信息系统项目管理师_2024年软考学习应考交流_信息系统项目管理师考试

 找回密码
 马上注册

QQ登录

只需一步,快速开始

查看: 1617|回复: 1
打印 上一主题 下一主题

[转帖]信 息 技 术小型防火墙产品安全检验规范

[复制链接]

该用户从未签到

升级  30.8%

跳转到指定楼层
楼主
发表于 2006-4-6 10:55:55 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
<h1 align="center" style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%; TEXT-ALIGN: center;"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;">目<span lang="EN-US"><span style="mso-spacerun: yes;">&nbsp;&nbsp;&nbsp; </span></span>次<span lang="EN-US"><p></p></span></span></h1><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;"><p>&nbsp;</p></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc1" style="MARGIN: 0cm 0cm 0pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327450"><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">前言</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">III</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc1" style="MARGIN: 0cm 0cm 0pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327451"><span style="FONT-FAMILY: 宋体;">1<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">范围</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">1</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc1" style="MARGIN: 0cm 0cm 0pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327452"><span style="FONT-FAMILY: 宋体;">2<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">引用标准</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">1</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc1" style="MARGIN: 0cm 0cm 0pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327453"><span style="FONT-FAMILY: 宋体;">3<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">小型防火墙定义</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">1</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc1" style="MARGIN: 0cm 0cm 0pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327454"><span style="FONT-FAMILY: 宋体;">4<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">安全功能要求</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">1</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc2" style="MARGIN: 0cm 0cm 0pt 21pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327455"><span style="FONT-FAMILY: 宋体;">4.1<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">用户数据保护功能类(FDP</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">1</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327456"><span style="FONT-FAMILY: 宋体;">4.1.1<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">完整的客体访问控制(FDP_ACC.2</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">1</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327457"><span style="FONT-FAMILY: 宋体;">4.1.2<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">访问授权与拒绝(FDP_ACF.4</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">1</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327458"><span style="FONT-FAMILY: 宋体;">4.1.3<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">多种安全属性访问控制(FDP_ACF.2</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">1</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327459"><span style="FONT-FAMILY: 宋体;">4.1.4<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">管理员属性修改(FDP_SAM.1</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">2</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327460"><span style="FONT-FAMILY: 宋体;">4.1.5<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">管理员属性查询(FDP_SAQ.1</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">2</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc2" style="MARGIN: 0cm 0cm 0pt 21pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327461"><span style="FONT-FAMILY: 宋体;">4.2<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">识别与鉴别功能类(FIA</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">2</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327462"><span style="FONT-FAMILY: 宋体;">4.2.1<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">授权管理员和可信主机鉴别数据初始化(FIA_ADA.1</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">2</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327463"><span style="FONT-FAMILY: 宋体;">4.2.2<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">授权管理员和可信主机鉴别数据的基本保护(FIA_ADP.1</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">2</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327464"><span style="FONT-FAMILY: 宋体;">4.2.3<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">授权管理员可信主机和主机属性的初始化(FIA_ATA.1</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">2</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327465"><span style="FONT-FAMILY: 宋体;">4.2.4<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">授权管理员、可信主机和主机唯一属性定义(FIA_ATD.2</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">2</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327466"><span style="FONT-FAMILY: 宋体;">4.2.5<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">授权管理员的基本鉴别(FIA_UAU.1</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">2</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327467"><span style="FONT-FAMILY: 宋体;">4.2.6<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">单一使用<span lang="EN-US">的鉴别机制(FIA_UAU.2</span></span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">2</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327468"><span style="FONT-FAMILY: 宋体;">4.2.7<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">授权管理员、可信主机和主机唯一身份识别(FIA_UID.2</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">3</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc2" style="MARGIN: 0cm 0cm 0pt 21pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327469"><span style="FONT-FAMILY: 宋体;">4.3<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">保密功能类(FEN</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">3</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327470"><span style="FONT-FAMILY: 宋体;">4.3.1<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">符合规定的加密操作(FCS_COP.2</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">3</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc2" style="MARGIN: 0cm 0cm 0pt 21pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327471"><span