CACS459 Information Security

Information SecurityUnit 110 min read

Information Security: Core Concepts, Threats & Foundations

Unit 1 of Information Security introduces foundational concepts like definitions of security, threats, attacks, and fundamental principles, while exploring real-world risks, security services, and the role of auditing in safeguarding digital assets.

TAKEAWAYS:

  • Information security protects confidentiality, integrity, and availability (CIA triad) of data from unauthorized access or damage.
  • Threats (e.g., malware, phishing) and attacks (active/passive) exploit vulnerabilities in systems, requiring proactive defenses.
  • Security principles like defense in depth, least privilege, and fail-safe design are critical for robust security architectures.
  • Security audits and intrusion detection systems (IDS) monitor systems for anomalies and ensure compliance with policies.
  • Pretty Good Privacy (PGP) and digital signatures enable secure email communication and authentication.
  • Real-world examples like eSewa’s transaction encryption (PGP) and NTC’s network security (IDS) demonstrate these concepts in action.

1. Definitions: Security, Threats, and Attacks

Information security is the practice of protecting digital and physical systems from unauthorized access, use, disclosure, disruption, modification, or destruction. It revolves around three core principles:

figure: CIA Triad

Confidentiality: Ensures data is accessible only to authorized parties. Integrity: Guarantees data is accurate and unaltered. Availability: Ensures systems and data are accessible when needed.


Threats and Attacks

  • Threats: Potential dangers to security, such as natural disasters, human errors, or malicious actors.
  • Attacks: Exploitations of vulnerabilities to compromise security. They are classified into:
    • Active Attacks: Directly alter system resources (e.g., denial-of-service, man-in-the-middle).
    • Passive Attacks: Monitor or eavesdrop without altering data (e.g., sniffing, traffic analysis).

Example: A hacker intercepting Khalti’s payment transactions (passive attack) to steal login credentials is a threat. If they then alter transaction amounts (active attack), they exploit both types.


Types of Security Threats

Category Examples Impact
Malware Viruses, worms, ransomware Data corruption, system shutdown
Social Engineering Phishing, pretexting Credential theft, unauthorized access
Denial-of-Service (DoS) Flooding attacks System unavailability
Insider Threats Disgruntled employees, leaks Data breaches, sabotage

Visual:

mindmap
  root((Security Threats))
    Malware
      Viruses
      Worms
      Ransomware
    Social Engineering
      Phishing
      Pretexting
    DoS Attacks
      Flooding
      SYN Floods
    Insider Threats
      Malicious Employees
      Careless Handling

2. Security Principles and Design Principles

Security is built on foundational principles that guide system design:

Fundamental Security Principles

  1. Confidentiality: Restrict access to sensitive data (e.g., NEPSE’s market data is encrypted).
  2. Integrity: Ensure data is unaltered (e.g., bank transaction logs use checksums).
  3. Availability: Maintain uptime (e.g., NTC’s redundant servers prevent outages).

Security Design Principles

Principle Description Example
Defense in Depth Layered security to slow attackers. Firewalls + IDS + Encryption
Least Privilege Grant minimal access rights. Employees access only their data
Fail-Safe Defaults Default to "deny" access unless permitted. Locked systems until authenticated
Separation of Duties Divide critical tasks among multiple people. Approval workflows in Daraz orders
Economy of Mechanism Keep designs simple to reduce vulnerabilities. Minimal software dependencies

Worked Example: Pathao’s Ride-Sharing Security:

  • Confidentiality: Driver/passenger data encrypted in transit (TLS).
  • Integrity: GPS coordinates hashed to prevent tampering.
  • Availability: Redundant servers ensure uptime during peak hours.

3. Security Services

Security services protect systems and data through mechanisms like:

  • Access Control: Restrict system access (e.g., Ncell’s SIM authentication).
  • Authentication: Verify user identity (e.g., eSewa’s OTP).
  • Non-Repudiation: Prove actions (e.g., digital signatures in contracts).
  • Confidentiality: Encrypt data (e.g., PGP for emails).

Visual:

flowchart TD
    A["User"] -->|"Login"| B["Authentication Service"]
    B -->|"Verify Credentials"| C{"Authorized?"}
    C -->|"Yes"| D["Access Granted"]
    C -->|"No"| E["Deny Access"]
    D --> F["Data Access"]
    F -->|"Encrypt"| G["Confidentiality Service"]

4. Intrusion Detection Systems (IDS)

IDS monitors networks for suspicious activity and alerts administrators. Types include:

  • Network IDS (NIDS): Monitors network traffic (e.g., NTC’s firewall logs).
  • Host IDS (HIDS): Monitors system activity (e.g., server logs in banks).
  • Signature-Based: Detects known threats (e.g., malware signatures).
  • Anomaly-Based: Detects unusual behavior (e.g., sudden login spikes).

