摘要
划分安全域是保护资产的一项重要措施。面向安全域划分的需要,提出了网络访问控制的层次模型,把网络访问控制划分为网络边界访问控制、安全域边界访问控制、主机网络访问控制3个层次,并探讨了网络组织、非军事区、地址转换、访问控制策略等关键问题。网络访问控制的层次模型有效地做到了纵深保护信息资产的目的。
The division of security domain is an important way for protecting information assets. To meet the need of security domain,this paper provides a hierarchical model of network access control,which consists of network border access control, security domain border access control and host-based network access control. And some key problems,such as network topology,non-military zone,network address translation,access control policies,are also discussed. The hierarchical model of network access control could provide in-depth protection of information assets.
出处
《信息安全与通信保密》
2010年第7期84-86,共3页
Information Security and Communications Privacy
关键词
安全域
访问控制
层次模型
security domain
access control
hierarchical model