Click here to load reader

  · Web view信息安全等级保护系统 采购编号:SZZHJ2018-XC-T-020号. 信息安全等级保护系统 采购编号:SZZHJ2018-XC-T-020号. 第 52 页 共 59 页. 第

  • Upload
    dokhanh

  • View
    284

  • Download
    0

Embed Size (px)

Citation preview

SZZHJ2018-XC-T-020

SZZHJ2018-XC-T-020

-

SZZHJ2018-XC-T-020

52 59

-

SZZHJ2018-XC-T-020

1

700000.00

2

20189219:0011:30,13:3017:00

7569902

A

1

2

3

4

5

6

7

B

1

2

3

1201892809:00

201892809:30

168

2201892809:30

3168

7569902 215009

0512-69290321 0512-69291321

6

0512-66731139

320

1

2

0512-67591006

2018918

1

2

60

3

10500.00

8906 0154 8000 00869

310305000056

4

7

7 77569020512-692903210512-69291321/[email protected]

27

5

6

201892809:0009:30

:168

7

201892809:30

:168

8

1001.5%1005001.1%500~10000.8%30003000:

105536 0104 0038 966

06 09

20

35

47

53

SZZHJ2018-XC-T-020

1

700000.00

3

20189219:0011:30,13:3017:00

7569902

A

1

2

3

4

5

6

7

B

1

2

3

1201892809:00

201892809:30

168

2201892809:30

3168

7569902 215009

0512-69290321 0512-69291321

7

0512-66731139

320

1

2

0512-67591006

2018918

A.

1.

1.1

1.2

1.3

2.

2.1

2.2

2.3

2.4

2.5

2.6

2.7

2.8

2.9

2.10

2.11

2.12

2.13

2.14

2.15

2.16

B.

3.

3.1

4.

4.1

5.

5.1

6.

6.1

7.

7.1

C.

8.

8.1

8.2

9.

9.1

9.2

10.

10.1

10.2

10.3

10.4

11.

11.1

11.2

11.2.1

11.2.2

11.2.3

11.2.4

11.3

D.

12.

12.1

12.2

13.

13.1

13.2

14.

15.

15.1

16.

16.1

16.2

16.3

16.4

16.5

17.

17.1

17.2

17.3

17.4 5

17.5 :

17.5.1

17.5.2

17.5.3

17.5.4

17.5.5

17.5.6

17.5.7

17.5.8

18.

18.1 60

18.2 17

19.

19.1

19.2

19.3 ,

E.

20.

20.1

20.2

21.

21.1

21.2

21.3

22.

F.

23.

23.1

23.2

23.3

23.4

23.5

23.6

23.7

23.8

23.9

23.10

23.11

23.12

24.

24.1

24.2

24.2.1

24.2.2

24.2.3

24.2.4

24.3

24.3.1

24.3.2

24.3.3

24.3.4

24.3.5

24.3.6

25.

25.1

25.2

25.3

26.

26.1

26.1.1

26.1.2

26.1.3

26.1.4

26.1.5

26.1.6

26.1.7

26.1.8

26.1.9

26.2

26.3

26.3.1

26.3.2

26.3.3

26.3.4

27.

27.1

27.2

28.

28.1

28.1.1

28.1.2

28.1.3 3

29.

29.1

29.2

29.2.1

29.2.2

29.2.3

29.2.4

29.2.5

29.2.6

29.3

29.4

30.

30.1

30.2

31.

31.1

31.2

32.

32.1

32.2

32.3

32.4

33.

33.1

33.2 15

34.

34.1

34.2

35.

35.1

1

SZZHJ2018-XC-T-020

1

2

2

1

2

360

4

5

6

7

8

9

10

11

3

:

1

2

3

4

5

6

4

___________

5

6

2016

2016

2

3

3

7

1

8

1

2

3

4

5

6

1231=2+3456

9

1

2

3

4

5

10

[2011]181______

1[2011]300_____3______

2

3__________________

12017

22011300

3

11

SZZHJ2018-XC-T-020

:

:

:

:

:

