Introduction to Information TechnologyUnit 712 min read
Computer Security & Cryptography: Threats, Defenses, and Encryption
Unit 7 of Introduction to Information Technology explores how computers are protected from unauthorized access, damage, or theft, covering security threats, defense mechanisms (firewalls, encryption), cryptographic techniques (symmetric/asymmetric), and real-world applications like eSewa transactions and WhatsApp end-t
TAKEAWAYS
- Computer security protects data, hardware, and networks from cyber threats like malware, phishing, and hacking.
- Cryptography uses mathematical algorithms (e.g., AES, RSA) to encrypt data, ensuring confidentiality and integrity.
- Firewalls act as network gatekeepers, filtering traffic based on predefined security rules.
- Symmetric encryption (e.g., DES) is fast but requires secure key exchange, while asymmetric encryption (e.g., RSA) solves this with public/private keys.
- Authentication mechanisms (passwords, biometrics) verify user identity to prevent unauthorized access.
- Real-world examples include eSewa’s transaction encryption and NTC’s network firewall to block DDoS attacks.
1. Introduction to Computer Security
Computer security is the practice of protecting computers, servers, networks, and data from unauthorized access, use, disclosure, disruption, modification, or destruction. It encompasses confidentiality (data privacy), integrity (data accuracy), and availability (system uptime).
Why is Security Critical?
- Financial loss: Hackers steal credit card data (e.g., Daraz payment frauds).
- Reputation damage: Data breaches (e.g., Ncell customer records leak).
- Operational disruption: Ransomware attacks (e.g., hospitals or banks locked out of systems).
Common Security Threats
flowchart TD
A["Threats"] --> B["Malware"]
A --> C["Phishing"]
A --> D["Denial of Service"]
A --> E["Unauthorized Access"]
A --> F["Insider Threats"]- Malware: Software designed to damage (viruses, worms) or spy (spyware).
- Phishing: Fake emails/websites tricking users into revealing credentials (e.g., fake "eSewa login" emails).
- DoS/DDoS: Overloading a system to crash it (e.g., NTC’s network under attack).
- Unauthorized Access: Hackers bypassing security (e.g., brute-force password attacks).
- Insider Threats: Employees misusing access (e.g., stealing customer data).
2. Security Mechanisms
Security mechanisms are tools or techniques to mitigate threats. They fall into two categories:
A. Preventive Mechanisms
- Firewalls: Filter network traffic based on rules (e.g., NTC’s firewall blocking malicious IPs).
- Encryption: Converts data into unreadable code (e.g., WhatsApp’s end-to-end encryption).
- Authentication: Verifies user identity (passwords, biometrics, tokens).
B. Detective Mechanisms
- Intrusion Detection Systems (IDS): Monitors for suspicious activity (e.g., unusual login attempts).
- Audit Logs: Records user actions for later review (e.g., bank transaction logs).
C. Corrective Mechanisms
- Backups: Restores data after an attack (e.g., NEPSE’s daily market data backups).
- Patch Management: Fixes vulnerabilities in software (e.g., updating WhatsApp to close security holes).
3. Firewalls: Network Gatekeepers
A firewall is a security system that controls incoming/outgoing network traffic based on predefined rules.
How Firewalls Work
- Packet Filtering: Checks each packet’s source/destination IP and port.
- Stateful Inspection: Tracks the state of active connections (e.g., HTTP vs. HTTPS).
- Proxy Firewalls: Acts as an intermediary between users and the internet.
Types of Firewalls
| Type | Description | Example Use Case |
|---|---|---|
| Packet Filtering | Filters based on IP/port rules. | NTC’s basic network security. |
| Stateful Inspection | Tracks connection states (e.g., TCP handshake). | Banks securing online transactions. |
| Application-Level | Inspects application data (e.g., HTTP headers). | WhatsApp blocking malicious links. |
Example: NTC’s Firewall
Nepal Telecommunications Corporation (NTC) uses firewalls to:
- Block DDoS attacks (e.g., during elections).
- Filter malicious websites (e.g., phishing pages).
- Enforce access rules (e.g., only allow HTTPS traffic).
4. Cryptography: The Art of Secret Communication
Cryptography is the science of encoding messages to prevent unauthorized access. It ensures confidentiality, integrity, and authentication.
Key Concepts
- Plaintext: Original message (e.g., "Send 1000 NPR").
- Ciphertext: Encrypted message (e.g., "3F4G7H8I").
- Key: Secret value used for encryption/decryption (e.g., "AES-256").
Types of Cryptography
A. Symmetric Cryptography
- Uses the same key for encryption and decryption.
