上海交通大学自动隔离高效安全措施系统第一年的实际运行效果

Kazuhiro Mishima, Takahiro Nemoto, Yoichi Hagiwara, T. Tsujisawa
{"title":"上海交通大学自动隔离高效安全措施系统第一年的实际运行效果","authors":"Kazuhiro Mishima, Takahiro Nemoto, Yoichi Hagiwara, T. Tsujisawa","doi":"10.1145/3347709.3347809","DOIUrl":null,"url":null,"abstract":"To reinforce a security measure on our campus network, we implemented a brand-new style of secure campus network system in 2017. The variety of the device in campus network is more complicated. The existence of various devices also increases the possibility of security incidents. In Tokyo University of Agriculture and Technology (TUAT), since Bring Your Own Device (BYOD) was started from 2016, the types of devices connected to our campus network is increased. Therefore, as a security measure, we designed and implemented a campus network security system based on automatic isolation. In our system, network traffic is monitored on the campus network side (e.g. core switch, edge switch), and a device considered as high security risk is automatically isolated from the campus network on the edge switch. In our system, it is possible not only to perform shutdown automatically but also to automatically perform recovery processing by end-user, and reduce operational cost. After more than a year since the operation began, we clarified the actual operation conditions of our system. In this paper, we introduce the overview of our system, and summarize the operational situation from the start of operation. This makes it possible to overview the appearance of our actual system and the situation of security incident status at the Japanese National University in the science area. By considering the results of our system, we will also help to think about security measures in university environment.","PeriodicalId":130111,"journal":{"name":"Proceedings of the 2019 ACM SIGUCCS Annual Conference","volume":"5 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-10-26","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"First Year’s Actual Operational Results of Efficient Security Measure System with Automatic Isolation in TUAT\",\"authors\":\"Kazuhiro Mishima, Takahiro Nemoto, Yoichi Hagiwara, T. Tsujisawa\",\"doi\":\"10.1145/3347709.3347809\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"To reinforce a security measure on our campus network, we implemented a brand-new style of secure campus network system in 2017. The variety of the device in campus network is more complicated. The existence of various devices also increases the possibility of security incidents. In Tokyo University of Agriculture and Technology (TUAT), since Bring Your Own Device (BYOD) was started from 2016, the types of devices connected to our campus network is increased. Therefore, as a security measure, we designed and implemented a campus network security system based on automatic isolation. In our system, network traffic is monitored on the campus network side (e.g. core switch, edge switch), and a device considered as high security risk is automatically isolated from the campus network on the edge switch. In our system, it is possible not only to perform shutdown automatically but also to automatically perform recovery processing by end-user, and reduce operational cost. After more than a year since the operation began, we clarified the actual operation conditions of our system. In this paper, we introduce the overview of our system, and summarize the operational situation from the start of operation. This makes it possible to overview the appearance of our actual system and the situation of security incident status at the Japanese National University in the science area. By considering the results of our system, we will also help to think about security measures in university environment.\",\"PeriodicalId\":130111,\"journal\":{\"name\":\"Proceedings of the 2019 ACM SIGUCCS Annual Conference\",\"volume\":\"5 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2019-10-26\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings of the 2019 ACM SIGUCCS Annual Conference\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/3347709.3347809\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 2019 ACM SIGUCCS Annual Conference","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3347709.3347809","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

摘要

为了加强校园网的安全措施,我们在2017年实施了一种全新的安全校园网系统。校园网中设备的种类更加复杂。各种设备的存在也增加了安全事故发生的可能性。在东京农业技术大学(TUAT),自2016年开始实施自带设备(BYOD)以来,连接到我们校园网的设备类型增加了。因此,作为一种安全措施,我们设计并实现了一种基于自动隔离的校园网安全系统。在我们的系统中,对校园网侧(如核心交换机、边缘交换机)的网络流量进行监控,并在边缘交换机上自动将安全风险较高的设备与校园网隔离。在我们的系统中,不仅可以自动关闭,还可以由最终用户自动执行恢复处理,从而降低运营成本。经过一年多的运行,我们明确了系统的实际运行情况。本文介绍了本系统的总体情况,总结了系统运行以来的运行情况。这样就可以概览我国实际系统的面貌和日本国立大学科学领域的安全事件现状。通过考虑我们系统的结果,我们也将有助于思考大学环境中的安全措施。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
First Year’s Actual Operational Results of Efficient Security Measure System with Automatic Isolation in TUAT
To reinforce a security measure on our campus network, we implemented a brand-new style of secure campus network system in 2017. The variety of the device in campus network is more complicated. The existence of various devices also increases the possibility of security incidents. In Tokyo University of Agriculture and Technology (TUAT), since Bring Your Own Device (BYOD) was started from 2016, the types of devices connected to our campus network is increased. Therefore, as a security measure, we designed and implemented a campus network security system based on automatic isolation. In our system, network traffic is monitored on the campus network side (e.g. core switch, edge switch), and a device considered as high security risk is automatically isolated from the campus network on the edge switch. In our system, it is possible not only to perform shutdown automatically but also to automatically perform recovery processing by end-user, and reduce operational cost. After more than a year since the operation began, we clarified the actual operation conditions of our system. In this paper, we introduce the overview of our system, and summarize the operational situation from the start of operation. This makes it possible to overview the appearance of our actual system and the situation of security incident status at the Japanese National University in the science area. By considering the results of our system, we will also help to think about security measures in university environment.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信