IT240 Business Data Communication and Networking

Business Data Communication and NetworkingUnit 99 min read

Network Security Basics: Threats, Protocols, and Safeguards

Unit 9 of Business Data Communication and Networking explores foundational network security concepts, including threats (viruses, DDoS, phishing), cryptographic protocols (SSL/TLS, VPNs), firewalls, authentication methods (biometrics, MFA), and real-world security breaches like the 2022 Ncell data leak. Students learn

Core Concepts: Why Security Matters in Networks

Network security is the practice of protecting data, devices, and systems from unauthorized access, misuse, or attacks. In business, a single breach can cost millions (e.g., Nepal Rastra Bank’s 2021 cyberattack, which exposed customer data) and damage reputation. This unit covers:

  1. Threats and vulnerabilities (what attackers exploit).
  2. Security protocols (how data stays safe in transit).
  3. Defensive tools (firewalls, encryption, authentication).
  4. Real-world case studies (how companies like Khalti or NTC implement security).

1. Types of Network Security Threats

Threats exploit weaknesses in networks, software, or human behavior. Classify them as:

mindmap
  root((Network Threats))
    Malware["Malware\n(Viruses, Worms, Ransomware)"]
      Virus["Attaches to clean files (e.g., 2017 WannaCry ransomware)"
            "Spreads via email/USB drives"]
      Ransomware["Encrypts data; demands payment (e.g., 2020 Nepal hospital attacks)"]
      Trojan["Disguised as legitimate software (e.g., fake 'eSewa update' apps)"]
    Unauthorized Access["Gaining control without permission"]
      Phishing["Fake emails (e.g., 'Your Khalti account is locked!')"]
      Brute Force["Guessing passwords (e.g., weak Wi-Fi passwords in cafes)"]
      Man-in-the-Middle["Intercepting data (e.g., public Wi-Fi eavesdropping)"]
    Denial-of-Service["Overloading systems to crash them"]
      DDoS["Botnets flood targets (e.g., 2021 Daraz website outages)"]
    Insider Threats["Employees/malicious admins (e.g., 2020 Ncell employee leak)"]
    Physical Threats["Theft/damage to hardware (e.g., stolen routers in offices)"]

Worked Example: Phishing Attack on eSewa

  1. Attack: A user receives an email: "Your eSewa transaction failed! Click here to verify."
  2. Red Flags:
    • URL: eSewa-verify[.]com (not eSewa[.]com).
    • Generic greeting: "Dear User" (legit emails use your name).
  3. Outcome: Clicking installs malware stealing login credentials. Prevention: Always verify URLs and use multi-factor authentication (MFA).

2. Security Protocols: How Data Stays Safe

Protocols encrypt data or authenticate users. Key ones:

Protocol Purpose Example Use Case Weakness
SSL/TLS Encrypts web traffic (HTTPS) eSewa payments, bank logins Outdated versions vulnerable to POODLE
VPN Secures remote connections NTC employees accessing office files remotely Poor password policies
IPSec Secures IP communications Government networks (e.g., NEPSE trading) Complex setup
SSH Secure remote login IT admins managing Daraz servers Weak keys can be brute-forced
WPA3 Secures Wi-Fi networks Coffee shops, co-working spaces Misconfigurations (e.g., default passwords)

SSL/TLS handshake diagram**How a browser and server establish an encrypted connection (Image: Essich, CC BY 3.0, via Wikimedia Commons)

Worked Example: HTTPS vs. HTTP

  • HTTP: Unencrypted (passwords/credit cards visible to attackers).
  • HTTPS: Uses TLS to encrypt data.
    • Trace: When you log into Khalti, your browser checks for a valid SSL certificate (issued by GlobalSign or DigiCert). If missing, Chrome shows:

      "Your connection is not private" → *Attackers could steal your data!


3. Defensive Tools: Firewalls, Encryption, and Authentication

A. Firewalls: The Network Bouncer

Firewalls filter traffic based on rules. Types:

flowchart TD
  A["Firewall Types"] --> B["Packet-Filtering\n(Routers, basic rules)"]
  A --> C["Stateful Inspection\n(Tracks connections, e.g., NTC network)"]
  A --> D["Application-Level\n(Deep packet inspection, e.g., banks)"]
  A --> E["Next-Gen\n(Uses AI to detect threats, e.g., Daraz servers)"]

Example: Nepal Rastra Bank’s firewall rules:

  • Block: Port 22 (SSH) from public IPs → Only internal admins can access.
  • Allow: Port 443 (HTTPS) → Secure web traffic.

