CACS459 Information Security

Information SecurityUnit 912 min read

Network Security & Protocols: Threats, Protocols, IDS, Audits

Unit 9 of Information Security covers network security threats (active/passive), core protocols (SSL/TLS, IPsec, VPNs), intrusion detection systems (IDS types, architecture), security auditing (trails, architecture, requirements), and real-world applications in eSewa, banks, and NEPSE. Learn how protocols protect data,

TAKEAWAYS:

  • Network security threats are classified into active (e.g., DoS, MITM) and passive (e.g., eavesdropping, traffic analysis) attacks, each requiring distinct countermeasures.
  • SSL/TLS and IPsec are the backbone protocols for securing web and VPN traffic, respectively, using symmetric/asymmetric encryption and handshake processes.
  • Intrusion Detection Systems (IDS) monitor networks for malicious activity, categorized into signature-based (rule-matching) and anomaly-based (behavioral) systems.
  • Security auditing involves audit trails (logs of events), architecture (collection, analysis, response), and requirements (integrity, non-repudiation, accountability).
  • Real-world examples: eSewa uses TLS for secure transactions, Ncell employs IDS to detect SIM-swapping attacks, and NEPSE relies on audit trails for trade compliance.
  • Exam focus: Define threats/attacks, explain SSL/TLS handshakes, justify IDS as a security backbone, and compare ACL vs. ACM in access control.

Core Concepts: Network Security Threats

Network security threats are deliberate or accidental actions that compromise confidentiality, integrity, or availability (CIA triad) of data. They are broadly classified into two categories:

1. Active Attacks

Active attacks involve modifying or disrupting data or services. Examples:

  • Denial of Service (DoS/DDoS): Overwhelming a system to make it unavailable (e.g., NTC’s website crashes during peak hours due to botnet attacks).
  • Man-in-the-Middle (MITM): Intercepting and altering communications (e.g., Khalti’s payment redirection scams).
  • Replay Attacks: Repeating valid data transmissions to gain unauthorized access (e.g., eSewa login replay).
  • Masquerading: Impersonating legitimate users (e.g., fake Daraz seller accounts).

2. Passive Attacks

Passive attacks involve eavesdropping or monitoring without altering data. Examples:

  • Eavesdropping: Listening to private communications (e.g., unencrypted WhatsApp calls in public Wi-Fi).
  • Traffic Analysis: Studying patterns of communication (e.g., Ncell tracking call metadata).
  • Release of Message Content: Disclosing sensitive data (e.g., leaked NEPSE trader messages).

classDiagram
    class Threat {
        +Type: Active/Passive
        +Impact: CIA Triad
        +Example: DoS, MITM, Eavesdropping
    }
    class ActiveAttack {
        +Modifies Data/Services
        +Examples: DoS, MITM, Replay
    }
    class PassiveAttack {
        +Monitors Data
        +Examples: Eavesdropping, Traffic Analysis
    }
    Threat <|-- ActiveAttack
    Threat <|-- PassiveAttack

Why it matters: Active attacks require prevention (e.g., encryption, firewalls), while passive attacks need detection (e.g., IDS, audit logs).


## In the Real World

  1. eSewa’s TLS Security: When you pay utility bills via eSewa, the SSL/TLS handshake ensures your credit card details are encrypted. The protocol uses:

    • Asymmetric encryption (RSA) for key exchange.
    • Symmetric encryption (AES) for fast data transfer.
    • Digital certificates (from Nepal Government CA) to verify eSewa’s identity. Worked Example: If a hacker intercepts your payment, TLS prevents them from reading it without the session key.
  2. Ncell’s SIM-Swapping Defense: Ncell uses anomaly-based IDS to detect unusual SIM-swapping attempts. For example:

    • Normal: Your SIM activates in Kathmandu at 8 AM.
    • Anomaly: Your SIM suddenly activates in Pokhara at 3 AM → flagged as MITM. Visual: Ncell’s fraud detection dashboard (hypothetical) would show spikes in failed login attempts.
  3. NEPSE’s Audit Trails: The Nepal Stock Exchange (NEPSE) logs every trade in an immutable audit trail. If a broker manipulates prices, the trail proves:

    • Who executed the trade.
    • The exact timestamp.
    • The order’s validity. Example: In 2021, NEPSE used audit logs to reverse fraudulent trades worth Rs. 500 million.

