IT246 IT Ethics and Cybersecurity

IT Ethics and CybersecurityUnit 67 min read

Cybersecurity Fundamentals: Threats, Models, Controls & Best Practices

Unit 6 of IT Ethics and Cybersecurity explores core cybersecurity concepts—confidentiality, integrity, availability (CIA triad), security models (Bell-LaPadula, Biba), threats (malware, phishing), and defensive strategies like encryption, firewalls, and risk assessment—with real-world applications in Nepalese tech (e.g

Core Concepts: The CIA Triad

Cybersecurity revolves around three pillars: Confidentiality, Integrity, and Availability (CIA Triad). These principles define what security aims to protect.

1. Confidentiality

  • Ensures data is accessible only to authorized users.
  • Mechanisms: Encryption, access controls (passwords, biometrics), and authentication (e.g., OTPs in Khalti or eSewa).
  • Example: When you transfer money via eSewa, your transaction details are encrypted to prevent unauthorized access.

2. Integrity

  • Guarantees data accuracy and consistency—no unauthorized modifications.
  • Mechanisms: Hash functions (e.g., SHA-256), digital signatures, checksums.
  • Example: Nepal Stock Exchange (NEPSE) uses digital signatures to verify trades and prevent tampering.

3. Availability

  • Ensures systems and data are accessible when needed.
  • Threats: DDoS attacks, hardware failures.
  • Example: NTC’s fiber-optic network must stay available to prevent service disruptions during peak hours.
pie
    title CIA Triad in Cybersecurity
    "Confidentiality" : 33
    "Integrity" : 33
    "Availability" : 33

Security Models: Rules for Access Control

Security models define how access is granted or restricted. Two key models:

1. Bell-LaPadula Model (Military Security)

  • Goal: Prevent unauthorized data disclosure (confidentiality).
  • Rules:
    • No read-up: Users can’t read data at a higher security level.
    • No write-down: Users can’t write data to a lower security level.
  • Example: In a Nepal Police database, a constable can’t access DIG-level case files.

2. Biba Model (Data Integrity)

  • Goal: Prevent unauthorized data modification (integrity).
  • Rules:
    • No read-down: Users can’t read data at a lower integrity level.
    • No write-up: Users can’t write data to a higher integrity level.
  • Example: In Ncell’s billing system, a clerk can’t alter CEO-level financial records.
Model Primary Focus Key Rule Real-World Use Case
Bell-LaPadula Confidentiality No read-up, no write-down Government databases (e.g., NIDA)
Biba Integrity No read-down, no write-up Banking transaction logs (e.g., Nabil Bank)

Cyber Threats: Malware, Phishing, and More

Cyber threats exploit vulnerabilities in systems. Key types:

1. Malware (Malicious Software)

  • Types:
    • Viruses: Attach to clean files (e.g., ransomware locking Daraz customer data).
    • Worms: Self-replicating (e.g., Emotet targeting Nepalese government emails).
    • Trojan Horses: Disguised as legitimate software (e.g., fake WhatsApp updates stealing data).
  • Example: In 2021, a malware attack disrupted NTC’s email servers, causing delays in service requests.

2. Phishing Attacks

  • How it works: Fraudulent emails/websites trick users into revealing credentials.
  • Example: Fake eSewa login pages stealing user IDs and passwords during Dashain sales.

3. Denial-of-Service (DoS/DDoS)

  • Goal: Overload a system to make it unavailable.
  • Example: Pathao drivers reported DDoS attacks during Tihar festival, causing app crashes.
flowchart TD
    A["Cyber Threat"] --> B["Malware<br/>(Viruses, Worms, Trojans)"]
    A --> C["Phishing<br/>(Fake Emails, Websites)"]
    A --> D["DoS/DDoS<br/>(Server Overload)"]
    B --> E["Ncell SIM Fraud<br/>2022"]
    C --> F["eSewa Scams<br/>2023"]
    D --> G["Pathao App Crashes<br/>Tihar 2023"]

Defensive Strategies: Firewalls, Encryption, and More

1. Firewalls

  • Role: Filter traffic between trusted and untrusted networks.
  • Types:
    • Packet-filtering: Checks IP/port (e.g., NTC’s network firewall).
    • Stateful inspection: Tracks connections (e.g., Ncell’s 4G firewall).
  • Example: Daraz uses firewalls to block malicious IP addresses during Black Friday sales.

2. Encryption

  • Purpose: Scrambles data so only authorized parties can read it.
  • Types:
    • Symmetric (AES): Fast, same key for encryption/decryption (e.g., Khalti’s transaction encryption).
    • Asymmetric (RSA): Public/private keys (e.g., NEPSE’s secure trading keys).
  • Example: When you send money via eSewa, AES-256 encrypts your card details.

3. Intrusion Detection Systems (IDS)

  • Role: Monitors network for suspicious activity.
  • Example: Ncell uses IDS to detect SIM-box fraud in real time.
Control Function Nepalese Example
Firewall Traffic filtering NTC’s network security
Encryption Data confidentiality eSewa’s transaction security
IDS Threat detection Ncell’s fraud monitoring

Risk Management: Assessing and Mitigating Threats

1. Risk Assessment

  • Steps:
    1. Identify assets (e.g., NEPSE’s trading database).
    2. Identify threats (e.g., insider attacks, hacking).
    3. Assess impact (financial, reputational).
    4. Mitigate risks (e.g., two-factor authentication).

2. Risk Mitigation Strategies

Strategy Example in Nepal
Access Controls Nabil Bank requires biometric login.
Employee Training NTC conducts phishing simulation drills.
Backup Systems Daraz uses cloud backups for order data.

In the Real World

  1. eSewa’s Transaction Security

    • Uses AES-256 encryption (confidentiality) and OTP verification (integrity) to secure money transfers.
    • Bell-LaPadula model ensures users can’t access higher-value transactions (e.g., a merchant can’t see a customer’s savings).
  2. Ncell’s SIM Fraud Prevention

    • Employs firewalls and IDS to detect SIM-box fraud (unauthorized call routing).
    • Availability is critical—fraud disrupts services, costing Ncell millions in losses annually.
  3. NEPSE’s Secure Trading

    • Digital signatures (integrity) prevent trade tampering.
    • Biba model ensures low-level staff can’t alter high-integrity trade records.

Exam Tip

  • CIA Triad: Always relate threats to confidentiality, integrity, or availability. Example:

    "A DDoS attack on Pathao violates availability by overwhelming servers."

  • Security Models: Compare Bell-LaPadula (confidentiality) vs. Biba (integrity) with real examples (e.g., government data vs. banking logs).
  • Threats: Link malware/phishing to Nepalese cases (e.g., eSewa scams, NTC disruptions).
  • Controls: Match firewalls to NTC/Daraz, encryption to eSewa/Khalti, and IDS to Ncell fraud detection.

Based on the TU BIM syllabus for IT Ethics and Cybersecurity (IT246), unit 6.

Discussion

Loading…