Security Laboratory

Security Laboratory: Defense In Depth Series


Hybrid Threats - June 18th, 2008
Can you build a Defense in Depth architecture without an architect? - Updated May 13th, 2008
The Attack Surface Problem - November 6th, 2007
The Uniform Method of Protection to Achieve Defense-in-Depth - February 26th, 2007
Security Convergence and The Uniform Method of Protection to Achieve Defense in Depth - September 7th, 2007
Protected Enclaves Defense-in-Depth - February 26th, 2007
Information Centric Approach to Defense-in-Depth - February 26th, 2007
Vector Oriented Defense in Depth - February 26th, 2007
Role Based Access Control to Achieve Defense in Depth - Updated December 26th, 2007

Protected Enclaves Defense-in-Depth

February 26th, 2007
By Stephen Northcutt



Protected enclaves simply means subdividing the internal network so that it is not one large zone with no internal protections. This architectural approach to information security defense-in-depth can be accomplished in a number of ways including:

The application for a computer security manager is pretty simple. Though there is some operational configuration overhead, these architectural approaches do not need to add a substantial amount of cost, and they buy you a lot of security. The biggest potential gotcha is that they can reduce throughput and or add latency. Test thoroughly in a lab environment before procurement and deployment. All of this information is covered in detail in SANS Perimeter Protection In-Depth.[8]

1. http://www.sans.edu/resources/musings/ciscobook.php
2. http://www.corecom.com/external/livesecurity/firewallplace.html
3. http://www.3com.com/en_US/jump_page/embedded_firewall.html
4. https://honor.icsalabs.com/pipermail/firewall-wizards/2004-December/017670.html
5. http://www.cisco.com/en/US/products/hw/switches/ps663/products_configuration_guide_chapter09186a00800ddcfb.html#wp1050355
6.
http://www.sans.org/resources/perlscript.php
7. http://www1.tools.ietf.org/wg/tsvwg/draft-ietf-tsvwg-vpn-signaled-preemption/draft-ietf-tsvwg-vpn-signaled-preemption-02-from-01.diff.html
8. http://www.sans.org/training/description.php?tid=422