CryptographyUnit 812 min read
Network Security & Protocols: CIA Triad, IPSec, SSL/TLS, Kerberos, Attacks & Real-World Apps
Unit 8 of Cryptography explores how cryptographic protocols secure networks, covering the CIA triad, IPSec, SSL/TLS, Kerberos, authentication systems, and common attacks like MITM. It ties theory to real-world systems (eSewa, WhatsApp, Ncell) and includes hands-on examples like encrypting a Daraz order or analyzing a N
TAKEAWAYS:
- The CIA triad (Confidentiality, Integrity, Availability) defines core security goals, while protocols like IPSec and SSL/TLS enforce them in practice.
- IPSec (AH + ESP) secures IP traffic via authentication headers and encrypted payloads, while SSL/TLS (handshake → symmetric session) protects web apps like eSewa.
- Kerberos uses ticket-based authentication to prevent replay attacks in systems like Ncell’s internal networks.
- Attacks (MITM, meet-in-the-middle) exploit protocol weaknesses; countermeasures include digital signatures and perfect forward secrecy.
- Message Authentication Codes (MACs) and hash functions (MD4/MD5) verify data integrity, critical for bank transactions or NEPSE trades.
- Real-world layered security (e.g., WhatsApp’s end-to-end encryption + transport-layer TLS) combines multiple protocols for defense-in-depth.
Core Concepts: The CIA Triad and Security Services
Security is not a single tool but a layered framework built on three pillars: Confidentiality, Integrity, and Availability (the CIA triad). These principles guide every protocol and mechanism in network security.
The CIA Triad
mindmap
root((CIA Triad))
Confidentiality["Prevents unauthorized access\n* Encryption (AES, RSA)\n* Access controls (firewalls, ACLs)"]
Integrity["Ensures data is unaltered\n* Hash functions (SHA-256)\n* Digital signatures (ECDSA)\n* Checksums (CRC)"]
Availability["Guarantees system uptime\n* Redundancy (load balancers)\n* DDoS protection (rate limiting)\n* Backup systems"]Why it matters:
- eSewa uses confidentiality (TLS 1.3) to encrypt user payments.
- NEPSE relies on integrity (blockchain-like digests) to prevent trade manipulation.
- Ncell’s network prioritizes availability with redundant towers to avoid outages.
Protocol Deep Dive: IPSec (Internet Protocol Security)
IPSec is a suite of protocols (AH, ESP, IKE) that secures IP-layer communication, often used in VPNs or government networks (e.g., NTC’s backbone).
How IPSec Works
- Authentication Header (AH): Verifies packet origin via HMAC (hash-based MAC).
- Encapsulating Security Payload (ESP): Encrypts packet payload (e.g., with AES).
- Internet Key Exchange (IKE): Establishes secure keys via Diffie-Hellman + digital signatures.
Real-World Example:
- NTC’s fiber-optic network uses IPSec to protect data between regional offices, ensuring confidentiality (ESP) and integrity (AH).
- Worked Example: Encrypting a Daraz order (IP packet) with ESP:
Original Packet: [IP Header][Order Data: "UserID=123, Item=Laptop"] ESP-Encrypted: [IP Header][ESP Header][AES-256(Order Data)][MAC]
IPSec Modes
| Mode | Description | Use Case |
|---|---|---|
| Transport | Encrypts only payload (not outer IP header). | Host-to-host (e.g., bank servers). |
| Tunnel | Encrypts entire IP packet + new outer header (for VPNs). | Site-to-site (e.g., Ncell HQ → towers). |
Advantages:
- Works at network layer (OSI Layer 3), transparent to apps.
- Supports both authentication and encryption.
Disadvantages:
- Complexity: Requires manual key management (IKEv2 helps).
- Performance overhead: ~10–20% latency increase.
