Computer Network Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 13 March 2012

Planning Network Security

Posted on 09:27 by Unknown
Planning Network Security

The Need for Computer / Network Security:


Computer / network security includes:


Control of physical accessibility to computers / network
Prevention of accidental data
Erasure, modification, compromise
Detection and prevention of
Intentional internal security breaches
Unauthorized external intrusions (hacking)


All three legs of the triangle must exist for a network intrusion to occur:
Motive
A reason to want to breach your security
Means
The ability
Opportunity
The chance to enter the network
This last item is the administrator's only chance at controlling events.


Principles of Network Security:
Network security goals are sometimes identified as Confidentiality.
Only the sender and intended recipient should "see" the message Integrity.
Sender and receiver want to make sure that the message is not altered in transit, or afterwords.

Authentication
The sender and receiver want to confirm each other's identity Availability.
Services and resources must be available and accessible.

Understanding Risk Management:
A key principle of security is that no network is completely secure.
Information security deals principally with risk management.
The more important an asset, the more it is exposed to security threats, thus the more resources you must put into securing it.


Understanding Risk Management - 2:
In general, without training, administrators respond to a security threat in one of three ways:
Ignore the threat, or acknowledge it but do nothing to prevent it from occurring.
Address the threat in an ad hoc fashion.
Attempt to completely security all assets to the utmost degree, without regard for usability or manageability
None of these strategies take into account what the actual risk is, and all of them will usually lead to long-term failure.


What are Some Risks?
Eavesdropping
Interception of messages
Hijacking
Taking over the role of a sender or receiver.
Insertion
Of messages into an active connection
Impersonation
Spoofing a source address in a packet or any field in a packet
Denial of service (DOS).
Prevent others from gaining access to resources, usually by overloading system.


Managing Risk:
Once the assets and their corresponding threats have been identified risk management can consist of:
Acceptance
Mitigation
Transference
Avoidance


Accepting Risk:
If you take no proactive measures, you accept the full exposure and consequences of the security threats to an asset.
Should accept risk only as a last resort when no other reasonable alternatives exist, or when the costs are extremely high.
When accepting risk, it is always a good idea to create a contingency plan.
A contingency plan details a set of actions that will be taken after the risk is realized and will lessen the impact of the compromise of loss of the asset.


Mitigating Risk:
The most common method of securing computers and networks is to mitigate security risks.
By taking proactive measures either to reduce an asset's exposure to threats or reduce the organizations dependency on the asset, you are mitigating the security risk.
A simple example: installing antivirus software.


Transferring Risk:
Transfer security risk to another party has many advantage including:
Economies of scale, such as insurance.
Use of another organization expertise and services.
Example: using a web hosting service.
When undertaking this type of risk transference, the details of the arrangement should be clearly stated in a contract known as a service level agreement (SLA).


Avoiding Risk:
The opposite of accepting risk is to avoid the risk entirely.
To avoid risk, you must remove the source of the threat, exposure to the threat, or your organization reliance on the asset.
Generally, you avoid risk when there are little to no possibilities for mitigating or transferring the risk, or when the consequences of realizing the risk far outweigh the benefits gained from undertaking the risk.
An example can be a military or law enforcement dBase that, if compromised, could put lives at risk.


Implementing Security:
Think of security in terms of granting the least amount of privileges required to carry out the task.
Example: consider the case of a network administrator unwittingly opening an e-mail attachment that launches a virus.
If the administrator is logged on as the domain administrator, the virus will have administrator privileges on all computers in the domain and thus unrestricted access to nearly all data on the network.


Defense in Depth:
Imagine the security of your network as a series of layers.
Each layer you pull away gets you closer to the center, where the critical asset exists.
On your network, defend each layer as though the previous outer layer is ineffective or nonexistent.
The total security of your network will dramatically increase if you defend at all levels and increase the fault tolerance of security.
Example: to protect users from launching an e-mail-borne virus, in addition to antivirus software on the users' computers, you could use e-mail client software that blocks potentially dangerous file types from being executed, block potentially dangerous attachments according to their file type, and ensures that the user is running under a limited user account.


Reducing the Attack Surface:
An attacker needs to know of only one vulnerability to attack your network successfully, whereas you must pinpoint all you vulnerabilities to defend your network.
The smaller your attack surface, the better chance you have of accounting for all assets and their protection.
Attackers will have fewer targets, and you will have less to monitor and maintain.
Example: to lower the attack surface of individual computers on your network, you can disable services that are not used and remove software that is not necessary.


Addressing Security Objectives:
Controlling Physical Access to
Servers
Networked workstations
Network devices
Cabling plant
Being aware of security considerations with wireless media related to portable computers.
Recognizing the security risk.
Of allowing data to be printed out.
Involving floppy disks, CDs, tapes, other removable media.


