CSC416 Network Security

Network SecurityUnit 111 min read

Network Security Basics: Threats, Models, and Core Services

Unit 1 of Network Security introduces foundational concepts—defining security threats (e.g., eavesdropping, DoS), the OSI/TCP-IP security layers, core security services (confidentiality, integrity, availability), and real-world applications like eSewa’s encrypted transactions and Ncell’s SIM-based authentication. Learn

1. What is Network Security?

Network security protects data, devices, and systems from unauthorized access, misuse, or attacks during transmission or storage. It spans hardware, software, and policies to ensure:

  • Confidentiality: Only authorized users access data (e.g., bank PINs in eSewa).
  • Integrity: Data remains unaltered (e.g., Daraz order confirmations).
  • Availability: Systems operate without disruption (e.g., NTC’s network during peak hours).

Why it matters:

  • Nepal’s digital economy (Khalti, NEPSE) relies on secure transactions.
  • IoT devices (smart meters, traffic lights) are prime attack targets.
  • Regulations (e.g., Nepal’s Electronic Transactions Act 2008) mandate security.

2. Threats to Network Security

Threats exploit vulnerabilities in networks. Classify them by origin and type:

A. Classification of Threats

mindmap
  root((Network Threats))
    Passive
      Eavesdropping: Listening to traffic (e.g., Wi-Fi sniffing in cafes)
      Traffic Analysis: Inferring data patterns (e.g., Ncell call metadata)
    Active
      Interception: Altering data (e.g., MITM in Pathao rides)
      Fabrication: Injecting fake data (e.g., spoofed emails)
      Masquerading: Impersonating users (e.g., fake eSewa login pages)
    Insider
      Malicious: Employees leaking data (e.g., bank insider fraud)
      Negligent: Accidental breaches (e.g., unpatched servers)
    Physical
      Theft: Stealing hardware (e.g., routers from ISPs)
      Damage: Sabotage (e.g., cutting fiber cables)

B. Real-World Examples

  • eSewa: Uses TLS encryption to prevent eavesdropping on payment data.
  • Ncell: SIM-based authentication stops unauthorized SIM swaps.
  • Daraz: Rate-limiting prevents DoS attacks on checkout servers.

3. Security Services in Networks

Security services are functions that protect data. They map to the OSI model (see below):

A. Core Security Services

Service Definition Example in Nepal Protocol/Tool
Confidentiality Ensures data is readable only by intended recipients. Khalti’s end-to-end encryption for transfers. AES, TLS
Integrity Detects unauthorized data modification. NEPSE’s digital signatures for stock trades. HMAC, SHA-256
Availability Guarantees access to resources when needed. NTC’s redundant fiber routes to avoid outages. Load balancers, RAID
Authentication Verifies user/device identity. eSewa’s OTP + biometric login. Kerberos, OAuth
Non-repudiation Prevents denial of actions (e.g., "I didn’t send this email"). Bank transaction logs for disputes. Digital signatures

B. OSI Security Layers

Network security operates across all OSI layers. Below is a layered model with threats and protections:


4. Cryptography Basics: Symmetric vs. Asymmetric

Security relies on cryptographic algorithms to protect data.

A. Symmetric Encryption

  • Key Idea: Same key for encryption/decryption.
  • Example: AES (used in WhatsApp messages).
  • Worked Example:
    • Alice wants to send a secret message to Bob using AES-256.
    • They share a key K = "TU2024ExamKey!" (in reality, keys are 256-bit random strings).
    • Alice encrypts: Ciphertext = AES-256(Plaintext, K).
    • Bob decrypts: Plaintext = AES-256(Ciphertext, K).

B. Asymmetric Encryption

  • Key Idea: Public key (encrypt) + private key (decrypt).
  • Example: RSA (used in HTTPS handshakes).
  • Worked Example:
    • Alice sends Bob a message using Bob’s public key.
    • Bob decrypts with his private key.
    • Digital signatures: Alice signs with her private key; Bob verifies with her public key.

C. Hash Functions

  • Purpose: Generate fixed-size "digests" of data (e.g., passwords).
  • Example: SHA-256 (used in blockchain and Git).
  • Worked Example:
    • Hash of "password123" → 5e884898da28047151d0e56f8dc6292773603d0d6aabbdd62a11ef721d1542d8.
    • Used in eSewa’s password storage (never store plaintext passwords!).

