Nagasaki University has recently launched an incident detection system using flow information to strengthen the information security of the campus-wide information network. Flow information from network devices including L2 switches at the network edge enables detailed monitoring and analysis of communications closed to inner networks or private IP address spaces, while traditional perimeter defense systems perform monitoring and analysis of communications passing through the boundaries between the internet and inner networks. In this paper, after a brief overview of the university's campus network, the necessity, effectiveness, and issues of the flow-based incident detection system in university networks are investigated based on the experiences in implementation and operation of the system.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Operation and Evaluation of Flow Information-Based Incident Detection System in Campus Network

  • Daisuke Yagyu,
  • Yoshifumi Ueshige,
  • Masato Tsuru

摘要

Nagasaki University has recently launched an incident detection system using flow information to strengthen the information security of the campus-wide information network. Flow information from network devices including L2 switches at the network edge enables detailed monitoring and analysis of communications closed to inner networks or private IP address spaces, while traditional perimeter defense systems perform monitoring and analysis of communications passing through the boundaries between the internet and inner networks. In this paper, after a brief overview of the university's campus network, the necessity, effectiveness, and issues of the flow-based incident detection system in university networks are investigated based on the experiences in implementation and operation of the system.