ǰÑÔ
µ±Ç°£¬ÐÅÏ¢°²È«¡¢ÍøÂ簲ȫºÍ¸öÈ˼ÆËã»úµÄ°²È«ÊÇÒ»¸öÆÈÇÐÐèÒª½â¾öµÄÎÊÌ⣬ԽÀ´Ô½¶àµÄÓû§¿ªÊ¼´Ó´«Í³µÄ±»¶¯µÄ¡°·À¡±¡¢¡°¶Â¡±µÈ°²È«ÊÖ¶ÎÏò»ý¼«·ÀÓùµÄ¡°¿ÉÐżÆË㡱¹ý¶É¡£µ±Ç°´ó²¿·ÖÐÅÏ¢°²È«ÏµÍ³Ö÷ÒªÊÇÓÉ·À»ðǽ¡¢ÈëÇÖ¼à²âºÍ²¡¶¾·À·¶µÈ×é³É£¬ÕâЩ³£¹æµÄ°²È«ÊÖ¶ÎÖ»ÄÜÊÇÒÔ¹²ÏíÐÅÏ¢×ÊԴΪÖÐÐÄ£¬ÔÚÍâΧ¶Ô·Ç·¨Óû§ºÍԽȨ·ÃÎʽøÐзâ¶Â£¬ÒÔ´ïµ½·ÀÖ¹Íⲿ¹¥»÷µÄÄ¿µÄ£¬¶Ô¹²ÏíÔ´µÄ·ÃÎÊÕßÔ´¶Ë²»¼Ó¿ØÖÆ¡£¶ñÒâÓû§µÄ¹¥»÷ÊÖ¶ÎÔ½À´Ô½¸ßÃ÷£¬·À»¤ÕßÖ»Äܽ«·À»ðǽԽ¡°Æö¡±Ô½¸ß¡¢ÈëÇÖ¼ì²âÔ½×öÔ½¸´ÔÓ¡¢¶ñÒâ´úÂë¿âÔ½×öÔ½´ó£¬´Ó¶øµ¼ÖÂÎó±¨ÂÊÔö¶à¡¢°²È«Í¶Èë²»¶ÏÔö¼Ó¡¢Î¬»¤Óë¹ÜÀí¸ü¼Ó¸´ÔÓºÍÄÑÒÔʵʩÒÔ¼°ÐÅϢϵͳµÄʹÓÃЧÂÊ´ó´ó½µµÍ¡£
1.·À»ðǽµÄ×÷ÓÃ
ÖÃÓÚ²»Í¬ÍøÂ簲ȫÓòÖ®¼ä£¬ËüÊDz»Í¬ÍøÂ簲ȫÓò¼äͨÐÅÁ÷µÄΨһͨµÀ£¬Äܸù¾ÝÆóÒµÓйصݲȫÕþ²ß¿ØÖÆ£¨ÔÊÐí¡¢¾Ü¾ø¡¢¼àÊÓ¡¢¼Ç¼£©½ø³öÍøÂçµÄ·ÃÎÊÐÐΪ¡£·À»ðǽֻÊǼòµ¥µÄ¸øÓû§ÌṩһÖÖÅж¨»úÖÆ£¬¼´Óû§¿É×Ô¼ºÑ¡ÔñÊÇ·ñÔËÐгÌÐò£¬µ«¸Ã³ÌÐòÊÇ·ñ°²È«£¬·À»ðǽÎÞ·¨×ö³öÅжϣ¬Òò´ËÎÞ·¨·ÀÖ¹¶ñÒâ³ÌÐòµÄ¹¥»÷¡£ Èçͼ1Ëùʾ£º
ͼ1 £º·À»ðǽÔÀíͼ
2.ÈëÇÖ¼ì²âϵͳµÄ×÷ÓÃ
ÈëÇÖ¼ì²âϵͳ(Intrusion Detection System)ͨ¹ý´Ó¼ÆËã»úÍøÂç»ò¼ÆËã»úϵͳµÄ¹Ø¼üµãÊÕ¼¯ÐÅÏ¢²¢½øÐзÖÎö£¬´ÓÖз¢ÏÖÍøÂç»òϵͳÖÐÊÇ·ñÓÐÎ¥·´°²È«²ßÂÔµÄÐÐΪºÍ±»¹¥»÷µÄ¼£Ïó¡£ÈëÇÖ¼ì²âϵͳÖÐ×î¹Ø¼üµÄ¾ÍÊ**¹½¨ÈëÇÖÐÐÎªÌØÕ÷¿â£¬ÓÉÓÚĿǰûÓÐÒ»ÖֺõĻúÖÆÀ´Åж϶ñÒâÐÐΪ£¬Òò´ËÖ»ÄÜ·ÀÖ¹²¿·ÖµÄ¶ñÒâÐÐΪ¡£Í¼2 ΪÈëÇÖ¼ì²âµÄÁ÷³Ìͼ£¬Í¼3Ϊ¿É¼ì²âµ½µÄ²¿·Ö¹¥»÷ÀàÐÍ
