BIT254 Network and Data Communications

Network and Data CommunicationsUnit 108 min read

Network Security & Management: Threats, Protocols, Firewalls, VPNs & Monitoring

Unit 10 of Network and Data Communications covers network security principles (confidentiality, integrity, availability), common threats (DoS, MITM, phishing), security protocols (IPSec, SSL/TLS), firewall types (packet-filtering, stateful, NGFW), VPNs, intrusion detection systems, and network management tools (SNMP, R

Network Security Fundamentals: CIA Triad and Threats

The CIA Triad: Core Security Principles

Network security revolves around three pillars visualized below:

mindmap
  root((CIA Triad))
    Confidentiality
      Definition: Ensuring data is accessible only to authorized users
      Example: Encrypted eSewa transactions
    Integrity
      Definition: Protecting data from unauthorized modification
      Example: Digital signatures in NEPSE stock trades
    Availability
      Definition: Ensuring systems are operational when needed
      Example: Ncell's 99.99% uptime SLA

Key Threats that violate these principles:

Threat Type Description Example Attack Vector
DoS/DDoS Overwhelms systems with traffic Ncell website crash during peak hours
MITM (Man-in-Middle) Intercepts communications Fake WiFi hotspots in Kathmandu hotels
Phishing Tricks users into revealing secrets Fake "Khalti verification" SMS scams
Malware Malicious software Banking trojans stealing Daraz credentials
SQL Injection Exploits database queries Fake login pages stealing Pathao passwords

Security Protocols: How Data Travels Safely

IPSec (Internet Protocol Security)

SenderOriginal PacketIPSec (ESP/AH)Encrypted/Authenticated PacketReceiverDecrypted Packet
IPSec encapsulates packets with ESP (encryption) or AH (authentication) headers before transmission.

Real-world use: WhatsApp uses IPSec-like encryption for end-to-end messages between servers.

SSL/TLS Handshake (Transport Layer Security)

1. ClientHelloClient sendssupported cipher suite2. ServerHello + CertificateServer selectscipher, sends certific3. Key ExchangeClient/Serverexchange keys (RSA/ECD4. Session KeyServer sendssession key5. Encrypted DataSecure communication begins
SSL/TLS Handshake: Step-by-step key negotiation and authentication.

Worked Example: When you log into eSewa:

  1. Your browser sends TLS 1.3 handshake
  2. eSewa's server presents its certificate from GlobalSign
  3. Your device verifies the certificate chain
  4. Symmetric keys are established for session encryption

Firewalls: The Network's First Line of Defense

InternetFirewallInternal Network
Firewall placement: Blocks unauthorized traffic between untrusted and trusted zones.

Firewall Types Comparison

Type Operation Level Example Rule Pros Cons
Packet Filtering Network layer Block port 22 (SSH) from external IPs Fast, low overhead No state tracking
Stateful Transport layer Track TCP connection states Better security than PF Higher resource usage
NGFW (Next-Gen) Application layer Deep packet inspection for malware Blocks advanced threats Complex configuration

Real-world deployment:

  • Ncell uses stateful firewalls to protect its core network
  • Banks implement NGFWs to detect SQL injection attempts in online transactions

Virtual Private Networks (VPNs)

How VPNs Work

[object Object][object Object][object Object][object Object]DeviceVPN ServerCorporate NetworkPublic WiFi
VPN vs. Public WiFi: Encrypted tunnel protects data in transit.

VPN Protocols Comparison:

Protocol Port Encryption Use Case
PPTP 1723 Weak (MPPE) Legacy systems
L2TP/IPsec 1701 Strong Enterprise networks
OpenVPN 1194 AES-256 High-security needs
WireGuard 51820 ChaCha20 Modern lightweight VPNs

Real-world example: When Daraz employees access internal systems from home, they use OpenVPN with AES-256 encryption to prevent MITM attacks on their WiFi connections.

Intrusion Detection Systems (IDS)

IDS vs IPS

classDiagram
    class IDS {
        +Detects anomalies
        +Passive monitoring
        +Generates alerts
    }
    class IPS {
        +Detects AND prevents
        +Active intervention
        +Inline inspection
    }
    IDS <|-- IPS : "Extends"

Signature-based vs Anomaly-based Detection:

Type How It Works Example Detection
Signature-based Matches known attack patterns Detects EternalBlue exploit
Anomaly-based Learns normal behavior Flags sudden spike in database queries

Real-world deployment: NTC uses hybrid IDS/IPS systems to detect:

  • Unusual routing table changes (potential BGP hijacking)
  • Port scans targeting their DNS servers

Network Management: Keeping Systems Healthy

SNMP (Simple Network Management Protocol)

[object Object][object Object][object Object][object Object]ManagerAgentDevice
SNMP Polling: Manager queries device metrics via Agent.

SNMP Commands:

  • GET: Retrieve device information
  • SET: Configure device parameters
  • TRAP: Send unsolicited alerts

Real-world use: Ncell uses SNMP to:

  1. Monitor 4G tower temperatures
  2. Track bandwidth usage per cell
  3. Receive immediate alerts when a tower goes offline

RMON (Remote Monitoring)

RMON Groups:

  1. Statistics (packets/errors)
  2. History (trends over time)
  3. Alarms (threshold breaches)
  4. Events (specific conditions)
[object Object][object Object]RMON ProbeNetwork DevicesManagement Station
RMON Architecture: Probe collects data from distributed devices.

Worked Example: At a university network:

  • RMON detects a sudden spike in broadcast traffic
  • SNMP identifies the faulty switch port
  • NMS (Network Management System) automatically logs the incident

Security Management Frameworks

ISO 27001 Implementation Steps

Real-world application: Banks in Nepal implement ISO 27001 for:

  • Secure online transaction processing
  • Employee access controls
  • Regular security audits

Exam Tip: How to Score Full Marks

  1. Diagrams are worth 20% of marks: Always draw:

    • Firewall architectures
    • VPN tunnel diagrams
    • Protocol handshakes (3-way handshake, TLS)
    • Attack vectors (MITM, DoS)
  2. Real-world mapping: For every concept, mention:

    • How eSewa/Khalti uses it (encryption, authentication)
    • How Ncell protects its network (firewalls, IDS)
    • How Daraz handles DDoS attacks (rate limiting)
  3. Comparison tables: The exam loves:

    • Firewall types (packet-filtering vs stateful)
    • VPN protocols (PPTP vs OpenVPN)
    • IDS vs IPS capabilities
  4. Numerical problems: Practice calculating:

    • Throughput degradation from attacks (e.g., 50% packet loss from DoS)
    • Encryption overhead (e.g., 10% increase in packet size with AES-256)
    • False positive rates for IDS systems
  5. Short notes format: For 5-mark questions:

    • Definition (1 mark)
    • Working principle (2 marks)
    • Real-world example (1 mark)
    • Advantage/disadvantage (1 mark)

Key Formulae to Memorize:

  1. Throughput with attacks: (for ALOHA networks)
    • Where = throughput, = offered load, = frame collision probability
  2. Encryption overhead:
  3. False positive rate:

Based on the TU BIT syllabus for Network and Data Communications (BIT254), unit 10.

Discussion

Loading…