Computer NetworksUnit 1014 min read
Network Security: Threats, Protocols, Encryption & Defense Mechanisms
Unit 10 of Computer Networks covers network security fundamentals, including threats (malware, DoS, MITM), cryptographic algorithms (RSA, AES, hashing), secure protocols (HTTPS, SSH, VPN), firewalls, intrusion detection, and real-world applications like eSewa’s encrypted transactions and Ncell’s secure authentication s
TAKEAWAYS:
- Network security protects data integrity, confidentiality, and availability using encryption (symmetric/asymmetric), authentication (biometrics, certificates), and access control (firewalls, IDS).
- HTTPS secures web traffic via TLS/SSL, while VPNs create encrypted tunnels over untrusted networks (e.g., Pathao drivers using VPNs for customer data).
- RSA (asymmetric encryption) and AES (symmetric) are foundational for secure communications—e.g., Khalti uses RSA for key exchange and AES for transaction data.
- Denial-of-Service (DoS/DDoS) attacks exploit network layers (e.g., SYN flood at Transport Layer); mitigation includes rate limiting and anycast routing (used by NTC for load balancing).
- Firewalls filter traffic based on rules (stateless/stateful), while intrusion detection systems (IDS) monitor anomalies (e.g., Daraz’s servers detect brute-force login attempts).
- Secure protocols like SSH (secure shell) and DNSSEC (secure DNS) prevent eavesdropping and spoofing—critical for remote access (e.g., NEPSE traders using SSH for secure trading terminals).
1. Introduction to Network Security
Network security refers to the protection of data, devices, and networks from unauthorized access, misuse, or attacks. It ensures the CIA triad:
- Confidentiality: Data is accessible only to authorized users (e.g., bank transactions in eSewa).
- Integrity: Data is not altered in transit (e.g., Khalti’s checksum validation).
- Availability: Systems are operational when needed (e.g., Ncell’s 911 emergency services).
Why is Network Security Critical?
- Financial loss: Unauthorized transactions (e.g., credit card fraud in Daraz).
- Reputation damage: Data breaches (e.g., NTC’s customer data leaks).
- Legal consequences: Non-compliance with laws like Nepal’s Electronic Transactions Act, 2008.
2. Common Network Threats and Attacks
Attacks target vulnerabilities at different OSI layers. Visualize the OSI model with attack examples:
Key Threats by Layer
| Layer | Attack Type | Example | Real-World Impact |
|---|---|---|---|
| Application | Malware, Phishing | Fake eSewa login pages stealing credentials. | Financial theft. |
| Transport | SYN Flood (DoS) | Overwhelms servers (e.g., NEPSE trading platforms during crashes). | Downtime, lost trades. |
| Network | IP Spoofing, Man-in-the-Middle | Hacker intercepts Khalti transactions between user and bank. | Unauthorized fund transfers. |
| Data Link | ARP Spoofing | Redirects traffic to a rogue device (e.g., Pathao driver’s hotspot). | Data theft, GPS tracking. |
| Physical | Eavesdropping, Tampering | Unauthorized access to NTC fiber cables. | Government/commercial espionage. |
3. Cryptography: The Backbone of Security
Cryptography converts data (plaintext) into ciphertext using algorithms. Two main types:
A. Symmetric Encryption (Shared Key)
- Algorithm: AES (Advanced Encryption Standard).
- How it works:
- Same key encrypts/decrypts data.
- Faster than asymmetric but key distribution is risky.
- Example:
- eSewa uses AES-256 to encrypt transaction details between user and bank.
- Worked Example:
If Alice sends ₹5,000 to Bob via eSewa, the data is encrypted with AES:
Plaintext: "Transfer ₹5000 to Bob" Key: "eSewaKey123" (shared securely via RSA) Ciphertext: "ب¥¢¤£¥¢¤£¥¢¤£" (unreadable without key)
B. Asymmetric Encryption (Public-Private Key)
- Algorithm: RSA (Rivest-Shamir-Adleman).
- How it works:
- Public key encrypts; private key decrypts.
- Solves key distribution problem (e.g., HTTPS).
- RSA Worked Example:
- Ncell’s secure login:
- User’s device generates a random session key.
- Ncell’s server encrypts it with Ncell’s public key.
- User decrypts with Ncell’s private key (stored securely).
- All further data uses this symmetric session key (faster).
- Ncell’s secure login:
sequenceDiagram
User->>Ncell: "Login Request"
Ncell->>User: "Public Key (RSA)"
User->>User: "Generate Symmetric Key (AES)"
User->>Ncell: "Encrypted Key (RSA Public)"
Ncell->>Ncell: "Decrypt with Private Key"
User->>Ncell: "Encrypted Data (AES)"
Ncell->>User: "Verify & Authenticate"C. Hashing (One-Way Encryption)
- Algorithm: SHA-256 (Secure Hash Algorithm).
- Purpose: Ensures data integrity (e.g., file downloads, passwords).
- Example:
- Khalti’s password storage:
- User enters
Password123. - Khalti hashes it:
SHA-256("Password123") = "5e884898da28047151d0e56f8dc6292773603d0d6aabbdd62a11ef721d1542d8". - Stores only the hash; compares hashes during login.
- User enters
- Khalti’s password storage:
4. Secure Protocols
Protocols add security layers to existing services.
A. HTTPS (HTTP + TLS/SSL)
- How it works:
- Browser requests
https://esewa.com. - Server sends digital certificate (issued by CA like Let’s Encrypt).
- Browser verifies certificate → establishes TLS handshake.
- Symmetric key exchange (AES) for encrypted communication.
