ITC307 Computer and Information Technology

Computer and Information TechnologyUnit 68 min read

Computer Security and Malware – Threats, Defenses, and Real‑World Applications

Unit 6 of Computer and Information Technology: explores the fundamentals of computer security, malware taxonomy, cryptographic techniques, network protection mechanisms, and real‑world applications in Nepali and global contexts.

Key points

  • Security is built on the CIA triad: confidentiality, integrity, and availability.
  • Malware can be classified into viruses, worms, trojans, ransomware, and adware, each with distinct propagation mechanisms.
  • Cryptography uses symmetric (AES) and asymmetric (RSA) algorithms to secure data and authenticate users.
  • Network security relies on firewalls, IDS/IPS, VPNs, and TLS to protect data in transit.
  • Effective defense requires layered security, continuous monitoring, and incident response planning.

1. Introduction to Computer Security

Computer security, also known as information security, is the practice of protecting information systems from theft, damage, or unauthorized access. It encompasses policies, procedures, and technologies that safeguard data, maintain system integrity, and ensure reliable service delivery.

2. Threat Landscape

2.1 Malware Taxonomy

Malware Type Definition Propagation Typical Impact
Virus Self‑replicating code attached to legitimate programs Manual execution Corrupts files, slows performance
Worm Autonomous program that spreads over networks Network scanning Rapid network exhaustion
Trojan Malicious code disguised as benign software User installation Steals data, opens backdoors
Ransomware Encrypts user data, demands ransom Email attachments, drive‑by downloads Data loss, financial loss
Adware Displays unwanted advertisements Browser extensions Privacy breach, performance hit

2.2 Attack Vectors

  • Phishing: deceptive emails that trick users into revealing credentials.
  • Drive‑by downloads: malicious code executed when visiting compromised websites.
  • Supply‑chain attacks: inserting malware into legitimate software updates.
  • Zero‑day exploits: vulnerabilities unknown to vendors.

3. Security Principles

3.1 CIA Triad

  • Confidentiality: ensuring data is accessible only to authorized users.
  • Integrity: guaranteeing data is accurate and unaltered.
  • Availability: ensuring systems and data are accessible when needed.

3.2 Defense in Depth

Layered security measures (physical, network, application, user) reduce the risk that a single vulnerability compromises the entire system.

4. Authentication and Access Control

4.1 Passwords, OTP, Biometrics

  • Passwords: simplest form; vulnerable to brute force and credential stuffing.
  • One‑Time Passwords (OTP): generated per session; mitigates replay attacks.
  • Biometrics: fingerprint or facial recognition; offers strong user verification.

4.2 Multi‑Factor Authentication (MFA)

Combines two or more authentication factors (something you know, have, or are).

Example: eSewa Transaction Authentication

  1. User enters mobile number and password.
  2. eSewa sends an OTP to the registered mobile.
  3. User inputs OTP; system verifies.
  4. Transaction proceeds only after successful MFA.
sequenceDiagram
    participant U as User
    participant E as eSewa Server
    participant M as Mobile Network
    U->>E: Login (mobile, password)
    E->>M: Send OTP
    M->>U: Deliver OTP
    U->>E: Enter OTP
    E->>U: Authentication Success

5. Cryptography

5.1 Symmetric vs Asymmetric

Feature Symmetric Asymmetric
Key usage Same key for encryption/decryption Public/Private key pair
Speed Faster Slower
Key distribution Challenging Easier via public key

5.2 RSA Key Generation and Digital Signature

RSA uses two large primes and .

  • (modulus)
  • Choose such that and .
  • Compute where .

Worked Example (small primes for illustration):
Let , .
.
.
Choose (since ).
Find such that .
.

Public key: .
Private key: .

Encrypt message :
.

Decrypt:
.

5.3 AES (Advanced Encryption Standard)

  • Symmetric block cipher, 128‑bit block size.
  • Key sizes: 128, 192, 256 bits.
  • Widely used for data at rest (e.g., encrypted database fields).

6. Network Security

6.1 Layered Model – OSI

ApplicationPresentationSessionTransportNetworkData LinkPhysicalhigher layers use lower layers' services
OSI 7-layer model showing protocol hierarchy (e.g., HTTP uses TCP, which uses IP).

