ÕªÒª£º Ëæ×ÅÐÅÏ¢²úÒµµÄ¸ßËÙ·¢Õ¹£¬ÖÚ¶àÆóÒµ¶¼ÀûÓû¥ÁªÍø½¨Á¢ÁË×Ô¼ºµÄÐÅϢϵͳ£¬ÒÔ³ä·ÖÀûÓø÷ÀàÐÅÏ¢×ÊÔ´¡£µ«ÊÇÎÒÃÇÔÚÏíÊÜÐÅÏ¢²úÒµ·¢Õ¹´ø¸øÎÒÃǵıãÀûµÄͬʱ£¬Ò²ÃæÁÙמ޴óµÄ·çÏÕ¡£ÎÒÃǵÄÏµÍ³ËæÊ±¿ÉÄÜÔâÊܲ¡¶¾µÄ¸ÐȾ¡¢ºÚ¿ÍµÄÈëÇÖ£¬Õâ¶¼¿ÉÒÔ¸øÎÒÃÇÔì³É¾Þ´óµÄËðʧ¡£±¾ÎÄÖ÷Òª½éÉÜÁËÐÅϢϵͳËùÃæÁٵļ¼Êõ°²È«Òþ»¼£¬²¢Ìá³öÁËÐÐÖ®ÓÐЧµÄ½â¾ö·½°¸¡£
¹Ø¼ü×Ö£ºÐÅϢϵͳ ÐÅÏ¢°²È« Éí·ÝÈÏÖ¤ °²È«¼ì²â
Abstract£º
Along with the high-speed development of information industries, the multitudinous enterprise has established their own information system using the Internet to use each kind of information resource. But while we enjoy the information industries development to take to our convenient, we also faced the huge risk. Our system possibly suffers viral infection, hacker¡¯s invasion; this all may create massive loss to us. This article mainly introduced the technical security hidden danger, which the information system faces, and proposed the effective solution.
Keywords£ºInformation system Information security
Status authentication Safe examination
Ò»¡¢Ä¿Ç°ÐÅϢϵͳ¼¼Êõ°²È«µÄÑо¿
1. ÆóÒµÐÅÏ¢°²È«ÏÖ×´·ÖÎö
Ëæ×ÅÐÅÏ¢»¯½ø³ÌµÄÉîÈ룬ÆóÒµÐÅÏ¢°²È«¼º¾ÒýÆðÈËÃǵÄÖØÊÓ£¬µ«ÒÀÈ»´æÔÚ²»ÉÙÎÊÌâ¡£Ò»Êǰ²È«¼¼Êõ±£ÕÏÌåϵÉв»ÍêÉÆ£¬ÆóÒµ»¨ÁË´óÁ¿µÄ½ðÇ®¹ºÂòÁËÐÅÏ¢°²È«É豸£¬µ«ÊǼ¼Êõ±£Õϲ»³ÉÌåϵ£¬´ï²»µ½Ô¤ÏëµÄÄ¿±ê:¶þÊÇÓ¦¼±·´Ó¦ÌåϵûÓо³£»¯¡¢ÖƶȻ¯:ÈýÊÇÆóÒµÐÅÏ¢°²È«µÄ±ê×¼¡¢ÖƶȽ¨ÉèÖͺó¡£
2003Äê5ÔÂÖÁ2004Äê5Ô£¬ÔÚ7072¼Ò±»µ÷²éµ¥Î»ÖÐÓÐ4057¼Òµ¥Î»·¢Éú¹ýÐÅÏ¢ÍøÂ簲ȫʼþ£¬Õ¼±»µ÷²é×ÜÊýµÄ58%¡£µ÷²é½á¹û±íÃ÷£¬Ôì³ÉÍøÂ簲ȫʼþ·¢ÉúµÄÖ÷ÒªÔÒòÊǰ²È«¹ÜÀíÖÆ¶È²»ÂäʵºÍ°²È«·À·¶Òâʶ±¡Èõ¡£ÆäÖУ¬ÓÉÓÚδÐÞ²¹»ò·À·¶Èí¼þ©¶´µ¼Ö·¢Éú°²È«Ê¼þµÄÕ¼°²È«Ê¼þ×ÜÊýµÄ¡°%£¬µÇ¼ÃÜÂë¹ýÓÚ¼òµ¥»òδÐÞ¸ÄÃÜÂëµ¼Ö·¢Éú°²È«Ê¼þµÄÕ¼19%.