Recognizing Network Security threats:
To protect your network, you must consider the following:
Question: from whom or what are you protecting if?
Who: types of network intruders and their motivations.
What: types of network attackers and how they work.
These questions form the basis for performing a threat analysis.
A comprehensive threat analysis should be the product of brainstorming among people who are knowledgeable about the business processes, industry, security, and so on.


Classifying specific Types of Attacks:
Social engineering attacks
DOS attacks
Scanning and spoofing
Source routing and other protocol exploits
SOFTWARE and system exploits
Trojans, Viruses and worms


It is important to understand the types of threats in order to deal with them properly.


Designing a Comprehensive Security Plan:
RFC2196, the Site Security Handbook.
Identify what your are trying to protect.
Determine what you are trying to protect it from.
Determine how likely the anticipated threats are.
Implement measures that will protect your assets in a cost-effective manner.
Review the process continually and make improvements each time a weakness is discovered.


Steps to Creating a Security Plan:
Your security plan will generally consist of three different aspects of protecting your network.
Prevention: the measures that are implemented to keep your information from being modified, destroyed, or compromised.
Detection: the measures that are implemented to recognize when a security breach has occurred or has been attempted, and possibly, the origin of the breach.
Reaction: the measures that are implemented to recover from a security breach to recover lost or altered data, to restore system or network operations, and to prevent future occurrences.


Security Ratings:
The U.S.

government provides specifications for the rating of network security implementations in a publication often referred to as the Orange Book, formally called the DOD Trusted Computer System.
Evaluation criteria, or TCSEC.
The Red book, or Trusted Network Interpretation of the TCSEC (TNI) explains how the TCSEC evaluation.
criteria are applied to computer networks.
Canada has security rating systems that work in a similar way.
CTPEC

Security Ratings -2:
To obtain a government contract, companies are often required to obtain a C2 rating.
A C2 rating has several requirements.
That the operating system in use be capable of tracking access to data, including both who accessed it and when it was accessed.
That users' access to objects be subject to control (access permissions).
That users are uniquely identified on the system (user account name and password).
That security-related events can be tracked and permanently recorded for auditing (audit log).

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in computer network security, network intrusion, physical accessibility | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Network Support For Computer Network Topology Problems
    Network Support For Computer Network Topology Problems When an user has to use multiple computers for his business purpose or personal use...
  • Network Security is Crucial for the Reputation of Business
    Network Security is Crucial for the Reputation of Business Network security is a major issue of concern today for both private as well as ...
  • Ethical Hackers May Help Streamline Network Security
    Ethical Hackers May Help Streamline Network Security Network security is critical for the proper functioning of organization and timely de...
  • Need technical help for your computer troubles? Get professional help today!
    Today, computers can be made to do almost any task by designing a computer program. Every one starting from children to our grandparents are...
  • The Significance of Network Support Services for an Organization
    Running an organization is not an easy job to do. It requires a lot of skills, expertise and patience in managing an organization effectivel...
  • Affiliate Network
    Affiliate Network An Affiliate Network has a number of categories in which they have various offers. For example, a network may have Elec...
  • Make your business bloom with the best networking support
    There is no questioning the fact that businesses require support for their functioning. Proper infrastructure is essential so that you have ...
  • Designing Secure Communications Between Networks
    Designing Secure Communications Between Networks This chapter presents the skills and concepts related to creating a CompTIA security desi...
  • Benefits of hiring computer network installation services
    Every layman in the 21st century is well aware of how complex a computer network can be. That is the reason whether you are going to establi...
  • Technical support to troubleshoot common network security
    Technical support to troubleshoot common network security   Network security is very important to a business for its success as taking pre...

