Network Security Architectures

  • Published: Apr 19, 2004
  • Copyright 2004
  • Dimensions: 7-3/8" x 9-1/8"
  • Pages: 792
  • Edition: 1st
  • Book
  • ISBN-10: 1-58714-297-X
  • ISBN-13: 978-1-58714-297-0
  • eBook (Watermarked)
  • ISBN-10: 1-58705-369-1
  • ISBN-13: 978-1-58705-369-6

Register your product to gain access to bonus material or receive a coupon.

More Information

DescriptionReviewsSample Content

Product Description

Expert guidance on designing secure networks

  • Understand security best practices and how to take advantage of the networking gear you already have
  • Review designs for campus, edge, and teleworker networks of varying sizes
  • Learn design considerations for device hardening, Layer 2 and Layer 3 security issues, denial of service, IPsec VPNs, and network identity
  • Understand security design considerations for common applications such as DNS, mail, and web
  • Identify the key security roles and placement issues for network security elements such as firewalls, intrusion detection systems, VPN gateways, content filtering, as well as for traditional network infrastructure devices such as routers and switches
  • Learn 10 critical steps to designing a security system for your network
  • Examine secure network management designs that allow your management communications to be secure while still maintaining maximum utility
  • Try your hand at security design with three included case studies
  • Benefit from the experience of the principal architect of the original Cisco Systems SAFE Security Blueprint

Written by the principal architect of the original Cisco Systems SAFE Security Blueprint, Network Security Architectures is your comprehensive how-to guide to designing and implementing a secure network. Whether your background is security or networking, you can use this book to learn how to bridge the gap between a highly available, efficient network and one that strives to maximize security. The included secure network design techniques focus on making network and security technologies work together as a unified system rather than as isolated systems deployed in an ad-hoc way.

 

Beginning where other security books leave off, Network Security Architectures shows you how the various technologies that make up a security system can be used together to improve your network's security. The technologies and best practices you'll find within are not restricted to a single vendor but broadly apply to virtually any network system. This book discusses the whys and hows of security, from threats and counter measures to how to set up your security policy to mesh with your network architecture. After learning detailed security best practices covering everything from Layer 2 security to e-commerce design, you'll see how to apply the best practices to your network and learn to design your own security system to incorporate the requirements of your security policy. You'll review detailed designs that deal with today's threats through applying defense-in-depth techniques and work through case studies to find out how to modify the designs to address the unique considerations found in your network.

 

Whether you are a network or security engineer, Network Security Architectures will become your primary reference for designing and building a secure network.

 

This book is part of the Networking Technology Series from Cisco Press, which offers networking professionals valuable information for constructing efficient networks, understanding new technologies, and building successful careers.

Customer Reviews

12 of 12 people found the following review helpful
5.0 out of 5 stars Cisco Security for Network Architecture, December 2, 2004
By 
Joel E. Natt (Atlanta, GA USA) - See all my reviews
(REAL NAME)   
Welcome to the twenty-first century in the world of computers and networking. With more issues occurring that have negative affects on the environment that information technologists work in, the knowledge of information security is slowly becoming critical. Sean Convery presents a detailed guide into the world of designing a secure network environment. Within "Network Security Architecture", Sean delves into the whys, the hows, and most importantly the cause and effect. As you examine the table of contents alone, it becomes clear that he has spent a great deal of time researching and detailing numerous different components of a network environment that have to be examined and considered for proper network security.

A close look at the book's table of contents will point out different areas that any Network Engineering individual from the Junior Administrator to the Senior Architect needs to be knowledgeable in. Sean examines policy, threats and the technologies... Read more
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


9 of 9 people found the following review helpful
5.0 out of 5 stars Network Security Design Must Have, June 1, 2004
I have read many books in the Cisco Press and this one is up there with the best in terms of practical use, technical depth and ease of reading. The author does a great job of laying out the book in a logical manner that is sure to help Security Architects take on the daunting task of network security design with a higher level of confidence. As a systems engineer responsible for large network designs, I have found this book to provide very good information for many scenarios, a multitude of good links to provide additional resources for discussed topics as well as out of scope topics, and also a good supplement for the backround knowledge required for the CCIE Security exam, for which I am currently preparing for. I consider this one as much a must have as Doyle for IP Routing or Clarke for LAN Switching.

Raymond Santini CCIE# 12315

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


8 of 8 people found the following review helpful
5.0 out of 5 stars Recommended for professional infosec architects, June 26, 2004
By 
This comprehensive textbook is ideal for information security architects tasked with designing secure networks, both as a teaching text and as a reference. It covers:
- Good practice network security design guidelines ('axioms')
- Purpose and definition of network security policies
- Good advice on designing the network security system (i.e. the overarching network security architecture into which individual network devices must fit) from the ground up (i.e. physical security to application security, OSI layers 1 to 7)
- Specific technical advice on configuring network devices for
security ('hardening')
- Technical descriptions of the vulnerabilities in network services, accompanied by advice on how to secure them
- Typical design considerations for network perimeter ('edge') security, internal network ('campus') security and remote access (teleworker) security
- Secure network management and network security management (compared and contrasted... Read more
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


Share your thoughts with other customers:
 See all 6 customer reviews...

Table of Contents

Foreword.


Preface.

I. NETWORK SECURITY FOUNDATIONS.

1. Network Security Axioms.

Network Security Is a System. Business Priorities Must Come First. Network Security Promotes Good Network Design. Everything Is a Target. Everything Is a Weapon. Strive for Operational Simplicity. Good Network Security Is Predictable. Avoid Security Through Obscurity. Confidentiality and Security Are Not the Same. Summary. Reference. Applied Knowledge Questions.

