Computer NetworksUnit 1014 min read

Network Security: Threats, Protocols, Encryption & Defense Mechanisms

Unit 10 of Computer Networks covers network security fundamentals, including threats (malware, DoS, MITM), cryptographic algorithms (RSA, AES, hashing), secure protocols (HTTPS, SSH, VPN), firewalls, intrusion detection, and real-world applications like eSewa’s encrypted transactions and Ncell’s secure authentication s

TAKEAWAYS:

  • Network security protects data integrity, confidentiality, and availability using encryption (symmetric/asymmetric), authentication (biometrics, certificates), and access control (firewalls, IDS).
  • HTTPS secures web traffic via TLS/SSL, while VPNs create encrypted tunnels over untrusted networks (e.g., Pathao drivers using VPNs for customer data).
  • RSA (asymmetric encryption) and AES (symmetric) are foundational for secure communications—e.g., Khalti uses RSA for key exchange and AES for transaction data.
  • Denial-of-Service (DoS/DDoS) attacks exploit network layers (e.g., SYN flood at Transport Layer); mitigation includes rate limiting and anycast routing (used by NTC for load balancing).
  • Firewalls filter traffic based on rules (stateless/stateful), while intrusion detection systems (IDS) monitor anomalies (e.g., Daraz’s servers detect brute-force login attempts).
  • Secure protocols like SSH (secure shell) and DNSSEC (secure DNS) prevent eavesdropping and spoofing—critical for remote access (e.g., NEPSE traders using SSH for secure trading terminals).

1. Introduction to Network Security

Network security refers to the protection of data, devices, and networks from unauthorized access, misuse, or attacks. It ensures the CIA triad:

  • Confidentiality: Data is accessible only to authorized users (e.g., bank transactions in eSewa).
  • Integrity: Data is not altered in transit (e.g., Khalti’s checksum validation).
  • Availability: Systems are operational when needed (e.g., Ncell’s 911 emergency services).

Why is Network Security Critical?

  • Financial loss: Unauthorized transactions (e.g., credit card fraud in Daraz).
  • Reputation damage: Data breaches (e.g., NTC’s customer data leaks).
  • Legal consequences: Non-compliance with laws like Nepal’s Electronic Transactions Act, 2008.

2. Common Network Threats and Attacks

Attacks target vulnerabilities at different OSI layers. Visualize the OSI model with attack examples:

Application (Layer 7)DataPresentation (6)DataSession (5)DataTransport (4)SegmentNetwork (3)PacketData Link (2)FramePhysical (1)Bits
OSI Model with Layer-Specific Attack Examples

Key Threats by Layer

Layer Attack Type Example Real-World Impact
Application Malware, Phishing Fake eSewa login pages stealing credentials. Financial theft.
Transport SYN Flood (DoS) Overwhelms servers (e.g., NEPSE trading platforms during crashes). Downtime, lost trades.
Network IP Spoofing, Man-in-the-Middle Hacker intercepts Khalti transactions between user and bank. Unauthorized fund transfers.
Data Link ARP Spoofing Redirects traffic to a rogue device (e.g., Pathao driver’s hotspot). Data theft, GPS tracking.
Physical Eavesdropping, Tampering Unauthorized access to NTC fiber cables. Government/commercial espionage.

3. Cryptography: The Backbone of Security

Cryptography converts data (plaintext) into ciphertext using algorithms. Two main types:

016324863Version4 bitsHeaderLength4 bitsType ofService8 bitsTotal Length16 bitsIdentification16 bitsFlags3 bitsFragmentOffset13 bitsTime toLive (TTL)8 bitsProtocol8 bitsHeader Checksum16 bitsSource IP32 bitsDestination IP32 bits
IPv4 Header Structure (Key Fields for Spoofing Attacks)

A. Symmetric Encryption (Shared Key)

  • Algorithm: AES (Advanced Encryption Standard).
  • How it works:
    • Same key encrypts/decrypts data.
    • Faster than asymmetric but key distribution is risky.
  • Example:
    • eSewa uses AES-256 to encrypt transaction details between user and bank.
    • Worked Example: If Alice sends ₹5,000 to Bob via eSewa, the data is encrypted with AES:
      Plaintext: "Transfer ₹5000 to Bob"
      Key: "eSewaKey123" (shared securely via RSA)
      Ciphertext: "ب¥¢¤£¥¢¤£¥¢¤£" (unreadable without key)
      

