IT225 Computer Security and Cyber Law

Computer Security and Cyber LawUnit 616 min read

Security Models & Policies: Frameworks, Access Control & Real-World Applications

Unit 6 of Computer Security and Cyber Law explores foundational security models (Bell-LaPadula, Biba, Clark-Wilson), access control mechanisms (MAC, DAC, RBAC), policy design principles, and their real-world applications in banking, e-commerce, and government systems. Students learn how to design secure systems, evalua

Core Concepts: Security Models and Policies

1. What Are Security Models?

Security models are mathematical frameworks that define rules for protecting assets (data, systems, networks) by controlling access, integrity, and confidentiality. They provide a structured way to design secure systems and evaluate their vulnerabilities.

Key Characteristics of Security Models

  • Formalized rules: Define what can be accessed, how, and by whom.
  • Policy enforcement: Guide administrators in configuring firewalls, encryption, and authentication.
  • Trade-offs: Balance security with usability (e.g., strict access control vs. convenience).
  • Compliance: Help meet legal requirements (e.g., Nepal’s Electronic Transactions Act 2063).

2. Major Security Models

Three models dominate modern security design: Bell-LaPadula (Confidentiality), Biba (Integrity), and Clark-Wilson (Integrity + Audit).

Comparison Table

Model Primary Goal Key Rules Example Use Case Weakness
Bell-LaPadula Confidentiality No read-up, no write-down (prevents unauthorized data access). Military classified files, bank databases. Ignores integrity (data tampering).
Biba Integrity No read-down, no write-up (prevents data corruption). Medical records, government reports. Overly restrictive for collaboration.
Clark-Wilson Integrity + Audit Separation of duties, well-formed transactions, auditing. E-commerce (Daraz order processing). Complex to implement.

Visual: Bell-LaPadula vs. Biba

graph LR
    A["Bell-LaPadula\n(Confidentiality)"] --> B["Prevents: Read-up\nWrite-down"]
    C["Biba\n(Integrity)"] --> D["Prevents: Read-down\nWrite-up"]
    B --> E["Example: Classified Docs\n(Secret → Top Secret)"]
    D --> F["Example: Medical Records\n(Unverified → Verified)"]

Why This Matters:

  • Bell-LaPadula is used in Nepal Rastra Bank (NRB) to protect financial data from unauthorized access.
  • Biba ensures NTC’s billing system cannot be tampered with by lower-level employees.
  • Clark-Wilson secures eSewa transactions by enforcing dual approval for payments.

3. Access Control Mechanisms

Security policies are enforced via access control models. The three primary types:

A. Mandatory Access Control (MAC)

  • Definition: Access is controlled by a central authority (e.g., system administrator).
  • Example: Military systems, government databases.
  • Pros: High security, enforces strict hierarchy.
  • Cons: Inflexible, user inconvenience.
Example: National Defense PlansClassified DocsTop SecretExample: NTC InfrastructureConfidential ProjectsSecretExample: NRB Audit DataInternal ReportsConfidentialSecurity LevelsRead: Low → HighWrite: High → LowClearance RulesMAC Hierarchy (Military-Grade)
Bell-LaPadula model applied to Nepali government systems

B. Discretionary Access Control (DAC)

  • Definition: Owners of resources (files, folders) decide who can access them.
  • Example: Personal files in Windows/Linux (chmod, chown).
  • Pros: Flexible, user-friendly.
  • Cons: Vulnerable to insider threats (e.g., an employee leaking data).

C. Role-Based Access Control (RBAC)

  • Definition: Access is granted based on roles (e.g., "Manager," "Cashier").
  • Example:
    • Pathao drivers can only access trip details, not user accounts.
    • Ncell employees have roles like "Technician," "Billing Officer," or "CEO."
  • Pros: Scalable, reduces administrative overhead.
  • Cons: Role misassignments can cause breaches.

Real-World Example: RBAC in Ncell

  • CEO: Full access to all systems.
  • Billing Officer: Can view customer data but not modify network settings.
  • Technician: Access only to troubleshooting tools.

Worked Example: If a Ncell technician tries to access a customer’s call records (a "Billing Officer" task), the system denies access because their role lacks permission. This prevents unauthorized data exposure.


4. Designing Security Policies

A security policy is a document outlining rules for protecting assets. Key steps to design one:

Step-by-Step Process

  1. Asset Identification

    • List critical assets (e.g., customer databases, source code, hardware).
    • Example: For Daraz, assets include order history, payment gateways, and inventory.
  2. Threat Analysis

    • Identify threats (e.g., hackers, insiders, natural disasters).
    • Example: Khalti faces threats like phishing (customer data theft) and DDoS attacks.
  3. Risk Assessment

    • Evaluate likelihood and impact of threats.
    • Use: Risk Matrix (Low/Medium/High risk).
  4. Policy Formulation

    • Define rules for:
      • Authentication (e.g., 2FA for eSewa).
      • Authorization (RBAC for NTC employees).
      • Audit Logging (tracking changes in NEPSE systems).
  5. Implementation & Enforcement

    • Deploy firewalls, encryption, and monitoring tools.
    • Example: Nepal Police Cyber Bureau enforces policies via legal frameworks.
  6. Review & Update

    • Regularly audit policies (e.g., after a breach like the 2021 Nepal Police data leak).

