Skip to main content

My InfoTech Journal!

My InfoTech Journal: Decoding the Networking Enigma: OSI vs. TCP/IP Reference Models

My InfoTech Journal: Decoding the Networking Enigma: OSI vs. TCP/IP Reference Models The OSI (Open Systems Interconnection) Reference Model and the TCP/IP (Transmission Control Protocol/Internet Protocol) Reference Model: The OSI Reference Model and the TCP/IP Reference Model are both conceptual frameworks used to understand and standardize how different networking protocols and technologies interact. Here are some areas of comparison: 1. Number of Layers: OSI Model : It consists of seven layers: Physical, Data Link, Network, Transport, Session, Presentation, and  TCP/IP Model : It has four layers: Network Interface, Internet, Transport, and Application. 2. L ayer Functionality: OSI Model : Tends to be more comprehensive and abstract, defining each layer's functions independently. TCP/IP Model : Reflects the actual implementation of the Internet and focuses on how protocols are used in practice. 3. Adoption / Use: OSI Model : Less commonly used in practice, but it is still valuab...

Fortifying the Digital Frontier: Unmasking Network Security Risks and Solutions

Fortifying the Digital Frontier: 

Unmasking Network Security Risks and Solutions




It has been a while since my last post. I have been busy with work and learning Microsoft PowerBI and Power Automate. These are very good tools for dashboard creation and automation. Very easy to learn and use. Kudos to Microsoft for coming up with these great tools!


Fast forward, I have recently enrolled in a Master of Information Systems (MIS) program via Distance Education. I am excited to be an online distance education student. It has been a  very long time since I was a student. I know there will be adjustments needed from me… to be diligent, to be disciplined in balancing my work-studies-life, and to persevere to achieve my goal of getting my Master’s Degree.


I have decided to share my research in MyInfoTech Journal hoping these information will also be able to help those researching for similar topics.


Today, I am researching on the Network Layer and its Security Implications.


The information herein are paraphrased and simplified explanation of network layers and their security implications. These are general explanation of network security concepts which are based on research.



Network Layer:


The Network Layer is like the postal system for computers. When you send an email or visit a website, your data is divided into small packets (like letters), and the Network Layer helps these packets find their way from your computer to their destination, which could be another computer across the world.



Security Implications:


Data Privacy: The Network Layer is responsible for sending your data over the internet. If it's not secure, your personal information, like passwords or messages, could be intercepted by hackers. To protect your data, encryption (making data unreadable except for the intended recipient) is used.


DDoS Attacks: Network Layer security helps defend against DDoS (Distributed Denial of Service) attacks. These attacks overwhelm a network with so much traffic that it can't function properly. Security measures at this layer can detect and mitigate such attacks.


Routing Security: The Network Layer is responsible for routing packets. If attackers manipulate routing, they can intercept or redirect your data. Security mechanisms like BGP (Border Gateway Protocol) security help prevent this.


IP Spoofing: Attackers can impersonate legitimate sources by spoofing IP addresses, making it challenging to trace the source of malicious traffic. Implementing ingress and egress filtering can help prevent IP spoofing.



Risks and Vulnerabilities:


Unauthorized Access: Unauthorized users may gain access to network devices, leading to data breaches or disruptions. Strong access controls, authentication, and intrusion detection systems can mitigate this risk.


Weak Authentication: Weak or default credentials on network devices can be exploited by attackers. Regularly updating and securing device credentials is essential.


Malware and Phishing: Malware can infect devices within the network, while phishing attacks target network users. Robust antivirus software, email filtering, and user education are essential defenses.


Unpatched Software: Failing to update network equipment and software leaves vulnerabilities open. Regular patch management is critical.


Ways to Secure the Network Layer:


Firewalls: Deploy firewalls to filter incoming and outgoing traffic, allowing only authorized communication. Think of firewalls as security guards for your network. They sit at the Network Layer and decide which data packets are allowed to enter or leave your network. They block suspicious or harmful traffic.


Intrusion Detection and Prevention Systems (IDS/IPS): Implement IDS/IPS to detect and respond to suspicious network activities. 

IDS (IntrusionDetectionSystem) detects potential threats and alerts administrators but does not actively block them.

IPS (Intrusion Prevention System) goes a stepfurther by detecting threats and actively blocking or preventing them in real-time.

IDPS (Intrusion Detection & Prevention System) combinesthe features of both IDS and IPS, offering detection and prevention capabilities within a single system, providing a more holistic approach to network security.


The choice between IDS,IPS, or IDPS dependson the specific security needs and risk tolerance of an organization. Some situations may require the visibility and alerting of IDS, while others may demand the active prevention of IPS or the comprehensive approach of IDPS.


VPN and Encryption: Use Virtual Private Networks (VPNs) and encryption (e.g., IPsec, SSL/TLS) to secure data in transit. VPNs create secure tunnels through the network layer. They protect your data by encrypting it and making it difficult for anyone to snoop on your online activities.


Access Controls: Enforce strict access controls, limit user privileges, and regularly review and revoke unnecessary access.


Security Policies: Develop and enforce network security policies, including strong password policies and access management.


Network Monitoring: Continuously monitor network traffic for anomalies or signs of attacks.


Regular Updates: Keep network devices and software up to date with security patches.


DDoS Protection: Employ DDoS protection services and strategies, such as rate limiting and traffic scrubbing.


Training and Awareness: Educate network users about security best practices and how to recognize phishing attempts.


Incident Response Plan: Prepare an incident response plan to address and mitigate security breaches promptly.


The Network Layer is crucial for sending data across the internet, but it's also a prime target for security threats.


Securing the Network Layer involves a combination of technologies, policies, and proactive measures to protect against various threats and vulnerabilities, ensuring the confidentiality, integrity, and availability of network resources and data.


