...
首页> 外文期刊>International Journal of Information Technology and Computer Science >A Proposed Model for Datacenter in -Depth Defense to Enhance Continual Security(Applied Study to ENR Datacenter – Egyptian National Railways)
【24h】

A Proposed Model for Datacenter in -Depth Defense to Enhance Continual Security(Applied Study to ENR Datacenter – Egyptian National Railways)

机译:旨在提高持续安全性的深度防御中数据中心的建议模型(适用于ENR数据中心的研究–埃及国家铁路)

获取原文
           

摘要

Defense in Depth is practical strategy for achieving Information Assurance in today’s highly datacenter environments. It is a “best practices” strategy in that it relies on the intelligent application of techniques and technologies that exist today. The strategy recommends a balance between the protection capability and cost, performance, and operational considerations. This paper provides an overview of the major elements of the strategy and provides links to resources that provide additional insight. Companies need to address the security challenges of datacenter using a comprehensive defense-in-depth strategy. No single security solution will keep a determined thief from the goal of compromising the hardware or software given enough time and resources. Applying multiple layers of system security will slow the progress made by a thief, and hopefully, force the thief to abandon the pursuit, at the least, resale of the stolen property, and at worst, of confidential corporate data. The Defense in depth is the concept of protecting a Datacenter with a series of defensive mechanisms such that if one mechanism fails, another will already be in place to thwart an attack. In this paper, the main focus is given to highlight the security aspects of data center from perspectives of threats and attacks from one side and approaches for solutions from the other side. The paper also proposes an effective and flexible distributed scheme with two salient features. Our scheme achieves the integration of continual security improvement and Security Risk localization. This paper deals with the implementation of defense in depth at a strategic, principle-based level and provides additional guidance on specific sets of controls that may be applicable to support an organization’s defense in depth initiatives. The paper will present in Section (1) the Defense in depth concept, Section (2) Threats, Adversaries, Motivations, Classes of Attack and Vulnerability Analysis, Section (3) Information Security Assurance, Defense in Multiple Places, Layered Defenses, Security Robustness, Section (4) Design Goals and finally proposed solution and provide The IT Security Role & Functional Matrix.
机译:深度防御是在当今高度数据中心环境中实现信息保障的实用策略。这是“最佳实践”策略,因为它依赖于当今存在的技术的智能应用。该策略建议在保护功能与成本,性能和操作注意事项之间取得平衡。本文概述了该策略的主要元素,并提供了指向可提供更多见解的资源的链接。公司需要使用全面的纵深防御策略来应对数据中心的安全挑战。在足够的时间和资源的情况下,没有哪个安全解决方案可以使窃贼免受损害硬件或软件的目标。应用多层系统安全性将减缓小偷的进步,并希望迫使小偷至少放弃对被盗财产的转售,至少放弃对机密公司数据的转售。深度防御是一种通过一系列防御机制保护数据中心的概念,这样,如果一种机制失败了,那么另一种机制就已经可以阻止攻击。在本文中,主要重点是从一侧的威胁和攻击以及另一侧的解决方案的角度突出显示数据中心的安全性。本文还提出了一种具有两个显着特征的有效而灵活的分布式方案。我们的方案实现了持续安全改进和安全风险本地化的集成。本文讨论了在战略性,基于原则的水平上实施深度防御的问题,并提供了一些特定的控制措施指导,这些措施可能适用于支持组织的深度防御计划。本文将在(1)纵深防御概念,(2)威胁,对手,动机,攻击类别和漏洞分析,第(3)信息安全保证,多处防御,分层防御,安全健壮性中介绍,第(4)节设计目标,最后提出解决方案,并提供IT安全角色和功能矩阵。

著录项

相似文献

  • 外文文献
  • 中文文献
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号