- Fast but requires secure key exchange.
| Algorithm | Key Size | Use Case |
|---|---|---|
| DES | 56-bit | Legacy systems (obsolete). |
| AES | 128/192/256-bit | eSewa transactions, secure files. |
| 3DES | 168-bit | Banking (e.g., NMB’s secure loans). |
Worked Example: AES Encryption Encrypt the message "Pay 500" using AES-128:
- Convert text to binary:
01001000 01101001 01110010 01101111 00100000 01100101 00100000 00111111. - Apply AES-128 algorithm with a 128-bit key (e.g.,
1A2B3C4D5E6F708192A3B4C5D6E7F890). - Output ciphertext:
3F4G7H8I...(actual binary would be longer).
B. Asymmetric Cryptography
- Uses a public key (shared) and a private key (secret).
- Solves the key distribution problem.
| Algorithm | Key Size | Use Case |
|---|---|---|
| RSA | 1024/2048-bit | WhatsApp encryption, SSL/TLS. |
| ECC | 256-bit | IoT devices (e.g., smart locks). |
Worked Example: RSA Encryption
- Key Generation:
- Choose two primes:
p = 61,q = 53. - Compute
n = p × q = 3233,φ(n) = (p-1)(q-1) = 3120. - Pick
e = 17(coprime with φ(n)), computed = e⁻¹ mod φ(n) = 2753. - Public key:
(n, e) = (3233, 17); Private key:(n, d) = (3233, 2753).
- Choose two primes:
- Encryption: Encrypt
M = 65("A") asC = Mᵉ mod n = 65¹⁷ mod 3233 = 2063. - Decryption:
M = Cᵈ mod n = 2063²⁷⁵³ mod 3233 = 65.
5. Authentication: Verifying Identity
Authentication ensures only authorized users access systems. Methods include:
| Method | Description | Example |
|---|---|---|
| Passwords | User-provided secret. | eSewa login. |
| Biometrics | Physical traits (fingerprint, iris). | Pathao driver verification. |
| Tokens | Physical devices (e.g., USB keys) or time-based codes. | Bank ATM cards. |
| Multi-Factor | Combines two+ methods (e.g., password + SMS code). | Ncell account login. |
Example: eSewa’s Authentication
- User enters username/password (password).
- System sends an SMS OTP (second factor).
- Only after both steps is access granted.
6. Real-World Applications
classDiagram class User {
+String username
+String password
+String otp
}
class BankServer {
+AES-256 key
+RSA-2048 publicKey
}
class Transaction {
+String amount
+String ciphertext
}
User --> BankServer : "Sends password + OTP"
BankServer --> User : "Returns AES-encrypted transaction"
User --> BankServer : "Verifies RSA signature"
BankServer --> Transaction : "Logs ciphertext (3F4G7H8I...)"
class WhatsAppServer {
+RSA-2048 privateKey
}
WhatsAppServer --> User : "Decrypts with private key"Updated class diagram showing RSA signature verification and WhatsApp’s role in end-to-end encryption.## In the real world
eSewa’s Transaction Security
- Idea: Uses AES-256 encryption for all payment data.
- How: When you pay ₹500 via eSewa, your card details are encrypted end-to-end. Even if hackers intercept the data, they can’t read it without the decryption key (held by eSewa’s servers).
- Worked Example: If a hacker steals a packet of your eSewa transaction, they see ciphertext like
3F4G7H8I...instead of your card number4111 1111 1111 1111.
WhatsApp’s End-to-End Encryption
- Idea: Uses asymmetric cryptography (RSA + AES).
- How: When you send a message to a friend, WhatsApp:
- Generates a one-time key for that conversation.
- Encrypts it with the recipient’s public key.
- Sends it securely. Only the recipient’s private key can decrypt it.
- Worked Example: If a government tries to intercept your chat with a friend, they see gibberish like
∆∆∆∆∆∆∆∆∆∆∆∆instead of "Meet at 5 PM."
NTC’s Firewall Against DDoS Attacks
- Idea: Uses stateful packet inspection.
- How: During the 2022 Nepal elections, NTC’s firewall:
- Detected a DDoS attack (thousands of fake requests flooding its servers).
- Blocked traffic from suspicious IPs.
- Allowed only legitimate users (e.g., voters checking results).
- Worked Example: Imagine a traffic jam at a Kathmandu bridge. The firewall is like a police officer checking licenses—only letting through authorized vehicles (legitimate users) while stopping the fake ones (malicious traffic).
7. Exam Tip
- Focus on definitions: Know the difference between confidentiality, integrity, and availability.
- Compare symmetric vs. asymmetric encryption: Use a table like the one above.
- Practice RSA/AES examples: Show step-by-step encryption/decryption (even if simplified).
- Link real-world examples: Always tie concepts to apps you use (e.g., "eSewa uses AES-256").
- Diagrams are key: Draw firewalls, encryption flows, and authentication steps.
- Past exam patterns: Expect questions on:
- Firewall functions (3–5 marks).
- Cryptographic algorithms (5–7 marks).
- Authentication methods (3–4 marks).
- Real-world scenarios (e.g., "How does WhatsApp secure chats?").
Based on the TU BIT syllabus for Introduction to Information Technology (BIT101), unit 7.
Discussion
Loading…