节点文献
企事业单位内部网络终端安全系统设计与实现
Design And Implementation of The Enterprises Intranet Network Terminal Security System
【作者】 刘辉;
【作者基本信息】 电子科技大学 , 电子与通信工程(专业学位), 2014, 硕士
【摘要】 随着现代互联网技术的不断革新和消费者市场需求的推动,计算机的应用越来越广泛,企业内部网的使用提高了办公效率,使企业内部沟通及与外部的沟通都变的更为便捷。但是,内部网带来办公优势的同时,也带来了前所未有的风险。各种信息的泄露、终端的安全攻击等等,也能使企业蒙受严重的损失。终端桌面安全管理技术的发展,从不同程度上满足了企事业单位IT办公安全性的需求,但是终端桌面安全管理技术并没有一个统一的标准,安全产品及厂商提供的服务种类多,质量参差不齐。所以,如何完善企事业内部的网络终端安全,仍是一个值得深入研究的课题。本文就是基于此背景,来研究企事业内部网络终端安全框架的设计、实施及改进方案。论文的主要研究内容如下:(1)介绍目前企事业单位存在的安全性威胁,主要包括终端自身安全漏洞,移动存储介质威胁等等。(2)针对以上威胁,搜集目前典型应对策略,并对现在的终端安全系统进行了深入的分析,在此基础上设计了安全系统的总体框架,并对本文使用的设计原理进行了详细的介绍,重点阐述了系统的设计、部署、配置及安全评估标准。(3)对于提出的安全系统,提出了测试标准及测试方法,并对此安全系统进行了功能测试和性能测试。本文主要创新点是在前文研究的基础上,提出了通过个人终端管理和移动存储介质管理对终端进行综合管理的方法:(1)个人终端管理在没有终端安全管理系统的环境中,存在一系列问题,例如IP地址更改、内部文件遭窃、病毒感染等,通过个人终端管理的方法可以解决上述问题,这样既提高管理效率又降低管理成本。(2)移动存储介质管理利用访问控制、审计等技术手段对移动存储介质进行安全防护,未授权介质到单位内部无法使用,单位的授权介质拿出去无法使用,未经授权的人员打不开授权介质中的文件,并且对任何操作都进行记录和管理,对于违规操作可以进行跟踪和审计。
【Abstract】 With the development of the modern internet technology and the promote of the consumer demand, the computer is used more widely. In order to improve office efficiency, the Intranet is used in many places, which makes the communication inside and outside becoming more convenient. However, with the advantages the internal office network brings, the unprecedented risk is also brought.The development of the terminal desktop security management technology can meets the enterprises IT security requirements of the office a certain extent. But the terminal desktop security management technology does not have a uniform standard, and the types of security product and service provided by multiple vendors with varying quality. So, how to improve the network security inside enterprises is still a topic worthy of further studying.Based on the backgroud, this article is going to study the design and implementation for enterprises of the internal network terminal security framework.The main contents are as follows:(1) Introduced the security threats in the current enterprises and institutions, including the terminal’s own vulnerabilities, threats of removable storage media and so on.(2)For the threats in front, collected the current typical coping strategies and analyzed the terminal security system deeply. Base on the search, the overall framework of security system is designed.(3) For the security system proposed before, proposed testing standards and testing methods, and executed the functional testing and performance testing of the safety system.The main innovation of this thesis is that proposed approach of terminal management and removable storage media management terminal integrated management, based on the previous study.(1) The management of personal terminalThere are a series of problems in the system with no terminal safety management, such as changes of IP address, and stealing of internal documents, and infection of virus, etc. All the problems can be solved efficiently by using personal terminal management approach.(2) Management of removable storage mediaUsing access controlling and auditing technical to make the removable storage media safety, the unauthorized media cannot be used in the enterprise and the files in the authorized media cannot be opened by unauthorized man out of the enterprise. Every operation on media will be recorded and managed and the illegal operations can be tracked and audited.
【Key words】 enterprises intranet; terminal security; removable storage media; firewall;
- 【网络出版投稿人】 电子科技大学 【网络出版年期】2016年 03期
- 【分类号】TP393.08
- 【被引频次】2
- 【下载频次】90