Network Security Axioms

This chapter covers the following topics:

• Network Security Is a System

• Business Priorities Must Come First

• Network Security Promotes Good Network Design

• Everything Is a Target

• Everything Is a Weapon

• Strive for Operational Simplicity

• Good Network Security Is Predictable

• Avoid Security Through Obscurity

• Confidentiality and Security Are Not the Same

Appear at points which the enemy must hasten to defend; march swiftly to places where you are not expected.

Sun Zi, The Art of War

[The U.S. military must] adopt a new "capabilities-based" approachone that focuses less on who might threaten us, or where, and more on how we might be threatened and what is needed to deter and defend against such threats.

U.S. Secretary of Defense Donald Rumsfeld, Foreign Affairs, Volume 81, No. 3, May 2002

First-time network security architects always come to a realization about halfway through their first network security design project. It eclipses all of the other realizations that they've had to date regarding network security. Minor observations such as "Network security is hard," "I don't know enough," or "Why didn't the last security administrator document things better?" all lead to the main conclusion: "I'm in the wrong business if I don't like being the underdog."

One of the things that can help you in the challenging undertaking of secure network design is an understanding of the ground rules. I call these ground rules axioms. An axiom as defined by Merriam-Webster is "a maxim widely accepted on its intrinsic merit." When I say "axiom" in this book, I am referring to overarching design principles, considerations, or guidelines that are broad enough to apply to all areas of secure network design. Also, since "intrinsic merit" is a bit open to interpretation, I'll provide empirical proofs to back up my claims.

Axioms are similar to design principles but are subtly different. A design principle is smaller in scope and often involves only a single technology or affects only a limited area of the network. For example, that the intrusion-detection system (IDS) should be installed as close as possible to the hosts you are trying to protect is a design principle. But because it applies only to IDS deployments, it is not an axiom.

Axioms are presented first for two reasons. First, they allow you to consider and apply the axioms as you read the rest of this book. Second, if I didn't mention them now, this book would be three times as long because I would repeat myself constantly. A solid under-standing of these axioms will help you understand how to approach designing secure networks.

Continue reading here: Network Security Is a System

Was this article helpful?

0 0