节点文献

新型分布式防火墙

Research on a New Type of Distributed Firewall Technology

【作者】 舒朗

【导师】 王蔚然;

【作者基本信息】 电子科技大学 , 通信与信息系统, 2005, 硕士

【副题名】日志与审计系统的设计与实现

【摘要】 随着Internet 的急剧发展,网络安全问题格外突出,信产部基金课题“新型分布式防火墙”拟针对这一实际问题,提出了一整套完整解决方案。其目标是建立一套集防火墙、入侵检测【1】、策略中心、日志服务器为一体的安全防护体系。作为分布式防火墙【3】中主要模块之一的日志服务器,它有别于传统意义边界防火墙【5】的日志系统,其主要作用有:接收、处理、存储来自内网受保护主机与边界主机上传的日志信息;审计与监测异常行为,防止用户越权使用;基于日志分析的统计入侵检测并发现来自外部或内部的入侵行为以便通过策略中心加以阻击等。它的设计与实现关系着分布式防火墙地整体架构与性能。本论文的课题是对分布式防火墙系统中的日志服务器进行研究、设计并实现其功能,并研究其与策略服务器、主机防火墙、边界防火墙等模块一起构造完整的分布式防火墙安全防御体系。首先本文陈述了防火墙、数据库、入侵检测、SSL 加密通讯【7】、多线程、安全联动【8】等相关技术基础。接着叙述分布式防火墙系统的整体框架、本质特征以及工作流程等。然后讨论日志服务器模块的总体设计方案与结构。并从其划分的几个关键模块:日志程序初始化、数据采集、审计系统、基于日志分析的统计入侵检测与日志模块安装等分别论述了设计过程,给出了具体实现方案、数据处理流程、函数原型及相关说明等。论文最后详细描叙了测试结果和性能分析,并在现有基础上对今后的扩展与开发进行了展望。

【Abstract】 With the rapid development of the Internet, the problem of network security is outstanding increasingly. The new type of the distributed firewall which is the project of Ministry of Information Industry, gives a solution to the problems. The purpose of the project is to found a system that is based on the distributed firewall, including firewall, intrusion detect, policy center and log server. As a main module of the distributed firewall, the log server , which is different from log system of tradition perimeter firewall, has the following functions: receiving, disposing and saving log information which uploaded by inner host and boundary firewall; auditing and inspecting abnormal actions; Preventing users from going beyond their commission uses; statistical IDS based on log analysis; finding out invasion behaviors that comes from inside or outside and block them through tactics center. Its design and realization are related to the whole framework and performance of distributed firewall. The purpose of this paper is to study and design the log server in the system of distributed fire wall, and realize its function, to carry on the research into how policy center, host firewall, perimeter firewall and some other modules form completed distributed safe defense system with it. Firstly, this paper states the theoretical foundation of the technology of firewall, database, IDS technology, the encrypt communication technology of SSL and some relevant technologies. And then it deeply analyzes the whole framework, essential characteristic and procedure of the distributed firewall system. This thesis mainly studies the overall design plan and system structure of log server module, separately discusses the several key modules which divided by system structure: Initializing of log program, data acquire, audit system, statistical IDS based on log analysis and the setup of log module, etc, and provides the concrete scheme, data processing procedure, function prototype and relevant description. Finally, illustrating the test result and performance analysis of this new technology in details, the paper looks forward to the expansion and development of it in the future on the existing foundation.

  • 【分类号】TP393.08
  • 【被引频次】4
  • 【下载频次】278
节点文献中: 

本文链接的文献网络图示:

本文的引文网络