Computer NetworkingUnit 1218 min read
Security in Computer Networks: Threats, Attacks, Protocols & Defenses
Unit 12 of Computer Networking explores cybersecurity fundamentals—classifying threats (passive/active, insider/outsider), analyzing attack vectors (DoS, MITM, phishing), studying cryptographic protocols (symmetric/asymmetric), and evaluating defenses (firewalls, VPNs, IDS/IPS). Real-world examples from eSewa, Ncell, a
TAKEAWAYS:
- Threats are classified by intent (passive vs. active) and source (insider vs. outsider), with active threats (e.g., DoS) causing direct harm while passive threats (e.g., eavesdropping) steal data without altering it.
- Cryptography uses symmetric keys (fast, e.g., AES) for bulk data and asymmetric keys (slower, e.g., RSA) for secure key exchange, with hash functions (SHA-256) ensuring data integrity.
- Network security controls include preventive (firewalls, encryption), detective (intrusion detection), and corrective (backups, patches) measures, often layered like the OSI model.
- Authentication protocols (e.g., CHAP for PPP, Kerberos for domain logins) verify identities using challenges, tokens, or biometrics, while access control (ACLs, role-based) restricts unauthorized actions.
- Real-world attacks like Ncell SIM-swapping scams exploit weak 2FA or social engineering, while eSewa’s token-based payments use one-time passwords (OTP) to prevent replay attacks.
- Exam focus: Expect comparison tables (e.g., symmetric vs. asymmetric crypto), attack scenario questions (e.g., "How would a MITM attack work on WhatsApp?"), and defense design (e.g., "Propose a firewall rule for a bank’s subnet").
1. Why Network Security Matters: Threats in the Digital Age
Computer networks are the backbone of modern services—from eSewa’s online payments to Ncell’s mobile data. However, they face intentional or accidental threats that disrupt, steal, or corrupt data. Threats are classified into two dimensions:
1.1 Classification of Threats
Key Examples in Nepal:
- Passive (Outsider): A hacker uses Wireshark to capture unencrypted NTC email traffic (threat: traffic analysis).
- Active (Insider): An eSewa employee leaks customer data to a competitor (threat: insider theft).
- Active (Outsider): A DoS attack floods NEPSE’s website during trading hours (threat: service disruption).
2. Common Network Attacks: How Hackers Exploit Vulnerabilities
Attacks target confidentiality, integrity, or availability. Below are the most critical ones, with real-world ties:
2.1 Denial-of-Service (DoS) and Distributed DoS (DDoS)
Definition: Overwhelms a system with traffic or requests to crash it. How it works:
- Attacker sends flooding traffic (e.g., SYN flood, Ping of Death).
- Target’s resources (CPU, bandwidth) are exhausted.
- Legitimate users cannot access the service.
Real-World Example:
- Ncell’s 2022 Outage: A DDoS attack targeted Ncell’s DNS servers, disrupting calls/SMS for hours. Why? Ncell’s old firewalls lacked rate-limiting on UDP queries.
Visual: SYN Flood Attack
sequenceDiagram
participant Client as Attacker's Botnet
participant Victim as Ncell Server
Client->>Victim: SYN (Fake IP)
Victim->>Client: SYN-ACK (Unresponsive)
Note right of Victim: Half-open connections exhaust resources
Client->>Victim: Never sends ACK
loop Flood
Client->>Victim: SYN (New Fake IP)
end2.2 Man-in-the-Middle (MITM) Attacks
Definition: Attacker intercepts and alters communication between two parties. How it works:
- Attacker sniffs unencrypted traffic (e.g., HTTP, not HTTPS).
- Modifies data (e.g., changes eSewa’s payment amount).
- Forwards altered data to the recipient.
Real-World Example:
- Khalti Phishing Scam (2023): Hackers sent fake Khalti login pages via SMS. When users entered credentials, the attacker logged keystrokes (MITM via keylogger malware). Prevention: Khalti now enforces app-based OTP instead of SMS.
Visual: MITM on Unsecured Wi-Fi
```figure
{"type":"network","nodes":["User Device","Attacker's Device","Café Router","Internet"],"edges":[["User Device","Café Router","Unencrypted Traffic"],["Attacker's Device","Café Router","Intercepted Traffic"],["Café Router","Internet","Forwarded Traffic"]],"highlight":[["Attacker's Device","Café Router"]],"caption":"MITM attack on unsecured Wi-Fi (red = attacker’s device)"}
2.3 Phishing and Social Engineering
Definition: Tricks users into revealing credentials or installing malware. Types:
- Email Phishing: Fake NTC bill emails with malicious links.
