节点文献
内部网络服务审计系统的分析与设计
The Analyse and Design of Intranet Service Audit System
【作者】 彭勇;
【导师】 何伟;
【作者基本信息】 重庆大学 , 通信与信息系统, 2009, 硕士
【摘要】 当前网络正以惊人的速度向世界各个角落蔓延,人们的工作、学习、生活越来越依赖于网络。各企业、公司、学校也纷纷建立起属于自己的局域网。在网络方便大家的生活,提高人们生活质量的同时,病毒、非法访问、垃圾邮件、网络阻塞却给人们带来了巨大的损失,网络隐患暗藏杀机。许多公司、企事业单位内部员工私自开设网络游戏或文件传输服务器,架设网站更是加剧了这种情形。这些网络非允许开设的服务不仅会带来潜在的诸如泄密、病毒传播等安全隐患,而且会占用大量的带宽,严重影响网络正常业务的运行。内部网络服务审计系统课题正是为解决上述问题提出的。内部网络服务审计系统把服务审计提升到一个战略的地位,同时把网络带宽滥用纳入研究的范围,是一个新的课题。该课题不同于传统安全审计系统被动防御方式,系统按照用户配置信息,积极查找并定位内部网络非法服务,解除内网安全隐患和网络畅通障碍,同时提供告警和日志信息,属于安全审计系统中主动防御方式的范畴。内部网络服务审计和漏洞扫描同属于主动防御的范畴,但后者偏重漏洞扫描,前者偏重服务审计。内部网络服务审计系统借鉴了漏洞扫描系统中漏洞特征查找方法和漏洞库存储结构特征,以及网络技术中已经比较成熟的多线程并发技术,端口扫描技术和网络嗅探技术;在功能模块和结构设计时,参考了安全审计系统的设计;在用户操作界面上,充分吸收了诺顿反病毒软件客户端以及其他扫描器配置简易方便的优点。内部网络服务审计系统的设计采用面向对象设计技术,先分析了用户需求,提出系统模型,然后设计了系统整体框架并设计了主要功能模块。在系统的分析设计中,对一些关键技术和方法进行了论证。在系统初步完成后,进行了功能和性能测试,测试结果表明内部网络服务审计系统基本满足用户需求,能有效地监控内部网络服务运行情况,发现和定位非法开设的网络服务,减少了内网安全隐患,保证有限带宽合理利用,有效地净化了内部网络环境。
【Abstract】 In modern life, network overwhelms the worldwide as far as it can. More people can not work without net, also live and study. As the organization of enterprise and the office of school build their own inner network one after another to live and work efficiently, all kinds of problem come along with it, such as virus, illegal access and rubbish mail etc. The situation even make worse when inner employee establish game and file transfer server, and some build private web site. These illegal intranet services not only bring about security thread, for example, secret betrayed, virus spread etc, but also disturb normal network service for engrossing the bandwidth. Intranet service audit system is designed to resolve this problem.Intranet service audit system is a new thesis which upgrades strategically service audit to a higher position and puts the abuse of bandwidth into reserch. This thesis belongs to the theme of active defense. In this thesis, user configurtes parametor firstly, then the system actively finds and locates the illegal services, the alarm information and audit information will be provided in logs. This subject is the same theme of active defense as vulnerabilities scanner, but former puts emphasize on service audit, the latter lays importance on vulnerabilities scan. Though they are different, intranet service audit system makes full use of the method in sign-code exploration and the structure style of sign-code warehouse. The former also absorbs other network technology which is highly researched before, like multithread technology, port scan technology and detective technology. The functional module and system frame of security audit system is also as reference when designed. The simple and convenient configuration of Symantec Antivirus client and other net scanner is another point which is used for reference in the user interface design.Intranet service audit system adopts the technology of object-oriented design. Firstly it analyses the need of user, then builds the model and structure, and puts it into realization. After finishes the job, test is carried out. Test result indicates this system can work rightly to supervise intranet service, include finding and locating illegal one. For many vulnerabilities being hidden in the illegal intranet service, Intranet service audit system can diminish threat coming from the inner network, also it can prevent the limited bandwidth being used by game players. Therefore, this tool can keep the network working in normal.
【Key words】 network service; security audit; sign code; security vulnerabilities;