作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (20): 180-183. doi: 10.3969/j.issn.1000-3428.2008.20.066

• 安全技术 • 上一篇    下一篇

P2DR模型中策略部署模型的研究与设计

韩锐生,徐开勇,赵 彬   

  1. (解放军信息工程大学电子技术学院信息安全研究所,郑州 450004)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-10-20 发布日期:2008-10-20

Research and Design of Policy Deployment Model for P2DR Model

HAN Rui-sheng, XU Kai-yong, ZHAO Bin   

  1. (Information Security Institution, Electronic Technology Academy, PLA Information Engineering University, Zhengzhou 450004)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-10-20 Published:2008-10-20

摘要: 分析动态自适应网络安全模型P2DR的缺陷,提出对P2DR模型的几点改进建议。针对模型中策略相关不足设计了一个策略部署模型,该部署模型实现了策略统一定制、自动分发、自适应管理等功能,同时在部署模型中引入了安全事件关联分析的思想,共享设备间安全信息以实现安全策略的联动操作,达到安全事故及时响应的目标。该部署模型实现了P2DR模型的动态性和自适应以及策略核心作用。

关键词: 部署模型, 自适应管理, 策略联动, 安全事件关联

Abstract: This paper analyzes the insufficiency of dynamic adaptation network security model P2DR, and asserts some improved proposal for P2DR. A policy deployment model is designed on the insufficiency of policy for P2DR model. Deployment model provides the policy uniform defines, automatic distribution, self-adaptive management functions and so on. The security event coordination analysis is introduced in the deployment model. The model shares the security information between devices in order to realize cooperation of security policies, and achieves the goal of reposing security incident in time. The significance of deployment model is really realizing the dynamic and adaptive of P2DR model, and it makes the core effect of policy realized.

Key words: deployment model, self-adaptive management, policy linkage, security event coordination

中图分类号: