Guarding a computer network, whether it's configured for as many as 10 thousand or as few as 10 users, most often means a firewall, anti-virus software, and possibly encryption. Other elements include intrusion detection, patch management, and backup and recovery systems. While 10 years ago protecting a network meant almost exclusively safeguarding the data. Threats are simple conceptually. On the one hand is data security and on the other are efficient business operations.

Network Protection Strategies

The first line of defense is a network firewall, which is typically a combination of hardware and software. The hardware component is the broadband router, the hub between the users on a network and the Internet. It's the traffic controller, then, and typically uses a packet filtering system to guard the system against intrusive requests, directory harvesting attacks, spam traffic, and computer viruses. Other options include application and circuit gateways and proxy servers.

Packets are smaller pieces of the puzzle that make up a single data files--whether that's a corporate report, a graphic file, a text email, a single spreadsheet, or any binary information. Files are broken into components just before being sent and are recombined after being received. Packet information may or may not include sender IP information or any other identifier.

Firewalls are configured to block traffic of a certain type in certain directions. Hardware configuration focuses on the system's TCP/IP ports (that acronym, by the way, means transmission control protocol/Internet protocol). Software protection is significantly more flexible, in that it can be configured on a per program and per file type basis. The downside is that its protection is restricted to the machine on which it's installed. Above and beyond the firewall, however, are several other layers of network protection. Anti-virus software is critical, and not only the software itself, but continually updated virus definitions.

