【24h】

CARP Compliant Proxy Enforcer Frame Work

机译:鲤鱼兼容的代理执法者框架工作

获取原文

摘要

One of the important aspects of network management is the proxy usage. Nowadays it is a common practice to force the user to connect to some network services via the proxy. The disadvantage of this method is that it requires from the user an additional network knowledge and manual client configuration. The problem can be solved by developing a system that will enforce proxy usage and should remain completely transparent to user. In addition to that, the enforcing should reduce network traffic, increase the speed and thus increase performance. In this research we present a frame work of a proxy system that is able to process the requests of a number of different application level protocols. The system deals with program redirection of HTTP protocol requests, but the same scheme can be applied to implement the enforcer for other protocols too. The system is implemented on Linux Red Hat platform and can run on new distribution of host operating systems that implements IP firewall (ipfw). This system also posses a different dimension of implementing and enforcing security policy among enterprises. This could be achieved by stopping any proxy bypass event processed by clients to browse for prohibited sites during the working hours according to certain companies' security policies. The system can be installed on host operating system to provide support to all clients independent of their platforms. The system is tested in a private network that simulates the real traffic environment with 10 proxy servers, 50 hosts that serve 250,000 clients connected via different network topologies, technologies and services. The system showed feasibility and efficiency for improving network performance between 17-23 % which is a fairly successful result.
机译:网络管理的一个重要方面是代理使用。如今,迫使用户通过代理将用户连接到某些网络服务是一个常见的做法。该方法的缺点是它需要用户提供额外的网络知识和手动客户端配置。通过开发将执行代理用法的系统可以解决问题,并且应该对用户完全透明地保持完全透明。除此之外,强制性还应缩短网络流量,提高速度,从而提高性能。在本研究中,我们展示了一个能够处理许多不同应用级别协议的请求的代理系统的帧工作。该系统涉及HTTP协议请求的程序重定向,但也可以应用相同的方案来实现其他协议的Enforcer。系统是在Linux Red Hat平台上实现的,可以在实现IP防火墙(IPFW)的主机操作系统的新分发上运行。该制度还拥有不同的实施和执行企业安全政策的层面。这可以通过阻止客户处理的任何代理旁路事件来实现,以根据某些公司的安全政策在工作时间浏览禁止的网站。系统可以安装在主机操作系统上,为所有独立于其平台的客户提供支持。该系统在专用网络中进行测试,该网络模拟具有10个代理服务器的真实流量环境,50个主机,可通过不同的网络拓扑,技术和服务连接250,000个客户端。该系统显示了提高网络性能的可行性和效率,介于17-23%之间,这是一个相当成功的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号