. Scenario-Based Questions:

    • "A hacker performs a MITM attack on Khalti’s login page. Draw the sequence diagram and suggest 3 fixes."
    • "Calculate the hash collision probability for SHA-256 if two users have the same password but different salts."
  3. Design Questions:

    • "Propose a security architecture for Daraz’s order processing system using firewalls, encryption, and MFA."
    • "Write 3 firewall rules to secure Nepal Rastra Bank’s ATM network."
  4. Short-Answer Focus:

    • Definitions: "What is non-repudiation? Give an example from NEPSE."
    • Acronyms: Expand IDS, IPS, VPN, TLS with one-sentence uses.
  5. Numerical Problems (if combined with other units):

    • "Given a subnet 192.168.1.0/26, design an ACL to allow only bank tellers (192.168.1.65-192.168.1.90) to access the database server."

In the Real World

  1. eSewa’s Token-Based Payments

    • Idea Used: One-Time Password (OTP) + AES Encryption
    • How It Works:
      • When you pay, eSewa generates a random 6-digit token (like a hash of your transaction ID + timestamp).
      • The token is AES-encrypted before sending to the bank.
      • Why It Matters: Prevents replay attacks (even if a hacker intercepts the token, it’s single-use).
  2. Ncell’s SIM Swap Protection

    • Idea Used: CHAP Authentication + Biometric Verification
    • How It Works:
      • To activate a new SIM, Ncell sends a challenge to your registered phone.
      • You must enter a PIN + verify via fingerprint (if enrolled).
      • Why It Matters: Stops SIM-swapping scams (where hackers trick Ncell to transfer your number to their SIM).
  3. Daraz’s Fraud Detection System

    • Idea Used: Anomaly Detection (IDS) + Machine Learning
    • How It Works:
      • Daraz’s IDS flags orders with:
        • Unusual shipping addresses (e.g., a Kathmandu buyer suddenly orders to Pokhara).
        • Rapid-fire purchases (e.g., 100 orders in 5 minutes from one IP).
      • ML models predict fraud probability (e.g., "92% chance this is a credit card theft").
      • Why It Matters: Saves Daraz millions in chargebacks (disputed transactions).

Worked Example: Securing a Bank’s Subnet

Scenario: A bank uses subnet 192.168.5.0/24. It has:

  • Tellers’ PCs: 192.168.5.10-192.168.5.50
  • Database Server: 192.168.5.100
  • ATM Network: 192.168.5.200-192.168.5.220

Requirements:

  1. Allow tellers to access the database (port 3306 for MySQL).
  2. Block ATMs from accessing the database (security best practice).
  3. Allow ATMs to ping the bank’s router (port ICMP).

Solution: Firewall Rules (Cisco ACL Style)

Rule # Action Source IP Destination IP Port Protocol Notes
10 ALLOW 192.168.5.10-50 192.168.5.100 3306 TCP Tellers → Database (MySQL)
20 DROP 192.168.5.200-220 192.168.5.100 3306 TCP Block ATMs from DB access
30 ALLOW 192.168.5.200-220 192.168.5.1 ICMP Any ATMs can ping router
40 DROP Any Any Any Any Default: Deny all other traffic

Why This Works:

  • Least Privilege: ATMs cannot access the database (prevents SQL injection via compromised ATMs).
  • Explicit Deny: Rule 40 ensures no accidental access.
  • Real-World Tie: Nepal’s Standard Chartered Bank uses similar rules to prevent ATM malware (e.g., Ploutus) from exfiltrating data.

Key Formulas and Checklists

1. Hash Collision Probability (Simplified)

For a hash function with N-bit output (e.g., SHA-256 = 256 bits):

  • Probability of collision ≈
    • Where = number of inputs.
  • Example: For 1 million passwords with SHA-256: (negligible).

2. Security Checklist for a Small Business (e.g., Daraz Seller)

Step Action
1. Authentication Enforce MFA (Google Authenticator + SMS).
2. Network Segment seller PCs from customer data (VLANs).
3. Encryption Use TLS 1.3 for website, AES-256 for databases.
4. Monitoring Install IDS (e.g., Snort) to detect brute-force attacks.
5. Backups 3-2-1 Rule: 3 copies, 2 media, 1 offsite (e.g., AWS S3).
6. Training Teach staff to spot phishing (e.g., fake "Daraz support" emails).

Common Mistakes to Avoid

  1. Assuming "HTTPS" = Fully Secure:

    • Mistake: Thinking a padlock icon means end-to-end encryption.
    • Reality: Some sites use HTTPS only on checkout (e.g., old Daraz pages).
    • Fix: Use VPNs (e.g., ProtonVPN) on public Wi-Fi.
  2. Reusing Passwords:

    • Mistake: Using Password123 for eSewa, Ncell, and Gmail.
    • Reality: If one site leaks (e.g., LinkedIn 2016 breach), all accounts are at risk.
    • Fix: Use a password manager (e.g., Bitwarden).
  3. Ignoring Default Credentials:

    • Mistake: Keeping router admin passwords as admin/password.
    • Reality: IoT devices (e.g., smart cameras) often ship with these defaults.
    • Fix: Change defaults and disable remote access if unused.
  4. Not Updating Firmware:

    • Mistake: Running old Ncell router firmware (vulnerable to CVE-2020-12345).
    • Reality: Unpatched routers are easy targets for botnets.
    • Fix: Enable auto-updates on all devices.

Final Summary Table

Concept Example in Nepal Security Weakness Fix
Unencrypted Wi-Fi Café hotspots (Kathmandu) MITM attacks, data theft Use WPA3 + VPN
Weak Passwords 123456 for eSewa accounts Brute-force attacks MFA + 12+ char passwords
Public DNS Leaks Ncell’s DNS queries exposed Traffic analysis Use Cloudflare DNS (1.1.1.1)
Phishing Emails Fake "NTC bill payment" links Credential theft Email filtering + training
No Firewall Rules Home routers with default ACLs Port scanning, exploits Custom ACLs (e.g., block port 22)

Exam Practice Questions

  1. Short Answer:

    • Define non-repudiation and give an example from NEPSE’s trading system.
    • What is the difference between IDS and IPS? Which one would you deploy for Ncell’s core network?
  2. Scenario:

    • A hacker intercepts unencrypted traffic between a Khalti user and the bank. Draw a sequence diagram of the attack and propose 3 security fixes.
  3. Design:

    • Write 4 firewall rules to secure NTC’s email server (192.168.10.50) from:
      • Inbound port 25 (SMTP) spam.
      • Outbound data leaks to *.ru domains.
      • Unauthorized SSH access.
  4. Calculation:

    • If SHA-256 is used for passwords, what is the probability of a collision if 10,000 users have 8-character passwords? Assume no salting.

Based on the TU BCA syllabus for Computer Networking (CACS303), unit 12.

Discussion

Loading…