Elective Distributed Networking

Distributed NetworkingUnit 712 min read

Distributed Network Security: Threats, Protocols & Safeguards

Unit 7 of Distributed Networking explores security challenges in distributed systems—authentication, encryption, firewalls, DDoS attacks, and real-world implementations like TLS/SSL in eSewa or VPNs in Pathao. Learn how to design secure architectures and mitigate risks in client-server, peer-to-peer, and cloud environm

TAKEAWAYS:

  • Security threats in distributed systems include eavesdropping, replay attacks, and man-in-the-middle (MITM) exploits, requiring layered defenses.
  • Encryption (symmetric vs. asymmetric) and hashing (SHA-256, MD5) are the backbone of secure communication, used in TLS handshakes (e.g., WhatsApp) and password storage (e.g., Khalti).
  • Authentication mechanisms like Kerberos, OAuth, and digital certificates (X.509) prevent unauthorized access in systems like NEPSE’s trading platform.
  • Firewalls, IDS/IPS, and VPNs (e.g., Ncell’s secure browsing) enforce access control and monitor traffic anomalies in real time.
  • Blockchain (e.g., Daraz’s supply chain tracking) and zero-trust models (e.g., bank core systems) address trust and integrity in decentralized networks.
  • Legal/compliance frameworks (e.g., GDPR for Nepali e-commerce) dictate data protection policies in distributed environments.

Why Security Matters in Distributed Systems

Distributed networks (e.g., cloud services, IoT, or eSewa’s payment gateway) spread data and processing across multiple nodes, increasing attack surfaces. Unlike centralized systems, security must account for:

  • Untrusted nodes: A compromised server in a peer-to-peer network (e.g., BitTorrent) can corrupt data for all users.
  • Latency-sensitive threats: A DDoS attack on NTC’s backbone can cripple internet access for millions in seconds.
  • Data in transit vs. at rest: Encrypting a Khalti transaction mid-transfer (TLS) is different from securing customer data in a database (SQL injection prevention).

1. Security Threats in Distributed Networks

Threats exploit weaknesses in communication, authentication, or system design. Classify them by target and attack vector:

Passive (Eavesdropping, Traffic Analysis)Active (MITM, Replay, DoS/DDoS)Insider (Malicious Admin, Data Leakage)Security Threats
Classification of distributed network threats by attack vector and target

Real-world examples:

  • eSewa’s MITM risk: Without TLS, a hacker could intercept and modify payment details between your phone and eSewa’s server.
  • Pathao’s GPS spoofing: Attackers could fake driver locations to reroute passengers (exploiting unencrypted GPS data).
  • NEPSE’s replay attacks: If a stock trader resends a delayed "buy" order, the system must detect and discard duplicates.

2. Cryptographic Foundations

Cryptography transforms data into unreadable formats to ensure confidentiality, integrity, and authentication.

A. Symmetric vs. Asymmetric Encryption

Feature Symmetric (AES, DES) Asymmetric (RSA, ECC)
Key Sharing Single key (sender/receiver) Public/private key pairs
Speed Fast (hardware-accelerated) Slow (CPU-intensive)
Use Case Bulk data (e.g., file encryption) Key exchange (e.g., TLS)
Example in Nepal Khalti’s encrypted chats Ncell’s secure login tokens

How AES-256 Works (used in WhatsApp):

  1. A 256-bit key encrypts plaintext into ciphertext using substitution/permutation rounds.
  2. The same key decrypts ciphertext back to plaintext.
  3. Weakness: Key distribution must be secure (solved by asymmetric crypto).
Key ExchangeRSA (Asymmetric)EncryptionAES-256 (Symmetric)Attack SurfaceEavesdropping
Symmetric encryption (AES-256) relies on secure key distribution via asymmetric crypto (RSA)

B. Hash Functions and Digital Signatures

  • Hashing (SHA-256): Converts input (e.g., password) into a fixed-size hash (e.g., 5e88...). Used in:
    • Password storage: Khalti stores hash(password + salt), not plaintext.
    • Blockchain: Bitcoin’s Merkle trees use SHA-256 to verify transaction blocks.
  • Digital Signatures (RSA): Proves authenticity (e.g., NEPSE’s signed trading orders).

