BIT101 Introduction to Information Technology

Introduction to Information TechnologyUnit 712 min read

Computer Security & Cryptography: Threats, Defenses, and Encryption

Unit 7 of Introduction to Information Technology explores how computers are protected from unauthorized access, damage, or theft, covering security threats, defense mechanisms (firewalls, encryption), cryptographic techniques (symmetric/asymmetric), and real-world applications like eSewa transactions and WhatsApp end-t

TAKEAWAYS

  • Computer security protects data, hardware, and networks from cyber threats like malware, phishing, and hacking.
  • Cryptography uses mathematical algorithms (e.g., AES, RSA) to encrypt data, ensuring confidentiality and integrity.
  • Firewalls act as network gatekeepers, filtering traffic based on predefined security rules.
  • Symmetric encryption (e.g., DES) is fast but requires secure key exchange, while asymmetric encryption (e.g., RSA) solves this with public/private keys.
  • Authentication mechanisms (passwords, biometrics) verify user identity to prevent unauthorized access.
  • Real-world examples include eSewa’s transaction encryption and NTC’s network firewall to block DDoS attacks.

1. Introduction to Computer Security

Computer security is the practice of protecting computers, servers, networks, and data from unauthorized access, use, disclosure, disruption, modification, or destruction. It encompasses confidentiality (data privacy), integrity (data accuracy), and availability (system uptime).

Why is Security Critical?

  • Financial loss: Hackers steal credit card data (e.g., Daraz payment frauds).
  • Reputation damage: Data breaches (e.g., Ncell customer records leak).
  • Operational disruption: Ransomware attacks (e.g., hospitals or banks locked out of systems).

Common Security Threats

flowchart TD
    A["Threats"] --> B["Malware"]
    A --> C["Phishing"]
    A --> D["Denial of Service"]
    A --> E["Unauthorized Access"]
    A --> F["Insider Threats"]
  • Malware: Software designed to damage (viruses, worms) or spy (spyware).
  • Phishing: Fake emails/websites tricking users into revealing credentials (e.g., fake "eSewa login" emails).
  • DoS/DDoS: Overloading a system to crash it (e.g., NTC’s network under attack).
  • Unauthorized Access: Hackers bypassing security (e.g., brute-force password attacks).
  • Insider Threats: Employees misusing access (e.g., stealing customer data).

2. Security Mechanisms

Security mechanisms are tools or techniques to mitigate threats. They fall into two categories:

Firewalls (NTC’s packet filtering rules)Encryption (eSewa’s AES-256)Authentication (Ncell’s OTP + password)PreventiveIntrusion Detection Systems (IDS) (e.g., monitoring NEPSE’s Audit Logs (bank transaction records)DetectiveBackups (NEPSE’s daily market data backups)Patch Management (WhatsApp’s monthly security updates)CorrectiveSecurity Mechanisms
Classification of security mechanisms by function (Preventive, Detective, Corrective) with Nepal-specific examples.

A. Preventive Mechanisms

  • Firewalls: Filter network traffic based on rules (e.g., NTC’s firewall blocking malicious IPs).
  • Encryption: Converts data into unreadable code (e.g., WhatsApp’s end-to-end encryption).
  • Authentication: Verifies user identity (passwords, biometrics, tokens).

B. Detective Mechanisms

  • Intrusion Detection Systems (IDS): Monitors for suspicious activity (e.g., unusual login attempts).
  • Audit Logs: Records user actions for later review (e.g., bank transaction logs).

C. Corrective Mechanisms

  • Backups: Restores data after an attack (e.g., NEPSE’s daily market data backups).
  • Patch Management: Fixes vulnerabilities in software (e.g., updating WhatsApp to close security holes).

3. Firewalls: Network Gatekeepers

A firewall is a security system that controls incoming/outgoing network traffic based on predefined rules.

Rules-based (IP, port, protocol)Packet Filtering (NTC)Tracks connection stateStateful Inspection (eSewa)Intermediary server for requestsProxy Firewall (Ncell)Firewall Types
Classification of firewall types with Nepal-based examples.

How Firewalls Work

  1. Packet Filtering: Checks each packet’s source/destination IP and port.
  2. Stateful Inspection: Tracks the state of active connections (e.g., HTTP vs. HTTPS).
  3. Proxy Firewalls: Acts as an intermediary between users and the internet.

Types of Firewalls

Type Description Example Use Case
Packet Filtering Filters based on IP/port rules. NTC’s basic network security.
Stateful Inspection Tracks connection states (e.g., TCP handshake). Banks securing online transactions.
Application-Level Inspects application data (e.g., HTTP headers). WhatsApp blocking malicious links.

Example: NTC’s Firewall

Nepal Telecommunications Corporation (NTC) uses firewalls to:

  • Block DDoS attacks (e.g., during elections).
  • Filter malicious websites (e.g., phishing pages).
  • Enforce access rules (e.g., only allow HTTPS traffic).

4. Cryptography: The Art of Secret Communication

Cryptography is the science of encoding messages to prevent unauthorized access. It ensures confidentiality, integrity, and authentication.

2010 BS (1953 AD)[object Object]2018 BS (2061 AD)[object Object]2020 BS (2063 AD)[object Object]

Key Concepts

  • Plaintext: Original message (e.g., "Send 1000 NPR").
  • Ciphertext: Encrypted message (e.g., "3F4G7H8I").
  • Key: Secret value used for encryption/decryption (e.g., "AES-256").

