A Security Architecture Framework for Critical Infrastructure with Ring-based Nested Network Zones

被引:0
|
作者
Chaisuriya, Sarayut [1 ]
Keretho, Somnuk [1 ]
Sanguanpong, Surasak [1 ]
Praneetpolgrang, Prasong [2 ]
机构
[1] Kasetsart Univ, Fac Engn, Bangkok, Thailand
[2] Sripatum Univ, Fac Informat Technol, Bangkok, Thailand
关键词
Security Architecture; Nested Zones; Critical Infrastructure; Attack Hops; Defense in Depth;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The defense-in-depth approach has been widely recommended for designing critical information infrastructure, however, the lack of holistic design guidelines makes it difficult for many organizations to adopt the concept. Therefore, this paper proposes a holistic architectural framework and guidelines based on ring-based nested network zones for designing such highly secured information systems. This novel security architectural framework and guidelines offer the overall structural design and implementation options for holistically designing the N-tier/shared nothing system architectures. The implementation options, e.g. for the zone's perimeters, are recommended to achieve different capability levels of security or to trade off among different required security attributes. This framework enables the adaptive capability suitable for different real-world contexts. This paper also proposes an attack-hops verification approach as a tool to evaluate the architectural design.
引用
收藏
页码:248 / 253
页数:6
相关论文
共 50 条
  • [31] The impact of network bandwidth on the performance of ring-based multiprocessor systems
    Chung, SW
    Jhang, ST
    Jhon, CS
    PARALLEL AND DISTRIBUTED COMPUTING SYSTEMS, 2000, : 35 - 40
  • [32] Modeling and evaluation of ring-based interconnects for Network-on-Chip
    Bourduas, Stephan
    Zilic, Zeljko
    JOURNAL OF SYSTEMS ARCHITECTURE, 2011, 57 (01) : 39 - 60
  • [33] Optimal interconnection network bandwidth for ring-based multiprocessor systems
    Chung, SW
    Jhon, CS
    INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED PROCESSING TECHNIQUES AND APPLICATIONS, VOLS I-V, PROCEEDINGS, 1999, : 2266 - 2271
  • [34] CPRring: A Structure-aware Ring-based Checkpointing Architecture for FPGA Computing
    Vu, Hoang Gia
    Takamaeda-Yamazaki, Shinya
    Nakada, Takashi
    Nakashima, Yasuhiko
    2017 IEEE 25TH ANNUAL INTERNATIONAL SYMPOSIUM ON FIELD-PROGRAMMABLE CUSTOM COMPUTING MACHINES (FCCM 2017), 2017, : 192 - 192
  • [35] Designing Critical Infrastructure Cyber Security Segmentation Architecture by Balancing Security with Reliability and Availability
    Kawano, Kegan
    CRITICAL INFORMATION INFRASTRUCTURES SECURITY, 2008, 5141 : 261 - 273
  • [36] OpenStackDP: a scalable network security framework for SDN-based OpenStack cloud infrastructure
    Prabhakar Krishnan
    Kurunandan Jain
    Amjad Aldweesh
    P. Prabu
    Rajkumar Buyya
    Journal of Cloud Computing, 12
  • [37] Ring-based local access PON architecture for supporting private networking capability
    Hossain, ASMD
    Dorsinville, R
    Ali, MA
    Shami, A
    Assi, C
    JOURNAL OF OPTICAL NETWORKING, 2006, 5 (01): : 26 - 39
  • [38] Layout optimization methodology for ring-based on-chip optical network
    Wang, Kang
    Wang, Kun
    Yang, Yintang
    Wang, Yue
    Gu, Huaxi
    IEICE ELECTRONICS EXPRESS, 2019, 16 (20): : 1 - 6
  • [39] OpenStackDP: a scalable network security framework for SDN-based OpenStack cloud infrastructure
    Krishnan, Prabhakar
    Jain, Kurunandan
    Aldweesh, Amjad
    Prabu, P.
    Buyya, Rajkumar
    JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2023, 12 (01):
  • [40] Dynamic Ring-based Multicast with Wavelength Reuse for Optical Network on Chips
    Liu, Feiyang
    Zhang, Haibo
    Chen, Yawen
    Huang, Zhiyi
    Gu, Huaxi
    2016 IEEE 10TH INTERNATIONAL SYMPOSIUM ON EMBEDDED MULTICORE/MANY-CORE SYSTEMS-ON-CHIP (MCSOC), 2016, : 153 - 160