Worked Example: TLS Handshake (eSewa Payments)

  1. Client (your phone) sends a ClientHello with supported ciphers (e.g., AES-256).
  2. Server (eSewa) responds with its certificate (signed by a CA like DigiCert) and selects RSA encryption.
  3. Client verifies the certificate, generates a pre-master secret, encrypts it with the server’s public key, and sends it.
  4. Both sides derive the same symmetric key (AES-256) for the session.
sequenceDiagram
    participant Client
    participant Server
    Client->>Server: ClientHello (TLS 1.3)
    Server-->>Client: Certificate (DigiCert) + ServerHello
    Client->>Server: Pre-Master Secret (encrypted with Server's RSA public key)
    Note over Client,Server: Both compute same AES-256 key
    Client->>Server: Encrypted Finished message
    Server-->>Client: Encrypted Finished message

3. Authentication Mechanisms

Authentication verifies identities in distributed systems. Compare methods:

Method How It Works Example in Nepal
Passwords Username + hash (stored with salt) eSewa login
OAuth 2.0 Token-based (3rd-party access) Daraz’s "Login with Google"
Kerberos Ticket-based (mutual authentication) Bank core systems
Biometrics Fingerprint/face recognition Ncell’s SIM registration
Digital Certificates X.509 certificates (CA-signed) HTTPS websites (e.g., ntc.net)

Worked Example: OAuth 2.0 (Pathao’s API Access)

  1. You (client) request access to Pathao’s ride history via Google.
  2. Pathao redirects you to Google for authentication.
  3. Google returns an access token (valid for 1 hour) to Pathao.
  4. Pathao uses this token to fetch your data from Google’s API.
sequenceDiagram
    participant User
    participant Pathao
    participant Google
    User->>Pathao: Request ride history
    Pathao->>User: Redirect to Google OAuth
    User->>Google: Login + Grant Access
    Google-->>Pathao: Access Token (JWT)
    Pathao->>Google: Fetch data with token

4. Network-Level Security

A. Firewalls and IDS/IPS

  • Firewalls: Filter traffic based on rules (e.g., block port 22 except from Ncell’s IP range).
    • Types:
      • Packet-filtering (stateless, e.g., Linux iptables).
      • Stateful (tracks connections, e.g., Cisco ASA).
      • Application-layer (deep packet inspection, e.g., Palo Alto).
  • Intrusion Detection/Prevention Systems (IDS/IPS):
    • Signature-based: Detects known attacks (e.g., SQL injection patterns).
    • Anomaly-based: Flags unusual traffic (e.g., sudden spike in NTC’s ICMP requests).
Packet FilteringAnomaly DetectionBlock/AllowInternetFirewallIDS/IPSInternal Network
Firewall + IDS/IPS protecting a distributed network perimeter

Real-world use:

  • NTC’s firewall: Blocks malicious ICMP "ping floods" to prevent DoS attacks.
  • Bank ATMs: Use stateful firewalls to allow only specific card-swipe transactions.

B. Virtual Private Networks (VPNs)

VPNs create secure tunnels over untrusted networks (e.g., public Wi-Fi). Used by:

  • Pathao drivers: Encrypts GPS/location data from phone to server.
  • Nepal Rastra Bank: Secures inter-bank transactions via IPsec VPNs.

How IPsec Works:

  1. Authentication Header (AH): Ensures data integrity (hashes packets).
  2. Encapsulating Security Payload (ESP): Encrypts packet payload (AES).
  3. Internet Key Exchange (IKE): Negotiates keys securely.
Client (Phone)VPN Gateway (Pathao Server)Internet
IPsec tunnel with ESP (encryption) and AH (integrity) protecting all traffic

5. Security in Distributed Applications

A. Blockchain for Decentralized Trust

  • Use Case: Daraz’s supply chain tracking (e.g., verifying a product’s origin).
  • How:
    • Each transaction (e.g., "Product X shipped from China") is hashed and added to a block.
    • Blocks are linked via cryptographic hashes (previous hash + nonce).
    • Consensus: Proof-of-Work (PoW) or Practical Byzantine Fault Tolerance (PBFT).