5. Authentication Mechanisms

Authentication verifies identities. Common methods:

Method How It Works Example in Nepal Weakness
Passwords User provides a secret. eSewa login. Phishing, brute force.
OTP (One-Time Password) Temporary codes sent via SMS/email. Khalti transactions. SIM swapping attacks.
Biometrics Unique physical traits (fingerprint, face). Ncell’s face unlock. Spoofing (e.g., photos).
Multi-Factor (MFA) Combines ≥2 methods (e.g., password + OTP). Bank logins. Complexity for users.
Public Key (PKI) Digital certificates (e.g., Let’s Encrypt). HTTPS websites. Certificate revocation needed.

6. Security Attacks and Countermeasures

A. Common Attack Types

classDiagram
  class Attack {
    +name: String
    +description: String
    +countermeasure: String
  }
  class MITM {
    +description: Intercepts communication between A and B.
    +countermeasure: TLS/SSL, VPNs.
  }
  class DoS {
    +description: Floods a system to crash it.
    +countermeasure: Rate limiting, firewalls.
  }
  class Phishing {
    +description: Tricks users into revealing credentials.
    +countermeasure: User training, email filters.
  }
  Attack <|-- MITM
  Attack <|-- DoS
  Attack <|-- Phishing

B. Real-World Attack: MITM in Pathao

  • Scenario: A hacker sets up a rogue Wi-Fi hotspot ("PathaoFreeWiFi") near a busy street.
  • Attack:
    1. User connects to the hotspot.
    2. Hacker intercepts login credentials when the user opens the Pathao app.
    3. Hacker uses stolen credentials to ride for free or steal money.
  • Countermeasure: Use TLS (HTTPS) and VPNs to encrypt traffic.

7. Security Policies and Standards

A. Security Policies

  • Access Control: Who can access what (e.g., role-based access in banks).
  • Audit Logs: Track user actions (e.g., NTC’s network logs).
  • Incident Response: Steps to take after a breach (e.g., Nepal Rastra Bank’s guidelines).

B. Security Standards

Standard Purpose Example Use Case
ISO 27001 Information security management. Banks, government systems.
PCI DSS Secure credit card transactions. Khalti, Daraz payments.
NIST SP 800-53 U.S. security guidelines (adopted globally). Critical infrastructure.
GDPR Protects EU citizen data (applies to Nepalese companies handling EU data). Any app storing European user data.

In the Real World

  1. eSewa’s Encrypted Transactions

    • Idea Used: TLS 1.3 for confidentiality and integrity.
    • How: When you pay via eSewa, your card details are encrypted using AES-256 and RSA for the handshake. Even if a hacker intercepts the traffic, they can’t read it without the private key.
  2. Ncell’s SIM-Based Authentication

    • Idea Used: Challenge-Response Authentication (SIM cards store a unique key).
    • How: When you log into Ncell’s app, the server sends a challenge to your SIM. Your phone proves it has the SIM by responding correctly. This stops SIM swapping attacks.
  3. Daraz’s Order Queue Security

    • Idea Used: Priority Queues + Rate Limiting.
    • How: During sales, Daraz uses token buckets to limit how many orders a user can place per second. This prevents credit card fraud (where attackers try to buy items repeatedly with stolen cards).

Exam Tip

  1. Define Clearly: Start answers with precise definitions (e.g., "Network security is the practice of protecting data during transmission and storage using...").
  2. Layer Mapping: Always relate threats/services to the OSI model (e.g., "Firewalls operate at Layer 3/4...").
  3. Real-World Links: Connect theory to Nepalese examples (e.g., "Like Ncell’s SIM authentication, Kerberos uses...").
  4. Diagrams: Draw packet formats (e.g., IP header with security flags) or attack flows (e.g., MITM steps).
  5. Shortcuts for Full Marks:
    • For mutual authentication, describe Diffie-Hellman key exchange + digital signatures.
    • For security services, use the CIA triad (Confidentiality, Integrity, Availability) + authentication/non-repudiation.
    • For standards, name ISO 27001 and PCI DSS with one use case each.

Past Exam Question Trace: Q: "How is mutual authentication done using symmetric encryption?" A:

  1. Shared Secret: Alice and Bob pre-share a key K.
  2. Challenge-Response:
    • Alice sends Bob a random nonce N1.
    • Bob encrypts N1 with K and sends back E_K(N1).
    • Alice decrypts and verifies. If correct, Bob is authenticated.
  3. Repeat: Bob sends a new nonce N2 to Alice for her authentication. Visual: Use a sequence diagram of the steps.

Based on the TU BSc CSIT syllabus for Network Security (CSC416), unit 1.

Discussion

Loading…