style="FONT-FAMILY: 宋体;">4.4<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">可信安全功能保护类(FPT</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">3</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327472"><span style="FONT-FAMILY: 宋体;">4.4.1<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">防火墙安全策略的不可旁路性(FPT_RVM.1</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">3</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327473"><span style="FONT-FAMILY: 宋体;">4.4.2<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">安全功能区域分割(FPT_SEP.1</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">3</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc2" style="MARGIN: 0cm 0cm 0pt 21pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327474"><span style="FONT-FAMILY: 宋体;">4.5<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">安全审计功能类(FAU</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">3</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327475"><span style="FONT-FAMILY: 宋体;">4.5.1<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">审计数据生成(FAU_GEN.1</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">3</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327476"><span style="FONT-FAMILY: 宋体;">4.5.2<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">可理解的格式(FAU_POP.1</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">3</span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></font></a></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span></p><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><a href="http://www.doocai.com/bbs/post.asp?action=new&amp;boardid=36#_Toc61327477"><span style="FONT-FAMILY: 宋体;">4.5.3<span style="mso-spacerun: yes;">&nbsp; </span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">限制审计跟踪访问(FAU_PRO.1</span></span><span lang="EN-US" style="FONT-FAMILY: 宋体;"><span lang="EN-US">)</span></span><font face="Times New Roman"><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"><span style="mso-tab-count: 1 dotted;">... </span></span><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;">3</span></font><span style="DISPLAY: none; COLOR: windowtext; TEXT-DECORATION: none; text-underline: none; mso-hide: screen;"></span></a></span></span></p><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"></span></span>&nbsp;</p><span class="MsoHyperlink"><span lang="EN-US" style="mso-no-proof: yes;"><div class="Section1" style="LAYOUT-GRID:  15.6pt none;"><h1 align="center" style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%; TEXT-ALIGN: center;"><a name="_Toc61327450"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;">前<span lang="EN-US"><span style="mso-spacerun: yes;">&nbsp;&nbsp;&nbsp; </span></span>言</span></a><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;"><p></p></span></h1><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;"><p>&nbsp;</p></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt;"><span style="mso-spacerun: yes;"><font face="Times New Roman">&nbsp;&nbsp;&nbsp; </font></span></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">小型防火墙是专门为中小企业、中小型办公室环境或家庭用户提供安全保护的防火墙产品。</span><span lang="EN-US" style="FONT-SIZE: 12pt;"><p></p></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt;"><span style="mso-spacerun: yes;"><font face="Times New Roman">&nbsp;&nbsp;&nbsp; </font></span></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">小型防火墙的目的是要在内外网络之间建立一个安全控制点,通过允许、拒绝或重定向经过防火墙的数据流,实现对进出内部网络的服务和访问的审计和控制。</span><span lang="EN-US" style="FONT-SIZE: 12pt;"><p></p></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt;"><span style="mso-spacerun: yes;"><font face="Times New Roman">&nbsp;&nbsp;&nbsp; </font></span></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">小型防火墙的特点是体积小、硬件配置低、流量性能低,其主要访问控制能力与普通防火墙基本相同,但其部分安全功能要求比普通防火墙低,只能适用于中小企业、中小型办公室环境或家庭用户。</span><span lang="EN-US" style="FONT-SIZE: 12pt;"><p></p></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;"><span style="mso-spacerun: yes;">&nbsp;&nbsp;&nbsp; </span></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">小</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">型防火墙</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">产品的安全功能要求是完全包含在《</span><span lang="EN-US" style="FONT-SIZE: 12pt;"><font face="Times New Roman">GB/T 18019-1999 </font></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">信息技术包过滤防火墙安全技术要求》之内的,</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">因此</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">只能选用</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">《</span><span lang="EN-US" style="FONT-SIZE: 12pt;"><font face="Times New Roman">GB/T 18019-1999 </font></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">信息技术包过滤防火墙安全技术要求》中的部分安全功能要求。</span><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;"><p></p></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;"><p>&nbsp;</p></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;"><p>&nbsp;</p></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;"><p>&nbsp;</p></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">本规范规定了小型防火墙产品的安全技术要求。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">本规范起草单位:公安部计算机信息系统安全产品质量监督检验中心。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;"><p>&nbsp;</p></span></p></div><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span lang="EN-US" style="FONT-SIZE: 10.5pt; FONT-FAMILY: 'Times New Roman'; mso-font-kerning: 1.0pt; mso-bidi-font-size: 12.0pt; mso-fareast-font-family: 宋体; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA;"><br clear="all" style="AGE-BREAK-BEFORE: always; mso-break-type: section-break;"/></span>&nbsp;</p><h1 style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%;"><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;"><span lang="EN-US"><p></p></span></span></p><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;"><p>&nbsp;</p></span></h1><p class="MsoToc3" style="MARGIN: 0cm 0cm 0pt 42pt; tab-stops: right dotted 414.8pt;"><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span>&nbsp;</p></span></span><span lang="EN-US" style="mso-no-proof: yes;"><p></p></span>&nbsp;
分享到:  QQ好友和群QQ好友和群 QQ空间QQ空间 腾讯微博腾讯微博 腾讯朋友腾讯朋友
收藏收藏 转播转播 分享分享 顶 踩

