With the continuous development of computer networks, global information technology has become a major trend in human development.
But since the computer network has joint forms of diversity, Terminal distribution inhomogeneity and network openness, interconnectivity and other features, leaving the network vulnerable to hackers, cyberpunk, malware and other dishonest attacks, online information security and privacy is a critical issue.For the military of automation command network, C3I system and the transmission of sensitive data such as the Bank's computer network system for online information secure and confidential.
Therefore, the network must have enough strong security measures, or the network will be a useless, or even threaten the national security network. Whether in the LAN or Wan, there is a natural and man-made, and many other factors of vulnerability and potential threats. Therefore, the network security measures should be tailor-made for different kinds of threats and vulnerabilities in order to ensure that network information confidentiality, integrity, and availability.Computing network threats
Computer network threats in General can be divided into two kinds: first, the information in the network; the second is the threat of network equipment.
Impact of computer network to a number of factors, some of the factors may be intentional or unintentional; may be human or non-human; may be external hackers on illegal Internet system resources so that they have, boils, against network security threats, there are three:1 people-from unintentional errors:
If the operator security configuration security vulnerabilities caused by improper, user safety awareness is not strong, select the user's password, the user will inadvertently own account feel free to lend or share with others, and so will the threat to network security.
2 as a malicious attack:
This is a computer network, the greatest threat to the opponent's attacks and computer crime would fall into this category.
This type of attack can be divided into two kinds: one is the active attacks, it means selectively destroy the validity and integrity of information; the other is passive attack, it is without prejudice to the normal work situations, to intercept, steal, decipher for important confidential information. Both of these attacks are on the Internet cause great harm, and result in leakage of confidential data.3 network software vulnerabilities and the "back door":
Network software can't be 100% free of defect and no vulnerability, however, these flaws and defects precisely hackers to attack a target of choice, have seen the hacker to hack into networks internal events, most of these events is that security measures do not improve the bitter fruit of incurred.
In addition, the software's "backdoor" is a software company for programmers to help themselves, which is not generally known to outsiders, but once the "backdoor" yawning, its consequences will be disastrous.Computer network security policies
1 physical security policy
Physical security policy aims to protect computer systems, networks, servers, printers and other hardware entity and communication links from natural disasters, man-made destruction and daxian attacks; verify user identity and privileges, preventing the user from ultra vires actions; ensure that the computer system has a good electromagnetic compatibility work environment; to establish a comprehensive security management system to prevent illegal access to computer control room and a variety of theft, sabotage.
Suppress and prevent electromagnetic leaks (i.e. TEMPEST Technologies) is the physical security policies is a major problem.
At present, the main protection measures have two categories: one category is protective for conducted emissions, mainly to take on the power cable and signal wire with good performance, reduce transmission impedance filters and cross-coupling between the conductors. Another kind of protection against radiation, such protection measures can be divided into the following two ways: first, using a variety of electromagnetic shielding measures, such as on the equipment of metal shielding and various plug shield, at the same time on the engine room of the sewage pipes, heating pipes and metal doors and Windows for shielding and isolation; the second is the interference protection measures, that is, computer system, the use of jamming devices produce a computer system pseudo noise radiation related to space radiation to cover up the computer system of the operating frequency and information features.2 access control policy
Access control, network security and protection of major policy, its main task is to ensure that network resources from unauthorized use and very accessible.
It also maintains a network system security, the protection of important means of network resources. Various security policies must complement can really play a protective effect, but the access control can be said that it is necessary to ensure network security and the most important one of the core strategies. Here we talk about a variety of access control policy.Network access control
Network access control for network access, provides the first layer of access control.
It controls which users can log on to the server and access network resources, network access control to allow users and allow them access at any workstation.The user's network access control can be divided into three steps: identification and authentication of the user name, user password of identification and authentication, the user account's default restriction checking.
Three points in any of the gateway as long as they are not, the user will not be able to access the network.On the network user name and password for authentication to prevent illegal access to the first line of Defense.
