透過您的圖書館登入
IP:18.216.124.8
  • 學位論文

基於目錄服務之側接式網路存取控制

Directory Service Based Out-of-band Network Access Control

指導教授 : 方鄒昭聰
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


現代組織已和資訊系統密不可分,組織需依賴資訊系統來實現其業務功能。隨著資訊化程度與組織規模的增長,我們已無法輕忽資訊安全漏洞所造成的損失,針對應用層控管及人員驗證的需求,網路存取控制開始被業界提出討論。Windows Server 2008系列產品中,微軟針對網路存取控制提出了NAP(Network Access Protection)方案,而Cisco也提出了NAC(Network Admission Control)方案。這些方案有其優點,亦有其不足。因此本研究開發一套DONAC網路存取控制系統,利用了目錄服務得到完整的使用者驗證功能,並利用了乙太網路的特性,使用側接設備達成網路阻隔的效果,可即時監控網域內之所有主機與使用者行為並產生使用行為記錄,具擴充彈性之政策管理機制,可針對目前所採取之資訊安全政策實行各種管理政策並可整合外部管理政策使用,當發生違反管理政策之異常使用行為時,系統將會即時阻斷該主機與限制該使用者之網路存取能力。在系統架構變動彈性、政策管理機制擴充性、資訊完整度、系統導入變動成本、設備成本等方面改善了既有的網路存取控制解決方案。經由實際測試,本研究中實作之DONAC系統,能有效控制所管理網域內所有被監控之主機設備其網路存取。不符合管理政策之主機或使用者皆會立即被阻斷其網路存取,有效達成網路存取控制的目標。

並列摘要


Network Applications is necessary nowadays. Network Management and security issues in the organization become more and more important. Modern organization and information systems have been inseparable. Organizations achieve their business process depending on the information systems. As the degree of information and the scale of the organizations increase, we cannot overlook the loss caused by the information security vulnerabilities. Focus on the requirement of application-layer controlling and user certifying, NAC (Network Access Control) begin to be discussed. Microsoft proposed a NAC solution called NAP (Network Access Protection) in Windows Server 2008, and Cisco also proposed a solution named NAC (Network Admission Control). These solutions have different advantages, and shortcomings. Therefore, we develop a system, named DONAC. DONAC could get better user authentication by directory service, and out-of-band block invalid user taking advantage of Ethernet features. It monitors real-time and logs all hosts and users in the network, provides flexible management policy. Once a client (host or user) violate the policy, DONAC prohibit the client from accessing the network immediately. It improves existing NAC solutions in flexibility, scalability, information integrity, and cost. Via actual test, DONAC system implementation can effectively control the network access of the client. Clients do not meet the policy will be blocked all network access immediately. It matches the goal of network access control.

參考文獻


12. 楊文龍(2008),基於SNMP之ARP攻擊偵測研究,國立暨南國際大學資訊管理學系碩士論文。
2. 吳文政(2003),入境偵測系統攻擊徵兆MIB設計,中華大學資訊工程學系碩士專班碩士論文。
3. 李為漢(2005),網際網路惡意程式之活動調查-以某企業對外網路連線為例,國立中央大學資訊管理研究所碩士論文。
15. 蔡博偉(2003),網路多模組監控回報系統之研究與設計,元智大學資訊管理學系碩士班碩士論文。
4. Geoffrey Goodell, Mema Roussopoulos, and Scott Bradner(2009), A Directory Service for Perspective Access Networks, IEEE/ACM TRANSACTIONS ON NETWORKING, VOL. 17, NO. 2, APRIL 2009, pp.501-514.

延伸閱讀