Types of Cryptography

A. Symmetric Cryptography
  • Uses the same key for encryption and decryption.
  • Fast but requires secure key exchange.
Algorithm Key Size Use Case
DES 56-bit Legacy systems (obsolete).
AES 128/192/256-bit eSewa transactions, secure files.
3DES 168-bit Banking (e.g., NMB’s secure loans).

Worked Example: AES Encryption Encrypt the message "Pay 500" using AES-128:

  1. Convert text to binary: 01001000 01101001 01110010 01101111 00100000 01100101 00100000 00111111.
  2. Apply AES-128 algorithm with a 128-bit key (e.g., 1A2B3C4D5E6F708192A3B4C5D6E7F890).
  3. Output ciphertext: 3F4G7H8I... (actual binary would be longer).
B. Asymmetric Cryptography
  • Uses a public key (shared) and a private key (secret).
  • Solves the key distribution problem.
Algorithm Key Size Use Case
RSA 1024/2048-bit WhatsApp encryption, SSL/TLS.
ECC 256-bit IoT devices (e.g., smart locks).

Worked Example: RSA Encryption

  1. Key Generation:
    • Choose two primes: p = 61, q = 53.
    • Compute n = p × q = 3233, φ(n) = (p-1)(q-1) = 3120.
    • Pick e = 17 (coprime with φ(n)), compute d = e⁻¹ mod φ(n) = 2753.
    • Public key: (n, e) = (3233, 17); Private key: (n, d) = (3233, 2753).
  2. Encryption: Encrypt M = 65 ("A") as C = Mᵉ mod n = 65¹⁷ mod 3233 = 2063.
  3. Decryption: M = Cᵈ mod n = 2063²⁷⁵³ mod 3233 = 65.

5. Authentication: Verifying Identity

Authentication ensures only authorized users access systems. Methods include:

2010 BS (1953 AD)[object Object]2020 BS (2063 AD)[object Object]2070 BS (2013 AD)[object Object]
Evolution of authentication methods in Nepal’s digital landscape.
024.54973.598Passwords70OTP (SMS)85Biometrics (Fingerprint)92Hardware Tokens98
Security strength of authentication methods (percentage of successful prevention against brute-force attacks).
Method Description Example
Passwords User-provided secret. eSewa login.
Biometrics Physical traits (fingerprint, iris). Pathao driver verification.
Tokens Physical devices (e.g., USB keys) or time-based codes. Bank ATM cards.
Multi-Factor Combines two+ methods (e.g., password + SMS code). Ncell account login.

Example: eSewa’s Authentication

  1. User enters username/password (password).
  2. System sends an SMS OTP (second factor).
  3. Only after both steps is access granted.

6. Real-World Applications

classDiagram class User {
  +String username
  +String password
  +String otp
}

class BankServer {
  +AES-256 key
  +RSA-2048 publicKey
}

class Transaction {
  +String amount
  +String ciphertext
}

User --> BankServer : "Sends password + OTP"
BankServer --> User : "Returns AES-encrypted transaction"
User --> BankServer : "Verifies RSA signature"
BankServer --> Transaction : "Logs ciphertext (3F4G7H8I...)"

class WhatsAppServer {
  +RSA-2048 privateKey
}

WhatsAppServer --> User : "Decrypts with private key"
Updated class diagram showing RSA signature verification and WhatsApp’s role in end-to-end encryption.

## In the real world

  1. eSewa’s Transaction Security

    • Idea: Uses AES-256 encryption for all payment data.
    • How: When you pay ₹500 via eSewa, your card details are encrypted end-to-end. Even if hackers intercept the data, they can’t read it without the decryption key (held by eSewa’s servers).
    • Worked Example: If a hacker steals a packet of your eSewa transaction, they see ciphertext like 3F4G7H8I... instead of your card number 4111 1111 1111 1111.
  2. WhatsApp’s End-to-End Encryption

    • Idea: Uses asymmetric cryptography (RSA + AES).
    • How: When you send a message to a friend, WhatsApp:
      1. Generates a one-time key for that conversation.
      2. Encrypts it with the recipient’s public key.
      3. Sends it securely. Only the recipient’s private key can decrypt it.
    • Worked Example: If a government tries to intercept your chat with a friend, they see gibberish like ∆∆∆∆∆∆∆∆∆∆∆∆ instead of "Meet at 5 PM."
  3. NTC’s Firewall Against DDoS Attacks

    • Idea: Uses stateful packet inspection.
    • How: During the 2022 Nepal elections, NTC’s firewall:
      1. Detected a DDoS attack (thousands of fake requests flooding its servers).
      2. Blocked traffic from suspicious IPs.
      3. Allowed only legitimate users (e.g., voters checking results).
    • Worked Example: Imagine a traffic jam at a Kathmandu bridge. The firewall is like a police officer checking licenses—only letting through authorized vehicles (legitimate users) while stopping the fake ones (malicious traffic).

7. Exam Tip

  • Focus on definitions: Know the difference between confidentiality, integrity, and availability.
  • Compare symmetric vs. asymmetric encryption: Use a table like the one above.
  • Practice RSA/AES examples: Show step-by-step encryption/decryption (even if simplified).
  • Link real-world examples: Always tie concepts to apps you use (e.g., "eSewa uses AES-256").
  • Diagrams are key: Draw firewalls, encryption flows, and authentication steps.
  • Past exam patterns: Expect questions on:
    • Firewall functions (3–5 marks).
    • Cryptographic algorithms (5–7 marks).
    • Authentication methods (3–4 marks).
    • Real-world scenarios (e.g., "How does WhatsApp secure chats?").

Based on the TU BIT syllabus for Introduction to Information Technology (BIT101), unit 7.

Discussion

Loading…