SANE: A Protection Architecture For Enterprise Networks
نویسنده
چکیده
In a relatively short period, enterprise networks have evolved from small-sized LANs with simple architectures, to present day large networks with very complex architectures. Their topologies now include combinations of Local Area Networks (LANs), Wireless access networks, Metropolitan Area Networks (MANs), Wide Area Networks (WANs) and Virtual Private Networks (VPNs) that often span across multiple continents. Sustaining these highly interconnected, but also more dynamic and complex architectures currently occurs through the implementation of complex routing and switching protocols. Nevertheless, the increased network connectivity and higher availability have still not been sufficiently balanced by improved security. Threats from Viruses, worms, trojan horses and DoS attacks are still persistent, with rising tendencies in their sophistication and ability to spread. Mechanisms such as ACL, packet filters, firewalls, IDS and IPS, etc, put in place to curb these increased levels of threats and attacks have also caused the network to become inflexible, fragile and difficult to manage. This paper addresses issues such as trust, access control, complex routing and switching, and other forms of attacks that affect present day enterprise networks. It evaluates and analyzes current methods used to resolve these issues, points out their limitations and then proposes a new approach in dealing with the fundamental problem. It presents a newly designed protection architecture (SANE) for the enterprise network. This architecture is based on a single, logically centralized protection layer that is used to setup, secure and control all connectivities within the network.
منابع مشابه
SANE: A Protection Architecture for Enterprise Networks
Connectivity in today’s enterprise networks is regulated by a combination of complex routing and bridging policies, along with various interdiction mechanisms such as ACLs, packet filters, and other middleboxes that attempt to retrofit access control onto an otherwise permissive network architecture. This leads to enterprise networks that are inflexible, fragile, and difficult to manage. To add...
متن کاملArchitectural Support for Security Management in Enterprise Networks a Dissertation Submitted to the Department of Computer Science and the Committee on Graduate Studies of Stanford University in Partial Fulfillment of the Requirements for the Degree of Doctor of Philosophy
Enterprise networks are often large, run a wide variety of applications and protocols, and operate under strict reliability constraints; thus, they represent a challenging environment for security management. Security policies in todays enterprise are typ ically enforced by regulating connectivity with a combination of complex routing and bridging policies along with various interdiction mecha...
متن کاملطراحی چارچوب معماری اطلاعاتی برای بهکارگیری شبکههای اجتماعی در نظام آموزش عالی ایران
Management of social networks, has become a strategic challenge for different applications including education due to its growing importance. Enterprise Architecture (EA), uses a holistic specification of information technology functions in organizations to decrease the complexity of using information technology and to increase its efficiency. As regards, using social networks in education in ...
متن کاملA Reference Architecture for Automation of Inter-Organizational Process-Oriented Collaboration
In today’s competitive, dynamic, and changing business environment, being able to collaborate globally within and beyond the enterprise borders is critical. Inter-Organizational Collaborations (IOCs) have been proposed as a response to the characteristics of highly competitive global business environments. So far, a number of reference models, frameworks, and ad hoc architectures related to som...
متن کاملEvolution of Neural Network’s Architecture through Symbiotic Neuroevolution
In this paper an extension of SANE that simultaneously evolves the weights and architecture of an MLP neural network is presented. The symbiotic adaptive neuroevolution (SANE) system coevolves a population of neurons that cooperate to form a functioning neural network. Evolutionary Strategies (ES) is applied to evolve the network weights. In order to increase the evolving system performance and...
متن کامل