Classified Network
The classified network has stringent expectations placed on it. To recap, all data must be cryptographically protected on the network, and data must reside in one central location rather than being distributed.
Doing this properly in a traditional PC-and-server topology is very problematic based on today's technology. Also, the application requirements of the network are limited, making the flexibility of the PC platform not strictly necessary. As a result, diskless terminals are used with all data residing in central servers, and only screen and keyboard information is sent from the server to the client. These diskless systems are strongly authenticated, and all communications between the client and server are cryptographically protected.
After sitting down at their workstations, users gain access to their terminals through another smart card and password authentication process. The smart card is the same physical device as their photo
ID card, which they are required to wear at all times. Smart card access is proximity based, which means that when the user steps away from the workstation, the system automatically logs off.
The identity management issues in a system like this are significant. Because there are only 150 users organization-wide, they are manageable here. Also, the security requirements are significant enough that the management issues are acceptable and the organization can staff appropriately to deal with them.
NOTE
Diskless workstations, or "thin clients" as they are sometimes known, are available from a number of vendors. Sun Microsystems, for example, has its Sun Ray line, which supports smart cards.
This server-centric computing model allows the administrative staff to focus exclusively on securing and maintaining the server. The server should have every host control discussed in Chapter 4 applied in addition to OS and application hardening. File system crypto is particularly important because it is mandated by the security requirements.
This kind of security design does have the "eggs in one basket" property, but with the physical security controls in one place and the limited size of the network, this is deemed an acceptable risk. Because all data is encrypted from client to server, there is very little requirement for security at the network layer. With only 100 devices at the main site and 25 at each satellite, the design can primarily be at L2 with the exception of the WAN links. Figure 17-7 shows the classified network topology.
Figure 17-7. BHR Proposed Classified Network Layout
Figure 17-7. BHR Proposed Classified Network Layout
Here you can see things are very basic. A firewall is used for some limited defense-in-depth but is not strictly necessary based on the physical security and application security controls. The NIDS should never alarm because all data is encrypted, but it will act as a good detection device in case of any misconfiguration or unforeseen attack.
Continue reading here: Security Will Become Computationally Less Expensive
Was this article helpful?