信息安全研究 ›› 2021, Vol. 7 ›› Issue (9): 844-848.

• 学术论文 • 上一篇    下一篇

 网络安全态势感知标准架构设计

陈妍1),朱燕2),刘玉岭2),刘星材1)   

  1. 1)(公安部第三研究所 公安部信息安全产品检测中心,上海 200031)
    2)(中国科学院信息工程研究所 第六研究室,北京 100093)

  • 出版日期:2021-09-13 发布日期:2021-09-13
  • 通讯作者: 陈妍
  • 作者简介:陈妍 博士 副研究员,主要研究领域为网络安全、云计算安全、网络安全态势感知、安全测评和认证. chenyan@mctc.org.cn. 朱燕 硕士,助理工程师,主要研究领域为网络安全态势感知. zhuyan0117@iie.ac.cn

Design of the standard architecture of the network security situation awareness

  • Online:2021-09-13 Published:2021-09-13

摘要: 网络安全态势感知平台作为网络安全的实时守护者,是实现“全天候全方位感知网络安全态势”的主要手段。然而不同于传统防火墙、入侵检测、安全审计等功能相对固化的产品,网络安全态势感知的概念及应用则复杂很多。文章在国内外网络安全态势感知的典型模型的基础上,围绕组织在进行网络安全态势感知能力建设、厂商在开发和设计网络安全态势感知产品时面临的问题,给出了网络安全态势感知的标准架构,能够为网络安全态势感知研发、生产和检测单位开展规范化科研、生产和检测提供依据。

关键词: 网络安全, 入侵检测, 态势感知, 典型模型, 标准架构

Abstract: As the real-time guardian of the network security, network security situation awareness platform is the main means to realize "all-weather and all-round awareness of the network security situation". However, being different from the traditional firewall, intrusion detection, security audit and other functions of relatively fixed products, the concept and application of the network security situation awareness is much more complex. Based on the investigation of typical models of network security situation awareness at home and abroad, this paper presents the standard framework of network security situation awareness, focusing on the problems faced by organizations in building network security situation awareness capability and manufacturers in developing and designing network security situation awareness products. It can provide basis for the network security situation awareness R & D, production and testing units to carry out standardized scientific research, production and testing.

Key words:  , network security, intrusion detection, situation awareness, typical model, standard architecture