{"title":"A small LAN Zero Trust network model based on Elastic Stack","authors":"Congwang Kong, Jian Liu, Ming Xian, Huimei Wang","doi":"10.1109/ICMCCE51767.2020.00236","DOIUrl":null,"url":null,"abstract":"Recently, people have changed from using USB and other media to relying on network protocol for data transmission. However, for the sake of security, important confidential units still disable all networks and use USB to transmit files, which wastes a lot of human resources and personnel energy. This paper constructs a small Zero Trust network model based on Elastic Stack, aiming to try to solve the problem of no network availability for important confidential units, and provide a method for solving the hidden danger of leakage. This model uses fingerprint as the user login credentials, and maps all operations to people accurately. Beats components running on the computer can collect and audit information such as user operation records. The information will be sent to Elasticsearch(ES), which will also be monitored by Kibana analysis. Users will be recorded and alerted if they overstep their authority or violate the rules. The security concept and effect of Zero-Trust network are very consistent with the work requirements of important confidential units. This paper proposed that important confidential units should try to build a zero-trust network, and use the network to improve work efficiency while ensuring confidentiality.","PeriodicalId":6712,"journal":{"name":"2020 5th International Conference on Mechanical, Control and Computer Engineering (ICMCCE)","volume":"34 1","pages":"1075-1078"},"PeriodicalIF":0.0000,"publicationDate":"2020-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 5th International Conference on Mechanical, Control and Computer Engineering (ICMCCE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICMCCE51767.2020.00236","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Recently, people have changed from using USB and other media to relying on network protocol for data transmission. However, for the sake of security, important confidential units still disable all networks and use USB to transmit files, which wastes a lot of human resources and personnel energy. This paper constructs a small Zero Trust network model based on Elastic Stack, aiming to try to solve the problem of no network availability for important confidential units, and provide a method for solving the hidden danger of leakage. This model uses fingerprint as the user login credentials, and maps all operations to people accurately. Beats components running on the computer can collect and audit information such as user operation records. The information will be sent to Elasticsearch(ES), which will also be monitored by Kibana analysis. Users will be recorded and alerted if they overstep their authority or violate the rules. The security concept and effect of Zero-Trust network are very consistent with the work requirements of important confidential units. This paper proposed that important confidential units should try to build a zero-trust network, and use the network to improve work efficiency while ensuring confidentiality.