摘要
文中旨在研究大型复杂网络的安全管理特性,从信息保护、入侵检测、响应、恢复(PDRR)的角度抽象出一个理论上可供深入研究的安全管理模型。该模型可使OSI/RM七个协议层之间层层协同、步步防护,共同提高网络安全管理的整体性能;提出信息流闭环访问机制和事务提交回滚机制,其中后者可对入侵攻击实时检测、响应、恢复,使网络免遭攻击破坏。
This paper deals with large-scale network security management, establing a model on the basis of PDRR in theory. The model takes every protocol layer of the whole OSI/RM into account, with each layer joining in cooperation and protection, putting forward two mechanisms: one is information-stream closed-circle access while the other is transaction submitting and rolling-back. The latter can make real-time detection, reaction and restoring, saving the whole network from being destroyed under intrusions.
出处
《计算机应用》
CSCD
北大核心
2004年第2期30-32,共3页
journal of Computer Applications
基金
国家 86 3计划资助项目 (2 0 0 2AA1 440 2 0 )
关键词
网络安全管理模型
安全通道
信息流闭环访问
事务提交回滚
network security management model
security channel
information-stream closed-circle access
transaction submitting and rolling-back