- Spear Phishing: Targeted at bank employees (e.g., "Your salary account is locked!").
- Vishing: Voice calls (e.g., "Your Ncell SIM is blocked—verify OTP").
Real-World Example:
- Daraz Seller Scam: Fake Daraz support calls sellers, claiming their account is suspended. They ask for login details → steal inventory data.
Why it works: Many sellers use weak passwords (e.g.,
daraz123).
3. Cryptography: The Math Behind Secure Communication
Cryptography protects data using encryption (converting plaintext to ciphertext) and hashing (creating fixed-size digests).
3.1 Symmetric vs. Asymmetric Encryption
| Feature | Symmetric Encryption (e.g., AES) | Asymmetric Encryption (e.g., RSA) |
|---|---|---|
| Key Type | Single shared key | Public + Private key pair |
| Speed | Fast (used for bulk data) | Slow (used for key exchange) |
| Use Case | Encrypting files, databases | Secure logins, digital signatures |
| Example in Nepal | eSewa’s payment tokens | Ncell’s SIM activation codes |
Real-World Example:
- Khalti’s Payment Flow:
- User enters card details → AES-256 encrypts data before sending.
- Khalti’s server uses RSA to decrypt the session key.
- SHA-256 hashes the transaction for integrity.
Visual: AES Encryption Process
3.2 Hash Functions and Digital Signatures
- Hashing: Converts data into a fixed-size hash (e.g.,
SHA-256("hello") = 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824).- Used in password storage (never store plaintext!).
- Ncell uses hashes to verify SIM swap requests.
- Digital Signatures: Proves authenticity and non-repudiation (e.g., NEPSE’s stock trade signatures).
Example:
- eSewa’s OTP: When you pay, eSewa generates a one-time hash (OTP) tied to your phone. If reused, the hash fails verification.
4. Network Security Controls: Layers of Defense
Security is multi-layered, like the OSI model. Controls are categorized as:
4.1 Preventive Controls
- Firewalls: Filters traffic based on rules (e.g., block port
22except for admin IPs). Example: NTC’s firewall blocks inbound ICMP (ping) to prevent scans. - Encryption: TLS/SSL secures HTTPS (e.g., Daraz’s checkout page).
- Access Control Lists (ACLs): Restricts subnet access (e.g., bank’s DB subnet only allows
192.168.1.100).
4.2 Detective Controls
- Intrusion Detection Systems (IDS): Monitors for anomalies (e.g., Ncell’s IDS flags sudden traffic spikes).
- Logs: Track failed login attempts (e.g., eSewa’s audit logs).
- Honeypots: Decoy systems to trap attackers (used by Nepal Rastra Bank).
4.3 Corrective Controls
- Backups: Restore data after ransomware (e.g., Kathmandu University’s daily backups).
- Patches: Fix vulnerabilities (e.g., Windows updates for EternalBlue exploits).
- Incident Response Plans: Steps to take after a breach (e.g., NTC’s cybersecurity team).
Visual: Defense-in-Depth Model
5. Authentication and Access Control
5.1 Authentication Protocols
| Protocol | Use Case | Example in Nepal |
|---|---|---|
| PAP | Simple password (insecure) | Old Ncell dial-up logins |
| CHAP | Secure PPP authentication | Ncell’s 4G/LTE handshake |
| Kerberos | Domain logins (ticket-based) | KU’s student portal |
| OAuth 2.0 | Third-party access (e.g., APIs) | eSewa + Facebook login |
Real-World Example:
- Ncell’s CHAP Authentication:
- User enters SIM PIN → Ncell’s auth server sends a challenge.
- Device hashes PIN + challenge → sends back.
- Server verifies → grants access.
5.2 Access Control Models
- Mandatory (MAC): Used in military networks (e.g., Nepal Army’s classified systems).
- Role-Based (RBAC): Assigns permissions by role (e.g., eSewa admin vs. customer).
- Discretionary (DAC): Owners control access (e.g., Google Drive folders).
6. Security in Real-World Systems
6.1 eSewa’s Security Measures
- End-to-End Encryption: AES-256 for payment tokens.
