CACS459 Information Security

Information SecurityUnit 211 min read

Security Principles & Threats: CIA Triad, Attacks, Controls & Real-World Risks

Unit 2 of Information Security explores the foundational principles of security (confidentiality, integrity, availability) and their real-world threats (passive/active attacks, malware, social engineering), how security controls (preventive/detective/corrective) mitigate risks, and how these concepts apply to Nepali sy

TAKEAWAYS:

  • The CIA triad (Confidentiality, Integrity, Availability) defines core security goals, but real systems must balance trade-offs (e.g., eSewa prioritizes availability over confidentiality for quick payments).
  • Threats are classified into passive (eavesdropping, traffic analysis) and active (DoS, MITM, replay attacks), each requiring different countermeasures.
  • Security controls fall into preventive (firewalls, encryption), detective (IDS, logs), and corrective (backups, patches) categories—Ncell uses all three to protect mobile networks.
  • Social engineering exploits human trust (e.g., phishing emails mimicking NEPSE alerts) and is the #1 cause of breaches in Nepal’s financial sector.
  • Worked example: A Kathmandu traffic route optimization system fails when GPS data is spoofed (integrity attack), causing gridlock—this mirrors real-world IoT vulnerabilities.
  • Exam focus: Memorize CIA triad conflicts, attack vs. threat definitions, and control types with real-world mapping (e.g., Daraz’s SSL = preventive control).

Core Concepts: The CIA Triad and Security Goals

The CIA triad is the bedrock of information security. Each principle addresses a critical aspect of protecting data and systems:

mindmap
  root((CIA Triad))
    Confidentiality
      Definition: Ensures data is accessible only to authorized users.
      Example: Bank PINs (Nabil Bank), eSewa OTPs.
      Threats: Unauthorized disclosure, data leaks.
    Integrity
      Definition: Guarantees data accuracy and consistency.
      Example: NEPSE stock price updates (no tampering).
      Threats: Data corruption, MITM attacks.
    Availability
      Definition: Ensures systems/resources are accessible when needed.
      Example: Ncell network uptime during festivals.
      Threats: DoS attacks, hardware failures.

Trade-offs: Systems often conflict between CIA goals. For example:

  • eSewa prioritizes availability (quick transactions) over confidentiality (less encryption for speed).
  • NEPSE prioritizes integrity (signed trades) but risks availability during high-volume days.

Worked Example: Bank Loan Approval A bank processes a loan request with:

  1. Confidentiality: Customer’s income data is encrypted (AES-256).
  2. Integrity: Digital signature verifies the application hasn’t been altered.
  3. Availability: The system must respond within 2 seconds (SLA). Attack scenario: An attacker spoofs the loan officer’s email (social engineering) to change the approval limit. This violates integrity and confidentiality.

Threats: Passive vs. Active Attacks

Threats exploit vulnerabilities to compromise security. They are categorized as passive (stealing data) or active (modifying data/systems).

Passive Attacks

Exploits: WiretappingExploits: MalwarePassive AttackActive AttackThreat Vector
Passive vs. Active Attack Vectors

Real-World Example: Ncell Network Traffic Analysis

  • Threat: Attackers monitor call metadata (duration, location) to predict user behavior.
  • Impact: Privacy violation (confidentiality breach).
  • Countermeasure: Encrypted signaling (e.g., 5G’s IP Multimedia Subsystem).

Active Attacks

Active attacks modify data or systems. Common types:

Attack Type Description Example in Nepal Countermeasure
MITM (Man-in-the-Middle) Intercepts/compromises communication. Fake Wi-Fi hotspot in Thamel stealing login credentials. HTTPS, VPNs, certificate pinning.
DoS/DDoS Overwhelms systems to deny service. NEPSE website crash during IPOs. Rate limiting, cloud scrubbing.
Replay Attack Reuses valid data (e.g., OTPs). Repeating a Khalti transaction OTP. One-time tokens, timestamps.
Spoofing Impersonates entities (IP, email). Fake "NTC" email asking for user details. DMARC, SPF, email verification.

Worked Example: Daraz Order Queue Tampering

  • Scenario: An attacker modifies the order queue in Daraz’s database to prioritize their own items.
  • Impact: Integrity (queue order altered) and availability (legitimate users delayed).
  • Detection: Intrusion Detection System (IDS) flags unusual SQL queries.

Security Controls: Preventive, Detective, and Corrective

Controls mitigate threats. They are classified into three types:

Access ControlsEncryptionFirewallsPreventive Controls
Examples of Preventive Security Controls
pie
  title Security Controls
  "Preventive (35%)" : 35
  "Detective (30%)" : 30
  "Corrective (35%)" : 35
  "Residual (5%)" : 5
Security Controls Distribution (with Residual category added)
Control Type Examples Nepali Use Case Limitations
Preventive Firewalls, Encryption, Access Control Ncell’s SIM card PINs, eSewa’s 2FA. Can’t stop insider threats.
Detective IDS, Logs, Audits NTC monitoring fiber-optic cable cuts. Reacts after breach occurs.
Corrective Backups, Patches, Incident Response NEPSE restoring data after a ransomware attack. Requires post-breach action.

