Neil Barrett
Neil Barrett

Building castles in cyberspace

The medieval architects who designed fortified strongholds could teach software designers a thing or two

Neil Barrett

Defence in depth: one of the most fundamental and important of military concepts. Whether it's the movement of an infantry section or an entire division, the commanders always retain a portion of their force ready to move up and to support the advancing units.

In the case of castles, the principle is taken to the extreme. Outer walls are defended by strongpoint towers, themselves capable of being defended floor by floor. Within the castle, there are inner and outer walls; barbicans and killing zones; and an inner keep to act as the ultimate, last-ditch defensive position.

Advertisement

Even the coming of gunpowder and cannon didn't do that much to remove the need for castle defences. Outer walls were surrounded by deep ditches and traps for the attacking infantry; carefully placed mounds were used to deflect cannon balls; and surrounding hills - that could have been used by an attacker from which to fire their cannon - were themselves topped by smaller fortified positions.

The castle builders understood the principle of defence in depth and it was the fundamental notion behind all of their constructions.

A similar notion has been introduced for the physical security of many establishments, with CCTV, guards, screens, vaults and time-locked safes. Physically, banks and armoured cars are protected to a remarkable degree.

Why then has the philosophy been so difficult to introduce into information security?

Partly, this is because of the way in which information security is seen always as an "add-on" to a basic design; and partly it's to do with the nature of the measures themselves.

All of the most crucial elements of information security are designed to keep an attacker outside the outermost wall. Firewalls and passwords, smartcards and biometrics: all are intended to make sure that only those who should be on the inside are allowed to be there.

Yet the majority of security problems are caused by those who are already inside that wall. Employees, contractors, partners: these are the people we trust the most, and these are the people who do the most damage. Yet our defences are like Minstrel chocolates: a hard shell around a soft inner core.

We need to adopt a greater depth of information security, with measures for preventing, detecting and (perhaps most importantly) deterring intruders from proceeding deeper into the information "castle".

Each and every server should be considered a "strongpoint", with its own lines of defence and monitoring; each portion of the network should be firewalled and screened from every other; and intrusion detection systems should monitor everyone who acts on the network.

Some of the supposedly most trusted networks in the UK's Critical National Infrastructure - the finance, transport and utilities networks on which we depend - are not protected from internal abuse.

Correcting this will take time, money and dedication, but the result will be a secure infrastructure and a secure nation. It still might not be completely safe from information warfare and cyber-terrorism, but it will at least be able to provide a plausible defence.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Cost of cyber-crime continues to decline

Attacks cause less financial damage as security investments start to pay off

Related whitepapers

Related jobs

Most watched

Social networking

Summit: How businesses should manage their brands online

In part one of V3.co.uk's interview with Dirk Singer, he dicusses social media monitoring strategies

RIM discusses new developer tools

Blackberry exec on the latest offerings for programmers

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

Summit: Views From the Valley

V3.co.uk's US office weighs in on the information overload crisis

money

Summit: Managing information overload in a recession

Balancing exploding data with shrinking budgets

Chambers outlines Cisco's corporate plans

CEO describes broader company focus

Social networking

Summit: How businesses should manage their brands online

In part one of V3.co.uk's interview with Dirk Singer, he...

Primary Navigation