IT240 Business Data Communication and Networking

Business Data Communication and NetworkingUnit 911 min read

Network Security Basics: Threats, Controls, and Protocols

Unit 9 of Business Data Communication and Networking explores foundational concepts of network security, including threats (malware, DoS, phishing), security controls (firewalls, encryption, authentication), and protocols (SSL/TLS, VPNs), with real-world applications in Nepali and global tech ecosystems.

Core Concepts of Network Security

Network security protects data integrity, confidentiality, and availability in digital communications. It involves preventing unauthorized access, detecting threats, and mitigating risks across networks.

1. Security Threats and Vulnerabilities

Threats exploit weaknesses in networks. Key categories:

A. Types of Security Threats

VirusesWormsTrojansRansomwareMalwareHackingBrute Force AttacksSocial EngineeringUnauthorized AccessDenial of Service (DoS/DDoS)Man-in-the-Middle (MITM)Insider ThreatsSecurity Threats
Hierarchy of security threats with icons for quick recognition

B. Common Attack Vectors

Threat Description Example
Phishing Tricking users into revealing credentials via fake emails/websites. Fake "eSewa payment failed" emails stealing login details.
SQL Injection Exploiting input fields to manipulate databases. Attacking Daraz’s login page to dump user data.
DDoS Attacks Overloading servers with traffic to crash services. Ncell’s website going down during peak hours due to botnet attacks.
MITM Attacks Intercepting communications between two parties. Public Wi-Fi eavesdropping on unencrypted bank transactions.

C. Vulnerabilities in Networks

  • Weak passwords (e.g., "123456" for NEPSE trading accounts).
  • Unpatched software (e.g., outdated WhatsApp versions exploited for spyware).
  • Lack of encryption (e.g., unsecured Wi-Fi in coffee shops leaking data).


2. Security Controls and Countermeasures

Security controls mitigate threats. They are classified into three types:

A. Preventive Controls

023466992Firewalls85Encryption92Access Control78Antivirus88IPS72Effectiveness (%)
Effectiveness of preventive controls (hypothetical % reduction in breaches)

Key Preventive Measures

Control How It Works Real-World Use
Firewalls Filters traffic between trusted/untrusted networks. Nabil Bank’s firewall blocking unauthorized access to customer databases.
Encryption (SSL/TLS) Scrambles data to prevent eavesdropping. HTTPS on eSewa’s website (TLS 1.3) securing transactions.
VPNs Creates a secure tunnel over public networks. Pathao drivers using VPNs to hide location from hackers.
Antivirus Software Detects and removes malware. Kaspersky protecting Daraz’s servers from ransomware.


B. Detective Controls

Detective controls identify security breaches after they occur:

  • Intrusion Detection Systems (IDS): Monitors network traffic for suspicious activity (e.g., NTC’s IDS detecting DDoS attacks on its servers).
  • Logs and Audits: Tracks user activities (e.g., NEPSE’s audit logs for suspicious trading patterns).
  • Security Alerts: Notifies admins of breaches (e.g., Khalti’s SMS alerts for failed transactions).

C. Corrective Controls

Corrective controls fix issues post-breach:

  • Patch Management: Updates software to fix vulnerabilities (e.g., Google’s monthly Android security patches).
  • Backup and Recovery: Restores data after ransomware attacks (e.g., Himalayan Java’s cloud backups).
  • Incident Response Plans: Steps to contain and recover from attacks (e.g., Ncell’s cybersecurity team isolating infected servers).

3. Security Protocols

Protocols ensure secure communication. Key ones:

A. SSL/TLS (Secure Sockets Layer/Transport Layer Security)

  • Purpose: Encrypts data between web servers and clients.
  • How It Works:
    1. Client requests a secure connection.
    2. Server sends a digital certificate (e.g., Let’s Encrypt).
    3. Symmetric key exchange via RSA or Diffie-Hellman.
    4. Encrypted data transfer.
  • Example:
    • When you log into eSewa, TLS 1.3 encrypts your password and transaction details.
sequenceDiagram
  Client->>Server: Requests HTTPS connection
  Server-->>Client: Sends Certificate (e.g., DigiCert)
  Client->>Server: Verifies Certificate
  Client->>Server: Sends Pre-Master Key (encrypted)
  Server->>Client: Sends Session Key
  Client->>Server: Sends Encrypted Data
  Server->>Client: Responds with Encrypted Data


B. VPN (Virtual Private Network)

  • Purpose: Secures remote access to private networks.
  • How It Works:
    • Uses IPsec or OpenVPN to create an encrypted tunnel.
    • Routes traffic through a secure server (e.g., NordVPN).
  • Example:
    • A Daraz employee accessing company databases from home via a VPN.