该用户从未签到

升级  30.8%

沙发
 楼主| 发表于 2006-4-6 10:56:05 | 只看该作者
<h1 style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%;"><a name="_Toc61327451"><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;">1<span style="mso-spacerun: yes;">&nbsp; </span></span></a><span style="mso-bookmark: _Toc61327451;"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;">范围</span></span><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;"><p></p></span></h1><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">本规范规定了小型防火墙产品的安全技术要求。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">本规范适用于小型防火墙产品安全功能的研制、开发、测试、评估和产品的采购。<span lang="EN-US"><p></p></span></span></p><h1 style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%;"><a name="_Toc61327452"><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;">2<span style="mso-spacerun: yes;">&nbsp; </span></span></a><span style="mso-bookmark: _Toc61327452;"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;">引用标准</span></span><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;"><p></p></span></h1><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt;"><font face="Times New Roman"><span style="mso-spacerun: yes;">&nbsp;&nbsp;&nbsp; </span>GB/T 18019-1999 </font></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">信息技术包过滤防火墙安全技术要求</span><span lang="EN-US" style="FONT-SIZE: 12pt;"><p></p></span></p><h1 style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%;"><a name="_Toc61327453"><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;">3<span style="mso-spacerun: yes;">&nbsp; </span></span></a><span style="mso-bookmark: _Toc61327453;"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;">小型防火墙定义</span></span><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;"><p></p></span></h1><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt;"><span style="mso-spacerun: yes;"><font face="Times New Roman">&nbsp;&nbsp;&nbsp; </font></span></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">小型防火墙是专门为中小企业、中小型办公室环境或家庭用户提供安全保护的防火墙产品。</span><span lang="EN-US" style="FONT-SIZE: 12pt;"><p></p></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt;"><span style="mso-spacerun: yes;"><font face="Times New Roman">&nbsp;&nbsp;&nbsp; </font></span></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">小型防火墙的目的是要在内外网络之间建立一个安全控制点,通过允许、拒绝或重定向经过防火墙的数据流,实现对进出内部网络的服务和访问的审计和控制。</span><span lang="EN-US" style="FONT-SIZE: 12pt;"><p></p></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt;"><span lang="EN-US" style="FONT-SIZE: 12pt;"><span style="mso-spacerun: yes;"><font face="Times New Roman">&nbsp;&nbsp;&nbsp; </font></span></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">小型防火墙的特点是体积小、硬件配置低、流量性能低,其主要访问控制能力与普通防火墙基本相同,但其部分安全功能要求比普通防火墙低,只能适用于中小企业、中小型办公室环境或家庭用户,建议内网用户一般不超过</span><span lang="EN-US" style="FONT-SIZE: 12pt;"><font face="Times New Roman">10</font></span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman';">个。</span><span lang="EN-US" style="FONT-SIZE: 12pt;"><p></p></span></p><h1 style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%;"><a name="_Toc61327454"><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;">4<span style="mso-spacerun: yes;">&nbsp; </span></span></a><span style="mso-bookmark: _Toc61327454;"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;">安全功能要求</span></span><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-font-kerning: 1.0pt; mso-bidi-font-weight: normal;"><p></p></span></h1><h2 style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%;"><a name="_Toc61327455"><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">4.1<span style="mso-spacerun: yes;">&nbsp; </span></span></a><span style="mso-bookmark: _Toc61327455;"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">用户数据保护功能类(<span lang="EN-US">FDP</span>)</span></span><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;"><p></p></span></h2><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327456"></a><a name="_Toc29354113"></a><a name="_Toc29353922"></a><a name="_Toc27892983"><span style="mso-bookmark: _Toc29353922;"><span style="mso-bookmark: _Toc29354113;"><span style="mso-bookmark: _Toc61327456;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.1.1<span style="mso-spacerun: yes;">&nbsp; </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892983;"><span style="mso-bookmark: _Toc29353922;"><span style="mso-bookmark: _Toc29354113;"><span style="mso-bookmark: _Toc61327456;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">完整的客体访问控制(<span lang="EN-US">FDP_ACC.2</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应在以下方面执行未鉴别的端到端策略<span lang="EN-US">:<p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">a</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)主体:未经防火墙鉴别的主机;<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">b</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)客体:内部或外部网上的主机。