Network SecurityUnit 67 min read
IP Security: Protocols, Attacks, and Protection Mechanisms
Unit 6 of Network Security explores IPsec (AH, ESP), IKE, VPNs, and attacks like spoofing, replay, and DoS, with real-world examples from eSewa, Ncell, and global networks. Learn how encryption, authentication, and key exchange secure IP traffic.
Core Concepts of IP Security
IP Security (IPsec) is a suite of protocols designed to secure IPv4 and IPv6 communications by authenticating and encrypting packets at the network layer (Layer 3). Unlike TLS (Transport Layer Security), which operates at Layer 4 (Transport), IPsec secures all IP traffic, making it ideal for VPNs, remote access, and sensitive data transfers.
Why IPsec?
- Transparency: Works at the network layer, so any application (email, VoIP, file transfer) benefits without modification.
- Performance: Encryption/decryption happens once per session, not per packet (unlike TLS).
- Flexibility: Supports site-to-site VPNs (e.g., Ncell’s corporate network) and remote access VPNs (e.g., eSewa’s secure login).
1. IPsec Architecture: AH, ESP, and IKE
IPsec consists of three main protocols:
- Authentication Header (AH): Ensures data integrity and authentication but does not encrypt data.
- Encapsulating Security Payload (ESP): Provides confidentiality (encryption), integrity, and authentication.
- Internet Key Exchange (IKE): A protocol to negotiate and establish shared secrets (keys) for AH/ESP.
How AH and ESP Work
| Feature | AH | ESP |
|---|---|---|
| Purpose | Integrity + Authentication | Confidentiality + Integrity + Auth |
| Encryption | ❌ No | ✅ Yes (AES, 3DES, etc.) |
| Header | Adds 96-bit integrity check | Adds pseudo-header + payload |
| Use Case | Sensitive but unencrypted data | High-security data (banks, VPNs) |
IPsec Modes
IPsec operates in two modes:
- Transport Mode: Encrypts only the payload (used for end-to-end security, e.g., eSewa’s login traffic).
- Tunnel Mode: Encrypts the entire IP packet (used for VPNs, e.g., Ncell’s remote office connections).
flowchart TD
A["IPsec Modes"] --> B["Transport Mode\n(End-to-End)"]
A --> C["Tunnel Mode\n(VPN/Gateway)"]
B --> D["Encrypts payload only\n(e.g., HTTP, DNS)"]
C --> E["Encrypts entire packet\n(e.g., VPN between routers)"]2. Internet Key Exchange (IKE)
IKE is a hybrid protocol combining:
- Oakley (key exchange)
- ISAKMP (key management)
- SKIP (session management)
IKE Phases
Phase 1 (IKE SA Establishment)
- Negotiates a secure channel using Diffie-Hellman (DH) for key exchange.
- Supports authentication (pre-shared keys, digital certificates, or RSA).
- Creates an IKE Security Association (SA).
Phase 2 (IPsec SA Establishment)
- Uses the IKE SA to negotiate AH/ESP SAs for actual data transfer.
- Supports perfect forward secrecy (PFS) (new keys per session).
sequenceDiagram
participant Initiator as IKE Initiator
participant Responder as IKE Responder
Initiator->>Responder: Phase 1: DH + Auth (Pre-shared Key)
Responder->>Initiator: Respond with DH params
Initiator->>Responder: Phase 2: AH/ESP SA Negotiation
Responder->>Initiator: Confirm SA
Initiator->>Responder: Encrypted Data (ESP)3. IPsec Attacks and Countermeasures
| Attack | Description | Countermeasure |
|---|---|---|
| IP Spoofing | Fake source IP to bypass filters | AH/ESP authentication |
| Replay Attack | Repeats valid packets to replay data | Sequence numbers + timestamps |
| Denial-of-Service (DoS) | Floods network with fake IPsec traffic | Rate limiting + strong IKE keys |
| Man-in-the-Middle (MITM) | Intercepts unencrypted IKE phase 1 | Digital certificates (X.509) |
Real-World Example: Ncell’s VPN Security
Ncell uses IPsec in tunnel mode to secure:
- Remote office connections (AH for integrity, ESP for encryption).
- IKEv2 for mobile users (faster than IKEv1).
- PFS to prevent key compromise if one session is hacked.
In the Real World
eSewa’s Secure Transactions
- Uses IPsec ESP in tunnel mode between eSewa’s servers and banks (e.g., NMB, Global IME) to encrypt all financial data in transit.
- IKEv2 ensures fast, secure key exchange for mobile payments.
Ncell’s Corporate VPN
- Employees connect to Ncell’s HQ via IPsec VPN (ESP + AES-256).
- AH ensures no one tampers with routing updates between offices.
Nepal Stock Exchange (NEPSE) Data Security
- NEPSE’s trading servers use IPsec AH to verify integrity of stock price updates and ESP to encrypt sensitive trades.
4. Virtual Private Networks (VPNs) and IPsec
VPNs use IPsec to create secure tunnels over untrusted networks (e.g., the internet).
- Site-to-Site VPN: Connects two offices (e.g., Daraz’s warehouse to HQ).
- Remote Access VPN: Allows employees to connect securely (e.g., Pathao drivers accessing dispatch systems).
graph TD
A["User\n(Home)"]
B["ISP\n(Untrusted)"]
C["VPN Gateway\n(IPsec Tunnel)"]
D["Corporate Network\n(Secure)"]
A -->|"IPsec Tunnel"| B
B -->|"ESP Encrypted"| C
C -->|"Decrypted"| D5. IPsec vs. TLS/SSL
| Feature | IPsec | TLS/SSL |
|---|---|---|
| Layer | Network (Layer 3) | Transport (Layer 4) |
| Scope | All IP traffic | Application-specific (HTTP, SMTP) |
| Performance | Faster (single encryption) | Slower (per-session handshake) |
| Use Case | VPNs, ISP networks | Web browsing, email (SMTPS) |
When to Use Which?
- Use IPsec for entire network security (e.g., NTC’s backbone).
- Use TLS for application-level security (e.g., WhatsApp’s end-to-end encryption).
Exam Tip
- Memorize AH vs. ESP: Know which provides encryption and which does not.
- IKE Phases: Phase 1 = key exchange, Phase 2 = IPsec SA setup.
- VPN Modes: Transport = end-to-end, Tunnel = gateway-to-gateway.
- Attacks: Spoofing → AH, Replay → Sequence numbers, DoS → Rate limiting.
- Real-World Links:
- eSewa → IPsec ESP for payments.
- Ncell VPN → Tunnel mode for offices.
- NEPSE → AH for stock data integrity.
Common Exam Questions:
- Draw an IPsec ESP packet format.
- Explain IKEv2 vs. IKEv1 (IKEv2 supports mobility).
- Compare IPsec and TLS in a table.
- Describe how PFS prevents key compromise.
How IKE establishes shared secrets (Image: de:Benutzer:DaMutz, CC BY-SA 4.0, via Wikimedia Commons)
Based on the TU BIT syllabus for Network Security, unit 6.
Discussion
Loading…