透過您的圖書館登入
IP:18.223.211.185
  • 學位論文

使用Security Gateway之雲端安全架構設計

Design the Cloud Security Architecture Using Security Gateway

指導教授 : 曾嘉影
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


近來雲端運算之盛行,生活中、工作上各式的裝置皆與雲端連上關係,但是許多人卻誤以為現在人人所稱的雲端運算即是虛擬化,其實這是錯誤的,雲端運算不等於虛擬化,但是虛擬化技術卻提供了現成的資源共享的平台,因此許多企業開始考量虛擬化的平台的導入與應用,一方面為了節省成本,一方面為了包裝自己產品與雲端連上關係,但許多以往在實體的主機上可能見到的資訊安全問題,例如:惡意程式、殭屍電腦、阻斷式攻擊、社交攻擊、跳板攻擊、SSL漏洞…等,在虛擬平台上卻依舊存在,並未隨著虛擬化而減少,且今日的虛擬化平台遇到了更多新的資訊安全問題,例如:虛擬平台自身的弱點、共享資源的風險、跨虛擬主機的攻擊…等。因此,如何避免與解決在虛擬平台中資訊安全的問題,便成了一項重要的課題。在本論文中,我們利用了Snort之技術,建立一個Security Gateway,負責在虛擬平台中監控資料流的安全性,並適時的結合Iptables的功能進而對攻擊行為進行阻擋,以確保虛擬平台的安全性,利用最精簡的成本,達到較高的資安效益。

關鍵字

Snort 資訊安全 虛擬化 雲端運算 雲端

並列摘要


Recently, with cloud computing becoming popular, various cloud computing equipment are widely used either in our life or on the work. However, a lot of people have wrong impression that cloud computing is equal to virtualization. Actually, virtualization can provide a platform for resource sharing. Hence, more and more companies consider to introduce the virtualization platform to various applications. The companies not only can save money but also link their products to virtualization. Although cloud computing has many benefit on resource sharing, it still has some security issues as physical, such as Malware, zombie computers, blocking attacks, social attack, a springboard for attacks, SSL vulnerabilities, and etc.. Cloud computing even encounter more new security issues, such as the risk of virtual platform for the existing weaknesses and sharing of resources across virtual hosts attack, and etc. Therefore, it is very important and urgent to provide a method that can improve security on virtual platforms. Here, we provide Snort technology, which sets up a security gateway in virtual platforms. This gateway can monitor data flow security on virtual platforms and combines Iptables to avoid any attacks. The highly efficient security with low cost can be achieved by this new method.

並列關鍵字

Snort Security Gateway Virtualization Cloud Computing Cloud

參考文獻


[5] IBM CP-40, Retrieved March 9, 2012, from
[13] 陳永昇,Introduction to Linux Netfilter補充資料,Redhat Linux 技術應用系列研討會,2002
[16] Snort, Retrieved March 9, 2012, from http://www.snort.org
[17] 胡志凱,雲端運算中動態調整虛擬機器運算資源機制,大同大學,2010
[18] Cent OS, Retrieved March 9, 2012, from http://www.centos.org

延伸閱讀