home news blogs forums events research newsletter whitepapers careers


Network Computing Network Computing Powered by InformationWeek Business Technology Network
InformationWeek 500 Conference -- September 14-16, 2008 Registed Today!

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Sneak Preview
W O R K S H O P  
Building an In-Depth Defense

  July 9, 2001
  By Brooke Paul


Network security continues to grow more complex. Services that once were centralized and available to a relatively small group of internal users are becoming decentralize d and available to a wide audience via the Internet and extranets. For many organizations, the audience now comprises users within the enterprise as well as customers, business partners and prospects beyond traditional network boundaries.

Enabling access to critical applications and data while maintaining the confidentiality, integrity and availability of these resources can be a daunting task. One of the first steps to completing it is to use network segmentation and access-control methodologies.



Defense in Depth

Defense in depth is the practice of layering defenses to provide added protection. Defense in depth increases security by raising the cost of an attack. This system places multiple barriers between an attacker and your business-critical information resources: The deeper an attacker tries to go, the harder it gets. These multiple layers prevent direct attacks against important systems and avert easy reconnaissance of your networks. In addition, a defense-in-depth strategy provides natural areas for the implementation of intrusion-detection technologies. Ideally, the defense-in-depth measures you implement should buy you time to detect and respond to a breach, reducing its impact.

In many environments, defense in depth can be implemented with few incremental equipment costs. Most router and switch vendors provide access-control mechanisms within their products. Although many security professionals would not rely solely on VLANs (virtual LANs) and router ACLs (access-control lists) for Internet-based security controls, their implementation as internal controls can be valuable. The keys are to ensure that these mechanisms are implemented according to your business risks and that they are monitored and maintained.

Classifying Network-Security Domains

To implement a network-access control, such as a firewall, you must define the boundaries between security domains in your enterprise. A network-security domain is a region of a network that shares a common security policy. Most companies begin to define network-security domains simply when they connect to the Internet. But today's business models require connectivity--logical and physical--between your enter- prise and the Internet and between your enterprise and the networks of business partners, information providers and customers.

A simple, two-domain network security model doesn't capture the complexity of the relationships between these various networks. From a security perspective, the differences between networks are much more complicated than "internal" and "not internal." With this scheme, how would you categorize extranet connections to business partners? What about systems and networks that support highly sensitive functions, such as HR?

Clearly, some networks have different security needs. To further complicate matters, some highly sensitive networks may need to provide services to a larger population. For example, an HR network may want to set up an intranet for employee self-service, letting workers view their time-off allotment or change insurance beneficiaries or mailing addresses.



Once you have defined the network-security domains within your enterprise, it's necessary to examine the interactions between domains. This includes the traffic and data flows, as well as the access required. Access-control technologies can be used to manage security-policy enforcement at the boundaries between network-security domains, and network intrusion-detection solutions can be used to monitor for attacks and other violations. The remaining step is to find a way to keep critical data protected while still providing access for authorized personnel.

A critical network-design element that has found its place in Internet hosting is the demilitarized zone, or DMZ. This element can be used internally, as well as for Internet and extranet services, to provide an additional layer of control and security to protect critical information resources.

DMZ

The term demilitarized zone comes to the IS world from the military, where it is defined as an area in which military actions are prohibited. In the technology arena, DMZs were first defined as the network segment between the external interface of a firewall and the internal interface of an external (often an Internet) router.

DMZ has evolved, however, to mean an isolated network segment for providing services to untrusted systems. Today the term is most often used by IT professionals to refer to a network segment between two firewalls (see "sandwich DMZ"), or a "dead-end" or "wing" network connected to a firewall (see "Single-Firewall DMZ"). Other common names for a DMZ are services network and atrium.



Regardless of its name, the DMZ's purpose is to segregate sensitive internal networks from other networks while allowing services to be offered--a defense-in-depth strategy for the network layer. Traffic cannot flow into or out of the DMZ without being forwarded through a network access-control system.

Policies on firewalls and access-control systems define and restrict all traffic passing through the DMZ. In contrast, traffic flow on the Internet and between internal corporate networks is usually unrestricted.


   Page: 1 | 2 | Next Page





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo Jitter
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet Evolution
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space
App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights