摘要
文章介绍了现今数据防泄漏技术的研究现状,分析了现有数据防泄漏技术实现的难点和弱点。在前人的基础上提出并改进了一套基于ICAP协议的实时数据防泄漏方案,弥补了现有技术对HTTPS协议流量进行分析检测的困难和对恶意软件通过加密通道盗取敏感数据无法防御的不足。最后搭建实验环境,测试其运行性能,证明了该系统具有一定的实用价值。
This paper introduce nowadays Data Leakage Prevent(DLP) researching. And analysis the challenge and weakness of present DLP techniques. Thanks for the achievements of previous researhers, we design and implement a real time data leakage prevent system based on ICAP. This system makes up for 2 the weaknesses of regular DLP solutions. One is the ability of intercept and analysis HTTPS encrypted data flow, the other one is defending data leakage due to malicious software's custom encrypted tunnel over regular HTTP port. Last of all, we build up the environment and test the average latency of our DLP system which proves it have potential of being put into practise.
出处
《信息网络安全》
2013年第11期49-53,共5页
Netinfo Security
基金
国家自然基金[61070204
61101108]