节点文献

防火墙实验系统日志管理与规则优化研究

Reseach on Log Management and Rule Optimzation in Experiment Firewall System

【作者】 杨奕

【导师】 杨树堂;

【作者基本信息】 上海交通大学 , 通信与信息系统, 2008, 硕士

【摘要】 随着计算机网络技术的飞速发展,社会生活信息化的程度不断提高。人们通过互联网越来越容易获取需要的信息,但同时也带来了信息丢失、泄漏等安全问题。提高信息传递的安全等级是解决问题的途径之一,同样不可忽略的是针对用户的计算机网络与信息安全技术的学习、培训和实践。目前虽然网络保护技术中的传统防火墙技术已经发展得比较成熟,但是用于教学实验的防火墙系统基本仍是处于起步阶段。受国家863计划资助,新近的研究成果支持多用户并发控制的防火墙教学实验系统,也正式填补该领域的空白,但是其本身的日志管理系统和其规则匹配速度缺陷对系统仍造成一定的性能问题。本文正是为了对该防火墙教学实验系统进行完善工作,对其薄弱技术环节进行研究和改进。其中重点正是日志管理技术与规则优化。本文首先分析了教学实验特点,防火墙功能特点,并结合这些特点分析了防火墙教学实验系统的特点,并针对此设计了实验系统的实现框架,并对各种实现关键技术进行了探讨。接着文章介绍了防火墙教学实验系统中的大规模并发控制技术,从根本上探讨了防火墙教学系统与一般防火墙在规则上的不同之处。再接着文章教学系统特点设计和实现防火墙教学系统中的日志管理模块,解决了原系统中的日志访问无法统一管理和访问效率低下的问题。最后,基于对日志管理系统的应用,文章对防火墙规则优化问题进行了研究,并通过实验结果证明了其对防火墙规则的优化结果。文章中研究的算法和技术有效地解决防火墙实验教学系统中日志管理和运行效率的诸多问题等,提高了了整个系统的运行效率,从而为一个支持多用户并发控制的防火墙教学实验系统的完整实现扫清了诸多障碍。

【Abstract】 With the development of computer network and information technology, it is more convenient to get access to Internet so as the data transmission. The fact also should not be ignored is that people are facing the dangers of their privacy leaking, virus threating and hacker’s attacking when they connect to Internet. On one hand, the information security level has to be improved; on the other hand, we should learn something about computer network and information security technology. So, today, more researchers are working on how to providing a platform for these technologies’learning, training and practising.Though, among the current network protection technologies, the tranditional firewall technology is retlatively developped, the experiment firewall system which is for educational experiment is still in developing phase. The newly reseach achievement, multi-user concurrent control supported experiment firewall system, sponosored by national 863 project, fills this gap. And this paper is aimed at research and improvement of the weakness of the experiment firewall system in order to perfect this system. The improvement focuses on log management technology and firewall rules optimization.At the beginning, this paper analyzes the features of educational experiment and firewall function. Based on these features, we analyze the traits of experiment firewall system, design the framework of the system, and discuss the key technologies for the implementation. After that, this paper introduces the multi-user concurrent technology in the experiment firewall system to discuss the basic differences between tranditional firewall and experiment firewall system. Further more, this paper designs and implements the universal log management module of the experiment system, thus solving the problem of difficult universal management and low efficiency in the original log management. At last, based on the universal log management system’s usage, this paper does reseahces on the firewall rules’optimization to improve the experiment firewall system’s performance. The prositive result of performance improvmenet by this technology is proved by experiments.The algorithm and techonologies in this paper effectively improve the expereiment firewall system’s log management and rules matching performance, thus improving the overall performance of the system and helping perfect the multi-user concurrent control supported experiment firewall system.

  • 【分类号】TP393.08
  • 【被引频次】4
  • 【下载频次】184
节点文献中: 

本文链接的文献网络图示:

本文的引文网络