Computers and the Internet have revolutionized modern life and industry in unprecedented ways. Their greatest impact has been their ability to speed up communication and information exchange in various application domains as well as facilitate automation and service delivery in areas such as healthcare, education, commerce, law enforcement, supply chain, logistics, aerospace, and manufacturing. Internet-based computing systems and networks not only provide a unique platform for commercial entities to run their services and store sensitive data but also allows individuals to stay connected with friends and family and build social networks with people of similar interests. Some of these online activities, such as private conversations, intellectual property, and personally identifying information, need some measure of secrecy or discretion (Xiao & Guo, 2020). Otherwise, their disclosure to unauthorized parties could cause irreparable losses or damage. It is for this reason that network security is needed. Thus, network security involves protecting the underlying network infrastructure from misuse or unauthorized access (Cisco Systems Inc, 2022). network security technology is continuously developing to counter the ever-evolving nature of network security threats. This blog examines the common security threats and vulnerabilities facing a network and how to prevent them.

What is Network Security



The International Organization for Standardization (IOS) defines network security as the act of protecting software, hardware, and data resources found in computer systems from malicious or accidental destruction, alteration, or leakage so that these systems can operate normally and reliably (Xiao & Guo, 2020). From this definition, computer network security addresses four areas: networking hardware, software, shared resources, and Internet of things (IoT) services. Networking hardware includes devices such as hubs, switches, and routers. These devices can be built into a communication network through wires and cables or wireless connections.


Network Security Threats:



Security threats also flow from the four components of a network. They include (1) misuse of IoT information, (2) attacks on the background service, (3) attacks on network integrity, and (4) leakage of information (Xiao & Guo, 2020). misuse of IoT information arises from the user domain when people click or download website content without screening them. This increases the risk of malware and virus attacks. Misuse of network resources by intruders can also be caused by vulnerabilities and configuration errors in software applications. Background service attacks, also called denial-of-service-attacks (DoS), seek to cause delays in the network or use up network resources such as bandwidth and storage space to interrupt service delivery. Some attacks, such as hacking, target the integrity of computer networks. Lastly, information leakages to unauthorized entities can arise from worms and viruses, Trojan-horse intrusion, pre-existing system vulnerabilities, network interception, and eavesdropping, among others. There is a growing trend towards using exploit kits (e.g., black hole) to exploit multiple vulnerabilities and infect computers automatically without the intervention of the user (Kumar & Kumar, 2014). This has been worsened by the availability of free attack tools (e.g., Stacheldraht and Trino)o over the Internet, as well as the proliferation of mobile devices that have expanded the attack surface available to cyber attackers.

Overall, the motives behind network security attacks include data theft (e.g., intellectual property, marketing plans, and financial data), loss of time, monetary loss, crippled services, and legal implications such as lawsuits. The costs of unauthorized network intrusion can be severe. One such consequence is the theft of trade secrets or sensitive government information that undermines competitive advantage in business and warfare. Other consequences include the hijacking the network systems that underlie critical infrastructures such as energy and water systems and facilitating unauthorized credit card and bank transactions. In 2012, for instance, a worm stole more than 45,000 login credentials of Facebook users compared to 6.5 million LinkedIn passwords stolen and leaked online (Kumar & Kumar, 2014).


Network Security Approaches & Techniques:

Network security combines multiple layers of defenses within and at the edge of the network with each layer comprising a separate set of security policies and controls. The three layers of network security include the physical, administrative, and technical layers (Malviya, 2021). Physical network security is about physical safeguards that prevent unauthorized persons from accessing the rooms or offices where network devices are kept. It includes protocols such as physical locks on doors and windows, employing security guards, biometric authentication, and surveillance cameras. Administrative network security refers to the policies and procedures that determine the scope of user access and privileges with regard to the network resources and information. It includes user authentication, security awareness training, and personnel registration measures. These protocols aim at reducing the security vulnerabilities arising from the user. Lastly, technical network security seeks to protect the network devices as well as stored and in-transit data from both unauthorized personnel and external attackers. Examples include encryption, network authentication, firewalls, intrusion detection systems (IDS), and anti-malware software.

Best Practices:

Some of the best practices of network security include performing a network audit, deploying network security devices, disabling file sharing features, updating anti-malware and antivirus software, securing the routers, using private IP addresses, establishing a maintenance system for network security, segmenting and segregating the network, and creating a security-oriented culture (Malviya, 2021). Securing a network should begin with an audit that identifies the weaknesses in the network design and infrastructure. An effective audit identifies security vulnerabilities that can act as entry points for malicious attacks. The audit also assesses the status and effectiveness of backup systems, malicious detection software, open ports, unnecessary/unused applications, and third-party risks. Once the vulnerabilities are known, entities should deploy network security devices such as web application firewalls for preventing web-based attacks, as well as intrusion detection systems (IDS), intrusion prevention system (IPS), DLP (data loss prevention) software, and SIEM (security information & event management) systems (Malviya, 2021). These security devices monitor network traffic and data packets for known cyberattack signatures and incapacitate them before they can cause havoc.






File sharing is one of the major appeals of computer networks. However, it can easily introduce malware into the network. It is therefore prudent to disable file sharing on personnel devices and only use the sharing features on private or independent servers. Continuous update of anti-malware and antivirus software is also important to keep pace with new viruses. Securing the routers is non-negotiable. Routers play the vital role of connecting computer systems or local area networks (LANs) to the Internet and direct the delivery of data packets to specified users. However, the integrity of a router can be compromised by simply resetting previously-defined security protocols. As such, network security administrators should change the default password settings and network names/addresses and keep the routers in secure locations such as server rooms with video surveillance. Private IP addresses should also be assigned to critical network devices and servers, making it easy for network administrators to detect unauthorized attempts to access the network. The administrators should also establish a proper maintenance system involving regular backups, software updates, and alterations in network names and passwords.

While network monitoring for threats is helpful, it is more prudent to divide or segment the network into different trust zones (Malviya, 2021). This strategy enables the isolation of affected networks from the rest when security incidents occur, thus minimizing the adverse impact of a network intrusion. In addition, it ensures continuity of network services even while the incident is being addressed. Lastly, all the mentioned best practices will be inconsequential if efforts are not made to create a culture of security-centered culture that can be achieved through education and training of personnel.



Cyberattacks are not just a threat but a reality for many individuals, network users, and organizations. These threats are ever-evolving, given the growing sophistication of ICT and digital technologies. The motivation for these attacks is also changing from the usual profiteering to cyberactivism and cyber warfare. Network security is integral to the integrity of computer networks.

References:

Cisco Systems Inc. (2022). What is network security? Cisco. Retrieved March 18, 2022, from https://www.cisco.com/c/en/us/products/security/what-is-network-security.html#~how-network-security-works


Kumar, G., & Kumar, K. (2014). Network security – an updated perspective. Systems Science & Control Engineering, 2(1), 325-334. https://doi.org/10.1080/21642583.2014.895969


Malviya, N. (2021, June 22). 9 best practices for network security. Infosec Resources.

             Retrieved March 18, 2022, from https://resources.infosecinstitute.com/topic/9-best-practices-for-network-security/


Xiao, M., & Guo, M. (2020). Computer network security and preventive measures in the age of big data. Procedia Computer Science, 166, 438-442.

             https://doi.org/10.1016/j.procs.2020.02.068


Comments