摘要
在详细分析用户需求的基础上,结合现有网络拓扑结构,提出了一个从点、线到面的综合网络安全系统设计方案。在点上即员工工作站上安装上网行为和带宽管理客户软件,在线上即对外链路上部署防火墙,在面上部署入侵检测设备和上网行为及带宽管理服务器。通过综合利用防火墙、入侵检测、上网行为管理和带宽管理技术,有效保障了企业内部网络的安全,规范了员工的上网行为,满足了企业关键业务的带宽需求。
On the basis of analysis of user' s requirement in detail, topology of network. The solution provides security from points, the system' s solution plan is designed by combing with the present line to areas. At the points, those are employees' workstations, there set up network supervision and bandwidth management clients. On the line, that is link to connect outside, there installs firewall. There deploy intrusion detection equipment and network supervision and bandwidth management server in the areas behind the firewall. Through using firewall, intrusion detection, network supervision and bandwidth management technologies, the solution guarantees the security of Intranet effectively, supervises behavior of network users and satisfies bandwidth requirement of key operations.
出处
《计算机工程与设计》
CSCD
北大核心
2009年第13期3072-3074,共3页
Computer Engineering and Design
基金
国家自然科学基金项目(60373156
10871222
10726012)
关键词
防火墙
入侵检测
上网行为管理
带宽管理
网络安全
firewall
intrusion detection
network supervision
bandwidth management
network security