Elective Computer and IT Applications

Computer and IT ApplicationsUnit 1016 min read

Cyber Security & Ethics: Threats, Safeguards & Digital Rights

Unit 10 of Computer and IT Applications explores cybersecurity principles (malware, phishing, encryption), ethical guidelines for IT professionals, and legal frameworks governing digital privacy in Nepal and globally. It links technical safeguards to real-world business and personal risks, with case studies from Nepali

TAKEAWAYS

  • Cybersecurity protects data from malware, phishing, and unauthorized access using firewalls, encryption, and multi-factor authentication (MFA).
  • Ethical IT use requires transparency, respect for privacy (e.g., GDPR, Nepal’s Electronic Transactions Act 2008), and accountability for digital actions.
  • Social engineering attacks (e.g., fake Daraz support calls) exploit human trust—always verify before sharing credentials.
  • Nepal’s cyber laws (e.g., Cyber Crime Act 2074) penalize hacking, data leaks, and online fraud, while global standards like ISO 27001 guide business compliance.
  • Exam focus: Define terms (e.g., ransomware, ethical hacking), compare safeguards (e.g., VPN vs. firewall), and analyze case studies (e.g., Ncell SIM frauds).

1. Cybersecurity: Protecting Digital Assets

Cybersecurity is the practice of safeguarding systems, networks, and data from digital attacks, damage, or unauthorized access. It involves prevention, detection, and response to threats like malware, phishing, and DDoS attacks.

Key Cyber Threats

Cyber threats exploit vulnerabilities in hardware, software, or human behavior. Common types include:

Malicious LinkStolen CredentialsUnauthorized AccessReportedUser DevicePhishing SiteHacker ServerBank ServerNepal Police Cyber Unit
Common cyber threat pathways in Nepal (phishing → credential theft → fraud → reporting).
Threat Type Description Example in Nepal
Malware Software designed to harm systems (viruses, worms, Trojans). Fake "eSewa update" links spreading ransomware to lock user accounts.
Phishing Fraudulent emails/calls mimicking trusted sources to steal credentials. "Ncell customer service" SMS asking for OTPs to "verify your account."
DDoS Attacks Overloading a server with traffic to crash it. Hackers targeting NEPSE’s website during trading hours to manipulate stock prices.
Man-in-the-Middle Intercepting communications (e.g., unsecured Wi-Fi in cafes). Public Wi-Fi in Thamel used to steal login details from online banking apps.
Social Engineering Psychological manipulation to trick users into revealing secrets. "IT support" calling to "fix your computer" and installing spyware.

How Cyber Attacks Work: A Trace

Use a mermaid sequenceDiagram to visualize a phishing attack on a Daraz user:

sequenceDiagram
    participant User
    participant FakeDaraz as Fake Daraz Email
    participant Hacker
    participant DarazDB

    User->>FakeDaraz: Opens email: "Your order #12345 is delayed. Click here to update."
    FakeDaraz-->>User: Redirects to fake Daraz login page
    User->>FakeDaraz: Enters username/password
    FakeDaraz->>Hacker: Sends credentials
    Hacker->>DarazDB: Accesses user account
    Hacker-->>User: Changes shipping address to steal package

Why it matters: In 2023, Daraz users in Nepal reported 30% of phishing emails mimicking order confirmations (source: Cyber Security Nepal).


2. Cybersecurity Safeguards

Protecting against threats requires technical, administrative, and physical controls.

Technical Safeguards

Control How It Works Example in Nepal
Firewalls Filters network traffic (blocks unauthorized access). Ncell’s corporate network uses firewalls to prevent external attacks on customer data.
Antivirus Software Scans for and removes malware. ESET NOD32 used by banks to detect ransomware in transactions.
Encryption Converts data into unreadable code (e.g., HTTPS, VPNs). eSewa uses AES-256 encryption for financial transactions.
Multi-Factor Auth (MFA) Requires 2+ verification steps (password + OTP + biometrics). NEPSE traders enable MFA to prevent unauthorized stock trades.
Intrusion Detection Monitors networks for suspicious activity. NTC’s fiber-optic networks use IDS to detect DDoS attacks.
FirewallTrusted NetworkUntrusted Network
Firewall filtering traffic between trusted (internal) and untrusted (external) networks (e.g., blocking malicious Daraz phishing links).

Administrative Safeguards

  • Password Policies: Enforce strong passwords (e.g., 12+ chars, no reuse).
  • Employee Training: Simulate phishing attacks (e.g., Pathao’s "Security Awareness Week").
  • Access Controls: Limit data access (e.g., only managers can approve Daraz refunds).

