透過您的圖書館登入
IP:3.140.185.147
  • 學位論文

於雲端資料中心建構動態式虛擬防火牆之設計與實現

Design and Implementation of Dynamic Virtual Firewalls in a Cloud Data Center

指導教授 : 陳景章
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


雲端運算近年來蓬勃發展,各種雲端網路服務紛紛應運而生,其中雲端服務中較底層的雲端設備服務(Infrastructure as a Service,IaaS)也成為了熱門的應用之一。當使用者將自行開發的Applications轉移到雲上或是租用雲服務供應商(Cloud Service Provider)的服務時。雖然使用者可在雲端上建立起龐大的虛擬運算網路,取代實體設備之龐大的成本及設置,但在安全議題上也成為了使用者所顧慮的要點。 因此本論文為了提昇使用者對雲服務的可靠性,將以防火牆作為設計考量。在商業化環境中,不論是實體環境或是虛擬環境,防火牆的設置往往都是最要緊、最基本的。在本論文中,將提出一套運用在雲端虛擬環境中之動態式虛擬防火牆架構,利用雲端虛擬化技術的彈性化,讓系統的安全設備能達到動態建立、動態釋放虛擬資源。並利用了開源軟體OpenWrt編譯出適合使用在雲端環境中的作業系統,供本論文所提出之系統使用,藉此讓整個系統的成本降低、以及可以靈活運用雲端虛擬資源。

並列摘要


Cloud computing is booming in recent years, a variety of cloud services have emerged and Infrastructure as a Service which is lower layer of the cloud services has become one of popular applications. User may hire the cloud services from cloud service providers, when they migrate self-developed applications into the cloud environment. Although users can create the huge virtual computing network, which can substitute the huge costs and settings of physical devices, the security issues have become the main points of users concerns. Therefore, this paper in order to enhance the reliability of cloud services for users, we will be focus on the design of the firewall in a cloud data center. Firewall settings are often the most important and basic in the commercial environment, whether the physical environment or virtual environment. In this thesis, we proposed an architecture about dynamic virtual firewall in the cloud virtual environment. The use of cloud virtualization technology flexible, so that the system can achieve security device to dynamically establish and release virtual resources. We used the open-source software OpenWrt compile suitable for use in the cloud environment, the operating system for the proposed system of this paper use, thereby the system cost could be reduced, and the flexible firewall resource could be used efficiently.

並列關鍵字

OpenWrt OpenStack IaaS virtual firewall

參考文獻


[1] Zhifeng Xiao, Yang Xiao, “Security and Privacy in Cloud Computing”, Communications Surveys & Tutorials, IEEE. vol. 15, 2013, pp. 843–859.
[2] 洪光耀, “在雲端虛擬環境建構網路安全防禦架構之研究與實現”, 國立中正大學通訊工程研究所碩士論文, 嘉義民雄, 2014.
[4] Y. Bai, H. Kobayshi, “Intrusion Detection System: Technology and Development”, Proceedings of the 17th International Conference on Advanced Information Networking and Applications, 2003.
[5] Hwang, K., Cai, M., Chen, Y. and Qin, M., “Hybrid Intrusion Detection with Weighted Signature Generation over Anomalous Internet Episodes”, Dependable and Secure Computing, Vol. 4, no. 1, pp. 41-55.
[9] Mishra M, Das A, Kulkarni P, Sahoo A, “Dynamic resource management using virtual machine migrations”, Communications Magazine, IEEE. vol. 50, 2012, pp. 34–40.

延伸閱讀