Boosting performance Network segmentation can improve performance through an
organizational scheme in which systems that often communicate are located in the
same segment while systems that rarely or never communicate are located in other
segments.
Reducing communication problems Network segmentation often reduces congestion
and contains communication problems, such as broadcast storms, to individual
subsections of the network.
Providing security Network segmentation can also improve security by isolating traffic
and user access to those segments where they are authorized.
Segments can be created by using switch-based VLANs, routers, or firewalls, individually or in
combination. A private LAN or intranet, a DMZ, and an extranet are all types of network
segments.
When you’re designing a secure network (whether a private network, an intranet, or an
extranet), you must evaluate numerous networking devices. Not all of these components a re
necessary for a secure network, but they are all common network devices that may have an
impact on network security. (Stewart et al., 2004)
3. Network and Protocol Security Mechanisms
TCP/IP is the primary protocol suite used on most networks and on the Internet. It is a robust
protocol suite, but it has numerous security deficiencies. In an effort to improve the security of
TCP/IP, many sub-protocols, mechanisms, or applications have been developed to protect the
confidentiality, integrity, and availability of transmitted data.
It is important to remember that even with the foundational
protocol suite of TCP/IP; there are literally hundreds, if not
thousands, of individual protocols, mechanisms, and applications
in use across the Internet. Some of them are designed to provide
security services. Some protect integrity, others protect
confidentiality, and others provide authentication and access
control. (Stewart et al., 2004)
4. Network Access Control
Controlling network access is to prevent unauthorized access to networked services. Access to
both internal and external networked services should be controlled. User access to networks
and network services should not compromise the security of the network services by ensuring:
a) appropriate interfaces are in place between the organization’s network and networks
owned by other organizations, and public networks;
b) appropriate authentication mechanisms are applied for users and equipment;
c) control of user access to information services is enforced.
Lebanese National Security Policy Guidelines v1.7
Page
25 |