A kind of network security server and intelligent protecting method thereof
The present invention relates to a kind of network security server technology, relate to a kind of PC level server and intelligent full automatic safety protecting method thereof or rather with network security capability.
Universal day by day along with Internet, the informatization of China has also obtained develop rapidly, and e-government implementation has become a kind of inevitable trend.But usually suffer the attack of " hacker " in view of present Internet, and the spreading unchecked of computer virus, therefore, Chinese Government clearly stipulates, the in-house network of Party and government offices and classified network (hereinafter to be referred as Intranet) must not directly be connected with Internet, must be from physically isolating, to guarantee the security of inner-mesh network information.
The patent No. is 98206671.6 Chinese utility model patent " secure network computer that can connect Intranet and outer net simultaneously ", it is exactly a kind of network security computing machine that development is under these circumstances come out, a kind of secure network computer technology that can connect Intranet and outer net is simultaneously disclosed in this patent, form by plural main frame, one of them main frame is connected with internal network, another main frame is connected with external network, two shared cover keyboards of main frame, Genius mouse, input-output apparatus and power supplys such as display are to be connected with two main frames respectively by the control module (switching controls card) that does not have the message exchange loop.Guaranteed can not communicate between two main frames by control module, user interface system is designed to unidirectional traffic, reaches from physically isolating.But because two main frames need be set, not only the cost height, volume is big and safeguard difficulty, be unsuitable for promoting the use of.
At present, the secure network computer of further developing that can connect Intranet and outer net simultaneously, include only a cover mainboard system, peripherals comprises two hard disks (Intranet hard disk and outer net hard disk), a CD-ROM drive, a floppy drive, a Genius mouse, a keyboard and a display, in switching synchronously by the switching controls module that does not have the message exchange loop, in outer net hard disk and the conversion, the outer net network port, carry out the conversion between Intranet and outer net, reach from physically isolating fully, in making at one time, one cover mainboard system can only connect a physical hard disk and a network port, not another physical hard disk that is used by mainboard system and another network port, and then be physically-isolated fully between mainboard system.
On the other hand, owing to be provided with classified network, grid has just become the independent grid of being made up of Intranet and outer net of two covers by original single network, should there be any physics contact between them, more should there be logical communication link, therefore a server group of planes also should be separate, and network security server is exactly a kind of server product that is born around the classified network construction requirements.
Referring to Fig. 1, existing shown in the figure by the network security server scheme of server zone (as user side and website side) is set separately respectively in Intranet and outer net, Intranet (LAN) side connects database server, file server and Intranet mail server etc. by switch-SWITCH (as hub HUB), and outer net (LAN Internet) connects database server, WAB server (www server) and outer net mail server etc. by switch-SWITCH (as hub HUB).Because general PC server is not provided with safety feature on hardware, just the security function of utilizing network platform software is set on software, its security set is more rudimentary.In this technical scheme, server is not in a safe condition fully, though the security of Intranet is than outer net height, but in Intranet, also there is delinquenent element to do illegal thing unavoidably, and outer net is because of linking with Internet, therefore more do not have security, be easy under attack and cause file to lose or take place the ruined thing in website.Obviously, server also must be provided with more further safety feature except having the safety guarantee on hardware on software platform.
In addition, the webserver generally all is to adopt the cold machine backup of two-node cluster hot backup formula in the network fault tolerance backup solution that was in the past provided, realize cumbersomely, and poor stability is owing to be that two-shipper is the two server setting, so cost is higher, use also extremely inconvenient.
Moreover, the busiest parts are CPU (central processing unit) (CPU) in the webserver, it also is maximum pyrotoxin, the radiating effect of CPU (central processing unit) will directly have influence on the travelling speed of server, existing to carry out air-cooled technology with fan be to satisfy the radiating requirements of server CPU fully, thereby can often cause the server operational efficiency low even cause deadlock.
The objective of the invention is to design a kind of network security server and intelligent protecting method thereof, can in Intranet and outer net, use respectively, safety with the interior network server after the further reinforcement isolation, prevent internal staff's illegal act, and make outer network server safer, guarantee the security of network on the whole;
Another object of the present invention is a kind of network security server of design, is that the full mirror image of hot completely machine is high fault-tolerant from backing up network security server.
Another purpose of the present invention is a kind of network security server of design, can thoroughly solve the heat dissipation problem of CPU (central processing unit) (CPU), thereby promote the operating rate of CPU significantly, keeps very strong stability under high-speed cruising.
