作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (6): 158-160. doi: 10.3969/j.issn.1000-3428.2008.06.058

• 安全技术 • 上一篇    下一篇

基于动态监控器的安全局域网

程 磊,司天歌,戴一奇   

  1. (清华大学计算机科学与技术系网络所,北京 100084)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-03-20 发布日期:2008-03-20

Secure Local Area Network Based onDynamical Monitor

CHENG Lei, SI Tian-ge, DAI Yi-qi   

  1. (Institute of Network, Dept. of Computer Science and Technology, Tsinghua University, Beijing 100084)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-03-20 Published:2008-03-20

摘要: 从体系结构角度,提出一种新的局域网安全解决方案。该方案采用透明计算机进行集中统一存储,用星型结构作为局域网的拓扑结构,并且在网络中心节点引入监控器。监控器拥有局域网的主动控制权,对各个网络部件之间的通信过程实施强制访问控制,以实现对终端与终端之间及终端与外网之间的通信数据的过滤和动态物理隔离。

关键词: 局域网安全, 透明计算, 可信计算机系统, 计算机网络

Abstract: This paper proposes a new solution to the security of LAN in perspective of architecture. There are two characteristics in this solution: consolidating discrete storage devices in the LAN by means of transparence computing technology, the LAN has a star topology with a central monitor, which can proactively regulate the network traffic. With mandatory access control over the communication among the entities in the network, the monitor can filter the traffic and dynamically isolate the physical connections among host computers, and between host computers and outside network.

Key words: local area network security, transparence computing, trusted computer system, computer network

中图分类号: