摘要
为了利用虚拟机技术建立满足《信息系统安全等级保护基本要求GB/T 22239-2008》要求的信息系统网络结构,首先分析了虚拟机的六大安全风险,然后提出了一个管理中心一个物理资源池多个虚拟安全域、一个管理中心多个物理资源池多个虚拟安全域和多个管理中心多个物理资源池多个虚拟安全域等三种虚拟机部署模式,最后以信息系统的Web服务器、应用服务器和数据库服务器部署的安全域为主要因素,提出了基于这三种虚拟机部署模式的信息系统部署架构。这三种部署架构分别满足等级保护一、二、三级的结构安全要求。
In order to establish information system network structure satisfying "Information System Security Level Protection basic Demands(GB/T 22239-2008)" with virtual machine(VM), the six kinds of safety risk in VM are analyzed first. Then three VM deployment models are proposed, such as one management center(MC) one physical resource pool(PRP) multiple virtual safety domains(VSD), one MC multiple PRPs multiple VSDs, and multiple MCs multiple PRPs multiple VSDs. Finally, on the basis of the three VM deployment models, information system deployment architectures are presented in consideration of the safety domains of Web server, application server and database server. The three deployment architectures are respectively satisfied with the structure safety demands about the first level, the second level and the third level.
出处
《微型机与应用》
2015年第3期11-14,共4页
Microcomputer & Its Applications
关键词
虚拟机
安全域
信息系统
等级保护
结构安全
virtual machine
safety domain
information system
level protection
structure safety