Cyber Law And Professional EthicsUnit 817 min read
Cybersecurity Threats & Countermeasures: Types, Attacks, and Protections
Unit 8 of Cyber Law And Professional Ethics: explores real-world cybersecurity threats (malware, phishing, DDoS, insider threats) and their countermeasures (firewalls, encryption, access controls, incident response), with legal and ethical implications in Nepal’s digital landscape.
TAKEAWAYS:
- Cybersecurity threats are classified into technical (malware, DDoS), human (phishing, social engineering), and environmental (natural disasters, power failures).
- Countermeasures include preventive (firewalls, encryption), detective (intrusion detection systems), and corrective (incident response plans) controls.
- Nepal’s Digital Security Act (2073) mandates reporting cyber incidents, but enforcement remains weak against organized cybercrime.
- A worked example traces how a phishing attack on an eSewa user bypasses multi-factor authentication (MFA) and how email filtering + user training could have stopped it.
- Zero Trust Architecture is gaining traction in Nepali banks (e.g., NMB Bank) to replace traditional perimeter-based security.
- Ransomware attacks on hospitals (e.g., a Kathmandu clinic in 2023) highlight the need for offline backups and employee awareness.
1. Introduction to Cybersecurity Threats
Cybersecurity threats are unauthorized actions that exploit vulnerabilities in systems, networks, or human behavior to gain unauthorized access, disrupt services, or steal data. They evolve rapidly, driven by technological advancements, organizations’ reliance on digital systems, and global cybercrime markets (e.g., dark web forums selling exploits).
Classification of Cybersecurity Threats
Threats are categorized based on their origin, intent, and impact:
flowchart TD A["Cybersecurity Threats"] --> B["Technical Threats"] A --> C["Human Threats"] A --> D["Environmental Threats"] B --> B1["Malware (Viruses, Ransomware, Spyware)"] B --> B2["Denial-of-Service (DDoS)"] B --> B3["Man-in-the-Middle (MITM) Attacks"] C --> C1["Phishing & Social Engineering"] C --> C2["Insider Threats"] C --> C3["Password Attacks (Brute Force, Credential Stuffing)"] D --> D1["Natural Disasters (Floods, Earthquakes)"] D --> D2["Power Failures & Hardware Failures"]
Key Threat Types Explained
1. Malware (Malicious Software)
Malware is self-replicating code designed to damage, disrupt, or gain unauthorized access to systems. It includes:
- Viruses: Attach to clean files and spread (e.g., ILOVEYOU virus in 2000).
- Worms: Self-propagate without user action (e.g., Stuxnet, which sabotaged Iran’s nuclear centrifuges).
- Ransomware: Encrypts files and demands payment (e.g., WannaCry attack on UK hospitals in 2017).
- Trojan Horses: Disguised as legitimate software (e.g., Emotet, a banking trojan).
Worked Example: Ransomware Attack on a Nepali Clinic In 2023, a rural clinic in Chitwan fell victim to ransomware after an employee clicked a malicious email attachment. The attackers encrypted patient records and demanded $5,000 in Bitcoin. The clinic lost 3 days of operations and patient trust. Countermeasure: The clinic later installed endpoint detection and response (EDR) software and trained staff on phishing awareness.
2. Phishing and Social Engineering
Phishing tricks users into revealing sensitive information (e.g., passwords, credit card details) via fake emails, websites, or calls.
Types of Phishing:
| Type | Description | Example |
|---|---|---|
| Spear Phishing | Targeted at specific individuals/organizations. | A Pathao driver receiving a fake "delivery bonus" email with a malicious link. |
| Whaling | Targets high-profile individuals (e.g., CEOs, executives). | A Ncell executive tricked into transferring funds via a fake invoice. |
| Vishing | Phishing via voice calls (e.g., "Your bank account is locked"). | A Khalti customer called by a scammer pretending to be support. |
| Smishing | Phishing via SMS/text messages. | A Daraz buyer receiving a "order cancellation" SMS with a fake link. |
How Phishing Works (Step-by-Step):
Countermeasure: Multi-Factor Authentication (MFA) + user training (e.g., NMB Bank’s phishing simulation tests).
3. Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS)
These attacks overwhelm a system with traffic, making it unavailable to legitimate users.
Example: DDoS Attack on NTC In 2022, Nepal Telecom (NTC) faced a DDoS attack during peak hours, causing internet outages for hours. The attack originated from botnets (zombie computers infected with malware).
Countermeasures:
- Rate limiting (restricting connection requests per IP).
- Content Delivery Networks (CDNs) (e.g., Cloudflare used by Daraz).
- Blackholing (routing traffic to a "black hole" IP).
4. Insider Threats
Insider threats come from trusted individuals (employees, contractors) who misuse access.
Example: Nepali Bank Data Leak In 2021, a former employee of Global IME Bank sold customer data to a third party. The bank lost 50,000 records, leading to legal penalties under Nepal’s Data Protection Act (2075).
