Information SecurityUnit 810 min read

Network & Web Security: Protocols, Attacks, Defenses, HTTPS, Firewalls

Unit 8 of Information Security explores how data travels securely over networks and the web, covering protocols (TCP/IP, HTTPS), common attacks (MITM, DDoS, SQLi), defense mechanisms (firewalls, VPNs, IDS), and real-world implementations like eSewa’s encrypted transactions and Ncell’s secure mobile banking. Includes ha

Core Concepts: How Data Travels Securely

The OSI and TCP/IP Models: Layers Where Security Happens

Network security is built on layered models. The Open Systems Interconnection (OSI) model divides communication into 7 layers, while the TCP/IP model (used in real networks) simplifies it to 4 layers. Security mechanisms operate at different layers:

Application (Layer 7)DataPresentation (Layer 6)DataSession (Layer 5)DataTransport (Layer 4: TCP/UDP)SegmentNetwork (Layer 3: IP, Routers)PacketData Link (Layer 2: Switches,MAC)FramePhysical (Layer 1: Cables,Signals)Bits
OSI Model (left) vs. TCP/IP Model (right) with security-relevant layers highlighted.

Where security fits:

  • Application Layer (7): HTTPS (TLS/SSL), secure APIs, web app firewalls.
  • Transport Layer (4): TCP sequence numbers (prevents replay attacks), UDP (no built-in security).
  • Network Layer (3): IPsec (encrypts IP packets), firewalls filter traffic here.
  • Data Link Layer (2): MAC address spoofing, ARP poisoning.

TCP/IP Packet Structure: Fields That Can Be Exploited

Every packet has a header with metadata that attackers target. Here’s a TCP packet header (simplified):

08162431Source Port16 bitsDestination Port16 bitsSequence Number32 bitsAcknowledgment Num32 bitsData Offset4 bitsReserved3 bitsFlags (SYN, ACK,etc.)9 bitsWindow Size16 bits
Simplified TCP header structure with exploitable fields (real-world size in bits).

Real-world example:

  • Pathao’s ride-hailing app uses TCP’s sequence numbers to ensure your ride details (location, driver ID) arrive intact. If an attacker alters the sequence number, the app rejects the packet, preventing tampering.

Network Security Mechanisms

Firewalls: The First Line of Defense

Firewalls filter traffic based on rules (e.g., block port 22 from external IPs). Types:

Type How It Works Example Use Case
Packet Filter Checks headers (source/dest IP, port) against a rule set. Blocking Ncell’s internal servers from public internet.
Stateful Tracks connection state (e.g., TCP handshake). Allowing eSewa’s HTTPS (port 443) but blocking unencrypted HTTP.
Application Inspects payload (e.g., SQL queries in HTTP). Blocking SQL injection in Daraz’s checkout page.
Next-Gen (NGFW) Combines stateful + deep packet inspection + IPS/IDS. Protecting NEPSE’s trading platform from DDoS.
Packet FilteringStateful InspectionInternetFirewallLAN
Firewall placement between untrusted (Internet) and trusted (LAN) networks.

Intrusion Detection/Prevention Systems (IDS/IPS)

  • IDS: Monitors traffic (e.g., Snort) and alerts admins (e.g., "SQLi detected on port 80").
  • IPS: Actively blocks malicious traffic (e.g., stops a DDoS mid-attack). How they work:
sequenceDiagram
    participant User as Client
    participant IDS as Intrusion Detection System
    participant Admin as Security Team
    User->>IDS: Sends HTTP request to bank.nepal.gov.np
    IDS->>IDS: Analyzes payload (e.g., checks for XSS patterns)
    alt Malicious payload detected
        IDS->>Admin: Alerts via email: "XSS attempt from IP 192.168.1.100"
        Admin->>IDS: Configures IPS to block IP
    else Clean traffic
        IDS->>User: Allows request
    end

Real-world example:

  • NTC’s network uses IDS to detect and block unauthorized access attempts to its billing systems. In 2022, an IDS alerted NTC to a brute-force attack on their VPN, allowing them to reset passwords before data breaches occurred.

Virtual Private Networks (VPNs): Secure Tunnels

VPNs encrypt all traffic between a device and a server. How it works:

  1. Client authenticates with VPN server (e.g., using a certificate or password).
  2. Server assigns a virtual IP (e.g., 10.8.0.5).
  3. All traffic is encrypted using IPsec or OpenVPN and routed through the VPN tunnel.

VPN Protocols Compared:

Protocol Encryption Port Use Case
PPTP Weak (MPPE) 1723 Legacy systems (e.g., old Ncell VPN).
L2TP/IPsec Strong (AES) 1701 Enterprise (e.g., NABIL Bank).
OpenVPN Configurable (AES) 1194 Consumer (e.g., Astrill VPN for Nepal).
WireGuard Modern (ChaCha20) 51820 Future-proof (used in Linux servers).

Real-world example:

  • Khalti’s mobile app uses a VPN-like tunnel to encrypt transactions between your phone and Khalti’s servers. Even if someone intercepts your Wi-Fi (e.g., at a café), they see only gibberish.

