Network Security
by
Jinlei Wang
Southern New Hampshire University
Abstract
With rapid development of information technology and Internet, the computer becomes
more and more significant in our daily life. Many people use computer to do their work,
send email and purchase online. Many people and organizations use Internet to pass the
significant information. So the computer network security problem, directly relates to
domain the and so on a national politics, military, economy security and the stability. In
this paper first talk about the radical change which the information network security
connotation occurs, talk about the network security problem is one of most significant
issue that people need to concerned. Further discuss the network topology safe design
which includes the network topology analysis and the network security brief analysis.
Then specifically narrated the network firewall security technology classification and it’s
the main technical characteristic, the firewall deployment principle, and the position which
deployed from the firewall in detail elaborated the firewall choice standard.
Simultaneously, mad the brief analysis on exchange of information encryption technology
classification and the RSA algorithm. Finally, analyzes the network security technology the
research present situation and the trend.
Table of Content
Research Purpose and Background of the Network Security Technology. 3
Advanced Technologies and Products for Networking Security. 5
Firewall Technology. 5
Data Encryption. 6
Authentication Technology. 6
Anti-virus Software. 7
Common Network Attacks. 8
Trojan Horse. 8
Mail Bomb. 9
Overload Attack. 10
Flooding Attack. 11
The Security Design of Network Topology. 11
Brief Analysis about Network Attack. 14
Firewall Technology. 16
The Define and Origin of the Firewall 17
The Choice of Firewall 18
Encryption Technology. 20
Symmetric Encryption Technology. 20
Asymmetric Encryption/Public Key Encryption. 21
RSA Algorithm.. 22
Registration and Certification Management 23
Certification Authority. 23
Registration Authority. 23
Security Backup and Restore. 23
Certificate Management and Revoke System.. 24
The Trend of Network Security in The Future. 24
Research Purpose and Background of the Network Security Technology
With the rapid development of information technology, the computer becomes the
significant part of people life. More and more computers and servers are through Internet
to connect with each others. The meaning of information security is a fundamental change
has taken place. It not only from the general defense into a very ordinary precautions, but
also from a special field come into everywhere of people daily life. When the world turns
into the information society and network society,
world would establish a complete set of network security system.
Network security consists of the provisions and policies adopted by a network
administrator to prevent and monitor unauthorized access, misuse, modification, or denial
of a computer network and network-accessible resources. Network security involves the
authorization of access to data in a network, which is controlled by the network
administrator. Users choose or are assigned an ID and password or other authenticating
information that allows them access to information and programs within their authority.
Network security covers a variety of computer networks, both public and private, that are
used in everyday jobs conducting transactions and communications among businesses,
government agencies and individuals. [1]
The products about network security have the following characteristics: first, the
diversification of network security policy and technology. It is not safe if using a uniform
strategy and technology. Second, as the development of network security strategy, the
network security mechanism is also constantly changing. Third, with the extension of
network in the social various aspects, there are more and more methods access into the
network. Therefore, network security is a kind of very complicated system engineering.
The technology of network security and the technology anti-security just like the two sides
of a coin are constantly to rise. The network security is a kind of industry that will develop
as the improvement of technology in the future.
Computer network is faced with great threat at nowadays. The threat is compose of many
factors and will be constantly brought huge losses to the society. Network security has
been paid great attention in every field of the information society. With the continuous
development of computer network, the global information has become the trend of human
development to bring a revolutionary reform for the government agencies, enterprises and
institutions. But because of the computer network to connect various forms, terminal
distribution inhomogeneity and network features such as openness and connectivity,
causing network vulnerable to hackers, viruses, malware and other misconduct in the
attack. So the security and confidentiality of information on the Internet is a viral problem.
For the military automated command network, C3I system, Banks and government these
transmission of sensitive data in terms of computer system, the security and confidentiality
of information on the Internet are more important. Therefore, the network must have a
strong enough safety measures, otherwise, the network will be a useless, and even
endanger the safety of national networks. Whether in LAN or WAN, there is the potential
threat from natural and human factors and the vulnerability of the network. The network
security measures should be comprehensive to against various threats and network
vulnerability, only in this way to ensure that network information confidentiality, integrity
and availability. In order to ensure information on the Internet safety and smooth, the
computer network security and the preventive measures is imminent. This paper talks
about the computer net work security management and technology measures.
Advanced Technologies and Products for Networking Security
To guarantee the security of computer network system, people need to use and research
some advanced technologies and products. People mainly use the relevant technologies
and products have the following kinds at present:
Firewall Technology
In order to guarantee the network security, prevent the extranet illegal invasion of Intranet,
set up a barrier between the protected network and public network. This barrier is called a
firewall. It is one or a set of system, the system can be set which internal services are can
be accessed by the outside world, who from the outside world can access to the internal
services, and which external services can be accessed by the internal person. A Firewall is
a collection of components, which are situated between two networks that filters traffic
between them by means of some security policies. A Firewall can be an effective means of
protecting a local system or network systems from network based security threats while at
the same time affording access to the outside world through wide area networks and the
Internet. [4]It can monitor, limit, change of data flow across the firewall, confirm the
sources and destination, check the data format and content, and in accordance with the
rules of the user or data transmission. It mainly includes: the application layer gateway,
packet filtering and proxy server and so on several big types.
Data Encryption
Data encryption usually is used with firewall security technology. It can improve the
security and privacy of information systems and data, to prevent the secret data by external
broken analysis. With the rapid development of information technology, network security
and information security has become increasingly aroused people’s concern. For apart
from law, management, strengthen the security protection of data on, from two aspects of
technology in software and hardware measures to promote the development of data
encryption technology and physical protection technology. According to the function
different, data encryption technology is mainly divided into the integrity of the data
transmission, data storage, data identification and key management these four
technologies.
Authentication Technology
Authentication technology is a very significant way to prevent network attack. It is the
important role of all kinds of information security for open environment. Authentication is
to point to verify the identity of an end user or equipment process, namely certification to
establish the identity of the sender or receiver information. There are two purposes of
certification. First, to verify the information of sender is real, not be pretend. This is known
as signal source identification. Second, the integrity of the authentication information is to
ensure that the information in the process of transfer has not been doctor or delay, etc.
Currently in use of authentication mainly include: the message authentication,
authentication and digital signature.
Anti-virus Software
Most of the computer viruses written in the early and mid-1980s were limited to
self-reproduction and had no specific damage routine built into the code. [3] To improve
the networking security, first, people need to strengthen the consciousness of anti-virus.
Second, people need to install good anti-virus software. Qualified antivirus software
should satisfy the following conditions:
First, strong ability of scan and antivirus, there are more than 40000 kinds of popular
computer virus in the current global computer network. In a variety of operating system
including windows, UNIX and Netware system have a great number of viruses that can
harm computer. Based on that, people require the installation of anti-virus software with
the strong ability that can antivirus and scan virus in the different systems.
Second, the perfect upgrade services, compared with the other software, antivirus software
is more need to constantly upgrade for help user find out some new virus in their computer.
Common Network Attacks
Trojan Horse
Trojan horse is entrained in entrained in normal function in the implementation of the
program for a period of additional code to operate. Because of Trojan horse in additional
operation code, the user does not know contain a Trojan horse program at execution time,