Enterprise security analysis and a solution proposal
Is this your thesis?
This record came from a bulk archive import. If it’s yours, link it to your profile.
Abstract (EN)
Over the past half a century, organizations have implemented information systems for managing their business processes. These information systems have now evolved into as commonly known as enterprise information systems. Computer and Information Security are needed to think in a different way for two circumstances. When personel computers' security is concerned; access to computer and can operate on data on this computer comes to mind. On the other hand, when security of enterprise information system comes to mind, a structure which consist of lots of computers, should be concerned. Enterprise networks, today carry a range of mission critical communications. The sheer number of computers to be connected to each other with local computer network; the presence of other hardwares on it, makes complicate the security of enterprise information systems. Enterprise information security architecture is a key component of information security processes. Organizations amass a great deal of confidential information about their employees and users. Most of this information is now collected, processed and stored in an online warehouses and transmitted across networks to other online devices. Organizations should protect their datas, sources and especially their reputation. When a vulnerability found in system and some confidential datas are leaked by a black hat hackers from this kind of organizations which has respected positions in society like universities, banks and public institutions, is undermine the confidense in these organizations. It will be a massive damage for any organizations who faced with these problems. For instance, when society learns a vulnerability show up in internet banking application, sooner or later it will cause customers cancel their accounts in bank. Or, if a hacker found a vulnerability and theft datas and leaked from the systems an institution like İTÜ, will bring down the reputation of the school and will also undermine the confidense of the school in the eyes of public. Today, there is still no mandatory security policy for universities in Turkey, but it would be unevitable in the coming period. Because, managing the security of enterprise information systems has become a critical issue in this century. Hacktivism and cyber warefares are spreading all over the world. One day, if one of the universities officers computer turns out to be used as a zombie computer for an attack to an organization; it would be a big scandal not only for public citizens, but also for all country. To illustrate of this, it is obviously known that all officers are admin on their computers and some days their children plays games on these computers, especially flash games. And most of these games carried malwares, flash games are the most common one. When user starts and play the game, malware locate itself sneaky in operating system and some of them transform computer as a zombie to use future attacks, some of them taking videos of desktop and stores all key actions of users. In a nutshell, for all these reasons, universities should have standard security policy and they should comply with all specifications, carefully. Security can not be managed, unless it can be measured. The need for metrics is important for assessing the current security status, to develop operational best practices. To develop an organization's security policy, the review should be made and it should be started firstly with the diagnosis of in-house information systems to find metrics. Because of the fact that, there is continuous additions to in-house information systems, tasks and functions of the hardwares can be forgotten in times. Therefore, the positions and functions of all hardwares and softwares should be put forth. After this learning phase, some works about units which will improve of information security and its awareness should be made. In this context, examinations for İTÜ Automation System (a.k.a Student Affairs) have been made and as a result of this examination, it is tried to determine the possible security vulnerabilities and also determined precautions are reported to the manager to prevent from the security problems in the future, in these thesis. It is revealed with basic security questioning and examining the system, whether a vulnerability exist or not. Besides, security performance measurement by using standardized metrics gained increasingly interest during the last years with the help of guidelines, code of practices and standards accepted widely over the world. Therefore, the policy of ISO 27001 and instructions of 27002 are used to determine precautions and standards. By preparing these a policy for university, it is aimed to be as possible as protected from the external attack. All organizations need to build an information security architecture to keep secure their systems and all organizations should keep in their mind that information security policy is not an option instead it is an obligation in this era. Those described above are mentioned about problems which are caused by external users, but there can be problems arising from internal users as it is known as the general characteristics of the information security system. The aim of this thesis is to reveal the security disruptive behavior will arise because of both internal and external users. Therefore, in second phase extremely