Computer Security and Cyber LawUnit 310 min read
Network Security: Protocols, Attacks, Firewalls & VPNs
Unit 3 of Computer Security and Cyber Law explores the core principles of securing networks, covering encryption protocols (SSL/TLS, IPsec), common attacks (DDoS, MITM, ARP poisoning), defensive mechanisms (firewalls, IDS/IPS), and real-world implementations like VPNs and secure e-commerce. Students learn to analyze vu
TAKEAWAYS:
- Network security protects data integrity, confidentiality, and availability using protocols (SSL/TLS, IPsec), firewalls, and encryption.
- Common attacks like DDoS, MITM, and ARP spoofing exploit weaknesses in network layers (OSI model).
- Firewalls (stateful, packet-filtering) and IDS/IPS (signature-based, anomaly detection) are first-line defenses against intrusions.
- VPNs (PPTP, L2TP, OpenVPN) secure remote access by encrypting traffic over untrusted networks.
- Secure e-commerce relies on HTTPS, digital certificates (PKI), and PCI-DSS compliance to prevent fraud.
- Network segmentation and zero-trust models reduce attack surfaces in modern architectures.
1. Introduction to Network Security
Network security safeguards data during transmission and storage by implementing policies, technologies, and practices to prevent unauthorized access, misuse, or attacks. It operates across the OSI model (Layer 2–7), targeting vulnerabilities in protocols, devices, and human behavior.
Why Network Security Matters
- Data breaches: 68% of businesses in Nepal reported cyber incidents in 2023 (Nepal Rastra Bank).
- Financial loss: A single DDoS attack on an e-commerce site like Daraz can cost $50,000/day in lost sales.
- Reputation damage: Khalti faced backlash after a 2022 data leak exposed user transactions.
Key Goals of Network Security
mindmap
root((Network Security Goals))
Confidentiality["Prevent unauthorized data access (Encryption, Access Control)"]
Integrity["Ensure data accuracy (Hashing, Digital Signatures)"]
Availability["Uptime guarantees (DDoS protection, Redundancy)"]
Authenticity["Verify user/device identity (PKI, Biometrics)"]
Non-Repudiation["Prevent denial of actions (Audit Logs, Digital Signatures)"]2. Network Security Protocols
Protocols define rules for secure communication. Two critical categories:
A. Encryption Protocols
| Protocol | Layer (OSI) | Use Case | Example in Nepal |
|---|---|---|---|
| SSL/TLS | Application | Secure web traffic (HTTPS) | eSewa, Daraz, Ncell Online |
| IPsec | Network | VPNs, remote access | NTC’s secure government networks |
| SSH | Application | Secure remote login | Linux servers in IT firms |
| PGP/GPG | Application | Email encryption | Journalists, activists |
Worked Example: HTTPS in eSewa
- User visits
https://esewa.com.np. - Server sends digital certificate (signed by GlobalSign).
- Browser verifies certificate → establishes TLS 1.3 session.
- All data (login, transactions) encrypted with AES-256. Why it matters: Prevents MITM attacks (e.g., fake eSewa clones stealing credentials).
3. Common Network Attacks
Attackers exploit weaknesses in protocols or misconfigurations. Classified by OSI layer:
A. Layer 2 Attacks
classDiagram
class ARP_Spoofing {
+Targets: Switches, Routers
+Method: Fake MAC-IP mappings
+Impact: MITM, Data Theft
}
class VLAN_Hopping {
+Targets: Misconfigured VLANs
+Method: Exploit trunk ports
+Impact: Lateral movement
}
class MAC_Flooding {
+Targets: Switches
+Method: Overload CAM table
+Impact: Forces hub behavior
}Real-World Example:
- Pathao drivers reported fake GPS spoofing in 2023, where attackers redirected rides to stolen vehicles using ARP poisoning on local networks.
B. Layer 3/4 Attacks
| Attack | Mechanism | Example in Nepal |
|---|---|---|
| DDoS | Flood traffic (UDP, ICMP) | Nepal Police website crashes (2021) |
| SYN Flood | Exhaust TCP handshake queues | Banking websites during protests |
| IP Spoofing | Fake source IP | Phishing emails from "ntc.gov.np" |
C. Layer 7 Attacks
- SQL Injection: Exploits poor input validation (e.g., Nepal Stock Exchange (NEPSE) hack 2020).
- Cross-Site Scripting (XSS): Steals cookies (e.g., Khalti checkout pages).
- Session Hijacking: Steals session IDs (e.g., WhatsApp Web takeovers).
4. Defensive Mechanisms
A. Firewalls
flowchart TD
A["Internet"] -->|"Untrusted"| B["Firewall"]
B --> C["Packet Filtering"]
B --> D["Stateful Inspection"]
B --> E["Application Gateway"]
C --> F["Drops SYN Floods"]
D --> G["Tracks TCP Sessions"]
E --> H["Inspects HTTPS"]
B --> I["DMZ"]
I --> J["Web Server"]
I --> K["Mail Server"]Types:
| Type | How It Works | Example Use Case |
|---|---|---|
| Packet-Filtering | Blocks based on IP/port rules | Home routers (e.g., NTC Fiberbox) |
| Stateful | Tracks session state (TCP/UDP) | Corporate networks (e.g., Ncell) |
| Next-Gen (NGFW) | Deep packet inspection (DPI) | Nepal Rastra Bank |
Worked Example: Firewall Rules for a Bank
# Block DDoS tools
DROP INBOUND TCP ANY -- ANY 4444
# Allow HTTPS to web server
ACCEPT INBOUND TCP ANY -- 192.168.1.10 443
# Log suspicious ICMP
LOG INBOUND ICMP ANY -- ANY
B. Intrusion Detection/Prevention Systems (IDS/IPS)
| Type | Detection Method | Deployment Example |
|---|---|---|
| Signature-Based | Matches known attacks | Snort in government networks |
| Anomaly-Based | AI detects deviations | Darktrace in banks |
5. Virtual Private Networks (VPNs)
VPNs encrypt traffic over untrusted networks (e.g., public Wi-Fi). Nepal’s use cases:
- Remote workers (e.g., F1Soft employees) accessing company databases.