- Browser requests
- Comparison: HTTP vs. HTTPS
| Feature | HTTP | HTTPS |
|---|---|---|
| Security | No encryption (plaintext) | Encrypted (TLS/SSL) |
| Port | 80 | 443 |
| Use Case | Internal networks (e.g., intranet) | Public websites (e.g., Daraz, eSewa) |
| Performance | Faster (no encryption overhead) | Slightly slower |
| Trust | Vulnerable to MITM attacks | Secure (certificate validation) |
B. VPN (Virtual Private Network)
- How it works:
- Creates a secure tunnel over untrusted networks (e.g., public Wi-Fi).
- Uses IPsec or OpenVPN for encryption.
- Example:
- Pathao drivers use VPNs to securely transmit passenger locations to the central server, preventing GPS spoofing.
C. SSH (Secure Shell)
- Purpose: Secure remote login/replacement for Telnet.
- Example:
- NEPSE traders use SSH to access trading terminals from home, preventing eavesdropping.
5. Firewalls and Intrusion Detection
A. Firewalls
- Types:
- Packet-filtering: Checks headers (e.g., block port 22 except for Ncell’s IP).
- Stateful: Tracks connections (e.g., allows return traffic for established sessions).
- Application-level: Inspects payload (e.g., blocks SQL injection in Daraz’s checkout).
- Example:
- NTC’s firewall rules:
ALLOW TCP 80 (HTTP) from any to web servers ALLOW TCP 443 (HTTPS) from any to web servers BLOCK TCP 22 (SSH) except from NTC admin IPs
- NTC’s firewall rules:
B. Intrusion Detection Systems (IDS)
- Types:
- Signature-based: Matches known attack patterns (e.g., SQLi strings).
- Anomaly-based: Detects deviations (e.g., sudden spike in login attempts to eSewa).
- Example:
- Daraz’s IDS flags unusual order patterns (e.g., 100 identical items in 1 second = bot).
6. Network Security Mechanisms
| Mechanism | Purpose | Example |
|---|---|---|
| Authentication | Verify user identity | OTP (One-Time Password) in Khalti |
| Authorization | Grant access rights | Role-based access in NEPSE terminals |
| Encryption | Protect data in transit | AES for eSewa transactions |
| Access Control | Restrict network entry | Firewall rules for NTC routers |
| Audit Logging | Track activities for forensics | Ncell call logs for fraud detection |
7. Real-World Applications
A. eSewa: Secure Transactions
- How it uses security:
- HTTPS: Encrypts user-bank communication.
- RSA: Exchanges session keys.
- AES: Encrypts transaction data.
- OTP: Two-factor authentication.
- Threat mitigated: Man-in-the-middle attacks (e.g., intercepting payment details).
B. Khalti: Fraud Prevention
- Mechanisms:
- Biometric authentication (fingerprint/face ID).
- Transaction limits (e.g., ₹50,000/day without OTP).
- Behavioral analysis (flags unusual spending patterns).
C. Ncell: Secure Authentication
- Challenge: SIM swapping attacks.
- Solution:
- SMS OTP + App-based OTP (two-factor).
- Device fingerprinting (blocks logins from new devices).
D. Daraz: DDoS Protection
- Problem: Black Friday traffic spikes cause outages.
- Solution:
- Anycast routing: Distributes traffic across multiple servers.
- Rate limiting: Blocks malicious requests (e.g., 10 requests/second per IP).
8. Case Study: NTC’s Network Security
Scenario: NTC’s fiber-optic network is targeted by a DDoS attack during peak hours. Security Measures:
- Firewall: Drops malformed packets.
- IDS: Detects traffic anomalies (e.g., 10x normal traffic from a single IP).
- Load Balancing: Distributes traffic across redundant routers.
- VPN for Remote Access: Securely connects field technicians to the central network.
Outcome: Attack is mitigated; 99.9% uptime maintained.
9. Exam Tip: How to Score Full Marks
Diagrams are mandatory:
- Draw OSI layer attacks, RSA handshake, or firewall rules to explain concepts.
- Example: For HTTPS, show the TLS handshake sequence diagram.
Compare and contrast:
- Questions often ask to compare HTTP vs. HTTPS, symmetric vs. asymmetric encryption, or firewall types. Use tables.
Real-world examples:
- Link theories to eSewa, Khalti, Ncell, or Daraz. For instance:
- "Like how Khalti uses OTP for authentication, a network can use CHAP (Challenge-Handshake Authentication Protocol) for secure login."
- Link theories to eSewa, Khalti, Ncell, or Daraz. For instance:
Worked examples:
- For RSA, show key generation and encryption steps.
- For AES, describe how a 128-bit key works (even if simplified).
Common pitfalls:
- Don’t confuse:
- Hashing (one-way) vs. encryption (reversible).
- Firewall (prevents attacks) vs. IDS (detects attacks).
- Always justify: If you say "HTTPS is secure," explain why (TLS, certificates).
- Don’t confuse:
Past exam patterns:
- Part (a): Short definitions (e.g., "What is a digital certificate?").
- Part (b): Long explanations (e.g., "Explain RSA with a diagram").
- Diagrams: Always label components (e.g., in a TLS handshake, label "ClientHello," "ServerHello," "Session Key").
10. Summary Checklist
Before the exam, ensure you can:
- Explain CIA triad with examples from eSewa/Khalti.
- Differentiate symmetric (AES) vs. asymmetric (RSA) encryption.
- Draw a TLS/HTTPS handshake sequence diagram.
- Describe how a firewall filters traffic (with rules for NTC).
- List 3 real-world security breaches in Nepal (e.g., Nepal Rastra Bank’s 2018 data leak) and their causes.
- Solve a worked example: "If a bank uses RSA with a 1024-bit key, how does it securely exchange a symmetric key with a customer?"
Based on the PU BE Computer (PU) syllabus for Computer Networks, unit 10.
Discussion
Loading…