基于宣告式網(wǎng)絡(luò)的安全溯源技術(shù)研究
發(fā)布時間:2018-05-16 22:12
本文選題:宣告式網(wǎng)絡(luò)技術(shù) + 網(wǎng)絡(luò)溯源; 參考:《西安石油大學(xué)》2015年碩士論文
【摘要】:隨著信息化技術(shù)的飛速發(fā)展,分布式系統(tǒng)也隨之不斷改進(jìn),已經(jīng)從原先簡單的本地網(wǎng)絡(luò)到如今大規(guī)模的P2P網(wǎng)絡(luò)和云計(jì)算平臺,部署的節(jié)點(diǎn)成百上千,覆蓋多個地區(qū)和管理域。由于系統(tǒng)規(guī)模的不斷擴(kuò)大,復(fù)雜度和風(fēng)險性也日益變大,系統(tǒng)安全面臨前所未有的挑戰(zhàn)。系統(tǒng)管理者迫切需要通過可靠的網(wǎng)絡(luò)舉證技術(shù)來幫助解決故障發(fā)現(xiàn)、系統(tǒng)調(diào)試、行為問責(zé)和損害評估等問題。網(wǎng)絡(luò)溯源舉證技術(shù)就是指通過技術(shù)手段,將網(wǎng)絡(luò)狀態(tài)變化、網(wǎng)絡(luò)行為以及應(yīng)用行為等追溯到發(fā)起者,追蹤問題源頭,并為采取法律措施提供有效證據(jù)。本文敘述了項(xiàng)目的背景、意義及目標(biāo),介紹了互聯(lián)網(wǎng)發(fā)展與網(wǎng)絡(luò)安全、分布式系統(tǒng)、宣告式網(wǎng)絡(luò)以及網(wǎng)絡(luò)溯源方法等相關(guān)技術(shù),從系統(tǒng)需求分析、基于宣告式網(wǎng)絡(luò)溯源系統(tǒng)的設(shè)計(jì)和Witness系統(tǒng)實(shí)現(xiàn)幾方面對該系統(tǒng)實(shí)現(xiàn)過程進(jìn)行了詳細(xì)介紹,研究了云平臺架構(gòu)、虛擬化服務(wù)器架構(gòu)、溯源信息的查詢、維護(hù)及網(wǎng)絡(luò)安全溯源模型等問題,最后展示了控制面板、資源、分析、管理等4個模塊。Witness軟件基于Java語言開發(fā),整個軟件分為Server、Agent和Database三個部分,其中Server從Agent端獲取軟件信息列表和標(biāo)準(zhǔn)數(shù)據(jù),并保存在數(shù)據(jù)庫里,并且提供了訪問模型。軟件整體采用B/S架構(gòu),是以系統(tǒng)服務(wù)的形式工作運(yùn)行的,能很好地在Windows和Linux系統(tǒng)平臺下運(yùn)行,本軟件實(shí)際應(yīng)用在基于Windows操作系統(tǒng)的虛擬云平臺上,通過將Agent寄主安裝在云平臺上的多個代理終端上,來負(fù)責(zé)收集數(shù)據(jù)信息,通過輸入相應(yīng)網(wǎng)址進(jìn)入Witness主頁來實(shí)時觀測相關(guān)數(shù)據(jù)變化、警報生成事件和其他資源。
[Abstract]:With the rapid development of information technology, the distributed system has also been improved. From the original simple local network to the large-scale P2P network and cloud computing platform, the nodes deployed over hundreds of thousands, covering a number of regions and management domains. The system managers urgently need to help solve problems such as fault discovery, system debugging, behavior accountability and damage assessment through reliable network proof technology. Network tracing technology means tracing the change of network state, network behavior and application behavior to the initiator through technical means. Tracing the source of the problem and providing effective evidence for legal measures. This paper describes the background, significance and objectives of the project. It introduces the related technologies of Internet development and network security, distributed system, declarative network and network tracing method, from system requirement analysis, design and Witness system based on declarative network traceability system. The realization process of the system is introduced in detail, and the problems of cloud platform architecture, virtual server architecture, traceability information query, maintenance and network security traceability model are studied. At last, the 4 modules of.Witness software are developed based on the Java language, such as control panel, resource, analysis and management, and the whole software is divided into Server, Agent and Database three parts, in which Server obtains the software information list and standard data from the Agent side, and saves it in the database, and provides the access model. The software uses B/S architecture as a whole and runs in the form of system service. It can run well under the Windows and Linux system platform. This software is actually applied to W based on W. On the virtual cloud platform of the indows operating system, by installing the Agent host on multiple proxy terminals on the cloud platform, it is responsible for collecting data information and entering the Witness home page by entering the corresponding URL to observe the change of the related data in real time, the alarm generation and other resources.
【學(xué)位授予單位】:西安石油大學(xué)
【學(xué)位級別】:碩士
【學(xué)位授予年份】:2015
【分類號】:TP393.08
【參考文獻(xiàn)】
相關(guān)期刊論文 前7條
1 肖軍;云曉春;張永錚;;隨機(jī)偽造源地址分布式拒絕服務(wù)攻擊過濾[J];軟件學(xué)報;2011年10期
2 楊坤;楊庚;;關(guān)于無線傳感器網(wǎng)絡(luò)中溯源方法的分析[J];計(jì)算機(jī)技術(shù)與發(fā)展;2011年07期
3 費(fèi)洪曉;李文興;覃思明;李欽秀;;一種動-靜態(tài)結(jié)合的概率包標(biāo)記IP追蹤方案[J];計(jì)算機(jī)工程與應(yīng)用;2011年09期
4 荊一楠;王雪平;肖曉春;張根度;;一種無日志的快速DDoS攻擊路徑追蹤算法[J];小型微型計(jì)算機(jī)系統(tǒng);2007年09期
5 閆巧,吳建平,江勇;網(wǎng)絡(luò)攻擊源追蹤技術(shù)的分類和展望[J];清華大學(xué)學(xué)報(自然科學(xué)版);2005年04期
6 丁麗萍,王永吉;計(jì)算機(jī)取證的相關(guān)法律技術(shù)問題研究[J];軟件學(xué)報;2005年02期
7 李強(qiáng);汪仲謙;周富成;;DDoS攻擊的分析與對策[J];軍事通信技術(shù);2002年02期
,本文編號:1898629
本文鏈接:http://sikaile.net/guanlilunwen/ydhl/1898629.html
最近更新
教材專著