Network and Data CommunicationsUnit 108 min read
Network Security & Management: Threats, Protocols, Firewalls, VPNs & Monitoring
Unit 10 of Network and Data Communications covers network security principles (confidentiality, integrity, availability), common threats (DoS, MITM, phishing), security protocols (IPSec, SSL/TLS), firewall types (packet-filtering, stateful, NGFW), VPNs, intrusion detection systems, and network management tools (SNMP, R
Network Security Fundamentals: CIA Triad and Threats
The CIA Triad: Core Security Principles
Network security revolves around three pillars visualized below:
mindmap
root((CIA Triad))
Confidentiality
Definition: Ensuring data is accessible only to authorized users
Example: Encrypted eSewa transactions
Integrity
Definition: Protecting data from unauthorized modification
Example: Digital signatures in NEPSE stock trades
Availability
Definition: Ensuring systems are operational when needed
Example: Ncell's 99.99% uptime SLAKey Threats that violate these principles:
| Threat Type | Description | Example Attack Vector |
|---|---|---|
| DoS/DDoS | Overwhelms systems with traffic | Ncell website crash during peak hours |
| MITM (Man-in-Middle) | Intercepts communications | Fake WiFi hotspots in Kathmandu hotels |
| Phishing | Tricks users into revealing secrets | Fake "Khalti verification" SMS scams |
| Malware | Malicious software | Banking trojans stealing Daraz credentials |
| SQL Injection | Exploits database queries | Fake login pages stealing Pathao passwords |
Security Protocols: How Data Travels Safely
IPSec (Internet Protocol Security)
Real-world use: WhatsApp uses IPSec-like encryption for end-to-end messages between servers.
SSL/TLS Handshake (Transport Layer Security)
Worked Example: When you log into eSewa:
- Your browser sends TLS 1.3 handshake
- eSewa's server presents its certificate from GlobalSign
- Your device verifies the certificate chain
- Symmetric keys are established for session encryption
Firewalls: The Network's First Line of Defense
Firewall Types Comparison
| Type | Operation Level | Example Rule | Pros | Cons |
|---|---|---|---|---|
| Packet Filtering | Network layer | Block port 22 (SSH) from external IPs | Fast, low overhead | No state tracking |
| Stateful | Transport layer | Track TCP connection states | Better security than PF | Higher resource usage |
| NGFW (Next-Gen) | Application layer | Deep packet inspection for malware | Blocks advanced threats | Complex configuration |
Real-world deployment:
- Ncell uses stateful firewalls to protect its core network
- Banks implement NGFWs to detect SQL injection attempts in online transactions
Virtual Private Networks (VPNs)
How VPNs Work
VPN Protocols Comparison:
| Protocol | Port | Encryption | Use Case |
|---|---|---|---|
| PPTP | 1723 | Weak (MPPE) | Legacy systems |
| L2TP/IPsec | 1701 | Strong | Enterprise networks |
| OpenVPN | 1194 | AES-256 | High-security needs |
| WireGuard | 51820 | ChaCha20 | Modern lightweight VPNs |
Real-world example: When Daraz employees access internal systems from home, they use OpenVPN with AES-256 encryption to prevent MITM attacks on their WiFi connections.
Intrusion Detection Systems (IDS)
IDS vs IPS
classDiagram
class IDS {
+Detects anomalies
+Passive monitoring
+Generates alerts
}
class IPS {
+Detects AND prevents
+Active intervention
+Inline inspection
}
IDS <|-- IPS : "Extends"Signature-based vs Anomaly-based Detection:
| Type | How It Works | Example Detection |
|---|---|---|
| Signature-based | Matches known attack patterns | Detects EternalBlue exploit |
| Anomaly-based | Learns normal behavior | Flags sudden spike in database queries |
Real-world deployment: NTC uses hybrid IDS/IPS systems to detect:
- Unusual routing table changes (potential BGP hijacking)
- Port scans targeting their DNS servers
Network Management: Keeping Systems Healthy
SNMP (Simple Network Management Protocol)
SNMP Commands:
GET: Retrieve device informationSET: Configure device parametersTRAP: Send unsolicited alerts
Real-world use: Ncell uses SNMP to:
- Monitor 4G tower temperatures
- Track bandwidth usage per cell
- Receive immediate alerts when a tower goes offline
RMON (Remote Monitoring)
RMON Groups:
- Statistics (packets/errors)
- History (trends over time)
- Alarms (threshold breaches)
- Events (specific conditions)
Worked Example: At a university network:
- RMON detects a sudden spike in broadcast traffic
- SNMP identifies the faulty switch port
- NMS (Network Management System) automatically logs the incident
Security Management Frameworks
ISO 27001 Implementation Steps
Real-world application: Banks in Nepal implement ISO 27001 for:
- Secure online transaction processing
- Employee access controls
- Regular security audits
Exam Tip: How to Score Full Marks
Diagrams are worth 20% of marks: Always draw:
- Firewall architectures
- VPN tunnel diagrams
- Protocol handshakes (3-way handshake, TLS)
- Attack vectors (MITM, DoS)
Real-world mapping: For every concept, mention:
- How eSewa/Khalti uses it (encryption, authentication)
- How Ncell protects its network (firewalls, IDS)
- How Daraz handles DDoS attacks (rate limiting)
Comparison tables: The exam loves:
- Firewall types (packet-filtering vs stateful)
- VPN protocols (PPTP vs OpenVPN)
- IDS vs IPS capabilities
Numerical problems: Practice calculating:
- Throughput degradation from attacks (e.g., 50% packet loss from DoS)
- Encryption overhead (e.g., 10% increase in packet size with AES-256)
- False positive rates for IDS systems
Short notes format: For 5-mark questions:
- Definition (1 mark)
- Working principle (2 marks)
- Real-world example (1 mark)
- Advantage/disadvantage (1 mark)
Key Formulae to Memorize:
- Throughput with attacks: (for ALOHA networks)
- Where = throughput, = offered load, = frame collision probability
- Encryption overhead:
- False positive rate:
Based on the TU BIT syllabus for Network and Data Communications (BIT254), unit 10.
Discussion
Loading…