Business Data Communication and NetworkingUnit 99 min read
Network Security Basics: Threats, Protocols, and Safeguards
Unit 9 of Business Data Communication and Networking explores foundational network security concepts, including threats (viruses, DDoS, phishing), cryptographic protocols (SSL/TLS, VPNs), firewalls, authentication methods (biometrics, MFA), and real-world security breaches like the 2022 Ncell data leak. Students learn
Core Concepts: Why Security Matters in Networks
Network security is the practice of protecting data, devices, and systems from unauthorized access, misuse, or attacks. In business, a single breach can cost millions (e.g., Nepal Rastra Bank’s 2021 cyberattack, which exposed customer data) and damage reputation. This unit covers:
- Threats and vulnerabilities (what attackers exploit).
- Security protocols (how data stays safe in transit).
- Defensive tools (firewalls, encryption, authentication).
- Real-world case studies (how companies like Khalti or NTC implement security).
1. Types of Network Security Threats
Threats exploit weaknesses in networks, software, or human behavior. Classify them as:
mindmap
root((Network Threats))
Malware["Malware\n(Viruses, Worms, Ransomware)"]
Virus["Attaches to clean files (e.g., 2017 WannaCry ransomware)"
"Spreads via email/USB drives"]
Ransomware["Encrypts data; demands payment (e.g., 2020 Nepal hospital attacks)"]
Trojan["Disguised as legitimate software (e.g., fake 'eSewa update' apps)"]
Unauthorized Access["Gaining control without permission"]
Phishing["Fake emails (e.g., 'Your Khalti account is locked!')"]
Brute Force["Guessing passwords (e.g., weak Wi-Fi passwords in cafes)"]
Man-in-the-Middle["Intercepting data (e.g., public Wi-Fi eavesdropping)"]
Denial-of-Service["Overloading systems to crash them"]
DDoS["Botnets flood targets (e.g., 2021 Daraz website outages)"]
Insider Threats["Employees/malicious admins (e.g., 2020 Ncell employee leak)"]
Physical Threats["Theft/damage to hardware (e.g., stolen routers in offices)"]Worked Example: Phishing Attack on eSewa
- Attack: A user receives an email: "Your eSewa transaction failed! Click here to verify."
- Red Flags:
- URL:
eSewa-verify[.]com(noteSewa[.]com). - Generic greeting: "Dear User" (legit emails use your name).
- URL:
- Outcome: Clicking installs malware stealing login credentials. Prevention: Always verify URLs and use multi-factor authentication (MFA).
2. Security Protocols: How Data Stays Safe
Protocols encrypt data or authenticate users. Key ones:
| Protocol | Purpose | Example Use Case | Weakness |
|---|---|---|---|
| SSL/TLS | Encrypts web traffic (HTTPS) | eSewa payments, bank logins | Outdated versions vulnerable to POODLE |
| VPN | Secures remote connections | NTC employees accessing office files remotely | Poor password policies |
| IPSec | Secures IP communications | Government networks (e.g., NEPSE trading) | Complex setup |
| SSH | Secure remote login | IT admins managing Daraz servers | Weak keys can be brute-forced |
| WPA3 | Secures Wi-Fi networks | Coffee shops, co-working spaces | Misconfigurations (e.g., default passwords) |
How a browser and server establish an encrypted connection (Image: Essich, CC BY 3.0, via Wikimedia Commons)
Worked Example: HTTPS vs. HTTP
- HTTP: Unencrypted (passwords/credit cards visible to attackers).
- HTTPS: Uses TLS to encrypt data.
- Trace: When you log into Khalti, your browser checks for a valid SSL certificate (issued by GlobalSign or DigiCert). If missing, Chrome shows:
"Your connection is not private" → *Attackers could steal your data!
- Trace: When you log into Khalti, your browser checks for a valid SSL certificate (issued by GlobalSign or DigiCert). If missing, Chrome shows:
3. Defensive Tools: Firewalls, Encryption, and Authentication
A. Firewalls: The Network Bouncer
Firewalls filter traffic based on rules. Types:
flowchart TD A["Firewall Types"] --> B["Packet-Filtering\n(Routers, basic rules)"] A --> C["Stateful Inspection\n(Tracks connections, e.g., NTC network)"] A --> D["Application-Level\n(Deep packet inspection, e.g., banks)"] A --> E["Next-Gen\n(Uses AI to detect threats, e.g., Daraz servers)"]
Example: Nepal Rastra Bank’s firewall rules:
- Block: Port 22 (SSH) from public IPs → Only internal admins can access.
- Allow: Port 443 (HTTPS) → Secure web traffic.
