错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Critical Server Security Protection Strategy Based on Traffic Log Analysis

  • Haiyong Zhu,
  • Chengyu Wang,
  • Bingnan Hou,
  • Yonghao Tang,
  • Zhiping Cai

摘要

Traditional perimeter-based security systems provide a level of defense against external attacks. However, with the increasing prevalence of advanced network attacks and the continual emergence of novel attack methodologies, these conventional security mechanisms are witnessing diminishing effectiveness. Attackers frequently shift their focus to the core assets within an organization’s internal network, such as database servers, file servers, and email servers. By breaching the external perimeter, they execute lateral movement within the internal network, searching for high-value assets to achieve the goal of data theft. The potential consequences stemming from an assault on core assets can be monumental, underscoring the paramount importance of safeguarding them. Nevertheless, existing measures for the protection of critical core assets exhibit several deficiencies. In response, we propose a security protection strategy for critical servers based on the analysis of traffic logs. We establish an integrated micro-boundary on the critical servers, comprising four constituent modules. A micro-boundary intrusion detection system (IDS) module, a micro-boundary traffic collection module, a micro-boundary dynamic access control module, and an agent module. This security protection strategy encompasses three core security functionalities. Network intrusion detection, network access relationship analysis, and dynamic management of access control policy. It facilitates timely and effective detection of internal threats, significantly bolstering the security of critical servers. We have implemented this security protection strategy in two real-world scenarios, assessed the feasibility of its implementation, and uncovered potential security vulnerabilities and network threats.