Information SecurityUnit 110 min read
Information Security: Core Concepts, Threats & Foundations
Unit 1 of Information Security introduces foundational concepts like definitions of security, threats, attacks, and fundamental principles, while exploring real-world risks, security services, and the role of auditing in safeguarding digital assets.
TAKEAWAYS:
- Information security protects confidentiality, integrity, and availability (CIA triad) of data from unauthorized access or damage.
- Threats (e.g., malware, phishing) and attacks (active/passive) exploit vulnerabilities in systems, requiring proactive defenses.
- Security principles like defense in depth, least privilege, and fail-safe design are critical for robust security architectures.
- Security audits and intrusion detection systems (IDS) monitor systems for anomalies and ensure compliance with policies.
- Pretty Good Privacy (PGP) and digital signatures enable secure email communication and authentication.
- Real-world examples like eSewa’s transaction encryption (PGP) and NTC’s network security (IDS) demonstrate these concepts in action.
1. Definitions: Security, Threats, and Attacks
Information security is the practice of protecting digital and physical systems from unauthorized access, use, disclosure, disruption, modification, or destruction. It revolves around three core principles:
figure: CIA Triad
Confidentiality: Ensures data is accessible only to authorized parties. Integrity: Guarantees data is accurate and unaltered. Availability: Ensures systems and data are accessible when needed.
Threats and Attacks
- Threats: Potential dangers to security, such as natural disasters, human errors, or malicious actors.
- Attacks: Exploitations of vulnerabilities to compromise security. They are classified into:
- Active Attacks: Directly alter system resources (e.g., denial-of-service, man-in-the-middle).
- Passive Attacks: Monitor or eavesdrop without altering data (e.g., sniffing, traffic analysis).
Example: A hacker intercepting Khalti’s payment transactions (passive attack) to steal login credentials is a threat. If they then alter transaction amounts (active attack), they exploit both types.
Types of Security Threats
| Category | Examples | Impact |
|---|---|---|
| Malware | Viruses, worms, ransomware | Data corruption, system shutdown |
| Social Engineering | Phishing, pretexting | Credential theft, unauthorized access |
| Denial-of-Service (DoS) | Flooding attacks | System unavailability |
| Insider Threats | Disgruntled employees, leaks | Data breaches, sabotage |
Visual:
mindmap
root((Security Threats))
Malware
Viruses
Worms
Ransomware
Social Engineering
Phishing
Pretexting
DoS Attacks
Flooding
SYN Floods
Insider Threats
Malicious Employees
Careless Handling2. Security Principles and Design Principles
Security is built on foundational principles that guide system design:
Fundamental Security Principles
- Confidentiality: Restrict access to sensitive data (e.g., NEPSE’s market data is encrypted).
- Integrity: Ensure data is unaltered (e.g., bank transaction logs use checksums).
- Availability: Maintain uptime (e.g., NTC’s redundant servers prevent outages).
Security Design Principles
| Principle | Description | Example |
|---|---|---|
| Defense in Depth | Layered security to slow attackers. | Firewalls + IDS + Encryption |
| Least Privilege | Grant minimal access rights. | Employees access only their data |
| Fail-Safe Defaults | Default to "deny" access unless permitted. | Locked systems until authenticated |
| Separation of Duties | Divide critical tasks among multiple people. | Approval workflows in Daraz orders |
| Economy of Mechanism | Keep designs simple to reduce vulnerabilities. | Minimal software dependencies |
Worked Example: Pathao’s Ride-Sharing Security:
- Confidentiality: Driver/passenger data encrypted in transit (TLS).
- Integrity: GPS coordinates hashed to prevent tampering.
- Availability: Redundant servers ensure uptime during peak hours.
3. Security Services
Security services protect systems and data through mechanisms like:
- Access Control: Restrict system access (e.g., Ncell’s SIM authentication).
- Authentication: Verify user identity (e.g., eSewa’s OTP).
- Non-Repudiation: Prove actions (e.g., digital signatures in contracts).
- Confidentiality: Encrypt data (e.g., PGP for emails).
Visual:
flowchart TD
A["User"] -->|"Login"| B["Authentication Service"]
B -->|"Verify Credentials"| C{"Authorized?"}
C -->|"Yes"| D["Access Granted"]
C -->|"No"| E["Deny Access"]
D --> F["Data Access"]
F -->|"Encrypt"| G["Confidentiality Service"]4. Intrusion Detection Systems (IDS)
IDS monitors networks for suspicious activity and alerts administrators. Types include:
- Network IDS (NIDS): Monitors network traffic (e.g., NTC’s firewall logs).
- Host IDS (HIDS): Monitors system activity (e.g., server logs in banks).
- Signature-Based: Detects known threats (e.g., malware signatures).
- Anomaly-Based: Detects unusual behavior (e.g., sudden login spikes).
Why IDS is the Backbone:
- Detects breaches early (e.g., Daraz’s fraud detection).
- Provides audit trails for compliance (e.g., NEPSE’s regulatory checks).
Visual:
sequenceDiagram
participant User
participant Network
participant IDS
participant Admin
User->>Network: Suspicious Traffic
Network->>IDS: Alert Triggered
IDS->>Admin: Notification
Admin->>Network: Investigate5. Security Audits
A security audit evaluates systems for vulnerabilities, compliance, and risks. Key components:
- Compliance Checks: Ensure adherence to policies (e.g., GDPR for eSewa).
- Risk Assessment: Identify threats and vulnerabilities.
- Audit Trail: Log of all system activities (e.g., bank transaction logs).
Architecture of Security Auditing:
mindmap
root((Security Audit Architecture))
Compliance Checks
Policy Alignment
Regulatory Checks
Risk Assessment
Vulnerability Scanning
Threat Modeling
Audit Trail
Log Collection
Analysis
Reporting
Findings
RecommendationsWorked Example: Ncell’s Security Audit:
- Compliance: Checks for SIM registration rules.
- Risk Assessment: Tests for weak passwords in user accounts.
- Audit Trail: Logs all call data records for fraud detection.
6. Pretty Good Privacy (PGP)
PGP is an encryption standard for secure email communication. Key services:
- Encryption: Protects email content.
- Digital Signatures: Verifies sender identity.
- Key Management: Secure key exchange.
- Compression: Reduces email size.
- Integrity Checks: Ensures emails aren’t altered.
How PGP Works:
- Sender encrypts email with recipient’s public key.
- Recipient decrypts with their private key.
- Digital signature proves sender’s identity.
Real-World Use: eSewa’s Secure Transactions:
- Uses PGP to encrypt transaction details between users and servers.
7. Passive vs. Active Attacks
| Type | Description | Example | Impact |
|---|---|---|---|
| Passive | Eavesdrop without altering data. | Sniffing network traffic. | Data leakage |
| Active | Directly interfere with systems. | Man-in-the-middle attack. | Data corruption, unauthorized access |
Example:
- Passive: A hacker listens to WhatsApp calls (eavesdropping).
- Active: A hacker alters WhatsApp messages (MITM attack).
In the Real World
eSewa’s Transaction Security:
- Uses PGP encryption to secure payment data during transfers, ensuring confidentiality and integrity.
- Worked Example: When you transfer ₹1,000 to a friend, PGP encrypts the transaction details so even if intercepted, the data remains unreadable.
NTC’s Network Security:
- Implements intrusion detection systems (IDS) to monitor for DoS attacks or unauthorized access attempts.
- Worked Example: During peak hours, NTC’s IDS detects a sudden spike in login attempts from a single IP, triggering an alert to block the source.
Daraz’s Order Fulfillment:
- Uses least privilege access control to ensure warehouse staff can only access inventory for their assigned orders.
- Worked Example: A warehouse worker can only scan and process orders assigned to their section, reducing the risk of internal fraud.
Exam Tip
- Focus on Definitions: Clearly define threats, attacks, CIA triad, and security principles—these are high-weightage topics.
- Compare Types: Differentiate between active vs. passive attacks, NIDS vs. HIDS, and signature vs. anomaly-based IDS.
- Apply Real-World Scenarios: Relate concepts to eSewa, NTC, or Daraz—examiners love practical examples.
- Diagrams: Draw the CIA triad, IDS architecture, and PGP workflow—visuals score extra marks.
- Avoid Vague Answers: For questions like "Why is IDS the backbone?", link it to early breach detection and compliance explicitly.
Key Formula to Remember: For any security question, structure your answer as:
- Definition (1 mark).
- Explanation (2-3 marks).
- Example (1-2 marks).
- Real-World Tie-In (bonus).
Final Visual:
stateDiagram-v2
[*] --> Secure: System is Secure
Secure --> Threat: Threat Detected (e.g., Malware)
Threat --> IDS: IDS Monitors
IDS --> Alert: Alert Triggered
Alert --> Admin: Admin Investigates
Admin --> Patch: Apply Fixes
Patch --> SecureBased on the TU BCA syllabus for Information Security (CACS459), unit 1.
Discussion
Loading…