SSL/TLS: Securing the Web (eSewa, WhatsApp, Google)
SSL/TLS is the de facto standard for securing web traffic (HTTPS) and apps (WhatsApp, Khalti). It uses asymmetric cryptography (RSA/ECC) for key exchange and symmetric cryptography (AES) for bulk data.
TLS Handshake (Simplified)
sequenceDiagram
participant C as Client (e.g., Browser)
participant S as Server (e.g., eSewa)
C->>S: ClientHello (Supported Ciphers)
S->>C: ServerHello + Certificate (CA-signed)
C->>S: PreMasterSecret (RSA-encrypted)
S->>C: Session Key (Symmetric, e.g., AES-256)
C->>S: Finished (MAC of handshake)
S->>C: FinishedKey Steps:
- Certificate Validation: Server proves identity via a CA-signed certificate (e.g., Let’s Encrypt for Daraz).
- Key Exchange: Client and server derive a symmetric session key (ECDHE for forward secrecy).
- Session Establishment: Data encrypted with AES-GCM.
Real-World Example:
- WhatsApp uses TLS for server-to-server communication (e.g., Nepal → Singapore data centers).
- Khalti uses TLS 1.3 to encrypt payment tokens during checkout.
TLS vs. IPSec
| Feature | TLS | IPSec |
|---|---|---|
| Layer | Application/Transport (5–7) | Network (3) |
| Use Case | Web (HTTPS), APIs | VPNs, IPsec tunnels |
| Key Exchange | RSA/ECDHE | IKE (DH + signatures) |
| Performance | Lower latency (no IP overhead) | Higher overhead (tunneling) |
Authentication Protocols: Kerberos (Ncell, Banks)
Kerberos is a ticket-based authentication system used in enterprise networks (e.g., Ncell’s internal systems, bank ATMs) to prevent replay attacks.
How Kerberos Works
sequenceDiagram
participant U as User
participant AS as Authentication Server
participant TGS as Ticket Granting Server
participant S as Service (e.g., Ncell Database)
U->>AS: Request TGT (Timestamp + ID)
AS->>U: TGT (Encrypted with K_user)
U->>TGS: TGT + Service Request
TGS->>U: Service Ticket (Encrypted with K_service)
U->>S: Service Ticket + Authenticator
S->>U: Access GrantedKey Components:
- Ticket Granting Ticket (TGT): Short-lived credential from AS.
- Service Ticket: Grants access to a specific service (e.g., Ncell’s billing system).
- Session Key: Derived from TGT for service communication.
Why Kerberos?
- No password transmission: Avoids MITM attacks on login credentials.
- Time-stamped tickets: Prevents replay attacks (critical for bank transactions).
Real-World Example:
- Ncell’s internal network uses Kerberos to authenticate employees accessing the billing database, ensuring only authorized staff can process data.
Attacks on Protocols: MITM and Meet-in-the-Middle
Even secure protocols can be broken if misconfigured. Two classic attacks:
1. Man-in-the-Middle (MITM) Attack on Diffie-Hellman
Scenario: Alice and Bob exchange keys over an untrusted network (e.g., public Wi-Fi at a café). Attack:
sequenceDiagram
participant A as Alice
participant M as Mallory (Attacker)
participant B as Bob
A->>M: Public Key (g^a mod p)
M->>B: Public Key (g^c mod p) # Mallory's fake key
B->>M: Public Key (g^b mod p)
M->>A: Public Key (g^c mod p) # Mallory's fake key
M->>M: Computes Shared Keys (g^bc mod p)
M->>A: Decrypts Alice's Traffic
M->>B: Decrypts Bob's TrafficWorked Example (from past exam):
- Given: Prime p = 19, root g = 10, Alice’s private a = 5, Mallory’s random c = 4.
- Alice’s public: .
- Bob’s public: (unknown to Mallory).
- Mallory’s shared key: (computed after intercepting Bob’s public key).
Countermeasure: Use Ephemeral Diffie-Hellman (ECDHE) with forward secrecy.
