Niki ukeneye kumenya kubyerekeye umutekano wurusobe?

Umuyoboro wumuyoboroibikoresho bitunganya traffic traffic kugirango ibindi bikoresho byo gukurikirana, nkibyahariwe kugenzura imikorere ya Network no kugenzura bijyanye n’umutekano, bishobora gukora neza. Ibiranga gushiramo paki gushungura kugirango umenye urwego rwibyago, imizigo yipaki, hamwe nibyuma bishingiye kumashanyarazi.

Umutekano w'urusobe

Umuyoboro wumutekano wububikobivuga urutonde rwinshingano zijyanye nubwubatsi bwumutekano wububiko, ubwubatsi bwumutekano wububiko, hamwe nububiko bwumutekano. Ukurikije ingano yumuryango, hashobora kubaho umunyamuryango umwe ushinzwe buri domeni. Ubundi, ishyirahamwe rishobora guhitamo umuyobozi. Ibyo ari byo byose, amashyirahamwe akeneye gusobanura uwabishinzwe kandi akabaha imbaraga zo gufata ibyemezo bikomeye.

Isuzuma ry'urusobe ni urutonde rwuzuye rw'uburyo ibitero byimbere cyangwa byo hanze byangiza cyangwa bitayoborwa bishobora gukoreshwa muguhuza umutungo. Isuzuma ryuzuye ryemerera umuryango gusobanura ingaruka no kuzigabanya binyuze mu kugenzura umutekano. Izi ngaruka zishobora kubamo:

- understanding Gusobanukirwa bidahagije kuri sisitemu cyangwa inzira

-  Sisitemu igoye gupima urwego rwibyago

-  "Hybrid" sisitemu ihura nubucuruzi nubuhanga

Gutegura igereranyo cyiza bisaba ubufatanye hagati ya IT nabafatanyabikorwa mubucuruzi kugirango bumve urugero rwibyago. Gukorera hamwe no gukora inzira yo gusobanukirwa ishusho yagutse yingaruka ningirakamaro nkibyanyuma byashyizweho.

Zero Yubaka Ubwubatsi (ZTA)ni umuyoboro wumutekano wumutekano wibwira ko abashyitsi bamwe kuri neti ari akaga kandi ko hari ahantu henshi ho kwinjira kugirango harindwe byimazeyo. Kubwibyo, kurinda neza umutungo uri kumurongo aho kuba umuyoboro ubwawo. Nkuko bifitanye isano nuyikoresha, umukozi ahitamo niba yemeza buri cyifuzo gisabwa hashingiwe ku mwirondoro w’ibyago wabazwe ushingiye ku guhuza ibintu bifatika nko gusaba, ahantu, umukoresha, igikoresho, igihe, igihe cyo kumva amakuru, n'ibindi. Nkuko izina ribivuga, ZTA nubwubatsi, ntabwo ari ibicuruzwa. Ntushobora kuyigura, ariko urashobora kuyiteza imbere ukurikije bimwe mubintu bya tekiniki birimo.

umutekano w'urusobe

Firewallni ibicuruzwa bikuze kandi bizwi cyane byumutekano hamwe nuruhererekane rwibintu byagenewe kubuza kwinjira mu buryo butaziguye porogaramu yakiriwe na seriveri. Imiyoboro yumurongo itanga ihinduka ryimiyoboro yimbere hamwe nigicu. Ku gicu, hariho ibicu-bishingiye ku bicu, kimwe nuburyo bwoherejwe nabatanga IaaS kugirango bashyire mubikorwa bimwe mubushobozi bumwe.

Irembo rya Securewebbyahindutse bivuye mugutezimbere umurongo wa interineti kugeza kurinda abakoresha ibitero bibi kuri enterineti. Akayunguruzo ka URL, anti-virusi, gushishoza no kugenzura imbuga za interineti zinjira kuri HTTPS, gukumira amakuru (DLP), hamwe n’uburyo buke bw’umutekano w’ibicuruzwa (CASB) ubu ni ibintu bisanzwe.

Kwinjira kureyishingikiriza kuri bike kuri VPN, ariko byinshi kandi byinshi kumurongo wa zeru-kwizerana (ZTNA), ifasha abayikoresha kugera kumurongo wihariye ukoresheje imyirondoro yimiterere itagaragara kumitungo.

Sisitemu yo Kurinda Kwinjira (IPS)irinde intege nke zidatewe kwibasirwa no guhuza ibikoresho bya IPS na seriveri zidatumwe kugirango tumenye kandi duhagarike ibitero. Ubushobozi bwa IPS ubu bushyirwa mubindi bicuruzwa byumutekano, ariko haracyari ibicuruzwa byonyine. IPS itangiye kongera kuzamuka nkuko igicu kavukire kigenda kibazana buhoro buhoro mubikorwa.

