| 168 | 11 | 29 |
| 下载次数 | 被引频次 | 阅读次数 |
堡垒机是管控IT运维人员访问核心IT资产的专用系统主机。使用基于应用代理的运维堡垒机取代传统的基于录像的堡垒机,审计效率和安全系数至少可以提高1个数量级。在介绍运维堡垒机应用背景、分析现有运维堡垒机的审计缺陷后,提出应用代理改进方案。在介绍堡垒机的概念、构成、拓扑、主要功能后,提出基于应用代理的重要改进。以Windows系统为例,列举出一期常用的需求和功能:文件管理、IIS管理、系统服务管理、计划任务管理、进程管理、远程桌面管理,并给出上述需求的技术实现方法。最后,列举了传统堡垒机和基于应用代理的堡垒机各种数据比较。
Abstract:The bastion machine is a dedicated system host which control IT operation and maintenance personnel to access the core IT assets.The audit efficiency and safety factor will increase at least by a magnitude using application proxy bastion machines rather than the traditional video playback bastion machines.After introducing the background of operation and maintenance bastion machines and analyzing the shorts of current bastion machines,giving the solution about application proxy.After introducing the concept,construction,topology,main functions of bastion machines,bring the important improvements about application proxy.For example of Windows,lists some frequent requirements and functions: file management,IIS management,system service management,scheduled tasks management,process management,remote desktop management,and lists the implemention methods of above requirements.Finally,compare the application proxy bastion machines with the traditional bastion machines based video playback.
[1]王栋,来风刚,李静,数据中心IT运维审计体系研究.[J]ELECTRIC POWER IT,2012,10(1):20-23.
[2]杜宁宁,赵庆亮,浅谈信息安全审计在金融行业的实践.[J]中国内部审计,2012-4:66-68.
[3]韩荣杰,于晓谊,基于堡垒主机概念的运维审计系统.[J]安全视窗,2012-13:56-58.
[4]林秀,IT安全管理与综合审计系统应用探讨.[J]电信技术,2011-6:66-68.
基本信息:
中图分类号:TP309
引用信息:
[1]吴耀芳,来学嘉.基于应用代理的运维堡垒机研究[J].微型电脑应用,2013,29(08):34-36.
2013-08-20
2013-08-20