¶ÔÓÚÍøÂ簲ȫ¹ÜÀíÇé¿öµÄµ÷²é:µ÷²é±íÃ÷£¬½üÄêÀ´£¬Ê¹Óõ¥Î»¶ÔÐÅÏ¢ÍøÂ簲ȫ¹ÜÀí¹¤×÷µÄÖØÊÓ³Ì¶ÈÆÕ±éÌá¸ß£¬80%µÄ±»µ÷²éµ¥Î»ÓÐרְ»ò¼æÖ°µÄ°²È«¹ÜÀíÈËÔ±£¬12%µÄµ¥Î»½¨Á¢Á˰²È«×éÖ¯£¬ÓÐ2%µÄµ¥Î»ÇëÐÅÏ¢°²È«·þÎñÆóÒµÌṩרҵ»¯µÄ°²È«·þÎñ¡£µ÷²é±íÃ÷£¬ÈÏΪµ¥Î»ÐÅÏ¢ÍøÂ簲ȫ·À»¤ÄÜÁ¦¡°½Ï¸ß¡±ºÍ¡°Ò»°ã¡±µÄ±È½Ï¶à£¬·Ö±ðÕ¼44%¡£µ«ÊÇ£¬±»µ÷²éµ¥Î»Ò²ÆÕ±é·´Ó³Óû§°²È«¹ÛÄÈõ¡¢°²È«¹ÜÀíԱȱ·¦Åàѵ¡¢°²È«¾·ÑͶÈë²»×ãºÍ°²È«²úÆ·²»ÄÜÂú×ãÒªÇóµÈÎÊÌ⣬Ҳ˵Ã÷Ŀǰ°²È«¹ÜÀíˮƽºÍÉç»á»¯·þÎñµÄ³Ì¶È»¹±È½ÏµÍ ¡£
2. ÆóÒµÐÅÏ¢°²È«·À·¶µÄÈÎÎñ
ÐÅÏ¢°²È«µÄÈÎÎñÊÇ¶à·½ÃæµÄ£¬¸ù¾Ýµ±Ç°ÐÅÏ¢°²È«µÄÏÖ×´£¬Öƶ¨ÐÅÏ¢°²È«·À·¶µÄÈÎÎñÖ÷ÒªÊÇ:
´Ó°²È«¼¼ÊõÉÏ£¬½øÐÐÈ«ÃæµÄ°²È«Â©¶´¼ì²âºÍ·ÖÎö£¬Õë¶Ô¼ì²âºÍ·ÖÎöµÄ½á¹ûÖÆ¶¨·À·¶´ëÊ©ºÍÍêÕûµÄ½â¾ö·½°¸;ÕýÈ·ÅäÖ÷À»ðǽ¡¢ÍøÂç·À²¡¶¾Èí¼þ¡¢ÈëÇÖ¼ì²âϵͳ¡¢½¨Á¢°²È«ÈÏ֤ϵͳµÈ°²È«ÏµÍ³¡£
´Ó°²È«¹ÜÀíÉÏ£¬½¨Á¢ºÍÍêÉÆ°²È«¹ÜÀí¹æ·¶ºÍ»úÖÆ£¬ÇÐʵ¼ÓÇ¿ºÍÂäʵ°²È«¹ÜÀíÖÆ¶È£¬ÔöÇ¿°²È«·À·¶Òâʶ¡£
ÐÅÏ¢°²È«·À·¶ÒªÈ·±£ÒÔϼ¸·½ÃæµÄ°²È«¡£ÍøÂ簲ȫ:±£Õϸ÷ÖÖÍøÂç×ÊÔ´(×ÊÔ´¡¢ÊµÌå¡¢ÔØÌå)Îȶ¨¿É¿¿µØÔËÐС¢ÊܿغϷ¨µØÊ¹Óá£ÐÅÏ¢°²È«:±£ÕÏ´æ´¢¡¢´«Êä¡¢Ó¦ÓõĻúÃÜÐÔ(Confidentiality )¡¢ÍêÕûÐÔ(Integrity)¡¢¿¹·ñÈÏÐÔ(non-Repudiation) ,¿ÉÓÃÐÔ(Availability)¡£ÆäËû°²È«:²¡¶¾·ÀÖΡ¢Ô¤·ÀÄÚ²¿·¸×ï¡£
¶þ¡¢¼ÆËã»úÍøÂçÖÐÐÅϢϵͳµÄ°²È«·À·¶´ëÊ©
£¨Ò»£©ÍøÂç²ã°²È«´ëÊ©
¢Ù·À»ðǽ¼¼Êõ
