Posts

Showing posts with the label Networking

DMZ Design Fundamentals

DMZ design, like security design, is always a work in progress. As in security planning and analysis, we find DMZ design carries great flexibility and change potential to keep the protection levels we put in place in an effective state. The ongoing work is required so that the system’s security is always as high as we can make it within the constraints of time and budget, while still allowing appropriate users and visitors to access the information and services we provide for their use. You will find that the time and funds spent in the design process and preparation for the implementation are very good investments if the process is focused and effective; this will lead to a high level of success and a good level of protection for the network you are protecting. Design of the DMZ is critically important to the overall protection of your internal network—and the success of your firewall and DMZ deployment.The DMZ design can incorporate sections that isolate incoming VPN tr...

DMZ Concepts

Image
The use of a DMZ and its overall design and implementation can be relatively simple or extremely complex, depending on the needs of the particular business or network system. The DMZ concept came into use as the need for separation of networks became more acute when we began to provide more access to services for individuals or partners outside the LAN infrastructure. One of the primary reasons why the DMZ has come into favor is the realization that a single type of protection is subject to failure. This failure can arise from configuration errors, planning errors, equipment failure, or deliberate action on the part of an internal employee or external attack force. The DMZ has proven more secure and offers multiple layers of protection for the security of the protected networks and machines. It is also very flexible, scalable, and relatively robust in its capability to provide the protection we need. DMZ design now includes the ability to use multiple products (both hardwa...

Identifying Potential Network Threats

As you prepare your overall security plan and de-militarized zone (DMZ), it is important to identify and evaluate the potential risks and threats to your network, systems, and data. You must evaluate your risks thoroughly during the identification process to assign some sort of value to the risks to determine priorities for protection and likelihood of loss resulting from those risks and threats if they materialize. You should be looking at and establishing a risk evaluation for anything that could potentially disrupt, slow, or damage your systems, data, or credibility. In this area, it is important to assign these values to potential threats such as: Outside hacker attacks Trojans, worms, and virus attacks DoS or Distributed Denial of Service (DDoS) attacks Compromise or loss of internal confidential information Network monitoring and data interception Internal attacks by employees Hardware failures Loss of critical systems This identification process creat...

Untrusted Networks

The federation of networks that became the Internet consisted of a relatively small community of users by the 1980s, primarily in the research and academic communities. Because it was rather difficult to get access to these systems and the user communities were rather closely knit, security was not much of a concern. The main objective of connecting these various networks together was to share information, not keep it locked away. Technologies such as the UNIX operating system and the TCP/IP networking protocols that were designed for this environment reflected this lack of security concern; security was simply viewed as unnecessary. By the early 1990s, however, commercial interest in the Internet grew. These commercial interests had very different perspectives on security, often in opposition to those of academia. Commercial information had value, and access to it had to be limited to specifically authorized people. UNIX,TCP/IP, and connections to the Internet became ave...

Trusted Networks

It is not easy to define what a trusted network consists of, or what comprises a trusted network even within a single corporation or entity, since the concept of “trust” doesn’t apply equally even within a single company—you’ll still want to control access to sensitive information such as payroll or HR information. The old concept of firewalls and networking dictated that we have an Internet connection coming into a firewall from a single point, and this firewall would protect our inside networks from all attackers. Today, the idea of the network perimeter is expanding and shifting; many technologies make this previous definition outdated. Today we are remotely accessing our network via mobile phones, VPN clients from a personal DSL connection in our homes; we are also providing access to our network for our employees, and often for our suppliers and customers. The idea of perimeter security is disappearing because of the prevalence of wireless and home-based high-speed I...

DMZ Design Fundamentals

DMZ design, like security design, is always a work in progress. As in security planning and analysis, we find DMZ design carries great flexibility and change potential to keep the protection levels we put in place in an effective state. The ongoing work is required so that the system’s security is always as high as we can make it within the constraints of time and budget, while still allowing appropriate users and visitors to access the information and services we provide for their use. You will find that the time and funds spent in the design process and preparation for the implementation are very good investments if the process is focused and effective; this will lead to a high level of success and a good level of protection for the network you are protecting. Design of the DMZ is critically important to the overall protection of your internal network—and the success of your firewall and DMZ deployment.The DMZ design can incorporate sections that isolate incoming VPN tr...

Different Access for Different Organizations

Before developing your security policy, determine whether you will need to have different policies for different locations or if you will have only one. If you have a single security policy , you can enforce the same policy on all firewalls and other security devices, usually from a single management station. Otherwise, you will have to maintain a different policy for different locations. Although for business reasons this might be necessary, it can add a level of complexity to your environment that could decrease your overall effective security. If it is necessary, make sure it is thoroughly documented. Some different types of organizations that may have differing access requirements include: SOHO - The Small-Office-Home-Office network is often more concerned with accessibility than security, since these organizations often do not have dedicated IT professionals on hand, or may have an “IT person” who is doing double-duty while performing accounting or other admini...

Drafting the Network Security Policy

Writing a security policy is a logical progression of steps. Briefly, the structure of the policy should include the following: Introduction. In this section, you should state the purpose of this policy. What is the objective of the policy? Why it is important to the organization? Guidelines. In this section, you should detail guidelines for choosing controls to meet the objectives of the policy. These are the basic requirements. Typically, you will see the word should in these statements. Standards. In this section, you should detail the standards for implementing and deploying the selected controls. For example, this section will state the initial configuration or firewall architecture. This section tends to detail the requirements given in the meeting with the interested departments and business units. This section is written with the words such as, “It is the policy that… .” Procedures. In this section, you should detail the procedures for ma...