The object of the present invention is achieved like this: a kind of network security server is a kind of Standard PC server, it is characterized in that: also include the intelligent safety protection module, be connected with the pci bus of Standard PC server master board; Described intelligent safety protection module is linked in sequence by data acquisition unit, data-analyzing machine and numerical control actuator and constitutes; Data acquisition unit is isolated source address and the physical address in the visit book server access side TCP/IP packet structure, data-analyzing machine record access book server access side's source address and physical address, and record access number of times, surpass preset times rear drive numerical control actuator in access times, the numerical control actuator sends interrupt request to the Standard PC server master board, by Standard PC server master board interruption access side's request of access, interrupt the network interface card operation.
Described intelligent safety protection module is a computer card that is subjected to the standard of Standard PC server master board computer supervisory control system (BIOS) control, be interrupt address and I/O (I/O) address that utilizes computer supervisory control system, a hardware that contains software of embedding.
Described data-analyzing machine includes the dynamic register that is used for record access side's source address and physical address more than, is provided with the counter that is used to write down these access side's access times in the subarea of each dynamic register.
Also include from backing up fault-tolerant hard disk groups, form by fault-tolerant verification module and backup image hard disk; The Primary Hard Drive of described backup image hard disk and described Standard PC server is connected with described fault-tolerant verification module, described fault-tolerant verification module is connected with the mainboard hard-disk interface bus of described Standard PC server, break down and when the Standard PC server provides fault-signal at the Primary Hard Drive of described Standard PC server, make the backup image hard disk be in read-write state by the Standard PC server by described fault-tolerant verification module, finish the conversion between backup image hard disk and Primary Hard Drive.
The power supply of described backup image hard disk and described Primary Hard Drive sharing criteria PC server.
Also include refrigeration unit, form by refrigeration compressor, heating radiator, temperature sensor and temperature controller; Heating radiator is arranged on outside the CPU (central processing unit) (CPU) of described Standard PC server master board, and heating radiator connects by heat-transfer tube and refrigeration compressor, and temperature sensor is connected with temperature controller, the working power of temperature controller control refrigeration compressor; Described heating radiator and heat-transfer tube also are coated with the insulation material layer that makes thermal component and air isolated fully outward.
The intelligent protecting method of a kind of network security server of the present invention is characterized in that comprising the steps:
Utilize the part interrupt address and the I/O address of Standard PC server master board, embed an intelligent safety protection module that controlled by Standard PC server master board computer supervisory control system (BIOS); From the access side's of visit book server TCP/IP packet structure, isolate its source address and physical address by the intelligent safety protection module; The access side's of intelligent safety protection module records visit book server source address and physical address, and write down the number of times of its connected reference; The intelligent safety protection module is sent interrupt request to the Standard PC server master board after the access times of judging this access side surpass preset times, by Standard PC server master board interruption access side's request of access, interrupt the network interface card operation.
The access times of described record access side are to carry out fast and after constantly scanning the book server password with scanning software in the short time the access side who visits book server.
A kind of network security server of the present invention and intelligent protecting method thereof, follow international standard, in fairly perfect server standard, add the intelligent safety protection module, this module has analysis, record, arbitration functions, can monitor each visitor, to spiteful visitor's intelligent decision and refuse its visit, this technology of various visit informations being done dynamic monitoring record and processing, the Firewall Protection technology that is different from existing static state is because static Firewall Protection technology must be provided with address that allows calling party or the information datas such as address that the disable access user is set in advance in advance.Therefore network security server of the present invention and intelligent protecting method thereof have further been strengthened the safety of interior network server after the isolation, and network server is safer outside also can making when preventing internal staff's illegal act.Network security server of the present invention with backup image hard disk and master (with) hard disk is integrated in the same station server, when network security server moves, backup image hard disk (writing state) works together with Primary Hard Drive (read-write state), write down corresponding various information and data, when Primary Hard Drive breaks down or attacked and when damaging, the backup image hard disk can be converted to Primary Hard Drive (read-write state) rapidly, guarantee the reliability service of server, realized that the full mirror image of hot completely machine is high fault-tolerant from backup.Network security server of the present invention, on the basis of the original air-cooled facility of server, install a cover Small Refrigerating Equipment additional, specially the CPU to server cools off, and makes the CPU surface temperature can reach-39 ℃ to-42 ℃, works being similar under the superconducting state, the work efficiency of CPU is improved effectively, thereby the performance of server is improved greatly, and arithmetic speed can reach per minute more than 100,000,000 times, has had the performance of minicomputer.