B. Encryption: Scrambling Data
- Symmetric Key: Same key encrypts/decrypts (fast, e.g., AES-256 in WhatsApp).
- Asymmetric Key: Public/private keys (secure, e.g., RSA in SSL).
- Hashing: One-way encryption (e.g., storing passwords as SHA-256 hashes).
C. Authentication: Proving You’re Who You Say
Methods ranked by security:
| Method | Strength | Example | Weakness |
|---|---|---|---|
| Password | Low | password123 (eSewa default) |
Guessable |
| MFA (SMS/Email) | Medium | Khalti’s OTP after login | SIM-swapping attacks |
| Biometrics (Fingerprint) | High | Ncell’s iris scan for transactions | Spoofing with high-res photos |
| Hardware Tokens | Very High | Bank ATMs with physical keys | Lost/stolen |
Worked Example: Ncell’s Biometric Security
- Process:
- User registers fingerprint/iris at Ncell store.
- Device stores a template (not the actual image).
- For transactions, the phone matches live scan to template.
- Why It Works: Harder to replicate than passwords.
4. Real-World Case Study: The 2022 Ncell Data Leak
What Happened:
- A third-party vendor’s database was exposed online (unencrypted).
- 1.2 million customers’ data (names, phone numbers, SIM details) leaked.
- Impact: Phishing scams surged; some users received fake "Ncell upgrade" calls.
How It Could Have Been Prevented:
- Encryption: Store data as AES-256 encrypted backups.
- Access Control: Only allow vendors to access minimal data (e.g., no full customer lists).
- Monitoring: Use SIEM tools (like Splunk) to detect unauthorized access.
Lesson: Even large companies fail due to human error or third-party risks.
5. Network Security in Business: Applying the Concepts
Businesses use security to:
- Protect transactions (e.g., eSewa’s PCI-DSS compliance).
- Prevent downtime (e.g., NTC’s DDoS protection).
- Meet legal requirements (e.g., Nepal’s 2018 Cyber Security Act).
Example: Daraz’s Security Measures
| Threat | Daraz’s Countermeasure | Why It Works |
|---|---|---|
| Payment fraud | 3D Secure (MFA for cards) | Adds extra verification step |
| Data breaches | AWS Cloud encryption | Industry-standard encryption |
| DDoS attacks | Cloudflare protection | Absorbs attack traffic |
In the Real World
eSewa’s SSL/TLS:
- When you transfer money, your browser checks for a valid SSL certificate (issued by DigiCert). If expired, the transaction fails → Prevents MITM attacks.
- How it works: Your phone and eSewa’s server perform a TLS handshake to agree on encryption keys.
Khalti’s MFA:
- After entering your password, Khalti sends an OTP via SMS. Even if hackers steal your password, they can’t bypass the OTP.
- Real scenario: In 2021, a Khalti user reported fraud after reusing a weak password. MFA blocked the attacker.
NTC’s Firewall Rules:
- NTC blocks inbound RDP (port 3389) to prevent brute-force attacks on internal servers.
- Why it matters: In 2020, a Nepalese ISP was hacked via an unpatched RDP server.
Exam Tip: How to Score Full Marks
Define and Differentiate:
- Always start with clear definitions (e.g., "SSL provides encryption; TLS is its updated version").
- Compare protocols in tables (e.g., SSL vs. IPSec).
Use Real Examples:
- Link threats to Nepali companies:
- "A DDoS attack on Daraz would disrupt e-commerce, costing merchants sales."
- Cite laws:
- "Nepal’s Cyber Security Act 2018 mandates encryption for sensitive data."
- Link threats to Nepali companies:
Diagrams Are Your Friends:
- Draw firewall rule sets or encryption workflows (e.g., how AES works).
- Use mindmaps for threat classifications.
Common Pitfalls to Avoid:
- ❌ "Firewalls prevent all viruses." → False. Firewalls block network-level threats; antivirus handles malware.
- ❌ "VPNs are 100% secure." → False. Weak passwords can still be brute-forced.
Case Study Approach:
- If asked "How would you secure eSewa?", structure your answer:
- Threat: Phishing → Solution: MFA + email verification.
- Threat: Data leaks → Solution: Encrypted databases + access logs.
- If asked "How would you secure eSewa?", structure your answer:
Quick Revision Checklist
- Can you list 5 types of malware and give a Nepali example for each?
- Draw the TLS handshake steps (3-way process).
- Compare symmetric vs. asymmetric encryption in a table.
- Explain how Ncell’s biometric system prevents fraud.
- Name 3 security protocols used in banking and their weaknesses.
Based on the TU BIM syllabus for Business Data Communication and Networking (IT240), unit 9.
Discussion
Loading…