Information SecurityUnit 211 min read
Security Principles & Threats: CIA Triad, Attacks, Controls & Real-World Risks
Unit 2 of Information Security explores the foundational principles of security (confidentiality, integrity, availability) and their real-world threats (passive/active attacks, malware, social engineering), how security controls (preventive/detective/corrective) mitigate risks, and how these concepts apply to Nepali sy
TAKEAWAYS:
- The CIA triad (Confidentiality, Integrity, Availability) defines core security goals, but real systems must balance trade-offs (e.g., eSewa prioritizes availability over confidentiality for quick payments).
- Threats are classified into passive (eavesdropping, traffic analysis) and active (DoS, MITM, replay attacks), each requiring different countermeasures.
- Security controls fall into preventive (firewalls, encryption), detective (IDS, logs), and corrective (backups, patches) categories—Ncell uses all three to protect mobile networks.
- Social engineering exploits human trust (e.g., phishing emails mimicking NEPSE alerts) and is the #1 cause of breaches in Nepal’s financial sector.
- Worked example: A Kathmandu traffic route optimization system fails when GPS data is spoofed (integrity attack), causing gridlock—this mirrors real-world IoT vulnerabilities.
- Exam focus: Memorize CIA triad conflicts, attack vs. threat definitions, and control types with real-world mapping (e.g., Daraz’s SSL = preventive control).
Core Concepts: The CIA Triad and Security Goals
The CIA triad is the bedrock of information security. Each principle addresses a critical aspect of protecting data and systems:
mindmap
root((CIA Triad))
Confidentiality
Definition: Ensures data is accessible only to authorized users.
Example: Bank PINs (Nabil Bank), eSewa OTPs.
Threats: Unauthorized disclosure, data leaks.
Integrity
Definition: Guarantees data accuracy and consistency.
Example: NEPSE stock price updates (no tampering).
Threats: Data corruption, MITM attacks.
Availability
Definition: Ensures systems/resources are accessible when needed.
Example: Ncell network uptime during festivals.
Threats: DoS attacks, hardware failures.Trade-offs: Systems often conflict between CIA goals. For example:
- eSewa prioritizes availability (quick transactions) over confidentiality (less encryption for speed).
- NEPSE prioritizes integrity (signed trades) but risks availability during high-volume days.
Worked Example: Bank Loan Approval A bank processes a loan request with:
- Confidentiality: Customer’s income data is encrypted (AES-256).
- Integrity: Digital signature verifies the application hasn’t been altered.
- Availability: The system must respond within 2 seconds (SLA). Attack scenario: An attacker spoofs the loan officer’s email (social engineering) to change the approval limit. This violates integrity and confidentiality.
Threats: Passive vs. Active Attacks
Threats exploit vulnerabilities to compromise security. They are categorized as passive (stealing data) or active (modifying data/systems).
Passive Attacks
Real-World Example: Ncell Network Traffic Analysis
- Threat: Attackers monitor call metadata (duration, location) to predict user behavior.
- Impact: Privacy violation (confidentiality breach).
- Countermeasure: Encrypted signaling (e.g., 5G’s IP Multimedia Subsystem).
Active Attacks
Active attacks modify data or systems. Common types:
| Attack Type | Description | Example in Nepal | Countermeasure |
|---|---|---|---|
| MITM (Man-in-the-Middle) | Intercepts/compromises communication. | Fake Wi-Fi hotspot in Thamel stealing login credentials. | HTTPS, VPNs, certificate pinning. |
| DoS/DDoS | Overwhelms systems to deny service. | NEPSE website crash during IPOs. | Rate limiting, cloud scrubbing. |
| Replay Attack | Reuses valid data (e.g., OTPs). | Repeating a Khalti transaction OTP. | One-time tokens, timestamps. |
| Spoofing | Impersonates entities (IP, email). | Fake "NTC" email asking for user details. | DMARC, SPF, email verification. |
Worked Example: Daraz Order Queue Tampering
- Scenario: An attacker modifies the order queue in Daraz’s database to prioritize their own items.
- Impact: Integrity (queue order altered) and availability (legitimate users delayed).
- Detection: Intrusion Detection System (IDS) flags unusual SQL queries.
Security Controls: Preventive, Detective, and Corrective
Controls mitigate threats. They are classified into three types:
pie title Security Controls "Preventive (35%)" : 35 "Detective (30%)" : 30 "Corrective (35%)" : 35 "Residual (5%)" : 5Security Controls Distribution (with Residual category added)
| Control Type | Examples | Nepali Use Case | Limitations |
|---|---|---|---|
| Preventive | Firewalls, Encryption, Access Control | Ncell’s SIM card PINs, eSewa’s 2FA. | Can’t stop insider threats. |
| Detective | IDS, Logs, Audits | NTC monitoring fiber-optic cable cuts. | Reacts after breach occurs. |
| Corrective | Backups, Patches, Incident Response | NEPSE restoring data after a ransomware attack. | Requires post-breach action. |
In the Real World
- eSewa’s 2FA System
- Principle: Confidentiality (OTP protects transactions).
