Enterprises use security equipments in order to protect their information assets from various attacks such as viruses and
hacking. However, such individual equipments hardly provide enterprise level integrated security. Recently, there has been
a great need in small/medium businesses to purchase such integrated security services in a cost effective way by means of
an ASP solution. We propose the architecture of a web-based enterprise security manager that can be used as an ASP solution.
To the best of our knowledge, it is the first such system that provides integrated security management services through the
web. We conducted experiments on our prototype system, and showed that it could handle 30 million logs per day, and serve
300 concurrent web users with 20 transactions per session. This system is now running as a commercial application service
at KT Bizmeka, which is one of the largest Korean ASPs.
This work was supported by the KT Information Security Business Unit.