當今企業對網路應用的依賴日漸增加,網路安全早已成為企業基礎建設裡不可或缺的一個環節。而隨著資訊系統的複雜度的增加,作業系統或網路系統的漏洞也隨之不斷增多;網際網路的高度運用,無法避免的衍生資訊的大量暴露,上網的人數迭創高峰,非法使用者或惡意行為者也隨之大幅成長;資訊技術不斷提昇之際,而駭客的手法也在不斷翻新,各種病毒攻擊事件亦時有所聞。 這麼多屢見不鮮的網路安全問題並不全然因為駭客具有高深的技術,諷刺地來說,若是沒有使用者的大意與漠視網路安全,駭客或電腦病毒的攻擊不是那麼容易得逞的。當今企業內的資訊安全管理人員面臨了空前的挑戰,他們不但要肩負一般例行性任務,更必須一手挑起維護企業網路安全的重任。然而隨著企業購置越來越多的網路安全解決方案來保護他們的資產,從基本的防火牆、入侵偵測系統,一直到弱點評估、防毒系統、垃圾郵件過濾系統等,這些設備所產生的資料量已經達到驚人的地步且複雜度日益增加。而這些資安產品發展的複雜性,卻大大的增加了管理上的困難度。 因此本論文研究的重點,就是在探討企業如何自行規劃建置資訊安全監控中心,以簡單且集中化的管理,可以迅速掌握公司整體的資安現況,部署新的資安策略,做到快速反應以防止病毒疫情的擴散或爆發;而資訊安全監控中心的報表服務系統,除了可以節省管理上的人力和時間外,更能提供管理人員或高層主管過去的事件統計,以作為決策的參考依據。
Along with the increasing demand for networking in enterprises, network security has become an essential part of the enterprise foundation. While the complexity of the information system rises, security holes in the operating system or networking system are also getting much more than ever. Following the high utilization of Internet, it is also hard to avoid the information exposure. Moreover, hackers and malicious activities grow with a tremendous rate, and has resulted in the frequently report of virus attack. Ironically, most of the network security issues are not from the advance technology or skillful hackers; instead, thoughtless users and ignorance of the importance of network security are both responsible for these security issues. Due to the fact above, information management department faces the challenge to guard against the malicious activities on the top of the daily routine tasks. However, there are more and more hardware and software combination coming from the rapid growing number of network security solutions, including the basic firewall, intrusion detection system, vulnerability assessment, anti-virus system, and spam filtering system. In the event, the quantity and complexity from the solutions reach an amazing extent and it does not seem to stop anywhere today. As a result, it made the life much more difficult in terms of management and also become an expensive cost for the enterprise. This thesis tries to solve the problem by studying to implement Mini-Security Operation Center for Enterprise. By the simple and centric administration, information management department could monitor the status in the enterprise in terms of network security anytime, deploy a new network security policy in no time, and avoid the infection or outbreak of viruses at the early stage. In addition, the reporting service system of Mini-SOC not only saves the human resource and invaluable time, it also is vital statistic data as a reference for the essential strategic decision.