Categories

  • access virus
  • active running
  • additional security measures
  • advanced traffic management
  • Advertising amp; Marketing
  • affiliate marketing network
  • affiliate network
  • analog cameras
  • analogue devices
  • anonymous hackers
  • anti virus software
  • application directory
  • Arts amp; Entertainment
  • authentication protocol
  • authentication protocols
  • automatic notifications
  • backup scripts
  • best colleges in the united states
  • best inventions
  • bus topology
  • business establishments
  • business networking
  • business networking groups
  • business owners face
  • Business Products amp; Services
  • business social networks
  • campus network security
  • ccd sensors
  • central processing unit
  • certification study materials
  • certified ethical hacker
  • chief security officer
  • chief technology officer
  • chinese internet users
  • civil lawsuits
  • clock services
  • Clothing amp; Fashion
  • coaxial cable network
  • comic book titles
  • commercial lawyer
  • computer disaster recovery
  • computer hardware software
  • computer method
  • computer network administrator
  • Computer Network Installation
  • computer network security
  • computer network support
  • computer network topology
  • computer networking support
  • computer security services
  • computer security specialist
  • computer security specialists
  • computer security system
  • computer software system
  • Computer Support Services
  • computer support technician
  • computer support technicians
  • computer system elements
  • connectivity capabilities
  • corporate corporations
  • corporate security policies
  • couple events
  • cpa firm
  • cracking software
  • credit card details
  • credit card fraud
  • custom web server
  • customer networking
  • cyber crimes
  • daily basis
  • data backup software
  • date of births
  • debit card numbers
  • denial of service attack
  • destructive program
  • disaster recovery plan
  • double edged sword
  • e mail addresses
  • e mail marketing
  • effective networking
  • electrical problems
  • electronic information system
  • encryption and decryption
  • encryption methods
  • energy consumption
  • enjoyable fellowship
  • enterprise network security
  • ethical hacker
  • ethical hackers
  • ethical hacking tools
  • factor authentication
  • Financial
  • fingerprint scan
  • firewall functions
  • firewall internet security
  • firewall intrusion detection
  • firewall protection
  • firewall security
  • Foods amp; Culinary
  • foremost memory
  • forming a business
  • gain unauthorized access
  • game screenshot
  • global network management
  • google search engine
  • guest appearance
  • hacker access
  • hacker proof
  • hackers crackers
  • hardware firewall
  • Health amp; Fitness
  • Health Care amp; Medical
  • high speed internet connectivity
  • Home Products amp; Services
  • Home Security Network
  • Home Security Networks
  • home video surveillance
  • home video surveillance system
  • home wireless networks
  • hospitality company
  • huge computer
  • illicit connections
  • implementing network
  • importance network security
  • important network
  • income households
  • incorrect assumption
  • increased system
  • information security services
  • information security training
  • information superhighway
  • information systems security
  • information technology services
  • installation capability
  • intelligent cameras
  • internet google
  • internet hay
  • internet network marketing
  • internet protocol suite
  • internet security solution
  • internet security solutions
  • internet security system
  • Internet Services
  • internet software vendors
  • internet stock trading
  • intrusion detection software
  • intrusion detection system
  • intrusion prevention
  • intrusion prevention system
  • intrusion prevention systems
  • ip cameras
  • ip standards
  • lan resources
  • lan users
  • lawyer experience
  • lawyer networks
  • Legal
  • lifetime network
  • login credentials
  • long distance charges
  • malicious scripts
  • malwares
  • management functionality
  • managing a business
  • mandatory safety standards
  • market eight
  • market research survey
  • massachusetts institute of technology
  • mathematical principle
  • media access control
  • melbourne victoria
  • merchant affiliate programs
  • merchant services providers
  • minimum budget
  • Miscellaneous
  • model layer
  • more virus
  • multi level marketing
  • mutual relationship
  • mysteries thrillers
  • name your pet
  • neighborhood network
  • network access point
  • network address translation
  • network audit
  • network backup software
  • network cameras
  • network disaster recovery
  • network emulation
  • network failure
  • network firewalls
  • network infrastructures
  • network installation services
  • network intrusion
  • network management applications
  • network management protocol
  • network management protocols
  • network marketing
  • network monitoring system
  • network monitoring tools
  • network penetration
  • network safety
  • network security assessment
  • network security audits
  • network security concepts
  • network security integration
  • network security issues
  • network security management
  • network security policy
  • network security problems
  • network security risks
  • network security services
  • network security software
  • network security solution
  • network security solutions
  • network security system
  • network security technology
  • network security threats
  • network security tips
  • network security training
  • network security vulnerabilities
  • network support services
  • network visibility
  • Networker
  • networking approach
  • networking businesses
  • networking consultant
  • networking courses
  • networking engineer
  • networking events
  • networking marketing
  • networking skills
  • networking strategy
  • networking success
  • networking system
  • noncompliance issues
  • novel network
  • office removals
  • On site computer repairs
  • osi reference model
  • outgoing mails
  • packet inspection
  • pan tilt
  • pan tilt zoom cameras
  • party validation
  • pc network management
  • pc safety
  • personal revenge
  • personal transactions
  • photo sharing website
  • photo sharing websites
  • physical accessibility
  • physical networking
  • physical security procedures
  • plain text password
  • power consumption
  • private computer networks
  • productive network
  • professional public relations
  • proper measures
  • proper model
  • protocol label
  • rapid popularity
  • rating technology
  • Relationships
  • remote server support
  • reputation management
  • reset passwords
  • safety solutions
  • search engine listings
  • security breaches
  • security firewalls
  • security information systems
  • security method
  • security officer services
  • security perspective
  • security system software
  • setup a network
  • setup router
  • six degrees of separation
  • sky is the limit
  • small business office
  • small business owners
  • social networking site
  • social networking sites
  • social networking websites
  • social threats
  • social unrest
  • software network
  • sole proprietor
  • speed signs
  • Sports amp; Athletics
  • spread spectrum technology
  • spy ware
  • star network topology
  • start advertising
  • symantec gateway security
  • technical mechanisms
  • Technology
  • technology trend
  • test conductor
  • time connectivity
  • time login
  • time networks
  • traffic reviews
  • trojan horses
  • trojan viruses
  • twitter
  • type ipconfig
  • unified threat management
  • unsung hero
  • vantage points
  • video surveillance camera
  • video surveillance system
  • video tape recorders
  • virtual private network
  • virtual private networks
  • virus makers
  • virus package
  • virus program
  • virus worm
  • vital aspects
  • voice communication technology
  • vulnerability assessment tools
  • vulnerability scanners
  • water proof camera
  • Web Resources
  • web signs
  • website publishers
  • wireless access points
  • wireless internet device
  • wireless intrusion prevention
  • wireless network adapter
  • wireless network camera
  • wireless network configuration
  • wireless network security
  • wireless router
  • woman entrepreneur
  • word processor document
  • work colleagues
  • worse case scenario
  • wpa crack
  • wrong software

