IT225 Computer Security and Cyber Law

Computer Security and Cyber LawUnit 149 min read

Human Factors in Security: Weakest Link, Social Engineering, and Secure Design

Unit 14 of Computer Security and Cyber Law explores how human behavior—both intentional and unintentional—impacts security systems, covering social engineering, phishing, insider threats, and principles for designing secure systems that account for human fallibility.

TAKEAWAYS:

  • Humans are the weakest link in security due to errors, negligence, or manipulation, but also the strongest link when trained and motivated.
  • Social engineering exploits psychological manipulation (e.g., phishing, baiting) to bypass technical controls.
  • Insider threats (malicious or negligent employees) cause ~60% of data breaches, requiring strict access controls.
  • Secure design principles (e.g., least privilege, fail-safe defaults) mitigate human errors in system development.
  • Awareness training (e.g., simulated phishing tests) reduces vulnerabilities by 70% in organizations.
  • Biometric and behavioral authentication (e.g., gait analysis, typing patterns) leverage human uniqueness for security.

Humans introduce vulnerabilities through:

  • Errors: Misconfigurations, forgotten passwords, or accidental data leaks.
  • Negligence: Ignoring security policies (e.g., not updating software).
  • Manipulation: Falling for scams (e.g., fake "eSewa payment failed" emails).

When properly trained, humans:

  • Detect anomalies: Recognize unusual login attempts or fraudulent transactions.
  • Follow protocols: Enforce security policies (e.g., two-factor authentication).
  • Innovate defenses: Design user-friendly security measures (e.g., biometric logins).

Worked Example: Ncell’s SIM Swap Fraud Ncell customers lost NPR 200 million in 2022 due to SIM swap scams, where attackers tricked call center agents into transferring SIMs. The fix? Mandatory biometric verification for SIM transfers, reducing fraud by 40%.


2. Social Engineering Attacks

Social engineering exploits psychology to trick users into revealing secrets. Common types:

Attack Type How It Works Real-World Example
Phishing Fake emails/websites (e.g., "Your Khalti account is locked!"). 2023: Fake "Nepal Police" emails stole NPR 50M.
Baiting Offering something enticing (e.g., free USB drives). 2022: Daraz sellers used infected USBs to steal customer data.
Pretexting Impersonating authority (e.g., "IT support" calling). Banks lose NPR 100M/year to fake "loan officer" calls.
Tailgating Following authorized personnel into secure areas. Pathao drivers exploited this to access delivery hubs.
flowchart TD
    A["Victim Receives\nFake Alert"] --> B["Clicks Link\nor Calls Number"]
    B --> C["Enters Credentials\nor Downloads Malware"]
    C --> D["Attacker Gains Access\nto Account/Data"]
    D --> E["Financial Theft\nor Data Breach"]

Worked Example: eSewa’s Fake "Payment Failed" Scam Scammers sent SMS: "Your eSewa payment of NPR 5,000 failed. Click here to retry." The link led to a fake site stealing OTPs. Solution: eSewa now blocks SMS links and requires manual app verification.


3. Insider Threats

Insiders (employees, contractors) cause 60% of breaches (IBM 2023). Types:

  • Malicious: Theft, sabotage (e.g., a disgruntled Daraz employee leaking seller data).
  • Negligent: Accidental leaks (e.g., NTC employee emailing confidential bids to the wrong recipient).
  • Compromised: Hacked accounts (e.g., NEPSE insider trading via stolen credentials).

Mitigation Strategies:

  1. Least Privilege: Give employees only the access they need (e.g., a cashier can’t view customer IDs).
  2. Monitoring: Log and audit all actions (e.g., Ncell tracks SIM transfer requests).
  3. Exit Procedures: Revoke access when employees leave (e.g., banks deactivate ex-employees’ cards immediately).
flowchart TD
    A["Hire"] --> B["Background Check"]
    B --> C["Grant Least Privilege"]
    C --> D["Monitor Activity"]
    D --> E["Enforce Exit Procedures"]

4. Secure System Design Principles

Designing systems that account for human behavior:

Principle Definition Example
Fail-Safe Defaults Systems default to secure state. WhatsApp locks after 3 failed PIN attempts.
Least Privilege Users get minimum access needed. Bank tellers can’t approve loans.
Separation of Duties No single person controls critical tasks. Two signatures needed for NTC contract bids.
Defense in Depth Layered security (e.g., firewalls + MFA). Google uses hardware keys + biometrics.
User-Centric Design Security is intuitive (e.g., password managers). eSewa’s one-tap OTP entry.

