作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (09): 131-133.

• 安全技术 • 上一篇    下一篇

基于域的网络安全策略研究

唐成华1,2,胡昌振1,2,崔中杰1,2   

  1. (1. 北京理工大学信息安全与对抗技术研究中心,北京 100081;2. 北京理工大学机电工程学院,北京100081)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-05-05 发布日期:2007-05-05

Research of Network Security Policy Based on Domain

TANG Chenghua1,2, HU Changzhen1,2, CUI Zhongjie1,2   

  1. (1. Information Security and Antagonism Research Center, Beijing Institute of Technology, Beijing 100081; 2. College of Mechatronic Engineering, Beijing Institute of Technology, Beijing 100081)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-05-05 Published:2007-05-05

摘要: 针对大规模网络环境下的安全特点,提出了一种基于域的网络安全策略模型,通过应用域和规范安全策略语言,研究了策略的存储、查找、冲突检测与消解、发布实施过程中的技术和原则。应用该模型后的系统成为一种具有自动化策略管理特点的安全系统。

关键词: 安全策略, 域, 策略冲突, 实体

Abstract: Aiming at the security characters of large-scale network environment, a network security policy model based on domain is proposed. By applying domain and the security policy language criterion, the techniques and principles of policies’ store, finding, implementation, conflicts detection and resolution are studied. The system which applies this model is a safe one with the peculiarity of auto-managing policy.

Key words: Security policy, Domain, Policy conflict, Entity

中图分类号: