摘要
网络拓扑的安全性是保障网络服务安全的核心研究内容;尤其在虚拟私有网络(VPN:Virtual Private Network)拓扑中,由于VPN的隧道技术、私有路由技术和加密技术,一方面使得内部服务群暴露在Internet中,另一方面增加防火墙和入侵检测系统(IDS:Intrusion Detection System)保护内部网络的难度。为此,本文提出以VPN网关为中心,协同用户终端、防火墙、IDS和内部的应用服务,构建的多层安全防护机制--关联控制机制(CCM:Correlative Control Mechanism)。CCM将终端延伸、IDS关联和应用引擎三者关联,使得VPN防护构成一个关联整体,提高了网络拓扑的安全性。
The research of the security of the network topology is the core content for the guarantee for the security of the network services. Especially in the VPN(Virtual Private Network)topology, because of the VPN's tunneling, private routing and cipher technology, there are two embarrassments for the protection of the internal network. One is the internal services could be uncovered in the internet by the VPN's tunneling, the other is firewall and IDS(Intrusion Detection System)could not completely analyze the network packet content because of the VPN's private routing and cipher technology. Hence, we propose CCM(Correlative Control Mechanism)that is a multilayered security protection mechanism based on VPN gateway incorporating client end-point, firewall, IDS and internal services. By the correlation among terminal-extending, IDS-correlation and application-engine, CCM can make the VPN protection into one correlative whole and improve the security of the VPN topology.
出处
《计算机科学》
CSCD
北大核心
2007年第1期39-41,152,共4页
Computer Science
基金
国家自然科学基金
编号60373088
关键词
虚拟私有网络
关联控制机制
多层安全防护
Virtual private network, Correlative control mechanism, Multilayered security protection