节点文献

龙岩电业局企业网络防火墙及虚拟专用网技术的应用研究

Longyan Electric Power Bureau Enterprise Network Firewall and Virtual Private Network Technology Research

【作者】 陈曦

【导师】 黄立勤;

【作者基本信息】 福州大学 , 电子与通信工程(专业学位), 2015, 硕士

【摘要】 随着互联网技术的不断提升,企业信息化进程也日益普及,但伴随而来的网络安全问题也逐渐突显。病毒和黑客侵袭等拥有先进技术的攻击手段日趋增多,并且这些攻击都具有隐蔽性强、传播快等特点。所以要保证企业的网络数据安全就必须不断的提升企业局域网的安全性能,加强局域网建设的安全级别,进而通过对网络安全措施的分析研究为企业提供更为安全可靠的网络环境。作为龙岩地区唯一的电力供应商,龙岩电业局的分支机构众多,分布地域广,有的甚至位于偏远山区,142个变电站、127家供电所信息网络分布在不同的ISP网络中。在公共的互联网环境中传送单位内部的数据,经常受到外部网络攻击,数据的安全性难以得到保障。由企业自建网络通道与变电站及供电所互联,安全性虽得到保障,但为此投入的建设和维护费用巨大。因此,迫切需要一种低成本、扩展性强、安全性高的解决方案,在不同的ISP之间互联,并对接入的IP和用户身份认证进行统一管理,构建局本部与变电站、供电所之间安全的网络环境。本文主要对龙岩电业局企业防火墙和VPN结合的改造过程进行分析和研究。解决思路基于平滑过渡的基础上实现对原网络规划区域的防火墙和IPSec VPN的改造。首先,分析并研究防火墙分类和技术原理,IPSec VPN的基础原理和实现方式,通过探讨龙岩电业局原先的网络架构,针对造成局域网信息安全隐患的原因进行分析,设计并创建了一个结合VPN与防火墙的改进方案。由IPSec通过端对端的安全加密通道,防御来自Internet对专业网络的攻击。IPSec VPN将企业内部传输的数据进行封装,在服务器和客户终端之间进行交互认证。并向网络层和上层的信息数据流添加加密字段,采用IDEA、3DES、DES等算法对外隐藏关键信息。利用NAT技术对内外网IP地址进行转换,并通过UDP封装IPSec的方法解决二者之间的矛盾。最后,本研究通过对防火墙和虚拟专用网部署的环境进行功能测试和性能测试,对测试结果进行分析。通过测试结果表明,本文采用的防火墙与IPSec VPN结合的传输模式,充分克服了原先网络的安全问题,最大限度地保留了原有架构,并节约了投资成本。使龙岩电业局和县供电公司及下属的变电站、供电所的数据传输不但可以防止非法用户的访问,而且传输过程中的安全性也得到了保证,改进后的传输网络具备更完善的安全功能。

【Abstract】 As Internet technology continues to improve,the process of enterprise information has become more and more popular,but accompanied by network security problems is becoming more and more important.Virus and hacker attacks and other technologically advanced means of attack is increasing day by day,and these attacks have the characteristics of concealment,spread fast,so ensure the safety performance of the network data security for enterprises must constantly upgrade enterprise LAN construction,strengthen the security level,and provide more secure and reliable network the environment through the application research of network security measures.As the sole supplier of electricity in Longyan region,branch of Longyan Electric Power Bureau number,wide distribution,and some even in remote mountain areas,142 substations,127 power supply information network distribution in different ISP networks.Unit of transfer internal data in the public Internet environment,is often affected by external network attack,it is difficult to protect the security of data.By the enterprise self built network channel and substation and power supply interconnection,although guaranteed safety,but the construction of this investment and maintenance costs of great.Therefore,there is an urgent need for a low cost,strong expansibility,high security solutions,the interconnection between different ISP,and IP and user authentication to access the unified management,construction bureau and substation,the safety of power supply between the network environment.Analysis and Research on the transformation process of this paper focuses on the Longyan Electric Power Bureau Enterprise Firewall and VPN binding.Solution of the original network transformation to realize the regional planning of firewall and IPSec VPN based on the smooth transition.First of all,the analysis and study of the classification and principle of the firewall technology,and the realization principle of IPSec VPN,through the discussion of Longyan Electric Power Bureau,the original network architecture,analyze the causes of risks of information security of LAN,design and create a combination of VPN and fire wall of the improved scheme.By IPSec end to end encryption channel through security,defense from Internet to professional network attacks.IPSec VPN will package the enterprise internal data transmission,for mutual authentication between the server and the client terminal.And to the information and data in network layer and the upper layer flow field to add encryption,using IDEA,3DES,DES and other foreign key information hiding algorithm.On the inside and outside the network IP address conversion by NAT technology,and solve the contradiction between the two through the UDP IPSec package.Finally,the research on the function test and performance test through the deployment of firewall and virtual private network environment,analysis of test results.The test results show that the transmission mode of firewall and IPSec VPN used in this combination,sufficient to overcome the problem of security of the original network,to maximize the retention of the original framework,and saves the cost of investment.The Longyan Electric Power Bureau and county power supply company and the subordinate substation,power supply of the data transmission can not only prevent the illegal user access and transmission in the process of security is ensured and improved the safety of transmission network has more perfect function.

【关键词】 防火墙虚拟专用网IPSec隧道信息安全
【Key words】 FirewallVirtual Private NetworkIPSecTunnelInformation Security
  • 【网络出版投稿人】 福州大学
  • 【网络出版年期】2018年 07期
节点文献中: 

本文链接的文献网络图示:

本文的引文网络