Information SecurityUnit 912 min read
Network Security & Protocols: Threats, Protocols, IDS, Audits
Unit 9 of Information Security covers network security threats (active/passive), core protocols (SSL/TLS, IPsec, VPNs), intrusion detection systems (IDS types, architecture), security auditing (trails, architecture, requirements), and real-world applications in eSewa, banks, and NEPSE. Learn how protocols protect data,
TAKEAWAYS:
- Network security threats are classified into active (e.g., DoS, MITM) and passive (e.g., eavesdropping, traffic analysis) attacks, each requiring distinct countermeasures.
- SSL/TLS and IPsec are the backbone protocols for securing web and VPN traffic, respectively, using symmetric/asymmetric encryption and handshake processes.
- Intrusion Detection Systems (IDS) monitor networks for malicious activity, categorized into signature-based (rule-matching) and anomaly-based (behavioral) systems.
- Security auditing involves audit trails (logs of events), architecture (collection, analysis, response), and requirements (integrity, non-repudiation, accountability).
- Real-world examples: eSewa uses TLS for secure transactions, Ncell employs IDS to detect SIM-swapping attacks, and NEPSE relies on audit trails for trade compliance.
- Exam focus: Define threats/attacks, explain SSL/TLS handshakes, justify IDS as a security backbone, and compare ACL vs. ACM in access control.
Core Concepts: Network Security Threats
Network security threats are deliberate or accidental actions that compromise confidentiality, integrity, or availability (CIA triad) of data. They are broadly classified into two categories:
1. Active Attacks
Active attacks involve modifying or disrupting data or services. Examples:
- Denial of Service (DoS/DDoS): Overwhelming a system to make it unavailable (e.g., NTC’s website crashes during peak hours due to botnet attacks).
- Man-in-the-Middle (MITM): Intercepting and altering communications (e.g., Khalti’s payment redirection scams).
- Replay Attacks: Repeating valid data transmissions to gain unauthorized access (e.g., eSewa login replay).
- Masquerading: Impersonating legitimate users (e.g., fake Daraz seller accounts).
2. Passive Attacks
Passive attacks involve eavesdropping or monitoring without altering data. Examples:
- Eavesdropping: Listening to private communications (e.g., unencrypted WhatsApp calls in public Wi-Fi).
- Traffic Analysis: Studying patterns of communication (e.g., Ncell tracking call metadata).
- Release of Message Content: Disclosing sensitive data (e.g., leaked NEPSE trader messages).
classDiagram
class Threat {
+Type: Active/Passive
+Impact: CIA Triad
+Example: DoS, MITM, Eavesdropping
}
class ActiveAttack {
+Modifies Data/Services
+Examples: DoS, MITM, Replay
}
class PassiveAttack {
+Monitors Data
+Examples: Eavesdropping, Traffic Analysis
}
Threat <|-- ActiveAttack
Threat <|-- PassiveAttackWhy it matters: Active attacks require prevention (e.g., encryption, firewalls), while passive attacks need detection (e.g., IDS, audit logs).
## In the Real World
eSewa’s TLS Security: When you pay utility bills via eSewa, the SSL/TLS handshake ensures your credit card details are encrypted. The protocol uses:
- Asymmetric encryption (RSA) for key exchange.
- Symmetric encryption (AES) for fast data transfer.
- Digital certificates (from Nepal Government CA) to verify eSewa’s identity. Worked Example: If a hacker intercepts your payment, TLS prevents them from reading it without the session key.
Ncell’s SIM-Swapping Defense: Ncell uses anomaly-based IDS to detect unusual SIM-swapping attempts. For example:
- Normal: Your SIM activates in Kathmandu at 8 AM.
- Anomaly: Your SIM suddenly activates in Pokhara at 3 AM → flagged as MITM. Visual: Ncell’s fraud detection dashboard (hypothetical) would show spikes in failed login attempts.
NEPSE’s Audit Trails: The Nepal Stock Exchange (NEPSE) logs every trade in an immutable audit trail. If a broker manipulates prices, the trail proves:
- Who executed the trade.
- The exact timestamp.
- The order’s validity. Example: In 2021, NEPSE used audit logs to reverse fraudulent trades worth Rs. 500 million.
Network Security Protocols
Protocols are rulesets for secure communication. Key protocols in Unit 9:
1. SSL/TLS (Secure Sockets Layer/Transport Layer Security)
- Purpose: Secures web traffic (HTTP → HTTPS).
- How it works:
- ClientHello: Browser sends supported cipher suites.
- ServerHello: Server picks a cipher (e.g., AES-256) and sends its digital certificate.
- Key Exchange: Client verifies the certificate (via CA like DigiCert) and generates a pre-master key, encrypted with the server’s public key.
- Session Key: Both sides derive a symmetric key for encryption.
- Data Transfer: Encrypted with AES/ChaCha20.
sequenceDiagram
Client->>Server: ClientHello (TLS 1.3, cipher suites)
Server->>Client: ServerHello + Certificate (DigiCert)
Client->>Client: Verify CA signature
Client->>Server: Pre-Master Key (encrypted with Server's RSA)
Server->>Client: Finished (hash of handshake)
Client->>Server: Finished
Note over Client,Server: Symmetric Session Established (AES-256)Real Picture:
A labeled flowchart of the 4-step TLS 1.3 handshake. (Image: Essich, CC BY 3.0, via Wikimedia Commons)
Advantages:
- Confidentiality: Data encrypted in transit.
- Integrity: Hashes (SHA-256) detect tampering.
- Authentication: Certificates verify server identity.
Disadvantages:
- Latency: Handshake adds ~2 RTTs.
- Certificate Cost: Expensive for small businesses (e.g., local Daraz sellers).