2. Meet-in-the-Middle Attack on Symmetric Ciphers
Scenario: Attacker precomputes possible keys to crack a double-encrypted message (e.g., Playfair cipher with two passes). Example:
- Message: "INFORMATION" encrypted twice with keyword "SECURITY".
- Attack: Precompute all possible first-key encryptions, then decrypt with second key.
Countermeasure: Use stronger ciphers (AES-256) or salting.
Message Authentication Codes (MACs) and Hash Functions
MACs and hashes verify data integrity and authenticate senders.
MACs in Action
- HMAC-SHA256 is used in IPSec (AH) and TLS to ensure packets/messages aren’t tampered with.
- Example: eSewa uses HMAC to sign transaction IDs before sending to banks.
Hash Functions: MD4 vs. MD5 vs. SHA-256
| Algorithm | Output Size | Collision Resistance | Use Case |
|---|---|---|---|
| MD4 | 128-bit | Broken (easy collisions) | Legacy systems (avoid!) |
| MD5 | 128-bit | Broken (e.g., MD5 hash collisions) | Avoid in security! |
| SHA-256 | 256-bit | Strong | TLS, Bitcoin, NEPSE trades |
Worked Example: Computing MD4 digest for "NEPSE":
- Pad input to 512-bit blocks.
- Process in three passes (rounds of bitwise ops + constants).
- Final hash:
5d41402abc4b2a76b9719d911017c592(truncated for brevity).
In the Real World
eSewa:
- Protocol: TLS 1.3 (for HTTPS) + HMAC-SHA256 (for transaction signing).
- How: When you pay a bill, eSewa encrypts your bank details with AES-256 and signs the transaction with a private key (only eSewa knows). The bank verifies the MAC to ensure no tampering.
WhatsApp:
- Protocol: Signal Protocol (X3DH key exchange) + AES-256 for messages.
- How: When you send a message to a friend, WhatsApp generates a one-time key pair, exchanges it securely, and encrypts the message. Even if Ncell intercepts the traffic, they can’t decrypt it (forward secrecy).
NEPSE (Nepal Stock Exchange):
- Protocol: Blockchain-like digests (SHA-256) + digital signatures.
- How: Every trade is hashed and signed by the exchange. If someone tries to alter a trade record, the hash mismatches, exposing fraud.
Ncell’s Network:
- Protocol: IPSec (ESP mode) between towers + Kerberos for internal auth.
- How: Data from your phone to Ncell’s server is encrypted with AES-256 (ESP). Only authorized staff can access the billing system via Kerberos tickets.
Exam Tip
- CIA Triad: Always define all three components (Confidentiality, Integrity, Availability) with one example each (e.g., "AES for confidentiality, HMAC for integrity, load balancers for availability").
- Protocols:
- IPSec: Draw the AH vs. ESP table and explain IKE phases.
- TLS: Sketch the handshake diagram and mention forward secrecy (ECDHE).
- Kerberos: Explain TGT vs. Service Ticket and why it’s replay-resistant.
- Attacks:
- MITM on DH: Show the sequence diagram with Mallory intercepting.
- Meet-in-the-middle: Relate to double encryption (e.g., Playfair cipher).
- MACs/Hashes:
- Compare MD5 (broken) vs. SHA-256 (secure).
- For MD4 passes, mention three rounds (but don’t derive full hash—examiners want the process, not the output).
- Real-World Links:
- eSewa → TLS + HMAC.
- WhatsApp → Signal Protocol + AES.
- NEPSE → SHA-256 digests.
- Ncell → IPSec + Kerberos.
Avoid:
- Describing RSA encryption (Unit 5 topic).
- Going into AES internals (Unit 4).
- Forgetting layer numbers (e.g., TLS is Layer 5–7, IPSec is Layer 3).
Based on the TU BSc CSIT syllabus for Cryptography (CSC316), unit 8.
Discussion
Loading…