next up previous contents
Next: 8.2 Network security controls Up: 8.1 General concepts in Previous: 8.1.1 Threats in networks

8.1.2 Network layers - placement of security services

In order to make it possible for network vendors to create open systems that can interact, a layered model has been proposed to identify various services that networking systems can provide. This 7-layered model was standardized by ISO as the OSI Basic Reference Model ISO/IEC 7498-1. In the mean time a different construct known as the TCP/IP suite evolved from the Internet community.

Within these layered constructs we can put four basic architectural levels for security as shown in figure B.1 ([FOR94, p.54]).

  
Figure B.1: Architectural layers for security
\resizebox*{1\textwidth}{!}{\includegraphics{arch_layers_for_sec.eps}}


The next paragraph gives a short description of the possibilities and some comments of the implementation of security services at the corresponding level:

In many cases a combination of methods at different layers constitutes the optimal solution at best price for the level of protection required. Risk analysis is necessary to locate the vulnerable areas and analyse the requirements.


next up previous contents
Next: 8.2 Network security controls Up: 8.1 General concepts in Previous: 8.1.1 Threats in networks
(c) 1998, Filip Schepers