节点文献

基于沙箱技术的网络虚拟化实现

Implementation of Network Virtualization Based on Sandbox Technology

【作者】 吴旭

【导师】 龙涛;

【作者基本信息】 华中科技大学 , 计算机技术, 2012, 硕士

【摘要】 随着社交网络化、电子政务化和电子商务化的逐步推广,复杂的网络环境和信息总量的爆炸增长无形中给内网安全带来了严峻的挑战。在内部网络中,通常用户在工作中访问下载安全域中的网络资源,其中包含各类不同密级的文档和敏感信息。这些敏感信息通常缺乏有效管理手段混杂存储在用户计算机中,不利于数据数据分类存储与保密,还可能给内网信息保密带来潜在风险。同时,网络协议潜在的安全漏洞也给安全的网络通信添加了麻烦。为解决以上问题,提出了一种基于沙箱技术的内网安全访问终端的思路。借助沙箱的隔离特性,构造一个虚拟环境访问网络资源。利用虚拟网卡和文件系统透明加密技术实现端到端的信息安全传输与分类存储。针对网络环境虚拟化方案做了较为深入的探索,其中使用虚拟网卡技术实现加密隧道来保证安全的网络通信,用户通过直接访问或者远程接入的方式安全访问内部资源,并结合统一用户认证针对内部网络中的应用系统用户提供统一的身份鉴别和通信密钥管理。加强对内部网络的用户统一管理,为用户通信分配会话密钥。参照SSL(Secure Sockets Layer)和OpenVPN(Open Virtual Private Network)通信协议针对本方案定制了通信协议,提高了用户终端对内部网络资源访问的安全性。最后,通过对方案的设计实现和总体的测试,对系统性能做了分析,最后针对提出了一些改进措施。

【Abstract】 With the gradual promotion of persocial web, e-government&e-commerce, complexnetwork environment and explosive growth of the amount of information virtually give aserious challenge to the internal network security.In the interal network, people often need to download the resources which contain allkinds of different security classification of documents and sensitive information from thesecurity domain. The sensitive information is often lack of effective manage and mixedstored in the user’s computer. It is not conducive to the data classification storage andconfidentiality; it can also add potential risk to interal network information confidential.Potential security vulnerabilities of network protocol also add trouble to secure networkcommunications.To solve the above problems, we present an idea which interal network secureterminal based sandbox technology. With the isolation characteristics of thesandbox, wecould construct a virtual environment to access network resources. With virtual NetworkInterface Card and transparent file system encryption technology, we could achieveend-to-end secure transmission of information and the classification storage of sensitiveinformation. We focused on the network virtualization exploration.We use the virtualNetwork Interface Card encrypted tunnel to ensure securenetwork communications; itallows user access to internal resources through direct access or remote access security.Combined with Unified-authentication technology, our systems provide a unified-authentication and communication key management for internal users. To strengthen theunified management on the internal network, users are allocated for user communicationsession keys.According to the Secure Sockets Layer&Open Virtual Private Networkcommunication protocol, we customize the communicate protocol for the systemt toimprove the security of the user terminal to access internal network resources.Finally, across the design and implementation of the program and the overall test, wepropose some improvements about system performance.

  • 【分类号】TP393.08
  • 【被引频次】8
  • 【下载频次】351
节点文献中: