A COMPREHENSIVE APPROACH TO ENSURING THE CYBERSECURITY OF CORPORATE NETWORK INFRASTRUCTURE

Authors

  • Tetyana Derkach
  • Andrii Dmytrenko
  • Lina Klochko

DOI:

https://doi.org/10.26906/SUNZ.2026.3.161

Keywords:

cybersecurity, corporate network, network infrastructure, information security, Defense in Depth, AAA, RADIUS, SSH, ACL, VLAN, Port Security, Dynamic ARP Inspection, OSI model, access control

Abstract

Relevance. The rapid development of digital technologies, the widespread implementation of corporate information systems, and the continuous increase in the number of cyber threats necessitate the improvement of approaches to protecting corporate network infrastructure. Traditional protection methods based on the use of separate software or hardware security tools do not provide an adequate level of resistance to modern cyberattacks, which are characterized by complexity, multiple attack vectors, and the ability to bypass individual security mechanisms. Therefore, the development of a comprehensive multi-layered cybersecurity system aimed at ensuring the confidentiality, integrity, and availability of the information resources of enterprises, institutions, and organizations is highly relevant. Subject of the research: modern approaches, models, protocols, and technologies for ensuring the cybersecurity of corporate network infrastructure. Purpose of the research: to substantiate a comprehensive approach to designing secure corporate computer networks based on multilayered protection and the integrated application of modern network security technologies. Research objectives. To analyze the role of the Open Systems Interconnection reference model as a methodological basis for designing secure computer networks; to identify the main information security threats affecting corporate networks; to investigate the implementation of security mechanisms at the physical, data link, network, and application layers; to examine the principles of the Defense in Depth concept; to analyze the capabilities of the AAA, RADIUS, SSH, ACL, VLAN, Port Security, DHCP Snooping, and Dynamic ARP Inspection models, protocols, and technologies; and to determine the advantages of their integrated application for improving the cybersecurity of corporate network infrastructure. Research methods. The study employs the methods of systems analysis, comparison, generalization, classification, and systematization of scientific and technical information. A structural and functional approach is applied to analyze security mechanisms at different layers of the OSI model. The method of modelling a comprehensive corporate network security architecture is also used. Research results. The main threats to the information security of corporate networks are identified, including MAC Spoofing, MAC Flooding, ARP Spoofing, ARP Cache Poisoning, Man-in-the-Middle attacks, unauthorized device connections, the compromise of user and administrator accounts, and violations of access control policies. The Defense in Depth concept, which involves creating several complementary layers of protection against external and internal cyber threats, is analyzed. It is established that the application of a multi-layered approach makes it possible to minimize the consequences of the compromise of individual network components and ensure the continuity of information systems even when particular attacks are successfully implemented. The capabilities of the AAA model for centralized access management to information resources are examined, together with the operating principles of the RADIUS protocol as a means of centralized authentication, authorization, and accounting of user activities. The advantages of using the cryptographically protected SSH protocol for the secure administration of network equipment are identified. The application of Access Control Lists for implementing security policies and controlling communication between corporate network segments is investigated. Port Security, DHCP Snooping, and Dynamic ARP Inspection technologies aimed at countering data-link-layer attacks and unauthorized device connections are analyzed. It is established that the logical segmentation of the network environment using VLAN technology is an effective mechanism for improving cybersecurity, as it enables the localization of cyber incidents, limits the lateral movement of attacks, and supports the implementation of the principle of least privilege. Conclusions. The highest level of protection of corporate network infrastructure is achieved through the integrated application of AAA, RADIUS, SSH, ACL, VLAN, Port Security, DHCP Snooping, and Dynamic ARP Inspection technologies in accordance with the principles of the Defense in Depth concept. The proposed approach provides centralized access control, increases the protection of information resources, improves the manageability of the network environment, reduces the risk of cyberattack propagation, and meets modern requirements for designing secure corporate information systems.

Downloads

Download data is not yet available.

References

1. Kurose, J. F., and Ross, K. W. (2025), Computer Networking: A Top-Down Approach, 9th ed., Pearson, New York, 864 p. available at: https://www.pearson.com/en-us/subject-catalog/p/computer-networking-a-top-down-approach/P200000013385

2. Buriachok, V. L., Hulak, H. M., and Tolubko, V. B. (2024), Information and cyberspaces: security problems, methods and means of counteraction, textbook, Magnolia-2006, Lviv 2024. 448 p. available at: https://magnolia.lviv.ua/wpcontent/uploads/2024/04/INF-TA-KIBERPROSTORY-pidruchnyk_zmist.pdf

3. Khomchak, M. (2025), “Cybersecurity risk assessment for selecting a cloud provider”, Cybersecurity: Education, Science, Technique, no. 27, pp. 549–559, doi: https://doi.org/10.28925/2663-4023.2025.27.773 DOI: https://doi.org/10.28925/2663-4023.2025.27.773