- Journalists (e.g., Reporters Without Borders) bypassing censorship.
VPN Protocols Compared
| Protocol | Security Level | Speed | Compatibility | Nepal Example |
|---|---|---|---|---|
| PPTP | Weak (MPPE) | Fast | Windows, Routers | Old NTC VPNs (deprecated) |
| L2TP/IPSec | Strong (AES) | Medium | Most devices | Ncell Business VPN |
| OpenVPN | Very Strong | Slow | Linux, Android | Privacy-focused NGOs |
| WireGuard | Strong (ChaCha) | Fast | Modern devices | Tech startups |
6. Secure E-Commerce and PCI-DSS
Nepal’s e-commerce giants (Daraz, eSewa, Hamrobazaar) must comply with:
- PCI-DSS: 12 requirements for card data security (e.g., tokenization).
- HTTPS: Mandatory for all transactions.
- Tokenization: Replace card numbers with tokens (e.g., Khalti’s "Khalti Token").
Worked Example: Daraz’s PCI-DSS Compliance
- Requirement 4: Encrypt transmission (TLS 1.2+).
- Requirement 6: Secure coding (no SQLi/XSS).
- Requirement 10: Log all access to cardholder data.
7. Network Security Best Practices
mindmap
root((Best Practices))
Network_Segmentation["VLANs, DMZs"]
Least_Privilege["Limit user permissions"]
Patch_Management["Update OS/firmware"]
Monitoring["SIEM tools (e.g., Splunk)"]
Employee_Training["Phishing simulations"]
Zero_Trust["Verify every request"]Real-World Application:
- NTC’s 2023 upgrade: Deployed micro-segmentation to isolate critical systems (e.g., billing databases) after a ransomware attempt.
In the Real World
eSewa’s HTTPS Security:
- Uses TLS 1.3 + ECDHE for key exchange to prevent forward secrecy breaches.
- Digital certificates from DigiCert ensure users connect to the real site (not a phishing clone).
Khalti’s Fraud Prevention:
- 3D Secure (3DS) adds an extra authentication step for high-value transactions (e.g., $500+ payments).
- Behavioral analytics flags unusual patterns (e.g., sudden login from a new country).
Ncell’s Core Network Protection:
- Stateful firewalls block SYN floods during peak hours (e.g., New Year’s Eve).
- IDS (Suricata) detects ARP spoofing attempts on subscriber networks.
Exam Tip
- Diagrams are worth 20% of marks:
- Draw OSI layer attacks (e.g., ARP spoofing at Layer 2).
- Sketch a firewall rule table or VPN tunnel.
- Compare protocols:
- Contrast SSL vs. TLS (e.g., "TLS 1.3 removes RSA key exchange").
- Compare VPN protocols (e.g., "WireGuard is faster but less compatible").
- Case studies:
- Relate attacks to Nepali examples (e.g., "DDoS on NEPSE during market volatility").
- Short-answer hooks:
- "List 3 Layer 2 attacks" → ARP spoofing, VLAN hopping, MAC flooding.
- "Name 2 PCI-DSS requirements" → Encrypt transmission, secure coding.
- Avoid memorization traps:
- Instead of listing all firewall types, explain how a stateful firewall stops a SYN flood.
Key Equations/Formulas
TLS Handshake Time: (Where = Round-Trip Time, = Asymmetric crypto delay).
DDoS Amplification Factor: (e.g., DNS amplification can reach 50x).
Common Pitfalls in Exams
- Confusing SSL and TLS: Always say "TLS 1.2/1.3" (SSL is obsolete).
- Ignoring OSI layers: Attacks are layer-specific (e.g., MITM is Layer 7).
- Overlooking real-world examples: Examiners love Nepali cases (e.g., "How would you secure Khalti?").
- Mixing IDS and IPS: IDS detects, IPS prevents (like a burglar alarm vs. a security guard).
Practice Questions (Self-Check)
- Design a firewall rule to block Port 22 (SSH) from all except your IP (203.123.45.67).
- Explain how ARP spoofing enables MITM attacks in a Khalti checkout session.
- Compare OpenVPN and WireGuard for a Nepal-based NGO needing low-latency encryption.
- List 3 PCI-DSS requirements and how Daraz implements them.
Further Reading
- Books:
- Network Security Essentials (William Stallings).
- Hacking Exposed (Stuart McClure) – for attack perspectives.
- Standards:
- PCI-DSS 4.0
- NIST SP 800-41 (Recommended Security Practices).
- Tools:
- Wireshark (packet analysis).
- Metasploit (ethical hacking lab).
- OpenVPN (hands-on VPN setup).
Based on the TU BITM syllabus for Computer Security and Cyber Law (IT225), unit 3.
Discussion
Loading…