Network SecurityUnit 1110 min read
Security Standards & Protocols: Frameworks, TLS, SSH, IPSec, Cloud & IoT
Unit 11 of Network Security explores standardized security frameworks (ISO/IEC 27001, NIST, PCI-DSS), core protocols (TLS 1.3, SSH, IPSec), cloud security models (SaaS/PaaS/IaaS), and IoT security challenges. It compares encryption protocols (TKIP vs CCMP), traces TLS handshakes, and analyzes real-world risks in eSewa/
Core Concepts: What Are Security Standards and Protocols?
1. Definitions and Purpose
Security standards are formalized guidelines (e.g., ISO/IEC 27001, NIST SP 800-53) that define best practices for protecting systems. They ensure interoperability, compliance, and risk mitigation across organizations. Security protocols are rule-based procedures (e.g., TLS, SSH, IPSec) that enforce security measures during data transmission or access control.
Why do they matter?
- Consistency: Uniform security across systems (e.g., banks use PCI-DSS for payment security).
- Trust: Certifications (e.g., ISO 27001) signal reliability to customers (e.g., Daraz’s secure checkout).
- Legality: Compliance avoids fines (e.g., GDPR for EU data protection).
2. Key Security Standards
| Standard | Domain | Key Requirements | Example Use Case |
|---|---|---|---|
| ISO/IEC 27001 | Information Security | Risk assessment, access control, incident response, audits. | Ncell’s customer data protection. |
| NIST SP 800-53 | U.S. Government Systems | Security controls for federal agencies (e.g., identity management, encryption). | U.S. Department of Defense networks. |
| PCI-DSS | Payment Card Industry | Encrypt card data, secure networks, monitor access. | Khalti/eSewa payment gateways. |
| HIPAA | Healthcare (U.S.) | Patient data privacy, audit logs, breach notification. | Hospitals using electronic health records. |
| GDPR | EU Data Protection | User consent, data minimization, right to erasure. | Google’s EU user data handling. |
In the Real World
eSewa/Khalti Transactions
- Protocol Used: TLS 1.3 (for encrypting payment data between your phone and the bank).
- Standard Applied: PCI-DSS (ensures card details are never stored unencrypted).
- Risk Mitigated: Man-in-the-middle attacks (e.g., intercepting your OTP during transfer).
Ncell’s 4G Network Security
- Protocol Used: IPSec (secures VPN tunnels for remote workers).
- Standard Applied: ISO 27001 (protects subscriber data from breaches).
- Real Example: When you use Ncell’s "Secure WiFi" at hotels, IPSec encrypts your traffic even if the hotel’s network is compromised.
Pathao Driver App
- Protocol Used: SSH (for secure remote login to Pathao’s backend servers).
- Standard Applied: NIST Guidelines (for secure API authentication between app and servers).
- Risk Mitigated: Unauthorized access to driver locations or fare data.
3. Core Security Protocols
A. Transport Layer Security (TLS)
How TLS Works: The Handshake Process
sequenceDiagram
Client->>Server: ClientHello (supports TLS 1.3, cipher suites)
Server->>Client: ServerHello, Certificate, ServerKeyExchange
Client->>Server: ClientKeyExchange, Finished (encrypted)
Server->>Client: Finished (encrypted)
Note over Client,Server: Symmetric key established for sessionKey Features
- Confidentiality: Symmetric encryption (AES) after handshake.
- Integrity: HMAC-SHA256 ensures no tampering.
- Authentication: Server (and optionally client) certificates verify identity.
TLS vs. SSL
| Feature | TLS | SSL |
|---|---|---|
| Version | TLS 1.0–1.3 (SSL is obsolete) | SSL 2.0/3.0 (vulnerable) |
| Encryption | AES, ChaCha20 | Weak ciphers (e.g., RC4) |
| Handshake | 1-RTT (faster) | 2-RTT |
| Use Case | HTTPS, APIs, email (SMTP) | Legacy systems (avoid) |
Worked Example: Securing a Bank Transfer (e.g., NMB Bank)
- You enter your credentials on the bank’s website → TLS 1.3 handshake occurs.
- Your browser verifies the bank’s certificate (issued by a trusted CA like DigiCert).
- All data (account number, OTP) is encrypted with AES-256.
- The bank’s server signs responses with HMAC to prevent replay attacks.
Step-by-step packet exchange in TLS 1.3 (Image: Halub3, CC BY-SA 4.0, via Wikimedia Commons)
B. Secure Shell (SSH)
SSH Connection Modes
- Local Forwarding: Redirects a local port to a remote service (e.g.,
ssh -L 8080:localhost:80 user@server→ access server’s port 80 via local 8080). - Remote Forwarding: Exposes a remote port to your local machine (e.g.,
ssh -R 8080:localhost:80 user@server→ others can access your local port 80 via the server’s 8080).
