本研究實作“校園網路資安主動聯防系統(CISPDS)”之偵測、阻擋與告警機制。本研究延續基於威脅情資與校園網路流量之智慧型資安聯防系統建置計畫,持續整合外部威脅情資、防火牆、入侵偵測系統、DNS與NetFlow進行分析,開發流量異常、攻擊或惡意攻擊之偵測、封鎖及告警機制。可偵測並封鎖大規模與大範圍掃描或攻擊、DDoS攻擊,偵測與阻擋惡意網域連線、封鎖異常流量等,並自動告警與通報相關資訊,供使用單位與維運人員處理。再藉由偵測之結果轉化為內部情資並收斂情資內容,使情資更為精準,運用於資安設備可有效減輕設備之負擔。
This study expands functions of the 〞Campus Information Security Proactive Defense System,〞 adding malicious domain detection/blocking, malicious traffic analysis and alarm mechanism. This study continues the project of 〞Building of Campus Information Security Proactive Defense System based on Threat Intelligence and Network Traffic,〞 continuously integrating external threats, firewall logs, intrusion detection system logs, DNS and NetFlow for analysis, and developing detection/blocking/alerting mechanisms for abnormal traffic, attacks, or malicious attacks. It can detect and block large-scale and wide-range scanning or attacks, DDoS attacks, detect and block malicious domain connections, block abnormal traffic, etc., and automatically alert and notify relevant information for the users and administrator. Then, the result of the detection turns into internal intelligence, which makes it more precise, and apply to the security equipment can effectively reduce the burden on the equipment.