2. IPsec (Internet Protocol Security)
- Purpose: Secures IP traffic (used in VPNs, e.g., Ncell’s corporate network).
- Modes:
- Transport Mode: Encrypts payload only (used in L2TP/IPsec VPNs).
- Tunnel Mode: Encrypts entire packet (used in site-to-site VPNs).
Worked Example: When a Pathao driver connects to the company VPN:
- IPsec establishes a Security Association (SA) with a shared key.
- All traffic between driver’s phone and Pathao’s server is encrypted.
- AH (Authentication Header) ensures no one alters the packet.
Comparison Table:
| Protocol | Layer | Use Case | Encryption |
|---|---|---|---|
| SSL/TLS | App | Web (HTTPS) | Symmetric (AES) |
| IPsec | Net | VPNs, Remote Access | Symmetric (AES) + AH |
3. VPN (Virtual Private Network)
- Purpose: Extends a private network over a public one (e.g., NTC’s remote engineers).
- Types:
- Remote Access VPN: Single user connects to a network (e.g., Khalti’s remote auditors).
- Site-to-Site VPN: Connects two networks (e.g., Ncell’s Kathmandu-Pokhara data centers).
Real Picture:
Intrusion Detection Systems (IDS)
IDS is the "immune system" of networks, detecting and responding to threats. It works in two modes:
1. Signature-Based IDS
- How it works: Matches traffic against a database of known attack patterns (signatures).
- Example: Detecting a SQL injection (
' OR 1=1 --) in a login form. - Advantages:
- Low false positives.
- Fast detection.
- Disadvantages:
- Misses zero-day attacks (unknown threats).
2. Anomaly-Based IDS
- How it works: Learns normal behavior and flags deviations (e.g., sudden spike in login attempts).
- Example: Ncell’s IDS detects a SIM-swap attack if:
- 10 failed PIN attempts in 1 minute.
- Location jumps from Kathmandu to India.
- Advantages:
- Detects new attacks.
- Disadvantages:
- High false positives (e.g., legitimate travel).
stateDiagram-v2
[*] --> Normal: Traffic within baseline
Normal --> Alert: Anomaly detected (e.g., port scan)
Alert --> Investigate: Admin reviews logs
Investigate --> Block: Firewall rules updated
Block --> [*]IDS Architecture:
Real-World Use:
- Google’s IDS: Detects DDoS attacks on YouTube by analyzing traffic patterns.
- Ncell’s IDS: Blocks SIM-cloning attempts by monitoring IMEI changes.
Security Auditing
Auditing ensures systems comply with security policies. Key components:
1. Audit Trail
- Definition: A log of security-relevant events (e.g., login failures, data access).
- Example: NEPSE’s audit trail records:
- Trader ID:
T12345 - Action:
Sold 1000 shares of NABIL - Timestamp:
2023-10-15 14:30:22 - IP Address:
192.168.1.100
- Trader ID:
Requirements for Audit Trails:
| Requirement | Example |
|---|---|
| Immutability | Logs stored in write-once media (e.g., WORM drives). |
| Integrity | Hashes (SHA-256) verify logs aren’t altered. |
| Non-Repudiation | Trader T12345 can’t deny selling shares. |
| Accountability | Every action tied to a user/process. |
2. Security Audit Architecture
Worked Example: If Pathao’s database is accessed at 3 AM:
- Audit Trail: Logs
USER: admin | ACTION: SELECT * FROM payments | TIME: 03:15. - Analysis: Admin notices no legitimate reason for late access.
- Response: Lock admin account and investigate.
Access Control: ACL vs. ACM
| Feature | ACL (Access Control List) | ACM (Access Control Matrix) |
|---|---|---|
| Structure | List of permissions per object. | Matrix of subjects vs. objects. |
| Example | File.txt: Read=Alice, Write=Bob |
Grid showing all users’ permissions. |
| Use Case | Simple systems (e.g., local files). | Complex systems (e.g., bank databases). |
| Scalability | Poor (linear growth). | Better (matrix operations). |
Real Example:
- Ncell’s ACL: Restricts
engineer1toBTS_Configfiles only. - Bank’s ACM: Shows which teller can access which customer’s account.
## Exam Tip
Threats vs. Attacks:
- Threat: Potential danger (e.g., "Hackers could eavesdrop").
- Attack: Executed threat (e.g., "MITM attack on Khalti"). Exam Question: "Define threats and attacks in IS." → Always give examples.
SSL/TLS Handshake:
- Must mention: ClientHello, ServerHello, certificate verification, and symmetric key establishment.
- Shortcut: Draw the sequence diagram (3 steps: handshake → key exchange → data transfer).
IDS Justification:
- Signature-based: Good for known attacks (e.g., SQLi).
- Anomaly-based: Better for zero-day threats.
- Exam Tip: Relate to Ncell’s SIM-swap detection or NEPSE’s fraud logs.
Audit Trail:
- Immutability = WORM storage.
- Non-repudiation = Digital signatures.
- Example: "NEPSE uses audit trails to prove trade validity."
ACL vs. ACM:
- ACL: Simple, file-based (e.g.,
chmodin Linux). - ACM: Complex, database-style (e.g., bank permissions).
- Table is worth 3 marks in TU exams.
- ACL: Simple, file-based (e.g.,
Final Checklist for Full Marks: ✅ Define active/passive attacks with real examples (eSewa, Ncell). ✅ Explain SSL/TLS handshake with a sequence diagram. ✅ Compare signature-based vs. anomaly-based IDS. ✅ Describe audit trail requirements (immutability, integrity). ✅ Draw ACL vs. ACM in a table for comparison.
Based on the TU BCA syllabus for Information Security (CACS459), unit 9.
Discussion
Loading…