中国民航大学学报

• 民用航空 • 上一篇    下一篇

SWIM Web 防火墙的设计和实现

吴志军,陈焕,雷缙   

  1. (中国民航大学电子信息与自动化学院,天津 300300)
  • 收稿日期:2017-12-25 修回日期:2018-02-10 出版日期:2018-12-25 发布日期:2018-12-27
  • 作者简介:吴志军(1965—),男,新疆库尔勒人,教授,博士后,研究方向为航空电信网及网络安全、航空信息系统及信息安全、大数据和云计算安全。
  • 基金资助:
    国家自然科学基金项目(U1533107);天津市自然科学基金重点项目(17JCZDJC30900)

Design and implementation of SWIM Web firewall

WU Zhijun, CHEN Huan, LEI Jin   

  1. (College of Electronic Information and Automation, CAUC, Tianjin 300300, China)
  • Received:2017-12-25 Revised:2018-02-10 Online:2018-12-25 Published:2018-12-27

摘要: 广域信息管理系统(SWIM)是国际民航组织(ICAO)推行的下一代空中交通管理信息共享基础网络,采用面向服务的架构实现航空交通运输资源的共享服务。首先设计了SWIM 应用的场景要要SWIM 服务管理中心,进行Web 服务的安全策略研究,结合SWIM Web 订阅/发布服务请求的高并发特征,设计了SWIM Web
防火墙,保障SWIM 各客户端之间的安全通信。SWIM Web 防火墙基于SWIM 服务管理节点架构进行分布式部署,通过实现流量控制尧负载均衡和内容过滤功能,达到对服务过滤并合理分配的目的。将该防火墙部署在LNMP 平台中进行测试与验证,实验结果表明该防火墙可对数据包合理分配和有效过滤。

关键词: 广域信息管理系统, Web 防火墙, 流量控制, 负载均衡, 内容过滤

Abstract: SWIM is the information sharing infrastructure network implemented by ICAO for the next generation of air traffic management. SOA is employed in SWIM to realize the sharing of air traffic resource service. Firstly, the application scenario, SWIM service management center, is designed in order to study the security strategy of Web service. In response to the high concurrency feature of SWIM Web subscription/publish service requests, a SWIM Web firewall is designed to ensure secure communication among clients. The distributed implementation of SWIM Web firewall is conducted basing on the architecture of SWIM service management node, achieving filtering and reasonable distribution of service through flow control, load balancing and content filtering. The current firewall is then embedded in LNMP platform to conduct test and verification. Experimental results prove that this firewall can reasonably allocate and effectively filter data packets.

Key words: SWIM, web firewall, flow control, load balancing, content filtering

中图分类号: