Secure Campus Network System with Automatic Isolation of High Security Risk Device

Kazuhiro Mishima,Takeshi Sakurada,Yoichi Hagiwara,Takahiko Tsujisawa
DOI: https://doi.org/10.1145/3235715.3235738
2018-09-11
Abstract:In recent years, there are many problems of network security such data breaches and unauthorized access due to targeted attacks on vulnerabilities. The campus network in a university is under various threats as well as corporate networks. In addition, many universities including the Tokyo University of Agriculture and Technology (TUAT) have taken Bring Your Own Device (BYOD), and the number and types of devices connected to our campus network are increasing. Since a campus network is used for wide range of education and research, there are many more types of connected devices than corporate network. Until now, we tried to reduce the security risk for our campus network by using the quarantine / authentication system, but it is not a sufficient system because some users bypass the quarantine using the system's loophole. Therefore, we designed a campus network security system based on automatic shutdown with network monitoring for brand-new security measures of our campus network. In our system, network traffic is monitored on the campus network side (e.g. core switch, edge switch), and a device considered as high security risk is automatically isolated from the campus network on the edge switch. A dedicated portal is also provided for presenting the reason for isolating to the user. This can make it possible to effectively implement high levels of security measures while reducing the management cost for an operation and a user support as much as possible. In this presentation, we introduce details of the design and actual architecture of our system.
What problem does this paper attempt to address?