A Threat-Driven Approach to Modeling a Campus Network Security
Marlon A. Naagas, Thelma Domingo Palaoag · 2018
The Higher Education Institutions (HEI) readiness to cyber security threats has gotten less consideration than certain organizations and financial companies and the need to address these kinds of adversities are necessary in colleges and universities. These institutions face challenges which are unique to the way they operate, meaning they have to seek out appropriate solutions to keep their assets safe and secure. Threat-Driven Approach is a systematic approach that is driven by a clear understanding of the security need. Using this systematic approach, the strength of a protection is easily gauged through simple identification of the weakest link of the network. Various Threat Driven approach have been proposed, but most of the study focuses on the security of software development and business infrastructure. Based on the existing literature, there is no HEI that are practicing the systematic approach in securing their assets. The primary purpose of this paper is to enable HEI to apply this approach and will provide detailed guidance that will enable HEI to place threats at the forefront of planning, design, testing, deployment and operational activities. The THREAT DRIVEN APPROACH is a set of integrated methodology, practices and tools into one framework/model. The STRIDE and DREAD are also used in this study to identify and calculate the potential threats of the Network Security. As a result, our approach can make network design secured from anticipated security threats and, thus, reduce significant design-level vulnerabilities.