IT231 Foundation Of Information Technology

Foundation Of Information TechnologyUnit 710 min read

Internet & Web Tech: Protocols, Services & Security

Unit 7 of Foundation of Information Technology explores the architecture of the internet (TCP/IP, OSI), web technologies (HTML/CSS/JS), modern services (IoT, cloud, APIs), and security threats (phishing, malware) with real-world examples from Nepal and globally.

TAKEAWAYS

  • The OSI model and TCP/IP protocol suite are the backbone of internet communication, breaking data into packets for reliable delivery.
  • Web technologies (HTML5, CSS3, JavaScript) and client-server architecture power dynamic websites like Daraz and Pathao.
  • IoT connects everyday devices (eSewa QR codes, NTC smart meters) to the internet, enabling automation and data collection.
  • Cloud computing (Google Drive, Ncell’s cloud storage) and APIs (Khalti’s payment gateway) enable scalable business operations.
  • Cybersecurity threats (phishing, DDoS) target users and businesses; encryption and firewalls mitigate risks.
  • Web 3.0 and blockchain (NEPSE’s digital ledger) introduce decentralized, user-controlled data ownership.

1. Introduction to the Internet

The internet is a global network of networks connecting millions of devices via protocols (rules for communication). It enables:

  • Data transmission (emails, videos, IoT sensor data).
  • Resource sharing (cloud storage, APIs).
  • Decentralized services (blockchain, peer-to-peer networks).

How the Internet Works: Packet Switching

The internet uses packet switching to break data into small packets, which travel independently via routers. Each packet contains:

  • Header: Source/destination IP, sequence number.
  • Payload: Actual data (e.g., a webpage chunk).
  • Trailer: Error-checking bits.
flowchart TD
    A["User"] -->|"Sends packet"| B["Packet Header: Source IP, Destination IP, Sequence Number"]
    B -->|"Contains"| C["Packet Payload: Data Chunk (e.g., webpage)"]
    C -->|"Followed by"| D["Packet Trailer: Error-Checking Bits"]
    D -->|"Routed via"| E["Router 1"]
    E -->|"..."| F["Router 2"]
    F -->|"Delivers to"| G["Server"]
    G -->|"Response"| F
    F -->|"..."| E
    E -->|"Delivers to"| A

Worked Example: When you order food via Pathao, your request is split into packets. Each packet takes a different route to the Pathao server, reassembling your order details before processing.


2. Internet Protocols and Models

OSI Model (7 Layers)

The Open Systems Interconnection (OSI) model standardizes internet communication into 7 layers:

Application LayerPresentation LayerSession LayerTransport LayerNetwork LayerData Link LayerOSI Model (7 Layers)
Comparison of OSI’s 7 layers with key protocols.
Layer Function Example Protocol
Application User interfaces (e.g., web browsers, apps) HTTP, FTP, SMTP
Presentation Data translation (encryption, compression) SSL/TLS, JPEG
Session Manages connections (e.g., keeps a chat open) NetBIOS, RPC
Transport Ensures end-to-end delivery (TCP/UDP) TCP, UDP
Network Logical addressing (IP routing) IP, ICMP
Data Link Physical addressing (MAC addresses) Ethernet, Wi-Fi
Physical Raw bit transmission (cables, signals) USB, Ethernet cables

TCP/IP Model (4 Layers)

The internet uses the TCP/IP model, a simplified 4-layer version of OSI:

Application LayerTransport LayerInternet LayerNetwork Access LayerTCP/IP Model (4 Layers)
Hierarchy of the TCP/IP model layers with key protocols.

Comparison Table: OSI vs. TCP/IP

Feature OSI Model TCP/IP Model
Layers 7 (detailed) 4 (simplified)
Used by Standards (e.g., ISO) Internet (practical)
Flexibility High (theoretical) Low (practical)

Worked Example: When you browse NEPSE, your browser (Application Layer) sends an HTTP request. TCP (Transport Layer) ensures the request reaches the server, while IP (Internet Layer) routes it via routers.


3. Web Technologies

HTML5, CSS3, and JavaScript

  • HTML5: Structures web content (e.g., <div>, <video>).
  • CSS3: Styles content (colors, layouts, animations).
  • JavaScript: Adds interactivity (e.g., Daraz’s dynamic product filters).

Client-Server Architecture

Websites use a client-server model:

  • Client: User’s device (e.g., smartphone accessing Khalti).
  • Server: Hosts data (e.g., Khalti’s payment gateway).
flowchart TD
    A["Client (User)"] -->|"HTTP Request"| B["Web Server (Khalti)"]
    B -->|"Processes Payment"| C["Database"]
    C -->|"Returns Data"| B
    B -->|"HTTP Response"| A

Advantages:

  • Scalability (servers handle many clients).
  • Security (servers enforce access controls).