Defining a Network Security Policy

You just received the task to define a network security policy for your network. You need to think about several topics before defining your new network security policy. A good way to start is to think about your organization. How well do you know your organization’s business processes, both as an individual company and the needs and requirements of its industry as a whole? Sometimes, when an information security engineer or a consultant is asked to design a network security policy, he or she realizes that it is imperative to develop a better understanding of the organization before beginning. To be able to design a useful network security policy, you need to know what the network is designed for. You need to design and deploy a network security policy that secures a company’s resources, while still allowing people to do their jobs. Therefore, think about the department, the business, what the company produces or sells, whether the business is seasonal or cyclical, or if i...

Network Security Policy

Deploying a network security policy is a significant and serious undertaking. Making good decisions in this matter will save a great deal of money and prevent many future security issues on your network, while making incorrect or hasty decisions will lay the foundation for an insecure network infrastructure. Creating a network security policy will affect your organization in a number of ways, including (but not limited to): Financial. A new network security policy may require you to purchase new equipment and software, such as firewalls, IPS (intrusion protection/prevention system), anti-virus software, new routers, and more. You’ll likely also incur additional salary costs for security personnel trained to manage the new hardware and software. Network availability. You may have to install new hardware and software on your network to comply with a new network security policy, which may impact your overall network availability as you install and configure thi...

Network Cable

Image
You can construct an Ethernet network by using one of two different types of cable: coaxial cable, which resembles TV cable, or twisted-pair cable, which looks like phone cable. Twisted-pair cable is sometimes called UTP, or 10BaseT cable, for reasons I try hard not to explain later. You may encounter other types of cable in an existing network: thick yellow cable that used to be the only type of cable used for Ethernet , fiber-optic cables that span long distances at high speeds, or thick twisted-pair bundles that carry multiple sets of twisted-pair cable between wiring closets in a large building. For all but the largest networks, the choice is between coaxial cable and twisted-pair cable. A third choice — one that’s becoming more popular every day — is to forego network cable and instead build your network using wireless network components. Coaxial Cable A type of cable that was once popular for Ethernet networks is coaxial cable, sometimes called thinnet or BNC cab...

Hubs, Switches, Repeaters, Bridges and Routers

Image
The biggest difference between using coaxial cable and twisted-pair cable is that when you use twisted-pair cable, you also must use a separate device called a hub. Years ago, hubs were expensive devices — expensive enough that most do-it-yourself networkers who were building small networks opted for thinnet cable in order to avoid the expense and hassle of using hubs. Nowadays, the cost of hubs has dropped so much that the advantages of twisted-pair cabling outweigh the hassle and cost of using hubs. With twistedpair cabling, you can more easily add new computers to the network, move computers, find and correct cable problems, and service the computers that you need to remove from the network temporarily. A switch is simply a more sophisticated type of hub. Because the cost of switches has come down dramatically in the past few years, most new networks are built with switches rather than hubs. If you have an older network that uses hubs and seems to run slowly, you may be...

Network Servers

Server computers are the lifeblood of any network. Servers provide the shared resources that network users crave, such as file storage, databases, e-mail, Web services, and so on. Choosing the equipment you use for your network’s servers is one of the key decisions you’ll make when you setup a network . For a home network or a small office network with only a few computers, you can get away with true peer-to-peer networking. That’s where each client computer shares its resources such as file storage or printers, and a dedicated server computer is not needed. Here are some general things to keep in mind when picking a server computer for your network: Scalability: Scalability refers to the ability to increase the size and capacity of the server computer without unreasonable hassle. It is a major mistake to purchase a server computer that just meets your current needs because, you can rest assured, your needs will double within a year. If at all possible, equip yo...

Ethernet Protocol

Image
As you know, the first two layers of the OSI model deal with the physical structure of the network and the means by which network devices can send information from one device on a network to another. By far, the most popular set of protocols for the Physical and Data Link layers is Ethernet. Ethernet has been around in various forms since the early 1970s. The current incarnation of Ethernet is defined by the IEEE standard known as 802.3. Various flavors of Ethernet operate at different speeds and use different types of media. However, all the versions of Ethernet are compatible with each other, so you can mix and match them on the same network by using devices such as bridges, hubs, and switches to link network segments that use different types of media. The actual transmission speed of Ethernet is measured in millions of bits per second, or Mbps. Ethernet comes in three different speed versions: 10Mbps, known as Standard Ethernet; 100Mbps, known as Fast Ethernet; and 1...

Seven Layers Of OSI Reference Model

Image
OSI sounds like the name of a top-secret government agency you hear about only in Tom Clancy novels. What it really stands for in the networking world is Open Systems Interconnection, as in the Open Systems Interconnection Reference Model, affectionately known as the OSI model . The OSI model breaks the various aspects of a computer network into seven distinct layers. These layers are kind of like the layers of an onion: Each successive layer envelops the layer beneath it, hiding its details from the levels above. The OSI model is also like an onion in that if you start to peel it apart to have a look inside, you’re bound to shed a few tears. The OSI model is not a networking standard in the same sense that Ethernet and Token Ring are networking standards. Rather, the OSI model is a framework into which the various networking standards can fit. The OSI model specifies what aspects of a network’s operation can be addressed by various network standards. So, in a sense, t...