B. Asymmetric Encryption (Public-Private Key)

  • Algorithm: RSA (Rivest-Shamir-Adleman).
  • How it works:
    • Public key encrypts; private key decrypts.
    • Solves key distribution problem (e.g., HTTPS).
  • RSA Worked Example:
    • Ncell’s secure login:
      1. User’s device generates a random session key.
      2. Ncell’s server encrypts it with Ncell’s public key.
      3. User decrypts with Ncell’s private key (stored securely).
      4. All further data uses this symmetric session key (faster).
sequenceDiagram
    User->>Ncell: "Login Request"
    Ncell->>User: "Public Key (RSA)"
    User->>User: "Generate Symmetric Key (AES)"
    User->>Ncell: "Encrypted Key (RSA Public)"
    Ncell->>Ncell: "Decrypt with Private Key"
    User->>Ncell: "Encrypted Data (AES)"
    Ncell->>User: "Verify & Authenticate"

C. Hashing (One-Way Encryption)

  • Algorithm: SHA-256 (Secure Hash Algorithm).
  • Purpose: Ensures data integrity (e.g., file downloads, passwords).
  • Example:
    • Khalti’s password storage:
      • User enters Password123.
      • Khalti hashes it: SHA-256("Password123") = "5e884898da28047151d0e56f8dc6292773603d0d6aabbdd62a11ef721d1542d8".
      • Stores only the hash; compares hashes during login.

4. Secure Protocols

Protocols add security layers to existing services.

A. HTTPS (HTTP + TLS/SSL)

  • How it works:
    1. Browser requests https://esewa.com.
    2. Server sends digital certificate (issued by CA like Let’s Encrypt).
    3. Browser verifies certificate → establishes TLS handshake.
    4. Symmetric key exchange (AES) for encrypted communication.
  • Comparison: HTTP vs. HTTPS
Feature HTTP HTTPS
Security No encryption (plaintext) Encrypted (TLS/SSL)
Port 80 443
Use Case Internal networks (e.g., intranet) Public websites (e.g., Daraz, eSewa)
Performance Faster (no encryption overhead) Slightly slower
Trust Vulnerable to MITM attacks Secure (certificate validation)

B. VPN (Virtual Private Network)

  • How it works:
    • Creates a secure tunnel over untrusted networks (e.g., public Wi-Fi).
    • Uses IPsec or OpenVPN for encryption.
  • Example:
    • Pathao drivers use VPNs to securely transmit passenger locations to the central server, preventing GPS spoofing.
VPN Tunnel (Encrypted)Secure ConnectionUnencrypted (Blocked)Public InternetUser DeviceVPN ServerPathao Central ServerPublic Internet
VPN Tunnel for Secure Data Transmission (Pathao Example)

C. SSH (Secure Shell)

  • Purpose: Secure remote login/replacement for Telnet.
  • Example:
    • NEPSE traders use SSH to access trading terminals from home, preventing eavesdropping.

5. Firewalls and Intrusion Detection

Inbound TrafficAllowed (HTTP/HTTPS)Strictly FilteredOutbound ResponsesInternal NetworkFirewallDMZInternet
Firewall Architecture with DMZ for NTC’s Web Services

A. Firewalls

  • Types:
    • Packet-filtering: Checks headers (e.g., block port 22 except for Ncell’s IP).
    • Stateful: Tracks connections (e.g., allows return traffic for established sessions).
    • Application-level: Inspects payload (e.g., blocks SQL injection in Daraz’s checkout).
  • Example:
    • NTC’s firewall rules:
      ALLOW TCP 80 (HTTP) from any to web servers
      ALLOW TCP 443 (HTTPS) from any to web servers
      BLOCK TCP 22 (SSH) except from NTC admin IPs
      

B. Intrusion Detection Systems (IDS)

  • Types:
    • Signature-based: Matches known attack patterns (e.g., SQLi strings).
    • Anomaly-based: Detects deviations (e.g., sudden spike in login attempts to eSewa).
  • Example:
    • Daraz’s IDS flags unusual order patterns (e.g., 100 identical items in 1 second = bot).

