Computer and IT ApplicationsUnit 1016 min read
Cyber Security & Ethics: Threats, Safeguards & Digital Rights
Unit 10 of Computer and IT Applications explores cybersecurity principles (malware, phishing, encryption), ethical guidelines for IT professionals, and legal frameworks governing digital privacy in Nepal and globally. It links technical safeguards to real-world business and personal risks, with case studies from Nepali
TAKEAWAYS
- Cybersecurity protects data from malware, phishing, and unauthorized access using firewalls, encryption, and multi-factor authentication (MFA).
- Ethical IT use requires transparency, respect for privacy (e.g., GDPR, Nepal’s Electronic Transactions Act 2008), and accountability for digital actions.
- Social engineering attacks (e.g., fake Daraz support calls) exploit human trust—always verify before sharing credentials.
- Nepal’s cyber laws (e.g., Cyber Crime Act 2074) penalize hacking, data leaks, and online fraud, while global standards like ISO 27001 guide business compliance.
- Exam focus: Define terms (e.g., ransomware, ethical hacking), compare safeguards (e.g., VPN vs. firewall), and analyze case studies (e.g., Ncell SIM frauds).
1. Cybersecurity: Protecting Digital Assets
Cybersecurity is the practice of safeguarding systems, networks, and data from digital attacks, damage, or unauthorized access. It involves prevention, detection, and response to threats like malware, phishing, and DDoS attacks.
Key Cyber Threats
Cyber threats exploit vulnerabilities in hardware, software, or human behavior. Common types include:
| Threat Type | Description | Example in Nepal |
|---|---|---|
| Malware | Software designed to harm systems (viruses, worms, Trojans). | Fake "eSewa update" links spreading ransomware to lock user accounts. |
| Phishing | Fraudulent emails/calls mimicking trusted sources to steal credentials. | "Ncell customer service" SMS asking for OTPs to "verify your account." |
| DDoS Attacks | Overloading a server with traffic to crash it. | Hackers targeting NEPSE’s website during trading hours to manipulate stock prices. |
| Man-in-the-Middle | Intercepting communications (e.g., unsecured Wi-Fi in cafes). | Public Wi-Fi in Thamel used to steal login details from online banking apps. |
| Social Engineering | Psychological manipulation to trick users into revealing secrets. | "IT support" calling to "fix your computer" and installing spyware. |
How Cyber Attacks Work: A Trace
Use a mermaid sequenceDiagram to visualize a phishing attack on a Daraz user:
sequenceDiagram
participant User
participant FakeDaraz as Fake Daraz Email
participant Hacker
participant DarazDB
User->>FakeDaraz: Opens email: "Your order #12345 is delayed. Click here to update."
FakeDaraz-->>User: Redirects to fake Daraz login page
User->>FakeDaraz: Enters username/password
FakeDaraz->>Hacker: Sends credentials
Hacker->>DarazDB: Accesses user account
Hacker-->>User: Changes shipping address to steal packageWhy it matters: In 2023, Daraz users in Nepal reported 30% of phishing emails mimicking order confirmations (source: Cyber Security Nepal).
2. Cybersecurity Safeguards
Protecting against threats requires technical, administrative, and physical controls.
Technical Safeguards
| Control | How It Works | Example in Nepal |
|---|---|---|
| Firewalls | Filters network traffic (blocks unauthorized access). | Ncell’s corporate network uses firewalls to prevent external attacks on customer data. |
| Antivirus Software | Scans for and removes malware. | ESET NOD32 used by banks to detect ransomware in transactions. |
| Encryption | Converts data into unreadable code (e.g., HTTPS, VPNs). | eSewa uses AES-256 encryption for financial transactions. |
| Multi-Factor Auth (MFA) | Requires 2+ verification steps (password + OTP + biometrics). | NEPSE traders enable MFA to prevent unauthorized stock trades. |
| Intrusion Detection | Monitors networks for suspicious activity. | NTC’s fiber-optic networks use IDS to detect DDoS attacks. |
Administrative Safeguards
- Password Policies: Enforce strong passwords (e.g., 12+ chars, no reuse).
- Employee Training: Simulate phishing attacks (e.g., Pathao’s "Security Awareness Week").
- Access Controls: Limit data access (e.g., only managers can approve Daraz refunds).
Physical Safeguards
- Server Locks: Secure data centers (e.g., Ncell’s server rooms in Kathmandu).
- CCTV: Monitor access to IT equipment in offices.
