摘要
电子审批系统是一种近年来发展迅速且作用日益重要的应用系统,这种系统在开放互联环境中为公众提供服务,因此面临诸多安全威胁。这里在分析各种安全威胁的基础上,提出一种"底层安全增强,上层安全过滤,统一安全管理"的系统安全防护技术框架,并以可信计算为基础,以访问控制为核心,提供安全审计的先进技术体系,确保框架的合理可行和高安全性。对安全防护效果的分析表明,这里提出的安全防护技术框架能够主动防御各种安全威胁,全面保护系统的安全,满足了电子审批系统的实际安全需求。
Electronic examination system,as an important application system,develops very rapidly in recent years. This system provides services for the public in an open environment,and thus faces many security threats. Based on analysis of various security threats,a technical framework with"bottom-level security enhancements top-level security filtering and unified security management"is proposed for protection of the system security. Then,with trusted computing as the foundation,access control as the core,an advanced technical system is provided for security audit,thus to ensure that the framework is reasonable,practicable and of high security. Analysis on security protection effects shows that the proposed technical framework of security protection can proactively resist a variety of security threats,offer a comprehensive protection of system security,and thus meet the actual security demand of e-examination system.
出处
《信息安全与通信保密》
2011年第7期28-29,32,共3页
Information Security and Communications Privacy
关键词
应用系统安全
操作系统安全
可信计算
访问控制
application system security
operating system security
trusted computing
access control