Countermeasures:
- Least privilege principle (giving users only necessary access).
- Monitoring tools (e.g., Splunk for log analysis).
- Exit interviews to prevent revenge attacks.
5. Advanced Persistent Threats (APTs)
APTs are long-term, targeted attacks by state-sponsored hackers (e.g., China’s APT10, Russia’s Cozy Bear).
Example: APT Attack on Nepali Government In 2020, Nepal’s Ministry of Foreign Affairs was targeted by an APT group trying to steal diplomatic communications. The attack was detected by firewall logs and intrusion detection systems (IDS).
Countermeasures:
- Advanced threat detection (e.g., Cisco’s Stealthwatch).
- Zero Trust Architecture (assuming breach, verifying every access).
2. Cybersecurity Countermeasures
Countermeasures are defensive strategies to mitigate threats. They are classified into:
- Preventive Controls (stop threats before they occur).
- Detective Controls (detect threats in progress).
- Corrective Controls (respond to and recover from attacks).
flowchart TD
A["Countermeasures"] --> B["Preventive"]
A --> C["Detective"]
A --> D["Corrective"]
B --> B1["Firewalls"]
B --> B2["Encryption"]
B --> B3["Access Controls"]
C --> C1["Intrusion Detection Systems (IDS)"]
C --> C2["Log Monitoring"]
D --> D1["Incident Response Plans"]
D --> D2["Backup & Recovery"]1. Preventive Countermeasures
A. Firewalls
A firewall is a network security system that filters traffic based on predefined rules.
| Type | How It Works | Example Use Case |
|---|---|---|
| Packet-Filtering | Filters based on IP addresses, ports. | Small businesses (e.g., a local café’s Wi-Fi). |
| Stateful Inspection | Tracks connection state (e.g., TCP handshake). | Banks (e.g., NMB’s internal network). |
| NGFW | Combines firewall + intrusion prevention, application awareness. | NTC’s national backbone network. |
Worked Example: Firewall Blocking a DDoS Attack During the 2022 NTC DDoS attack, a stateful firewall detected unusual traffic patterns from 10,000+ compromised devices and dropped malicious packets, reducing downtime to 30 minutes.
B. Encryption
Encryption scrambles data so that only authorized parties can read it.
| Algorithm | Type | Key Size | Use Case |
|---|---|---|---|
| AES | Symmetric | 128/256 | Encrypting eSewa transactions. |
| RSA | Asymmetric | 2048+ | Digital signatures in NEPSE trades. |
| ECC | Asymmetric | 256 | Mobile banking (Khalti) for speed. |
Example: Encrypted Payments in Nepal
- eSewa uses AES-256 to encrypt user credentials during transactions.
- NEPSE uses RSA-2048 for digital signatures in stock trading.
C. Access Controls
Access controls restrict who can access what.
| Model | Description | Example Use Case |
|---|---|---|
| DAC | Users grant access to others (e.g., file permissions). | Personal computer file sharing. |
| MAC | Access based on security labels (e.g., military classifications). | Government databases (Ministry of Defense). |
| RBAC | Access based on job roles (e.g., admin, user). | Banking systems (NMB, Global IME). |
Example: RBAC in Nepali Banks
- A teller can only process transactions but cannot transfer funds.
- A branch manager has admin rights to approve loans.
2. Detective Countermeasures
A. Intrusion Detection Systems (IDS)
An IDS monitors network traffic for suspicious activity and alerts administrators.
| Feature | IDS | IPS |
|---|---|---|
| Detection | Yes | Yes |
| Blocking | No | Yes |
| Deployment | Network/Host-based | Network/Host-based |
| Example | Snort (open-source) | Cisco Firepower |
Example: IDS Detecting a Phishing Attempt When a Pathao driver clicked a malicious link, the host-based IDS flagged the unusual outbound connection to a dark web forum, triggering an alert.
B. Log Monitoring
Logs record user activities, system events, and security incidents.
Example: SIEM in Nepali Banks
- Global IME Bank uses Splunk to monitor login attempts, data access, and unusual transactions.
- If 5 failed login attempts occur in 5 minutes, the system locks the account.
3. Corrective Countermeasures
A. Incident Response Plan (IRP)
An IRP defines steps to take during and after a breach.
Example: IRP for a Ransomware Attack
- Detection: IT team notices unusual disk activity.
- Containment: Isolate infected machines from the network.
- Eradication: Remove ransomware via antivirus and restore from backups.
- Recovery: Reconnect systems after cleaning.
- Lessons Learned: Improve backup frequency and train staff on email security.
B. Backup and Recovery
Backups ensure data can be restored after an attack.
Example: Backup Saving a Nepali Hospital In 2023, a Kathmandu hospital suffered a ransomware attack. Thanks to daily backups stored in an offline server, they restored all records in 2 hours without paying ransom.
3. Cybersecurity Threats and Countermeasures in Nepal
Nepal’s digital landscape is growing rapidly, but cybersecurity laws are still evolving.
1. Legal Framework
| Act/Law | Year | Key Provisions |
|---|---|---|
| Digital Security Act (2073) | 2016 | Mandates reporting cyber incidents to Cyber Security Bureau. |
| Data Protection Act (2075) | 2018 | Requires consent for data collection and right to access personal data. |
| Cyber Crime Act (2075) | 2018 | Criminalizes hacking, phishing, and ransomware. |
2. Common Threats in Nepal
| Threat Type | Example in Nepal | Impact |
|---|---|---|
| Phishing | Fake eSewa/Khalti login pages. | $500,000 stolen in 2023 (Nepal Rastra Bank). |
| DDoS | NTC internet outages during exams. | E-commerce losses (Daraz, SastoDeal). |
| Insider Threats | Bank employee data leaks. | Legal fines + reputational damage. |
| Ransomware | Hospital records encrypted. | Patient trust lost + operational halt. |
3. Countermeasures Adopted in Nepal
| Organization | Countermeasure Used | Result |
|---|---|---|
| NMB Bank | Zero Trust + MFA | 90% reduction in fraud. |
| NTC | DDoS protection via Cloudflare | 95% attack mitigation. |
| NEPSE | Blockchain-based trade verification | Reduced insider trading. |
| Pathao | AI-based fraud detection | $200,000 saved in 2023. |
4. Emerging Threats and Future Trends
1. AI-Powered Attacks
- Deepfake phishing: AI-generated voice/video calls tricking victims (e.g., a CEO asking for a transfer).
- Automated malware: AI writes new malware strains faster than defenses can block them.
Countermeasure: AI-driven threat detection (e.g., Darktrace used by Global IME).
2. IoT Vulnerabilities
- Smart devices (CCTV, routers) often have weak passwords.
- Example: Nepal’s smart traffic lights were hacked in 2022, causing gridlock in Kathmandu.
Countermeasure: Segment IoT networks and update firmware regularly.
3. Quantum Computing Threats
- Future quantum computers could break RSA encryption.
- Post-quantum cryptography (e.g., Lattice-based encryption) is being researched.
In the Real World
eSewa’s Fraud Prevention
- Idea Used: Behavioral Biometrics (typing patterns, mouse movements) to detect account takeovers.
- How: If eSewa detects unusual login behavior (e.g., fast typing, wrong password attempts), it blocks the session and sends a push notification to the user’s phone.
- Real Impact: Reduced fraud by 40% in 2023.
Khalti’s Anti-Phishing Training
- Idea Used: Phishing Simulation Tests (employees click fake phishing emails to learn).
- How: Khalti sends monthly fake phishing emails to employees. If they click, they get training on how to spot scams.
- Real Impact: 90% of employees now recognize phishing emails after training.
NMB Bank’s Zero Trust Model
- Idea Used: Zero Trust Architecture (ZTA) – assumes no user is trusted by default.
- How: Every time an employee or customer accesses banking systems, NMB verifies identity via MFA + device checks before granting access.
- Real Impact: Stopped a $1.2M fraud attempt in 2023 when an attacker tried to transfer funds via a compromised laptop.
Exam Tip
This unit is highly practical, so expect:
- Scenario-based questions (e.g., "A Nepali hospital falls victim to ransomware. Describe the incident response steps.").
- Comparison tables (e.g., "Compare firewall types with examples from Nepali organizations.").
- Case studies (e.g., "Analyze how eSewa uses behavioral biometrics to prevent fraud.").
- Legal questions (e.g., "Explain the role of Nepal’s Digital Security Act in reporting cyber incidents.").
Key Exam Strategies:
- Memorize threat types (malware, phishing, DDoS, insider threats) with real Nepali examples.
- Understand countermeasures (firewalls, encryption, IDS, IRP) and match them to threats.
- Relate to Nepal’s laws (Digital Security Act, Data Protection Act).
- Practice diagrams (e.g., incident response lifecycle, firewall types comparison).
- Use worked examples (e.g., ransomware attack on a clinic, phishing on Pathao drivers) to explain concepts.
Common Mistakes to Avoid:
- ❌ Mixing up IDS and IPS (IDS = detect only, IPS = detect + block).
- ❌ Forgetting Nepal-specific examples (e.g., NTC DDoS, NMB Bank’s Zero Trust).
- ❌ Ignoring legal aspects (e.g., reporting cyber incidents under Digital Security Act).
- ❌ Overlooking human factors (e.g., phishing relies on human error, not just tech flaws).
Final Note: Cybersecurity is not just about technology—it’s about people, processes, and laws. Nepal’s digital economy (eSewa, Daraz, NEPSE) is growing, but cyber threats are evolving faster. Always stay updated, use strong passwords, and report suspicious activity to Cyber Security Bureau (CSB).
Based on the TU BCA syllabus for Cyber Law And Professional Ethics (CACS401), unit 8.
Discussion
Loading…