Network security server of the present invention can be series of products, adopts different configurations, the server of different model just, a kind of as in the multiple server as shown in Fig. 1.
Further specify Apparatus and method for of the present invention below in conjunction with embodiment and accompanying drawing.
Fig. 1 is the existing schematic network structure that server zone is set separately respectively in Intranet and outer net.
Fig. 2 is the intelligent safety protection modular structure synoptic diagram of network security server of the present invention.
Fig. 3 is the fault-tolerant hard disk groups mode configuration of the backup certainly synoptic diagram of network security server of the present invention.
Fig. 4 be network security server of the present invention back up syndeton synoptic diagram between fault-tolerant hard disk and server master board certainly.
Fig. 5 is the fault-tolerant hard disk principle of work of the backup certainly synoptic diagram of network security server of the present invention.
Fig. 6 is the structural representation of the refrigeration unit of network security server of the present invention.
Fig. 7 is the graph of relation of the temperature and the speed of CMOS integrated chip.
Fig. 8 is that the refrigeration unit of network security server of the present invention is provided with structural representation in server.
Address before Fig. 1 illustrates, repeat no more.
Network security server of the present invention, in the Standard PC server of forming by computer cabinet, power supply, mainboard, hard disk, network interface card, sound card, video card, Genius mouse, keyboard, display etc., by increasing the intelligent protection module, back up fault-tolerant hard disk groups and refrigeration unit certainly, and form a kind of new PC level server with network security capability.
Referring to Fig. 2, the intelligent safety protection modular structure of network security server of the present invention shown in the figure, form by data acquisition unit 21, data-analyzing machine 22 and numerical control actuator 23, can be designed to the computer card of a standard, be connected with the pci bus 20 of PC server master board.The intelligent safety protection module adopts embedded PC technology, in server master board, be subjected to BIOS (computer supervisory control system) control, be to utilize the many interrupt addresses reserve and part interrupt address and the I/O address in the I/O address, a hardware that contains software of embedding.24 is network interface cards among the figure.
In computer network, no matter be server or desktop workstations, all be to be connected with network by the network interface card in the machine, thereby network interface card is the indispensable communication component of compunication, information (network data signals) is transmitted by network interface card from network, network interface card is the transmission of machine internal bus as calculated again, and finishes information analysis and exchange between server master board, realizes network service.At present, applied network communication protocol major part is an ICP/IP protocol, and for computer network, no matter adopts what network platform, as long as used ICP/IP protocol, just has a fixing packet structure; No matter adopt any means of communication between network,, will communicate as long as the agreement that adopt at two ends is identical.
In the TCP/IP packet structure, include destination address, source address (IP address) and MAC Address (physical address), these addresses are unique in internet (Internet), intelligent protecting method of the present invention just is based on that these characteristics make.
Carry out data acquisition by data acquisition unit 21, source address in the TCP/IP packet structure and physical address are separated, send the analytic record of carrying out data in the data-analyzing machine 22 then; Be provided with a large amount of registers in the data-analyzing machine 22, be used to write down source address and the physical address that those visit the access side of book servers, this register is dynamic, can refresh reporter's record in the past automatically.In the subarea of each register, all be provided with counter, to write down this visitor's access times.The highest access times of counter can manually be set, as be set to three times.
The file service structure of server generally is made up of two parts, promptly disclosed information and covert information, and covert part all is provided with password, if check or change then necessary this password of input of file of this part.When online hacker carried out unlawful activities, must utilize certain decoding instrument was that alleged scanning software removes to untie password and just can login, and the characteristics of this scanning software are to scan password apace in the very short time, constantly access server.Thereby; data-analyzing machine 22 is after the IP address of noting scanning person and MAC Address; the accumulative total of number of times also will conduct interviews; when reaching default the highest access times at short notice; data-analyzing machine 22 can be sent drive signal to numerical control actuator 23; send the interrupt request instruction by numerical control actuator 23 to the PC server master board; the PC server master board is denied access automatically; interrupt this visitor's request of access; if this visitor also continues to visit by force, numerical control actuator 23 will send interrupt request once more, interrupt network interface card 24 operations (network interface card I/O look-at-me); realize that off-grid step of going forward side by side reports to the police, with protection data in server safety.
