防火墙策略配置审计系统审计方案的分析与设计

来源 :北京邮电大学 | 被引量 : 4次 | 上传用户:qzyss
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Along with the proliferation of Internet and network application system, sorts of network intrusions and attacks have emerged, severely impacting the normal operation of the system. As an access control mechanism deployed between two separate networks, firewall is able to guarantee the reliable data flow to pass through and decline the unreliable one, in purpose of preventing from illegal visits.Firewall, as an indispensable network protection tool, is extensively deployed in different network application scenarios. Network Address Translation (NAT) and Access Control List (ACL) strategies, as the core policies in firewall, are conferred the responsibilities of intranet-protection as well as the address-multiplexing. However, the situations of configuration-disorder and efficiency-declination are triggered by the lack of uniform firewall configuration management and auditing, greatly threating the network security status for which this firewall is responsible.Due to the above several aspects of threats, auditing the configurations of firewall strategies is of significance in implementing network security check. The audit process can be divided into those following steps:firstly, analyzing configuration files of firewalls; then, filtering the items with flaws and deficiencies; finally, checking the connectivity of network. The above process is the key to keep target system operating securely.On the basis of firewall configuration information and the theoretic model of firewall configuration audit scheme, this paper designs and proposes the audit scheme for Cisco, Huawei and Juniper firewalls. This scheme can implement audit works for these three types of firewalls, and then exhibit the audit results which can be a reference for security engineers deploying the network security check.This paper has conducted the works as following:Firstly, in terms of Cisco ASA firewall, auditing rules and corresponding auditing methods are proposed on the basis of NAT policy analysis; Moreover, NAT substitution and comparison algorithms are raised. Predicated with all above, a scheme aiming at auditing the NAT policies of Cisco Firewall are designed.Secondly, as to Huawei Eudemon and Juniper SRX firewalls, auditing rules and corresponding auditing methods are proposed on the basis of ACL policy analysis. Schemes aiming at auditing the ACL policies of Huawei and Juniper Firewalls are designed respectively.Finally, according to the designs of auditing schemes catering for three types of firewalls, this paper conducts feasibility analysis. By adopting the analysis, these schemes are able to provide theoretical supports for later research and development of firewall policy auditing systems.
其他文献
今年11月7日是人民教育家陶行知先生创办的育才学校65周年大庆。我离开母校——重庆市育才中学校(当时叫重庆市第二十中学校1已经44年了,当时我不到十六岁。虽然事隔久远,但在
文章基于2019年新三板公司的年报数据,对其中的环保公司相关数据展开分析,结果显示:新三板环保公司2019年总体景气表现不及2018年。
在全球饱受疫情之苦的2020年,中国家电行业一年一度的最高技术盛会依旧如约而至。10月29~30日,2020年中国家用电器技术大会在浙江宁波召开。这场家电行业年度技术盛会的热度,
1981年10月31日下午,刚恢复育才校名的原重庆市20中学师生,热烈欢迎育才学校第一任音乐组主任、著名音乐家贺绿汀老师回母校参观。
嗅觉系统在昆虫生存生活中起着至关重要的作用,而离子型受体(Ionotropic Receptors,IRs)是昆虫嗅觉系统中重要的受体之一。IRs是一类古老而且保守的受体,参与昆虫识别酸、胺
循环冷却水系统一般由冷却塔、循环水池、循环泵、水质处理设施及相应管道阀门组成。对冷却塔性能标准及其选型、循环冷却水系统布置、循环冷却水处理方式及加药系统进行了论
针对农村信息服务资源建设滞后,农民利用信息的能力不强,农业专业技术水平参差不齐等问题,结合微信平台与微视频的优势,应用HTML5移动开发技术,设计开发一款基于微信平台的农
我是龚九宏,是武钢有限焦化公司机械技能大师,先后荣获“全国五一劳动奖章”、央企劳模、央企优秀党员、武汉工匠等荣誉称号。针对生产难题,我开发实用新型专利,获得了31项国
社会的变迁对言语文明造成了巨大的影响,苏联的解体使俄语的言语文明出现了一些新特点,一方面在一定程度上促进了俄语言语文明的发展,给俄语带来了新的活力,另一方面社会的变迁也
以上海昌平路既有建筑为例,通过建筑工业化的建造方式,探索适合于我国既有建筑围护结构改造的新模式。在设计阶段,将建筑外立面装饰效果与使用功能综合考虑,并结合现场实际情