计算机应用 ›› 2009, Vol. 29 ›› Issue (09): 2315-2318.

• 信息安全 •    下一篇

网络安全组件协同操作研究

杨宏宇1,邓强2,谢丽霞3   

  1. 1. 中国民航大学
    2. 中国民航大学计算机学院
    3. 中国民航大学 计算机学院
  • 收稿日期:2009-03-30 修回日期:2009-05-14 发布日期:2009-11-10 出版日期:2009-09-01
  • 通讯作者: 杨宏宇
  • 基金资助:
    国家863计划项目重点课题(2006AA12A106);国家自然科学基金资助项目(60776807);天津市科技支撑计划重点项目(07ZCKFGX01700);民航科技基金项目(RKXZY0814);国家级基金;省部级基金;校级基金

Research on collaborative operation of network security components

  • Received:2009-03-30 Revised:2009-05-14 Online:2009-11-10 Published:2009-09-01

摘要: 当前网络环境中安全组件难以实施统一的安全策略,无法充分发挥网络安全防护的整体优势。提出一种基于安全域分层思想的协同操作模型,采用三层结构、两级管理模式,以安全域作为实现功能的最小单元实现安全组件间的协同和管理。采用基于可扩展块交换协议(BEEP)框架的入侵检测交换协议(IDXP)实现对入侵检测消息交换格式(IDMEF)消息的传递。仿真实验结果表明,提出的安全协同操作模型和IDXP可以有效实现网络安全组件间的信息传输和协同操作。

关键词: 网络安全, 协同操作, 组件, 协同响应, 安全域

Abstract: Nowadays, it is very difficult for various network security components to adopt unified security policy in one network environment, which results in not fully taking advantage of the whole network protection. The authors presented a cooperative model based on security domain layer with three-layer structure and two-class management. The security domain was used as the fundamental unit to implement collaboration and management, and an Intrusion Detection Exchange Protocol (IDXP) protocol based on Blocks Extensible Exchange Protocol (BEEP) frame was implemented to transmit Intrusion Detection Message Exchange Format (IDMEF) messages. The experimental results demonstrate that this model and IDXP can effectively implement message transmission and collaborative operation.

Key words: security network, collaborative operation, component, cooperative response, security domain

中图分类号: