作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2012, Vol. 38 ›› Issue (12): 115-117. doi: 10.3969/j.issn.1000-3428.2012.12.034

• 安全技术 • 上一篇    下一篇

基于流量特征的可信网络系统设计与实现

杨文思 1,2,张 斌 1,于爱民 1,2   

  1. (1. 中国科学院软件研究所信息安全国家重点实验室,北京 100190;2. 信息安全共性技术国家工程研究中心,北京 100190)
  • 收稿日期:2011-10-22 出版日期:2012-06-20 发布日期:2012-06-20
  • 作者简介:杨文思(1988-),女,硕士研究生,主研方向:可信计算;张 斌,副研究员;于爱民,博士
  • 基金资助:

    中国科学院基金资助项目“创新工程领域前沿项目”(ISCAS2009-DR14, ISCAS2009-GR03)

Design and Implementation of Trusted Network System Based on Traffic Characteristic

YANG Wen-si 1,2, ZHANG Bin 1, YU Ai-min 1,2   

  1. (1. State Key Laboratory of Information Security, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China; 2. National Engineering Research Center of Information Security, Beijing 100190, China)
  • Received:2011-10-22 Online:2012-06-20 Published:2012-06-20

摘要: 大多数可信网络系统使用的完整性度量技术仅能度量可执行文件而忽略了脚本文件,造成安全隐患。针对该问题,设计实现一种基于流量特征的可信网络系统,不仅对终端进行完整性度量,还利用终端网络流量的周期统计信息判断终端的完整性状态,由此保证脚本文件的可信性。在Linux上实现该系统,结果证明其能够快速检测出特定的脚本病毒。

关键词: 可信网络系统, 网络流量特征, 完整性管理, 完整性度量, 可信计算, 可信平台模块

Abstract: Most integrity measurement technologies of trusted network systems make use of focuses on executable files. In order to solve the problem that integrity measurement can not guarantee the credibility of the script files, this paper designs a trusted network system based on network traffic characteristics. Besides executing the integrity measurement, the system also computes the network traffic statistic information to judge the integrity state of the endpoint, which can be used to detect security threats when executing scripts. The system is implemented on Linux, and application results show that the system can detect some script viruses quickly.

Key words: trusted network system, network traffic characteristic, integrity management, integrity measurement, trusted computing, Trusted Platform Module(TPM)

中图分类号: