Distributed NetworkingUnit 712 min read
Distributed Network Security: Threats, Protocols & Safeguards
Unit 7 of Distributed Networking explores security challenges in distributed systems—authentication, encryption, firewalls, DDoS attacks, and real-world implementations like TLS/SSL in eSewa or VPNs in Pathao. Learn how to design secure architectures and mitigate risks in client-server, peer-to-peer, and cloud environm
TAKEAWAYS:
- Security threats in distributed systems include eavesdropping, replay attacks, and man-in-the-middle (MITM) exploits, requiring layered defenses.
- Encryption (symmetric vs. asymmetric) and hashing (SHA-256, MD5) are the backbone of secure communication, used in TLS handshakes (e.g., WhatsApp) and password storage (e.g., Khalti).
- Authentication mechanisms like Kerberos, OAuth, and digital certificates (X.509) prevent unauthorized access in systems like NEPSE’s trading platform.
- Firewalls, IDS/IPS, and VPNs (e.g., Ncell’s secure browsing) enforce access control and monitor traffic anomalies in real time.
- Blockchain (e.g., Daraz’s supply chain tracking) and zero-trust models (e.g., bank core systems) address trust and integrity in decentralized networks.
- Legal/compliance frameworks (e.g., GDPR for Nepali e-commerce) dictate data protection policies in distributed environments.
Why Security Matters in Distributed Systems
Distributed networks (e.g., cloud services, IoT, or eSewa’s payment gateway) spread data and processing across multiple nodes, increasing attack surfaces. Unlike centralized systems, security must account for:
- Untrusted nodes: A compromised server in a peer-to-peer network (e.g., BitTorrent) can corrupt data for all users.
- Latency-sensitive threats: A DDoS attack on NTC’s backbone can cripple internet access for millions in seconds.
- Data in transit vs. at rest: Encrypting a Khalti transaction mid-transfer (TLS) is different from securing customer data in a database (SQL injection prevention).
1. Security Threats in Distributed Networks
Threats exploit weaknesses in communication, authentication, or system design. Classify them by target and attack vector:
Real-world examples:
- eSewa’s MITM risk: Without TLS, a hacker could intercept and modify payment details between your phone and eSewa’s server.
- Pathao’s GPS spoofing: Attackers could fake driver locations to reroute passengers (exploiting unencrypted GPS data).
- NEPSE’s replay attacks: If a stock trader resends a delayed "buy" order, the system must detect and discard duplicates.
2. Cryptographic Foundations
Cryptography transforms data into unreadable formats to ensure confidentiality, integrity, and authentication.
A. Symmetric vs. Asymmetric Encryption
| Feature | Symmetric (AES, DES) | Asymmetric (RSA, ECC) |
|---|---|---|
| Key Sharing | Single key (sender/receiver) | Public/private key pairs |
| Speed | Fast (hardware-accelerated) | Slow (CPU-intensive) |
| Use Case | Bulk data (e.g., file encryption) | Key exchange (e.g., TLS) |
| Example in Nepal | Khalti’s encrypted chats | Ncell’s secure login tokens |
How AES-256 Works (used in WhatsApp):
- A 256-bit key encrypts plaintext into ciphertext using substitution/permutation rounds.
- The same key decrypts ciphertext back to plaintext.
- Weakness: Key distribution must be secure (solved by asymmetric crypto).
B. Hash Functions and Digital Signatures
- Hashing (SHA-256): Converts input (e.g., password) into a fixed-size hash (e.g.,
5e88...). Used in:- Password storage: Khalti stores
hash(password + salt), not plaintext. - Blockchain: Bitcoin’s Merkle trees use SHA-256 to verify transaction blocks.
- Password storage: Khalti stores
- Digital Signatures (RSA): Proves authenticity (e.g., NEPSE’s signed trading orders).
Worked Example: TLS Handshake (eSewa Payments)
- Client (your phone) sends a
ClientHellowith supported ciphers (e.g., AES-256). - Server (eSewa) responds with its certificate (signed by a CA like DigiCert) and selects RSA encryption.
- Client verifies the certificate, generates a pre-master secret, encrypts it with the server’s public key, and sends it.
- Both sides derive the same symmetric key (AES-256) for the session.
sequenceDiagram
participant Client
participant Server
Client->>Server: ClientHello (TLS 1.3)
Server-->>Client: Certificate (DigiCert) + ServerHello
Client->>Server: Pre-Master Secret (encrypted with Server's RSA public key)
Note over Client,Server: Both compute same AES-256 key
Client->>Server: Encrypted Finished message
Server-->>Client: Encrypted Finished message3. Authentication Mechanisms
Authentication verifies identities in distributed systems. Compare methods:
| Method | How It Works | Example in Nepal |
|---|---|---|
| Passwords | Username + hash (stored with salt) | eSewa login |
| OAuth 2.0 | Token-based (3rd-party access) | Daraz’s "Login with Google" |
| Kerberos | Ticket-based (mutual authentication) | Bank core systems |
| Biometrics | Fingerprint/face recognition | Ncell’s SIM registration |
| Digital Certificates | X.509 certificates (CA-signed) | HTTPS websites (e.g., ntc.net) |
Worked Example: OAuth 2.0 (Pathao’s API Access)
- You (client) request access to Pathao’s ride history via Google.
- Pathao redirects you to Google for authentication.
- Google returns an access token (valid for 1 hour) to Pathao.
