DocumentCode
3527994
Title
Using ITU-T X.805 for comprehensive network security assessment and planning
Author
McGee, Andrew R. ; Chandrashekhar, U. ; Richman, Steven H.
Author_Institution
Lucent Technol. Bell Labs., Holmdel, NJ, USA
fYear
2004
fDate
13-16 June 2004
Firstpage
273
Lastpage
278
Abstract
In the wake of recent events, network security and reliability have become top issues for service providers and enterprises. The worldwide cost of cyber attacks is estimated to have been in the $145 billion dollar range for 2003. 2003 was also regarded as the "worst year ever" for computer viruses and worms; in 2001 the Code Red worm took several days to create widespread damage, whereas Slammer in 2003 had significant impact in just minutes. Over 90% of network attacks resulting in significant financial loss originate from inside a network\´s perimeter. Unfortunately, there appears to be no end in sight to these threats to network security; in fact, there is an increasing trend of attacking financial resources in addition to computing resources. The newly ratified ITU-T Recommendation X.805 "security architecture for systems providing end-to-end communications" was developed as the framework for the architecture and dimensions in achieving end-to-end security of distributed applications. It provides a comprehensive, multilayered, end-to-end network security framework across eight security dimensions in order to combat network security threats. We introduce the X.805 standard and describe how it can be applied to all phases of a network security program. We also provide examples of the business impact of network security vulnerabilities and the application of X.805 for network security assessments. Enterprises and service providers alike should use X.805 to provide a rigorous approach to network security throughout the entire lifecycle of their security programs.
Keywords
IP networks; business communication; computer network management; computer network reliability; computer viruses; open systems; telecommunication security; ITU-T X.805 Recommendation; X.805 standard; computer viruses; computer worms; distributed application; end-to-end communications; enterprise network; network reliability; network security program; security architecture; Communication system security; Computer architecture; Computer network reliability; Computer networks; Computer viruses; Computer worms; Costs; Data security; Information security; Investments;
fLanguage
English
Publisher
ieee
Conference_Titel
Telecommunications Network Strategy and Planning Symposium. NETWORKS 2004, 11th International
Print_ISBN
3-8007-2840-0
Type
conf
DOI
10.1109/NETWKS.2004.1341856
Filename
1341856
Link To Document