ͼ2£ºÈëÇÖ¼ì²âµÄÁ÷³Ìͼ
ͼ3£º¿É¼ì²âµ½µÄ¹¥»÷ÀàÐÍ
4×ܽá
¶ñÒâÓû§µÄ¹¥»÷Êֶα仯¶à¶Ë,·À»¤ÕßÖ»ÄÜ:
·À»ðǽԽÆöÔ½¸ß
ÈëÇÖ¼ì²âÔ½×öÔ½¸´ÔÓ
¶ñÒâ´úÂë¿âÔ½×öÔ½´ó
µ¼ Ö£º
Îó±¨ÂÊÔö¶à£¬
°²È«Í¶Èë²»¶ÏÔö¼Ó
ά»¤Óë¹ÜÀí¸ü¼Ó¸´ÔÓºÍÄÑÒÔʵʩ
ÐÅϢϵͳµÄʹÓÃЧÂÊ´ó´ó½µµÍ
¶ÔÐµĹ¥»÷ÈëÇÖºÁÎÞ·ÀÓùÄÜÁ¦£¨Èç³å»÷²¨£©
·´Ë¼£ºÀÏÈýÑù¡¢¶Â©¶´¡¢×÷¸ßǽ¡¢ ·ÀÍâ¹¥¡¢·À²»Ê¤·À
²úÉúÕâÖÖ¾ÖÃæµÄÖ÷ÒªÔÒòÊDz»È¥¿ØÖÆ·¢Éú²»°²È«ÎÊÌâµÄ¸ùÔ´£¬¶ø½öÔÚÍâΧ½øÐзâ¶Â¡£ÈëÇÖ¹¥»÷µÄÔ´Í·ÊÇPCÖÕ¶ËÉÏ£¬ºÚ¿ÍÀûÓñ»¹¥»÷ϵͳµÄ©¶´ÇÔÈ¡³¬¼¶Óû§È¨ÏÞ£¬ËÁÒâ½øÐÐÆÆ»µ£»×¢È벡¶¾Ò²ÊÇ´ÓÖÕ¶Ë·¢ÆðµÄ£¬²¡¶¾³ÌÐòÀûÓÃPC²Ù×÷ϵͳÔÚÖ´ÐдúÂëʱ²»¼ì²éÆäÒ»ÖÂÐÔµÄÈõµã£¬½«²¡¶¾´úÂëǶÈëµ½Ö´ÐдúÂë³ÌÐò£¬ÊµÏÖ²¡¶¾´«²¥£»¸üΪÑÏÖØµÄÊÇÖն˶ÔÓû§Ã»ÓнøÐÐÑϸñµÄ·ÃÎÊ¿ØÖÆ£¬ÇÖÈëÕß¿ÉÒÔ½øÐÐԽȨ·ÃÎÊ£¬Ôì³É²»°²È«Ê¹ʡ£
Èç¹û´ÓÖն˲Ù×÷ƽ̨¾Í¿ªÊ¼ÊµÊ©¸ßµÈ¼¶·À·¶£¬ÕâЩ²»°²È«ÒòËØ½«´ÓÖÕ¶ËÔ´Í·±»¿ØÖÆ¡£ÎªÁ˽â¾öPC»ú½á¹¹ÉϵIJ»°²È«£¬´Ó¸ù±¾ÉÏÌá¸ßÆä°²È«ÐÔ£¬ÔÚÊÀ½ç·¶Î§ÄÚÍÆÐпÉÐżÆËã¼¼Êõ£¬1999ÄêÓÉCompaq¡¢HP¡¢IBM¡¢IntelºÍMicrosoftǣͷ×éÖ¯TCPA( Trusted Computing Platform