Security starts from internal management
■ Zhuang Jiaxiang
The security problems faced by enterprise networks can be summarized into the following aspects: unauthorized access by internal employees, illegal intrusion by external hackers, and the proliferation of Network viruses. To deal with these increasingly severe security threats, it is important to deploy comprehensive security solutions, and implementing comprehensive security management within the enterprise is even more indispensable.
Formulating targeted security planning is the key to implementing internal management. According to the enterprise's expectations for security, the IT Director needs to combine the management architecture with the security system to develop a set of targeted security plans. When formulating security plans, enterprises should clarify the following: what are the current threats facing the enterprise network? Which network resources need to be protected? What security level does the network resource to be protected need to reach?
Next, the IT supervisor needs to refine the security system, define the Internet access mode, restrict access behavior of enterprise employees, and manage all behavior of employees that affect network security. The enterprise security system should clearly define the following content: employees who can use the system, time periods for employees to use the system, employees' permission to use the system, and authorization procedures for system access; revocation program of system access rights (when an employee leaves office); system usage; remote and local logon; all passwords set by the developer are modified; use a password that is not easy to guess (the password must contain at least eight characters, especially special characters, and both cases are used); rotate the password regularly; perform regular virus checks on all systems; regularly send security briefings on security threats, security policies, and remedial measures; Regularly back up all sensitive data; educate employees to use specific identification processes to check suspicious emails.
After specifying the protection object and the required security level, enterprise users need to build a security system based on security devices. The specific approach is to classify the enterprise network by department or security level. Through a vswitch with VLAN (Virtual LAN) function, similar physically dispersed devices are combined in the same virtual network, and access between different network segments is restricted through routers and firewalls. VLAN technology actually transforms the broadcast mechanism into a point-to-point communication mechanism, so that information only arrives at the desired location, which can prevent most network listening behaviors.
VLANs can be divided according to the system security. For example, you can separate the servers at the enterprise headquarters to form a VLAN for the database server and email server. You can also divide the VLAN based on the organization's functions, the network of the key department is used as a VLAN, and other departments are used as another VLAN. Users in the same VLAN are connected through vswitches, and vrouters are used to connect VLANs. To ensure one-way information flow between VLANs, that is, allows the VLAN where key departments are located to view information about other VLANs. Other VLANs cannot access the information about the VLAN where key departments are located, enterprise users need to set firewalls between key VLANs and other VLANs as security isolation devices to control information exchange.
Users need to pay attention to the fact that VLAN technology has also brought about new security problems. For example, devices that execute virtual network switching become more and more complex and become attacked objects; network broadcast-based intrusion detection technology requires special settings in high-speed switching networks. MAC-based VLAN cannot prevent MAC spoofing attacks. To address the preceding security risks, it is recommended that enterprise users divide VLAN Based on switch ports.