Network SecurityUnit 310 min read

Transport Level Security: TLS/SSL, VPNs, Firewalls & Secure Protocols

Unit 3 of Network Security explores Transport Layer Security (TLS/SSL), Virtual Private Networks (VPNs), firewalls, and secure protocols like HTTPS, FTPS, and SSH, explaining their mechanisms, cryptographic foundations, and real-world applications in securing data in transit.

Core Concepts

Transport Layer Security (TLS/SSL)

TLS (Transport Layer Security) and its predecessor SSL (Secure Sockets Layer) are cryptographic protocols designed to provide secure communication over a computer network. They operate at the transport layer (Layer 5) of the OSI model, ensuring data confidentiality, integrity, and authentication between applications.

How TLS Works

TLS uses a combination of symmetric encryption (for speed) and asymmetric encryption (for key exchange) to secure data. The process involves four main phases:

  1. Handshake Phase: Establishes a secure connection.
  2. Key Exchange: Uses asymmetric encryption (e.g., RSA or Diffie-Hellman) to exchange a symmetric key.
  3. Authentication: Verifies the identity of the server (and optionally the client) using digital certificates.
  4. Data Transfer: Encrypts data using symmetric encryption (e.g., AES).
sequenceDiagram
    participant Client as Client (Browser)
    participant Server as Server (Website)
    Client->>Server: ClientHello (supports TLS 1.3, cipher suites)
    Server->>Client: ServerHello, Certificate, ServerKeyExchange
    Client->>Server: ClientKeyExchange, ChangeCipherSpec, Finished
    Server->>Client: ChangeCipherSpec, Finished
    Note over Client,Server: Symmetric key established\nSecure session begins

TLS Record Protocol

TLS encrypts data using the TLS Record Protocol, which:

  • Compresses data (optional).
  • Applies a Message Authentication Code (MAC) for integrity.
  • Encrypts the data (e.g., using AES or ChaCha20).
  • Transmits the result.

TLS Versions

Version Year Key Features Security Issues
SSL 3.0 1996 First widely used, but insecure. POODLE, BEAST attacks
TLS 1.0 1999 Fixed SSL 3.0 vulnerabilities. Weak cipher suites, outdated
TLS 1.1 2006 Removed unsafe features (e.g., CBC mode without padding). Still vulnerable to some attacks
TLS 1.2 2008 Stronger cryptography, support for AEAD ciphers (e.g., GCM). No major flaws (if configured properly)
TLS 1.3 2018 Faster handshake, removed outdated features, mandatory forward secrecy. Most secure to date

Worked Example: HTTPS Connection (eSewa Payment)

When you log in to eSewa to make a payment:

  1. Your browser sends a ClientHello to https://esewa.com.np.
  2. The server responds with its digital certificate (issued by a trusted CA like DigiCert).
  3. Your browser verifies the certificate and negotiates a symmetric key using ECDHE (Elliptic Curve Diffie-Hellman Ephemeral).
  4. All subsequent data (login credentials, payment details) is encrypted with AES-256-GCM.

TLS handshake diagram**A visual breakdown of the TLS handshake phases. (Image: Fleshgrinder and The People from The Tango! Desktop Project., Public domain, via Wikimedia Commons)


Virtual Private Networks (VPNs)

VPNs create a secure, encrypted tunnel over an untrusted network (e.g., the internet) to protect data in transit. They are widely used by:

  • Individuals: To bypass geo-restrictions (e.g., accessing Netflix US from Nepal).
  • Businesses: To securely connect remote offices or employees (e.g., Ncell’s remote workforce).
  • Governments: To secure diplomatic communications.

How VPNs Work

  1. Authentication: User authenticates via username/password, certificates, or biometrics.
  2. Tunnel Establishment: A secure tunnel is created using IPSec or OpenVPN.
  3. Encryption: All traffic is encrypted (e.g., using AES-256) and routed through a VPN server.
  4. Decryption: The VPN server decrypts and forwards traffic to the destination.

VPN Protocols

Protocol Port Encryption Use Case Security Level
PPTP 1723 MPPE (weak) Legacy systems (avoid) Low
L2TP/IPsec 1701 AES, 3DES Corporate networks Medium
OpenVPN 1194 AES, ChaCha20 General use (secure) High
IKEv2/IPsec 500/4500 AES-GCM Mobile devices (fast reconnect) Very High
WireGuard 51820 ChaCha20/Poly1305 Modern, lightweight Very High

Worked Example: Ncell Employee Accessing Corporate Network

An Ncell employee in Pokhara connects to the corporate network via VPN:

  1. The employee’s device connects to vpn.ncell.com using OpenVPN.
  2. The VPN server authenticates the employee via RADIUS (username/password + 2FA).
  3. All traffic (emails, internal databases) is encrypted with AES-256.
  4. The employee accesses internal resources as if on the local network.