Physical Safeguards

  • Server Locks: Secure data centers (e.g., Ncell’s server rooms in Kathmandu).
  • CCTV: Monitor access to IT equipment in offices.

Worked Example: Securing an eSewa Transaction

  1. User logs into eSewa via HTTPS (encrypted connection).
  2. Enters password + OTP sent to registered phone (MFA).
  3. Transaction data is encrypted before processing.
  4. eSewa’s firewall blocks any unauthorized access attempts.
  5. Audit logs track all transactions for fraud detection.

3. Cyber Ethics: Responsible Digital Behavior

Ethics in IT governs right vs. wrong in technology use, balancing innovation with responsibility.

Key Ethical Principles

  1. Transparency: Disclose data collection (e.g., WhatsApp’s privacy policy).
  2. Privacy: Respect user data (e.g., GDPR in Europe; Nepal’s Right to Privacy Act 2075).
  3. Accountability: Take responsibility for mistakes (e.g., Pathao’s 2022 data leak apology).
  4. Accessibility: Ensure tech is usable by all (e.g., screen readers for visually impaired users).

Ethical Dilemmas in Nepal

Scenario Ethical Issue Solution
Deepfake News Spreads misinformation during elections. Platforms (e.g., Facebook) must flag unverified content.
Employee Monitoring Employers tracking workers’ keystrokes. Nepal’s Labor Act requires employee consent for surveillance.
Open-Source Software Piracy Using Linux without attribution. Follow GPL licenses (e.g., Ubuntu’s terms).
AI Bias in Hiring Algorithms discriminating against candidates. Audit AI tools (e.g., Daraz’s hiring chatbots) for fairness.
Example: Government demands user data without warrantNepali Law: Electronic Transactions Act 2063Privacy vs. SecurityExample: Blocking social media during protestsNepali Law: Cyber Crime Act 2075Freedom vs. CensorshipEthical Dilemma
Key ethical conflicts in Nepali digital rights cases (with legal references).
Law/Act Key Provisions
Electronic Transactions Act 2008 Legal recognition of digital signatures.
Cyber Crime Act 2074 Punishes hacking (up to 10 years jail), data theft, and online fraud.
Right to Privacy Act 2075 Protects personal data; companies must disclose breaches within 72 hours.
Computer Crime Act 2064 Criminalizes unauthorized access to computer systems.

Worked Example: Ncell SIM Fraud Case (2022)

  • Issue: Hackers cloned SIMs to bypass OTPs and steal accounts.
  • Ethical Violation: Ncell failed to warn users promptly about the breach.
  • Legal Outcome: Fined Rs. 5 million under the Cyber Crime Act 2074 for negligence.
  • Lesson: Companies must disclose breaches and strengthen MFA.

4. Cybersecurity in Business: Case Studies

Case 1: eSewa’s Security Measures

  • Threat: Phishing emails targeting financial data.
  • Solution:
    • MFA for all transactions.
    • Real-time fraud detection using AI.
    • User education via SMS alerts.
  • Outcome: Reduced fraud cases by 40% in 2023.

Case 2: Daraz’s Supply Chain Security

  • Threat: Fake seller accounts scamming buyers.
  • Solution:
    • Biometric verification for sellers.
    • Blockchain to track product authenticity.
  • Outcome: 35% drop in fake product reports.

Case 3: NTC’s Network Security

  • Threat: DDoS attacks disrupting internet services.
  • Solution:
    • Firewalls + IDS to detect attacks.
    • Redundant servers to maintain uptime.
  • Outcome: 99.9% uptime during peak hours.

5. Personal Cybersecurity: Protecting Yourself

Best Practices for Nepali Users

  1. Use Strong Passwords:
    • Example: KtmTraffic$2024! (avoid password123).
    • Tool: Use Bitwarden (open-source password manager).
  2. Enable MFA:
    • Example: Google Authenticator for eSewa/Ncell logins.
  3. Avoid Public Wi-Fi for Banking:
    • Use VPNs (e.g., ProtonVPN) on unsecured networks.
  4. Verify Before Sharing:
    • Example: If "NEPSE support" calls asking for OTPs, hang up and call official helpline.
  5. Update Software:
    • Example: Keep WhatsApp updated to patch vulnerabilities.

Worked Example: Spotting a Fake Ncell SMS

  • Real SMS: "Your Ncell bill is due. Pay here: [official link]."
  • Fake SMS: "URGENT: Your Ncell account is suspended! Click [suspicious link] to reactivate."
  • Red Flags:
    • Poor grammar/spelling.
    • Links to non-Ncell domains (e.g., ncell-support[.]com).
    • Urgency pressure.