Web Security: HTTPS and Common Attacks

HTTPS: How Websites Stay Secure

HTTPS uses TLS/SSL to encrypt HTTP traffic. Handshake process:

sequenceDiagram
    participant Client as Browser
    participant Server as Website (e.g., esewa.com.np)
    Client->>Server: GET /login (unencrypted)
    Server->>Client: Sends SSL Certificate (includes public key)
    Client->>Client: Verifies certificate (checks CA signature)
    Client->>Server: Sends symmetric key encrypted with public key
    Server->>Client: Encrypts all further traffic with symmetric key
Intermediate CAServer Certificate (esewa.com.np)Root CA (e.g., DigiCert)Certificate Authority (CA)
Certificate chain of trust for HTTPS validation.

Certificate Validation Steps:

  1. Browser checks if the certificate is signed by a trusted CA (e.g., DigiCert).
  2. Verifies the domain name matches (e.g., esewa.com.np).
  3. Checks for expiry date and revocation status (via CRL/OCSP).

Common Web Attacks and Defenses

Attack How It Works Defense Mechanism Example in Nepal
MITM (Man-in-Middle) Attacker intercepts unencrypted traffic (e.g., HTTP) and alters it. Use HTTPS (e.g., Daraz’s checkout page). Café Wi-Fi snooping on unencrypted bank logins.
SQL Injection Injects SQL queries (e.g., ' OR '1'='1) to steal data. Use parameterized queries (e.g., PHP PDO). NEPSE’s old website was vulnerable in 2018.
XSS (Cross-Site Scripting) Injects malicious scripts into web pages. Content Security Policy (CSP) headers. Fake "You won a prize!" pop-ups on eSewa.
CSRF (Cross-Site Request Forgery) Forces users to execute actions (e.g., transfer money). Anti-CSRF tokens (e.g., in Khalti’s forms). Tricking a user into clicking a malicious link.
DDoS (Distributed Denial of Service) Overwhelms a server with traffic (e.g., botnets). Cloudflare or Akamai CDN. Ncell’s website crashes during sales.

Worked Example: SQL Injection on a Daraz Order Suppose an attacker targets Daraz’s "Forgot Password" feature with:

username=' OR '1'='1' --

Without defenses, the query becomes:

SELECT * FROM users WHERE username='' OR '1'='1' -- ' AND password='...'

→ Returns all users (including admins). Fix: Use parameterized queries:

cursor.execute("SELECT * FROM users WHERE username=?", (user_input,))

In the Real World

  1. eSewa’s Encrypted Transactions

    • Idea: HTTPS + TLS 1.3 encrypts all payment data between your phone and eSewa’s servers.
    • How: When you pay a bill, your phone and eSewa’s server perform a TLS handshake, then all data (amount, recipient) is encrypted with AES-256. Even if intercepted, the data is unreadable.
    • Real impact: In 2023, eSewa reported zero cases of payment data theft due to this encryption.
  2. Ncell’s Secure Mobile Banking

    • Idea: VPN + Biometric Authentication secures the Ncell Money app.
    • How: When you log in, your phone creates a VPN tunnel to Ncell’s servers. Then, the app requires fingerprint + OTP before allowing transactions. If someone steals your phone, they can’t access funds without both.
    • Real impact: Ncell’s fraud rate dropped by 40% after implementing this in 2022.
  3. NTC’s Firewall Against DDoS

    • Idea: Stateful Firewall + Rate Limiting protects NTC’s billing system.
    • How: NTC’s firewall tracks TCP connections (e.g., blocks more than 100 SYN packets/second from a single IP). During the 2021 monsoon outages, a DDoS attack hit NTC’s website, but the firewall absorbed the traffic while admins investigated.
    • Real impact: Downtime was limited to 2 minutes vs. 2 hours in previous attacks.

Exam Tip

This unit is heavily tested on:

  1. Protocol layers: Know which attacks target which layer (e.g., ARP spoofing = Data Link; SQLi = Application).
  2. HTTPS/TLS: Be able to draw the handshake and explain certificate validation. Memorize the 4 steps of the TLS handshake.
  3. Firewall rules: Given a scenario (e.g., "block all traffic to port 22 except from 192.168.1.100"), write the exact rule.
  4. Web attacks: For each attack (XSS, CSRF, SQLi), give:
    • How it works (1 sentence).
    • Real-world example (e.g., "NEPSE’s old site was vulnerable to SQLi").
    • Defense (e.g., "Use prepared statements").
  5. VPN vs. Firewall: Compare them in a table (who they protect, where they operate).
  6. Packet analysis: Given a Wireshark capture, identify:
    • The protocol (TCP/UDP/ICMP).
    • Flags (e.g., SYN, ACK).
    • Potential attack (e.g., "SYN flood if SYN > ACK").

Common pitfalls:

  • Confusing IDS (detects) and IPS (prevents).
  • Forgetting that UDP has no built-in security (used by DNS, VoIP).
  • Misremembering TLS 1.2 vs. 1.3 (e.g., 1.3 removes RSA key exchange).

Based on the TU BITM syllabus for Information Security (IT244), unit 8.

Discussion

Loading…