6. Network Security Mechanisms

Mechanism Purpose Example
Authentication Verify user identity OTP (One-Time Password) in Khalti
Authorization Grant access rights Role-based access in NEPSE terminals
Encryption Protect data in transit AES for eSewa transactions
Access Control Restrict network entry Firewall rules for NTC routers
Audit Logging Track activities for forensics Ncell call logs for fraud detection

7. Real-World Applications

A. eSewa: Secure Transactions

  • How it uses security:
    1. HTTPS: Encrypts user-bank communication.
    2. RSA: Exchanges session keys.
    3. AES: Encrypts transaction data.
    4. OTP: Two-factor authentication.
  • Threat mitigated: Man-in-the-middle attacks (e.g., intercepting payment details).

B. Khalti: Fraud Prevention

  • Mechanisms:
    • Biometric authentication (fingerprint/face ID).
    • Transaction limits (e.g., ₹50,000/day without OTP).
    • Behavioral analysis (flags unusual spending patterns).

C. Ncell: Secure Authentication

  • Challenge: SIM swapping attacks.
  • Solution:
    • SMS OTP + App-based OTP (two-factor).
    • Device fingerprinting (blocks logins from new devices).

D. Daraz: DDoS Protection

  • Problem: Black Friday traffic spikes cause outages.
  • Solution:
    • Anycast routing: Distributes traffic across multiple servers.
    • Rate limiting: Blocks malicious requests (e.g., 10 requests/second per IP).

8. Case Study: NTC’s Network Security

Scenario: NTC’s fiber-optic network is targeted by a DDoS attack during peak hours. Security Measures:

  1. Firewall: Drops malformed packets.
  2. IDS: Detects traffic anomalies (e.g., 10x normal traffic from a single IP).
  3. Load Balancing: Distributes traffic across redundant routers.
  4. VPN for Remote Access: Securely connects field technicians to the central network.
DDoS TrafficFiltered TrafficRedundant Path 1Redundant Path 2Secure ConnectionSecure ConnectionAttackerNTC FirewallLoad BalancerRouter 1Router 2NTC Central Server
NTC’s Multi-Layered Security Architecture

Outcome: Attack is mitigated; 99.9% uptime maintained.


9. Exam Tip: How to Score Full Marks

  1. Diagrams are mandatory:

    • Draw OSI layer attacks, RSA handshake, or firewall rules to explain concepts.
    • Example: For HTTPS, show the TLS handshake sequence diagram.
  2. Compare and contrast:

    • Questions often ask to compare HTTP vs. HTTPS, symmetric vs. asymmetric encryption, or firewall types. Use tables.
  3. Real-world examples:

    • Link theories to eSewa, Khalti, Ncell, or Daraz. For instance:
      • "Like how Khalti uses OTP for authentication, a network can use CHAP (Challenge-Handshake Authentication Protocol) for secure login."
  4. Worked examples:

    • For RSA, show key generation and encryption steps.
    • For AES, describe how a 128-bit key works (even if simplified).
  5. Common pitfalls:

    • Don’t confuse:
      • Hashing (one-way) vs. encryption (reversible).
      • Firewall (prevents attacks) vs. IDS (detects attacks).
    • Always justify: If you say "HTTPS is secure," explain why (TLS, certificates).
  6. Past exam patterns:

    • Part (a): Short definitions (e.g., "What is a digital certificate?").
    • Part (b): Long explanations (e.g., "Explain RSA with a diagram").
    • Diagrams: Always label components (e.g., in a TLS handshake, label "ClientHello," "ServerHello," "Session Key").

10. Summary Checklist

Before the exam, ensure you can:

  • Explain CIA triad with examples from eSewa/Khalti.
  • Differentiate symmetric (AES) vs. asymmetric (RSA) encryption.
  • Draw a TLS/HTTPS handshake sequence diagram.
  • Describe how a firewall filters traffic (with rules for NTC).
  • List 3 real-world security breaches in Nepal (e.g., Nepal Rastra Bank’s 2018 data leak) and their causes.
  • Solve a worked example: "If a bank uses RSA with a 1024-bit key, how does it securely exchange a symmetric key with a customer?"

Based on the PU BE Computer (PU) syllabus for Computer Networks, unit 10.

Discussion

Loading…