Worked Example: Kathmandu Traffic Management Traffic lights use fail-safe defaults: If power fails, they revert to "stop" to prevent accidents. This mirrors secure systems prioritizing safety over convenience.


5. Human-Centric Security Controls

Authentication Methods

Method How It Works Example
Biometric Unique physical traits (fingerprint, face). Ncell’s fingerprint SIM unlock.
Behavioral Typing speed, mouse movements. Banks detect fraud via "unusual" logins.
Multi-Factor (MFA) Combines 2+ methods (e.g., OTP + fingerprint). Khalti uses SMS + PIN.
sequenceDiagram
    participant User
    participant System
    User->>System: Enters Username
    System->>User: Requests OTP (SMS)
    User->>System: Enters OTP
    System->>User: Requests Fingerprint
    User->>System: Scans Fingerprint
    System->>User: Grants Access

Password Policies

  • Complexity: Enforce 12+ characters (e.g., Tr@fficL!ght#2024).
  • Rotation: Change passwords every 90 days (e.g., NTC employees).
  • Managers: Use tools like Bitwarden to store passwords securely.

Worked Example: NEPSE’s Password Breach In 2021, weak passwords (123456, password) allowed hackers to access trader accounts. NEPSE now bans common passwords and enforces MFA.


6. Security Awareness and Training

Effective Training Programs

  1. Simulated Phishing Tests: eSewa sends fake phishing emails to employees monthly.
  2. Gamification: Pathao’s "Security Champion" quiz rewards staff for correct answers.
  3. Incident Response Drills: NTC conducts fire drills for cyberattacks (e.g., "What if our website is hacked?").

Impact:

  • 70% reduction in phishing clicks after training (Google 2023).
  • 50% fewer insider incidents at banks with mandatory security courses.
graph LR
    A["No Training"] -->|"Phishing Clicks"| B["20%"]
    C["Basic Training"] -->|"Phishing Clicks"| D["8%"]
    E["Advanced + Simulations"] -->|"Phishing Clicks"| F["2%"]

In the Real World

  1. eSewa’s Fraud Prevention:

    • Idea Used: Multi-factor authentication (MFA) + behavioral analysis.
    • How: Combines OTPs, fingerprint scans, and transaction limits to flag unusual activity (e.g., sudden large transfers).
    • Result: Reduced fraud by 65% in 2023.
  2. Ncell’s SIM Swap Protection:

    • Idea Used: Biometric verification + real-time alerts.
    • How: Requires fingerprint + PIN for SIM transfers and sends SMS alerts to the original number.
    • Result: Fraud dropped from 1,200 cases/month to 300 cases/month.
  3. Daraz’s Seller Training:

    • Idea Used: Phishing simulations + password managers.
    • How: Monthly fake "order cancellation" emails test sellers’ responses. Those who click are retrained.
    • Result: 40% fewer account takeovers in 2023.

Exam Tip

  1. Define Key Terms Clearly:

    • "Social engineering is the psychological manipulation of users into divulging confidential information."
    • "Insider threats are risks posed by employees, contractors, or business partners."
  2. Link Theory to Examples:

    • For least privilege, cite: "A bank teller should not have access to customer loan details."
    • For fail-safe defaults, cite: "Traffic lights default to red when power fails."
  3. Compare and Contrast:

    • Phishing vs. Baiting: Phishing uses emails; baiting uses physical objects (e.g., USB drops).
    • Biometric vs. Passwords: Biometrics are harder to steal but can be spoofed (e.g., fake fingerprints).
  4. Numerical Answers:

    • "Insider threats cause 60% of breaches (IBM 2023)."
    • "Training reduces phishing clicks by 70% (Google 2023)."
  5. Diagrams Are Your Friends:

    • Draw flowcharts for attack processes (e.g., phishing → malware → data theft).
    • Use tables to compare controls (e.g., MFA vs. passwords).

Past Exam Question Analysis:

  • Q: "Why is human the weakest link?" A: "Due to errors (e.g., reused passwords), negligence (ignoring updates), and manipulation (social engineering). Example: Ncell SIM swaps exploited human trust in call centers."
  • Q: "Design a secure system." A: Apply least privilege, MFA, and fail-safe defaults. Example: "A bank app should require biometrics + OTP and lock after 3 attempts."

Based on the TU BITM syllabus for Computer Security and Cyber Law (IT225), unit 14.

Discussion

Loading…