隨著資訊科技的進步,企業皆利用資訊技術來處理許多業務,然而卻導致有心人士利用資訊技術弱點來竊取機敏資料,其中「USB病毒」就是最近相當熱門的資訊安全議題之一。 本論文目的在針對內部員工有意或無意疏失使用「USB移動式儲存媒體」,諸如:記憶卡、拇指碟、移動式儲存硬碟等,複製企業內部機敏資料進行交換時,導致資料洩漏造成企業嚴重損失等原因,提出一套制度與方法,在有限度的管控範圍內,合法地使用該裝備,並阻絕有意或無意的竊取資料,產生監控稽核機制嚇阻潛藏人員違法使用,增加企業安全能力。 故本研究利用開發之「USB儲存裝置管控系統」,實際架設於企業內執行,並搭配中央防毒系統及入侵偵測系統事件記錄交叉比對是否降低內部資安風險。其實驗結果發現,在執行三個月的過程中,病毒事件及入侵事件皆有降低,能有效幫助管理者即時處置內部風險,取代從以往「被動式」防禦轉向為「主動式」發覺,提昇企業整體資訊安全。
Nowadays, almost enterprises utilize technological tools to process their business because of the improvement of information technology. However, some people steal confidential data from the drawback of technological skills. For example, “USB (Universal Serial Bus) virus” is one of most prominent information security issues. The object of our research focuses on monitor and audit internal employee’s intended or unintended use “USB portable storages” such as memory card and portable hard disk. When a worker uses a portable storage to copy the internal data from his or her business and try to sell it, it would lead to information divulgence and destroy the enterprise seriously. As a result, we offer a new method and system which only allows employees legal to use USB portable storages in a limited control range. It does not only avoid employee’s intended or unintended to copy data; but also builds up the audit rule to control staff use USB portable storages illegally and even improve the security ability of an enterprise. All in all, our research had developed the USB portable storages control system and used in the real case for practical implementation. We also compared system event records of IDS and central anti-virus system. The result is revealed that anti-virus and IDS have been decreased in last three months. In addition, the role of protecting business security is from passive fixer tends to interactive preventer. It can also assist managers to process a business internal and improves the entire enterprise information security.