Firewalls

Firewalls act as a barrier between a trusted internal network and untrusted external networks (e.g., the internet). They filter traffic based on rules (e.g., IP addresses, ports, protocols).

Types of Firewalls

Type Description Example Use Case
Packet Filtering Filters based on IP/port (Layer 3/4). Basic home router security.
Stateful Inspection Tracks connection state (e.g., TCP handshake). Corporate networks (e.g., NTC).
Application-Level (Proxy) Inspects application data (e.g., HTTP headers). Web filtering in schools.
Next-Gen (NGFW) Combines firewall + IPS/IDS + sandboxing. Banks (e.g., NMB Bank).

Worked Example: Blocking Malicious Traffic to a Bank

A firewall at NMB Bank is configured to:

  • Allow traffic on port 443 (HTTPS) to bank.nmb.com.
  • Block all inbound traffic on port 22 (SSH) from external IPs (except whitelisted admins).
  • Drop packets with malformed TCP flags (potential scans).


Secure Protocols

Several protocols ensure secure communication at the transport layer:

1. HTTPS (HTTP + TLS)

  • Used for secure web browsing (e.g., Daraz, eSewa).
  • Ensures confidentiality and integrity of web traffic.

2. FTPS (FTP Secure)

  • Secures File Transfer Protocol (FTP) using TLS.
  • Used by NTC to securely transfer network configuration files.

3. SSH (Secure Shell)

  • Replaces insecure Telnet for remote access.
  • Used by Nepal Stock Exchange (NEPSE) admins to manage servers.

4. SMTP with TLS (SMTPS)

  • Secures email transmission (e.g., Gmail, Ncell Email).

Comparison Table: Secure vs. Insecure Protocols

Protocol Secure Version Use Case Risk if Unsecured
HTTP HTTPS Web browsing Eavesdropping, MITM attacks
FTP FTPS/SFTP File transfers Data leakage, unauthorized access
Telnet SSH Remote server access Credential theft
SMTP SMTPS Email transmission Email interception

Protocol stack with TLS/SSL**A layered diagram showing where TLS fits in the OSI model (between transport and application layers). (Image: Gorivero, CC BY 3.0, via Wikimedia Commons)


## In the real world

  1. eSewa (HTTPS/TLS)

    • When you pay bills via eSewa, TLS encrypts your card details and transaction ID to prevent man-in-the-middle (MITM) attacks. The site uses TLS 1.3 with ECDHE-RSA-AES256-GCM-SHA384, ensuring forward secrecy.
  2. Ncell VPN for Remote Workers

    • Ncell employees in rural areas use OpenVPN to securely access internal databases (e.g., customer records). The VPN enforces two-factor authentication (2FA) and logs all sessions for auditing.
  3. Daraz’s Firewall Rules

    • Daraz’s servers block SQL injection attempts by filtering malicious payloads at the firewall (e.g., dropping requests with ' OR 1=1 --). Their NGFW also scans for zero-day exploits in real time.
  4. NTC’s FTPS for Network Updates

    • NTC technicians use FTPS to securely upload firmware updates to base stations. Without encryption, attackers could intercept and modify the firmware, disrupting services.
  5. NEPSE’s SSH for Server Management

    • NEPSE admins use SSH key pairs (not passwords) to log into trading servers. If an attacker steals a password, they cannot decrypt past sessions due to TLS’s forward secrecy.

## Exam Tip

  1. Diagrams Are Key

    • Draw the TLS handshake (ClientHello → ServerHello → Key Exchange → Finished).
    • Sketch a VPN tunnel showing encryption/decryption at both ends.
    • Label a firewall rule table with source/destination ports and actions (ALLOW/DROP).
  2. Compare Protocols

    • Memorize the differences between TLS 1.2 vs. 1.3 (e.g., 1.3 removes RSA key exchange, uses 0-RTT).
    • Know when to use SSH vs. FTPS (SSH for remote access, FTPS for file transfers).
  3. Real-World Scenarios

    • Expect questions like:
      • "How does eSewa prevent MITM attacks during login?" (Answer: TLS certificate pinning + HSTS).
      • "Why does Ncell use OpenVPN instead of PPTP?" (Answer: PPTP is vulnerable to MS-CHAPv2 cracking).
    • Always tie answers to Nepali companies (eSewa, Ncell, NTC, NEPSE).
  4. Weaknesses to Watch For

    • POODLE (SSL 3.0), Heartbleed (OpenSSL), BEAST (CBC mode).
    • VPN risks: Misconfigured firewalls, weak encryption (e.g., DES).
  5. Maths for Marks

    • Calculate TLS session resumption time savings (TLS 1.3’s 0-RTT).
    • Estimate VPN overhead (e.g., 10% latency increase due to encryption).

Based on the TU BIT syllabus for Network Security, unit 3.

Discussion

Loading…