Information SecurityUnit 813 min read

Network & Web Security: Protocols, Attacks & Defenses

Unit 8 of Information Security explores how data travels securely over networks and the web, covering protocols (HTTP/HTTPS, TLS, DNS), common attacks (MITM, DDoS, SQLi), and defenses (firewalls, VPNs, WAFs), with real-world examples from Nepalese platforms like eSewa and Ncell.

TAKEAWAYS:

  • Network protocols (HTTP/HTTPS, TLS, DNS) define how data is transmitted and secured over the internet, with HTTPS using TLS for encryption.
  • Web security threats like MITM, XSS, and CSRF exploit protocol weaknesses, requiring defenses like encryption, input validation, and session tokens.
  • Firewalls, VPNs, and WAFs are hardware/software solutions to block unauthorized access and filter malicious traffic.
  • Secure coding practices (input validation, HTTPS enforcement) prevent attacks like SQL injection and cross-site scripting.
  • Real-world applications: eSewa uses HTTPS/TLS for secure transactions, while Ncell’s mobile network relies on firewalls to prevent DDoS attacks.
  • Exam focus: Compare protocols (HTTP vs. HTTPS), trace attack flows (e.g., MITM steps), and design defense strategies (e.g., firewall rules).

1. Network Security Fundamentals

Network security ensures data integrity, confidentiality, and availability during transmission. Key components include:

  • Confidentiality: Data is readable only by authorized parties (e.g., encrypted emails).
  • Integrity: Data remains unaltered during transit (e.g., checksums in TCP).
  • Availability: Systems and data are accessible when needed (e.g., DDoS protection).

1.1 Network Layers and Security

The OSI model (7 layers) and TCP/IP model (4 layers) define how data travels. Security mechanisms operate at different layers:

Application (Layer 7)Presentation (Layer 6)Session (Layer 5)Transport (Layer 4: TLS/SSL)Network (Layer 3: IPsec,Firewalls)Data Link (Layer 2: MACsec)Physical (Layer 1: EncryptedSignals)
OSI model with security protocols mapped to layers (TLS/SSL at Transport, IPsec/Firewalls at Network)
  • Application Layer (Layer 7): HTTPS, DNSSEC.
  • Transport Layer (Layer 4): TLS/SSL (encrypts data between client/server).
  • Network Layer (Layer 3): IPsec (encrypts IP packets), firewalls.
  • Data Link Layer (Layer 2): MACsec (secure Ethernet frames).

1.2 Common Network Attacks

Attack Type Description Example Prevention
MITM (Man-in-the-Middle) Intercepts/unaltered communication. Fake Wi-Fi hotspot stealing login credentials. Use HTTPS, VPNs, certificate pinning.
DDoS (Distributed Denial of Service) Overwhelms a system with traffic. Ncell website crash during peak hours. Rate limiting, cloud scrubbing.
Eavesdropping Unauthorized listening to data. Packet sniffing on unencrypted Wi-Fi. Encrypt traffic (WPA3, TLS).
Spoofing Impersonating a trusted source. Fake NEPSE email with phishing links. Digital signatures, DMARC.
Spoofed IPARP Cache PoisoningMAC FloodingVictimAttackerRouterSwitch
Common Layer 2/3 attacks: ARP spoofing, MAC flooding, and IP spoofing

Worked Example: MITM Attack on eSewa

  1. Attacker sets up a fake Wi-Fi hotspot ("eSewa Free Wi-Fi").
  2. User connects and logs in; attacker captures credentials.
  3. Attacker transfers money from the user’s account. Defense: eSewa enforces HTTPS (TLS 1.3) and warns users about untrusted networks.

2. Web Security Protocols

2.1 HTTP vs. HTTPS

  • HTTP (Hypertext Transfer Protocol): Unencrypted (Layer 7), sends data in plaintext.
GET /login (plaintext: username=admin)ClientServer
HTTP request/response in plaintext (Layer 7, unencrypted)
  • HTTPS (HTTP Secure): Encrypted using TLS/SSL (Layer 4/6).
1. ClientHelloTLS 1.3 support2. ServerHelloeSewa’s CA-signedcertificate3. EncryptedKeyExchangeSymmetric keyestablished4. GET /login (encrypted)Secure request5. 200 OK (encrypted)Secure response
HTTPS handshake and encrypted communication flow (TLS/SSL at Layers 4/6)

