Networking and System AdministrationUnit 106 min read
Firewalls, Security Policies, Encryption & Threat Mitigation
Unit 10 of Networking and System Administration covers firewall types (hardware/software), security policies (ACLs, least privilege), encryption (symmetric/asymmetric), threat detection (IDS/IPS), and real-world attack scenarios like SQL injection and DDoS—with hands-on examples from Nepali banks, eSewa, and Ncell.
Core Concepts
1. Firewall Fundamentals
Firewalls act as barriers between trusted internal networks and untrusted external networks (e.g., the internet). They filter traffic based on predefined rules, protecting systems from unauthorized access.
Types of Firewalls
classDiagram
class PacketFilter {
+Filters based on IP/port
+Stateless
}
class StatefulInspection {
+Tracks connection state
+Dynamic port rules
}
class ProxyFirewall {
+Acts as intermediary
+Hides internal IPs
}
class NGFW {
+Deep packet inspection
+Application-aware
}
PacketFilter --> StatefulInspection : "Evolves into"
StatefulInspection --> ProxyFirewall : "Enhances with"
ProxyFirewall --> NGFW : "Modernizes into"How Firewalls Work
- Packet Filtering: Checks source/destination IP, port, and protocol (e.g., block all traffic to port 22 except from Ncell’s IP range).
- Stateful Inspection: Tracks active connections (e.g., allows return traffic for an established HTTP session).
- Application-Layer Filtering: Inspects payload (e.g., block SQL queries with
DROP TABLEin eSewa’s database).
Worked Example: Ncell’s Firewall Rules Ncell uses a stateful firewall to:
- Allow inbound traffic only on ports 80 (HTTP) and 443 (HTTPS) from global users.
- Block all outbound traffic to port 22 (SSH) except from its internal admin network.
- Log and alert on repeated failed login attempts (brute-force detection).
2. Security Policies
Security policies define rules for access control, authentication, and data protection.
Access Control Models
| Model | Description | Example in Nepal |
|---|---|---|
| MAC (Mandatory) | Access granted by system admin (e.g., military-grade systems). | NTC’s core network access. |
| DAC (Discretionary) | Owners control access (e.g., Linux file permissions). | Daraz seller’s inventory management. |
| RBAC (Role-Based) | Permissions tied to roles (e.g., "Manager" can approve orders). | Khalti’s admin vs. user roles. |
| ABAC (Attribute-Based) | Access based on attributes (e.g., time, location). | eSewa’s OTP validation for mobile users. |
Least Privilege Principle
- Definition: Users/groups get only the minimum permissions needed.
- Example: A Daraz delivery agent should not access customer billing data.
3. Encryption Techniques
Encryption protects data confidentiality and integrity.
Symmetric vs. Asymmetric Encryption
mindmap
root((Encryption))
Symmetric
"Same key for encryption/decryption"
"Faster, but key distribution issue"
Example: AES-256
Asymmetric
"Public/private key pairs"
"Slower, but secure key exchange"
Example: RSA, ECC
Hybrid
"Combines both (e.g., TLS)"
"Used in HTTPS, VPNs"Worked Example: eSewa’s Payment Security
- Symmetric Encryption (AES-256): Encrypts user payment data on the server.
- Asymmetric Encryption (RSA): Secures the symmetric key exchange between user and server.
- Hashing (SHA-256): Verifies data integrity (e.g., checking if a transaction log was tampered with).
4. Intrusion Detection and Prevention
- IDS (Intrusion Detection System): Monitors and alerts (e.g., Snort detecting a scan on port 3389).
- IPS (Intrusion Prevention System): Actively blocks threats (e.g., stopping a SQL injection attempt on NEPSE’s website).
Signature-Based vs. Anomaly-Based Detection
| Type | How It Works | Example |
|---|---|---|
| Signature-Based | Matches known attack patterns. | Blocking a known malware hash (e.g., Emotet). |
| Anomaly-Based | Detects deviations from normal traffic. | Alerting on sudden spikes in login attempts (e.g., Pathao driver app). |
5. Common Threats and Mitigations
| Threat | Description | Mitigation Strategy |
|---|---|---|
| SQL Injection | Malicious SQL queries (e.g., ' OR '1'='1). |
Use parameterized queries (e.g., PHP PDO). |
| DDoS | Overwhelming traffic (e.g., taking down a bank’s website). | Rate limiting + cloud scrubbing (e.g., AWS Shield). |
| Man-in-the-Middle | Eavesdropping on unencrypted traffic. | Use TLS/SSL (e.g., HTTPS for all eSewa transactions). |
| Phishing | Fake login pages (e.g., "Your Khalti account is locked!"). | Multi-factor authentication (MFA). |
Worked Example: Ncell’s DDoS Protection Ncell uses:
- Anycast Routing: Distributes traffic across multiple data centers.
- Behavioral Analysis: Flags traffic spikes from single IPs (e.g., blocking a botnet).
- Blackholing: Temporarily routes malicious traffic to a null route.
In the Real World
eSewa’s Security Stack
- Firewall: Cloud-based NGFW (e.g., Palo Alto) to block malicious IPs.
- Encryption: TLS 1.3 for all transactions + AES-256 for stored data.
- Threat Detection: SIEM (Security Information and Event Management) logs all login attempts.
Ncell’s Core Network
- Firewall Rules: Stateful inspection to allow only VoIP (SIP) and data traffic.
- IDS: Darktrace detects anomalies like a sudden increase in SMS gateway requests.
Daraz’s Payment Gateway
- PCI Compliance: Encrypts credit card data with 3D Secure (3DS) authentication.
- Rate Limiting: Blocks repeated failed payment attempts (mitigating brute-force).
Exam Tip
- Firewall Questions: Expect 2-3 marks on rule configurations (e.g., "Write a rule to block ICMP from 192.168.1.100").
- Encryption: Compare symmetric/asymmetric in 1 mark each (e.g., "Why does TLS use both?").
- Threats: Match threats to mitigations (e.g., "How would you stop a SQLi attack on a bank’s login page?").
- Diagrams: Draw a firewall rule table or encryption workflow (e.g., TLS handshake) for 5+ marks.
Based on the TU BITM syllabus for Networking and System Administration (IT271), unit 10.
Discussion
Loading…