bastion host - 堡垒主机 / 跳板机

本文详细介绍了堡垒主机的概念,它是网络上的专用计算机,设计用于抵御攻击。通常运行单一应用程序并移除其他服务以降低风险。文章还探讨了其在网络安全中的角色及配置要点。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

bastion host - 堡垒主机 / 跳板机

A bastion host is a special purpose computer on a network specifically designed and configured to withstand attacks. The computer generally hosts a single application, for example a proxy server, and all other services are removed or limited to reduce the threat to the computer. It is hardened in this manner primarily due to its location and purpose, which is either on the outside of a firewall or in a demilitarized zone (DMZ) and usually involves access from untrusted networks or computers.
堡垒主机是网络上的专用计算机,专门设计和配置以抵御攻击。计算机通常运行单个应用程序,例如代理服务器,并且移除或限制所有其他服务以减少对计算机的威胁。它以这种方式硬化主要是由于它的位置和目的,它位于防火墙的外部或非军事区 (DMZ),并且通常涉及来自不受信任的网络或计算机的访问。

The term is generally attributed to a 1990 article discussing firewalls by Marcus J. Ranum. Ranum defined a Bastion host as a system identified by the firewall administrator as a critical strong point in the network security. Generally, bastion hosts will have some degree of extra attention paid to their security, may undergo regular audits, and may have modified software.
该术语通常归因于 1990 年由 Marcus J. Ranum 讨论防火墙的文章。Ranum 将 Bastion 主机定义为由防火墙管理员识别的系统,是网络安全中的关键优势。一般来说,堡垒主机会对其安全性有一定程度的额外关注,可能会进行定期审核,并且可能会修改软件。

Krutz and Vines have described a bastion host as "any computer that is fully exposed to attack by being on the public side of the DMZ, unprotected by a firewall or filtering router. Firewalls and routers, anything that provides perimeter access control security can be considered bastion hosts. Other types of bastion hosts can include web, mail, DNS, and FTP servers...Due to their exposure, a great deal of effort must be put into designing and configuring bastion hosts to minimize the chances of penetration."
Krutz 和 Vines 已经将堡垒主机描述为:任何完全暴露于 DMZ 公共端的攻击的计算机,不受防火墙或过滤路由器的保护。防火墙和路由器,任何提供周边访问控制安全性的东西都可以考虑堡垒主机。其他类型的堡垒主机可以包括网络,邮件,DNS 和 FTP 服务器... 由于它们的曝光,必须花费大量精力设计和配置堡垒主机,以尽量减少渗透的机会。

bastion host [ˈbæstiən həust]:堡垒主机,跳板机
withstand [wɪð'stænd]:vt. 抵挡,禁得起,反抗 vi. 反抗
demilitarize [ˌdi:'mɪlɪtəraɪz]:vt. 解除武装,使非军事化
primarily ['praɪm(ə)rɪlɪ; praɪ'mer-]:adv. 首先,主要地,根本上
audit ['ɔːdɪt]:vi. 审计,查账 n. 审计,查账

References
https://en.wikipedia.org/wiki/Bastion_host

 

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

Yongqiang Cheng

梦想不是浮躁,而是沉淀和积累。

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值