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">以及安全功能策略所包括主体和客体上的所有操作。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应确保安全功能策略包括了控制范围中的任何主体和客体之间的所有操作。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327457"></a><a name="_Toc29354114"></a><a name="_Toc29353923"></a><a name="_Toc27892984"><span style="mso-bookmark: _Toc29353923;"><span style="mso-bookmark: _Toc29354114;"><span style="mso-bookmark: _Toc61327457;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.1.2<span style="mso-spacerun: yes;">&nbsp; </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892984;"><span style="mso-bookmark: _Toc29353923;"><span style="mso-bookmark: _Toc29354114;"><span style="mso-bookmark: _Toc61327457;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">访问授权与拒绝(<span lang="EN-US">FDP_ACF.4</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应执行未鉴别的端到端策略。根据主体和客体的安全属性值提供明确的访问保障能力。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应执行未鉴别的端到端策略。根据主体和客体的安全属性值提供明确的拒绝访问能力。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327458"></a><a name="_Toc29354115"></a><a name="_Toc29353924"></a><a name="_Toc27892985"><span style="mso-bookmark: _Toc29353924;"><span style="mso-bookmark: _Toc29354115;"><span style="mso-bookmark: _Toc61327458;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.1.3<span style="mso-spacerun: yes;">&nbsp; </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892985;"><span style="mso-bookmark: _Toc29353924;"><span style="mso-bookmark: _Toc29354115;"><span style="mso-bookmark: _Toc61327458;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">多种安全属性访问控制(<span lang="EN-US">FDP_ACF.2</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙应根据源地址,目的地址,传输层协议和请求的服务(如源端口号或目的端口号)对客体执行未鉴别的端到端策略。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙应执行以下规则以确定受控主体与受控客体之间的操作是否被允许:<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">a</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)防火墙应拒绝从外部网络发出的、但拥有内部网络上的主机源地址的访问或服务请求。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; tab-stops: list 18.0pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">b</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)防火墙应拒绝从外部网络发出的、但拥有广播网络上的主机源地址的访问或服务请求。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; tab-stops: list 18.0pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">c</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)防火墙应拒绝从外部网络发出的、但拥有保留网络上的主机源地址的访问或服务请求。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; tab-stops: list 18.0pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">d</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)防火墙应拒绝从外部网络发出的、但拥有环回网络上的主机源地址的访问或服务请求。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327459"></a><a name="_Toc29354117"></a><a name="_Toc29353926"></a><a name="_Toc27892987"><span style="mso-bookmark: _Toc29353926;"><span style="mso-bookmark: _Toc29354117;"><span style="mso-bookmark: _Toc61327459;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.1.4<span style="mso-spacerun: yes;">&nbsp; </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892987;"><span style="mso-bookmark: _Toc29353926;"><span style="mso-bookmark: _Toc29354117;"><span style="mso-bookmark: _Toc61327459;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">管理员属性修改(<span lang="EN-US">FDP_SAM.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙应执行访问控制的功能策略(<span lang="EN-US">SFP</span>):未鉴别的端到端策略,向授权管理员提供修改下述参数的能力:<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; tab-stops: list 18.0pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">a</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)标识与角色(例如:管理员)的关联。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; tab-stops: list 18.0pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">b</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)<span lang="EN-US">FDP_ACF.2</span>中标识的访问控制属性。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; tab-stops: list 18.0pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">c</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)与安全有关的管理数据。