防火墻功能外包的隱私保護(hù)技術(shù)研究
[Abstract]:With the continuous development of Internet technology and communication technology, network has been integrated into all aspects of people's lives, which brings great convenience to people's lives. But at the same time, a variety of cyber attacks emerge one after another, and the security of cyberspace is greatly threatened. Therefore, we need a variety of network defense technology to resist network attacks. Firewall technology is one of the key technologies to resist network attack and guarantee network security. The firewall can monitor and check the incoming and outgoing network traffic, prevent the malicious packet from entering the intranet, and kill the malicious packet at the entrance of the intranet. But deploying and managing firewalls brings a lot of overhead, which increases the company's operating costs. To reduce the company's overhead, the company began to consider outsourcing firewall capabilities to cloud service providers to handle. However, firewall function outsourcing will reveal the company's firewall policy, the existing firewall function outsourcing scheme either does not protect the privacy of the firewall policy, or the performance or security is not high. This makes the privacy protection of firewall policy become a hindrance to the company adopting firewall function outsourcing technology. The purpose of this paper is to solve the privacy protection problem of firewall policy in firewall function outsourcing. The specific contents of the study include the following aspects: 1. This paper presents a dual cloud-based firewall function outsourcing system architecture. In view of the problems existing in the existing firewall function outsourcing system architecture, we propose a firewall function outsourcing system architecture based on two independent cloud platforms. The two cloud platforms in this system architecture are independent of each other and can provide firewall functions in accordance with the protocol. 2. Based on the above-mentioned dual-cloud outsourcing system architecture, a privacy-protected firewall outsourcing scheme is proposed by using Paillier partial homomorphism encryption. In this scheme, we combine Paillier partial homomorphism encryption with cryptology fuzzizer, design a cryptology fuzzer based on Paillier partial homomorphism encryption, and then use this cryptology fuzzizer to defuzzify firewall strategy. Thus ensuring the privacy of the outsourced firewall policy. 3. Based on the outsourced system architecture of traffic redirection, a privacy-protected firewall outsourcing scheme is proposed by using prefix-preserving encryption. This scheme uses prefix-preserving encryption algorithms to encrypt firewall policies, thus ensuring the privacy of outsourced firewall policies. 4. The simulation experiments of the above two schemes are carried out by using Click modular router, and the feasibility of the proposed scheme is verified. At the same time, we test the processing delay and throughput of the two schemes, and verify the performance of the two schemes.
【學(xué)位授予單位】:中國(guó)科學(xué)技術(shù)大學(xué)
【學(xué)位級(jí)別】:碩士
【學(xué)位授予年份】:2017
【分類(lèi)號(hào)】:TP393.08
【相似文獻(xiàn)】
相關(guān)期刊論文 前10條
1 ;防火墻功能分類(lèi)及其局限性分析[J];計(jì)算機(jī)與網(wǎng)絡(luò);2010年07期
2 林琪;如何評(píng)價(jià)防火墻功能[J];計(jì)算機(jī)安全;2002年03期
3 清涼心;;防火墻功能指標(biāo)詳解[J];網(wǎng)絡(luò)與信息;2007年04期
4 陳德模;用LRP實(shí)現(xiàn)防火墻功能[J];電腦知識(shí)與技術(shù);2001年16期
5 山德魯;;學(xué)用Windows防火墻,做好安全防護(hù)[J];電腦知識(shí)與技術(shù)(經(jīng)驗(yàn)技巧);2014年08期
6 ;業(yè)界要聞[J];電子產(chǎn)品世界;1997年04期
7 曹喜波;;基于ASP的主頁(yè)防火墻功能的實(shí)現(xiàn)[J];中國(guó)科技信息;2004年24期
8 曹偉;利用Linux防火墻功能保護(hù)校園網(wǎng)的安全[J];丹東紡專(zhuān)學(xué)報(bào);2005年01期
9 龐亞賓;任治洪;;思科IOS系統(tǒng)的防火墻功能實(shí)現(xiàn)研究[J];甘肅科技;2008年09期
10 ;擴(kuò)展防火墻功能 再創(chuàng)性?xún)r(jià)比新高 SonicWALL推出防火墻新品—PRO230和PRO330[J];信息安全與通信保密;2003年04期
相關(guān)重要報(bào)紙文章 前9條
1 ;阿爾卡特Speed Touch 511路由器兼具防火墻功能[N];中國(guó)計(jì)算機(jī)報(bào);2003年
2 ;東軟:用虛擬防火墻為用戶(hù)護(hù)航[N];中國(guó)計(jì)算機(jī)報(bào);2007年
3 甘肅 飛揚(yáng);激活Windows XP的防火墻[N];中國(guó)電腦教育報(bào);2001年
4 離子翼;安全無(wú)處不在[N];中國(guó)電腦教育報(bào);2005年
5 陳會(huì)安;揭開(kāi)FTP服務(wù)器無(wú)法訪問(wèn)之謎[N];中國(guó)電腦教育報(bào);2004年
6 雷燕;美國(guó)網(wǎng)屹登陸中國(guó)[N];通信產(chǎn)業(yè)報(bào);2000年
7 ;奧聯(lián)科技 APN GW 5000[N];中國(guó)計(jì)算機(jī)報(bào);2006年
8 孫曉明;移動(dòng)辦公更要安全[N];中國(guó)計(jì)算機(jī)報(bào);2002年
9 ;迷你的SAFE[N];網(wǎng)絡(luò)世界;2002年
相關(guān)碩士學(xué)位論文 前1條
1 盛化龍;防火墻功能外包的隱私保護(hù)技術(shù)研究[D];中國(guó)科學(xué)技術(shù)大學(xué);2017年
,本文編號(hào):2470828
本文鏈接:http://www.wukwdryxk.cn/guanlilunwen/ydhl/2470828.html