B. Encryption: Scrambling Data

  • Symmetric Key: Same key encrypts/decrypts (fast, e.g., AES-256 in WhatsApp).
  • Asymmetric Key: Public/private keys (secure, e.g., RSA in SSL).
  • Hashing: One-way encryption (e.g., storing passwords as SHA-256 hashes).

C. Authentication: Proving You’re Who You Say

Methods ranked by security:

Method Strength Example Weakness
Password Low password123 (eSewa default) Guessable
MFA (SMS/Email) Medium Khalti’s OTP after login SIM-swapping attacks
Biometrics (Fingerprint) High Ncell’s iris scan for transactions Spoofing with high-res photos
Hardware Tokens Very High Bank ATMs with physical keys Lost/stolen

Worked Example: Ncell’s Biometric Security

  1. Process:
    • User registers fingerprint/iris at Ncell store.
    • Device stores a template (not the actual image).
    • For transactions, the phone matches live scan to template.
  2. Why It Works: Harder to replicate than passwords.

4. Real-World Case Study: The 2022 Ncell Data Leak

What Happened:

  • A third-party vendor’s database was exposed online (unencrypted).
  • 1.2 million customers’ data (names, phone numbers, SIM details) leaked.
  • Impact: Phishing scams surged; some users received fake "Ncell upgrade" calls.

How It Could Have Been Prevented:

  1. Encryption: Store data as AES-256 encrypted backups.
  2. Access Control: Only allow vendors to access minimal data (e.g., no full customer lists).
  3. Monitoring: Use SIEM tools (like Splunk) to detect unauthorized access.

Lesson: Even large companies fail due to human error or third-party risks.


5. Network Security in Business: Applying the Concepts

Businesses use security to:

  • Protect transactions (e.g., eSewa’s PCI-DSS compliance).
  • Prevent downtime (e.g., NTC’s DDoS protection).
  • Meet legal requirements (e.g., Nepal’s 2018 Cyber Security Act).

Example: Daraz’s Security Measures

Threat Daraz’s Countermeasure Why It Works
Payment fraud 3D Secure (MFA for cards) Adds extra verification step
Data breaches AWS Cloud encryption Industry-standard encryption
DDoS attacks Cloudflare protection Absorbs attack traffic

In the Real World

  1. eSewa’s SSL/TLS:

    • When you transfer money, your browser checks for a valid SSL certificate (issued by DigiCert). If expired, the transaction fails → Prevents MITM attacks.
    • How it works: Your phone and eSewa’s server perform a TLS handshake to agree on encryption keys.
  2. Khalti’s MFA:

    • After entering your password, Khalti sends an OTP via SMS. Even if hackers steal your password, they can’t bypass the OTP.
    • Real scenario: In 2021, a Khalti user reported fraud after reusing a weak password. MFA blocked the attacker.
  3. NTC’s Firewall Rules:

    • NTC blocks inbound RDP (port 3389) to prevent brute-force attacks on internal servers.
    • Why it matters: In 2020, a Nepalese ISP was hacked via an unpatched RDP server.

Exam Tip: How to Score Full Marks

  1. Define and Differentiate:

    • Always start with clear definitions (e.g., "SSL provides encryption; TLS is its updated version").
    • Compare protocols in tables (e.g., SSL vs. IPSec).
  2. Use Real Examples:

    • Link threats to Nepali companies:
      • "A DDoS attack on Daraz would disrupt e-commerce, costing merchants sales."
    • Cite laws:
      • "Nepal’s Cyber Security Act 2018 mandates encryption for sensitive data."
  3. Diagrams Are Your Friends:

    • Draw firewall rule sets or encryption workflows (e.g., how AES works).
    • Use mindmaps for threat classifications.
  4. Common Pitfalls to Avoid:

    • ❌ "Firewalls prevent all viruses." → False. Firewalls block network-level threats; antivirus handles malware.
    • ❌ "VPNs are 100% secure." → False. Weak passwords can still be brute-forced.
  5. Case Study Approach:

    • If asked "How would you secure eSewa?", structure your answer:
      1. Threat: Phishing → Solution: MFA + email verification.
      2. Threat: Data leaks → Solution: Encrypted databases + access logs.

Quick Revision Checklist

  • Can you list 5 types of malware and give a Nepali example for each?
  • Draw the TLS handshake steps (3-way process).
  • Compare symmetric vs. asymmetric encryption in a table.
  • Explain how Ncell’s biometric system prevents fraud.
  • Name 3 security protocols used in banking and their weaknesses.

Based on the TU BIM syllabus for Business Data Communication and Networking (IT240), unit 9.

Discussion

Loading…