Solution of unified security man的為agement and operation and maintenanc區區e audit in Colleges and Universities
Industry pain points and needs

With the gradual deepening of camp她火us digitization and information constr機森uction, the integration of various in飛化formation resources on campus has e視農ntered the stage of comprehensiv國們e planning and implementation, such as 西計campus one card in combination with th知人e ongoing construction of identity au算資thentication, personnel, student and雪為 engineering MIS and applicati討和on systems. Through the common 舊章identity authentication mechanis車費m, realize the integration and 線訊sharing of data management, and make t影我he Campus All-in-one Card system a化美n organic part of campus information c日件onstruction. Through this organic combi多關nation, it lays a foundation for resour務要ce sharing among systems.

The high concentration of informatio暗件n makes the security of data mo門業re and more valued. As an education 秒筆industry related to the rise and 化上fall of the country, once the data is l放畫eaked, it will have a negative impact 自妹on the society and become a ho船雪t issue concerned by public opini藍拿on and the media. Driven by the huge c國藍ommercial interests, the databa你筆se of the education industry ha如村s to face the double folder of inte我放rnal and external threats, especia子舊lly the illegal "invasion" for the p去很urpose of business, which not only是飛 has a serious impact on the publi人讀c image and authority trust of 白還the school, but also divulges pers雪下onal information, damages the perso他山nal interests of students, and 她光adds disharmony to the cause of edu明知cation.


Combined with the current secur他你ity situation faced by the informa裡得tization development of colleges a愛得nd universities, there are mainly秒器 the following risks in operation and m我技aintenance management:  是海


1. Management status: the IT system sup南現porting the operation of the universi舞黃ty industry is mainly composed of a lar城區ge number of network equipment, 花低host system and application sys錯技tem. These equipment and systems b新民elong to different departments from the唱外 perspective of application. The 離還network equipment and host system h購話ave independent user management書也, authentication and authorization房熱 and audit systems respectively, Diff民亮erent system administrators are respo熱章nsible for the maintenance and manage那舊ment. When facing these systems, t音聽he work of maintenance personn為來el is very complex;


2. Unclear authorization: in this u章行niversity industry system, the prin如腦ciple of user minimum authority allo答農cation in the best practice of 你暗it operation and maintenance cannot be老土 strictly implemented due to the sepa道農rate authorization of each system如影. At the same time, with the increas光頻e of business systems and users拍就, the user authorization management be女內comes quite complex and the system 民有security is threatened;


3. Hidden dangers of shared accounts: 在司in order to reduce the complexit自算y and difficulty of management, some a姐睡ccounts are shared by multiple p快購eople, the proliferation of these ac紙謝counts is not easy to control, an商林d security accidents often occur due to校舊 such account sharing;


4. Hidden danger of simple passwo黑術rd: for maintenance personnel, frequent都讀 system switching requires enterin白姐g user names and passwords of different得呢 systems for login. In order to facil小呢itate memory, maintenance personnel票資 often use relatively simple passwo年說rds or multiple systems use the sam對熱e password. In case of emergency, they了匠 may also share their user name雜爸s and passwords with others, These 答很all pose a great threat to the security公冷 of the whole system;


5. Lack of centralized log aud年報it: due to the independent oper術亮ation of each system, the system ope地行ration log and operation audit o吧懂f maintenance personnel can only be ca友到rried out independently by system. I信麗n case of system failure, the problem刀從s must be investigated system b微謝y system, and unified and central但件ized problem investigation cannot報好 be carried out, which greatly reduces區到 the work efficiency and leads to th少麗e possibility of loss expansion.


Our programme


As the most advanced, core and comprehe吧些nsive technology trend of intranet 劇說security, fortress machine technolog玩通y provides the most core monitoring an火討d protection for the core server, d市子atabase, switch and other equipment 中答resources of University Informat哥店ion Center.


Centralized account management


Improve the management effective但區ness and establish a new user syst亮草em to completely replace the us很數er system independently manage答了d by the original systems. The front-化商end users directly correspond to th車秒e maintenance personnel and th看個e back-end users directly correspond家校 to the original system users, pro如線viding a centralized real name user能時 management mechanism. Through the uni如媽fied user information maintena大劇nce portal, ensure the uniquenes大友s and synchronous update of user 友厭account information of each syste體近m;  


Centralized authentication and a筆近ccess control


Improve the operation and mainte通高nance security centralized authenticat影快ion, realize the centralization 西從and unification of the authenti喝離cation entrance for users to acc兵些ess the information system, and ado紙技pt high-intensity authentication mode 國算to make the login and authenti如還cation behavior of the whole inform劇他ation system controllable and man林花ageable, so as to improve busin舞場ess continuity and system secu友慢rity. Centralized access control pro湖筆vides unified system and equipme如白nt access for maintenance personnel, pr場麗ovides access control function, eff刀森ectively solves the operation p一很roblems of operation and maintenanc雪地e personnel, and reduces the s現的ecurity risks of relevant info她男rmation systems;


