cyber security and diversity

Relevance of diversity strategy while securing any set of national assets. Diversity in national infrastructure involves the introduction of intentional differences into systems such as vendor source, deployment approach, network connectivity, targeted standards, programming language, operating system, and software version. Two systems are considered diverse if their key attributes differ, and nondiverse otherwise. The requirement for physical diversity in the design of computing infrastructure is perhaps the most familiar of all diversity-related issues. The idea is that any computing or networking asset that serves as an essential component of some critical function must include physical distribution to increase its survivability. A national diversity program should be developed that would call for coordination between companies and governmental agencies in several .

Save Time On Research and Writing
Hire a Pro to Write You a 100% Plagiarism-Free Paper.
Get My Paper

 how the types of threats discussed in the below article could impact our economy, and how implementing Diversity (as discussed in the attachment) could help mitigate these threats?

 

https://www.resdal.org/Archivo/usa-home-prote.htm

 

Save Time On Research and Writing
Hire a Pro to Write You a 100% Plagiarism-Free Paper.
Get My Paper

1

Copyright © 2012, Elsevier Inc.

All Rights Reserved

Chapter

4

Divers

ity

Cyber Attacks
Protecting National Infrastructure, 1st ed.

2

Copyright © 2012, Elsevier Inc.

All rights Reserved

C
h
a
p
te

r 4

D
iv

e
rs

ity

Introduction

• The securing any set of national assets should
include a diversity strategy

• The deliberate introduction of diversity into national
infrastructure to increase security has not been well
explored

• Two system are considered diverse if their key
attributes differ

• Diversity bucks the trend to standardize assets for
efficiency’s sake

3

Fig. 4.1 – Diverse and nondiverse
components through attribute

differences

Copyright © 2012, Elsevier Inc.
All rights Reserved
C
h
a
p
te
r 4

D
iv
e
rs
ity

4
Copyright © 2012, Elsevier Inc.
All rights Reserved
C
h
a
p
te
r 4

D
iv
e
rs
ity

Diversity and Worm Propagation

• Worm propagation is an example of an attack that
relies on a nondiverse target environment

• Worm functionality in three steps:
– Step #1: Find a target system on the network for

propagation of worm program

– Step #2: Copy program to that system

– Step #3: Remotely execute program

– Repeat

• Diversity may be expensive to introduce, but saves
money on response costs in the long run

5

Copyright © 2012, Elsevier Inc.
All rights Reserved
C
h
a
p
te
r 4

D
iv
e
rs
ity

Fig. 4.2 – Mitigating worm activity
through diversity

6

Copyright © 2012, Elsevier Inc.
All rights Reserved
C
h
a
p
te
r 4

D
iv
e
rs
ity

Desktop Computer System Diversity

• Most individual computers run the same operating
system software on a standard processor platform
and browse the Internet through one or two popular
search engines with the one of only a couple
browsers

• The typical configuration is a PC running Windows on
an Intel platform, browsing the Internet with Internet
Explorer, searching with Google

• This makes the average home PC user a highly
predictable target

7

Copyright © 2012, Elsevier Inc.
All rights Reserved
C
h
a
p
te
r 4

D
iv
e
rs
ity

Fig. 4.3 – Typical PC configuration
showing diversity

8

Copyright © 2012, Elsevier Inc.
All rights Reserved
C
h
a
p
te
r 4

D
iv
e
rs
ity
Desktop Computer System Diversity

• Three Considerations
– Platform costs

– Application interoperability

– Support and training

9

• Ultimate solution for making desktops more secure
involves their removal
– Not a practical solution

• Cloud computing may offer home PC users a diverse,
protected environment

Copyright © 2012, Elsevier Inc.
All rights Reserved
C
h
a
p
te
r 4

D
iv
e
rs
ity

Diversity Paradox of Cloud
Computing

10

Copyright © 2012, Elsevier Inc.
All rights Reserved
C
h
a
p
te
r 4

D
iv
e
rs
ity

Fig. 4.4 – Spectrum of desktop diversity
options

11

Copyright © 2012, Elsevier Inc.
All rights Reserved
C
h
a
p
te
r 4

D
iv
e
rs
ity

Fig. 4.5 – Diversity and attack difficulty
with option of removal

12

• Modern telecommunications consist of the following
two types of technologies
– Circuit-switched

– Packet-switched

• When compared to one another, these two
technologies automatically provide diversity

• Diversity may not always be a feasible goal
– Maximizing diversity may defend against large-scale

attacks, but one must also look closely at the entire
architecture

Copyright © 2012, Elsevier Inc.
All rights Reserved
C
h
a
p
te
r 4

D
iv
e
rs
ity

Network Technology Diversity

13

Copyright © 2012, Elsevier Inc.
All rights Reserved
C
h
a
p
te
r 4

D
iv
e
rs
ity

Fig. 4.6 – Worm nonpropagation benefit
from diverse telecommunications

14

Copyright © 2012, Elsevier Inc.
All rights Reserved
C
h
a
p
te
r 4

D
iv
e
rs
ity

Fig. 4.7 – Potential for impact
propagation over shared fiber

15

• Any essential computing or networking asset that
serves a critical function must include physical
distribution to increase survivability

• Physical diversity has been part of the national asset
system for years
– Backup center diversity

– Supplier/vendor diversity

– Network route diversity

Copyright © 2012, Elsevier Inc.
All rights Reserved
C
h
a
p
te
r 4

D
iv
e
rs
ity

Physical Diversity

16

Copyright © 2012, Elsevier Inc.
All rights Reserved
C
h
a
p
te
r 4

D
iv
e
rs
ity

Fig. 4.8 – Diverse hubs in satellite
SCADA configurations

17

• A national diversity program would coordinate
between companies and government agencies
– Critical path analysis

– Cascade modeling

– Procurement discipline

Copyright © 2012, Elsevier Inc.
All rights Reserved
C
h
a
p
te
r 4

D
iv
e
rs
ity

National Diversity Program

Calculate your order
Pages (275 words)
Standard price: $0.00
Client Reviews
4.9
Sitejabber
4.6
Trustpilot
4.8
Our Guarantees
100% Confidentiality
Information about customers is confidential and never disclosed to third parties.
Original Writing
We complete all papers from scratch. You can get a plagiarism report.
Timely Delivery
No missed deadlines – 97% of assignments are completed in time.
Money Back
If you're confident that a writer didn't follow your order details, ask for a refund.

Calculate the price of your order

You will get a personal manager and a discount.
We'll send you the first draft for approval by at
Total price:
$0.00
Power up Your Academic Success with the
Team of Professionals. We’ve Got Your Back.
Power up Your Study Success with Experts We’ve Got Your Back.

Order your essay today and save 30% with the discount code ESSAYHELP