Alliance)£¬Ä¿Ç°ÒÑ·¢Õ¹³ÉÔ±190¼Ò£¬±é²¼È«Çò¸÷´óÖÞÖ÷Á¦³§ÉÌ¡£TCPAרעÓÚ´Ó¼ÆËãÆ½Ì¨Ìåϵ½á¹¹ÉÏÔöÇ¿Æä°²È«ÐÔ£¬²¢ÓÚ2001Äê1Ô·¢²¼ÁË¿ÉÐżÆËãÆ½Ì¨±ê×¼¹æ·¶£¨v1.1£©¡£2003Äê3ÔÂTCPA¸Ä×éΪTCG(Trusted Computing Group)£¬ÆäÄ¿µÄÊÇÔÚ¼ÆËãºÍͨÐÅϵͳÖй㷺ʹÓûùÓÚÓ²¼þ°²È«Ä£¿éÖ§³ÖϵĿÉÐżÆËãÆ½Ì¨£¬ÒÔÌá¸ßÕûÌåµÄ°²È«ÐÔ¡£
5.TPMÓÅÔ½µÄ°²È«ÌØÐÔ
¿ÉÐżÆËãÒÔ¼°ÏàËÆ¸ÅÄîËùÊܵ½µÄÍÆ³ç£¬¾¿Æä¸ù±¾Ô´×ÔÓÚÈÕÒæ¸´ÔӵļÆËã»·¾³Öвã³ö²»ÇîµÄ°²È«Íþв£¬´«Í³µÄ°²È«±£»¤·½·¨ÎÞÂÛ´Ó¹¹¼Ü»¹ÊÇ´ÓÇ¿¶ÈÉÏÀ´¿´ÒѾÁ¦ÓÐδ´þ¡£Ä¿Ç°ÒµÄڵݲȫ½â¾ö·½°¸ÍùÍù²àÖØÓÚÏÈ·ÀÍâºó·ÀÄÚ¡¢ÏÈ·À·þÎñÉèÊ©ºó·ÀÖÕ¶ËÉèÊ©£¬¶ø¿ÉÐżÆËãÔò·´ÆäµÀ¶øÐÐÖ®£¬Ê×Ïȱ£Ö¤ËùÓÐÖն˵ݲȫÐÔ¡£
¿ÉÐżÆËã¼¼ÊõÊÇÕë¶ÔĿǰ¼ÆËãϵͳ²»ÄÜ´Ó¸ù±¾ÉϽâ¾ö°²È«ÎÊÌâ¶øÌá³öµÄ£¬Í¨¹ýÔÚ¼ÆËãϵͳÖм¯³ÉרÓÃÓ²¼þÄ£¿é½¨Á¢ÐÅÈÎÔ´µã£¬ÀûÓÃÃÜÂë»úÖÆ½¨Á¢ÐÅÈÎÁ´£¬¹¹½¨¿ÉÐÅÀµµÄ¼ÆËã»·¾³£¬Ê¹´Ó¸ù±¾ÉϽâ¾ö¼ÆË㰲ȫÎÊÌâ³ÉΪ¿ÉÄÜ¡£¿ÉÐżÆËãµÄºËÐÄÊdzÆÎªTPM£¨¿ÉÐÅÆ½Ì¨Ä£¿é£©µÄ°²È«Ð¾Æ¬£¬×÷Ϊ¿ÉÐżÆËã¼¼ÊõµÄµ×²ãºËÐĹ̼þ£¬TPM±»ÒµÄÚÓ÷Ϊ°²È«PC²úÒµÁ´µÄ¡°ÐÅÈÎԵ㡱¡£ÔÚʵ¼ÊÓ¦ÓÃÖУ¬TPM°²È«Ð¾Æ¬±»Ç¶Èëµ½PCÖ÷°åÖ®ÉÏ£¬¿ÉΪƽ̨ÌṩÍêÕûÐÔ¶ÈÁ¿ÓëÑéÖ¤£¬Êý¾Ý°²È«±£»¤ºÍÉí·ÝÈÏÖ¤µÈ¹¦ÄÜ¡£
ͨ¹ýÍêÕûÐÔ¶ÈÁ¿ÓëÑéÖ¤£¬±£Ö¤PC´Ó¼Óµçʱ¿ÌÆð£¬Ò»Ö±µ½ÔÚÆäÉÏÔËÐеÄÿһ¸öÓ²¼þ¡¢²Ù×÷ϵͳÒÔ¼°Ó¦ÓÃÈí¼þ¶¼ÊÇ¿ÉÐŵá£
