Information SecurityUnit 18 min read
INFOSEC Basics: Threats, Attacks, Risks, Controls & Authentication
Unit 1 of Information Security introduces core concepts like threats vs. attacks, risk assessment frameworks, authentication methods (biometric/password), security controls (preventive/detective), and real-world applications in Nepalese systems (eSewa, Ncell). Includes definitions, classifications, and a worked example
Core Concepts: Definitions and Classifications
1.1 Information Security: The CIA Triad
Information security protects data against unauthorized access, disclosure, modification, or destruction. The CIA Triad defines its three pillars:
- Confidentiality: Ensures data is accessible only to authorized users (e.g., bank account details).
- Integrity: Guarantees data accuracy and consistency (e.g., unaltered transaction records).
- Availability: Ensures systems/data are accessible when needed (e.g., NTC’s network uptime).
1.2 Threats vs. Attacks
| Term | Definition | Example |
|---|---|---|
| Threat | Potential danger to assets (e.g., malware, natural disasters). | A hacker exploiting a vulnerability in eSewa’s payment gateway. |
| Attack | Deliberate exploitation of a threat (e.g., DDoS, phishing). | A Pathao driver’s app being hacked to steal customer locations. |
| Vulnerability | Weakness in a system (e.g., unpatched software, weak passwords). | Ncell’s old SIM cards with predictable PINs. |
| Exploit | Method to trigger a vulnerability (e.g., SQL injection, buffer overflow). | Hackers using Daraz’s checkout page to inject malicious code. |
Worked Example: A threat to NEPSE’s trading platform is "insider trading" (threat = malicious insider). An attack would be an employee leaking stock prices to a broker (exploiting trust).
1.3 Risk Assessment: Identify, Analyze, Treat
Risk assessment follows 4 steps:
flowchart TD
A["Identify Assets"] --> B["Identify Threats/Vulnerabilities"]
B --> C["Assess Likelihood & Impact"]
C --> D["Treat Risks: Mitigate/Accept/Transfer/Avoid"]Risk Treatment Strategies
| Strategy | Definition | Example in Nepal |
|---|---|---|
| Mitigate | Reduce risk (e.g., firewalls, encryption). | Khalti uses 2FA to reduce fraud risk. |
| Accept | Acknowledge risk if cost > benefit. | A small shop not encrypting Wi-Fi (low-value data). |
| Transfer | Shift risk to a third party (e.g., insurance). | Banks buying cyber insurance for ATM fraud. |
| Avoid | Eliminate the risk entirely. | NTC avoiding cloud storage for sensitive customer data. |
Worked Example: A bank offering loans assesses risk as follows:
- Asset: Loan database.
- Threat: SQL injection attack.
- Likelihood: High (common exploit).
- Impact: Critical (data breach).
- Treatment: Mitigate (encrypt databases, use WAFs) + Transfer (cyber insurance).
1.4 Authentication: Verifying Identity
Authentication proves a user’s identity. Methods include:
Biometric Authentication
Biometrics use unique physical traits:
- Fingerprint: Used in NID card verification.
- Facial Recognition: eSewa app for OTP-less logins.
- Iris Scan: High-security systems (e.g., military bases).
How Biometrics Work:
- Enrollment: Scan trait → store template (not raw data).
- Verification: Compare live scan to template.
- Decision: Match → grant access.
Advantages: ✔ Hard to steal (unlike passwords). ✔ Non-repudiation (can’t deny identity).
Disadvantages: ✖ False positives/negatives (e.g., twins’ fingerprints). ✖ Privacy concerns (e.g., Ncell’s iris data leaks).
1.5 Security Controls: Preventive, Detective, Corrective
Controls are categorized by function:
| Type | Examples | Nepalese Use Case |
|---|---|---|
| Preventive | Firewalls, encryption, access controls. | Nepal Rastra Bank’s encrypted interbank transactions. |
| Detective | Intrusion detection, logs, audits. | NTC’s network monitoring for DDoS attacks. |
| Corrective | Backups, patch management, incident response. | Daraz’s rollback system after a failed update. |
Worked Example: A Khalti transaction fails due to a DDoS attack.
- Preventive: Rate-limiting API calls.
- Detective: Alerting security team via SIEM tools.
- Corrective: Restoring service from cloud backups.
In the Real World
eSewa’s Authentication:
- Uses multi-factor authentication (MFA): Password + OTP + Biometric (fingerprint).
- Why? Prevents unauthorized access even if passwords are leaked.
Ncell’s SIM Security:
- Risk: Vulnerable SIM cards (e.g., Simjacker attacks).
- Control: Encrypted SIM toolkit and biometric SIM unlocking (in newer phones).
Daraz’s Order Fulfillment:
- Threat: Order data theft during transit.
- Control: End-to-end encryption for customer orders + detective logs to trace breaches.
Exam Tip
Definitions Matter:
- Memorize threat vs. attack (threat = potential; attack = execution).
- Example answer for "Define authentication":
"Authentication is the process of verifying a user’s claimed identity using credentials (passwords, biometrics, tokens) to grant or deny access to resources."
Risk Assessment Questions:
- Always structure answers as Identify → Analyze → Treat.
- Example for "Risk treatment methods":
"For a bank’s online loan system, risks like phishing (high likelihood, high impact) are mitigated via MFA, while low-risk threats (e.g., hardware failure) may be accepted due to cost constraints."
Biometrics:
- Explain how (enrollment vs. verification) and trade-offs (convenience vs. privacy).
- Link to Nepalese examples (e.g., NID card, eSewa).
CIA Triad:
- Relate to real systems:
- Confidentiality: Nepal Rastra Bank’s encrypted ledgers.
- Integrity: NEPSE’s tamper-proof trade records.
- Availability: NTC’s redundant fiber networks.
- Relate to real systems:
Past Exam Patterns:
- Short answers: Define terms (e.g., "security threat").
- Long answers: Compare concepts (e.g., "threats vs. attacks") or apply to scenarios (e.g., "risk treatment for a bank").
Key Formula to Remember: Risk = Likelihood × Impact (Used in risk assessment questions.)
Based on the TU BIT syllabus for Information Security (BIT303), unit 1.
Discussion
Loading…