Network SecurityUnit 111 min read
Network Security Basics: Threats, Models & Defense Layers
Unit 1 of Network Security introduces foundational concepts of computer network security, covering threats, security models (confidentiality, integrity, availability), OSI security layers, and basic defense mechanisms like firewalls and encryption.
TAKEAWAYS:
- Understand the CIA triad (Confidentiality, Integrity, Availability) as the core security goals in networks.
- Learn how threats (passive/active, insider/outsider) exploit vulnerabilities in networks.
- Recognize the OSI model’s security layers and where attacks/defenses apply.
- Compare firewalls, encryption, and authentication as primary defense mechanisms.
- Apply security principles to real-world scenarios like eSewa transactions or Ncell data protection.
- Know how security policies (e.g., password policies, access controls) mitigate risks.
1. Introduction to Network Security
Network security protects data and resources from unauthorized access, misuse, or attacks. Unlike physical security (e.g., locks on doors), network security relies on software, protocols, and policies to safeguard digital assets.
Why is Network Security Critical?
- Data breaches (e.g., stolen customer records in banks or eSewa).
- Financial fraud (e.g., unauthorized transactions via hacked accounts).
- Operational disruptions (e.g., DDoS attacks on NTC or NEPSE websites).
- Reputation damage (e.g., Pathao or Daraz losing user trust after a leak).
2. Security Goals: The CIA Triad
The Confidentiality, Integrity, Availability (CIA) triad defines the three pillars of network security.
| Goal | Definition | Example in Nepal | How Achieved |
|---|---|---|---|
| Confidentiality | Ensures data is accessible only to authorized users. | eSewa hiding your transaction PIN from hackers. | Encryption (AES), access controls, VPNs. |
| Integrity | Ensures data is accurate and unaltered. | Ncell ensuring your call logs aren’t tampered with. | Hashing (SHA-256), digital signatures, checksums. |
| Availability | Ensures systems and data are accessible when needed. | Daraz’s website staying up during sales. | Redundancy, DDoS protection, load balancing. |
Worked Example: eSewa Transaction When you pay a bill via eSewa:
- Your PIN (confidentiality) is encrypted before transmission.
- The transaction amount (integrity) is verified using a hash.
- The server (availability) must remain online for the payment to process.
3. Security Threats and Attacks
Threats can be passive (eavesdropping) or active (modifying data), and perpetrated by insiders (employees) or outsiders (hackers).
Classification of Threats
classDiagram
class Threat {
-Type: Passive/Active
-Source: Insider/Outsider
}
class Passive {
+Eavesdropping
+Traffic Analysis
}
class Active {
+Masquerading
+Replay Attacks
+Denial of Service (DoS)
}
class Insider {
+Malicious Employees
+Negligent Users
}
class Outsider {
+Hackers
+Organized Crime
}
Threat <|-- Passive
Threat <|-- Active
Threat <|-- Insider
Threat <|-- OutsiderReal-World Example: Ncell SIM Swapping Attack
- Threat Type: Active (outsider)
- How it works:
- Hacker tricks Ncell support to transfer your number to their SIM.
- They bypass 2FA (authentication) by intercepting OTPs.
- They drain your bank account linked to the number.
- Prevention: Use hardware tokens (e.g., YubiKey) instead of SMS OTPs.
4. Security Models and OSI Layer Attacks
Security must be applied at different layers of the OSI model. Each layer has unique vulnerabilities.
OSI Model with Security Layers
Where Attacks Happen:
| Layer | Common Attacks | Defense Mechanism |
|---|---|---|
| Application | SQL Injection, XSS | Input validation, WAF (Web App Firewall) |
| Transport | Man-in-the-Middle (MITM), Port Scanning | TLS/SSL, Firewalls |
| Network | IP Spoofing, DDoS | Firewalls, Intrusion Detection Systems (IDS) |
| Data Link | ARP Poisoning, MAC Flooding | MAC filtering, VLAN segmentation |
| Physical | Eavesdropping (Wi-Fi sniffing) | Encrypted Wi-Fi (WPA3), Airgap |
Worked Example: Daraz Order Queue (Network Layer Attack)
- Attack: A hacker floods Daraz’s servers with fake orders (DDoS) to crash the site during Black Friday.
- Defense:
- Firewall drops malicious traffic.
- Load balancers distribute traffic across servers.
- CDN (Cloudflare) absorbs excess traffic.
5. Defense Mechanisms
A. Firewalls
Firewalls filter traffic based on rules (e.g., block port 22 for SSH unless from a trusted IP).
How a Firewall Works (Packet Filtering)
sequenceDiagram
participant Client
participant Firewall
participant Server
Client->>Firewall: Request (e.g., HTTP to port 80)
Firewall->>Firewall: Check rules (Is port 80 allowed?)
