Network Sales and Services Handbook (Cisco Press Networking Technology)

The goal of network security is to provide users with access to necessary network resources, while preventing access against known and unknown, internal and external, threats. Network or system threats are categorized as follows:

There are many ways that attackers can access or abuse unprotected networks or hosts (computers), the most popular being via the introduction of macros or viruses to a network system.

Firewalls are an effective solution against most network attacks because they can stop an attacker outside the network from logging into a computer inside the network and wreaking havoc on network resources. Intrusion Detection Systems (IDSs) are another effective solution against most network attacks. IDSs detect the inappropriate, incorrect, or anomalous activity impacting network and its resources. An intrusion can include a network attack from the outside (intruder or unauthorized user) or from an internal network user (misuse).

IDSs are implemented in one of two ways:

Firewalls and IDSs can be placed anywhere within a network, but the most common and effective placements are at the network perimeter, the network backbone, and network server farms.

Категории