Intelligent protecting method of the present invention need not be provided with the user in advance, is dynamically recording fully, thereby is different from firewall technology, and range of application is wideer, moves more effectively, is difficult for being broken, even we can say and can not be broken.
In conjunction with referring to Fig. 3, Fig. 4, Fig. 5, syndeton and principle of work between fault-tolerant hard disk groups structure of backing up certainly of network security server of the present invention and server master board are shown respectively.Network security server of the present invention is integrated into backup image hard disk 31 and Primary Hard Drive 30 in the same station server by fault-tolerant verification module 32, and it is high fault-tolerant from backup to form the full mirror image of hot machine.Primary Hard Drive 30 and backup image hard disk 31 all are connected with fault-tolerant verification module 32, and fault-tolerant verification module 32 is connected with server master board hard-disk interface bus 34 by an I/O mouth 33, as shown in Figure 3.35 is server master board hard-disk interfaces among the figure,
Network security server of the present invention is according to the design of the principle of work of computing machine, its profile adopts the standard design of machine element, the overall height of cabinet 41 of using a computer drives the position, backup image hard disk 31 is identical with server hard disc with the power supply 40 that fault-tolerant verification module 32 is used, and 42 of server master boards link by standard hard drive interface 35, as shown in Figure 4.
Have a cover to calculate supervisory system in the server master board, promptly alleged BIOS system has the every function of computer motherboard, as automatically, manually being provided with and peripheral hardware monitor for faults diagnostic function, is the auto-cental system of server master board.When adding some peripheral hardwares and functional module on server, this BIOS system will these parts of Auto-Sensing, and are confirmed.As make a mistake, can provide error signal automatically, and be shown, inform the user, the present invention utilizes this function design.
When the server operate as normal, Primary Hard Drive 30 is worked simultaneously with backup image hard disk 31, but Primary Hard Drive 30 is in direct-connected state with server master board 42, and carries out normal read-write operation, and backup image hard disk 31 just is in the state of writing.The read-write state of Primary Hard Drive 30 or backup image hard disk 31 can be finished by logic gate IC3 by the high-low level control of reading writing signal line in mainboard hard disk (data) interface.After Primary Hard Drive 30 breaks down, by the fault diagnosis signal line, Primary Hard Drive 30 can be exported fault-signal (high or low level) at once, follow by the IC2 follower and to provide a fault-signal and give fault-tolerant control circuit 50, at this moment, the delay circuit that is connected and composed by capacitor C, resistance R can continue to keep the operate as normal level of Primary Hard Drive 30, simultaneous failure tolerance control circuit 50 fast processing fault-signals, open or logic gate IC1 and make backup image hard disk 31 be in read-write state, and provide alerting signal, finish ' conversion between the active and standby part hard disk.As shown in Figure 5.
In conjunction with referring to Fig. 6, Fig. 7, Fig. 8, the small-sized refrigerating unit structure in the network security server has adopted the vapour phase condensation technology, comprises heating radiator, temperature sensor, temperature controller and refrigeration compressor, is exclusively used in the cooling of mainboard CPU.
Because parts and maximum pyrotoxin the busiest in the server are CPU, according to temperature velocity curve shown in Figure 7, when the cmos device temperature reduced, the travelling speed of chip will promote, if allow the working temperature of CMOS be reduced to-40 ℃, its performance just can improve 33%-35%.The present invention makes according to this physical law.
Heating radiator 60 is set outside the CPU on mainboard 42, temperature sensor 61 transmits the cpu temperature signal of actual measurement to temperature controller 62, refrigeration compressor 63 is carried out the automatic control of power on/off, and 60 in refrigeration compressor 63 and heating radiator connect by heat pipe 64, and 80 is former fans in the server among the figure.Refrigeration unit of the present invention can be discharged the heat of 150W, has not only thoroughly solved heat dissipation problem, and has improved the CPU travelling speed.As the CPU that makes AMD 750MHz can be stable be operated in 1000MHz, make the CPU of 850MHz stably be operated in 1.2GHz, make the CPU of 1GHz can stably be operated in 1.4GHz.
The present invention is coated with insulation material layer at heating radiator 60 and heat-transfer tube 64, makes between thermal component and air to isolate fully, thereby can not produce condensate water, can not cause the damage of server component because of the condensate water that produces.
The present invention adds oneself and backs up fault-tolerant hard disk groups, intelligent safety protection module and small-sized refrigerating unit on the foundation structure of Standard PC server, thereby forms a kind of super PC level server with network security capability.