sensitive situations like student Grade Entrance, Grade Correction and Graduation Status Controls are investigated for Automation System. The existence of students who don't deserve their notes in lightest form and in the graduation of the students even did not record in school with the most severe form of result the ignoring such cases. Because of not experienced these kind of problems don't mean it will never be, studies are conducted in order to minimize problems that may arise in future. A system is recommended to make more secure of Grade Entrance, Correction and Graduation Status Control. According to the recommended system, while teaching staff will enter notes, they'll make it on a desktop application which is not connected to internet. After that, the application create note document as EVA or XML format and both they will store original documents in application and send a copy to the database of own Faculty. Finally, Faculty will share the document with encrypted connection with Student Affairs' database. Besides, that Grade Correction is carried out with decision correspondence document. Hence faculty member who made the grade correction sends grade documents to the faculty as EVA or XML format. Faculty, store grade correction correspondense its related database firstly, then stores grade document to its related database. Finally, faculty sends both documents to Student Affairs through secure connection line established between two sides to be stored also in there. Securiy Affairs stores those documents to related databases to be an evidence for future. Grade documents will be stored in grade databases and correction correspondence document will be stored in correspondense databases; so there will be two databases in there, too. In the case of a student's graduation, both Faculty database and Automation database will cross-check with each other, and if both results are same then "student can graduate" information will be send to Student Affairs. Otherwise, they will be informed with a message which carries "student can't graduate. Results do not match." Right after, an investigation will be started to understand the reason of different grade results. Storing Grade Correction Correspondece document as an electronic format in both Faculty database and Automation database, makes any investigation easier. In final stage, a decision support software developed. It works with log files which have taken from Student Affairs Department and it aims to investigate insider threat in Automation System. Coverage of this work may be one of the following: it can be a student who sell lessons in a black market or it can be lecturer who abuse system with his/her powers, even it can be a Student Affairs' officer who change students' grade exchange with money. Some metric rules are needed to be created to develope a decision support machine software. In this stage software aims to find authenticated user who abused the Automation's system. The thesis consists of five main sections: first of all it begins with Introduction Section that aims to express main details of studied subject and its environmental factors. Next Section dwell on Enterprise Information Security Concept and expresses it in some detail based on known standards which are specified by Standardization Organizations like SANS, ISO etc. In Section Three an investigation made to find vulnerability in system. A questionare is prepared for Student Affairs officers and according to their answers actions are taken and possible vulnerabilities are determined. After that based on possible vulnerability points, counter measures are spesified to build more secure system. Counter measures are prepared as suggestions list and it is delivered, right after that. In Fourth Section authorized users behaviours investigated from logs and tried to create characterization for each classes according to metric rules. In this work, it is aimed to find improper actions and abusements has been acted by authorized users. Thus, results which ensued from possible improper action, are examined and another list prepared to examine whether there is an bad action had been made by users. Decision Support Software creates lists according to log files from Automation System to ensue those improper action. The software is delivered to İTÜ Automation System to be used. Eventually, Final Section is consist of conclusions and recommendations. Besides of all conclusions about above sections, this section includes recommended system to make more secure Grade Entrance, Correction and Student Graduation stages. Also why recommended system is more secure than the current one is explained in details.
Author
Ayşe Bilge Gündüz
Institution
How to Cite
Ayşe Bilge Gündüz (Master Thesis). Enterprise security analysis and a solution proposal, 2016, İstanbul Technical University.
Keywords
License
Tüm Hakları Saklıdır
This work is shared under the specified license terms.
More theses from İstanbul Technical University
- Removal and recovery of platinum group metals through anode slimes of moebius electrolysis(2015)
- Investigation Of Stretching Effect With Mixed Finite Element Formulations For Laminated Beams And Plates(2023)
- Fire safety measures in subways(2015)
- Gold and silver recovery from primary and secondary sources with different processes(2015)
- Fun palace as a laboratory of action/fun: Extensions and reflections of spatial experience(2015)
- İnce cidarlı kompozit kiriş olarak modellenmiş uyarlanabilir uçak kanatlarının dinamik analizi(2015)