CACS459 Information Security

Information SecurityUnit 1014 min read

Security Auditing & Intrusion Detection: Audit Trails, IDS/IPS, Forensics & Compliance

Unit 10 of Information Security explores how organizations detect breaches, verify compliance, and recover from attacks through systematic auditing and intrusion detection systems. Covers audit trails, IDS/IPS architectures, forensic analysis, and real-world applications like bank transaction monitoring and Ncell netwo

TAKEAWAYS:

  • Security auditing is a structured review of systems, policies, and logs to verify compliance with security standards (ISO 27001, PCI-DSS).
  • Intrusion Detection Systems (IDS) monitor network traffic/host activities for anomalies or malicious patterns, while IPS actively blocks threats.
  • Audit trails create immutable records of user actions, system changes, and access attempts—critical for forensic investigations.
  • Signature-based IDS detects known attacks via predefined patterns, while anomaly-based IDS flags deviations from normal behavior.
  • Security audits must follow C-I-A triad (Confidentiality, Integrity, Availability) and least privilege principles to minimize risks.
  • Real-world examples: eSewa’s transaction logs (audit trails), Ncell’s SIEM (intrusion detection), and bank fraud investigations (forensic analysis).

Core Concepts: Security Auditing

1. Definition and Purpose

Security auditing is the systematic examination of IT systems, policies, and operations to ensure they comply with security policies, laws, and best practices. It helps:

  • Identify vulnerabilities before attackers exploit them.
  • Verify that security controls (firewalls, encryption, access controls) are functioning correctly.
  • Provide evidence for legal compliance (e.g., GDPR, Nepal’s Electronic Transaction Act 2008).
  • Support incident response by reconstructing events post-breach.

2. Key Components of Security Auditing

A security audit involves three critical phases:

stateDiagram-v2
    [*] --> Planning
    Planning --> Execution
    Execution --> Reporting
    Reporting --> Follow-up
    Follow-up --> [*]

A. Planning Phase

  • Scope Definition: Decide what to audit (e.g., servers, databases, user access logs).
  • Audit Criteria: Standards to measure against (e.g., ISO 27001, NIST SP 800-53).
  • Resource Allocation: Assign auditors, tools (e.g., Nessus, OpenVAS), and timelines.

B. Execution Phase

  • Interviews: Talk to IT staff, managers, and users to understand processes.
  • Document Review: Check policies, logs, and configurations.
  • Testing: Perform penetration tests or vulnerability scans.
  • Evidence Collection: Gather logs, screenshots, and system snapshots.

C. Reporting Phase

  • Findings: List vulnerabilities, misconfigurations, and non-compliance issues.
  • Risk Assessment: Rate each finding by severity (Low/Medium/High/Critical).
  • Recommendations: Suggest fixes (e.g., patching, policy updates).

D. Follow-up

  • Verify that recommended fixes were implemented.
  • Re-audit if necessary.

3. Audit Trail: The Digital Footprint

An audit trail is a chronological record of system activities, user actions, and access attempts. It is immutable (cannot be altered without detection) and used for:

  • Forensic analysis (e.g., tracing a hacker’s steps in a Khalti breach).
  • Compliance proof (e.g., NEPSE must log all stock transactions).
  • Incident reconstruction (e.g., who deleted a critical file in a bank’s core banking system).

Example: Audit Trail in eSewa

When a user transfers Rs. 5,000 from their eSewa wallet to a merchant:

  1. Timestamp: 2024-05-20 14:30:45
  2. User ID: user12345
  3. Action: Transfer to Merchant ID: merch6789
  4. Amount: Rs. 5,000
  5. IP Address: 192.168.1.100
  6. Status: Success
  7. Audit Flag: Verified by Two-Factor Authentication

Why is this important? If a user reports fraud, eSewa can verify the transaction’s legitimacy using the audit trail.


4. Security Auditing Architecture

A typical auditing system has three layers:

Key Tools in Auditing

Tool Purpose Example Use Case
SIEM (Security Information and Event Management) Correlates logs from multiple sources to detect threats. Ncell uses SIEM to monitor for SIM-swapping attacks.
Log Management Stores and analyzes logs (e.g., Apache, Windows Event Logs). Daraz logs all order cancellations for fraud detection.
Penetration Testing Simulates cyberattacks to find vulnerabilities. Nepal Rastra Bank hires ethical hackers to test ATM systems.
Configuration Compliance Scanners Checks if systems meet security policies. ISO 27001 audit for a Nepalese bank.

Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS)

1. What is an IDS?

An Intrusion Detection System (IDS) monitors network traffic or system activities for suspicious behavior and alerts administrators. It does not block attacks—it only detects.

→→Network TrafficIDS SensorCentral Management Console
Basic IDS architecture: passive monitoring of network traffic

2. Types of IDS

Type Description Example Attack Detected Pros Cons
Network-Based (NIDS) Monitors network traffic (e.g., Snort, Suricata). DDoS attack on a bank’s website. Covers entire network. High false positives.
Host-Based (HIDS) Monitors a single host (e.g., OSSEC, AIDE). Unauthorized file modification on a server. Detects internal threats. Limited to one machine.
Signature-Based Uses known attack patterns (like antivirus). SQL Injection in a Daraz checkout page. Fast and accurate for known threats. Fails against zero-day attacks.
Anomaly-Based Detects deviations from normal behavior. Insider leaking data from a government server. Catches unknown attacks. High false positives.

3. How IDS Works: A Worked Example

Scenario: A hacker tries to brute-force an Ncell employee’s VPN password.

  1. Normal Traffic:
    • User logs in with correct credentials → IDS records baseline behavior.
  2. Attack Attempt:
    • Hacker tries admin:password1, admin:123456, etc.
    • Signature-Based IDS detects repeated failed login attempts (matches a known brute-force pattern).
    • Anomaly-Based IDS sees 100 login attempts in 5 minutes (unusual behavior).
  3. Alert Triggered:
    • IDS sends an alert to the Security Operations Center (SOC).
    • SOC investigates and blocks the attacker’s IP.

4. Intrusion Prevention System (IPS)

Unlike IDS, an IPS actively blocks detected threats. It sits inline with traffic (unlike IDS, which is passive).

sequenceDiagram
    participant User
    participant Firewall
    participant IPS
    participant Server

    User->>Firewall: Request to access Server
    Firewall->>IPS: Forward traffic for inspection
    IPS->>IPS: Check for malicious patterns (e.g., SQLi)
    alt Malicious Traffic Detected
        IPS->>Firewall: DROP packet
        Firewall-->>User: Connection Denied
    else Clean Traffic
        IPS->>Firewall: ALLOW packet
        Firewall->>Server: Forward request
    end

Real-World Example:

  • Nepal’s NTC uses IPS to block DDoS attacks on its website during peak hours.
  • Banks deploy IPS to prevent man-in-the-middle (MITM) attacks on online transactions.

5. IDS vs. IPS: Key Differences

Feature IDS (Intrusion Detection System) IPS (Intrusion Prevention System)
Position in Network Passive (monitors only). Inline (blocks traffic).
Action on Detection Alerts administrators. Blocks/drops malicious traffic.
Performance Impact Minimal (only monitoring). High (traffic must pass through it).
Example Use Case Detecting APT (Advanced Persistent Threats) in a government network. Preventing ransomware from encrypting files.

Security Auditing and Forensic Analysis

Incident DetectionAlert triggered bySIEMEvidence CollectionForensic imagingof diskAnalysisTimelinereconstruction with AuReportingChain of custodydocumented
Standard forensic investigation workflow

1. Digital Forensics: Reconstructing Cybercrimes

When a breach occurs, forensic analysis helps:

  • Identify the attacker’s methods.
  • Recover lost data.
  • Prosecute the attacker (if applicable).

Steps in Digital Forensics:

  1. Preservation: Ensure evidence is not altered (e.g., write-blockers for hard drives).
  2. Collection: Gather logs, memory dumps, and network traffic.
  3. Analysis: Use tools like Autopsy or Wireshark to examine evidence.
  4. Reporting: Document findings for legal or management review.

2. Case Study: Bank Fraud Investigation

Scenario: A Nepalese bank detects unauthorized fund transfers totaling Rs. 20 million.