SSH Protocol Layers
classDiagram
class Transport {
+Encryption: AES, ChaCha20
+Compression: zlib
}
class UserAuth {
+Methods: Password, Public Key, Kerberos
}
class Connection {
+Channels: Session, X11, Port Forwarding
}
Transport --> UserAuth : Uses
UserAuth --> Connection : ManagesReal Example: Securing a Remote Database (e.g., Daraz’s Inventory System)
- Daraz’s DevOps team uses SSH to remotely manage database servers.
- Local Forwarding:
ssh -L 5432:localhost:5432 db-admin@daraz-server→ developers access PostgreSQL via their local port 5432, encrypted over SSH.
C. Internet Protocol Security (IPSec)
IPSec Modes
| Mode | Description | Use Case |
|---|---|---|
| Transport | Encrypts payload only (IP header remains visible). | Host-to-host (e.g., VPN between your PC and a server). |
| Tunnel | Encrypts entire IP packet (new IP header added). | Network-to-network (e.g., NTC’s core routers). |
Security Association (SA) Parameters
| Parameter | Description |
|---|---|
| SPI (Security Parameter Index) | Unique identifier for the SA. |
| Protocol (AH/ESP) | AH (Authentication Header) or ESP (Encapsulating Security Payload). |
| Algorithm | Encryption (AES), Integrity (SHA-2), Key Exchange (IKE). |
| Lifetime | How long the SA remains valid (e.g., 1 hour). |
Worked Example: NTC’s VPN for Remote Offices
- NTC uses IPSec in Tunnel Mode to connect regional offices to the central network.
- AH ensures no one alters routing headers.
- ESP encrypts all traffic between offices, preventing eavesdropping.
4. Cloud Security: Models and Risks
Cloud Service Models
mindmap
root((Cloud Security Models))
SaaS
+Provider manages apps/data (e.g., Google Workspace).
+Customer controls: User access, data.
PaaS
+Provider manages OS/runtime (e.g., Heroku).
+Customer controls: Apps, data.
IaaS
+Provider manages hardware (e.g., AWS EC2).
+Customer controls: OS, apps, data.Security Risks and Countermeasures
| Risk | Countermeasure |
|---|---|
| Data Breaches | Encryption (AES-256), tokenization, access controls. |
| Insider Threats | Role-based access (RBAC), audit logs. |
| DDoS Attacks | Cloudflare/WAF, rate limiting. |
| Compliance Violations | Automated compliance checks (e.g., AWS Config for PCI-DSS). |
Real Example: eSewa’s Cloud Security
- Uses SaaS model (eSewa handles all infrastructure).
- Countermeasures:
- TLS 1.3 for all API calls.
- IAM policies to restrict admin access.
- Regular audits via ISO 27001.
5. IoT Security Challenges
Key Vulnerabilities
- Weak Default Credentials: Many IoT devices ship with
admin:admin. - Lack of Encryption: Unencrypted Zigbee/Z-Wave signals in smart homes.
- Firmware Updates: Rare or unpatched (e.g., vulnerable cameras in hotels).
Security Protocols for IoT
| Protocol | Use Case | Example |
|---|---|---|
| MQTT-SN | Low-power IoT (e.g., sensors). | Smart agriculture (soil moisture sensors). |
| CoAP | Constrained devices (REST-like). | Smart lights (Philips Hue). |
| DTLS | Secure MQTT/CoAP (TLS for IoT). | Secure home automation (e.g., Nest). |
Real Example: Kathmandu Traffic Management
- Problem: Traffic lights use unencrypted radio signals → hackers could cause gridlock.
- Solution: Deploy DTLS to encrypt commands between traffic controllers and central servers.
Exam Tip
For Standards (ISO, PCI-DSS, NIST):
- Memorize 1 key requirement per standard (e.g., PCI-DSS = "encrypt card data").
- Link to real-world examples (e.g., "Khalti uses PCI-DSS for payments").
For Protocols (TLS, SSH, IPSec):
- Draw diagrams: TLS handshake, SSH forwarding, IPSec modes.
- Compare: TLS vs SSL, AH vs ESP in IPSec.
- Worked examples: Always tie to a Nepali context (e.g., "How does Ncell secure its VPN?").
For Cloud/IoT:
- Mindmaps for service models (SaaS/PaaS/IaaS).
- Risk tables: Match risks to countermeasures (e.g., "DDoS → Cloudflare").
Common Pitfalls:
- Don’t confuse TLS session (reused keys) vs. connection (new handshake).
- IPSec AH only authenticates, ESP encrypts + authenticates.
- SSH local forwarding ≠ remote forwarding (exam loves this distinction).
Based on the TU BSc CSIT syllabus for Network Security (CSC416), unit 11.
Discussion
Loading…