IT231 Foundation Of Information Technology

Foundation Of Information TechnologyUnit 910 min read

Information Security & Ethical IT Issues

Unit 9 of Foundation Of Information Technology: Explores cybersecurity principles (confidentiality, integrity, availability), ethical dilemmas in IT, legal frameworks (Nepal’s IT Act), and real-world threats (malware, phishing) with case studies from eSewa, NTC, and global tech giants.

TAKEAWAYS:

  • Information security is built on CIA triad (Confidentiality, Integrity, Availability) and authentication (biometrics, passwords, tokens).
  • Ethical IT balances privacy (GDPR, Nepal’s IT Act) with innovation, requiring transparency in data use (e.g., Daraz’s customer tracking).
  • Malware (viruses, ransomware) exploits vulnerabilities like weak passwords or unpatched systems (seen in NTC’s 2022 breach).
  • Social engineering (phishing, pretexting) targets human error—e.g., WhatsApp scams tricking users into sharing OTPs.
  • Legal compliance (Nepal’s IT Act 2075) mandates data protection but lacks teeth; global firms like Google face stricter GDPR fines.
  • Emerging threats (AI-driven attacks, IoT vulnerabilities) demand proactive defenses (e.g., Ncell’s SIM swap fraud prevention).

1. Defining Information Security

Information security protects data from unauthorized access, disclosure, alteration, or destruction. It relies on three core principles:

mindmap
  root((Information Security))
    CIA((CIA Triad))
      Confidentiality((Keep data private))
        - Encryption (AES, RSA)
        - Access controls (RBAC, MAC)
      Integrity((Prevent unauthorized changes))
        - Hashing (SHA-256)
        - Digital signatures
      Availability((Ensure access when needed))
        - Redundancy (RAID, cloud backups)
        - DDoS protection
    Authentication((Verify identity))
      - Something you know (passwords)
      - Something you have (smart cards)
      - Something you are (fingerprint, iris)
    Non-repudiation((Prove actions))
      - Logs + digital signatures

Worked Example: eSewa’s Security eSewa uses multi-factor authentication (MFA) to prevent unauthorized transactions. When a user logs in, they must:

  1. Enter password (something you know).
  2. Scan fingerprint (something you are).
  3. Approve via SMS OTP (time-based one-time password). This combines confidentiality (passwords), authentication (biometrics), and non-repudiation (logs).

2. Types of Information Security Threats

Threats exploit weaknesses in systems. Classify them as:

Category Example Impact Real-World Case
Malware Ransomware (Locky) Encrypts files; demands payment NTC’s 2022 data breach (ransomware)
Phishing Fake login pages Steals credentials WhatsApp OTP scams (2023)
Social Engineering Pretexting (fake support) Manipulates users into disclosing data Pathao driver scams (fake "manager")
Insider Threats Disgruntled employees Sabotage or data leaks Google’s 2018 insider leak (100M emails)
Denial-of-Service DDoS attacks Crashes services Daraz’s 2021 Black Friday outage
Hardware Tampering Skimming devices Steals card data ATM skimmers in Kathmandu banks
Pretexting (e.g., Pathao driver scams)Phishing (fake emails)Social EngineeringDisgruntled employees (e.g., Google 2018 leak)Careless employees (e.g., accidental data leaks)Insider ThreatsVirus (replicates)Worm (self-spreading)Trojan (disguised malware)Spyware (data theft)Ransomware (encryption extortion)MalwareDenial-of-Service (e.g., Daraz 2021 outage)Hardware Tampering (e.g., ATM skimmers)Technical ThreatsInformation Security Threats
Classification of information security threats with examples

3. Ethical Issues in IT

Ethics governs moral principles in IT use. Key dilemmas include:

Privacy Concerns (35%)IP Theft (25%)Bias in AI (20%)Other Ethical Issues (20%)
Distribution of common ethical issues in IT (based on global surveys)

A. Privacy vs. Surveillance

  • Privacy: Right to control personal data (e.g., eSewa’s transaction history).
  • Surveillance: Government/marketers tracking data (e.g., NTC’s user location logs).
  • Example: Nepal’s IT Act 2075 requires user consent for data collection but lacks enforcement. Compare to GDPR (EU), which fines companies up to 4% of global revenue for violations.

B. Intellectual Property (IP) Theft

  • Plagiarism: Copying code (e.g., students submitting others’ projects).
  • Software Piracy: Unauthorized use of licensed software (e.g., running cracked Windows in offices).
  • Worked Example: Daraz’s Copyright Battle Daraz sued a local seller for selling counterfeit Nike shoes via its platform. The case highlighted:
    • Ethical duty: Daraz must moderate listings to prevent IP theft.
    • Legal recourse: Nepal’s Copyright Act 2063 allows takedown requests.

C. Bias in AI/Algorithms

  • Example: Pathao’s surge pricing algorithm may penalize low-income riders during peak hours, creating ethical concerns.
  • Mitigation: Transparent algorithms and diversity in training data.

A. Nepal’s IT Act 2075

  • Key Provisions:
    • Mandates data localization (sensitive data must stay in Nepal).
    • Defines cybercrimes (e.g., hacking, identity theft) with penalties up to 10 years in prison.
    • Requires user consent for data collection (but lacks enforcement mechanisms).
  • Gap: No data protection authority to investigate breaches (unlike GDPR’s EDPB).

