节点文献

基于CSCW的内网安全审计系统应用研究

The Application and Research of Intranet Security Audit System Based on CSCW

【作者】 陈柏兴

【导师】 傅秀芬;

【作者基本信息】 广东工业大学 , 计算机应用技术, 2008, 硕士

【摘要】 随着网络的快速发展和计算机的普及,网络已成为社会运行和国家发展的必备基础设施,网络安全问题已经不容忽视。人们不断研发新的技术以保障网络安全,如:认证加密、防病毒、防火墙和入侵检测系统等技术。然而根据各方的数据统计:五成以上的网络攻击事件源于网络内部。要想从根本上杜绝恶性攻击事件的发生,必须首先强化企业内部网的安全防范与安全管理。内网安全是目前网络安全领域的研究热点,内网安全审计系统随之诞生和发展。基于传统的内网安全审计系统只专注于对审计策略的定制、用户行为的监控、各种审计日志的管理、告警行为的处理等,审计的控制中心往往是孤立地工作,有时候单凭个人的经验,对审计策略的定制可能准确性不高、针对性不强,对目前内网的安全隐患不能作出及时的反应和察觉。当审计的客户机数目比较庞大时,控制中心很可能会因不堪重荷而无法正常工作。现阶段几乎每项工作的完成都是许多人智慧的共同结晶,因此协同工作在当今社会变得日益重要。利用协同工作提高整个内网安全审计的效率,使具有多个控制中心的内网安全审计系统能够协同工作,是解决上述问题的关键。负载均衡提供了一种廉价有效的扩展服务器带宽和增加吞吐量,加强网络数据处理能力,提高网络的灵活性和可用性的方法。可行有效的负载均衡能为系统构造一个良好的协同工作环境。论文分析了当前的内网安全审计系统,针对现有内网安全审计系统协同性的不足,详细探讨了内网安全审计系统与CSCW相结合的可能性,研究了内网安全审计系统的协同工作可能带来的问题,以及CSCW环境下内网安全审计系统的新特性,在现有负载均衡算法的基础上,提出了基于可拓模糊理论的负载均衡算法,构建了一个协同环境,设计了一个基于CSCW的内网安全审计系统。该系统以通信机制作为协同工作的基础,以Agent作为协同工作的单元,把协同和控制中心相结合。本文结合相关的关键技术和编程技巧,实现了系统原型的核心模块,解决了安全审计系统中控制中心不能协同工作的问题。最后总结了本文的研究工作,指出了下一步的研究方向。

【Abstract】 With the rapid development of Internet and the popularity of computer, network has become the necessary infrastructure of social and national development. The network security problems can not to be ignored. People take a variety of measures to protect network security, such as Authenticated Encryption, Anti-Virus, Firewall, Intrusion Detection System and other technology. However, more than 50 percents of network attacks originate from Intranet in accordance with the statistics. To fundamentally eliminate the vicious attacks, we must strengthen the security guard and security management of Intranet at first.Intranet security is the hotspot of research on network security, following it, the Intranet security audit system has produced and developed. But the traditional Intranet security audit systems only focus on customizing the audit strategy, monitoring the user behaviors, managing various audit logs and handling the warning behaviors. Usually the control center of audit works in isolation, if only use the personal experience to customize the audit strategy , the accuracy is not high, the pertinence is not strong and it can not make the in-time response and detection to the network security risks. If the number of the audit clients is too big, the load is likely to be too heavy and so that the control centre can not work properly.At this stage, the completion of each work is the wisdom crystallization of many people. So teamwork is becoming increasingly important in today’s society. Use cooperative work to improve the efficiency of the Intranet security audit, so that the Intranet security audit system with a number of control centers can work collaboratively, which is the key to solve the problem. Load balancing provides a cheap and effective capacity to expand the bandwidth and throughput of servers, enhance network’s data processing capacity and improve network’s flexibility as well as the number of availability methods. Feasible and effective load balancing system can construct a good collaborative work environment.This paper analyses current Intranet security audit systems, focuses on the disadvantage of existing Intranet security audit system in the collaboration, discusses the combinability between Intranet security audit system and CSCW, studies the potential problems in the cooperative work and the new characteristics in the Intranet security audit system based on CSCW, and then based on existing load balancing algorithmic, brings forward a new load balancing algorithmic based on extension theory, structures a cooperative environmet and designs a Intranet security audit system based on CSCW. The cooperative work of the system base on message communication mechanism and Agent. The paper combines the key technologies and programming skills, implements the core modules of the system. It solves the collaboration in the control center of Intranet security audit system. At the end, the paper summarizes the research and presents the next research.

  • 【分类号】TP393.08
  • 【被引频次】2
  • 【下载频次】108
节点文献中: 

本文链接的文献网络图示:

本文的引文网络