Network and Cyber SecurityUnit 112 min read
Cyber Security Basics: Threats, Attacks, Defenses & Models
Unit 1 of Network and Cyber Security introduces core concepts of cyber security, including threats, vulnerabilities, attacks, security models (CIA triad, AAA), and fundamental security principles. It covers real-world examples, security architectures, and the importance of cyber security in modern systems.
TAKEAWAYS:
- Cyber security protects systems, networks, and data from unauthorized access, damage, or disruption.
- Threats (e.g., malware, phishing) exploit vulnerabilities in systems to cause attacks.
- The CIA triad (Confidentiality, Integrity, Availability) and AAA (Authentication, Authorization, Accounting) are foundational security models.
- Security principles like least privilege, defense in depth, and fail-safe defaults guide secure system design.
- Real-world applications include secure transactions (e.g., eSewa, Khalti) and network protocols (e.g., TLS in WhatsApp).
- Understanding cyber security threats and defenses is critical for designing secure systems and protecting digital assets.
1. Introduction to Cyber Security
Cyber security is the practice of protecting systems, networks, and data from digital attacks, unauthorized access, or damage. It encompasses technologies, processes, and practices designed to safeguard digital assets. In today’s interconnected world, cyber security is essential for individuals, businesses, and governments.
Key Concepts
- System: A collection of hardware, software, and processes working together (e.g., a computer, network, or cloud service).
- Network: A group of interconnected systems sharing resources (e.g., the internet, a corporate LAN).
- Data: Information stored or transmitted digitally (e.g., personal records, financial transactions).
- Threat: Any potential danger to a system (e.g., hackers, malware).
- Vulnerability: A weakness in a system that can be exploited by threats.
- Attack: An attempt to exploit vulnerabilities (e.g., phishing, DDoS).
2. Threats, Vulnerabilities, and Attacks
Threats
Threats can be categorized as follows:
- Natural Threats: Disasters like floods or earthquakes.
- Human Threats:
- Accidental: Human errors (e.g., misconfigurations, data leaks).
- Intentional:
- Internal: Employees or insiders (e.g., disgruntled employees leaking data).
- External: Hackers, competitors, or cybercriminals.
- Environmental Threats: Power outages, hardware failures.
Vulnerabilities
Vulnerabilities are weaknesses in systems, software, or human behavior. Examples:
- Software Vulnerabilities: Unpatched bugs (e.g., Heartbleed in OpenSSL).
- Hardware Vulnerabilities: Faulty routers or unsecured IoT devices.
- Human Vulnerabilities: Phishing emails tricking users into revealing passwords.
Attacks
Attacks exploit vulnerabilities to compromise systems. Common types:
| Attack Type | Description | Example |
|---|---|---|
| Malware | Malicious software (viruses, worms, ransomware). | WannaCry ransomware attack. |
| Phishing | Tricking users into revealing sensitive information. | Fake eSewa login pages. |
| Denial of Service (DoS/DDoS) | Overloading systems to disrupt services. | DDoS attacks on NTC or Ncell. |
| Man-in-the-Middle (MitM) | Intercepting communications between two parties. | Unsecured Wi-Fi eavesdropping. |
| SQL Injection | Exploiting SQL databases to steal or manipulate data. | Hacking Daraz customer databases. |
| Social Engineering | Manipulating human behavior to gain access. | Impersonating a bank officer. |
3. Security Models: CIA Triad and AAA
CIA Triad
The Confidentiality, Integrity, Availability (CIA) triad is the foundation of cyber security:
mindmap
root((CIA Triad))
Confidentiality
Ensures data is accessible only to authorized users.
Example: Encryption (e.g., WhatsApp end-to-end encryption).
Integrity
Ensures data is accurate and unaltered.
Example: Hash functions (e.g., SHA-256 for file verification).
Availability
Ensures systems and data are accessible when needed.
Example: Redundant servers (e.g., Google Cloud failover).AAA Framework
Authentication, Authorization, Accounting (AAA) ensures secure access to resources:
| Component | Description | Example |
|---|---|---|
| Authentication | Verifies the identity of users or devices. | Username + password, biometrics. |
| Authorization | Determines what authenticated users can access. | Role-based access (e.g., admin vs. user). |
| Accounting | Tracks user activities for auditing. | Logs of login attempts (e.g., bank transactions). |
4. Security Principles
Five fundamental principles guide secure system design:
| Principle | Description | Example |
|---|---|---|
| Least Privilege | Users/processes get only the minimum access needed. | Restricting database access to admins. |
| Defense in Depth | Layered security (e.g., firewalls, encryption, IDS). | TLS + Firewall + Antivirus. |
| Fail-Safe Defaults | Systems default to a secure state. | Disabling ports unless explicitly enabled. |
| Separation of Duties | No single user controls critical functions. | Two-factor approval for transfers. |
| Minimization | Reduce attack surfaces (e.g., disable unused services). | Disabling FTP on a web server. |
In the Real World
eSewa and Khalti (Nepal):
- Idea Used: Authentication and Authorization (AAA).