B. Global Standards (GDPR, CCPA)

Law Region Key Requirement Fine Example
GDPR EU Right to erasure; strict consent rules Google fined €50M (2019)
CCPA California Right to opt-out of data sales Facebook fined $5B (2023)
Nepal IT Act Nepal Data localization; vague enforcement No major fines recorded yet

5. Secure Coding Practices

Preventing vulnerabilities starts at the code level:

flowchart TD
    A["Secure Coding Practices"] --> B["Input Validation"]
    A --> C["Use Prepared Statements"]
    A --> D["Encrypt Data"]
    A --> E["Follow Principle of Least Privilege"]
    A --> F["Regular Updates"]
    B --> B1["Sanitize user input"]
    B1 --> B1a["Prevent SQL injection"]
    C --> C1["Parameterized queries"]
    D --> D1["AES-256 for passwords"]
    D --> D2["Hashing for sensitive data"]
    E --> E1["Grant only required permissions"]
    F --> F1["Patch vulnerabilities"]
    F --> F2["Update libraries"]

Worked Example: SQL Injection Vulnerability Unsafe Code (Nepalese bank’s old login system):

SELECT * FROM users WHERE username = '$_POST[username]' AND password = '$_POST[password]';

Attack: User enters admin' -- → Bypasses password check. Secure Fix: Use prepared statements (PHP PDO):

$stmt = $pdo->prepare("SELECT * FROM users WHERE username = ? AND password = ?");
$stmt->execute([$username, $password]);

6. Incident Response Plan

When a breach occurs, follow this NIST-recommended process:

sequenceDiagram
    participant User
    participant System
    participant SOC
    participant Legal

    User->>System: Detect anomaly (e.g., unusual login)
    System->>SOC: Trigger alert (SIEM tool)
    SOC->>SOC: Isolate affected system
    SOC->>Legal: Report to authorities (if cybercrime)
    Legal->>Police: File complaint under IT Act 2075
    SOC->>User: Notify stakeholders (if data exposed)

Real-World Case: NTC’s 2022 Breach

  • Incident: Ransomware encrypted NTC’s internal systems.
  • Response:
    1. Containment: Isolated infected machines.
    2. Eradication: Reinstalled OS and patched vulnerabilities.
    3. Recovery: Restored from backups (no data loss).
    4. Lessons: Lack of automated backups delayed recovery.

7. Emerging Threats

A. AI-Driven Attacks

  • Deepfake Phishing: AI-generated voice calls impersonating bosses (e.g., "Transfer funds to this account").
  • Example: In 2023, a UK energy firm lost £243,000 to a deepfake CEO scam.

B. IoT Vulnerabilities

  • Example: Ncell’s smart meters were hacked in 2022 due to default passwords on routers.
  • Mitigation:
    • Enable two-factor authentication on IoT devices.
    • Segment IoT networks from corporate systems.

In the Real World

  1. eSewa’s Two-Factor Authentication

    • Idea Used: Multi-factor authentication (MFA) combining passwords, biometrics, and OTPs.
    • Why It Matters: Prevents account takeovers during phishing attacks. When a user logs in from a new device, eSewa sends an OTP to their registered phone, enforcing availability (only authorized users access funds).
  2. NTC’s SIM Swap Fraud Prevention

    • Idea Used: Biometric verification for SIM registrations.
    • Why It Matters: In 2021, Nepal saw 10,000+ SIM swap frauds where attackers hijacked users’ phone numbers. NTC now requires fingerprint verification during registration, addressing the authentication gap in the CIA triad.
  3. Daraz’s Copyright Moderation

    • Idea Used: Automated IP detection + human review.
    • Why It Matters: Daraz uses hash-matching algorithms to flag counterfeit products (e.g., fake Nike shoes). This balances integrity (protecting brands) with availability (keeping the marketplace functional).

Exam Tip

  • Focus on the CIA Triad: Always link security measures (e.g., encryption, firewalls) to confidentiality, integrity, or availability.
  • Compare Legal Frameworks: Nepal’s IT Act is vague; contrast it with GDPR or CCPA for full marks.
  • Worked Examples: Expect 1–2 questions with real-world scenarios (e.g., "How would you secure a bank’s ATM network?").
  • Ethics Over Theory: Prioritize practical dilemmas (e.g., "Is it ethical for Pathao to track rider locations for ads?") over abstract definitions.
  • Malware Types: Memorize ransomware, phishing, and social engineering—these appear in short-answer questions.

Sample Question Breakdown:

  • Define: "Explain the CIA triad." → 1 mark each for confidentiality, integrity, availability.
  • Apply: "How would you secure eSewa’s mobile app?" → 3 marks:
    1. MFA (2 marks).
    2. Encryption (1 mark).
    3. Regular audits (0.5 marks).
  • Compare: "Differentiate GDPR and Nepal’s IT Act." → Table format (2 marks for 2 clear differences).

Based on the TU BITM syllabus for Foundation Of Information Technology (IT231), unit 9.

Discussion

Loading…