- Threat Mitigated: Phishing (active attack).
- Control: Preventive (OTP) + Detective (failed login alerts).
Ncell’s Network Security
- Principle: Availability (99.9% uptime SLA).
- Threat: DoS during festivals (e.g., Dashain).
- Control: Preventive (DDoS protection) + Corrective (auto-scaling).
NEPSE’s Blockchain Pilot
- Principle: Integrity (tamper-proof trades).
- Threat: Insider fraud (active attack).
- Control: Detective (smart contract audits).
Social Engineering: The Human Firewall
Social engineering exploits psychology, not technology. Top tactics in Nepal:
stateDiagram-v2
[*] --> Attacker
Attacker --> "Build Trust" : "Fake NTC helpline call"
"Build Trust" --> "Create Urgency" : "Your SIM is blocked!"
"Create Urgency" --> "Extract Data" : "Click this link to verify."
"Extract Data" --> [*]Real-World Example: "Nabil Bank Phishing" Scam
- Email: "Your account is locked! Click here to verify."
- Link: Redirects to a fake Nabil Bank login page.
- Outcome: Credentials stolen (confidentiality breach). Countermeasure: User training (detective control) + DMARC (preventive).
Security Auditing: The Detective’s Toolkit
Definition: Systematic review of security measures to ensure compliance and effectiveness.
Key Components:
- Audit Trail: Logs of all security-relevant events (e.g., failed login attempts).
- Architecture:
- Collection: Gather logs from firewalls, servers.
- Analysis: Use tools like Splunk or Wireshark.
- Reporting: Generate compliance reports (e.g., for RBI audits).
Worked Example: NTC Fiber-Optic Audit
- Goal: Ensure integrity of data transmitted via fiber.
- Process:
- Collect: Logs from optical network terminals.
- Analyze: Check for light signal drops (indicating tampering).
- Report: Flag anomalies to engineers.
- Outcome: Detects MITM attacks on fiber links.
Exam Tip: How to Score Full Marks
CIA Triad Questions:
- Always define each term (e.g., "Confidentiality ensures only authorized users access data").
- Compare with real systems (e.g., "eSewa balances CIA by using OTPs for confidentiality but risks availability during server overloads").
Threats vs. Attacks:
- Threat: Potential danger (e.g., "Malware is a threat to Ncell’s Android apps").
- Attack: Execution of a threat (e.g., "A MITM attack on Daraz’s checkout page").
Controls:
- Preventive: "Firewalls block unauthorized traffic to NEPSE’s servers."
- Detective: "IDS logs detect brute-force attacks on eSewa."
- Corrective: "Nabil Bank restores data from backups after a ransomware attack."
Social Engineering:
- Structure answer as:
- Tactic (e.g., phishing).
- Example (e.g., fake "NTC" email).
- Countermeasure (e.g., email verification).
- Structure answer as:
Auditing:
- Audit Trail: "Logs of all login attempts to Khalti’s dashboard."
- Architecture: Draw a 3-step flow (collect → analyze → report).
Common Pitfalls:
- ❌ Confusing passive (eavesdropping) and active (DoS) attacks.
- ❌ Forgetting real-world examples (e.g., Ncell, eSewa).
- ❌ Not linking controls to CIA principles (e.g., "Firewalls ensure confidentiality").
Summary Table: Key Concepts at a Glance
| Concept | Definition | Example | Exam Focus |
|---|---|---|---|
| CIA Triad | Confidentiality, Integrity, Availability | eSewa’s OTPs (C), NEPSE trades (I), Ncell uptime (A) | Trade-offs, real-world mapping. |
| Passive Attack | Steals data without altering it. | Traffic analysis on NTC’s fiber links. | Eavesdropping, countermeasures. |
| Active Attack | Modifies data/systems. | MITM on Daraz’s payment page. | DoS, replay, spoofing. |
| Preventive Control | Stops attacks before they occur. | Nabil Bank’s firewall. | Firewalls, encryption, access control. |
| Detective Control | Detects attacks after they occur. | IDS alerting on failed Khalti logins. | Logs, audits, monitoring. |
| Corrective Control | Fixes issues after a breach. | Restoring NEPSE data post-ransomware. | Backups, patches, incident response. |
| Social Engineering | Exploits human psychology. | Fake "NTC" call asking for SIM details. | Phishing, pretexting, countermeasures. |
| Audit Trail | Record of security-relevant events. | Logs of all admin actions in Ncell’s core. | Collection, analysis, reporting. |
Based on the TU BCA syllabus for Information Security (CACS459), unit 2.
Discussion
Loading…