ͨ¹ýÊý¾Ý°²È«±£»¤£¬¸ø¸÷ÖÖÓ¦ÓÃÌṩ»ùÓÚÓ²¼þµÄ´æ´¢£¬´Ó¸ùÉϱ£Ö¤Êý¾ÝµÄ°²È«£¬Í¬Ê±Í¨¹ýÊý¾Ý·â×°µÈ¹¦ÄÜʵÏÖÊý¾ÝÓëÆ½Ì¨µÄ°ó¶¨£¬±ÈÈçÓû§¶ªÁ˱ʼDZ¾µçÄÔ£¬¼´Ê¹±ðÈËͨ¹ý°²×°ÆäËüµÄ²Ù×÷ϵͳ²é¿´µ½´ÅÅÌ£¬µ«ÓÉÓÚ´ÅÅÌÊý¾ÝÒѾÓëÆ½Ì¨°ó¶¨£¬¶øÆ½Ì¨µÄÐÅÏ¢ÒѾ·¢ÉúÁ˱仯£¬Òò´ËÆäËüÓû§Ò²ÎÞ·¨»ñÈ¡´ÅÅÌÊý¾Ý¡£Î¢ÈíµÄ×îвÙ×÷ϵͳvistaÖÐÌṩµÄ´ÅÅ̱£»¤¹¤¾ßbitlocker¾ÍÊÇ»ùÓÚÊý¾Ý·âװʵÏÖ´ÅÅÌÊý¾ÝµÄ°²È«±£»¤¡£
ͨ¹ýÉí·ÝÈÏÖ¤£¬ÏòÍⲿʵÌåÌṩϵͳƽ̨Éí·ÝÖ¤Ã÷ºÍÓ¦ÓÃÉí·ÝÖ¤Ã÷·þÎñ¡£ÏÖÓеļÆËã»úÔÚÍøÂçÉÏÊÇÒÀ¿¿²»¹Ì¶¨µÄÒ²²»Î¨Ò»µÄIP µØÖ·½øÐл£¬µ¼ÖÂÍøÂçºÚ¿Í·ºÀĺÍÓû§ÐÅÓò»×ã¡£¶ø¾ß±¸ÓÉȨÍþ»ú¹¹°ä·¢µÄΨһµÄÉí·ÝÖ¤ÊéµÄ¿ÉÐżÆËãÆ½Ì¨¾ß±¸ÔÚÍøÂçÉϵÄΨһµÄÉí·Ý±êʶ£¬´Ó¶øÎªµç×ÓÉÌÎñÖ®ÀàµÄϵͳӦÓõ춨ÐÅÓûù´¡£¬¶Ô»¥ÁªÍøµÄÓ¦ÓþßÓо޴óµÄ´Ù½ø×÷Óá£
5¡¢Êг¡·ÖÎö
¿ÉÐżÆËã¸ÅÄîµÄÌá³öµ½·¢Õ¹ÔÚÈ«ÇòÒ²¾Í¼¸Äê×óÓÒµÄʱ¼ä£¬Õ⼸Äêʱ¼äÕýÊÇÐÅÏ¢°²È«¼¼ÊõµÃÒÔ·ÉËÙ·¢Õ¹£¬³ÊÏÖÁîÈËÑÛ»¨çÔÂÒ¾ÖÃæµÄÖØÒªÊ±ÆÚ¡£Ãæ¶Ô²ã³ö²»ÇîµÄÐÅÏ¢ÍþвºÍ¹¥»÷£¬ÒÔÍùµÄ·À·¶´ëÊ©²»¶ÏÀÛ¼Ó£¬ÒÀÈ»²»¾¡ÈçÈËÒ⡣ר¼ÒÃÇ·ÖÎöÈÏΪ£¬¾ÉÓеķÀÓùÊÖ¶ÎÔÚÌåϵÉè¼ÆÉϾʹæÔÚ×ÅһЩÎÊÌ⣬¿ÉÐżÆËãµÄÉè¼ÆË¼Ïë±Ø½«³ÉΪ¹ú¼ÊÐÅÏ¢°²È«·¢Õ¹µÄÖ÷Á÷¡£
¾Ý°¬ÈðÊý¾Ý·ÖÎö£¬È«ÇòµÄÐÅÏ¢°²È«·¢Õ¹ËÙ¶ÈÕýÔÚÒÔÿÄê%ÒÔÉϵÄÊýÖµÔö³¤¡£¾ÝIDCµÄÁíÒ»ÏîÑо¿½á¹ûÏÔʾ£¬µ½2007Ä꣬ȫÇòËùÓÐPCÖн«ÓÐ% ¶¼»á¼ÓÉϰ²È«Ð¾Æ¬ºÍ¿ÉÐÅÈí¼þ£»
ת×Ô£ºhttp://sec.hebei.com.cn/blog_read.do?postID=182