透過您的圖書館登入
IP:18.217.67.16
  • 學位論文

在雲端虛擬環境建構網路安全防禦架構之研究與實現

The Research and Implementation of Network Security Defense Architecture in Cloud Virtual Environments

指導教授 : 陳景章
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


自從2009年雲端運算的概念被提出來以後,各種網路服務紛紛應運而生。對於雲端運算的概念,簡單來說就是透過提供商所提供之虛擬網路資源,使用者可在雲端上快速建立起龐大的虛擬運算網路,取代實體設備之龐大成本及設置,並且達到異地備源及不中斷服務等優點。於是各大企業莫不往虛擬化環境尋找更方便快速且省成本的方法。但是,對於虛擬環境的網路安全並沒有統一的規範與作法,各大資安廠商皆致力於開發新的網路防護設備,而最快的作法仍然是從改善防火牆來著手。 本論文針對虛擬環境中的網路管理以及安全防禦提出一架構,解決傳統實體網路轉換到雲端虛擬網路後,可能遇到的一些安全問題。在本論文中根據VLAN切割之防禦方法,將實體防火牆改由具封包轉向功能之虛擬交換機來取代,節省網路封包在實體與虛擬間交換之時間。並結合安全政策決策系統來制定防禦規則 ,由控制器根據防禦規則來下指令給虛擬交換機執行。透過本論文,希望能初步建構出一簡單的虛擬防火牆,並將實體網路安全防禦系統在雲端虛擬網路中實現。

並列摘要


Since 2009 the concept of cloud computing has been proposed, a variety of Internet services have emerged. The concept of cloud computing, is simply through a virtual network resources provided by providers, users can quickly build a huge network of virtual computing in the cloud environments, users can quickly build a huge network of virtual computing in the cloud environments to replace the physical equipments to save the huge cost and the complex settings, and to achieve offsite backup and without service interruption and so on. So the major companies all working to find a more convenient and quickly and cost-saving methods within virtual environments. However, the network security for virtual environments has no uniform specification and approaches, major security vendors are committed to developing a new protective equipment, but improving the firewall is still the fastest approach. In this thesis, we propose a defense architecture about network management and security, for resolve some security issues after the traditional physical network transform to cloud virtual network. In this paper, a method based on VLAN segmentation will be improved, replacing a physical firewall by the virtual switch which has the function of packets forwarding, to save the time that packets exchanged between the physical and virtual network. Combined with the security policy decision system to make defense rules, according to defense rules by SPDS, controller will command the virtual switch to perform it. Through this paper, we hope to construct a simple virtual firewall which can implement the function of physical network security defense system in cloud virtual environments.

參考文獻


[5] 葉曉霈,"以Openflow交換機建構網路安全防禦系統之研究與實現",2013全國電信研討會,國立中正大學通訊研究所碩士論文,嘉義,2013
[8] Y. Bai , H. Kobayshi, "Intrusion Detection System: Technology and Development", Proceedings of the 17th International Conference on Advanced Information Networking and Applications, 2003.
[15]黃勝獅,"使用Openflow交換機分析偵測殭屍網路", 國立中央大學資訊工程研究所碩士論文,桃園,2010
[16] R. Braga, E. Mota, A. Passito, "Lightweight DDoS flooding attack detection using NOX/Openflow", Local Computer Networks (LCN), 2010 IEEE 35th Conference on, 2010, pp. 408-415.
[18] K. Hyojoon , N. Feamster , "Improving network management with software defined networking," Communications Magazine, IEEE, vol. 51, pp. 114-119, 2013.

被引用紀錄


吳嘉恩(2016)。於雲端資料中心建構動態式虛擬防火牆之設計與實現〔碩士論文,國立中正大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0033-2110201614044373

延伸閱讀