信息网络安全 ›› 2015, Vol. 15 ›› Issue (1): 56-60.doi: 10.3969/j.issn.1671-1122.2015.01.010

• 技术研究 • 上一篇    下一篇

基于云查杀技术的轻量级局域网信息保护机制研究

程骏路(), 杨阳, 秦鹏宇, 程久军   

  1. 同济大学计算机科学与工程系,上海 201804
  • 收稿日期:2014-09-30 出版日期:2015-01-10 发布日期:2015-07-05
  • 作者简介:

    作者简介: 程骏路(1990-),男,上海,硕士研究生,主要研究方向:车联网、信息安全;杨阳(1991-),男,山东,硕士研究生,主要研究方向:车联网、信息安全;秦鹏宇(1993-),男,山东,本科,主要研究方向:信息安全;程久军(1974-),男,安徽,副教授,博士,主要研究方向:网络与分布式计算。

  • 基金资助:
    国家国际科技合作专项[2013DFM10100]

Lightweight LAN Information Security Protection Mechanism Based on Cloud Security

CHENG Jun-lu(), YANG Yang, QIN Peng-yu, CHENG Jiu-jun   

  1. Department of Computer Science & Engineering, Tongji University, Shanghai 201804, China
  • Received:2014-09-30 Online:2015-01-10 Published:2015-07-05

摘要:

文章基于云查杀技术,设计并实现了一个轻量级的局域网信息保护机制。该机制主要围绕局域网内的路由器做安全防护,可以截获试图非法修改路由器配置信息的数据包,弹出相应的提示信息;将网内某台主机作为云检测端,维护一个相关配置信息的数据库(如DNS库,库中维护相应信息的黑名单和白名单),周期性地对网内终端进行扫描,查看每个终端的配置信息,与配置信息数据库中的数据进行比对,并根据规则在需要的情况下对终端做相应的重新配置或向终端用户及管理员发出警告。该机制借鉴了云查杀的理念,将其从公网移植到了局域网,弥补了一般网络入侵检测机制缺乏应用层分析手段的弊端。针对目前家庭路由器用户普遍缺乏安全保护意识,不懂如何进行家庭网络防护的问题,文中机制不需要用户具备信息安全方面知识,对普通用户十分友好,在家庭局域网中具有广阔的应用前景。

关键词: 局域网, 路由器, 入侵检测系统, 云查杀

Abstract:

This paper designed and implemented a cloud-based lightweight local area network (LAN) information security protection mechanism. This mechanism mainly protects the safety of routers inside a LAN by capturing the illegal packets which trying to modify configurations of routers and warning the users. Some computer acts as the detector in the cloud, maintains a database containing configurations, such as black and white lists of DNS servers, scans every terminals in the network periodically, lookups their configurations, compares them with data in the database and resets them if necessary according to the rules or warns the administrator. It borrowed the idea of cloud security in the Internet and applied to intranets and makes up the malpractice of normal intrusion detection system lacking of analysis on application layer. It is very friendly to normal users, as they don’t need a lot of information security knowledge, which results in a wide application foreground in home LANs.

Key words: LAN, router, IDS, cloud security

中图分类号: