| Nome: | Descrição: | Tamanho: | Formato: | |
|---|---|---|---|---|
| 6.25 MB | Adobe PDF |
Autores
Orientador(es)
Resumo(s)
A segurança dos sistemas SAP assume um papel crítico na proteção da informação
empresarial, uma vez que estes sistemas suportam processos de negócio fundamen
tais em muitas organizações. No entanto, a análise de configurações de segurança em
ambientes SAP continua frequentemente a ser realizada de forma manual, exigindo
elevado conhecimento técnico e um investimento significativo de tempo por parte das
equipas de administração e auditoria, através de ferramentas SAP que são complexas
de configurar ou por ferramentas privadas bastante dispendiosas.
Opresenteprojetopropõeodesenvolvimentodeumaaplicaçãowebdestinadaàau
tomatização da análise de segurança em sistemas SAP, com os objetivos de identificar
vulnerabilidades, avaliar o nível de conformidade das configurações e apoiar a mitiga
ção de riscos operacionais. A solução desenvolvida integra um backend implementado
em Java, responsável pela execução das verificações de segurança e comunicação com
os sistemas SAP através de ligações RFC e com o frontend desenvolvido em React/
Next.js que permite a configuração de auditorias, visualização de resultados e gestão
de relatórios.
Aaplicação implementa um conjunto de verificações automáticas com base em re
comendações de segurança documentadas pela própria SAP, incluindo análise de con
tas padrão, parâmetros de autenticação, configurações de RFC, permissões críticas e
exposição de serviços web. Os resultados obtidos durante os testes demonstram que a
solução é capaz de identificar vulnerabilidades reais em sistemas SAP e reduzir signi
ficativamente o tempo necessário para realizar auditorias de segurança.
Desta forma, o trabalho contribui para a melhoria dos processos de auditoria em
ambientes SAP, promovendo uma abordagem mais eficiente, sistemática e alinhada
com as boas práticas de segurança.
The security of SAP systems plays a critical role in protecting enterprise information, as these systems support core business processes in many organisations. However, the analysis of security configurations in SAP environments is still frequently performed manually, requiringspecialised technical knowledgeandsignificanteffortfromsystem administrators and auditors. This project proposes the development of a web application designed to automate security analysis in SAP systems, with the objective of identifying vulnerabilities, as sessing configuration compliance and supporting risk mitigation. The developed so lution integrates a Java-based backend responsible for executing security checks and communicatingwithSAPsystemsthroughRFCconnections,aswellasaReact/Next.js frontendthatenablesauditconfiguration, resultvisualisationandreportmanagement. Theapplicationimplementsasetofautomatedchecksbasedonsecurityrecommen dations documentedbySAP,including theanalysis of default accounts, authentication parameters, RFCconfigurations, critical authorisations and exposed web services. The results obtained during testing demonstrate that the solution is capable of identifying real vulnerabilities in SAP systems and significantly reducing the time required to per form security audits. Overall, this work contributes to improving security auditing processes in SAP en vironments by providing a more efficient, systematic and scalable approach aligned with recognised security best practices
The security of SAP systems plays a critical role in protecting enterprise information, as these systems support core business processes in many organisations. However, the analysis of security configurations in SAP environments is still frequently performed manually, requiringspecialised technical knowledgeandsignificanteffortfromsystem administrators and auditors. This project proposes the development of a web application designed to automate security analysis in SAP systems, with the objective of identifying vulnerabilities, as sessing configuration compliance and supporting risk mitigation. The developed so lution integrates a Java-based backend responsible for executing security checks and communicatingwithSAPsystemsthroughRFCconnections,aswellasaReact/Next.js frontendthatenablesauditconfiguration, resultvisualisationandreportmanagement. Theapplicationimplementsasetofautomatedchecksbasedonsecurityrecommen dations documentedbySAP,including theanalysis of default accounts, authentication parameters, RFCconfigurations, critical authorisations and exposed web services. The results obtained during testing demonstrate that the solution is capable of identifying real vulnerabilities in SAP systems and significantly reducing the time required to per form security audits. Overall, this work contributes to improving security auditing processes in SAP en vironments by providing a more efficient, systematic and scalable approach aligned with recognised security best practices
Descrição
Palavras-chave
SAP Cibersegurança Auditoria de segurança Automatização Sistemas ERP