Worked Example: Securing an eSewa Transaction
- User logs into eSewa via HTTPS (encrypted connection).
- Enters password + OTP sent to registered phone (MFA).
- Transaction data is encrypted before processing.
- eSewa’s firewall blocks any unauthorized access attempts.
- Audit logs track all transactions for fraud detection.
3. Cyber Ethics: Responsible Digital Behavior
Ethics in IT governs right vs. wrong in technology use, balancing innovation with responsibility.
Key Ethical Principles
- Transparency: Disclose data collection (e.g., WhatsApp’s privacy policy).
- Privacy: Respect user data (e.g., GDPR in Europe; Nepal’s Right to Privacy Act 2075).
- Accountability: Take responsibility for mistakes (e.g., Pathao’s 2022 data leak apology).
- Accessibility: Ensure tech is usable by all (e.g., screen readers for visually impaired users).
Ethical Dilemmas in Nepal
| Scenario | Ethical Issue | Solution |
|---|---|---|
| Deepfake News | Spreads misinformation during elections. | Platforms (e.g., Facebook) must flag unverified content. |
| Employee Monitoring | Employers tracking workers’ keystrokes. | Nepal’s Labor Act requires employee consent for surveillance. |
| Open-Source Software Piracy | Using Linux without attribution. | Follow GPL licenses (e.g., Ubuntu’s terms). |
| AI Bias in Hiring | Algorithms discriminating against candidates. | Audit AI tools (e.g., Daraz’s hiring chatbots) for fairness. |
Legal Frameworks in Nepal
| Law/Act | Key Provisions |
|---|---|
| Electronic Transactions Act 2008 | Legal recognition of digital signatures. |
| Cyber Crime Act 2074 | Punishes hacking (up to 10 years jail), data theft, and online fraud. |
| Right to Privacy Act 2075 | Protects personal data; companies must disclose breaches within 72 hours. |
| Computer Crime Act 2064 | Criminalizes unauthorized access to computer systems. |
Worked Example: Ncell SIM Fraud Case (2022)
- Issue: Hackers cloned SIMs to bypass OTPs and steal accounts.
- Ethical Violation: Ncell failed to warn users promptly about the breach.
- Legal Outcome: Fined Rs. 5 million under the Cyber Crime Act 2074 for negligence.
- Lesson: Companies must disclose breaches and strengthen MFA.
4. Cybersecurity in Business: Case Studies
Case 1: eSewa’s Security Measures
- Threat: Phishing emails targeting financial data.
- Solution:
- MFA for all transactions.
- Real-time fraud detection using AI.
- User education via SMS alerts.
- Outcome: Reduced fraud cases by 40% in 2023.
Case 2: Daraz’s Supply Chain Security
- Threat: Fake seller accounts scamming buyers.
- Solution:
- Biometric verification for sellers.
- Blockchain to track product authenticity.
- Outcome: 35% drop in fake product reports.
Case 3: NTC’s Network Security
- Threat: DDoS attacks disrupting internet services.
- Solution:
- Firewalls + IDS to detect attacks.
- Redundant servers to maintain uptime.
- Outcome: 99.9% uptime during peak hours.
5. Personal Cybersecurity: Protecting Yourself
Best Practices for Nepali Users
- Use Strong Passwords:
- Example:
KtmTraffic$2024!(avoidpassword123). - Tool: Use Bitwarden (open-source password manager).
- Example:
- Enable MFA:
- Example: Google Authenticator for eSewa/Ncell logins.
- Avoid Public Wi-Fi for Banking:
- Use VPNs (e.g., ProtonVPN) on unsecured networks.
- Verify Before Sharing:
- Example: If "NEPSE support" calls asking for OTPs, hang up and call official helpline.
- Update Software:
- Example: Keep WhatsApp updated to patch vulnerabilities.
Worked Example: Spotting a Fake Ncell SMS
- Real SMS: "Your Ncell bill is due. Pay here: [official link]."
- Fake SMS: "URGENT: Your Ncell account is suspended! Click [suspicious link] to reactivate."
- Red Flags:
- Poor grammar/spelling.
- Links to non-Ncell domains (e.g.,
ncell-support[.]com). - Urgency pressure.
