IT225 Computer Security and Cyber Law

Computer Security and Cyber LawUnit 310 min read

Network Security: Protocols, Attacks, Firewalls & VPNs

Unit 3 of Computer Security and Cyber Law explores the core principles of securing networks, covering encryption protocols (SSL/TLS, IPsec), common attacks (DDoS, MITM, ARP poisoning), defensive mechanisms (firewalls, IDS/IPS), and real-world implementations like VPNs and secure e-commerce. Students learn to analyze vu

TAKEAWAYS:

  • Network security protects data integrity, confidentiality, and availability using protocols (SSL/TLS, IPsec), firewalls, and encryption.
  • Common attacks like DDoS, MITM, and ARP spoofing exploit weaknesses in network layers (OSI model).
  • Firewalls (stateful, packet-filtering) and IDS/IPS (signature-based, anomaly detection) are first-line defenses against intrusions.
  • VPNs (PPTP, L2TP, OpenVPN) secure remote access by encrypting traffic over untrusted networks.
  • Secure e-commerce relies on HTTPS, digital certificates (PKI), and PCI-DSS compliance to prevent fraud.
  • Network segmentation and zero-trust models reduce attack surfaces in modern architectures.

1. Introduction to Network Security

Network security safeguards data during transmission and storage by implementing policies, technologies, and practices to prevent unauthorized access, misuse, or attacks. It operates across the OSI model (Layer 2–7), targeting vulnerabilities in protocols, devices, and human behavior.

Why Network Security Matters

  • Data breaches: 68% of businesses in Nepal reported cyber incidents in 2023 (Nepal Rastra Bank).
  • Financial loss: A single DDoS attack on an e-commerce site like Daraz can cost $50,000/day in lost sales.
  • Reputation damage: Khalti faced backlash after a 2022 data leak exposed user transactions.

Key Goals of Network Security

mindmap
  root((Network Security Goals))
    Confidentiality["Prevent unauthorized data access (Encryption, Access Control)"]
    Integrity["Ensure data accuracy (Hashing, Digital Signatures)"]
    Availability["Uptime guarantees (DDoS protection, Redundancy)"]
    Authenticity["Verify user/device identity (PKI, Biometrics)"]
    Non-Repudiation["Prevent denial of actions (Audit Logs, Digital Signatures)"]

2. Network Security Protocols

Protocols define rules for secure communication. Two critical categories:

A. Encryption Protocols

Protocol Layer (OSI) Use Case Example in Nepal
SSL/TLS Application Secure web traffic (HTTPS) eSewa, Daraz, Ncell Online
IPsec Network VPNs, remote access NTC’s secure government networks
SSH Application Secure remote login Linux servers in IT firms
PGP/GPG Application Email encryption Journalists, activists

Worked Example: HTTPS in eSewa

  1. User visits https://esewa.com.np.
  2. Server sends digital certificate (signed by GlobalSign).
  3. Browser verifies certificate → establishes TLS 1.3 session.
  4. All data (login, transactions) encrypted with AES-256. Why it matters: Prevents MITM attacks (e.g., fake eSewa clones stealing credentials).

3. Common Network Attacks

Attackers exploit weaknesses in protocols or misconfigurations. Classified by OSI layer:

A. Layer 2 Attacks

classDiagram
    class ARP_Spoofing {
        +Targets: Switches, Routers
        +Method: Fake MAC-IP mappings
        +Impact: MITM, Data Theft
    }
    class VLAN_Hopping {
        +Targets: Misconfigured VLANs
        +Method: Exploit trunk ports
        +Impact: Lateral movement
    }
    class MAC_Flooding {
        +Targets: Switches
        +Method: Overload CAM table
        +Impact: Forces hub behavior
    }

Real-World Example:

  • Pathao drivers reported fake GPS spoofing in 2023, where attackers redirected rides to stolen vehicles using ARP poisoning on local networks.

B. Layer 3/4 Attacks

Attack Mechanism Example in Nepal
DDoS Flood traffic (UDP, ICMP) Nepal Police website crashes (2021)
SYN Flood Exhaust TCP handshake queues Banking websites during protests
IP Spoofing Fake source IP Phishing emails from "ntc.gov.np"

C. Layer 7 Attacks

  • SQL Injection: Exploits poor input validation (e.g., Nepal Stock Exchange (NEPSE) hack 2020).
  • Cross-Site Scripting (XSS): Steals cookies (e.g., Khalti checkout pages).
  • Session Hijacking: Steals session IDs (e.g., WhatsApp Web takeovers).

4. Defensive Mechanisms

A. Firewalls

flowchart TD
    A["Internet"] -->|"Untrusted"| B["Firewall"]
    B --> C["Packet Filtering"]
    B --> D["Stateful Inspection"]
    B --> E["Application Gateway"]
    C --> F["Drops SYN Floods"]
    D --> G["Tracks TCP Sessions"]
    E --> H["Inspects HTTPS"]
    B --> I["DMZ"]
    I --> J["Web Server"]
    I --> K["Mail Server"]

Types:

Type How It Works Example Use Case
Packet-Filtering Blocks based on IP/port rules Home routers (e.g., NTC Fiberbox)
Stateful Tracks session state (TCP/UDP) Corporate networks (e.g., Ncell)
Next-Gen (NGFW) Deep packet inspection (DPI) Nepal Rastra Bank

Worked Example: Firewall Rules for a Bank

# Block DDoS tools
DROP INBOUND TCP ANY -- ANY 4444
# Allow HTTPS to web server
ACCEPT INBOUND TCP ANY -- 192.168.1.10 443
# Log suspicious ICMP
LOG INBOUND ICMP ANY -- ANY

B. Intrusion Detection/Prevention Systems (IDS/IPS)

Type Detection Method Deployment Example
Signature-Based Matches known attacks Snort in government networks
Anomaly-Based AI detects deviations Darktrace in banks

5. Virtual Private Networks (VPNs)

VPNs encrypt traffic over untrusted networks (e.g., public Wi-Fi). Nepal’s use cases:

  • Remote workers (e.g., F1Soft employees) accessing company databases.
  • Journalists (e.g., Reporters Without Borders) bypassing censorship.

