.NET ProgrammingUnit 106 min read
Deployment & Security in .NET: IIS, Cloud, Encryption, and OWASP
Unit 10 of .NET Programming covers deploying applications via IIS, Azure, and Docker, securing them with encryption (AES, RSA), authentication (JWT/OAuth), and OWASP guidelines, and hardening APIs against attacks. Includes real-world examples from Nepal’s eSewa (JWT tokens) and Daraz (HTTPS encryption).
1. Deployment Methods in .NET
Deployment is the process of making a .NET application accessible to end-users. Common methods include:
1.1 Web Deployment (IIS, Azure, Docker)
Internet Information Services (IIS)
Microsoft’s web server for hosting ASP.NET applications.
Supports Windows Authentication, Anonymous Access, and SSL/TLS.
Steps to Deploy on IIS:
- Publish the ASP.NET Core app (
dotnet publish -c Release). - Copy files to
C:\inetpub\wwwroot\YourApp. - Configure Application Pool (use No Managed Code for .NET Core).
- Bind to a port (80/443) and enable SSL via a certificate.
flowchart TD A["1. Publish App"] --> B["2. Copy to IIS Root"] B --> C["3. Configure App Pool"] C --> D["4. Bind Port & SSL"] D --> E["5. Test via Browser"]
- Publish the ASP.NET Core app (
Azure App Service
- Cloud-based PaaS for .NET apps.
- Supports CI/CD (GitHub Actions, Azure DevOps).
- Steps:
- Create an App Service in Azure Portal.
- Deploy via FTP, Git, or CLI (
az webapp up). - Configure SSL (Let’s Encrypt or custom cert).
Docker Deployment
- Containerizes apps for consistent environments.
- Steps:
- Create a
Dockerfile:FROM mcr.microsoft.com/dotnet/aspnet:8.0 WORKDIR /app COPY . . ENTRYPOINT ["dotnet", "YourApp.dll"] - Build & run:
docker build -t myapp . docker run -p 8080:80 myapp - Deploy to Azure Container Instances (ACI) or Kubernetes.
- Create a
1.2 Mobile & Desktop Deployment
| Method | Tool | Use Case |
|---|---|---|
| Windows Forms | ClickOnce |
Auto-updates for desktop apps. |
| MAUI | .msix bundle |
Cross-platform mobile/desktop apps. |
| NuGet | dotnet pack |
Share libraries across projects. |
Example: Deploying a Khalti payment app (MAUI) to Android/iOS via .msix.
2. Security in .NET Applications
Security prevents unauthorized access, data breaches, and attacks.
2.1 Authentication & Authorization
JWT (JSON Web Tokens)
Used by eSewa, Daraz, and Ncell apps for secure API access.
Structure:
{ "header": { "alg": "HS256", "typ": "JWT" }, "payload": { "userId": 123, "exp": 1735689600 }, "signature": "base64UrlEncoded" }How it works:
- User logs in → server issues a signed JWT.
- Client sends JWT in
Authorization: Bearer <token>. - Server validates the signature and expiry.
sequenceDiagram User->>Server: Login (username/password) Server-->>User: JWT Token User->>Server: API Request (JWT in header) Server->>Server: Validate Token Server-->>User: Data (if valid)
OAuth 2.0
- Used by Google, Facebook logins in apps.
- Flows:
- Authorization Code (for web apps).
- Implicit (for SPAs).
- Client Credentials (for server-to-server).
2.2 Encryption
| Algorithm | Use Case | Key Size |
|---|---|---|
| AES | Encrypting data (e.g., NTC’s e-billing). | 128/256-bit |
| RSA | Secure key exchange (e.g., HTTPS). | 2048/4096-bit |
| SHA-256 | Hashing passwords (e.g., Khalti DB). | 256-bit |
Example: Encrypting a Daraz order’s payment details with AES-256:
using System.Security.Cryptography;
using System.Text;
// Encrypt
public string Encrypt(string plainText, string key)
{
using (Aes aes = Aes.Create())
{
aes.Key = Encoding.UTF8.GetBytes(key);
aes.IV = new byte[16]; // Zero IV (not secure for production!)
ICryptoTransform encryptor = aes.CreateEncryptor();
using (MemoryStream ms = new MemoryStream())
{
using (CryptoStream cs = new CryptoStream(ms, encryptor, CryptoStreamMode.Write))
{
using (StreamWriter sw = new StreamWriter(cs))
sw.Write(plainText);
}
return Convert.ToBase64String(ms.ToArray());
}
}
}
2.3 OWASP Top 10 & Mitigations
| Threat | Example in Nepal | Mitigation in .NET |
|---|---|---|
| SQL Injection | NEPSE website hack (2021) | Use Parameterized Queries (@param). |
| XSS (Cross-Site Scripting) | Fake Daraz login pages | Sanitize inputs (HtmlEncoder.Default). |
| CSRF | Fake Khalti transactions | Use Anti-Forgery Tokens ([ValidateAntiForgeryToken]). |
| Broken Authentication | Weak eSewa passwords | Enforce strong passwords + MFA. |
3. Real-World Applications
Case 1: eSewa (JWT + HTTPS)
- Problem: Secure API access for payments.
- Solution:
- Uses JWT for user authentication.
- HTTPS (TLS 1.2+) encrypts all transactions.
- Rate limiting prevents brute-force attacks.
Case 2: Daraz (AES + OWASP)
- Problem: Protecting customer data.
- Solution:
- AES-256 encrypts order details.
- OWASP ESAPI sanitizes user inputs.
- CORS policies restrict API access.
Case 3: NTC’s e-Billing (Docker + Azure)
- Problem: Scalable deployment.
- Solution:
- Docker containers ensure consistency.
- Azure App Service auto-scales during peak hours.
4. Exam Tip
- Deployment:
- Know IIS vs. Azure vs. Docker trade-offs.
- Memorize JWT payload structure and OAuth flows.
- Security:
- AES vs. RSA: When to use each.
- OWASP Top 10: At least 3 threats + fixes.
- Code:
- Write a JWT validation snippet (5 marks).
- Trace an AES encryption step-by-step (3 marks).
Visual Summary
mindmap
root((.NET Security & Deployment))
Deployment
IIS["IIS: App Pool, SSL"]
Azure["Azure App Service: CI/CD"]
Docker["Docker: Containers, Kubernetes"]
Security
Auth["JWT: Header/Payload/Signature"]
Encryption["AES: Symmetric, RSA: Asymmetric"]
OWASP["SQLi, XSS, CSRF Mitigations"]
Real-World
eSewa["JWT + HTTPS"]
Daraz["AES + OWASP"]
NTC["Docker + Azure"]Based on the TU BIM syllabus for .NET Programming (IT275), unit 10.
Discussion
Loading…