DESIGN and IMPLEMENTATION of a SECURE CAMPUS NETWORK G.Michael, Assistant Professor, Department of CSE, Bharath University, Chen
Total Page:16
File Type:pdf, Size:1020Kb
International Journal of Pure and Applied Mathematics Volume 116 No. 8 2017, 303-307 ISSN: 1311-8080 (printed version); ISSN: 1314-3395 (on-line version) url: http://www.ijpam.eu Special Issue ijpam.eu DESIGN AND IMPLEMENTATION OF A SECURE CAMPUS NETWORK G.Michael, Assistant Professor, Department of CSE, Bharath University, Chennai [email protected] Abstract: Security has been a essential issue within the There are plenty of similarities between securing an style in readying of an enterprise network. A campus outsized network and university network,however each network is a very important part of campus life and has its own problems and network security is crucial for a campus network. challenges.Currentinstitutionorganisations pay a lot of Secured network protects an establishment from attention to IT to boost their students’ learning security attacks related to network. A university experience. Architects of campus can do this if IT network includes a range of uses liketeaching, learning, managers hold on to the basic principles self-addressed research, management, e-library, result publication. during this reference architecture namely LAN or Network security can stop the university network from WAN connectivity design considerations, security, and differing kinds of threats and attacks. The theoretical centralized management[5,6]. contribution of this study may be a reference model The network infrastructure style has become a vital part design of the university campus network that may be for a few IT organizations in recent years. a very pre-designed or custom-made to make strong, however important network design consideration for today's versatile network that the successive generation needs. networks is making the potential to support future growth in a very reliable, scalable and secure manner. Keywords: Campus Network, Security, WAN, This needs the designer to outline the client's unique Security Threats, Network Attacks, VPN, VLAN, situation needed for what significantly the current Firewall. technology, application, and information design. Here, completely different analysis papers are 1. Introduction consulted for security in campusnetwork.Numerous network info for security issues and their solutions. As the computers and networked systems thrive in They represented the current security info standing of today’s world, the necessity for increased robust pc and the campus network, analysed security threat to campus network security becomes more and more necessary network and represented the ways to maintenance of [1,2] . The rise within the network system has exposed network security . several varied styles of web threats.The safety could embrace identification, authentication,authorization and 2. Background camera to safeguard integrity, convenience, authenticity of element or network instrumentation. There’s no laid- There are various categories of network like Personal down procedure for coming up with a secure network. Area Network (PAN), Local Area Network (LAN), Network security must be designed to suit the Metropolitan Area Network (MAN), campus Area requirements of aorganisation[3,4]. Network (CAN),Storage Area Network (SAN) and Campuss network is crucial and it plays a very Wide Area Network (WAN). important role for any organization. Architecture and A Personal Area Network (PAN) may be a its security are as necessary as air, water, food, and network organized around a private person. Personal shelter. Network security threat and architecture are Area Networks usually involve a mobile, a cellphone invariably serious problems. A campus network is an and/or a hand-held computing device such as PDA. A autonomous network beneath the management of a Local Area Network (LAN) may be a cluster of university that is at within a neighbourhood computers and associated devices that share a standard geographical place and typically it should be a communications line or wireless link. Typically, metropolitan area network. connected devices share the resources of one processor Generally, IT manager in a very network faces many or server withina little geographical area. A challenges within the course of Metropolitan Area Network (MAN) may be a network maintaining,availability,performance,good that interconnects users with system resources in an infrastructure, and security. Securing an enormous exceedingly geographical area or region larger than that network has been always a difficulty to an IT manager. filled by even a large Local Area Network (LAN) 303 International Journal of Pure and Applied Mathematics Special Issue however smaller than the space filled by a Wide AreaArea categorizations of network attacks. The question is: Network (WAN). A campus Area Network (CAN) may how will we minimize these network attacks? The sort be a proprietary Local Area Network (LAN) or set of of attack, as specified by the categorization of interconnected LANs serving a organisation, federal reconnaissance, access, or DoS attack, determines the agency, university, or similar organization. A StorageStorage suggests that of mitigating a network threat[14,15]. Area Network (SAN) may be a high-speed network of storage devices that additionally connects those storagestorage Table 1. Identify the threat devices with servers[18,19]. It provides block -level storage that may be accessed by the applications running on any networked servers. a Wide Area Network (WAN) may be a geographically distributed telecommunications network. The term distinguishes a broader tele communication structure from an Local Area Network (LAN). Intensive analysis or project hashas been done in the position of network architecture andand security problems in CAN[7,8,9]. 2.1 Network architecture in campus area network The campus network of our study is meant in an hierarchical manner that may be a common practice ofof campus and enterprise networks. It provides a Types of network attacks: Classes of attack would standard topology of building blocks that enable thethe possibly add passive observance of communications, network to evolve simply.A hierarchical design avoidsavoids active networkattacks, close-in attacks, exploitation by the necessity for a fully-meshed network which all insiders, and attacks through the service supplier[26]. network nodes are interconnected[10,11]. Data systems and networks offer attractive targets and Designing a campus network might not seem as will be resistant to attack from the complete vary of fascinating or exciting as designing an associate IPIP thre at agents, from hackers to nation -states. A system telephone network, an associate IP video network, oror should be ready to limit injury and recover rapidlyafter maybe planning a wireless network. Ho wever , once attacks occur. Here are some attacks emerging applications like these are engineered uponupon types[22,23]: the campus foundation. Very similar to the 1. Passive Attack development of a house, if the engineering work is 2. Active Attack skipped at the foundation level, the house can crackcrack 3. Distributed Attack and eventually collapse[20,21]. 4. Insider Attack If the foundation services associated reference 5. Close-in Attack design in an enterprise network don't seem to be rockrock - 6. Phishing Attack solid, applications that depend upon the services 7. Hijack attack offered by the network like IP telephone, IP video and 8. Spoof attack wireless communications can eventually suffer 9. Buffer overflow performan ce and responsibility challenges. To continue 10. Exploit attack the analogy, if a reliable foundation is built and 11. Password attack engineered, the house can indicate years, growing withwith the owner through alterations and expansions to 3. Real time data: some network attacks provide safe and reliable service throughout its lifelife cycle[12,13]. A. Denial of service (dos) The same is true for associate enterprise campus network. The design principles and implementation Denial of service (DoS) is a interruption of service best practices represented during this document are either as a result of the system is destroyed, or as a tried-and-true lessons learned over time according to result of it’s quickly out of stock. Examples add my referred research papers. destroying a computer's hard disc, cutting the physical infrastructure[24,25], and consumption of all offered memory on a resource. Fig1 shows a true note value of DoS attack knowledge in a very campus network 2.2 Security issues in campus network usingCyberoamsecuritydevice . After configure Firewall and VLAN for DoSattackAttacker tried DoS There are a large vary of network attacks and securitsecurityy threats, network attack methodologies, and 304 International Journal of Pure and Applied Mathematics Special Issue Attack however the protection device dropped the traffic that we've shown within the diagram. Figure 1. Attacker IP List Figure 3. Traditional campus network design B. Arp spoofing attack 3. Conclusion ARP spoofing could be a style of attack during which a malicious actor sends falsified ARP(Address Network architecture and its security are necessary for Resolution Protocol) messages over Local Area any organization. If we tend to follow the hierarchic Network(LAN).This ends up in the linking of associate network design, network will be scalable, performance attacker's mackintosh(MAC) addresswithIPaddress of and securityareincreased , and therefore the network a re aserver on the network. We are showing some real time simple to take care of. During this work,we tend to information