信息安全研究 ›› 2021, Vol. 7 ›› Issue (1): 75-80.

• 学术论文 • 上一篇    下一篇

面向网络安全防御防护的大数据平台架构研究

王逸鹤1,黄亦芃2   

  1. 1. 中核战略规划研究总院有限公司
    2. 清华大学软件学院
  • 收稿日期:2021-01-10 出版日期:2021-01-05 发布日期:2021-01-10
  • 通讯作者: 王逸鹤
  • 作者简介:王逸鹤 网络安全工程师,主要研究方向为网络安全和信息风险管理. tinayihe@163.com 黄亦芃 博士后,主要研究方向为大数据、机器学习与运筹优化. huang.yipeng@hotmail.com

A Study of Big Data Platform Architecture to Address Cybersecurity Protection and Defense

  • Received:2021-01-10 Online:2021-01-05 Published:2021-01-10

摘要: 近年来,日益严峻的网络安全形势对信息系统的网络安全防御防护能力提出了更高的要求. 大量且多样的网络数据使得网络攻击的态势感知、应急处置等防御环节面临挑战. 因此,网络安全技术以及网络安全架构设计也应在此趋势下做出及时和持续的改进. 本文通过对网络安全防御防护能力和大数据技术的研究,提出了以态势感知、应急处置决策支持和网络安全系统智能优化为主的网络安全大数据平台功能需求,并设计了平台的技术架构. 基于该架构建设的网络安全大数据平台可以提高网络威胁态势感知的前瞻性和准确性、网络事件应急处置的实时性和有效性、网络安全体系架构的前沿性和全面性以及架构优化调整的及时性.

关键词: 网络安全, 大数据, 态势感知, 应急处置, 决策支持, 系统优化

Abstract: The increasingly serious situation of cybersecurity keeps challenging the protection and defense of information systems against vulnerabilities and cyber attacks. The network flows and data with high volume and large variety bring even more issues to the information system protection in terms of cybersecurity situation awareness, crisis handling, etc. Thus, the cybersecurity technology and the information system architecture should have timely and continuous improvement in order to deal with situation changes. By analyzing the cybersecurity abilities of a information system and the big data technologies, this study proposes 3 main features of a big data platform for cybersecurity concerns: cybersecurity situation awareness, decision support for handling cybersecurity crises and cybersecurity system optimization, and therefore provides the technical architecture of the platform that aims at addressing cybersecurity protection and defense. A big data platform based on the proposed architecture can improve the foresight and the accuracy of the situation awareness, ensure the real-time performance and the effectiveness of the crisis handling and guarantee the technological advancement and the versatility of the information system architecture towards cybersecurity considering the timeliness in its optimization.

Key words: cybersecurity, big data, situation awareness, crisis handling, decision support, system optimization