Business Data Communication Networking - c11.pdf
(
6436 KB
)
Pobierz
369-433_Fitzg11_p4.qxd 7/5/06 6:54 PM Page 369
PART
4
NETWORK MANAGEMENT
Courtesy Alan Dennis
369-433_Fitzg11_p4.qxd 7/5/06 6:54 PM Page 370
369-433_Fitzg11_p4.qxd 7/15/06 11:47 AM Page 371
CHAPTER
11
NETWORK SECURITY
1
Fundamental Concepts
Network Technologies
Application Layer
LAN WLAN
Backbone
Transport Layer
Network Layer
Data Link Layer
Physical Layer
WAN
Internet
Network
Security
M
k
Network Management
The Three Faces of Networking
1
This chapter was written by Alan Dennis and Dwight Worker.
371
369-433_Fitzg11_p4.qxd 7/5/06 6:54 PM Page 372
372
CHAPTER 11
NETWORK SECURITY
T
HIS CHAPTER
describes why networks need security and how to provide it. The
first step in any security plan is risk assessment, understanding the key assets that need
protection, and assessing the risks to each. There are a variety of steps that can be taken
to prevent, detect, and correct security problems due to disruptions, destruction, disaster,
and unauthorized access.
OBJECTIVES
Be familiar with the major threats to network security
■
Be familiar with how to conduct a risk assessment
■
Understand how to conduct business continuity planning
■
Understand how to prevent intrusion
■
CHAPTER OUTLINE
INTRODUCTION
Why Networks Need Security
Types of Security Threats
Network Controls
RISK ASSESSMENT
Develop a Control Spreadsheet
Identify and Document the Controls
Evaluate the Network’s Security
BUSINESS CONTINUITY PLANNING
Preventing Disruption, Destruction, and Disaster
Detecting Disruption, Destruction, and Disaster
Correcting Disruption, Destruction, and Disaster
INTRUSION PREVENTION
Preventing Intrusion
Detecting Intrusion
Correcting Intrusion
BEST PRACTICE RECOMMENDATIONS
IMPLICATIONS FOR MANAGEMENT
SUMMARY
369-433_Fitzg11_p4.qxd 7/5/06 6:54 PM Page 373
373
INTRODUCTION
INTRODUCTION
Business and government have always been concerned with physical and information se-
curity. They have protected physical assets with locks, barriers, guards, and the military
since organized societies began. They have also guarded their plans and information with
coding systems for at least 3,500 years. What has changed in the last 50 years is the intro-
duction of computers and the Internet.
The rise of the Internet has completely redefined the nature of information security.
Now companies face global threats to their networks, and, more importantly, to their data.
Viruses and worms have long been a problem, but credit card theft and identity theft, two
of the fastest growing crimes, pose immense liability to firms who fail to protect their cus-
tomers’ data. Laws have been slow to catch up, despite the fact that breaking into a com-
puter in the United States—even without causing damage—is now a federal crime
punishable by a fine and/or imprisonment. Nonetheless, we have a new kind of transbor-
der cyber crime against which laws may apply but will be very difficult to enforce. The
United States and Canada may extradite and allow prosecution of digital criminals operat-
ing within their borders, but investigating, enforcing, and prosecuting transnational cyber
crime across different borders is much more challenging. And even when someone is
caught they face lighter sentences than bank robbers.
Computer security has become increasingly important over the last 5 years with the
passage of the Sarbanes-Oxley Act (SOX) and the Health Insurance Portability and Ac-
countability Act (HIPAA). The number of Internet security incidents reported to the
Com-
puter Emergency Response Team (CERT)
has doubled every year up until 2003, when
CERT stopped keeping records because there were so many incidents that it was no longer
meaningful to keep track.
2
CERT was established by the U.S. Department of Defense at
Carnegie Mellon University with a mission to work with the Internet community to re-
spond to computer security problems, raise awareness of computer security issues, and
prevent security breaches.
Several other organizations monitor security threats. Postini, an e-mail software
vendor, provides information on current virus, spam, and other threats. Figure 11.1 shows
the current threats when I visited their site in 2006. About 70 percent of all e-mail sent
worldwide was spam, and about 1 percent of all e-mail messages contained a virus.
Approximately 95% of the respondents to the 2005 Computer Security Institute/FBI
Computer Crime and Security Survey reported that they had detected security breaches in
the last 12 months. About 90% reported they suffered a measurable financial loss due to a
security problem, with the average loss being about $200,000, which is significantly
lower than in previous years. Experts estimate that worldwide annual losses due to secu-
rity problems exceed $2 trillion.
Part of the reason for the increase in computer security problems is the increasing
availability of sophisticated tools for breaking into networks. Five years ago, someone
wanting to break into a network needed to have some expertise. Today, even inexperi-
enced attackers can download tools from a Web site and immediately begin trying to
break into networks.
2
CERT maintains a Web site on security at www.cert.org. Another site for security information is www.
infosyssec.net.
Plik z chomika:
Januszek66
Inne pliki z tego folderu:
Back Seat_ A Mumbai Tale - Aditya Kripalani.mobi
(755 KB)
Brief Wondrous Life of Oscar Wao, The - Junot Diaz.opf
(3 KB)
Don't Make Me Think, Revisited_ - Steve Krug.mobi
(9256 KB)
M. T. Anderson - Norumbegan 03 - The Empire of Gut and Bone # (v5.0).epub
(2209 KB)
M. T. Anderson - Norumbegan 02 - The Suburb Beyond the Stars # (v5.0).epub
(2105 KB)
Inne foldery tego chomika:
Dokumenty
Galeria
LUDLUM ROBERT
Midi - Kar
Mszał Rzymski PL
Zgłoś jeśli
naruszono regulamin