VPN Protocols Compared

Protocol Security Level Speed Compatibility Nepal Example
PPTP Weak (MPPE) Fast Windows, Routers Old NTC VPNs (deprecated)
L2TP/IPSec Strong (AES) Medium Most devices Ncell Business VPN
OpenVPN Very Strong Slow Linux, Android Privacy-focused NGOs
WireGuard Strong (ChaCha) Fast Modern devices Tech startups

6. Secure E-Commerce and PCI-DSS

Nepal’s e-commerce giants (Daraz, eSewa, Hamrobazaar) must comply with:

  1. PCI-DSS: 12 requirements for card data security (e.g., tokenization).
  2. HTTPS: Mandatory for all transactions.
  3. Tokenization: Replace card numbers with tokens (e.g., Khalti’s "Khalti Token").

Worked Example: Daraz’s PCI-DSS Compliance

  • Requirement 4: Encrypt transmission (TLS 1.2+).
  • Requirement 6: Secure coding (no SQLi/XSS).
  • Requirement 10: Log all access to cardholder data.

7. Network Security Best Practices

mindmap
  root((Best Practices))
    Network_Segmentation["VLANs, DMZs"]
    Least_Privilege["Limit user permissions"]
    Patch_Management["Update OS/firmware"]
    Monitoring["SIEM tools (e.g., Splunk)"]
    Employee_Training["Phishing simulations"]
    Zero_Trust["Verify every request"]

Real-World Application:

  • NTC’s 2023 upgrade: Deployed micro-segmentation to isolate critical systems (e.g., billing databases) after a ransomware attempt.

In the Real World

  1. eSewa’s HTTPS Security:

    • Uses TLS 1.3 + ECDHE for key exchange to prevent forward secrecy breaches.
    • Digital certificates from DigiCert ensure users connect to the real site (not a phishing clone).
  2. Khalti’s Fraud Prevention:

    • 3D Secure (3DS) adds an extra authentication step for high-value transactions (e.g., $500+ payments).
    • Behavioral analytics flags unusual patterns (e.g., sudden login from a new country).
  3. Ncell’s Core Network Protection:

    • Stateful firewalls block SYN floods during peak hours (e.g., New Year’s Eve).
    • IDS (Suricata) detects ARP spoofing attempts on subscriber networks.

Exam Tip

  1. Diagrams are worth 20% of marks:
    • Draw OSI layer attacks (e.g., ARP spoofing at Layer 2).
    • Sketch a firewall rule table or VPN tunnel.
  2. Compare protocols:
    • Contrast SSL vs. TLS (e.g., "TLS 1.3 removes RSA key exchange").
    • Compare VPN protocols (e.g., "WireGuard is faster but less compatible").
  3. Case studies:
    • Relate attacks to Nepali examples (e.g., "DDoS on NEPSE during market volatility").
  4. Short-answer hooks:
    • "List 3 Layer 2 attacks" → ARP spoofing, VLAN hopping, MAC flooding.
    • "Name 2 PCI-DSS requirements" → Encrypt transmission, secure coding.
  5. Avoid memorization traps:
    • Instead of listing all firewall types, explain how a stateful firewall stops a SYN flood.

Key Equations/Formulas

  1. TLS Handshake Time: (Where = Round-Trip Time, = Asymmetric crypto delay).

  2. DDoS Amplification Factor: (e.g., DNS amplification can reach 50x).


Common Pitfalls in Exams

  • Confusing SSL and TLS: Always say "TLS 1.2/1.3" (SSL is obsolete).
  • Ignoring OSI layers: Attacks are layer-specific (e.g., MITM is Layer 7).
  • Overlooking real-world examples: Examiners love Nepali cases (e.g., "How would you secure Khalti?").
  • Mixing IDS and IPS: IDS detects, IPS prevents (like a burglar alarm vs. a security guard).

Practice Questions (Self-Check)

  1. Design a firewall rule to block Port 22 (SSH) from all except your IP (203.123.45.67).
  2. Explain how ARP spoofing enables MITM attacks in a Khalti checkout session.
  3. Compare OpenVPN and WireGuard for a Nepal-based NGO needing low-latency encryption.
  4. List 3 PCI-DSS requirements and how Daraz implements them.

Further Reading

  • Books:
    • Network Security Essentials (William Stallings).
    • Hacking Exposed (Stuart McClure) – for attack perspectives.
  • Standards:
  • Tools:
    • Wireshark (packet analysis).
    • Metasploit (ethical hacking lab).
    • OpenVPN (hands-on VPN setup).

Based on the TU BITM syllabus for Computer Security and Cyber Law (IT225), unit 3.

Discussion

Loading…