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327460"></a><a name="_Toc29354118"></a><a name="_Toc29353927"></a><a name="_Toc27892988"><span style="mso-bookmark: _Toc29353927;"><span style="mso-bookmark: _Toc29354118;"><span style="mso-bookmark: _Toc61327460;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.1.5<span style="mso-spacerun: yes;">&nbsp; </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892988;"><span style="mso-bookmark: _Toc29353927;"><span style="mso-bookmark: _Toc29354118;"><span style="mso-bookmark: _Toc61327460;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">管理员属性查询(<span lang="EN-US">FDP_SAQ.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙应执行访问控制的功能策略:未鉴别的端到端策略,向授权管理员提供以下查询:<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; tab-stops: list 18.0pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">a</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)<span lang="EN-US">FDP_ACF.2</span>中标识的访问控制属性。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 36pt; tab-stops: list 18.0pt; mso-char-indent-count: 3.0;"><span lang="EN-US" style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">b</span><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">)主机名。<span lang="EN-US"><p></p></span></span></p><h2 style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%;"><a name="_Toc61327461"><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">4.2<span style="mso-spacerun: yes;">&nbsp; </span></span></a><span style="mso-bookmark: _Toc61327461;"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">识别与鉴别功能类(<span lang="EN-US">FIA</span>)</span></span><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;"><p></p></span></h2><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327462"></a><a name="_Toc29354120"></a><a name="_Toc29353929"></a><a name="_Toc27892990"><span style="mso-bookmark: _Toc29353929;"><span style="mso-bookmark: _Toc29354120;"><span style="mso-bookmark: _Toc61327462;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.2.1<span style="mso-spacerun: yes;">&nbsp; </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892990;"><span style="mso-bookmark: _Toc29353929;"><span style="mso-bookmark: _Toc29354120;"><span style="mso-bookmark: _Toc61327462;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">授权管理员和可信主机鉴别数据初始化(<span lang="EN-US">FIA_ADA.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙应根据<span lang="EN-US">FIA_UAU.1</span>和<span lang="EN-US">FIA_UAU.2</span>中规定的鉴别数据提供授权管理员和可信主机鉴别数据的初始化功能。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙应确保只允许授权管理员使用这些功能。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327463"></a><a name="_Toc29354121"></a><a name="_Toc29353930"></a><a name="_Toc27892991"><span style="mso-bookmark: _Toc29353930;"><span style="mso-bookmark: _Toc29354121;"><span style="mso-bookmark: _Toc61327463;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.2.2<span style="mso-spacerun: yes;">&nbsp; </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892991;"><span style="mso-bookmark: _Toc29353930;"><span style="mso-bookmark: _Toc29354121;"><span style="mso-bookmark: _Toc61327463;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">授权管理员和可信主机鉴别数据的基本保护(<span lang="EN-US">FIA_ADP.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙应保护存储于设备中的鉴别数据不受未授权查阅、修改和破坏。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327464"></a><a name="_Toc29354123"></a><a name="_Toc29353932"></a><a name="_Toc27892993"><span style="mso-bookmark: _Toc29353932;"><span style="mso-bookmark: _Toc29354123;"><span style="mso-bookmark: _Toc61327464;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.2.3<span style="mso-spacerun: yes;">&nbsp; </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892993;"><span style="mso-bookmark: _Toc29353932;"><span style="mso-bookmark: _Toc29354123;"><span style="mso-bookmark: _Toc61327464;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">授权管理员可信主机和主机属性的初始化(<span lang="EN-US">FIA_ATA.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应提供用默认值对授权管理员,可信主机和主机属性初始化的能力。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327465"></a><a name="_Toc29354124"></a><a name="_Toc29353933"></a><a name="_Toc27892994"><span style="mso-bookmark: _Toc29353933;"><span style="mso-bookmark: _Toc29354124;"><span style="mso-bookmark: _Toc61327465;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.2.4<span style="mso-spacerun: yes;">&nbsp; </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892994;"><span style="mso-bookmark: _Toc29353933;"><span style="mso-bookmark: _Toc29354124;"><span style="mso-bookmark: _Toc61327465;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">授权管理员、可信主机和主机唯一属性定义(<span lang="EN-US">FIA_ATD.2</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应为每一个规定的授权管理员、可信主机和主机提供一套唯一的,为了执行安全策略所必须的安全属性。