首页> 外文OA文献 >Design and development of an intelligent security layer for web-based applications
【2h】

Design and development of an intelligent security layer for web-based applications

机译:设计和开发基于Web的应用程序的智能安全层

摘要

Methods to activate firewall mechanism have been introduced in this research. The purpose is to build stronger protection for the intranet from the threats of Internet. The foundation of the work is the threat reduction strategies that are derived from formalizing and identifying the interaction between internal users and external parties. Internet access model is developed to facilitate this task. Mechanism of active firewall are divided into two main process i.e. initialisation and runtime process. The former process deals with the mechanism to start up and bring the active firewall into a point of its operation. Three approaches are introduced, namely open condition, close condition and lattice-based method. The open condition and close condition set the firewall into its extreme condition i.e. to open all available communication line or to close all connection respectively, while the lattice-based method affords to bring firewall into its optimum level to protect the intranet by establishing Internet connection based on the predetermined security level. In the runtime process, three methods are introduced as well i.e. adaptively updating security policy using fuzzy reasoning, detecting suspicious process using distributed agent-based module, and zero-based approach to have minimal network services at runtime. Besides analysing each method using its own parameters such as processing time, accuracy and speed for organizing canals, global evaluations were also held to investigate the protection can be delivered to the intranet. In this evaluation, security analysis and comparative study is held, in which each initialisation and runtime process are combined and analysed using three parameters that are created based on RFC 2979 i.e. probability of available network services, probability of exposed line, and denial of services. Results of this study deliver the combination of lattice-based and agent-based module become the best method for activating firewall.
机译:本研究介绍了激活防火墙机制的方法。目的是为Intranet建立更强大的保护,使其免受Internet威胁。工作的基础是减少威胁的策略,这些策略是通过形式化和识别内部用户与外部方之间的交互作用而得出的。开发了Internet访问模型来简化此任务。主动防火墙的机制分为两个主要过程,即初始化和运行过程。前一个过程处理启动机制,并使活动防火墙进入其运行点。介绍了三种方法,即开放条件,封闭条件和基于格的方法。打开状态和关闭状态将防火墙设置为极端状态,即分别打开所有可用的通信线路或关闭所有连接,而基于格的方法通过建立基于Internet的连接,使防火墙处于最佳状态以保护Intranet。在预定的安全级别上。在运行时过程中,还引入了三种方法,即使用模糊推理自适应更新安全策略,使用基于分布式代理的模块检测可疑过程以及基于零的方法以在运行时具有最少的网络服务。除了使用其自身的参数(例如,处理时间,准确性和组织运河的速度)分析每种方法外,还进行了全局评估以调查可将保护措施传递到Intranet的方式。在此评估中,进行了安全性分析和比较研究,其中使用基于RFC 2979创建的三个参数(即可用网络服务的概率,裸线的概率和拒绝服务)组合并分析了每个初始化和运行时过程。这项研究的结果提供了基于晶格和基于代理的模块的组合,成为激活防火墙的最佳方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号