The Research and Implementation of Network Security Defense Architecture in Cloud Virtual Environments

碩士 === 國立中正大學 === 通訊工程研究所 === 102 === Since 2009 the concept of cloud computing has been proposed, a variety of Internet services have emerged. The concept of cloud computing, is simply through a virtual network resources provided by providers, users can quickly build a huge network of virtual compu...

Full description

Bibliographic Details
Main Authors: Kuang-Yao Hung, 洪光耀
Other Authors: Kim-Joan Chen
Format: Others
Language:zh-TW
Published: 2014
Online Access:http://ndltd.ncl.edu.tw/handle/65590578430208015262
id ndltd-TW-102CCU00650076
record_format oai_dc
spelling ndltd-TW-102CCU006500762016-03-11T04:12:46Z http://ndltd.ncl.edu.tw/handle/65590578430208015262 The Research and Implementation of Network Security Defense Architecture in Cloud Virtual Environments 在雲端虛擬環境建構網路安全防禦架構之研究與實現 Kuang-Yao Hung 洪光耀 碩士 國立中正大學 通訊工程研究所 102 Since 2009 the concept of cloud computing has been proposed, a variety of Internet services have emerged. The concept of cloud computing, is simply through a virtual network resources provided by providers, users can quickly build a huge network of virtual computing in the cloud environments, users can quickly build a huge network of virtual computing in the cloud environments to replace the physical equipments to save the huge cost and the complex settings, and to achieve offsite backup and without service interruption and so on. So the major companies all working to find a more convenient and quickly and cost-saving methods within virtual environments. However, the network security for virtual environments has no uniform specification and approaches, major security vendors are committed to developing a new protective equipment, but improving the firewall is still the fastest approach. In this thesis, we propose a defense architecture about network management and security, for resolve some security issues after the traditional physical network transform to cloud virtual network. In this paper, a method based on VLAN segmentation will be improved, replacing a physical firewall by the virtual switch which has the function of packets forwarding, to save the time that packets exchanged between the physical and virtual network. Combined with the security policy decision system to make defense rules, according to defense rules by SPDS, controller will command the virtual switch to perform it. Through this paper, we hope to construct a simple virtual firewall which can implement the function of physical network security defense system in cloud virtual environments. Kim-Joan Chen 陳景章 2014 學位論文 ; thesis 70 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 國立中正大學 === 通訊工程研究所 === 102 === Since 2009 the concept of cloud computing has been proposed, a variety of Internet services have emerged. The concept of cloud computing, is simply through a virtual network resources provided by providers, users can quickly build a huge network of virtual computing in the cloud environments, users can quickly build a huge network of virtual computing in the cloud environments to replace the physical equipments to save the huge cost and the complex settings, and to achieve offsite backup and without service interruption and so on. So the major companies all working to find a more convenient and quickly and cost-saving methods within virtual environments. However, the network security for virtual environments has no uniform specification and approaches, major security vendors are committed to developing a new protective equipment, but improving the firewall is still the fastest approach. In this thesis, we propose a defense architecture about network management and security, for resolve some security issues after the traditional physical network transform to cloud virtual network. In this paper, a method based on VLAN segmentation will be improved, replacing a physical firewall by the virtual switch which has the function of packets forwarding, to save the time that packets exchanged between the physical and virtual network. Combined with the security policy decision system to make defense rules, according to defense rules by SPDS, controller will command the virtual switch to perform it. Through this paper, we hope to construct a simple virtual firewall which can implement the function of physical network security defense system in cloud virtual environments.
author2 Kim-Joan Chen
author_facet Kim-Joan Chen
Kuang-Yao Hung
洪光耀
author Kuang-Yao Hung
洪光耀
spellingShingle Kuang-Yao Hung
洪光耀
The Research and Implementation of Network Security Defense Architecture in Cloud Virtual Environments
author_sort Kuang-Yao Hung
title The Research and Implementation of Network Security Defense Architecture in Cloud Virtual Environments
title_short The Research and Implementation of Network Security Defense Architecture in Cloud Virtual Environments
title_full The Research and Implementation of Network Security Defense Architecture in Cloud Virtual Environments
title_fullStr The Research and Implementation of Network Security Defense Architecture in Cloud Virtual Environments
title_full_unstemmed The Research and Implementation of Network Security Defense Architecture in Cloud Virtual Environments
title_sort research and implementation of network security defense architecture in cloud virtual environments
publishDate 2014
url http://ndltd.ncl.edu.tw/handle/65590578430208015262
work_keys_str_mv AT kuangyaohung theresearchandimplementationofnetworksecuritydefensearchitectureincloudvirtualenvironments
AT hóngguāngyào theresearchandimplementationofnetworksecuritydefensearchitectureincloudvirtualenvironments
AT kuangyaohung zàiyúnduānxūnǐhuánjìngjiàngòuwǎnglùānquánfángyùjiàgòuzhīyánjiūyǔshíxiàn
AT hóngguāngyào zàiyúnduānxūnǐhuánjìngjiàngòuwǎnglùānquánfángyùjiàgòuzhīyánjiūyǔshíxiàn
AT kuangyaohung researchandimplementationofnetworksecuritydefensearchitectureincloudvirtualenvironments
AT hóngguāngyào researchandimplementationofnetworksecuritydefensearchitectureincloudvirtualenvironments
_version_ 1718202783110266880