.NET ProgrammingUnit 106 min read

Deployment & Security in .NET: IIS, Cloud, Encryption, and OWASP

Unit 10 of .NET Programming covers deploying applications via IIS, Azure, and Docker, securing them with encryption (AES, RSA), authentication (JWT/OAuth), and OWASP guidelines, and hardening APIs against attacks. Includes real-world examples from Nepal’s eSewa (JWT tokens) and Daraz (HTTPS encryption).

1. Deployment Methods in .NET

Deployment is the process of making a .NET application accessible to end-users. Common methods include:

1.1 Web Deployment (IIS, Azure, Docker)

Internet Information Services (IIS)

  • Microsoft’s web server for hosting ASP.NET applications.

  • Supports Windows Authentication, Anonymous Access, and SSL/TLS.

  • Steps to Deploy on IIS:

    1. Publish the ASP.NET Core app (dotnet publish -c Release).
    2. Copy files to C:\inetpub\wwwroot\YourApp.
    3. Configure Application Pool (use No Managed Code for .NET Core).
    4. Bind to a port (80/443) and enable SSL via a certificate.
    flowchart TD
      A["1. Publish App"] --> B["2. Copy to IIS Root"]
      B --> C["3. Configure App Pool"]
      C --> D["4. Bind Port & SSL"]
      D --> E["5. Test via Browser"]

Azure App Service

  • Cloud-based PaaS for .NET apps.
  • Supports CI/CD (GitHub Actions, Azure DevOps).
  • Steps:
    1. Create an App Service in Azure Portal.
    2. Deploy via FTP, Git, or CLI (az webapp up).
    3. Configure SSL (Let’s Encrypt or custom cert).

Docker Deployment

  • Containerizes apps for consistent environments.
  • Steps:
    1. Create a Dockerfile:
      FROM mcr.microsoft.com/dotnet/aspnet:8.0
      WORKDIR /app
      COPY . .
      ENTRYPOINT ["dotnet", "YourApp.dll"]
      
    2. Build & run:
      docker build -t myapp .
      docker run -p 8080:80 myapp
      
    3. Deploy to Azure Container Instances (ACI) or Kubernetes.

1.2 Mobile & Desktop Deployment

Method Tool Use Case
Windows Forms ClickOnce Auto-updates for desktop apps.
MAUI .msix bundle Cross-platform mobile/desktop apps.
NuGet dotnet pack Share libraries across projects.

Example: Deploying a Khalti payment app (MAUI) to Android/iOS via .msix.


2. Security in .NET Applications

Security prevents unauthorized access, data breaches, and attacks.

2.1 Authentication & Authorization

JWT (JSON Web Tokens)

  • Used by eSewa, Daraz, and Ncell apps for secure API access.

  • Structure:

    {
      "header": { "alg": "HS256", "typ": "JWT" },
      "payload": { "userId": 123, "exp": 1735689600 },
      "signature": "base64UrlEncoded"
    }
    
  • How it works:

    1. User logs in → server issues a signed JWT.
    2. Client sends JWT in Authorization: Bearer <token>.
    3. Server validates the signature and expiry.
    sequenceDiagram
      User->>Server: Login (username/password)
      Server-->>User: JWT Token
      User->>Server: API Request (JWT in header)
      Server->>Server: Validate Token
      Server-->>User: Data (if valid)

OAuth 2.0

  • Used by Google, Facebook logins in apps.
  • Flows:
    • Authorization Code (for web apps).
    • Implicit (for SPAs).
    • Client Credentials (for server-to-server).

2.2 Encryption

Algorithm Use Case Key Size
AES Encrypting data (e.g., NTC’s e-billing). 128/256-bit
RSA Secure key exchange (e.g., HTTPS). 2048/4096-bit
SHA-256 Hashing passwords (e.g., Khalti DB). 256-bit

Example: Encrypting a Daraz order’s payment details with AES-256:

using System.Security.Cryptography;
using System.Text;

// Encrypt
public string Encrypt(string plainText, string key)
{
    using (Aes aes = Aes.Create())
    {
        aes.Key = Encoding.UTF8.GetBytes(key);
        aes.IV = new byte[16]; // Zero IV (not secure for production!)
        ICryptoTransform encryptor = aes.CreateEncryptor();
        using (MemoryStream ms = new MemoryStream())
        {
            using (CryptoStream cs = new CryptoStream(ms, encryptor, CryptoStreamMode.Write))
            {
                using (StreamWriter sw = new StreamWriter(cs))
                    sw.Write(plainText);
            }
            return Convert.ToBase64String(ms.ToArray());
        }
    }
}

2.3 OWASP Top 10 & Mitigations

Threat Example in Nepal Mitigation in .NET
SQL Injection NEPSE website hack (2021) Use Parameterized Queries (@param).
XSS (Cross-Site Scripting) Fake Daraz login pages Sanitize inputs (HtmlEncoder.Default).
CSRF Fake Khalti transactions Use Anti-Forgery Tokens ([ValidateAntiForgeryToken]).
Broken Authentication Weak eSewa passwords Enforce strong passwords + MFA.

3. Real-World Applications

Case 1: eSewa (JWT + HTTPS)

  • Problem: Secure API access for payments.
  • Solution:
    • Uses JWT for user authentication.
    • HTTPS (TLS 1.2+) encrypts all transactions.
    • Rate limiting prevents brute-force attacks.

Case 2: Daraz (AES + OWASP)

  • Problem: Protecting customer data.
  • Solution:
    • AES-256 encrypts order details.
    • OWASP ESAPI sanitizes user inputs.
    • CORS policies restrict API access.

Case 3: NTC’s e-Billing (Docker + Azure)

  • Problem: Scalable deployment.
  • Solution:
    • Docker containers ensure consistency.
    • Azure App Service auto-scales during peak hours.

4. Exam Tip

  • Deployment:
    • Know IIS vs. Azure vs. Docker trade-offs.
    • Memorize JWT payload structure and OAuth flows.
  • Security:
    • AES vs. RSA: When to use each.
    • OWASP Top 10: At least 3 threats + fixes.
  • Code:
    • Write a JWT validation snippet (5 marks).
    • Trace an AES encryption step-by-step (3 marks).

Visual Summary

mindmap
  root((.NET Security & Deployment))
    Deployment
      IIS["IIS: App Pool, SSL"]
      Azure["Azure App Service: CI/CD"]
      Docker["Docker: Containers, Kubernetes"]
    Security
      Auth["JWT: Header/Payload/Signature"]
      Encryption["AES: Symmetric, RSA: Asymmetric"]
      OWASP["SQLi, XSS, CSRF Mitigations"]
    Real-World
      eSewa["JWT + HTTPS"]
      Daraz["AES + OWASP"]
      NTC["Docker + Azure"]

Based on the TU BIM syllabus for .NET Programming (IT275), unit 10.

Discussion

Loading…