4. Derkach, T. M., Holovko, H. V., Dmytrenko, A. O., and Klochko, L. A. (2026), “Analysis of threats and vulnerabilities of computer networks and substantiation of a comprehensive approach to ensuring their cybersecurity”, Control, Navigation and Communication Systems, no. 2, pp. 73–80, doi: https://doi.org/10.26906/SUNZ.2026.2.073 DOI: https://doi.org/10.26906/SUNZ.2026.2.073

5. Derkach, T. M., and Lavrenko, M. (2024), “Cyberspace: analysis of threats and protection methods”, Innovative Education: Problems and Prospects of Scientific Research, Proceedings of the 50th International Scientific and Practical Conference, Stuttgart, December 4–6, pp. 112–115, available at: https://reposit.nupp.edu.ua/handle/PoltNTU/18104

6. Korchenko, O., Ivanchenko, E., Bakalinsky, O., Myalkovskyi, D., and Zubkov, D. (2024), “Method for assessing the level of cybersecurity improvement of critical infrastructure facilities of the state”, Science-Based Technologies, no. 61(1), pp. 3–20, doi: https://doi.org/10.18372/2310-5461.61.18509 DOI: https://doi.org/10.18372/2310-5461.61.18509

7. Anderson, R. (2020), Security Engineering: A Guide to Building Dependable Distributed Systems, Wiley, Hoboken, 1248 p., available at: https://www.cl.cam.ac.uk/archive/rja14/book.html DOI: https://doi.org/10.1002/9781119644682

8. Easttom, C. (2024), Network Defense and Countermeasures, Springer, William Easttom II, 412 p. available at: https://books.google.com.ua/books/about/Network_Defense_and_Countermeasures.html?hl=ar&id=_NFTDwAAQBAJ&redir_esc=y

9. Stewart, J. M., Chapple, M., and Gibson, D. (2024), ISC2 CISSP Certified Information Systems Security Professional Official Study Guide, 10th ed.: Wiley, Hoboken, ISBN 978-1-394-25470-5, 1248 p., available at: https://www.wiley.com/enus/ISC2+CISSP+Certified+Information+Systems+Security+Professional+Official+Study+Guide%2C+10th+Edition-p9781394254705

10. Tanenbaum, A. S., and Wetherall, D. J. (2011), Computer Networks, 5th ed. Upper Saddle River: Pearson, 2011. 960 p. available at: https://www.pearson.com/en-us/subject-catalog/p/computer-networks/P200000003188

11. Lakhno, V., Yerbolat, K.., Bagdat, Y., Kryvoruchko, O., Desiatko, A., Tsiutsiura, S., and Tsiutsiura, M. (2022), “A model for protecting the local network of an educational institution”, Cybersecurity: Education, Science, Technique, no. 18, pp. 6–23, doi: https://doi.org/10.28925/2663-4023.2022.18.623 DOI: https://doi.org/10.28925/2663-4023.2022.18.623

12. (2024), NIST Cybersecurity Framework (CSF) 2.0, National Institute of Standards and Technology, available at: https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf

13. (2018), IEEE Computer Society. IEEE Standard for Virtual Bridged Local Area Networks (IEEE 802.1Q), IEEE, New York, available at: https://standards.ieee.org/standard/802_1Q-2018.html

14. Derkach, T. M., and Prykhodko, R. (2025), “Intrusion detection system as a key element of multilayered cyber protection of information systems”, Research in Science, Technology and Economics, Proceedings of the 5th International Scientific and Practical Conference, Luxembourg, December 10–12, 2025, pp. 308–311, available at: https://reposit.nupp.edu.ua/handle/PoltNTU/20866

15. (1994), ISO/IEC 7498-1:1994. Information Technology – Open Systems Interconnection – Basic Reference Model, available at: https://www.ecma-international.org/wp-content/uploads/s020269e.pdf

16. Stallings W. (2017), Network Security Essentials: Applications and Standards, 6th ed., Pearson, Boston, 464 p., available at: https://www.pearson.com/en-us/subject-catalog/p/network-security-essentials/P200000003180

17. Cisco Systems. Catalyst 2960 and 2960-S Switches Software Configuration Guide, Cisco IOS Release 15.2(1)E. Cisco, 2013. available at: https://www.cisco.com

18. Odom W. (2024), CCNA 200-301, vol. 1, Official Cert Guide, Cisco Press, 1087 p., available at: https://faspco.com/academy/Ebook/Cisco/CCNA%20200-301%20Official%20Cert%20Guide%20Volume%201%20Second%20Edition.pdf

19. Ylonen T., and Lonvick C. (2006), The Secure Shell (SSH) Protocol Architecture: RFC 4251, IETF, available at: https://www.rfc-editor.org/rfc/rfc4251 DOI: https://doi.org/10.17487/rfc4251

20. Dahm, T., Ota, A., Medway Gash, D.C., Carrel, D., and Grant, L. (2020), RFC 8907: The Terminal Access Controller AccessControl System Plus (TACACS+) Protocol, IETF, Fremont, 66 p., DOI: https://doi.org/10.17487/RFC8907 DOI: https://doi.org/10.17487/RFC8907

Published

2026-09-18

Most read articles by the same author(s)