论文部分内容阅读
为了解决内网信息泄露问题,提出一种新的内网安全策略。该策略有2个特点:一是采用层次化的手段对信息进行分级;二是引入了监控器这个部件,监控器对内网各网络部件之间的通信过程实行控制,动态地隔离涉密的主机。新的安全策略在保障信息安全的前提下,有效地提高了资源使用效率。基于该策略设计了一种基于Intel IXP2400芯片的监视器系统。实验结果表明,凭借IXP2400芯片的强大处理能力,该监检测系统可以高效地处理Gb/s速率的网络数据流。
In order to solve the problem of intranet information leakage, a new intranet security policy is proposed. The strategy has two characteristics: First, the use of hierarchical means to grade the information; the second is the introduction of this part of the monitor, the monitor on the network between the various network components of the communication process control, dynamic isolation of confidential Host. Under the premise of ensuring information security, the new security strategy effectively improves the efficiency of resource utilization. Based on this strategy, a monitor system based on Intel IXP2400 chip is designed. The experimental results show that with the IXP2400 chip’s powerful processing capabilities, the monitoring system can efficiently process network data streams at Gb / s rates.