C. WPA3 (Wi-Fi Protected Access 3)

  • Purpose: Secures wireless networks.
  • Improvements over WPA2:
    • SAE (Simultaneous Authentication of Equals): Prevents brute-force attacks.
    • Forward Secrecy: Compromised keys don’t expose past sessions.
  • Example:
    • NTC’s public Wi-Fi using WPA3 to prevent hackers from stealing customer data.

4. Authentication and Authorization

A. Authentication Methods

Method Description Example
Passwords Basic credentials (weak if reused). eSewa login (but vulnerable to phishing).
Multi-Factor (MFA) Requires 2+ factors (SMS, biometrics, tokens). Nabil Bank’s app requiring OTP + fingerprint.
Biometrics Uses fingerprints, facial recognition. Pathao’s driver app unlocking with face ID.
Smart Cards Physical tokens with embedded chips. Corporate networks using RFID cards.

B. Authorization Models

  • Role-Based Access Control (RBAC): Users get permissions based on roles (e.g., admin vs. employee in a company).
  • Attribute-Based Access Control (ABAC): Grants access based on attributes (e.g., time of day, location).
  • Example:
    • NEPSE traders can only access their own portfolios, not others’.

5. Physical Security Measures

Often overlooked but critical:

  • Cable Locks: Prevents theft of network devices (e.g., routers in cafes).
  • Biometric Scanners: Restricts data center access (e.g., Chaudhary Group’s server rooms).
  • Surveillance Cameras: Deters tampering (e.g., Ncell’s exchange offices).

In the Real World

  1. eSewa’s Security:

    • Uses TLS 1.3 for encrypted payments.
    • Implements MFA (OTP + fingerprint) to prevent unauthorized logins.
    • Real Example: When a user logs in, eSewa’s server verifies the certificate (from DigiCert) and establishes an encrypted session.
  2. Nabil Bank’s Fraud Prevention:

    • Firewalls block SQL injection attempts on their ATM network.
    • Behavioral Analytics flags suspicious transactions (e.g., sudden large withdrawals).
    • Real Example: If a hacker tries brute-forcing an ATM PIN, the system locks the account after 3 failed attempts.
  3. Daraz’s Supply Chain Security:

    • VPNs secure warehouse inventory systems from remote access.
    • Blockchain tracks shipments to prevent counterfeit products.
    • Real Example: When a seller ships a package, Daraz’s system logs the GPS coordinates and temperature (for perishables) via encrypted IoT sensors.

Exam Tip

How This Unit is Tested

  1. Definitions and Concepts (20%):

    • Know the difference between preventive, detective, and corrective controls.
    • Memorize SSL/TLS handshake steps and VPN working.
    • Understand phishing vs. MITM attacks.
  2. Scenario-Based Questions (30%):

    • Example Question: "A company’s website was defaced due to a SQL injection. What security control could have prevented this?" Answer: Input validation + firewalls (preventive) and IDS (detective).
  3. Diagrams and Flowcharts (20%):

    • Draw the OSI security layers (e.g., firewall at Network Layer, encryption at Presentation Layer).
    • Sketch a TLS handshake or VPN tunnel.
  4. Real-World Applications (30%):

    • Relate concepts to Nepali companies (e.g., NTC’s DDoS protection, Khalti’s MFA).
    • Worked Example: "How does Pathao ensure driver data is secure?" Answer:
      • Encryption: TLS for app communications.
      • Authentication: OTP + biometrics.
      • Physical Security: GPS tracking with tamper-proof sensors.

Quick Revision Checklist

Topic Key Points to Remember
Threats Malware, DoS, phishing, MITM.
Firewalls Packet filtering (stateless) vs. stateful inspection.
Encryption Symmetric (AES) vs. asymmetric (RSA) keys.
SSL/TLS Handshake: Certificate → Key Exchange → Encrypted Data.
VPN IPsec vs. OpenVPN; used by remote workers.
Authentication MFA > passwords; biometrics > tokens.
Physical Security Cable locks, biometric scanners, surveillance.

Final Case Study: Ncell’s Network Security

Scenario: Ncell’s 4G network was targeted by a DDoS attack during a major festival, causing call drops. Security Measures Deployed:

  1. Preventive:
    • Firewalls at data centers to filter malicious traffic.
    • Rate Limiting to prevent server overload.
  2. Detective:
    • IDS detected the attack pattern (sudden spike in ICMP packets).
  3. Corrective:
    • Traffic Redirection to backup servers.
    • Customer Alerts via SMS about the issue.

Lesson: A multi-layered security approach (prevent + detect + correct) is essential for large-scale networks.


Based on the TU BITM syllabus for Business Data Communication and Networking (IT240), unit 9.

Discussion

Loading…