Chapter 3.
Analysis of the Existing System
3.1 Introduction
This chapter examines the prevailing state of network security in the organization, concentrating
on network resource protection, threats, and data protection. Vulnerabilities in the prevailing
approach, such as obsolescent security, lack of surveillance, and ineffective threat handling, are
identified, thereby putting the organization at risk for threats such as unauthorized access,
malware attacks, and data breaches.
The chapter emphasizes the requirement of an efficient Network Security System to work
towards enhancing confidentiality, integrity, and availability as well as ensuring the efficiency of
operations to gain the trust of users.
3.2 Organization Overview
The organization is dependent on the use of the computer network for its operations,
communications, and storage. The current state of security on the computer network lacks depth.
These security systems on the computer network emphasize connectivity and neglect security.
With the ever-growing use of internet services, cloud computing, and networked systems, there is
a pressing need for a systematic and holistic approach to security to effectively detect, prevent,
and respond to threats.
3.3 Roles and Responsibilities
The tasks of network security management can't be encompassed by a single
1. Network Administrator: Responsible for the setup and maintenance of routers,
switches, and firewalls for secure connectivity on the network.
2. System Administrator: Maintains servers, user accounts, and operating systems for
secure setup and updates.
3. Security Analyst: Analyzes network activity, identifies potential threats, responds to
security events, and makes recommendations for remediation.
4. IT Manager: Manages the/company’s total information technology operations, enforces
strict security policies, and implements security strategies aligned with business goals.
5. End Users: Adhere to security practices, employ network resources effectively, or report
unusual events.
3.4 Problem Analysis
The existing network security environment is confronted by many challenges that undermine the
security and integrity of network activities:
1. Weak Access Control: Authentication and user authorization are weak, which can pose a
threat for unauthorized access to sensitive data systems.
2. Lack of Real-Time Monitoring: The absence of real-time monitoring results in delayed
threat and abnormal activity identification.
3. Basic Firewall and Policy Setup: There are deficiencies in existing firewall rules that
allow possible attacks to take advantage of them.
4. High Possibility of Cyber Attacks: Use of obsolete antivirus software also makes it
prone to cyber-attacks because of the absence of an intrusion detection system.
5. Operational Inefficiencies: Manual management of the system is fraught with
inefficiencies, such as delays, errors, and inconsistencies.
3.5 Proposed Solution
The proposed Network Security System is expected to improve the organization’s security
environment by providing a multi-layer security system. The main characteristics and advantages
of the proposed system include:
1. State-of-the-art firewalls and intrusion detection/prevention systems
Network segmentation with a secure VPN connection for remote users
2. Real-time monitoring and automated alerts of threats
3. Centralized Management Dashboard for Administrator’s
The system will ensure decreased risks of unauthorized entry, faster reaction time in the event of
an incident, and overall network reliability.
Feasibility studies were done:
1. Technical Feasibility: Existing hardware, software, and technical skills to implement
were analyzed.
2. Economic Feasibility: Evaluated the cost benefit of implementing the system compared
to the cost of losses that might result due to security breaches.
3. Organizational Feasibility: Analyzed the readiness of the organizational members and
the ability to implement new security methods.
3.5.1 Analysis Techniques
To have relevant information regarding the existing network security system and the required
information of the proposed system in place, different fact-finding methods are employed. These
methods have been helpful in making the researcher aware of the way in which the current
system functions, the loopholes in the present system regarding security, and the needs of the
users as well as the management.
Interviews: Interviews were conducted with the IT personnel as well as management staff
responsible for network administration and decision-making in the company. Interviews will help
in evaluating network security processes, methods of accessing the network, network security
issues, and the network incident response process in the company.
Questionnaires: These were given to network users to help evaluate their awareness regarding
network security policies, their observance of network security rules, and the difficulties
encountered.
Observation: Observation was used to investigate network topology, device physical security
measures, as well as system daily operations.
Document Review: Documents such as security policies and network maps were reviewed to
understand the present state of the security setup.
3.6 System Requirements
3.6.1 Functional Requirements
The proposed system shall:
Authenticate and authorize users on the network
Monitor Network Traffic and Detect Security Threats
Log security events and reports
Limit access to unauthorized use of the network resources.
3.6.2 Non-Functional Requirements
The proposed system shall be:
Secure: Protect data confidentiality, integrity, and availability
Dependable: Operates continuously with little or no downtime
Scalable: support expansion of network in the future.
User friendly: easy to handle by IT administrators
3.7 System Design
This section provides the design for the proposed network security system, including network
architecture, access control structure, and security components.