节点文献

基于802.1x认证方式的端点准入防御的应用与研究

Research and Application for Endpoint Admission Defense Based on the802.1x Authentication Mode

【作者】 杨波

【导师】 蔡坤宝;

【作者基本信息】 重庆大学 , 电子与通信工程, 2012, 硕士

【摘要】 伴随着网络经济的迅速发展,网络安全已经上升为全球问题,近年来,与互联网连接而成为频繁攻击点的组织和个人越来越多。大多数的网络安全威胁是由于不安全的用户终端和非法的网络使用行为造成的。如不及时更新最新的病毒库、对于来访用户的控制缺乏必要手段、非法用户可以对内部网络进行非法接入和访问等。传统的网络安全措施不能有效的防御来自企业内部的安全威胁。端点准入防御(EndpointAdmission Defense EAD)为企业网络提供了一套立体的安全体系,集中管理用户、实施统一的安全策略,从而提升了网络的安全性和健壮性。接入认证技术是EAD实现的载体,接入认证技术可以是802.1x认证、PORTAL认证、L2TP。802.1x作为一种基于端口访问控制机制,由于其低成本,良好的扩充性以及较高的安全性和灵活性,在EAD的部署中得到广泛的应用。本文详细阐述了802.1x的接入认证在EAD中的应用。文中首先论述了网络安全的现状,传统网络安全的技术措施,包括防火墙技术、入侵检测技术、反病毒技术、VPN(Virtual Private Network)技术。接着深入研究端点准入方案的技术实现,包括EAD组成部件、EAD接入控制和原理、EAD报文交互协议。再接着论述802.1x在EAD中的应用,详细阐述了802.1x的认证细节与EAD有机的结合。最后,结合在H3C北京研究所的实际EAD部署方案,进一步说明EAD在大型企业中的实际应用。本论文所研究的端点准入防御解决方案,在安全客户端、安全联动设备、安全策略服务器、第三方服务器的整合联动下,可以有效整合孤立的单点防御系统,对用户进行的集中管理,实施统一的企业安全策略,从而提高了网络终端的主动抵抗网络安全威胁的能力。

【Abstract】 With the rapid development of network economy, network security has become aglobal problem. In recent years, more and more organizations and individuals thatconnect with the Internet become a point of attack frequently. Most of the networksecurity events are due to the fragility of the user terminal and uncontrolled use ofnetwork behavior. For example, not timely update the virus database, for the visitinguser’s control lack of necessary means, illegal users connect the internal network forillegal access. Traditional network security measures can not effectively defend againstsecurity threats from the enterprise inside.The endpoint admission defense for theenterprise network provides a solid security system, thereby improving the security androbustness of network.The access authentication technology is the carrier of EAD implementation,andaccess authentication technology including the802.1x certification, PORTALcertification, L2TP, The802.1x is a port based access control mechanism. Because ofthe low cost, good expansibility and high security and flexibility of the mechanism, ithas been widely applied in the deployment of EAD. This paper describes the802.1xaccess authentication application in EAD.This paper firstly introduces the current situation of network security, thetraditional network security technology measures, including the firewall technology,intrusion detection technology, VPN technology,and then thorough researchings EADtechnology including the EAD component, EAD access control and principle, EADmessage exchange protocol. Next this paper discusses802.1x application in EAD.Describes the802.1x authentication details and EAD organic combination. Finally, Incombined with the actual EAD in H3C of BeiJing Institute deployment scenarios,further description of EAD in the large enterprise application is given.This paper introduces the EAD solution. It can effectively integrate isolated singlepoint defense systems, strengthen the user’s centralized management, unifyimplementation of the enterprise security strategy and improve the network terminalactive resistance.

  • 【网络出版投稿人】 重庆大学
  • 【网络出版年期】2013年 03期
  • 【分类号】TP393.08
  • 【被引频次】3
  • 【下载频次】140
节点文献中: