论文部分内容阅读
随着计算机网络技术的迅猛发展和Internet/Intranet用户数量的激增,以及新型网络服务的研究、实施和应用,计算机网络安全问题日益突出。使得计算机安全问题成为影响计算机互连网络进一步发展的一个重要因素。以往采用的安全保护中使用最多的是传统的防火墙机制,可是随着网络技术的不断发展,传统的防火墙已经逐渐不能,满足安全的需要。本文针对传统防火墙所带来的问题,提出了一种基于Kerberos认证的分布式防火墙的新型体系结构,在保留传统防火墙优点的基础上,以Kerberos协议为主要基础,综合网络安全软件算法合理运用防火墙相关知识,实现内部网安全分布式防火墙系统,解决了传统防火墙的安全隐患。为众多内部网络用户的需要重点保护的网络资源提供一个可管理的、分布式的安全网络环境。
With the rapid development of computer network technology and the surge of Internet / Intranet users, as well as the research, implementation and application of new network services, the problem of computer network security has become increasingly prominent. Making computer security an issue that has an impact on the further development of computer interconnection networks. In the past, the most widely used security protection was the traditional firewall mechanism. However, with the continuous development of network technology, the traditional firewall has gradually failed to meet the needs of security. Aiming at the problems brought by traditional firewalls, this paper proposes a new architecture of distributed firewall based on Kerberos authentication. Based on the advantages of traditional firewalls and Kerberos protocol, this paper synthesizes network security software algorithms to make rational use of firewalls Related knowledge, to achieve internal network security distributed firewall system, to solve the security risks of the traditional firewall. For many internal network users need to focus on the protection of network resources to provide a managed, distributed security network environment.