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327466"></a><a name="_Toc29354125"></a><a name="_Toc29353934"></a><a name="_Toc27892995"><span style="mso-bookmark: _Toc29353934;"><span style="mso-bookmark: _Toc29354125;"><span style="mso-bookmark: _Toc61327466;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.2.5<span style="mso-spacerun: yes;">&nbsp; </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892995;"><span style="mso-bookmark: _Toc29353934;"><span style="mso-bookmark: _Toc29354125;"><span style="mso-bookmark: _Toc61327466;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">授权管理员的基本鉴别(<span lang="EN-US">FIA_UAU.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应鉴别任何通过防火墙的控制口履行授权管理员功能的管理员身份。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327467"></a><a name="_Toc29354126"></a><a name="_Toc29353935"></a><a name="_Toc27892996"><span style="mso-bookmark: _Toc29353935;"><span style="mso-bookmark: _Toc29354126;"><span style="mso-bookmark: _Toc61327467;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.2.6<span style="mso-spacerun: yes;">&nbsp; </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892996;"><span style="mso-bookmark: _Toc29353935;"><span style="mso-bookmark: _Toc29354126;"><span style="mso-bookmark: _Toc61327467;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">单一使用的鉴别机制(<span lang="EN-US">FIA_UAU.2</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应鉴别任何声称要履行授权管理员和可信主机功能的管理员和主机的身份。<span lang="EN-US"><p></p></span></span></p><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙应预防与远程管理和远程可信主机操作有关的鉴别数据的重用。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327468"></a><a name="_Toc29354127"></a><a name="_Toc29353936"></a><a name="_Toc27892997"><span style="mso-bookmark: _Toc29353936;"><span style="mso-bookmark: _Toc29354127;"><span style="mso-bookmark: _Toc61327468;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.2.7<span style="mso-spacerun: yes;">&nbsp; </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892997;"><span style="mso-bookmark: _Toc29353936;"><span style="mso-bookmark: _Toc29354127;"><span style="mso-bookmark: _Toc61327468;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">授权管理员、可信主机和主机唯一身份识别(<span lang="EN-US">FIA_UID.2</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应确保在所有授权管理员、可信主机和主机请求执行的任何操作之前,对每个授权管理员、可信主机和主机进行唯一身份识别。<span lang="EN-US"><p></p></span></span></p><h2 style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%;"><a name="_Toc61327469"></a><a name="_Toc29354128"></a><a name="_Toc29353937"></a><a name="_Toc27892998"><span style="mso-bookmark: _Toc29353937;"><span style="mso-bookmark: _Toc29354128;"><span style="mso-bookmark: _Toc61327469;"><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">4.3<span style="mso-spacerun: yes;">&nbsp; </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892998;"><span style="mso-bookmark: _Toc29353937;"><span style="mso-bookmark: _Toc29354128;"><span style="mso-bookmark: _Toc61327469;"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">保密功能类(<span lang="EN-US">FEN</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;"><p></p></span></h2><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327470"></a><a name="_Toc29354129"></a><a name="_Toc29353938"></a><a name="_Toc27892999"><span style="mso-bookmark: _Toc29353938;"><span style="mso-bookmark: _Toc29354129;"><span style="mso-bookmark: _Toc61327470;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.3.1<span style="mso-spacerun: yes;">&nbsp; </span></span></span></span></span></a><span style="mso-bookmark: _Toc27892999;"><span style="mso-bookmark: _Toc29353938;"><span style="mso-bookmark: _Toc29354129;"><span style="mso-bookmark: _Toc61327470;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">符合规定的加密操作(<span lang="EN-US">FCS_COP.2</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应保证其从外部网络到防火墙的远程管理会话的加密符合国家密码管理的有关规定。<span lang="EN-US"><p></p></span></span></p><h2 style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%;"><a name="_Toc61327471"><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">4.4<span style="mso-spacerun: yes;">&nbsp; </span></span></a><span style="mso-bookmark: _Toc61327471;"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">可信安全功能保护类(<span lang="EN-US">FPT</span>)</span></span><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;"><p></p></span></h2><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327472"></a><a name="_Toc29354131"></a><a name="_Toc29353940"></a><a name="_Toc27893001"><span style="mso-bookmark: _Toc29353940;"><span style="mso-bookmark: _Toc29354131;"><span style="mso-bookmark: _Toc61327472;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.4.1<span style="mso-spacerun: yes;">&nbsp; </span></span></span></span></span></a><span style="mso-bookmark: _Toc27893001;"><span style="mso-bookmark: _Toc29353940;"><span style="mso-bookmark: _Toc29354131;"><span style="mso-bookmark: _Toc61327472;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">防火墙安全策略的不可旁路性(<span lang="EN-US">FPT_RVM.