Comparison Table:

Feature HTTP HTTPS
Encryption None AES-256 (TLS)
Port 80 443
Security Vulnerable to MITM, eavesdropping Secure (integrity + confidentiality)
Performance Faster (no encryption overhead) Slightly slower (encryption)
Use Case Internal networks (e.g., intranet) Public websites (e.g., Daraz, eSewa)

Worked Example: HTTPS on Ncell’s Website

  • Ncell’s website uses Let’s Encrypt for free TLS certificates.
  • When you log in, your credentials are encrypted with AES-256-GCM.
  • Attackers cannot read your session token even if they intercept traffic.

2.2 TLS/SSL Deep Dive

  • TLS (Transport Layer Security): Successor to SSL (now obsolete).
  • Key Exchange: Uses Diffie-Hellman Ephemeral (DHE) or RSA to agree on a symmetric key.
  • Symmetric Encryption: AES or ChaCha20 encrypts the actual data.
  • Certificates: Issued by CAs (Certificate Authorities) like DigiCert or Let’s Encrypt.
Domain: e.g., eSewa.comPublic KeyExpiry DateSignatureCertificateCertificate Authority (CA)
Hierarchy of TLS/SSL certificates (CA → Certificate → Key Components)

Real-World Example: eSewa’s TLS Certificate

  • eSewa’s website (https://esewa.com.np) uses a certificate signed by Sectigo.
  • The certificate includes:
    • Domain: esewa.com.np
    • Public key: RSA 2048-bit
    • Validity: 2023–2025
    • Extensions: Subject Alternative Name (SAN) for api.esewa.com.np

3. Web Application Security Threats

3.1 Common Web Attacks

Attack How It Works Example Prevention
Cross-Site Scripting (XSS) Injects malicious scripts into web pages. Stealing cookies via <script>document.cookie</script>. Input validation, CSP headers.
SQL Injection (SQLi) Executes malicious SQL queries. ' OR '1'='1 bypasses login. Prepared statements, ORM.
Cross-Site Request Forgery (CSRF) Forces users to execute actions. Tricks user into transferring money via a fake button. CSRF tokens, SameSite cookies.
Session Hijacking Steals session cookies. MITM attack captures JSESSIONID. HttpOnly, Secure flags, short expiry.

Worked Example: SQL Injection on a Daraz Order

  1. Attacker enters ' OR '1'='1 in the "Username" field.
  2. SQL query becomes:
    SELECT * FROM users WHERE username = '' OR '1'='1' AND password = '...';
    
  3. Returns all users; attacker logs in as any user. Defense: Daraz uses parameterized queries:
    // Vulnerable (SQLi)
    String query = "SELECT * FROM users WHERE username = '" + userInput + "'";
    
    // Secure (Prepared Statement)
    PreparedStatement stmt = conn.prepareStatement("SELECT * FROM users WHERE username = ?");
    stmt.setString(1, userInput);
    

3.2 Defense Mechanisms

  • Input Validation: Reject non-alphanumeric characters in login fields.
  • Output Encoding: Escape HTML/JS in user-generated content (e.g., < → &lt;).
  • Security Headers:
    • Content-Security-Policy (CSP): Restricts script sources.
    • HttpOnly: Prevents JavaScript from accessing cookies.
    • Secure: Ensures cookies are sent only over HTTPS.
  • Web Application Firewall (WAF): Filters malicious traffic (e.g., Cloudflare, ModSecurity).

4. Network Security Tools and Technologies

4.1 Firewalls

  • Purpose: Filters traffic based on rules (IP, port, protocol).
  • Types:
    • Packet-filtering: Blocks by IP/port (e.g., iptables).
    • Stateful: Tracks connections (e.g., Cisco ASA).
    • Next-gen (NGFW): Deep packet inspection (e.g., Palo Alto).
  • Rule Example (Ncell’s Firewall):
    ALLOW TCP any any 443 (HTTPS)
    DROP TCP any any 22 (SSH) from untrusted IPs
    
08162431Source IP32 bitsDestination IP32 bitsProtocol8 bitsPorts16 bitsFlags8 bits
Packet header fields inspected by firewalls (e.g., IP, TCP/UDP)

4.2 VPNs (Virtual Private Networks)

  • Purpose: Encrypts traffic over untrusted networks (e.g., public Wi-Fi).
  • Types:
    • Remote Access VPN: User connects to a corporate network (e.g., Ncell’s remote office).
    • Site-to-Site VPN: Connects two networks (e.g., Daraz’s HQ to data center).
  • Protocols: OpenVPN, IPSec, WireGuard.
  • Worked Example: A Pathao driver uses a VPN to securely access the dispatch system on a café’s Wi-Fi.

