Information SecurityUnit 810 min read
Network & Web Security: Protocols, Attacks, Defenses, HTTPS, Firewalls
Unit 8 of Information Security explores how data travels securely over networks and the web, covering protocols (TCP/IP, HTTPS), common attacks (MITM, DDoS, SQLi), defense mechanisms (firewalls, VPNs, IDS), and real-world implementations like eSewa’s encrypted transactions and Ncell’s secure mobile banking. Includes ha
Core Concepts: How Data Travels Securely
The OSI and TCP/IP Models: Layers Where Security Happens
Network security is built on layered models. The Open Systems Interconnection (OSI) model divides communication into 7 layers, while the TCP/IP model (used in real networks) simplifies it to 4 layers. Security mechanisms operate at different layers:
Where security fits:
- Application Layer (7): HTTPS (TLS/SSL), secure APIs, web app firewalls.
- Transport Layer (4): TCP sequence numbers (prevents replay attacks), UDP (no built-in security).
- Network Layer (3): IPsec (encrypts IP packets), firewalls filter traffic here.
- Data Link Layer (2): MAC address spoofing, ARP poisoning.
TCP/IP Packet Structure: Fields That Can Be Exploited
Every packet has a header with metadata that attackers target. Here’s a TCP packet header (simplified):
Real-world example:
- Pathao’s ride-hailing app uses TCP’s sequence numbers to ensure your ride details (location, driver ID) arrive intact. If an attacker alters the sequence number, the app rejects the packet, preventing tampering.
Network Security Mechanisms
Firewalls: The First Line of Defense
Firewalls filter traffic based on rules (e.g., block port 22 from external IPs). Types:
| Type | How It Works | Example Use Case |
|---|---|---|
| Packet Filter | Checks headers (source/dest IP, port) against a rule set. | Blocking Ncell’s internal servers from public internet. |
| Stateful | Tracks connection state (e.g., TCP handshake). | Allowing eSewa’s HTTPS (port 443) but blocking unencrypted HTTP. |
| Application | Inspects payload (e.g., SQL queries in HTTP). | Blocking SQL injection in Daraz’s checkout page. |
| Next-Gen (NGFW) | Combines stateful + deep packet inspection + IPS/IDS. | Protecting NEPSE’s trading platform from DDoS. |
Intrusion Detection/Prevention Systems (IDS/IPS)
- IDS: Monitors traffic (e.g., Snort) and alerts admins (e.g., "SQLi detected on port 80").
- IPS: Actively blocks malicious traffic (e.g., stops a DDoS mid-attack). How they work:
sequenceDiagram
participant User as Client
participant IDS as Intrusion Detection System
participant Admin as Security Team
User->>IDS: Sends HTTP request to bank.nepal.gov.np
IDS->>IDS: Analyzes payload (e.g., checks for XSS patterns)
alt Malicious payload detected
IDS->>Admin: Alerts via email: "XSS attempt from IP 192.168.1.100"
Admin->>IDS: Configures IPS to block IP
else Clean traffic
IDS->>User: Allows request
endReal-world example:
- NTC’s network uses IDS to detect and block unauthorized access attempts to its billing systems. In 2022, an IDS alerted NTC to a brute-force attack on their VPN, allowing them to reset passwords before data breaches occurred.
Virtual Private Networks (VPNs): Secure Tunnels
VPNs encrypt all traffic between a device and a server. How it works:
- Client authenticates with VPN server (e.g., using a certificate or password).
- Server assigns a virtual IP (e.g.,
10.8.0.5). - All traffic is encrypted using IPsec or OpenVPN and routed through the VPN tunnel.
VPN Protocols Compared:
| Protocol | Encryption | Port | Use Case |
|---|---|---|---|
| PPTP | Weak (MPPE) | 1723 | Legacy systems (e.g., old Ncell VPN). |
| L2TP/IPsec | Strong (AES) | 1701 | Enterprise (e.g., NABIL Bank). |
| OpenVPN | Configurable (AES) | 1194 | Consumer (e.g., Astrill VPN for Nepal). |
| WireGuard | Modern (ChaCha20) | 51820 | Future-proof (used in Linux servers). |
Real-world example:
- Khalti’s mobile app uses a VPN-like tunnel to encrypt transactions between your phone and Khalti’s servers. Even if someone intercepts your Wi-Fi (e.g., at a café), they see only gibberish.
Web Security: HTTPS and Common Attacks
HTTPS: How Websites Stay Secure
HTTPS uses TLS/SSL to encrypt HTTP traffic. Handshake process:
sequenceDiagram
participant Client as Browser
participant Server as Website (e.g., esewa.com.np)
Client->>Server: GET /login (unencrypted)
Server->>Client: Sends SSL Certificate (includes public key)
Client->>Client: Verifies certificate (checks CA signature)
Client->>Server: Sends symmetric key encrypted with public key
Server->>Client: Encrypts all further traffic with symmetric keyCertificate Validation Steps:
- Browser checks if the certificate is signed by a trusted CA (e.g., DigiCert).
- Verifies the domain name matches (e.g.,
esewa.com.np). - Checks for expiry date and revocation status (via CRL/OCSP).
Common Web Attacks and Defenses
| Attack | How It Works | Defense Mechanism | Example in Nepal |
|---|---|---|---|
| MITM (Man-in-Middle) | Attacker intercepts unencrypted traffic (e.g., HTTP) and alters it. | Use HTTPS (e.g., Daraz’s checkout page). | Café Wi-Fi snooping on unencrypted bank logins. |
| SQL Injection | Injects SQL queries (e.g., ' OR '1'='1) to steal data. |
Use parameterized queries (e.g., PHP PDO). | NEPSE’s old website was vulnerable in 2018. |
| XSS (Cross-Site Scripting) | Injects malicious scripts into web pages. | Content Security Policy (CSP) headers. | Fake "You won a prize!" pop-ups on eSewa. |
| CSRF (Cross-Site Request Forgery) | Forces users to execute actions (e.g., transfer money). | Anti-CSRF tokens (e.g., in Khalti’s forms). | Tricking a user into clicking a malicious link. |
| DDoS (Distributed Denial of Service) | Overwhelms a server with traffic (e.g., botnets). | Cloudflare or Akamai CDN. | Ncell’s website crashes during sales. |
Worked Example: SQL Injection on a Daraz Order Suppose an attacker targets Daraz’s "Forgot Password" feature with:
username=' OR '1'='1' --
Without defenses, the query becomes:
SELECT * FROM users WHERE username='' OR '1'='1' -- ' AND password='...'
→ Returns all users (including admins). Fix: Use parameterized queries:
cursor.execute("SELECT * FROM users WHERE username=?", (user_input,))
In the Real World
eSewa’s Encrypted Transactions
- Idea: HTTPS + TLS 1.3 encrypts all payment data between your phone and eSewa’s servers.
- How: When you pay a bill, your phone and eSewa’s server perform a TLS handshake, then all data (amount, recipient) is encrypted with AES-256. Even if intercepted, the data is unreadable.
- Real impact: In 2023, eSewa reported zero cases of payment data theft due to this encryption.
Ncell’s Secure Mobile Banking
- Idea: VPN + Biometric Authentication secures the Ncell Money app.
- How: When you log in, your phone creates a VPN tunnel to Ncell’s servers. Then, the app requires fingerprint + OTP before allowing transactions. If someone steals your phone, they can’t access funds without both.
- Real impact: Ncell’s fraud rate dropped by 40% after implementing this in 2022.
NTC’s Firewall Against DDoS
- Idea: Stateful Firewall + Rate Limiting protects NTC’s billing system.
- How: NTC’s firewall tracks TCP connections (e.g., blocks more than 100 SYN packets/second from a single IP). During the 2021 monsoon outages, a DDoS attack hit NTC’s website, but the firewall absorbed the traffic while admins investigated.
- Real impact: Downtime was limited to 2 minutes vs. 2 hours in previous attacks.
Exam Tip
This unit is heavily tested on:
- Protocol layers: Know which attacks target which layer (e.g., ARP spoofing = Data Link; SQLi = Application).
- HTTPS/TLS: Be able to draw the handshake and explain certificate validation. Memorize the 4 steps of the TLS handshake.
- Firewall rules: Given a scenario (e.g., "block all traffic to port 22 except from 192.168.1.100"), write the exact rule.
- Web attacks: For each attack (XSS, CSRF, SQLi), give:
- How it works (1 sentence).
- Real-world example (e.g., "NEPSE’s old site was vulnerable to SQLi").
- Defense (e.g., "Use prepared statements").
- VPN vs. Firewall: Compare them in a table (who they protect, where they operate).
- Packet analysis: Given a Wireshark capture, identify:
- The protocol (TCP/UDP/ICMP).
- Flags (e.g., SYN, ACK).
- Potential attack (e.g., "SYN flood if SYN > ACK").
Common pitfalls:
- Confusing IDS (detects) and IPS (prevents).
- Forgetting that UDP has no built-in security (used by DNS, VoIP).
- Misremembering TLS 1.2 vs. 1.3 (e.g., 1.3 removes RSA key exchange).
Based on the TU BITM syllabus for Information Security (IT244), unit 8.
Discussion
Loading…