- Pathao uses this token to fetch your data from Google’s API.
sequenceDiagram
participant User
participant Pathao
participant Google
User->>Pathao: Request ride history
Pathao->>User: Redirect to Google OAuth
User->>Google: Login + Grant Access
Google-->>Pathao: Access Token (JWT)
Pathao->>Google: Fetch data with token4. Network-Level Security
A. Firewalls and IDS/IPS
- Firewalls: Filter traffic based on rules (e.g., block port 22 except from Ncell’s IP range).
- Types:
- Packet-filtering (stateless, e.g., Linux
iptables). - Stateful (tracks connections, e.g., Cisco ASA).
- Application-layer (deep packet inspection, e.g., Palo Alto).
- Packet-filtering (stateless, e.g., Linux
- Types:
- Intrusion Detection/Prevention Systems (IDS/IPS):
- Signature-based: Detects known attacks (e.g., SQL injection patterns).
- Anomaly-based: Flags unusual traffic (e.g., sudden spike in NTC’s ICMP requests).
Real-world use:
- NTC’s firewall: Blocks malicious ICMP "ping floods" to prevent DoS attacks.
- Bank ATMs: Use stateful firewalls to allow only specific card-swipe transactions.
B. Virtual Private Networks (VPNs)
VPNs create secure tunnels over untrusted networks (e.g., public Wi-Fi). Used by:
- Pathao drivers: Encrypts GPS/location data from phone to server.
- Nepal Rastra Bank: Secures inter-bank transactions via IPsec VPNs.
How IPsec Works:
- Authentication Header (AH): Ensures data integrity (hashes packets).
- Encapsulating Security Payload (ESP): Encrypts packet payload (AES).
- Internet Key Exchange (IKE): Negotiates keys securely.
5. Security in Distributed Applications
A. Blockchain for Decentralized Trust
- Use Case: Daraz’s supply chain tracking (e.g., verifying a product’s origin).
- How:
- Each transaction (e.g., "Product X shipped from China") is hashed and added to a block.
- Blocks are linked via cryptographic hashes (previous hash + nonce).
- Consensus: Proof-of-Work (PoW) or Practical Byzantine Fault Tolerance (PBFT).
B. Zero-Trust Architecture
Assume no node is trusted by default. Used in:
- Bank core systems: Every login (even internal) requires MFA.
- Cloud providers (e.g., Google Cloud): Micro-segmentation (isolate VMs by role).
Key Principles:
- Verify explicitly: Authenticate every access request.
- Use least privilege: Grant minimal permissions (e.g., a teller can’t access loan data).
- Assume breach: Monitor and log all activities (e.g., Ncell’s SIM swap alerts).
6. Legal and Compliance Frameworks
Distributed systems must comply with:
- GDPR (Global): Applies to Nepali e-commerce handling EU citizen data.
- Nepal’s Cyber Security Act (2018): Mandates data localization for critical infrastructure (e.g., NTC’s customer databases).
- PCI DSS: Required for payment processors like Khalti.
Worked Example: Khalti’s Compliance
- Encryption: All transactions use TLS 1.3 + AES-256.
- Audit Logs: Stores logs for 6 months (per PCI DSS).
- Data Localization: Customer data must reside in Nepal (per Cyber Security Act).
In the Real World
eSewa’s Security Stack:
- Threat: MITM attacks on payment pages.
- Solution: TLS 1.3 + HSTS (HTTP Strict Transport Security) forces encrypted connections.
- Real Impact: Prevents credit card skimming during online bill payments.
Pathao’s Driver Authentication:
- Threat: Fake driver accounts (Sybil attack).
- Solution: Biometric verification (fingerprint) + GPS spoofing detection.
- Real Impact: Reduces fraudulent rides by 40% (Pathao’s 2023 report).
NTC’s DDoS Protection:
- Threat: Volumetric attacks (e.g., 100Gbps floods).
- Solution: Scrubbing centers (e.g., Cloudflare) + rate limiting.
- Real Impact: Mitigated a 2022 attack that would’ve taken down 90% of Nepal’s internet.
Nepal Rastra Bank’s Inter-Bank VPNs:
- Threat: Unauthorized fund transfers.
- Solution: IPsec VPNs + hardware security modules (HSMs) for key storage.
- Real Impact: Zero reported breaches in 5 years (as of 2023).
Exam Tip
- Diagrams are worth 20% of marks:
- Draw TLS handshake, firewall rules, or blockchain structure from memory.
- Label every arrow/field (e.g., "Pre-Master Secret (RSA-encrypted)").
Compare and contrast:
- Symmetric vs. asymmetric crypto (speed vs. security).
- Firewall types (packet-filtering vs. stateful).
- Authentication methods (OAuth vs. Kerberos).
Real-world applications:
- Link eSewa’s TLS to confidentiality.
- Link Pathao’s GPS spoofing to integrity attacks.
- Link NTC’s firewall to DoS mitigation.
Short-answer traps:
- "What’s the difference between IDS and IPS?" → IDS detects, IPS prevents.
- "Why use salt in hashing?" → Prevents rainbow table attacks.
- "How does blockchain ensure immutability?" → Cryptographic hashes + consensus.
Case study questions:
- "Design a secure system for Daraz’s order queue."
- Use TLS for client-server, digital signatures for orders, and firewall rules to block SQLi.
- "How would you secure NEPSE’s trading platform?"
- Kerberos for mutual auth, HSMs for private keys, and anomaly detection for pump-and-dump bots.
- "Design a secure system for Daraz’s order queue."
Based on the TU BSc CSIT syllabus for Distributed Networking, unit 7.
Discussion
Loading…