6. Cybersecurity Careers in Nepal

Role Responsibilities Salary Range (NPR) Where to Start
Ethical Hacker Legally test systems for vulnerabilities. 80,000–200,000 Certifications: CEH, OSCP.
Cybersecurity Analyst Monitor networks for threats (e.g., at NTC, Ncell). 70,000–180,000 Learn SIEM tools (Splunk, Wazuh).
Data Privacy Officer Ensure compliance with laws (e.g., at banks, eSewa). 90,000–220,000 Study GDPR, Nepal’s Privacy Act.
IT Auditor Audit systems for security gaps (e.g., at NEPSE, Daraz). 100,000–250,000 Certifications: CISA, CISM.

In the Real World

  1. eSewa’s Encryption:

    • Idea Used: AES-256 encryption for financial transactions.
    • How: When you transfer Rs. 5,000 to a friend, the data is encrypted before leaving your device, ensuring hackers can’t read it even if they intercept it. This is critical because 60% of Nepali internet users access eSewa via mobile, often on unsecured networks.
  2. Pathao’s Driver Verification:

    • Idea Used: Biometric authentication + background checks.
    • How: Before approving a driver, Pathao verifies their fingerprint and face scan, then cross-checks their license and criminal record. This reduces scams (e.g., fake drivers stealing fares) by 50% compared to manual verification.
  3. NEPSE’s Trading System Security:

    • Idea Used: Multi-factor authentication (MFA) + audit logs.
    • How: To buy/sell stocks, traders must enter:
      • Password
      • OTP from their registered phone
      • Fingerprint (if using a biometric device)
    • Real Impact: During the 2023 market crash, NEPSE’s MFA system blocked 12,000 unauthorized trades, preventing panic selling.

Exam Tip

  1. Define and Differentiate:

    • Example Question: "Distinguish between a firewall and an intrusion detection system (IDS)."
    • Answer:
      Firewall Intrusion Detection System (IDS)
      Blocks unauthorized traffic based on rules. Monitors traffic for suspicious activity.
      Works at the network/host level. Works at the application/data level.
      Example: Ncell’s border router. Example: NTC’s SIEM tool analyzing logs.
  2. Case Study Analysis:

    • Example Question: "How would you secure a Daraz seller account from hacking?"
    • Answer:
      1. Enable MFA (OTP + fingerprint).
      2. Use a strong, unique password (never reuse).
      3. Disable auto-login on shared devices.
      4. Monitor account activity via Daraz’s security dashboard.
      5. Educate staff on phishing (e.g., fake "order cancellation" emails).
  3. Ethical Scenario Questions:

    • Example Question: "Your friend asks you to crack a neighbor’s Wi-Fi password. What are the ethical and legal consequences?"
    • Answer:
      • Ethical: Violates transparency and privacy (unauthorized access).
      • Legal: Under Nepal’s Cyber Crime Act 2074, punishable by 3 months to 5 years jail.
      • Alternative: Advise your friend to use legal methods (e.g., asking the neighbor for the password).
  4. Diagram-Based Questions:

    • Example Question: "Draw a sequence diagram showing how a phishing email leads to data theft."
    • Solution: Use the mermaid sequenceDiagram from Section 1, but label it for the exam:
sequenceDiagram
  participant User
  participant PhishingEmail as Phishing Email (Fake Bank Alert)
  participant Hacker
  participant BankDB as Bank Database
  User->>PhishingEmail: Clicks "Bank Alert" link
  PhishingEmail-->>User: Redirects to fake bank login page (URL: fakebank.com)
  User->>PhishingEmail: Enters credentials (username/password)
  PhishingEmail->>Hacker: Sends credentials via HTTP
  Hacker->>BankDB: Withdraws Rs. 50,000
  BankDB-->>Hacker: Transaction confirmation
  Hacker-->>User: Sends empty receipt (covering tracks)
  1. Short-Answer Focus:
    • Memorize these high-yield terms:
      • Ransomware: Malware that encrypts files and demands payment (e.g., 2021 attack on a Kathmandu hospital).
      • Ethical Hacking: Legally testing systems for vulnerabilities (e.g., hired by Ncell to find flaws).
      • GDPR: Global data privacy law (Nepal’s Privacy Act is modeled after it).
      • Zero-Day Exploit: Attack on an unknown vulnerability (e.g., WhatsApp’s 2019 spyware flaw).

Final Note: Cybersecurity is not just IT’s job—every user (from Daraz sellers to NEPSE traders) must practice safe habits. In exams, always link theory to real-world examples (e.g., Ncell frauds, eSewa encryption). Use diagrams for protocols (e.g., HTTPS handshake) and tables for comparisons (e.g., firewall vs. IDS).

Based on the PU BBA (PU) syllabus for Computer and IT Applications, unit 10.

Discussion

Loading…