Network Security Protocols

Protocols are rulesets for secure communication. Key protocols in Unit 9:

1. SSL/TLS (Secure Sockets Layer/Transport Layer Security)

  • Purpose: Secures web traffic (HTTP → HTTPS).
  • How it works:
    1. ClientHello: Browser sends supported cipher suites.
    2. ServerHello: Server picks a cipher (e.g., AES-256) and sends its digital certificate.
    3. Key Exchange: Client verifies the certificate (via CA like DigiCert) and generates a pre-master key, encrypted with the server’s public key.
    4. Session Key: Both sides derive a symmetric key for encryption.
    5. Data Transfer: Encrypted with AES/ChaCha20.
sequenceDiagram
    Client->>Server: ClientHello (TLS 1.3, cipher suites)
    Server->>Client: ServerHello + Certificate (DigiCert)
    Client->>Client: Verify CA signature
    Client->>Server: Pre-Master Key (encrypted with Server's RSA)
    Server->>Client: Finished (hash of handshake)
    Client->>Server: Finished
    Note over Client,Server: Symmetric Session Established (AES-256)

Real Picture: SSL TLS handshake diagramA labeled flowchart of the 4-step TLS 1.3 handshake. (Image: Essich, CC BY 3.0, via Wikimedia Commons)

Advantages:

  • Confidentiality: Data encrypted in transit.
  • Integrity: Hashes (SHA-256) detect tampering.
  • Authentication: Certificates verify server identity.

Disadvantages:

  • Latency: Handshake adds ~2 RTTs.
  • Certificate Cost: Expensive for small businesses (e.g., local Daraz sellers).

2. IPsec (Internet Protocol Security)

  • Purpose: Secures IP traffic (used in VPNs, e.g., Ncell’s corporate network).
  • Modes:
    • Transport Mode: Encrypts payload only (used in L2TP/IPsec VPNs).
    • Tunnel Mode: Encrypts entire packet (used in site-to-site VPNs).

Worked Example: When a Pathao driver connects to the company VPN:

  1. IPsec establishes a Security Association (SA) with a shared key.
  2. All traffic between driver’s phone and Pathao’s server is encrypted.
  3. AH (Authentication Header) ensures no one alters the packet.

Comparison Table:

Protocol Layer Use Case Encryption
SSL/TLS App Web (HTTPS) Symmetric (AES)
IPsec Net VPNs, Remote Access Symmetric (AES) + AH

3. VPN (Virtual Private Network)

  • Purpose: Extends a private network over a public one (e.g., NTC’s remote engineers).
  • Types:
    • Remote Access VPN: Single user connects to a network (e.g., Khalti’s remote auditors).
    • Site-to-Site VPN: Connects two networks (e.g., Ncell’s Kathmandu-Pokhara data centers).

Real Picture:


Intrusion Detection Systems (IDS)

IDS is the "immune system" of networks, detecting and responding to threats. It works in two modes:

1. Signature-Based IDS

  • How it works: Matches traffic against a database of known attack patterns (signatures).
  • Example: Detecting a SQL injection (' OR 1=1 --) in a login form.
  • Advantages:
    • Low false positives.
    • Fast detection.
  • Disadvantages:
    • Misses zero-day attacks (unknown threats).

