CMP426 Network and Cyber Security

Network and Cyber SecurityUnit 112 min read

Cyber Security Basics: Threats, Attacks, Defenses & Models

Unit 1 of Network and Cyber Security introduces core concepts of cyber security, including threats, vulnerabilities, attacks, security models (CIA triad, AAA), and fundamental security principles. It covers real-world examples, security architectures, and the importance of cyber security in modern systems.

TAKEAWAYS:

  • Cyber security protects systems, networks, and data from unauthorized access, damage, or disruption.
  • Threats (e.g., malware, phishing) exploit vulnerabilities in systems to cause attacks.
  • The CIA triad (Confidentiality, Integrity, Availability) and AAA (Authentication, Authorization, Accounting) are foundational security models.
  • Security principles like least privilege, defense in depth, and fail-safe defaults guide secure system design.
  • Real-world applications include secure transactions (e.g., eSewa, Khalti) and network protocols (e.g., TLS in WhatsApp).
  • Understanding cyber security threats and defenses is critical for designing secure systems and protecting digital assets.

1. Introduction to Cyber Security

Cyber security is the practice of protecting systems, networks, and data from digital attacks, unauthorized access, or damage. It encompasses technologies, processes, and practices designed to safeguard digital assets. In today’s interconnected world, cyber security is essential for individuals, businesses, and governments.

Key Concepts

  • System: A collection of hardware, software, and processes working together (e.g., a computer, network, or cloud service).
  • Network: A group of interconnected systems sharing resources (e.g., the internet, a corporate LAN).
  • Data: Information stored or transmitted digitally (e.g., personal records, financial transactions).
  • Threat: Any potential danger to a system (e.g., hackers, malware).
  • Vulnerability: A weakness in a system that can be exploited by threats.
  • Attack: An attempt to exploit vulnerabilities (e.g., phishing, DDoS).

2. Threats, Vulnerabilities, and Attacks

0.30.50.2MalwarePhishingDDoSInsider ThreatSocial Engineering
Example threat relationships (weight = correlation strength)

Threats

Threats can be categorized as follows:

NaturalAccidentalInternalExternalIntentionalHumanEnvironmentalThreats
Hierarchical classification of cyber threats (rooted tree)
  • Natural Threats: Disasters like floods or earthquakes.
  • Human Threats:
    • Accidental: Human errors (e.g., misconfigurations, data leaks).
    • Intentional:
      • Internal: Employees or insiders (e.g., disgruntled employees leaking data).
      • External: Hackers, competitors, or cybercriminals.
  • Environmental Threats: Power outages, hardware failures.

Vulnerabilities

Vulnerabilities are weaknesses in systems, software, or human behavior. Examples:

  • Software Vulnerabilities: Unpatched bugs (e.g., Heartbleed in OpenSSL).
  • Hardware Vulnerabilities: Faulty routers or unsecured IoT devices.
  • Human Vulnerabilities: Phishing emails tricking users into revealing passwords.

Attacks

Attacks exploit vulnerabilities to compromise systems. Common types:

Attack Type Description Example
Malware Malicious software (viruses, worms, ransomware). WannaCry ransomware attack.
Phishing Tricking users into revealing sensitive information. Fake eSewa login pages.
Denial of Service (DoS/DDoS) Overloading systems to disrupt services. DDoS attacks on NTC or Ncell.
Man-in-the-Middle (MitM) Intercepting communications between two parties. Unsecured Wi-Fi eavesdropping.
SQL Injection Exploiting SQL databases to steal or manipulate data. Hacking Daraz customer databases.
Social Engineering Manipulating human behavior to gain access. Impersonating a bank officer.

3. Security Models: CIA Triad and AAA

CIA Triad

The Confidentiality, Integrity, Availability (CIA) triad is the foundation of cyber security:

mindmap
  root((CIA Triad))
    Confidentiality
      Ensures data is accessible only to authorized users.
      Example: Encryption (e.g., WhatsApp end-to-end encryption).
    Integrity
      Ensures data is accurate and unaltered.
      Example: Hash functions (e.g., SHA-256 for file verification).
    Availability
      Ensures systems and data are accessible when needed.
      Example: Redundant servers (e.g., Google Cloud failover).

AAA Framework

Authentication, Authorization, Accounting (AAA) ensures secure access to resources:

Component Description Example
Authentication Verifies the identity of users or devices. Username + password, biometrics.
Authorization Determines what authenticated users can access. Role-based access (e.g., admin vs. user).
Accounting Tracks user activities for auditing. Logs of login attempts (e.g., bank transactions).

4. Security Principles

Five fundamental principles guide secure system design:

Principle Description Example
Least Privilege Users/processes get only the minimum access needed. Restricting database access to admins.
Defense in Depth Layered security (e.g., firewalls, encryption, IDS). TLS + Firewall + Antivirus.
Fail-Safe Defaults Systems default to a secure state. Disabling ports unless explicitly enabled.
Separation of Duties No single user controls critical functions. Two-factor approval for transfers.
Minimization Reduce attack surfaces (e.g., disable unused services). Disabling FTP on a web server.