User registration when first entering the user name and password, the server will verify the entered user name is legitimate. If the validation is legitimate, they continue to validate user input of a password, otherwise, the user will be denied from the network. The user's password is user access. In order to guarantee the security of your password, the user password can not be displayed on the screen, the password length should be not less than 6 characters, and password characters are best numbers, letters and other characters, the user's password must be encrypted, the encryption method for many, the most common methods are: based on the one-way function password encryption, based on the test mode password encryption, based on public key encryption scheme for password encryption, the square of the remaining password-based encryption, shared based on polynomialPassword encryption, digital signature scheme of password encryption. After the above method of encryption password, even if you are a system administrator to obtain it. Users also can use one-time user password, you can also use portable validator (e.g. smart cards) to verify the identity of a user.The network administrator can control and restrict the normal user account use, access, network, time, manner.
Username or user ID is all computer system the most basic form of security. User account should be a system administrator to set up. User password should be a per-user access networks must be submitted by the "documents", users can modify their own password, the system administrator should be able to control the password following limit: minimum password lengths, forced to modify the password of a time interval, password uniqueness, passwords expire after the number of grace allowed network access.A valid user name and password authentication, and then further fulfilment of the user account's default restriction checking.
Network should be able to control user logins access site, restrict user access time, restrict user access, the number of workstations. When users access the network on paying "tariff" exhausted, the network should also be able to limit the user's account, the user should be can't access network to access network resources. Network access to all users. If you repeatedly for a password is not correct, you think is illegal intrusion, the user should give the alarm message.Network access control
Network access control is illegal operation against a network's security protective measures.
Users and user groups are given certain privileges. Network control users and user groups have access to which directories, subdirectories, files and other resources. You can specify the user on the file, directory, equipment to perform which operations. Trustee assignments and inherited permissions mask (IRM) as its two implementations. Trustee assignment control for users and groups how to use the Web server's directory, files, and device. Inherited rights mask acts like a filter, you can limit the subdirectories inherit from parent directory permissions. We can access the user is divided into the following categories: (1) special users (that is, the system administrator); (2) General user, system administrator according to their actual needs permission for their distribution operations; and (3) the audit of the user, is responsible for network security control and audit of the use of resources. Users on a network resource access rights to use an access control sheet to describe.Directory-level security controls
Network should allow the control user to the directory, file, device access.
User in the directory level specified permissions on all files and subdirectories are valid, you can further specify a subdirectory of the directory and file permissions. On the directory and file access permissions are eight: System Administrator rights (Supervisor), read permissions (Read), write (Write), create permissions (Create), delete permissions (Erase), modify permissions (Modify), file search permissions (File Scan), access control permissions (Access Control). Users of the file or destination of the effective permissions depend on the following two factors: the user's trustee assignment, the user's Group Trustee assignment, inherited permissions mask cancel user permissions. A network system administrator for the user to specify the appropriate access permissions, the access control user access to the server. Eight kinds of access rights effective combination allows users to work efficiently and effectively to control user access to resources on the server, thereby strengthening the network and server security.Property security control
When using the file, directory, and network devices, network systems administrator should to files, directories, specify the access properties.
Property security controls can be given property and network servers, directories, and link the network device. Property security in access security to provide further security. Resources on the network should be proactively identified a set of security attributes. Users on a network resource access rights corresponding to an access control sheet, denoting the user access to network resources. Property is set to overwrite the specified any trustee assignments and effective permissions. Properties are often able to control the following rights: to write data to a file, copy a file, delete the directory or file, view the directory and file, executable file, hidden files, shared, System properties, and so on. Network property can protect critical directories and files, preventing the user from the directory and files mistakenly delete, modify, display, perform, and so on.Network server security control
Network allowed on the server console to perform a series of actions.
The user uses consoles can load and unload the module, you can install and remove software, and so on. Network server security controls including the ability to set a password to lock the server console to prevent unauthorized user to modify, delete, or destroy data, important information; you can set the Server login time restriction, illegal access to testing and close intervals.Network monitoring and locking control
The network administrator should monitor the implementation of the network, the server should log user access to network resources, on the illegal network access, the server should be based on a graphic or text, or sound, alarm, network administrator's attention.
If criminals trying to enters the network, the network server should automatically record attempt to try to enter the number of the network, if the number of illegal access to set the value, then the account will be automatically locked.
No comments:
Post a Comment