2. Security Policy and Operations Life Cycle.

You Can't Buy Network Security. What Is a Security Policy? Security System Development and Operations Overview. Summary. References. Applied Knowledge Questions.

3. Secure Networking Threats.

The Attack Process. Attacker Types. Vulnerability Types. Attack Results. Attack Taxonomy. Summary. References. Applied Knowledge Questions.

4. Network Security Technologies.

The Difficulties of Secure Networking. Security Technologies. Emerging Security Technologies. Summary. References. Applied Knowledge Questions.

II. DESIGNING SECURE NETWORKS.

5. Device Hardening.

Components of a Hardening Strategy. Network Devices. Host Operating Systems. Applications. Appliance-Based Network Services. Rogue Device Detection. Summary. References. Applied Knowledge Questions.

6. General Design Considerations.

Physical Security Issues. Layer 2 Security Considerations. IP Addressing Design Considerations. ICMP Design Considerations. Routing Considerations. Transport Protocol Design Considerations. DoS Design Considerations. Summary. References. Applied Knowledge Questions.

7. Network Security Platform Options and Best Deployment Practices.

Network Security Platform Options. Network Security Device Best Practices. Summary. Reference. Applied Knowledge Questions.

8. Common Application Design Considerations.

E-Mail. DNS. HTTP/HTTPS. FTP. Instant Messaging. Application Evaluation. Summary. References. Applied Knowledge Questions.

9. Identity Design Considerations.

Basic Foundation Identity Concepts. Types of Identity. Factors in Identity. Role of Identity in Secure Networking. Identity Technology Guidelines. Identity Deployment Recommendations. Summary. References. Applied Knowledge Questions.

10. IPsec VPN Design Considerations.

VPN Basics. Types of IPsec VPNs. IPsec Modes of Operation and Security Options. Topology Considerations. Design Considerations. Site-to-Site Deployment Examples. IPsec Outsourcing. Summary. References. Applied Knowledge Questions.

11. Supporting-Technology Design Considerations.

Content. Load Balancing. Wireless LANs. IP Telephony. Summary. References. Applied Knowledge Questions.

12. Designing Your Security System.

Network Design Refresher. Security System Concepts. Impact of Network Security on the Entire Design. Ten Steps to Designing Your Security System. Summary. Applied Knowledge Questions.

III. SECURE NETWORK DESIGNS.

13. Edge Security Design.

What Is the Edge? Expected Threats. Threat Mitigation. Identity Considerations. Network Design Considerations. Small Network Edge Security Design. Medium Network Edge Security Design. High-End Resilient Edge Security Design. Provisions for E-Commerce and Extranet Design. Summary. References. Applied Knowledge Questions.

14. Campus Security Design.

What Is the Campus? Campus Trust Model. Expected Threats. Threat Mitigation. Identity Considerations. Network Design Considerations. Small Network Campus Security Design. Medium Network Campus Security Design. High-End Resilient Campus Security Design. Summary. References. Applied Knowledge Questions.

15. Teleworker Security Design.

Defining the Teleworker Environment. Expected Threats. Threat Mitigation. Identity Considerations. Network Design Considerations. Software-Based Teleworker Design. Hardware-Based Teleworker Design. Design Evaluations. Summary. Reference. Applied Knowledge Questions.

IV. NETWORK MANAGEMENT, CASE STUDIES, AND CONCLUSIONS.

16. Secure Network Management and Network Security Management.

Utopian Management Goals. Organizational Realities. Protocol Capabilities. Tool Capabilities. Secure Management Design Options. Network Security Management Best Practices. Summary. References. Applied Knowledge Questions.

17. Case Studies.

Introduction. Real-World Applicability. Organization. NetGamesRUs.com. University of Insecurity. Black Helicopter Research Limited. Summary. Reference. Applied Knowledge Questions.

18. Conclusions.

Introduction. Management Problems Will Continue. Security Will Become Computationally Less Expensive. Homogeneous and Heterogeneous Networks. Legislation Should Garner Serious Consideration. IP Version 6 Changes Things. Network Security Is a System. Summary. References.

Appendix A: Glossary of Terms.

Appendix B: Answers to Applied Knowledge Questions.

Chapters 1-16.

Appendix C: Sample Security Policies.

Index.

Best Value

Book + eBook Bundle $118.99 $71.79

Book Price: $53.59
eBook Price: $18.20

Buy

This book includes free shipping!

Buy

Book  $66.99  $53.59

Usually ships in 24 hours.

This book includes free shipping!

Buy

eBook (Watermarked)  $52.00  $41.60

About Watermarked eBooks

This PDF will be accessible from your Account page after purchase and requires the free Adobe® Reader® software to read it.

The eBook requires no passwords or activation to read. We customize your eBook by discretely watermarking it with your name, making it uniquely yours.

Watermarked eBook FAQ

Purchase Reward: One Month Free Subscription
By completing any purchase on Cisco Press, you become eligible for an unlimited access one-month subscription to Safari Books Online.

Get access to thousands of books and training videos about technology, professional development and digital media from more than 40 leading publishers, including Addison-Wesley, Prentice Hall, Cisco Press, IBM Press, O'Reilly Media, Wrox, Apress, and many more. If you continue your subscription after your 30-day trial, you can receive 30% off a monthly subscription to the Safari Library for up to 12 months. That's a total savings of $199.