Protecting it involves encryption, firewalls, DDoS defense, VPNs, routing security, and intrusion detection systems to keep your data and network safe.


Disclaimer
 

This article is a result of my personal research and is not a substitute for legal advise. Please consult your Legal Team, Ethics & Compliance, or Regulatory Team for the interpretation of  specific CyberSecurity requirements.




Comments

POPULAR: My InfoTech Journal

MyInfoTechJournal: Never Let a Crisis Go to Waste: The Ultimate Business Continuity Plan (BCP) for Thriving in Any Situation (Part 3 of 3: EXAMPLE)

MyInfoTechJournal: Never Let a Crisis Go to Waste: The Ultimate Business Continuity Plan (BCP) for Thriving in Any Situation  (Part 3 of 3: EXAMPLE)

My InfoTech Journal: Decoding the Networking Enigma: OSI vs. TCP/IP Reference Models

My InfoTech Journal: Decoding the Networking Enigma: OSI vs. TCP/IP Reference Models The OSI (Open Systems Interconnection) Reference Model and the TCP/IP (Transmission Control Protocol/Internet Protocol) Reference Model: The OSI Reference Model and the TCP/IP Reference Model are both conceptual frameworks used to understand and standardize how different networking protocols and technologies interact. Here are some areas of comparison: 1. Number of Layers: OSI Model : It consists of seven layers: Physical, Data Link, Network, Transport, Session, Presentation, and  TCP/IP Model : It has four layers: Network Interface, Internet, Transport, and Application. 2. L ayer Functionality: OSI Model : Tends to be more comprehensive and abstract, defining each layer's functions independently. TCP/IP Model : Reflects the actual implementation of the Internet and focuses on how protocols are used in practice. 3. Adoption / Use: OSI Model : Less commonly used in practice, but it is still valuab...

My InfoTech Journal: Unpacking the OSI Model: Your Guide to Networking Layers

My InfoTech Journal: Unpacking the OSI Model: Your Guide to Networking Layers The OSI (Open Systems Interconnection) reference model is a way to understand how different parts of computer networks communicate. Each layer having a specific job. 1. Physical Layer: This is the actual hardware, like cables and switches. Example: Ethernet cables connect devices in a network. 2. Data Link Layer: Ensures data is sent and received without errors within a local network. Example: Ethernet frames help in local data transfer. 3. Network Layer: Manages data routing between different networks. Example: IP (Internet Protocol) routers guide data between your home and a website. 4. Transport Layer: Ensures data arrives reliably and in order. Example: TCP (Transmission Control Protocol) guarantees error-free data transfer. 5. Session Layer: E stablishes, maintains, and ends connections between devices. Example: Setting up a video call on Skype. 6. Presentation Layer: Translates data into a format that ...

Information Security Tenets (The CIA Triad)

My InfoTech Journal:   Information Security Tenets The CIA Triad The   three tenets or fundamental principles of Information Security are  Confidentiality ,  Integrity , and  Availability .  This is also commonly known as the CIA Triad . The Information Security  programs refers to the controls designed and implemented to protect these three tenets:  Confidentiality ,  Integrity , and  Availability .   What is Confidentiality? Confidentiality ensures that private information remains private and that these private information can only be accessed or viewed by authorized individuals on need to know basis. Information Security controls must therefore be put in place to protect the data from unauthorized disclosure.  Examples of  Information Security controls  to ensure Data Confidentiality : Access Control List (ACL) Username and Password  Encryption  Two-Factor Authentication (Password, Token, PIN, Biome...

CyberSecurity Vulnerabilities in Control Systems

My InfoTech Journal:  CyberSecurity Vulnerabilities in Industrial Control Systems For this article, I will be presenting an overview of CyberSecurity Vulnerabilities, using the US   CyberSecurity & Infrastructure Security Agency (CISA) guidelines for Industrial Control Systems . Please note that this US CISA CyberSecurity guideline is specific to Industrial Control Systems. Nonetheless the framework and line of thought can be used as reference for any other similar environment. CyberSecurity aims to protect sensitive information hosted in critical systems from different faces of evolving threats. Year-by-year business reports would publish the cost of data breaches globally in millions of US dollars. This includes losses in business revenues, cost of responding to the breach, cost of deciphering the extent of the data breach,  performing root cause analysis, and most of all the long term damage of the company reputation and brand. In order to protect your Control Syst...

Network Security: How to minimize the Risk of your Wireless Network

My InfoTech Journal: What you can do to minimize the risk of your wireless network? Access Points are usually targets for unauthorized access. You have to ensure that your access points are secured to prevent unauthorized access.  There are several ways of securing your wireless access points.  Here is a Security Tip from the US CISA. Change default password. Restrict access. Encrypt the data on your network. Protect your Service Set Identifier (SSID). Install a Firewall. Maintain Anti-Virus software.I Use file sharing with caution. Keep your access point software patched and up to date. Check your internet provider’s router or router manufacturers wireless security options. Connect Using Virtual Private Network (VPN). A more detailed discussion of this tip can be found in this post:   US CISA: Security Tip (ST 005-003) Securing Wireless Networks End Notes  US CISA: Security Tip Disclaimer   This article is a result of my personal research and is not a substitut...

The Ultimate Guide to Protecting Your Company's Secrets and Personal Information - Don't Get Hacked!

My InfoTech Journal: The Ultimate Guide to Protecting Your Company's Secrets and Personal Information - Don't Get Hacked!

Are You Safe? The Shocking Truth About Privacy Risks and How to Protect Yourself

My InfoTech Journal: Are You Safe? The Shocking Truth About Privacy Risks and How to Protect Yourself

Playbook for Conducting a Comprehensive IT Infrastructure Audit

Playbook for Conducting a Comprehensive IT Infrastructure Audit