Disadvantages:

  • Single point of failure (if the server crashes, the site goes down).
  • Latency (depends on server distance).

4. Internet Services

IoT (Internet of Things)

IoT connects physical devices to the internet for automation. Examples:

  • eSewa QR codes: Enable instant payments by scanning a code linked to a user’s account.
  • NTC smart meters: Track electricity usage in real-time via IoT sensors.

Cloud Computing

Cloud services (e.g., Google Drive, Ncell’s cloud backup) store data remotely, offering:

  • Scalability: Pay for storage as needed.
  • Accessibility: Access files from anywhere (e.g., Ncell’s cloud-based customer support).

Comparison Table: Traditional vs. Cloud Storage

Feature Traditional Storage Cloud Storage
Location Local (hard drive) Remote (servers)
Scalability Limited by hardware Unlimited (pay-as-you-go)
Access Requires physical access Accessible via internet

APIs (Application Programming Interfaces)

APIs allow software integration. Example:

  • Khalti’s Payment API: Lets Daraz embed Khalti’s payment button without redirecting users.
flowchart TD
    A["Daraz Website"] -->|"API Request"| B["Khalti API Gateway"]
    B -->|"Authenticates"| C["Khalti Server"]
    C -->|"Processes Payment"| D["Database: Transaction Records"]
    D -->|"Returns Status"| C
    C -->|"Response"| B
    B -->|"Response"| A

5. Internet Security

Threats

  • Phishing: Fake emails (e.g., "Your eSewa account is locked!").
  • Malware: Viruses (e.g., ransomware locking Ncell’s customer data).
  • DDoS Attacks: Overloading servers (e.g., targeting NEPSE during high traffic).

Security Measures

  • Firewalls: Block unauthorized access (e.g., NTC’s network firewall).
  • Encryption: Secures data (e.g., HTTPS for Khalti transactions).
  • Multi-Factor Authentication (MFA): Adds a second layer (e.g., eSewa’s SMS verification).
023.7547.571.2595Firewall95Encryption90Multi-Factor Auth85Antivirus80
Effectiveness (%) of common security measures against threats.

6. Emerging Web Technologies

Web 3.0

  • Decentralized: No single owner (e.g., blockchain-based NEPSE).
  • User Control: Users own their data (e.g., decentralized social media).
  • AI Integration: Smart recommendations (e.g., YouTube’s personalized feeds).

Blockchain

  • NEPSE’s Digital Ledger: Records stock trades transparently.
  • Smart Contracts: Self-executing agreements (e.g., automated loan repayments).

Comparison Table: Web 2.0 vs. Web 3.0

Feature Web 2.0 Web 3.0
Ownership Centralized (e.g., Facebook) Decentralized (blockchain)
Data Control Companies own user data Users own their data
Example Google, WhatsApp NEPSE, decentralized apps

In the Real World

  1. eSewa’s QR Codes (IoT + Mobile Payments)

    • Idea: IoT-enabled QR codes on eSewa’s app allow instant payments by scanning a code linked to a merchant’s account.
    • How: The QR code contains a URL or payment request that triggers eSewa’s backend to process the transaction securely.
  2. Pathao’s Ride-Hailing App (Client-Server + APIs)

    • Idea: Pathao’s app uses a client-server architecture to connect riders with drivers. The Google Maps API provides real-time location tracking, while the Pathao backend manages ride assignments.
    • Worked Example: When you request a ride, your location is sent to Pathao’s server via the API. The server matches you with the nearest driver, updates their app in real-time, and processes payment via Khalti’s API.
  3. NEPSE’s Blockchain for Stock Trading (Web 3.0)

    • Idea: NEPSE is exploring blockchain to record stock trades immutably (cannot be altered). This reduces fraud and ensures transparency.
    • How: Each trade is recorded as a block in a chain, linked cryptographically to previous trades. Investors can verify transactions without relying on a central authority.

Exam Tip

  • Focus on real-world examples: Examiners love questions like "How does IoT improve business operations?" or "Explain Web 3.0 with a Nepalese example." Tie concepts to eSewa, Khalti, NEPSE, or Pathao.
  • Diagrams are worth marks: Draw the OSI model, client-server flow, or IoT network to visualize answers.
  • Compare technologies: For questions like "Advantages of cloud vs. traditional storage," use a Markdown table to structure your answer clearly.
  • Security is key: Always mention encryption, firewalls, or MFA when discussing threats like phishing or DDoS.
  • Time management: Spend 20% of your time on diagrams (e.g., TCP/IP layers) and 30% on examples (e.g., Khalti’s API or NEPSE’s blockchain).

Based on the TU BITM syllabus for Foundation Of Information Technology (IT231), unit 7.

Discussion

Loading…