In the Real World

  1. eSewa’s 2FA System
    • Principle: Confidentiality (OTP protects transactions).
    • Threat Mitigated: Phishing (active attack).
    • Control: Preventive (OTP) + Detective (failed login alerts).
PhysicalBitsData LinkFramesNetworkPacketsTransportSegmentsApplicationData
OSI Model with Example Data Units
  1. Ncell’s Network Security

    • Principle: Availability (99.9% uptime SLA).
    • Threat: DoS during festivals (e.g., Dashain).
    • Control: Preventive (DDoS protection) + Corrective (auto-scaling).
  2. NEPSE’s Blockchain Pilot

    • Principle: Integrity (tamper-proof trades).
    • Threat: Insider fraud (active attack).
    • Control: Detective (smart contract audits).

Social Engineering: The Human Firewall

Social engineering exploits psychology, not technology. Top tactics in Nepal:

stateDiagram-v2
    [*] --> Attacker
    Attacker --> "Build Trust" : "Fake NTC helpline call"
    "Build Trust" --> "Create Urgency" : "Your SIM is blocked!"
    "Create Urgency" --> "Extract Data" : "Click this link to verify."
    "Extract Data" --> [*]

Real-World Example: "Nabil Bank Phishing" Scam

  1. Email: "Your account is locked! Click here to verify."
  2. Link: Redirects to a fake Nabil Bank login page.
  3. Outcome: Credentials stolen (confidentiality breach). Countermeasure: User training (detective control) + DMARC (preventive).

Security Auditing: The Detective’s Toolkit

Definition: Systematic review of security measures to ensure compliance and effectiveness.

016324863AUDITOR32 bitsAUDIT32 bitsSECURITY_CONTROL32 bitsCOMPLIANCE32 bits
Audit Relationships (Simplified ER Diagram)

Key Components:

  1. Audit Trail: Logs of all security-relevant events (e.g., failed login attempts).
  2. Architecture:
    • Collection: Gather logs from firewalls, servers.
    • Analysis: Use tools like Splunk or Wireshark.
    • Reporting: Generate compliance reports (e.g., for RBI audits).

Worked Example: NTC Fiber-Optic Audit

  • Goal: Ensure integrity of data transmitted via fiber.
  • Process:
    1. Collect: Logs from optical network terminals.
    2. Analyze: Check for light signal drops (indicating tampering).
    3. Report: Flag anomalies to engineers.
  • Outcome: Detects MITM attacks on fiber links.

Exam Tip: How to Score Full Marks

  1. CIA Triad Questions:

    • Always define each term (e.g., "Confidentiality ensures only authorized users access data").
    • Compare with real systems (e.g., "eSewa balances CIA by using OTPs for confidentiality but risks availability during server overloads").
  2. Threats vs. Attacks:

    • Threat: Potential danger (e.g., "Malware is a threat to Ncell’s Android apps").
    • Attack: Execution of a threat (e.g., "A MITM attack on Daraz’s checkout page").
  3. Controls:

    • Preventive: "Firewalls block unauthorized traffic to NEPSE’s servers."
    • Detective: "IDS logs detect brute-force attacks on eSewa."
    • Corrective: "Nabil Bank restores data from backups after a ransomware attack."
  4. Social Engineering:

    • Structure answer as:
      1. Tactic (e.g., phishing).
      2. Example (e.g., fake "NTC" email).
      3. Countermeasure (e.g., email verification).
  5. Auditing:

    • Audit Trail: "Logs of all login attempts to Khalti’s dashboard."
    • Architecture: Draw a 3-step flow (collect → analyze → report).

Common Pitfalls:

  • ❌ Confusing passive (eavesdropping) and active (DoS) attacks.
  • ❌ Forgetting real-world examples (e.g., Ncell, eSewa).
  • ❌ Not linking controls to CIA principles (e.g., "Firewalls ensure confidentiality").

Summary Table: Key Concepts at a Glance

Concept Definition Example Exam Focus
CIA Triad Confidentiality, Integrity, Availability eSewa’s OTPs (C), NEPSE trades (I), Ncell uptime (A) Trade-offs, real-world mapping.
Passive Attack Steals data without altering it. Traffic analysis on NTC’s fiber links. Eavesdropping, countermeasures.
Active Attack Modifies data/systems. MITM on Daraz’s payment page. DoS, replay, spoofing.
Preventive Control Stops attacks before they occur. Nabil Bank’s firewall. Firewalls, encryption, access control.
Detective Control Detects attacks after they occur. IDS alerting on failed Khalti logins. Logs, audits, monitoring.
Corrective Control Fixes issues after a breach. Restoring NEPSE data post-ransomware. Backups, patches, incident response.
Social Engineering Exploits human psychology. Fake "NTC" call asking for SIM details. Phishing, pretexting, countermeasures.
Audit Trail Record of security-relevant events. Logs of all admin actions in Ncell’s core. Collection, analysis, reporting.

Based on the TU BCA syllabus for Information Security (CACS459), unit 2.

Discussion

Loading…