- How: These apps use multi-factor authentication (password + OTP) to verify users (Authentication) and restrict transactions based on user roles (Authorization). Accounting logs track every transaction for auditing.
WhatsApp (Global):
- Idea Used: Confidentiality (CIA Triad).
- How: WhatsApp uses end-to-end encryption to ensure only the sender and recipient can read messages, protecting confidentiality even if intercepted.
NTC and Ncell (Nepal):
- Idea Used: Denial of Service (DoS) Mitigation.
- How: These companies deploy firewalls and rate-limiting to prevent DDoS attacks that could disrupt telecom services. For example, during peak hours, traffic is monitored to block malicious spikes.
Bank Transactions (Global):
- Idea Used: Least Privilege and Separation of Duties.
- How: Banks use role-based access control (e.g., tellers can’t approve loans) and two-person authorization for large transfers to prevent fraud.
Daraz Order Processing:
- Idea Used: Availability (CIA Triad).
- How: Daraz uses load balancers and redundant servers to ensure its website remains available during sales events (e.g., Dashain), preventing downtime from traffic surges.
5. Security Architectures and Layers
Security is implemented across multiple layers, from hardware to applications:
- Physical Layer: Secure data centers, biometric access.
A labelled rack of servers with firewalls and access controls. (Image: Derrick Coetzee from Berkeley, CA, USA, CC0, via Wikimedia Commons) - Network Layer: Firewalls, VPNs, intrusion detection systems (IDS).
- System Layer: Operating system security (e.g., Linux permissions, Windows BitLocker).
- Application Layer: Secure coding (e.g., input validation to prevent SQL injection).
- User Layer: Training on phishing, password policies.
Worked Example: Securing a Bank Transaction
Consider a user transferring money via an online banking app:
- Authentication: User logs in with a username, password, and OTP.
- Authorization: The system checks if the user has permission to transfer funds.
- Encryption: Data is encrypted using TLS during transmission.
- Logging: The transaction is recorded in an audit log (Accounting).
- Fail-Safe: If the system detects unusual activity (e.g., multiple failed attempts), it locks the account.
6. Common Security Standards and Frameworks
Organizations use frameworks to guide security practices:
| Framework | Description | Example Organizations |
|---|---|---|
| ISO/IEC 27001 | International standard for information security management. | Banks, government agencies. |
| NIST Cybersecurity Framework | Risk-based approach to cyber security. | U.S. government, multinational corps. |
| PCI DSS | Security standards for payment card data. | eSewa, Khalti, Visa/Mastercard. |
| GDPR | Regulates data protection and privacy for EU citizens. | Global companies handling EU data. |
Exam Tip
This unit is conceptual and application-based. Expect:
- Definitions: Know the difference between threats, vulnerabilities, and attacks.
- CIA Triad and AAA: Be able to apply these models to real-world scenarios (e.g., "How does WhatsApp ensure confidentiality?").
- Security Principles: Match principles to examples (e.g., "Why does a bank use two-factor authentication?" → Least Privilege + Separation of Duties).
- Layered Security: Explain how multiple layers (e.g., firewall + encryption) work together.
- Real-World Applications: Relate concepts to Nepalese or global examples (e.g., "How does NTC prevent DDoS attacks?").
Common Mistakes to Avoid:
- Confusing confidentiality (hiding data) with integrity (ensuring data isn’t altered).
- Forgetting availability in the CIA triad (e.g., a DDoS attack violates availability).
- Mixing up authentication (proving identity) and authorization (granting access).
Scoring Full Marks:
- Use real examples (e.g., eSewa, WhatsApp, NTC) in your answers.
- Draw layered diagrams or CIA/AAA mindmaps where applicable.
- Explain how a principle or model works, not just what it is. For example:
"Defense in depth is used in TLS by combining encryption (confidentiality), digital signatures (integrity), and session keys (availability) to protect data in transit."
Based on the PU BE Computer (PU) syllabus for Network and Cyber Security (CMP426), unit 1.
Discussion
Loading…