Firewall-->>Server: Forward if allowed
Server-->>Firewall: Response
Firewall-->>Client: Deliver responseTypes of Firewalls:
| Type | How It Works | Example Use Case |
|---|---|---|
| Packet Filter | Checks headers (source IP, port). | Basic home router firewall. |
| Stateful | Tracks connections (e.g., TCP handshake). | Corporate networks (e.g., Ncell HQ). |
| Application | Inspects payload (e.g., SQL in HTTP). | Web applications (e.g., Daraz checkout). |
B. Encryption
Encryption scrambles data so only authorized parties can read it.
Symmetric vs. Asymmetric Encryption
| Type | Key Type | Speed | Use Case |
|---|---|---|---|
| Symmetric | Single key (AES) | Fast | Encrypting large data (e.g., files). |
| Asymmetric | Public/Private (RSA) | Slow | Secure key exchange (e.g., HTTPS). |
Worked Example: Khalti Payment Encryption
- Your card details are encrypted with AES before leaving your phone.
- Khalti’s server uses RSA to securely exchange the decryption key.
- The bank verifies the transaction using a digital signature.
C. Authentication
Ensures only authorized users access resources.
Methods:
- Something you know: Password, PIN (e.g., eSewa login).
- Something you have: OTP, Smart card (e.g., Ncell SIM).
- Something you are: Biometrics (fingerprint, face ID).
Multi-Factor Authentication (MFA) Example (NEPSE Trading)
- Password (something you know).
- OTP from Ncell (something you have).
- Fingerprint scan (something you are).
6. Security Policies and Best Practices
A. Password Policies
- Weak:
123456(easy to guess). - Strong:
Tr0ub4dour&2024!(12+ chars, mixed case, symbols). - Best Practice: Enforce password rotation (e.g., every 90 days).
B. Access Control
- Principle of Least Privilege: Give users only the access they need.
- Example: A Daraz customer service agent should not access financial records.
- Role-Based Access Control (RBAC):
- Admin: Full access.
- Editor: Can update content but not delete.
- Viewer: Read-only.
C. Physical Security
- Server Rooms: Biometric locks, CCTV.
- Cables: Shielded Ethernet (prevents eavesdropping).
- Wi-Fi: Use WPA3 (not WEP) to encrypt traffic.
7. Real-World Applications
A. eSewa: Securing Digital Payments
- Confidentiality: AES-256 encrypts transaction data.
- Integrity: SHA-256 hashes ensure no tampering.
- Availability: Cloud redundancy prevents downtime.
B. Ncell: Protecting Mobile Data
- Authentication: SIM cards + PIN prevent unauthorized access.
- Encryption: 4G/LTE uses AES for voice/data calls.
- DDoS Protection: Cloudflare shields Ncell’s DNS servers.
C. Daraz: E-Commerce Security
- Firewalls: Block SQL injection attacks on checkout.
- SSL/TLS: Encrypts credit card details in transit.
- MFA: Requires OTP for high-value orders.
8. Common Vulnerabilities and Mitigations
| Vulnerability | Example Attack | Mitigation |
|---|---|---|
| Weak Passwords | Brute-force attack on eSewa. | Enforce strong passwords + MFA. |
| Unpatched Software | Exploiting old Windows OS. | Regular updates (e.g., Ncell’s core network). |
| Phishing | Fake NEPSE login page. | User training + email filters. |
| DDoS | Overloading NTC’s website. | Cloudflare, rate limiting. |
| Man-in-the-Middle | Intercepting Khalti transactions. | Use HTTPS (TLS) everywhere. |
Exam Tip
- Memorize the CIA Triad – Always relate answers to confidentiality, integrity, or availability.
- OSI Layers + Attacks – Know which layer each attack (e.g., ARP poisoning = Layer 2) and defense (e.g., TLS = Layer 4) belongs to.
- Real-World Scenarios – Expect questions like:
- "How does eSewa ensure confidentiality?" → Encryption (AES).
- "What firewall type would you use for Ncell’s HQ?" → Stateful firewall.
- Diagrams – Be ready to draw:
- OSI model with security layers.
- Firewall packet filtering sequence.
- CIA triad table.
- Short vs. Long Answers:
- Short (2 marks): Define "firewall" or "encryption."
- Long (5+ marks): Explain how Daraz secures payments (cover encryption, MFA, firewalls).
Final Checklist Before Exam: ✅ Can you list 3 passive and 3 active threats? ✅ Do you know where each defense (firewall, encryption, MFA) fits in the OSI model? ✅ Can you explain a real-world example (eSewa, Ncell, Daraz) using CIA triad? ✅ Are you comfortable drawing a firewall sequence diagram?
Based on the TU BIT syllabus for Network Security, unit 1.
Discussion
Loading…