Igenzura ry'Urusobeitanga kugaragara kubintu byose biri kuri Network no kugenzura uburyo bwo kugera kubikorwa remezo byumushinga. Politiki irashobora gusobanura kwinjira ukurikije uruhare rwumukoresha, kwemeza, cyangwa ibindi bintu.

DNS Isukura (Sisitemu Yizina rya Sisitemu)ni serivisi itangwa n'abacuruzi ikora nka domaine yumuryango Izina rya sisitemu yo gukumira abakoresha amaherezo (harimo n'abakozi ba kure) kwinjira ku mbuga zitemewe.

DDoSmitigation (Kugabanya DDoS)igabanya ingaruka zangiza zo kugabanywa guhakana ibitero bya serivisi kumurongo. Igicuruzwa gifata inzira nyinshi zo kurinda umutungo wurusobe imbere muri firewall, aboherejwe imbere yumurongo wa firewall, hamwe nabari hanze yumuryango, nkurusobe rwibikoresho biva mubatanga serivise za interineti cyangwa gutanga ibintu.

Imicungire ya Politiki yo gucunga umutekano (NSPM)bikubiyemo isesengura nubugenzuzi kugirango hongerwe amategeko agenga umutekano wurusobe, kimwe no guhindura imikorere yimikorere, kugerageza amategeko, gusuzuma kubahiriza, no kureba. Igikoresho cya NSPM kirashobora gukoresha ikarita y'urusobekerane rwerekana kwerekana ibikoresho byose hamwe na firewall yo kwinjira bikubiyemo inzira nyinshi.

Microsegmentationni tekinike ibuza ibitero byurusobe bimaze kugenda gutambuka kugirango bigere kumitungo ikomeye. Ibikoresho bya Microisolation kumutekano wurusobe biri mubyiciro bitatu:

- tools Ibikoresho bishingiye ku muyoboro byashyizwe kumurongo, akenshi bifatanije numuyoboro usobanurwa na software, kugirango urinde umutungo uhujwe numuyoboro.

- tools Ibikoresho bishingiye kuri Hypervisor nuburyo bwambere bwibice bitandukanye kugirango tunonosore neza urujya n'uruza rwimodoka rwimuka hagati ya hypervisors.

-  Ibikoresho byabashitsi bishingiye kubikoresho bishyiraho abakozi kubakira bashaka kwitandukanya nabandi basigaye; Umukozi wakiriye igisubizo gikora neza kubikorwa byigicu, imizigo ya hypervisor, hamwe na seriveri yumubiri.

Serivise Yizewe Yumutekano (SASE)ni urwego rugaragara ruhuza ubushobozi bwumutekano wurusobe rwuzuye, nka SWG, SD-WAN na ZTNA, hamwe nubushobozi bwuzuye bwa WAN kugirango dushyigikire umutekano wibikenewe byimiryango. Byinshi mubitekerezo birenze urwego, SASE igamije gutanga serivise yumutekano ihuriweho itanga imikorere ikora murusobekerane muburyo bworoshye, bworoshye, kandi bwihuse.

Kumenya imiyoboro no gusubiza (NDR)ubudahwema gusesengura ibinyabiziga byinjira n’ibisohoka n’ibiti by’umuhanda kugirango wandike imyitwarire isanzwe ya Network, bityo anomalies irashobora kumenyekana no kumenyeshwa amashyirahamwe. Ibi bikoresho bihuza kwiga imashini (ML), heuristics, gusesengura, hamwe no kumenya amategeko.

Kwagura Umutekano DNSni inyongera kuri protocole ya DNS kandi yagenewe kugenzura ibisubizo bya DNS. Inyungu z'umutekano za DNSSEC zisaba gusinywa hifashishijwe imibare ya DNS yemewe, inzira yibanda cyane.

Firewall nka serivisi (FWaaS)ni ikoranabuhanga rishya rifitanye isano rya hafi na SWGS. Itandukaniro riri mubwubatsi, aho FWaaS inyura muri VPN ihuza hagati yimpera nibikoresho kuruhande rwurusobe, kimwe numutekano mukicu. Irashobora kandi guhuza abakoresha amaherezo muri serivisi zaho binyuze muri tunnel ya VPN. FWaaS kuri ubu ntisanzwe cyane kuruta SWGS.


Igihe cyo kohereza: Werurwe-23-2022