首页 | 本学科首页   官方微博 | 高级检索  
     

面向虚拟桌面内外部数据流的安全控制机制研究
引用本文:邓霄霄,路川,马威.面向虚拟桌面内外部数据流的安全控制机制研究[J].计算机科学,2016,43(4):122-126.
作者姓名:邓霄霄  路川  马威
作者单位:中国人民解放军装备学院 北京101416,中国人民解放军装备学院 北京101416,北京交通大学计算机与信息技术学院 北京100044
基金项目:本文受中国铁路总公司科技研究开发计划重大课题(2013X010-A)资助
摘    要:桌面虚拟化需要借助虚拟桌面协议来实现内部应用数据和外部操作平台的数据交互。然而该类协议中的数据流控制机制并不完善,存在数据非法交互的安全隐患。为解决该问题,基于网关模式提出了一种面向虚拟桌面内外部数据流的安全控制机制SCIED。它不仅能对协议中的虚拟通道进行全面管控,避免修改协议和大量的终端,还具有较高的兼容性、拓展性。将它部署于网关并用于防护边界攻击,能显著减少服务器端的负载和安全隐患。实验表明,该SCIED能够有效保证数据流的安全交互,并且对现有桌面会话的性能影响较小。

关 键 词:桌面虚拟化  虚拟桌面协议  安全控制机制  内外部数据流
收稿时间:2015/2/15 0:00:00
修稿时间:2015/5/28 0:00:00

Secure Control Mechanism of Internal and External Data-flow Oriented to Virtual-desktop
DENG Xiao-xiao,LU Chuan and MA Wei.Secure Control Mechanism of Internal and External Data-flow Oriented to Virtual-desktop[J].Computer Science,2016,43(4):122-126.
Authors:DENG Xiao-xiao  LU Chuan and MA Wei
Affiliation:Academy of Equipment,Beijing 101416,China,Academy of Equipment,Beijing 101416,China and School of Computer and Information Technology,Beijing Jiaotong University,Beijing 100044,China
Abstract:The data interaction of desktop virtualization between internal application data and external user operation platform are realized by virtual desktop protocol.Because of the deficiency of the data flow control mechanism in this kind of protocol,it may lead to the illegal interaction.In order to resolve this problem,based on gateway,this paper proposed a secure control mechanism of internal and external data-flow oriented to virtual-desktop.It not only has the overall control of virtual channel,avoiding modifying lots of transport protocols or terminals,but also has high compatibilities,expansibilities and usability.Deploying it at the gateway to protect from boundaries attack can reduce the server load and safety concerns significantly.Experiments prove that this mechanism can control the direction of data flow effectively.Meanwhile,it has little impact on existing desktop session.
Keywords:Desktop virtualization  Virtual desktop protocol  Secure control mechanism  Internal and external dataflow
点击此处可从《计算机科学》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号