Forensic Steps:

  1. Audit Trail Review:
    • Check transaction logs → Find suspicious IP (185.143.223.45).
  2. Network Forensics:
    • Use Wireshark to analyze packets → Discover phishing emails sent to employees.
  3. Host Forensics:
    • Examine compromised workstations → Find keylogger malware.
  4. Legal Action:
    • Provide evidence to Nepal Police Cyber Bureau → Arrest the hacker.

In the Real World

1. eSewa: Audit Trails for Financial Security

  • What it uses: Immutable audit trails for every transaction.
  • How it works:
    • Every Rs. 100 transfer is logged with timestamp, user ID, recipient, and device fingerprint.
    • If a user reports fraud, eSewa can prove whether the transaction was legitimate.
  • Why it matters: Prevents chargebacks and legal disputes.

2. Ncell: SIEM for Network Security

  • What it uses: SIEM (Security Information and Event Management) to monitor 4G/5G networks.
  • How it works:
    • Detects SIM-swapping attacks (where hackers take over a user’s phone number).
    • Flags unusual login attempts from new devices.
  • Real Example:
    • In 2023, Ncell’s SIEM blocked a large-scale SIM-swap attack targeting business customers.

3. Daraz: IDS for E-Commerce Protection

  • What it uses: Network-Based IDS (Snort) to monitor checkout pages.
  • How it works:
    • Detects SQL injection attempts (e.g., ... UNION SELECT password FROM users).
    • Blocks credit card skimmers on payment pages.
  • Impact:
    • Prevents fraudulent orders and data breaches during sales events.

4. Nepal Rastra Bank (NRB): Security Audits for Financial Stability

  • What it uses: Annual ISO 27001 audits for all banks.
  • How it works:
    • Checks for weak encryption, unpatched systems, and insider threats.
    • Ensures compliance with Nepal’s Payment System Regulations.
  • Example:
    • After an audit in 2022, NRB forced Global IME Bank to upgrade its fraud detection system.

Exam Tip

How to Score Full Marks in TU/PU Exams

  1. Define Clearly:

    • Start every answer with precise definitions (e.g., "An audit trail is an immutable record of system activities...").
    • Example:

      "An Intrusion Detection System (IDS) is a device or software application that monitors network or system activities for malicious or unauthorized behavior."

  2. Use Diagrams:

    • Draw layered models (e.g., auditing architecture) or sequence diagrams (e.g., IDS/IPS workflow).
    • Example:

      "The security auditing process can be visualized as three phases: Planning → Execution → Reporting (use a state diagram)."

  3. Real-World Examples:

    • Always tie theory to Nepalese companies (eSewa, Ncell, banks, NTC).
    • Example:

      "Just like Ncell uses SIEM to detect SIM-swapping, anomaly-based IDS can flag unusual login patterns in a bank’s core system."

  4. Comparison Tables:

    • IDS vs. IPS, Signature vs. Anomaly-Based Detection are high-mark questions.
    • Example:
      Feature Signature-Based IDS Anomaly-Based IDS
      Detection Method Matches known patterns. Learns normal behavior.
      Effectiveness High for known attacks. Better for zero-days.
  5. Forensic & Audit Trail Questions:

    • Always mention:
      • Immutability (cannot be altered).
      • Legal admissibility (used in court).
      • Tools (SIEM, Autopsy, Wireshark).
    • Example:

      "In a bank fraud case, the audit trail proved that the transaction was initiated from a new device, helping authorities trace the hacker."

  6. Common Pitfalls to Avoid:

    • ❌ Confusing IDS and IPS (IDS detects, IPS prevents).
    • ❌ Ignoring Nepalese context (always relate to eSewa, Ncell, banks).
    • ❌ Overcomplicating answers (examiners want clear, structured responses).

Final Checklist Before Submission

✅ Definitions: Clearly defined (IDS, audit trail, SIEM). ✅ Diagrams: At least 2-3 visuals (state diagram, comparison table, real-world example). ✅ Real-World Tie-Ins: eSewa, Ncell, Daraz, banks used as examples. ✅ Exam Strategy: Structured answers with bullet points for easy marking. ✅ No Redundancy: Avoid repeating the same idea in different words.

Based on the TU BCA syllabus for Information Security (CACS459), unit 10.

Discussion

Loading…