IT Ethics and CybersecurityUnit 67 min read
Cybersecurity Fundamentals: Threats, Models, Controls & Best Practices
Unit 6 of IT Ethics and Cybersecurity explores core cybersecurity concepts—confidentiality, integrity, availability (CIA triad), security models (Bell-LaPadula, Biba), threats (malware, phishing), and defensive strategies like encryption, firewalls, and risk assessment—with real-world applications in Nepalese tech (e.g
Core Concepts: The CIA Triad
Cybersecurity revolves around three pillars: Confidentiality, Integrity, and Availability (CIA Triad). These principles define what security aims to protect.
1. Confidentiality
- Ensures data is accessible only to authorized users.
- Mechanisms: Encryption, access controls (passwords, biometrics), and authentication (e.g., OTPs in Khalti or eSewa).
- Example: When you transfer money via eSewa, your transaction details are encrypted to prevent unauthorized access.
2. Integrity
- Guarantees data accuracy and consistency—no unauthorized modifications.
- Mechanisms: Hash functions (e.g., SHA-256), digital signatures, checksums.
- Example: Nepal Stock Exchange (NEPSE) uses digital signatures to verify trades and prevent tampering.
3. Availability
- Ensures systems and data are accessible when needed.
- Threats: DDoS attacks, hardware failures.
- Example: NTC’s fiber-optic network must stay available to prevent service disruptions during peak hours.
pie
title CIA Triad in Cybersecurity
"Confidentiality" : 33
"Integrity" : 33
"Availability" : 33Security Models: Rules for Access Control
Security models define how access is granted or restricted. Two key models:
1. Bell-LaPadula Model (Military Security)
- Goal: Prevent unauthorized data disclosure (confidentiality).
- Rules:
- No read-up: Users can’t read data at a higher security level.
- No write-down: Users can’t write data to a lower security level.
- Example: In a Nepal Police database, a constable can’t access DIG-level case files.
2. Biba Model (Data Integrity)
- Goal: Prevent unauthorized data modification (integrity).
- Rules:
- No read-down: Users can’t read data at a lower integrity level.
- No write-up: Users can’t write data to a higher integrity level.
- Example: In Ncell’s billing system, a clerk can’t alter CEO-level financial records.
| Model | Primary Focus | Key Rule | Real-World Use Case |
|---|---|---|---|
| Bell-LaPadula | Confidentiality | No read-up, no write-down | Government databases (e.g., NIDA) |
| Biba | Integrity | No read-down, no write-up | Banking transaction logs (e.g., Nabil Bank) |
Cyber Threats: Malware, Phishing, and More
Cyber threats exploit vulnerabilities in systems. Key types:
1. Malware (Malicious Software)
- Types:
- Viruses: Attach to clean files (e.g., ransomware locking Daraz customer data).
- Worms: Self-replicating (e.g., Emotet targeting Nepalese government emails).
- Trojan Horses: Disguised as legitimate software (e.g., fake WhatsApp updates stealing data).
- Example: In 2021, a malware attack disrupted NTC’s email servers, causing delays in service requests.
2. Phishing Attacks
- How it works: Fraudulent emails/websites trick users into revealing credentials.
- Example: Fake eSewa login pages stealing user IDs and passwords during Dashain sales.
3. Denial-of-Service (DoS/DDoS)
- Goal: Overload a system to make it unavailable.
- Example: Pathao drivers reported DDoS attacks during Tihar festival, causing app crashes.
flowchart TD
A["Cyber Threat"] --> B["Malware<br/>(Viruses, Worms, Trojans)"]
A --> C["Phishing<br/>(Fake Emails, Websites)"]
A --> D["DoS/DDoS<br/>(Server Overload)"]
B --> E["Ncell SIM Fraud<br/>2022"]
C --> F["eSewa Scams<br/>2023"]
D --> G["Pathao App Crashes<br/>Tihar 2023"]Defensive Strategies: Firewalls, Encryption, and More
1. Firewalls
- Role: Filter traffic between trusted and untrusted networks.
- Types:
- Packet-filtering: Checks IP/port (e.g., NTC’s network firewall).
- Stateful inspection: Tracks connections (e.g., Ncell’s 4G firewall).
- Example: Daraz uses firewalls to block malicious IP addresses during Black Friday sales.
2. Encryption
- Purpose: Scrambles data so only authorized parties can read it.
- Types:
- Symmetric (AES): Fast, same key for encryption/decryption (e.g., Khalti’s transaction encryption).
- Asymmetric (RSA): Public/private keys (e.g., NEPSE’s secure trading keys).
- Example: When you send money via eSewa, AES-256 encrypts your card details.
3. Intrusion Detection Systems (IDS)
- Role: Monitors network for suspicious activity.
- Example: Ncell uses IDS to detect SIM-box fraud in real time.
| Control | Function | Nepalese Example |
|---|---|---|
| Firewall | Traffic filtering | NTC’s network security |
| Encryption | Data confidentiality | eSewa’s transaction security |
| IDS | Threat detection | Ncell’s fraud monitoring |
Risk Management: Assessing and Mitigating Threats
1. Risk Assessment
- Steps:
- Identify assets (e.g., NEPSE’s trading database).
- Identify threats (e.g., insider attacks, hacking).
- Assess impact (financial, reputational).
- Mitigate risks (e.g., two-factor authentication).
2. Risk Mitigation Strategies
| Strategy | Example in Nepal |
|---|---|
| Access Controls | Nabil Bank requires biometric login. |
| Employee Training | NTC conducts phishing simulation drills. |
| Backup Systems | Daraz uses cloud backups for order data. |
In the Real World
eSewa’s Transaction Security
- Uses AES-256 encryption (confidentiality) and OTP verification (integrity) to secure money transfers.
- Bell-LaPadula model ensures users can’t access higher-value transactions (e.g., a merchant can’t see a customer’s savings).
Ncell’s SIM Fraud Prevention
- Employs firewalls and IDS to detect SIM-box fraud (unauthorized call routing).
- Availability is critical—fraud disrupts services, costing Ncell millions in losses annually.
NEPSE’s Secure Trading
- Digital signatures (integrity) prevent trade tampering.
- Biba model ensures low-level staff can’t alter high-integrity trade records.
Exam Tip
- CIA Triad: Always relate threats to confidentiality, integrity, or availability. Example:
"A DDoS attack on Pathao violates availability by overwhelming servers."
- Security Models: Compare Bell-LaPadula (confidentiality) vs. Biba (integrity) with real examples (e.g., government data vs. banking logs).
- Threats: Link malware/phishing to Nepalese cases (e.g., eSewa scams, NTC disruptions).
- Controls: Match firewalls to NTC/Daraz, encryption to eSewa/Khalti, and IDS to Ncell fraud detection.
Based on the TU BIM syllabus for IT Ethics and Cybersecurity (IT246), unit 6.
Discussion
Loading…