Go to Main Contents

Access security and traffic detection

Identification of cross-border access leads and development of alerts and traceability

NATSHEL_CROSS_BORDER_TRAFFIC is capable of collecting visible traffic by side, and in combination with multiple identification methods, discovers cross-border VPN, proxy, offshore IP and unusual outreach leads to provide the basis for statistics, records, warnings and follow-up disposal.

:: Capacity chain

The detection system is for visualization and analysis, the implementation equipment is for disposal.

(c) Delineate detection, recording, warning, traceability and interdiction to avoid mixing the responsibilities of different components.

01

Sideways capture and recognition

Receive mirror traffic on the network core or by exit, combining DPI, flow statistics, VPN/ agency protocol features and off-shore IP information identification access clues.

02

Statistics and scenario analysis

The network managers are assisted in understanding the conduct of visits by means of statistics and drilling at dimensions such as source IP, purpose IP, domain name, application protocol etc.

03

Recording, warning and traceability

The formation of session records and alerts; where the certification log is relevant, it can further assist in matching network behaviour to account or user.

04

Equipment connection disposal

Tests systems to export clues or strategies, and stops, limits flow or isolates by route, firewall or other implementing equipment.

:: Conditions of deployment

We need to confirm before we start the assessment.

  • Whether core or export provides the required mirror flow
  • Test systems can see export, network and application flows.
  • Whether there is a certified or session log for account association
  • Alerts need to be delivered through company micromail, nails, mailboxes or something.
  • If blocked, whether the on-site route, firewall or security equipment supports connection

:: Applied scene

Redeployment when clear monitoring requirements are in place

  • Cross-border access trail monitoring and traceability of universities ' exports
  • Analysis of unusual outreach and cross-border visits to business parks
  • Related traffic statistics, records and alerts for the operation of networks
  • Items that need to link the results to the certification log

• Application conditions

Key capabilities matched the actual network environment

The capacity, identification effects, the range of application banks, the duration and compatibility of disposal are determined by combining model, version, link and test conditions.

Identification criteria

Encryption, confusion, unknown protocols and traffic visibility can affect the identification effect, which is recommended to be validated in conjunction with actual export flows.

Disposition

The by-pass detection system focuses on discovery and warning; if a disruption is required, it should be accompanied by route routes, firewalls or other implementing equipment, and interfaces and strategies validated.

Identity association

Links access to an account or person require the full validity of the authentication log, session log, time synchronization and field association conditions.

Compliance requirements

Testing, recording and reporting can provide a basis for network management, and the scope of construction still needs to be determined in conjunction with regulatory requirements at project sites.

Project judgement

Export bandwidth, mirror conditions, log source and disposal target provided first

Re-judge the location of the detection system deployment, required storage, warning methods and connection to the implementation equipment.

Obtaining preliminary judgement
Access Program I'll be right back. Telephone counselling