透過您的圖書館登入
IP:3.16.70.101
  • 會議論文
  • OpenAccess

伺服器防火牆維運管理之研究

摘要


防火牆(Firewall)為維護網路安全的第一道防線,多設置於內、外網的閘口,以當今的設備功能大致已具備基本的防護能力,面對層出不窮的網路威脅,僅仰賴單一閘口式防火牆,已無法完全阻擋複雜多變的攻擊行為,需運用縱深防禦機制始能有效防護,在這種架構下,伺服器防火牆應用日趨廣泛,但相對地,因為防火牆數量增加,若缺乏完善的管控措施,將造成管理人員的困擾,市面上雖有推出之可集中控管防火牆之管理系統,惟無法全面納管該類設備,形成資安管理的困擾,本研究透過自行開發Linux伺服器防火牆管理系統,以集中管控設備及規則,期望應用在縱深防禦架構中,有助於資安維護工作。實證研究後發現,確實可透過自行開發的管理系統,達成伺服器防火牆設備管理、規則派送、快速備份還原的要求,可應用在縱深防禦的資安架構,集中管理伺服器防火牆,加速及簡化管理效能,透過管理系統執行政策派送及設定,簡化原有的設定方式,減低管理人員的負擔。

並列摘要


Firewall is the first line of defense for network security. It is commonly installed as the gateway between the internal and external networks. It can provide basic protection for the devices in the internal network. However, as the network threats continue to grow exponentially, relying on a single firewall is no longer enough. Single firewall cannot completely block today's complex and diversify attacks for all devices in the inside network, the defense-in-depth mechanism shall be applied to effectively protect each individual device. Therefore, to enhance the security level, most of the server managers will activate the server host-based firewall. If the number of servers is large, to manage the firewall rules on each individual server will be quite difficult without a centralized management facility. Although there are management systems that can centrally manage most of the commercial firewalls, they are generally not able to manage those host-based firewalls of servers. This study develops a server firewall management system that can centrally manage the internal firewall for Linux servers. The developed server firewall management system can perform rule setup, delivery, backup, and restore. It can effectively fit in the defense-oriented security architecture and centrally manage the server firewalls. With this system, it can greatly reduce the burden of managers.

延伸閱讀