BIT303 Information Security

Information SecurityUnit 18 min read

INFOSEC Basics: Threats, Attacks, Risks, Controls & Authentication

Unit 1 of Information Security introduces core concepts like threats vs. attacks, risk assessment frameworks, authentication methods (biometric/password), security controls (preventive/detective), and real-world applications in Nepalese systems (eSewa, Ncell). Includes definitions, classifications, and a worked example

Core Concepts: Definitions and Classifications

1.1 Information Security: The CIA Triad

Information security protects data against unauthorized access, disclosure, modification, or destruction. The CIA Triad defines its three pillars:

Confidentiality (33%)Integrity (33%)Availability (33%)
CIA Triad proportions (equal emphasis on all three pillars)
  • Confidentiality: Ensures data is accessible only to authorized users (e.g., bank account details).
  • Integrity: Guarantees data accuracy and consistency (e.g., unaltered transaction records).
  • Availability: Ensures systems/data are accessible when needed (e.g., NTC’s network uptime).

1.2 Threats vs. Attacks

Term Definition Example
Threat Potential danger to assets (e.g., malware, natural disasters). A hacker exploiting a vulnerability in eSewa’s payment gateway.
Attack Deliberate exploitation of a threat (e.g., DDoS, phishing). A Pathao driver’s app being hacked to steal customer locations.
Vulnerability Weakness in a system (e.g., unpatched software, weak passwords). Ncell’s old SIM cards with predictable PINs.
Exploit Method to trigger a vulnerability (e.g., SQL injection, buffer overflow). Hackers using Daraz’s checkout page to inject malicious code.
ExploitsWeaknessesConsequencesThreatsVulnerabilitiesAttacksImpacts
Relationship between threats, vulnerabilities, attacks, and impacts

Worked Example: A threat to NEPSE’s trading platform is "insider trading" (threat = malicious insider). An attack would be an employee leaking stock prices to a broker (exploiting trust).


1.3 Risk Assessment: Identify, Analyze, Treat

Risk assessment follows 4 steps:

flowchart TD
    A["Identify Assets"] --> B["Identify Threats/Vulnerabilities"]
    B --> C["Assess Likelihood & Impact"]
    C --> D["Treat Risks: Mitigate/Accept/Transfer/Avoid"]

Risk Treatment Strategies

Strategy Definition Example in Nepal
Mitigate Reduce risk (e.g., firewalls, encryption). Khalti uses 2FA to reduce fraud risk.
Accept Acknowledge risk if cost > benefit. A small shop not encrypting Wi-Fi (low-value data).
Transfer Shift risk to a third party (e.g., insurance). Banks buying cyber insurance for ATM fraud.
Avoid Eliminate the risk entirely. NTC avoiding cloud storage for sensitive customer data.

Worked Example: A bank offering loans assesses risk as follows:

  1. Asset: Loan database.
  2. Threat: SQL injection attack.
  3. Likelihood: High (common exploit).
  4. Impact: Critical (data breach).
  5. Treatment: Mitigate (encrypt databases, use WAFs) + Transfer (cyber insurance).

1.4 Authentication: Verifying Identity

Authentication proves a user’s identity. Methods include:

Weak (e.g., '1234')Strong (e.g., 'P@ssw0rd!')PasswordsFingerprintFacial RecognitionBiometricsHardware (e.g., YubiKey)Software (e.g., TOTP)Tokens2FA (e.g., SMS + Password)3FA (e.g., Biometric + Token + Password)Multi-FactorAuthentication Methods
Authentication methods with common examples

Biometric Authentication

Biometrics use unique physical traits:

  • Fingerprint: Used in NID card verification.
  • Facial Recognition: eSewa app for OTP-less logins.
  • Iris Scan: High-security systems (e.g., military bases).

How Biometrics Work:

  1. Enrollment: Scan trait → store template (not raw data).
  2. Verification: Compare live scan to template.
  3. Decision: Match → grant access.

Advantages: ✔ Hard to steal (unlike passwords). ✔ Non-repudiation (can’t deny identity).

Disadvantages: ✖ False positives/negatives (e.g., twins’ fingerprints). ✖ Privacy concerns (e.g., Ncell’s iris data leaks).


1.5 Security Controls: Preventive, Detective, Corrective

Controls are categorized by function:

Access Controls (e.g., Firewalls)Encryption (e.g., AES)PreventiveIntrusion Detection Systems (IDS)Auditing (e.g., Logs)DetectivePatch ManagementIncident ResponseCorrectiveSecurity Controls
Classification of security controls with examples
Type Examples Nepalese Use Case
Preventive Firewalls, encryption, access controls. Nepal Rastra Bank’s encrypted interbank transactions.
Detective Intrusion detection, logs, audits. NTC’s network monitoring for DDoS attacks.
Corrective Backups, patch management, incident response. Daraz’s rollback system after a failed update.

Worked Example: A Khalti transaction fails due to a DDoS attack.

  • Preventive: Rate-limiting API calls.
  • Detective: Alerting security team via SIEM tools.
  • Corrective: Restoring service from cloud backups.

In the Real World

  1. eSewa’s Authentication:

    • Uses multi-factor authentication (MFA): Password + OTP + Biometric (fingerprint).
    • Why? Prevents unauthorized access even if passwords are leaked.
  2. Ncell’s SIM Security:

    • Risk: Vulnerable SIM cards (e.g., Simjacker attacks).
    • Control: Encrypted SIM toolkit and biometric SIM unlocking (in newer phones).
  3. Daraz’s Order Fulfillment:

    • Threat: Order data theft during transit.
    • Control: End-to-end encryption for customer orders + detective logs to trace breaches.

Exam Tip

  1. Definitions Matter:

    • Memorize threat vs. attack (threat = potential; attack = execution).
    • Example answer for "Define authentication":

      "Authentication is the process of verifying a user’s claimed identity using credentials (passwords, biometrics, tokens) to grant or deny access to resources."

  2. Risk Assessment Questions:

    • Always structure answers as Identify → Analyze → Treat.
    • Example for "Risk treatment methods":

      "For a bank’s online loan system, risks like phishing (high likelihood, high impact) are mitigated via MFA, while low-risk threats (e.g., hardware failure) may be accepted due to cost constraints."

  3. Biometrics:

    • Explain how (enrollment vs. verification) and trade-offs (convenience vs. privacy).
    • Link to Nepalese examples (e.g., NID card, eSewa).
  4. CIA Triad:

    • Relate to real systems:
      • Confidentiality: Nepal Rastra Bank’s encrypted ledgers.
      • Integrity: NEPSE’s tamper-proof trade records.
      • Availability: NTC’s redundant fiber networks.
  5. Past Exam Patterns:

    • Short answers: Define terms (e.g., "security threat").
    • Long answers: Compare concepts (e.g., "threats vs. attacks") or apply to scenarios (e.g., "risk treatment for a bank").

Key Formula to Remember: Risk = Likelihood × Impact (Used in risk assessment questions.)

Based on the TU BIT syllabus for Information Security (BIT303), unit 1.

Discussion

Loading…