Network Segmentation and Its Advancement in Containing Insider Threats
摘要
There has been a growing number of cyber-attacks in the recent years and insiders have contributed to the success of a generous portion. Insiders skip the initial access phase of attacks and already have a large amount of access to assets in an organisations system. While there are various techniques to prevent this, our focus in this project will be in the scope of network segmentation and its effectiveness of containing such a threat actor. If a threat is contained to a segment of an organisations systems, their impact will be reduced significantly, and the attack will be resolved much sooner as the scale of disaster recovery is inherently less. This project will be to analyse, compare, and contrast a variety of highly regarded peer-reviewed journal articles. Such journals will be found using keywords across several research platforms. With this information, a determination of whether network segmentation is a strong solution to containing an insider threat or an attacker already at the initial access stage to the already compromised area of a system. Zero Trust Architecture will be consulted with respect to its support of the topic. Increased clarity of definitions throughout the literature will be provided to clear the common misconception of insider threats. Finally, we will provide direction for further research in this field to expand the knowledge span amongst researchers.