SZZHJ2018-XC-T-020

1

700000.00

1

1

2

1

3

1

4

1

5

1

6

HIS

1

7

1

2

1

410/100/1000BASE-TBypass

300

IP

ISP

PPPoE

DHCP Replay/Server

DNS,

ospfvlan

httphttpssocks5DNSdns

mac802.3ad6

vpn

l2tpgre vpnpptpipsec

DNSICMPTCP

sslssh

/

ipip

Radius

Dkey

key

APP

APPACM

URL

cpu

50

ipmac

Nat

DOS

dosipip

ARP

ARParparp

TCPUDPICMPTCP SYNUDP

IP MACVLAN ID IP MAC IP+MACVLAN

IP MAC IP+MACVLAN

NetbIOS

NetbIOS IP MAC

mac

snmparpmac

LDAPad

CSV//IP/MAC//

portal

AdLDAPRadiusPOP3Proxy

Windows

windowspc

ADPOP3ProxyPPPOE H3C IMC/CAMS SAMweb

cookiemac

URL

401000URL

URL

URLurlurl

2000300

ipip/

L2TPGRELWAPPCAPWAP

httpsssl

https

///POP3/SMTP/Web Mailssl

cpusyslog

urlurl

IMipip

URL

URLURL

ip

url

url

//(//)/(/)///5N

1n

DKEY

usb-keykey

ftp

Syslog

Syslog

qqpppoe

POP3/SMTP/Web Mail

POP3/SMTP/Web Mail

POP3/SMTP/Web Mail

Windows pcqqmsnIM

qq

Facebook line

url

url

url

Telnet

telnet

http

httpmac

FTP

FTP

ftpim

: IP IP NAT ( IP ).

URL//FTP//

ip

cpu

url

urlurlurl

3724 1800

2

3GIPS + 5G2G1204

62Bypass2SFP3PCIe

12 USB1VGA

100, HTTP/HTTPS/FTP/SMTP/POP3/TFTP/TCP/UDP/NFS/SNMP/ICMP/RTMP/DNS/IRC

(Rootkits)

APT

C&C

APTAPTC&CC&CURLIPAPT

SQL, , Webshell , XSS , CSRF

6,000+

Web

URLURLURL

3,000,000+750,000++

LDAPMS Active DirectoryOpen LDAP

MS ADOpen LDAP

()+ISP&WAN

WebCLISSHSNMP

//VPN//////////

SyslogSyslog

///

///WebN/URL/N

URLURL///

CPU///

SSL

Fail Open

, APT, , ,Web, OEM

CMMI 5

3724 1800

3

4

AD

ADOU

AD

AD

IP

unixwindowsC/SB/S

SSHTELNETFTPSFTPVNCXWINDOWWINDOWS

unixwindows

FTP

FTPtelnetssh

SS0

enableunixsu

Zmodem

rzsz

CA

RADIUSTACACS+

RADIUSTACACS+RadiusTACACS

IPIPIPIP

RDP

FTP

FTP

FTP

VPN

VPNVPN

WordExcelPDF

cpu WEB

NTP

NFSwindows

3724 1800

4

UTM

410/100/1000MBase-T

500G

2Gbps

600Mbps

SQL/S

35000

280000

OracleMSSQLDB2SybaseInformixMYSQ

IPIPSQL

SQL/SQLSQL

Bind VariableBind Variable

IP

SQLSQLSQL

SQL

TDSTNS

SQLSelectInsertUpdateDelete,

IP

IPIP

SQL

MYSQL

4

SYSOGSNMP TRAPFTP

IP

SQLSQL

FTP

SGA

DPASOX

WEBHTTPS

3724 1800

5

50

40000/

35000/

20000/

10:120000/Mb

BT,10s

SyslogSNMP TrapNetflowJDBCSSHWMIFTPSCP

Agent

10:1

SANNAS

FTP

IPIP

IP

IPIPIPExcel

3724 1800

6HIS

1MS SQL ServerORACLE

2

1windows 64bitLINUXORACLEMSSQL 64bit

2HIS

3

4

5DDLDMLDDLDML

6

7HIS1

8

9HIS,HISHIS

10

1 HIS

2

3 HIS

4 5

7 :1

8 20189259:00-9:30

0512-66731139

,

1

2

3

4

5

1

2123

3

4

5

620

7

8

1

2

3

4

5

6

7

8

9

10201611

11

1

2

1

1

2

3

4

5

6

2201811

2.1

2.2

2.3

2.4

3http://www.ccgp.gov.cnhttp://www.zfcg.suzhou.gov.cn

3

SZZHJ2018-XC-T-020

1

2ABC6095%5%60

A

B

C

3

1

2

3

4

1

2

120

2

1

2

2.1 5%

2.2

2.3

3

3.1 245%

3.2

3.3

4

4.1

4.2

1

1.1

1.2

1.2.1

1.2.2

1.3

1.4

1

1.1

1.1.1

1.1.2

1.1.3

2

1

2

1

1.1

1.2

1.35

1.4

1.5

1.6

2011181

20113002016

6%8%

2011300

2

1

2

3

4()

1 48

40 58