2. Anomaly-Based IDS

  • How it works: Learns normal behavior and flags deviations (e.g., sudden spike in login attempts).
  • Example: Ncell’s IDS detects a SIM-swap attack if:
    • 10 failed PIN attempts in 1 minute.
    • Location jumps from Kathmandu to India.
  • Advantages:
    • Detects new attacks.
  • Disadvantages:
    • High false positives (e.g., legitimate travel).
stateDiagram-v2
    [*] --> Normal: Traffic within baseline
    Normal --> Alert: Anomaly detected (e.g., port scan)
    Alert --> Investigate: Admin reviews logs
    Investigate --> Block: Firewall rules updated
    Block --> [*]

IDS Architecture:

Real-World Use:

  • Google’s IDS: Detects DDoS attacks on YouTube by analyzing traffic patterns.
  • Ncell’s IDS: Blocks SIM-cloning attempts by monitoring IMEI changes.

Security Auditing

Auditing ensures systems comply with security policies. Key components:

1. Audit Trail

  • Definition: A log of security-relevant events (e.g., login failures, data access).
  • Example: NEPSE’s audit trail records:
    • Trader ID: T12345
    • Action: Sold 1000 shares of NABIL
    • Timestamp: 2023-10-15 14:30:22
    • IP Address: 192.168.1.100

Requirements for Audit Trails:

Requirement Example
Immutability Logs stored in write-once media (e.g., WORM drives).
Integrity Hashes (SHA-256) verify logs aren’t altered.
Non-Repudiation Trader T12345 can’t deny selling shares.
Accountability Every action tied to a user/process.

2. Security Audit Architecture

Worked Example: If Pathao’s database is accessed at 3 AM:

  1. Audit Trail: Logs USER: admin | ACTION: SELECT * FROM payments | TIME: 03:15.
  2. Analysis: Admin notices no legitimate reason for late access.
  3. Response: Lock admin account and investigate.

Access Control: ACL vs. ACM

Feature ACL (Access Control List) ACM (Access Control Matrix)
Structure List of permissions per object. Matrix of subjects vs. objects.
Example File.txt: Read=Alice, Write=Bob Grid showing all users’ permissions.
Use Case Simple systems (e.g., local files). Complex systems (e.g., bank databases).
Scalability Poor (linear growth). Better (matrix operations).

Real Example:

  • Ncell’s ACL: Restricts engineer1 to BTS_Config files only.
  • Bank’s ACM: Shows which teller can access which customer’s account.

## Exam Tip

  1. Threats vs. Attacks:

    • Threat: Potential danger (e.g., "Hackers could eavesdrop").
    • Attack: Executed threat (e.g., "MITM attack on Khalti"). Exam Question: "Define threats and attacks in IS." → Always give examples.
  2. SSL/TLS Handshake:

    • Must mention: ClientHello, ServerHello, certificate verification, and symmetric key establishment.
    • Shortcut: Draw the sequence diagram (3 steps: handshake → key exchange → data transfer).
  3. IDS Justification:

    • Signature-based: Good for known attacks (e.g., SQLi).
    • Anomaly-based: Better for zero-day threats.
    • Exam Tip: Relate to Ncell’s SIM-swap detection or NEPSE’s fraud logs.
  4. Audit Trail:

    • Immutability = WORM storage.
    • Non-repudiation = Digital signatures.
    • Example: "NEPSE uses audit trails to prove trade validity."
  5. ACL vs. ACM:

    • ACL: Simple, file-based (e.g., chmod in Linux).
    • ACM: Complex, database-style (e.g., bank permissions).
    • Table is worth 3 marks in TU exams.

Final Checklist for Full Marks: ✅ Define active/passive attacks with real examples (eSewa, Ncell). ✅ Explain SSL/TLS handshake with a sequence diagram. ✅ Compare signature-based vs. anomaly-based IDS. ✅ Describe audit trail requirements (immutability, integrity). ✅ Draw ACL vs. ACM in a table for comparison.

Based on the TU BCA syllabus for Information Security (CACS459), unit 9.

Discussion

Loading…