Skip to content
Open access

A COMPREHENSIVE APPROACH TO ENSURING THE CYBERSECURITY OF CORPORATE NETWORK INFRASTRUCTURE

Sep 2026 · Системи управління навігації та зв'язку Збірник наукових праць · 0 citations · 9 references

Abstract

Relevance. The rapid development of digital technologies, the widespread implementation of corporate information systems, and the continuous increase in the number of cyber threats necessitate the improvement of approaches to protecting corporate network infrastructure. Traditional protection methods based on the use of separate software or hardware security tools do not provide an adequate level of resistance to modern cyberattacks, which are characterized by complexity, multiple attack vectors, and the ability to bypass individual security mechanisms. Therefore, the development of a comprehensive multi-layered cybersecurity system aimed at ensuring the confidentiality, integrity, and availability of the information resources of enterprises, institutions, and organizations is highly relevant. Subject of the research: modern approaches, models, protocols, and technologies for ensuring the cybersecurity of corporate network infrastructure. Purpose of the research: to substantiate a comprehensive approach to designing secure corporate computer networks based on multilayered protection and the integrated application of modern network security technologies. Research objectives. To analyze the role of the Open Systems Interconnection reference model as a methodological basis for designing secure computer networks; to identify the main information security threats affecting corporate networks; to investigate the implementation of security mechanisms at the physical, data link, network, and application layers; to examine the principles of the Defense in Depth concept; to analyze the capabilities of the AAA, RADIUS, SSH, ACL, VLAN, Port Security, DHCP Snooping, and Dynamic ARP Inspection models, protocols, and technologies; and to determine the advantages of their integrated application for improving the cybersecurity of corporate network infrastructure. Research methods. The study employs the methods of systems analysis, comparison, generalization, classification, and systematization of scientific and technical information. A structural and functional approach is applied to analyze security mechanisms at different layers of the OSI model. The method of modelling a comprehensive corporate network security architecture is also used. Research results. The main threats to the information security of corporate networks are identified, including MAC Spoofing, MAC Flooding, ARP Spoofing, ARP Cache Poisoning, Man-in-the-Middle attacks, unauthorized device connections, the compromise of user and administrator accounts, and violations of access control policies. The Defense in Depth concept, which involves creating several complementary layers of protection against external and internal cyber threats, is analyzed. It is established that the application of a multi-layered approach makes it possible to minimize the consequences of the compromise of individual network components and ensure the continuity of information systems even when particular attacks are successfully implemented. The capabilities of the AAA model for centralized access management to information resources are examined, together with the operating principles of the RADIUS protocol as a means of centralized authentication, authorization, and accounting of user activities. The advantages of using the cryptographically protected SSH protocol for the secure administration of network equipment are identified. The application of Access Control Lists for implementing security policies and controlling communication between corporate network segments is investigated. Port Security, DHCP Snooping, and Dynamic ARP Inspection technologies aimed at countering data-link-layer attacks and unauthorized device connections are analyzed. It is established that the logical segmentation of the network environment using VLAN technology is an effective mechanism for improving cybersecurity, as it enables the localization of cyber incidents, limits the lateral movement of attacks, and supports the implementation of the principle of least privilege. Conclusions. The highest level of protection of corporate network infrastructure is achieved through the integrated application of AAA, RADIUS, SSH, ACL, VLAN, Port Security, DHCP Snooping, and Dynamic ARP Inspection technologies in accordance with the principles of the Defense in Depth concept. The proposed approach provides centralized access control, increases the protection of information resources, improves the manageability of the network environment, reduces the risk of cyberattack propagation, and meets modern requirements for designing secure corporate information systems.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.