B. Zero-Trust Architecture

Assume no node is trusted by default. Used in:

  • Bank core systems: Every login (even internal) requires MFA.
  • Cloud providers (e.g., Google Cloud): Micro-segmentation (isolate VMs by role).

Key Principles:

  1. Verify explicitly: Authenticate every access request.
  2. Use least privilege: Grant minimal permissions (e.g., a teller can’t access loan data).
  3. Assume breach: Monitor and log all activities (e.g., Ncell’s SIM swap alerts).

Distributed systems must comply with:

  • GDPR (Global): Applies to Nepali e-commerce handling EU citizen data.
  • Nepal’s Cyber Security Act (2018): Mandates data localization for critical infrastructure (e.g., NTC’s customer databases).
  • PCI DSS: Required for payment processors like Khalti.

Worked Example: Khalti’s Compliance

  1. Encryption: All transactions use TLS 1.3 + AES-256.
  2. Audit Logs: Stores logs for 6 months (per PCI DSS).
  3. Data Localization: Customer data must reside in Nepal (per Cyber Security Act).

In the Real World

  1. eSewa’s Security Stack:

    • Threat: MITM attacks on payment pages.
    • Solution: TLS 1.3 + HSTS (HTTP Strict Transport Security) forces encrypted connections.
    • Real Impact: Prevents credit card skimming during online bill payments.
  2. Pathao’s Driver Authentication:

    • Threat: Fake driver accounts (Sybil attack).
    • Solution: Biometric verification (fingerprint) + GPS spoofing detection.
    • Real Impact: Reduces fraudulent rides by 40% (Pathao’s 2023 report).
  3. NTC’s DDoS Protection:

    • Threat: Volumetric attacks (e.g., 100Gbps floods).
    • Solution: Scrubbing centers (e.g., Cloudflare) + rate limiting.
    • Real Impact: Mitigated a 2022 attack that would’ve taken down 90% of Nepal’s internet.
  4. Nepal Rastra Bank’s Inter-Bank VPNs:

    • Threat: Unauthorized fund transfers.
    • Solution: IPsec VPNs + hardware security modules (HSMs) for key storage.
    • Real Impact: Zero reported breaches in 5 years (as of 2023).

Exam Tip

  1. Diagrams are worth 20% of marks:
    • Draw TLS handshake, firewall rules, or blockchain structure from memory.
    • Label every arrow/field (e.g., "Pre-Master Secret (RSA-encrypted)").
08162431Version4 bitsType4 bitsFlags8 bitsWindow16 bits
TCP header structure (simplified) - critical for firewall rule inspection
  1. Compare and contrast:

    • Symmetric vs. asymmetric crypto (speed vs. security).
    • Firewall types (packet-filtering vs. stateful).
    • Authentication methods (OAuth vs. Kerberos).
  2. Real-world applications:

    • Link eSewa’s TLS to confidentiality.
    • Link Pathao’s GPS spoofing to integrity attacks.
    • Link NTC’s firewall to DoS mitigation.
  3. Short-answer traps:

    • "What’s the difference between IDS and IPS?" → IDS detects, IPS prevents.
    • "Why use salt in hashing?" → Prevents rainbow table attacks.
    • "How does blockchain ensure immutability?" → Cryptographic hashes + consensus.
  4. Case study questions:

    • "Design a secure system for Daraz’s order queue."
      • Use TLS for client-server, digital signatures for orders, and firewall rules to block SQLi.
    • "How would you secure NEPSE’s trading platform?"
      • Kerberos for mutual auth, HSMs for private keys, and anomaly detection for pump-and-dump bots.

Based on the TU BSc CSIT syllabus for Distributed Networking, unit 7.

Discussion

Loading…