文章以基于MPLS VPN技术的平安城市网络视频监控系统的一期建设项目工程为背景,通过详细的调研,从当前项目系统运行的现状和存在的问题出发,深入分析和研究了该系统的安全性,并提出安全改进的总体解决方案。文章首先针对平安城市网络监控系统现状,提出了安全域的划分原则和方法,并将系统划分为核心网络域、业务计算域、公共服务域和终端接入域4个安全域;接着从安全域的角度对如何在技术上改进系统的安全性提出相应的优化对策,并根据安全域的划分得出详细的安全优化实施技术方案,即采取双PE冗余备份策略加固核心网络性能,制定网络边界防火墙部署方案、流量控制检测部署方案和IDS/IPS入侵检测系统实施方案;最后对该系统安全性能优化解决方案进行了总结并提出持续改进的设想,从安全性能维护角度为该项目的后期建设提供参考。
This paper is based on the peace city network video monitoring system, by a detailed research; check the present situation and problems, follow the method of system safety analysis, proposed the solutions and improvements. The article firstly puts forward the principles and methods of security domain division, and divides the system into four security zones: network core domain, business computing domain, public service domain and client domain; then describe the optimization countermeasures of system security enhancement. The main methods are as follows: take advantage of dual PE redundant backup strategy reinforce the network core performance, network firewall deployment, implement intrusion prevention system. Finally summarizes and prospect for the solution of the network video monitoring system.