Affichage des articles dont le libellé est Network Security. Afficher tous les articles
Affichage des articles dont le libellé est Network Security. Afficher tous les articles
lundi 16 janvier 2017
Security policy
Security
policy is a definition of what it means to be secure for a system, organization
or other entity. For an organization, it addresses the constraints on behavior
of its members as well as constraints imposed on adversaries by mechanisms such
as doors, locks, keys and walls. For systems, the security policy addresses
constraints on functions and flow among them, constraints on access by external
systems and adversaries including programs and access to data by people.
Significance
If it is
important to be secure, then it is important to be sure all of the security
policy is enforced by mechanisms that are strong enough. There are many
organized methodologies and risk assessment strategies to assure completeness
of security policies and assure that they are completely enforced. In complex
systems, such as information systems, policies can be decomposed into
sub-policies to facilitate the allocation of security mechanisms to enforce
sub-policies. However, this practice has pitfalls. It is too easy to simply go
directly to the sub-policies, which are essentially the rules of operation and
dispense with the top level policy. That gives the false sense that the rules
of operation address some overall definition of security when they do not.
Because it is so difficult to think clearly with completeness about security,
rules of operation stated as "sub-policies" with no
"super-policy" usually turn out to be rambling rules that fail to
enforce anything with completeness. Consequently, a top-level security policy
is essential to any serious security scheme and sub-policies and rules of
operation are meaningless without it.
Network security policy
A network
security policy, or NSP,
is a generic document that outlines rules for computer network access, determines how policies are
enforced and lays out some of the basic architecture of the company security/ network security environment. The document itself is
usually several pages long and written by a committee. A security policy goes
far beyond the simple idea of "keep the bad guys out". It's a very
complex document, meant to govern data access, web-browsing habits,
use of passwords and encryption, email attachments
and more. It specifies these rules for individuals or groups of individuals
throughout the company.
Security policy should
keep the malicious users out and also exert control over potential risky users
within your organization. The first step in creating a policy is to understand
what information and services are available (and to which users), what the
potential is for damage and whether any protection is already in place to
prevent misuse.
In addition, the
security policy should dictate a hierarchy of access permissions; that is,
grant users access only to what is necessary for the completion of their work.
While writing the
security document can be a major undertaking, a good start can be achieved by
using a template. National Institute for Standards and Technology provides a security-policy guideline.
The policies could be
expressed as a set of instructions that could be understood by special purpose network hardware dedicated for securing the network.
Network security
Network
security consists
of the policies and practices adopted to prevent and monitor unauthorized
access, misuse, modification, or denial of a computer network and
network-accessible resources. Network security involves the authorization of
access to data in a network, which is controlled by the network administrator.[citation
needed] Users choose or are assigned an ID and password or other
authenticating information that allows them access to information and programs
within their authority. Network security covers a variety of computer networks,
both public and private, that are used in everyday jobs; conducting
transactions and communications among businesses, government agencies and
individuals. Networks can be private, such as within a company, and others
which might be open to public access. Network security is involved in
organizations, enterprises, and other types of institutions. It does as its
title explains: It secures the network, as well as protecting and overseeing
operations being done. The most common and simple way of protecting a network
resource is by assigning it a unique name and a corresponding password.
Network
Security concepts
Network security starts
with authenticating, commonly with a username and a
password. Since this requires just one detail authenticating the user
name—i.e., the password—this is sometimes termed one-factor authentication.
With two-factor
authentication,
something the user 'has' is also used (e.g., a security token or 'dongle', an ATM card, or a mobile phone); and with three-factor
authentication, something the user 'is' is also used (e.g., a fingerprint or retinal
scan).Once authenticated, a firewall enforces access policies such as what services are allowed to be accessed by the network users.[1] Though effective to prevent unauthorized access, this component may fail to check potentially harmful content such as computer worms or Trojans being transmitted over the network. Anti-virus software or an intrusion prevention system (IPS)[2] help detect and inhibit the action of such malware. An anomaly-based intrusion detection system may also monitor the network like wireshark traffic and may be logged for audit purposes and for later high-level analysis. Newer systems combining unsupervised machine learning with full network traffic analysis can detect active network attackers from malicious insiders or targeted external attackers that have compromised a user machine or account.[3]
Communication between two hosts using a network may be encrypted to maintain privacy.
Honeypots, essentially decoy network-accessible resources, may be deployed in a network as surveillance and early-warning tools, as the honeypots are not normally accessed for legitimate purposes. Techniques used by the attackers that attempt to compromise these decoy resources are studied during and after an attack to keep an eye on new exploitation techniques. Such analysis may be used to further tighten security of the actual network being protected by the honeypot. A honeypot can also direct an attacker's attention away from legitimate servers. A honeypot encourages attackers to spend their time and energy on the decoy server while distracting their attention from the data on the real server. Similar to a honeypot, a honeynet is a network set up with intentional vulnerabilities. Its purpose is also to invite attacks so that the attacker's methods can be studied and that information can be used to increase network security. A honeynet typically contains one or more honeypots.[4]
Security
management
Security management for
networks is different for all kinds of situations. A home or small office may
only require basic security while large businesses may require high-maintenance
and advanced software and hardware to prevent malicious attacks from hacking and spamming.
Types
of Attacks
Networks are subject to attacks from malicious sources. Attacks can be from two categories:
"Passive" when a network intruder intercepts data traveling through
the network, and "Active" in which an intruder initiates commands to
disrupt the network's normal operation or to conduct reconnaissance and lateral
movement to find and gain access to assets available via the network.[5]Types of attacks include:[6]
- Passive
- Network
- Wiretapping
- Port
scanner
- Idle
scan
- Active
- Denial-of-service
attack
- DNS
spoofing
- Man
in the middle
- ARP
poisoning
- VLAN
hopping
- Smurf
attack
- Buffer
overflow
- Heap
overflow
- Format
string attack
- SQL
injection
- Phishing
- Cross-site
scripting
- CSRF
- Cyber-attack