Visual: Policy Design Workflow

flowchart TD
    A["1. Identify Assets"] --> B["2. Analyze Threats"]
    B --> C["3. Assess Risks\n(Risk Matrix)"]
    C --> D["4. Formulate Policies\n(Rules, Roles, Controls)"]
    D --> E["5. Implement\n(Firewalls, Encryption, RBAC)"]
    E --> F["6. Enforce & Monitor\n(Audits, Logging)"]
    F --> G["7. Review & Update\n(After Incidents)"]

5. Common Security Policy Challenges

Challenge Example Solution
Overly Restrictive Policies Employees can’t collaborate. Use ABAC (Attribute-Based Access Control).
Insider Threats A Daraz employee leaks data. Separation of Duties (e.g., no single person approves payments).
Compliance Costs Meeting PCI-DSS for Khalti. Automate audits with tools like Splunk.
User Resistance Employees ignore password policies. Security Awareness Training (e.g., NTC’s cybersecurity workshops).

6. Real-World Applications

A. Banking: Nepal Rastra Bank (NRB) Security Model

  • Model Used: Bell-LaPadula (confidentiality) + Clark-Wilson (integrity for transactions).
  • How It Works:
    • No read-up: A teller cannot access a customer’s loan details without authorization.
    • Well-formed transactions: Every transfer requires dual approval (e.g., manager + system).
  • Result: Prevents fraud like the 2018 NMB Bank hack.

B. E-Commerce: Daraz’s Order Integrity

  • Model Used: Biba Integrity Model.
  • How It Works:
    • No write-up: A warehouse worker cannot modify order status to "Shipped" without system validation.
    • Audit logs: Every change is recorded (e.g., "Order #12345 status changed from ‘Processing’ to ‘Shipped’ by User ID 789").
  • Result: Prevents fake order cancellations or refund fraud.

C. Government: NTC’s Billing System

  • Model Used: RBAC + MAC.
  • How It Works:
    • Roles:
      • Customer Service: Can view bills but not modify rates.
      • Billing Officer: Can update rates but not access personal data.
    • MAC: Only authorized personnel can change tariffs.
  • Result: Prevents rate manipulation (e.g., a disgruntled employee lowering bills for friends).

Humans are both the weakest and strongest link in security:

  • Weaknesses:
    • Phishing: Employees clicking malicious links (e.g., 2020 Nepal Police email scam).
    • Password Reuse: Using "123456" for multiple accounts (common in Khalti breaches).
    • Social Engineering: Tricking staff into revealing credentials (e.g., "Your account is locked—call this number").
  • Strengths:
    • Multi-Factor Authentication (MFA): eSewa’s OTP system reduces fraud.
    • Security Awareness: NTC’s training on recognizing phishing emails.
    • Incident Reporting: Employees reporting suspicious activity (e.g., Ncell’s fraud detection team).

Visual: Human Error vs. Human Strength

mindmap
  root((Human Factors in Security))
    Weaknesses
      Phishing["Example: Fake 'NRB Loan' Email"]
      Passwords["Weak: 'password123'\nStrong: 'Nepal@2024#NTC'"]
      Social Engineering["Example: 'Call your bank—your card is blocked'"]
    Strengths
      MFA["eSewa OTP"]
      Training["NTC Cybersecurity Workshops"]
      Reporting["Ncell Fraud Hotline"]

Exam Tip: How to Score Full Marks

  1. Define Models Clearly
    • Always start with the primary goal (confidentiality/integrity) and key rules (e.g., "Bell-LaPadula prevents read-up").
    • Example Answer Start:

      *"The Bell-LaPadula model ensures confidentiality by enforcing two rules: (1) Simple Security Property (No Read-Up): A subject at a security level cannot read an object at a higher level. (2) Star Property (No Write-Down): A subject cannot write to an object at a lower level."*

2015 BSFirst NepaliCybersecurity Law enac2020 BSNCC established2023 BSNepal joinsBudapest Convention2024 BSMandatory MFA forall government systems
Key milestones in Nepali cybersecurity policy (helpful for exam context)
  1. Use Real-World Examples

    • Examiners love Nepali context. Tie models to:
      • Banks (NRB, NMB, Global IME).
      • E-commerce (Daraz, Sastodeal).
      • Government (NTC, Ncell, Nepal Police).
    • Example:

      "In Ncell’s system, the Biba model ensures that a technician cannot modify a customer’s call detail record (CDR) to a higher integrity level (e.g., marking a call as 'completed' when it was dropped). This prevents billing fraud."

