Operating Systems
Unit 6: Protection & Security
From access matrices to ransomware defence — master OS-level protection, authentication, and security mechanisms that safeguard modern systems.
⏱️ 6 hrs theory + 4 hrs lab | 💰 Earning Potential: ₹5K–₹20K/month | 📝 30 MCQs (Bloom's Mapped)
💼 Jobs this unlocks: Security Engineer (₹6–12 LPA) | Linux Admin (₹4–8 LPA)
Opening Hook — When an OS Fails to Protect
🏥 AIIMS Delhi Ransomware Attack — November 2022
On 23rd November 2022, India's most prestigious hospital — All India Institute of Medical Sciences, New Delhi — went dark. Ransomware crippled the hospital's entire IT infrastructure. Patient registration, lab reports, billing, smart-lab systems, and the outpatient department all ground to a halt. Doctors were forced to switch to pen-and-paper records for nearly two weeks.
The root cause? A buffer overflow vulnerability in an unpatched server. Attackers exploited this OS-level flaw to inject malicious code, escalated privileges, and deployed ransomware that encrypted 5 servers and 1.3 terabytes of data. An estimated 40 million patient records — including those of VVIPs, diplomats, and politicians — were at risk.
The attackers demanded cryptocurrency in exchange for decryption keys. CERT-In, NIA, and Delhi Police's IFSO were called in. It took 15 days to restore full operations. Total estimated damage: ₹200+ crores in disruption, reputation loss, and recovery.
Could OS-level protection mechanisms have stopped this? Could proper access control, buffer overflow protections, and security hardening have prevented a national health crisis? That's exactly what this chapter answers.
Learning Outcomes — Bloom's Taxonomy Mapped
| Bloom's Level | Learning Outcome |
|---|---|
| 🔵 Remember | List the types of malware (virus, worm, trojan, ransomware, spyware) and define buffer overflow, trapdoor, and access matrix |
| 🔵 Understand | Explain how the access matrix model enforces protection domains and how ACLs differ from capability lists |
| 🟢 Apply | Demonstrate Linux file permissions (chmod, chown, setuid) and implement password hashing using Python's hashlib |
| 🟢 Analyze | Analyze how the AIIMS ransomware attack exploited OS vulnerabilities and identify which protection mechanisms were missing |
| 🟠 Evaluate | Evaluate the effectiveness of India's IT Act 2000, CERT-In guidelines, and DPDP Act 2023 in preventing cyberattacks |
| 🟠 Create | Design a Linux Security Hardening Checklist for a small business server, applying the principle of least privilege |