Operating Systems

Unit 6: Protection & Security

From access matrices to ransomware defence — master OS-level protection, authentication, and security mechanisms that safeguard modern systems.

⏱️ 6 hrs theory + 4 hrs lab  |  💰 Earning Potential: ₹5K–₹20K/month  |  📝 30 MCQs (Bloom's Mapped)

💼 Jobs this unlocks: Security Engineer (₹6–12 LPA)  |  Linux Admin (₹4–8 LPA)

Section A

Opening Hook — When an OS Fails to Protect

🏥 AIIMS Delhi Ransomware Attack — November 2022

On 23rd November 2022, India's most prestigious hospital — All India Institute of Medical Sciences, New Delhi — went dark. Ransomware crippled the hospital's entire IT infrastructure. Patient registration, lab reports, billing, smart-lab systems, and the outpatient department all ground to a halt. Doctors were forced to switch to pen-and-paper records for nearly two weeks.

The root cause? A buffer overflow vulnerability in an unpatched server. Attackers exploited this OS-level flaw to inject malicious code, escalated privileges, and deployed ransomware that encrypted 5 servers and 1.3 terabytes of data. An estimated 40 million patient records — including those of VVIPs, diplomats, and politicians — were at risk.

The attackers demanded cryptocurrency in exchange for decryption keys. CERT-In, NIA, and Delhi Police's IFSO were called in. It took 15 days to restore full operations. Total estimated damage: ₹200+ crores in disruption, reputation loss, and recovery.

Could OS-level protection mechanisms have stopped this? Could proper access control, buffer overflow protections, and security hardening have prevented a national health crisis? That's exactly what this chapter answers.

🏥 AIIMS Delhi🛡️ CERT-In🇮🇳 NIA🔒 Ransomware⚠️ Buffer Overflow
India was the most targeted country for ransomware in the APAC region in 2022–2023. Over 75% of Indian organisations experienced at least one ransomware attack (Sophos, 2023). The average ransom demand in India: ₹4.8 crores. OS hardening and proper access control could prevent 60%+ of these attacks.
Section B

Learning Outcomes — Bloom's Taxonomy Mapped

Bloom's LevelLearning Outcome
🔵 RememberList the types of malware (virus, worm, trojan, ransomware, spyware) and define buffer overflow, trapdoor, and access matrix
🔵 UnderstandExplain how the access matrix model enforces protection domains and how ACLs differ from capability lists
🟢 ApplyDemonstrate Linux file permissions (chmod, chown, setuid) and implement password hashing using Python's hashlib
🟢 AnalyzeAnalyze how the AIIMS ransomware attack exploited OS vulnerabilities and identify which protection mechanisms were missing
🟠 EvaluateEvaluate the effectiveness of India's IT Act 2000, CERT-In guidelines, and DPDP Act 2023 in preventing cyberattacks
🟠 CreateDesign a Linux Security Hardening Checklist for a small business server, applying the principle of least privilege