节点文献

分布式环境下的安全策略关键技术研究

Research on Key Technologies for Security Policy in the Distributed System Environment

【作者】 杨明

【导师】 郭树旭;

【作者基本信息】 吉林大学 , 电路与系统, 2011, 博士

【摘要】 分布式系统安全是当前信息安全领域的一个重点研究方向。分布式系统安全策略一般是由各应用系统分散管理,存在多样性和复杂性等问题,不能很好的满足信息安全对整体性、协同性管理的要求。如何构建一个高效的、协同的、统一的安全策略机制,提高系统整体安全管理能力,是信息系统建设中的重要任务之一。本文对分布式系统安全策略的若干关键问题进行了研究,主要包括:分布式安全策略框架和表示方法、分布式安全策略生成方法、分布式安全策略调度和集成方法、分布式安全策略实施和管理方法。首先,结合IETF策略框架和COSO参考模型,提出了一种分布式系统安全策略框架和一种基于风险的控制模型,通过将风险关键因素量化,发现主要风险,实现风险控制;通过将安全策略关键要素定义,给出了一种基于XML的安全策略表示方法,从形式化上描述了安全控制的过程,使得安全策略更具有通用性、易理解和形式简单等特点。其次,结合在IPSec环境下生成安全策略为例,阐述了其存在的问题。通过引入策略引擎模型,改进了安全策略的实现方式。在此基础上,将机器学习理论引入IPSec策略生成方式,提出了一种基于λ-ID3决策树的安全策略生成模型和实现算法。通过引入关键因子λ改进了ID3算法,区分了不同属性之间的关系和重要程度,克服了决策树生成取值偏向等缺点,较好的解决了安全策略动态生成的问题。第三,通过增加前置预处理装置改进了任务调度方法,实现了系统对服务请求的动态调度预处理,在满足任务对QoS要求的同时,又能有效的提高系统对任务调度的处理能力;通过引入信息集成模块,改进了分布式安全策略集成方法,实现了安全策略服务、接口、参数的统一和协同管理,减小了应用间的耦合度,提高了安全策略管理的可维护性和安全性。最后,本文提出了一种安全策略集中化部署方式,将原先分散在各应用系统的安全策略进行统一管理,发挥了集中化管理的效率,满足了当前分布式环境下对信息安全整体性、协同性管理的需求;通过安全策略具体实施案例,构建了集中化安全策略体系框架和功能架构,并给出了安全策略实施和管理建议。

【Abstract】 Distributed system security is one of the key areas of current information security research. Distributed system security policy, generally, is managed by separated and decentralized applications. But it could not meet the information security requirement as a whole and coordinated management due to the diversity and complexity of the policy. How to build an efficient, coordinated, unified security policy mechanism and how to enhance the overall safety management system capability are one of the important information system tasks. A number of key technologies of distributed system security policy were researched in this paper, including:distributed security policy framework and representation, distributed security policy generation method, distributed security policy scheduling and integration method, distributed security policy implementation and management method.Major works of this paper are listed as below:Firstly, with IETF policy framework and COSO reference model, this paper presented a framework and a risk-based control model for distributed security policy. Through quantification of key risk factors to identify the main risks and to achieve risk controls.By defining the key elements of security policy, the paper presented a representation method related to XML based on security policy. It described the safety control process by assigning the associated XML representation to make the security policy to be more universal, easy to understand and simple in form.Secondly, considered an example of the security policy that generated under the IPSec environment, it described its problems. Trough proposing a policy engine for the existing IPSec infrastructure, it improved the security policy implementation. Based on this, the theory of machine learning was induced into IPSec policy generation method. An improved ID3 algorithm based on the importance factorλof attributes was raised, which can improve the security policy generation method, and distinguish the importance of the different attributes, and avoid the defects of the traditional ID3 algorithm inclining to the attribute with more values. The method resolves the problems that how to generate auto-corresponding security policy due to the diversity of network security. Thirdly, this paper presented a scheduling method based on a pretreatment device. It achieved the service requests of the dynamic scheduling pretreatment, and it raised the efficiency and appropriateness of the task scheduling. The paper also presented an integration method of distributed security policy. It improved the centralization and the integration of system. Through the introduction of information integration module, it achieved the unified and collaborative management in relation to security policy services, interfaces and parameters, and reduced the coupling between the applications, and improved the maintainability and security of the security policy management.Finally, this paper presented a deployment method of the centralized security policy. The scattered security policies in various applications were unified and managed centrally to raise the efficiency of the centralized management and to meet the requirement of integrity and interoperability for the security management under the current distributed environment. Through the case of implementation of the security policies, a centralized system security policy framework and functional structure were established to provide the security policy implementation and recommendations.

  • 【网络出版投稿人】 吉林大学
  • 【网络出版年期】2011年 09期
节点文献中: 

本文链接的文献网络图示:

本文的引文网络