Blog Archive

  • ►  2013 (21)
    • ►  September (2)
    • ►  August (3)
    • ►  July (5)
    • ►  June (3)
    • ►  May (4)
    • ►  April (2)
    • ►  March (2)
  • ▼  2012 (127)
    • ►  September (12)
    • ►  August (13)
    • ►  July (15)
    • ►  June (11)
    • ►  May (6)
    • ►  April (1)
    • ▼  March (67)
      • Business Networking
      • Technical support to troubleshoot common network s...
      • Twitter application directory
      • Importance Of Wireless Network Security
      • A Secure Network Is A Productive Network
      • Networking Success - Turbo Charge Your Networking?
      • The Value of Your Network and Networking
      • Network ip security
      • Google Social Networking - The Social Networking A...
      • Vulnerabilities In Network Security
      • Security Network Planning and Computer Disaster Re...
      • Affiliate Network
      • Try Networking
      • Social Networking Security Awareness
      • Internet Network Marketing in Social Network Site
      • Planning Network Security
      • Browser Vendors Pointing The Country Secure Networ...
      • Intrusion Detection Software: Guarding Network Sec...
      • Make Your Network With Legal Network
      • Designing Secure Communications Between Networks
      • Network and computer Security services by BEL Netw...
      • Networking Management
      • Network Storage
      • Photo Networking
      • Security Network Planning And Computer Disaster Re...
      • Ethical Hackers May Help Streamline Network Security
      • Virtual Private Networks: Securing Your Business's...
      • Network Support For Computer Network Security Prob...
      • Features and Benefits of Network Security
      • How to Improve Network Security
      • Wireless Network Security - Is it Secure?
      • Network Support For Computer Network Topology Prob...
      • Network Camera
      • Networking,yahoo
      • NETWORK IP SECURITY
      • Network Security Testing Product Comparison
      • MPLS Network
      • Network Problems
      • Network security and Ethical Hacking
      • Ways to Improve Your Network Security
      • Home Network Manager A Perfect Network Guide
      • To Continue Moving Forward Wlan Network Security T...
      • How to Improve Network Security
      • Business Networking
      • Best network security support for your business
      • How to Improve Network Security: Tips to Improve Y...
      • Enterprise Network Security- Stops Gap to Help Pro...
      • Network Marketing
      • Positive Networking
      • Network Security Audits
      • Business Networking - Am I a Nurturing Networker?
      • Affiliate Network
      • Network Applications Of Home Monitoring Network Ca...
      • Social Networking
      • Business Networking Through Social Networking
      • Secure your wireless network solution
      • How To Build The Overall Security Of The Actual Ca...
      • The Novel Network-The Novel Network Review
      • Security Of Network Information Security Managemen...
      • Networking Courses - Learn Networking Now
      • Affiliate Network
      • Today The Value Of Network Security Solution
      • 24x7 Network Security Solutions & Tools
      • Beyond Utm: Network Security Platform Customized V...
      • Network Security for a Business or Organization
      • Network Camera ? Cameras for Security
      • Beyond UTM: network security platform customized v...
    • ►  February (2)
Powered by Blogger.

About Me

Unknown
View my complete profile