6.2 Packet/Frame Format – IP Header

08162431Version4 bitsIHL4 bitsType of Service8 bitsTotal Length16 bitsIdentification16 bitsFlags3 bitsFragment Offset13 bitsTime to Live(TTL)8 bitsProtocol8 bitsHeader Checksum16 bitsSource IP32 bitsDestination IP32 bits
IPv4 header structure (20-byte minimum). Highlighted fields are critical for routing.

6.3 TLS Handshake (Secure Communication)

ClientClientHelloServerServerHello + Certificate
TLS Handshake message flow (simplified). Client and server exchange keys and verify the connection before encrypted communication begins.

Example: Pathao App Uses TLS

  • All API calls from the mobile app to the Pathao backend are wrapped in TLS 1.3.
  • The server presents a valid certificate signed by a trusted CA.
  • Mutual authentication is optional; client verifies server certificate to prevent MITM attacks.

6.4 Firewalls, IDS/IPS, VPN

  • Firewalls filter traffic based on rules.
  • Intrusion Detection/Prevention Systems (IDS/IPS) monitor for malicious patterns.
  • Virtual Private Networks (VPNs) encrypt traffic over public networks.

7. Malware Types and Lifecycle

stateDiagram-v2
    [*] --> Downloaded
    Downloaded --> Executed : User action
    Executed --> Propagated : Malware spreads
    Propagated --> PayloadDelivered : Targets infected
    PayloadDelivered --> [*] : Mission complete
    state Downloaded {
        [*] --> Downloaded : Downloaded but not executed
    }
    state Executed {
        [*] --> Executed : Running in memory
    }
    state Propagated {
        [*] --> Propagated : Spread via network/USB
    }
    state PayloadDelivered {
        [*] --> PayloadDelivered : Ransomware/keylogger activated
    }
Malware lifecycle with user/system interactions highlighted.

7.1 WannaCry Ransomware Case Study

  • Exploited SMB vulnerability (MS17‑010).
  • Propagated via network shares.
  • Encrypted files, displayed ransom note.
  • Mitigation: apply patch, disable SMBv1, use endpoint protection.

8. Detection and Prevention

8.1 Antivirus and Heuristic Analysis

  • Signature‑based detection: matches known malware patterns.
  • Heuristic: analyzes code behavior for suspicious traits.

8.2 Sandboxing

  • Executes suspicious code in isolated environment to observe behavior.

8.3 Google Safe Browsing

  • Maintains a database of malicious URLs; browsers query to warn users.

9. Incident Response and Recovery

  1. Identification – detect anomalous activity.
  2. Containment – isolate affected systems.
  3. Eradication – remove malware, patch vulnerabilities.
  4. Recovery – restore from backups, monitor for reinfection.
  5. Lessons Learned – update policies, conduct training.
  • Computer Crime Act, 2018 (NEPRA) – penalizes unauthorized access, data theft.
  • GDPR – governs personal data protection (relevant for Nepali companies with EU customers).
  • Ethical hacking: requires explicit permission and adherence to code of conduct.

11. In the real world

  • eSewa: Uses RSA digital signatures to authenticate transaction requests, ensuring that only legitimate users can initiate fund transfers.
  • Pathao: Implements TLS 1.3 for all mobile‑app API traffic, protecting rider and driver data from eavesdropping.
  • Google: Employs multi‑factor authentication and end‑to‑end encryption for Gmail, safeguarding user emails from interception.

12. Exam tip

  • Definitions: Be able to define malware, CIA triad, symmetric/asymmetric encryption, and authentication factors.
  • Comparisons: Know the differences between virus, worm, trojan, ransomware, and adware.
  • Diagrams: Sketch the OSI model, IP header, and TLS handshake.
  • Case studies: Briefly describe WannaCry or a phishing attack, including propagation and mitigation.
  • Security principles: Recall least privilege, defense in depth, and MFA.

Based on the TU BTTM syllabus for Computer and Information Technology (ITC307), unit 6.

Discussion

Loading…