Network security architecture

Author: (USA) Convery (Convery/S.) / Wang Yingchun / Xie Lin / Jiang Kui
Publisher:
Publish Date: 2005-06-01
Features: The authors are the Chief Architect of the SAEE Security Blueprint at Cisco Systems. This book is a comprehensive guide to designing and implementing secure networks. Regardless of your background in security or networking, you will learn how to achieve a highly available, effective, and as secure as possible network. The security network design techniques in this book emphasize the integration of network and security technologies as a unified system, rather than deploying isolated systems in a particular way. This book fills in the gaps left by other security books and demonstrates how to comprehensively use various technologies that make up a security system to enhance network security. The technologies and best practices you will see are not limited to any specific vendor but are widely applicable to any network system. The book discusses why and how to implement security, from threats and countermeasures to establishing security policies and designing network architecture. After learning detailed security best practices covering everything from Layer 2 security to e-commerce design, you will see how to apply these best practices to your network and learn how to design your own security system to meet security policy requirements. You will also examine detailed designs for addressing current threats by applying defense-in-depth techniques and carefully studying case studies to identify how to modify these designs to solve specific network problems. Whether you are a network engineer or a security engineer, this book will be an essential reference for designing and building secure networks.
"Designing and configuring networks to confidently face malicious attacks, errors, and misfortunes remains a mysterious field. Perhaps it will eventually be fully understood and become a fixed formula. But for now, this book is one of the guiding principles." — Ross Anderson, Professor of Security Engineering, University of Cambridge
This is a very comprehensive book on network security, divided into 4 parts and 3 appendices. Part 1 outlines the fundamentals of network security, providing the prerequisites for designing secure networks and the basic elements needed for such designs, laying the foundation for subsequent chapters. Part 2 comprehensively discusses the various technologies available to security designers for building secure network systems, as well as specific security areas such as identification, IPsec VPN, and various supporting technology sets. Part 3 introduces the main components of secure network design and design approaches based on network scale. Part 4 focuses on network management, case studies, and conclusions. Appendix A summarizes the terminology used in this book. Appendix B provides answers to application questions for each chapter. Appendix C includes examples of installation strategies. The target audience for this book includes network/security designers, network/security operation engineers, IT managers, CIOs, and other professionals interested in network security.

📌 Related Posts