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应确保任何与安全有关的操作被允许执行之前,都必须通过安全策略的检查。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327473"></a><a name="_Toc29354132"></a><a name="_Toc29353941"></a><a name="_Toc27893002"><span style="mso-bookmark: _Toc29353941;"><span style="mso-bookmark: _Toc29354132;"><span style="mso-bookmark: _Toc61327473;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.4.2<span style="mso-spacerun: yes;">&nbsp; </span></span></span></span></span></a><span style="mso-bookmark: _Toc27893002;"><span style="mso-bookmark: _Toc29353941;"><span style="mso-bookmark: _Toc29354132;"><span style="mso-bookmark: _Toc61327473;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">安全功能区域分割(<span lang="EN-US">FPT_SEP.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应为其自身的执行过程设定一个安全区域,以保护其免遭不可信主体的干扰和篡改。<span lang="EN-US"><p></p></span></span></p><h2 style="MARGIN: 6pt 0cm; LINE-HEIGHT: 150%;"><a name="_Toc61327474"><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">4.5<span style="mso-spacerun: yes;">&nbsp; </span></span></a><span style="mso-bookmark: _Toc61327474;"><span style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;">安全审计功能类(<span lang="EN-US">FAU</span>)</span></span><span lang="EN-US" style="FONT-SIZE: 12pt; LINE-HEIGHT: 150%; FONT-FAMILY: 宋体; mso-bidi-font-weight: normal;"><p></p></span></h2><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327475"></a><a name="_Toc29354136"></a><a name="_Toc29353945"></a><a name="_Toc27893006"><span style="mso-bookmark: _Toc29353945;"><span style="mso-bookmark: _Toc29354136;"><span style="mso-bookmark: _Toc61327475;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.5.1<span style="mso-spacerun: yes;">&nbsp; </span></span></span></span></span></a><span style="mso-bookmark: _Toc27893006;"><span style="mso-bookmark: _Toc29353945;"><span style="mso-bookmark: _Toc29354136;"><span style="mso-bookmark: _Toc61327475;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">审计数据生成(<span lang="EN-US">FAU_GEN.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应能够对可审计事件生成一个审计记录:<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327476"></a><a name="_Toc29354138"></a><a name="_Toc29353947"></a><a name="_Toc27893008"><span style="mso-bookmark: _Toc29353947;"><span style="mso-bookmark: _Toc29354138;"><span style="mso-bookmark: _Toc61327476;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.5.2<span style="mso-spacerun: yes;">&nbsp; </span></span></span></span></span></a><span style="mso-bookmark: _Toc27893008;"><span style="mso-bookmark: _Toc29353947;"><span style="mso-bookmark: _Toc29354138;"><span style="mso-bookmark: _Toc61327476;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">可理解的格式(<span lang="EN-US">FAU_POP.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应使审计记录中的所有审计数据可为人所理解。<span lang="EN-US"><p></p></span></span></p><h3 style="MARGIN: 6pt 0cm; LINE-HEIGHT: normal;"><a name="_Toc61327477"></a><a name="_Toc29354139"></a><a name="_Toc29353948"></a><a name="_Toc27893009"><span style="mso-bookmark: _Toc29353948;"><span style="mso-bookmark: _Toc29354139;"><span style="mso-bookmark: _Toc61327477;"><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">4.5.3<span style="mso-spacerun: yes;">&nbsp; </span></span></span></span></span></a><span style="mso-bookmark: _Toc27893009;"><span style="mso-bookmark: _Toc29353948;"><span style="mso-bookmark: _Toc29354139;"><span style="mso-bookmark: _Toc61327477;"><span style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;">限制审计跟踪访问(<span lang="EN-US">FAU_PRO.1</span>)</span></span></span></span></span><span lang="EN-US" style="FONT-WEIGHT: normal; FONT-SIZE: 12pt; FONT-FAMILY: 宋体; mso-bidi-font-weight: bold;"><p></p></span></h3><p class="MsoNormal" style="MARGIN: 0cm 0cm 0pt; TEXT-INDENT: 24pt; mso-char-indent-count: 2.0;"><span style="FONT-SIZE: 12pt; FONT-FAMILY: 宋体;">防火墙的安全功能应只允许授权管理员访问审计记录。<span lang="EN-US"><p></p></span></span></p>
您需要登录后才可以回帖 登录 | 马上注册

本版积分规则

小黑屋|手机版|Archiver|信息系统项目管理师_软考交流平台. ( 鄂ICP备11002878号-1  公安备案号:42011102001150

GMT+8, 2025-7-5 18:00

Software by Discuz! X3.2

© 2001-2013 SKIN BY DSVUE

快速回复 返回顶部 返回列表