A Security Architecture Framework for Critical Infrastructure with Ring-based Nested Network Zones

被引:0
|
作者
Chaisuriya, Sarayut [1 ]
Keretho, Somnuk [1 ]
Sanguanpong, Surasak [1 ]
Praneetpolgrang, Prasong [2 ]
机构
[1] Kasetsart Univ, Fac Engn, Bangkok, Thailand
[2] Sripatum Univ, Fac Informat Technol, Bangkok, Thailand
关键词
Security Architecture; Nested Zones; Critical Infrastructure; Attack Hops; Defense in Depth;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The defense-in-depth approach has been widely recommended for designing critical information infrastructure, however, the lack of holistic design guidelines makes it difficult for many organizations to adopt the concept. Therefore, this paper proposes a holistic architectural framework and guidelines based on ring-based nested network zones for designing such highly secured information systems. This novel security architectural framework and guidelines offer the overall structural design and implementation options for holistically designing the N-tier/shared nothing system architectures. The implementation options, e.g. for the zone's perimeters, are recommended to achieve different capability levels of security or to trade off among different required security attributes. This framework enables the adaptive capability suitable for different real-world contexts. This paper also proposes an attack-hops verification approach as a tool to evaluate the architectural design.
引用
收藏
页码:248 / 253
页数:6
相关论文
共 50 条
  • [1] A nested ring-based architecture for building a very large-scale network switching system
    Lee, LT
    Tao, DF
    Chang, CC
    Shih, LC
    Lin, HW
    2002 IEEE REGION 10 CONFERENCE ON COMPUTERS, COMMUNICATIONS, CONTROL AND POWER ENGINEERING, VOLS I-III, PROCEEDINGS, 2002, : 859 - 862
  • [2] Protection for a Ring-Based EPON Architecture
    Hossain, A. S. M. Delowar
    Erkan, H.
    Dorsinville, R.
    Ali, M.
    Shami, A.
    Assi, C.
    2ND INTERNATIONAL CONFERENCE ON BROADBAND NETWORKS (BROADNETS 2005), 2005, : 626 - 631
  • [3] A very large-scale switching system by using nested ring-based architecture
    Tao, Der-Fu
    Lee, Liang-Teh
    Wu, Chen-Feng
    COMPUTERS & ELECTRICAL ENGINEERING, 2008, 34 (03) : 222 - 231
  • [4] A Novel Ring-Based EPON Architecture
    Hossain, A. S. M. Delowar
    Erkan, H.
    Dorsinville, R.
    Ali, M.
    Shami, A.
    Assi, C.
    2ND INTERNATIONAL CONFERENCE ON BROADBAND NETWORKS (BROADNETS 2005), 2005,
  • [5] Physical Security of Ring-based PUF
    Bossuet, L.
    24TH IEEE EUROPEAN CONFERENCE ON CIRCUIT THEORY AND DESIGN (ECCTD 2020), 2020,
  • [6] Experimental demonstration of a distributed ring-based EPON architecture
    Pathak, B.
    Ummy, M. A.
    Madamopoulos, N.
    Antoniades, N.
    Ali, M. A.
    Dorsinville, R.
    PHOTONIC NETWORK COMMUNICATIONS, 2010, 19 (01) : 55 - 61
  • [7] A Security framework for Wireless Network based on Public Key Infrastructure
    Tan, Wuzheng
    Yang, Maojiang
    Ye, Feng
    Ren, Wei
    2009 ISECS INTERNATIONAL COLLOQUIUM ON COMPUTING, COMMUNICATION, CONTROL, AND MANAGEMENT, VOL II, 2009, : 567 - 570
  • [8] State Based Network Isolation for Critical Infrastructure Systems Security
    Conklin, Wm. Arthur
    2015 48TH HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES (HICSS), 2015, : 2280 - 2287
  • [9] Experimental demonstration of a distributed ring-based EPON architecture
    B. Pathak
    M. A. Ummy
    N. Madamopoulos
    N. Antoniades
    M. A. Ali
    R. Dorsinville
    Photonic Network Communications, 2010, 19 : 55 - 61
  • [10] The stereo correspondence problem on a ring-based network
    Arabnia, HR
    SECOND AIZU INTERNATIONAL SYMPOSIUM ON PARALLEL ALGORITHMS/ARCHITECTURE SYNTHESIS, PROCEEDINGS, 1997, : 265 - 275