·À»ðǽ¼¼ÊõÊǽ¨Á¢ÔÚÏÖ´úͨÐÅÍøÂç¼¼ÊõºÍÐÅÏ¢°²È«¼¼Êõ»ù´¡ÉϵÄÓ¦ÓÃÐÔ°²È«¼¼Êõ£¬Ô½À´Ô½¶àµØÓ¦ÓÃÓÚרÓÃÍøÂçÓ빫ÓÃÍøÂçµÄ»¥Áª»·¾³Ö®ÖУ¬ÓÈÆäÒÔ½ÓÈëInternetÍøÂçΪÉõ¡£
·À»ðǽÊÇÖ¸ÉèÖÃÔÚ²»Í¬ÍøÂç(Èç¿ÉÐÅÈÎµÄÆóÒµÄÚ²¿ÍøºÍ²»¿ÉÐŵĹ«¹²Íø)»òÍøÂ簲ȫÓòÖ®¼äµÄһϵÁв¿¼þµÄ×éºÏ¡£ËüÊDz»Í¬ÍøÂç»òÍøÂ簲ȫÓòÖ®¼äÐÅÏ¢µÄΨһ³öÈë¿Ú£¬Äܸù¾ÝÆóÒµµÄ°²È«Õþ²ß¿ØÖÆ(ÔÊÐí¡¢¾Ü¾ø¡¢¼à²â)³öÈëÍøÂçµÄÐÅÏ¢Á÷£¬ÇÒ±¾Éí¾ßÓнÏÇ¿µÄ¿¹¹¥»÷ÄÜÁ¦¡£ËüÊÇÌṩÐÅÏ¢°²È«·þÎñ£¬ÊµÏÖÍøÂçºÍÐÅÏ¢°²È«µÄ»ù´¡ÉèÊ©¡£ÔÚÂß¼ÉÏ£¬·À»ðǽÊÇÒ»¸ö·ÖÀëÆ÷£¬Ò»¸öÏÞÖÆÆ÷£¬Ò²ÊÇÒ»¸ö·ÖÎöÆ÷£¬ÓÐЧµØ¼à¿ØÁËÄÚ²¿ÍøºÍInternetÖ®¼äµÄÈκλ£¬±£Ö¤ÁËÄÚ²¿ÍøÂçµÄ°²È« ¡£
·À»ðǽÊÇÍøÂ簲ȫµÄÆÁÕÏ£ºÒ»¸ö·À»ðǽ(×÷Ϊ×èÈûµã¡¢¿ØÖƵã)Äܼ«´óµØÌá¸ßÒ»¸öÄÚ²¿ÍøÂçµÄ°²È«ÐÔ£¬²¢Í¨¹ý¹ýÂ˲»°²È«µÄ·þÎñ¶ø½µµÍ·çÏÕ¡£ÓÉÓÚÖ»Óо¹ý¾«ÐÄÑ¡ÔñµÄÓ¦ÓÃÐÒé²ÅÄÜͨ¹ý·À»ðǽ£¬ËùÒÔÍøÂç»·¾³±äµÃ¸ü°²È«¡£·À»ðǽ¿ÉÒÔÇ¿»¯ÍøÂ簲ȫ²ßÂÔ£ºÍ¨¹ýÒÔ·À»ðǽΪÖÐÐĵݲȫ·½°¸ÅäÖã¬Äܽ«ËùÓа²È«Èí¼þ(Èç¿ÚÁî¡¢¼ÓÃÜ¡¢Éí·ÝÈÏÖ¤¡¢É󼯵È)ÅäÖÃÔÚ·À»ðǽÉÏ¡£¶ÔÍøÂç´æÈ¡ºÍ·ÃÎʽøÐÐ¼à¿ØÉ󼯣ºÈç¹ûËùÓеķÃÎʶ¼¾¹ý·À»ðǽ£¬ÄÇô£¬·À»ðǽ¾ÍÄܼǼÏÂÕâЩ·ÃÎʲ¢×ö³öÈÕÖ¾¼Ç¼£¬Í¬Ê±Ò²ÄÜÌá¹©ÍøÂçʹÓÃÇé¿öµÄͳ¼ÆÊý¾Ý¡£·ÀÖ¹ÄÚ²¿ÐÅÏ¢µÄÍâй£ºÍ¨¹ýÀûÓ÷À»ðǽ¶ÔÄÚ²¿ÍøÂçµÄ»®·Ö£¬¿ÉʵÏÖÄÚ²¿ÍøÖصãÍø¶ÎµÄ¸ôÀ룬´Ó¶øÏÞÖÆÁ˾ֲ¿Öصã»òÃô¸ÐÍøÂ簲ȫÎÊÌâ¶ÔÈ«¾ÖÍøÂçÔì³ÉµÄÓ°Ïì¡£³ýÁ˰²È«×÷Óã¬ÓеķÀ»ðǽ»¹Ö§³Ö¾ßÓÐInternet·þÎñÌØÐÔµÄÆóÒµÄÚ²¿ÍøÂç¼¼ÊõÌåϵVPN ¡£Í¨¹ýVPN£¬½«ÆóÊÂÒµµ¥Î»ÔÚµØÓòÉÏ·Ö²¼ÔÚÈ«ÊÀ½ç¸÷µØµÄLAN»òרÓÃ×ÓÍø£¬ÓлúµØÁª³ÉÒ»¸öÕûÌå¡£²»½öʡȥÁËרÓÃͨÐÅÏß·£¬¶øÇÒΪÐÅÏ¢¹²ÏíÌṩÁ˼¼Êõ±£ÕÏ¡£