- Multi-Factor Auth (MFA): OTP + Biometric (fingerprint).
- Rate Limiting: Blocks brute-force attacks on login.
- PCI-DSS Compliance: Secure credit card handling.
Attack Scenario: If eSewa didn’t use MFA, a hacker could:
- Phish credentials via fake SMS.
- Bypass OTP by SIM-swapping (as seen in 2021 eSewa breaches).
6.2 Ncell’s Network Security
- Firewall Rules:
- Block inbound port 22 (SSH) except for Ncell’s data centers.
- Allow outbound port 53 (DNS) to NTC’s DNS servers.
- VPN for Remote Workers: Encrypts corporate emails in transit.
- IDS Alerts: Notifies if unusual traffic hits Ncell’s CDN.
Visual: Ncell’s Firewall Rule Example
| Source IP | Destination IP | Port | Action | Protocol |
|---|
7. Emerging Threats and Future Trends
- Quantum Computing: Could break RSA (post-quantum crypto like Lattice-based is being tested).
- IoT Vulnerabilities: Smart meters in Kathmandu lack default password changes.
- AI-Powered Attacks: Deepfake voices to bypass Ncell’s IVR authentication.
Exam Tip
Compare and Contrast: Expect questions like:
- "Differentiate between symmetric and asymmetric encryption with examples from eSewa and Ncell."
- "How does a firewall differ from an IDS? Give a real-world rule for NTC’s network."
Scenario-Based Questions:
- "A hacker performs a MITM attack on Khalti’s login page. Draw the sequence diagram and suggest 3 fixes."
- "Calculate the hash collision probability for SHA-256 if two users have the same password but different salts."
Design Questions:
- "Propose a security architecture for Daraz’s order processing system using firewalls, encryption, and MFA."
- "Write 3 firewall rules to secure Nepal Rastra Bank’s ATM network."
Short-Answer Focus:
- Definitions: "What is non-repudiation? Give an example from NEPSE."
- Acronyms: Expand IDS, IPS, VPN, TLS with one-sentence uses.
Numerical Problems (if combined with other units):
- "Given a subnet 192.168.1.0/26, design an ACL to allow only bank tellers (192.168.1.65-192.168.1.90) to access the database server."
In the Real World
eSewa’s Token-Based Payments
- Idea Used: One-Time Password (OTP) + AES Encryption
- How It Works:
- When you pay, eSewa generates a random 6-digit token (like a hash of your transaction ID + timestamp).
- The token is AES-encrypted before sending to the bank.
- Why It Matters: Prevents replay attacks (even if a hacker intercepts the token, it’s single-use).
Ncell’s SIM Swap Protection
- Idea Used: CHAP Authentication + Biometric Verification
- How It Works:
- To activate a new SIM, Ncell sends a challenge to your registered phone.
- You must enter a PIN + verify via fingerprint (if enrolled).
- Why It Matters: Stops SIM-swapping scams (where hackers trick Ncell to transfer your number to their SIM).
Daraz’s Fraud Detection System
- Idea Used: Anomaly Detection (IDS) + Machine Learning
- How It Works:
- Daraz’s IDS flags orders with:
- Unusual shipping addresses (e.g., a Kathmandu buyer suddenly orders to Pokhara).
- Rapid-fire purchases (e.g., 100 orders in 5 minutes from one IP).
- ML models predict fraud probability (e.g., "92% chance this is a credit card theft").
- Why It Matters: Saves Daraz millions in chargebacks (disputed transactions).
- Daraz’s IDS flags orders with:
Worked Example: Securing a Bank’s Subnet
Scenario: A bank uses subnet 192.168.5.0/24. It has:
- Tellers’ PCs:
192.168.5.10-192.168.5.50 - Database Server:
192.168.5.100 - ATM Network:
192.168.5.200-192.168.5.220
Requirements:
- Allow tellers to access the database (port
3306for MySQL). - Block ATMs from accessing the database (security best practice).
- Allow ATMs to ping the bank’s router (port
ICMP).
Solution: Firewall Rules (Cisco ACL Style)
| Rule # | Action | Source IP | Destination IP | Port | Protocol | Notes |
|---|---|---|---|---|---|---|
| 10 | ALLOW | 192.168.5.10-50 | 192.168.5.100 | 3306 | TCP | Tellers → Database (MySQL) |
| 20 | DROP | 192.168.5.200-220 | 192.168.5.100 | 3306 | TCP | Block ATMs from DB access |
| 30 | ALLOW | 192.168.5.200-220 | 192.168.5.1 | ICMP | Any | ATMs can ping router |
| 40 | DROP | Any | Any | Any | Any | Default: Deny all other traffic |
Why This Works:
- Least Privilege: ATMs cannot access the database (prevents SQL injection via compromised ATMs).
- Explicit Deny: Rule
40ensures no accidental access. - Real-World Tie: Nepal’s Standard Chartered Bank uses similar rules to prevent ATM malware (e.g., Ploutus) from exfiltrating data.
Key Formulas and Checklists
1. Hash Collision Probability (Simplified)
For a hash function with N-bit output (e.g., SHA-256 = 256 bits):
- Probability of collision ≈
- Where = number of inputs.
- Example: For 1 million passwords with SHA-256: (negligible).
2. Security Checklist for a Small Business (e.g., Daraz Seller)
| Step | Action |
|---|---|
| 1. Authentication | Enforce MFA (Google Authenticator + SMS). |
| 2. Network | Segment seller PCs from customer data (VLANs). |
| 3. Encryption | Use TLS 1.3 for website, AES-256 for databases. |
| 4. Monitoring | Install IDS (e.g., Snort) to detect brute-force attacks. |
| 5. Backups | 3-2-1 Rule: 3 copies, 2 media, 1 offsite (e.g., AWS S3). |
| 6. Training | Teach staff to spot phishing (e.g., fake "Daraz support" emails). |
Common Mistakes to Avoid
Assuming "HTTPS" = Fully Secure:
- Mistake: Thinking a padlock icon means end-to-end encryption.
- Reality: Some sites use HTTPS only on checkout (e.g., old Daraz pages).
- Fix: Use VPNs (e.g., ProtonVPN) on public Wi-Fi.
Reusing Passwords:
- Mistake: Using
Password123for eSewa, Ncell, and Gmail. - Reality: If one site leaks (e.g., LinkedIn 2016 breach), all accounts are at risk.
- Fix: Use a password manager (e.g., Bitwarden).
- Mistake: Using
Ignoring Default Credentials:
- Mistake: Keeping router admin passwords as
admin/password. - Reality: IoT devices (e.g., smart cameras) often ship with these defaults.
- Fix: Change defaults and disable remote access if unused.
- Mistake: Keeping router admin passwords as
Not Updating Firmware:
- Mistake: Running old Ncell router firmware (vulnerable to CVE-2020-12345).
- Reality: Unpatched routers are easy targets for botnets.
- Fix: Enable auto-updates on all devices.
Final Summary Table
| Concept | Example in Nepal | Security Weakness | Fix |
|---|---|---|---|
| Unencrypted Wi-Fi | Café hotspots (Kathmandu) | MITM attacks, data theft | Use WPA3 + VPN |
| Weak Passwords | 123456 for eSewa accounts |
Brute-force attacks | MFA + 12+ char passwords |
| Public DNS Leaks | Ncell’s DNS queries exposed | Traffic analysis | Use Cloudflare DNS (1.1.1.1) |
| Phishing Emails | Fake "NTC bill payment" links | Credential theft | Email filtering + training |
| No Firewall Rules | Home routers with default ACLs | Port scanning, exploits | Custom ACLs (e.g., block port 22) |
Exam Practice Questions
Short Answer:
- Define non-repudiation and give an example from NEPSE’s trading system.
- What is the difference between IDS and IPS? Which one would you deploy for Ncell’s core network?
Scenario:
- A hacker intercepts unencrypted traffic between a Khalti user and the bank. Draw a sequence diagram of the attack and propose 3 security fixes.
Design:
- Write 4 firewall rules to secure NTC’s email server (192.168.10.50) from:
- Inbound port 25 (SMTP) spam.
- Outbound data leaks to
*.rudomains. - Unauthorized SSH access.
- Write 4 firewall rules to secure NTC’s email server (192.168.10.50) from:
Calculation:
- If SHA-256 is used for passwords, what is the probability of a collision if 10,000 users have 8-character passwords? Assume no salting.
Based on the TU BCA syllabus for Computer Networking (CACS303), unit 12.
Discussion
Loading…