  2. Compare Models in Tables

    • For questions like "Explain Bell-LaPadula and Biba with examples," use a 2-column table with:
      • Model Name | Goal | Rules | Example | Limitation.
  3. Policy Design Questions

    • Structure answers using the 6-step policy design workflow (above).
    • For "Design a security policy for a bank," include:
      • Assets: Customer data, transaction logs.
      • Threats: SQL injection, insider theft.
      • Controls: Firewalls, RBAC, encryption.
  4. Human Factors

    • Balance weaknesses (phishing, passwords) with strengths (MFA, training).
    • Example:

      "While humans are the weakest link due to password reuse (e.g., Khalti breaches), they are also the strongest link when MFA is enforced (e.g., eSewa’s OTP system), as it adds an extra layer of verification."

  5. Avoid Vague Answers

    • ❌ "Security models are important."
    • ✅ "The Clark-Wilson model enforces integrity in e-commerce by requiring separation of duties (e.g., Daraz’s order processing needs both a warehouse worker and a manager’s approval) and well-formed transactions (e.g., no order can be marked as 'delivered' without a valid tracking number)."

Past Exam Questions Solved

Q1: As a database security administrator, what factors do you consider while designing and implementing database security policy?

Answer: When designing a database security policy (e.g., for Nepal Stock Exchange (NEPSE)), consider:

  1. Data Classification

    • Label data by sensitivity (e.g., Public, Internal, Confidential).
    • Example: NEPSE’s shareholder data is confidential; market trends are public.
  2. Access Control Model

    • Use RBAC for roles like:
      • Analyst: Read-only access to historical data.
      • Trader: Can modify orders but not view personal data.
  3. Encryption

    • At rest: AES-256 for stored data.
    • In transit: TLS 1.3 for API calls.
  4. Audit Logging

    • Track all changes (e.g., "User ID 567 modified share price for Company X at 10:30 AM").
  5. Compliance

    • Meet Nepal’s Data Privacy Act 2075 and PCI-DSS (if handling payments).
  6. Backup & Recovery

    • Immutable backups (e.g., WORM storage) to prevent ransomware.

Visual:


Q2: Explain Biba Integrity Model with Example

Answer: The Biba Integrity Model ensures data integrity by preventing unauthorized modifications. It enforces two rules:

  1. Simple Integrity Axiom (No Read-Down)

    • A subject at a higher integrity level cannot read data from a lower level.
    • Example: A verified medical record (high integrity) cannot be read by an unverified entry (low integrity).
  2. Star Integrity Axiom (No Write-Up)

    • A subject cannot write to a higher integrity level.
    • Example: A NTC technician cannot modify a billing rate (high integrity) directly; changes must go through an approved workflow.

Real-World Example: NTC Billing System

  • Scenario: A technician tries to update a customer’s bill to reduce charges.
  • Biba Enforcement:
    • The system checks the technician’s integrity level (low).
    • The billing rate is at a higher integrity level (verified by finance).
    • Result: The update is blocked, preventing fraud.

Visual:

graph LR
    A["High Integrity\n(Verified Data)"] -->|"Cannot Read"| B["Low Integrity\n(Unverified Data)"]
    C["Low Integrity\n(User Input)"] -->|"Cannot Write"| D["High Integrity\n(Approved Rates)"]
    B -->|"Allowed"| E["Low Integrity\nLogs"]
    C -->|"Allowed"| F["Low Integrity\nDrafts"]

Answer:

Problem Description Example Mitigation
Buffer Overflow Writing beyond allocated memory, causing crashes or code execution. A Daraz login page crashes when a user enters a 1000-character password. Use input validation and safe functions (e.g., strncpy in C).
SQL Injection Malicious SQL queries inserted via input fields. Attacker enters ' OR '1'='1 in a login form to bypass authentication. Use prepared statements (e.g., PreparedStatement in Java).
Cross-Site Scripting (XSS) Injecting malicious scripts into web pages viewed by others. A Khalti user posts <script>stealCookies()</script> in a forum. Sanitize input and use Content Security Policy (CSP) headers.
Race Condition Unintended behavior due to improper handling of concurrent access. Two Ncell users book the same ticket simultaneously, but only one gets it. Use locks or atomic transactions (e.g., database transactions).

Answer: Humans are the weakest link due to:

  1. Cognitive Biases
    • Example: Employees ignore password expiry warnings (e.g., Nepal Police reusing passwords).
  2. Social Engineering
    • Example: A Pathao driver is tricked into installing malware via a fake "Bonus Earnings" SMS.
  3. Negligence
    • Example: Leaving a laptop with NTC login unlocked in a café.

Humans are the strongest link because:

  1. Multi-Factor Authentication (MFA)
    • Example: eSewa’s OTP system prevents unauthorized logins even if passwords are stolen.
  2. Security Awareness
    • Example: NTC’s training reduces phishing attacks by 40%.
  3. Incident Response
    • Example: Ncell employees reporting suspicious calls quickly.

Visual:

Weakest Link (Errors) (45%)Strongest Link (MFA/Training) (55%)
Nepal-specific data: Human error vs. proactive measures (2023)

Based on the TU BITM syllabus for Computer Security and Cyber Law (IT225), unit 6.

Discussion

Loading…