¢ÚÈëÇÖ¼ì²â¼¼Êõ
IETF ½«Ò»¸öÈëÇÖ¼ì²âϵͳ·ÖΪËĸö×é¼þ£ºÊ¼þ²úÉúÆ÷(Event Generators )£»Ê¼þ·ÖÎöÆ÷(Event Analyzers )£»ÏìÓ¦µ¥Ôª(Response Units)ºÍʼþÊý¾Ý¿â(Event Data Bases )¡£Ê¼þ²úÉúÆ÷µÄÄ¿µÄÊÇ´ÓÕû¸ö¼ÆËã»·¾³ÖлñµÃʼþ£¬²¢ÏòϵͳµÄÆäËû²¿·ÖÌṩ´Ëʼþ¡£Ê¼þ·ÖÎöÆ÷·ÖÎöµÃµ½µÄÊý¾Ý£¬²¢²úÉú·ÖÎö½á¹û¡£ÏìÓ¦µ¥ÔªÔòÊǶԷÖÎö½á¹û×ö³ö·´Ó¦µÄ¹¦Äܵ¥Ôª£¬Ëü¿ÉÒÔ×ö³öÇжÏÁ¬½Ó¡¢¸Ä±äÎļþÊôÐÔµÈÇ¿ÁÒ·´Ó¦£¬Ò²¿ÉÒÔÖ»ÊǼòµ¥µÄ±¨¾¯¡£Ê¼þÊý¾Ý¿âÊÇ´æ·Å¸÷ÖÖÖмäºÍ×îÖÕÊý¾ÝµÄµØ·½µÄͳ³Æ£¬Ëü¿ÉÒÔÊǸ´ÔÓµÄÊý¾Ý¿â£¬Ò²¿ÉÒÔÊǼòµ¥µÄÎı¾Îļþ¡£
¸ù¾Ý¼ì²â¶ÔÏóµÄ²»Í¬£¬ÈëÇÖ¼ì²âϵͳ¿É·ÖΪÖ÷»úÐͺÍÍøÂçÐÍ¡£»ùÓÚÖ÷»úµÄ¼à²â¡£Ö÷»úÐÍÈëÇÖ¼ì²âϵͳ¾ÍÊÇÒÔϵͳÈÕÖ¾¡¢Ó¦ÓóÌÐòÈÕÖ¾µÈ×÷ΪÊý¾ÝÔ´£¬µ±È»Ò²¿ÉÒÔͨ¹ýÆäËûÊÖ¶Î(Èç¼à¶½ÏµÍ³µ÷ÓÃ)´ÓËùÔÚµÄÖ÷»úÊÕ¼¯ÐÅÏ¢½øÐзÖÎö¡£Ö÷»úÐÍÈëÇÖ¼ì²âϵͳ±£»¤µÄÒ»°ãÊÇËùÔÚµÄϵͳ¡£ÕâÖÖϵͳ¾³£ÔËÐÐÔÚ±»¼à²âµÄϵͳ֮ÉÏ£¬ÓÃÒÔ¼à²âϵͳÉÏÕýÔÚÔËÐеĽø³ÌÊÇ·ñºÏ·¨¡£×î½ü³öÏÖµÄÒ»ÖÖID ( Intrusion Detection )£ºÎ»ÓÚ²Ù×÷ϵͳµÄÄÚºËÖ®Öв¢¼à²âϵͳµÄ×îµ×²ãÐÐΪ¡£ËùÓÐÕâЩϵͳ×î½üÒѾ¿ÉÒÔ±»ÓÃÓÚ¶àÖÖÆ½Ì¨¡£ÍøÂçÐÍÈëÇÖ¼ì²â¡£ËüµÄÊý¾ÝÔ´ÊÇÍøÂçÉϵÄÊý¾Ý°ü¡£ÍùÍù½«Ò»Ì¨»ú×ÓµÄÍø¿¨ÉèÓÚ»ìÔÓģʽ(Promise Mode )£¬¶ÔËùÓб¾Íø¶ÎÄÚµÄÊý¾Ý°ü²¢½øÐÐÐÅÏ¢ÊÕ¼¯£¬²¢½øÐÐÅжϡ£Ò»°ãÍøÂçÐÍÈëÇÖ¼ì²âϵͳµ£¸º×ű£»¤Õû¸öÍø¶ÎµÄÈÎÎñ¡£
¼ÆËã»úÁªËøÏµÍ³µÄÈÝ´í¼¼Êõ
¼ÆËã»ú¶àýÌå¼¼ÊõÔÚ»úе½ÌѧÖеÄÓ¦ÓÃ