Why IDS is the Backbone:

  • Detects breaches early (e.g., Daraz’s fraud detection).
  • Provides audit trails for compliance (e.g., NEPSE’s regulatory checks).

Visual:

sequenceDiagram
    participant User
    participant Network
    participant IDS
    participant Admin
    User->>Network: Suspicious Traffic
    Network->>IDS: Alert Triggered
    IDS->>Admin: Notification
    Admin->>Network: Investigate

5. Security Audits

A security audit evaluates systems for vulnerabilities, compliance, and risks. Key components:

  • Compliance Checks: Ensure adherence to policies (e.g., GDPR for eSewa).
  • Risk Assessment: Identify threats and vulnerabilities.
  • Audit Trail: Log of all system activities (e.g., bank transaction logs).

Architecture of Security Auditing:

mindmap
  root((Security Audit Architecture))
    Compliance Checks
      Policy Alignment
      Regulatory Checks
    Risk Assessment
      Vulnerability Scanning
      Threat Modeling
    Audit Trail
      Log Collection
      Analysis
    Reporting
      Findings
      Recommendations

Worked Example: Ncell’s Security Audit:

  • Compliance: Checks for SIM registration rules.
  • Risk Assessment: Tests for weak passwords in user accounts.
  • Audit Trail: Logs all call data records for fraud detection.

6. Pretty Good Privacy (PGP)

PGP is an encryption standard for secure email communication. Key services:

  1. Encryption: Protects email content.
  2. Digital Signatures: Verifies sender identity.
  3. Key Management: Secure key exchange.
  4. Compression: Reduces email size.
  5. Integrity Checks: Ensures emails aren’t altered.

How PGP Works:

  1. Sender encrypts email with recipient’s public key.
  2. Recipient decrypts with their private key.
  3. Digital signature proves sender’s identity.

Real-World Use: eSewa’s Secure Transactions:

  • Uses PGP to encrypt transaction details between users and servers.

7. Passive vs. Active Attacks

Type Description Example Impact
Passive Eavesdrop without altering data. Sniffing network traffic. Data leakage
Active Directly interfere with systems. Man-in-the-middle attack. Data corruption, unauthorized access

Example:

  • Passive: A hacker listens to WhatsApp calls (eavesdropping).
  • Active: A hacker alters WhatsApp messages (MITM attack).

In the Real World

  1. eSewa’s Transaction Security:

    • Uses PGP encryption to secure payment data during transfers, ensuring confidentiality and integrity.
    • Worked Example: When you transfer ₹1,000 to a friend, PGP encrypts the transaction details so even if intercepted, the data remains unreadable.
  2. NTC’s Network Security:

    • Implements intrusion detection systems (IDS) to monitor for DoS attacks or unauthorized access attempts.
    • Worked Example: During peak hours, NTC’s IDS detects a sudden spike in login attempts from a single IP, triggering an alert to block the source.
  3. Daraz’s Order Fulfillment:

    • Uses least privilege access control to ensure warehouse staff can only access inventory for their assigned orders.
    • Worked Example: A warehouse worker can only scan and process orders assigned to their section, reducing the risk of internal fraud.

Exam Tip

  • Focus on Definitions: Clearly define threats, attacks, CIA triad, and security principles—these are high-weightage topics.
  • Compare Types: Differentiate between active vs. passive attacks, NIDS vs. HIDS, and signature vs. anomaly-based IDS.
  • Apply Real-World Scenarios: Relate concepts to eSewa, NTC, or Daraz—examiners love practical examples.
  • Diagrams: Draw the CIA triad, IDS architecture, and PGP workflow—visuals score extra marks.
  • Avoid Vague Answers: For questions like "Why is IDS the backbone?", link it to early breach detection and compliance explicitly.

Key Formula to Remember: For any security question, structure your answer as:

  1. Definition (1 mark).
  2. Explanation (2-3 marks).
  3. Example (1-2 marks).
  4. Real-World Tie-In (bonus).

Final Visual:

stateDiagram-v2
    [*] --> Secure: System is Secure
    Secure --> Threat: Threat Detected (e.g., Malware)
    Threat --> IDS: IDS Monitors
    IDS --> Alert: Alert Triggered
    Alert --> Admin: Admin Investigates
    Admin --> Patch: Apply Fixes
    Patch --> Secure

Based on the TU BCA syllabus for Information Security (CACS459), unit 1.

Discussion

Loading…