节点文献

四川移动客服系统网络安全的策略研究与实现

【作者】 张亮

【导师】 杨波; 李伟军;

【作者基本信息】 电子科技大学 , 电子与通信工程, 2007, 硕士

【摘要】 随着计算机信息技术与网络技术的迅速发展,计算机和网络已经成为企业的重要信息载体和传输渠道,在享受计算机以及计算机网络所带来的方便性的同时,安全隐患也不时显露,特别是企业内部重要信息的外泄而给企业带来损失的事件时有发生,因此,针对内部网络的数据信息安全隐患而采取防范措施,具有非常重要的意义。作者在分析当前各种网络安全技术的优缺点后,根据四川移动客户服务系统网络安全现状以及对网络安全的需求,设计了网络安全体系。将客服系统网络系统按功能划分为生产网、办公自动化(OA)网和测试网,确定生产网是首要的保护对象,OA网和测试网则重点强调网络边界的安全。确定3个子网络对外接口,根据出口的可控性,设定不同的风险等级,采取相应的安全防范措施。采用虚拟局域网(VLAN)技术,制定VLAN划分规则,将生产网设备进行逻辑划分;根据不同的应用情况采用相应的防火墙技术,在系统网络对外接口和其内部各子网之间的连接点设置防火墙;对重要的网络设备、资源区及所有的安全设备实施安全评估策略;依据所要保护的网络类型、采用的边界防护系统和保护级别采取不同方式的入侵检测系统。并根据网络入侵检测系统的设计原理、设计思路、实现方法,采纳一些已成熟的入侵检测系统技术,参考大量的商业级别的入侵检测系统的源码,用PERL作为脚本开发语言,在呼叫中心的Linux操作系统下,在RedHat环境中完成了一个网络入侵检测系统的设计和实现。本方案的基本原则和方法建立在实际工作基础上,对呼叫中心的客服系统的网络结构调整和安全设计具有一定的现实意义。

【Abstract】 With the rapid development of computer information technology and network technology, computer and network, have become an important information carrier and transmission channels for the enterprises. Aside from the conveniences brought along, potential safety problems appear now and then, which is particularly true when enterprises suffer occasionally from leakage of important information to enterprises. Therefore, it is of great significance to take preventive measures targeting at internal network information security risks.By analyzing the current network security technology advantages and disadvantages, the author designs a call center network security system according to the status quo and needs of call center network security, design a call center network security system. Functionally, call center network system falls into two types: production network, the prioritized protection target; office automation (OA) network, emphasizing network border security. Corresponding security measures are taken through setting external interfaces of 2 sub-networks, in accordance with the controllability of exports, risk levels.Virtual local area network (VLAN) technology is employed, and VLAN division rule is set down, logic division is done on production network; According to different case, corresponding fire wall technologic is adopted, and what’s more, fire wall is set on external interfaces and internal networks. Security assessments are carried through on important network equipments, resource, and security equipments. According to the type of network to be protected, boundary protection system adopted and different protection rank, the mode of entering into detection system is ranked either. What’s more, according to design theory and methods of network invading adopt several mature invading detection system technology, reference to a large quantity of source code of invading detection system in business rank, develop language with PERL, in the system of Linux from Agriculture Bank, with background of RedHat, a network invading detection system is designed and implemented.This program, whose basic principles and methods are based on practical work, has some practical significance for the structural adjustment of call center customer service system and designing of network security.

  • 【分类号】TP393.08
  • 【下载频次】122
节点文献中: