Computer and Information TechnologyUnit 68 min read
Computer Security and Malware – Threats, Defenses, and Real‑World Applications
Unit 6 of Computer and Information Technology: explores the fundamentals of computer security, malware taxonomy, cryptographic techniques, network protection mechanisms, and real‑world applications in Nepali and global contexts.
Key points
- Security is built on the CIA triad: confidentiality, integrity, and availability.
- Malware can be classified into viruses, worms, trojans, ransomware, and adware, each with distinct propagation mechanisms.
- Cryptography uses symmetric (AES) and asymmetric (RSA) algorithms to secure data and authenticate users.
- Network security relies on firewalls, IDS/IPS, VPNs, and TLS to protect data in transit.
- Effective defense requires layered security, continuous monitoring, and incident response planning.
1. Introduction to Computer Security
Computer security, also known as information security, is the practice of protecting information systems from theft, damage, or unauthorized access. It encompasses policies, procedures, and technologies that safeguard data, maintain system integrity, and ensure reliable service delivery.
2. Threat Landscape
2.1 Malware Taxonomy
| Malware Type | Definition | Propagation | Typical Impact |
|---|---|---|---|
| Virus | Self‑replicating code attached to legitimate programs | Manual execution | Corrupts files, slows performance |
| Worm | Autonomous program that spreads over networks | Network scanning | Rapid network exhaustion |
| Trojan | Malicious code disguised as benign software | User installation | Steals data, opens backdoors |
| Ransomware | Encrypts user data, demands ransom | Email attachments, drive‑by downloads | Data loss, financial loss |
| Adware | Displays unwanted advertisements | Browser extensions | Privacy breach, performance hit |
2.2 Attack Vectors
- Phishing: deceptive emails that trick users into revealing credentials.
- Drive‑by downloads: malicious code executed when visiting compromised websites.
- Supply‑chain attacks: inserting malware into legitimate software updates.
- Zero‑day exploits: vulnerabilities unknown to vendors.
3. Security Principles
3.1 CIA Triad
- Confidentiality: ensuring data is accessible only to authorized users.
- Integrity: guaranteeing data is accurate and unaltered.
- Availability: ensuring systems and data are accessible when needed.
3.2 Defense in Depth
Layered security measures (physical, network, application, user) reduce the risk that a single vulnerability compromises the entire system.
4. Authentication and Access Control
4.1 Passwords, OTP, Biometrics
- Passwords: simplest form; vulnerable to brute force and credential stuffing.
- One‑Time Passwords (OTP): generated per session; mitigates replay attacks.
- Biometrics: fingerprint or facial recognition; offers strong user verification.
4.2 Multi‑Factor Authentication (MFA)
Combines two or more authentication factors (something you know, have, or are).
Example: eSewa Transaction Authentication
- User enters mobile number and password.
- eSewa sends an OTP to the registered mobile.
- User inputs OTP; system verifies.
- Transaction proceeds only after successful MFA.
sequenceDiagram
participant U as User
participant E as eSewa Server
participant M as Mobile Network
U->>E: Login (mobile, password)
E->>M: Send OTP
M->>U: Deliver OTP
U->>E: Enter OTP
E->>U: Authentication Success5. Cryptography
5.1 Symmetric vs Asymmetric
| Feature | Symmetric | Asymmetric |
|---|---|---|
| Key usage | Same key for encryption/decryption | Public/Private key pair |
| Speed | Faster | Slower |
| Key distribution | Challenging | Easier via public key |
5.2 RSA Key Generation and Digital Signature
RSA uses two large primes and .
- (modulus)
- Choose such that and .
- Compute where .
Worked Example (small primes for illustration):
Let , .
.
.
Choose (since ).
Find such that .
.
Public key: .
Private key: .
Encrypt message :
.
Decrypt:
.
5.3 AES (Advanced Encryption Standard)
- Symmetric block cipher, 128‑bit block size.
- Key sizes: 128, 192, 256 bits.
- Widely used for data at rest (e.g., encrypted database fields).
6. Network Security
6.1 Layered Model – OSI
6.2 Packet/Frame Format – IP Header
6.3 TLS Handshake (Secure Communication)
Example: Pathao App Uses TLS
- All API calls from the mobile app to the Pathao backend are wrapped in TLS 1.3.
- The server presents a valid certificate signed by a trusted CA.
- Mutual authentication is optional; client verifies server certificate to prevent MITM attacks.
6.4 Firewalls, IDS/IPS, VPN
- Firewalls filter traffic based on rules.
- Intrusion Detection/Prevention Systems (IDS/IPS) monitor for malicious patterns.
- Virtual Private Networks (VPNs) encrypt traffic over public networks.
7. Malware Types and Lifecycle
stateDiagram-v2
[*] --> Downloaded
Downloaded --> Executed : User action
Executed --> Propagated : Malware spreads
Propagated --> PayloadDelivered : Targets infected
PayloadDelivered --> [*] : Mission complete
state Downloaded {
[*] --> Downloaded : Downloaded but not executed
}
state Executed {
[*] --> Executed : Running in memory
}
state Propagated {
[*] --> Propagated : Spread via network/USB
}
state PayloadDelivered {
[*] --> PayloadDelivered : Ransomware/keylogger activated
}Malware lifecycle with user/system interactions highlighted.7.1 WannaCry Ransomware Case Study
- Exploited SMB vulnerability (MS17‑010).
- Propagated via network shares.
- Encrypted files, displayed ransom note.
- Mitigation: apply patch, disable SMBv1, use endpoint protection.
8. Detection and Prevention
8.1 Antivirus and Heuristic Analysis
- Signature‑based detection: matches known malware patterns.
- Heuristic: analyzes code behavior for suspicious traits.
8.2 Sandboxing
- Executes suspicious code in isolated environment to observe behavior.
8.3 Google Safe Browsing
- Maintains a database of malicious URLs; browsers query to warn users.
9. Incident Response and Recovery
- Identification – detect anomalous activity.
- Containment – isolate affected systems.
- Eradication – remove malware, patch vulnerabilities.
- Recovery – restore from backups, monitor for reinfection.
- Lessons Learned – update policies, conduct training.
10. Legal and Ethical Aspects
- Computer Crime Act, 2018 (NEPRA) – penalizes unauthorized access, data theft.
- GDPR – governs personal data protection (relevant for Nepali companies with EU customers).
- Ethical hacking: requires explicit permission and adherence to code of conduct.
11. In the real world
- eSewa: Uses RSA digital signatures to authenticate transaction requests, ensuring that only legitimate users can initiate fund transfers.
- Pathao: Implements TLS 1.3 for all mobile‑app API traffic, protecting rider and driver data from eavesdropping.
- Google: Employs multi‑factor authentication and end‑to‑end encryption for Gmail, safeguarding user emails from interception.
12. Exam tip
- Definitions: Be able to define malware, CIA triad, symmetric/asymmetric encryption, and authentication factors.
- Comparisons: Know the differences between virus, worm, trojan, ransomware, and adware.
- Diagrams: Sketch the OSI model, IP header, and TLS handshake.
- Case studies: Briefly describe WannaCry or a phishing attack, including propagation and mitigation.
- Security principles: Recall least privilege, defense in depth, and MFA.
Based on the TU BTTM syllabus for Computer and Information Technology (ITC307), unit 6.
Discussion
Loading…