In the Real World

  1. eSewa and Khalti (Nepal):

    • Idea Used: Authentication and Authorization (AAA).
    • How: These apps use multi-factor authentication (password + OTP) to verify users (Authentication) and restrict transactions based on user roles (Authorization). Accounting logs track every transaction for auditing.
  2. WhatsApp (Global):

    • Idea Used: Confidentiality (CIA Triad).
    • How: WhatsApp uses end-to-end encryption to ensure only the sender and recipient can read messages, protecting confidentiality even if intercepted.
  3. NTC and Ncell (Nepal):

    • Idea Used: Denial of Service (DoS) Mitigation.
    • How: These companies deploy firewalls and rate-limiting to prevent DDoS attacks that could disrupt telecom services. For example, during peak hours, traffic is monitored to block malicious spikes.
  4. Bank Transactions (Global):

    • Idea Used: Least Privilege and Separation of Duties.
    • How: Banks use role-based access control (e.g., tellers can’t approve loans) and two-person authorization for large transfers to prevent fraud.
  5. Daraz Order Processing:

    • Idea Used: Availability (CIA Triad).
    • How: Daraz uses load balancers and redundant servers to ensure its website remains available during sales events (e.g., Dashain), preventing downtime from traffic surges.

5. Security Architectures and Layers

Security is implemented across multiple layers, from hardware to applications:

016324863Version4 bitsHeaderLength4 bitsType ofService8 bitsTotal Length16 bitsIdentification16 bitsFlags3 bitsFragmentOffset13 bitsTTL8 bits
IPv4 header showing Network Layer security fields
Physical Layer (Hardware)Network Layer (Firewalls,Routers)System Layer (OS, Drivers)Application Layer (Software)User Layer (Authentication)Increasing abstraction
Security layers with examples at each level
  • Physical Layer: Secure data centers, biometric access. server rack in data centerA labelled rack of servers with firewalls and access controls. (Image: Derrick Coetzee from Berkeley, CA, USA, CC0, via Wikimedia Commons)
  • Network Layer: Firewalls, VPNs, intrusion detection systems (IDS).
  • System Layer: Operating system security (e.g., Linux permissions, Windows BitLocker).
  • Application Layer: Secure coding (e.g., input validation to prevent SQL injection).
  • User Layer: Training on phishing, password policies.

Worked Example: Securing a Bank Transaction

Consider a user transferring money via an online banking app:

  1. Authentication: User logs in with a username, password, and OTP.
  2. Authorization: The system checks if the user has permission to transfer funds.
  3. Encryption: Data is encrypted using TLS during transmission.
  4. Logging: The transaction is recorded in an audit log (Accounting).
  5. Fail-Safe: If the system detects unusual activity (e.g., multiple failed attempts), it locks the account.

6. Common Security Standards and Frameworks

Organizations use frameworks to guide security practices:

Framework Description Example Organizations
ISO/IEC 27001 International standard for information security management. Banks, government agencies.
NIST Cybersecurity Framework Risk-based approach to cyber security. U.S. government, multinational corps.
PCI DSS Security standards for payment card data. eSewa, Khalti, Visa/Mastercard.
GDPR Regulates data protection and privacy for EU citizens. Global companies handling EU data.

Exam Tip

This unit is conceptual and application-based. Expect:

  1. Definitions: Know the difference between threats, vulnerabilities, and attacks.
  2. CIA Triad and AAA: Be able to apply these models to real-world scenarios (e.g., "How does WhatsApp ensure confidentiality?").
  3. Security Principles: Match principles to examples (e.g., "Why does a bank use two-factor authentication?" → Least Privilege + Separation of Duties).
  4. Layered Security: Explain how multiple layers (e.g., firewall + encryption) work together.
  5. Real-World Applications: Relate concepts to Nepalese or global examples (e.g., "How does NTC prevent DDoS attacks?").

Common Mistakes to Avoid:

  • Confusing confidentiality (hiding data) with integrity (ensuring data isn’t altered).
  • Forgetting availability in the CIA triad (e.g., a DDoS attack violates availability).
  • Mixing up authentication (proving identity) and authorization (granting access).

Scoring Full Marks:

  • Use real examples (e.g., eSewa, WhatsApp, NTC) in your answers.
  • Draw layered diagrams or CIA/AAA mindmaps where applicable.
  • Explain how a principle or model works, not just what it is. For example:

    "Defense in depth is used in TLS by combining encryption (confidentiality), digital signatures (integrity), and session keys (availability) to protect data in transit."

Based on the PU BE Computer (PU) syllabus for Network and Cyber Security (CMP426), unit 1.

Discussion

Loading…