4.3 Intrusion Detection/Prevention Systems (IDS/IPS)

  • IDS: Monitors traffic (e.g., Snort, Suricata).
  • IPS: Actively blocks threats (e.g., inline with a firewall).
  • Signature-Based: Matches known attack patterns.
  • Anomaly-Based: Detects unusual behavior (e.g., sudden spike in traffic = DDoS).

Mermaid Diagram: IDS/IPS Deployment

InternetFirewallIDS/IPSInternal Network
IDS/IPS deployment (Snort/Suricata) between firewall and internal network

5. Secure Coding Practices

5.1 OWASP Top 10 (2021)

Risk Mitigation
Injection (SQLi, XSS) Use ORM, input validation.
Broken Authentication Enforce MFA, strong passwords.
Sensitive Data Exposure Encrypt data at rest (AES-256).
XML External Entities Disable XXE parsing.
Broken Access Control Role-based access control (RBAC).

Worked Example: Secure Login in a Banking App

# Vulnerable (Predictable Session ID)
session_id = str(uuid.uuid4())  # No entropy source

# Secure (Cryptographically Random)
import os
session_id = os.urandom(16).hex()  # 128-bit randomness

5.2 Security Headers

  • Strict-Transport-Security (HSTS):
    Strict-Transport-Security: max-age=31536000; includeSubDomains
    
    Forces browsers to use HTTPS for a year (e.g., eSewa).
  • X-Content-Type-Options:
    X-Content-Type-Options: nosniff
    
    Prevents MIME-type sniffing attacks.

## In the Real World

  1. eSewa’s HTTPS Security

    • Idea Used: TLS 1.3 encryption for transactions.
    • How: When you pay a bill, your card details are encrypted with AES-256. Even if an attacker intercepts the traffic (e.g., on a café Wi-Fi), they cannot decrypt it without the session key.
    • Real Impact: Prevents MITM attacks where fraudsters steal payment details.
  2. Ncell’s Firewall Against DDoS

    • Idea Used: Stateful firewall + rate limiting.
    • How: During the 2022 monsoon, Ncell’s website faced a DDoS attack. Their firewall:
      • Dropped packets with spoofed source IPs.
      • Rate-limited requests from a single IP to 100/sec.
    • Real Impact: Kept the website available for customers despite the attack.
  3. Pathao’s VPN for Driver Safety

    • Idea Used: IPsec VPN for secure GPS/data transmission.
    • How: Pathao drivers connect to the company’s VPN when on the road. This ensures:
      • Ride details (pickup/drop locations) are encrypted.
      • No third-party can eavesdrop on driver-passenger communication.
    • Real Impact: Prevents hackers from tracking drivers or altering ride data.

## Exam Tip

  1. Protocol Comparisons: Always compare HTTP vs. HTTPS, TLS 1.2 vs. 1.3, and symmetric vs. asymmetric encryption in tables.
  2. Attack Traces: For MITM or SQLi, draw a sequence diagram showing each step (e.g., attacker intercepts → modifies → forwards).
  3. Defense Strategies:
    • For web apps: Mention OWASP Top 10 mitigations (e.g., "Use prepared statements to prevent SQLi").
    • For networks: Describe firewall rules or VPN protocols (e.g., "IPSec in tunnel mode for site-to-site VPNs").
  4. Real-World Scenarios: Relate to Nepalese examples:
    • "How would you secure eSewa’s login page?" → HTTPS + CSRF tokens.
    • "How does Ncell prevent DDoS?" → Cloudflare scrubbing + rate limiting.
  5. Diagrams: The exam loves layered models (OSI/TCP/IP), protocol handshakes (TLS), and attack flowcharts (MITM steps). Practice drawing these under time pressure.

Based on the TU BIM syllabus for Information Security (IT244), unit 8.

Discussion

Loading…