Stock Abbreviation : Topsec      Stock Code : 002212
7*24 hour service: 400-777-0777

University of Science and Technology

After the network upgrade, the traffic of Web services has surged, exposing the university to risks such as Web application attacks and sensitive information leakage. It is imperative to build an efficient and reliable security protection system to ensure the stability of teaching and research services.

Background

As a core institution of higher education and scientific research, it undertakes key Web services such as teaching management, research data sharing, and teacher-student services. With the upgrade and expansion of the campus network, the access traffic of Web services has increased significantly. Meanwhile, it is confronted with network attack threats including SQL injection, XSS, and application-layer DDoS, and there is a risk of leakage of sensitive data such as research data and personal information of teachers and students. The existing protection system can no longer meet the security needs under heavy traffic, so a professional WAF solution is urgently required to build a solid security defense line.

Activity & Announcement
Requirement Analysis
01

It is required to meet compliance requirements.

02

It can defend against various types of Web application attacks.

03

To protect important data and students' personal sensitive information.

04

To prevent webpages from being tampered with.

Solution Architecture

Topsec TopWAF is adopted to build a multi-layered security protection system, with the core deployment mode of "inline dual-machine high availability + out-of-band monitoring deployment". Based on the transparent bridging mode, the inline deployment requires no adjustment to the existing IP architecture and realizes real-time traffic filtering and attack interception; the dual-machine configuration avoids the risk of single point of failure and ensures uninterrupted services. The out-of-band deployment is adopted in the DMZ area for traffic monitoring and log analysis without affecting the operation of core businesses.

Value to Customers
Regulatory Compliance

Deployment of TopWAF enables compliance with the website security requirements specified in the National Information Security Classified Protection Scheme.

Prevention of Unknown Threats

Leveraging self-learning technology, it enables intelligent modeling based on actual business scenarios and automatically generates protection rules. This standardizes users’ submission behaviors on web applications and provides effective defense against unknown threats.

Sensitive Information Protection

It supports filtering and protection of sensitive data (customizable). By means of masking and replacement, it ensures the security of users’ personal information.

Brand & Reputation ProtectionThis helps establish baselines for normal user behavior on web applications

It monitors and recovers website tampering incidents through fingerprint comparison and page caching technologies. Meanwhile, it allows website lockdown during special periods, safeguarding the public image of government agencies and enterprises.