Centralized operation audit

Improve the traceability and positio相作ning ability, and be able to captur開行e the user operation data flow dynamic街但ally and in real time. The centra化明lized audit module logically reor數著ganizes the audited data packets, 笑白restores and restores the user's remo答外te access operation process, and a吧冷utomatically records it in ses長做sion mode; The log audit center provid街麗es a powerful search engine to ena腦做ble users to query time, login addr他工ess, host address, host account, user o照大peration commands and other rich quer媽拍y conditions, quickly locate the日懂 session log that meets the monitori妹好ng rules and restore the operat區都ion site. Centralized authorizati國上on provides unified information sys文現tem authorization management, stan錢輛dardizes the authorization of a兵做ll managed information resources,大物 and fine permission allocation str風子ategy ensures that administrator秒醫s can grant appropriate permis坐師sions to different users, which confor謝冷ms to the principle of minimum permis熱媽sion allocation to the greatest 很物extent, and protects the security of 員湖information support system resources白知 to a great extent. Centralized sec民就urity audit provides centralized 林離log audit, which can correlate use刀拿r's operation behavior, quickly disc煙紅over, analyze, locate and respond to 得大illegal login and illegal operation, 問海and provide basis for security好站 audit and tracking.


Deployment mode

Program advantages


Mature and stable


After more than ten years of market ver舞關ification and technology accumulatio飛民n, a large number of successful cases 房筆have been deployed in complex applica坐木tion production environment, and ther女哥e are many cases in the education聽月 industry, including famous un文飛iversities such as Shanghai Jiaoton短水g University, Shanghai Univers短兵ity of Finance and economics, Wuhan物報 University, Huazhong University of sci風科ence and technology, Xi'an Jiaoto舊樹ng University and so on.


Safe and reliable


At the same time, two sets of unifie用玩d operation and maintenance platforms w海行ith independent applications and comple現慢te functions are provided. The de西生vice HA can achieve real-time synchro路空nization of configuration and audit l小上og;


Strong adaptability to network env可報ironment, realize green deployment,體樂 do not change the original network top哥小ology, support cluster deployment and 上放cross network segment deployment;


The system development and update sha坐日ll follow the safety software developme吧錯nt life cycle process to realize vers件區ion management, and each iterative up他見grade shall ensure that the best 東笑practices are met.


modern techniques


Support local authentication, ad domai一我n authentication, radius authentication物見, fingerprint authentication, wechat 裡筆authentication, SMS authenticatio國少n, etc., with the most complete ident數要ity authentication methods in the 購間industry;


The system login strategy of us開公ers can be set, including limiti空黑ng login IP, login time period兒間, port, account, etc., to ensure that 船黑new users can access the background re熱做sources they have permissions 我理and realize controllable operation 能樹and maintenance;


Support the alarm and blocking of 自快high-risk commands, and effect聽紅ively control the risks caused by 訊謝misoperation and high-risk operatio些日n in operation and maintenance;


Unified management of in band and o雜懂ut of band operation and maintenance小線, the only mainstream KVM over IP prod鐘會ucts in the industry that simu離廠ltaneously support Avocent, Raritan, at會她en, etc;


The original database operation and mai問相ntenance audit platform covers mai頻線nstream commercial database enterpris家樂e applications and operation and m討生aintenance operations.


Customer Benefits


1. Realize core data assets, virt綠山ualization equipment, scientifi錢唱c research system and data, netwo船說rk center assets including busin拿家ess support system, business delivery北資 system, campus "all-in-one ca司資rd", intranet core network equi為外pment, host equipment and databas吧不e assets, and realize account number,時說 authentication and Centralized知海 control and management of authorizatio你們n and audit.

2.

Realize centralized identity a亮歌uthentication and access portal,事明 realize centralized access authorizati吃唱on, access control and role authorizati光拿on management based on centralized co姐妹ntrol security policy, and ensu外下re that various business deliver去做y systems in the network center pro錢上vide 7x24 hours of uninterrupt開現ed operation and maintenance.


Classic cases
  • 上海交通(tōng)大學
  • 華中科技大學
  • 西安電子(zǐ)科技大學
  • 上海音樂(yuè)學院
  • 西安外國語大學
  • 武漢大學
  • 北京工業(yè)大學
  • 上海财經大學
  • 上海金融學院
  • 中北大學
Copyright © 2019 All Rights Res中器erved Designed
Hangzhou pldsec Network Technology站資 Co