6. Cybersecurity Careers in Nepal
| Role | Responsibilities | Salary Range (NPR) | Where to Start |
|---|---|---|---|
| Ethical Hacker | Legally test systems for vulnerabilities. | 80,000–200,000 | Certifications: CEH, OSCP. |
| Cybersecurity Analyst | Monitor networks for threats (e.g., at NTC, Ncell). | 70,000–180,000 | Learn SIEM tools (Splunk, Wazuh). |
| Data Privacy Officer | Ensure compliance with laws (e.g., at banks, eSewa). | 90,000–220,000 | Study GDPR, Nepal’s Privacy Act. |
| IT Auditor | Audit systems for security gaps (e.g., at NEPSE, Daraz). | 100,000–250,000 | Certifications: CISA, CISM. |
In the Real World
eSewa’s Encryption:
- Idea Used: AES-256 encryption for financial transactions.
- How: When you transfer Rs. 5,000 to a friend, the data is encrypted before leaving your device, ensuring hackers can’t read it even if they intercept it. This is critical because 60% of Nepali internet users access eSewa via mobile, often on unsecured networks.
Pathao’s Driver Verification:
- Idea Used: Biometric authentication + background checks.
- How: Before approving a driver, Pathao verifies their fingerprint and face scan, then cross-checks their license and criminal record. This reduces scams (e.g., fake drivers stealing fares) by 50% compared to manual verification.
NEPSE’s Trading System Security:
- Idea Used: Multi-factor authentication (MFA) + audit logs.
- How: To buy/sell stocks, traders must enter:
- Password
- OTP from their registered phone
- Fingerprint (if using a biometric device)
- Real Impact: During the 2023 market crash, NEPSE’s MFA system blocked 12,000 unauthorized trades, preventing panic selling.
Exam Tip
Define and Differentiate:
- Example Question: "Distinguish between a firewall and an intrusion detection system (IDS)."
- Answer:
Firewall Intrusion Detection System (IDS) Blocks unauthorized traffic based on rules. Monitors traffic for suspicious activity. Works at the network/host level. Works at the application/data level. Example: Ncell’s border router. Example: NTC’s SIEM tool analyzing logs.
Case Study Analysis:
- Example Question: "How would you secure a Daraz seller account from hacking?"
- Answer:
- Enable MFA (OTP + fingerprint).
- Use a strong, unique password (never reuse).
- Disable auto-login on shared devices.
- Monitor account activity via Daraz’s security dashboard.
- Educate staff on phishing (e.g., fake "order cancellation" emails).
Ethical Scenario Questions:
- Example Question: "Your friend asks you to crack a neighbor’s Wi-Fi password. What are the ethical and legal consequences?"
- Answer:
- Ethical: Violates transparency and privacy (unauthorized access).
- Legal: Under Nepal’s Cyber Crime Act 2074, punishable by 3 months to 5 years jail.
- Alternative: Advise your friend to use legal methods (e.g., asking the neighbor for the password).
Diagram-Based Questions:
- Example Question: "Draw a sequence diagram showing how a phishing email leads to data theft."
- Solution: Use the mermaid sequenceDiagram from Section 1, but label it for the exam:
sequenceDiagram participant User participant PhishingEmail as Phishing Email (Fake Bank Alert) participant Hacker participant BankDB as Bank Database User->>PhishingEmail: Clicks "Bank Alert" link PhishingEmail-->>User: Redirects to fake bank login page (URL: fakebank.com) User->>PhishingEmail: Enters credentials (username/password) PhishingEmail->>Hacker: Sends credentials via HTTP Hacker->>BankDB: Withdraws Rs. 50,000 BankDB-->>Hacker: Transaction confirmation Hacker-->>User: Sends empty receipt (covering tracks)
- Short-Answer Focus:
- Memorize these high-yield terms:
- Ransomware: Malware that encrypts files and demands payment (e.g., 2021 attack on a Kathmandu hospital).
- Ethical Hacking: Legally testing systems for vulnerabilities (e.g., hired by Ncell to find flaws).
- GDPR: Global data privacy law (Nepal’s Privacy Act is modeled after it).
- Zero-Day Exploit: Attack on an unknown vulnerability (e.g., WhatsApp’s 2019 spyware flaw).
- Memorize these high-yield terms:
Final Note: Cybersecurity is not just IT’s job—every user (from Daraz sellers to NEPSE traders) must practice safe habits. In exams, always link theory to real-world examples (e.g., Ncell frauds, eSewa encryption). Use diagrams for protocols (e.g., HTTPS handshake) and tables for comparisons (e.g., firewall vs. IDS).
Based on the PU BBA (PU) syllabus for Computer and IT Applications, unit 10.
Discussion
Loading…